[
  {
    "runId": "f431ddef-3cdd-4976-ae6e-4360ee578ff5",
    "step": "assess",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T22:49:35.331Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T22:49:35.331Z",
    "updatedAt": "2026-08-18T22:49:35.350Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "ef4e5fc0-1450-47e3-8fb2-09acb1357c96",
    "step": "report",
    "inputs": {
      "system_description": "AI ActRadar helps EU compliance teams map AI systems to obligations under the EU AI Act and auto-generate risk registers.",
      "intended_users": "HR teams, recruiters, compliance officers",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-006",
            "title": "Human oversight (Art. 14)",
            "severity": "high",
            "remediation": "For high-risk systems, implement effective human oversight (Art. 14): mechanisms to understand, monitor, and override/interrupt the system. Do not ship fully autonomous decisions without review.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR teams, recruiters, compliance officers typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:35:40.992Z",
    "updatedAt": "2026-08-18T23:35:40.992Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "ee75442b-0c5f-4336-b2bc-2dce25ac674c",
    "step": "report",
    "inputs": {
      "system_description": "test",
      "intended_users": "test",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with test typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:45:11.998Z",
    "updatedAt": "2026-08-18T23:45:11.998Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "ed5227cb-1e8d-44a0-90bf-4bbc4b02bcc7",
    "step": "assess",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "High-volume hiring with automated decision support"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:19:51.231Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:19:51.230Z",
    "updatedAt": "2026-08-18T16:19:51.250Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "e9b05dfe-b223-4122-88a3-8be980ea35b4",
    "step": "report",
    "inputs": {},
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "modelText": "Describe your AI system to classify its EU AI Act risk tier."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:28:20.510Z",
    "updatedAt": "2026-08-18T23:28:20.510Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "e16adfa4-6824-4d12-8277-87b1943b8e5b",
    "step": "report",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR departments and recruiters typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:37:57.955Z",
    "updatedAt": "2026-08-18T16:37:57.955Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "e0cec715-c92d-4f9d-ab34-59ff371c9add",
    "step": "report",
    "inputs": {
      "system_description": "AI screener",
      "intended_users": "Recruiters",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with Recruiters typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:47:48.718Z",
    "updatedAt": "2026-08-18T23:47:48.718Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "de2f2f6e-996c-4b70-adc2-17232168566e",
    "step": "assess",
    "inputs": {},
    "artifacts": {
      "ingestedAt": "2026-07-22T21:46:02.747Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -721
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -536
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-07-22T21:46:02.746Z",
    "updatedAt": "2026-07-22T21:46:02.766Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "d9265df3-0e89-49ad-999a-bd58769835f4",
    "step": "report",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR departments and recruiters typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:37:30.963Z",
    "updatedAt": "2026-08-18T16:37:30.963Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "d82b30cb-41ac-4d4d-bc2e-3ee6065f9736",
    "step": "assess",
    "inputs": [],
    "artifacts": {
      "ingestedAt": "2026-08-18T16:11:21.530Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:11:21.530Z",
    "updatedAt": "2026-08-18T16:11:21.533Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "cbe6669a-0027-4372-b843-b9e0124f2527",
    "step": "assess",
    "inputs": {
      "system_description": "test",
      "intended_users": "HR",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:03:29.685Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:03:29.685Z",
    "updatedAt": "2026-08-19T00:03:29.688Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "cbb2b063-919b-4387-9e8a-6fb674a233ba",
    "step": "report",
    "inputs": {
      "threat_focus": "Prompt injection",
      "agent_description": "test",
      "capabilities": "test"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "modelText": "Describe your AI system to classify its EU AI Act risk tier."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T04:09:39.354Z",
    "updatedAt": "2026-08-19T04:09:39.354Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "cbafe1ef-5785-46ee-bfd2-a3bd9ae1bef5",
    "step": "assess",
    "inputs": {
      "system_description": "test"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:11:53.172Z",
      "inputKeys": [
        "system_description"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:11:53.172Z",
    "updatedAt": "2026-08-18T16:11:53.174Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "c027e8fe-d0a7-4f91-8710-e19652fcc6f1",
    "step": "report",
    "inputs": {},
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "modelText": "Describe your AI system to classify its EU AI Act risk tier."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:40:53.476Z",
    "updatedAt": "2026-08-18T23:40:53.476Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "b5e79655-6d22-43bb-823c-47cb01efc89e",
    "step": "report",
    "inputs": {},
    "artifacts": {
      "ingestedAt": "2026-08-18T16:38:29.236Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "highRisk": false,
      "modelText": "**Demo Mode: AI System Assessment**\n\nGiven the lack of specific information about the AI system, its intended users, and deployment context, I will provide a general assessment based on the EU AI Act's requirements.\n\n**Risk Tier:** Limited\nRationale: The risk tier is classified as Limited due to the absence of specific information about the AI system's capabilities, potential impact, and deployment context.\n\n**Applicable Obligations:**\n\n1. Under Art. 13, deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system where applicable.\n2. Compliance with the EU AI Act's general principles, including human oversight, data minimization, and transparency (Art. 12).\n\n**Key Deadlines:**\n\n1. The EU AI Act (Regulation 2024/1689) is expected to be implemented in phases, with the first phase focusing on high-risk AI systems. However, as this system is classified as Limited risk, it is likely to be subject to the second or third phase of implementation.\n2. The exact deadlines will depend on the EU's regulatory roadmap and the specific obligations applicable to the system.\n\n**Required Actions Checklist:**\n\n1. Gather information about the AI system's capabilities, limitations, and potential impact.\n2. Identify the intended users and deployment context.\n3. Conduct a risk assessment to determine the system's risk tier.\n4. Develop a compliance plan to address the applicable obligations, including transparency and user information.\n5. Establish a system for monitoring and reporting on the AI system's performance and any potential issues.\n6. Review and update the compliance plan as necessary to reflect changes in the system or regulatory requirements.\n\nPlease note that this assessment is in demo mode and is not a real compliance assessment. In a real-world scenario, a more detailed and specific assessment would be required based on the actual AI system, its intended users, and deployment context.",
      "analyze": {
        "findings": [
          {
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "evidence": "AIACT-005",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "summary": "**Demo Mode: AI System Assessment**\n\nGiven the lack of specific information about the AI system, its intended users, and deployment context, I will provide a general assessment based on the EU AI Act's requirements.\n\n**Risk Tier:** Limited\nRationale: The risk tier is classified as Limited due to the absence of specific information about the AI system's capabilities, potential impact, and deploymen"
      },
      "report": "EU AI ACT OBLIGATION MAP · run b5e79655-6d22-43bb-823c-47cb01efc89e\nSystem: (not provided)\nIntended users: ? · Context: Not sure\nRuleset: eu-ai-act@2026-07-21\nHigh-risk (Annex III): not flagged by rules\nInferred role (heuristic): deployer\n\n=== Rule-based findings (EU AI Act 2024/1689) ===\n- [medium] AIACT-005 Transparency & user information (Art. 13)\n  remediation: Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.\n\n=== Applicable phased deadlines (Digital Omnibus-adjusted) ===\n- 2024-08-01 · Entry into force of the AI Act (no obligations yet — transition clock starts) [748d ago] (AIACT-DL-01)\n- 2025-02-02 · Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply [563d ago] (AIACT-DL-02)\n\n=== Model-assisted obligation mapping ===\n**Demo Mode: AI System Assessment**\n\nGiven the lack of specific information about the AI system, its intended users, and deployment context, I will provide a general assessment based on the EU AI Act's requirements.\n\n**Risk Tier:** Limited\nRationale: The risk tier is classified as Limited due to the absence of specific information about the AI system's capabilities, potential impact, and deployment context.\n\n**Applicable Obligations:**\n\n1. Under Art. 13, deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system where applicable.\n2. Compliance with the EU AI Act's general principles, including human oversight, data minimization, and transparency (Art. 12).\n\n**Key Deadlines:**\n\n1. The EU AI Act (Regulation 2024/1689) is expected to be implemented in phases, with the first phase focusing on high-risk AI systems. However, as this system is classified as Limited risk, it is likely to be subject to the second or third phase of implementation.\n2. The exact deadlines will depend on the EU's regulatory roadmap and the specific obligations applicable to the system.\n\n**Required Actions Checklist:**\n\n1. Gather information about the AI system's capabilities, limitations, and potential impact.\n2. Identify the intended users and deployment context.\n3. Conduct a risk assessment to determine the system's risk tier.\n4. Develop a compliance plan to address the applicable obligations, including transparency and user information.\n5. Establish a system for monitoring and reporting on the AI system's performance and any potential issues.\n6. Review and update the compliance plan as necessary to reflect changes in the system or regulatory requirements.\n\nPlease note that this assessment is in demo mode and is not a real compliance assessment. In a real-world scenario, a more detailed and specific assessment would be required based on the actual AI system, its intended users, and deployment context.\n\n---\nSources: Rule-based checklist (eu-ai-act@2026-07-19) + Model-assisted mapping. This is decision-support, not legal advice."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:38:29.236Z",
    "updatedAt": "2026-08-18T16:38:31.398Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "b2fb7a18-18a9-4ed2-aa90-2af1e52e00a7",
    "step": "report",
    "inputs": {},
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "modelText": "Describe your AI system to classify its EU AI Act risk tier."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:28:12.037Z",
    "updatedAt": "2026-08-18T23:28:12.037Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "aff0026d-fb22-4dec-89d2-c7905f882df4",
    "step": "report",
    "inputs": {
      "system_description": "test AI screener",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:13:24.379Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true,
      "modelText": "**Risk Tier:** High-risk classification under Annex III\nRationale: The AI system, test AI screener, is intended for HR teams in the workplace, which aligns with a high-risk use case as per Annex III of the EU AI Act.\n\n**Applicable Obligations:**\n\n1. Risk management system (Art. 9)\n2. Technical documentation (Annex IV, Art. 11)\n3. Human oversight (Chapter III, Section 2)\n4. Accuracy (Chapter III, Section 2)\n5. Conformity assessment & CE marking (Art. 43)\n\n**Key Deadlines:**\n\n1. Draft technical documentation file (Annex IV) before market placement.\n2. Establish a continuous risk-management system (Art. 9) before market placement.\n3. Complete conformity assessment (Art. 43) and obtain CE marking before EU market placement.\n\n**Required Actions Checklist:**\n\n1. Identify known and foreseeable risks associated with the AI system.\n2. Mitigate and monitor the identified risks through a continuous risk-management system.\n3. Draft a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence.\n4. Establish a human oversight mechanism to ensure the AI system's accuracy and reliability.\n5. Engage a notified body for conformity assessment (Art. 43) if required.\n6. Obtain CE marking before EU market placement.\n7. Inform users (HR teams) about the AI system's capabilities and limitations (Art. 13).",
      "analyze": {
        "findings": [
          {
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "evidence": "AIACT-001",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "evidence": "AIACT-002",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "evidence": "AIACT-003",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "evidence": "AIACT-005",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "evidence": "AIACT-007",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "summary": "**Risk Tier:** High-risk classification under Annex III\nRationale: The AI system, test AI screener, is intended for HR teams in the workplace, which aligns with a high-risk use case as per Annex III of the EU AI Act.\n\n**Applicable Obligations:**\n\n1. Risk management system (Art. 9)\n2. Technical documentation (Annex IV, Art. 11)\n3. Human oversight (Chapter III, Section 2)\n4. Accuracy (Chapter III, S"
      },
      "report": "EU AI ACT OBLIGATION MAP · run aff0026d-fb22-4dec-89d2-c7905f882df4\nSystem: test AI screener\nIntended users: HR teams · Context: Workplace / HR\nRuleset: eu-ai-act@2026-07-21\nHigh-risk (Annex III): LIKELY — confirm with legal\nInferred role (heuristic): deployer\n\n=== Rule-based findings (EU AI Act 2024/1689) ===\n- [high] AIACT-001 High-risk classification under Annex III\n  remediation: If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).\n- [high] AIACT-002 Annex IV technical documentation (Art. 11 / Annex IV)\n  remediation: High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.\n- [high] AIACT-003 Risk management system (Art. 9)\n  remediation: Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.\n- [medium] AIACT-005 Transparency & user information (Art. 13)\n  remediation: Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.\n- [high] AIACT-007 Conformity assessment & CE marking (Art. 43)\n  remediation: High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.\n\n=== Applicable phased deadlines (Digital Omnibus-adjusted) ===\n- 2024-08-01 · Entry into force of the AI Act (no obligations yet — transition clock starts) [748d ago] (AIACT-DL-01)\n- 2025-02-02 · Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply [563d ago] (AIACT-DL-02)\n- 2026-08-02 · Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance [17d ago] (AIACT-DL-04)\n- 2027-12-02 · High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus) [470d left] (AIACT-DL-06)\n\n=== Model-assisted obligation mapping ===\n**Risk Tier:** High-risk classification under Annex III\nRationale: The AI system, test AI screener, is intended for HR teams in the workplace, which aligns with a high-risk use case as per Annex III of the EU AI Act.\n\n**Applicable Obligations:**\n\n1. Risk management system (Art. 9)\n2. Technical documentation (Annex IV, Art. 11)\n3. Human oversight (Chapter III, Section 2)\n4. Accuracy (Chapter III, Section 2)\n5. Conformity assessment & CE marking (Art. 43)\n\n**Key Deadlines:**\n\n1. Draft technical documentation file (Annex IV) before market placement.\n2. Establish a continuous risk-management system (Art. 9) before market placement.\n3. Complete conformity assessment (Art. 43) and obtain CE marking before EU market placement.\n\n**Required Actions Checklist:**\n\n1. Identify known and foreseeable risks associated with the AI system.\n2. Mitigate and monitor the identified risks through a continuous risk-management system.\n3. Draft a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence.\n4. Establish a human oversight mechanism to ensure the AI system's accuracy and reliability.\n5. Engage a notified body for conformity assessment (Art. 43) if required.\n6. Obtain CE marking before EU market placement.\n7. Inform users (HR teams) about the AI system's capabilities and limitations (Art. 13).\n\n---\nSources: Rule-based checklist (eu-ai-act@2026-07-19) + Model-assisted mapping. This is decision-support, not legal advice."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:13:24.378Z",
