# AI System Card (EU AI Act orientation template)

Not legal advice. This is an internal-facing system card you can share with compliance, risk, engineering, and leadership.

## 1) Identification

- **System name:**  
- **Product / service:**  
- **Owner (name + role):**  
- **Responsible team:**  
- **Primary stakeholders (risk/compliance/legal):**  
- **Version / release:**  
- **Environment(s):** dev / staging / prod
- **Geography:** EU / UK / global

## 2) Role and scope

- **We are a:** Provider / Deployer / Distributor / Importer / Not sure
- **What the system does (plain language):**
- **Intended purpose:**  
- **Out of scope / excluded uses:**  
- **Users:** internal / external / both
- **Who can trigger the system / actions:**  

## 3) System type and components

- **System category:** chatbot / generative AI / hiring / credit & insurance / biometrics / healthcare / other
- **Primary model(s):**  
- **Vendors / third parties:**  
- **Key datasets / data sources:**  
- **Tools / orchestration:** (agent framework, workflow engine, queues, etc.)
- **Human-in-the-loop touchpoints:**  

## 4) High-stakes / risk tier orientation (estimate)

- **Potential prohibited elements (Article 5)?:** yes / no / not sure
- **Potential Annex III high-risk use case?:** yes / no / not sure
- **Transparency duty likely (Article 50)?:** yes / no / not sure
- **Notes / classification rationale:**  
- **Who approved the classification (and when):**  

## 5) Controls (operational)

### Govern

- **Policy gates / checkpoints:**  
- **Escalation rules:**  
- **Change control for model/policy updates:**  

### Measure

- **Evaluation approach:** (sampling, test sets, drift, red-teaming)
- **Key quality metrics:**  
- **Monitoring signals + alerting:**  

### Prove

- **Audit trail sources:** (logs, approvals, ticketing, evidence exports)
- **Retention policy:**  
- **Evidence export cadence:**  

## 6) Human oversight plan (minimum)

- **When a human must review:**  
- **How to intervene/override:**  
- **What gets recorded (evidence):**  
- **Training / playbooks:**  

## 7) Incident response and reporting

- **What counts as an incident for this system:**  
- **Escalation contacts:**  
- **Containment & rollback path:**  
- **Post-incident evidence to preserve:**  

