Rekvira

Jobs / AI-governance or compliance lead

AI system classification memo

“We are about to put an AI system into service and have to say where it sits under the AI Act.”

1.9 min55 tool calls40 sources read33 citations verified

Recorded 23 September 2026 on the live service with Claude Code 2.1.280 (headless: claude -p), model claude-opus-5-5.

Today A vendor puts a lawyer's AI Act classification of one system at about 10 billable hours. Vendor estimate: Aguardic

The run

Each step is a Rekvira playbook your assistant reads and follows. Open a step to see every call it made and what came back.

  1. Connected and read what the corpus holds today

    2 tool calls · under 1 s
    Show the 2 calls
    RekviraConnected, no accountconnect0.2 s
    connect({})
    RekviraRead what the corpus holds todaystart_here0.2 s
    start_here({})
  2. Tested the system against Article 6 and Annex III

    9 tool calls · 10 s
    Show the 9 calls
    RekviraOpened the playbook high-risk-triageget_workflow0.2 s
    get_workflow({"workflow_id": "high-risk-triage"})
    RekviraChecked which acts are loaded and their dateslist_regulations0.1 s
    list_regulations({})
    • eu-ai-act EU AI Act
    • dora DORA (Digital Operational Resilience Act)
    • gdpr GDPR (General Data Protection Regulation)
    RekviraSearched eu-ai-act for “high-risk AI system Annex III creditworthiness credit score”search_regulation0.1 s
    search_regulation({"regulation": "eu-ai-act", "query": "high-risk AI system Annex III creditworthiness credit score"})
    • ANNEX III(5)
    • Article 5(1)
    • Article 6(2)
    RekviraArticle 6, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 6})
    • Article 6 Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the A
    RekviraANNEX III, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "annex", "number": "III"})
    • ANNEX III Biometrics, in so far as their use is permitted under relevant Union or national law: (a) (a) remote biometric identification systems. This shall not include AI systems intended to be u
    RekviraObligation headings for deployer in eu-ai-actlookup_obligations0.0 s
    lookup_obligations({"regulation": "eu-ai-act", "role": "deployer", "system_class": "high-risk"})
    • Article 26
    RekviraObligation headings for provider in eu-ai-actlookup_obligations0.1 s
    lookup_obligations({"regulation": "eu-ai-act", "role": "provider", "system_class": "high-risk"})
    • Article 16
    RekviraArticle 3, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 3})
    • Article 3 ‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs
    RekviraArticle 25, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 25})
    • Article 25 Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circums
  3. You confirm. Confirm the system description and whether you are its provider or its deployer.

    In this run: Checkpoints (recorded without a person present): Checkpoint: the system is a vendor-built model that scores the creditworthiness of individuals applying for consumer loans of up to EUR 15,000. Loan officers see the score and three reason codes, and a loan officer makes the final decision. Lumen Bankas does not change the model and uses it only in internal tools. I treat Lumen Bankas as the deployer and the vendor as the provider.

  4. Listed the duties that follow for the confirmed role

    11 tool calls · 15 s
    Show the 11 calls
    RekviraOpened the playbook deployer-obligationsget_workflow0.0 s
    get_workflow({"workflow_id": "deployer-obligations"})
    RekviraArticle 26, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 26})
    • Article 26 Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6. Deployers shall assign human o
    RekviraArticle 27, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 27})
    • Article 27 Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing
    RekviraArticle 4, full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 4})
    • Article 4 Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical
    RekviraArticle 86, full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 86})
    • Article 86 Any affected person subject to a decision which is taken by the deployer on the basis of the output from a high-risk AI system listed in Annex III, with the exception of systems listed under point 2 thereof, and which produces legal effects or similarly signif
    RekviraArticle 113, full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 113})
    • Article 113 This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union . It shall apply from 2 August 2026. However: (a) Chapters I and II shall apply from 2 February 2025; (b) Chapter III S
    RekviraArticle 5(1), full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "pinpoint": "Article 5(1)"})
    • Article 5(1) The following AI practices shall be prohibited: (a) the placing on the market, the putting into service or the use of an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the
    RekviraSearched eu-ai-act for “creditworthiness credit score access to financial resources”search_regulation0.0 s
    search_regulation({"regulation": "eu-ai-act", "query": "creditworthiness credit score access to financial resources", "kinds": ["recital"]})
    • Recital (58)
    • Recital (158)
    • Recital (102)
    RekviraArticle 13, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 13})
    • Article 13 High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately. An appropriate type and degree of transparency shall b
    RekviraRecital (58), full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "recital", "number": 58})
    • Recital (58) Another area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living.
    RekviraArticle 4, amendment (4), full textread_unit0.1 s
    read_unit({"regulation": "gdpr", "pinpoint": "Article 4(4)"})
    • Article 4, amendment (4) ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performan
  5. Checked every citation against the official text

