Reporting and governance
An EU AI Act report should answer:
What is the current legal position of this named system, which obligations and roles were assessed, what evidence and testing support the result, and what action remains?
Selected-system report
Section titled “Selected-system report”The report should include:
- System name, identifier, version and intended purpose.
- Entity and operator roles.
- EU nexus and exclusions.
- Methodology and legal snapshot.
- Current and future application dates.
- Authoritative routes and triggering facts.
- Article 5 status.
- High-risk classification basis.
- Atomic answer, depth and legal basis.
- Approved N/A decisions.
- Accepted/rejected evidence.
- Passing/failed tests.
- Open findings.
- Current-law conclusion.
- Future-readiness conclusion.
- Confidence, residual risk, owner, reviewer and review date.
- Reassessment triggers and confirmation basis.
If the system-specific assessment record is absent, the report should show unassessed. It must not fall back to another system or a browser-active workspace scratch record.
Workspace report
Section titled “Workspace report”A portfolio roll-up may show:
- Systems in and out of scope.
- Article 5 potential or confirmed stops.
- High-risk systems by Annex I/III basis.
- Applicable operator roles.
- FRIA coverage.
- Article 50 trigger coverage.
- GPAI provider and supply-chain exposure.
- Current gaps and future-readiness gaps.
- Systems awaiting confirmation or legal review.
Aggregation is conservative. A workspace average never proves that each system is compliant.
Current-law reporting
Section titled “Current-law reporting”Clearly state:
- “As of” date.
- Binding provisions considered.
- Role and factual assumptions.
- In-force applicable items.
- Assurance exceptions.
- Scope limitations.
Future duties and proposed amendments belong in separate sections.
Article 5 reporting
Section titled “Article 5 reporting”Do not bury prohibited-practice status in a percentage. Report:
- Atomic check.
- Clear, potential or prohibited result.
- Facts and evidence.
- Legal review status.
- Deployment restriction or stop.
- Decision owner and next action.
High-risk classification reporting
Section titled “High-risk classification reporting”Show:
- Annex I two-part analysis.
- Annex III point.
- Article 6 exception analysis.
- Profiling result.
- Final classification.
- Provider documentation/registration where an exception is used.
- Legal uncertainty.
Atomic assurance reporting
Section titled “Atomic assurance reporting”For each item, show:
- Legal answer.
- Assurance depth.
- Accepted evidence.
- Test position.
- Open adverse finding.
- Current/future status.
Do not report “compliant” without making the supporting depth and limitations visible.
Governance decisions
Section titled “Governance decisions”The report can inform:
- Deployment approval or restriction.
- Remediation priority.
- Legal review.
- Conformity and registration work.
- Supplier or representative action.
- FRIA completion.
- Notice and transparency changes.
- Incident escalation readiness.
- Evidence request and retest.
- Risk acceptance.
The assessment confirmation is not automatically a deployment approval or legal-risk acceptance. Record those decisions separately under the organisation’s authority model.
Right audience, right detail
Section titled “Right audience, right detail”Assessor and counsel
Section titled “Assessor and counsel”Need atomic facts, legal basis, workpapers, evidence and tests.
System and control owners
Section titled “System and control owners”Need implementation gaps, owners, due dates and retest criteria.
Executive or board
Section titled “Executive or board”Need material systems, Article 5 stops, high-risk exposure, assurance exceptions, legal deadlines, residual risk and decisions requiring authority or funding.
Regulator or customer
Section titled “Regulator or customer”Need a controlled pack with scope, roles, methodology, current-law status, relevant evidence and limitations. Apply least privilege and legal review before disclosure.
Cross-framework evidence reuse
Section titled “Cross-framework evidence reuse”EU AI Act items map to GTSAF, MAESTRO and ATF where evidence may be relevant.
Reuse means:
- One artefact may support several requirements.
- A failed technical test may inform several frameworks.
- Traceability reduces duplicate work.
It does not mean:
Passing a GTSAF or MAESTRO item automatically proves EU AI Act compliance.
The EU legal trigger, role and assurance decision remain separate.
Report wording
Section titled “Report wording”Prefer:
“Under the stated system boundary, operator roles and legal snapshot, all applicable in-force atomic items in this confirmed assessment meet Gamut’s depth-3 assurance gate, with the limitations and reassessment triggers stated below.”
Avoid:
- “EU approved.”
- “Certified compliant.”
- “No legal risk.”
- “The whole workspace is compliant” based on an average.
- “N/A” without the decision basis.
- “AI confirmed compliance.”
Export quality checklist
Section titled “Export quality checklist”- Correct named system and entity.
- Methodology and legal snapshot visible.
- Current, future and proposed states separated.
- Article 5 visible.
- Classification rationale visible.
- Roles and value chain visible.
- Atomic population and coverage shown.
- Evidence, tests and adverse findings reconciled.
- N/A approvals included.
- Human owner, confidence, residual risk and review present.
- No cross-system leakage.
- No certification or legal-advice claim.