Questionnaire answers · AI topics · Article 113

How to answer AI regulatory compliance questions in a supplier questionnaire

The short answer

Name the law, the version and the date for each duty, per system. The AI Act's duties apply on different dates under Article 113, and Regulation (EU) 2026/1744 has already moved some of them; an answer that names the text it rests on stays checkable when the law changes again. Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“Which AI regulations apply to you?”
  2. Q2“How do you track changes in AI regulation?”
  3. Q3“When do the AI Act's duties apply to your systems?”
  4. Q4“Who is responsible for regulatory compliance?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: How do you track changes in AI regulation?

Direct answerYes, partly or no first
Each AI system's classification records the version of the law it was made against, and amending acts are checked against the provisions it cites.
ControlWhat you actually do
When an amending act touches a provision our records cite, the owner of each affected system is told and re-checks the classification.
ScopeWhich AI systems
All seven systems in our register.
EvidenceWhat you can show
The legal-watch email received when Regulation (EU) 2026/1744 was published, and the re-confirmed classifications that followed.
ExceptionsBe honest
National implementing laws are tracked by our counsel, not in the register.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • Each classification with the version of the law it rests on.
  • The record of what changed when the law changed, and who re-checked it.
  • Your counsel's advice where national law applies.

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

Article 113

the Regulation applies from 2 August 2026, with the exceptions of its third paragraph as amended by Regulation (EU) 2026/1744: point (a), Chapters I and II from 2 February 2025, except Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), from 2 December 2026; point (b), Chapter III, Section 4, Chapters V, VII and XII and Article 78 from 2 August 2025, except Article 101; point (c), Chapter III, Sections 1, 2 and 3, except Article 6(5), from 2 December 2027 for systems high-risk under Article 6(2) and Annex III and from 2 August 2028 under Article 6(1) and Annex I; point (d), Articles 102 to 110 from 27 July 2026.

Read Article 113 on EUR-Lex ↗

What Complipath does

  • Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
  • Regulatory change monitoring Checks the provisions your confirmed records cite against amending acts, and emails you per affected system
  • Deadlines Each obligation carries the date it applies from, derived from where the provision sits rather than written onto the row
  • Article mapping Each reason behind a verdict names the provision it rests on, so a reader can check it herself
  • Named owners A person behind every system and every duty

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • ISO/IEC 42001 mapping Not supported The assistant answers questions about ISO/IEC 42001 next to the AI Act. There is no mapping of its controls to the Act, and Complipath certifies nothing.

Questions

Is the AI Act the only AI law we should name?

No. The GDPR applies wherever personal data is processed, and sector rules apply in finance, health and employment. Name the AI Act's duties per system with their dates, and the other laws where your counsel has said they apply. Complipath covers the AI Act; it does not map the others.

What changed with Regulation (EU) 2026/1744?

Among other things, it replaced Article 4 on AI literacy, moved the dates in Article 113 for the high-risk duties, and added prohibited practices that apply from 2 December 2026 under Article 113, third paragraph, point (a). Our page on the amending act lists every point it amends, in its own words.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.