Frameworks51EU AI Actobligations, scoped to each system by rules38ISO/IEC 42001Annex A controls, in a statement of applicabilityNIST AI RMFMapped to the readiness assessmentSources & updates
How it works
One AI system, from unknown to on record.
Four steps from one fictional workspace. Every count, match and fingerprint is computed by the same rules the product runs.
01Find
Start with the AI you didn’t know about.
Drop an SSO or expense export. Each app or merchant name is matched against a versioned catalogue of AI tools, and nothing is saved until you confirm.
Shadow AI scanFictional example · Acme Europe
CSV
expenses-2026-08.csv6 merchant lines
Catalogue v1.0.0
3 of 6 merchants match the AI catalogue
Tool
Found as
Risk
Trains on data
Otter.aiMeeting transcription
OTTER.AI BUSINESS ANNUAL
High
Default on
Fireflies.aiMeeting transcription
FIREFLIES.AI PRO
High
Configurable
GrammarlyWriting assistant
GRAMMARLY BUSINESS
Medium
Configurable
No catalogue match for 3 lines: NORTHSTAR LTD SCREENER SEATS, ADOBE CREATIVE CLOUD, SLACK TECHNOLOGIES. Bespoke tools are registered by hand.
Preview — nothing is saved until you confirm
02Classify
Rules decide the risk tier. A person settles it.
9 prohibited practices and 8 high-risk areas are checked in order, without a model. What the description can’t answer goes to a named reviewer.
AI Act classification · Northstar Applicant ScreenerFictional example · Acme Europe
PurposeRank job applicants for recruitment shortlisting.
Article 5 · prohibited practices9 / 9 · no match
Annex III · high-risk areasAnnex III(4) · matched on “recruitment”
Article 50 · transparencyNot reached — a high-risk match decides the tier first
High riskConfirmedRules · no model request
20 candidate obligations
High risk by presumption, not by finding. The description can’t answer the 2 questions that decide it, so a person does.
Determination recorded · Nadia Ferreira · 9 Sep 2026, 11:20
03Prove
Every obligation, traced to a clause.
Drop a procedure and the clause it cites is matched to the duties it supports. Library files are linked, not copied. What is already in force comes first.
Evidence · Northstar Applicant ScreenerFictional example · Acme Europe
Northstar Applicant ScreenerFictional example · Acme Europe
Risk tier
High risk · Annex III(4)rule fired on “recruitment”, in the purpose
Rule
Candidate obligations
20each with the article it comes from
Rule
Applies from
2 Dec 2027Annex III duties
Rule
Rationale
Drafted around the tiercites only Annex III(4), the rule that fired
Model
Clause excerpt
§3.2 “A human recruiter reviews every ranked applicant and records the reason for accepting or overriding the recommendation.”kept because it is in oversight-procedure.pdf word for word
Model
Open questions
2 answeredthe Article 6(3) assessment among them
Person
Determination
High risk, confirmedNadia Ferreira · 9 Sep 2026, 11:20
Person
Report sign-off
FinalisedNadia Ferreira · 9 Sep 2026
Person
Verify a record
A sealed export and a reviewer’s replay of it. The check runs on the reviewer’s machine, where E-ARI is not.
Illustration: a sealed export as E-ARI issues it, and the independent verifier replaying it offline, using the worked example from the published scoring spec. It is not a live result and contains no information about your own assessment.
02ConformanceThe published corpus, through its own implementationpasses
03RecomputeThe scoring pipeline, on the sealed answers43.71 · follower
04CompareWith the composite and band the platform sealedequal
05ReportA signed ReplayReport, for the filewritten
REPLAYED-IDENTICALexit 0
Had the platform’s score not followed from its sealed answers, the same run ends in REPLAY MISMATCH, exit 4: the alarm.
Verification proves a record is intact and reproducible — not that it is compliant or correct.
Illustrative transcript from the published scoring example. Use the verifier to run a check yourself.
Inside the verification chain
Canonical manifests, SHA-256 artifact hashes and Ed25519 signatures bind the bundle. A public append-only transparency log supplies inclusion and consistency proofs. The independent CLI implements the published specification and can run offline.
From a source file to a reviewable record. Connect a supported source, use the API or upload a document. The same integrity checks apply.
Illustrative record
human-oversight-policy.pdfReview pending
01
Your systems
Your evidence sources
Live9
Ingestion API
GitHub
Jira
Microsoft 365OneDrive files
Confluence
Google DrivePersonal files
Notion
Slack
Drop folders
02
E-ARI
Shared ingestion
Integrity checked
Server-recomputed SHA-256
Duplicates prevented
Content-addressed dedupe
Verifiable exports
Sealable into the public transparency log
03
Your reviewer
Human oversight
What the policy says
A recruiter reviews every shortlisted applicant.
Still neededOversight test
What a governed record makes possible
Link evidence to obligations
Trace a requirement to the clause and source that support it.
Make review easier
Keep supporting records together for the person making the decision.
Preserve a verifiable record
Include evidence in sealed exports that others can check independently.
The policy is here. The oversight test is missing.Collect the test, then review the gap.
Nadia Ferreira · Head of Compliance
Where the evidence will run short
A fictional workspace’s collection history, projected to the deadline: which duties will lack evidence, and when collection has to start.
