◊

fall-euaiact

EU AI Act sovereign toolkit · prime 607 · ◊·κ=1

Paste your AI system description → get risk tier with article cites. Navigate the Act by use case. Drop in audit-trail JS for Article 12. Generate transparency badges. Built sovereign · runs offline · your data never leaves the browser.

RESEARCH ONLY · NOT LEGAL ADVICE · verify with counsel
UI only · article text stays in English with EUR-Lex links to all 24 official languages
Honest framing: this is a heuristic toolkit grounded in the AI Act text (Regulation 2024/1689). The risk classifier is a starting point, not a definitive judgment. For systems that materially affect anyone, get a qualified legal opinion. The Act's full text is at eur-lex.europa.eu/eli/reg/2024/1689/oj.

⚙ Settings · BYOK deep classifier

T0 keyword classifier always runs (offline · no key). T2 adds LLM-powered deeper analysis using your own API key. Key stays in localStorage on your device · never sent anywhere except the provider you choose.

R0 ● Risk classifier

Paste a plain-English description of what your AI system does. The classifier matches against the Act's risk tiers and returns the most-likely category with the article cites you need to read.

R1 〜 Article navigator · search the Act by use case

Most common operational questions mapped to the articles you need. Click to expand. Text is summaries — read the Act text via the official link for legal weight.

Article 5 · Prohibited AI practices (don't deploy these)

Eight categories are flat-banned. If your system does any of these in the EU, you cannot deploy:

  • Subliminal/manipulative techniques that materially distort behaviour and cause harm
  • Exploitation of vulnerabilities (age, disability, social/economic situation) to materially distort behaviour
  • Social scoring by public authorities causing detrimental treatment
  • Predictive policing assessing risk of an individual committing a crime based solely on profiling
  • Untargeted scraping of facial images from internet/CCTV for facial recognition databases
  • Emotion recognition in workplaces and educational institutions (with narrow medical/safety carveouts)
  • Biometric categorisation by race, political opinion, sexual orientation, religion etc.
  • Real-time remote biometric identification in public spaces for law enforcement (with very narrow exceptions)

Enforcement: applies from 2 Feb 2025. Fines up to €35M or 7% global turnover.

Article 6 + Annex III · High-risk classification (the wedge)

Your system is high-risk if it falls into one of the 8 Annex III categories:

  • 1 Biometrics (when not Article 5 prohibited)
  • 2 Critical infrastructure (water · gas · electricity · road · rail · digital infra)
  • 3 Education & vocational training (admissions · scoring · cheating detection)
  • 4 Employment, worker management & access to self-employment (CV screening · performance evaluation · task allocation)
  • 5 Access to essential services (credit scoring · health insurance pricing · emergency services dispatch · public benefits eligibility)
  • 6 Law enforcement (evidence reliability · profiling · crime analytics)
  • 7 Migration, asylum & border control
  • 8 Administration of justice and democratic processes

Carveouts: if your system performs a narrow procedural task, or just improves a previously-completed human activity, OR is purely preparatory — you can argue it's NOT high-risk under Article 6(3). Document this assessment.

Enforcement: high-risk obligations apply from 2 Aug 2026 (for standalone systems) or 2 Aug 2027 (when AI is a safety component of a product covered by other EU regulation).

Article 9 · Risk management system (if high-risk)

You must establish, implement, document and maintain a risk management system across the entire system lifecycle. Specifically:

  • Identify and analyse known and foreseeable risks
  • Estimate and evaluate risks that may emerge in intended use AND foreseeable misuse
  • Adopt targeted risk-management measures
  • Test the system to identify the most appropriate risk-management measures

The system must be tested against established metrics throughout development and before placing on the market.

Article 10 · Data and data governance

Training, validation and testing datasets must:

  • Be relevant, sufficiently representative, and as far as possible free of errors and complete
  • Have the appropriate statistical properties for the intended purpose
  • Have data governance practices documented (collection · origin · annotation · curation)
  • Examine for possible biases that affect health, safety, fundamental rights, or could lead to discrimination

Sovereign-friendly: if your training data never leaves the user's device (your estate's pattern), this article is much easier to satisfy than for hosted services.

