How the analysis is conducted
The unit of analysis is one workflow, agreed with you before anything starts. We begin from what the procedure says and what you describe of it, then we look for the elements that would confirm it. Where the two disagree, that is a finding. Where nothing allows us to check, we say so.
Cite this methodology
The Sprinkling Act methodology is publicly versioned and citable. The current edition is v1.10, September 2026, rendered from this page so that the document and the page cannot diverge. The editions it replaces stay available as published, uncorrected: v1.6 of August 2026, and the April 2026 card — a condensed snapshot of v1.1, regulatory freeze March 2026, cryptographically timestamped via OpenTimestamps and anchored on the Bitcoin blockchain. The August editions are not timestamped, and we make no such claim for them until they are.
Human in the Map
None of them answers the question a director actually asks, which is not who approves this output, but where the humans are across everything now running, and what the whole set costs. That question is about the map, not the loop. Human in the Map is the position it is asked from, and the one an organisation cannot occupy from inside itself.
Two levels, two different questions
Evidence check
“What supports what you already know about this workflow?”
Six questions, two minutes, no account, and nothing is sent or stored. It returns your own answers, grouped and readable, as a text you can take away. It concludes nothing: a director is not in a position to judge whether the question concerns them, which is what the survey exists to establish. It shows and it hands back, and it recommends nothing.
Baseline
“How far is what you describe from what the elements show?”
We agree the scope with you, then take your description of the workflow — you alone, because it is your map we are measuring. We then read whatever elements already exist: an export, a shared calendar, a version history, a folder of dated files. A second conversation sets the two against each other and records your objections. You receive a written report and a sixty-minute readout, five business days from the close of collection.
How we work
01
Findings come from the elements, the description is taken cold
A finding never rests on your word alone: it rests on what your elements establish. But your description is taken first, before you have gathered anything, and that is deliberate. A description prepared from your own elements no longer says what you see, it says what your elements say, and the distance we measure disappears. What you discover afterwards, while assembling your own file, is recorded separately: it is often the most telling finding of the survey. This is not an inventory of your AI systems: an inventory claims coverage, this survey is bounded by your elements, and it names what it could not reach.
02
What separates an element from a declaration
Not the medium, but the date and purpose of creation. An element existed before the engagement and for another use: an invoice, a version history, an internal procedure, a note you wrote in March for yourself. A declaration is produced for the engagement, whatever its medium: what you say in conversation, but also a table filled in your client space or an email sent after the call. The same information changes status by its date and purpose, never by being spoken or written. We refuse nothing you bring. What is bounded is not acceptance, it is promotion: nothing becomes established without a second source of a different type.
03
Three types of element, and the third is the most productive
Invoicing over twelve months says what you pay for. Prior procedures and notes say what was decided. And the dated outputs of the workflow — histories, exports, versions, logs, documents produced — say what was actually done. The third reaches what the other two miss: AI embedded in software already paid for something else bills nothing and is never cited, because it is not experienced as AI. It still leaves a trace on what it produces. We do not look for the tool, we look for its output. Expected coverage: at least two categories of different types, over twelve months, and for each missing type, the reason for its absence, in writing. A use that bills nothing and leaves no dated output is beyond this method, and the report says so.
04
Where a workflow starts and where it stops
A workflow starts at the framing of a request to an AI tool and stops at the first output that leaves the control of the person who asked for it: published, sent, committed, or picked up by someone else. This boundary does not depend on your size and always yields a finite object. The workflow examined is the one you designate, after a three-question sort: does it touch a client or money, is a decision coming on it, what happens if its output is wrong and nobody sees it.
05
Exports, not access
We ask for material your team can share rather than credentials to your systems. Nothing is installed, no agent runs on your side, and nothing is left behind.
06
Declared first, then checked
We start from the procedure and from what the director describes of it, taken before they have gathered anything. Then we read the elements, and a finding rests on what those elements establish, never on the description alone. Starting instead from a system's own documentation would tell us what it was designed to do, not what it does.
07
Every finding says what it rests on
A finding rests on the procedure as written, on elements we could examine, or on an inference we make explicit. The reader always knows which.
