EU AI Act
Which obligations a runtime record actually answers.
The Act asks for things that only exist while a system is running — what it did, on whose behalf, under whose authority, and whether anyone could have intervened. That is the part of a compliance program FaburAI is built to supply.
What this mapping is, and is not.
This is not a claim that FaburAI makes anyone compliant. It is a statement of which obligations our runtime artifacts serve, which they only contribute to, and which they do not touch.
Where the answer is partial, it says partial. A mapping table with an unbroken row of ticks is not a credible document, and it does not survive contact with an auditor.
Obligation by obligation.
| Article | What it asks for | What FaburAI provides | Coverage |
|---|---|---|---|
| Article 9 | Risk management across the system lifecycle — identify, evaluate, mitigate, iterate. | A proposed rule can be evaluated against real recorded activity before it governs anything, and run live without blocking while recording what it would have denied. Risk decisions are tested against evidence rather than argued. | Contributes |
| Article 10 | Data governance — quality, relevance, and management of sensitive attributes. | Columns are labeled at discovery — PII, PHI, GDPR, SOX, HIPAA — and policy binds to individual fields. Statements are parsed so implicitly-reached tables and columns are governed too, not just the operation named. | Contributes |
| Article 12 | Automatic recording of events over the system lifetime. | Every governed call produces a record: the AI actor, the user role it acted for, the server, tool and target reached, the outcome, the rule that decided, and the time. Queryable and exportable. | Serves directly |
| Article 13 | Transparency to deployers — interpretable output, known capabilities and limits. | Any decision can be opened to show the conditions evaluated and which matched. A past decision can be replayed against current policy to show whether the answer would differ today. | Serves directly |
| Article 14 | Human oversight — monitor, interpret, intervene, and stop. | A rule cannot enforce until approved; approval is refused structurally, not by process. Observe and simulate modes let behavior be watched without blocking, and an actor can be stopped unconditionally without authoring a rule. | Serves directly |
| Article 17 | Quality management system — documented, consistent governance practice. | Policy lifecycle with recorded approvals, roles federated from the identity provider already in use, versioned snapshots of servers, models and agents, and encrypted credentials at rest. | Contributes |
| Article 26 | Deployer obligations — monitor operation, keep logs, assign oversight. | Continuous telemetry from governed calls, the decision record itself, and role-based assignment of who may approve what. Policies are machine-readable statements of permitted use. | Serves directly |
| Articles 72–73 | Post-market monitoring, and detection and notification of serious incidents. | Continuous invocation telemetry and policy-activity views supply the underlying signal. FaburAI does not score incident severity and does not carry a regulator notification workflow. | Needs other tooling |
Discover, classify, govern, evidence.
The order matters, and it is the order the Act implies: you cannot classify what you cannot see, and you cannot evidence what you did not enforce.
Discover
Enumerate the AI systems, the tools they expose, the data behind them, and the callers reaching them.
Classify
Label sensitivity at the column, and decide which combinations of access are unacceptable.
Govern
Enforce those decisions at the call, with a human approval behind every rule that enforces.
Evidence
Produce the record — what was decided, by which rule, for whom — as a by-product of enforcement.
What this mapping does not reach.
- Training-data quality, bias examination and fairness metricsArticle 10's data-quality limbs. Owned by your MLOps and evaluation practice — we govern what agents may reach, not how a model was trained.
- Annex IV technical documentationOwned by your GRC tooling or counsel. We supply the inventory and decision records that documentation cites.
- Fundamental-rights impact assessment under Article 27Owned by your privacy and legal function. Our catalog shows which AI systems reach which categories of personal data, which is normally the hard input to gather.
- Registration in the EU database under Articles 49 and 71Owned by your compliance function.
- Incident detection, severity scoring and notification under Article 73Owned by your detection and response tooling and your compliance workflow. Decision records are exportable, so they can feed what already aggregates your telemetry.
- Disclosure and marking of AI-generated contentOwned by your product teams, at the point the content reaches an end user.
Every line above is a reason we integrate rather than replace. We are glad to work alongside the vendors and advisers already in your program, and to be the runtime evidence layer underneath them rather than something they have to route around.
Bring the article your counsel is focused on.
These conversations go better when they start from a specific obligation rather than from the regulation as a whole.

