Article by article.
The Act's core obligations and where Automatos is on each. Reviewed as the product and the European AI Office's guidance change.
| Article | Obligation | Where Automatos is | Status |
| Art. 5 | Prohibited practices | A platform-wide filter for prohibited practices (social scoring, manipulation, biometric categorisation) is planned. Today deployers must not configure prohibited uses. | Roadmap |
| Art. 6 + Annex III | High-risk classification | Risk classes and oversight tiers on every gated action. An Annex III tier per agent and mission is planned. | Partly |
| Art. 9 | Risk management | Automatic verification of task outputs. An auditor-facing posture view is planned. | Partly |
| Art. 10 | Data governance | Provenance tracking for retrieval corpora is planned. | Roadmap |
| Art. 12 | Record-keeping | Append-only audit logs with a 180-day floor. Tamper evidence and longer retention for high-risk use are planned. | Partly |
| Art. 13 | Transparency to deployers | Generated agent cards (capabilities, limits, oversight needs) are planned. | Roadmap |
| Art. 14 | Human oversight | Grant, deny and revoke approvals, mission approval and pause. The policy plane that enforces the tiers ships switched off and says so; a workspace turns it on. | In product |
| Art. 15 | Accuracy and robustness | Output verification. Adversarial robustness testing is planned. | Partly |
| Art. 43 | Conformity assessment support | A platform-level Annex IV technical-documentation draft. Per-agent documentation and export are planned. | Partly |
| Art. 50 | Transparency to end users | A built-in AI-interaction notice for chat, voice and widgets is planned. Until then, add the disclosure in your own copy. | Roadmap |
| Art. 53–55 | General-purpose AI models | These obligations sit with the model providers. Showing their disclosures in the model catalogue is planned. | Roadmap |
| Art. 73 | Serious incident reporting | An incident-reporting workflow is planned. | Roadmap |
Common questions.
Is Automatos EU AI Act certified?
No, and nobody is yet for most categories: no notified certification body exists for them. This page shows what the platform does today and what's planned, so you can judge for yourself.
Does using Automatos make my system compliant?
Not on its own. Compliance depends on your use case and how you configure it. Automatos gives you human-oversight tooling and audit logs today; several obligations above are still on our roadmap, so plan for them with your counsel.
Who is the provider and who is the deployer?
Automatos provides the platform. The business that builds and runs agents on it is usually the deployer of the resulting AI system, and carries the deployer obligations for its use case.
What if my use case is high-risk under Annex III?
High-risk uses (HR screening, credit scoring, critical infrastructure, education, law enforcement and others) carry the full Chapter III obligations. Several of the platform pieces they need are on our roadmap today. Talk to us and to your own legal counsel before deploying.
Does this cover GDPR?
The AI Act and GDPR are separate. For GDPR, Automatos has workspace export, workspace erasure and data-subject erasure for memories, and our Privacy Policy applies.
Where is my data?
Document and vector storage runs on AWS in Ireland (eu-west-1) today. That's our current deployment, not a contractual residency guarantee. Inference runs with the model provider you choose.