Complipath classifies AI systems and holds the evidence for the classification. That is one job out of the nine or ten a company needs for the EU AI Act, and this page is the list — what the product does per article, whether it does it for you or asks you to, and what you end up holding.
These are the obligations one high-risk Annex III system returned. A different system returns a different list, and that run returned no Article 50 transparency obligations at all. The product derives the list; we do not write it.
| Article | What the product does | Yours or ours | What you get |
|---|---|---|---|
| Article 9 — risk management | Lists the obligation with its application date and what evidence answers it. The documentation workspace has a risks and mitigations section, and drafts it from what you have recorded. | Ours to list and draft, yours to review | A checklist row with a date, and a drafted section that stays a draft until a named person marks it reviewed |
| Article 10 — data and data governance | Lists the obligation with its date and evidence guidance. The workspace has a data description section, and drafts it. | Ours to list and draft, yours to review | A checklist row, and a drafted section |
| Article 11 and Annex IV — technical documentation | The workspace asks for point 1 and point 2(d) of Annex IV, and the risk management system under Article 9 that point 5 of Annex IV requires. It does not ask for point 3 or point 4, and it covers one lettered item of point 2. | Ours to draft, yours to review and to finish | Four sections of the Annex IV file, not the whole file |
| Article 12 — record-keeping | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 13 — information to deployers | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 14 — human oversight | Lists the obligation with its date and evidence guidance. The workspace has a human oversight section, and drafts it. | Ours to list and draft, yours to review | A checklist row, and a drafted section |
| Article 15 — accuracy, robustness, cybersecurity | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 17 — quality management system | Lists the obligation with its date and evidence guidance. | Ours to list, yours to do | A checklist row with a date |
| Article 49 — registration in the EU database | Lists the obligation with its date and evidence guidance — and it carries a different date from the rest, because Article 49 sits in a Section the 2026 amendment did not defer. | Ours to list, yours to do | A checklist row with its own date |
| Article 72 — post-market monitoring | We found no support for this in what we have built. MVP searched 245 shipped source files, 44 migrations, 14 obligation templates, 15 export columns and 12 Annex IV limbs, on the article number and on the provision's own words: nothing on any of the five. | Neither — there is nothing here to divide | Nothing |
| Article 73 — serious incident reporting | We found no support for this in what we have built. Same search, same five places: nothing. | Neither — there is nothing here to divide | Nothing |
| Article 43 — conformity assessment | We found no support for this in what we have built. The same search found the number in one file — a comment using it as an example of the Official Journal's citation form — and the words in six, every one of them quoting Article 6(1), point (b)'s third-party condition, an Article 5 sentence or a section name. No template, no column, no limb. | Neither — there is nothing here to divide | Nothing |
Four fields: a status, an owner, an evidence link and a note. The status is one of not started, in progress, complete or blocked. There is no file upload — the evidence is a link to where the document lives, not the document. And there is no way to mark a single obligation not applicable: what the product has is an Article 6(3) claim against the whole system, with a mandatory reason, which decides which obligations it reaches. If you need a row-by-row not-applicable with a justification per row, we do not have it.
Model drafting is planned for Starter and is not built yet. When it ships, three of the sections above will be drafted for you from what you have already recorded, and the product will mark them as what they are: “Generated from what you have recorded. It stays a draft until a named person marks it as reviewed.” The drafting is designed to be kept away from the classification — the engine that decides risk will not read the drafts, and the drafts will not reach the engine.
Three of those rows say we found no support for them in what we have built, and that is the honest shape of the product: post-market monitoring, incident reporting and formal conformity assessment are not things this does, and pointing you at ourselves for them would waste your quarter. The wording is deliberate — we searched our own repository and found nothing, which is a smaller claim than saying the feature does not exist, and it is the one we can stand behind. Standing behind a claim is not the same as your being able to test it, so how to check the claims on this site instead of taking them is written down separately. Conformity assessment in particular is a notified body's job for the routes that need one, not software's. And the documentation row is smaller than it looks. Four sections of Annex IV is not Annex IV.
Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.
Complipath is built by Yobel Tzegai in Gothenburg, Sweden.
Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.
We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.