Skip to content

More than the AI Act applies to your system

Start with the picture the spine levels draw. When a system is high-risk under the EU AI Act, the law pulls a fixed set of obligations into scope — the Articles 9–15 spine: a risk-management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11 + Annex IV), record-keeping (Art. 12), transparency to deployers (Art. 13), human oversight (Art. 14), and accuracy/robustness/cybersecurity (Art. 15). That spine is the same for every high-risk system, regardless of sector. Student selection — high-risk under Annex III §3, education — runs the spine and nothing else stacked on top. That is the clean spine.

An overlay is what happens when the system also falls under a sector-specific regime that the EU layers on top of the AI Act:

  • Health. A diagnostic or screening tool is also a medical device, so the MDR (Reg. EU 2017/745) applies — its General Safety and Performance Requirements (GSPR, Annex I), its clinical-evaluation duty (Annex XIV), its conformity-assessment route (MDR Art. 52).
  • Finance. A credit model operated by a financial entity also carries DORA (Reg. EU 2022/2554) — digital operational resilience, an ICT third-party register, incident reporting.
  • Employment. A hiring or worker-management tool carries the GDPR (Art. 22 on automated decisions) and national labour law on top of the AI Act.

Each overlay brings its own obligations and its own standards. The system now answers to several regimes at once — that is the whole idea of an overlay: one system, N regimes.

flowchart TB
  subgraph SPINE["EU AI Act spine — every high-risk system"]
    direction LR
    A9["Art. 9<br/>risk mgmt"]
    A10["Art. 10<br/>data gov"]
    A11["Art. 11<br/>Annex IV"]
    A13["Art. 13<br/>transparency"]
    A14["Art. 14<br/>oversight"]
    A15["Art. 15<br/>robustness"]
  end
  subgraph OVERLAY["Sector overlay — stacks ON TOP (this system only)"]
    direction LR
    MDR["MDR (health)<br/>GSPR + Art. 52 NB<br/><b>crosswalk + GAP</b>"]
    DORA["DORA (finance)<br/>ICT resilience<br/><b>crosswalk + GAP</b>"]
    NAT["National + GDPR (employment)<br/><b>crosswalk + GAP</b>"]
  end
  BUNDLE["ONE signed evidence bundle"]
  BUNDLE --> SPINE
  BUNDLE --> OVERLAY
  SPINE -->|"projection → real verdicts<br/>(ISO 23894 · prEN 18228)"| GOV["Governed catalogs<br/>Covered / Attested / Partial / Gap"]
  OVERLAY -->|"projection → signed crosswalk,<br/>NOT a verdict"| DOC["Documentation + honest GAP"]

Read it top to bottom. The spine sits under every high-risk system. The overlay box stacks on top of it for this system only — a student-selection model has an empty overlay box; a retina screener has the MDR box; a bank’s credit model has the DORA box. And there is exactly one signed evidence bundle feeding both: the engine projects it onto the spine’s governed catalogs (real verdicts) and onto the overlay’s catalog (a signed crosswalk, not a verdict). The split on the right is the lesson — keep reading.

One bundle, many catalogs — projection, not paperwork

Section titled “One bundle, many catalogs — projection, not paperwork”

The first thing an overlay does not do is double your work. You do not assemble one dossier for the AI Act, a second for the MDR, a third for DORA. There is one signed evidence bundle — the manifest, the measured controls, the residual, the management state — and the engine projects it onto each regime’s clause catalog. You meet this projection on the clean spine in Level 2: a single bundle reported against ISO 23894 and prEN 18228 with real per-clause verdicts, no re-annotation. An overlay is the same projection, pointed at one more catalog: declare eu/mdr@2017 in the manifest, and the engine maps the same risks and measures onto the MDR’s GSPR clauses too.

So an overlay is cheap in effort and expensive in honesty. Cheap, because the evidence is reused. Expensive, because you now have to be very clear about what kind of output each catalog produces — and that is where the two categories come in.

Two kinds of catalog: governed vs crosswalk + GAP

Section titled “Two kinds of catalog: governed vs crosswalk + GAP”

Not every regime the engine can project onto is a regime the engine can vouch for. There are two categories, and conflating them is the over-claim this whole course exists to prevent.

