Last reviewed 28 August 2026 · re-checked as European Commission guidance evolves

Our Risk Classification

The short version, then the reasoning.

In our assessment, ComplianceGxP is not a “high-risk AI system” under Annex III of the EU AI Act

ComplianceGxP is a RAG-based content-drafting copilot for pharma compliance documents — SOPs, deviations, CAPAs, CSV protocols. It doesn't fall into any of the eight Annex III categories (biometric ID, critical infrastructure, education/employment access, essential services, law enforcement, migration, justice/democratic processes), it isn't a safety component of a regulated medical device, and it doesn't make autonomous decisions with legal or similarly significant effect on a person. It answers questions about compliance frameworks like MDR — it doesn't perform a regulated medical function.

That means the Act's heaviest machinery — formal risk-management documentation, third-party conformity assessment, CE marking, EU database registration — does not apply to ComplianceGxP as a mandatory baseline. We re-check this conclusion periodically, since the European Commission's Annex III classification guidance is still evolving.

Who's Who Under the Act

Obligations differ sharply by role — here's how the pieces line up.

Party Role under the Act
LLMOps.Pro Provider of the ComplianceGxP AI system
Your organization Deployer of ComplianceGxP — you index your own SOPs, run queries, and feed outputs into your own QMS
Anthropic (Claude) Provider of the underlying general-purpose AI (GPAI) model. LLMOps.Pro is a deployer of that model, not a provider of a derivative one — ComplianceGxP calls the vendor's hosted API with retrieved context; it never touches model weights or fine-tunes.

What We Do Today

Controls that apply regardless of risk tier, plus voluntary strengths most “compliant” high-risk systems don't ship with.

  • Persistent AI-system disclosure. Every query surface states plainly that responses are AI-generated and require qualified human review before regulated use — addresses Article 50(1) transparency directly, rather than relying on it being “obvious from context.”
  • Tamper-evident audit trail, including refused queries. A SHA-256 hash-chained record of every interaction — answered and blocked — is a stronger record-keeping story than most nominally “high-risk-compliant” systems ship with.
  • Source-grounded generation by design. The system is instructed to answer only from your retrieved, indexed documents and to say so when it can't — materially reducing hallucination risk versus an ungrounded chat model.
  • Human-review gating baked into the prompts themselves. CAPA and CSV modes instruct the model to mark its own output DRAFT — REQUIRES REVIEW, not left to UI copy alone.
  • A runtime behavioral contract. Enforces citation requirements, blocks PII/credential leakage, requires disclaimers on interpretive answers, and caps latency/cost — an auditable governance artifact, not just a README claim.
  • GAMP5 IQ/OQ/PQ validation package. Not a substitute for AI Act technical documentation, but real, existing validation rigor most tools in this space don't have.

If You Hold Us to the High-Risk Bar Anyway

Some QA teams are more conservative than the strict legal text. Here's honestly where we'd stand against Articles 9–15, even though they aren't mandatory for us.

Requirement Status Why
Record-keeping (Art. 12) Strong Tamper-evident hash-chained audit trail, merges in blocked queries too
Human oversight (Art. 14) Strong Draft-labeling hard-coded into prompts; never writes back to your systems of record — feeds into your QMS, doesn't replace it
Risk management (Art. 9) Partial Runtime behavioral contract enforces constraints; a formal, continuous risk-management process document is not yet written up in AI-Act-specific shape
Data governance (Art. 10) Partial RAG grounds every answer in your own isolated, versioned documents by design; a formal due-diligence record for the underlying GPAI model is in progress
Technical documentation (Art. 11) Partial GAMP5 IQ/OQ answers “does it work as installed” — a dedicated Annex-IV-shaped technical file is in progress
Transparency to users (Art. 13) Partial Source citations and mode descriptions ship today; a single bundled “instructions for use” document is in progress
Accuracy, robustness, cybersecurity (Art. 15) Partial Retrieval-similarity thresholds and a functional OQ test suite exist; dedicated adversarial-robustness testing framed in AI-Act terms is not yet built

Reading this honestly: the rows a pharma QA auditor cares about most — record-keeping and human oversight — are genuinely solid. The partial rows are mostly documentation work: the underlying behavior is often already there, it just isn't written up yet in the shape an AI Act auditor expects.

Want the full analysis?

A detailed, working gap-list — classification reasoning, article-by-article evidence, and our closure plan — is available under NDA for pilot and prospect conversations.

Request the Full Analysis

Or start with the free Community demo — no registration required.

This page is informational, not legal advice. It reflects our own working analysis of the ComplianceGxP codebase against publicly available summaries of the EU AI Act (in force since 2 August 2026), reviewed 28 August 2026. It is not a certified determination and should not be relied upon as a substitute for review by qualified EU AI Act counsel — particularly before any compliance claim is treated as contractually binding. Deployers (your organization) retain their own obligations under the Act independent of what's described here; nothing on this page constitutes a warranty of regulatory compliance.