You are being asked to sign for AI systems reaching patients, applicants, and children.

For DPO & CISO

Sign against evidence,
not against assurances.

Data categories, legal basis, Art. 10 bias examination, Art. 14 oversight design, Art. 12 logging design, agent tool boundaries, and diagnostic results - assembled per system, routed to the role that must defend the decision.

GDPR Art. 9 · 22 · 35AI Act Art. 10 · 12 · 14 · 15No raw data requestedClearance that expiresNot certification

A sign-off you cannot reconstruct is a sign-off you cannot defend.

When a supervisory authority asks why this model was cleared for these patients, the answer has to be a record: what was proven, by which diagnostic, against which article, on which model version, and who accepted it. Not a recollection, and not a vendor's PDF.

For DPOs

The passport, read against the articles you are accountable for.

Health AI carries GDPR Art. 9 and, as a device, MDR. Financial AI carries Art. 22 and DORA. Anything a minor can reach carries Art. 8 and DSA Art. 28. The passport is structured around those obligations - in that order.

“Which systems process special-category or children's data - and on what condition?”

Every passport records data categories with the GDPR Art. 6 basis, the Art. 9 condition, Art. 8 where a minor can be reached, and Art. 22 where the decision is automated. Atlas lets you filter the whole estate by exposure, not by vendor name.

“Is there a DPIA under Art. 35 - and does it describe the system that is actually running?”

DPIA status is a required field, tied to the model version it was written against. A model or provider change is a reason to re-review: record it, and the DPIA and the accuracy evidence are reviewed again before the affected visas are renewed.

“Was bias examined, or merely denied?”

AI Act Art. 10 requires examination of possible biases. A Ripple carries a group-disparity Evidence Record - including whether a removed protected attribute is being reconstructed from postcode, device class, or referral pathway.

“Can I hand a competent authority a single, structured record?”

A Wake: an evidence export carrying identity, basis, DPIA, bias examination, oversight design, diagnostic results, and the decision record - assembled once, read without re-running anything.

Evidence without centralising the data

The finding travels. The patient record does not.

For CISOs

The visa, granted before the agent's first call.

An agent calls tools, holds credentials, and writes to systems. A Droplet declares what it may do, in which context, until when - and lapses unless a new decision renews it.

“Which agents hold credentials, and what may they call?”

A Droplet declares the tool allowlist, the systems in scope, and whether the credential is read or write - before the agent's first call. Anything outside the list is outside the clearance on record.

“Can a retrieved document instruct our assistant?”

Treat the RAG corpus as untrusted input, because it is. The visa records it as such, and its handling is cleared before the grant - an injected instruction inherits the agent's data access, not the attacker's.

“Is every tool-call recorded?”

AI Act Art. 12 requires automatic recording of events over the system's lifetime. The passport records how the system logs - what is captured, where it is kept, and whether a human cleared the act. A system that cannot show it stays unproven.

“Can I withdraw an agent's clearance right now?”

An agent can be marked revoked in one action, and the revocation is recorded with actor and timestamp. Stopping the agent itself happens in your own systems; the record shows who decided, and when.

Failure modes a visa is written against

Prompt injection reaching the model through a RAG corpus
An agent holding write credentials to a clinical or core system
Tool-calls executed and never recorded - AI Act Art. 12
A silent model swap behind an unchanged endpoint
Distribution shift: accuracy holding in aggregate, failing in a subgroup
Oversight that exists as an approve button and nothing else

Review workflow

From open file to recorded decision.

01

The file opens

Currents names the system, its data categories, and its provisional Annex III classification.

02

The passport is issued

The provider completes the Ripple; diagnostic results record the bias, accuracy, and exposure evidence.

03

The queue routes

DPO takes basis, DPIA, and bias. CISO takes tools, credentials, egress, and logging. Neither reviews the other's.

04

The gaps are named

Unproven sections block the decision. Absence of evidence does not default to allow.

05

The visa is granted or refused

One context, stated conditions, an expiry date - logged with actor, role, rationale and time in a hash-linked audit log.

The difference

The review, with and without the record.

Signing on assurances

  • Legal basis asserted in prose across four documents
  • Bias 'addressed' - no test, no result, no population
  • Oversight described; the overseer has nothing to disagree with
  • Agent tool-calls unlogged and unreconstructable
  • Accuracy quoted from a validation run two model versions ago
  • A clearance that never expires and cannot be withdrawn

Signing on evidence

  • Art. 6 / 9 / 22 basis and Art. 35 DPIA as required, versioned fields
  • Art. 10 group-disparity result recorded as an Evidence Record
  • Art. 14 acts named, with the human who can override
  • Art. 12 logging design recorded and reviewed by the CISO
  • Art. 15 accuracy evidence reviewed against the population in front of it
  • A visa with an expiry date; renewal is a new decision

Addressed

How this fits the role you already hold.

“We already use Microsoft Purview or equivalent privacy tooling.”

Data classification tells you where sensitive data sits. It does not tell you whether this triage model was validated on a population resembling your patients, whether its agent can write to the record, or whether its retrieval corpus has ever been checked for injected instructions. Those are the questions you are being asked to sign against.

“We cannot upload raw data, prompts, or models for evidence collection.”

You do not. Raw records, prompts, corpora and model weights are never requested. You supply evidence - documents, summaries, results - and it is recorded against the system.

“Our review process is already established.”

AL360° Oceans does not replace it. It supplies the evidence your process currently assumes exists: the Art. 10 bias examination that was never run, the Art. 14 oversight design that is an approve button, and the Art. 15 accuracy figure that predates the current model.

“Under DORA and MDR we already register third-party dependencies.”

Registration records the dependency. It does not record that the dependency silently changed. A passport ties evidence to the model version it was produced against - so a recorded model change sends the file back to review at the gate, rather than leaving it quietly in the register.

Step 1 - the scan

Know what you are being asked to sign for
before you are asked to sign.

A scan names every AI system reaching health, financial, or minors' data, classifies it against Annex III, and hands you a review queue with the gaps already named.

AffectLog provides technical and operational evidence to support AI access, supplier-risk, security, privacy, and governance review. Not legal advice, certification, notified-body conformity assessment, or regulatory approval.