EU AI Act High-Risk AI System Documentation
Overview
The EU AI Act (Regulation 2024/1689, entered into force 1 August 2024, with high-risk obligations applicable from 2 August 2026) establishes a risk-based regulatory framework for artificial intelligence systems. High-risk AI systems — those listed in Annex III or used as safety components of products covered by Union harmonisation legislation in Annex I — must meet extensive documentation, transparency, and governance requirements before being placed on the EU market. Cerebrum AI Labs must prepare comprehensive technical documentation, implement a risk management system, ensure data governance, and undergo conformity assessment for each high-risk AI system.
High-Risk Classification
Annex III Categories Relevant to Cerebrum AI Labs
| Category |
Annex III Reference |
Cerebrum AI Labs System |
Classification |
| Employment and workers management |
Annex III, para. 4(a) |
CV Screening AI — automated filtering of job applications |
High-risk |
| Access to essential services |
Annex III, para. 5(b) |
Credit Scoring AI — creditworthiness assessment for financial products |
High-risk |
| Law enforcement |
Annex III, para. 6(a) |
Not applicable |
N/A |
| Biometric identification |
Annex III, para. 1(a) |
Facial Verification AI — identity verification at onboarding |
High-risk |
| Education and vocational training |
Annex III, para. 3(a) |
Not applicable |
N/A |
Classification Decision Tree
Is the AI system listed in Annex III?
├── Yes → High-risk (unless exception applies under Art. 6(3))
│ └── Does the system make decisions materially affecting natural persons?
│ ├── Yes → High-risk confirmed
│ └── No → May qualify for Art. 6(3) exception (narrow, profiling, preparatory)
│
├── No → Is it a safety component of a product under Annex I legislation?
│ ├── Yes → High-risk (subject to third-party conformity assessment)
│ └── No → Not high-risk under AI Act
│
└── Is it a general-purpose AI model with systemic risk? (Art. 51)
├── Yes → GPAI systemic risk obligations
└── No → GPAI transparency obligations only
Technical Documentation Requirements (Art. 11)
Annex IV — Required Documentation Content
Section 1: General Description
| Document Element |
Content for Cerebrum AI Labs CV Screening AI |
| Intended purpose |
Automated screening and ranking of job applications based on qualification match |
| Provider name and contact |
Cerebrum AI Labs, 42 Innovation Drive, Dublin, Ireland |
| AI system version |
v2.4.1 (deployed March 2026) |
| Hardware/software requirements |
Cloud-hosted on EU infrastructure (AWS eu-west-1), Python 3.11, PyTorch 2.2 |
| Product integration |
Integrated into Cerebrum TalentFlow ATS platform |
Section 2: Detailed Description of System Elements
| Element |
Documentation Required |
| Development methodology |
Model architecture, training approach, design choices and rationale |
| Computational resources |
Training compute (GPU hours), energy consumption |
| Training data |
Data sources, collection methods, size, labeling methodology, preprocessing |
| Validation and testing |
Test datasets, metrics, results, known limitations |
| Input data specifications |
Expected input format, quality requirements |
| Output description |
Output format, confidence scores, decision thresholds |
Section 3: Monitoring, Functioning, and Control
| Element |
Documentation Required |
| Human oversight measures |
Art. 14 requirements: override capability, decision review process |
| Technical measures for accuracy |
Accuracy metrics, drift detection, retraining triggers |
| Cybersecurity measures |
Data encryption, access controls, adversarial robustness testing |
| Performance in edge cases |
Known failure modes, boundary conditions, degradation behavior |
Section 4: Risk Management
| Element |
Documentation Required |
| Risk management system |
Art. 9 risk management process documentation |
| Known and foreseeable risks |
Risk register with severity and likelihood |
| Mitigation measures |
Controls for each identified risk |
| Residual risk assessment |
Acceptable residual risk justification |
Risk Management System (Art. 9)
Continuous Risk Management Process for Cerebrum AI Labs
| Phase |
Activity |
Frequency |
| Identification |
Identify risks to health, safety, and fundamental rights |
Initial + quarterly |
| Analysis |
Estimate risk severity and likelihood |
Initial + quarterly |
| Evaluation |
Compare risks against acceptance criteria |
Initial + quarterly |
| Mitigation |
Implement risk reduction measures |
Ongoing |
| Monitoring |
Track risk indicators in production |
