---

Why mapping matters

A risk classification tells you the tier; an obligation map tells you what to actually do. Most teams stop at "we're probably high-risk" and never connect each system component to the article it touches. The result is a pile of obligations with no owner and no evidence. Mapping turns the Act from a wall of text into a checklist tied to the parts of your system you control.

ClauseGuard produces a gap report that lines up your system description against the obligations attached to its tier. The map is a view of exposure — it shows where you stand, not a sign-off that you are done.

The obligation map for high-risk systems (Art. 9–17)

For a high-risk system (Annex III use), the core obligations are:

  • Art. 9 — Risk management system: a continuous process to identify and mitigate known and foreseeable risks.
  • Art. 10 — Data and data governance: training, validation, and testing data examined for bias and representativeness.
  • Art. 11 — Technical documentation: the system described well enough for a third party to assess conformity.
  • Art. 12 — Record-keeping / logging: capabilities to trace how the system produced its output.
  • Art. 13 — Transparency and user information: users told they are interacting with an AI system and what its limits are.
  • Art. 14 — Human oversight: a natural person who understands, monitors, and can interrupt the system.
  • Art. 15 — Accuracy, robustness, and cybersecurity: perform as intended and resist errors, manipulation, and attacks.
  • Art. 16 — Compliance with cybersecurity requirements and Art. 17 — Conformity assessment for high-risk systems.

A mapping lists, per article, whether you can currently evidence the control. Every "no" becomes a remediation item.

Who carries each obligation (deployer vs provider)

For high-risk uses, most of the duties above land on the deployer — the organization that puts the system into a specific use with a specific purpose. The general-purpose model provider carries a different, narrower set. This split is the single most misunderstood point in EU AI Act planning: buying a compliant-model claim from your vendor does not discharge the deployer's Art. 9–17 duties.

A readiness report helps the deployer evidence those controls. It is one input to conformity, not the certificate itself.

What a mapping cannot tell you

A map shows gaps against the text of the Act. It does not tell you whether your specific deployment clears the bar in practice, whether your evidence would survive a regulator's review, or whether a national authority has additional expectations. Those judgements stay with qualified counsel and the deploying organization. Treat the map as a starting point for a conversation with counsel, not a substitute for it.

Authoritative references

  • EU AI Act (Reg. 2024/1689), Art. 9 / 10 / 11 / 12 / 13 / 14 / 15 / 16 / 17: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  • AI Act explorer: https://artificialintelligenceact.eu/
  • European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai