ComplianceGxP & the EU AI Act
Where we stand, in plain language — what applies, what we've built, and what's still open.
Last reviewed 28 August 2026 · re-checked as European Commission guidance evolves
Our Risk Classification
The short version, then the reasoning.
Who's Who Under the Act
Obligations differ sharply by role — here's how the pieces line up.
| Party | Role under the Act |
|---|---|
| LLMOps.Pro | Provider of the ComplianceGxP AI system |
| Your organization | Deployer of ComplianceGxP — you index your own SOPs, run queries, and feed outputs into your own QMS |
| Anthropic (Claude) | Provider of the underlying general-purpose AI (GPAI) model. LLMOps.Pro is a deployer of that model, not a provider of a derivative one — ComplianceGxP calls the vendor's hosted API with retrieved context; it never touches model weights or fine-tunes. |
What We Do Today
Controls that apply regardless of risk tier, plus voluntary strengths most “compliant” high-risk systems don't ship with.
- Persistent AI-system disclosure. Every query surface states plainly that responses are AI-generated and require qualified human review before regulated use — addresses Article 50(1) transparency directly, rather than relying on it being “obvious from context.”
- Tamper-evident audit trail, including refused queries. A SHA-256 hash-chained record of every interaction — answered and blocked — is a stronger record-keeping story than most nominally “high-risk-compliant” systems ship with.
- Source-grounded generation by design. The system is instructed to answer only from your retrieved, indexed documents and to say so when it can't — materially reducing hallucination risk versus an ungrounded chat model.
- Human-review gating baked into the prompts themselves. CAPA and CSV modes instruct the model to mark its own output
DRAFT — REQUIRES REVIEW, not left to UI copy alone. - A runtime behavioral contract. Enforces citation requirements, blocks PII/credential leakage, requires disclaimers on interpretive answers, and caps latency/cost — an auditable governance artifact, not just a README claim.
- GAMP5 IQ/OQ/PQ validation package. Not a substitute for AI Act technical documentation, but real, existing validation rigor most tools in this space don't have.
If You Hold Us to the High-Risk Bar Anyway
Some QA teams are more conservative than the strict legal text. Here's honestly where we'd stand against Articles 9–15, even though they aren't mandatory for us.
| Requirement | Status | Why |
|---|---|---|
| Record-keeping (Art. 12) | Strong | Tamper-evident hash-chained audit trail, merges in blocked queries too |
| Human oversight (Art. 14) | Strong | Draft-labeling hard-coded into prompts; never writes back to your systems of record — feeds into your QMS, doesn't replace it |
| Risk management (Art. 9) | Partial | Runtime behavioral contract enforces constraints; a formal, continuous risk-management process document is not yet written up in AI-Act-specific shape |
| Data governance (Art. 10) | Partial | RAG grounds every answer in your own isolated, versioned documents by design; a formal due-diligence record for the underlying GPAI model is in progress |
| Technical documentation (Art. 11) | Partial | GAMP5 IQ/OQ answers “does it work as installed” — a dedicated Annex-IV-shaped technical file is in progress |
| Transparency to users (Art. 13) | Partial | Source citations and mode descriptions ship today; a single bundled “instructions for use” document is in progress |
| Accuracy, robustness, cybersecurity (Art. 15) | Partial | Retrieval-similarity thresholds and a functional OQ test suite exist; dedicated adversarial-robustness testing framed in AI-Act terms is not yet built |
Reading this honestly: the rows a pharma QA auditor cares about most — record-keeping and human oversight — are genuinely solid. The partial rows are mostly documentation work: the underlying behavior is often already there, it just isn't written up yet in the shape an AI Act auditor expects.
Want the full analysis?
A detailed, working gap-list — classification reasoning, article-by-article evidence, and our closure plan — is available under NDA for pilot and prospect conversations.
Request the Full AnalysisOr start with the free Community demo — no registration required.