---
Why mapping matters
A risk classification tells you the tier; an obligation map tells you what to actually do. Most teams stop at "we're probably high-risk" and never connect each system component to the article it touches. The result is a pile of obligations with no owner and no evidence. Mapping turns the Act from a wall of text into a checklist tied to the parts of your system you control.
ClauseGuard produces a gap report that lines up your system description against the obligations attached to its tier. The map is a view of exposure — it shows where you stand, not a sign-off that you are done.
The obligation map for high-risk systems (Art. 9–17)
For a high-risk system (Annex III use), the core obligations are:
- Art. 9 — Risk management system: a continuous process to identify and mitigate known and foreseeable risks.
- Art. 10 — Data and data governance: training, validation, and testing data examined for bias and representativeness.
- Art. 11 — Technical documentation: the system described well enough for a third party to assess conformity.
- Art. 12 — Record-keeping / logging: capabilities to trace how the system produced its output.
- Art. 13 — Transparency and user information: users told they are interacting with an AI system and what its limits are.
- Art. 14 — Human oversight: a natural person who understands, monitors, and can interrupt the system.
- Art. 15 — Accuracy, robustness, and cybersecurity: perform as intended and resist errors, manipulation, and attacks.
- Art. 16 — Compliance with cybersecurity requirements and Art. 17 — Conformity assessment for high-risk systems.
A mapping lists, per article, whether you can currently evidence the control. Every "no" becomes a remediation item.
Who carries each obligation (deployer vs provider)
For high-risk uses, most of the duties above land on the deployer — the organization that puts the system into a specific use with a specific purpose. The general-purpose model provider carries a different, narrower set. This split is the single most misunderstood point in EU AI Act planning: buying a compliant-model claim from your vendor does not discharge the deployer's Art. 9–17 duties.
A readiness report helps the deployer evidence those controls. It is one input to conformity, not the certificate itself.
What a mapping cannot tell you
A map shows gaps against the text of the Act. It does not tell you whether your specific deployment clears the bar in practice, whether your evidence would survive a regulator's review, or whether a national authority has additional expectations. Those judgements stay with qualified counsel and the deploying organization. Treat the map as a starting point for a conversation with counsel, not a substitute for it.
Authoritative references
- EU AI Act (Reg. 2024/1689), Art. 9 / 10 / 11 / 12 / 13 / 14 / 15 / 16 / 17: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- AI Act explorer: https://artificialintelligenceact.eu/
- European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai