How AnnexWise derives its verdicts
Every classification is produced by a deterministic rules engine that encodes Regulation (EU) 2024/1689 article by article. No language model sits between your answers and your verdict: the same answers always produce the same result, and every rule below is traceable to the article it implements.
Rule set v1.1.0Legal state as of 2026-07-31
Classification order
- Article 5 screen. Any selected prohibited practice classifies the system as prohibited — nothing else is evaluated for tiering, and the €35M / 7% fine tier applies.
- Article 6(1): regulated-product safety components are high-risk. The Article 6(3) derogation does not apply to them.
- Article 6(2) + Annex III. A match with any Annex III category is high-risk, unless the Article 6(3) derogation is claimed — in which case the system is classified out of high-risk and a counsel-review flag is attached, because that derogation is a documented-judgement call, not a checkbox.
- Article 50 transparency triggers attach duties regardless of tier; with no high-risk match they classify the system as limited risk.
- GPAI (Articles 53/55) duties attach orthogonally when you provide a general-purpose model; systemic-risk scale adds the Article 55 regime.
- Anything else is minimal risk (Article 4 AI literacy still applies).
Rule inventory
Prohibited practices — Article 5(1)
- Subliminal or purposefully manipulative techniques — Interfaces designed to distort behaviour and cause significant harm
- Exploiting vulnerabilities (age, disability, social situation) — Targeting children or financially distressed users to their detriment
- Social scoring by general behaviour or characteristics — Scoring citizens/customers leading to unrelated detrimental treatment
- Predicting criminal offences from profiling alone — Risk-of-crime scores based solely on personality traits
- Untargeted scraping of facial images — Building face databases from internet or CCTV footage
- Emotion recognition in workplaces or schools — Inferring employee/student emotions (outside medical/safety uses)
- Biometric categorisation of sensitive attributes — Inferring race, political views, religion or orientation from biometrics
- Real-time remote biometric ID in public spaces (law enforcement) — Live facial recognition in publicly accessible spaces
High-risk categories — Annex III
- Biometric identification or categorisation — Remote biometric ID, emotion recognition (where not prohibited)
- Safety component in critical infrastructure — AI managing energy grids, water, traffic, digital infrastructure
- Education and vocational training — Admissions, exam scoring, proctoring, learning-outcome evaluation
- Employment and worker management — CV screening, interview scoring, promotion/termination decisions
- Access to essential services — Credit scoring, insurance pricing (life/health), benefits eligibility
- Law enforcement — Evidence reliability assessment, recidivism risk, polygraph-type tools
- Migration, asylum and border control — Visa/asylum application assessment, border risk assessment
- Administration of justice and democratic processes — Assisting courts in interpreting facts/law; influencing elections
Transparency triggers — Article 50
- People interact directly with the AI (chatbot, voice agent)
- Generates synthetic audio, image, video or text content
- Generates or manipulates deepfake content
- Uses emotion recognition or biometric categorisation (permitted cases)
Provider obligations for high-risk systems (Chapter III)
| Article | Obligation | Severity weighting |
|---|
| Art. 9 | Risk management system | critical |
| Art. 10 | Data and data governance | critical |
| Art. 11 + Annex IV | Technical documentation | critical |
| Art. 12 | Record-keeping (automatic logs) | high |
| Art. 13 | Transparency and instructions for deployers | high |
| Art. 14 | Human oversight by design | critical |
| Art. 15 | Accuracy, robustness and cybersecurity | high |
| Art. 17 | Quality management system | high |
| Art. 43 + 48 | Conformity assessment and CE marking | critical |
| Art. 49 | EU database registration | high |
| Art. 72 | Post-market monitoring | medium |
| Art. 73 | Serious incident reporting | medium |
Deployer obligations for high-risk systems (Art. 26–27)
| Article | Obligation | Severity weighting |
|---|
| Art. 26(1) | Operate per provider instructions | high |
| Art. 26(2) | Assign trained human oversight | critical |
| Art. 26(4) | Input data control | high |
| Art. 26(5) | Monitor and suspend on risk | high |
| Art. 26(6) | Retain logs (minimum 6 months) | medium |
| Art. 26(7) | Inform affected workers | medium |
| Art. 27 | Fundamental rights impact assessment | high |
Transparency obligations (Art. 50)
| Article | Obligation | Severity weighting |
|---|
| Art. 50(1) | Disclose AI interaction | high |
| Art. 50(2) | Machine-readable content marking | high |
| Art. 50(4) | Label deepfakes | high |
| Art. 50(3) | Disclose emotion recognition / biometric categorisation | medium |
GPAI provider obligations (Art. 53 / 55)
| Article | Obligation | Severity weighting |
|---|
| Art. 53(1)(a-b) | GPAI technical documentation | high |
| Art. 53(1)(c) | Copyright policy | medium |
| Art. 53(1)(d) | Training-content summary | medium |
| Art. 55 | Systemic-risk model duties | critical |
Scoring
The compliance score is the weight of satisfied obligations divided by the weight of all applicable obligations, on a 0–100 scale. Weights reflect severity: critical items (e.g. conformity assessment, technical documentation, human oversight) weigh roughly twice as much as procedural ones. A prohibited classification scores 0 by definition.
Verification & change control
- Every rule is covered by a golden test suite — canonical scenarios with expected verdicts that run on every change to the engine.
- Any change to classification logic, obligations or weights bumps the rule-set version. Reports permanently record the version and an input fingerprint, so any verdict can be re-derived and audited later.
- The rule set tracks Commission guidelines, AI Office templates and harmonised standards; the legal-state date above tells you exactly how current your verdict is.
- Genuinely gray areas (e.g. the Article 6(3) derogation) are surfaced as counsel-review flags rather than silently resolved.
AnnexWise is compliance software, not a law firm. This page documents how the software reasons so that your counsel can audit it; it does not replace their judgement.