A complete sample dossier, nothing hidden

Compliance tools love screenshots of dashboards and hate showing the actual deliverable. Here is ours, in full: a fictional German recruiter running a CV-ranking system (Annex III, employment) with an applicant-facing chatbot (Article 50). Every word below was generated by the same deterministic engine that runs real assessments — verdict, per-obligation binding dates under the 2026 Omnibus timeline, counsel flags, remediation plan.

Verdict: High-risk (Annex III) + Article 50 dutiesRule set v1.4.1 · legal state 2026-08-02

Compliance gap report

Free tier — every user gets this. Note the per-obligation binding dates: Article 50 duties are marked binding now; the Chapter III stack carries its 2 December 2027 date.

# EU AI Act Compliance Gap Report
## Nordwind Recruiting GmbH (fictional) — CandidateRank

> Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment.

**Date:** 2026-08-03
**Role under the Act:** both
**Risk classification:** High-risk system
**Compliance score:** 9/100
**Key deadline:** 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus); Article 50 transparency duties apply already
**Maximum fine exposure:** €15,000,000 or 3% of global annual turnover

**Audit trail:** rule set v1.4.1 · legal state as of 2026-08-02 · generated 2026-08-03 · assessment fingerprint `22ad9520474969bc`

Your system falls under Annex III or is a regulated product safety component. The full high-risk obligation set applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) — postponed by the 2026 Omnibus. Any Article 50 transparency duties apply already, and the runway is what makes conformity achievable in-house.

## ⚑ Counsel review flags (1)

The following points sit in genuinely gray areas of the Act. The classification above assumes your answers; these positions should be confirmed by qualified counsel in writing:

- **Provider/deployer boundary (Art. 25)** — You act as both provider and deployer. Note that a deployer who substantially modifies a high-risk system, rebrands it, or repurposes a system into high-risk use becomes its provider under Art. 25 and inherits the full provider obligation set. Map which entity holds which role per system with counsel.

---

## Applicable obligations (22)

| Status | Article | Obligation | Severity | Applies from |
|---|---|---|---|---|
| ✅ Done | Art. 4 | AI literacy | medium | binding now |
| ✅ Done | Best practice | AI system inventory | medium | good practice |
| ❌ Open | Art. 9 | Risk management system | critical | 2027-12-02 |
| ❌ Open | Art. 10 | Data and data governance | critical | 2027-12-02 |
| ❌ Open | Art. 11 + Annex IV | Technical documentation | critical | 2027-12-02 |
| ❌ Open | Art. 12 | Record-keeping (automatic logs) | high | 2027-12-02 |
| ❌ Open | Art. 13 | Transparency and instructions for deployers | high | 2027-12-02 |
| ❌ Open | Art. 14 | Human oversight by design | critical | 2027-12-02 |
| ❌ Open | Art. 15 | Accuracy, robustness and cybersecurity | high | 2027-12-02 |
| ❌ Open | Art. 17 | Quality management system | high | 2027-12-02 |
| ❌ Open | Art. 43 + 48 | Conformity assessment and CE marking | critical | 2027-12-02 |
| ❌ Open | Art. 49 | EU database registration | high | 2027-12-02 |
| ❌ Open | Art. 72 | Post-market monitoring | medium | 2027-12-02 |
| ❌ Open | Art. 73 | Serious incident reporting | medium | 2027-12-02 |
| ❌ Open | Art. 26(1) | Operate per provider instructions | high | 2027-12-02 |
| ❌ Open | Art. 26(2) | Assign trained human oversight | critical | 2027-12-02 |
| ❌ Open | Art. 26(4) | Input data control | high | 2027-12-02 |
| ❌ Open | Art. 26(5) | Monitor and suspend on risk | high | 2027-12-02 |
| ❌ Open | Art. 26(6) | Retain logs (minimum 6 months) | medium | 2027-12-02 |
| ❌ Open | Art. 26(7) | Inform affected workers | medium | 2027-12-02 |
| ❌ Open | Art. 27 | Fundamental rights impact assessment | high | 2027-12-02 |
| ✅ Done | Art. 50(1) | Disclose AI interaction | high | binding now |

---

## 30-day remediation plan

### Week 1
- [ ] **Art. 9 — Risk management system** (~5 working days, severity: critical)
      Establish, document and maintain a continuous, iterative risk management process across the system lifecycle.
- [ ] **Art. 11 + Annex IV — Technical documentation** (~4 working days, severity: critical)
      Maintain complete Annex IV technical documentation before placing on the market, kept up to date.
- [ ] **Art. 26(1) — Operate per provider instructions** (~2 working days, severity: high)
      Assign technical and organisational measures to use the system strictly according to its instructions for use.
- [ ] **Art. 26(2) — Assign trained human oversight** (~2 working days, severity: critical)
      Name specific, competent, trained people with authority to oversee the system and overrule or halt it.

