Every Penaxtra finding carries the specific EU AI Act article
PDF and JSON exports format the evidence for technical-documentation Annex IV submission..
The EU AI Act creates a horizontal regulatory regime for AI systems across the European Union, with the strictest obligations falling on providers of high-risk AI systems. Cybersecurity, robustness, and accuracy obligations under Article 15 plus risk-management obligations under Article 9 are legally due 2 August 2026 for many in-scope systems; a proposed Digital Omnibus deferral to 2 December 2027 is pending ratification and is not yet in force.
Last reviewed July 2026
An auditor works from a framework control list; a scan produces a finding list. Without a mapping between the two, each finding has to be translated onto the controls by hand before an audit.
Penaxtra produces evidence aligned to high-risk provider obligations: risk-management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11), record-keeping (Art. 12), transparency to deployers (Art. 13), human oversight (Art. 14), accuracy and cybersecurity (Art. 15), quality management (Art. 17), and post-market monitoring (Art. 72).
PDF and JSON exports format the evidence for technical-documentation Annex IV submission..
A prompt-injection finding against an internal copilot maps to EU AI Act Art. 15(4) cybersecurity, Art. 9(2)(a) risk management, and Art. 12(1) record-keeping in a single row.
Each control has a dedicated page: what it covers and how Penaxtra tests and evidences it.