Version: 1.1 | Date: 2026-07-10 Regulation: EU AI Act (Regulation (EU) 2024/1689) — current high-risk timeline: 2027-12-02 for Annex III systems and 2028-08-02 for product-integrated systems Status: Engineering compliance mapping — not legal advice
This document maps AMC's five maturity dimensions and evidence infrastructure to the EU AI Act's obligations for high-risk AI systems. AMC provides deterministic, evidence-linked compliance signals — not legal certifications.
A signed or VALID AMC report proves artifact integrity, not evidence sufficiency. Use a mapping externally only when evidence readiness is READY; AMC does not classify a system as a matter of law, perform conformity assessment, or certify legal compliance.
The EU AI Act applies a risk-based approach. AMC's compliance engine now supports EU_AI_ACT as a first-class framework alongside SOC2, NIST AI RMF, ISO 27001, and ISO 42001.
amc compliance report --framework EU_AI_ACT --window 30d --out .amc/reports/eu-ai-act.md
amc comply risk-classify --employment --jsonAMC uses Domain Risk Classification as a technical pre-check for which governance tier may apply. Final classification depends on intended purpose, role, and use case and requires qualified review:
| Domain Risk Class | Candidate EU AI Act Tier | AMC Policy Response |
|---|---|---|
critical |
Unacceptable (Art. 5) | Prohibited unless exempted; AMC blocks deployment |
high |
High-risk (Annex III) | Full Art. 9-15, 17 obligations; strict human oversight |
elevated |
Limited risk | Transparency obligations (Art. 50); moderate oversight |
standard |
Minimal risk | Voluntary codes of practice; baseline AMC governance |
Domain classification is stored in .amc/eu_ai_act_classification.json and scored by src/score/euAIActCompliance.ts.
Annex III identifies specific high-risk use cases in areas including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, asylum, border control, and justice. An industry label alone does not establish classification.
Use amc comply risk-classify for the CLI risk-tier pre-check. It is an alias for amc compliance risk-classify and maps capability flags to the EU AI Act risk tiers in Regulation (EU) 2024/1689, including Article 5 prohibited practices, Article 6 high-risk systems, Annex III use areas, and Article 50 transparency obligations. Official source: https://data.europa.eu/eli/reg/2024/1689/oj.
AMC can apply stricter internal policy targets as autonomy duration grows — the time between human interventions. These are product policy defaults, not statutory maturity thresholds:
| Autonomy Duration | Suggested Oversight | Example AMC Policy Target |
|---|---|---|
| < 1 minute | Standard approval gates | Level 3+ maturity |
| 1-15 minutes | Enhanced monitoring + circuit breakers | Level 4+ maturity |
| 15-60 minutes | Continuous oversight dashboard + auto-pause | Level 4+ with drift alerts |
| > 60 minutes | Mandatory periodic human checkpoints | Level 5 only, with FRIA |
Agents that proactively pause and request human input when encountering uncertainty score higher on oversight quality.
Requirement: Continuous risk management throughout the AI system lifecycle.
| AMC Evidence | Module | Questions |
|---|---|---|
| Risk register and treatment plans | src/ops/, src/forecast/ |
AMC-2.8, AMC-4.5 |
Assurance pack: duality (risk scenarios) |
src/assurance/packs/ |
— |
| Drift regression detection | src/drift/ |
AMC-4.1 |
Compliance mapping: euai_art9_risk_management |
src/compliance/builtInMappings.ts |
— |
Evidence requirement: Audit/metric/review events with ≥60% OBSERVED trust tier + duality pack score ≥75.
Requirement: Data quality, bias examination, and governance for training/operation data.
| AMC Evidence | Module | Questions |
|---|---|---|
| Data governance artifacts | docs/DATA_GOVERNANCE.md |
AMC-1.5 |
| DLP and exfiltration controls | src/shield/, src/vault/ |
AMC-1.8 |
Compliance mapping: euai_art10_data_governance |
src/compliance/builtInMappings.ts |
— |
Requirement: Technical documentation before market placement, sufficient for conformity assessment.
| AMC Evidence | Module | Questions |
|---|---|---|
| Architecture documentation | docs/ARCHITECTURE_MAP.md |
AMC-2.9 |
| Master reference | docs/AMC_MASTER_REFERENCE.md |
— |
| Agent passport (per-agent technical profile) | src/passport/ |
— |
Compliance mapping: euai_art11_technical_documentation |
src/compliance/builtInMappings.ts |
— |
Requirement: Automatic logging enabling traceability of system functioning.
| AMC Evidence | Module | Questions |
|---|---|---|
| Append-only evidence ledger | src/ledger/ |
AMC-1.6, AMC-1.7 |
| Hash-chained transparency log | src/transparency/logChain.ts |
— |
| Signed receipts | src/receipts/ |
— |
Compliance mapping: euai_art12_record_keeping |
src/compliance/builtInMappings.ts |
— |
Evidence requirement: LLM request/response + tool action/result + audit events with ≥70% OBSERVED trust tier.