  • Governed standards — real verdicts. ISO 23894 (the international AI-risk process guide) and prEN 18228 (the EU’s harmonised draft operationalising Article 9) are catalogs the engine drives end-to-end. For each clause it emits a genuine verdict — Covered, Attested, Partial, or Gap — derived from the signed evidence. These are the AI Act spine’s own standards. (Even here honesty bites: prEN 18228 is a draft, so its presumption flag reads false until it is cited in the Official Journal — see standards & presumption.)

  • Crosswalk + GAP regimes — documentation, not a verdict. MDR and DORA are binding sectoral law, but they are not harmonised AI-risk-management standards the engine is built to adjudicate. For these the engine produces a signed crosswalk: it maps your risks and measured controls onto the regime’s clauses (the MDR’s GSPR, DORA’s register fields) and signs that mapping. That crosswalk is real, useful documentation — but it is not a conformity verdict. Where the regime requires something the engine cannot supply — an external notified body for an MDR Class IIa device, a clinical evaluation, an ICT-resilience test — the crosswalk shows an honest GAP, not a fabricated “covered”.

The honest boundary: an overlay does not certify the sector

Section titled “The honest boundary: an overlay does not certify the sector”

Here is the sentence to leave with. Declaring an overlay does three honest things: it pulls the sector’s obligations into scope, it adds the sector’s clause catalog to the projection, and it surfaces — as signed GAPs — exactly what the engine cannot supply. It does not do a fourth thing: it does not turn the engine into a body that can certify that you meet the sectoral regime. The AI Act spine, the engine drives with real verdicts. The sectoral overlay, the engine documents — and where the regime demands an external actor (a notified body) or an out-of-engine artifact (a clinical evaluation, an ICT pen-test), the overlay teaches that as a GAP, not as a capability.

That honest split is the reason overlays are a teaching device, not a marketing one. You meet your first overlay — health/MDR — in Level 3, where a retina screener is simultaneously AI Act high-risk and an MDR Class IIa device, and the notified-body GAP is the whole lesson.

What is an overlay, and how is it different from the 'clean spine'?

An overlay is a sectoral regime stacked on top of the EU AI Act spine — so one high-risk system is subject to several regimes at once (the AI Act plus, say, the MDR for a medical device, or DORA for a bank’s credit model). The clean spine is the opposite: a high-risk system with no sector regime layered above it — just Articles 9–15 and their AI-risk standards (ISO 23894, prEN 18228). Student selection is a clean spine; retina screening (AI Act + MDR) is an overlay. An overlay is triggered either through Annex III (a high-risk use) or through Annex I + Art. 6(1) (the system is a safety component of an already-regulated product, e.g. a medical device).

An overlay system carries several regimes. Does that mean it keeps several separate dossiers, and does declaring an overlay let the engine certify that sectoral regime?

No to both. There is one signed evidence bundle, and the engine projects it onto each regime’s clause catalog — no second pile of paperwork. And declaring an overlay does not let the engine certify the sector. The catalogs split in two: governed standards (ISO 23894, prEN 18228) get real per-clause verdicts; crosswalk + GAP regimes (MDR, DORA) get signed documentation mapping evidence onto their clauses, not a conformity verdict — with an honest GAP wherever the regime needs something the engine can’t supply (a notified body, a clinical evaluation, an ICT-resilience test). An overlay adds obligations and a catalog; it never turns the engine into a certifier of the sector.

The engine emits a signed MDR crosswalk for a medical-device system. Is that system therefore 'MDR-governed'?

No. The MDR crosswalk is signed documentation — the engine mapping your risks and measured controls onto the MDR’s GSPR clauses — but it is not a conformity verdict. The MDR is binding law, not a harmonised AI-risk-management standard the engine adjudicates, so it confers no presumption through the engine and is never printed as “covered/conformant”. Calling the system “MDR-governed” because it carries a crosswalk is the over-claim to avoid: the crosswalk is evidence and documentation; the verdict belongs to the regime’s own conformity route — for an MDR Class IIa device, an external notified body.