The AI management system you can put in front of an auditor
Keep every AI system and agent on one record: who owns it, what it may do, the policy people have acknowledged, its risks and the evidence behind each duty. Exported as sealed records a reviewer can verify outside E-ARI.
A fictional workspace, shown in ten steps: find AI tools nobody declared, classify a recruitment screener as high risk under Annex III(4), match evidence to 20 candidate obligations, treat a risk and watch the enforced go-live check refuse production until the rest is done, connect evidence sources, record a reviewed decision, review an AI contract before it renews, finalise a report whose fingerprint breaks if a figure changes, then try the rules on a system of your own.
Otter.ai NewMeeting transcription · found in expense data
Not classified
—
Unassigned
System facts What the rules read
Sector
Recruitment
Role
Deployer
Purpose
Rank job applicants for recruitment shortlisting.
Description
An AI system scores CVs and ranks job applicants for review by a human recruiter.
AI Act classification Run classification
Article 5 · prohibited practices0 / 9
Checked first, in order
Annex III · high-risk areas0 / 8
8 areas, from biometrics to justice
Article 50 · transparency4 duties
Not reached — a high-risk match decides the tier first
9 prohibited practices · no match8 Annex III areas · matched Annex III(4) on “recruitment”
High riskProvisionalRules · no model request0 candidate obligations
High risk by presumption, not by finding. The description can’t answer the 2 questions that decide it, so a person does.
Does an Article 6(3) derogation apply — narrow procedural task, improving a completed human activity, detecting patterns without replacing human judgement, or preparatory work — and has that assessment been documented?
yesnonot applicable
Is it used to recruit or select, or to make or materially influence decisions on terms, promotion, termination, task allocation or monitoring?
yesnonot applicable
Confirm the determinationRecorded under your name
Drop policies, procedures, contractsPDF, Word, HTML · hashed on arrival, clauses extracted
PDF
oversight-procedure.pdfHashing and reading clauses…
Supports 3
PDF
acceptable-use-policy.pdf§2 · linked from the library, not copied
Supports 10
PDF
vendor-agreement.pdf§9 · linked from the library, not copied
Supports 1
HTML
applicant-ai-notice.htmllinked from the library, not copied
Supports 1
3 library files cite articles that apply hereLink all
oversight-procedure.pdf · §3.2 Review of rankings
A human recruiter reviews every ranked applicant and records the reason for accepting or overriding the recommendation.
Turn governance and contract findings into owned work, evidence and reviewed decisions.
Open 1Awaiting review 1Reviewed 0
Support AI literacy for the recruiting teamNorthstar Applicant Screener · Art. 4
MLMarc Laurent · due 30 SepAwaiting review
Completing work does not override the live control state.
Where actions come from
Controls
Evidence and gaps
AI spend
Incidents
Assessment results
Northstar Applicant Screener · Art. 4 gap
Support AI literacy for the recruiting team
Awaiting review
Action owner
MLMarc Laurent
Due date
30 Sep 2026
Supporting evidence
literacy-assignment.pdf
Outcome
Literacy module assigned to the recruiting team in the Training programme; the assignment record is attached. Submitted for review by Marc Laurent · 16:40
Decision and next review
Art. 4 asks for measures that support AI literacy — not a guaranteed level in anyone.
Reviewed decisionEvidence reviewed
Next review date
Return to workApprove outcome
This records a workspace review, not certification or a new score.
Evidence reviewed · Nadia Ferreira · 9 Sep 2026, 17:05Next review 9 Mar 2027 · the filed record supports Art. 4: 16 of 20 now evidenced
AI spend
What each AI contract costs, how many of its seats were used, and what the rules recommend before it renews.
Systems, open questions, contracts and deadlines in one workspace, with the next thing that needs a person at the top of the inbox.
01 / 10
Fictional example. The rule checks, the candidate obligations, what each file supports, the catalogue matches, the spend recommendations and the report fingerprint are computed by E-ARI’s own rules; names, files and prices are illustrative.
FrameworksEU AI ActClassification and duties per systemISO/IEC 42001Statement of applicabilityNIST AI RMFMapped to the readiness assessmentSources & updates
From the first undeclared tool to the audit
17 modules in 5 stages, arranged the way the workspace is. They share one record: the owner you name is the owner the go-live check asks for, and the policy you publish counts in the ISO/IEC 42001 statement.
Each judgement on the record has one owner: a published rule, a model inside fixed limits, or a named person. The three instruments below run on the product’s own engines.