    "updatedAt": "2026-08-19T00:13:25.999Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "aa063734-f0b3-48d1-9f40-bfb36aa84d94",
    "step": "report",
    "inputs": {
      "system_description": "pre-browser smoke test",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:19:02.073Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true,
      "modelText": "(1) **High-risk**: The system matches an Annex III use case (pre-browser smoke test for HR teams), which involves high-risk classification under Annex III.\n\n(2) **Applicable obligations:**\n\n- Meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy)\n- Establish a continuous risk-management system (Art. 9)\n- Draft a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Conduct a conformity assessment (Art. 43), obtain a Declaration of Conformity, and apply CE marking before EU market placement\n- Engage a notified body if required for conformity assessment\n\n(3) **Key deadlines:**\n\n- Draft technical documentation (Annex IV) before market placement\n- Complete conformity assessment and obtain CE marking before EU market placement\n- Establish a continuous risk-management system (Art. 9) and maintain it throughout the system's lifecycle\n\n(4) **Required actions checklist:**\n\n- Identify known and foreseeable risks associated with the pre-browser smoke test AI system\n- Mitigate and monitor the identified risks\n- Draft technical documentation (Annex IV) covering design, intended purpose, and conformity evidence\n- Conduct a conformity assessment (Art. 43) and obtain a Declaration of Conformity\n- Apply CE marking to the system before EU market placement\n- Engage a notified body if required for conformity assessment\n- Inform HR teams of the AI system's capabilities and limitations\n- Continuously monitor and update the risk-management system (Art. 9) throughout the system's lifecycle",
      "analyze": {
        "findings": [
          {
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "evidence": "AIACT-001",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "evidence": "AIACT-002",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "evidence": "AIACT-003",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "evidence": "AIACT-005",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "evidence": "AIACT-007",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "summary": "(1) **High-risk**: The system matches an Annex III use case (pre-browser smoke test for HR teams), which involves high-risk classification under Annex III.\n\n(2) **Applicable obligations:**\n\n- Meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy)\n- Establish a continuous risk-management system (Art. 9)\n- Draft a technical docu"
      },
      "report": "EU AI ACT OBLIGATION MAP · run aa063734-f0b3-48d1-9f40-bfb36aa84d94\nSystem: pre-browser smoke test\nIntended users: HR teams · Context: Workplace / HR\nRuleset: eu-ai-act@2026-07-21\nHigh-risk (Annex III): LIKELY — confirm with legal\nInferred role (heuristic): deployer\n\n=== Rule-based findings (EU AI Act 2024/1689) ===\n- [high] AIACT-001 High-risk classification under Annex III\n  remediation: If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).\n- [high] AIACT-002 Annex IV technical documentation (Art. 11 / Annex IV)\n  remediation: High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.\n- [high] AIACT-003 Risk management system (Art. 9)\n  remediation: Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.\n- [medium] AIACT-005 Transparency & user information (Art. 13)\n  remediation: Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.\n- [high] AIACT-007 Conformity assessment & CE marking (Art. 43)\n  remediation: High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.\n\n=== Applicable phased deadlines (Digital Omnibus-adjusted) ===\n- 2024-08-01 · Entry into force of the AI Act (no obligations yet — transition clock starts) [748d ago] (AIACT-DL-01)\n- 2025-02-02 · Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply [563d ago] (AIACT-DL-02)\n- 2026-08-02 · Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance [17d ago] (AIACT-DL-04)\n- 2027-12-02 · High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus) [470d left] (AIACT-DL-06)\n\n=== Model-assisted obligation mapping ===\n(1) **High-risk**: The system matches an Annex III use case (pre-browser smoke test for HR teams), which involves high-risk classification under Annex III.\n\n(2) **Applicable obligations:**\n\n- Meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy)\n- Establish a continuous risk-management system (Art. 9)\n- Draft a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Conduct a conformity assessment (Art. 43), obtain a Declaration of Conformity, and apply CE marking before EU market placement\n- Engage a notified body if required for conformity assessment\n\n(3) **Key deadlines:**\n\n- Draft technical documentation (Annex IV) before market placement\n- Complete conformity assessment and obtain CE marking before EU market placement\n- Establish a continuous risk-management system (Art. 9) and maintain it throughout the system's lifecycle\n\n(4) **Required actions checklist:**\n\n- Identify known and foreseeable risks associated with the pre-browser smoke test AI system\n- Mitigate and monitor the identified risks\n- Draft technical documentation (Annex IV) covering design, intended purpose, and conformity evidence\n- Conduct a conformity assessment (Art. 43) and obtain a Declaration of Conformity\n- Apply CE marking to the system before EU market placement\n- Engage a notified body if required for conformity assessment\n- Inform HR teams of the AI system's capabilities and limitations\n- Continuously monitor and update the risk-management system (Art. 9) throughout the system's lifecycle\n\n---\nSources: Rule-based checklist (eu-ai-act@2026-07-19) + Model-assisted mapping. This is decision-support, not legal advice."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:19:02.072Z",
    "updatedAt": "2026-08-19T00:19:04.259Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "a7e39753-c93e-4f38-bf3e-818077160f7c",
    "step": "report",
    "inputs": {
      "system_description": "AI CV screener",
      "intended_users": "HR teams",
      "risk_context": "Recruitment"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Recruitment context with HR teams typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:11:42.674Z",
    "updatedAt": "2026-08-18T16:11:42.674Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "9c8a81a5-a3ad-4a02-9864-5441ac18fea9",
    "step": "report",
    "inputs": {
      "system_description": "An AI hiring tool that screens job applicants' resumes and scores them based on qualifications",
      "intended_users": "HR teams, recruiters, hiring managers",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR teams, recruiters, hiring managers typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T15:25:53.443Z",
    "updatedAt": "2026-08-18T15:25:53.443Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "9a9bba84-9bff-415a-a587-72dda8da8529",
    "step": "assess",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T22:46:30.263Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T22:46:30.263Z",
    "updatedAt": "2026-08-18T22:46:30.283Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "9a6b2de0-9c5a-43bd-b800-67acab35a573",
    "step": "assess",
    "inputs": [],
    "artifacts": {
      "ingestedAt": "2026-08-18T16:11:20.908Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:11:20.908Z",
