Art. 9
Risk management
A risk register per project, opened at scoping and maintained through operations. Every identified risk carries a mitigation measure and an owner.
The AI charter
The European Artificial Intelligence Act sets the frame. This charter states how NEURIXIS designs, deploys and maintains AI systems, article by article — and what we refuse to build, for anyone.
Regulation (EU) 2024/1689 entered into force on 1 August 2024, and its obligations phase in through 2027. It does not ask the same of every system: it classifies them by risk level and strictly regulates only those that can harm people.
This charter is our answer. It states what we do by default, on every project, including where the law does not yet require it — and where it never will, because the system is minimal risk. Our trade is measuring what AI returns; it starts with measuring what it risks.
What this page is not: neither a certification nor legal advice. Your compliance is built with your DPO and your counsel. Our part is technical: we produce the pieces — documentation, logs, measurements, files — that make it achievable.
The regulation sorts systems into four risk levels. We apply that sorting from the scoping workshop: the level of a use case decides its deliverables, its safeguards and, sometimes, its refusal.
Article 5 prohibits practices we would never have accepted anyway. Writing them down costs little and commits a lot: if someone offers them to you one day, it will not be us.
The requirements of Articles 9 to 15 are mandatory for high-risk systems. We hold them as our manufacturing standard whatever the project’s level: they describe, when it comes down to it, what a serious system should have done long before the law stepped in.
Art. 9
A risk register per project, opened at scoping and maintained through operations. Every identified risk carries a mitigation measure and an owner.
Art. 10
Quality, representativeness and traceability of datasets before any training. No model without an identified data owner.
Art. 11
The file describing the system, its data, its limits and its performance measurements is a deliverable, handed over with the code. Never a document written after the fact.
Art. 12
System events are logged: every automated decision can be traced and replayed after the fact.
Art. 13
Instructions for use, performance conditions, known limitations: you know what you are deploying, and so do your teams.
Art. 14
A human can interrupt, correct or take back control of the system. Not a slogan on a wall — a mechanism, designed and tested.
Art. 15
Accuracy measured and tracked, attack scenarios considered, model drift monitored continuously. A system no longer watched is a system no longer controlled.
Two obligations of the regulation fit in one sentence each. Honouring them mostly takes not trying to work around them.
Art. 50
Your users know when they are interacting with a machine, and content generated by your systems is labelled as such. No cosmetic exceptions.
Art. 4
The regulation expects the people using these systems to understand them. Training your teams is part of every engagement: it is our transfer commitment too.
This charter is reviewed every year, and on every change of the regulation or its harmonised standards. Its version and date appear at the bottom of the page: a charter without a date is a charter without commitment.
It binds the company, and it is signed by its two founders. A question on a point, a doubt on a running project: write to us, you will get a named answer.
To verify
Version 1.0 — August 2026
An hour is enough to tell whether your subject stands up. If it does not, we will tell you then, not after three months of project.