Regulation (EU) 2024/1689 — EU AI Act · Voluntary Internal Documentation
AI Systems Governance Dossier
EU AI Act Alignment Record · Agent Control Plane (ACP) — Verified Digital Agents
DOCUMENT STATUS — DEMO DATA · NOT FOR REGULATORY RELIANCE
Scope. Of 4 AI systems: 1 High Risk (Annex III §§1–8 triggered); 3 with high-risk indicators requiring Compliance Officer determination. Risk classes are pinned deterministically by the platform rules table (reproducible). High-risk systems engage the Art. 9–15 obligations as MANDATORY (not voluntary) and may require Art. 49 registration; "indeterminate" systems must not be relied upon until a Compliance Officer + legal determination resolves the classification.
Generated by the ACP Governance Module · DEMO DATA — synthetic illustrative data; Compliance Officer attestation required before any external use.
Regulatory Timeline Context
| Provision | Status / application date | Bearing on this dossier |
|---|
| Art. 5 — Prohibited practices | In force since 2 Feb 2025 | Mandatory now · assessed per agent |
| Art. 4 — AI literacy | In force since 2 Feb 2025 | Mandatory now |
| Art. 51–55 — GPAI provider obligations | Applied since 2 Aug 2025 | Borne by Google DeepMind (Gemini provider), not the deployer |
| Art. 50 — Transparency to natural persons | Applies from 2 Aug 2026 | ACP implements ahead of the deadline (per-agent consumer-facing assessment) |
| Art. 9–17 — High-risk obligations (Annex III) | Deferred to 2 Dec 2027 (Digital Omnibus) | Not applicable to Limited-Risk systems · adopted here voluntarily |
Section 2 — Per-System Governance Records
Platform controls are uniform (the ACP platform enforces them identically). Assessment fields are specific to each agent's real function — assessed, not stamped.
01
Account Opening Agent
account-opening-agent · Onboarding · Origination · 3 governance files
● HIGH-RISK INDICATORS · CO DETERMINATION
Purpose Art. 50 / vol. Art. 13
This agent processes new customer account applications by performing mandatory identity verification, screening against sanctions and Politically Exposed Persons (PEP) lists, and computing an applicant risk score. It is authorised to auto-approve standard applications with low risk and no sanctions hits, while preventing account opening for high-risk or sanctioned individuals.
Risk classification Art. 6 + Annex III
Indeterminate — Annex III §5(b) candidate vs fraud-detection exclusion. Performs financial due-diligence / risk screening that sits between Annex III §5(b) creditworthiness (high-risk) and the §5(b) exclusion for fraud detection (out of scope). High-risk indicators present — Compliance Officer and legal determination required.
Personal data & lawful basis GDPR · Art. 10 N/A
The agent processes extensive personal data, including applicant details (name, address, financial information), identity verification data, PEP status, and sanctions hits. The primary lawful basis for processing is GDPR Art. 6(1)(c) 'legal obligation', as financial institutions are legally required to conduct 'Know Your Customer' (KYC), Anti-Money Laundering (AML), and Counter-Terrorist Financing (CTF) checks. Additionally, Art. 6(1)(b) 'contract' applies as processing is necessary for entering into an account agreement. Given the handling of 'sanctionsHits', the agent likely processes 'criminal convictions and offences' data, falling under GDPR Art. 10.
Annex III assessment Art. 6 + Annex III §§1–8
The determined risk class is 'Indeterminate' due to the agent's dual functionality. It performs due-diligence and risk screening, including a 'riskScore' which could be seen as 'evaluating the creditworthiness of natural persons' under Annex III §5(b), indicating high-risk. However, its explicit functions of screening against sanctions and PEP lists are directly related to the 'detecting financial fraud' exclusion within the same §5(b), which would render it out of scope. The 'Indeterminate' classification therefore reflects the competing interpretations and necessitates further legal and compliance review to definitively classify its high-risk status.
