Questionnaire answers · AI topics · Article 5 · Article 50
How to answer EU AI Act questions in a supplier questionnaire
Written by Yobel TzegaiLast reviewed 9 October 2026Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
The short answer
Answer per system, not for the company: whether any practice is prohibited under Article 5, whether the system is high-risk under Article 6 with Annex I or Annex III, and which Article 50 disclosures it carries. "We are AI Act compliant" is not an answer; the classification with its article is. Complipath (complipath.io) keeps the record these answers rest on.
What they usually ask
- Q1“Are you compliant with the EU AI Act?”
- Q2“Do any of your AI systems fall under a prohibited practice?”
- Q3“Are any of your AI systems high-risk?”
- Q4“Do you disclose to users when they interact with AI?”
An example answer, part by part
An illustration for an invented product, not a real supplier's answer, to the question: Are any of your AI systems high-risk?
- Direct answerYes, partly or no first
- No. None of our three AI systems is high-risk.
- ControlWhat you actually do
- Each system was classified against Article 5, Article 6 with Annex I and Annex III and Article 50; a named person confirmed each classification.
- ScopeWhich AI systems
- The support assistant, the ticket summariser and the spam filter.
- EvidenceWhat you can show
- The classification record of each system, with the provisions it rests on and the date it was confirmed, 3 September 2026.
- ExceptionsBe honest
- The support assistant carries the Article 50(1) disclosure, shown at the start of every conversation.
Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.
What counts as proof
- DOCThe classification of each system, with the provision behind each reason and the version of the law it was made against.
- DOCWho confirmed each classification, and when.
- DOCFor each Article 50 duty, a screenshot of the disclosure as the user sees it.
Common mistakes
- ✗Answering for the company. Article 6 classifies systems, not companies.
- ✗"Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
- ✗A policy title as the control. It says nothing about what happens to an output.
- ✗Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
- ✗Not applicable with no reason. The reason is the classification.
- ✗Dropping the exception. The summary that leaves out "unless" is the one that is wrong.
What the law says
Article 5the prohibited practices, applying since 2 February 2025, except Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), which apply from 2 December 2026 (Article 113, third paragraph, point (a), as replaced by Regulation (EU) 2026/1744).
Read Article 5 on EUR-Lex ↗ Article 6: high-risk under Article 6(1) with Annex I, or under Article 6(2) with Annex III; an Annex III system can fall outside under Article 6(3), and the provider documents that assessment first (Article 6(4)).
Article 50the transparency duties for systems that interact with people, generate content, recognise emotions or categorise biometrically, and for deep fakes.
Read Article 50 on EUR-Lex ↗
What Complipath does
- ✓Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
- ✓Article mapping Each reason behind a verdict names the provision it rests on, so a reader can check it herself
- ✓Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence
- ✓Deadlines Each obligation carries the date it applies from, derived from where the provision sits rather than written onto the row
- ✓Regulatory change monitoring Checks the provisions your confirmed records cite against amending acts, and emails you per affected system
Rules decide. AI only drafts. A person confirms.
What it does not do yet
- ✗Conformity assessment (Article 43) Not supported We found no support for this in what we have built. The same search found the number in one file — a comment using it as an example of the Official Journal's citation form — and the words in six, every one of them quoting Article 6(1), point (b)'s third-party condition, an Article 5 sentence or a section name. No template, no column, no limb.
- ✗Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
Questions
Can we answer that we are EU AI Act compliant?
Not as one word for the company. The Act sets duties per system and per role, and the high-risk duties apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems under Article 113, third paragraph, point (c). Answer with each system's classification, its article and the duties that follow.
Our customer asks for an AI Act certificate. What do we send?
There is none for a system that is not high-risk: the conformity assessment of Article 43 concerns high-risk systems. Send each system's classification with the provisions it rests on, who confirmed it and when, and the version of the law it was made against.
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.