| Article | Subject | Status | Criteria |
|---|---|---|---|
| Art. 9 | Risk management system | NOT EVIDENCED | C1, C2, C6 |
| Risk management (Art. 9): scope adherence, tool authorisation, or differential-treatment control failed. Not evidenced. | |||
| Art. 12 | Record-keeping and automatic logging (structural) | EVIDENCED | Attestation chain |
| Art. 13 | Transparency to deployers | EVIDENCED | C4 |
| Art. 14 | Human oversight | EVIDENCED | C3 |
| Art. 15 | Accuracy, robustness, cybersecurity | NOT EVIDENCED | C2, C5 |
| Accuracy and robustness (Art. 15): tool authorisation or data boundary controls failed. Not evidenced. | |||
| Art. 26 | Deployer obligations | NOT EVIDENCED | C1, C2, C3, C4, C5, C6 |
| Deployer obligations (Art. 26): one or more accountability criteria failed. Not evidenced. | |||
| Art. 72 | Post-market monitoring (structural) | NOT EVIDENCED | Attestation chain |
| Post-market monitoring (Art. 72): drift monitoring is not configured for this agent owner. Not evidenced. | |||