Does an AI-generated classification become official automatically?
No, and it cannot. Every AI-generated risk classification or compliance determination stays a draft until a named human explicitly accepts it, with their name and a timestamp recorded. No AI output reaches a cleared or compliant state on its own — this is enforced in the software, not just stated in the documentation.
This is the rule the rest of the product is arranged around.
An AI-generated classification is a proposal. It appears as a draft, it is labelled as a draft, and it does not satisfy anything until a person on your team accepts it. That acceptance records who accepted it and when, and the accepting person takes the accountability for the determination.
The design follows the EU AI Act’s own logic. The regulation places obligations on providers and deployers — organisations — and expects human oversight over consequential AI output. A compliance tool that let its own AI mark a company compliant would be an odd thing to hand a regulator.
It also produces the artefact an audit actually wants. “The system says high-risk” is a machine output. “Our Head of Product reviewed and accepted the high-risk determination on 14 March, with these notes” is a governance record.
Practically: run the classification, read the citations and the confidence report, then accept, override, or send it to someone qualified to judge.
Related API endpoints
/api/risk-classification/{system_id}/accept bearer Accept an AI-generated risk classification
Base URL https://api.maditon.app ·
full specification at openapi.json
Regulation references
- Regulation (EU) 2024/1689 (EU AI Act) · CELEX 32024R1689
Read next
A free Solo account runs a real classification on one of your own systems — no card, no sales call.
Run a free classification