Our engineers set up and run your first chatbot / LLM security scan. Get in touch

EU AI Act Compliance Mapping

The EU AI Act creates a horizontal regulatory regime for AI systems across the European Union, with the strictest obligations falling on providers of high-risk AI systems. Cybersecurity, robustness, and accuracy obligations under Article 15 plus risk-management obligations under Article 9 are legally due 2 August 2026 for many in-scope systems; a proposed Digital Omnibus deferral to 2 December 2027 is pending ratification and is not yet in force.

Last reviewed July 2026

Why EU AI Act evidence is hard

An auditor works from a framework control list; a scan produces a finding list. Without a mapping between the two, each finding has to be translated onto the controls by hand before an audit.

How Penaxtra maps to EU AI Act

Penaxtra produces evidence aligned to high-risk provider obligations: risk-management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11), record-keeping (Art. 12), transparency to deployers (Art. 13), human oversight (Art. 14), accuracy and cybersecurity (Art. 15), quality management (Art. 17), and post-market monitoring (Art. 72).

EU AI Act capabilities

Every Penaxtra finding carries the specific EU AI Act article

PDF and JSON exports format the evidence for technical-documentation Annex IV submission..

Audit-ready PDF export with control IDs attached

JSON export for GRC ticketing systems

Configurable audit retention from 1 day to 10 years

Cross-framework overlaps reduce duplicate evidence collection

EU AI Act control coverage

A prompt-injection finding against an internal copilot maps to EU AI Act Art. 15(4) cybersecurity, Art. 9(2)(a) risk management, and Art. 12(1) record-keeping in a single row.