Most conformity pages are written by someone with nothing to declare. This one is not: this site runs a retrieval-grounded assistant over my own writing, exposes that same corpus to other people's AI clients over MCP, and publishes a daily edition. All of that is squarely inside the scope of the EU AI Act, and since 2 August 2026 part of it has been binding on me rather than theoretical.

So the page has two halves. First the declaration — what runs here and what I claim about it. Then the explainer — what “conformity” means under this law, because the word does a lot of work and most of it is not what people assume.

What runs here

Four things on this site involve an AI model. None of them decides anything about anyone.

Concierge
The chat assistant and the “ask the vault” box. A retrieval pipeline over my published notes: it classifies the question, rewrites it into a search query, retrieves and reranks passages, answers only from those passages, and runs a grounding check on its own answer before it is shown. The generation model is Anthropic's Claude; embeddings and reranking are either Voyage or a self-hosted encoder. It is instructed to cite every claim, to refuse rather than invent, and to hand off to me when it has no sourced answer.
Corpus boundary
Only public and gated documents are ever embedded into the knowledge base. Private material is excluded at ingestion time, not by asking the model nicely in a prompt. That is the one guarantee here that does not depend on a model behaving.
MCP server
An authenticated endpoint that lets your AI client read the same published material as tools. It serves what is already public on this site; the tools a given caller sees depend on the scopes they were granted.
Daily editions
A publishing pipeline that produces a dated piece with its claims and sources enumerated and a corrections field attached. The claim-and-source structure is the point: every factual assertion is meant to be traceable to something you can open yourself.

Where that puts me

The AI Act sorts systems by what they could do to people, not by how clever they are. Four tiers, and the duties differ by orders of magnitude between them.

UNACCEPTABLEBanned outright — Art. 5HIGH-RISKConformity assessment · CE mark · registration · Annex I & IIILIMITEDTell people it is AI — Art. 50MINIMALNo system-specific dutyTHIS SITE
Fig. 1 — The four tiers, drawn at the width of the population each one actually contains. Banned practices are a short list; high-risk is a defined enumeration in Annexes I and III; almost everything else that talks to a person lands in the limited-risk band, where the entire duty is to be honest that it is a machine. Everything on this site sits in that third band.
The declaration

Nothing on this site is a high-risk AI system, and nothing here performs a prohibited practice. No conformity assessment is owed, no CE mark applies, and there is nothing for me to register.

What does bind me is Article 50 — the transparency obligations — which have applied since 2 August 2026 and which the Digital Omnibus pointedly did not postpone. That is a real duty with a real date, and the ledger below is where I say how I am meeting it, including where I am not yet.

Two roles matter here and they carry different duties. I am the deployer of these systems because I operate them; I am also their provider, because I build them and put them into service under my own name. The underlying general-purpose model is a different question: Anthropic is the provider of Claude, and the Chapter V obligations that attach to a general-purpose model are theirs, not mine. Building on someone else's model does not make me responsible for that model — and it does not relieve me of responsibility for the system I built with it.

Obligation ledger
ObligationApplies fromWhere this site stands
AI literacyArt. 42 Feb 2025Met — a one-person operation, and the person operating it writes about this weekly.
Prohibited practicesArt. 52 Feb 2025Met — no emotion inference, no biometric categorisation, no scraping of faces, no social scoring, no subliminal technique.
Tell people it is an AIArt. 50(1)2 Aug 2026Met — the assistant's turns are labelled AI Assistant in the chat, and the vault answer box says on its face that the answer is generated. Neither is left to context.
Mark synthetic output machine-readablyArt. 50(2)2 Aug 2026Partial— the disclosure is human-readable today. A machine-readable marking on generated answers is outstanding, and I would rather say so here than let this row read “met”.
Disclose AI-generated text on public-interest mattersArt. 50(4)2 Aug 2026Met by review — the editions carry editorial responsibility and per-claim sourcing. The exemption is for human-reviewed publication, which is the basis relied on.
High-risk regime, standaloneAnnex III2 Dec 2027Out of scope — no listed use case. Nothing here touches employment, credit, education, law enforcement or essential services.
High-risk regime, embeddedAnnex I2 Aug 2028Out of scope — no regulated product carries this software.
General-purpose model dutiesChapter V2 Aug 2025Not mine — borne by the model provider. I am downstream of it.

What I am not claiming

A conformity page is only worth reading if it is also willing to be a page of limits. So, plainly:

  • This is not a certification.No notified body has looked at anything here. None is required to. When a vendor waves “AI Act compliant” at you without naming an obligation and a date, that phrase is decoration.
  • I am not claiming the assistant is correct. It is grounded, cited and checked, and it is still a language model. The sources it cites are the thing to trust; the prose around them is a convenience.
  • This is not legal advice — not to you, and not from me. It is a description of my own position, published because I think anyone running AI in public ought to be able to write one.
  • Accessibility is a commitment, not a legal claim here. The interface is built to WCAG 2.2 AA contrast and focus behaviour because that is the right way to build it, not because a statute compels this site.

What conformity actually means

Now the explainer, because the word is used loosely enough to be misleading. Under the AI Act, conformity is not a general virtue and not a certificate. It is a specific procedure that attaches to a specific tier — and for most systems, it never attaches at all.

The duty follows the role, not the software

The same model can put four different people under four different sets of obligations. A provider develops a system and places it on the market under its own name; the heavy obligations sit here. A deployer uses a system under its own authority; its duties are narrower — operate it as instructed, keep a human in the loop where required, inform the people affected. An importer and a distributormostly verify that the provider did its job. The role is a fact about what you do, not a label you pick: put your own name on a system built from someone else's model and you have become its provider.

Conformity assessment, for the systems that need it

For a high-risk system, conformity assessment is the procedure that establishes the thing actually meets the Act's requirements before it is allowed on the market: a risk management system, data governance, technical documentation, logging, human oversight, accuracy and robustness, and a quality management system behind all of it. Most Annex III systems are assessed by the provider itself against harmonised standards — internal control, not an external audit. Only some cases, chiefly biometrics, go to a notified body. It ends in an EU declaration of conformity, a CE mark and registration in an EU database.

That is the machinery the word is pointing at. If a system is not high-risk, none of it applies, and a declaration of conformity for it would be meaningless — which is precisely why this page declares an obligation ledger instead of a CE mark.

Where the transparency tier sits

Between “heavily regulated” and “unregulated” there is a third thing, and it is where nearly every product people actually ship lands. Article 50 asks for one honest sentence in four situations: when a system interacts with a person, it must say it is a machine; when it generates synthetic media, the output must be markable as such; when it does emotion recognition or biometric categorisation, the people exposed must be told; and when AI-generated text is published to inform the public, that must be disclosed unless a human took editorial responsibility for it.

It is a small duty and an unusually enforceable one — which is why the fact that the Digital Omnibus left it exactly where it was, while moving the high-risk dates by more than a year, is the most load-bearing detail in the whole package.

Try it against your own systemWhere does your AI system land?Describe it in a paragraph and watch the same law applied to it — with the trace showing which parts of the answer came from a model and which came out of a table.Read nextThe Digital Omnibus, broken downOne package, two proposals, two completely different fates. What became law on 27 July 2026, what is still stuck behind 1,750 amendments, and which dates actually moved.
Notes
  1. Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force 27 July 2026.
  2. Personal data, lawful bases, processors and your rights are covered separately on the privacy page. Nothing you send the assistant is used to train a model.
  3. If you think a row in the ledger above is wrong, that is worth telling me, and the fastest route is the chat on this site — which will, appropriately, tell you it is an AI before it hands you to me.