Q1 What is your relationship to the AI system? We build and sell it (provider) We use someone else's system (deployer) Both - we build on a model and deploy it
Q2 Where does it touch the EU? We are established in the EU No EU entity, but our system's output is used in the EU No EU users or customers at all
Q3 Does it operate in a high-risk area (Annex III): employment, credit or insurance decisions, education, essential services, law enforcement, migration, justice? Yes No Not sure
Q4 Do people interact with it directly (chat, voice, agent)? Yes No - it runs behind the scenes
Q5 Does it generate synthetic content (text for publication, images, audio, video)? Yes No
Q6 How are agent events logged today? Tamper-evident audit trail (append-only, verifiable) Ordinary logs / observability tooling Not systematically logged
Q7 How long are those logs kept? Six months or more, enforced Less than six months, or plan-dependent No retention policy
Q8 When a human approves, overrides, or reviews the AI, is that recorded as evidence? Yes, systematically No, or only in tickets and chat
Q9 Are users told they are interacting with AI, and is that disclosure recorded? Disclosed and recorded Disclosed, but not recorded anywhere Not disclosed Not applicable - no direct interaction
Answer the questions above