Back to the kit

Evidence Kit · Samples

Full samples, nothing held back

These are complete documents, generated for a fictional company — Northwind Talent, a recruiter whose CV-ranking tool lands in Annex III point 4. Nothing is truncated and nothing is watermarked. If they are not worth paying for, you will know before you pay.

Placeholders marked [to be completed] are deliberate: they are the points where only you can supply the fact, and a blank invites the conversation that a confident guess would skip.

Sample. Fictional organisation and system. Do not use this as your own record — the reasoning in it belongs to a company that does not exist.

AI Act classification memorandum

CandidateRank (version 2.4) — Northwind Talent GmbH, HRB 998877, Berlin

Prepared for internal record and for production to national competent authorities on request. Supporting record for the classification reached.

1. Purpose and status of this document

Art. 6(4); Art. 49(2)

This memorandum records the risk classification of the AI system identified below under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026, the reasoning behind it, and the obligations that follow. It is written to be handed to a national competent authority without further preparation.

Where a provider concludes that an Annex III system is not high-risk, Article 6(4) makes documenting that assessment a legal duty. Where the conclusion is different — prohibited, high-risk, transparency-only or minimal — no provision compels a memorandum, but the same record is what every later obligation is built on, and it is the first thing an authority or an acquirer asks for.

2. Identification

Organisation
Northwind Talent GmbH, HRB 998877, Berlin
Country of establishment
Germany
AI system
CandidateRank (version 2.4)
Built by
In-house, built on a third-party general-purpose model via API
Assessment date
2026-09-11
Assessment owner
Jana Novak — Head of People Operations, acting AI compliance owner
Reviewed by
Not yet reviewed — see the review section

3. The system being assessed

Art. 3(1); Art. 3(12)

Intended purpose, as declared by the provider:

Intended purpose

Ranks inbound job applications by fit against the role description in order to produce a shortlist, which a recruiter reviews before any interview or rejection decision is taken.

Classification under the AI Act turns on the intended purpose, not on the technology used. A change to the intended purpose is therefore a change to the classification — see the obligations section.

People affected by its output
External job applicants in the EU; internal candidates applying for promotion.
Processes personal data
Yes
Placed on the market before 2 August 2026
Yes

4. Our role in relation to this system

Art. 3(3), 3(4); Art. 25

Role assessed
Both — we build it and use it ourselves

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority. The roles carry different obligations and the same organisation is frequently both.

5. Step one — prohibited practices

Art. 5

The Article 5 prohibitions were screened first, because a prohibited practice cannot be cured by documentation or a later deadline. The prohibitions in Article 5(1)(a) to (h) have applied since 2 February 2025. Two further prohibitions, inserted by Regulation (EU) 2026/1744 — Article 5(1)(ba) on non-consensual intimate imagery and Article 5(1)(bb) on child sexual abuse material — apply from 2 December 2026.

Conclusion: none of the Article 5 prohibitions applies to this system, on the basis of the intended purpose recorded above.

Practices identified
None

6. Step two — regulated products (Annex I)

Art. 6(1); Art. 2(2); Annex I

Article 6(1) has two cumulative conditions: the AI system is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I; and that product must undergo a third-party conformity assessment under that legislation. Both must be true.

Finding
No — it is not part of a regulated product, or the product self-certifies without a notified body

Conclusion: the Annex I route does not apply. The assessment therefore proceeds to Annex III.

7. Step three — use-case areas (Annex III)

Art. 6(2); Annex III

Annex III lists eight areas in which a stand-alone AI system is high-risk. Annex III itself was not amended by Regulation (EU) 2026/1744 and no delegated act under Article 7 has added to it.

Areas identified
Employment and workers management — recruitment, screening or ranking candidates, decisions on promotion, termination or task allocation, monitoring and evaluating workers

The system operates in an Annex III area, so the Article 6(3) filter below must be applied before any conclusion is drawn.

8. Step four — the Article 6(3) filter

Art. 6(3); Art. 3(52)

An Annex III system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights. Article 6(3) is satisfied where ANY ONE of four conditions is met: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from prior patterns and is not meant to replace or influence the previously completed human assessment without proper human review; or it performs a preparatory task to an assessment relevant to the Annex III use case.

Condition relied on
None of these — it materially influences the decision or outcome

Conclusion: the filter does not apply, either because the system materially influences the outcome or because it profiles natural persons. The system is high-risk under Article 6(2) and Annex III.

9. Steps five and six — transparency and general-purpose models

Art. 50; Chapter V

Transparency duties under Article 50 sit in Chapter IV and are independent of risk tier: a minimal-risk system can owe them, and a high-risk system owes them in addition to Chapter III. They have applied since 2 August 2026 and were not deferred.

Article 50 triggers identified
Interacts directly with people — chatbots, voice assistants, conversational agents; Generates synthetic audio, image, video or text content
General-purpose AI model placed on the market by us
No

The disclosure wordings and the marking policy that satisfy these triggers are set out in the companion Article 50 disclosure kit.