What the record rests on: the risk tier, the readiness score, the dates. The rules are published and versioned, so the same inputs give the same result, and a classification names the rule that fired and the words it fired on.
A model assists
Where reading and writing are the work: the rationale around a tier, document labels, clause excerpts, first drafts of a FRIA or an Annex IV file. It never decides a tier or a score. A citation the rules never applied is withheld, and an excerpt that is not in your file word for word is dropped.
A person determines
What the Act leaves to judgement: the Article 6(3) assessment, the answers to open questions, decisions, the sign-off on a report. Each is recorded with who made it and when, kept apart from what the rules said.
The EU AI Act engine the product runs on. It marks the words its rules fired on, and says what it leaves to a person.
Deterministic
It classifies
It looks up
It won’t guess
No account, and no logging: your question is answered and forgotten.
is a CV screening tool high risk?
Read as a classification question
Decided by rules
High-riskby presumptionprovisional
Annex III(4)Employment, workers management and access to self-employmenton “cv screening”
Left to a person
Does an Article 6(3) derogation apply — narrow procedural task, improving a completed human activity, detecting patterns without replacing human judgement, or preparatory work — and has that assessment been documented? +1 more
Not legal advice — a deterministic reading of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Same question in, same answer out, every time. Verify with counsel.
A fictional workspace’s collection history, projected to the deadline: which duties will lack evidence, and when collection has to start.
Countdown · fictional workspaceAs of 9 Sept 2026
At the observed pace of 2.0 files a month
5of 10candidate duties projected to lack evidence by 2 Dec 2027
Scenario range 5–9 · conditional projection
Calendar from 9 Sept 2026 to the deadline, 2 Dec 2027, with the latest date to start collecting evidence for each duty projected to miss it.
TodayJan 27Apr 27Jul 272 Dec 2027
Art. 74 · Cooperation with market surveillance authoritiesStart by 15 Oct 2027
Art. 27 · Fundamental rights impact assessment (FRIA) for deployersStart by 26 Oct 2027
Art. 25 · Responsibilities along the value chainStart by 5 Nov 2027
Art. 26(5) · Reporting serious incidents by deployersStart by 18 Nov 2027
Art. 26(5) · Monitoring high-risk AI systems operated by deployersStart by 20 Nov 2027
Time before collection must startLatest responsible startCollection window: 5–40 days of work, plus a buffer
All 10 duties:5 projected gaps4 on pace1 date not settled
Files a month
2.0
Months of history
7.2
Days to the deadline
449
Inspect the scenario inputs
Fixed fictional scenario as of 2026-09-09; deadline 2027-12-02, read from the platform timeline. Tier-and-role candidates, not a confirmed determination of applicability. Policy uploads only; no existing evidence links or measured obligation-clearance history, so capacity comes from the raw upload rate. A start-by date is the latest responsible start — the duty's collection effort before the deadline, less a published buffer — not a recommendation to wait. The projection is conditional on the observed pace: not a probability or a compliance verdict, and no customer forecast or measured accuracy is implied.
AI_ACT_ART_26_5_INCIDENT · Reporting serious incidents by deployers
AI_ACT_ART_27 · Fundamental rights impact assessment (FRIA) for deployers
AI_ACT_ART_25 · Responsibilities along the value chain
AI_ACT_ART_26_5_MONITOR · Monitoring high-risk AI systems operated by deployers
AI_ACT_ART_74 · Cooperation with market surveillance authorities
AI_ACT_ART_5_CSAM · Prohibited: AI producing child sexual abuse material (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
AI_ACT_ART_5_NCII · Prohibited: AI generating or manipulating non-consensual intimate imagery of identifiable people (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
AI_ACT_ART_26 · Obligations of deployers of high-risk AI systems
AI_ACT_ART_4A_2 · Special-category data processed for bias detection outside the high-risk provider case — deployers of high-risk systems, and providers and deployers of other AI systems and models
AI_ACT_ART_49_3 · EU database registration — deployer duties where applicable. Timing unsettled: Art.49 was not among the provisions the Omnibus deferred, yet the Commission states the Annex III rules apply from 2 Dec 2027 and the database is not yet reachable
Same projection engine and critical path as the portal's Countdown
Measure progress that supports obligations.
Track artifact collection and, when snapshot history exists, the net rate of obligations evidenced. More uploads do not necessarily mean more coverage.
Know when a forecast is premature.
With insufficient history, E-ARI provides collection priorities instead of an unsupported projection. Scenario bands expose uncertainty in the observed pace.
A sealed export and a reviewer’s replay of it. The check runs on the reviewer’s machine, where E-ARI is not.
