The gaps that appear when you actually score

Most teams assume they are "mostly fine" until they map the system to the articles. The same gaps show up again and again — none of them exotic, all of them easy to miss until you look.

Gap 1 — no named human-oversight owner (Art. 14)

High-risk systems need a natural person who understands, monitors, and can interrupt the system. Teams ship the model but never assign the owner. The control exists in theory, unowned in practice.

Gap 2 — data governance not documented (Art. 10)

Training and evaluation data need examination for bias and representativeness. Teams use the data but never document the governance, so they cannot evidence Art. 10 at assessment time.

Gap 3 — no risk management file (Art. 9 / Art. 11)

The Act expects a risk-management system and technical documentation. Teams iterate on the model but keep no risk file, so the conformity assessment has no artifact to point at.

Gap 4 — transparency duties unlabeled (Art. 50)

A chatbot or synthetic-content feature needs disclosure. Teams ship it without labeling, hitting the "limited-risk" transparency layer they did not know applied.

Closing the gaps

Score the system, list the gaps per article, assign an owner to each, and log the assessment. Re-run after any material change. The report is a view of your exposure, not a guarantee — but it turns invisible gaps into an owned remediation list.

Authoritative references

  • EU AI Act (Reg. 2024/1689), Art. 9 / 10 / 11 / 14 / 50: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  • AI Act explorer: https://artificialintelligenceact.eu/
  • European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai