Regulation (EU) 2024/1689

The file exists.
Now prove the sentence.

Since 2 August 2026 the obligations for high-risk AI systems apply. Most organisations now have the technical documentation. What they do not have is the ability to show, for one specific sentence in it, where that sentence comes from.

The question it comes down to

"Your risk management file states that the residual risk in this scenario is acceptable. On what basis?"

Article 9 requires risk management as a continuous process, Article 11 and Annex IV require it to be documented, Article 12 requires logs, and Article 14 requires evidence of human oversight. The answer to the question above usually lives in four separate documents written by three different teams over eighteen months.

Why ordinary search does not get there

The documentation was assembled, not written as one argument.

Risk assessment, data governance record, test protocol and instructions for use each stand alone. The connections between them exist only in the heads of the people who wrote them.

Keyword search finds the paragraph, not the reasoning.

The auditor is not asking where the word 'residual risk' appears. They are asking which measure reduced it, which test confirmed the reduction, and who signed off.

Every version bump invalidates a previous answer.

Article 72 post-market monitoring keeps the file alive. An answer that was correct against version 3 of the risk file is wrong against version 5, and nothing tells you which answers went stale.

A worked example

The query

On what basis was the residual risk for the automated pre-assessment classified as acceptable?

  1. 01
    Risk management file, section 4.2

    Identifies the hazard and names mitigation measure M-07.

  2. 02
    Test protocol TP-2026-014

    Measures M-07 against the acceptance criterion and records the result.

  3. 03
    Human oversight concept, section 3

    Defines the escalation path that the criterion assumes to be in place.

  4. 04
    Change log, entry 2026-05-12

    Confirms the criterion has not been amended since the test was run.

The answer

Acceptable on the basis of measure M-07, verified in TP-2026-014 under the escalation path defined in the oversight concept — with all four documents cited and the version state named.

What ARGUS does here

Cross-document reasoning

Answers questions whose answer spans the risk file, test protocols, data governance records and instructions for use, rather than searching each in isolation.

Evidence ledger per answer

Each statement carries the document, the section and the retrieval step that produced it. No source, no answer — the system abstains rather than filling the gap.

Version-aware questioning

Where several versions of a document are indexed, the answer names which one it relied on, so a stale answer is visible as stale.

Runs inside your perimeter

On-premise or EU-hosted deployment. Documentation of a high-risk system does not leave the organisation to be analysed.

What it does not do

Stated here rather than discovered in week three of a pilot.

  • ARGUS does not classify your system as high-risk or not. That determination is legal work.
  • ARGUS does not produce a conformity assessment and is not a notified body.
  • ARGUS answers from the documents you index. If the reasoning was never written down anywhere, the honest output is a gap, not a reconstruction.
  • We have built and demonstrated these scenarios. We have no production installations and name no customer references.

Questions we get asked

Does this make our system compliant?+
No. It makes your documentation answerable. Compliance is the outcome of the assessment; this addresses the part of it where someone has to defend individual statements under questioning.
Is ARGUS itself a high-risk AI system?+
That depends on the purpose you deploy it for. Used as an internal retrieval and reasoning tool over your own documents, it typically falls outside Annex III. We will not give you a legal opinion on your specific deployment — your counsel should.
What does deployment require?+
A container environment inside your infrastructure, a PostgreSQL instance, and the documents. Model access is your choice: a commercial API, an EU-hosted endpoint, or a model running on your own hardware.

Test it on a question you already lost time on

Bring one question your own documents should be able to answer, and the documents that ought to contain the answer. If the evidence is not there, that is the result — and it is worth knowing before an auditor finds it.