Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.flowx.ai/llms.txt

Use this file to discover all available pages before exploring further.

Observatory ships with 18 EU AI Act requirements pre-mapped to operational controls. The scope of each requirement depends on the risk tier of the app (minimal / limited / high), set in the AI Registry.

Requirement scope by risk tier

Risk tierNumber of EU AI Act requirements in scope
MinimalTransparency obligations only
LimitedTransparency + user information
HighAll 18 requirements
UnacceptableBanned — flagged for removal
If an app’s tier is set incorrectly, the wrong requirements light up. Confirm the tier before reading status.

The 18 mapped requirements

These are grouped roughly along the Act’s structure. Observatory tracks them individually; the grouping is for readability.

Risk management and quality (Articles 9, 17)

RequirementBacking controls
Risk management systemRisk Dashboard + Assessments
Quality management systemAudit Trail + Evidence

Data and data governance (Article 10)

RequirementBacking controls
Training data governanceManual evidence (data lineage docs)
Validation and testing dataDatasets + Experiments
Bias detection in trainingManual evidence + drift monitor on protected attributes

Technical documentation (Articles 11, 12, 13)

RequirementBacking controls
Technical documentationManual evidence + registry metadata
Record-keeping (logging)Telemetry + 7-year retention setting
Transparency to usersManual evidence + UI screenshots

Human oversight (Article 14)

RequirementBacking controls
Human-in-the-loopManual evidence + tool definitions
Override mechanismsManual evidence

Accuracy and robustness (Article 15)

RequirementBacking controls
Accuracy levelsEvaluations + Experiments
CybersecurityPolicies (prompt-injection) + Audit Trail
Robustness to errorsAlerts + Drift Monitor

Post-market monitoring (Article 61)

RequirementBacking controls
Post-market monitoring planManual evidence (the plan document)
Continuous monitoring dataTelemetry + Analytics
Serious-incident reportingAlerts with incident tag + Audit Trail

Notifications (Article 62)

RequirementBacking controls
Conformity assessmentAssessments template
Registration in EU databaseManual evidence (registration confirmation)

Status semantics

Each requirement evaluates to:
  • Met — all backing controls have approved, in-date evidence
  • Partial — some controls met, others have gaps
  • Gap — at least one control has no current evidence
  • Out of scope — risk tier doesn’t trigger this requirement
The Article-level roll-up is the worst status of its requirements (any Gap → Gap).

Producing the audit pack

The EU AI Act view supports a one-click export of the audit pack:
  • Per-requirement evidence list with timestamps
  • Backing telemetry summaries
  • Assessment results
  • Gap analysis with remediation plan
POST /api/compliance/export?framework=eu-ai-act&app_id=...
Returns a ZIP with PDF and JSON outputs.

Gap analysis & heatmap

Cross-framework view that includes EU AI Act.

NIST AI RMF

Many EU AI Act requirements overlap with NIST controls.
Last modified on June 2, 2026