The regulation requires documented evidence your AI agents were tested. Most companies don't have it.
EU AI Act Article 9 mandates that high-risk AI systems implement a risk management system including systematic adversarial testing. A documented, repeatable scan process is the evidence you need.
Where most AI teams are today.
Article 9 compliance is not a checkbox. It requires a documented, repeatable, evidence-generating process.
Which articles Orithos
covers β and how.
The EU AI Act does not describe a testing methodology. It describes requirements. Orithos translates each requirement into testable probes and generates the evidence your legal team needs.
What a notified body
actually wants to see.
The EU AI Act requires evidence packages, not reports. Every Orithos scan generates a structured evidence pack with control citations a notified body or internal legal team can act on.
| Article | Regulatory requirement | Evidence Orithos generates | Status |
|---|---|---|---|
| Art. 9(4)(b) | Identification and analysis of known and foreseeable risks | Threat taxonomy mapped to your agent configuration | β Automated |
| Art. 9(4)(c) | Testing to identify appropriate risk management measures | Probe sets, 3-tier judge confirmation, risk score with methodology | β Automated |
| Art. 9(5) | Risk management system reviewed throughout lifecycle | Scheduled re-testing with risk score trend over time | β Automated |
| Art. 9(7) | Testing against groups for which the system is intended | Domain-specific probe packs (FS, Health, Legal) | β Automated |
| Art. 13(1) | Transparency of design and functionality | Attack surface documentation per agent configuration | β Automated |
| Art. 13(3)(b)(v) | Performance metrics including known limitations | Residual risk section with unaddressed finding documentation | ~ Partial |
| Art. 14(4)(a) | Ability to detect anomalies and unexpected performance | Scheduled scans with regression alerts on risk score change | β Automated |
| Art. 15(1) | Appropriate levels of accuracy and robustness | Adversarial robustness findings with severity and exploit path | β Automated |
| Art. 15(3) | Resilience against attempts to alter behaviour | Prompt injection, RAG poisoning, jailbreak detection evidence | β Automated |
This is what the
evidence pack looks like.
Every Business tier scan produces an EU AI Act audit-ready export. Below is a representative extract showing the structure your legal team and notified body receive.
From deployment to
audit-ready in one workflow.
Most companies treat EU AI Act compliance as a documentation exercise. Orithos treats it as a security programme β the documentation is a by-product of the testing.
Request access before
your competitors do.
High-risk obligations have been enforceable since 2 August 2026. Security teams that establish a documented testing programme now generate the evidence trail auditors and regulators ask for first β before a finding becomes an incident.