    "updatedAt": "2026-08-18T16:11:20.928Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "99129803-5243-4a8f-a362-610bc83f1e1a",
    "step": "assess",
    "inputs": {
      "system_description": "test",
      "intended_users": "HR",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:02:17.654Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:02:17.654Z",
    "updatedAt": "2026-08-19T00:02:17.656Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "97e5bf0c-5a46-445e-b66f-6c33ff2f28a7",
    "step": "assess",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "High-volume hiring with automated decision support"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:18:19.942Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:18:19.942Z",
    "updatedAt": "2026-08-18T16:18:19.960Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "8fbdd204-14ac-469d-9904-cd7d52bfe06e",
    "step": "assess",
    "inputs": {
      "system_description": "final test AI screener",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:06:06.614Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:06:06.614Z",
    "updatedAt": "2026-08-19T00:06:06.633Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "8dcc4be8-1da4-44f2-bcc2-8a86b5bcb8e8",
    "step": "report",
    "inputs": {
      "system_description": "An AI tool that screens job applicants' CVs",
      "intended_users": "HR teams, recruiters"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Not sure context with HR teams, recruiters typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T15:45:22.912Z",
    "updatedAt": "2026-08-18T15:45:22.912Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "88c1e13a-169a-45c0-99a4-263fd76d7ee7",
    "step": "assess",
    "inputs": {
      "system_description": "test AI CV screener for quota check",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:01:26.202Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:01:26.202Z",
    "updatedAt": "2026-08-19T00:01:26.205Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "7d2b3deb-1391-4a48-a53a-73e1c8861daf",
    "step": "assess",
    "inputs": {
      "system_description": "test AI CV screener after restart",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:03:20.072Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:03:20.071Z",
    "updatedAt": "2026-08-19T00:03:20.090Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "7b3784ed-2e0d-44bc-bf88-11b1f983429e",
    "step": "assess",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "High-volume hiring with automated decision support"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:26:39.993Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:26:39.992Z",
    "updatedAt": "2026-08-18T16:26:40.012Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "6febbaf9-1656-4a85-af19-14bb0d0c7965",
    "step": "report",
    "inputs": {
      "system_description": "HR resume screening AI",
      "users": "employees",
      "context": "workplace-HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -722
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -537
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 9
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 496
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Not sure context with broad users typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-07-23T14:09:08.320Z",
    "updatedAt": "2026-07-23T14:09:08.320Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "67f6d486-4ebd-4f21-a63b-185e4b7350d9",
    "step": "assess",
    "inputs": {
      "system_description": "test chatbot",
      "intended_users": "HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T22:52:58.286Z",
      "inputKeys": [
        "system_description",
        "intended_users"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T22:52:58.286Z",
    "updatedAt": "2026-08-18T22:52:58.306Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "64e3f8fc-2219-42a2-a364-a270ecdd47d5",
    "step": "assess",
    "inputs": {
      "system_description": "test chatbot",
      "intended_users": "HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T22:52:04.409Z",
      "inputKeys": [
        "system_description",
        "intended_users"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T22:52:04.409Z",
    "updatedAt": "2026-08-18T22:52:04.412Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "5c67622e-ec91-4bd9-8c86-5d28fdc40613",
    "step": "report",
    "inputs": {
      "system_description": "An AI tool that screens job applicants CVs and ranks candidates",
      "intended_users": "HR teams, recruiters",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -746
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -561
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -15
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 472
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR teams, recruiters typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-16T16:26:01.294Z",
    "updatedAt": "2026-08-16T16:26:01.294Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "52933370-7277-4e51-8fbe-e2c392c5a60e",
    "step": "report",
    "inputs": {
      "system_description": "An AI resume screening tool that uses NLP to match candidates to job descriptions",
      "intended_users": "HR teams and recruiters"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Not sure context with HR teams and recruiters typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:26:31.267Z",
    "updatedAt": "2026-08-18T23:26:31.267Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "4e36a922-a500-435b-9701-e887407c175a",
    "step": "report",
    "inputs": {
      "system_description": "AI CV screener",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR teams typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:43:34.939Z",
    "updatedAt": "2026-08-18T23:43:34.939Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "4b6855c5-e3a3-4869-bf5c-1cbbe4cc51ad",
    "step": "assess",
    "inputs": {
      "system_description": "test chatbot",
      "intended_users": "HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T22:51:51.089Z",
      "inputKeys": [
        "system_description",
        "intended_users"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T22:51:51.089Z",
    "updatedAt": "2026-08-18T22:51:51.108Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "3f8158f7-5d7c-4cd8-aca3-7a4a5f1d5ce3",
    "step": "assess",
    "inputs": {
      "system_description": "final AI screener after hardcode",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:06:29.573Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:06:29.573Z",
    "updatedAt": "2026-08-19T00:06:29.577Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "3f0807ec-65ac-408c-9621-5a6daccdc91f",
    "step": "report",
    "inputs": {},
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "modelText": "Describe your AI system to classify its EU AI Act risk tier."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:37:51.220Z",
    "updatedAt": "2026-08-18T23:37:51.220Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "3e758300-5a97-4fd3-a1e7-765bff29a228",
    "step": "assess",
    "inputs": {
      "system_description": "test",
      "intended_users": "HR",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:02:24.756Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:02:24.756Z",
    "updatedAt": "2026-08-19T00:02:24.758Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "2d3e3dfc-c1bb-4a98-88f5-a63d13679102",
    "step": "report",
    "inputs": {
      "risk_context": "Workplace / HR",
      "intended_users": "HR departments and recruiters",
      "system_description": "AI-powered recruitment chatbot for candidate screening"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:38:59.836Z",
      "inputKeys": [
        "risk_context",
        "intended_users",
        "system_description"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true,
