{
  "id": 3815237,
  "title": "We scanned public AI repos for EU AI Act compliance. Nearly every one failed.",
  "url": "https://urgent.news/2026/08/27/we-scanned-public-ai-repos-for-eu-ai-act-compliance-nearly-every-one",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-27T20:10:33.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/scanara/we-scanned-public-ai-repos-for-eu-ai-act-compliance-nearly-every-one-failed-4nme"
  },
  "original_language": "en",
  "account": "An automated scan of open-source artificial intelligence repositories found that nearly all of them failed to meet the requirements of the EU AI Act. Despite developers already possessing knowledge of best practices such as structured logging, input validation, and human oversight checkpoints, they were unaware that these had become legal obligations for high-risk AI systems being deployed within the European Union. The deadline for compliance had already passed on August 2, 2026, and failing to meet the necessary standards could result in significant consequences. The EU AI Act's high-risk obligations are now in force, requiring a risk classification and technical documentation file, encompassing nine sections that map the system's functionality to the regulation's requirements. Most teams are unaware if their system falls under Annex III, which includes sensitive areas like credit scoring, CV screening, and exam scoring. The majority of engineering teams neither know if they are in scope nor have the necessary documentation. The primary issues lie in Articles 9 (Risk Management), 12 (Record-Keeping), and 14 (Human Oversight), with Article 11 (Technical Documentation) being the only one that tends to pass, as developers frequently write documentation and type hints, which are considered sufficient for most requirements. However, this overlap in good engineering practices and legal obligations creates a gap in awareness. Many companies may assume that compliance tools like GRC platforms cover the necessary legal requirements, but these tools do not analyze the code itself. The EU AI Act demands proof of the system's design, oversight mechanisms, and potential consequences in case of errors, which are typically found in the code and documentation. This distinction highlights the need for a comprehensive approach to compliance that extends beyond existing tools.",
  "summary": "We scanned public AI repos against the EU AI Act's requirements. Nearly every one failed at least one requirement. The code wasn't bad. Developers already know how to write structured logging, input validation, and human-oversight checkpoints. Nobody told them these are now legal requirements for high-risk AI systems shipped into the EU. The gap The EU AI Act's high-risk obligations are in force…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}