Yes, and nothing on this page argues otherwise. We do not replace your lawyer. What we change is which hours you pay for: the first hours of a legal review go on establishing which AI systems are in scope and what each one does, and that is the part you already know best and the part a specialist rate is most wasted on.
So the division of labour, stated as a table rather than a promise. Both columns describe this product and your lawyer — neither describes how anybody else works.
| What the review needs | Where it comes from |
|---|---|
| Every AI system in scope, with what each one is for | The register. You answer the questions; it records the answers as given. |
| Which provision each classification rests on | The engine, with the reasoning attached to the verdict rather than summarised away from it. |
| Which version of the law it was decided against | Stamped on each record, with the amending acts named. |
| Who confirmed each classification, and when | Recorded against the assessment and carried in the export. |
| Whether Article 6(3) applies to a system | You, as the provider. Article 6(3) lets a provider conclude that a listed system is not high-risk, and Article 6(4) asks the provider to document that assessment before the system goes on the market. Your lawyer can advise you on it. The engine refuses this one deliberately: it does not reach that conclusion from your answers, and the record says which provisions it declined. |
| Whether a classification is right | Your lawyer. The record is the thing they check, and checking a record is faster than assembling one. |
| What any of it means for the business | Your lawyer. |
A legal review starts with questions only you can answer: what does this system do, who does it affect, what happens when it is wrong, who owns it. Those answers exist inside your company already — scattered across people, tickets and memory — and reconstructing them in a meeting is the slowest way to get them out. A register is the fast way, because the answers go in once, from the person who knows, and stay there with a date on them.
It is not a hedge, it is the design. A guided assessment returns a risk level with the provisions it rests on and the reasoning behind it. Where the Regulation asks for a judgement rather than a fact, the engine says so and stops. The clearest case is the one on our own example page: a provider may conclude under Article 6(3) that a system listed in Annex III is not high-risk, and that conclusion is the provider's to reach and document. Complipath does not reach it from your answers, and the record says which provisions it declined.
A register they can read in one sitting, an assessment per system with its citations, and an export per record carrying the engine version, the corpus it was decided against and the person who confirmed it. What they do with that is their work. What they do not have to do is spend the first part of it asking you what you have.
The provisions are Article 6(3) and Article 6(4) of Regulation (EU) 2024/1689. Where the engine stops and why is listed as a limit rather than a feature, and the example assessment shows a run that declined it.
Advise you on your own facts. Give you an opinion you can rely on, and stand behind it. Argue your position to a regulator or a counterparty. Tell you which risks are worth accepting. None of that is software, and none of it is on the roadmap. And one more thing worth saying in the same breath: no lawyer has reviewed our classification logic either. That is question seven on the review page, answered there with the other eleven. Nor is that the only thing worth checking before you rely on a verdict: what a reviewer can verify about us before trusting a classification is written out in full.
There is no figure on this page and there will not be one. We have not measured what a legal review costs, or what it costs with a register in front of it, and a number nobody measured is worth less than the sentence it sits in.
The neighbouring case — a spreadsheet and one person's time — is argued at what in-house compliance work does well, and where it stops, and what we cover of the Act is a table with three empty rows in it.
Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.
Complipath is built by Yobel Tzegai in Gothenburg, Sweden.
Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.
We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.