      "modelText": "Based on the provided description, I will assess the AI system according to the EU AI Act rules.\n\n(1) Risk Tier: High-risk classification under Annex III (rationale: The AI system matches an Annex III use case as it is an AI-powered recruitment chatbot for candidate screening, which is a high-risk use case due to potential biases in decision-making and impact on employment opportunities.)\n\n(2) Applicable Obligations:\n- Establish a risk management system (Art. 9)\n- Develop a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy)\n- Deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system (Art. 13)\n- Conduct a conformity assessment (Art. 43), a Declaration of Conformity, and obtain CE marking before EU market placement\n\n(3) Key Deadlines:\n- Draft the technical documentation file (Annex IV) before market placement\n- Complete the conformity assessment (Art. 43) and obtain CE marking before EU market placement\n\n(4) Required Actions Checklist:\n- Identify known and foreseeable risks associated with the AI system\n- Mitigate and monitor the identified risks\n- Develop a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Establish a risk management system (Art. 9) to cover the lifecycle of the AI system\n- Inform deployers of the AI system's capabilities and limitations\n- Engage a notified body for conformity assessment (Art. 43) if required\n- Obtain CE marking before EU market placement",
      "analyze": {
        "findings": [
          {
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "evidence": "AIACT-001",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "evidence": "AIACT-002",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "evidence": "AIACT-003",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "evidence": "AIACT-005",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "evidence": "AIACT-007",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "summary": "Based on the provided description, I will assess the AI system according to the EU AI Act rules.\n\n(1) Risk Tier: High-risk classification under Annex III (rationale: The AI system matches an Annex III use case as it is an AI-powered recruitment chatbot for candidate screening, which is a high-risk use case due to potential biases in decision-making and impact on employment opportunities.)\n\n(2) App"
      },
      "report": "EU AI ACT OBLIGATION MAP · run 2d3e3dfc-c1bb-4a98-88f5-a63d13679102\nSystem: AI-powered recruitment chatbot for candidate screening\nIntended users: HR departments and recruiters · Context: Workplace / HR\nRuleset: eu-ai-act@2026-07-21\nHigh-risk (Annex III): LIKELY — confirm with legal\nInferred role (heuristic): deployer\n\n=== Rule-based findings (EU AI Act 2024/1689) ===\n- [high] AIACT-001 High-risk classification under Annex III\n  remediation: If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).\n- [high] AIACT-002 Annex IV technical documentation (Art. 11 / Annex IV)\n  remediation: High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.\n- [high] AIACT-003 Risk management system (Art. 9)\n  remediation: Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.\n- [medium] AIACT-005 Transparency & user information (Art. 13)\n  remediation: Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.\n- [high] AIACT-007 Conformity assessment & CE marking (Art. 43)\n  remediation: High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.\n\n=== Applicable phased deadlines (Digital Omnibus-adjusted) ===\n- 2024-08-01 · Entry into force of the AI Act (no obligations yet — transition clock starts) [748d ago] (AIACT-DL-01)\n- 2025-02-02 · Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply [563d ago] (AIACT-DL-02)\n- 2025-08-02 · GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply [382d ago] (AIACT-DL-03)\n- 2026-08-02 · Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance [17d ago] (AIACT-DL-04)\n- 2026-12-02 · New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply [105d left] (AIACT-DL-05)\n- 2027-12-02 · High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus) [470d left] (AIACT-DL-06)\n\n=== Model-assisted obligation mapping ===\nBased on the provided description, I will assess the AI system according to the EU AI Act rules.\n\n(1) Risk Tier: High-risk classification under Annex III (rationale: The AI system matches an Annex III use case as it is an AI-powered recruitment chatbot for candidate screening, which is a high-risk use case due to potential biases in decision-making and impact on employment opportunities.)\n\n(2) Applicable Obligations:\n- Establish a risk management system (Art. 9)\n- Develop a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy)\n- Deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system (Art. 13)\n- Conduct a conformity assessment (Art. 43), a Declaration of Conformity, and obtain CE marking before EU market placement\n\n(3) Key Deadlines:\n- Draft the technical documentation file (Annex IV) before market placement\n- Complete the conformity assessment (Art. 43) and obtain CE marking before EU market placement\n\n(4) Required Actions Checklist:\n- Identify known and foreseeable risks associated with the AI system\n- Mitigate and monitor the identified risks\n- Develop a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Establish a risk management system (Art. 9) to cover the lifecycle of the AI system\n- Inform deployers of the AI system's capabilities and limitations\n- Engage a notified body for conformity assessment (Art. 43) if required\n- Obtain CE marking before EU market placement\n\n---\nSources: Rule-based checklist (eu-ai-act@2026-07-19) + Model-assisted mapping. This is decision-support, not legal advice."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:38:59.835Z",
    "updatedAt": "2026-08-18T16:39:01.682Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "2bff8ed7-256a-414d-8289-365648fcb50c",
    "step": "assess",
    "inputs": {},
    "artifacts": {
      "ingestedAt": "2026-07-22T21:32:14.995Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -721
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -536
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-07-22T21:32:14.995Z",
    "updatedAt": "2026-07-22T21:32:15.017Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "26a0e9de-3970-4168-b309-03dd4c45cfcd",
    "step": "report",
    "inputs": {
      "system_description": "AI CV screener",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR teams typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:41:44.145Z",
    "updatedAt": "2026-08-18T23:41:44.145Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "249089e5-c97c-4dfd-b2fa-28fa619ae936",
    "step": "report",
    "inputs": {},
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "modelText": "Describe your AI system to classify its EU AI Act risk tier."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:46:12.551Z",
    "updatedAt": "2026-08-18T23:46:12.551Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "1af2ad59-c0b7-437c-85c1-c65b01d9e8c8",
    "step": "assess",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "High-volume hiring with automated decision support"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:27:09.068Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:27:09.068Z",
    "updatedAt": "2026-08-18T16:27:09.072Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "15d41903-cd73-48a2-a3dd-b3d1ff498048",
    "step": "assess",
    "inputs": {},
    "artifacts": {
      "ingestedAt": "2026-08-19T04:08:41.628Z",
      "inputKeys": [],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "highRisk": false
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T04:08:41.628Z",
    "updatedAt": "2026-08-19T04:08:41.632Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "13ae5ccb-d523-45ab-ad11-bcf69b7f6c21",
    "step": "report",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "modelText": "EU AI ACT RISK ASSESSMENT\n\nRisk tier: HIGH-RISK\nRationale: A system used in Workplace / HR context with HR departments and recruiters typically falls under Annex III high-risk categories.\n\nApplicable obligations:\n  - Conformity assessment (Art. 43)\n  - Technical documentation (Art. 11)\n  - Human oversight (Art. 14)\n  - Risk management system (Art. 9)\n\nKey deadlines:\n  - High-risk (Annex III) obligations apply from 2 Dec 2027 (post Digital Omnibus)\n\nRequired actions checklist:\n  - [ ] Map system to Annex III use case\n  - [ ] Draft Art. 11 technical file\n  - [ ] Implement human-in-the-loop review\n\n--- (Mock demo. Pro unlocks continuous monitoring + deadline tracking.)"
