A complete sample dossier, nothing hidden
Compliance tools love screenshots of dashboards and hate showing the actual deliverable. Here is ours, in full: a fictional German recruiter running a CV-ranking system (Annex III, employment) with an applicant-facing chatbot (Article 50). Every word below was generated by the same deterministic engine that runs real assessments — verdict, per-obligation binding dates under the 2026 Omnibus timeline, counsel flags, remediation plan.
Compliance gap report
Free tier — every user gets this. Note the per-obligation binding dates: Article 50 duties are marked binding now; the Chapter III stack carries its 2 December 2027 date.
# EU AI Act Compliance Gap Report
## Nordwind Recruiting GmbH (fictional) — CandidateRank
> Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment.
**Date:** 2026-08-03
**Role under the Act:** both
**Risk classification:** High-risk system
**Compliance score:** 9/100
**Key deadline:** 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus); Article 50 transparency duties apply already
**Maximum fine exposure:** €15,000,000 or 3% of global annual turnover
**Audit trail:** rule set v1.4.1 · legal state as of 2026-08-02 · generated 2026-08-03 · assessment fingerprint `22ad9520474969bc`
Your system falls under Annex III or is a regulated product safety component. The full high-risk obligation set applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) — postponed by the 2026 Omnibus. Any Article 50 transparency duties apply already, and the runway is what makes conformity achievable in-house.
## ⚑ Counsel review flags (1)
The following points sit in genuinely gray areas of the Act. The classification above assumes your answers; these positions should be confirmed by qualified counsel in writing:
- **Provider/deployer boundary (Art. 25)** — You act as both provider and deployer. Note that a deployer who substantially modifies a high-risk system, rebrands it, or repurposes a system into high-risk use becomes its provider under Art. 25 and inherits the full provider obligation set. Map which entity holds which role per system with counsel.
---
## Applicable obligations (22)
| Status | Article | Obligation | Severity | Applies from |
|---|---|---|---|---|
| ✅ Done | Art. 4 | AI literacy | medium | binding now |
| ✅ Done | Best practice | AI system inventory | medium | good practice |
| ❌ Open | Art. 9 | Risk management system | critical | 2027-12-02 |
| ❌ Open | Art. 10 | Data and data governance | critical | 2027-12-02 |
| ❌ Open | Art. 11 + Annex IV | Technical documentation | critical | 2027-12-02 |
| ❌ Open | Art. 12 | Record-keeping (automatic logs) | high | 2027-12-02 |
| ❌ Open | Art. 13 | Transparency and instructions for deployers | high | 2027-12-02 |
| ❌ Open | Art. 14 | Human oversight by design | critical | 2027-12-02 |
| ❌ Open | Art. 15 | Accuracy, robustness and cybersecurity | high | 2027-12-02 |
| ❌ Open | Art. 17 | Quality management system | high | 2027-12-02 |
| ❌ Open | Art. 43 + 48 | Conformity assessment and CE marking | critical | 2027-12-02 |
| ❌ Open | Art. 49 | EU database registration | high | 2027-12-02 |
| ❌ Open | Art. 72 | Post-market monitoring | medium | 2027-12-02 |
| ❌ Open | Art. 73 | Serious incident reporting | medium | 2027-12-02 |
| ❌ Open | Art. 26(1) | Operate per provider instructions | high | 2027-12-02 |
| ❌ Open | Art. 26(2) | Assign trained human oversight | critical | 2027-12-02 |
| ❌ Open | Art. 26(4) | Input data control | high | 2027-12-02 |
| ❌ Open | Art. 26(5) | Monitor and suspend on risk | high | 2027-12-02 |
| ❌ Open | Art. 26(6) | Retain logs (minimum 6 months) | medium | 2027-12-02 |
| ❌ Open | Art. 26(7) | Inform affected workers | medium | 2027-12-02 |
| ❌ Open | Art. 27 | Fundamental rights impact assessment | high | 2027-12-02 |
| ✅ Done | Art. 50(1) | Disclose AI interaction | high | binding now |
---
## 30-day remediation plan
### Week 1
- [ ] **Art. 9 — Risk management system** (~5 working days, severity: critical)
Establish, document and maintain a continuous, iterative risk management process across the system lifecycle.
- [ ] **Art. 11 + Annex IV — Technical documentation** (~4 working days, severity: critical)
Maintain complete Annex IV technical documentation before placing on the market, kept up to date.
- [ ] **Art. 26(1) — Operate per provider instructions** (~2 working days, severity: high)
Assign technical and organisational measures to use the system strictly according to its instructions for use.
- [ ] **Art. 26(2) — Assign trained human oversight** (~2 working days, severity: critical)
Name specific, competent, trained people with authority to oversee the system and overrule or halt it.
### Week 2
- [ ] **Art. 10 — Data and data governance** (~6 working days, severity: critical)
Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation.
- [ ] **Art. 12 — Record-keeping (automatic logs)** (~3 working days, severity: high)
The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime.
- [ ] **Art. 13 — Transparency and instructions for deployers** (~3 working days, severity: high)
Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance.
