Why map rules to articles at all
When an agent operates in an Annex III high-risk use, the deployer — not the model provider — carries the duties. Mapping each policy rule to the article it supports turns a vague "we're governed" claim into a concrete, evidencable control. It also tells you which obligations you have no rule for yet.
The map agents actually use
- Refund / spend approval gate → Art. 14 (human oversight). A high-value action requires a person in the loop.
- Data-residency block → Art. 9 / Chapter IV (data governance). Personal data stays in its permitted region.
- Logged policy decision → Art. 12 (record-keeping / logging of high-risk activity).
- Input validation + fallback → Art. 15 (accuracy, robustness, cyber-security).
- Risk controls across the pipeline → Art. 9 (risk management system).
What the map does not prove
A rule mapped to Art. 14 is evidence of a control, not a conformity certificate. Conformity is the deployer's responsibility across the full system, and the mapping should be validated with qualified counsel — especially because the Digital Omnibus has delayed several high-risk obligations. Annex III extensions currently track toward 2 December 2027; verify the current effective date before committing a timeline.
Using the map in practice
Extract your rules, label each with the obligation it supports, and keep the list next to your conformity assessment. When an auditor asks "where is your Art. 14 oversight?", you point at the rule and its log — not at a paragraph in a PDF.
Authoritative references
- EU AI Act (Reg. 2024/1689), Art. 9 / 12 / 14 / 15: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- AI Act explorer: https://artificialintelligenceact.eu/
- European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai