Bring AI systems, applicable obligations and supporting evidence into one governed record. E-ARI helps governance, risk and compliance teams see what applies, what is evidenced and what needs attention.
A fictional workspace, shown in nine steps: find AI tools nobody declared, classify a recruitment screener as high risk under Annex III(4), match evidence to 20 candidate obligations, connect evidence sources, record a reviewed decision, review an AI contract before it renews, finalise a report whose fingerprint breaks if a figure changes, then try the rules on a system of your own.
Otter.ai NewMeeting transcription · found in expense data
Not classified
—
Unassigned
System facts What the rules read
Sector
Recruitment
Role
Deployer
Purpose
Rank job applicants for recruitment shortlisting.
Description
An AI system scores CVs and ranks job applicants for review by a human recruiter.
AI Act classification Run classification
Article 5 · prohibited practices0 / 9
Checked first, in order
Annex III · high-risk areas0 / 8
8 areas, from biometrics to justice
Article 50 · transparency4 duties
Not reached — a high-risk match decides the tier first
9 prohibited practices · no match8 Annex III areas · matched Annex III(4) on “recruitment”
High riskProvisionalRules · no model request0 candidate obligations
High risk by presumption, not by finding. The description can’t answer the 2 questions that decide it, so a person does.
Does an Article 6(3) derogation apply — narrow procedural task, improving a completed human activity, detecting patterns without replacing human judgement, or preparatory work — and has that assessment been documented?
yesnonot applicable
Is it used to recruit or select, or to make or materially influence decisions on terms, promotion, termination, task allocation or monitoring?
yesnonot applicable
Confirm the determinationRecorded under your name
Drop policies, procedures, contractsPDF, Word, HTML · hashed on arrival, clauses extracted
PDF
oversight-procedure.pdfHashing and reading clauses…
Supports 3
PDF
acceptable-use-policy.pdf§2 · linked from the library, not copied
Supports 10
PDF
vendor-agreement.pdf§9 · linked from the library, not copied
Supports 1
HTML
applicant-ai-notice.htmllinked from the library, not copied
Supports 1
3 library files cite articles that apply hereLink all
oversight-procedure.pdf · §3.2 Review of rankings
A human recruiter reviews every ranked applicant and records the reason for accepting or overriding the recommendation.
Turn governance and contract findings into owned work, evidence and reviewed decisions.
Open 1Awaiting review 1Reviewed 0
Support AI literacy for the recruiting teamNorthstar Applicant Screener · Art. 4
MLMarc Laurent · due 30 SepAwaiting review
Completing work does not override the live control state.
Where actions come from
Controls
Evidence and gaps
AI spend
Incidents
Assessment results
Northstar Applicant Screener · Art. 4 gap
Support AI literacy for the recruiting team
Awaiting review
Action owner
MLMarc Laurent
Due date
30 Sep 2026
Supporting evidence
literacy-assignment.pdf
Outcome
Literacy module assigned to the recruiting team in the Training programme; the assignment record is attached. Submitted for review by Marc Laurent · 16:40
Decision and next review
Art. 4 asks for measures that support AI literacy — not a guaranteed level in anyone.
Reviewed decisionEvidence reviewed
Next review date
Return to workApprove outcome
This records a workspace review, not certification or a new score.
Evidence reviewed · Nadia Ferreira · 9 Sep 2026, 17:05Next review 9 Mar 2027 · the filed record supports Art. 4: 16 of 20 now evidenced
AI spend
What each AI contract costs, how many of its seats were used, and what the rules recommend before it renews.
Systems, open questions, contracts and deadlines in one workspace, with the next thing that needs a person at the top of the inbox.
01 / 09
Fictional example. The rule checks, the candidate obligations, what each file supports, the catalogue matches, the spend recommendations and the report fingerprint are computed by E-ARI’s own rules; names, files and prices are illustrative.
Regulatory & framework mappingsEU AI ActISO/IEC 42001NIST AI RMFSources & updates
The governance workflow
One record, from discovery to evidence.
Identify AI tools in imported records. Register their purpose and ownership. Follow the applicable duties through to the evidence and documents your reviewers need.
Import SSO or expense data to surface AI tools and bring them into the register. Coverage depends on the sources you provide.
AI system registry
Shadow AI discovery
Vendor risk questionnaires
Understand what applies.
Inspect rule-based classifications, resolve open questions and assign ownership. Follow obligation-specific evidence and control states as the record changes.
Risk and operator-role scoping
Human determination and ownership
AI literacy and completion records
Show the work behind the claim.
Connect evidence to obligations, review generated documentation and assemble a submission pack from the system record.
Evidence vault and clause lineage
FRIA and technical documentation
Sealed exports and audit replay
From evidence to a decision
A renewal is a governance decision, too.
AI Spend connects contracts and imported usage with the systems they support. Review cost alongside ownership, vendor exposure and governance gaps.
E-ARI projects future evidence readiness from your recorded collection history and the obligations ahead. See which workstreams need attention, the assumptions behind the projection and when collection should begin.
Measure progress that supports obligations.
Track artifact collection and, when snapshot history exists, the net rate of obligations evidenced. More uploads do not necessarily mean more coverage.
Know when a forecast is premature.
With insufficient history, E-ARI provides collection priorities instead of an unsupported projection. Scenario bands expose uncertainty in the observed pace.