Art. 5 prohibited practices
Article 5(1)(a) and (b) are deemed inapplicable as the agent's function is rule-based and does not involve deploying subliminal techniques or exploiting vulnerabilities to distort behaviour. Articles 5(1)(c) through (f) are also inapplicable; the system does not perform social scoring, remote biometric identification, emotion recognition, or cognitive behavioural manipulation as defined.
Art. 50 transparency
This agent is consumer-facing because it directly processes applications from natural persons and makes decisions that significantly affect them, specifically regarding their ability to open an account. Consequently, relevant transparency obligations under Article 50 concerning the use of AI systems, such as informing individuals about the AI system's involvement and human oversight mechanisms, would apply.
Cross-regime obligations CRD · GDPR Art. 22
GDPR Art. 22 requirements apply, as this agent engages in automated individual decision-making, including profiling, based on computed 'riskScore' and screening results, which can lead to auto-approval or rejection of account applications without human intervention.
Control → Article → Clause → Witness conformance backbone
AC-2 → Art. 14 (human oversight), Art. 12 (record-keeping) → "MAY auto-approve standard account applications where the risk score is 40 or below and there are zero sanctions hits." → PASS · Witness #89
Platform controls Art. 12 / 14 / 15 — uniform
Logging: every decision sealed by the Witness Agent (Ed25519-signed record over a SHA-256 hash chain). Oversight: HITL gates in EXCEPTION overlays enforced by the Compliance Guard (ACP §2.1). Robustness: governed evaluation against versioned AGENTS/SOP/SKILL files; ESCALATE on any out-of-authority or unfetchable-governance condition (fail-open).
02
KYC Verification Agent
kyc-agent · KYC · Compliance · 4 governance files
● HIGH-RISK INDICATORS · CO DETERMINATION
Purpose Art. 50 / vol. Art. 13
The agent performs automated know-your-customer (KYC) due diligence on applicants for financial services. Its core function is to assess an applicant's risk profile based on various data points, determining whether standard or enhanced due diligence is required to comply with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) regulations.
Risk classification Art. 6 + Annex III
Indeterminate — Annex III §5(b) candidate vs fraud-detection exclusion. Performs financial due-diligence / risk screening that sits between Annex III §5(b) creditworthiness (high-risk) and the §5(b) exclusion for fraud detection (out of scope). High-risk indicators present — Compliance Officer and legal determination required.
Personal data & lawful basis GDPR · Art. 10 N/A
This agent processes personal data including risk assessments derived from financial behaviour (cleanTransactionHistory), relationship history (relationshipMonths, existingCustomer), and publicly available information (adverseMedia). Given its nature, it likely processes sensitive personal data related to criminal convictions (GDPR Art. 10) through adverse media checks. The lawful basis for processing this data is GDPR Art. 6(1)(c) 'legal obligation,' as KYC and AML compliance are statutory requirements for financial institutions.
Annex III assessment Art. 6 + Annex III §§1–8
The determined risk class is 'Indeterminate (Annex III §5(b) candidate vs fraud-detection exclusion)'. This agent falls under Annex III §5(b) as it evaluates the financial risk of natural persons applying for financial services. However, its function in detecting and preventing financial crime (AML/CTF) could be construed as 'fraud detection purposes in relation to the provision of financial services,' which is explicitly excluded from §5(b). The 'Indeterminate' status reflects this ambiguity, where the system's role in assessing individual financial standing for compliance presents high-risk indicators, while its crime prevention aspect points towards an exclusion.
Art. 5 prohibited practices
All prohibited practices under Art. 5 are deemed inapplicable. The agent does not employ subliminal techniques or exploit vulnerabilities (5(1)(a)-(b)), nor does it engage in social scoring (5(1)(c)). It does not perform real-time biometric identification in public spaces (5(1)(d)) or infer emotions (5(1)(e)). While it categorises individuals for risk, it does not do so based on biometric data or protected characteristics for targeted harm as per 5(1)(f).
