Self-assessment — AtherosAI Compliance Kit
_Generated by scripts/self_assessment.py against version 1.0.0, regulation version EU-2024/1689:2024-07-12._
We run this product on itself and publish the result, gaps included. A compliance tool whose vendor cannot produce its own assessment is not one anybody should buy.
Nothing here is tuned. The system description below is the one that would go in the technical file, not the one that scores well — and Module 1 is skipped rather than fed a synthetic corpus, because a filled row that means nothing is the theatre this product exists to replace.
---
What we are, under the EU AI Act
Tier: minimal · confidence 0.60 · basis no_indicator_matched
Reasoning
- no prohibited practice, Annex I product, Annex III use case, or Art. 50 transparency trigger was recognised in the description provided
The Kit is a deterministic analysis library. It makes no decision about any natural person, ranks nobody, and grants or denies nothing — so no Annex III use case attaches. It is not a general-purpose AI model, and its optional narrative layer is off by default, so no Art. 50 transparency duty is triggered by the shipped configuration.
What that verdict does NOT mean. These are the limits the tool printed about its own classification:
- This verdict rests on no indicator matching, which is not the same as evidence of low risk. The lexicon is structural and recognises only what it has been taught. A minimal classification should be re-run whenever the use case changes.
Our customers' systems are frequently high-risk. Ours is not, and the distinction is the product: the Kit produces evidence about systems that need it without becoming one.
Our own Annex IV documentation
Completeness: 33% — 6 of 9 sections missing or partial.
| Annex IV | Section | Coverage |
|---|
| Annex IV(1) | General description of the AI system | covered |
| Annex IV(2)(a-b) | Development process and system architecture | covered |
| Annex IV(2)(d) | Data and data governance | missing |
| Annex IV(2)(e) | Human oversight measures | missing |
| Annex IV(2)(g) | Accuracy, robustness and metrics | missing |
| Annex IV(3) | Risk-management system | missing |
| Annex IV(4) | Lifecycle changes | missing |
| Annex IV(5) | Harmonised standards applied | missing |
| Annex IV(8-9) | Post-market monitoring and logging | covered |
We are a minimal-risk system, so Art. 11 does not oblige us to hold this file at all. We generate it anyway, and publish it incomplete, because the number above is the honest one and because it demonstrates the behaviour the tool is sold on: evidence makes a section partial, never covered. A generator that emitted plausible prose for all nine would produce a document that looks complete and is not.
Our own guardrails
| |
|---|
| Invocations | 2 |
| Blocked | 1 |
| Degraded | 1 |
| Entity classes masked | EMAIL |
| Signatures triggered | instruction_override, verdict_override |
| Answered by | primary: 1, static: 1 |
The second self-test prompt is an injection attempt against our own wrapper. It is blocked, no token is spent, and the block is on the chain.
Our own suppliers
The Kit's optional narrative layer can reach these providers. It is off by default — the shipped configuration is none:deterministic, so a default install sends nothing anywhere. These assessments describe what a customer takes on if they switch it on.
| Provider | Score | Residency | Training opt-out | Unknown criteria |
|---|
| Google Cloud Vertex AI | 98.3 | requires_scc | available_not_evidenced | 0 |
| OpenAI | 83.3 | requires_scc | available_not_evidenced | 1 |
Note that our own registry flags its own facts as stale past 180 days, and does so here. That is the tool working, not the report failing.
Our own ledger
intact — recomputed every digest.
The gate, run on ourselves
AtherosAI compliance gate — FAILED
| Check | Value | Threshold | Detail |
|---|
| ⏭️ | rag_audit | — | — | module not configured |
| ✅ | eu_ai_act_tier | minimal | ['unacceptable'] | |
| ✅ | vendor_score.google_vertex | 98.3 | 60 | |
| ✅ | residency.google_vertex | requires_scc | ['non_compliant'] | |
| ✅ | vendor_score.openai | 83.3 | 60 | |
| ✅ | residency.openai | requires_scc | ['non_compliant'] | |
| ❌ | guard_blocks | 1 | 0 | 1 blocked invocation(s) exceed the configured cap of 0 |
| ✅ | audit_chain | intact | intact | |
1 check(s) did not run. This gate covers less than its check list suggests: rag_audit.
_Produced by the AtherosAI Compliance Kit._
Why guard_blocks is red. The self-test deliberately fires one injection attempt at our own wrapper, and the configured threshold is zero blocks. The gate is reporting exactly what happened. We leave it red rather than raising the threshold to make the report green — a threshold tuned until the gate passes is a threshold that measures nothing.
What this assessment does not establish
- Module 1 did not run. The Kit has no RAG corpus, so there was nothing to audit. The gate prints that as a skipped check rather than omitting the row.
- The classification is structural. It rests on a lexicon that recognises what it has been taught, applied to a description we wrote about ourselves.
- An intact chain attests to what was recorded, not to whether the assessments behind the records are correct.
- This is a self-assessment. It is not independent assurance. Independent assurance is a different product with a different signature on it, and conflating the two is the thing we tell customers not to do.
---
_Reproduce this: python scripts/self_assessment.py. No network, no API key, under a second. It runs on every CI build and the build fails if the committed copy has gone stale._
·
AtherosAI B.V.