Continuous |
| Review |
Review and update risk assessment |
Quarterly |
Risk Register — CV Screening AI
| Risk ID |
Risk Description |
Severity |
Likelihood |
Mitigation |
Residual Risk |
| R-001 |
Gender bias in screening recommendations |
High |
Medium |
Bias testing on protected attributes, debiasing training data |
Low |
| R-002 |
Discrimination against non-native language speakers |
High |
Medium |
Multilingual evaluation, language-agnostic features |
Medium |
| R-003 |
Over-reliance on AI recommendations by recruiters |
Medium |
High |
Mandatory human review, confidence thresholds |
Low |
| R-004 |
Inaccurate qualification matching for novel job roles |
Medium |
Medium |
Fallback to keyword matching, human review flag |
Low |
| R-005 |
Privacy breach via training data memorization |
High |
Low |
Differential privacy in training, memorization audit |
Low |
Data Governance (Art. 10)
Training Data Requirements
| Requirement |
Implementation at Cerebrum AI Labs |
| Relevance and representativeness |
Training data sourced from 50,000 job applications across 12 EU countries, balanced by gender, age, nationality |
| Bias examination |
Statistical parity analysis on protected attributes (gender, age, ethnicity, disability) before and after training |
| Gap identification |
Identified underrepresentation of applicants with disabilities; augmented with synthetic examples |
| Data quality |
Automated data quality checks: completeness >95%, label accuracy >98% (human-verified sample) |
| Personal data processing |
DPIA completed (DPIA-AI-2026-001); lawful basis: Art. 6(1)(f) legitimate interest; special categories removed |
Conformity Assessment (Art. 43)
Assessment Procedure for Cerebrum AI Labs
| System |
Assessment Type |
Basis |
| CV Screening AI |
Internal conformity assessment (Art. 43(2)) + quality management system |
Annex III, para. 4 — not biometric, not critical infrastructure |
| Credit Scoring AI |
Internal conformity assessment (Art. 43(2)) |
Annex III, para. 5 |
| Facial Verification AI |
Third-party conformity assessment (Art. 43(1)) via notified body |
Annex III, para. 1 — biometric identification |
Internal Conformity Assessment Steps
- Verify quality management system is established (Art. 17)
- Prepare technical documentation per Annex IV
- Conduct risk management assessment per Art. 9
- Verify data governance per Art. 10
- Verify transparency and information provision per Art. 13
- Verify human oversight per Art. 14
- Verify accuracy, robustness, and cybersecurity per Art. 15
- Draw up EU Declaration of Conformity (Art. 47)
- Affix CE marking (Art. 48)
- Register in EU database (Art. 49)
Post-Market Monitoring (Art. 72)
| Activity |
Frequency |
Owner |
| Performance metric monitoring |
Continuous |
ML Engineering |
| Bias drift detection |
Weekly |
Responsible AI team |
| Incident reporting |
As needed (within 15 days for serious incidents per Art. 73) |
DPO + Legal |
| User feedback collection |
Continuous |
Product team |
| Risk register update |
Quarterly |
Risk Management |
| Technical documentation update |
On material change |
ML Engineering + Legal |
Key Legal References
- EU AI Act (Regulation 2024/1689) — Full text, entered into force 1 August 2024
- AI Act Art. 6 + Annex III — High-risk classification criteria
- AI Act Art. 9 — Risk management system requirements
- AI Act Art. 10 — Data and data governance requirements
- AI Act Art. 11 + Annex IV — Technical documentation requirements
- AI Act Art. 13 — Transparency and provision of information to deployers
- AI Act Art. 14 — Human oversight requirements
- AI Act Art. 43 — Conformity assessment procedures
- AI Act Art. 72 — Post-market monitoring obligations
- AI Act Art. 73 — Reporting of serious incidents
- GDPR Art. 22 — Automated individual decision-making (complementary to AI Act)
- EDPB-EDPS Joint Opinion 5/2021 on the AI Act Proposal — Data protection perspective on AI regulation