Requirement: Instructions for use, intended purpose, known limitations, and performance characteristics.
| AMC Evidence | Module | Questions |
|---|---|---|
| Agent passport with capability declarations | src/passport/ |
AMC-2.4 |
| Transparency artifacts | src/transparency/ |
— |
Compliance mapping: euai_art13_transparency |
src/compliance/builtInMappings.ts |
— |
Requirement: Human oversight measures built into system design enabling intervention, override, or stop.
| AMC Evidence | Module | Questions |
|---|---|---|
| Approval gates and governor controls | src/approvals/, src/governor/ |
AMC-2.10, AMC-1.8 |
| Human oversight quality scoring | src/score/humanOversightQuality.ts |
AMC-HOQ-1 to AMC-HOQ-4 |
| Governance bypass assurance pack | src/assurance/packs/ |
— |
| Autonomy duration tracking | Domain risk × oversight interval | — |
Compliance mapping: euai_art14_human_oversight |
src/compliance/builtInMappings.ts |
— |
Evidence requirement: Audit/tool_action events ≥60% OBSERVED + governance_bypass pack score ≥85.
Requirement: Appropriate accuracy and resilience against errors, faults, and adversarial attacks.
| AMC Evidence | Module | Questions |
|---|---|---|
| Injection/exfiltration assurance packs | src/assurance/packs/ |
AMC-2.1, AMC-4.5 |
| Shield (prompt injection defense) | src/shield/ |
— |
| Production readiness scoring | src/score/productionReadiness.ts |
— |
Compliance mapping: euai_art15_accuracy_robustness |
src/compliance/builtInMappings.ts |
— |
Requirement: QMS ensuring compliance including documented policies and post-market monitoring.
| AMC Evidence | Module | Questions |
|---|---|---|
| Eval harness and test infrastructure | src/bench/, src/e2e/ |
AMC-2.2, AMC-2.3 |
| Compliance maps with signed governance | src/compliance/ |
— |
Compliance mapping: euai_art17_quality_management |
src/compliance/builtInMappings.ts |
— |
Requirement: FRIA completed before deploying in high-risk contexts.
| AMC Evidence | Module | Questions |
|---|---|---|
| FRIA artifact | docs/FRIA.md, .amc/fria.json |
AMC-2.6 |
| Diagnostic question bank (FRIA question) | src/diagnostic/questionBank.ts |
— |
Compliance mapping: euai_art27_fria |
src/compliance/builtInMappings.ts |
— |
Requirement: Post-market monitoring system proportionate to risks.
| AMC Evidence | Module | Questions |
|---|---|---|
| Drift detection and alerting | src/drift/, src/watch/ |
AMC-2.8 |
| Forecast and advisory engine | src/forecast/ |
— |
Compliance mapping: euai_art72_post_market_monitoring |
src/compliance/builtInMappings.ts |
— |
Requirement: Serious incidents reported to authorities within required timelines.
| AMC Evidence | Module | Questions |
|---|---|---|
| Incident subsystem | src/incidents/ |
AMC-2.7 |
| Audit trail for incident lifecycle | src/ledger/, src/audit/ |
— |
Compliance mapping: euai_art73_incident_reporting |
src/compliance/builtInMappings.ts |
— |
Requirement: Affected persons can obtain meaningful explanations of AI-assisted decisions.
| AMC Evidence | Module | Questions |
|---|---|---|
| Explainability packet | src/watch/explainabilityPacket.ts |
AMC-2.4 |
| Decision transparency artifacts | src/transparency/ |
— |
Compliance mapping: euai_art86_right_to_explanation |
src/compliance/builtInMappings.ts |
— |
AMC supports conformity assessment readiness through:
- Evidence-linked compliance reports —
amc compliance report --framework EU_AI_ACT - Signed audit binder — cryptographically verifiable evidence packages
- Cross-framework mapping —
src/score/crossFrameworkMapping.tsgenerates EU AI Act control coverage reports - Agent passport — per-agent technical documentation profile
AMC does not perform the conformity assessment itself — that requires a notified body or internal assessment per Art. 43 procedures.
| Date | Milestone |
|---|---|
| 2024-08-01 | Regulation entered into force |
| 2025-02-02 | Chapters I and II applicable |
| 2025-08-02 | Chapter III Section 4, Chapter V (GPAI) applicable |
| 2026-08-02 | Relevant Article 50 transparency obligations apply; GPAI enforcement powers also enter application |
| 2027-12-02 | Annex III high-risk rules apply under the current AI Omnibus political agreement timeline |
| 2028-08-02 | High-risk rules apply to systems integrated into regulated products under the current timeline |
The timeline can change. Verify it against the European Commission's high-risk guidance and AI Act policy page.
Healthcare, finance, employment, education, and law enforcement agents require stricter governance than code assistants or internal productivity tools. AMC enforces this through domain packs (src/score/domainPacks.ts) that adjust scoring thresholds based on deployment context.
Time between human interventions is a key maturity indicator:
- Low autonomy (frequent human checkpoints): Acceptable at lower maturity levels
- High autonomy (extended unsupervised operation): AMC recommends a Level 4-5 target with comprehensive evidence
- Self-limiting agents (proactively pause when uncertain): Score bonus on oversight quality dimension
This maps directly to Art. 14 human oversight requirements — the EU AI Act requires that oversight measures be "commensurate with the risks, level of autonomy and context of use."
- EU AI Act text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
- European Commission high-risk guidance: https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-high-risk-systems
- European Commission AI Act policy page: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- AMC Compliance Engine:
src/compliance/complianceEngine.ts - AMC EU AI Act Scorer:
src/score/euAIActCompliance.ts - AMC Cross-Framework Mapping:
src/score/crossFrameworkMapping.ts