Art. 26(5) · Reporting serious incidents by deployersGap projected
Art. 27 · Fundamental rights impact assessment (FRIA) for deployersGap projected
Art. 25 · Responsibilities along the value chainGap projected
Art. 26(5) · Monitoring high-risk AI systems operated by deployersGap projected
Art. 74 · Cooperation with market surveillance authoritiesGap projected
Artifacts / month
2.0
History / months
7.2
Projection basis
raw
Inspect the scenario inputs
Fixed fictional scenario as of 2026-09-09; deadline 2027-12-02, read from the platform timeline. Tier-and-role candidates, not a confirmed determination of applicability. Policy uploads only; no existing evidence links or measured obligation-clearance history. The projection is conditional on the observed pace: not a probability or a compliance verdict, and no customer forecast or measured accuracy is implied.
AI_ACT_ART_26_5_INCIDENT · Reporting serious incidents by deployers
AI_ACT_ART_27 · Fundamental rights impact assessment (FRIA) for deployers
AI_ACT_ART_25 · Responsibilities along the value chain
AI_ACT_ART_26_5_MONITOR · Monitoring high-risk AI systems operated by deployers
AI_ACT_ART_74 · Cooperation with market surveillance authorities
AI_ACT_ART_5_CSAM · Prohibited: AI producing child sexual abuse material (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
AI_ACT_ART_5_NCII · Prohibited: AI generating or manipulating non-consensual intimate imagery of identifiable people (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
AI_ACT_ART_26 · Obligations of deployers of high-risk AI systems
AI_ACT_ART_4A_2 · Special-category data processed for bias detection outside the high-risk provider case — deployers of high-risk systems, and providers and deployers of other AI systems and models
AI_ACT_ART_49_3 · EU database registration — deployer duties where applicable. Timing unsettled: Art.49 was not among the provisions the Omnibus deferred, yet the Commission states the Annex III rules apply from 2 Dec 2027 and the database is not yet reachable
Same projection engine as the compliance workspace
Independent verification
A record your reviewer can verify.
Sealed exports bind artifacts to a signed manifest. Independent verification checks their integrity. Audit Replay recomputes the assessment from its sealed inputs, outside E-ARI.
Illustration: a sealed export as E-ARI issues it, and the independent verifier replaying it offline, using the worked example from the published scoring spec. It is not a live result and contains no information about your own assessment.
02ConformanceThe published corpus, through its own implementationpasses
03RecomputeThe scoring pipeline, on the sealed answers43.71 · follower
04CompareWith the composite and band the platform sealedequal
05ReportA signed ReplayReport, for the filewritten
REPLAYED-IDENTICALexit 0
Had the platform’s score not followed from its sealed answers, the same run ends in REPLAY MISMATCH, exit 4: the alarm.
Verification proves a record is intact and reproducible — not that it is compliant or correct.
Illustrative transcript from the published scoring example. Use the verifier to run a check yourself.
Inside the verification chain
Canonical manifests, SHA-256 artifact hashes and Ed25519 signatures bind the bundle. A public append-only transparency log supplies inclusion and consistency proofs. The independent CLI implements the published specification and can run offline.
Deterministic where it matters. Assisted where it helps.
Published rules determine scores and risk tiers. AI assists with explanation, evidence extraction and drafting. Human review remains part of the governance process.
Inspect the inputs, rule trace and method version.
02 / EVIDENCE
Traceable support
Follow an obligation back to the supporting clause.
03 / ASSISTANCE
Contextual drafting
Generate explanations and documents for review.
04 / REVIEW
Accountable decisions
Record human determinations and finalise artifacts.
Deterministic
High-risk — by presumption. PROVISIONAL — confirm before relying on this. The rule engine matched 1 Annex III area: Employment, workers management and access to self-employment (Annex III(4)), on the phrase "cv screening". Article 6(2) makes a listed system high-risk BY PRESUMPTION; Article 6(3) lets the provider rebut it — narrow procedural task, improving a completed human activity, detecting patterns without replacing human judgement, or preparatory work — and that assessment must be documented. Nothing in a one-line question can show it was made.
Use source snapshots, API submissions or documents already on hand. Choose the collection route that fits the evidence; each route applies the same ingestion rules.
Your evidence sources
Documents · CI / API push Pull connectors · runtime capture
Connector maturity is stated individually; experimental connectors remain experimental. Runtime capture records configured traffic and does not enforce runtime policy. Write-scoped API access requires Enterprise.
Enterprise evaluation
Evaluate the platform with the facts in view.
Review our security posture, processing disclosures, methodology and published plans. Discuss your organisation’s requirements before deciding how to deploy E-ARI.
Certification status, hosting locations and sub-processors are set out in full on the Security page.
Before you decide
Questions that matter.
What does E-ARI bring together?
AI system registration, rule-based classification, obligation mapping, evidence, vendor questionnaires and AI literacy records. Governance teams can review generated FRIA and technical documentation and assemble submission packs from the system record. Feature availability follows the published plans.
Does a supported obligation mean we are compliant?
No. Evidence coverage identifies supporting clauses and records; it does not establish that every legal requirement is satisfied in practice. Classification can require a recorded human determination, generated documents require review, and the organisation remains responsible for its decisions.
Can our auditors verify the output independently?
Yes. The public verifier checks sealed bundles, and the independent CLI can verify them offline. Audit Replay recomputes an assessment from its sealed inputs. These checks establish integrity and reproducibility, not legal correctness or certification.
How are AI models used?
Rules determine readiness scores and risk tiers. Models assist with narrative, clause extraction and document drafting. Processing locations, providers and current safeguards are described on the security and data-processing pages.
How should we evaluate E-ARI for our organisation?
Start with the interactive examples and published methodology, then discuss your systems, evidence sources and procurement requirements with us. Self-service assessment and published plans are available. Connector maturity and security limitations are disclosed before you commit.
From governance to evidence
Put your AI governance to the test.
Explore the evidence workflow, inspect the verification path and discuss what your organisation needs to establish a defensible record.