Skip to content

register v11 · questionnaire v9

FR

What the register concludes, and why

Nine worked examples, classified by the v11 rules. Every verdict opens to show the reasoning that produced it and the obligations that follow — out of 61 the register tracks. The organisation is shown as “THE COMPANY”.

  1. AIS-101Depot rest-area fatigue and mood camera (pilot)PROHIBITED (unacceptable risk)Provider and deployer0/61 obligations ›

    PROHIBITED. The art.5(1)(a)-(h) prohibitions have applied since 2 February 2025. This is a bar, not a compliance deadline: the system may not be placed on the market, put into service or used, and there is nothing to bring into compliance.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. FPROHIBITED (unacceptable risk) — An art.5(1)(a)-(h) prohibited practice is declared. The system may not be placed on the market, put into service or used — this is not a heavier compliance burden, it is a bar.[CZ]From your answers to: Q3.1 — Does the tool do any of these things? (tick all that apply)

    Obligations that apply (0 of 61; 61 ruled out)

    None under the AI Act. Other instruments may still apply.

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY develops an AI system or tool for internal usage
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    No
    Personal data present? (GDPR art.4)
    Yes
  2. AIS-102Substation load-shedding advisorHigh risk (Annex III)Provider19/61 obligations ›

    Already applicable: art.4 AI literacy. Compliance is owed from placement, not from a future date. The art.6(2) high-risk requirements apply from 2 December 2027. The registration (art.49(2)) and the documentation of the non-classification assessment (art.6(4)) are due BEFORE the system is placed on the market or put into service — an event-anchored duty with no calendar date.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. DINo — materially influences a decision — The system materially influences the outcome of a decision, so it cannot be said to pose no significant risk.[DH]From your answers to: Q7.2 — Could the tool MATERIALLY influence the outcome of a decision, in a way liable to harm a person?
    3. FHigh risk (Annex III) — Falls within an Annex III area and the art.6(3) exemption is unavailable: high-risk under art.6(2).[HR]From your answers to: Q6.4 — Within the selected context or contexts, what is the system intended to do?

    Obligations that apply (19 of 61; 42 ruled out)

    The system is high-risk and you are its provider. Chapter III, Section 2 applies in full — these are the duties that must be discharged BEFORE the system is placed on the market or put into service, not afterwards.

    • art.9Risk management system (art.9)
    • art.10Data and data governance (art.10)
    • art.11 / Annex IVTechnical documentation (art.11 / Annex IV)
    • art.12Record-keeping / logs (art.12)
    • art.13Instructions & transparency for the deployer (art.13)
    • art.14Human oversight (art.14)
    • art.15Accuracy, robustness, cybersecurity (art.15)
    • art.16(b)Name, registered trade name and contact address on the system or packaging (art.16(b))
    • art.16(l)Accessibility requirements — Directives (EU) 2016/2102 and (EU) 2019/882 (art.16(l))
    • art.17Quality management system (art.17)
    • art.18Retain technical documentation, QMS records and declarations for 10 years (art.18)
    • art.19Retain automatically generated logs for at least 6 months (art.19)
    • art.20Corrective actions and duty to inform the chain and authorities (art.20)
    • art.16(k), art.21Cooperate with authorities and demonstrate conformity on reasoned request (art.16(k), art.21)
    • art.43/47/48Conformity assessment + CE + EU declaration (art.43/47/48)
    • art.72Post-market monitoring (art.72)
    • art.73Reporting of serious incidents (art.73)

    Critical-infrastructure systems register in the secure national section rather than the public EU database (art.49(1), second subparagraph). Same duty, different register — filing in the public one would not discharge it. The same TIMING CAVEAT applies as to the EU-database registration above: the trigger is placing on the market, the calendar date is under legal review, and the 2 December 2027 substantive milestone is not relief from it.