1---2name: ai-act-high-risk-docs3description: Preparing EU AI Act compliance documentation for high-risk AI systems. Covers Annex III classification, technical documentation under Art. 11, conformity assessment, risk management systems, and CE marking requirements. Keywords: EU AI Act, high-risk AI, Annex III, conformity assessment, CE marking.4license: Apache-2.05---67# EU AI Act High-Risk AI System Documentation89## Overview1011The EU AI Act (Regulation 2024/1689, entered into force 1 August 2024, with high-risk obligations applicable from 2 August 2026) establishes a risk-based regulatory framework for artificial intelligence systems. High-risk AI systems — those listed in Annex III or used as safety components of products covered by Union harmonisation legislation in Annex I — must meet extensive documentation, transparency, and governance requirements before being placed on the EU market. Cerebrum AI Labs must prepare comprehensive technical documentation, implement a risk management system, ensure data governance, and undergo conformity assessment for each high-risk AI system.1213## High-Risk Classification1415### Annex III Categories Relevant to Cerebrum AI Labs1617| Category | Annex III Reference | Cerebrum AI Labs System | Classification |18|----------|-------------------|------------------------|---------------|19| Employment and workers management | Annex III, para. 4(a) | CV Screening AI — automated filtering of job applications | High-risk |20| Access to essential services | Annex III, para. 5(b) | Credit Scoring AI — creditworthiness assessment for financial products | High-risk |21| Law enforcement | Annex III, para. 6(a) | Not applicable | N/A |22| Biometric identification | Annex III, para. 1(a) | Facial Verification AI — identity verification at onboarding | High-risk |23| Education and vocational training | Annex III, para. 3(a) | Not applicable | N/A |2425### Classification Decision Tree2627```28Is the AI system listed in Annex III?29├── Yes → High-risk (unless exception applies under Art. 6(3))30│ └── Does the system make decisions materially affecting natural persons?31│ ├── Yes → High-risk confirmed32│ └── No → May qualify for Art. 6(3) exception (narrow, profiling, preparatory)33│34├── No → Is it a safety component of a product under Annex I legislation?35│ ├── Yes → High-risk (subject to third-party conformity assessment)36│ └── No → Not high-risk under AI Act37│38└── Is it a general-purpose AI model with systemic risk? (Art. 51)39 ├── Yes → GPAI systemic risk obligations40 └── No → GPAI transparency obligations only41```4243## Technical Documentation Requirements (Art. 11)4445### Annex IV — Required Documentation Content4647**Section 1: General Description**4849| Document Element | Content for Cerebrum AI Labs CV Screening AI |50|-----------------|----------------------------------------------|51| Intended purpose | Automated screening and ranking of job applications based on qualification match |52| Provider name and contact | Cerebrum AI Labs, 42 Innovation Drive, Dublin, Ireland |53| AI system version | v2.4.1 (deployed March 2026) |54| Hardware/software requirements | Cloud-hosted on EU infrastructure (AWS eu-west-1), Python 3.11, PyTorch 2.2 |55| Product integration | Integrated into Cerebrum TalentFlow ATS platform |5657**Section 2: Detailed Description of System Elements**5859| Element | Documentation Required |60|---------|----------------------|61| Development methodology | Model architecture, training approach, design choices and rationale |62| Computational resources | Training compute (GPU hours), energy consumption |63| Training data | Data sources, collection methods, size, labeling methodology, preprocessing |64| Validation and testing | Test datasets, metrics, results, known limitations |65| Input data specifications | Expected input format, quality requirements |66| Output description | Output format, confidence scores, decision thresholds |6768**Section 3: Monitoring, Functioning, and Control**6970| Element | Documentation Required |71|---------|----------------------|72| Human oversight measures | Art. 14 requirements: override capability, decision review process |73| Technical measures for accuracy | Accuracy metrics, drift detection, retraining triggers |74| Cybersecurity measures | Data encryption, access controls, adversarial robustness testing |75| Performance in edge cases | Known failure modes, boundary conditions, degradation behavior |7677**Section 4: Risk Management**7879| Element | Documentation Required |80|---------|----------------------|81| Risk management system | Art. 9 risk management process documentation |82| Known and foreseeable risks | Risk register with severity and likelihood |83| Mitigation measures | Controls for each identified risk |84| Residual risk assessment | Acceptable residual risk justification |8586## Risk Management System (Art. 9)8788### Continuous Risk Management Process for Cerebrum AI Labs8990| Phase | Activity | Frequency |91|-------|----------|-----------|92| Identification | Identify risks to health, safety, and fundamental rights | Initial + quarterly |93| Analysis | Estimate risk severity and likelihood | Initial + quarterly |94| Evaluation | Compare risks against acceptance criteria | Initial + quarterly |95| Mitigation | Implement risk reduction measures | Ongoing |96| Monitoring | Track risk indicators in production | Continuous |97| Review | Review and update risk assessment | Quarterly |9899### Risk Register — CV Screening AI100101| Risk ID | Risk Description | Severity | Likelihood | Mitigation | Residual Risk |102|---------|-----------------|----------|------------|------------|--------------|103| R-001 | Gender bias in screening recommendations | High | Medium | Bias testing on protected attributes, debiasing training data | Low |104| R-002 | Discrimination against non-native language speakers | High | Medium | Multilingual evaluation, language-agnostic features | Medium |105| R-003 | Over-reliance on AI recommendations by recruiters | Medium | High | Mandatory human review, confidence thresholds | Low |106| R-004 | Inaccurate qualification matching for novel job roles | Medium | Medium | Fallback to keyword matching, human review flag | Low |107| R-005 | Privacy breach via training data memorization | High | Low | Differential privacy in training, memorization audit | Low |108109## Data Governance (Art. 10)110111### Training Data Requirements112113| Requirement | Implementation at Cerebrum AI Labs |114|-------------|-----------------------------------|115| Relevance and representativeness | Training data sourced from 50,000 job applications across 12 EU countries, balanced by gender, age, nationality |116| Bias examination | Statistical parity analysis on protected attributes (gender, age, ethnicity, disability) before and after training |117| Gap identification | Identified underrepresentation of applicants with disabilities; augmented with synthetic examples |118| Data quality | Automated data quality checks: completeness >95%, label accuracy >98% (human-verified sample) |119| Personal data processing | DPIA completed (DPIA-AI-2026-001); lawful basis: Art. 6(1)(f) legitimate interest; special categories removed |120121## Conformity Assessment (Art. 43)122123### Assessment Procedure for Cerebrum AI Labs124125| System | Assessment Type | Basis |126|--------|----------------|-------|127| CV Screening AI | Internal conformity assessment (Art. 43(2)) + quality management system | Annex III, para. 4 — not biometric, not critical infrastructure |128| Credit Scoring AI | Internal conformity assessment (Art. 43(2)) | Annex III, para. 5 |129| Facial Verification AI | Third-party conformity assessment (Art. 43(1)) via notified body | Annex III, para. 1 — biometric identification |130131### Internal Conformity Assessment Steps1321331. Verify quality management system is established (Art. 17)1342. Prepare technical documentation per Annex IV1353. Conduct risk management assessment per Art. 91364. Verify data governance per Art. 101375. Verify transparency and information provision per Art. 131386. Verify human oversight per Art. 141397. Verify accuracy, robustness, and cybersecurity per Art. 151408. Draw up EU Declaration of Conformity (Art. 47)1419. Affix CE marking (Art. 48)14210. Register in EU database (Art. 49)143144## Post-Market Monitoring (Art. 72)145146| Activity | Frequency | Owner |147|----------|-----------|-------|148| Performance metric monitoring | Continuous | ML Engineering |149| Bias drift detection | Weekly | Responsible AI team |150| Incident reporting | As needed (within 15 days for serious incidents per Art. 73) | DPO + Legal |151| User feedback collection | Continuous | Product team |152| Risk register update | Quarterly | Risk Management |153| Technical documentation update | On material change | ML Engineering + Legal |154155## Key Legal References156157- **EU AI Act (Regulation 2024/1689)** — Full text, entered into force 1 August 2024158- **AI Act Art. 6 + Annex III** — High-risk classification criteria159- **AI Act Art. 9** — Risk management system requirements160- **AI Act Art. 10** — Data and data governance requirements161- **AI Act Art. 11 + Annex IV** — Technical documentation requirements162- **AI Act Art. 13** — Transparency and provision of information to deployers163- **AI Act Art. 14** — Human oversight requirements164- **AI Act Art. 43** — Conformity assessment procedures165- **AI Act Art. 72** — Post-market monitoring obligations166- **AI Act Art. 73** — Reporting of serious incidents167- **GDPR Art. 22** — Automated individual decision-making (complementary to AI Act)168- **EDPB-EDPS Joint Opinion 5/2021 on the AI Act Proposal** — Data protection perspective on AI regulation