The cleanest way to keep your compliance‑AI out of the EU AI Act high‑risk class: AI proposes, a human approves and signs
I nearly signed off on an "auto‑close" feature for an AI that triaged evidence requests. It would have saved the team hours a week. We didn't enable it. To be fair, automation is seductive when your CAPA queue looks like a climbing route on the Wetterhorn, but granting an AI the power to act on regulated records is the moment you voluntarily take on provider obligations under the EU AI Act's…
The EU AI Act classifies AI systems as high‑risk if they make or execute decisions that materially affect safety, regulatory records, or legal obligations. One such risk lies in AI systems that could autonomously change or close regulated records. To avoid being thrown into this high‑risk category, the headline recommendation is a simple rule: "AI proposes, a human approves and signs."
This binary approach keeps the system in the decision‑support bucket rather than the automated decision bucket, preserving human accountability, and providing an unambiguous audit trail. By structuring AI‑assisted workflows to require human review and signature before any change to regulated records, organizations meet the conformity assessment, technical documentation, and post‑market monitoring requirements of the EU AI Act without having to endure the heavier burden of high‑risk classification.
Implementing this rule involves a few key technical controls. The AI can generate suggestions or draft content, but it must not change the record status field itself. Before any status change, an authenticated human must review, add rationale, and electronically approve the action. Immutable audit logs capture the AI’s input, its output, and the human reviewer’s decision, while distinct UI elements separate suggested content from approved content.
Procedural controls, SOPs, training records, and periodic reviews ensure accountability and traceability.
In practice, the organization rebuilt its workflow for AI‑assisted evidence triage and CAPA drafting. The AI could only write or tag records, but never alter the status. A mandatory “review comments” field required justification before approval, and all actions were logged immutably. UI affordances clearly distinguished suggested from approved content, preventing auto‑execution. Change control and periodic reviews ensured ongoing compliance.
Auditors are likely to focus on clear SOPs demonstrating the human approval step, audit logs proving the AI only proposed actions, evidence that approvers are trained and accountable, and records of any AI or prompt modifications. Essentially, while automation can aid efficiency, the ultimate compliance safeguard is ensuring a human—someone trained and documented—always approves and signs off before any change to regulated records.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.