    • art.49(5)Registration at NATIONAL level — Annex III point 2 (art.49(5))

    art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

    • art.4AI literacy (art.4)

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY sells or licenses an AI system or component to a Client or partner, under THE COMPANY's name
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    Critical infrastructure
    Personal data present? (GDPR art.4)
    No
  3. AIS-103Safety-training marking cross-checkNot high-risk (Annex III exemption)Deployer6/61 obligations ›

    Already applicable: art.4 AI literacy. Compliance is owed from placement, not from a future date. No further dated milestone.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. DIYes — One of the art.6(3) conditions is met and neither disqualifier applies, so the system is not high-risk despite falling in an Annex III area. The reasoning must be documented and the system still registered.[DJ]From your answers to: Q7.3 — Is the tool limited to AT LEAST ONE of the following?
    3. FNot high-risk (Annex III exemption) — Falls in an Annex III area but meets an art.6(3) condition without profiling or materially influencing a decision. The system is NOT high-risk — but the assessment must be documented and the system still registered under art.49(2).[HR, DJ]From your answers to: Q6.4 — Within the selected context or contexts, what is the system intended to do? ; Q7.3 — Is the tool limited to AT LEAST ONE of the following?

    Obligations that apply (6 of 61; 55 ruled out)

    art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

    • art.4AI literacy (art.4)

    Personal data is processed and the GDPR applies territorially. These duties are owed under the GDPR independently of anything the AI Act requires — a minimal-risk system can still carry all of them.

    • art.6 / art.9(2)Legal basis identified & documented (art.6 / art.9(2))
    • art.30Record of processing activities (art.30)
    • art.13-14Information to data subjects (art.13-14)
    • art.32Security of processing — technical and organisational measures (art.32)

    A third party processes this personal data on your behalf. art.28 requires a written processor agreement containing the mandated terms — a supplier contract that is silent on them does not satisfy it.

    • art.28(3)Written processor agreement with each processor (art.28(3))

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY buys or subscribes to an external AI system, or a foundation model, for internal usage
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    Education & vocational training
    Personal data present? (GDPR art.4)
    Yes
  4. AIS-104Technical-standards language model (licensed to clients)Limited risk (transparency)Provider8/61 obligations ›

    Already applicable: art.4 AI literacy and the art.53-55 GPAI model obligations. Compliance is owed from placement, not from a future date. Transitional deadline for the art.111(4) marking transition: 2 December 2026, because this system predates the rules. That transition is lost if the system is substantially modified.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. FLimited risk (transparency) — Not high-risk, but art.50 transparency duties apply: people must be told they are dealing with AI, or that content was generated by it.[DO]From your answers to: Q8.2 — Does the tool generate or manipulate content — text, images, audio or video?

    Obligations that apply (8 of 61; 53 ruled out)

    art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

    • art.4AI literacy (art.4)

    The system generates or manipulates synthetic content beyond assistive standard editing. art.50(2) requires the output to be marked machine-readably as artificially generated.

    • art.50(2)Mark synthetic content machine-readable (art.50(2))

    At least one art.50 transparency duty applies. art.50(5) governs HOW it must be discharged: clearly and distinguishably, at the latest at the first interaction or exposure, and accessibly.

    • art.50(5)Provide the information clearly and distinguishably at the latest at first interaction or exposure, meeting accessibility requirements (art.50(5))

    GPAI provider duties that survive the art.53(2) open-source carve-out. A model released under a free and open-source licence with its weights is relieved of these — unless it carries systemic risk, in which case they apply regardless.

    • art.53(1)(a)Technical documentation of the model (art.53(1)(a)) — exemptible under art.53(2)
    • art.53(1)(b)Information to downstream integrators (art.53(1)(b)) — exemptible under art.53(2)

    You fine-tune, retrain, or develop and distribute a general-purpose AI model, which makes you its provider. Consuming a model through an API would not — modifying it does.

