> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 10 AIGO EU AI Act Annexes Mapping v0.1

# AIGO — EU AI Act Annexes Mapping

## 1. Document Purpose

This document provides the AIGO mapping for the Annexes to Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744.

The Annexes contain important classification, documentation, conformity, registration, and related regulatory information. They therefore form a critical part of the AIGO regulatory-mapping architecture.

This document maps the Annex structure to:

* AIGO AI-system classification;
* regulatory applicability;
* risk;
* controls;
* assessments;
* conformity;
* documentation;
* evidence;
* registration;
* assurance;
* monitoring;
* change management;
* governance; and
* lifecycle management.

This document is an operational governance mapping. It is not legal advice, a legal opinion, a conformity assessment, or a declaration of compliance.

Regulation (EU) 2026/1744 amended several Annexes, including Annex I and Annex VIII, and added a new Annex XIV. The current consolidated legal position must therefore be used instead of the original 2024 Annex structure alone.

***

## 2. Mapping Information

| Field                      | Value                                          |
| -------------------------- | ---------------------------------------------- |
| Mapping                    | AIGO EU AI Act Annexes Mapping                 |
| Version                    | 0.1                                            |
| Status                     | Draft                                          |
| Document Identifier        | `AIGO-MAP-EUAI-010`                            |
| Document Type              | EU AI Act Mapping                              |
| Mapping Package            | `AIGO-MAP-EUAI`                                |
| Primary Legal Instrument   | Regulation (EU) 2024/1689                      |
| Current Amendment Baseline | Regulation (EU) 2026/1744                      |
| Primary Scope              | Annexes I–XIV, where applicable                |
| Mapping Architecture       | `AIGO-MAP-EUAI-ARCH-001`                       |
| Registry                   | `00-AIGO-EU-AI-Act-Mapping-Registry-v0.1.json` |

The Digital Omnibus amended Annex I, deleted one item from Section A, added Regulation (EU) 2023/1230 on machinery to Section B, modified Annex VIII, and added Annex XIV concerning the codes, categories, and corresponding AI-system types used for notification of conformity-assessment bodies.

***

# 3. Annex Governance Principle

AIGO should not treat the Annexes as a single classification list.

Each Annex has a distinct legal function.

The preferred model is:

```text id="0mbxaw" theme={null}
EU AI Act Annex
       ↓
Legal Function
       ↓
Applicability
       ↓
AIGO Mapping
       ↓
Control / Assessment / Evidence
```

Examples:

```text id="2qhn4y" theme={null}
Annex I
→ Product-related high-risk classification

Annex III
→ Stand-alone high-risk use-case classification

Annex IV
→ Technical documentation

Annex V
→ EU declaration of conformity

Annex VI / VII
→ Conformity-assessment procedures

Annex VIII / IX
→ Registration-related information

Annex XIV
→ Notified-body designation scope
```

The exact legal role of each Annex must always be checked against the current consolidated Regulation.

***

# 4. Annex Applicability Model

AIGO should determine the relevant Annex through a structured decision process:

```text id="w8kyl4" theme={null}
AI System
    ↓
Intended Purpose
    ↓
Actor
    ↓
Product / Use Context
    ↓
Article 6
    ↓
Relevant Annex
    ↓
Applicable Legal Requirements
```

One AI system may interact with more than one Annex.

For example:

```text id="t5iz3o" theme={null}
Annex I
   ↓
High-Risk Classification

Annex IV
   ↓
Technical Documentation

Annex V
   ↓
Declaration

Annex VIII / IX
   ↓
Registration

Annex XIV
   ↓
Conformity-Assessment-Body Scope
```

***

# 5. Annex I — Union Harmonisation Legislation

## 5.1 Legal Function

Annex I identifies Union harmonisation legislation relevant to the Article 6(1) high-risk pathway.

The classification framework distinguishes AI systems that are safety components of products covered by the listed Union harmonisation legislation, or AI systems that are themselves such products, subject to the statutory conditions. The Commission's draft high-risk guidance describes this as the first high-risk pathway.

## 5.2 AIGO Mapping

**AIGO Components:**

* AI System;
* Classification;
* Governance;
* Risk;
* Assessment;
* Conformity;
* Evidence;
* Assurance.

**Relationship:**

`DIRECT / CONDITIONAL / CRITICAL`

***

# 6. Annex I Classification Control

**Control Name:** Annex I Product-Related High-Risk Classification

The control should determine:

* applicable Union harmonisation legislation;
* product category;
* safety-component relationship;
* AI-system relationship;
* required conformity assessment;
* high-risk status;
* applicable transition;
* evidence.

The control should not simply classify a system as high-risk because the product appears in Annex I.

The full Article 6(1) legal conditions must also be satisfied.

***

# 7. Annex I Current Amendment

Regulation (EU) 2026/1744 amended Annex I.

Among other changes, it:

* deleted point 1 of Section A; and
* added Regulation (EU) 2023/1230 on machinery as point 21 of Section B.

The amendment also links certain machinery-related requirements to the revised AI Act application framework.

AIGO shall therefore treat the **current consolidated Annex I** as authoritative.