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:36:33.325Z",
    "updatedAt": "2026-08-18T16:36:33.325Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "128f8805-93bc-4a37-9a10-e2eefd0983e1",
    "step": "assess",
    "inputs": {
      "system_description": "test AI CV screener",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:02:07.167Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:02:07.167Z",
    "updatedAt": "2026-08-19T00:02:07.169Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "11978ee5-1056-4d96-8402-1cddb7098dd0",
    "step": "assess",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "High-volume hiring with automated decision support"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:28:36.620Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:28:36.619Z",
    "updatedAt": "2026-08-18T16:28:36.637Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  },
  {
    "runId": "0fbc27a8-785d-416d-8d16-0de2482bff74",
    "step": "report",
    "inputs": {},
    "artifacts": {
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          }
        ]
      },
      "modelText": "Describe your AI system to classify its EU AI Act risk tier."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T23:34:30.937Z",
    "updatedAt": "2026-08-18T23:34:30.937Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "0c4d053f-0e46-4712-a517-1d5a3f8252f7",
    "step": "report",
    "inputs": {
      "system_description": "AI-powered recruitment chatbot for candidate screening",
      "intended_users": "HR departments and recruiters",
      "risk_context": "High-volume hiring with automated decision support"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T16:32:52.587Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true,
      "modelText": "Based on the provided description, I will classify the AI system and provide the required compliance information.\n\n(1) Risk Tier: **High-risk** because the AI-powered recruitment chatbot for candidate screening matches an Annex III use case (high-volume hiring with automated decision support), which requires meeting Chapter III Section 2 requirements.\n\n(2) Applicable Obligations:\n- Establish a continuous risk-management system (Art. 9)\n- Draft and maintain a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy)\n- Deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system (Art. 13)\n- Conduct a conformity assessment (Art. 43), obtain a Declaration of Conformity, and affix CE marking before EU market placement\n\n(3) Key Deadlines:\n- Draft technical documentation file (Annex IV) before market placement\n- Conduct conformity assessment (Art. 43) and obtain Declaration of Conformity before EU market placement\n- Engage a notified body if required for conformity assessment\n\n(4) Required Actions Checklist:\n- Identify known and foreseeable risks associated with the AI system\n- Mitigate and monitor identified risks\n- Develop a risk management plan\n- Create technical documentation file (Annex IV)\n- Engage a notified body for conformity assessment if required\n- Conduct conformity assessment (Art. 43)\n- Obtain Declaration of Conformity\n- Affix CE marking before EU market placement\n- Inform users of the AI system's capabilities and limitations\n- Continuously monitor and update the risk management system",
      "analyze": {
        "findings": [
          {
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "evidence": "AIACT-001",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "evidence": "AIACT-002",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "evidence": "AIACT-003",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "evidence": "AIACT-005",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "evidence": "AIACT-007",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "summary": "Based on the provided description, I will classify the AI system and provide the required compliance information.\n\n(1) Risk Tier: **High-risk** because the AI-powered recruitment chatbot for candidate screening matches an Annex III use case (high-volume hiring with automated decision support), which requires meeting Chapter III Section 2 requirements.\n\n(2) Applicable Obligations:\n- Establish a con"
      },
      "report": "EU AI ACT OBLIGATION MAP · run 0c4d053f-0e46-4712-a517-1d5a3f8252f7\nSystem: AI-powered recruitment chatbot for candidate screening\nIntended users: HR departments and recruiters · Context: High-volume hiring with automated decision support\nRuleset: eu-ai-act@2026-07-21\nHigh-risk (Annex III): LIKELY — confirm with legal\nInferred role (heuristic): deployer\n\n=== Rule-based findings (EU AI Act 2024/1689) ===\n- [high] AIACT-001 High-risk classification under Annex III\n  remediation: If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).\n- [high] AIACT-002 Annex IV technical documentation (Art. 11 / Annex IV)\n  remediation: High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.\n- [high] AIACT-003 Risk management system (Art. 9)\n  remediation: Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.\n- [medium] AIACT-005 Transparency & user information (Art. 13)\n  remediation: Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.\n- [high] AIACT-007 Conformity assessment & CE marking (Art. 43)\n  remediation: High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.\n\n=== Applicable phased deadlines (Digital Omnibus-adjusted) ===\n- 2024-08-01 · Entry into force of the AI Act (no obligations yet — transition clock starts) [748d ago] (AIACT-DL-01)\n- 2025-02-02 · Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply [563d ago] (AIACT-DL-02)\n- 2025-08-02 · GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply [382d ago] (AIACT-DL-03)\n- 2026-08-02 · Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance [17d ago] (AIACT-DL-04)\n- 2026-12-02 · New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply [105d left] (AIACT-DL-05)\n- 2027-12-02 · High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus) [470d left] (AIACT-DL-06)\n\n=== Model-assisted obligation mapping ===\nBased on the provided description, I will classify the AI system and provide the required compliance information.\n\n(1) Risk Tier: **High-risk** because the AI-powered recruitment chatbot for candidate screening matches an Annex III use case (high-volume hiring with automated decision support), which requires meeting Chapter III Section 2 requirements.\n\n(2) Applicable Obligations:\n- Establish a continuous risk-management system (Art. 9)\n- Draft and maintain a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence\n- Meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy)\n- Deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system (Art. 13)\n- Conduct a conformity assessment (Art. 43), obtain a Declaration of Conformity, and affix CE marking before EU market placement\n\n(3) Key Deadlines:\n- Draft technical documentation file (Annex IV) before market placement\n- Conduct conformity assessment (Art. 43) and obtain Declaration of Conformity before EU market placement\n- Engage a notified body if required for conformity assessment\n\n(4) Required Actions Checklist:\n- Identify known and foreseeable risks associated with the AI system\n- Mitigate and monitor identified risks\n- Develop a risk management plan\n- Create technical documentation file (Annex IV)\n- Engage a notified body for conformity assessment if required\n- Conduct conformity assessment (Art. 43)\n- Obtain Declaration of Conformity\n- Affix CE marking before EU market placement\n- Inform users of the AI system's capabilities and limitations\n- Continuously monitor and update the risk management system\n\n---\nSources: Rule-based checklist (eu-ai-act@2026-07-19) + Model-assisted mapping. This is decision-support, not legal advice."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T16:32:52.587Z",
    "updatedAt": "2026-08-18T16:32:55.506Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "063b7de6-7fc5-454b-9bcb-1d41cea205cd",
    "step": "report",
    "inputs": {