    33 tool calls · 33 s
    Show the 33 calls
    RekviraArticle 6(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 6(2)", "regulation": "eu-ai-act", "quote": "AI systems referred to in Annex III shall be considered to be high-risk"})
    • Article 6(2) exists: held · quote: found
    RekviraArticle 6(3): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 6(3)", "regulation": "eu-ai-act", "quote": "an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons"})
    • Article 6(3) exists: held · quote: found
    RekviraArticle 6(1): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 6(1)", "regulation": "eu-ai-act", "quote": "covered by the Union harmonisation legislation listed in Annex I"})
    • Article 6(1) exists: held · quote: found
    RekviraArticle 6(4): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 6(4)", "regulation": "eu-ai-act", "quote": "A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment"})
    • Article 6(4) exists: held · quote: found
    RekviraAnnex III(5): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Annex III(5)", "regulation": "eu-ai-act", "quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud"})
    • ANNEX III exists: held · quote: found
    RekviraArticle 3(3): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 3(3)", "regulation": "eu-ai-act", "quote": "places it on the market or puts the AI system into service under its own name or trademark"})
    • Article 3, amendment (3) exists: held · quote: found
    RekviraArticle 3(4): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 3(4)", "regulation": "eu-ai-act", "quote": "using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity"})
    • Article 3, amendment (4) exists: held · quote: found
    RekviraArticle 3(52): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 3(52)", "regulation": "eu-ai-act", "quote": "‘profiling’ means profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679"})
    • Article 3, amendment (52) exists: held · quote: found
    RekviraArticle 4(4) GDPR: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 4(4) GDPR", "regulation": "gdpr", "quote": "to analyse or predict aspects concerning that natural person's performance at work, economic situation"})
    • Article 4, amendment (4) exists: held · quote: found
    RekviraArticle 25(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 25(1)", "regulation": "eu-ai-act", "quote": "they put their name or trademark on a high-risk AI system already placed on the market or put into service"})
    • Article 25(1) exists: held · quote: found
    RekviraArticle 5(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 5(1)", "regulation": "eu-ai-act", "quote": "detrimental or unfavourable treatment of certain natural persons or groups of persons in social contexts that are unrelated to the contexts in which the data was originally generated or collected"})
    • Article 5(1) exists: held · quote: found
    RekviraArticle 4: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 4", "regulation": "eu-ai-act", "quote": "shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff"})
    • Article 4 exists: held · quote: found
    RekviraArticle 26(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(1)", "regulation": "eu-ai-act", "quote": "use such systems in accordance with the instructions for use accompanying the systems"})
    • Article 26(1) exists: held · quote: found
    RekviraArticle 26(2): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(2)", "regulation": "eu-ai-act", "quote": "assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support"})
    • Article 26(2) exists: held · quote: found
    RekviraArticle 26(4): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(4)", "regulation": "eu-ai-act", "quote": "to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative"})
    • Article 26(4) exists: held · quote: found
    RekviraArticle 26(5): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(5)", "regulation": "eu-ai-act", "quote": "the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements"})
    • Article 26(5) exists: held · quote: found
    RekviraArticle 26(6): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(6)", "regulation": "eu-ai-act", "quote": "shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law"})
    • Article 26(6) exists: held · quote: found
    RekviraArticle 26(7): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(7)", "regulation": "eu-ai-act", "quote": "deployers who are employers shall inform workers’ representatives and the affected workers"})
    • Article 26(7) exists: held · quote: found
    RekviraArticle 26(9): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(9)", "regulation": "eu-ai-act", "quote": "to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679"})
    • Article 26(9) exists: held · quote: found
    RekviraArticle 26(11): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(11)", "regulation": "eu-ai-act", "quote": "shall inform the natural persons that they are subject to the use of the high-risk AI system"})
    • Article 26(11) exists: held · quote: found
    RekviraArticle 26(12): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(12)", "regulation": "eu-ai-act", "quote": "Deployers shall cooperate with the relevant competent authorities"})
    • Article 26(12) exists: held · quote: found
    RekviraArticle 27(1): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 27(1)", "regulation": "eu-ai-act", "quote": "deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights"})
    • Article 27(1) exists: held · quote: found
    RekviraArticle 27(2): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 27(2)", "regulation": "eu-ai-act", "quote": "The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system"})
    • Article 27(2) exists: held · quote: found
    RekviraArticle 27(3): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 27(3)", "regulation": "eu-ai-act", "quote": "the deployer shall notify the market surveillance authority of its results"})
    • Article 27(3) exists: held · quote: found
    RekviraArticle 27(4): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 27(4)", "regulation": "eu-ai-act", "quote": "shall complement that data protection impact assessment"})
    • Article 27(4) exists: held · quote: found
    RekviraArticle 86(1): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 86(1)", "regulation": "eu-ai-act", "quote": "the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken"})
    • Article 86(1) exists: held · quote: found
    RekviraArticle 86(3): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 86(3)", "regulation": "eu-ai-act", "quote": "only to the extent that the right referred to in paragraph 1 is not otherwise provided for under Union law"})
    • Article 86(3) exists: held · quote: found
    RekviraArticle 13(3): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 13(3)", "regulation": "eu-ai-act", "quote": "the human oversight measures referred to in Article 14"})
    • Article 13(3) exists: held · quote: found
    RekviraArticle 113: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 113", "regulation": "eu-ai-act", "quote": "It shall apply from 2 August 2026."})
    • Article 113 exists: held · quote: found
    RekviraRecital (58): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Recital (58)", "regulation": "eu-ai-act", "quote": "AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems"})
    • Recital (58) exists: held · quote: found
    RekviraArticle 26(3): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(3)", "regulation": "eu-ai-act", "quote": "without prejudice to other deployer obligations under Union or national law"})
    • Article 26(3) exists: held · quote: found
    RekviraArticle 16: heldverify_citation0.0 s
    verify_citation({"citation": "Article 16", "regulation": "eu-ai-act"})
    • Article 16 exists: held
    RekviraArticle 49(3): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 49(3)", "regulation": "eu-ai-act", "quote": "deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves"})
    • Article 49(3) exists: held · quote: found

