EU AI Act conformity
Classify an AI system into the Act's risk tiers from its declared use, sector, and properties, map a framework to controls and evidence, then seal the conformity decision into an offline-verifiable record. Conformity-readiness — not a certificate.
- —The declared use falls within an Annex III high-risk family, so the Chapter 2 provider obligation stack (Art. 9–15) applies before the system may be placed on the market.
- —Profiling of natural persons removes the Art. 6(3) procedural derogation, so high-risk classification stands.
Legal basis
- Annex III(5)(c) — risk assessment and pricing in life and health insurance.
- Art. 6(3) final subparagraph — profiling removes the derogation.
Applicable obligations
- Art. 9Risk-management system
Establish, document, and maintain a continuous risk-management system across the lifecycle: identify and analyse known and foreseeable risks, evaluate residual risk, and adopt targeted mitigation measures.
- Art. 10Data and data governance
Training, validation, and testing data sets are subject to governance: relevance, representativeness, freedom from errors, examination for bias, and appropriateness for the intended purpose.
- Art. 11Technical documentation
Draw up and keep up to date the Annex IV technical documentation demonstrating conformity before placing on the market.
- Art. 12Record-keeping / logging
Automatically record events (logs) over the system's lifetime to ensure a level of traceability appropriate to the intended purpose.
- Art. 13Transparency & provision of information to deployers
Design for sufficient transparency; provide instructions for use enabling deployers to interpret output and use the system appropriately.
- Art. 14Human oversight
Design and develop with effective human-oversight measures so natural persons can understand, monitor, and intervene — including a stop/override capability.
- Art. 15Accuracy, robustness & cybersecurity
Achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in those respects throughout the lifecycle.
Synthetic, operator-declared profile (Sandbox). This is a conformity-readiness classification for decision support — not a legal determination and not a conformity certificate. The Act's classification of a real system is a regulated determination reviewable by an auditor or notified body.
EU AI Act — high-risk provider obligations (Art. 9–15)
4 met · 2 in-progress · 1 gap · 57% readinessContinuous, documented risk-management system across the lifecycle.
1 current artifact (present, reviewed, within freshness window).
Governed, representative, bias-examined training/validation/test data.
Evidence attached but not current: 1 unreviewed.
Up-to-date Annex IV technical documentation prior to market placement.
1 current artifact (present, reviewed, within freshness window).
Automatic event logging over the system lifetime for traceability.
1 current artifact (present, reviewed, within freshness window).
Instructions for use enabling correct interpretation of output.
Evidence is referenced but no artifact is attached.
Effective human-oversight measures incl. stop/override capability.
1 current artifact (present, reviewed, within freshness window).
Appropriate, consistent accuracy/robustness/cybersecurity over the lifecycle.
Evidence attached but not current: 1 stale (past freshness window).
Framework references are real; evidence state is synthetic (Sandbox). The status computation and gap set are real. This is conformity-readiness for decision support — not a conformity certificate, and remediation tasks are proposed (held), not applied.
3 remediations — held for review
Drafted by the governed copilot and proposed, not applied. A human must approve before anything changes compliance state. Each is sealed into the record below as held-for-review.
- Art. 10in-progress
Bring Art. 10 to current: obtain reviewer sign-off on DG-014.
Evidence attached but not current: 1 unreviewed.
- Art. 13gap
Attach and review evidence for Art. 13 (Transparency to deployers).
Referenced artifact(s) IFU-002 are not attached.
- Art. 15in-progress
Bring Art. 15 to current: refresh ARC-011 (past freshness window).
Evidence attached but not current: 1 stale (past freshness window).
Conformity record
12 records · 3 heldThe classification, every control status, and every held remediation are sealed into a SHA-256 hash chain and signed (when a signing key is configured). This is a re-verifiable conformity record — not a held certification.
- #1agent-finding · recordedEU AI Act classification: "Prior-Auth Triage Assistant" → High-risk (Annex III). Basis: Annex III(5)(c) — risk assessment and pricing in life and health insurance. Art. 6(3) final subparagraph — profiling removes the derogation.
- #2agent-finding · recordedConformity assessment — EU AI Act — high-risk provider obligations (Art. 9–15): 4/7 met, 2 in-progress, 1 gap (57% readiness).
- #3agent-finding · recordedControl Art. 9 (Risk-management system): MET — 1 current artifact (present, reviewed, within freshness window).
- #4agent-finding · recordedControl Art. 10 (Data & data governance): IN-PROGRESS — Evidence attached but not current: 1 unreviewed.
- #5agent-finding · recordedControl Art. 11 (Technical documentation (Annex IV)): MET — 1 current artifact (present, reviewed, within freshness window).
- #6agent-finding · recordedControl Art. 12 (Record-keeping / logging): MET — 1 current artifact (present, reviewed, within freshness window).
- #7agent-finding · recordedControl Art. 13 (Transparency to deployers): GAP — Evidence is referenced but no artifact is attached.
- #8agent-finding · recordedControl Art. 14 (Human oversight): MET — 1 current artifact (present, reviewed, within freshness window).
- #9agent-finding · recordedControl Art. 15 (Accuracy, robustness & cybersecurity): IN-PROGRESS — Evidence attached but not current: 1 stale (past freshness window).
- #10held-write-proposed · held-for-reviewPROPOSED (held for review): remediation for Art. 10 — Bring Art. 10 to current: obtain reviewer sign-off on DG-014.
- #11held-write-proposed · held-for-reviewPROPOSED (held for review): remediation for Art. 13 — Attach and review evidence for Art. 13 (Transparency to deployers).
- #12held-write-proposed · held-for-reviewPROPOSED (held for review): remediation for Art. 15 — Bring Art. 15 to current: refresh ARC-011 (past freshness window).
Demo data is synthetic; governance, hash chaining, and verification are real, and signing is applied when configured. ControlFrame produces audit-readiness and a re-verifiable passport — the final attestation stays the auditor's.
Offline verify this proof
Recomputes the hash chain and checks an Ed25519 signature when one is present, against the key embedded in the passport. No server is contacted.