Our engineers set up and run your first chatbot / LLM security scan. Get in touch

EU AI Act Conformity

Register every AI system you operate, classify its EU AI Act risk tier, and track the high-risk provider obligations (Articles 9-17) and Annex IV technical documentation - each obligation cross-referenced to ISO/IEC 42001 and backed by your own scan findings as evidence.

Last reviewed July 2026

The gap EU AI Act Conformity closes

Tagging a finding with "EU AI Act Article 15" does not by itself demonstrate conformity. A provider of a high-risk AI system must classify each system under Annex III, satisfy the Article 9-17 obligations, and assemble an Annex IV technical-documentation file, then keep it current. Framework tagging on its own leaves that workflow sitting in a spreadsheet.

How Penaxtra delivers EU AI Act Conformity

Penaxtra adds an AI system register on top of the scan engine. Declare each AI system, classify its risk tier under Annex III, and the platform lays out the applicable obligations - Article 9 (risk management), 10 (data governance), 11 (technical documentation), 12 (record-keeping), 13 (transparency), 14 (human oversight), 15 (accuracy, robustness, cybersecurity) and 17 (quality management) - plus the nine Annex IV sections. Each obligation carries its ISO/IEC 42001 cross-reference and surfaces the open findings on that system's endpoints as supporting evidence, so the conformity record is built from the scans you already run.

EU AI Act Conformity capabilities

AI system register with EU AI Act Annex III high-risk classification (8 categories)

Article 9-17 high-risk provider obligations tracked per system, each with an ISO/IEC 42001 cross-reference

Annex IV technical-documentation sections tracked to a status (general description, data governance, risk management, post-market monitoring and more)

Conformity score per system, computed from obligations met or documented as not applicable

Scan findings on a system's endpoints surface as obligation evidence - your testing becomes your conformity evidence

Tenant-scoped, role-gated, and audit-logged

EU AI Act Conformity compliance mapping

Built around the EU AI Act high-risk provider obligations (Articles 9-17) and Annex IV technical documentation, cross-referenced to ISO/IEC 42001, which maps to seven AI Act articles. High-risk obligations are legally due 2 August 2026; a proposed Digital Omnibus deferral to 2 December 2027 is pending ratification and is not yet in force. Penaxtra produces the evidence and the obligation record; the legal conformity assessment remains the provider's responsibility.