EU AI Act — defensible compliance
Gamut turns Regulation (EU) 2024/1689 into a system-scoped assessment that connects legal classification, operator roles, implementation, evidence, testing, findings and accountable human sign-off.
The module is designed to answer:
Which EU AI Act provisions apply to this named AI system and organisation, why do they apply, what has been demonstrated, what remains unresolved, and what conclusion can responsibly be made as of the stated legal snapshot?
Start here
Section titled “Start here”| If you need to… | Read |
|---|---|
| Understand application dates, territorial scope and regulated roles | Legal status, scope and roles |
| Understand why categories appear for a system | Routing and classification |
| See every control family and atomic legal check | Atomic requirement catalogue |
| Complete an assessment from intake to confirmation | Assessment workflow |
| Explain Compliant, Non-compliant, N/A and depth 0–3 | Scoring, assurance and conclusions |
| Build an evidence pack and test obligations | Evidence, testing and findings |
| Use system-scoped AI analysis securely | AI Assist and security |
| Produce a defensible system or portfolio report | Reporting and governance |
| Follow a complete example | Worked example |
| Look up routes, statuses, dates, terms and safe explanations | Reference and glossary |
At a glance
Section titled “At a glance”| Property | Gamut implementation |
|---|---|
| Legal baseline | Regulation (EU) 2024/1689 |
| Legal snapshot | Reviewed 16 July 2026 |
| Methodology identifier | EUAIA-2026-07-16-defensible-system-scope |
| Assessment scope | One named AI system and its current intake |
| Routed categories | 11 |
| Parent requirements | 34 |
| Atomic assessment items | 72 |
| Hard stop | Confirmed or unresolved potential Article 5 prohibited practice |
| Answers | Compliant, Non-compliant or N/A |
| Assurance depth | 0 Gap, 1 Asserted, 2 Supported/Partial, 3 Assured |
| Confirmation model | Authoritative, evidence- and test-gated human sign-off |
| Legal presentation | Current-law conclusion separated from future-readiness information |
This is not a single risk-class selector
Section titled “This is not a single risk-class selector”The Act contains different legal mechanisms: scope, prohibited practices, high-risk classification, operator duties, transparency triggers, GPAI duties and application dates. They are not one mutually exclusive ladder.
A system may, for example:
- Be within territorial scope.
- Be an Annex III high-risk system.
- Trigger direct-interaction transparency.
- Use a GPAI model supplied by another organisation.
- Require deployer duties but not a FRIA.
- Carry future obligations that are not yet used in the current-law conclusion.
Gamut therefore calculates orthogonal routes. Each route is independently supported, excluded or left unresolved from structured system facts. The server, not free-form browser text, determines the authoritative route.
The eleven routes
Section titled “The eleven routes”| Route | Purpose |
|---|---|
SCOPE | EU nexus, exclusions, AI-system definition, role, timing and AI literacy |
PROHIBITED | Eight Article 5 prohibited-practice checks and hard-stop logic |
CLASSIFICATION | Article 6, Annex I, Annex III, exceptions and profiling override |
HIGHREQ | High-risk system requirements in Articles 8–15 |
OPERATORS | Provider, deployer, representative, importer, distributor and value-chain duties |
FRIA | Article 27 fundamental-rights impact assessment applicability and completion |
TRANSPARENCY | Trigger-specific Article 50 notices, marking and disclosures |
MONITORING | High-risk post-market monitoring and serious-incident handling |
GPAI_MONITORING | Article 55 systemic-risk evaluation, incidents and cybersecurity |
GPAI | GPAI classification, documentation, copyright, downstream and representative duties |
NA | Governed non-applicability decisions and residual evidence trail |
See Routing and classification for the decision logic and contradiction handling.
The operating model
Section titled “The operating model”Named AI system → structured legal intake → authoritative route and legal status → 72 applicable atomic checks → implementation answer and depth → accepted evidence + scoped test + findings review → current-law and future-readiness conclusions → accountable human confirmation → system report and conservative portfolio roll-upThe route decides what must be assessed. The assessment record decides what has been demonstrated. Neither is a substitute for the other.
What makes a conclusion defensible
Section titled “What makes a conclusion defensible”A strong conclusion requires all of the following:
- The correct named system and legal boundary.
- Structured facts sufficient to determine scope, role and triggered routes.
- No unresolved contradictions.
- Each applicable atomic item assessed independently.
- Compliant items supported at depth 3 by accepted evidence and effective testing.
- N/A items supported by a complete, approved, trigger-specific decision.
- No unresolved adverse finding or failed test contradicting the claim.
- Article 5 screening clear.
- Current binding law separated from future or proposed changes.
- An owner, confidence rating, residual-risk statement, review date, detailed conclusion and reassessment triggers.
Gamut fails confirmation closed when these conditions are not met.
Legal-status discipline
Section titled “Legal-status discipline”The module distinguishes:
- In force: used in the current-law compliance conclusion.
- Future obligation: tracked for readiness but not presented as a current breach.
- Proposed change only: implementation intelligence that is not substituted for binding law.
- Non-binding guidance or code: useful interpretive or demonstration material, clearly labelled.
The controlling text remains the official Regulation on EUR-Lex. The European Commission’s AI Act policy page should be checked for current implementation information.
Security and governance principles
Section titled “Security and governance principles”The assessment follows:
- System isolation: answers, evidence, tests, findings and AI analysis remain tied to the selected system.
- Zero trust: identity, workspace, role, entitlement and object scope are revalidated by the server.
- Least privilege: assessors and AI providers receive only the information required for the authorised action.
- Fail closed: missing scope facts, prohibited-practice potential, contradictions and assurance gaps block an overstated confirmation.
- Human accountability: AI suggestions cannot confirm applicability, accept evidence, approve N/A or sign the conclusion.
- Change sensitivity: a material change to the legal basis invalidates confirmation and requires reassessment.