***

# 8. Annex I Governance Record

For an Article 6(1) determination, AIGO should maintain:

| Field                | Purpose                         |
| -------------------- | ------------------------------- |
| AI System            | Identify system                 |
| Product              | Identify associated product     |
| Product Manufacturer | Identify actor                  |
| Union Legislation    | Identify applicable legislation |
| Annex I Section      | A / B                           |
| Annex I Point        | Exact point                     |
| Safety Component     | Determine relationship          |
| Conformity Route     | Determine assessment            |
| High-Risk Status     | Classification                  |
| Evidence             | Support determination           |
| Reviewer             | Accountability                  |
| Review Date          | Currency                        |

***

# 9. Annex I and Product Compliance

AIGO should maintain a relationship among:

```text id="5ufnq8" theme={null}
Product
   ↓
Union Harmonisation Legislation
   ↓
Conformity Assessment
   ↓
AI System
   ↓
Article 6(1)
   ↓
AI Act Requirements
```

AIGO should avoid creating a second product-compliance system where an existing product-compliance framework already provides authoritative records.

Instead, AIGO should integrate with the existing framework.

***

# 10. Annex I and Notified Bodies

Where third-party conformity assessment is required, Annex I classification may affect:

* notified-body scope;
* assessment module;
* product law;
* AI Act assessment;
* certification.

AIGO should preserve all relevant references.

The current amended AI Act also introduces transitional arrangements concerning certain notified bodies already notified under relevant Union harmonisation legislation.

***

# 11. Annex II — Governance Treatment

The AIGO mapping shall verify the current consolidated legal text before treating Annex II as an operational classification source.

The Annex numbering in a version-controlled regulatory mapping must not be inferred from secondary summaries.

Where an Annex has been repealed, renumbered, or otherwise altered by subsequent legislation, the registry should preserve its historical status.

Recommended states include:

```text id="4rxwpt" theme={null}
CURRENT
HISTORICAL
SUPERSEDED
REPEALED
NOT_APPLICABLE
```

This prevents historical Annex references from being mistaken for current requirements.

***

# 12. Annex III — High-Risk AI Systems Referred to in Article 6(2)

## 12.1 Legal Function

Annex III defines specified high-risk AI use cases for the Article 6(2) pathway.

The Commission's current draft high-risk guidance identifies Annex III as the second principal high-risk classification pathway.

## 12.2 AIGO Mapping

**Relationship:**

`DIRECT / CRITICAL`

## 12.3 AIGO Requirement

The organization should record:

* Annex III area;
* exact use case;
* intended purpose;
* actor;
* affected persons;
* applicable exception;
* high-risk determination;
* evidence;
* effective date.

***

# 13. Annex III Areas

The current Annex III structure covers high-risk use cases in areas including:

1. biometrics;
2. critical infrastructure;
3. education and vocational training;
4. employment, workers management and access to self-employment;
5. access to and enjoyment of essential private and public services and benefits;
6. law enforcement;
7. migration, asylum and border control;
8. administration of justice and democratic processes.

The precise legal wording and sub-points must be taken from the current consolidated Annex III.

The Commission's May 2026 review report specifically identified Annex III as subject to annual review to determine whether amendments are needed.

***

# 14. Annex III Classification Control

**Control Name:** Annex III High-Risk Use-Case Classification

The control should:

* identify the relevant Annex III category;
* assess the precise use case;
* evaluate applicable Article 6 conditions;
* consider statutory exceptions;
* record classification rationale;
* retain evidence.

***

# 15. Annex III and Article 5

The organization must perform Article 5 screening before treating an Annex III system as merely high-risk.

The governance sequence is:

```text id="y1f5er" theme={null}
Potential AI Use
      ↓
Article 5 Screening
      ↓
If Not Prohibited
      ↓
Article 6 / Annex III Classification
```

An AI system may be:

* prohibited;
* high-risk;
* neither;
* subject to other obligations.

A high-risk classification does not override Article 5.

***

# 16. Annex III and Fundamental Rights

Annex III systems may have significant effects on:

* employment;
* education;
* access to services;
* law enforcement;
* migration;
* justice;
* democratic processes.

AIGO should therefore connect Annex III classification to:

* Risk;
* Assessment;
* Fundamental Rights;
* Human Oversight;
* Monitoring;
* Evidence;
* Assurance.

***

# 17. Annex III and Article 27

Where Article 27 applies, the Annex III classification should feed the Fundamental-Rights Impact Assessment.

Recommended chain:

```text id="2ry7bq" theme={null}
Annex III Classification
      ↓
Article 27 Applicability
      ↓
Fundamental-Rights Assessment
      ↓
Controls
      ↓
Monitoring
```

***

# 18. Annex III Review and Regulatory Change

The Commission conducts annual review of the prohibited-practice list and Annex III high-risk use cases under Article 112(1). Its 2026 review report considered whether the list remains appropriate as AI technology develops.

AIGO should therefore treat Annex III as a controlled regulatory-change object.

***

# 19. Annex IV — Technical Documentation

## 19.1 Legal Function

Annex IV defines the information that must be included in the technical documentation for applicable high-risk AI systems.

## 19.2 AIGO Mapping

**Relationship:**

`DIRECT / CRITICAL`

## 19.3 AIGO Controls

* Technical Documentation Control;
* Document Integrity Control;
* Change Management Control;
* Evidence Control;
* Assurance Control.

***

# 20. Annex IV Documentation Structure

The AIGO technical-documentation framework should account for the legal categories in Annex IV, including, as applicable:

* general description;
* intended purpose;
* system architecture;
* development methods;
* design specifications;
* data requirements;
* computational resources;
* training;
* validation;
* testing;
* risk management;
* human oversight;
* performance;
* accuracy;
* robustness;
* cybersecurity;
* lifecycle;
* post-market monitoring.

The exact statutory content must be derived from the current Annex IV text.

***

# 21. Annex IV and AIGO AI System Profile

The AIGO AI System Profile can provide the operational foundation for many Annex IV data points.

