An example system, run through the real engine. Kestrel Applicant Ranking (test) is not a customer and not a real company. The system is invented; the engine, the rules, the citations and everything below are not. What it does: Ranks written job applications against the stated requirements of each open role, and returns an ordered shortlist to the hiring manager. Built in-house on an open-weights model, fine-tuned on our own historical hiring data. Used for roles advertised in Sweden, Germany and the Netherlands.
risk level: high · confirmed 2026-08-17 · engine 2026-08-17.2 · fetched 2026-08-23
This assessment was recorded on 17 August 2026. What it rested on is stored and unchanged: the provisions engaged, the engine version, and the source texts those were derived from. The citations below are shown in the notation the Regulation uses today — naming a provision differently does not change which provision it is.
This is a classification decision record. It carries the answers as they were given, the engine version that decided them, the version of the law it was decided against, the outcome with its reasoning, and the provisions the engine declined to reach a conclusion on.
What is still open, as the route reports it:
record complete: false
Complete against what this workspace asks for. It is not a statement that this system complies with the Regulation.
These provisions turn on a judgement the engine does not make. Each one is listed with what it rests on, and it is a person who reaches the conclusion.
Eight of this system's obligations apply from 2 December 2027; the registration duty applies from 2 August 2026. Both dates are derived, not chosen: Article 113, third paragraph, point (c), as amended by Regulation (EU) 2026/1744, defers Chapter III, Sections 1, 2 and 3 — and Article 49 sits in Section 5, which point (c) does not defer, so registration keeps the general date in Article 113, second paragraph. One system, two clocks, both read off which provision is deferred and which is not. Every date in one table.
All 9 as the engine derived them — including the statuses that look bad. Each carries the engine's guidance on what evidence answers it.
Produce a risk log, minutes of the reviews, and a list naming who owns each mitigation.
Produce a description of the datasets and a record of where they came from — and, if you carry out bias detection, its results.
Produce the technical documentation itself. The documentation workspace drafts some of its sections; the Annex IV points it does not reach are yours to add.
Produce a retention policy and a sample export of the logs.
Produce the instructions for use that go to whoever deploys the system, and keep the version you handed over.
Produce an escalation procedure and a training record for the people assigned to oversee the system.
Produce an accuracy test report, a summary of the penetration testing, and the monitoring alerts you keep.
Produce a quality management policy, a responsibility matrix and an internal audit plan.
Produce the confirmation of registration in the EU database and the data set filed under Annex VIII.
requires Annex IV documentation: true
The factors behind the verdict, as the engine recorded them.
The corpus comparison — the thing an assessment without a date cannot tell you.
corpus comparison run 23 August 2026, 17:55 UTC
The raw answer set, in the engine's own field names — the assessment works from what it was told, and this is what it was told.
Provenance is part of the assessment: a recorded answer has an answerer.
The Annex IV workspace as it stands — including what is not reviewed.
The scope the engine states for itself.
This page is rendered from the engine's own output, fetched from the app at every build — never written by hand. Corpus: Classification derived from Regulation (EU) 2024/1689, Regulation (EU) 2026/1744. Provisions in that corpus that this assessment does not detect: Article 6(1) — Annex I high-risk (applies from 2 August 2028).. Where the engine stops and why is in what this check can and cannot decide; the classification method it follows is the five-step order.
Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.
Complipath is built by Yobel Tzegai in Gothenburg, Sweden.
Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.
We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.