08
A gap needs a second source
When the procedure and the elements disagree, we look for a second source of a different kind before presenting the point as established. One source that contradicts another is a question, not yet a conclusion.
09
Open questions stay open
Where nothing available lets us check a point, it is reported as an open question. It is never quietly upgraded into an established fact.
10
No score
We do not produce a grade, a maturity level, or a percentage of an invisible total. A number would hide exactly what the analysis is meant to surface.
11
Dated and bounded
The analysis holds for a scope and a date. Workflows move, tools get added, roles change. We say from what point a finding stops being reliable.
What separates a piece from a declaration, the three kinds, and where a workflow starts and stops: these are what you actually gather from. They are set out on two pages, in the form the file is assembled in.
What counts as a piece (PDF)ONE RULE
The same rule, applied three times
The report sorts every finding by what supports it: confirmed, declared without an independent trace, gap, open question. That rule does not stop at the report.
To the words
The lexicon applies it to its own vocabulary. Each of the twenty-seven terms carries the standing of its source — peer-reviewed, convergent sources, recently formalised, method contested, not yet formalised — and a caveat stating what that source does not allow anyone to claim. Five terms are marked not yet formalised, and they are the ones our own method rests on. They are also the ones we are working to formalise, and the lexicon carries their standing until it changes.
To the sources
The work we cite carries the same mark. A peer-reviewed study can still be unusable if its population does not transpose to a European SME; a study commissioned by a vendor stays citable, provided the commissioner's interest is stated every time it is used, and not only the first.
To your findings
In the report, a gap is only presented as established once a second source, of a different kind, confirms it. Where nothing available allows a point to be checked, it stays an open question and never becomes a fact through an accumulation of hints.
The rule forces us to publish what our own claims are not worth. It is also the only reason to believe what is left.
The same principle decides whether there is a next step
The Baseline ends on one of three outcomes, and one of them concludes that nothing further is warranted. It is written into the method before any report exists, and its conditions are stated in advance rather than formed on reading. The free check makes no such judgement — it returns your own answers and concludes nothing, because a director is not in a position to decide whether the question concerns them. The renunciation therefore happens where it costs us something: on a delivered report, after the sale, not on a questionnaire before it.
Two words for two things
The visibility gap is what is measured: the distance between what a director describes and what the elements establish. Reconstruction is what happens in order to measure it: establishing what takes place from sources that are not people's recollection, then setting the two against each other. The first names the result, the second the method.
This term is defined in the lexicon, with the standing of its source — Reconstruction. Read the definition
This term is defined in the lexicon, with the standing of its source — Human in the Map. Read the definition
Conformity assessment: self-certification or third-party?
A widely-held misconception: “if my system is classified high-risk, I need to pay a Notified Body €50–150K.” True for some cases, not all. Article 43 of the AI Act defines two distinct conformity assessment procedures. The vast majority of Annex III systems (HR, credit, education) can take the internal route.
INTERNAL ROUTE
Annex VI · Self-assessment
Applies to most Annex III systems: employment and HR, credit and insurance, education, essential public services, asylum and migration, law enforcement (under conditions), administration of justice. The provider self-assesses against Art. 9–15, produces technical documentation (Art. 11) and signs the EU declaration of conformity (Art. 47). No Notified Body involved.
Indicative cost: €10–50K depending on external support level.
THIRD-PARTY ROUTE
Annex VII · Notified Body
Mandatory for: (1) AI as a safety component of a product already subject to third-party assessment under harmonization legislation (MDR, machinery, toys, vehicles), the AI Act procedure integrates into the product procedure; (2) Annex III §1(a) on remote biometrics, where Annex VII is explicitly required. A Notified Body audits the QMS and technical documentation before placing on the market.
Cost, from the only primary source available: the Commission’s impact assessment, SWD(2021) 84, puts the Notified Body documentary review at €3,000–7,500 and the quality-system audit at €1,000–2,000 per day. These are 2021 estimates, contested as low; vendor-published ranges are higher, with no primary source behind them.