However:

```text id="5m7fwm" theme={null}
AIGO AI System Profile
        ≠
Annex IV Technical Documentation
```

The profile may support and reference the statutory documentation but should not be declared complete merely because the AIGO profile exists.

***

# 22. Annex IV and Evidence

Each material technical-documentation component should be traceable to:

* source;
* version;
* owner;
* review;
* supporting evidence.

Recommended chain:

```text id="i29m5b" theme={null}
Annex IV Requirement
      ↓
Document Component
      ↓
Evidence
      ↓
Review
      ↓
Approval
```

***

# 23. Annex IV and Change Management

Changes affecting:

* architecture;
* model;
* training;
* data;
* intended purpose;
* performance;
* human oversight;
* cybersecurity;
* deployment

should trigger technical-documentation impact analysis.

***

# 24. Annex IV and Document Integrity

The Document Integrity Checker should verify:

* existence;
* readability;
* version;
* metadata;
* integrity;
* required references;
* internal consistency.

It does not determine substantive legal adequacy.

***

# 25. Annex V — EU Declaration of Conformity

## 25.1 Legal Function

Annex V establishes the information to be included in the EU declaration of conformity.

## 25.2 AIGO Mapping

**Relationship:**

`DIRECT / CRITICAL`

## 25.3 AIGO Control

**EU Declaration of Conformity Governance Control**

The control should maintain:

* declaration;
* applicable AI system;
* applicable legislation;
* provider;
* authorized signatory;
* date;
* version;
* supporting conformity evidence.

***

# 26. Annex V and AIGO Approval

An internal approval decision should remain separate from the EU declaration.

```text id="8z5dkl" theme={null}
AIGO Approval
        ≠
EU Declaration of Conformity
```

AIGO approval may provide governance evidence supporting the statutory process.

***

# 27. Annex V and Change Management

When a system changes, AIGO should determine whether the declaration of conformity must be:

* updated;
* replaced;
* reassessed;
* supplemented.

The specific legal requirement must be checked against the current law.

***

# 28. Annex VI — Conformity Assessment Based on Internal Control

## 28.1 Legal Function

Annex VI establishes the conformity-assessment procedure based on internal control for applicable high-risk AI systems.

## 28.2 AIGO Mapping

**Relationship:**

`DIRECT / CONDITIONAL`

## 28.3 AIGO Implementation

Where legally applicable, AIGO can support:

* internal control;
* documentation;
* risk management;
* QMS;
* testing;
* monitoring;
* evidence;
* corrective actions;
* review.

***

# 29. Annex VI and Internal Assessment

AIGO should distinguish:

```text id="d3k5ex" theme={null}
AIGO Internal Control Assessment
```

from:

```text id="7z4m8n" theme={null}
Statutory Conformity Assessment Based on Internal Control
```

The first may support the second.

It should not automatically be described as the second.

***

# 30. Annex VII — Conformity Assessment Based on Quality Management System and Assessment of Technical Documentation

## 30.1 Legal Function

Annex VII provides the conformity-assessment procedure involving quality management and, as applicable, assessment of technical documentation.

## 30.2 AIGO Mapping

**Relationship:**

`DIRECT / CRITICAL`

AIGO should support:

* QMS evidence;
* technical documentation;
* notified-body interaction;
* assessment findings;
* corrective actions;
* certificate;
* surveillance.

***

# 31. Annex VII and Notified Bodies

Where a notified body is required, AIGO should maintain:

* body identity;
* scope;
* notification status;
* contract;
* assessment;
* findings;
* certificate;
* surveillance.

The current legal framework must be checked when determining whether a particular body is eligible for a particular assessment.

***

# 32. Annex VIII — Information to Be Submitted for Registration

## 32.1 Legal Function

Annex VIII defines information used for registration-related purposes under the AI Act.

## 32.2 AIGO Mapping

**Relationship:**

`DIRECT`

## 32.3 AIGO Registration Control

The control should maintain:

* registration applicability;
* required information;
* responsible person;
* submission;
* identifier;
* update;
* evidence.

***

# 33. Annex VIII Amendment

Regulation (EU) 2026/1744 deleted points 7 and 9 from Section B of Annex VIII.

Therefore, AIGO registration templates and data structures must be checked against the current amended Annex VIII rather than relying on an older registration-information model.

***

# 34. Registration Data Governance

Registration information should be sourced from authoritative AIGO records.

Recommended chain:

```text id="k4wyz6" theme={null}
AI System
     ↓
Authoritative Metadata
     ↓
Registration Dataset
     ↓
Validation
     ↓
Submission
     ↓
Registration Evidence
```

This reduces the risk of inconsistent registration information.

***

# 35. Registration and Change Management

Changes should trigger registration review where legally relevant.

Potential triggers:

* provider change;
* system identity change;
* intended-purpose change;
* classification change;
* conformity change;
* deployment change;
* other legally relevant metadata changes.

***

# 36. Annex IX — Information Relating to Registration

## 36.1 Legal Function

AIGO shall maintain the current legal function and content of Annex IX as specified in the consolidated Regulation.

Where Annex IX contains registration-related information applicable to the organization's role or system, the information should be represented in the AIGO registration and evidence model.

## 36.2 AIGO Mapping

**Relationship:**

`DIRECT / CONDITIONAL`

***

# 37. Annex IX and Registration Architecture

Where applicable:

```text id="3c1w8c" theme={null}
Annex IX Requirement
       ↓
Registration Data
       ↓
AIGO AI System Record
       ↓
Submission
       ↓
Evidence
```

AIGO should verify the current Annex IX text before implementing or automating individual registration fields.

