EU AI Act

Register the AI systems your organisation builds or uses, record each one's risk level, and work through the obligations that follow — documentation, conformity, transparency and registration.

The EU AI Act (Regulation 2024/1689, a European law that regulates AI systems according to how much risk they pose) sets different duties for different systems. A spam filter is treated lightly; a system that screens job applicants or scores creditworthiness is high-risk and carries documentation, oversight and registration duties. This module holds one inventory of those systems and the flows that produce the paperwork each risk level demands. It does not classify a system for you, and it never makes a system lawful on its own.

This module is licence-gated

The EU AI Act is a pay-per-framework module. Without it in your licence the module home shows a short "not available on your current plan" message instead of the dashboard, and the sub-pages redirect instead of opening — Technical Documentation and Transparency Notices return you to /compliance, the rest to the module home. Ask your administrator if you expect the module and cannot see it.

Who uses it

Everyone who reaches the Compliance area can read the register. Changing it needs a higher role, and controls you may not use are hidden rather than shown and refused.

What's on this screen

Open Compliance in the left sidebar and choose EU AI Act. You land on the module home at /compliance/eu-ai-act, headed EU AI Act Compliance with the line "Manage compliance with EU AI Act (Regulation 2024/1689) requirements for AI system risk classification." To its right sits the one action button on this screen, AI Inventory Readiness. Below the header the page stacks four bands:

There is no filter bar and no table here — this screen is a hub, and the working lists live one level down. Its three live areas are numbered on the figure below: the readiness button 1, the saved-insights panel 2 and the action-items panel 3.

The AI assist

AI Inventory Readiness reads your registered systems and narrates where you stand. The scoring is done by Aegis, not the model: the counts and the severity-ranked gap list — each gap tied to an article, such as Article 6 for classification or Article 43 for conformity — are worked out first. The model writes them up and proposes three to five next steps. It never recomputes a score, reorders the gaps, or invents a system or an article. You decide what to do with it.

  1. Select AI Inventory Readiness at the top right. A dialog opens explaining what the assessment covers, with a Run Inventory Readiness button. Choose it and the answer streams in while four progress lines tick past. When it finishes, a confidence indicator and a Verified figures panel appear beneath the text, alongside Copy, Export DOCX and Export PDF.
  2. Select Save as record to keep the narrative. Close the dialog and the Saved AI insights panel lists it with the date it was saved, replacing the empty-state line.
  3. Select Create action item to turn a recommendation into tracked work. Give it a title and description and confirm; it then appears in Action items from AI at the foot of this page and in the main action items list.
The EU AI Act module home on a tenant with nothing registered yet — /compliance/eu-ai-act.
The EU AI Act module home on a tenant with nothing registered yet — /compliance/eu-ai-act.
A readiness read needs an inventory

With Total Systems at 0, as above, there is nothing to score and the read will say so. Register your systems first, then come back. Each run consumes one AI credit from your tenant's monthly pool.

Register an AI system

The AI Systems card opens /compliance/eu-ai-act/systems. Its table has columns for Name, Provider, Risk Level, Status, Domain, Conformity and Actions; the only row action is a Details link, because editing happens on the system page. It shows 25 systems per page, with paging controls below once you exceed that. Before anything is registered you see an empty state — "No AI systems registered yet. Register your first AI system to begin compliance tracking" — with a Register AI System button beneath it.

  1. Select Register AI System — top right of the inventory, or in the middle of the empty state. The form opens at /compliance/eu-ai-act/systems/new.
  2. Type a Name. It is the only required field, and the form will not submit without it. A recognisable name such as "Resume Screening Assistant" is what colleagues search for later.
  3. Set Operator role — your organisation's relationship to the system: Provider, Deployer, Importer, Distributor or Authorized Representative. Duties differ by role, so this drives what you owe.
  4. Choose a Risk level: Not Classified, Unacceptable, High Risk, Limited Risk or Minimal Risk. Leave it at Not Classified until the decision is taken, then classify it from the system page.
  5. Set the operational Status (Development, Testing, Production, Suspended or Decommissioned) and fill Provider, Intended purpose and Description if you know them.
  6. Select Register system. The button reads "Registering…" while it saves, then Aegis opens the new system's detail page, where the rest of the record and the obligation flows live. Cancel returns you to the inventory without saving.

Work through a system's obligations

The detail page at /compliance/eu-ai-act/systems/[id] is the workbench for one system. Its header shows the name with coloured risk-level and status badges. Under it is an action bar — Edit system, Classify risk and Delete system — each opening a dialog and each hidden from roles lacking the matching right. Classify risk asks for a risk level, a risk category (such as Employment & Worker Management) and a written justification, so the decision carries its reasoning.

Below that, an overview grid lays out the operator role, conformity status including CE marking (the mark declaring a product meets EU rules) and the EU database identifier, deployment details, and a side column with the classification, FRIA status and key dates. If the system is high-risk and unregistered, an amber banner says the EU database filing is outstanding. Then come the tools, each a step towards an obligation:

Screen for prohibited practices

Prohibited Practices Check opens /compliance/eu-ai-act/prohibited, a cross-system view of the Article 5 bans — the practices the Act forbids outright. A banner at the top reads green ("All n systems passed prohibited practices screening") or red with a count when systems are flagged. The table below lists System Name, Risk Level, Emotion Recognition, Biometric Categorization, Deepfake Capable and Status. A green tick means the practice is not flagged; a red Flagged warning means it is and needs review, and the row is tinted. Selecting a system name opens its detail page. With nothing registered you get an empty state and a Go to AI System Inventory link.

The screening surfaces the flags recorded against each system. It is not an independent detector — a system nobody has marked as emotion-recognising reads as clear here.

Tips and limits

Two of the four navigation cards behave differently from what their titles suggest:

Card What you get State
AI Systems Inventory, registration and the system workbench Built and in daily use.
Prohibited Practices Check Cross-system Article 5 screening table Built and in daily use.
Technical Documentation A signpost page with a Go to AI system inventory button No aggregate view yet; the per-system wizard and PDF export are built.
Transparency Notices A signpost page listing what is still to come — disclosure templates, Article 50 conformity tracking, deepfake labelling rules, an affected-user audit trail Labelled "Coming soon" there; the per-system notice editor is built.
Classification and conformity are your decisions

Aegis stores the risk level, conformity outcome and FRIA result that you enter. A Passed conformity status is your own attestation, not a legal certification, and no status here makes a system lawful. These fields are your organisation's record of decisions taken by people.

Deleting a system warns you first that its documentation items, transparency notices and assessments will no longer be reachable. And if the inventory fails to load it shows a red error — "Could not load your AI systems. This is a temporary problem" — with a Try again button rather than an empty table, so a passing fault never reads as though your records had vanished.

Where this connects