Gap & Remediation Plan — EU AI Act — Article 12
Company: Acme Corp
Generated: June 27, 2026
Audit Period: 2026-01-01 to 2026-12-31
Summary
- Total gaps identified: 1
- Critical/High severity: 0
- Medium/Low severity: 1
- Controls not assessed (outside scope): 0
Open Items
Gap 1: Art. 12(2)(a) — Identification of Input Data
- Framework: EU AI Act — Article 12
- Severity: Medium
- Status: ❌ OPEN
- Findings: 1
- src/services/recommendations.ts:24 — AI-generated recommendation engine logs outputs without recording the input-data reference (EU AI Act Art. 12(2)(a)) (medium)
- Recommended Fix: Record the input data — or a reference to it — alongside each AI event in the provenance ledger.
- Owner: [ORG TO COMPLETE: Remediation owner]
- Target Date: [ORG TO COMPLETE: Target remediation date]
- Completion Evidence: [ORG TO COMPLETE: Describe how closure will be verified]
Controls Outside Scope
None — all controls are testable at the code level.
Tracking
| Gap # | Control | Severity | Owner | Target Date | Status |
|---|
| 1 | Art. 12(2)(a) | Medium | [ORG TO COMPLETE: Owner] | [ORG TO COMPLETE: Target date] | Open |
Previously Remediated (Game Plan archive)
- Removed hardcoded Stripe secret key from the billing service — completed 2026-04-18
- Enabled TLS certificate verification on outbound webhook calls — completed 2026-05-09
Disclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
Note: Code-level provenance controls only. This assessment identifies where AI-generated code exists and whether provenance records are in place. It is a development aid for Article 12 readiness, not a legal compliance determination — consult qualified legal counsel for formal compliance assessment.