All insights
Regulation (EU) 2024/1689 · Deliverable

What an EU AI Act compliance deliverable actually contains

A usable compliance pack is an engineering artefact with a legal review, not a slide deck. This is the package LMXAI produces for teams shipping LLM, RAG and agent systems in the EU.

Regulation
Full application
Since 2 August 2026
Owner
Engineering + legal
Guide
Practical AI Act explainer

Nederlandse versie  ·  Türkçe versiyon

The deliverable is not a legal memo

An EU AI Act compliance deliverable is the set of artefacts that let you operate an AI system in the Union now that the high-risk framework has applied since 2 August 2026, without guessing. It answers four questions in writing: what the system is, which risk tier it falls in, which articles apply, and which evidence you can show — logs, evals, human-oversight design and a technical file — if a market-surveillance authority asks.

A law firm can interpret the text. It cannot produce the logging pipeline, the evaluation set or the deployment diagram. LMXAI’s deliverable is the engineering half of that pair. For the legal landscape itself, see the practical EU AI Act guide.

What is in the pack

  1. AI inventory and intended purpose. One record per system: users, data classes, deployment region, and whether you are a provider or a deployer under the Act.
  2. Risk classification. Mapping against Annex III, the Article 6(3) exception analysis, and a written rationale if you claim limited or minimal risk.
  3. Technical documentation draft. Architecture, training or adaptation data, evaluation protocol, known limitations — the skeleton of Annex IV, filled from the real stack.
  4. Logging and traceability. Event-level records aligned with Article 12: who asked what, which model version answered, which documents were retrieved.
  5. Human-oversight design. Where a person can stop, override or escalate — not a checkbox that “a human is somewhere in the company”.
  6. GPAI / model notes. If you host open weights or wrap a general-purpose model, the transparency and (where relevant) systemic-risk obligations that attach to that choice.
  7. Gap list and 90-day plan. What is already true in production versus what must be built before full enforcement.
WorkstreamLaw firmLMXAI deliverable
Legal interpretationPrimaryConsumed, not replaced
System inventoryInterview notesTied to repos, endpoints and models
Technical fileTemplateFilled from the running system
Art. 12 loggingRequirement textOpenTelemetry / gateway design
High-risk controlsPolicy languageEval, fallback, human gate in the graph

What it is not

It is not a CE-marking factory for every Annex III system, and it is not a substitute for notified-body work where that is required. It is also not “we used an EU cloud, therefore we are compliant.” Residency helps GDPR. The AI Act cares about risk, documentation and operational control.

When to commission this: you already have a prototype or a Copilot-class rollout, and legal has asked “are we a provider?” LMXAI runs the classification and the evidence map in weeks, then stays on to implement the gaps — logging, eval, sovereign serving — as the same partner.

How this ties to the rest of the stack

The same traces that satisfy Article 12 are the traces you need to debug a RAG agent. The same model card that feeds Annex IV is the card you need to swap vLLM weights without losing the plot. Compliance work that is detached from the serving stack becomes fiction the first time the model is updated.

Next step. If this is the decision in front of you, LMXAI will scope the system — not a workshop series.

Start a project