COMPLIPATHDOC complipath.io/guidesRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides

EU AI Act, one question at a time

Every claim in these guides cites the article it rests on in Regulation (EU) 2024/1689. Where the law is still settling — standards, delegated acts, national implementation — the guide says so rather than guessing. To see what this method produces when it runs, read a complete example assessment — an invented system, run through the real engine, every obligation and both application dates included.

Start here

the order a buyer asks in

Deadlines

6 guides

Risk classification

11 guides
How do you classify your AI system under the EU AI Act?

A five-step method to classify an AI system under the EU AI Act: the Article 5 gate, both routes to high-risk, the Article 6(3) exemption, and the paper trail.

What are the Annex III high-risk categories under the EU AI Act?

All eight Annex III high-risk areas — every point and letter with examples, the two express carve-outs, and how Article 7 lets the list change.

What are the limited-risk AI transparency obligations under the EU AI Act?

The four Article 50 transparency duties — chatbot disclosure, content marking, emotion-recognition notice, deepfake labels — live since 2 August 2026, with Article 111(4) giving pre-existing synthetic-content systems until 2 December 2026 for 50(2).

What do you actually have to do for minimal-risk AI under the EU AI Act?

Minimal risk is the AI Act's residual, not a category: the Article 4 AI literacy duty, Article 95 voluntary codes, and the Article 6(4) paper trail.

Is your AI system high-risk? A decision tree

Five yes/no questions to classify an AI system under the EU AI Act: the Article 5 gate, both high-risk routes, the Article 6(3) exemption, Article 50.

Can an Annex III AI system be exempt from high-risk under Article 6(3)?

The Article 6(3) exemption in full: the general test, the four exhaustive conditions, the profiling override that voids all of them, and the Article 6(4) documentation and Article 49(2) registration a claim creates.

What counts as an AI system under the EU AI Act?

The qualifying test in Article 3, point (1), limb by limb — including the two limbs that die in every summary — and the separate question the Regulation never answers: how many AI systems you have.

Is Complipath itself an AI system under the EU AI Act?

We ran the sharpest question a technical buyer asks — against Article 3, point (1), recital 12's own words, and our own engine's verdict on itself, published verbatim including what it got wrong.

What happened when we ran our classification engine on itself?

We answered our own engine's six questions about the engine and the draft generator, ran the real classify(), and published the outputs verbatim — including the sentence it got wrong about itself.

How many AI systems do you have under the EU AI Act?

The Regulation defines what an AI system is and never counts them — the seam the law is sensitive to is intended purpose, and the counting rule we use says plainly which limb is convention, not law.

What are the ten prohibited AI practices in Article 5 of the EU AI Act?

Article 5(1) point by point — the eight original prohibitions, the two added by Regulation (EU) 2026/1744, and the paragraphs that narrow the new ones before they reach anyone.

Roles

4 guides

Requirements

8 guides
What does Article 9 of the EU AI Act require for risk management?

Article 9's risk management system for high-risk AI: the four lifecycle steps, the residual-risk acceptability test, testing rules, and reuse of existing procedures.

What are the data governance requirements under the EU AI Act (Article 10)?

Article 10 sets quality criteria for training, validation and testing data: eight governance practices, a representativeness standard, a strict bias pathway.

What goes into EU AI Act technical documentation? The Annex IV checklist

Article 11(1) requires Annex IV technical documentation before market placement. All nine points, the SME simplified form, and the Article 18(1) ten-year keeping duty.

What are the logging and record-keeping requirements under the EU AI Act?

Article 12's automatic logging duty for high-risk AI, the minimum log set for remote biometric identification, and the six-month retention floors under Article 19 and Article 26(6).

What are the EU AI Act's transparency obligations toward deployers under Article 13?

Article 13's provider-to-deployer transparency for high-risk AI: interpretable operation by design, the instructions-for-use quality standard, and the minimum content list.

What does Article 14 of the EU AI Act require for human oversight?

Article 14's human oversight design duty for high-risk AI: the five overseer capabilities, proportionate measures, the two-person biometric rule, and the deployer's Article 26(2) assignment duty.

What does Article 15 of the EU AI Act require for accuracy, robustness and cybersecurity?

Article 15's accuracy, robustness and cybersecurity duties for high-risk AI: declared accuracy metrics, feedback-loop controls, AI-specific attack defences, and the cybersecurity-certification presumption.

Who does the EU AI Act's AI literacy duty apply to?

Article 4 binds every provider and deployer of AI systems at any risk level. The 2026 rewrite turned a duty to ensure a level into a duty to support development — the standard moved, the date did not.

Industry

3 guides

Comparisons

2 guides
Not a guide — about the product
What this check can and cannot decide →

The guides above are about the Regulation. This one is about our engine: five things the classification decides, five it hands to a human, written once by a person against what it actually covers.

Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.