Why this distinction matters: the two routes do not cost the same, and the gap is narrower than commonly claimed. On the Commission’s own figures, the third-party route adds €3,000–7,500 of review to €6,000–10,000 of compliance costs both routes carry: a ratio of roughly 1.4 to 2.1, not 5 to 10. The 5–10× factor served here until 4 September 2026 rested on no source, and the primary source contradicts it. Determining which route applies to a system is a legal qualification: it is not what the survey produces, and we do not sell it.
Sources: Art. 43 AI Act · Annex VI · Annex VII · SWD(2021) 84 · Art. 47 (EU Declaration of Conformity)
What the report contains
The reconstruction is the work; it is not the deliverable. The deliverable is the layer that makes the reconstruction decidable. Eight elements have to be in it, and a page that carries none of them belongs in the annex.
What breaks at a hand-off
Research on hand-off failures produces a distribution that reverses the assumption most leadership starts from. Close to two thirds of failures are transmission problems. The capability gap, the one supposed first, weighs under seven percent.
The result transmitted is altered or degraded between sender and receiver.
Content that was needed did not make it across the transition.
References become ambiguous: what exactly is being discussed is no longer shared.
The receiver does not have the means to handle what they received.
Proportions observed on multi-agent systems. We use them as a reading grid for human-AI chains, not as a prediction of what your own distribution will be.
The practical consequence is a question worth settling before funding anything: is the problem that people do not know, or that what they needed never reached them? The two have almost nothing in common, and one is far cheaper to correct.
The shortest lever is not the AI Act
Annex III obligations moved to December 2027, and that distance often reads as permission to wait. It is not one, because another text already applies to the same facts. Regulation (EU) 2016/679, articles 28, 30 and 32.
A processor acting on your behalf requires a contract. A tool brought in without going through the organisation may fall under this article, and where it does, the organisation stays responsible for a tool it never authorised. Whether it does is a qualification, and it belongs to your counsel rather than to us.
A record of processing activities is required. A survey does not produce it: the record is the controller's obligation and its completeness is their liability, so a partial one drawn up by a third party would expose them more than an acknowledged gap. What a survey does is document a chain the record probably ignores.
Appropriate technical and organisational measures are required. Undocumented AI data flows fail that standard by construction.
Your shadow AI problem is a data protection problem before it is an AI Act problem: already applicable, already familiar, already enforced.
What this is not. The survey is not a GDPR compliance exercise, not a data protection audit, and Sprinkling Act does not act as your data protection officer. It establishes what runs, where, and on whose authority. What you then do with it, and how it enters your record, belongs to you and to qualified counsel.
Limits
What follows is what Sprinkling Act is not. The limits of the method itself are not gathered here: each one is stated where it applies — the single source in the first principle, the unverifiable point in the one on open questions, the two numbers we do not produce in the list of what the report contains. A limit read at the end of a document is a disclaimer; read next to the finding it affects, it is information.
This is not an audit and not a certification. Nothing is checked against a standard, no judgement is issued, and no result is opposable to a third party as proof of anything.
This is not legal advice. Sprinkling Act is not a law firm, not a Notified Body and not a certification body. Where a regulatory reading is relevant, it is added as an annotation on top of the analysis and does not replace qualified counsel.
The analysis describes how the workflow runs. It does not decide for you whether to extend, renew, fix or stop, and it does not predict what the change will produce.
International Standards Alignment
The Sprinkling Act methodology is built exclusively on the EU AI Act (Regulation 2024/1689). It is not derived from, certified by, or dependent on any external standard. However, the gate logic and risk assessment structure are consistent with the principles of established international frameworks:
NIST AI RMF 1.0
NIST AI 100-1 (2023)
The four NIST functions (Govern, Map, Measure, Manage) mirror the lifecycle approach embedded in our gates. Gate evaluation (Map), scoring with obligations (Measure), and ongoing regulatory monitoring (Manage) follow the same iterative logic. The Sprinkling Act methodology addresses the Map and Measure functions; operational Govern and Manage remain the responsibility of the assessed organisation.