***

# 38. Annex X — Historical / Current-Status Verification

Where the consolidated AI Act contains Annex X material, the AIGO Registry shall record its current status explicitly.

The registry should distinguish:

* current Annex;
* amended Annex;
* superseded Annex;
* historical reference.

A mapping release must not infer substantive requirements from an obsolete Annex solely because a historical document still cites it.

***

# 39. Annex XI — Historical / Current-Status Verification

As with Annex X, the current legal status and operational function of Annex XI must be verified against the consolidated Regulation.

The AIGO mapping registry should maintain:

* title;
* legal function;
* current status;
* applicable article;
* AIGO relationship;
* review date.

***

# 40. Annex XII — Historical / Current-Status Verification

AIGO shall record Annex XII using the current consolidated legal text.

Where Annex XII supports:

* registration;
* documentation;
* classification;
* notification;
* other administrative purposes;

the relevant AIGO control should be identified.

Historical versions should not be treated as current requirements.

***

# 41. Annex XIII — Historical / Current-Status Verification

AIGO shall verify the current legal function of Annex XIII from the consolidated Regulation.

The mapping registry should identify:

```text id="co6sjn" theme={null}
Annex
Legal Function
Current Status
Relevant Article
AIGO Component
```

The architecture intentionally avoids inventing requirements where the current consolidated text needs to be consulted directly.

***

# 42. Annex XIV — Notified-Body Designation Scope

## 42.1 Current Legal Function

Regulation (EU) 2026/1744 added Annex XIV.

Annex XIV provides the lists of codes, categories, and corresponding AI-system types used for the notification procedure under Article 30 and defines the scope of designation of conformity-assessment bodies notified under the AI Act.

## 42.2 AIGO Mapping

**Relationship:**

`DIRECT / CONDITIONAL`

***

# 43. Annex XIV — Why It Matters

Annex XIV provides a machine-oriented classification layer for conformity-assessment-body designation.

The current Annex includes codes for:

* AI systems subject to Annex I;
* specified Annex III biometric systems;
* symbolic AI and expert systems;
* machine learning excluding generative and GPAI systems;
* generative AI and GPAI-based systems;
* emerging AI technologies, including agentic AI.

This creates a new mapping opportunity for AIGO's conformity-governance architecture.

***

# 44. Annex XIV Codes

The current Annex XIV identifies, among others:

```text id="tjsim9" theme={null}
AIP 0102–AIP 0112
→ Annex I AI-system types

AIB 0201
→ Remote biometric identification systems

AIB 0202
→ Biometric categorisation AI systems

AIB 0203
→ Emotion recognition AI systems

AIH 0101
→ Symbolic AI / expert / knowledge-based systems

AIH 0201–AIH 0205
→ Machine-learning technology categories

AIH 0301
→ Generative AI systems, including systems based on GPAI models

AIH 0401
→ Emerging AI technologies, including agentic AI
```

The organization should use the current EUR-Lex text for the authoritative code definitions.

***

# 45. Annex XIV AIGO Control

**Control Name:** Conformity-Assessment-Body Scope Verification

The control should verify:

* applicable AI-system category;
* relevant Annex XIV code;
* notified body's designated scope;
* requested assessment type;
* notification status;
* evidence of authority.

This control should be performed before relying on a notified body for an assessment.

***

# 46. Annex XIV and Notified-Body Selection

The selection process should be:

```text id="lxjhmv" theme={null}
AI System
      ↓
High-Risk Pathway
      ↓
Annex XIV Code
      ↓
Assessment Requirement
      ↓
Notified-Body Scope
      ↓
Eligible Body
      ↓
Contract / Assessment
```

This creates traceability between system type and assessment-body competence.

***

# 47. Annex XIV and Technology Categories

Annex XIV explicitly introduces technology-specific categories.

AIGO should therefore preserve the distinction between:

* legal risk category;
* technology category;
* conformity-assessment category;
* AIGO technical classification.

These should not be merged into a single classification field.

***

# 48. Annex XIV and Generative AI

The inclusion of generative AI and GPAI-based systems in Annex XIV means that AIGO should be prepared to map:

```text id="qdqzq4" theme={null}
GPAI / Generative Capability
        ↓
AIH 0301
        ↓
Conformity-Assessment-Body Scope
```

This does not mean that every generative AI system is high-risk.

Annex XIV codes support designation scope; they do not independently determine the complete Article 6 classification.

***

# 49. Annex XIV and Agentic AI

Annex XIV includes emerging AI technologies not covered by other codes, including agentic AI.

AIGO should therefore maintain the concept:

`AIH 0401 — Emerging AI technologies`

as a technology-classification field where relevant.

This should not automatically be interpreted as a high-risk determination.

***

# 50. Annex XIV and AIGO Technical Classification

The AIGO AI System Profile may eventually include:

```text id="8a2nwq" theme={null}
Technology Classification
Legal Classification
High-Risk Pathway
Annex Reference
Annex XIV Code
Conformity Pathway
```

This provides a structured bridge between legal and technical classifications.

***

# 51. Annex XIV and Supplier Governance

Where a notified body is procured, AIGO should require scope verification before engagement.

Supplier evidence should include:

* notification;
* scope;
* code;
* authority;
* validity;
* applicable assessment.

***

# 52. Annex XIV and Assurance

Assurance may review:

* code selection;
* notified-body scope;
* current authorization;
* assessment scope;
* certificate relationship.

This is particularly important because selecting an otherwise legitimate conformity-assessment body outside the relevant designated scope may create a material conformity issue.

