EU AI Act module
AI governance inside the platform you already use to run the organisation
The EU AI Act is often discussed as a compliance problem. We prefer to see it as an engineering principle: know which AI systems you use, understand their risk, know who is responsible, keep humans in control, train the people who use them — and keep the evidence that proves all of this.
The NexusOS AI Act module brings deployer accountability into the same operational environment where you already manage people, documents, processes and quality. Not another spreadsheet nobody wants to open.
EU AI Act as an engineering principle
Regulation (EU) 2024/1689 establishes harmonised rules for AI systems in the Union. Obligations depend on your role — provider, deployer, importer or distributor — and on the risk category of each system.
NexusOS is designed primarily for deployers: organisations that use AI under their authority. The module records your working classification, assigned users, duty registers and evidence — it supports accountability; it does not replace legal counsel or top-management decisions.
Key articles mapped in the product: Art. 4 AI literacy · Art. 5 prohibited-practice screening · Art. 26 deployer obligations · Art. 27 FRIA · Art. 50 transparency · Art. 71–72 documentation and logs · Art. 73 serious incidents · Art. 86 explanation of decisions.
A living inventory beats spreadsheets. Deployer duties attach to specific systems in use — Copilot licences, HR tools, chatbots, local Ollama deployments. NexusOS ties each system to coded records, assigned users, linked suppliers and models, duty registers, and a computed gap list.
- Art. 4 — AI literacy
- Art. 26 — Deployer duties
- Art. 27 — FRIA
- Art. 50 — Transparency
- Art. 73 — Serious incidents
- Art. 86 — Explanations
AI Act overview and gap engine
The AI Act landing page is your start-here view: quick paths into classification, systems inventory, deployer duties and literacy — with live gap counts and literacy coverage at a glance.
Gaps are computed from register completeness — missing FRIA, unsigned transparency notices, overdue literacy, unlinked evidence. Visible before an incident or regulator question, not after.
Activity feeds show who changed what. Reclassification updates the same record; audit trails stay connected to the system they describe.

Register hub — duties and catalogues in one place
The register hub cards give quick navigation to every duty area and catalogue: FRIA, transparency, incidents, human oversight, explanations, suppliers, models, course providers and literacy assignments.
All registers are tenant-scoped. Codes, sequences and records do not leak across companies. Business roles constrain access: members see My tools; managers maintain full registers; admins can trigger reminder checks.
This mirrors ISO 9001 controlled documented information (Clause 7.5) applied alongside AI-specific registers — with QMS documents linkable as evidence on each system.

Classification wizard
The classify wizard walks through identity, role fork (provider vs deployer), use kind, people and data involved, and Art. 5 prohibited-practice screening — with presets and live risk preview.
Classification applies deterministic heuristics, not a conformity assessment: HIGH when the system supports decisions about people in an Annex III area; LIMITED when it interacts with people (chat, synthetic content); MINIMAL otherwise. FRIA required when high-risk and not purely a staff SaaS tool.
Annex III areas supported: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, and AI as safety component of regulated products.

AI systems and SaaS tools inventory
Every AI system in use gets a coded record (SYS-…): role, risk class, status, Annex III area, FRIA flag, intended purpose, logging configuration, instructions and EU database registration where required.
The SaaS tools register filters staff AI tools from the main inventory — Copilot, chatbots, scoring tools — with presets, risk class and deployer metadata on each entry.
System detail tabs cover gaps, evidence (policies, DPAs, instructions), assigned users and related suppliers/models. When a use case changes, you update one record — not a disconnected spreadsheet row.

High-risk systems and FRIA
High-risk systems listed under Annex III show logging status, instructions compliance, oversight indicators and FRIA requirement flags.
The FRIA register (Art. 27) records processes affected, persons impacted, assessment outcome and reviewer — required for high-risk deployers before putting into service.
Evidence and gaps tabs on each system surface what is missing: unsigned instructions, no assigned overseer, overdue FRIA review. Export-ready for internal audit or management review.

Deployer duties hub
Art. 26 deployer obligations are organised in one hub: FRIA, transparency, serious incidents, human oversight and explanation of decisions — each with its own register and status tracking.
The hub connects back to the systems inventory. Duties are not abstract checklists; they attach to specific AI systems, users and evidence documents.
Reminders in settings are operational nudges for overdue reviews — not legal deadline calculators. Organisations verify current AI Act application dates against Official Journal text.

Transparency and serious incidents
Art. 50 transparency register: obligation type, notice text and where shown — for chatbots, synthetic audio/image/video/text, emotion recognition and deepfakes.
Art. 73 serious incidents register: severity, notification status and competent authority tracking. Incidents link to the AI system involved and supporting evidence.
Limited-risk systems still need transparency notices even when not high-risk. Minimal-risk systems remain in inventory for governance — voluntary codes of conduct encouraged by the Act.

Human oversight and explanation of decisions
Human oversight register (Art. 26): named person, role, override rights and training status for each high-risk system. Oversight is assigned, not assumed.
Explanation of decisions register (Art. 86): requester, decision summary, response status — for individuals who request an explanation of a decision supported by high-risk AI.
Human in the loop is not a slogan. NexusOS records who can override, who was trained, and whether explanations were provided — with dates and evidence.

Suppliers, models and AI literacy
Catalogues hub: AI suppliers (DPA, approval, risk level, last review), AI models (LOCAL/CLOUD, data classification, approval), course providers and literacy courses.
Art. 4 AI literacy: assignments register who passed what, with dates, scores and validity period. Providers and courses link to legal entity records.
Deployers shall ensure sufficient AI literacy of staff. NexusOS makes coverage visible — who is trained, who is overdue, which course applies to which role.

Dossier export and audit evidence
The dossier view provides searchable tables across all registers with export actions — ready for internal audit, management review or regulator request.
Evidence tab on each system links QMS controlled documents, DPAs, provider instructions and policies. Drive files remain the storage layer; AI Act metadata stays linked.
Gap engine highlights missing evidence before export. What you cannot demonstrate in an audit, you cannot claim in a policy.

Local AI Act copilot (Ollama)
Governance itself can benefit from AI — under human control. The NexusOS AI Act agent runs on local Ollama on the organisation's infrastructure. Inventory and register text are not sent to a public SaaS LLM by default.
The copilot helps navigate registers, draft notices and summarise gaps — with human confirmation before changes are made. This supports Art. 26 oversight expectations and GDPR data-minimisation for compliance records.
Cosmic Brokkoli selects intelligence placement deliberately: frontier models where advanced reasoning adds value under governance; local AI for sensitive compliance workloads.

Product scope and limitations
In scope: authentication, navigation, every register (systems, duties, catalogues, literacy), gap engine, dossier export, reminders, My tools for end users, and the on-premises AI Act agent.
Out of scope: CE marking, Annex IV technical documentation, notified-body files, EU database filing, provider quality management systems. When your organisation places AI on the market as a provider, seek specialist advice.
NexusOS records your working classification — not a legal determination or conformity assessment. Settings include reminder checks and a link to this product scope description.

Product screens
All AI Act module views — NAIACT v20260901.01
























Request a demo
Contact the team