EU AI Act

Which obligations a runtime record actually answers.

The Act asks for things that only exist while a system is running — what it did, on whose behalf, under whose authority, and whether anyone could have intervened. That is the part of a compliance program FaburAI is built to supply.

Before the table

What this mapping is, and is not.

This is not a claim that FaburAI makes anyone compliant. It is a statement of which obligations our runtime artifacts serve, which they only contribute to, and which they do not touch.

Where the answer is partial, it says partial. A mapping table with an unbroken row of ticks is not a credible document, and it does not survive contact with an auditor.

Article mapping

Obligation by obligation.

EU AI Act articles and the FaburAI artifacts that serve them
ArticleWhat it asks forWhat FaburAI providesCoverage
Article 9Risk management across the system lifecycle — identify, evaluate, mitigate, iterate.A proposed rule can be evaluated against real recorded activity before it governs anything, and run live without blocking while recording what it would have denied. Risk decisions are tested against evidence rather than argued.Contributes
Article 10Data governance — quality, relevance, and management of sensitive attributes.Columns are labeled at discovery — PII, PHI, GDPR, SOX, HIPAA — and policy binds to individual fields. Statements are parsed so implicitly-reached tables and columns are governed too, not just the operation named.Contributes
Article 12Automatic recording of events over the system lifetime.Every governed call produces a record: the AI actor, the user role it acted for, the server, tool and target reached, the outcome, the rule that decided, and the time. Queryable and exportable.Serves directly
Article 13Transparency to deployers — interpretable output, known capabilities and limits.Any decision can be opened to show the conditions evaluated and which matched. A past decision can be replayed against current policy to show whether the answer would differ today.Serves directly
Article 14Human oversight — monitor, interpret, intervene, and stop.A rule cannot enforce until approved; approval is refused structurally, not by process. Observe and simulate modes let behavior be watched without blocking, and an actor can be stopped unconditionally without authoring a rule.Serves directly
Article 17Quality management system — documented, consistent governance practice.Policy lifecycle with recorded approvals, roles federated from the identity provider already in use, versioned snapshots of servers, models and agents, and encrypted credentials at rest.Contributes
Article 26Deployer obligations — monitor operation, keep logs, assign oversight.Continuous telemetry from governed calls, the decision record itself, and role-based assignment of who may approve what. Policies are machine-readable statements of permitted use.Serves directly
Articles 72–73Post-market monitoring, and detection and notification of serious incidents.Continuous invocation telemetry and policy-activity views supply the underlying signal. FaburAI does not score incident severity and does not carry a regulator notification workflow.Needs other tooling
The sequence

Discover, classify, govern, evidence.

The order matters, and it is the order the Act implies: you cannot classify what you cannot see, and you cannot evidence what you did not enforce.

  1. Discover

    Enumerate the AI systems, the tools they expose, the data behind them, and the callers reaching them.

  2. Classify

    Label sensitivity at the column, and decide which combinations of access are unacceptable.

  3. Govern

    Enforce those decisions at the call, with a human approval behind every rule that enforces.

  4. Evidence

    Produce the record — what was decided, by which rule, for whom — as a by-product of enforcement.

Boundaries

What this mapping does not reach.

  • Training-data quality, bias examination and fairness metricsArticle 10's data-quality limbs. Owned by your MLOps and evaluation practice — we govern what agents may reach, not how a model was trained.
  • Annex IV technical documentationOwned by your GRC tooling or counsel. We supply the inventory and decision records that documentation cites.
  • Fundamental-rights impact assessment under Article 27Owned by your privacy and legal function. Our catalog shows which AI systems reach which categories of personal data, which is normally the hard input to gather.
  • Registration in the EU database under Articles 49 and 71Owned by your compliance function.
  • Incident detection, severity scoring and notification under Article 73Owned by your detection and response tooling and your compliance workflow. Decision records are exportable, so they can feed what already aggregates your telemetry.
  • Disclosure and marking of AI-generated contentOwned by your product teams, at the point the content reaches an end user.

Every line above is a reason we integrate rather than replace. We are glad to work alongside the vendors and advisers already in your program, and to be the runtime evidence layer underneath them rather than something they have to route around.

Talk to us

Bring the article your counsel is focused on.

These conversations go better when they start from a specific obligation rather than from the regulation as a whole.