- [ ] **Art. 14 — Human oversight by design** (~4 working days, severity: critical)
Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system.
- [ ] **Art. 26(4) — Input data control** (~3 working days, severity: high)
Ensure input data under your control is relevant and sufficiently representative for the intended purpose.
- [ ] **Art. 26(5) — Monitor and suspend on risk** (~2 working days, severity: high)
Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk.
- [ ] **Art. 26(6) — Retain logs (minimum 6 months)** (~1 working days, severity: medium)
Keep automatically generated logs under your control for at least six months.
### Week 3
- [ ] **Art. 15 — Accuracy, robustness and cybersecurity** (~6 working days, severity: high)
Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks.
- [ ] **Art. 17 — Quality management system** (~6 working days, severity: high)
Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring.
- [ ] **Art. 26(7) — Inform affected workers** (~1 working days, severity: medium)
Before using workplace AI, inform workers' representatives and affected workers that they are subject to it.
- [ ] **Art. 27 — Fundamental rights impact assessment** (~3 working days, severity: high)
Deployers that are public bodies or private entities providing public services, and deployers of credit-scoring or life/health-insurance risk-pricing systems (Annex III 5(b)/(c)), must complete a FRIA before first use.
### Week 4
- [ ] **Art. 43 + 48 — Conformity assessment and CE marking** (~5 working days, severity: critical)
Run the applicable conformity assessment procedure, draw up the EU declaration of conformity, and affix CE marking.
- [ ] **Art. 49 — EU database registration** (~1 working days, severity: high)
Register the high-risk system in the EU public database before placing it on the market.
- [ ] **Art. 72 — Post-market monitoring** (~2 working days, severity: medium)
Documented plan to actively collect and analyse performance data throughout the system lifetime.
- [ ] **Art. 73 — Serious incident reporting** (~1 working days, severity: medium)
Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases).
---
*Total estimated effort: 60 working days.
Prioritise critical items in weeks 1–2; conformity assessment and registration close the plan.*
Counsel pack cover letter
Free tier — the page a law firm reads first: verdict, temporal status, and the gray-area questions the engine refuses to decide on its own.
# Cover letter for counsel review ### Nordwind Recruiting GmbH (fictional) — CandidateRank > Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment. **Date:** 2026-08-03 **Audit trail:** rule set v1.4.1 · legal state as of 2026-08-02 · generated 2026-08-03 · assessment fingerprint `22ad9520474969bc` Dear counsel, We have run a structured EU AI Act classification of the system below using a deterministic, versioned rule set (methodology and full rule inventory: annexwise.com/methodology). This letter summarises the verdict, its temporal status under the timeline as amended by Regulation (EU) 2026/1744, and the specific points on which we ask for your written confirmation. The engine resolves nothing it should not: every genuinely gray call below is flagged for you, not decided for us. ## The verdict to confirm - **System:** CandidateRank — Scores and ranks incoming job applications for shortlisting, using a gradient-boosted model over CV features; also runs a customer-facing chatbot for applicant questions. - **Role under the Act:** both - **Classification:** High-risk system - **Temporal status:** 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus); Article 50 transparency duties apply already - **Obligations binding now:** 2 (Art. 4, Art. 50(1)) - **Obligations binding later:** 19 (Art. 9 from 2027-12-02, Art. 10 from 2027-12-02, Art. 11 + Annex IV from 2027-12-02, Art. 12 from 2027-12-02, Art. 13 from 2027-12-02, Art. 14 from 2027-12-02, Art. 15 from 2027-12-02, Art. 17 from 2027-12-02, Art. 43 + 48 from 2027-12-02, Art. 49 from 2027-12-02, Art. 72 from 2027-12-02, Art. 73 from 2027-12-02, Art. 26(1) from 2027-12-02, Art. 26(2) from 2027-12-02, Art. 26(4) from 2027-12-02, Art. 26(5) from 2027-12-02, Art. 26(6) from 2027-12-02, Art. 26(7) from 2027-12-02, Art. 27 from 2027-12-02) - **Maximum fine tier if breached:** €15,000,000 or 3% of global annual turnover ## Questions requiring your judgement (1) 1. **Provider/deployer boundary (Art. 25)** — You act as both provider and deployer. Note that a deployer who substantially modifies a high-risk system, rebrands it, or repurposes a system into high-risk use becomes its provider under Art. 25 and inherits the full provider obligation set. Map which entity holds which role per system with counsel. ## Enclosures 1. Compliance gap report (verdict, obligation table with per-obligation binding dates, 30-day remediation plan) 2. Annex IV technical documentation draft (structure per Article 11; engineering facts to be completed by the client) ## What we ask for - Written confirmation or correction of the classification above - A position on each flagged question - Any qualifications to record permanently in the compliance file The assessment is reproducible: the fingerprint above, together with the rule-set version, re-derives this exact verdict from the same answers. Kind regards, Nordwind Recruiting GmbH (fictional)
Annex IV technical documentation (draft)
Paid tiers — the Article 11 structure pre-filled from the assessment. Engineering facts (architecture, training data, metrics) are completed by your team: the tool structures the file, it does not invent evidence.
