EU AI Act Compliance Workbench
The EU AI Act workbench turns the regulation into a working checklist: declare what role you play, classify each AI system into the right risk tier, and track every resulting obligation to evidence you can show a regulator.
Step 1 — Declare your actor role
The Act places different duties on different parties, so the workbench starts by asking which role your organization plays for each system. The role you pick drives which obligation set appears; a system can carry different roles for different organizations in the same supply chain.
- Provider
- You develop an AI system or general-purpose AI model and place it on the market under your own name or trademark. Heaviest obligation set.
- Deployer
- You use an AI system under your own authority in a professional capacity. Most RAIC tenants are deployers for most of their estate.
- Importer
- You place on the EU market an AI system from a provider established outside the EU.
- Distributor
- You make an AI system available on the EU market without being the provider or importer.
Step 2 — Classify the risk tier
- Prohibited: practices banned outright, such as social scoring, untargeted facial-image scraping, and certain manipulative or exploitative techniques. Flagging a system here escalates immediately.
- High-risk: systems falling under Annex III use cases or acting as safety components of regulated products. This tier carries the substantive compliance burden.
- Limited risk: systems with transparency duties, notably chatbots, emotion recognition, and synthetic content that must be disclosed or labelled.
- Minimal risk: everything else. Registered for inventory completeness, no specific Act obligations.
Step 3 — Work the Annex III triggers
For any system you did not classify as prohibited, the workbench runs the Annex III trigger list: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice. Answering yes to a trigger moves the system into high-risk and expands its obligation checklist. Your answers are retained with a timestamp and reviewer so the classification decision itself is defensible.
Step 4 — Track obligations to evidence
Each classified system gets a generated obligation list scoped to its role and tier. Obligations are not free-text notes: each one links to the RAIC control, document, or register entry that satisfies it, so coverage is computed rather than asserted.
- Risk management system — links to the Risk Register entries for that system.
- Data and data governance — links to Dataset Registry entries, including provenance and quality criteria.
- Technical documentation and record-keeping — links to the Documented Information register.
- Transparency and information to deployers — links to the Transparency Register.
- Human oversight — links to the controls implementing review and override.
- Accuracy, robustness, and cybersecurity — links to control test evidence and Operation Monitoring metrics.
- Post-market monitoring and serious-incident reporting — links to incident records and monitoring thresholds.
Crosswalks and reporting
EU AI Act obligations crosswalk to ISO/IEC 42001 Annex A and NIST AI RMF, so a control you already operate for ISO can satisfy an Act obligation without duplicate work. Coverage rolls into the AI Maturity Index and into the executive summary and board reports. Gaps export to CSV and to a branded DOCX readiness report.
What the workbench does not do
RAIC structures your compliance work and holds the evidence; it does not give legal advice or certify conformity. Classification decisions, particularly around Annex III and prohibited practices, should be reviewed with counsel. Notified-body conformity assessment, where required, happens outside the platform — record the outcome in the Documented Information register.
