A complete sample dossier, nothing hidden
Compliance tools love screenshots of dashboards and hate showing the actual deliverable. Here is ours, in full: a fictional German recruiter running a CV-ranking system (Annex III, employment) with an applicant-facing chatbot (Article 50). Every word below was generated by the same deterministic engine that runs real assessments — verdict, per-obligation binding dates under the 2026 Omnibus timeline, counsel flags, remediation plan.
Compliance gap report
Free tier — every user gets this. Note the per-obligation binding dates: Article 50 duties are marked binding now; the Chapter III stack carries its 2 December 2027 date.
# EU AI Act Compliance Gap Report
## Nordwind Recruiting GmbH (fictional) — CandidateRank
> Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment.
**Date:** 2026-09-17
**Role under the Act:** both
**Risk classification:** High-risk system
**Compliance score:** 9/100
**Key deadline:** 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus); Article 50 transparency duties apply already
**Maximum fine exposure:** €15,000,000 or 3% of global annual turnover
**Audit trail:** rule set v1.6.1 · legal state as of 2026-08-05 · generated 2026-09-17 · assessment fingerprint `7ed710a6ba605646`
Your system falls under Annex III or is a regulated product safety component. The full high-risk obligation set applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) — postponed by the 2026 Omnibus. Any Article 50 transparency duties apply already, and the runway is what makes conformity achievable in-house.
## ⚑ Counsel review flags (1)
The following points sit in genuinely gray areas of the Act. The classification above assumes your answers; these positions should be confirmed by qualified counsel in writing:
- **Provider/deployer boundary (Art. 25)** — You act as both provider and deployer. Note that a deployer who substantially modifies a high-risk system, rebrands it, or repurposes a system into high-risk use becomes its provider under Art. 25 and inherits the full provider obligation set. Map which entity holds which role per system with counsel.
---
## Applicable obligations (22)
| Status | Article | Obligation | Severity | Applies from |
|---|---|---|---|---|
| ✅ Done | Art. 4 | AI literacy | medium | binding now |
| ✅ Done | Best practice | AI system inventory | medium | good practice |
| ❌ Open | Art. 9 | Risk management system | critical | 2027-12-02 |
| ❌ Open | Art. 10 | Data and data governance | critical | 2027-12-02 |
| ❌ Open | Art. 11 + Annex IV | Technical documentation | critical | 2027-12-02 |
| ❌ Open | Art. 12 | Record-keeping (automatic logs) | high | 2027-12-02 |
| ❌ Open | Art. 13 | Transparency and instructions for deployers | high | 2027-12-02 |
| ❌ Open | Art. 14 | Human oversight by design | critical | 2027-12-02 |
| ❌ Open | Art. 15 | Accuracy, robustness and cybersecurity | high | 2027-12-02 |
| ❌ Open | Art. 17 | Quality management system | high | 2027-12-02 |
| ❌ Open | Art. 43, 47 + 48 | Conformity assessment, declaration and CE marking | critical | 2027-12-02 |
| ❌ Open | Art. 49 | EU database registration | high | 2027-12-02 |
| ❌ Open | Art. 72 | Post-market monitoring | medium | 2027-12-02 |
| ❌ Open | Art. 73 | Serious incident reporting | medium | 2027-12-02 |
| ❌ Open | Art. 26(1) | Operate per provider instructions | high | 2027-12-02 |
| ❌ Open | Art. 26(2) | Assign trained human oversight | critical | 2027-12-02 |
| ❌ Open | Art. 26(4) | Input data control | high | 2027-12-02 |
| ❌ Open | Art. 26(5) | Monitor and suspend on risk | high | 2027-12-02 |
| ❌ Open | Art. 26(6) | Retain logs (minimum 6 months) | medium | 2027-12-02 |
| ❌ Open | Art. 26(7) | Inform affected workers | medium | 2027-12-02 |
| ❌ Open | Art. 26(11) + 86 | Inform affected persons; explain on request | medium | 2027-12-02 |
| ✅ Done | Art. 50(1) | Disclose AI interaction | high | binding now |
---
## 30-day remediation plan
### Week 1
- [ ] **Art. 9 — Risk management system** (~5 working days, severity: critical)
Establish, document and maintain a continuous, iterative risk management process across the system lifecycle.
- [ ] **Art. 11 + Annex IV — Technical documentation** (~4 working days, severity: critical)
Maintain complete Annex IV technical documentation before placing on the market, kept up to date.
- [ ] **Art. 26(1) — Operate per provider instructions** (~2 working days, severity: high)
Assign technical and organisational measures to use the system strictly according to its instructions for use.
- [ ] **Art. 26(2) — Assign trained human oversight** (~2 working days, severity: critical)
Name specific, competent, trained people with authority to oversee the system and overrule or halt it.
### Week 2
- [ ] **Art. 10 — Data and data governance** (~6 working days, severity: critical)
Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation.
- [ ] **Art. 12 — Record-keeping (automatic logs)** (~3 working days, severity: high)
The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime.
- [ ] **Art. 13 — Transparency and instructions for deployers** (~3 working days, severity: high)
Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance.
