Is Complipath itself an AI system under the EU AI Act?
Yes — all three of the systems Complipath ships are AI systems under the EU AI Act, and this page shows the analysis rather than asserting the conclusion. Three is our own counting rule, not the law's; the definition all three are measured against is Article 3, point (1). The model-backed features are the easy half. The deterministic classification engine is the hard case: recital 12 pulls a hand-written rule engine in both directions at once, and the Commission's guidelines settle where we land.
Written 11 August 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, and against our own engine run on 11 August 2026.
Quick answer
- The draft generator and the check's reading step call a general-purpose AI model. We treat both as AI systems under Article 3, point (1), and carry the consequences below.
- The classification engine is deterministic, hand-written rules — and that settles less than it sounds. Recital 12 pulls both ways in one breath; the Commission's guidelines' worked example of the inside class matches this engine, and we treat it as an AI system on that reading.
- We ran our own engine on itself and published the output verbatim — including the sentence it got wrong about itself, and the question it cannot ask at all.
- Either way, the practical delta is small and stated: minimal risk on the published runs, Article 4 binding us regardless, and one genuinely open Article 50(2) question we have not resolved.
- Your obligations do not move with our answer. Your systems are classified by what they do, not by what our tooling is.
What does Article 3, point (1) actually require?
The definition, in the Regulation's own words: an AI system is "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments". The limb-by-limb reading is in what counts as an AI system. The hinge is inference; recital 12 says what it means.
Two of recital 12's sentences point in opposite directions for a rule engine: the definition "should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations" — and the inside class below is named in the same recital.
The classification engine, held against both sentences
The verdict engine is deterministic: fixed rules mapping your confirmed answers to a classification with citations. No language model sits in that decision path — the model proposes, you confirm, the rules decide.
The case for outside the definition. Every rule, threshold and ordering in the engine was written by a person; nothing was derived from data, and it derives nothing at runtime — the same answers produce the same verdict, every time. Recital 12 says the capacity to infer "transcends basic data processing by enabling learning, reasoning or modelling", and a fixed mapping defined solely by natural persons and executed automatically reads like the excluded category.
The case for inside. The engine is a symbolic encoding of a legal task that deduces a conclusion from encoded knowledge — a fair description of the "logic- and knowledge-based approaches that infer from encoded knowledge or symbolic representation of the task to be solved" which recital 12 names as inside. "It is only rules" is exactly the answer what counts as an AI system tells readers does not settle the question, and the standard we apply to a reader's rules engine applies to ours.
Where the line runs — read against the Commission's guidelines. The Commission's guidelines — in our pinned corpus since 12 August 2026, guidance rather than law — answer with a worked example that fits this engine uncomfortably well. Their paragraph 39 describes the logic- and knowledge-based class as systems that "learn from knowledge including rules, facts and relationships encoded by human experts" and reason "via deductive or inductive engines or using operations such as sorting, searching, matching, chaining" — and its prominent example is "early generation expert systems intended for medical diagnosis", built from encoded expert knowledge and "intended to draw conclusions from a set of symptoms of a given patient". Substitute legal knowledge for medical, and confirmed answers for symptoms, and that is this engine's architecture.
The escape routes, each checked. Paragraph 41 concedes that "Some systems have the capacity to infer in a narrow manner but may nevertheless fall outside of the scope of the AI system definition because of their limited capacity to analyse patterns and adjust autonomously their output" — which describes this engine's fixedness exactly. But that sentence introduces examples — "Such systems may include:" — followed by four named classes, and none of the four is ours. That the list is illustrative rather than closed does not rescue us either: a system may fall outside the definition without appearing among the four, but resembling the chapeau is not itself the exclusion. Basic data processing (paragraph 46) requires "without any 'learning, reasoning or modelling' at any stage of the system lifecycle" and "without using AI techniques" — logic-based inference among the techniques it names — its examples database filters and spreadsheets. Classical heuristics (paragraph 48) are approximate problem-solving where exact solutions are impractical; a complete deterministic mapping approximates nothing. Optimisation acceleration and simple statistical prediction are not what a legal classifier does.
