How AnnexWise derives its verdicts

Every classification is produced by a deterministic rules engine that encodes Regulation (EU) 2024/1689 article by article. No language model sits between your answers and your verdict: the same answers always produce the same result, and every rule below is traceable to the article it implements.

Rule set v1.1.0Legal state as of 2026-07-31

Classification order

  1. Article 5 screen. Any selected prohibited practice classifies the system as prohibited — nothing else is evaluated for tiering, and the €35M / 7% fine tier applies.
  2. Article 6(1): regulated-product safety components are high-risk. The Article 6(3) derogation does not apply to them.
  3. Article 6(2) + Annex III. A match with any Annex III category is high-risk, unless the Article 6(3) derogation is claimed — in which case the system is classified out of high-risk and a counsel-review flag is attached, because that derogation is a documented-judgement call, not a checkbox.
  4. Article 50 transparency triggers attach duties regardless of tier; with no high-risk match they classify the system as limited risk.
  5. GPAI (Articles 53/55) duties attach orthogonally when you provide a general-purpose model; systemic-risk scale adds the Article 55 regime.
  6. Anything else is minimal risk (Article 4 AI literacy still applies).

Rule inventory

Prohibited practices — Article 5(1)

High-risk categories — Annex III

Transparency triggers — Article 50

Provider obligations for high-risk systems (Chapter III)

ArticleObligationSeverity weighting
Art. 9Risk management systemcritical
Art. 10Data and data governancecritical
Art. 11 + Annex IVTechnical documentationcritical
Art. 12Record-keeping (automatic logs)high
Art. 13Transparency and instructions for deployershigh
Art. 14Human oversight by designcritical
Art. 15Accuracy, robustness and cybersecurityhigh
Art. 17Quality management systemhigh
Art. 43 + 48Conformity assessment and CE markingcritical
Art. 49EU database registrationhigh
Art. 72Post-market monitoringmedium
Art. 73Serious incident reportingmedium

Deployer obligations for high-risk systems (Art. 26–27)

ArticleObligationSeverity weighting
Art. 26(1)Operate per provider instructionshigh
Art. 26(2)Assign trained human oversightcritical
Art. 26(4)Input data controlhigh
Art. 26(5)Monitor and suspend on riskhigh
Art. 26(6)Retain logs (minimum 6 months)medium
Art. 26(7)Inform affected workersmedium
Art. 27Fundamental rights impact assessmenthigh

Transparency obligations (Art. 50)

ArticleObligationSeverity weighting
Art. 50(1)Disclose AI interactionhigh
Art. 50(2)Machine-readable content markinghigh
Art. 50(4)Label deepfakeshigh
Art. 50(3)Disclose emotion recognition / biometric categorisationmedium

GPAI provider obligations (Art. 53 / 55)

ArticleObligationSeverity weighting
Art. 53(1)(a-b)GPAI technical documentationhigh
Art. 53(1)(c)Copyright policymedium
Art. 53(1)(d)Training-content summarymedium
Art. 55Systemic-risk model dutiescritical

Scoring

The compliance score is the weight of satisfied obligations divided by the weight of all applicable obligations, on a 0–100 scale. Weights reflect severity: critical items (e.g. conformity assessment, technical documentation, human oversight) weigh roughly twice as much as procedural ones. A prohibited classification scores 0 by definition.

Verification & change control

AnnexWise is compliance software, not a law firm. This page documents how the software reasons so that your counsel can audit it; it does not replace their judgement.