      "system_description": "test chatbot",
      "intended_users": "HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-18T22:56:03.262Z",
      "inputKeys": [
        "system_description",
        "intended_users"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "highRisk": false,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": true,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-03",
            "obligation": "GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply",
            "date": "2025-08-02",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -382
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-05",
            "obligation": "New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply",
            "date": "2026-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 105
          }
        ]
      },
      "highRisk": false,
      "modelText": "**Risk Tier:** Minimal\nRationale: The test chatbot is likely a low-risk AI system intended for HR purposes, which does not involve decision-making or high-stakes interactions.\n\n**Applicable Obligations:**\n\n1. Under Art. 13, deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system where applicable (AIACT-005).\n2. Provide a clear and concise description of the AI system's functionality, including its capabilities and limitations, in the documentation and user interface (Art. 13).\n\n**Key Deadlines:**\n\n1. The AI system must be compliant with the EU AI Act by the date of deployment, which is not specified in this scenario.\n\n**Required Actions Checklist:**\n\n1. Document the AI system's capabilities and limitations in the user interface and documentation.\n2. Inform HR users that they are interacting with an AI system where applicable.\n3. Review and update the documentation and user interface to ensure compliance with Art. 13.\n4. Conduct a risk assessment to ensure the AI system does not pose any unacceptable risks to users or the public.\n\n**Note:** Since the deployment context is not provided, it is assumed that the AI system will be deployed in a manner that does not pose any unacceptable risks. If the deployment context involves high-stakes interactions or decision-making, the risk tier may be reevaluated.",
      "analyze": {
        "findings": [
          {
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "evidence": "AIACT-005",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          }
        ],
        "summary": "**Risk Tier:** Minimal\nRationale: The test chatbot is likely a low-risk AI system intended for HR purposes, which does not involve decision-making or high-stakes interactions.\n\n**Applicable Obligations:**\n\n1. Under Art. 13, deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system where applicable (AIACT-005).\n2. Provide a clear and"
      },
      "report": "EU AI ACT OBLIGATION MAP · run 063b7de6-7fc5-454b-9bcb-1d41cea205cd\nSystem: test chatbot\nIntended users: HR · Context: Not sure\nRuleset: eu-ai-act@2026-07-21\nHigh-risk (Annex III): not flagged by rules\nInferred role (heuristic): deployer\n\n=== Rule-based findings (EU AI Act 2024/1689) ===\n- [medium] AIACT-005 Transparency & user information (Art. 13)\n  remediation: Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.\n\n=== Applicable phased deadlines (Digital Omnibus-adjusted) ===\n- 2024-08-01 · Entry into force of the AI Act (no obligations yet — transition clock starts) [748d ago] (AIACT-DL-01)\n- 2025-02-02 · Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply [563d ago] (AIACT-DL-02)\n- 2025-08-02 · GPAI model rules (Chapter V) + EU governance structure (Chapter VII) apply [382d ago] (AIACT-DL-03)\n- 2026-08-02 · Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance [17d ago] (AIACT-DL-04)\n- 2026-12-02 · New prohibitions (non-consensual sexual deepfakes, CSAM) + Art. 50(2) synthetic-content transition apply [105d left] (AIACT-DL-05)\n\n=== Model-assisted obligation mapping ===\n**Risk Tier:** Minimal\nRationale: The test chatbot is likely a low-risk AI system intended for HR purposes, which does not involve decision-making or high-stakes interactions.\n\n**Applicable Obligations:**\n\n1. Under Art. 13, deployers must be informed of the AI system's capabilities and limitations, and that they are interacting with an AI system where applicable (AIACT-005).\n2. Provide a clear and concise description of the AI system's functionality, including its capabilities and limitations, in the documentation and user interface (Art. 13).\n\n**Key Deadlines:**\n\n1. The AI system must be compliant with the EU AI Act by the date of deployment, which is not specified in this scenario.\n\n**Required Actions Checklist:**\n\n1. Document the AI system's capabilities and limitations in the user interface and documentation.\n2. Inform HR users that they are interacting with an AI system where applicable.\n3. Review and update the documentation and user interface to ensure compliance with Art. 13.\n4. Conduct a risk assessment to ensure the AI system does not pose any unacceptable risks to users or the public.\n\n**Note:** Since the deployment context is not provided, it is assumed that the AI system will be deployed in a manner that does not pose any unacceptable risks. If the deployment context involves high-stakes interactions or decision-making, the risk tier may be reevaluated.\n\n---\nSources: Rule-based checklist (eu-ai-act@2026-07-19) + Model-assisted mapping. This is decision-support, not legal advice."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-18T22:56:03.261Z",
    "updatedAt": "2026-08-18T22:56:05.347Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "03e2b6b9-d5c5-42b1-92c9-49aa1fc0130c",
    "step": "report",
    "inputs": {
      "system_description": "An AI tool that screens job applicants' CVs for HR teams.",
      "intended_users": "HR teams, recruiters.",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:20:04.316Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true,
      "modelText": "Based on the provided information, I will assess the AI system according to the EU AI Act rules.\n\n(1) Risk Tier: **Limited**\nThe AI system is used for HR purposes, which does not match the high-risk use cases listed in Annex III. However, it still requires technical documentation and a risk management system, indicating a limited risk level.\n\n(2) Applicable Obligations:\n- Establish a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence.\n- Develop a risk management system (Art. 9) covering the lifecycle, including identifying known and foreseeable risks, mitigating, and monitoring them.\n- Ensure transparency and user information (Art. 13) by informing users about the AI system's capabilities and limitations.\n- Comply with conformity assessment and CE marking requirements (Art. 43) for EU market placement.\n\n(3) Key Deadlines:\n- Technical documentation: Before market placement (exact date not specified in the rules).\n- Risk management system: Establish and maintain throughout the system's lifecycle.\n- Conformity assessment and CE marking: Before EU market placement (exact date not specified in the rules).\n\n(4) Required Actions Checklist:\n- Draft the technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence.\n- Develop a risk management system (Art. 9) to identify, mitigate, and monitor risks throughout the system's lifecycle.\n- Inform users about the AI system's capabilities and limitations (Art. 13).\n- Engage in conformity assessment (Art. 43) and obtain CE marking before EU market placement, if required.\n- Maintain the risk management system and update the technical documentation file as necessary.",
      "analyze": {
        "findings": [
          {