### Week 2
- [ ] **Art. 10 — Data and data governance** (~6 working days, severity: critical)
      Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation.
- [ ] **Art. 12 — Record-keeping (automatic logs)** (~3 working days, severity: high)
      The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime.
- [ ] **Art. 13 — Transparency and instructions for deployers** (~3 working days, severity: high)
      Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance.
- [ ] **Art. 14 — Human oversight by design** (~4 working days, severity: critical)
      Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system.
- [ ] **Art. 26(4) — Input data control** (~3 working days, severity: high)
      Ensure input data under your control is relevant and sufficiently representative for the intended purpose.
- [ ] **Art. 26(5) — Monitor and suspend on risk** (~2 working days, severity: high)
      Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk.
- [ ] **Art. 26(6) — Retain logs (minimum 6 months)** (~1 working days, severity: medium)
      Keep automatically generated logs under your control for at least six months.

### Week 3
- [ ] **Art. 15 — Accuracy, robustness and cybersecurity** (~6 working days, severity: high)
      Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks.
- [ ] **Art. 17 — Quality management system** (~6 working days, severity: high)
      Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring.
- [ ] **Art. 26(7) — Inform affected workers** (~1 working days, severity: medium)
      Before using workplace AI, inform workers' representatives and affected workers that they are subject to it.
- [ ] **Art. 27 — Fundamental rights impact assessment** (~3 working days, severity: high)
      Deployers that are public bodies or private entities providing public services, and deployers of credit-scoring or life/health-insurance risk-pricing systems (Annex III 5(b)/(c)), must complete a FRIA before first use.

### Week 4
- [ ] **Art. 43 + 48 — Conformity assessment and CE marking** (~5 working days, severity: critical)
      Run the applicable conformity assessment procedure, draw up the EU declaration of conformity, and affix CE marking.
- [ ] **Art. 49 — EU database registration** (~1 working days, severity: high)
      Register the high-risk system in the EU public database before placing it on the market.
- [ ] **Art. 72 — Post-market monitoring** (~2 working days, severity: medium)
      Documented plan to actively collect and analyse performance data throughout the system lifetime.
- [ ] **Art. 73 — Serious incident reporting** (~1 working days, severity: medium)
      Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases).

---

*Total estimated effort: 60 working days.
Prioritise critical items in weeks 1–2; conformity assessment and registration close the plan.*

Counsel pack cover letter

Free tier — the page a law firm reads first: verdict, temporal status, and the gray-area questions the engine refuses to decide on its own.

# Cover letter for counsel review
### Nordwind Recruiting GmbH (fictional) — CandidateRank

> Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment.

**Date:** 2026-08-03

**Audit trail:** rule set v1.4.1 · legal state as of 2026-08-02 · generated 2026-08-03 · assessment fingerprint `22ad9520474969bc`

Dear counsel,

We have run a structured EU AI Act classification of the system below using
a deterministic, versioned rule set (methodology and full rule inventory:
annexwise.com/methodology). This letter summarises the verdict, its temporal
status under the timeline as amended by Regulation (EU) 2026/1744, and the
specific points on which we ask for your written confirmation. The engine
resolves nothing it should not: every genuinely gray call below is flagged
for you, not decided for us.

## The verdict to confirm

- **System:** CandidateRank — Scores and ranks incoming job applications for shortlisting, using a gradient-boosted model over CV features; also runs a customer-facing chatbot for applicant questions.
- **Role under the Act:** both
- **Classification:** High-risk system
- **Temporal status:** 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus); Article 50 transparency duties apply already
- **Obligations binding now:** 2 (Art. 4, Art. 50(1))
- **Obligations binding later:** 19 (Art. 9 from 2027-12-02, Art. 10 from 2027-12-02, Art. 11 + Annex IV from 2027-12-02, Art. 12 from 2027-12-02, Art. 13 from 2027-12-02, Art. 14 from 2027-12-02, Art. 15 from 2027-12-02, Art. 17 from 2027-12-02, Art. 43 + 48 from 2027-12-02, Art. 49 from 2027-12-02, Art. 72 from 2027-12-02, Art. 73 from 2027-12-02, Art. 26(1) from 2027-12-02, Art. 26(2) from 2027-12-02, Art. 26(4) from 2027-12-02, Art. 26(5) from 2027-12-02, Art. 26(6) from 2027-12-02, Art. 26(7) from 2027-12-02, Art. 27 from 2027-12-02)
- **Maximum fine tier if breached:** €15,000,000 or 3% of global annual turnover

## Questions requiring your judgement (1)

1. **Provider/deployer boundary (Art. 25)** — You act as both provider and deployer. Note that a deployer who substantially modifies a high-risk system, rebrands it, or repurposes a system into high-risk use becomes its provider under Art. 25 and inherits the full provider obligation set. Map which entity holds which role per system with counsel.

## Enclosures

1. Compliance gap report (verdict, obligation table with per-obligation
   binding dates, 30-day remediation plan)
2. Annex IV technical documentation draft (structure per Article 11;
   engineering facts to be completed by the client)

## What we ask for

- Written confirmation or correction of the classification above
- A position on each flagged question
- Any qualifications to record permanently in the compliance file

The assessment is reproducible: the fingerprint above, together with the
rule-set version, re-derives this exact verdict from the same answers.