***

# 53. Annex XIV and Change Management

If the AI system changes technology category or intended use, AIGO should reassess:

* Annex XIV code;
* conformity pathway;
* notified-body scope;
* assessment requirements.

***

# 54. Annex XIV and Registry

The AIGO Mapping Registry should eventually include Annex XIV codes as controlled values where operationally useful.

Potential fields:

```text id="0kx65x" theme={null}
annexXIVCode
annexXIVCategory
technologyCategory
assessmentBodyScope
```

***

# 55. Annex Crosswalk

The principal AIGO crosswalk is:

| Annex      | Principal Function                                  | AIGO Mapping                                         |
| ---------- | --------------------------------------------------- | ---------------------------------------------------- |
| Annex I    | Product-related high-risk classification            | AI System / Classification / Conformity              |
| Annex II   | Current-status verification                         | Registry / Legal Source                              |
| Annex III  | Stand-alone high-risk use cases                     | Classification / Risk / Assessment                   |
| Annex IV   | Technical documentation                             | AI System / Evidence / Documentation                 |
| Annex V    | EU declaration of conformity                        | Evidence / Approval                                  |
| Annex VI   | Internal-control conformity assessment              | Assessment / Assurance                               |
| Annex VII  | QMS / technical-documentation conformity assessment | Governance / Assessment / Assurance                  |
| Annex VIII | Registration information                            | Governance / Evidence                                |
| Annex IX   | Registration-related information                    | Governance / Evidence                                |
| Annex X    | Current-status verification                         | Registry / Legal Source                              |
| Annex XI   | Current-status verification                         | Registry / Legal Source                              |
| Annex XII  | Current-status verification                         | Registry / Legal Source                              |
| Annex XIII | Current-status verification                         | Registry / Legal Source                              |
| Annex XIV  | Notified-body designation scope and AI-system codes | Classification / Conformity / Third-Party Governance |

The table deliberately avoids inventing substantive requirements for Annexes whose current legal function needs direct verification from the consolidated Regulation.

***

# 56. Annex Lifecycle Mapping

| Lifecycle Stage  | Annex Relevance                                |
| ---------------- | ---------------------------------------------- |
| Planning         | Annex III / Annex I classification             |
| Design           | Annex IV documentation                         |
| Development      | Annex IV                                       |
| Data Preparation | Annex IV / High-Risk obligations               |
| Testing          | Annex IV / VI / VII                            |
| Approval         | Annex V / VI / VII                             |
| Deployment       | Registration / conformity                      |
| Operation        | Monitoring / registration                      |
| Monitoring       | Annex IV / post-market records                 |
| Change           | Annex I / III / IV / conformity / registration |
| Assurance        | Annex VI / VII / XIV                           |
| Retirement       | Documentation / registration / retention       |

***

# 57. Annex Risk Mapping

Potential AIGO risks include:

```text id="9llq9n" theme={null}
ANNEX_CLASSIFICATION_RISK
PRODUCT_CONFORMITY_RISK
TECHNICAL_DOCUMENTATION_RISK
REGISTRATION_RISK
DECLARATION_RISK
NOTIFIED_BODY_SCOPE_RISK
CONFORMITY_ASSESSMENT_RISK
CHANGE_IMPACT_RISK
REGULATORY_CURRENCY_RISK
EVIDENCE_RISK
```

***

# 58. Annex Control Matrix

| Annex Area | Primary AIGO Control              | Evidence                      |
| ---------- | --------------------------------- | ----------------------------- |
| Annex I    | Product High-Risk Classification  | Classification Assessment     |
| Annex III  | High-Risk Use-Case Classification | Classification Assessment     |
| Annex IV   | Technical Documentation           | Technical Documentation       |
| Annex V    | Declaration Governance            | Declaration                   |
| Annex VI   | Internal Conformity Control       | Assessment                    |
| Annex VII  | QMS / Third-Party Assessment      | Assessment / Certificate      |
| Annex VIII | Registration                      | Registration Evidence         |
| Annex IX   | Registration Information          | Registration Evidence         |
| Annex XIV  | Notified-Body Scope Verification  | Scope / Notification Evidence |

***

# 59. Annex Evidence

AIGO evidence may include:

* classification assessments;
* product-law evidence;
* intended-purpose documentation;
* technical documentation;
* test results;
* QMS records;
* conformity assessments;
* declarations;
* certificates;
* registration records;
* notified-body scope evidence;
* regulatory correspondence;
* change records;
* assurance reports.

***

# 60. Annex Traceability

The minimum Annex traceability chain is:

```text id="rjvf5g" theme={null}
EU AI Act Annex
      ↓
Legal Function
      ↓
Applicable AI System
      ↓
Applicability / Classification
      ↓
AIGO Requirement
      ↓
Control
      ↓
Assessment
      ↓
Evidence
      ↓
Assurance
```

***

# 61. Annex and Article Traceability

Annex mappings should always connect back to their governing Article.

Examples:

```text id="a6z7y5" theme={null}
Article 6
   ↕
Annex I
   ↕
High-Risk Classification
```

```text id="h75wqy" theme={null}
Article 6
   ↕
Annex III
   ↕
High-Risk Classification
```

```text id="e9dr9b" theme={null}
Article 11
   ↕
Annex IV
   ↕
Technical Documentation
```

```text id="sq6o5u" theme={null}
Article 30
   ↕
Annex XIV
   ↕
Conformity-Assessment-Body Designation Scope
```

This article-to-annex linkage should be retained in machine-readable records.