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "evidence": "AIACT-001",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "evidence": "AIACT-002",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "evidence": "AIACT-003",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "evidence": "AIACT-005",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "evidence": "AIACT-007",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "summary": "Based on the provided information, I will assess the AI system according to the EU AI Act rules.\n\n(1) Risk Tier: **Limited**\nThe AI system is used for HR purposes, which does not match the high-risk use cases listed in Annex III. However, it still requires technical documentation and a risk management system, indicating a limited risk level.\n\n(2) Applicable Obligations:\n- Establish a technical doc"
      },
      "report": "EU AI ACT OBLIGATION MAP · run 03e2b6b9-d5c5-42b1-92c9-49aa1fc0130c\nSystem: An AI tool that screens job applicants' CVs for HR teams.\nIntended users: HR teams, recruiters. · Context: Workplace / HR\nRuleset: eu-ai-act@2026-07-21\nHigh-risk (Annex III): LIKELY — confirm with legal\nInferred role (heuristic): deployer\n\n=== Rule-based findings (EU AI Act 2024/1689) ===\n- [high] AIACT-001 High-risk classification under Annex III\n  remediation: If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).\n- [high] AIACT-002 Annex IV technical documentation (Art. 11 / Annex IV)\n  remediation: High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.\n- [high] AIACT-003 Risk management system (Art. 9)\n  remediation: Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.\n- [medium] AIACT-005 Transparency & user information (Art. 13)\n  remediation: Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.\n- [high] AIACT-007 Conformity assessment & CE marking (Art. 43)\n  remediation: High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.\n\n=== Applicable phased deadlines (Digital Omnibus-adjusted) ===\n- 2024-08-01 · Entry into force of the AI Act (no obligations yet — transition clock starts) [748d ago] (AIACT-DL-01)\n- 2025-02-02 · Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply [563d ago] (AIACT-DL-02)\n- 2026-08-02 · Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance [17d ago] (AIACT-DL-04)\n- 2027-12-02 · High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus) [470d left] (AIACT-DL-06)\n\n=== Model-assisted obligation mapping ===\nBased on the provided information, I will assess the AI system according to the EU AI Act rules.\n\n(1) Risk Tier: **Limited**\nThe AI system is used for HR purposes, which does not match the high-risk use cases listed in Annex III. However, it still requires technical documentation and a risk management system, indicating a limited risk level.\n\n(2) Applicable Obligations:\n- Establish a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence.\n- Develop a risk management system (Art. 9) covering the lifecycle, including identifying known and foreseeable risks, mitigating, and monitoring them.\n- Ensure transparency and user information (Art. 13) by informing users about the AI system's capabilities and limitations.\n- Comply with conformity assessment and CE marking requirements (Art. 43) for EU market placement.\n\n(3) Key Deadlines:\n- Technical documentation: Before market placement (exact date not specified in the rules).\n- Risk management system: Establish and maintain throughout the system's lifecycle.\n- Conformity assessment and CE marking: Before EU market placement (exact date not specified in the rules).\n\n(4) Required Actions Checklist:\n- Draft the technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence.\n- Develop a risk management system (Art. 9) to identify, mitigate, and monitor risks throughout the system's lifecycle.\n- Inform users about the AI system's capabilities and limitations (Art. 13).\n- Engage in conformity assessment (Art. 43) and obtain CE marking before EU market placement, if required.\n- Maintain the risk management system and update the technical documentation file as necessary.\n\n---\nSources: Rule-based checklist (eu-ai-act@2026-07-19) + Model-assisted mapping. This is decision-support, not legal advice."
    },
    "status": "done",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:20:04.316Z",
    "updatedAt": "2026-08-19T00:20:07.134Z",
    "rulesetVersion": "eu-ai-act@2026-07-21"
  },
  {
    "runId": "01961543-4849-4afa-99c8-a9ad413c1832",
    "step": "assess",
    "inputs": {
      "system_description": "test AI screener",
      "intended_users": "HR teams",
      "risk_context": "Workplace / HR"
    },
    "artifacts": {
      "ingestedAt": "2026-08-19T00:04:52.141Z",
      "inputKeys": [
        "system_description",
        "intended_users",
        "risk_context"
      ],
      "ruleHits": {
        "rulesetVersion": "eu-ai-act@2026-07-21",
        "hits": [
          {
            "id": "AIACT-001",
            "title": "High-risk classification under Annex III",
            "severity": "high",
            "remediation": "If the system matches an Annex III use case it is high-risk: you must meet Chapter III Section 2 requirements (risk management, data governance, technical documentation, human oversight, accuracy).",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-002",
            "title": "Annex IV technical documentation (Art. 11 / Annex IV)",
            "severity": "high",
            "remediation": "High-risk systems require a technical documentation file (Annex IV) covering design, intended purpose, and conformity evidence. Draft it before market placement.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-003",
            "title": "Risk management system (Art. 9)",
            "severity": "high",
            "remediation": "Establish a continuous risk-management system (Art. 9) covering the lifecycle: identify known and foreseeable risks, then mitigate and monitor them.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-005",
            "title": "Transparency & user information (Art. 13)",
            "severity": "medium",
            "remediation": "Under Art. 13, deployers must be informed of the AI system’s capabilities and limitations, and that they are interacting with an AI system where applicable.",
            "source": "Rule-based"
          },
          {
            "id": "AIACT-007",
            "title": "Conformity assessment & CE marking (Art. 43)",
            "severity": "high",
            "remediation": "High-risk systems require a conformity assessment (Art. 43), a Declaration of Conformity, and CE marking before EU market placement. Engage a notified body if required.",
            "source": "Rule-based"
          }
        ],
        "highRisk": true,
        "prohibited": false,
        "prohibitedPractices": [],
        "role": "deployer",
        "gpai": false,
        "deadlines": [
          {
            "id": "AIACT-DL-01",
            "obligation": "Entry into force of the AI Act (no obligations yet — transition clock starts)",
            "date": "2024-08-01",
            "ref": "https://artificialintelligenceact.eu/implementation-timeline",
            "daysLeft": -748
          },
          {
            "id": "AIACT-DL-02",
            "obligation": "Prohibitions on unacceptable-risk AI (Art. 5) + AI literacy (Art. 4) apply",
            "date": "2025-02-02",
            "ref": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
            "daysLeft": -563
          },
          {
            "id": "AIACT-DL-04",
            "obligation": "Majority of rules apply: Art. 50 transparency, Art. 6(1) classification, Art. 43 conformity assessment, Art. 71 governance",
            "date": "2026-08-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": -17
          },
          {
            "id": "AIACT-DL-06",
            "obligation": "High-risk AI systems under Annex III apply (postponed from 2 Aug 2026 by Digital Omnibus)",
            "date": "2027-12-02",
            "ref": "https://simpleact.eu/ai-act-deadlines",
            "daysLeft": 470
          }
        ]
      },
      "highRisk": true
    },
    "status": "failed",
    "pipelineId": "aiactradar-obligation-v1",
    "createdAt": "2026-08-19T00:04:52.141Z",
    "updatedAt": "2026-08-19T00:04:52.160Z",
    "rulesetVersion": "eu-ai-act@2026-07-21",
    "error": "AI request failed"
  }
]