Kind regards,
Nordwind Recruiting GmbH (fictional)

Annex IV technical documentation (draft)

Paid tiers — the Article 11 structure pre-filled from the assessment. Engineering facts (architecture, training data, metrics) are completed by your team: the tool structures the file, it does not invent evidence.

# Technical Documentation — CandidateRank
### Prepared under Article 11 and Annex IV, Regulation (EU) 2024/1689 (AI Act)

> Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment.

**Organisation:** Nordwind Recruiting GmbH (fictional)
**Role under the Act:** both
**Risk classification:** High-risk system
**Date:** 2026-08-03

**Audit trail:** rule set v1.4.1 · legal state as of 2026-08-02 · generated 2026-08-03 · assessment fingerprint `22ad9520474969bc`

---

## 1. General description of the AI system
- **Intended purpose:** Scores and ranks incoming job applications for shortlisting, using a gradient-boosted model over CV features; also runs a customer-facing chatbot for applicant questions.
- **Provider name:** Nordwind Recruiting GmbH (fictional)
- **Versions and how they relate:** _[version history and substantial modifications]_
- **Hardware on which the system runs:** _[describe]_
- **Forms in which the system is placed on the market:** _[SaaS / API / embedded / on-prem]_
- **Instructions for use for the deployer:** _[attach or reference]_

## 2. Detailed description of elements and development process
- **Development methods, including third-party tools and pre-trained models:** _[describe]_
- **Design specifications and key architecture choices:** _[describe]_
- **What the system is designed to optimise for; relevance of parameters:** _[describe]_
- **Description of the expected output and output quality:** _[describe]_
- **Human oversight measures built into the design (Art. 14):** _[describe]_
- **Predetermined changes and continuous-learning strategy:** _[describe]_
- **Validation and testing procedures, metrics and results:** _[accuracy, robustness, bias]_
- **Cybersecurity measures (Art. 15):** _[describe]_

## 3. Monitoring, functioning and control
- **Capabilities and limitations of the system:** _[expected accuracy for intended purpose]_
- **Foreseeable unintended outcomes and sources of risk:** _[health, safety, fundamental rights]_
- **Human oversight measures for deployers:** _[technical measures that facilitate interpretation]_
- **Input data specifications:** _[training/validation/test data requirements]_

## 4. Appropriateness of performance metrics
_[Why the chosen accuracy/robustness metrics are appropriate for this system.]_

## 5. Risk management system (Art. 9)
_[Summary of the documented, iterative risk management process: identified risks,
mitigations, residual-risk judgements, testing conclusions.]_

## 6. Lifecycle changes
_[Description of relevant changes made through the lifecycle.]_

## 7. Harmonised standards applied
_[List applied harmonised standards or, where none, detailed description of the
solutions adopted to meet Chapter III, Section 2 requirements.]_

## 8. EU declaration of conformity
_[Copy of the declaration of conformity per Article 47.]_

## 9. Post-market monitoring plan (Art. 72)
_[Description of the system to evaluate performance in the post-market phase.]_

---

### Open compliance gaps recorded at assessment time
- **Art. 9 — Risk management system:** Establish, document and maintain a continuous, iterative risk management process across the system lifecycle.
- **Art. 10 — Data and data governance:** Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation.
- **Art. 11 + Annex IV — Technical documentation:** Maintain complete Annex IV technical documentation before placing on the market, kept up to date.
- **Art. 12 — Record-keeping (automatic logs):** The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime.
- **Art. 13 — Transparency and instructions for deployers:** Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance.
- **Art. 14 — Human oversight by design:** Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system.
- **Art. 15 — Accuracy, robustness and cybersecurity:** Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks.
- **Art. 17 — Quality management system:** Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring.
- **Art. 43 + 48 — Conformity assessment and CE marking:** Run the applicable conformity assessment procedure, draw up the EU declaration of conformity, and affix CE marking.
- **Art. 49 — EU database registration:** Register the high-risk system in the EU public database before placing it on the market.
- **Art. 72 — Post-market monitoring:** Documented plan to actively collect and analyse performance data throughout the system lifetime.
- **Art. 73 — Serious incident reporting:** Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases).
- **Art. 26(1) — Operate per provider instructions:** Assign technical and organisational measures to use the system strictly according to its instructions for use.
- **Art. 26(2) — Assign trained human oversight:** Name specific, competent, trained people with authority to oversee the system and overrule or halt it.
- **Art. 26(4) — Input data control:** Ensure input data under your control is relevant and sufficiently representative for the intended purpose.
- **Art. 26(5) — Monitor and suspend on risk:** Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk.
- **Art. 26(6) — Retain logs (minimum 6 months):** Keep automatically generated logs under your control for at least six months.
- **Art. 26(7) — Inform affected workers:** Before using workplace AI, inform workers' representatives and affected workers that they are subject to it.
- **Art. 27 — Fundamental rights impact assessment:** Deployers that are public bodies or private entities providing public services, and deployers of credit-scoring or life/health-insurance risk-pricing systems (Annex III 5(b)/(c)), must complete a FRIA before first use.

This took the fictional Nordwind team about 10 minutes to produce.

The classification, gap report and counsel letter are free — no signup, and your answers never leave your browser.

Run the assessment on your own system →