Cell Register
Standards ยท AI Act

EU AI Act (Regulation (EU) 2024/1689)

Rendered when the buyer ticks "EU AI Act deployer". The register cites 8 of its 43 clauses, behind 1 finding: adaptive controller with no human oversight noted, and on the obligation rows of every asset it reaches. Binds Articles 26 and 4 bind the deployer, which is the asset owner using the system; Articles 12 to 15 bind the provider; a deployer that substantially modifies the system becomes its provider.

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches on the register: the AI Act regime page.

Clauses cited

8 of 43
AI Act Art. 6 Classification rules for high-risk AI systems

Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.

Evidence an auditor accepts: A classification record per AI system naming the Annex I legislation or the Annex III use case considered, and the conclusion reached; The documented Art.6(3) assessment where an Annex III system is judged not high-risk, dated before placing on the market; Evidence the profiling rule was applied, so any system profiling natural persons is classified high-risk regardless of the derogation
Common gap: Classification decided once at design time and never revisited when the intended purpose broadened
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

Evidence an auditor accepts: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable
Common gap: Deployer not following IFU
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 4 AI literacy

Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.

Evidence an auditor accepts: A register of the staff and contracted persons who operate or use AI systems on the organisation's behalf; Training content differentiated by role, prior technical knowledge and the deployment context; Attendance, completion and comprehension records per cohort
Common gap: One generic awareness module issued to everyone regardless of role or technical starting point
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 14 Human oversight

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of automation bias, correctly interpret the output, decide not to use the output or override or reverse it, intervene in operation, and stop the system.

Evidence an auditor accepts: Human-oversight design (UI, controls, alerts); Oversight-personnel training and authority
Common gap: Oversight is nominal (e.g. cannot stop the system in practice)
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 15 Accuracy, robustness and cybersecurity

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against attempts by unauthorised third parties to alter use, output or performance (incl data poisoning, model poisoning, adversarial examples and confidentiality attacks).

Evidence an auditor accepts: Accuracy/robustness measurements relevant to the intended purpose; Adversarial/data-poisoning threat modelling and mitigation; Cybersecurity controls aligned with state-of-the-art
Common gap: No adversarial-attack threat modelling
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 13 Transparency and provision of information to deployers

High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret the output and use it appropriately. Providers shall provide instructions for use including the system's intended purpose, level of accuracy/robustness/cybersecurity, foreseeable misuse, performance characteristics, human oversight measures, hardware/software requirements, lifetime and maintenance/care.

Evidence an auditor accepts: Instructions for use covering the Art.13 content list; Deployer-facing system documentation
Common gap: Generic IFU without the Art.13 content elements
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 12 Record-keeping (logs)

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the reference database against which input data has been checked, the input data for which the search led to a match, and the natural persons involved in the verification.

Evidence an auditor accepts: Logging capability design evidence; Log-retention policy aligned with the intended purpose
Common gap: Insufficient logging to reconstruct system operation
Source framework: EU AI Act (Regulation (EU) 2024/1689)
AI Act Art. 25 Responsibilities along the AI value chain

Distributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider, providing access to information, technical access and other assistance reasonably needed.

Evidence an auditor accepts: Documented allocation of provider status across the value chain; Cooperation agreements between original and new providers
Common gap: Substantial modification without taking on provider obligations
Source framework: EU AI Act (Regulation (EU) 2024/1689)

See which clauses your list engages

Paste the list and every asset names the clauses behind it, filtered to the regimes that apply to you. Eight assets free, no account.

Build my cell register