Skip to main content

How AnnexWise derives its verdicts

Every classification is produced by a deterministic rules engine that encodes Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), article by article. No language model sits between your answers and your verdict: the same answers always produce the same result, and every rule below is traceable to the article it implements.

Rule set v1.6.1Legal state as of 2026-08-05

Classification order

  1. Article 5 screen. Any selected prohibited practice classifies the system as prohibited — nothing else is evaluated for tiering, and the €35M / 7% fine tier applies.
  2. Article 6(1): regulated-product safety components are high-risk only where both limbs are met — the system is a safety component of (or is itself) a product covered by the Annex I harmonisation legislation, and that product is required to undergo third-party conformity assessment. A self-assessed product (a Class I medical device, most toys, machinery outside Annex IV of the Machinery Regulation) does not take this route. The Article 6(3) derogation does not apply to systems that do.
  3. Article 6(2) + Annex III. A match with any Annex III category is high-risk, unless the Article 6(3) derogation is claimed — in which case the system is classified out of high-risk and a counsel-review flag is attached, because that derogation is a documented-judgment call, not a checkbox.
  4. Article 50 transparency triggers attach duties regardless of high-risk status; with no high-risk match they classify the system as limited risk. One deliberate exception: for prohibited systems, tiering stops and no Article 50 obligations are listed — deployment must stop, so there is nothing left to make transparent.
  5. GPAI (Articles 53/55) duties attach orthogonally when you provide a general-purpose model; systemic-risk scale adds the Article 55 regime.
  6. Anything else is minimal risk (Article 4 AI literacy still applies).

Rule inventory

Prohibited practices — Article 5(1)

High-risk categories — Annex III

Transparency triggers — Article 50

Provider obligations for high-risk systems (Chapter III)

ArticleObligationSeverity weighting
Art. 9Risk management systemcritical
Art. 10Data and data governancecritical
Art. 11 + Annex IVTechnical documentationcritical
Art. 12Record-keeping (automatic logs)high
Art. 13Transparency and instructions for deployershigh
Art. 14Human oversight by designcritical
Art. 15Accuracy, robustness and cybersecurityhigh
Art. 17Quality management systemhigh
Art. 43, 47 + 48Conformity assessment, declaration and CE markingcritical
Art. 49EU database registrationhigh
Art. 72Post-market monitoringmedium
Art. 73Serious incident reportingmedium

Deployer obligations for high-risk systems (Art. 26–27)

ArticleObligationSeverity weighting
Art. 26(1)Operate per provider instructionshigh
Art. 26(2)Assign trained human oversightcritical
Art. 26(4)Input data controlhigh
Art. 26(5)Monitor and suspend on riskhigh
Art. 26(6)Retain logs (minimum 6 months)medium
Art. 26(7)Inform affected workersmedium
Art. 26(11) + 86Inform affected persons; explain on requestmedium

Transparency obligations (Art. 50)

ArticleObligationSeverity weighting
Art. 50(4)Label deepfakeshigh
Art. 50(3)Disclose emotion recognition / biometric categorisationmedium

GPAI provider obligations (Art. 53 / 55)

ArticleObligationSeverity weighting
Art. 53(1)(a-b)GPAI technical documentationhigh
Art. 53(1)(c)Copyright policymedium
Art. 53(1)(d)Training-content summarymedium
Art. 55Systemic-risk model dutiescritical

Scoring

The compliance score is the weight of satisfied obligations divided by the weight of all applicable obligations, on a 0–100 scale. Weights reflect severity: critical items (e.g. conformity assessment, technical documentation, human oversight) weigh roughly twice as much as procedural ones. A prohibited classification scores 0 by definition.

Verification & change control

Application timeline the engine applies

Deadlines quoted in verdicts and reports follow the timeline as amended by Regulation (EU) 2026/1744 (in force 27 July 2026), which postponed the high-risk regime and added a new Article 5 prohibition. These are fixed calendar dates — the proposed standards-availability trigger was dropped by the co-legislators.