What it produced: the classification memo

Word for word what the assistant wrote at the end of the run. The company in it is invented for this demonstration; the regulation text, pinpoints and checks are what Rekvira returned.

AI Act classification memo: vendor credit-scoring model, Lumen Bankas UAB

Regulation: Regulation (EU) 2024/1689 (EU AI Act) · CELEX: 32024R1689 · Corpus data_as_of: 2026-09-02T09:05:48Z (EUR-Lex consolidated text, held by Rekvira) Prepared: 2026-09-23 · Status: Sources, not advice. The classification and the compliance conclusion are for the compliance lead.

Checkpoints (recorded without a person present):

  • Checkpoint: the system is a vendor-built model that scores the creditworthiness of individuals applying for consumer loans of up to EUR 15,000. Loan officers see the score and three reason codes, and a loan officer makes the final decision. Lumen Bankas does not change the model and uses it only in internal tools. I treat Lumen Bankas as the deployer and the vendor as the provider.

1. System and intended purpose

  • What it does: it produces a creditworthiness score, with three reason codes, for individuals who apply for consumer loans of up to EUR 15,000.
  • Who it affects: individuals who apply for consumer credit at Lumen Bankas UAB, a specialised bank licensed in Lithuania, based in Vilnius, with 140 staff.
  • Who built it: an outside vendor.
  • Who runs it: Lumen Bankas. Its loan officers use the output, and a loan officer makes the final decision.
  • Changes by the bank: none. The system is used under the bank's name only inside internal tools.
  • Intended purpose is defined by the provider's documentation (Article 3(12)): "the use for which an AI system is intended by the provider … as specified in the information supplied by the provider in the instructions for use". The vendor's instructions for use were not reviewed for this memo. See §6.

2. Role

  • Deployer. Article 3(4) defines a deployer as "a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity".
  • Provider (the vendor). Article 3(3) defines a provider as a body "that develops an AI system … or that has an AI system … developed and places it on the market or puts the AI system into service under its own name or trademark".
  • When a deployer becomes a provider. Article 25(1) makes a deployer a provider, subject to Article 16, if:
  • (a) "they put their name or trademark on a high-risk AI system already placed on the market or put into service"; or
  • (b) they make "a substantial modification"; or
  • (c) they change the intended purpose.

On the facts given, the bank makes no modification and does not change the purpose. Point (a) is the one to check, because the bank uses the system "under its own name" in internal tools (see §6).

3. Classification under Article 6 and Annex III

Prohibited practices (Article 5(1)). Article 5(1)(c) prohibits social scoring that leads to "detrimental or unfavourable treatment … in social contexts that are unrelated to the contexts in which the data was originally generated or collected", or treatment that is "unjustified or disproportionate".

  • Nothing in the facts points to this. The system scores credit applicants for credit.
  • The inputs to the model were not reviewed, so this route has not been ruled out. The other points of Article 5(1) (manipulation, criminal-risk prediction, biometrics, emotion recognition) do not match the use described.