    • art.53(1)(c)Copyright compliance policy (art.53(1)(c))
    • art.53(1)(d)Public summary of training data (art.53(1)(d))
    • art.53(3)Cooperate with the Commission and national competent authorities (art.53(3))

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY sells or licenses an AI system or component to a Client or partner, under THE COMPANY's name
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    No
    Personal data present? (GDPR art.4)
    No
  5. AIS-105Site-safety scenario video studioLimited risk (transparency)Provider and deployer (reclassified art.25)4/61 obligations ›

    Already applicable: art.4 AI literacy and the art.50 transparency duties. Compliance is owed from placement, not from a future date. The art.50 transparency duties have applied since 2 August 2026. A system or model first placed on the market on or after that date must comply from placement — there is no separate future transition deadline.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. FLimited risk (transparency) — Not high-risk, but art.50 transparency duties apply: people must be told they are dealing with AI, or that content was generated by it.[DO, DT]From your answers to: Q8.2 — Does the tool generate or manipulate content — text, images, audio or video? ; Q8.7 — Does the tool generate or manipulate images, audio or video that resemble real people, objects, places, entities or events, and that would falsely appear to someone to be authentic or truthful — a deep fake?

    Obligations that apply (4 of 61; 57 ruled out)

    art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

    • art.4AI literacy (art.4)

    The system generates or manipulates synthetic content beyond assistive standard editing. art.50(2) requires the output to be marked machine-readably as artificially generated.

    • art.50(2)Mark synthetic content machine-readable (art.50(2))

    The system produces deep-fake image, audio or video content. art.50(4), first subparagraph, requires disclosure that the content has been artificially generated or manipulated.

    • art.50(4), 1st subparagraphDisclose deep fake content (art.50(4), 1st subparagraph)

      The obligation still applies: the content must be disclosed as artificially generated or manipulated. Because it forms part of an evidently artistic, creative, satirical or fictional work, art.50(4) limits that disclosure to making the existence of the generated content known in a manner that does not hamper the display or enjoyment of the work (recital 134). art.50(5) still governs how it is done — clearly, distinguishably, and no later than the first exposure. This holds only where the content is WHOLLY of that character: where an informative and a creative character combine, the informative one prevails and standard disclosure applies.

    At least one art.50 transparency duty applies. art.50(5) governs HOW it must be discharged: clearly and distinguishably, at the latest at the first interaction or exposure, and accessibly.

    • art.50(5)Provide the information clearly and distinguishably at the latest at first interaction or exposure, meeting accessibility requirements (art.50(5))

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY buys or subscribes to an external AI system, or a foundation model, for internal usage
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    No
    Personal data present? (GDPR art.4)
    No
  6. AIS-106Spare-parts demand forecasting, passed through to clientsMinimal riskDistributor1/61 obligations ›

    Already applicable: art.4 AI literacy. Compliance is owed from placement, not from a future date. No further dated milestone.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. FMinimal risk — In scope, not prohibited, not high-risk, and no art.50 transparency trigger. Voluntary codes of conduct apply; nothing mandatory follows from the risk level alone.

    Obligations that apply (1 of 61; 60 ruled out)

    art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

    • art.4AI literacy (art.4)

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY passes on or resells a supplier's AI tool to a Client, unchanged
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    No
    Personal data present? (GDPR art.4)
    No
  7. AIS-107Control-room operator attention monitorLimited risk (transparency)Deployer10/61 obligations ›

    Already applicable: art.4 AI literacy and the art.50 transparency duties. Compliance is owed from placement, not from a future date. The art.50 transparency duties have applied since 2 August 2026. A system or model first placed on the market on or after that date must comply from placement — there is no separate future transition deadline.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. FLimited risk (transparency) — Not high-risk, but art.50 transparency duties apply: people must be told they are dealing with AI, or that content was generated by it.[DR]From your answers to: Q8.5 — Does the tool read emotions from people, or sort people into categories using biometric data?

    Obligations that apply (10 of 61; 51 ruled out)

    art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)

    • art.4AI literacy (art.4)

    You deploy an emotion-recognition or biometric-categorisation system. art.50(3) requires the people exposed to it to be informed of its operation.

    • art.50(3)Inform persons exposed to emotion recognition / categorisation (art.50(3))

    At least one art.50 transparency duty applies. art.50(5) governs HOW it must be discharged: clearly and distinguishably, at the latest at the first interaction or exposure, and accessibly.