Applies fromProvisionsSet by
2025-02-02Article 5 prohibitions. Manipulative techniques, social scoring, untargeted facial-image scraping, emotion recognition at work and school, and the other banned practices — prohibited since 2 February 2025.Regulation (EU) 2024/1689
2025-08-02GPAI model duties. Articles 53/55 duties for general-purpose AI model providers and the governance structure around the AI Office — applicable since 2 August 2025.Regulation (EU) 2024/1689
2026-08-02Article 50 transparency + enforcement powers. Article 50 transparency duties (chatbot disclosure, deepfake and synthetic-content labelling), Commission penalty powers over GPAI providers, and national enforcement of everything already applicable — live since 2 August 2026. The Omnibus kept this application date (it amended the Art. 50(2) marking text — see the December 2026 entry).Regulation (EU) 2024/1689
2026-12-02New prohibition: non-consensual intimate imagery. The Omnibus adds an Article 5 prohibition on AI systems that generate or manipulate non-consensual intimate imagery of identifiable persons (“nudifiers”) and CSAM — reaching systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards. Applies from 2 December 2026. The same date ends the content-marking grace period for systems already on the market before 2 August 2026 (systems entering the market after that date must mark from day one).Regulation (EU) 2026/1744
2027-12-02Annex III high-risk obligations. The full high-risk regime for stand-alone Annex III systems — risk management, data governance, Annex IV technical documentation, logging, human oversight, conformity assessment, registration, Article 26 deployer duties — applies from 2 December 2027 (postponed from 2 August 2026 by the Omnibus).Regulation (EU) 2026/1744
2028-08-02Annex I embedded high-risk systems. High-risk obligations for AI that is a safety component of Annex I regulated products (medical devices, machinery, vehicles…) apply from 2 August 2028 (postponed by the Omnibus).Regulation (EU) 2026/1744

Rule-set changelog

Every change in the law that this engine incorporates is recorded here, permanently and publicly, with the rule-set version that shipped it. If the law moves and this log has not, that is a bug — tell us: support@annexwise.com.

2026-08-15rule set v1.6.1

Second pass on the same audit. Annex III point 2 (critical infrastructure) is expressly carved out of the Article 27 fundamental-rights impact assessment, and the engine no longer lists one where critical infrastructure is the only Annex III route; a counsel flag sets out the parallel differences in Article 49(1) registration and the Article 86(1) right to an explanation. The conformity obligation now cites Article 47 for the EU declaration of conformity, which sat between the Article 43 procedure and the Article 48 marking uncited. The published methodology page carried the pre-1.6.0 single-limb statement of Article 6(1) and now states the conjunctive test. Milestone status is computed against the Brussels offset actually in force on each date rather than a fixed +01:00, which had flipped the three August milestones an hour early. The Article 99(6) lower-of cap is no longer applied to the Article 5 tier in the exposure calculator, matching what our own fines guide says about that contested point.

Source: Regulation (EU) 2024/1689 arts. 6(1), 27(1), 43, 47, 48, 49(1), 86(1), 99(6)

2026-08-15rule set v1.6.0

Classification-scope corrections from a 15-agent adversarial audit. Article 6(1) is now applied as the conjunctive test it is: a safety component of an Annex I product is high-risk only where that product ALSO requires third-party conformity assessment — a new screening question, since self-assessed products (Class I medical devices, most toys, machinery outside Annex IV of the Machinery Regulation) were previously classified high-risk in error. Articles 27, 49 and 26(11), which the Regulation scopes to the Annex III systems of Article 6(2), are no longer emitted for systems that reach high-risk solely through the Annex I route. Article 50 duties are now attributed to their actual duty-holder — 50(1) and 50(2) to the provider, 50(3) and 50(4) to the deployer — instead of to every role. Article 50 transparency duties are no longer suppressed by a prohibited verdict, since Article 5 and Article 50 are independent. Assessments saved before this version re-derive to the same verdict: the new answer is canonicalised to yes, the reading that reproduces the classification they were originally given.