The high-risk test.

  • Article 6(1), product safety route: this covers systems that are a safety component of, or are themselves, a product "covered by the Union harmonisation legislation listed in Annex I". Nothing in the facts suggests this applies.
  • Article 6(2), Annex III route: "AI systems referred to in Annex III shall be considered to be high-risk."
  • Annex III, point 5(b): "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud."
  • Recital (58) (a recital, so not binding, but it explains the rule): "AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems, since they determine those persons' access to financial resources or essential services".

The Article 6(3) derogation. An Annex III system "shall not be considered to be high-risk where it does not pose a significant risk of harm … including by not materially influencing the outcome of decision making". At least one of these conditions must be met:

  • (a) a "narrow procedural task";
  • (b) improving "the result of a previously completed human activity";
  • (c) detecting decision-making patterns "not meant to replace or influence the previously completed human assessment";
  • (d) "a preparatory task to an assessment".

However, the same paragraph also says: "Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons."

  • Article 3(52) defines profiling by reference to GDPR Article 4(4).
  • GDPR Article 4(4) defines it as automated processing "to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's … economic situation … reliability".
  • Who may rely on the derogation: under Article 6(4), "A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment". That assessment is the vendor's to make. The deployer does not make it.

What points each way

Points toward high-riskPoints against, or open
The use matches the wording of Annex III 5(b) ("evaluate the creditworthiness of natural persons")The fraud-detection exception in 5(b) could apply only if the model's intended purpose is fraud detection. Nothing in the facts says so
Recital (58) names credit scoring expresslyA loan officer makes the final decision. That is relevant to "materially influencing" under 6(3), but see the profiling rule
The 6(3) profiling rule: a credit score for an individual appears to fit "economic situation … reliability" in GDPR Art 4(4)The Article 6(3) conditions (a)–(d) are framed around the system's intended purpose. This needs the vendor's documentation
Loan officers see the score and reason codes during the decision. The system is not described as an after-the-fact checkAny Article 6(4) assessment by the vendor was not seen

When the rules apply. Under Article 113, the Regulation "shall apply from 2 August 2026". Article 6(1) obligations apply from 2 August 2027. On the held text, the Annex III deployer duties apply on the date the system is put into service. The corpus is EUR-Lex consolidated text as of 2026-09-02. Check separately whether any amending act has changed these dates (see §6).

4. Obligations that follow if the system is high-risk and the bank is the deployer

Found through lookup_obligations (deployer, high-risk), which returned Article 26 only, plus Article 13 as a related article. That index lists only articles whose titles name the role, so it is not the full set of duties. Articles 4, 27 and 86 below were found by search and reading.

  • Article 4, AI literacy: "shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff".
  • Article 26(1), use per the instructions: "take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use".
  • Article 26(2), human oversight: "assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support".
  • Article 26(3): paragraphs 1 and 2 apply "without prejudice to other deployer obligations under Union or national law".
  • Article 26(4), input data: "to the extent the deployer exercises control over the input data, that deployer shall ensure that input data is relevant and sufficiently representative".
  • Article 26(5), monitoring and incidents:
  • The bank must monitor the system under the instructions for use.
  • If it has reason to consider there is an Article 79(1) risk, it must inform the provider and the market surveillance authority and "suspend the use".
  • It must report serious incidents "immediately", to the provider first.
  • For financial institutions, "the monitoring obligation … shall be deemed to be fulfilled by complying with the rules on internal governance arrangements" under Union financial services law.
  • Article 26(6), logs:
  • Logs under the bank's control must be kept for "at least six months".
  • Financial institutions "shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law".
  • Article 26(7), workers: "deployers who are employers shall inform workers' representatives and the affected workers" before putting a high-risk system into service at the workplace.
  • Article 26(9), DPIA: the bank uses the provider's Article 13 information "to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679".
  • Article 26(11), informing applicants: deployers of Annex III systems that make or help make decisions about natural persons "shall inform the natural persons that they are subject to the use of the high-risk AI system".
  • Article 26(12): "Deployers shall cooperate with the relevant competent authorities".
  • Article 27(1), fundamental rights impact assessment (FRIA): "deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights". The contents are listed in (a)–(f).
  • Article 27(2): this "applies to the first use".
  • Article 27(3): "the deployer shall notify the market surveillance authority of its results".
  • Article 27(4): the FRIA "shall complement that data protection impact assessment".
  • Article 86(1), explanation on request: affected persons have "the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken".
  • Article 86(3): this applies "only to the extent that the right … is not otherwise provided for under Union law".
  • Article 13(3), what the vendor must supply: the instructions for use must include, among other things, performance limits, the "human oversight measures referred to in Article 14", and log mechanisms. These are the inputs for 26(1), 26(5), 26(9) and 27(1)(d)–(e).

