Analysis

The EU AI Act as an evidence problem, not a legal one

13 August 2026

Most conversations about the EU AI Act start with the law and get stuck there. That is the wrong end of the telescope. For a delivery organisation, conformity is not primarily a legal problem — it is an evidence problem. Solve the evidence problem well and the legal position largely follows; solve the legal problem on paper and you still cannot prove anything when asked.

What "high-risk" actually demands

Strip the Act to its operational core and a high-risk AI system asks you to be able to show, at any time: what the system is and what it is for; the data and design decisions behind it; a risk assessment kept current; human-oversight arrangements; and records that let someone reconstruct what happened. Every one of those is a record you either have or you do not.

Conformity as a by-product of delivery

The expensive way to comply is to run a separate documentation project after the fact, reconstructing decisions from memory. The economical way is to capture the same information as delivery happens — decisions as they are taken, risk as it is assessed, evidence as it is produced — so that the conformity file assembles itself. This is exactly the machinery a governed delivery organisation already wants for its own sake.

The number worth knowing

The European Commission's own impact assessment put the conformity-assessment cost for a high-risk system in the region of €29k. The bulk of that is documentation and evidence — which is precisely the part you can make nearly free by producing it in the flow of work rather than afterwards.

Evidence label: our analysis, with the €29k figure sourced from the EC impact assessment. We are architects, not lawyers — this is how to make compliance provable, not legal advice.