QgenticQgentic
Qgentic / platforms / ai act
Qgentic AI Act · European Union

Automated AI Act Compliance.

Qgentic AI Act turns the records you already hold into a structured register. Risk categories are deterministically computed from declared system capabilities and the regulatory framework. One module enforces both EU mandates and UK standards.

Supports offline deployment. Includes sample data. Partner integration available.

Applicability

Supported Target Entities

EU Providers & Deployers

Organisations placing or deploying AI systems within the EU. Manages transparency duties, high-risk regime requirements, Annex IV documentation, and incident reporting timelines.

Non-EU Providers Placing On The EU Market

Organisations outside the EU whose AI systems are placed on the EU market or whose output is used within it. The Act reaches them, and the register does too.

UK Firms And Public Bodies

The UK has no AI Act. PRA SS1/23 model inventories and ATRS transparency records are covered by a separate module on the same platform — see Qgentic AI Governance (UK).

Regulatory Frameworks

Supported Rulebooks

EU · Regulation (EU) 2024/1689

✓ EU AI Act Register

Maintains AI systems as structured records. Computes risk classifications, enforces Annex IV documentation completeness, and manages incident reporting timelines. Non-compliant configurations are blocked by the validation engine.

UK · Regulatory Principles

UK Instruments Live On Their Own Page

The UK deliberately has no AI Act, so its instruments are not a sub-clause of this one. PRA SS1/23 model inventories and ATRS public records are covered by Qgentic AI Governance (UK) — same engine, same console, same licence.

Process Flow

Operational Pipeline

  1. IngestionSystem metadata is imported via file upload, CSV, or REST API.
  2. ClassificationRisk categories are automatically calculated based on EU AI Act taxonomy (Articles 5/6, Annex III). Inconsistent manual classifications are rejected.
  3. ValidationThe engine enforces documentation completeness, governance checkpoints, incident reporting timers, and ATRS field requirements.
  4. MonitoringAutomated alerts are generated for missing documentation and upcoming incident reporting deadlines.
  5. Approval & ExportA designated user reviews and approves the data, generating a complete, cryptographically hashed filing package.
How an AI system is classified and its technical file assembled Your model inventory, technical files and deployment context feed the Qgentic engine. The model reads the model cards and drafts Annex IV sections; code decides the classification — Article 5 prohibitions, the Annex III high-risk tests, the GPAI compute threshold and the fundamental-rights impact assessment trigger. Classification is a test rather than a guess: a class you assert that the Act's own tests contradict is rejected, and every answer names the article it came from. The run then stops at a named person approver, whose name, note and timestamp are written to the audit chain, before the AI system register, Annex IV checklist, registration record and incident log are exported with a manifest and a SHA-256 hash for every file. § YOUR SYSTEMS § THE QGENTIC ENGINE § THE GATE § THE TECHNICAL FILE Model inventory owner · purpose · market 5 AI systems Technical files training + testing docs one per system Deployment context who it affects, where and on whose behalf MODEL READS CODE DECIDES reads the model cards extracts the purpose drafts Annex IV text summarises for review Article 5 prohibitions Annex III risk tests GPAI compute threshold FRIA trigger rules CLASSIFICATION IS A TEST A class the Act's own tests contradict is refused. AIACT-CA-008 · every answer names its article 5 systems · 2 high-risk · 0 prohibited AWAITING APPROVAL A named person signs the file off. marta.lindqvist approver · admin The name, the note and the timestamp go on the chain. no self-approval Annex IV, assembled ai-system-register.csv annex-iv-checklist.json registration-record.json incident-log.json manifest.json SHA-256 per file the Article 73 clock starts on the incident audit chains VALID Regulation (EU) 2024/1689 · the same register carries PRA SS1/23 model inventories and ATRS records, because underneath them it is one inventory.
Risk class is where an AI register is usually softest, so it is the part that is not left to a model: prohibited, high-risk, GPAI and the FRIA trigger are each decided by the Act's own tests, and a classification you assert that those tests contradict is refused rather than recorded. Every answer carries the article it came from, which is what an Annex IV file has to survive.
System Reliability

Validation and Decision Boundaries

Deterministic ValidationHuman Input Required
Risk category computation and enforcementSystem capabilities and deployment context
Annex IV and governance completeness checksContent of technical documentation
Incident reporting deadline calculationsIncident severity assessment
UK risk tier computation and validation trackingMateriality thresholds and validation schedules
Cryptographic audit logging and export generationFinal review and package approval

Every regulatory decision is made by deterministic code. AI models play no part in governance or classification.

Outputs

Export Specifications

Export Packages

EU: Output includes the AI-system register, Annex IV checklists, Annex VIII records, and incident logs. UK: Output includes the model inventory, attestation summaries, and ATRS records. All files are hashed and exported post-approval.

ai-system-register.csv · annex-iv-checklist.json · model-inventory.csv · manifest.json

System Capabilities

The system supports validation for general-purpose AI models and fundamental-rights impact assessments. It is designed for preparation only; submission to EU databases and conformity assessments must be completed via your existing channels. Authorised representative requirements (Article 54) are currently out of scope.

Pricing Structure

Deployment Options

Pilot Implementation

£5,500 / €6,500 flat, 4–6 weeks

Initial system inventory and compliance gap analysis. Costs are credited to annual licences.

SaaS Deployment

from £1,500 / €1,750 /month + usage

Standard cloud deployment model scaled to system volume.

ATRS Publisher

£190 /month per public body

Dedicated tier for UK public bodies supporting up to 10 transparency records.

On-Premise Deployment

from £95K / €105K /year, capacity tier

Annual software licence for air-gapped deployment on internal infrastructure.

Detailed pricing structures are available on the pricing page.

FAQ

Frequently Asked Questions

What is the EU AI Act register?

A structured record of AI systems as mandated by Regulation (EU) 2024/1689. It includes system classifications, deployment contexts, and Annex IV technical documentation for high-risk systems.

How is an AI system's risk category decided?

Risk categories are computed deterministically based on Articles 5, 6, and Annex III of the AI Act. Manual overrides that violate these rules are rejected.

Does the UK have an AI Act?

No. The UK operates under regulatory principles delegated to existing sector regulators rather than a single statute. PRA SS1/23 model inventories and public-body ATRS records are covered by Qgentic AI Governance (UK).

What is SS1/23?

SS1/23 is a Bank of England supervisory statement requiring PRA-regulated entities to maintain a model inventory with risk tiering and validation schedules. It is served by Qgentic AI Governance (UK), not by this module.

Does this govern models or document them?

The system is designed for documentation and classification. It does not inspect model weights or perform model performance testing.

Are general-purpose AI models supported?

Yes. The system computes applicable duties under Articles 53 and 55, and handles Article 27 fundamental-rights impact assessments. Current status is tracked in product notes.

Demonstration Environment. The system can be evaluated offline using sample data. Contact sales to request a demonstration binary.