***

# 62. Annex and AIGO Schema Traceability

| Annex      | AIGO Schema                         |
| ---------- | ----------------------------------- |
| Annex I    | AI System / Assessment              |
| Annex III  | AI System / Assessment              |
| Annex IV   | AI System / Evidence                |
| Annex V    | Evidence / Approval                 |
| Annex VI   | Assessment / Assurance              |
| Annex VII  | Governance / Assessment / Assurance |
| Annex VIII | Governance / Evidence               |
| Annex IX   | Governance / Evidence               |
| Annex XIV  | AI System / Governance / Assessment |

***

# 63. Annex and Control Coverage

The Control Coverage Validator should eventually identify:

* applicable Annex;
* mapped AIGO control;
* implemented control;
* assessed control;
* evidenced control;
* assured control.

A legal Annex being mapped does not by itself mean the organization satisfies it.

***

# 64. Annex and Evidence Coverage

The Evidence Coverage Validator should eventually identify:

* missing technical documentation;
* missing classification evidence;
* missing registration evidence;
* missing conformity evidence;
* missing notified-body evidence.

***

# 65. Annex and Document Integrity

The Document Integrity Checker should verify:

* mapping files;
* legal source references;
* Annex version;
* cross-reference integrity;
* registry consistency;
* controlled Annex references.

***

# 66. Annex and Framework Consistency

The Framework Consistency Checker should detect:

* inconsistent Annex references;
* obsolete Annex names;
* incorrect article-to-annex relationships;
* stale dates;
* outdated product-law references;
* conflicting notified-body codes.

***

# 67. Annex and Repository Health

The Repository Health Checker should report:

* Annex mapping completeness;
* legal-source currency;
* broken Annex references;
* inconsistent Annex numbering;
* unreviewed amendments;
* registration mapping gaps;
* conformity mapping gaps.

***

# 68. Digital Omnibus Impact

Regulation (EU) 2026/1744 materially affects the Annex architecture.

At minimum, the AIGO mapping must account for:

* Annex I changes;
* Annex VIII changes;
* new Annex XIV;
* revised Article 6 timeline;
* revised conformity framework;
* updated notified-body arrangements.

This is a mandatory regulatory-update trigger for the Annex mapping.

***

# 69. Annual Annex Review

The organization should monitor the AI Act's annual review mechanism.

The Commission's 2026 report specifically evaluates whether the prohibited-practice list and Annex III high-risk use-case list need amendment.

AIGO should therefore schedule:

```text id="s1gg8s" theme={null}
Annual Regulatory Review
        ↓
Annex I Review
        ↓
Annex III Review
        ↓
Other Annex Review
        ↓
Impact Assessment
        ↓
Mapping Update
```

***

# 70. Annex Change Management

A change to an Annex should trigger:

1. source verification;
2. affected requirement identification;
3. affected AI-system identification;
4. classification review;
5. control-impact assessment;
6. evidence-impact assessment;
7. conformity-impact assessment;
8. documentation impact;
9. management review;
10. implementation;
11. verification.

***

# 71. Annex Applicability Findings

Potential findings include:

```text id="4k5ddz" theme={null}
ANNEX_APPLICABILITY_UNRESOLVED
ANNEX_REFERENCE_STALE
ANNEX_CLASSIFICATION_MISSING
ANNEX_I_PRODUCT_MAPPING_MISSING
ANNEX_III_USE_CASE_MAPPING_MISSING
ANNEX_IV_DOCUMENTATION_GAP
ANNEX_V_DECLARATION_GAP
ANNEX_VI_CONFORMITY_GAP
ANNEX_VII_CONFORMITY_GAP
ANNEX_VIII_REGISTRATION_GAP
ANNEX_IX_REGISTRATION_GAP
ANNEX_XIV_SCOPE_CODE_MISSING
ANNEX_CHANGE_NOT_ASSESSED
```

***

# 72. Critical Annex Findings

Potential critical findings include:

* high-risk classification relies on an obsolete Annex I or III version;
* required Annex IV documentation is materially absent;
* applicable conformity assessment has not been determined;
* required declaration is absent;
* registration requirements are not assessed;
* notified-body scope is not verified;
* Annex XIV code is incorrectly assigned for a required conformity assessment;
* material Annex amendment is not reflected in governance.

***

# 73. Annex Regulatory Currency

Each Annex mapping record should retain:

* legal source;
* amendment;
* publication date;
* effective date;
* applicability date;
* source verification date;
* mapping version.

This supports reproducibility.

***

# 74. Annex Source Hierarchy

For Annex-specific questions, AIGO should use:

```text id="tst3u0" theme={null}
Current EUR-Lex Consolidated Text
        ↓
Amending Regulation
        ↓
Official Commission Guidance
        ↓
Official AI Office Material
        ↓
AIGO Mapping
        ↓
Organizational Policy
```

Lower-level sources must not override binding legal text.

***

# 75. Annex Review Frequency

Minimum:

* annual;
* after every AI Act amendment;
* after new delegated acts;
* after implementing acts;
* after material Commission guidance;
* after major changes in harmonised standards or common specifications.

Event-driven review takes precedence.

***

# 76. Annex Mapping Confidence

Each Annex mapping should support:

```text id="m3fa47" theme={null}
HIGH
MEDIUM
LOW
PENDING_INTERPRETATION
```

Confidence represents mapping certainty, not legal certainty.

***

# 77. Annex Governance Ownership

The Annex mapping package should have:

* Mapping Owner;
* Legal/Compliance Reviewer;
* Conformity Reviewer;
* AI Governance Owner;
* Framework Architect;
* Evidence Owner;
* Assurance Reviewer.

Annex XIV code and notified-body mappings should have a specific conformity owner where relevant.