Art. 50 transparency
This agent is a back-office system performing automated risk assessment for compliance, and does not directly interact with natural persons. Therefore, it is not consumer-facing in the sense requiring direct, real-time transparency disclosures under Art. 50. Transparency obligations would be met through the financial institution's broader privacy policies and disclosures as required by GDPR and the AI Act for high-risk systems if applicable.
Cross-regime obligations CRD · GDPR Art. 22
This agent profiles individuals by assessing their risk and categorising them for due diligence levels, impacting their access to financial services. Therefore, GDPR Art. 22 on automated individual decision-making, including profiling, is applicable, requiring adherence to related rights and safeguards.
Control → Article → Clause → Witness conformance backbone
IA-5 → Art. 14 (human oversight), Art. 15 (accuracy & robustness) → "MAY proceed on standard verification without triggering enhanced due diligence." → PASS (exception) · Witness #90
Platform controls Art. 12 / 14 / 15 — uniform
Logging: every decision sealed by the Witness Agent (Ed25519-signed record over a SHA-256 hash chain). Oversight: HITL gates in EXCEPTION overlays enforced by the Compliance Guard (ACP §2.1). Robustness: governed evaluation against versioned AGENTS/SOP/SKILL files; ESCALATE on any out-of-authority or unfetchable-governance condition (fail-open).
03
Account Servicing Agent
servicing-agent · Servicing · Operations · 3 governance files
● HIGH RISK
Purpose Art. 50 / vol. Art. 13
This agent processes customer-initiated requests for in-life account changes, specifically focusing on credit limit adjustments. It autonomously actions limit changes below a €10,000 threshold for verified customers, while escalating larger requests to human reviewers. Its core function involves assessing the feasibility and risk associated with altering an individual's credit limit.
Risk classification Art. 6 + Annex III
High — Annex III §5(b) (creditworthiness / credit scoring). Evaluates creditworthiness or sets credit limits for natural persons — Annex III §5(b) high-risk. The §5(b) fraud-detection exclusion does not cover genuine credit decisions.
Personal data & lawful basis GDPR · Art. 10 N/A
This agent handles personal data such as 'request' details (e.g., type, amount), 'currentLimitEur', 'customerVerified' status, and 'requestedLimitEur'. The lawful basis for processing this data is GDPR Article 6(1)(b), as it is necessary for the performance of a contract to which the data subject is party (e.g., a credit agreement) or to take steps at the data subject's request prior to entering a contract. No special-category (Art. 9) or criminal-conviction (Art. 10) data is implied.
Annex III assessment Art. 6 + Annex III §§1–8
The system is classified as High-Risk under Annex III §5(b) because its function involves evaluating creditworthiness and setting or modifying credit limits for natural persons. By processing and making decisions (even if conditional or subject to human override) on 'requestedLimitEur' and 'currentLimitEur', it directly assesses the financial risk and capacity of the individual in relation to their financial services.
Art. 5 prohibited practices
The prohibited practices under Article 5(1)(a) and (b) (subliminal techniques, exploitation of vulnerabilities) are inapplicable, as this agent is an internal operational system not designed to manipulate user behaviour. Article 5(1)(c) (social scoring) is also inapplicable, as the system performs credit scoring for a private financial institution, not public authority social scoring. Articles 5(1)(d), (e), and (f) (biometrics, emotion recognition, predictive policing) are clearly not relevant to this agent's functionality.
Art. 50 transparency
This agent is consumer-facing. Although it performs back-office processing, it directly responds to and acts upon customer-initiated requests concerning their personal financial services. Consequently, the deployer must ensure transparency by informing the natural persons concerned that they are subject to the use of this high-risk AI system, in accordance with Article 50 of the AI Act.
Cross-regime obligations CRD · GDPR Art. 22
This agent's evaluation and decision-making regarding credit limits based on an individual's financial data constitutes 'profiling' under GDPR Article 4(4). This triggers obligations under GDPR Article 22, concerning automated individual decision-making, including profiling, which grants individuals rights such as the right to obtain human intervention and contest the decision.
