Section 01
EU AI Act executive summary
0Annex III indicators
76AI integrations
0Art. 50 gaps
18Doc artifacts
157Files scanned
78 EU AI Act signal(s); 1 fiction/KPI issue(s). Gate passes — MEDIUM findings are warnings under current failOn policy.
Section 02
EU AI Act compliance checklist
| Rule | Status | Evidence |
|---|---|---|
GATE-001 Merge gate passes on configured severities |
PASS | Gate pass — no blocking issues at configured severities |
CRED-001 No credential or secret patterns in scanned paths |
PASS | Scanned 191 path(s) — no credential patterns |
LEAK-001 No mock/sample JSON paths referenced from production directories |
PASS | Scanned 136 production file(s) — no sample-path leaks |
EUAI-001 High-risk AI indicators documented or absent |
PASS | No Annex III high-risk AI patterns detected in scanned paths |
EUAI-002 Article 50 transparency — AI outputs disclosed to users |
PASS | 76 AI integration(s) with Article 50 disclosure markers present |
EUAI-003 AI system documentation present when AI integrations detected |
PASS | 18 documentation artifact(s) found for 76 AI indicator(s) |
EUAI-004 Human oversight signals for high-risk AI decision paths |
PASS | No high-risk AI patterns — human oversight rule not applicable |
EUAI-005 AI decision logging for accountability |
FAIL | 2 AI decision path(s) without logging markers — add inference audit trail |
SUPPLY-001 No critical or high npm audit vulnerabilities |
PASS | npm audit: 0 critical, 0 high (scan) |
Section 03
Sample EU AI Act findings (prioritized)
| Severity | File | Finding | Remediation |
|---|---|---|---|
| MEDIUM | server/ai-proxy-gateway.js |
Generative AI or LLM integration detected | Review EU AI Act transparency and documentation obligations for this AI integration |
| MEDIUM | server/dlp-dashboard.js |
Generative AI or LLM integration detected | Review EU AI Act transparency and documentation obligations for this AI integration |
| MEDIUM | server/lib/code-understanding/code-understanding-engine.js |
Generative AI or LLM integration detected | Review EU AI Act transparency and documentation obligations for this AI integration |
| MEDIUM | server/lib/strategic-insights-engine.js |
Generative AI or LLM integration detected | Review EU AI Act transparency and documentation obligations for this AI integration |
| MEDIUM | server/lib/user-ai-keys-store.js |
Generative AI or LLM integration detected | Review EU AI Act transparency and documentation obligations for this AI integration |
| MEDIUM | server/routes/flexible-analyze-api.js |
Generative AI or LLM integration detected | Review EU AI Act transparency and documentation obligations for this AI integration |
Section 04
Recommended CI gate
npx simplebeacon init --profile eu-ai-act npx simplebeacon scan --gate npx simplebeacon compliance --checklist eu-ai-act --gate
This assessment is a static technical pattern review — not legal advice, formal conformity assessment, or certification under Regulation (EU) 2024/1689. Client remains responsible for legal classification and regulatory compliance.