Progressio.AI

Evidence for High-Risk AI systems

Autonomously assess documentation and surface the evidence needed to prove EU AI Act conformance.

eu-ai-act_audit-summary.pdf
Audit summary

EU AI Act · Atria Cardiac Risk Stratifier

Progressio.AI
Articles
9
Coverage rate
72.4%
Gap rate
27.6%
Provisions
76
Evidenced
55
Evidence gap
21
Coverage overview
Coverage rate:72.4% evidenced·27.6% evidence gap
Strongest coverage
Art 9 · 8 of 8 provisions
Most gaps
Art 14 · 5 of 7 provisions
EU AI Act · Audit SummaryProgressio.AI

Recognised by

  • Governance Award
    OpenUK Awards 2025
  • UK AI100
    UK AI100 List 2025
  • Highly Commended
    Innovate UK Women in Innovation 2026

Everything you need to prove EU AI Act conformance

Automated, evidence-based conformity assessments across the High-Risk AI system lifecycle.

01

Know every High-Risk AI system

Maintain a searchable inventory of High-Risk AI systems with ownership, metadata, and provenance across the organisation.

02

Audit evidence clause by clause

Autonomously analyse documentation, identify relevant evidence, and assess suitability and completeness against each obligation.

03

Remediate and stay ready

Surface gaps, prioritise corrective action, and export evidence packs so readiness is continuous, not point-in-time.

Auditing at scale in minutes, not months

Compress months of evidence discovery for High-Risk AI systems into minutes.

Autonomous auditScanning
EU AI Act · Chapter III
  • Art. 9Risk management
  • Art. 10Data & data governance
  • Art. 11Technical documentation
  • Art. 12Record-keeping
  • Art. 13Transparency to users
  • Art. 14Human oversight
  • Art. 15Accuracy & robustness
  • Art. 17Quality management system
  • Art. 18Documentation retention
Coverage
0.0%evidenced
Evidence0
Gaps0
Provisions76
EU AI Act · Chapter IIIProgressio.AI

Built to prevent false confidence

Conformity assessments fail when fluent language substitutes for evidence. Progressio.AI evaluates every obligation against structured evidence, not a reassuring narrative.

01

Specialized assessment models

Purpose-built text models evaluate evidence against each obligation. General-purpose language models are not used to decide conformance.

02

Deterministic obligation graph

Documentation and the regulatory framework are decomposed into a navigable graph of fully covered, non-overlapping atomic obligations. Assessment runs as a deterministic evaluation against that structure.

03

Tier-1 error minimization

We train the system to minimize errors by priority. Tier 1 is false confidence: treating a requirement as evidenced when evidence is missing or insufficient. Tier 2 covers remaining assessment errors.

Where language models fit. After the assessment is complete, a general-purpose language model articulates remediation guidance in clear, human-readable form. It does not determine evidence states, map obligations, or decide conformance.

From regulatory requirement to evidenced position

Progressio.AI performs automated, evidence-based, clause-by-clause conformity assessments against Articles 9, 10, 11, 12, 13, 14, 15, 17 and 18 of the EU AI Act.

Conformity is evidenced, not assumed

A clause-by-clause conformity assessment evaluates whether each applicable requirement of the EU AI Act can be objectively supported by evidence, not whether a policy, process, or document merely exists.

The real risk is false confidence.
Believing an area is strong when the evidence is incomplete, inconsistent, or missing is often more dangerous than knowing there is a gap.

Every assessment turns evidence into a defensible conformance baseline

Submitted materials are mapped to applicable regulatory obligations, assessed for sufficiency and consistency, and translated into a clear view of strengths, partial coverage, and evidence gaps.

Evidence Mapping

Map submitted evidence to each applicable obligation.

Conformity Assessment

Evaluate each obligation using objective evidence.

Gap Analysis

Identify where evidence is incomplete, inconsistent, or missing.

Prioritized Remediation

Focus corrective action by regulatory significance and effort.

Baseline Conformance Report

Establish a traceable snapshot for future reassessment.

Continuous Reassessment

Measure how the evidenced position changes over time.

Every requirement receives an evidence state

Evidenced

Objective evidence sufficiently supports the applicable requirement.