Control → Article → Clause → Witness conformance backbone
AU-2 → Art. 12 (record-keeping / logging) → "MUST escalate any credit-limit increase or transaction above €10,000 to a human reviewer." → ESCALATE · Witness #91
Platform controls Art. 12 / 14 / 15 — uniform
Logging: every decision sealed by the Witness Agent (Ed25519-signed record over a SHA-256 hash chain). Oversight: HITL gates in EXCEPTION overlays enforced by the Compliance Guard (ACP §2.1). Robustness: governed evaluation against versioned AGENTS/SOP/SKILL files; ESCALATE on any out-of-authority or unfetchable-governance condition (fail-open).
04
Account Review Agent
account-review-agent · Review · Assurance · 3 governance files
● HIGH-RISK INDICATORS · CO DETERMINATION
Purpose Art. 50 / vol. Art. 13
The agent runs periodic account reviews and renewals for financial services clients. Its primary function is to check for adverse media and changes in risk scores, enabling auto-completion of reviews for stable accounts or escalation of adverse changes to a compliance officer.
Risk classification Art. 6 + Annex III
Indeterminate — Annex III §5 candidate. Produces a risk assessment affecting access to an essential service. High-risk indicators present — Compliance Officer determination required.
Personal data & lawful basis GDPR · Art. 10 N/A
This agent processes personal data including adverse media findings and changes in risk scores, which may derive from financial history and public records. The lawful basis for processing is GDPR Article 6(1)(c), 'processing is necessary for compliance with a legal obligation to which the controller is subject,' as financial institutions are legally mandated to conduct such due diligence and AML/CTF checks. Processing of adverse media may involve GDPR Article 10 data concerning criminal convictions or offences.
Annex III assessment Art. 6 + Annex III §§1–8
The risk class is 'Indeterminate' because this agent's function aligns with Annex III, §5, concerning AI systems used for risk assessment of natural persons for managing essential private services. Specifically, it performs risk assessments (linking to §5(b) for creditworthiness or similar financial assessments). However, its role in detecting adverse changes also closely resembles financial fraud detection, which is explicitly excluded from the scope of §5(b), leading to the indeterminate classification.
Art. 5 prohibited practices
This agent operates internally, reviewing accounts without direct interaction with natural persons. It does not engage in subliminal manipulation, exploit vulnerabilities, or create 'social scores.' It also does not process biometric data or perform real-time remote biometric identification. Therefore, the prohibitions outlined in Article 5(1)(a), (b), (c), (d), (e), and (f) are inapplicable.
Art. 50 transparency
This agent is a back-office system, performing internal operational tasks. It does not directly interact with natural persons (consumers). Consequently, the transparency obligations under Article 50, which relate to systems intended to interact directly with natural persons, do not directly apply to this agent.
Cross-regime obligations CRD · GDPR Art. 22
This agent profiles individuals by assessing 'riskScoreChange' and 'adverseMediaChange' to make automated decisions regarding account reviews and escalations. This constitutes automated individual decision-making and profiling under GDPR Article 22, necessitating compliance with its requirements concerning transparency, right to human intervention, and challenge.
Control → Article → Clause → Witness conformance backbone
RA-5 → Art. 9 (risk management), Art. 15 (robustness) → "MAY auto-complete periodic reviews where no adverse change is detected." → PASS · Witness #92
Platform controls Art. 12 / 14 / 15 — uniform
Logging: every decision sealed by the Witness Agent (Ed25519-signed record over a SHA-256 hash chain). Oversight: HITL gates in EXCEPTION overlays enforced by the Compliance Guard (ACP §2.1). Robustness: governed evaluation against versioned AGENTS/SOP/SKILL files; ESCALATE on any out-of-authority or unfetchable-governance condition (fail-open).
