Live demo · Meridian Group (demo)
Example AI register One register for all your AI: automatic risk classification, the obligations that follow, and the legal source behind every conclusion.
Example data — read-only. This is a fictional register for a made-up company (“Meridian Group”). Nothing here is real customer data. Open any system to see its risk class and the obligations that follow, each linked to its source on EUR-Lex.
Ready to map your own AI? Create your register → Get an instant snapshot
Regulatory change · impact on this register what changed · who it hits · what to do High-risk implementation timeline — amended dates now in force Regulation (EU) 2026/1744 entered into force on 27 July 2026. Annex III requirements apply from 2 December 2027; Annex I embedded-product requirements from 2 August 2028. What to do: re-baseline each affected system against the applicable track and preserve the prior planning decision in the audit trail.
5 system(s) in this register are affected:
Recruitment screening (HR) Credit scoring for loans Medical triage assistant Access control with facial recognition Payment fraud detection
The register click a system to expand High risk (Annex III/I) Recruitment screening (HR) provider 11 obligations Sorts and scores candidates in the hiring process.
Accuracy and cyber-resilience Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I) Credit scoring for loans provider 11 obligations Assesses the creditworthiness of applicants.
Accuracy and cyber-resilience Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Prohibited practice (Art. 5) Real-time facial recognition (public space access) deployer 3 obligations Identifies people live via cameras in public spaces.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
GPAI in use Customer-service chatbot deployer 8 obligations Answers customer questions using an external language model.
Risk of becoming a provider Substantial modification plus your own branding can pull you into the GPAI provider regime.
Output transparency Art. 50 applies to your use of GPAI output; see the transparency entry.
Vendor assessment Your compliance leans on your model provider's; ask for their documentation and conformity (Chapter V).
Deepfake label Art. 50(4): the deployer discloses that image/audio/video content is a deepfake.
Emotion-recognition notice Art. 50(3): the deployer informs the people exposed about the system's operation.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Transparency (Art. 50) Marketing content generator provider 5 obligations Generates text and images for campaigns.
Chatbot disclosure Art. 50(1): the provider ensures a system interacting with people makes clear that it is AI.
Marking of synthetic output Art. 50(2): the provider marks AI output in a machine-readable, detectable format (see the 10 June 2026 code of practice).
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Minimal risk Internal document classification deployer 3 obligations Sorts incoming documents by type.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I) Medical triage assistant provider 11 obligations Decision support as a safety component in a medical device.
Accuracy and cyber-resilience Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I) Access control with facial recognition deployer 7 obligations Biometric access to the office building (not public, not real-time remote).
Fundamental-rights impact assessment Art. 27 requires certain deployers (e.g. public bodies) to carry out a FRIA before putting the system into use.
Logging Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Use per instructions and monitoring Art. 26 obliges deployers to use the system in line with the instructions and to monitor its operation.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
High risk (Annex III/I) Payment fraud detection provider 11 obligations Evaluates transactions at a financial services provider.
Accuracy and cyber-resilience Art. 15 requires an appropriate, consistent level of accuracy, robustness and security, stated in the instructions.
Conformity assessment and registration Art. 43 + 49 + 71: complete a conformity assessment, affix the CE marking and register in the EU database before market entry.
Data governance Art. 10 sets requirements for relevant, representative and error-minimised datasets, with attention to bias.
Technical documentation Art. 11 + Annex IV: documentation demonstrating conformity, in place before the system is placed on the market.
Logging Art. 12 + 19: the provider builds in automatic logging; the deployer retains the logs.
Human oversight Art. 14 + 26: the provider makes oversight possible; the deployer assigns competent people to exercise it.
Quality management system Art. 17 obliges providers to maintain a documented quality system that ensures and demonstrates compliance.
Risk management system Art. 9 requires a systematic process to identify and mitigate risks across the full lifecycle.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
GPAI in use Translation assistant (external language model) deployer 6 obligations Translates internal documents using a third-party GPAI model.
Risk of becoming a provider Substantial modification plus your own branding can pull you into the GPAI provider regime.
Output transparency Art. 50 applies to your use of GPAI output; see the transparency entry.
Vendor assessment Your compliance leans on your model provider's; ask for their documentation and conformity (Chapter V).
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Minimal risk Webshop product recommendations deployer 3 obligations Shows customers personalised product suggestions.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Minimal risk Predictive maintenance (factory) deployer 3 obligations Predicts maintenance needs of production machines.
Record-keeping Supervisors expect you to demonstrate your literacy measures; record-keeping makes that possible.
Literacy programme Art. 4 calls for measures ensuring a sufficient level of AI literacy among those working with AI.
Role-based knowledge Art. 4 ties the required level to context, tasks and the persons the AI system is applied to.
Now map one of your own AI systems You’ve seen how Meridian’s register works. Take two minutes to make a first, guided snapshot of one of your own systems — likely touchpoints and the questions worth resolving. Nothing is stored on our servers.
Map one of your own AI systems →
Important — read this first.
No one can guarantee compliance. No vendor, advisor or tool can —
not even those who claim to. Only a competent supervisory authority or court
decides in the end. This result is an expectation of likely attention points
under review , not an approval.
The standards are still moving. For high-risk systems the harmonised
standards are not yet finalised and interpretations shift. Every conclusion below
therefore carries its source and a version stamp, so you can see what it rests on
and that it moves with the law.
Get the full automatic snapshot → Create your register
The automatic snapshot adds a workload business case, relevant deadlines and a saved result without requiring a meeting.
Not legal advice. This is an indication of possible attention points; a competent supervisory authority or court always has the final say.