Read but not applicable on these facts:

  • Article 26(8) and Article 49(3): registration by deployers that are "public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf". The bank is a private entity.
  • Article 26(10): post-remote biometric identification.
  • Article 16: provider obligations. Relevant only if Article 25(1) applies. It was verified to exist but not read in full.
  • Article 50: transparency duties for certain AI systems. Not read, because the system is not described as interacting directly with applicants.

5. Citations checked (verify_citation, corpus data_as_of 2026-09-02)

PinpointExistsQuote
Art 3(3) AI Act (the tool labels it "Article 3, amendment (3)")heldfound
Art 3(4) (tool label "amendment (4)")heldfound
Art 3(52) (tool label "amendment (52)")heldfound
Art 3(12)read in the full Art 3 text, not run through verify_citation separately
Art 4heldfound
Art 5(1)heldfound
Art 6(1), 6(2), 6(3), 6(4)heldfound (each)
Annex III point 5(b) (tool resolved it at annex level, "ANNEX III")heldfound
Recital (58)heldfound
Art 13(3)heldfound
Art 16heldno quote checked
Art 25(1)heldfound
Art 26(1), (2), (3), (4), (5), (6), (7), (9), (11), (12)heldfound (each)
Art 27(1), (2), (3), (4)heldfound (each)
Art 49(3)heldfound
Art 86(1), 86(3)heldfound
Art 113heldfound
GDPR Art 4(4) (tool label "Article 4, amendment (4)")heldfound

No pinpoint failed. The only flag is Article 3(12): it was quoted from the full article text but not checked separately.

6. Open points for your decision

  1. Classification. Does Annex III 5(b) cover this system, and does the Article 6(3) profiling rule stop the derogation from applying? That is your call. Ask the vendor whether it has made an Article 6(4) non-high-risk assessment and registered under Article 49(2).
  2. "Under its own name" and Article 25(1)(a). Does internal branding amount to putting the bank's "name or trademark on a high-risk AI system"? If it does, the bank carries the Article 16 provider duties. Get the contract and the user interface screens and decide.
  3. Vendor documents needed:
  4. the instructions for use (Article 13(3));
  5. the intended purpose statement, including whether it excludes fraud detection;
  6. what logging the system does and who controls the logs;
  7. the inputs used (relevant to Article 5(1)(c) and Article 26(4)).
  8. FRIA and DPIA: plan the Article 27 FRIA to sit alongside the GDPR Article 35 DPIA. Confirm which Lithuanian authority receives the Article 27(3) notification.
  9. Financial-services carve-outs in 26(5) and 26(6): decide which Union financial services governance rules the bank relies on. Those rules are not in this corpus. DORA is loaded but was not searched for this memo.
  10. Dates: confirm that no amending act published after the 2026-09-02 corpus date changes the Article 113 dates for Annex III systems.
  11. Not held or not reviewed:
  12. Lithuanian implementing law and the designation of the market surveillance authority;
  13. Commission guidelines under Article 6(5);
  14. harmonised standards;
  15. the AI Office FRIA template (Article 27(5));
  16. EBA and national banking guidance;
  17. consumer credit law.

Not assessed at all: the model's accuracy, bias or data quality.

No assessment verdicts were recorded in Rekvira, because no officer has stated an applicability decision yet.

Start it yourself

Connect Rekvira to Claude, ChatGPT or Cursor (one step, no account), then paste this and add your facts:

Use Rekvira to write an AI Act classification memo for the AI system I describe below. Quote the official text with pinpoints and check every citation before you use it.

Where you decide

  • After tested the system against article 6 and annex iii: Confirm the system description and whether you are its provider or its deployer.

What comes back

  1. System and intended purpose
  2. Role
  3. Classification under Article 6 and Annex III
  4. Obligations that follow
  5. Citations checked
  6. Open points for your decision

How it keeps it defensible

  • Every pinpoint in the memo is checked with verify_citation
  • Says what could not be verified or is not held
  • States the data_as_of date of the text it read

What it will not do

  • Decide that the system is compliant, or that it is not high-risk: that call stays with you
  • Read national implementing law or guidance the corpus does not hold
  • Assess the model's accuracy, bias or data quality

Recorded on the live Rekvira service on 23 September 2026 without an account, with the job's playbooks named in the prompt. The prompt, every tool call and the finished text are stored as recorded; tool results above are shortened. The scenario is illustrative.