Skip to content
EU AI Assurance OS

FAQ

Frequently asked questions

When Annex III high-risk duties apply, what Article 50 requires, how a release gate works, and how to start. Not legal advice.

What is the EU AI Act?

Regulation (EU) 2024/1689 is the EU’s risk-based law for placing and using AI systems on the Union market. Duties depend on risk class and on whether you are a provider or a deployer. This product organises evidence against those duties. It is not legal advice.

When do high-risk AI duties apply?

Standalone Annex III high-risk obligations apply from 2 December 2027 under Regulation (EU) 2026/1744. AI embedded in Annex I products applies from 2 August 2028. Article 50 transparency has applied since 2 August 2026 and was not deferred.

What is Article 50 of the EU AI Act?

Article 50 is the transparency layer: disclose AI interaction when it is not obvious, mark synthetic content in a machine-readable way, and inform people exposed to certain emotion-recognition or biometric systems. It can apply even when the system is not high-risk.

What is an EU AI Act risk classification?

The tier assigned to a system — prohibited, high, limited, or minimal — from its intended use, sector, decision impact, and affected users. Annex III lists use cases presumed high-risk. The tier sets which controls and evidence this product requires before release.

Does this certify my AI system or replace a notified body?

No. EU AI Assurance OS is software for your own release governance. It is not a notified body, not a CE-mark issuer, and not a legal certificate. Counsel still owns the determination of obligations.

How is this different from a GRC platform?

Most GRC tools inventory policies and collect evidence across many frameworks. This is a fail-closed release gate for AI systems: missing evidence, a failed eval, an open contract breach, or a missing promotion timestamp does not pass.

What is Evgraph?

A separate library that checks promotion files and dataset licenses beside the release gate. If an approval timestamp or dataset license is not in the files, the check does not pass. We do not invent missing fields.

What is an evidence pack?

A sealed, exportable bundle (JSON plus a hashed PDF) of the documents, citations, eval results, contract status, approvals, and Evgraph artifacts behind a release decision — built for audit review, not as a legal Annex IV filing.

Are the named EU companies on this site customers?

No. Those examples are reconstructed from pages the organisations already published. They are not customers, not legal findings, and not accusations of non-compliance.

Who needs to approve a high-risk AI system release?

High-risk systems route through owner, compliance, and legal approval, and require documented human-oversight evidence before the release gate can pass.

What counts as a data-contract drift event?

A drift event is recorded when an input source no longer matches its agreed schema or semantic contract. An open breach-severity event blocks the release gate until it is closed.

How do you start?

Request a demo. We scope one named AI system and send a written quote. This is not a self-serve subscription and not a legal certificate.

Ready to see your release gate?

Request a demo for one named AI system. We follow up with a written quote. This is not a legal certificate.