Sealed exports bind artifacts to a signed manifest. Independent verification checks their integrity. Audit Replay recomputes the assessment from its sealed inputs, outside E-ARI.
Illustration: a sealed export as E-ARI issues it, and the independent verifier replaying it offline, using the worked example from the published scoring spec. It is not a live result and contains no information about your own assessment.
02ConformanceThe published corpus, through its own implementationpasses
03RecomputeThe scoring pipeline, on the sealed answers43.71 · follower
04CompareWith the composite and band the platform sealedequal
05ReportA signed ReplayReport, for the filewritten
REPLAYED-IDENTICALexit 0
Had the platform’s score not followed from its sealed answers, the same run ends in REPLAY MISMATCH, exit 4: the alarm.
Verification proves a record is intact and reproducible — not that it is compliant or correct.
Illustrative transcript from the published scoring example. Use the verifier to run a check yourself.
Inside the verification chain
Canonical manifests, SHA-256 artifact hashes and Ed25519 signatures bind the bundle. A public append-only transparency log supplies inclusion and consistency proofs. The independent CLI implements the published specification and can run offline.
Every source goes through the same ingestion checks
Connect a source, push through the API or upload documents you already have. Each route validates the file, records its SHA-256 and where it came from, and keeps one copy however many systems use it.
Your evidence sources
Supported3
Ingestion API
GitHub
Drop folders
Experimental9
Jira
ServiceNow
Microsoft 365
Confluence
Google Drive
Notion
Slack
Expense reports
Runtime traffic
Shared ingestion
Integrity checked
Server-recomputed SHA-256
Duplicates prevented
Content-addressed dedupe
Verifiable exports
Sealable into the public transparency log
Governed evidence
Link evidence to obligations
Trace a requirement to the clause and source that support it.
Make review easier
Keep supporting records together for the person making the decision.
Preserve a verifiable record
Include evidence in sealed exports that others can check independently.
Connector maturity is stated individually; experimental connectors remain experimental. Runtime capture records configured traffic and does not enforce runtime policy. Write-scoped API access requires Enterprise.
What to check before you buy
Our security posture, data processing, methodology and plans are published, so procurement can start before the first call.
Certification status, hosting locations and sub-processors are set out in full on the Security page.
Common questions
What does E-ARI bring together?
The AI system register, agents included, with shadow AI discovery and vendor reviews; governance bodies, owners and a go-live check; a versioned AI policy acknowledged by name; a risk register with impact assessments; rule-based EU AI Act classification, obligations and evidence; an ISO/IEC 42001 statement of applicability; AI literacy records; and reviewed decisions, AI spend and governance reports. Governance teams review generated FRIA and technical documentation before using it. Feature availability follows the published plans.
Does E-ARI support ISO/IEC 42001?
As a record, not a certificate. The statement of applicability lists every Annex A control: you record whether it applies, how far it is implemented and why any exclusion is justified, and E-ARI shows the records that bear on it, such as the published AI policy, governance bodies, impact assessments, risks, training and vendor reviews. The mapping from records to controls is E-ARI’s own, a starting point for an auditor’s questions. Certification is an auditor’s decision.
Does a supported obligation mean we are compliant?
No. Evidence coverage identifies supporting clauses and records; it does not establish that every legal requirement is satisfied in practice. Classification can require a recorded human determination, generated documents require review, and the organisation remains responsible for its decisions.
Can our auditors verify the output independently?
Yes. The public verifier checks sealed bundles, and the independent CLI can verify them offline. Audit Replay recomputes an assessment from its sealed inputs. These checks establish integrity and reproducibility, not legal correctness or certification.
How are AI models used?
Rules determine readiness scores, risk tiers and risk-register levels. Models assist with narrative, clause extraction and document drafting, and never decide a tier, a level or an approval. Processing locations, providers and current safeguards are described on the security and data-processing pages.
How do contract and governance decisions stay connected?
AI Spend brings contract costs, reported usage, renewal and notice timing into review. Source-linked actions collect evidence and record a human decision. Material changes to tracked facts or due review dates can bring that decision back for attention; governance reports preserve a point-in-time record. E-ARI does not autonomously cancel contracts or certify compliance.
How should we evaluate E-ARI for our organisation?
Start with the interactive examples and published methodology, then discuss your systems, evidence sources and procurement requirements with us. Self-service assessment and published plans are available. Connector maturity and security limitations are disclosed before you commit.
Start with one system
Classify a use case against the EU AI Act without an account, or talk to us about running the whole programme in E-ARI.