Audit Finds Nearly All Public AI Repos Fail EU AI Act Compliance Rules
A scan of public AI repositories against EU AI Act requirements found that almost every project failed at least one legal obligation, despite generally sound code quality. The Act's high-risk provisions, covering systems used in hiring, credit scoring, biometric categorization, and insurance, are already in force, with a key deadline of August 2, 2026 now passed. Most engineering teams are unaware whether their systems fall under Annex III scope, and fewer still have the required technical documentation package, which can take three to six months to produce. The most common failures involved Articles 9, 12, and 14, relating to risk management, record-keeping, and human oversight, largely because developers were never informed these coding practices had become legal requirements. Existing GRC platforms like OneTrust or Vanta do not capture application-level AI logic, meaning many organizations believe they are compliant when critical evidence gaps remain.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in