Understanding how AuditTrue supports alignment with the EU AI Act.
Informational Disclaimer: This page describes how AuditTrue's platform supports organizations under the EU AI Act (Regulation 2024/1689). AuditTrue is not a certified regulatory body, conformity assessment entity, or notified body. This is not legal advice.
Related: For a compliance-focused summary, see our EU AI Act compliance page. This page provides the full technical article-by-article breakdown.
The EU AI Act (Regulation 2024/1689) establishes the first comprehensive legal framework for artificial intelligence. It takes a risk-based approach — categorizing AI systems by their level of risk and imposing corresponding obligations on providers and deployers. AuditTrue provides tools to help organizations operationalize AI governance aligned with the Act's principles, from risk classification through post-market monitoring.
The Act defines four risk categories, each with distinct obligations:
AI systems that pose a clear threat to safety, livelihoods, or fundamental rights are banned. This includes social scoring by public authorities, real-time biometric identification in public spaces (with limited exceptions for law enforcement), manipulative or deceptive techniques, untargeted facial scraping, and exploitative profiling of vulnerable groups.
AI systems used in critical domains — employment screening, credit scoring, medical diagnostics, law enforcement, border control, education access, essential services, and democratic processes — are subject to the Act's most stringent requirements under Articles 9-15. Providers must undergo conformity assessment, maintain technical documentation, implement risk management systems, and ensure human oversight.
AI systems that interact with humans (chatbots, emotion recognition, deep fakes) must disclose that users are interacting with AI. Content generated or manipulated by AI must be marked as artificial.
AI systems with no significant risk face no mandatory obligations. Providers may voluntarily adopt codes of conduct.
Providers must establish a continuous, iterative risk management process throughout the AI system's lifecycle. This includes identification, estimation, and evaluation of known and reasonably foreseeable risks, adoption of risk treatment measures, and documentation of residual risks. AuditTrue provides structured risk assessment templates, continuous monitoring dashboards, and automated risk re-evaluation triggers when model or data changes occur.
Training, validation, and testing datasets must meet quality criteria — relevant, representative, free of errors, and complete to the extent possible. Special category data requires additional safeguards. AuditTrue's data governance module tracks data lineage, documents dataset provenance, records preprocessing steps, flags potential bias sources, and maintains data quality metrics across the lifecycle.
Providers must maintain comprehensive technical documentation (Annex IV) before placing systems on the market. This includes general description, intended purpose, development methodology, design specifications, data requirements, performance metrics, and human oversight measures. AuditTrue's documentation engine auto-generates model cards, system specifications, training methodology descriptions, performance reports, and change logs — all version-controlled and export-ready.
High-risk systems must automatically log events during operation. Logs must be kept for a period appropriate to the intended purpose and enable traceability. AuditTrue implements tamper-evident logging of every inference, decision, model version change, and human intervention — with configurable retention periods and cryptographic integrity verification.
Providers must supply deployers with instructions for use, including system capabilities, limitations, human oversight measures, and expected accuracy/durability. AuditTrue generates deployer-facing documentation packets with capability descriptions, known limitations, oversight protocol templates, and accuracy declarations.
High-risk systems must be designed to allow effective human oversight before and during use. Oversight measures must be proportionate to the risks, level of autonomy, and context of use. AuditTrue supports human-in-the-loop workflows, intervention logging, override documentation, and review checkpoint scheduling — ensuring oversight is both enabled and demonstrable.
Providers must achieve appropriate levels of accuracy, robustness, and cybersecurity throughout the lifecycle. This includes resilience to errors, faults, and unauthorized access. AuditTrue tracks accuracy metrics against declared baselines, monitors for drift, documents adversarial testing results, and maintains vulnerability assessment records.
Depending on the system type, providers follow one of two conformity assessment routes:
AuditTrue organizes and version-controls all evidence needed for either path, with export formats aligned to notified body submission requirements.
Last updated: July 10, 2026. Informational only — consult a qualified attorney and your regulatory affairs team.