Partial

Evidence exists but is incomplete, inconsistent, or insufficient.

Evidence Gap

Evidence is missing or does not support the applicable requirement.

The most dangerous gap is the one you believe does not exist.
Auditors and regulators focus on whether claims can be substantiated, not how confident the organization feels about them.

What each area really requires

Expand any Article to see the specific assessment focus, evidence typically involved, and findings that often reveal hidden exposure.

Assessment focus

Establishes whether a documented, continuous risk management system exists throughout the lifecycle of the High-Risk AI System.

Typical evidence

  • Risk Management Policy
  • Risk Register
  • Hazard Analysis
  • Validation & verification records
  • Monitoring procedures
  • CAPA records

Common findings

  • Risks identified but not systematically evaluated
  • Residual risks not documented
  • Mitigation effectiveness cannot be evidenced
  • Monitoring disconnected from risk management

Assessment focus

Evaluates whether data governance processes support the quality and suitability of data used throughout the AI lifecycle.

Typical evidence

  • Data Governance Policy
  • Dataset documentation
  • Data quality assessments
  • Bias assessments
  • Data lineage records
  • Validation procedures

Common findings

  • Incomplete data governance controls
  • Missing evidence of bias assessment
  • Data provenance cannot be evidenced
  • Dataset changes insufficiently documented

Assessment focus

Evaluates whether technical documentation sufficiently explains how the AI system was designed, developed, validated, and maintained.

Typical evidence

  • Technical documentation
  • System architecture
  • Development records
  • Validation documentation
  • Configuration records
  • Version history

Common findings

  • Documentation incomplete or outdated
  • Technical decisions lack supporting evidence
  • Traceability between development and documentation missing
  • Documentation inconsistent across versions

Assessment focus

Assesses whether appropriate logging and record keeping enable traceability throughout the AI system lifecycle.

Typical evidence

  • Logging procedures
  • Audit logs
  • Event records
  • Operational logs
  • Change history
  • Retention procedures

Common findings

  • Logging insufficient for traceability
  • Critical events not retained
  • Retention rules inconsistently applied
  • Audit trail incomplete

Assessment focus

Evaluates whether users receive the information necessary to understand intended use, limitations, assumptions, and operating conditions.

Typical evidence

  • User documentation
  • Instructions for use
  • Operational guidance
  • User warnings
  • Limitations documentation
  • Deployment documentation

Common findings

  • User instructions incomplete
  • System limitations insufficiently communicated
  • Operational assumptions undocumented
  • Human responsibilities unclear

Assessment focus

Assesses whether appropriate human oversight mechanisms enable effective intervention throughout operation of the AI system.

Typical evidence

  • Human oversight procedures
  • Operational roles
  • Escalation procedures
  • Training records
  • Override procedures
  • Operational guidance

Common findings

  • Oversight responsibilities unclear
  • Human intervention mechanisms not evidenced
  • Escalation procedures incomplete
  • Operator training insufficiently evidenced

Assessment focus

Evaluates whether the AI system achieves appropriate levels of accuracy, robustness, and cybersecurity throughout its intended lifecycle.

Typical evidence

  • Test results
  • Validation reports
  • Robustness testing
  • Performance monitoring
  • Cybersecurity assessments
  • Vulnerability management

Common findings

  • Performance claims unsupported
  • Robustness testing incomplete
  • Security controls insufficiently evidenced
  • Ongoing performance monitoring absent

Assessment focus

Assesses whether an appropriate quality management system governs the development, deployment, and maintenance of the AI system.

Typical evidence

  • Quality management procedures
  • Process documentation
  • Internal audit records
  • CAPA documentation
  • Management reviews
  • Process metrics

Common findings

  • Quality processes inconsistently implemented
  • Internal audits incomplete
  • Corrective actions not tracked
  • Quality objectives insufficiently evidenced

Assessment focus

Evaluates whether required documentation and evidence are retained appropriately and remain available for regulatory review.

Typical evidence

  • Document retention policy
  • Retention records
  • Archive procedures
  • Access controls
  • Evidence repository
  • Retention logs

Common findings

  • Required documentation unavailable
  • Retention periods inconsistently applied
  • Archived evidence incomplete
  • Evidence cannot be readily retrieved

Stakeholder value across the organisation

C-Suite

C-Suite

A clear view of AI risk posture, backed by the evidence needed for legal requirements, reputation, and confident decisions.