- [ ] **Art. 14 — Human oversight by design** (~4 working days, severity: critical)
Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system.
- [ ] **Art. 26(4) — Input data control** (~3 working days, severity: high)
Ensure input data under your control is relevant and sufficiently representative for the intended purpose.
- [ ] **Art. 26(5) — Monitor and suspend on risk** (~2 working days, severity: high)
Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk.
- [ ] **Art. 26(6) — Retain logs (minimum 6 months)** (~1 working days, severity: medium)
Keep automatically generated logs under your control for at least six months.
### Week 3
- [ ] **Art. 15 — Accuracy, robustness and cybersecurity** (~6 working days, severity: high)
Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks.
- [ ] **Art. 17 — Quality management system** (~6 working days, severity: high)
Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring.
- [ ] **Art. 26(7) — Inform affected workers** (~1 working days, severity: medium)
Before using workplace AI, inform workers' representatives and affected workers that they are subject to it.
- [ ] **Art. 26(11) + 86 — Inform affected persons; explain on request** (~1 working days, severity: medium)
Tell natural persons subject to decisions made or materially informed by an Annex III system that it is in use, and be ready to give the Article 86 explanation of the role the system played in a decision.
### Week 4
- [ ] **Art. 43, 47 + 48 — Conformity assessment, declaration and CE marking** (~5 working days, severity: critical)
Run the applicable conformity assessment procedure (Art. 43), draw up and sign the EU declaration of conformity (Art. 47) and keep it for ten years, then affix CE marking (Art. 48).
- [ ] **Art. 49 — EU database registration** (~1 working days, severity: high)
Register the high-risk system in the EU public database before placing it on the market.
- [ ] **Art. 72 — Post-market monitoring** (~2 working days, severity: medium)
Documented plan to actively collect and analyse performance data throughout the system lifetime.
- [ ] **Art. 73 — Serious incident reporting** (~1 working days, severity: medium)
Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases).
---
*Total estimated effort: 58 working days.
Prioritise critical items in weeks 1–2; conformity assessment and registration close the plan.*
Counsel pack cover letter
Free tier — the page a law firm reads first: verdict, temporal status, and the gray-area questions the engine refuses to decide on its own.
# Cover letter for counsel review ### Nordwind Recruiting GmbH (fictional) — CandidateRank > Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment. **Date:** 2026-09-17 **Audit trail:** rule set v1.6.1 · legal state as of 2026-08-05 · generated 2026-09-17 · assessment fingerprint `7ed710a6ba605646` Dear counsel, We have run a structured EU AI Act classification of the system below using a deterministic, versioned rule set (methodology and full rule inventory: annexwise.com/methodology). This letter summarises the verdict, its temporal status under the timeline as amended by Regulation (EU) 2026/1744, and the specific points on which we ask for your written confirmation. The engine resolves nothing it should not: every genuinely gray call below is flagged for you, not decided for us. ## The verdict to confirm - **System:** CandidateRank — Scores and ranks incoming job applications for shortlisting, using a gradient-boosted model over CV features; also runs a customer-facing chatbot for applicant questions. - **Role under the Act:** both - **Classification:** High-risk system - **Temporal status:** 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus); Article 50 transparency duties apply already - **Obligations binding now:** 2 (Art. 4, Art. 50(1)) - **Obligations binding later:** 19 (Art. 9 from 2027-12-02, Art. 10 from 2027-12-02, Art. 11 + Annex IV from 2027-12-02, Art. 12 from 2027-12-02, Art. 13 from 2027-12-02, Art. 14 from 2027-12-02, Art. 15 from 2027-12-02, Art. 17 from 2027-12-02, Art. 43, 47 + 48 from 2027-12-02, Art. 49 from 2027-12-02, Art. 72 from 2027-12-02, Art. 73 from 2027-12-02, Art. 26(1) from 2027-12-02, Art. 26(2) from 2027-12-02, Art. 26(4) from 2027-12-02, Art. 26(5) from 2027-12-02, Art. 26(6) from 2027-12-02, Art. 26(7) from 2027-12-02, Art. 26(11) + 86 from 2027-12-02) - **Maximum fine tier if breached:** €15,000,000 or 3% of global annual turnover ## Questions requiring your judgement (1) 1. **Provider/deployer boundary (Art. 25)** — You act as both provider and deployer. Note that a deployer who substantially modifies a high-risk system, rebrands it, or repurposes a system into high-risk use becomes its provider under Art. 25 and inherits the full provider obligation set. Map which entity holds which role per system with counsel. ## Enclosures 1. Compliance gap report (verdict, obligation table with per-obligation binding dates, 30-day remediation plan) 2. Annex IV technical documentation draft (structure per Article 11; engineering facts to be completed by the client) ## What we ask for - Written confirmation or correction of the classification above - A position on each flagged question - Any qualifications to record permanently in the compliance file The assessment is reproducible: the fingerprint above, together with the rule-set version, re-derives this exact verdict from the same answers. Kind regards, Nordwind Recruiting GmbH (fictional)
Annex IV technical documentation (draft)
Paid tiers — the Article 11 structure pre-filled from the assessment. Engineering facts (architecture, training data, metrics) are completed by your team: the tool structures the file, it does not invent evidence.