ISO/IEC 42001:2023
AI Management Systems
ISO 42001 requires organisations to establish risk assessment processes (Clause 6), operational controls (Clause 8), and performance evaluation (Clause 9). The Baseline produces neither a risk classification nor an obligation mapping. It establishes, on one workflow, the distance between what the director describes and what their elements establish, each finding carrying its evidence status. Clause 6 of an AIMS presupposes knowing what actually runs and who accepts what; that is the material the survey provides, and nothing more. It does not replace an AIMS.
Sprinkling Act does not claim ISO 42001 certification or NIST compliance. These references indicate structural coherence, not formal alignment or endorsement.
Sprinkling Act is an independent analysis firm. It is not a law firm, not a Notified Body, not a certification body, and not affiliated with the European Commission, the European Parliament, or any national supervisory authority. Reports are an informative analysis, not legal advice.
Methodology Changelog
v1.10
September 2026
The inversion of 4 September was right on the source of truth and wrong on the sequence, and this version corrects the sequence. Findings rest on the elements and never on the word alone: that stands. But the description is now taken FIRST, cold, before the director has gathered anything. The reason is in the specimen of 3 September: the gap of 1,096 unsigned-for commits appeared because the director described before touching his history. Had he gone through it first, he would have cited them and the finding would not exist. A description prepared from one’s own elements says what the elements say, not what the person sees, and the distance being measured disappears. What the director discovers while assembling his own file is now recorded separately, as a finding of its own. Same version, three additions the method lacked. First, what separates an element from a declaration: the date and purpose of creation, never the medium. A note written in March for oneself is an element; the same information typed for the engagement is a declaration. Nothing is refused; what is bounded is promotion, not acceptance. Second, the three types of element, and the third is the most productive: invoicing says what is paid for, prior procedures say what was decided, and the dated outputs of the workflow say what was actually done. AI embedded in software already paid for something else bills nothing and is never cited, because it is not experienced as AI; it still leaves a trace on what it produces. Expected coverage is two categories of different types over twelve months, with the reason written for each missing type. Third, where a workflow starts and stops: at the framing of a request to an AI tool, and at the first output that leaves the control of the person who asked for it.
Previous versions (11)
v1.9
September 2026
The entry inverts. Until now the survey started from what the director describes and looked for contradiction in the elements. It now starts from the elements themselves — tool invoicing, exports, dated files, version histories — and the description is taken second, as the control. What is measured is unchanged: the distance between the two. What changes is the door, and with it what is promised before purchase. The reason is in the evidence: on the internal specimen of 3 September 2026, everything that carried weight came from the traces, and the declared map ran to twelve lines. The part that did the work was the part that did not depend on the word. Consequence for the perimeter: the survey is bounded by what the elements establish. Whatever leaves no billed or dated trace does not appear in it, and the report names what it could not reach. This is still not an inventory: an inventory claims coverage, and this claims none. Consequence for the engagement: without invoicing or exports there is no survey, and that is said before payment rather than after. One person is still interviewed at the Baseline, and teams still come in only at the Full Map. Same version, catalogue: the Full Map includes the Baseline as one engagement. A buyer who already had the Baseline delivered pays the difference; it is not redone and not billed twice. The total is identical on both paths, nothing is refunded and nothing is discounted, so the rule that the diagnostic is never credited is untouched in substance.
v1.8
September 2026
Two figures served on this page since 10 April 2026 are withdrawn, and a deliverable promise with them. The 5–10× factor between self-certification and third-party audit rested on no source, and the only primary source available contradicts it: on the Commission’s impact assessment SWD(2021) 84, the third-party route adds €3,000–7,500 of documentary review to €6,000–10,000 of compliance costs both routes carry, a ratio of about 1.4 to 2.1. The indicative Notified Body cost of €50–150K per system is replaced by the figures that source actually carries, with its caveats: 2021 estimates, contested as low, vendor ranges higher and unsourced. The three sources displayed under those figures — Article 43, Annex VI, Annex VII — carry no cost at all; a figure placed above them borrowed their standing. SWD(2021) 84 is added. And the sentence stating that Sprinkling Act identifies which conformity assessment route applies to a system, in the full report, is removed: no current offer produces it, and determining a route is a legal qualification. Same version, ISO 42001 alignment: the claim that the 6-gate assessment produces a risk classification and an obligation mapping feeding an AIMS is withdrawn. The survey establishes a distance on one workflow, with an evidence status per finding; that is the material clause 6 presupposes, and nothing more.
