Complipath sorts AI systems into their risk classes and keeps the evidence behind every answer. That is one job out of the nine or ten a company needs for the EU AI Act, and this page is the list — what the product does per article, whether it does it for you or asks you to, and what you end up holding.
These are the obligations one high-risk Annex III system returned. A different system returns a different list, and that run returned no Article 50 transparency obligations at all. The product derives the list; we do not write it. The nine rows after Article 43 are not obligations the engine returns: they are what a buyer asks about, and each was read in the application on 8 October 2026.
| Article or need | Complipath's part | What the product does | Yours or ours | What you get |
|---|---|---|---|---|
| Article 9 — risk management | Live | Lists the obligation with its application date and what evidence answers it. The documentation workspace has a risks and mitigations section, and drafts it from what you have recorded. | Ours to list and draft, yours to review | A checklist row with a date, and a drafted section that stays a draft until a named person marks it reviewed |
| Article 10 — data and data governance | Live | Lists the obligation with its date and evidence guidance. The workspace has a data description section, and drafts it. | Ours to list and draft, yours to review | A checklist row, and a drafted section |
| Article 11 and Annex IV — technical documentation | Live | The workspace asks for all nine points of Annex IV, the lettered items of points 1 and 2 included, across its four sections. What fills them is your answers: it asks; it does not answer for you. | Ours to draft, yours to review and confirm | Four sections that between them ask for every point of Annex IV, exported as the PDF you keep |
| Article 12 — record-keeping | Live | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 13 — information to deployers | Live | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 14 — human oversight | Live | Lists the obligation with its date and evidence guidance. The workspace has a human oversight section, and drafts it. | Ours to list and draft, yours to review | A checklist row, and a drafted section |
| Article 15 — accuracy, robustness, cybersecurity | Live | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 17 — quality management system | Live | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 49 — registration in the EU database | Live | Lists the obligation with its date and evidence guidance — and it carries a different date from the rest, because Article 49 sits in a Section the 2026 amendment did not defer. | Ours to list, yours to do | A checklist row with its own date |
| Article 72 — post-market monitoring | Not supported | We found no support for this in what we have built. MVP searched 245 shipped source files, 44 migrations, 14 obligation templates, 15 export columns and 12 Annex IV limbs, on the article number and on the provision's own words: nothing on any of the five. | Neither — there is nothing here to divide | Nothing |
| Article 73 — serious incident reporting | Not supported | We found no support for this in what we have built. Same search, same five places: nothing. | Neither — there is nothing here to divide | Nothing |
| Article 43 — conformity assessment | Not supported | We found no support for this in what we have built. The same search found the number in one file — a comment using it as an example of the Official Journal's citation form — and the words in six, every one of them quoting Article 6(1), point (b)'s third-party condition, an Article 5 sentence or a section name. No template, no column, no limb. | Neither — there is nothing here to divide | Nothing |
| Evidence repository | Live | Upload a file once and it is linked to the requirements it proves, each match with the passage and the page it stands on; the passage is checked word for word against that page, and nothing changes until a person applies it. A language model (Anthropic) does the reading. | Ours to read and link, yours to apply | Every file next to what it proves |
| Sign-off with name and date | Live | Confirming a classification stamps it with the person who confirmed it and when; a documentation section is marked reviewed by a named person on a date. | Ours to record, yours to sign | A name and a date on every confirmed classification and reviewed section |
| Audit trail | Live | Settings → Audit log shows who did what, and when, with filters and a CSV export, on Starter and in the trial. No member can edit or delete a line, an owner included. A trail of every field changed on a system is not built. | Ours | A log you can read and export |
| EU hosting | Live | The database is in Supabase's eu-central-1 region and the app's functions in Vercel's fra1 region, both Frankfurt, read on 8 October 2026. You cannot choose another region. | Ours | Your workspace stored in Frankfurt |
| Article 27 — fundamental rights impact assessment | Not supported | The step-by-step plan lists Article 27 as a step only for systems classified under points 5(b) and 5(c) of Annex III. Article 27(1) also binds deployers that are bodies governed by public law or private entities providing public services, and the product does not ask whether you are one. Nothing carries the assessment itself. | Yours | A reminder on the plan, for two Annex III points |
| Article 47 — EU declaration of conformity | Not supported | The Annex IV documentation asks for a copy of the declaration and you upload it; the plan says to issue it when the system is ready. The declaration itself is not drafted. | Yours to draw up, ours to file | A place for the copy |
| ISO/IEC 42001 mapping | Not supported | The assistant answers questions about ISO/IEC 42001 next to the AI Act. There is no mapping of its controls to the Act, and Complipath certifies nothing. | Neither — there is nothing here to divide | Nothing |
| Vendor AI: the tools you buy | Live | An AI tool you buy is registered and classified like one you build, with the obligations of a deployer and the AI literacy record. There is no vendor questionnaire and no contract review. | Ours to list, yours to do | Bought tools in the same register, with your duties as deployer |
| Policy templates | Not supported | The product has no template for an AI policy or an acceptable-use policy. | Neither — there is nothing here to divide | Nothing |
Four fields: a status, an owner, an evidence link and a note. The status is one of not started, in progress, complete or blocked. There is no file upload — the evidence is a link to where the document lives, not the document. And there is no way to mark a single obligation not applicable: what the product has is an Article 6(3) claim against the whole system, with a mandatory reason, which decides which obligations it reaches. If you need a row-by-row not-applicable with a justification per row, we do not have it.
An AI drafting assistant is built and is in Starter: it writes the first draft of each section above from what you have already recorded. It drafts; it does not decide and it does not confirm — a section stays a draft until a named person on your team confirms it, and that confirmation is what makes it your evidence. No quota limits it. If one is introduced, this page will say so before it takes effect. The drafting is kept away from the classification: the engine that decides risk does not read the drafts, and the drafts do not reach the engine.
Three of those rows say we found no support for them in what we have built, and that is the honest shape of the product: post-market monitoring, incident reporting and formal conformity assessment are not things this does, and pointing you at ourselves for them would waste your quarter. The wording is deliberate — we searched our own repository and found nothing, which is a smaller claim than saying the feature does not exist, and it is the one we can stand behind. Standing behind a claim is not the same as your being able to test it, so how to check the claims on this site instead of taking them is written down separately. Conformity assessment in particular is a notified body's job for the routes that need one, not software's. And the documentation row says 'asks for' on purpose: since 1 September 2026 the workspace asks for every point of Annex IV, and what fills those points is your answers — reviewed and confirmed by a named person on your team, never generated into place.
See which of your own AI systems the EU AI Act covers.
a short set of questions, more if your answers open follow-ups. No account needed. Nothing is saved unless you choose to keep your result.