10. Conclusion and applicable dates

Art. 113 as amended

Classification
High-risk — Annex III use case + Transparency obligations — live now
DateWhat appliesBasisStatus
2 December 2027Chapter III, Sections 1–3 apply to Annex III high-risk systems (deferred from 2 August 2026 by Regulation (EU) 2026/1744; the deferral is unconditional — the proposed standards-readiness trigger was dropped).Art. 113(c)(i)Upcoming
2 August 2026Registration in the EU database (Article 49) is not deferred — it applies from the general application date.Art. 49; Art. 113Applies now
2 August 2026Article 50 transparency obligations apply.Art. 113Applies now
2 December 2026Generative systems placed on the market before 2 August 2026 have until this date to meet the Article 50(2) machine-readable marking duty.Art. 111(4) as inserted by Reg. (EU) 2026/1744Upcoming
Regulation (EU) 2026/1744 deferred the Chapter III high-risk regime to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). The deferral is unconditional: the standards-readiness trigger in the Commission's original proposal was dropped by the co-legislators. The general application date of 2 August 2026 was not moved, and enforcement began then.

Penalty exposure for the obligations identified: Most operator obligations, including Article 50: up to EUR 15 000 000 or 3% of worldwide annual turnover, whichever is higher (SMEs: whichever is lower, Art. 99(6)). Supplying incorrect information to authorities: up to EUR 7 500 000 or 1%.

11. Obligations that follow from this classification

  1. Register the system in the EU database under Article 49 before placing it on the market or putting it into service.
  2. Build the Articles 9 to 15 programme — risk management, data governance, technical documentation to Annex IV, automatic logging, instructions for deployers, human-oversight design, accuracy, robustness and cybersecurity.
  3. Establish a quality management system (Article 17), complete the conformity assessment (Article 43), draw up the EU declaration of conformity (Article 47) and affix the CE marking (Article 48).
  4. Operate post-market monitoring (Article 72) and serious-incident reporting (Article 73).
  5. Use the system in accordance with the instructions for use, assign human oversight to people with the necessary competence, training, authority and support (Article 26(2)), ensure input data under our control is relevant and sufficiently representative (Article 26(4)), and keep the automatically generated logs we control for at least six months (Article 26(6)).
  6. Inform workers' representatives and affected workers before putting the system into use in the workplace (Article 26(7)), and inform natural persons that they are subject to the system where it is used to make or assist decisions about them (Article 26(11)).
  7. Implement the Article 50 disclosures — these apply now, not in 2027.
  8. If the system generates synthetic content and was on the market before 2 August 2026, the Article 50(2) machine-readable marking duty must be met by 2 December 2026 under the new Article 111(4).
  9. Maintain a proportionate level of AI literacy among staff who deal with the system (Article 4, as rewritten by Regulation (EU) 2026/1744).

12. Review triggers and outstanding items

Art. 3(23); Art. 25; Art. 6(3)

This classification is valid for the intended purpose recorded above. It must be redone when any of the following happens:

  • The intended purpose changes, or the system is used for something it was not assessed for. Under Article 25 a change of intended purpose that makes a non-high-risk system high-risk moves the provider's obligations onto whoever made the change.
  • A substantial modification is made — a change after placing on the market or putting into service that was not foreseen or planned in the initial conformity assessment (Article 3(23)).
  • The system starts to profile natural persons, which defeats any reliance on Article 6(3).
  • We put our own name or trademark on a third-party high-risk system (Article 25).
  • The Commission adopts the final Article 6(5) classification guidelines, or amends Annex III by delegated act under Article 7.
Next scheduled review
[to be completed]
Review owner
Jana Novak

Assessment owner

Reviewer

Date

What a lawyer should check

Hand this list to counsel with the document. It is short on purpose — these are the points where a generated record most often diverges from the facts of a real organisation.

  1. Whether the intended purpose is the purpose actually marketed and actually used — misalignment here invalidates everything downstream.
  2. The role determination, particularly whether anything we do engages Article 25 and makes us a provider of a system we bought.
  3. Whether any Article 6(3) condition could in fact be relied on, which would change the classification and the deadline.
  4. Whether Article 27 applies to us on the facts, and whether the fundamental rights impact assessment can be combined with an existing DPIA under Article 27(4).
  5. The GDPR position in parallel: lawful basis, Article 22 automated decision-making, and whether a DPIA is required.
  6. Whether the conclusion reached should be disclosed to customers, insurers or investors, and whether any contract already warrants a different position.
  7. This document is a structured record of an assessment you made, drafted for your review. It is not legal advice and it does not bind any authority.
  8. It reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026. The Commission's guidelines on high-risk classification under Article 6(5) were due on 2 February 2026 and remain in draft (version of 19 May 2026), so classification positions that depend on them may change.
  9. No harmonised standard has yet been cited in the Official Journal, so the presumption of conformity in Article 40 is not available to anyone.
Generated by euai-act.com — a documented self-assessment, not legal advice.

Generate these for your own system

Run the free Navigator to classify your system, then the kit fills these documents in from your answers.