v1.7
August 2026
The methodology stops describing itself as a pre-conformity layer. Sprinkling Act enters at usage and visibility; the pre-conformity work comes after the survey rather than framing it, and the regulatory governance paragraph now says so. Nothing changes in the six gates: what changes is where the regulation sits relative to the measurement. The v1.6 edition stays available as published.
v1.6
August 2026
Structural incompatibilities move to the Full Map, on the same ground as rework time. The element already stated that it is the only finding requiring a view from above; the Baseline, whose single source is the director looking from one position, does not have one, so the list was asking it to contain what it cannot establish. Where the Baseline glimpses an incompatibility it is now recorded as an open question, a status the report already carries. Consequence: the Full Map no longer sells what the Baseline announces delivering. Eight elements still, none removed — this one now carries its tier in its title.
v1.5
August 2026
What the Baseline promises is narrowed to what it can establish. It states a position, it does not diagnose: what the director cannot know from where they stand, and what it costs to keep deciding without it. It does not return the teams’ uses and does not make visible what the director does not see — it measures the distance separating them from it. The ground is not commercial: Star and Strauss, CSCW 1999, establish that the invisibility of work is an organisational process, so making it visible is an operation nobody can run from inside the organisation. Consequence for the Full Map: its central deliverable is the gap document, that is the gap between the measurement taken with the director alone and the one taken with the three or four people who run the work. Without a delivered Baseline there is no term of comparison, so requiring it is a methodological constraint before it is a commercial one, and the Baseline report is sealed before the first Full Map interview — revised after hearing the teams it would no longer be a comparison but a reconstruction. The gap is not one quantity: it is attributed line by line by the date of the element. An element predating the close of the Baseline collection is a blind spot, established; one postdating it is drift, a finding in its own right; a line carried by a statement alone stays unattributed and is marked as such. The close of the collection is therefore dated in the report, distinctly from the readout. No validity window is published, and no variation of the deliverable is indexed on a triggering delay, for the same reason no price is.
v1.4
August 2026
The unit of analysis changes. The Baseline no longer describes a workflow, it measures the distance between what a director describes and what the elements they provide establish. The single source is the director: what escapes them does not become visible through better questioning, and that limit now sits in the first principle rather than in a closing section. The workflow examined is the one the director designates, not one we select by comparing several, which would require the overview we have just said we do not have. Consequence for the deliverable: first-pass acceptance rate and rework minutes move to the Full Map, where the estimate comes from the people who do the work rather than from the person who decides. The sentence “without those two numbers the report stays a description” remains exact — the Baseline is a dated, situated description of a distance, and the move to the Full Map is what turns it into an arbitration. Report structure: still seven parts, but not the same seven. “What the workflow takes” disappears, its substance being the two numbers that just moved, and what remains of it — subscriptions and direct costs, which an invoice establishes — joins the findings. “Workflow map” becomes “declared map”. “Priorities” becomes “what must be decided”, with the owner observed rather than proposed and the deadline drawn from a dated fact of the client’s own. A new part records the director’s corrections and objections verbatim, including those we did not retain. Same release, GDPR section: the claim that a survey of AI chains produces the article 30 record is withdrawn. The record is the controller’s obligation and its completeness is their liability; a survey documents a chain the record probably ignores and shows what is missing from it. Two legal qualifications move to the conditional, and whether these articles apply to a given use is stated as belonging to the client’s counsel.
