EU AI Act Conformity
Register every AI system you operate, classify its EU AI Act risk tier, and track the high-risk provider obligations (Articles 9-17) and Annex IV technical documentation - each obligation cross-referenced to ISO/IEC 42001 and backed by your own scan findings as evidence.
Last reviewed July 2026
The gap EU AI Act Conformity closes
Tagging a finding with "EU AI Act Article 15" does not by itself demonstrate conformity. A provider of a high-risk AI system must classify each system under Annex III, satisfy the Article 9-17 obligations, and assemble an Annex IV technical-documentation file, then keep it current. Framework tagging on its own leaves that workflow sitting in a spreadsheet.
How Penaxtra delivers EU AI Act Conformity
Penaxtra adds an AI system register on top of the scan engine. Declare each AI system, classify its risk tier under Annex III, and the platform lays out the applicable obligations - Article 9 (risk management), 10 (data governance), 11 (technical documentation), 12 (record-keeping), 13 (transparency), 14 (human oversight), 15 (accuracy, robustness, cybersecurity) and 17 (quality management) - plus the nine Annex IV sections. Each obligation carries its ISO/IEC 42001 cross-reference and surfaces the open findings on that system's endpoints as supporting evidence, so the conformity record is built from the scans you already run.
EU AI Act Conformity capabilities
Article 9-17 high-risk provider obligations tracked per system, each with an ISO/IEC 42001 cross-reference
Annex IV technical-documentation sections tracked to a status (general description, data governance, risk management, post-market monitoring and more)
Conformity score per system, computed from obligations met or documented as not applicable
Scan findings on a system's endpoints surface as obligation evidence - your testing becomes your conformity evidence
Tenant-scoped, role-gated, and audit-logged
EU AI Act Conformity compliance mapping
Built around the EU AI Act high-risk provider obligations (Articles 9-17) and Annex IV technical documentation, cross-referenced to ISO/IEC 42001, which maps to seven AI Act articles. High-risk obligations are legally due 2 August 2026; a proposed Digital Omnibus deferral to 2 December 2027 is pending ratification and is not yet in force. Penaxtra produces the evidence and the obligation record; the legal conformity assessment remains the provider's responsibility.