A classification decision that holds up
Provider versus deployer, high-risk versus limited-risk, GPAI obligations or not, written down with the reasoning, signed by the right party, and ready to show the market surveillance authority on day one.
A working programme for providers and deployers of AI systems: classification documented, the risk-management system in operation, data governance defensible, the technical file built the way Annex IV expects, and post-market monitoring in place before the obligation lands.
Annex III almost certainly catches the system. Your enterprise customer is now your deployer under the Act, and the procurement questionnaire reflects that. Without classification and a technical file, the deal stalls.
Recruitment screening, performance evaluation and workforce allocation are explicitly Annex III. As the deployer you owe a specific set of duties: human oversight, monitoring, fundamental-rights impact assessment in many cases, transparency to affected persons.
A slide that says "we comply" is not the answer. A documented programme, a named accountable owner, and an evidence trail tied to the specific articles, that is the answer the audit committee can sign off on.
GPAI obligations apply from August 2025, on technical documentation, copyright compliance, and a public training-content summary. Systemic-risk GPAI carries a heavier obligation set. The artifacts need to exist, in the right shape, on day one of enforcement.
Each phase produces an artifact the Act names by article number, not a deliverable we invented.
Provider, deployer, importer, distributor, or several at once. Which systems fall under prohibited practice, high-risk Annex III, limited-risk transparency, minimal-risk or GPAI. A documented classification memo with the reasoning, not a label on a slide.
Article 9 risk-management system designed as a continuous loop, not a one-off assessment. Article 10 data governance covering training, validation and test sets, with documented quality, representativeness, and bias-mitigation measures.
Annex IV technical file in the format the certifier expects, plus the Article 13 transparency artifacts for deployers, instructions for use, intended purpose, performance characteristics, limitations. For GPAI, the Article 53 documentation package on top.
Article 14 human oversight measures specified per system. Article 12 automatic logging configured and retention defined. Post-market monitoring under Article 72 designed so deployer-side feedback finds its way back to provider-side decisions.
The right assessment path under Annex VI or VII, the EU declaration of conformity, CE marking where it applies, and the registration in the EU database. We sit alongside the named accountable officer until the file is in.
Provider versus deployer, high-risk versus limited-risk, GPAI obligations or not, written down with the reasoning, signed by the right party, and ready to show the market surveillance authority on day one.
Article 9 implemented as a continuous loop, not a static document. Article 10 data governance in operation. The system the certifier opens at the start of a conformity assessment and finds in working order.
Each section in the format the certifier expects, cross-referenced to the operating evidence behind it. Procurement reviewers and notified bodies see the same artifact and reach the same conclusion.
Logging, incident reporting and a feedback loop from deployers back to the provider, so the system you launch with conformity is not the system that quietly diverges from it six months later.
"The AI Act will not be enforced by a single audit moment. It will be enforced through procurement questionnaires, market surveillance probes and incident triggers, continuously. The programme that survives is the one built for a working week, not for a one-off file."
Purple Dragon Cybersecurity
If you place an AI system on the EU market, put it into service in the EU, or your output is used in the EU, almost certainly yes, regardless of where you are headquartered. Providers carry the heaviest obligations, deployers carry a smaller but real set, and importers and distributors carry specific duties when they are in the chain.
Annex III names eight domains, biometrics, critical infrastructure, education and training, employment and HR, access to essential services, law enforcement, migration and border, administration of justice and democracy. If your system is intended to be used in those domains as a safety component or as a decision input, it is high-risk and the heavy obligations apply. We confirm classification before scoping work.
The Act is in force since August 2024 with staged obligations. Prohibited practices and AI literacy applied from February 2025. General-purpose AI obligations applied from August 2025. High-risk obligations under Annex III apply from August 2026, and Annex I-product-integrated high-risk from August 2027. The grace window narrows monthly.
ISO/IEC 42001 is the management-system standard for AI, useful as an operating spine. NIST AI RMF is a US framework with no binding force in the EU. The AI Act is the law. We use ISO 42001 as the operating framework and map its outputs to the specific AI Act articles, the certifier you eventually face will be checking the law, not the standard.
Providers of high-risk AI systems do. Most can self-assess under Annex VI for Annex III systems, biometric identification and a few categories require involving a notified body under Annex VII. We help you understand which path applies, prepare the technical documentation, and stay in the room when the assessment is taking place.
A working session that confirms your role, your classification, and what the next 90 days should produce before the high-risk obligations land.
Tell us what you're trying to ship, what's stalled, or which buyer security review is up next. We work with companies across the EU, EEA and US, and we reply within one business day.