EU AI Act  ·  High-Risk AI Systems

EU AI Act research and governance readiness.

EU AI Act high-risk obligations require a documented governance posture. Quebec HR-tech, fintech, and enterprise SaaS vendors with EU customers are in scope. PHAROS maps your Annex III exposure, identifies the Article 22 authorised representative obligation most Canadian teams overlook, and builds the documentation record a regulator or EU importer will ask for first.

For teams researching EU AI Act exposure, Annex III risk tiering, and audit-ready documentation before European procurement or market entry. Montreal, Quebec.

Governance program

Three phases to establish a durable EU AI Act governance posture.

Phase 1 · Exposure mapping

Know What You're Exposed To

Exposure Mapping

  • Identify every AI system that touches EU users — including third-party and vendor-supplied tools
  • Classify each system against Annex III: determine if you're in a prohibited or high-risk category
  • Produce the classification rationale and Article 22 assessment — the two documents a regulator or EU importer requests first from a non-EU provider
Phase 2 · Documentation

Build What the Regulation Requires

Documentation Sprint

  • Define who in your organization can authorize AI deployment — and document it before an auditor asks
  • Build per-system technical documentation: the required record under Articles 11–13 of the Act
  • Build your internal conformity assessment record — for most Annex III systems (outside biometrics), self-assessment is the required path; the gap is documentation depth, not third-party certification
Phase 3 · Evidence readiness

Hold the Line When They Come

Regulator-Ready

  • Assemble your full evidence package: the file you hand a notified body, an EU importer, or a procurement team
  • Governance documentation formatted for EU-side due diligence requests and enterprise procurement — structured for the 10-year record retention Article 22 requires of non-EU providers
  • Standing governance calendar so your compliance posture stays current through every product update

What You Walk Away With

Eight documents. The complete governance record the EU AI Act requires.

01

Full AI System and Vendor Inventory

02

Annex III Risk Classification Decision Record

03

AI Deployment Authority and Decision Rights Matrix

04

Per-System Control Register

05

Conformity Assessment Framework (Annex III-aligned)

06

Technical Documentation Package (Articles 11–13)

07

Ongoing Compliance and Review Calendar

08

Complete Evidence File — Regulator and Notified Body Ready

EU AI Act Research

What teams researching the Act need to know first.

Research note

Can the Act apply outside the EU?

Scope

  • Yes. The obligations can attach if a covered AI system is placed on or supports the EU market — Canadian or Quebec incorporation does not change this.
  • Article 22 adds a concrete structural obligation: non-EU providers must designate an EU-established authorised representative before placing high-risk AI on the EU market.
Research note

What fails first in review?

Review risk

  • The classification logic is usually missing or undocumented — particularly for HR and recruitment AI (Annex III Cat. 4) and credit-scoring systems (Cat. 5), both common in Quebec SaaS.
  • Human oversight design and technical documentation often cannot be reconstructed by a third party.
Research note

What does PHAROS build?

Output

  • An AI use-case inventory, Annex III risk tiering rationale, decision-rights matrix, and control register.
  • A technical documentation pack and evidence file a reviewer, importer, or procurement team can follow.
EU AI Act research session

Book 30-min debrief.

If you are researching the EU AI Act for a live product, we will tell you which obligations apply now, where the documentation gaps are, and whether the Governance Challenge is the right fit.

Or write directly: pharos@pharos-ai.ca