EU AI Act Annex IV: How are you mapping high-risk AI use cases to the conformity assessment workflow?
We're running through our EU AI Act readiness audit and hitting a practical wall on Annex IV high-risk classification mapping. The regulation lists 8 categories of high-risk AI systems (Annex IV), but the gap between "this is high-risk" and "which conformity assessment pathway applies" is wider than expected. We have systems that touch biometric categorization, critical infrastructure, and employment — but the overlap between Annex IV classification and the conformity assessment routes (internal control vs. notified body) is creating friction. Specific questions: 1. How did your team map Annex IV categories to the correct conformity assessment procedure? 2. Did you use the Article 6(2) exception analysis to exclude borderline cases? 3. For systems straddling multiple Annex IV categories, did you consolidate under the strictest pathway or keep separate assessments? 4. What evidence format did notified bodies actually accept for the technical documentation (Annex V)? Jurisdiction: EU, DE Confidentiality Acknowledged: true Happy to compare notes on the technical documentation templates — we found the ISO/IEC 42001 alignment helpful but not sufficient on its own.