Section 3 — Voluntary Art. 9–17 Alignment
| Governance element | ACP implementation | CO attestation |
|---|
| Risk management lifecycle (vol. Art. 9) | Adversarial governed evaluation at admission → EXCEPTION authority bounds → Compliance Guard at every invocation → Witness drift surfacing. | Yes — risk register & treatment |
| Inference-data governance (Art. 10 N/A) | No deployer fine-tuning. Gemini Flash via Vertex API; Google DeepMind holds Art. 53. Per-agent RAG inputs (AGENTS/SOP/SKILL) documented per system. | Yes — inference schema per agent |
| Technical documentation (vol. Art. 11 / Annex IV) | Governance files versioned in the ACP File Manager with NIST/framework mapping; live governance + immutable audit trail. | Yes — file release before the agent runs |
| Record-keeping & audit integrity (vol. Art. 12) | Witness entry per decision over a hash chain; clause applied, files consulted, and data snapshot recorded. | Automated — CO alerted on integrity failure |
| Transparency to natural persons (MANDATORY, Art. 50 — from 2 Aug 2026) | Consumer-facing status assessed per agent; consumer-facing agents carry a disclosure, others CO-attested exempt. | Yes — disclosure text & deployment |
| Human oversight (vol. Art. 14) | HITL gates enforced by the Compliance Guard (ACP §2.1); per-agent thresholds in EXCEPTION overlays; ESCALATE routes to a human reviewer. | Yes — HITL thresholds per agent |
| Accuracy & robustness (vol. Art. 15) | Governed evaluation with fail-open ESCALATE; out-of-band requests escalate rather than proceed. | Yes — periodic accuracy review |
| GPAI downstream cooperation (Art. 53(1)(d)) | Google DeepMind holds Art. 53 for Gemini Flash; deployer documents inference schemas and cooperates with upstream requests. | Yes — annual model usage-policy confirmation |
Section 4 — Regulatory Obligations Checklist
A — Mandatory (all systems)
✓Art. 5 — Prohibited practices: assessed per agent; no prohibited practice engaged.
✓Art. 50(1) — Transparency to natural persons: consumer-facing agents carry a disclosure; non-consumer-facing CO-attested exempt (from 2 Aug 2026).
✓Art. 4 — AI literacy: in force since 2 Feb 2025; staff training recorded.
✓GDPR Art. 22 — Automated decisions: consequential decisions carry HITL gates; individuals may request human review.
✓Art. 6 + Annex III — Risk classification: all systems assessed §§1–8; no category triggered (per-agent reasoning).
✓CRD Art. 6(1)(ea) — Personalised-price disclosure: engaged where an agent personalises pricing.
B — Voluntarily adopted
○Art. 9 risk management · Art. 11 technical documentation · Art. 12 logging · Art. 13 transparency to deployers · Art. 14 human oversight · Art. 15 accuracy & robustness · Art. 72/73 post-market & incident · Art. 53(1)(d) GPAI cooperation — adopted voluntarily (mirrored high-risk obligations deferred to 2 Dec 2027).
C — Not applicable
—Art. 10 training-data management — no deployer fine-tuning; Google DeepMind holds Art. 53.
—Art. 47/48 Declaration of Conformity / CE marking — Limited-Risk systems undergo no conformity assessment.
—Art. 49 EU public-database registration — required for high-risk / Annex-III-derogation systems; neither applies.
—Art. 51–55 GPAI provider obligations — borne by Google DeepMind for Gemini Flash.
Compliance Officer — signature & date
Technical Responsible — signature & date
Legal Counsel review — signature & date
DISCLAIMER. This Evidence Pack is auto-generated by the Agent Control Plane (ACP) Governance Module from in-process journey governance state and the Witness decision trail. It is a voluntary internal governance/audit-preparation document, NOT an Art. 49 EU AI Act registration submission. Risk classifications under Art. 6 and Annex III are the provider's good-faith assessment and must be confirmed with qualified legal counsel before any external use, in light of evolving EU AI Act implementing acts, the Digital Omnibus on AI, and national-authority guidance. Compliance Officer attestation is required before this document is treated as a regulatory artefact. In DEMO DATA state the deployer and agent records are synthetic and illustrative and must not be relied upon.