Source: Regulation (EU) 2024/1689 arts. 5, 6(1), 6(2), 26(11), 27, 49, 50; Regulation (EU) 2026/1744

2026-08-05rule set v1.5.0

Duty-holder precision in the deployer stack, following an independent legal audit: the Article 27 FRIA now attaches only to actual duty-holders (public bodies, public-service providers, and Annex III 5(b)/(c) credit-scoring or life/health-insurance deployers — new screening question; the essential-services category forces it on its own) instead of every high-risk deployer; Art. 26(7) worker notification now attaches on workplace context rather than universally; Art. 26(11) + Art. 86 (inform affected persons; explanation on request) added to the deployer catalogue — the guides promised this duty, the verdicts now deliver it; NCII-only prohibited verdicts state that the €35M/7% exposure attaches from 2 December 2026; reports now compute 'binding now' against the assessment date rather than the last review date.

Source: Articles 26(7), 26(11), 27, 86, 99, Regulation (EU) 2024/1689; Regulation (EU) 2026/1744

2026-08-03rule set v1.4.1

Precision pass following a four-agent adversarial audit of every legal claim: NCII prohibition scope now carries the statutory safeguards qualifier (reasonably foreseeable AND reproducible absent effective safeguards); content-marking timing split corrected (grace to 2 Dec 2026 only for systems on the market before 2 Aug 2026 — new systems mark from day one); Article 27 FRIA duty-holders corrected to deployers incl. credit-scoring and life/health-insurance deployers; dual-route high-risk systems (Annex I + Annex III) now bind from the earlier Annex III date; Article 5 entries carry their statutory exceptions; Art. 99(6) lower-of cap noted as extended to small mid-caps by the Omnibus and as not covering Commission GPAI fines under Art. 101; Art. 50(4) text exemption stated with both required limbs (human review AND editorial responsibility).

Source: Regulation (EU) 2024/1689 arts. 5, 27, 50, 99, 111; Regulation (EU) 2026/1744; Commission Code of Practice on Transparency of AI-Generated Content (10 June 2026)

2026-08-03rule set v1.4.0

Article 111 temporal status added to screening: high-risk assessments now ask whether the system was placed on the market before 2 August 2026 — the grandfathering cutoff the Omnibus deliberately left unmoved. Legacy systems receive a counsel flag covering the significant-change trap, the public-authority 2030 deadline, and the absence of grandfathering for systems launched between August 2026 and December 2027.

Source: Article 111, Regulation (EU) 2024/1689 (the 2 August 2026 cutoff preserved by Regulation (EU) 2026/1744, which added clarifications to the legacy-system regime)

2026-08-03rule set v1.3.0

Temporal validity layer: every obligation in a verdict is now stamped with the date its norm applies from (Article 50 and GPAI duties binding now; Chapter III / Article 26–27 from 2 December 2027 or 2 August 2028 by annex route), reports label each obligation 'binding now' vs. its future date, and the NCII prohibition carries an explicit not-yet-in-force counsel flag. No change to the underlying legal facts.

Source: Same instruments as v1.2.0; product change following external review

2026-08-02rule set v1.2.0

Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) incorporated: Annex III high-risk application postponed to 2 December 2027 and Annex I to 2 August 2028 as fixed dates; new Article 5 prohibition on non-consensual intimate imagery and revised content-marking provisions from 2 December 2026; Article 50 transparency duties, GPAI duties and the enforcement powers starting 2 August 2026 unchanged. Every verdict text, deadline and guide on this site was re-reviewed against the amended timeline.

Source: Regulation (EU) 2026/1744, OJ; European Commission announcement, 27 July 2026

2026-07-31rule set v1.1.0

Initial public rule set: Articles 5, 6, 26, 50, 53/55 and Annex III classification logic under Regulation (EU) 2024/1689 as adopted.

Source: Regulation (EU) 2024/1689, OJ L series, 12 July 2024

AnnexWise is compliance software, not a law firm. This page documents how the software reasons so that your counsel can audit it; it does not replace their judgment.