# Technical Documentation — CandidateRank ### Prepared under Article 11 and Annex IV, Regulation (EU) 2024/1689 (AI Act) > Generated by AnnexWise. This document is a structured starting point prepared from your self-assessment. It is not legal advice; have counsel review before relying on it for a conformity assessment. **Organisation:** Nordwind Recruiting GmbH (fictional) **Role under the Act:** both **Risk classification:** High-risk system **Date:** 2026-08-03 **Audit trail:** rule set v1.4.1 · legal state as of 2026-08-02 · generated 2026-08-03 · assessment fingerprint `22ad9520474969bc` --- ## 1. General description of the AI system - **Intended purpose:** Scores and ranks incoming job applications for shortlisting, using a gradient-boosted model over CV features; also runs a customer-facing chatbot for applicant questions. - **Provider name:** Nordwind Recruiting GmbH (fictional) - **Versions and how they relate:** _[version history and substantial modifications]_ - **Hardware on which the system runs:** _[describe]_ - **Forms in which the system is placed on the market:** _[SaaS / API / embedded / on-prem]_ - **Instructions for use for the deployer:** _[attach or reference]_ ## 2. Detailed description of elements and development process - **Development methods, including third-party tools and pre-trained models:** _[describe]_ - **Design specifications and key architecture choices:** _[describe]_ - **What the system is designed to optimise for; relevance of parameters:** _[describe]_ - **Description of the expected output and output quality:** _[describe]_ - **Human oversight measures built into the design (Art. 14):** _[describe]_ - **Predetermined changes and continuous-learning strategy:** _[describe]_ - **Validation and testing procedures, metrics and results:** _[accuracy, robustness, bias]_ - **Cybersecurity measures (Art. 15):** _[describe]_ ## 3. Monitoring, functioning and control - **Capabilities and limitations of the system:** _[expected accuracy for intended purpose]_ - **Foreseeable unintended outcomes and sources of risk:** _[health, safety, fundamental rights]_ - **Human oversight measures for deployers:** _[technical measures that facilitate interpretation]_ - **Input data specifications:** _[training/validation/test data requirements]_ ## 4. Appropriateness of performance metrics _[Why the chosen accuracy/robustness metrics are appropriate for this system.]_ ## 5. Risk management system (Art. 9) _[Summary of the documented, iterative risk management process: identified risks, mitigations, residual-risk judgements, testing conclusions.]_ ## 6. Lifecycle changes _[Description of relevant changes made through the lifecycle.]_ ## 7. Harmonised standards applied _[List applied harmonised standards or, where none, detailed description of the solutions adopted to meet Chapter III, Section 2 requirements.]_ ## 8. EU declaration of conformity _[Copy of the declaration of conformity per Article 47.]_ ## 9. Post-market monitoring plan (Art. 72) _[Description of the system to evaluate performance in the post-market phase.]_ --- ### Open compliance gaps recorded at assessment time - **Art. 9 — Risk management system:** Establish, document and maintain a continuous, iterative risk management process across the system lifecycle. - **Art. 10 — Data and data governance:** Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation. - **Art. 11 + Annex IV — Technical documentation:** Maintain complete Annex IV technical documentation before placing on the market, kept up to date. - **Art. 12 — Record-keeping (automatic logs):** The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime. - **Art. 13 — Transparency and instructions for deployers:** Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance. - **Art. 14 — Human oversight by design:** Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system. - **Art. 15 — Accuracy, robustness and cybersecurity:** Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks. - **Art. 17 — Quality management system:** Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring. - **Art. 43 + 48 — Conformity assessment and CE marking:** Run the applicable conformity assessment procedure, draw up the EU declaration of conformity, and affix CE marking. - **Art. 49 — EU database registration:** Register the high-risk system in the EU public database before placing it on the market. - **Art. 72 — Post-market monitoring:** Documented plan to actively collect and analyse performance data throughout the system lifetime. - **Art. 73 — Serious incident reporting:** Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases). - **Art. 26(1) — Operate per provider instructions:** Assign technical and organisational measures to use the system strictly according to its instructions for use. - **Art. 26(2) — Assign trained human oversight:** Name specific, competent, trained people with authority to oversee the system and overrule or halt it. - **Art. 26(4) — Input data control:** Ensure input data under your control is relevant and sufficiently representative for the intended purpose. - **Art. 26(5) — Monitor and suspend on risk:** Monitor operation, inform the provider of risks, and suspend use when the system presents a serious risk. - **Art. 26(6) — Retain logs (minimum 6 months):** Keep automatically generated logs under your control for at least six months. - **Art. 26(7) — Inform affected workers:** Before using workplace AI, inform workers' representatives and affected workers that they are subject to it. - **Art. 27 — Fundamental rights impact assessment:** Deployers that are public bodies or private entities providing public services, and deployers of credit-scoring or life/health-insurance risk-pricing systems (Annex III 5(b)/(c)), must complete a FRIA before first use.
This took the fictional Nordwind team about 10 minutes to produce.
The classification, gap report and counsel letter are free — no signup, and your answers never leave your browser.
Run the assessment on your own system →