So the conclusion sharpens, in the uncomfortable direction. The fragments we first saw pointed outside; the paragraphs read in context point in. On the guidelines' worked example this engine is an expert system over encoded legal knowledge — inside the definition — and we treat it as an AI system on that reading, not as caution. A court could draw the line elsewhere; until one does, we take the reading that binds us more. The consequences below were written to hold either way, and they do.
We ran our own engine on itself — here is what it said
On 11 August 2026 we answered the engine's six questions (the engine as it stood that day; it serves 7 today) for the engine and the draft generator, and ran the real classify() both times. Both runs returned minimal risk — and one answered something false about itself. The full outputs, published verbatim including the error, are in what happened when we ran our engine on itself; the inputs are in both pages' claims files.
What it could not decide is the most important output. The engine never asks whether the thing being classified is an AI system at all — question zero is not among its 7 questions, exactly as the decision tree states. Run on itself, it presupposes the answer to this page's title. That limit is recorded in what this check can and cannot decide, and a run that presupposes its own threshold question is evidence of the limit, not an answer to it.
What follows for us
Article 4 binds us on any reading. Whatever the engine's status, we use model-backed AI systems under our authority in a professional activity, and Article 4 binds providers and deployers of AI systems with no risk qualifier, applicable since 2 February 2025 under Article 113, third paragraph, point (a) — the same conclusion the minimal-risk guide reaches for every reader whose whole inventory is residual.
Article 50(2) is our genuinely open question. Providers of AI systems "generating synthetic audio, image, video or text content" must ensure outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated" — but the obligation "shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof". The draft generator drafts documentation from your own register data. Whether that is an assistive function over your input or generation that alters its semantics is exactly where the exception's line runs, we have not resolved it, and we will not pick the convenient side silently. Until it is resolved, this paragraph is the record that the question is open.
No high-risk route reaches these systems on the published runs. Compliance tooling appears in no Annex III category the engine asks about, and both runs returned minimal — with the reservation that the runs are our own answers through our own rules, published so you can check them, not a legal opinion. The engine's choice of citation for the residual is its own; how the residual works is the guide's account.
What this means for you
If you are a provider: nothing about our status changes yours. Your systems are classified by what they do under Article 6 and Annex III — the five-step order — whether the tool you use to record that classification is an AI system or not.
If you are a deployer: using Complipath does not add an AI system to your Annex III exposure on the published runs above. If your review process requires classifying your vendors' tooling, this page and its claims file are the assessment — the same apparatus we would ask of a vendor, run on ourselves. The product's register records your systems; it does not become one of them by recording them.
Run the same engine on a system of yours
Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
Is Complipath's classification engine an AI system? Recital 12 pulls both ways for a rule engine, but the Commission's guidelines resolve it for us: their worked example of the logic- and knowledge-based class — an expert system drawing conclusions from encoded expert knowledge — matches this engine's architecture. We treat the engine as an AI system on that reading. The guidelines are guidance, not law.
Where does Complipath use a language model? In two places: the draft generator and the check's optional reading step, both calling a general-purpose model through an API. Neither sits in the verdict path — the model proposes, you confirm, and the deterministic rules classify from your confirmed answers. We treat both model-backed features as AI systems under Article 3, point (1).
What does the AI Act require of Complipath itself? Article 4's AI-literacy duty binds us as provider and deployer of AI systems, applicable since 2 February 2025. Our published self-runs returned minimal risk, so the high-risk requirements do not attach on those runs. One question is open and recorded: whether Article 50(2)'s marking duty covers the draft generator's output.
Does Complipath's own status change my obligations? No. Your systems are classified by what they do — the Article 5 gates, the Article 6 routes, the Article 50 triggers — regardless of what your tooling is. Our status affects our duties. What you may want from us is evidence, and this page with its claims file is that evidence.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Article 3, points (1), (3) and (4), Article 4, Article 50(1) and (2), Article 96(1), point (f), Article 113, third paragraph, point (a), and recital 12; Regulation (EU) 2026/1744 (EUR-Lex) for the amended Article 4 text in force since 27 July 2026. Engine runs of 11 August 2026 against the app repository at commit 8bebc71; full inputs and outputs in this page's claims file.