Technology and Data

Technology and Data

Ship faster without the disruption of questionnaires and ad hoc evidence requests, through audits integrated into the AI lifecycle.

Legal and Compliance

Legal and Compliance

Meet EU AI Act evidentiary requirements with greater speed and consistency, while tracking gaps, progress, and trends.

The EU AI Act is already in force

Penalties of up to €35 million or 7% of global annual turnover, with enforcement powers live since August 2026. The Digital Omnibus moved the High-Risk deadline to 2 December 2027. The evidence runway is shorter than it looks.

  1. Feb 2025

    Prohibited AI practices ban in effect

  2. Aug 2025

    General-purpose AI (GPAI) obligations apply

  3. Aug 2026

    Transparency obligations and AI Office enforcement powers in force

  4. Dec 2027Upcoming

    High-Risk AI system obligations apply (Annex III)

  5. Aug 2028Upcoming

    High-Risk AI in regulated products (Annex I)

Timeline reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus), in force since 27 July 2026. Last reviewed August 2026.

Built in the EU. Your data stays in the EU.

All customer data is processed and stored exclusively within the European Union. It never leaves EU jurisdiction and is never used to train our models.

Privacy by design

Built with privacy across every layer of the platform.

End-to-end encryption

AES-256 at rest and TLS 1.3 in transit.

Immutable audit trail

Every action logged with tamper-proof timestamps.

Become a design partner

We are onboarding a limited number of design partners across banking, insurance, and medtech. Early partners assess their own High-Risk AI portfolios on the platform and work directly with the founding team to shape the roadmap.

Book a demo

Frequently asked questions

No. Customer data is never used to train our models. It is used solely to run your assessment: identifying, mapping, and evaluating the evidence needed to prove conformance with the EU AI Act for your High-Risk AI systems.

The platform is built for High-Risk AI systems under the EU AI Act. It performs evidence-based, clause-by-clause conformity assessments against Articles 9, 10, 11, 12, 13, 14, 15, 17 and 18. Each obligation is evaluated on whether objective evidence sufficiently supports it, not on whether a policy or document merely exists.

Manual High-Risk conformity work often takes months. Progressio.AI compresses initial assessments to minutes or hours once relevant evidence is available. Final timing depends on scope, the number of systems, and how readily documentation and operational records can be accessed.

The platform maps your documentation to atomic EU AI Act obligations, assesses whether the evidence is sufficient and consistent, and returns a clear evidenced position for each requirement. Gaps and partial coverage are surfaced with remediation guidance so teams know what to fix next.

No. The platform is designed to find and assess evidence where it already lives. That removes the need for technical teams to fill out endless questionnaires, chase artifacts, or recreate documentation for every audit cycle.

Most approaches rely on questionnaires, consultant-led checklists, or general-purpose AI assistants that summarize documents. Progressio.AI uses specialized text models and a structured obligation graph so assessment is deterministic against atomic requirements. We prioritize Tier 1 errors: false confidence that a requirement is evidenced when the evidence is missing or insufficient.

No. Assessment is performed by specialized text models against a structured obligation graph. A general-purpose language model is used only in post-processing to articulate remediation guidance after the assessment is complete.

Legal and compliance teams use it to establish and defend an evidenced EU AI Act position for High-Risk systems. Technology and data teams use it to reduce audit burden. Executives use it to see where High-Risk AI creates exposure and where action is required.

Yes. Every result is clause-linked and reviewable. Teams can inspect supporting evidence, see whether each obligation is Evidenced, Partial, or an Evidence Gap, and retain human ownership of the final conformance position.

Customer data is processed under strict access controls, encrypted in transit and at rest, and used only to perform your assessments. Data residency and handling controls are designed for regulated environments. Your data is not used to train our models.

Both. You can upload materials directly or connect enterprise systems that already hold technical, organizational, and operational evidence. The goal is to assess evidence in place, not force teams to recreate it for the audit.

EU AI Act conformity, at hyperspeed

Stop spending months buried in regulatory paperwork. Progressio.AI automates the heavy lifting so your teams can focus on what matters.