trusq← trusq.ioSign inCreate account

Live demo · Meridian Group (demo)

Example AI register

One register for all your AI: automatic risk classification, the obligations that follow, and the legal source behind every conclusion.

Example data — read-only. This is a fictional register for a made-up company (“Meridian Group”). Nothing here is real customer data. Open any system to see its risk class and the obligations that follow, each linked to its source on EUR-Lex. Ready to map your own AI? Create your register → Get an instant snapshot
12
AI systems
9
frameworks covered
82
obligations mapped
1
change to review

Regulatory change · impact on this register

what changed · who it hits · what to do
High-risk implementation timeline — amended dates now in force
Regulation (EU) 2026/1744 entered into force on 27 July 2026. Annex III requirements apply from 2 December 2027; Annex I embedded-product requirements from 2 August 2028. What to do: re-baseline each affected system against the applicable track and preserve the prior planning decision in the audit trail.

5 system(s) in this register are affected:

The register

click a system to expand
High risk (Annex III/I)Recruitment screening (HR)provider11 obligations

Sorts and scores candidates in the hiring process.

Accuracy and cyber-resilience
Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration
Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance
Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation
Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging
Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight
Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system
Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system
Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I)Credit scoring for loansprovider11 obligations

Assesses the creditworthiness of applicants.

Accuracy and cyber-resilience
Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration
Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance
Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation
Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging
Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight
Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system
Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system
Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Prohibited practice (Art. 5)Real-time facial recognition (public space access)deployer3 obligations

Identifies people live via cameras in public spaces.

Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
GPAI in useCustomer-service chatbotdeployer8 obligations

Answers customer questions using an external language model.

Risk of becoming a provider
Substantial modification plus your own branding can pull you into the GPAI provider regime.
Output transparency
Art. 50 applies to your use of GPAI output; see the transparency entry.
Vendor assessment
Your compliance leans on your model provider's; ask for their documentation and conformity (Chapter V).
Deepfake label
Art. 50(4): the deployer discloses that image/audio/video content is a deepfake.
Emotion-recognition notice
Art. 50(3): the deployer informs the people exposed about the system's operation.
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Transparency (Art. 50)Marketing content generatorprovider5 obligations

Generates text and images for campaigns.

Chatbot disclosure
Art. 50(1): the provider ensures a system interacting with people makes clear that it is AI.
Marking of synthetic output
Art. 50(2): the provider marks AI output in a machine-readable, detectable format (see the 10 June 2026 code of practice).
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Minimal riskInternal document classificationdeployer3 obligations

Sorts incoming documents by type.

Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I)Medical triage assistantprovider11 obligations

Decision support as a safety component in a medical device.

Accuracy and cyber-resilience
Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration
Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance
Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation
Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging
Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight
Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system
Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system
Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I)Access control with facial recognitiondeployer7 obligations

Biometric access to the office building (not public, not real-time remote).

Fundamental-rights impact assessment
Art. 27 requires certain deployers (e.g. public bodies) to carry out a FRIA before putting the system into use.
Logging
Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight
Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Use per instructions and monitoring
Art. 26 obliges deployers to use the system in line with the instructions and to monitor its operation.
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I)Payment fraud detectionprovider11 obligations

Evaluates transactions at a financial services provider.

Accuracy and cyber-resilience
Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration
Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance
Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation
Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging
Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight
Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system
Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system
Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
GPAI in useTranslation assistant (external language model)deployer6 obligations

Translates internal documents using a third-party GPAI model.

Risk of becoming a provider
Substantial modification plus your own branding can pull you into the GPAI provider regime.
Output transparency
Art. 50 applies to your use of GPAI output; see the transparency entry.
Vendor assessment
Your compliance leans on your model provider's; ask for their documentation and conformity (Chapter V).
Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Minimal riskWebshop product recommendationsdeployer3 obligations

Shows customers personalised product suggestions.

Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Minimal riskPredictive maintenance (factory)deployer3 obligations

Predicts maintenance needs of production machines.

Record-keeping
Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme
Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge
Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.

Now map one of your own AI systems

You’ve seen how Meridian’s register works. Take two minutes to make a first, guided snapshot of one of your own systems — likely touchpoints and the questions worth resolving. Nothing is stored on our servers.

Map one of your own AI systems →
Important — read this first.
  1. No one can guarantee compliance. No vendor, advisor or tool can — not even those who claim to. Only a competent supervisory authority or court decides in the end. This result is an expectation of likely attention points under review, not an approval.
  2. The standards are still moving. For high-risk systems the harmonised standards are not yet finalised and interpretations shift. Every conclusion below therefore carries its source and a version stamp, so you can see what it rests on and that it moves with the law.

Get the full automatic snapshot → Create your register

The automatic snapshot adds a workload business case, relevant deadlines and a saved result without requiring a meeting.