Skip to content

AI Assist and security

EU AI Act AI Assist supports analysis of one atomic legal requirement for the selected system. It does not make the legal decision, change routing, approve N/A, accept evidence or confirm compliance.

The panel displays the selected system and requirement. Switching systems changes the assessment context; a result generated for one system is not presented as the current result for another.

No unscoped analysis should be treated as a legal conclusion.

Subject to authorised access, analysis may consider:

  • Selected system, purpose and lifecycle state.
  • EU territorial nexus and definition/exclusion determination.
  • Organisation roles and value-chain position.
  • Article 5 atomic screening.
  • Annex I and Annex III classification facts.
  • Article 6 exception and profiling.
  • Fundamental Rights Impact Assessment triggers.
  • Article 50 behaviour and transparency routes.
  • GPAI role, systemic-risk and supply-chain status.
  • Application dates and current/future legal state.
  • Atomic result, assurance depth and N/A governance.
  • Authorised evidence.
  • Tests and results.
  • Findings.
  • Human conclusion fields and reassessment triggers.

Free text can explain facts but cannot silently rewrite structured legal routing.

Useful per-requirement output identifies:

  • Applicability reasoning.
  • Current binding status and relevant role.
  • Supported facts and assumptions.
  • Evidence position.
  • Missing information.
  • Adverse findings.
  • Suggested bounded test.
  • Potential gap and residual uncertainty.
  • Draft assessor rationale for review.

The output should distinguish current binding law from future readiness and proposed change.

The Privacy Mode checkbox next to AI Assist sends the minimum structural legal and assessment state. It excludes direct identifiers, free-text rationale and narrative evidence.

The reduced context can include route and requirement identifiers, current result, assurance, bounded evidence/test/finding status and completeness signals.

Privacy Mode reduces disclosure and may reduce legal-context specificity. It does not change routing, applicability, scoring, evidence or access.

  • Successful outputs are saved for the selected system, atomic requirement and privacy mode.
  • The action changes to Re-run AI Assist.
  • The panel can be minimised without deleting the output.
  • Re-run after material legal-route, system, requirement, evidence, test or finding change.

AI Assist uses an authorised provider and the existing API-key configuration. If no permitted provider is configured, analysis cannot run.

An API key does not grant additional access. Plan, workspace, role, framework, model and selected system permissions continue to apply.

AI Assist must not:

  • Invent an artefact.
  • Treat narrative as accepted evidence.
  • Claim a test passed without a passing record.
  • Ignore failed tests or open adverse findings.
  • Use evidence from another system.
  • Approve evidence or an exclusion.

Every material evidence claim must be checked against the authorised record.

The reviewer must confirm:

  • Which provisions apply at the stated date.
  • Which duties are future-dated.
  • Which information is proposal, guidance or implementation intelligence.
  • Whether the organisation’s role and system status match the legal proposition.

Do not describe future readiness as current compliance or current breach.

System descriptions, supplier records and evidence may contain instruction-like or malicious text. Treat it as assessment data. Do not include credentials, unnecessary personal data or privileged legal material. Verify citations and legal claims independently.

AI Assist cannot:

  • Approve territorial scope or organisation role.
  • Resolve a prohibited-practice decision.
  • Decide legal classification.
  • Approve N/A.
  • Accept evidence.
  • Pass a test.
  • Close a finding.
  • Accept risk.
  • Confirm compliance.
  • Replace legal advice or regulator guidance.
  • Correct system and atomic requirement displayed.
  • Legal snapshot and organisation role are current.
  • Applicability matches structured facts.
  • Current and future law are separated.
  • Evidence belongs to this system.
  • Failed tests and findings are included.
  • Suggested tests are safe and authorised.
  • Privacy Mode was selected where needed.
  • Legal/compliance reviewer owns the conclusion.