    • art.50(5)Provide the information clearly and distinguishably at the latest at first interaction or exposure, meeting accessibility requirements (art.50(5))

    Personal data is processed and the GDPR applies territorially. These duties are owed under the GDPR independently of anything the AI Act requires — a minimal-risk system can still carry all of them.

    • art.6 / art.9(2)Legal basis identified & documented (art.6 / art.9(2))
    • art.30Record of processing activities (art.30)
    • art.13-14Information to data subjects (art.13-14)
    • art.32Security of processing — technical and organisational measures (art.32)

    A data protection impact assessment is mandatory under GDPR art.35(3): the processing is a systematic and extensive automated evaluation on which decisions with legal or similarly significant effect are based (point a), or it processes art.9 special categories or art.10 conviction data at a scale you have not ruled out (point b), or it systematically monitors a publicly accessible area (point c). Decided on those tests alone — the AI Act art.6 classification is a different question with different triggers. The DPIA must be done BEFORE processing begins, and it does not replace a FRIA where AI Act art.27 also applies. Note art.35(3) is a non-exhaustive list: where no limb is established, art.35(1) and the supervisory authority’s own mandatory list still have to be screened, which is what register column EP reports.

    • art.35Data protection impact assessment — DPIA (art.35)

    Personal data leaves the EU/EEA, or it is UNKNOWN whether it does — including via a supplier or sub-processor. Chapter V requires a transfer mechanism. "Unknown" is treated as a transfer on purpose: an unmapped data flow is the normal way an unlawful transfer happens.

    • Ch. VTransfer safeguards outside the EU/EEA (Ch. V)

    A third party processes this personal data on your behalf. art.28 requires a written processor agreement containing the mandated terms — a supplier contract that is silent on them does not satisfy it.

    • art.28(3)Written processor agreement with each processor (art.28(3))

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY buys or subscribes to an external AI system, or a foundation model, for internal usage
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    No
    Personal data present? (GDPR art.4)
    Yes
  8. AIS-108Robot-cell proximity braking controllerAnnex I Section B — Machinery route (art.2(2))Provider0/61 obligations ›

    The art.2(2) machinery-route provisions apply from 2 August 2028.

    How this was decided

    1. CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
    2. FAnnex I Section B — Machinery route (art.2(2)) — A safety component of a product covered by the Machinery Regulation. art.2(2) routes it largely out of the AI Act's high-risk regime and into the sectoral one — a carve-out, not a clean exit, and one a lawyer should confirm.[DB, DC, DD]From your answers to: Q5.1 — Is the tool built into a product covered by the EU product-safety rules listed in Annex I — or is it that product itself? ; Q5.2 — What does the tool actually do inside that product? ; Q5.3 — Does that product have to be checked by an outside certification body, for health or safety reasons? ; Q5.4 — Is the product a machine covered by the Machinery Regulation (EU) 2023/1230?

    Obligations that apply (0 of 61; 61 ruled out)

    None under the AI Act. Other instruments may still apply.

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY sells or licenses an AI system or component to a Client or partner, under THE COMPANY's name
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    No
    Personal data present? (GDPR art.4)
    No
  9. AIS-109Aerodynamic surrogate solver (research programme)Outside AI Act scopeProvider and deployer0/61 obligations ›

    No AI Act compliance date arises for this system on the register's three tracks. Obligations under other instruments may still apply.

    How this was decided

    1. CMNo — exempt (art.2) — An art.2(3)-(12) exemption is claimed, which takes the system outside the Regulation entirely.[CL]From your answers to: Q2.2 — Does the tool fall into any of these cases?
    2. FOutside AI Act scope — The AI Act does not apply, so no risk level arises under it. Other law may still apply.

    Obligations that apply (0 of 61; 61 ruled out)

    None under the AI Act. Other instruments may still apply.

    Answers behind it

    Q1 · What does THE COMPANY do with this tool?
    THE COMPANY develops an AI system or tool for internal usage
    Q2 · At go-live, whose name or trademark is on it?
    —
    [B] High-risk area — Annex III
    No
    Personal data present? (GDPR art.4)
    No

Preview of the v11 rules on nine invented systems. Fictional data — they belong to nobody; no account, nothing stored.