4risk tiers of the EU AI Act, every verdict citing the exact article
13 / 13on its risk-classification exam, checked on every update
1stcustomer: this portfolio — Bridge registered as its first high-risk system
How it works
- One live list. Guardrail records every AI system a company runs —
what it does, what data it touches, who owns it.
- Risk sorting with receipts. Each system is checked against the law's
categories. Clear cases are decided by fixed rules; unclear ones come with a written
argument quoting the exact article — and a person makes the final call.
- Paperwork that writes itself. Model cards and the documentation
regulators ask for are drafted from real records — never invented — and stay marked
DRAFT until a person signs them.
- A board-level dashboard. Risk profile, the Aug 2 2026 high-risk
deadline, the human-review queue, and alarms when evidence gets stale.
Proof it works — it governs itself
Guardrail's first customer is this portfolio. Seeding it registers all six
products; Bridge — a lending tool — is correctly caught
as high-risk (credit scoring is a named high-risk category, Annex III(5)(b)),
with its full obligation checklist and a real fair-lending bias report attached. The others
resolve to lower tiers. A compliance product that starts by complying with itself.
For technical readers
- Versioned EU AI Act knowledge base: Art. 5 prohibited practices, Annex III high-risk categories, Art. 50 transparency, and the Art. 9–49 provider/deployer obligations.
- Two classifiers — a transparent rule engine for bright lines and a Claude model for gray zones — both citing the article behind every verdict; consequential or low-confidence cases route to human review.
- Generates model-card / technical-documentation drafts assembled only from inventory facts, plus auditor-facing evidence packs; sign-off is recorded and locks a version.
- The risk classifier is gated by a Checkpoint eval suite (13/13 across all four tiers) on every update.
What it can't do yet
- NIST AI RMF and ISO/IEC 42001 crosswalks are the next frameworks to add.
- Live connectors (code repos, model registries) that auto-discover systems are in development.
- It's decision-support for compliance teams, not legal advice.