Countdown · fictional workspaceAs of 9 Sept 2026
At the observed pace of 2.0 files a month
5of 10candidate duties projected to lack evidence by 2 Dec 2027
Scenario range 5–9 · conditional projection
Calendar from 9 Sept 2026 to the deadline, 2 Dec 2027, with the latest date to start collecting evidence for each duty projected to miss it.
TodayJan 27Apr 27Jul 272 Dec 2027
Art. 74 · Cooperation with market surveillance authoritiesStart by 15 Oct 2027
Art. 27 · Fundamental rights impact assessment (FRIA) for deployersStart by 26 Oct 2027
Art. 25 · Responsibilities along the value chainStart by 5 Nov 2027
Art. 26(5) · Reporting serious incidents by deployersStart by 18 Nov 2027
Art. 26(5) · Monitoring high-risk AI systems operated by deployersStart by 20 Nov 2027
Time before collection must startLatest responsible startCollection window: 5–40 days of work, plus a buffer
All 10 duties:5 projected gaps4 on pace1 date not settled
Files a month
2.0
Months of history
7.2
Days to the deadline
449
Inspect the scenario inputs
Fixed fictional scenario as of 2026-09-09; deadline 2027-12-02, read from the platform timeline. Tier-and-role candidates, not a confirmed determination of applicability. Policy uploads only; no existing evidence links or measured obligation-clearance history, so capacity comes from the raw upload rate. A start-by date is the latest responsible start — the duty's collection effort before the deadline, less a published buffer — not a recommendation to wait. The projection is conditional on the observed pace: not a probability or a compliance verdict, and no customer forecast or measured accuracy is implied.
AI_ACT_ART_26_5_INCIDENT · Reporting serious incidents by deployers
AI_ACT_ART_27 · Fundamental rights impact assessment (FRIA) for deployers
AI_ACT_ART_25 · Responsibilities along the value chain
AI_ACT_ART_26_5_MONITOR · Monitoring high-risk AI systems operated by deployers
AI_ACT_ART_74 · Cooperation with market surveillance authorities
AI_ACT_ART_5_CSAM · Prohibited: AI producing child sexual abuse material (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
AI_ACT_ART_5_NCII · Prohibited: AI generating or manipulating non-consensual intimate imagery of identifiable people (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
AI_ACT_ART_26 · Obligations of deployers of high-risk AI systems
AI_ACT_ART_4A_2 · Special-category data processed for bias detection outside the high-risk provider case — deployers of high-risk systems, and providers and deployers of other AI systems and models
AI_ACT_ART_49_3 · EU database registration of use — deployers that are public authorities, EU institutions or bodies, or act on their behalf (Art.49(3)). Timing unsettled: Art.49 was not among the provisions the Omnibus deferred, yet the Commission states the Annex III rules apply from 2 Dec 2027 and the database is not yet reachable
Same projection engine and critical path as the portal's Countdown
Measure progress that supports obligations.
Track artifact collection and, when snapshot history exists, the net rate of obligations evidenced. More uploads do not necessarily mean more coverage.
Know when a forecast is premature.
With insufficient history, E-ARI provides collection priorities instead of an unsupported projection. Scenario bands expose uncertainty in the observed pace.
Connector scope and setup requirements are documented in the catalogue. Runtime capture records configured traffic and does not enforce runtime policy. Write-scoped API access requires Enterprise.
What to check before you buy
Our security posture, data processing, methodology and plans are published, so procurement can start before the first call.
Certification status, hosting locations and sub-processors are set out in full on the Security page.
Common questions
Does E-ARI support ISO/IEC 42001?
As a record, not a certificate. The statement of applicability lists every Annex A control: you record whether it applies, how far it is implemented and why any exclusion is justified, and E-ARI shows the records that bear on it, such as the published AI policy, governance bodies, impact assessments, risks, training and vendor reviews. The mapping from records to controls is E-ARI’s own, a starting point for an auditor’s questions. Certification is an auditor’s decision.
Does a supported obligation mean we are compliant?
No. Evidence coverage identifies supporting clauses and records; it does not establish that every legal requirement is satisfied in practice. Classification can require a recorded human determination, generated documents require review, and the organisation remains responsible for its decisions.
Can our auditors verify the output independently?
Yes. The public verifier checks sealed bundles, and the independent CLI can verify them offline. Audit Replay recomputes an assessment from its sealed inputs. These checks establish integrity and reproducibility, not legal correctness or certification.
How are AI models used?
Rules determine readiness scores, risk tiers and risk-register levels. Models assist with narrative, clause extraction and document drafting, and never decide a tier, a level or an approval. Processing locations, providers and current safeguards are described on the security and data-processing pages.
How do contract and governance decisions stay connected?
AI Spend brings contract costs, reported usage, renewal and notice timing into review. Source-linked actions collect evidence and record a human decision. Material changes to tracked facts or due review dates can bring that decision back for attention; governance reports preserve a point-in-time record. E-ARI does not autonomously cancel contracts or certify compliance.
How should we evaluate E-ARI for our organisation?
Start with the interactive examples and published methodology, then discuss your systems, evidence sources and procurement requirements with us. Self-service assessment and published plans are available. Connector maturity and security limitations are disclosed before you commit.
Start with one system
Free: register your AI systems, see which obligations apply and run a readiness assessment. Pro adds evidence, FRIA, technical documentation and records anyone can verify.