Skip to content

Reporting and governance

An EU AI Act report should answer:

What is the current legal position of this named system, which obligations and roles were assessed, what evidence and testing support the result, and what action remains?

The report should include:

  • System name, identifier, version and intended purpose.
  • Entity and operator roles.
  • EU nexus and exclusions.
  • Methodology and legal snapshot.
  • Current and future application dates.
  • Authoritative routes and triggering facts.
  • Article 5 status.
  • High-risk classification basis.
  • Atomic answer, depth and legal basis.
  • Approved N/A decisions.
  • Accepted/rejected evidence.
  • Passing/failed tests.
  • Open findings.
  • Current-law conclusion.
  • Future-readiness conclusion.
  • Confidence, residual risk, owner, reviewer and review date.
  • Reassessment triggers and confirmation basis.

If the system-specific assessment record is absent, the report should show unassessed. It must not fall back to another system or a browser-active workspace scratch record.

A portfolio roll-up may show:

  • Systems in and out of scope.
  • Article 5 potential or confirmed stops.
  • High-risk systems by Annex I/III basis.
  • Applicable operator roles.
  • FRIA coverage.
  • Article 50 trigger coverage.
  • GPAI provider and supply-chain exposure.
  • Current gaps and future-readiness gaps.
  • Systems awaiting confirmation or legal review.

Aggregation is conservative. A workspace average never proves that each system is compliant.

Clearly state:

  • “As of” date.
  • Binding provisions considered.
  • Role and factual assumptions.
  • In-force applicable items.
  • Assurance exceptions.
  • Scope limitations.

Future duties and proposed amendments belong in separate sections.

Do not bury prohibited-practice status in a percentage. Report:

  • Atomic check.
  • Clear, potential or prohibited result.
  • Facts and evidence.
  • Legal review status.
  • Deployment restriction or stop.
  • Decision owner and next action.

Show:

  • Annex I two-part analysis.
  • Annex III point.
  • Article 6 exception analysis.
  • Profiling result.
  • Final classification.
  • Provider documentation/registration where an exception is used.
  • Legal uncertainty.

For each item, show:

  • Legal answer.
  • Assurance depth.
  • Accepted evidence.
  • Test position.
  • Open adverse finding.
  • Current/future status.

Do not report “compliant” without making the supporting depth and limitations visible.

The report can inform:

  • Deployment approval or restriction.
  • Remediation priority.
  • Legal review.
  • Conformity and registration work.
  • Supplier or representative action.
  • FRIA completion.
  • Notice and transparency changes.
  • Incident escalation readiness.
  • Evidence request and retest.
  • Risk acceptance.

The assessment confirmation is not automatically a deployment approval or legal-risk acceptance. Record those decisions separately under the organisation’s authority model.

Need atomic facts, legal basis, workpapers, evidence and tests.

Need implementation gaps, owners, due dates and retest criteria.

Need material systems, Article 5 stops, high-risk exposure, assurance exceptions, legal deadlines, residual risk and decisions requiring authority or funding.

Need a controlled pack with scope, roles, methodology, current-law status, relevant evidence and limitations. Apply least privilege and legal review before disclosure.

EU AI Act items map to GTSAF, MAESTRO and ATF where evidence may be relevant.

Reuse means:

  • One artefact may support several requirements.
  • A failed technical test may inform several frameworks.
  • Traceability reduces duplicate work.

It does not mean:

Passing a GTSAF or MAESTRO item automatically proves EU AI Act compliance.

The EU legal trigger, role and assurance decision remain separate.

Prefer:

“Under the stated system boundary, operator roles and legal snapshot, all applicable in-force atomic items in this confirmed assessment meet Gamut’s depth-3 assurance gate, with the limitations and reassessment triggers stated below.”

Avoid:

  • “EU approved.”
  • “Certified compliant.”
  • “No legal risk.”
  • “The whole workspace is compliant” based on an average.
  • “N/A” without the decision basis.
  • “AI confirmed compliance.”
  • Correct named system and entity.
  • Methodology and legal snapshot visible.
  • Current, future and proposed states separated.
  • Article 5 visible.
  • Classification rationale visible.
  • Roles and value chain visible.
  • Atomic population and coverage shown.
  • Evidence, tests and adverse findings reconciled.
  • N/A approvals included.
  • Human owner, confidence, residual risk and review present.
  • No cross-system leakage.
  • No certification or legal-advice claim.