Automatos·ai
GitHubContact →
Plate / EU EU AI Act
What's in the product, what's partly there, what's next.
Reviewed · 8 Oct 2026

The EU AI Act, honestly.

Where Automatos stands against the Act's obligations, article by article. We mark each one as in the product today, partly there, or on the roadmap, and we only say “in the product” where the code backs it. Automatos is not certified: no notified body certifies most AI Act categories yet.

Reviewed · 8 October 2026
Covers · Automatos OS and Studio
Free tool · Classify your system →

In the product today.

The pieces a deployer can use now to meet their own obligations.

Art. 14 · Human oversight

Approvals a person controls

Actions that spend money, publish or change things outside the workspace wait for a person. Approvals are granted, denied or revoked from one inbox, a mission's plan is approved before it runs, and missions and agents can be paused.

Art. 14 · supports Art. 9

A risk class on every gated action

Each gated tool action is classified as read, internal write, publish, external side effect or destructive, and mapped to an oversight tier: monitored, human on the loop, or human approval required. Every approval card shows the tier and why. This is our oversight scheme, not the Annex III classification.

Art. 12 · Record-keeping

Audit logs kept at least 180 days

Audit and orchestration events are append-only, and a hard floor keeps them for at least 180 days. They are not yet cryptographically tamper-evident.

Art. 9 · Art. 15

Outputs checked against their brief

A mission's task outputs are verified automatically against the task's success criteria before the work moves on.

GDPR

Export and erasure

Export a workspace's data as one bundle, or erase the whole workspace. Erasing a data subject removes their memories and reports exactly what could not be removed, rather than hiding the gaps.

Hosting

Documents and vectors in the EU

Document and vector storage runs on AWS in Ireland (eu-west-1) today. Models run with the provider you choose; bring your own key to control where inference happens.

Article by article.

The Act's core obligations and where Automatos is on each. Reviewed as the product and the European AI Office's guidance change.

ArticleObligationWhere Automatos isStatus
Art. 5Prohibited practicesA platform-wide filter for prohibited practices (social scoring, manipulation, biometric categorisation) is planned. Today deployers must not configure prohibited uses.Roadmap
Art. 6 + Annex IIIHigh-risk classificationRisk classes and oversight tiers on every gated action. An Annex III tier per agent and mission is planned.Partly
Art. 9Risk managementAutomatic verification of task outputs. An auditor-facing posture view is planned.Partly
Art. 10Data governanceProvenance tracking for retrieval corpora is planned.Roadmap
Art. 12Record-keepingAppend-only audit logs with a 180-day floor. Tamper evidence and longer retention for high-risk use are planned.Partly
Art. 13Transparency to deployersGenerated agent cards (capabilities, limits, oversight needs) are planned.Roadmap
Art. 14Human oversightGrant, deny and revoke approvals, mission approval and pause. The policy plane that enforces the tiers ships switched off and says so; a workspace turns it on.In product
Art. 15Accuracy and robustnessOutput verification. Adversarial robustness testing is planned.Partly
Art. 43Conformity assessment supportA platform-level Annex IV technical-documentation draft. Per-agent documentation and export are planned.Partly
Art. 50Transparency to end usersA built-in AI-interaction notice for chat, voice and widgets is planned. Until then, add the disclosure in your own copy.Roadmap
Art. 53–55General-purpose AI modelsThese obligations sit with the model providers. Showing their disclosures in the model catalogue is planned.Roadmap
Art. 73Serious incident reportingAn incident-reporting workflow is planned.Roadmap

Provider and deployer: who covers what.

The Act splits responsibilities between the provider of an AI system and the deployer who uses it. Automatos provides the platform; the business running agents on it is usually the deployer.

Automatos · provider of the platform
  • The oversight and approval tooling, and the policy plane
  • Audit logging and its retention
  • Security of the platform
  • The platform's technical documentation
  • The roadmap above, delivered and published here
You · deployer of your use case
  • Classifying your use case (the checker is a start)
  • Meaningful human oversight: turn the policy plane on
  • Disclosing AI interaction to your end users
  • Risk assessment for your domain
  • Incident reporting to authorities where required
  • Legal counsel for any high-risk deployment

The dates.

FromWhat appliesNote
1 Aug 2024The Act enters into forceObligations then phase in.
2 Feb 2025Prohibited practices banned; AI literacyArticles 4 and 5.
2 Aug 2025General-purpose AI model rulesArticles 53–55, for model providers.
2 Aug 2026Most high-risk obligationsThe EU has proposed moving some high-risk deadlines: check current guidance.
2 Aug 2027High-risk AI in regulated productsAnnex I systems.

Common questions.

Is Automatos EU AI Act certified?

No, and nobody is yet for most categories: no notified certification body exists for them. This page shows what the platform does today and what's planned, so you can judge for yourself.

Does using Automatos make my system compliant?

Not on its own. Compliance depends on your use case and how you configure it. Automatos gives you human-oversight tooling and audit logs today; several obligations above are still on our roadmap, so plan for them with your counsel.

Who is the provider and who is the deployer?

Automatos provides the platform. The business that builds and runs agents on it is usually the deployer of the resulting AI system, and carries the deployer obligations for its use case.

What if my use case is high-risk under Annex III?

High-risk uses (HR screening, credit scoring, critical infrastructure, education, law enforcement and others) carry the full Chapter III obligations. Several of the platform pieces they need are on our roadmap today. Talk to us and to your own legal counsel before deploying.

Does this cover GDPR?

The AI Act and GDPR are separate. For GDPR, Automatos has workspace export, workspace erasure and data-subject erasure for memories, and our Privacy Policy applies.

Where is my data?

Document and vector storage runs on AWS in Ireland (eu-west-1) today. That's our current deployment, not a contractual residency guarantee. Inference runs with the model provider you choose.

Where does your system land?

Five questions give you an indicative risk tier, the articles to review and an obligations checklist. It runs in your browser; nothing is sent.

Last reviewed 8 October 2026. This page describes what the Automatos platform does and plans to do. It is not legal advice; deployers remain responsible for their own compliance with the EU AI Act and national law. Questions: contact us.