Reference and glossary
Method reference
Section titled “Method reference”| Item | Value |
|---|---|
| Regulation | EU 2024/1689 |
| Snapshot | 16 July 2026 |
| Documentation source check | 21 July 2026 |
| Methodology | EUAIA-2026-07-16-defensible-system-scope |
| Categories | 11 |
| Parent requirements | 34 |
| Atomic items | 72 |
| Assessment unit | Named AI system |
Route reference
Section titled “Route reference”| Code | Meaning |
|---|---|
SCOPE | Scope, definition, role, timing, literacy |
PROHIBITED | Article 5 hard-stop screen |
CLASSIFICATION | Article 6, Annex I and Annex III |
HIGHREQ | Articles 8–15 |
OPERATORS | Operator and conformity duties |
FRIA | Article 27 |
TRANSPARENCY | Article 50 |
MONITORING | Articles 72–73 |
GPAI_MONITORING | Article 55 |
GPAI | Chapter V model and supply-chain duties |
NA | Governed non-applicability trail |
Answer and depth reference
Section titled “Answer and depth reference”| Dimension | Values |
|---|---|
| Legal answer | Compliant, Non-compliant, N/A, Unassessed |
| Depth | 3 Assured, 2 Supported/Partial, 1 Asserted, 0 Gap |
| Confidence | Low, Medium, High |
| Legal state | In force, Future obligation, Proposed change only |
Route-state reference
Section titled “Route-state reference”| State | Meaning |
|---|---|
not_assessed | No route decision |
applicable | Triggered |
not_applicable_with_evidence | Excluded through an approved decision |
incomplete | Facts or decision missing |
implemented | Routed work addressed, subject to assurance |
prohibited_stop | Article 5 stop |
future_obligation | Future readiness |
proposed_change_only | Not binding law |
Key dates
Section titled “Key dates”| Date | Significance |
|---|---|
| 1 August 2024 | Entry into force |
| 2 February 2025 | AI literacy and prohibited practices apply |
| 2 August 2025 | GPAI provider and governance provisions apply |
| 2 August 2026 | General application date in the adopted Regulation, subject to exceptions/amendments |
| 2 August 2027 | Original Annex I product-system high-risk date |
Check current formally adopted law before relying on the table.
Role glossary
Section titled “Role glossary”Provider
Entity developing or having developed and placing a system/model on the market or putting it into service under its name or trademark.
Deployer
Entity using an AI system under its authority in a professional context.
Importer
Union-established entity placing a third-country provider’s high-risk system on the Union market.
Distributor
Supply-chain entity making a system available without being provider or importer.
Product manufacturer
Manufacturer placing a product containing or using the high-risk system on the market under its name or trademark.
Authorised representative
Union-established person mandated to perform specified provider tasks. Article 22 and Article 54 routes must be distinguished.
GPAI model provider
Provider placing a general-purpose AI model on the market.
Downstream provider
Provider integrating a model into an AI system.
Assessment glossary
Section titled “Assessment glossary”Applicable
The legal trigger and role are present.
Atomic item
Smallest independently answered legal check in Gamut.
Assessment basis
The material legal-routing facts to which confirmation applies. A material change invalidates prior confirmation.
Current-law conclusion
Position using applicable provisions in force as of the stated snapshot.
Future readiness
Preparation for applicable obligations not yet used as current law.
Hard stop
Condition preventing confirmation regardless of other scores; Article 5 is the principal example.
N/A
Approved conclusion that a specific legal trigger does not apply. It is not “not yet done.”
Assured
Depth 3: current implementation, accepted evidence, effective test and no unresolved adverse finding.
Confirmation
Accountable human sign-off of the current validated assessment basis. It is not certification, deployment approval or risk acceptance by itself.
FRIA
Fundamental Rights Impact Assessment under Article 27 for specified deployers and uses.
GPAI
General-purpose AI model. Model-provider duties and downstream system duties are distinct.
Profiling override
Article 6 logic preventing reliance on the Annex III exception where profiling of natural persons is performed.
Substantial modification
Change that can trigger provider-role transfer and renewed compliance work under Article 25.
Frequently asked questions
Section titled “Frequently asked questions”Are there six EU AI Act risk classes in Gamut?
Section titled “Are there six EU AI Act risk classes in Gamut?”No. Earlier wording used six presentation groupings. The defensible method uses eleven orthogonal routes because scope, prohibited practices, high-risk duties, transparency and GPAI can coexist.
Does “not high-risk” mean out of scope?
Section titled “Does “not high-risk” mean out of scope?”No. Scope, Article 5, Article 4, Article 50 and other duties may still apply.
Does using a GPAI model make our system a GPAI model?
Section titled “Does using a GPAI model make our system a GPAI model?”Not necessarily. Determine whether the organisation is a GPAI model provider, downstream system provider, deployer or API consumer.
Does human review mean an Annex III system is not high-risk?
Section titled “Does human review mean an Annex III system is not high-risk?”No. Analyse the intended use, material influence, Article 6 exception and profiling. A nominal human-in-the-loop is not a blanket exclusion.
Does every high-risk deployer need a FRIA?
Section titled “Does every high-risk deployer need a FRIA?”No. Article 27 has its own deployer and use triggers.
Can a control be Compliant but not Assured?
Section titled “Can a control be Compliant but not Assured?”Yes. Compliant is the legal answer; depth describes verification. The claim may be Supported or Asserted until evidence and testing are complete.
Can N/A be used for future obligations?
Section titled “Can N/A be used for future obligations?”No. Use future-obligation status. N/A means the legal trigger does not apply.
Can an average offset one non-compliant obligation?
Section titled “Can an average offset one non-compliant obligation?”No. Category percentages support progress tracking; they do not erase an atomic legal gap.
Can AI Assist confirm compliance?
Section titled “Can AI Assist confirm compliance?”No. It provides system-scoped advisory analysis. Human assessors accept evidence, approve N/A, resolve legal issues and confirm.
What happens when the selected system changes?
Section titled “What happens when the selected system changes?”The assessment and AI context switch to that system. Prior AI analysis is cleared to prevent cross-system reuse.
Do AI features bypass plan entitlements?
Section titled “Do AI features bypass plan entitlements?”No. Identity, organisation, workspace, role, plan and object-scope access controls remain required.
Does confirmation mean EU certification?
Section titled “Does confirmation mean EU certification?”No. It means the assessment passed Gamut’s confirmation gates under its stated scope and snapshot.
One-minute explanation
Section titled “One-minute explanation”Gamut assesses the EU AI Act per named AI system. It first establishes EU scope, intended purpose and every operator role. Gamut then calculates eleven legal routes, including an eight-part Article 5 hard-stop screen, Annex I and all eight Annex III points, operator duties, FRIA, Article 50 and GPAI. Broad provisions are decomposed into 72 atomic checks. Each applicable item receives a legal answer and a separate assurance depth. Confirmation requires accepted evidence, passing testing and no unresolved adverse finding for every applicable in-force item, while future and proposed changes are reported separately. AI can assist analysis but cannot change routing or approve the conclusion.