***

# 78. Annex Registration and Machine Readability

A future AIGO mapping schema may include:

```text id="6q7z2b" theme={null}
annexId
annexVersion
legalFunction
articleReference
applicability
classificationPath
aigoComponent
control
assessment
evidence
conformity
registration
status
review
```

This would make Annex mappings usable by automated validators.

***

# 79. Annex XIV Machine-Readable Extension

Because Annex XIV introduces standardized codes for AI-system categories and conformity-assessment-body designation, AIGO should consider adding:

```text id="x5tt95" theme={null}
annexXIVCode
technologyCategory
aiSystemType
conformityBodyScope
```

to the future machine-readable mapping model.

***

# 80. Annex and Third-Party Governance

Where third parties perform:

* conformity assessment;
* notified-body functions;
* technical testing;
* verification;
* product compliance;

AIGO should maintain third-party governance.

The control should verify:

* authorization;
* scope;
* contract;
* deliverables;
* evidence;
* changes.

***

# 81. Annex and Management Review

Management review should consider:

* material Annex changes;
* new high-risk categories;
* product-law changes;
* registration changes;
* conformity changes;
* notified-body changes;
* documentation gaps;
* regulatory timing.

***

# 82. Annex and Improvement

Annex-related gaps should feed AIGO Improvement.

Examples:

* outdated classification logic;
* stale product-law mappings;
* incomplete documentation;
* registration gaps;
* conformity-body scope gaps;
* new Annex XIV codes requiring system changes.

***

# 83. Annex and Retirement

When AI systems are retired, AIGO should preserve:

* historical Annex classification;
* conformity records;
* technical documentation;
* declarations;
* certificates;
* registration;
* relevant regulatory communications.

The historical Annex version must remain identifiable.

***

# 84. Historical Annex Handling

AIGO should never rewrite a historical record solely to match a later Annex amendment.

Instead:

```text id="08phv0" theme={null}
Historical Record
      ↓
Historical Legal Baseline
      ↓
Current Amendment
      ↓
Impact Assessment
```

This preserves auditability.

***

# 85. Annex Cross-Version Governance

A controlled record may state:

```text id="2f7fs4" theme={null}
Classification Version:
EU AI Act Annex III — version applicable at decision date

Current Regulatory Version:
EU AI Act Annex III — current consolidated position
```

This distinction is particularly important for ongoing systems.

***

# 86. Annex Evidence Pack

A high-risk AI evidence package may contain:

```text id="o1k8zv" theme={null}
Article 6 Determination
Annex I / III Classification
Risk Assessment
Annex IV Technical Documentation
Conformity Assessment
Annex V Declaration
Registration
Annex XIV Notified-Body Scope
Monitoring
Incidents
Changes
Assurance
```

***

# 87. Annex Control Matrix

| Annex | AIGO Primary Control                | Supporting Controls         |
| ----- | ----------------------------------- | --------------------------- |
| I     | Product High-Risk Classification    | Conformity, Risk, Evidence  |
| III   | High-Risk Use-Case Classification   | Rights, Risk, Assessment    |
| IV    | Technical Documentation             | Integrity, Change, Evidence |
| V     | Declaration Governance              | Approval, Evidence          |
| VI    | Internal Conformity Control         | Assessment, Assurance       |
| VII   | QMS / Notified-Body Assessment      | Governance, Evidence        |
| VIII  | Registration Governance             | AI System, Evidence         |
| IX    | Registration Information Governance | AI System, Evidence         |
| XIV   | Notified-Body Scope Verification    | Third-Party, Assessment     |

***

# 88. Annex Traceability Example — Annex I

```text id="aw5mhy" theme={null}
EU AI Act Annex I
       ↓
Article 6(1)
       ↓
AI System
       ↓
Product Relationship
       ↓
High-Risk Classification
       ↓
Conformity Pathway
       ↓
Assessment
       ↓
Evidence
```

***

# 89. Annex Traceability Example — Annex III

```text id="7gdeus" theme={null}
EU AI Act Annex III
       ↓
Article 6(2)
       ↓
Use Case
       ↓
High-Risk Classification
       ↓
Risk
       ↓
Controls
       ↓
Assessment
       ↓
Rights / Evidence
       ↓
Assurance
```

***

# 90. Annex Traceability Example — Annex IV

```text id="enqijw" theme={null}
Article 11
       ↓
Annex IV
       ↓
Technical Documentation
       ↓
AI System Version
       ↓
Evidence
       ↓
Change Management
       ↓
Assurance
```

***

# 91. Annex Traceability Example — Annex XIV

```text id="qfk5pr" theme={null}
Article 30
       ↓
Annex XIV Code
       ↓
AI System Type
       ↓
Conformity Body Scope
       ↓
Notified Body
       ↓
Assessment
       ↓
Certificate
       ↓
Evidence
```

***

# 92. Annex Coverage

A future mapping validator should report:

```text id="2bt0uv" theme={null}
Annex Coverage
------------------------------
Current Annexes Identified
Legal Functions Mapped
AIGO Components Mapped
Critical Annex Gaps
Historical References
Unreviewed Amendments
```

The result should distinguish:

* legal completeness;
* AIGO implementation coverage;
* evidence coverage.

***

# 93. Annex Validation Requirements

The Annex mapping should satisfy:

### Source Validation

Each current Annex is identified from the consolidated legal text.

### Article Link Validation

Each Annex is linked to its governing Article where applicable.

### Classification Validation

Annex I and III are correctly connected to Article 6.

### Documentation Validation

Annex IV is connected to Article 11.

### Conformity Validation

Annexes V–VII are linked to the relevant conformity architecture.

### Registration Validation

Annexes VIII–IX are linked to registration requirements where applicable.

### Scope Validation

Annex XIV codes are linked to the relevant conformity-assessment-body scope.

### Amendment Validation

2026 amendments are reflected.

### Historical Validation

Historical Annex references remain distinguishable from current requirements.

***

# 94. Limitations

This mapping cannot independently determine:

* whether a particular product falls under Annex I;
* whether a particular use case falls within Annex III;
* whether an exception applies;
* whether technical documentation satisfies Annex IV;
* whether a conformity procedure is correctly selected;
* whether a notified body is legally eligible for a specific assessment;
* whether a declaration is legally valid;
* whether registration is required for a specific system.

Those determinations require current legal text, facts, technical evidence, and appropriate regulatory/conformity review.

***

# 95. Current Amendment Baseline

Regulation (EU) 2026/1744 is the principal current amendment incorporated into this mapping version.

It:

* modifies Annex I;
* modifies Annex VIII;
* adds Annex XIV;
* changes the high-risk application timetable;
* modifies conformity-assessment arrangements;
* changes certain supervisory and administrative structures.

The mapping must be reviewed whenever this legal baseline changes.

***

# 96. Current Regulatory Review Baseline

The Commission's May 2026 review of prohibited practices and Annex III demonstrates that the high-risk list is subject to ongoing regulatory review.

AIGO should therefore monitor annual reviews and incorporate material amendments into:

* classification;
* controls;
* assessments;
* evidence;
* conformity;
* monitoring.

***

# 97. Relationship to Other EU AI Act Mappings

| File                                                             | Relationship          |
| ---------------------------------------------------------------- | --------------------- |
| `01-AIGO-EU-AI-Act-Mapping-v0.1.md`                              | Master mapping        |
| `02-AIGO-EU-AI-Act-Prohibited-AI-Practices-Mapping-v0.1.md`      | Article 5             |
| `03-AIGO-EU-AI-Act-High-Risk-AI-Mapping-v0.1.md`                 | Article 6 / high-risk |
| `04-AIGO-EU-AI-Act-Transparency-Mapping-v0.1.md`                 | Article 50            |
| `05-AIGO-EU-AI-Act-GPAI-Mapping-v0.1.md`                         | GPAI                  |
| `06-AIGO-EU-AI-Act-AI-Literacy-Mapping-v0.1.md`                  | Article 4             |
| `07-AIGO-EU-AI-Act-Governance-and-Enforcement-Mapping-v0.1.md`   | Governance            |
| `08-AIGO-EU-AI-Act-Conformity-and-Documentation-Mapping-v0.1.md` | Conformity            |
| `09-AIGO-EU-AI-Act-Rights-and-Remedies-Mapping-v0.1.md`          | Rights                |
| `11-AIGO-EU-AI-Act-Applicability-and-Timeline-v0.1.md`           | Timeline              |
| `12-AIGO-EU-AI-Act-AIGO-Control-Mapping-v0.1.md`                 | Controls              |
| `13-AIGO-EU-AI-Act-Evidence-and-Assurance-Mapping-v0.1.md`       | Evidence / assurance  |

***

# 98. Relationship to AIGO Schemas

| Annex Activity                    | AIGO Schema             |
| --------------------------------- | ----------------------- |
| Product classification            | AI System / Assessment  |
| High-risk use-case classification | Assessment              |
| Technical documentation           | AI System / Evidence    |
| Declaration                       | Evidence                |
| Conformity                        | Assessment / Assurance  |
| Registration                      | Governance / Evidence   |
| Notified-body scope               | Governance / Assessment |
| Risk                              | Risk                    |
| Controls                          | Control                 |
| Monitoring                        | Monitoring              |
| Changes                           | Change                  |
| Incidents                         | Incident                |
| Assurance                         | Assurance               |
| Management review                 | Management Review       |
| Improvement                       | Improvement             |
| Retirement                        | Retirement              |

***

# 99. Relationship to AIGO Tools

The Annex mapping should be supported by:

* Schema Validator;
* Reference Validator;
* Traceability Validator;
* Control Coverage Validator;
* Evidence Coverage Validator;
* Framework Consistency Checker;
* Document Integrity Checker;
* Repository Health Checker.

***

# 100. Document Control

| Field                     | Value                          |
| ------------------------- | ------------------------------ |
| Document                  | AIGO EU AI Act Annexes Mapping |
| Version                   | 0.1                            |
| Status                    | Draft                          |
| Document Identifier       | `AIGO-MAP-EUAI-010`            |
| Document Type             | EU AI Act Mapping              |
| Primary Legal Instrument  | Regulation (EU) 2024/1689      |
| Amendment Baseline        | Regulation (EU) 2026/1744      |
| Owner                     |                                |
| Legal/Compliance Reviewer |                                |
| Conformity Reviewer       |                                |
| Governance Reviewer       |                                |
| Framework Architect       |                                |
| Approved By               |                                |
| Effective Date            |                                |
| Next Review Date          |                                |

***

# 101. Document Status

**Document:** AIGO — EU AI Act Annexes Mapping

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Identifier:** `AIGO-MAP-EUAI-010`

**Document Type:** EU AI Act Mapping

This document maps the EU AI Act Annex architecture to the AIGO AI Governance Operating Framework, including product-related high-risk classification, Annex III use cases, technical documentation, declarations, conformity procedures, registration information, historical Annex management, and the new Annex XIV classification codes for conformity-assessment-body designation scope.

End of Document
