Skip to main content

EU AI Act

Coming soon — Preview

The EU AI Act policy is in Preview and not yet generally available in azuma nori. It is not currently selectable when creating a project. The page below describes the intended analysis scope; it will move into the active policy set once the framework ships. See Policy Stability.

The EU Artificial Intelligence Act (AI Act) is the European Union's horizontal regulation for artificial-intelligence systems. It takes a risk-based approach, classifying AI systems by risk level (from prohibited practices through high-risk systems to limited- and minimal-risk uses) and attaching obligations accordingly — including risk management, data governance, technical documentation, transparency, human oversight, and robustness and cybersecurity for high-risk systems.

How the analysis knows the Act reaches you​

Whether the AI Act reaches your project is decided once, by you, in the guided triage — not separately by each control. Every control is handed the classification you confirmed and assesses against it.

That distinction matters more than it sounds, because two statements a reader often merges are now kept apart:

  • A duty has no subject in your system. The obligation reaches you; there is simply nothing here it attaches to. That is reported as Not Applicable.
  • The regulation does not reach the project at all. That is your recorded classification, and it switches off obligations wholesale.

The report shows both, separately, and only the second rests on your determination.

When a control disagrees​

A control reads your code and may conclude the opposite of what you recorded — that a duty attaches where your classification says it does not. When that happens the control's conclusions are held back and reported, not applied.

  • It is not an error. The control ran and reached conclusions. They are withheld because they rest on a premise that contradicts your recorded classification.
  • It is not Not Applicable either. Nothing has been ruled out of scope.
  • The desktop shows it amber and unscored, with Details still reachable so you can read what the control actually found.

Nothing goes out of scope on the model's say-so. nori reports the disagreement; it never acts on it. The disagreement is surfaced for you to resolve, and you resolve it by re-running the guided triage.

One consequence worth stating plainly: a disagreement never erases a defect that was actually found. If the control also found a real failure, it still fails on that failure — the disagreement is surfaced alongside it rather than swallowing it. A control is held back only when there was nothing else wrong.

What follows from a disagreement​

  • The report opens as a Draft, naming the affected controls. Draft is the expected state for a report carrying an unresolved disagreement, and it does not block export.
  • Changing your classification re-runs the analysis. Results reached under a different determination are not reused, so a fresh triage means the affected controls are evaluated again. Worth knowing, because it is a real cost.
note

Scope determinations come back from the AI model you selected, and support varies between models. If yours does not return them for some objectives, your report says so in an advisory rather than guessing. That advisory describes what nori received back — it is not a finding about your project.

Focus Areas for Nori Analysis​

When azuma nori evaluates a codebase against the AI Act, the sub-agents concentrate on the technical, code-visible obligations relevant to AI-enabled products, for example:

  1. Robustness & Cybersecurity: secure handling of models, inputs, and outputs, and defenses appropriate to AI components.
  2. Data Governance: how training, validation, and input data are handled, protected, and kept free of secrets or sensitive material in code.
  3. Transparency & Logging: presence of logging and traceability that supports the record- keeping expected of higher-risk systems.
  4. Human Oversight Hooks: code paths that enable oversight, intervention, or override where applicable.

Providing Manual Evidence​

Much of the AI Act is governance and process oriented — risk classification, conformity assessment, technical documentation, and post-market monitoring — which source-code analysis alone cannot demonstrate. For these requirements, attach your supporting documentation (risk assessments, data-governance policies, technical documentation) via the Evidence tab in the Standalone Client, and nori will synthesize it with the code findings.