6 ms·
The Annex III vs general purpose distinction is doing a lot of heavy lifting here that most teams aren't thinking about yet. If your agent is making or substant
by matrixgard 7mo ago
The Annex III vs general purpose distinction is doing a lot of heavy lifting here that most teams aren't thinking about yet. If your agent is making or substantially influencing decisions in employment, credit, education, or critical infrastructure, you're in the high-risk bucket with the full 25-item checklist. If it's general purpose AI (GPAI), you're under a different regime entirely with lighter obligations unless it's "systemic risk" tier. Getting this classification wrong in either direction is expensive — either you over-engineer compliance for something that doesn't need it, or you show up to an audit in August having built the wrong controls.
The part teams consistently underestimate is the human oversight requirement under Article 14. It's not just logging that a human was in the loop, you have to demonstrate the human had meaningful ability to override, and that the system was designed to make that possible. That's an architecture decision, not a documentation task, and you can't bolt it on after.
What's the actual deployment context here — are you shipping this to customers who then run agents against EU data subjects, or is this internal tooling?