Versatile AI Risk Assessment

Who it is for AI providers and development teams

Developing AI and reviewing obligations

You develop AI systems, integrate models or adapt existing applications. Find out how to clarify your role under the EU AI Act, assess technical risks and review requirements for documentation, conformity assessment and operation.

The starting point

The provider role does not only arise from building from scratch. Under Art. 25(1) it is enough to place a bought-in system under your own name, to substantially modify it, or to change its intended purpose. Anyone integrating a model into their own product therefore checks these three points first.

The difference is considerable. For deployers the compass lists 24 obligations, for providers 32. Among them are the risk management system under Art. 9, the technical documentation under Annex IV, the quality management system under Art. 17, the conformity assessment under Art. 43 and registration in the EU database.

It is enough to place a bought-in system under your own name. The full set of provider obligations then applies: 32 instead of 24.

Art. 25(1)

Assessments step by step (4)

Each step links to the relevant features and information.

  1. Clarify the role Developing, adapting, rebranding or changing the purpose: each path leads into the provider role.
  2. Address pre-operational threats The seven from supply chain and development that are hard to detect later.
  3. Build the evidence Risk register, technical documentation under Annex IV, logging concept, instructions for use.
  4. Assess and register Conformity assessment, declaration, CE marking, entry in the EU database.

Questions and answers (12)

Answers with sources and links for further review.

Are we a provider or a deployer?

A provider is anyone who develops a system and places it on the market or puts it into service. Under Art. 25(1) a deployer also becomes a provider by placing a system under its own name, substantially modifying it, or changing its intended purpose. Fine-tuning a bought-in model for a different purpose falls under this.

What belongs in the technical documentation?

It follows Annex IV and must be drawn up before placing on the market. It demonstrates that the system meets the requirements and allows authorities and notified bodies to assess it. It grows with every version and is at once the basis of the conformity assessment and the later evidence towards market surveillance.

Evidence
Documentation with version state and release, kept for ten years

Do we need a notified body?

For most Annex III systems internal control under Annex VI is sufficient. For biometric systems a notified body may be required. Clarify this early and plan for their capacity; substantial modifications require the assessment to be run again.

When must we register the system?

Before placing on the market or putting into service, in the EU database maintained by the Commission, under Art. 49(1) and Annex VIII. The entries are publicly accessible: check the details beforehand for trade secrets and for consistency with the declaration of conformity.

What is a serious incident and how quickly must it be reported?

It must be reported to the market surveillance authority of the member state concerned, immediately after establishing the link to the system, at the latest 15 days after becoming aware. In severe cases the deadline shortens to two days. Decide in advance who reports, to which authority and on which form; two days is short.

Evidence
Reporting process with deadlines and responsibilities

Which threats arise before operation?

Seven of the 52: three from the supply chain, namely infrastructure, models and datasets, and four from development, namely training data poisoning, targeted label poisoning, a backdoor in the model, and time-triggered hidden instructions. These seven are hard to detect in operation and must therefore be addressed beforehand.

What does the regulation require technically from a high-risk system?

Art. 15 requires accuracy, robustness and cybersecurity at an appropriate level, maintained across the life cycle. Added to this are logging under Art. 12, instructions for use for deployers under Art. 13, enabling human oversight by design under Art. 14, and data governance under Art. 10.

What applies to systems that generate content?

Outputs must be marked machine-readably as artificially generated, under Art. 50(2). Check whether your output chain preserves the marking: watermarks and metadata are frequently lost once content is converted, cropped or passed on through third parties. Existing generative systems must be retrofitted by 2 December 2026.

From when do the provider obligations apply?

In stages. Conformity assessment, registration, post-market monitoring and incident reporting have applied since 2 August 2026. The requirements for high-risk systems under Annex III take effect from 2 December 2027, under Annex I from 2 August 2028. Two new prohibitions apply from 2 December 2026.

We train our own model. Does something different apply to us?

Yes. Anyone providing a general-purpose AI model carries a separate set of 14 obligations, regardless of whether a high-risk system results from it. These include the technical documentation of the model under Annex XI, a policy for complying with copyright law, and a public summary of the training content. If the cumulative training compute exceeds ten to the power of twenty-five floating-point operations, notification of systemic risk to the Commission applies on top.

Our model predates August 2025. Do we have a deadline?

Yes, 2 August 2027. By then existing general-purpose models must be brought in line with the obligations of Chapter V. The effort usually lies in documenting training data and compute retrospectively. Start with the summary of the training content, because it becomes public and therefore needs the longest coordination.

Evidence
Retrospective documentation per model, with a schedule

What does the application explicitly not do for development?

It does not produce technical documentation and does not fill in Annex IV. It performs no conformity assessment and replaces no notified body. It reports nothing to authorities and registers nothing in the EU database. It tests no model and measures no accuracy.

Limits of the application (4)

These tasks require additional tools or professional review.

Tasks outside the application

  • It does not produce technical documentation and does not fill in Annex IV.
  • It performs no conformity assessment and replaces no notified body.
  • It registers nothing in the EU database and reports no incident.
  • It tests no model, measures no accuracy and verifies no robustness.

Suitable editions

€2,490 once

Professional Offline

For regular work across several systems: reports as PDF and workbook, machine-readable exports, extended evidence packages.

Open
free of charge

Live demo to get to know it

The complete Community Edition with example data, directly in the browser and without sign-up. For trying out the method; your own work inside a company or a public body is not covered by the Community licence.

Open

Compare the features, licence terms and prices of the Community, Professional and Enterprise editions. Compare editions

Other audiences (7)

Guidance for other responsibilities within your organisation or your clients’ organisations.

← Back to the overview