EUAIAct:whereobligationsland,andwhatsupportsthem

The Act allocates obligations by role and by risk classification. Most of the questions that matter are about your deployment rather than about a platform.

Startwithrole,notwithtechnology

The first question is not which controls a platform has. It is what role your organisation occupies for a given system, because that determines which obligations apply at all. An organisation that builds and puts into service its own AI system for its own operational use is in a different position from one that places a system on the market.

The second question is classification: whether a particular use falls into a prohibited category, a high-risk category, a transparency-obligation category, or none of them. This is a use-by-use determination, and two superficially similar workflows can classify differently depending on what the output is used for.

Both questions require your own legal analysis. What a platform can usefully do is make the resulting obligations implementable — and make the evidence they require a by-product of operating the system rather than a separate documentation project.

Controlsthatsupporthigh-riskobligations

Named against the obligation categories they support, without asserting that their presence satisfies anything.

  • Risk management

    Risk classification per workflow, driving approval thresholds, evidence depth and evaluation frequency.

  • Data and data governance

    Access-aware retrieval, scoped permissions, lineage, residency enforcement and recorded processing.

  • Technical documentation

    Versioned policies, mappings, prompts and model registrations with authors and change history.

  • Record keeping

    Automatically generated decision records including model and policy version in force at the time.

  • Transparency

    Recorded reasoning and resolvable citations, available to surface in your own disclosure processes.

  • Human oversight

    Approvals routed by ownership, with the case assembled, expiry, escalation and recorded reasoning.

  • Accuracy and robustness

    Evaluation suites and regression tests run as lifecycle gates on every change.

  • Cybersecurity

    Non-human identity, short-lived credentials, isolation, egress control and supply-chain provenance.

NeuroCluster supports controls relevant to this framework. Whether a particular deployment meets a particular obligation depends on how it is configured, operated and documented, so a deployment-specific assessment remains required. Nothing on this page is legal advice.

Questions

Does using NeuroCluster make us AI Act compliant?
No. No platform can. Compliance depends on your role, your classification, your configuration, your documentation and your processes. What the platform can do is make the required controls implementable and the required records a by-product of operation.
Are you a provider or are we?
It depends on what is built and how it is placed into service, and it is a determination for your legal advisers rather than for us to assert on a web page. We will engage with the analysis and provide what a provider or deployer needs from a technology supplier.
How do we classify our use cases?
Use by use, against the Act's categories, with legal input. A useful practical step is to write down what each output is actually used for and who is affected by it, because classification follows the consequence rather than the technique.

Bring us one operational problem.

You do not need a finished brief. Bring the problem — we will work out the next step together.

Or book a call with the team