AtherosAI Compliance Kit Türkçe

Self-assessment — AtherosAI Compliance Kit

_Generated by scripts/self_assessment.py against version 1.0.0, regulation version EU-2024/1689:2024-07-12._

We run this product on itself and publish the result, gaps included. A compliance tool whose vendor cannot produce its own assessment is not one anybody should buy.

Nothing here is tuned. The system description below is the one that would go in the technical file, not the one that scores well — and Module 1 is skipped rather than fed a synthetic corpus, because a filled row that means nothing is the theatre this product exists to replace.

---

What we are, under the EU AI Act

Tier: minimal · confidence 0.60 · basis no_indicator_matched

Reasoning

The Kit is a deterministic analysis library. It makes no decision about any natural person, ranks nobody, and grants or denies nothing — so no Annex III use case attaches. It is not a general-purpose AI model, and its optional narrative layer is off by default, so no Art. 50 transparency duty is triggered by the shipped configuration.

What that verdict does NOT mean. These are the limits the tool printed about its own classification:

- This verdict rests on no indicator matching, which is not the same as evidence of low risk. The lexicon is structural and recognises only what it has been taught. A minimal classification should be re-run whenever the use case changes.

Our customers' systems are frequently high-risk. Ours is not, and the distinction is the product: the Kit produces evidence about systems that need it without becoming one.

Our own Annex IV documentation

Completeness: 33% — 6 of 9 sections missing or partial.

Annex IVSectionCoverage
Annex IV(1)General description of the AI systemcovered
Annex IV(2)(a-b)Development process and system architecturecovered
Annex IV(2)(d)Data and data governancemissing
Annex IV(2)(e)Human oversight measuresmissing
Annex IV(2)(g)Accuracy, robustness and metricsmissing
Annex IV(3)Risk-management systemmissing
Annex IV(4)Lifecycle changesmissing
Annex IV(5)Harmonised standards appliedmissing
Annex IV(8-9)Post-market monitoring and loggingcovered

We are a minimal-risk system, so Art. 11 does not oblige us to hold this file at all. We generate it anyway, and publish it incomplete, because the number above is the honest one and because it demonstrates the behaviour the tool is sold on: evidence makes a section partial, never covered. A generator that emitted plausible prose for all nine would produce a document that looks complete and is not.

Our own guardrails

Invocations2
Blocked1
Degraded1
Entity classes maskedEMAIL
Signatures triggeredinstruction_override, verdict_override
Answered byprimary: 1, static: 1

The second self-test prompt is an injection attempt against our own wrapper. It is blocked, no token is spent, and the block is on the chain.

Our own suppliers

The Kit's optional narrative layer can reach these providers. It is off by default — the shipped configuration is none:deterministic, so a default install sends nothing anywhere. These assessments describe what a customer takes on if they switch it on.

ProviderScoreResidencyTraining opt-outUnknown criteria
Google Cloud Vertex AI98.3requires_sccavailable_not_evidenced0
OpenAI83.3requires_sccavailable_not_evidenced1

Note that our own registry flags its own facts as stale past 180 days, and does so here. That is the tool working, not the report failing.

Our own ledger

intact — recomputed every digest.

The gate, run on ourselves

AtherosAI compliance gate — FAILED

CheckValueThresholdDetail
⏭️rag_auditmodule not configured
eu_ai_act_tierminimal['unacceptable']
vendor_score.google_vertex98.360
residency.google_vertexrequires_scc['non_compliant']
vendor_score.openai83.360
residency.openairequires_scc['non_compliant']
guard_blocks101 blocked invocation(s) exceed the configured cap of 0
audit_chainintactintact
1 check(s) did not run. This gate covers less than its check list suggests: rag_audit.

_Produced by the AtherosAI Compliance Kit._

Why guard_blocks is red. The self-test deliberately fires one injection attempt at our own wrapper, and the configured threshold is zero blocks. The gate is reporting exactly what happened. We leave it red rather than raising the threshold to make the report green — a threshold tuned until the gate passes is a threshold that measures nothing.

What this assessment does not establish

---

_Reproduce this: python scripts/self_assessment.py. No network, no API key, under a second. It runs on every CI build and the build fails if the committed copy has gone stale._

· AtherosAI B.V.