Skip to main content

EU AI Act conformity

Classify an AI system into the Act's risk tiers from its declared use, sector, and properties, map a framework to controls and evidence, then seal the conformity decision into an offline-verifiable record. Conformity-readiness — not a certificate.

Properties
Real classification + gap computation over a synthetic profile.
High-risk (Annex III)
7 obligations
  • The declared use falls within an Annex III high-risk family, so the Chapter 2 provider obligation stack (Art. 9–15) applies before the system may be placed on the market.
  • Profiling of natural persons removes the Art. 6(3) procedural derogation, so high-risk classification stands.

Legal basis

  • Annex III(5)(c) — risk assessment and pricing in life and health insurance.
  • Art. 6(3) final subparagraph — profiling removes the derogation.

Applicable obligations

  • Art. 9Risk-management system

    Establish, document, and maintain a continuous risk-management system across the lifecycle: identify and analyse known and foreseeable risks, evaluate residual risk, and adopt targeted mitigation measures.

  • Art. 10Data and data governance

    Training, validation, and testing data sets are subject to governance: relevance, representativeness, freedom from errors, examination for bias, and appropriateness for the intended purpose.

  • Art. 11Technical documentation

    Draw up and keep up to date the Annex IV technical documentation demonstrating conformity before placing on the market.

  • Art. 12Record-keeping / logging

    Automatically record events (logs) over the system's lifetime to ensure a level of traceability appropriate to the intended purpose.

  • Art. 13Transparency & provision of information to deployers

    Design for sufficient transparency; provide instructions for use enabling deployers to interpret output and use the system appropriately.

  • Art. 14Human oversight

    Design and develop with effective human-oversight measures so natural persons can understand, monitor, and intervene — including a stop/override capability.

  • Art. 15Accuracy, robustness & cybersecurity

    Achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in those respects throughout the lifecycle.

Synthetic, operator-declared profile (Sandbox). This is a conformity-readiness classification for decision support — not a legal determination and not a conformity certificate. The Act's classification of a real system is a regulated determination reviewable by an auditor or notified body.

EU AI Act — high-risk provider obligations (Art. 9–15)

4 met · 2 in-progress · 1 gap · 57% readiness
Art. 9Risk-management system

Continuous, documented risk-management system across the lifecycle.

met

1 current artifact (present, reviewed, within freshness window).

RMS-001 currentArt. 9
Art. 10Data & data governance

Governed, representative, bias-examined training/validation/test data.

in-progress

Evidence attached but not current: 1 unreviewed.

DG-014 unreviewedArt. 10
Art. 11Technical documentation (Annex IV)

Up-to-date Annex IV technical documentation prior to market placement.

met

1 current artifact (present, reviewed, within freshness window).

TD-IV currentArt. 11
Art. 12Record-keeping / logging

Automatic event logging over the system lifetime for traceability.

met

1 current artifact (present, reviewed, within freshness window).

LOG-OPS currentArt. 12
Art. 13Transparency to deployers

Instructions for use enabling correct interpretation of output.

gap

Evidence is referenced but no artifact is attached.

IFU-002 missingArt. 13
Art. 14Human oversight

Effective human-oversight measures incl. stop/override capability.

met

1 current artifact (present, reviewed, within freshness window).

HO-007 currentArt. 14
Art. 15Accuracy, robustness & cybersecurity

Appropriate, consistent accuracy/robustness/cybersecurity over the lifecycle.

in-progress

Evidence attached but not current: 1 stale (past freshness window).

ARC-011 staleArt. 15

Framework references are real; evidence state is synthetic (Sandbox). The status computation and gap set are real. This is conformity-readiness for decision support — not a conformity certificate, and remediation tasks are proposed (held), not applied.

3 remediations — held for review

Drafted by the governed copilot and proposed, not applied. A human must approve before anything changes compliance state. Each is sealed into the record below as held-for-review.

  • Art. 10in-progress

    Bring Art. 10 to current: obtain reviewer sign-off on DG-014.

    Evidence attached but not current: 1 unreviewed.

  • Art. 13gap

    Attach and review evidence for Art. 13 (Transparency to deployers).

    Referenced artifact(s) IFU-002 are not attached.

  • Art. 15in-progress

    Bring Art. 15 to current: refresh ARC-011 (past freshness window).

    Evidence attached but not current: 1 stale (past freshness window).

Conformity record

12 records · 3 held

The classification, every control status, and every held remediation are sealed into a SHA-256 hash chain and signed (when a signing key is configured). This is a re-verifiable conformity record — not a held certification.

  1. #1agent-finding · recordedEU AI Act classification: "Prior-Auth Triage Assistant" → High-risk (Annex III). Basis: Annex III(5)(c) — risk assessment and pricing in life and health insurance. Art. 6(3) final subparagraph — profiling removes the derogation.
  2. #2agent-finding · recordedConformity assessment — EU AI Act — high-risk provider obligations (Art. 9–15): 4/7 met, 2 in-progress, 1 gap (57% readiness).
  3. #3agent-finding · recordedControl Art. 9 (Risk-management system): MET — 1 current artifact (present, reviewed, within freshness window).
  4. #4agent-finding · recordedControl Art. 10 (Data & data governance): IN-PROGRESS — Evidence attached but not current: 1 unreviewed.
  5. #5agent-finding · recordedControl Art. 11 (Technical documentation (Annex IV)): MET — 1 current artifact (present, reviewed, within freshness window).
  6. #6agent-finding · recordedControl Art. 12 (Record-keeping / logging): MET — 1 current artifact (present, reviewed, within freshness window).
  7. #7agent-finding · recordedControl Art. 13 (Transparency to deployers): GAP — Evidence is referenced but no artifact is attached.
  8. #8agent-finding · recordedControl Art. 14 (Human oversight): MET — 1 current artifact (present, reviewed, within freshness window).
  9. #9agent-finding · recordedControl Art. 15 (Accuracy, robustness & cybersecurity): IN-PROGRESS — Evidence attached but not current: 1 stale (past freshness window).
  10. #10held-write-proposed · held-for-reviewPROPOSED (held for review): remediation for Art. 10 — Bring Art. 10 to current: obtain reviewer sign-off on DG-014.
  11. #11held-write-proposed · held-for-reviewPROPOSED (held for review): remediation for Art. 13 — Attach and review evidence for Art. 13 (Transparency to deployers).
  12. #12held-write-proposed · held-for-reviewPROPOSED (held for review): remediation for Art. 15 — Bring Art. 15 to current: refresh ARC-011 (past freshness window).

Demo data is synthetic; governance, hash chaining, and verification are real, and signing is applied when configured. ControlFrame produces audit-readiness and a re-verifiable passport — the final attestation stays the auditor's.

Offline verify this proof

Recomputes the hash chain and checks an Ed25519 signature when one is present, against the key embedded in the passport. No server is contacted.

EU AI Act Conformity | ControlFrame