Skip to content

EU AI Act — defensible compliance

Gamut turns Regulation (EU) 2024/1689 into a system-scoped assessment that connects legal classification, operator roles, implementation, evidence, testing, findings and accountable human sign-off.

The module is designed to answer:

Which EU AI Act provisions apply to this named AI system and organisation, why do they apply, what has been demonstrated, what remains unresolved, and what conclusion can responsibly be made as of the stated legal snapshot?

If you need to…Read
Understand application dates, territorial scope and regulated rolesLegal status, scope and roles
Understand why categories appear for a systemRouting and classification
See every control family and atomic legal checkAtomic requirement catalogue
Complete an assessment from intake to confirmationAssessment workflow
Explain Compliant, Non-compliant, N/A and depth 0–3Scoring, assurance and conclusions
Build an evidence pack and test obligationsEvidence, testing and findings
Use system-scoped AI analysis securelyAI Assist and security
Produce a defensible system or portfolio reportReporting and governance
Follow a complete exampleWorked example
Look up routes, statuses, dates, terms and safe explanationsReference and glossary
PropertyGamut implementation
Legal baselineRegulation (EU) 2024/1689
Legal snapshotReviewed 16 July 2026
Methodology identifierEUAIA-2026-07-16-defensible-system-scope
Assessment scopeOne named AI system and its current intake
Routed categories11
Parent requirements34
Atomic assessment items72
Hard stopConfirmed or unresolved potential Article 5 prohibited practice
AnswersCompliant, Non-compliant or N/A
Assurance depth0 Gap, 1 Asserted, 2 Supported/Partial, 3 Assured
Confirmation modelAuthoritative, evidence- and test-gated human sign-off
Legal presentationCurrent-law conclusion separated from future-readiness information

The Act contains different legal mechanisms: scope, prohibited practices, high-risk classification, operator duties, transparency triggers, GPAI duties and application dates. They are not one mutually exclusive ladder.

A system may, for example:

  • Be within territorial scope.
  • Be an Annex III high-risk system.
  • Trigger direct-interaction transparency.
  • Use a GPAI model supplied by another organisation.
  • Require deployer duties but not a FRIA.
  • Carry future obligations that are not yet used in the current-law conclusion.

Gamut therefore calculates orthogonal routes. Each route is independently supported, excluded or left unresolved from structured system facts. The server, not free-form browser text, determines the authoritative route.

RoutePurpose
SCOPEEU nexus, exclusions, AI-system definition, role, timing and AI literacy
PROHIBITEDEight Article 5 prohibited-practice checks and hard-stop logic
CLASSIFICATIONArticle 6, Annex I, Annex III, exceptions and profiling override
HIGHREQHigh-risk system requirements in Articles 8–15
OPERATORSProvider, deployer, representative, importer, distributor and value-chain duties
FRIAArticle 27 fundamental-rights impact assessment applicability and completion
TRANSPARENCYTrigger-specific Article 50 notices, marking and disclosures
MONITORINGHigh-risk post-market monitoring and serious-incident handling
GPAI_MONITORINGArticle 55 systemic-risk evaluation, incidents and cybersecurity
GPAIGPAI classification, documentation, copyright, downstream and representative duties
NAGoverned non-applicability decisions and residual evidence trail

See Routing and classification for the decision logic and contradiction handling.

Named AI system
→ structured legal intake
→ authoritative route and legal status
→ 72 applicable atomic checks
→ implementation answer and depth
→ accepted evidence + scoped test + findings review
→ current-law and future-readiness conclusions
→ accountable human confirmation
→ system report and conservative portfolio roll-up

The route decides what must be assessed. The assessment record decides what has been demonstrated. Neither is a substitute for the other.

A strong conclusion requires all of the following:

  1. The correct named system and legal boundary.
  2. Structured facts sufficient to determine scope, role and triggered routes.
  3. No unresolved contradictions.
  4. Each applicable atomic item assessed independently.
  5. Compliant items supported at depth 3 by accepted evidence and effective testing.
  6. N/A items supported by a complete, approved, trigger-specific decision.
  7. No unresolved adverse finding or failed test contradicting the claim.
  8. Article 5 screening clear.
  9. Current binding law separated from future or proposed changes.
  10. An owner, confidence rating, residual-risk statement, review date, detailed conclusion and reassessment triggers.

Gamut fails confirmation closed when these conditions are not met.

The module distinguishes:

  • In force: used in the current-law compliance conclusion.
  • Future obligation: tracked for readiness but not presented as a current breach.
  • Proposed change only: implementation intelligence that is not substituted for binding law.
  • Non-binding guidance or code: useful interpretive or demonstration material, clearly labelled.

The controlling text remains the official Regulation on EUR-Lex. The European Commission’s AI Act policy page should be checked for current implementation information.

The assessment follows:

  • System isolation: answers, evidence, tests, findings and AI analysis remain tied to the selected system.
  • Zero trust: identity, workspace, role, entitlement and object scope are revalidated by the server.
  • Least privilege: assessors and AI providers receive only the information required for the authorised action.
  • Fail closed: missing scope facts, prohibited-practice potential, contradictions and assurance gaps block an overstated confirmation.
  • Human accountability: AI suggestions cannot confirm applicability, accept evidence, approve N/A or sign the conclusion.
  • Change sensitivity: a material change to the legal basis invalidates confirmation and requires reassessment.
  1. Legal status, scope and roles
  2. Routing and classification
  3. Atomic requirement catalogue
  4. Assessment workflow
  5. Scoring, assurance and conclusions
  6. Evidence, testing and findings
  7. AI Assist and security
  8. Reporting and governance
  9. Worked example
  10. Reference and glossary