GreyScape.ai

Compliance · EU AI Act

CursorPro monthly

Per-system compliance record · EU AI Act readiness

DeployerHigh-riskAnnex III · 1 use caseClassification complete$20/mo · No team · [email protected]

Role under the Act

Deployer

Risk class

High-risk

Annex III use-cases

  • Essential private services (credit scoring, insurance pricing)

Classified by

[email protected]6 Jul 2026, 12:00

Legal basis

Used in credit risk scoring per Article 6(2) and Annex III(5)(b). Risk class confirmed by Head of Risk + DPO.

Oversight design

Decisions ≥£10k always reviewed by named credit officer. Sub-£10k decisions sampled at 5% rate. Override + reason captured for every reviewed case. Monthly false-positive / false-negative reporting to Risk Committee.

No customer-facing AI output detected from the tool name. Operator should still verify manually.

If your deployment generates customer-facing AI output, the obligations below apply even if your risk class is "limited".
3 pending4 in progress5 complete0 not applicable12 applicable obligations
  • art_4_ai_literacyArticle 4complete

    AI literacy of staff

    Ensure staff and other persons dealing with AI on your behalf have a sufficient level of AI literacy — basic understanding of what AI systems do, their risks, and how to interpret their output.

  • art_26_1_instructions_for_useArticle 26(1)completeevidence expected

    Use system per instructions

    Take appropriate technical and organisational measures to ensure the system is used in accordance with the provider's instructions for use.

  • art_26_2_human_oversight_assignmentArticle 26(2)complete

    Assign human oversight

    Assign human oversight to natural persons with the necessary competence, training, authority and support. Document who is responsible.

  • art_26_3_input_dataArticle 26(3)in progress

    Ensure input data is relevant

    To the extent the deployer exercises control over input data, ensure that input data is relevant and sufficiently representative for the intended purpose.

  • art_26_5_monitor_inform_providerArticle 26(5)in progress

    Monitor + inform provider of risk

    Monitor operation. If reasonable grounds to believe use in accordance with instructions creates a risk under Article 79(1), inform the provider/distributor and a market surveillance authority. Suspend use immediately.

  • art_26_6_keep_logsArticle 26(6)complete

    Retain automatic logs ≥ 6 months

    Keep the automatically generated logs for a period appropriate for the intended purpose, but at least six months unless EU/national law provides otherwise.

  • art_26_7_inform_workersArticle 26(7)pending

    Inform workers' representatives

    Before deploying a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and affected workers that they will be subject to use of the system.

  • art_26_8_inform_affected_personsArticle 26(8)in progress

    Inform natural persons subject to decision

    Inform natural persons subject to decisions taken or assisted by a high-risk AI system that they are subject to such use. Provide clear and meaningful information about the role of the AI in the decision-making procedure.

  • art_27_friaArticle 27in progressFRIA expected

    Fundamental Rights Impact Assessment

    Required for deployers of high-risk AI systems that are bodies governed by public law, private entities providing public services, or deployers of certain Annex III systems (credit scoring, insurance pricing). Document foreseeable risks to fundamental rights.

  • art_50_1_disclose_ai_interactionArticle 50(1)complete

    Disclose AI interaction

    If the AI system interacts directly with natural persons, inform them they are interacting with an AI system unless this is obvious from the context. Applies to deployers AND providers of those systems.

  • art_50_4_disclose_deepfakesArticle 50(4)pending

    Disclose deepfakes

    Deployers of AI systems that generate or manipulate image, audio, or video content that constitutes a deepfake must disclose that the content has been artificially generated or manipulated.

    Save classification first — this row will be materialised the moment the classification record is upserted.

  • art_73_serious_incident_reportingArticle 73pending

    Serious incident reporting

    Report any serious incident (death, serious harm to health, infrastructure damage, fundamental rights breach) to market surveillance authorities of the Member State where the incident occurred — within 15 days for providers, deployer cooperates.

FilenameKindSizeUploaded byUploadedExpiresActions
cursor-instructions-for-use.txtinstructions_for_use243 B[email protected]15 Jul 2026
Download
cursor-dpia.txtdpia272 B[email protected]13 Jul 202620 Jul 2027
Download

Attach new evidence

Max 10 MB per file. Any file type; we hash + store it server-side.

Residual risk acceptable?

No operator actions logged for this system yet. Classification edits, obligation status changes, evidence uploads, and FRIA saves will appear here automatically.

View full audit pack