Article 11 + Annex IV · Technical documentation

Before placing a high-risk system on the market, you must compile technical documentation per Annex IV. This includes:

  • General description of the AI system (intended purpose · provider · version)
  • Detailed description of system elements (data · algorithms · architecture)
  • Detailed information on monitoring, functioning and control
  • Risk management documentation
  • Description of changes through lifecycle
  • List of harmonised standards applied (and where deviations exist, the technical solutions adopted)
  • EU declaration of conformity
  • Detailed description of the system for assessing post-market performance
Article 12 · Automatic record-keeping (audit logs)

High-risk systems must enable the automatic recording of events ("logs") over the system lifetime. Logs must allow:

  • Identification of situations that may result in the system presenting a risk
  • Identification of substantial modifications
  • Facilitation of post-market monitoring
  • Monitoring of operation for purposes of detecting bias

What to log: period of each use · reference database compared against · input data leading to a match · identification of natural persons involved in result verification.

Estate wedge: your Konomi prevHash + Ed25519 + cert chain already does this — better than most. See the "Drop-in audit shim" section below for the JS pattern.

Article 13 · Transparency to deployers

The system must come with instructions for use including:

  • Identity and contact details of provider
  • Intended purpose · including specific geographical/behavioural/functional setting
  • Level of accuracy, robustness and cybersecurity
  • Performance regarding specific persons or groups
  • Risks specific to the intended purpose
  • Human oversight measures (per Article 14)
  • Expected lifetime · maintenance · log access
Article 14 · Human oversight (the pause-before pattern)

High-risk systems must be designed so they can be effectively overseen by humans during use. The oversight must enable persons to:

  • Understand the system's capacities and limitations
  • Remain aware of "automation bias"
  • Correctly interpret the output
  • Decide not to use the output or override / reverse it
  • Intervene or interrupt the system via a "stop" button or similar

Estate match: every Fall* tool's pause-before-Save / pause-before-Post / pause-before-Submit gate is exactly this. You've been Article-14-compliant since v1.

Article 15 · Accuracy, robustness and cybersecurity

High-risk systems must achieve an appropriate level of:

  • Accuracy · declared in instructions for use
  • Robustness · to errors, faults, inconsistencies (technical redundancy · backup plans · fail-safe)
  • Cybersecurity · resilient against attempts to alter use, outputs or performance · including data-poisoning and adversarial examples
Article 50 · Transparency to end-users (the "this is AI" disclosure)

Four categories trigger user-facing transparency obligations:

  • AI systems interacting with humans (chatbots) → inform the user they're talking to AI, unless obvious
  • Emotion recognition / biometric categorisation → inform users when exposed
  • Deepfakes / manipulated content → disclose that content is AI-generated/manipulated
  • AI-generated text on matters of public interest → disclose AI generation (carveouts exist)

Generate a transparency badge: see the badge section below.

Enforcement: applies from 2 Aug 2026.

Article 26 · Obligations of deployers (the customer)

If you're the deployer (the one putting a high-risk system into service in the EU, even if you didn't build it), you have to:

  • Use the system in accordance with instructions
  • Assign human oversight to natural persons with the necessary competence, training, authority, and support
  • Monitor operation and inform the provider of risks or serious incidents
  • Keep the logs (Article 12) for at least 6 months
  • If you make decisions about natural persons using the system → inform them they're subject to a high-risk AI system
  • For workplace use → inform workers' representatives and the affected workers before deployment
Articles 51-55 · General Purpose AI (GPAI) obligations

If you're a provider of a general-purpose AI model (foundation model):

  • Technical documentation (Annex XI)
  • Information for downstream providers (Annex XII)
  • Copyright policy for training data
  • Public summary of training content

If the model presents systemic risk (huge compute thresholds), additional obligations: model evaluations, adversarial testing, incident tracking, cybersecurity protection.