v1.3
May 2026
Post-Digital Omnibus alignment (provisional trilogue agreement of 7 May 2026, EP press release IPR42011). Annex III standalone high-risk binding date moved from 2 August 2026 to 2 December 2027 (EP enumeration: biometrics, critical infrastructure, education, employment, law enforcement, border management; non-exhaustive). Annex I product-embedded safety components binding date moved from 2 August 2027 to 2 August 2028. Article 50 transparency unchanged (2 August 2026 baseline preserved). GenAI watermarking advanced from 2 February 2027 to 2 December 2026. Safety-component definition narrowed (verbatim: AI functions that only assist users or optimise performance no longer automatically face high-risk obligations, if their failure or malfunction does not create health or safety risks). Art. 5§1(i) added (provisional, applicable 2 December 2026 pending formal adoption): prohibition of AI systems generating CSAM/NCII content, three-branch architecture (designed-for / placed-without-safeguards / deployer-use). Art. 50§1-§4 obligations in scoring engine enriched with explicit application timeline (2 August 2026 new systems · 2 December 2026 transitional for §2 watermarking + §4 deepfake disclosure on systems already on EU market). Temporal indicators in score reports updated. Sleeper segments mapped: PWD × §4 employment platforms, CRA × AI Act IoT-AI.
v1.2
May 2026
Art. 5(1) split into absolute (§1(e)/(f)/(g)) vs conditional (§1(a)/(b)/(c)/(d)/(h)) prohibitions. Conditional triggers HIGH non-terminal with legal-verification flag instead of CRITICAL terminal. Art. 5§1(a) deceptive wording aligned with regulation: "causing or likely to cause significant harm". Annex III scoring now weighted by domain (structural vs operational). GPAI standard = LIMITED 35; GPAI systemic risk = HIGH 80 (smoother thresholds). Diagnostic scope clarified: screening, not legal qualification. Full report performs article-by-article qualification. Regulatory observation period: April–May 2026 (Digital Omnibus trilogue ongoing post 28 April stall, MDCG 2021-24 Rev.1 of 20 April integrated).
v1.1
April 2026
Art. 5§1(d) added: criminal risk profiling. Art. 5§1(h) reference corrected: real-time biometric. Art. 6(1) vs 6(2) reference corrected. Art. 50§2 content marking activated. All 8 prohibited practice checks (a-h) now covered. HIGH RISK obligations enriched with Art. 9-15 details. International standards alignment section added (NIST AI RMF, ISO 42001). Methodology card expanded to 23 pages.
v1.0
March 2026
Methodology versioned and published. GPAI systemic risk gate (Art. 55). Art. 6(3) exemption logic. AI Office guidance on Annex III. Regulatory freeze date: March 2026.
v0.1
January 2026
Initial release. 6 regulatory gates based on Art. 5, 6, 50, 51, 53. Article mapping for all Annex III domains.
Regulatory Intelligence
This methodology is kept current through dated regulatory signals: each material development across EU institutions, national authorities, and industry publications is logged, tier-scored, and reflected in a versioned methodology release when it changes the analysis (see the changelog above).
When a signal reaches CRITICAL or MAJOR tier, the Temporal Stability Indicator on affected reports is updated automatically. Every scoring axis is documented, every threshold is versioned.
Implementation governance state (May 2026): the EU AI Office is operational with ~125 staff (target 140+), CEN-CENELEC JTC 21 harmonised standards have missed two deadlines and target Q4 2026 publication (risk: not in OJ when 2 December 2027 enforcement starts on Annex III), the Article 67 Advisory Forum has not been constituted seven months after the call for expressions of interest closed (September 2025), the Article 68 Scientific Panel structure is defined but its constitution remains unconfirmed, and only one Member State (Spain · AESIA, 12 high-risk systems hosted) has an Article 57 sandbox publicly operational. The Sprinkling Act methodology sits upstream of that work rather than inside it: it establishes what is actually running, so that the pre-conformity work which comes after it stands on dated facts rather than on absent or delayed official guidance. What it records is defensible under the obligation de moyens standard regardless of standards publication status.
Active signals affecting this methodology:
Start with the scope
Tell us which decision is coming and which workflow carries it. If there is no fit, we say so before you pay.
Check the fitSix questions on your own uses, two minutes, no account. Your answers come back to you as a text you can take away — nothing is sent to us.
Take the checkSEE ALSO