# Technical Documentation — CandidateRank ### Prepared under Article 11 and Annex IV, Regulation (EU) 2024/1689 (AI Act) > Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment. **Organisation:** Nordwind Recruiting GmbH (fictional) **Role under the Act:** both **Risk classification:** High-risk system **Date:** 2026-09-17 **Audit trail:** rule set v1.6.1 · legal state as of 2026-08-05 · generated 2026-09-17 · assessment fingerprint `7ed710a6ba605646` --- ## 1. General description of the AI system - **Intended purpose:** Scores and ranks incoming job applications for shortlisting, using a gradient-boosted model over CV features; also runs a customer-facing chatbot for applicant questions. - **Provider name:** Nordwind Recruiting GmbH (fictional) - **Versions and how they relate:** _[version history and substantial modifications]_ - **Hardware on which the system runs:** _[describe]_ - **Forms in which the system is placed on the market:** _[SaaS / API / embedded / on-prem]_ - **Instructions for use for the deployer:** _[attach or reference]_ ## 2. Detailed description of elements and development process - **Development methods, including third-party tools and pre-trained models:** _[describe]_ - **Design specifications and key architecture choices:** _[describe]_ - **What the system is designed to optimise for; relevance of parameters:** _[describe]_ - **Description of the expected output and output quality:** _[describe]_ - **Human oversight measures built into the design (Art. 14):** _[describe]_ - **Predetermined changes and continuous-learning strategy:** _[describe]_ - **Validation and testing procedures, metrics and results:** _[accuracy, robustness, bias]_ - **Cybersecurity measures (Art. 15):** _[describe]_ ## 3. Monitoring, functioning and control - **Capabilities and limitations of the system:** _[expected accuracy for intended purpose]_ - **Foreseeable unintended outcomes and sources of risk:** _[health, safety, fundamental rights]_ - **Human oversight measures for deployers:** _[technical measures that facilitate interpretation]_ - **Input data specifications:** _[training/validation/test data requirements]_ ## 4. Appropriateness of performance metrics _[Why the chosen accuracy/robustness metrics are appropriate for this system.]_ ## 5. Risk management system (Art. 9) _[Summary of the documented, iterative risk management process: identified risks, mitigations, residual-risk judgements, testing conclusions.]_ ## 6. Lifecycle changes _[Description of relevant changes made through the lifecycle.]_ ## 7. Harmonised standards applied _[List applied harmonised standards or, where none, detailed description of the solutions adopted to meet Chapter III, Section 2 requirements.]_ ## 8. EU declaration of conformity _[Copy of the declaration of conformity per Article 47.]_ ## 9. Post-market monitoring plan (Art. 72) _[Description of the system to evaluate performance in the post-market phase.]_ --- ### Open compliance gaps recorded at assessment time - **Art. 9 — Risk management system:** Establish, document and maintain a continuous, iterative risk management process across the system lifecycle. - **Art. 10 — Data and data governance:** Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation. - **Art. 11 + Annex IV — Technical documentation:** Maintain complete Annex IV technical documentation before placing on the market, kept up to date. - **Art. 12 — Record-keeping (automatic logs):** The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime. - **Art. 13 — Transparency and instructions for deployers:** Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance. - **Art. 14 — Human oversight by design:** Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system. - **Art. 15 — Accuracy, robustness and cybersecurity:** Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks. - **Art. 17 — Quality management system:** Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring. - **Art. 43, 47 + 48 — Conformity assessment, declaration and CE marking:** Run the applicable conformity assessment procedure (Art. 43), draw up and sign the EU declaration of conformity (Art. 47) and keep it for ten years, then affix CE marking (Art. 48). - **Art. 49 — EU database registration:** Register the high-risk system in the EU public database before placing it on the market. - **Art. 72 — Post-market monitoring:** Documented plan to actively collect and analyse performance data throughout the system lifetime. - **Art. 73 — Serious incident reporting:** Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases). - **Art. 26(1) — Operate per provider instructions:** Assign technical and organisational measures to use the system strictly according to its instructions for use. - **Art. 26(2) — Assign trained human oversight:** Name specific, competent, trained people with authority to oversee the system and overrule or halt it. - **Art. 26(4) — Input data control:** Ensure input data under your control is relevant and sufficiently representative for the intended purpose. - **Art. 26(5) — Monitor and suspend on risk:** Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk. - **Art. 26(6) — Retain logs (minimum 6 months):** Keep automatically generated logs under your control for at least six months. - **Art. 26(7) — Inform affected workers:** Before using workplace AI, inform workers' representatives and affected workers that they are subject to it. - **Art. 26(11) + 86 — Inform affected persons; explain on request:** Tell natural persons subject to decisions made or materially informed by an Annex III system that it is in use, and be ready to give the Article 86 explanation of the role the system played in a decision.
This took the fictional Nordwind team about 10 minutes to produce.
The classification, gap report and counsel letter are free — no signup, and your answers never leave your browser.
Run the assessment on your own system →