Enforcement: applies from 2 Aug 2025 for new models; existing models had until 2 Aug 2027.

Penalties · what non-compliance costs

Maximum fines (whichever is higher):

  • Prohibited AI (Article 5): €35M or 7% of global annual turnover
  • Non-compliance with high-risk obligations: €15M or 3%
  • Supplying incorrect information to authorities: €7.5M or 1%

SMEs and startups: lower of the two amounts (capped not floored).

Member state authorities enforce. The European AI Office coordinates and is the sole authority for GPAI.

R6 ◯ Drop-in audit shim · Article 12 ready

Vanilla JS · zero dependencies · drop into any HTML tool to add Article-12-compliant logging. Stores in IndexedDB · cryptographically chained via SHA-256 prevHash. Export to JSON for the 6-month retention requirement.

// ◊ Article 12 audit shim · drop into any sovereign tool const EU_AUDIT = (() => { const DB_NAME = 'eu-aiact-audit'; let db = null; let prevHash = '0'.repeat(64); async function open() { if (db) return db; return new Promise((res, rej) => { const r = indexedDB.open(DB_NAME, 1); r.onupgradeneeded = e => { const d = e.target.result; if (!d.objectStoreNames.contains('log')) d.createObjectStore('log', { keyPath: 'id', autoIncrement: true }); }; r.onsuccess = e => { db = e.target.result; res(db); }; r.onerror = e => rej(e.target.error); }); } async function sha256(s) { const buf = new TextEncoder().encode(s); const h = await crypto.subtle.digest('SHA-256', buf); return Array.from(new Uint8Array(h)).map(b => b.toString(16).padStart(2,'0')).join(''); } async function log(event) { await open(); const entry = { ts: new Date().toISOString(), event_type: event.type || 'unknown', input_summary: event.input?.slice(0, 200) || null, output_summary: event.output?.slice(0, 200) || null, operator_id: event.operator || null, prev_hash: prevHash, }; entry.hash = await sha256(JSON.stringify(entry)); prevHash = entry.hash; const tx = db.transaction('log', 'readwrite'); tx.objectStore('log').add(entry); return entry; } async function exportAll() { await open(); const tx = db.transaction('log', 'readonly'); return new Promise((res, rej) => { const r = tx.objectStore('log').getAll(); r.onsuccess = () => res(r.result); r.onerror = e => rej(e.target.error); }); } return { log, exportAll }; })(); // ─── usage ───────────────────────────────────────────── // At every Article-12-relevant event: EU_AUDIT.log({ type: 'inference', // or 'model_update' · 'human_review' · 'override' · 'error' input: 'user query text', output: 'system response', operator: 'user-id-or-anon' }); // At export time (Article 26 · 6-month retention): const allLogs = await EU_AUDIT.exportAll(); console.log(JSON.stringify(allLogs, null, 2));

Composes with Konomi's prevHash + Ed25519 chain already running in your estate. The cryptographic chain means logs are tamper-evident · which goes beyond Article 12's literal text but matches the spirit (and is what auditors will actually want to see).

R3 ♡ Article 50 · transparency badge generator

Generate a small visible badge for your AI-using interface. Covers chatbots, emotion recognition systems, biometric categorisation, deepfakes, and AI-generated public-interest text.

R5 ◐ High-risk checklist · Annex IV documentation

If your classifier verdict came back HIGH RISK, tick each item once documentation exists. Aim for 100% before going live in the EU. Status persists in IndexedDB.

0 / 14 documented

R2 ┃ Annex IV documentation generator

Fill in each field. Output is a downloadable Markdown document structured per Annex IV. Use as the starting draft for your technical documentation file. Inputs persist locally so you can come back. Nothing is sent anywhere.

R4 △ Classification log

Every classification you run is logged locally (IndexedDB · never leaves device). Use this as your own Article 11 evidence of due-diligence assessments.

No classifications yet · paste a description above to start