Statutory routes
The places the Act itself lets earlier work count.
Each row quotes the provision that grants it. Where a route is open only to certain organisations, the condition is stated — a route offered to someone with no right to it is worse than no route at all.
EU AI Act Art. 27(4)Fundamental-rights impact assessment / DPIA
What the Act says — Where the obligations of Art. 27 are already met through the data-protection impact assessment carried out under GDPR Art. 35, the fundamental-rights assessment complements that assessment — the deployer may cross-reference it or incorporate the relevant parts.
What you are asked to confirm: Draw the overlapping parts from your data-protection impact assessment, then check they reach the fundamental-rights questions the DPIA was never written to answer.
EU AI Act Art. 26(9)Provider's instructions for use, feeding the DPIA
What the Act says — Deployers of high-risk systems shall use the information provided under Art. 13 to carry out their data-protection impact assessment under GDPR Art. 35.
What you are asked to confirm: Bring the provider's instructions for use into the impact assessment, then check they describe this deployment rather than the product in general.
EU AI Act Art. 8(2)Technical documentation and testing
What the Act says — Where a product is covered both by this Regulation and by the Annex I harmonisation legislation, the provider may integrate the testing, reporting, information and documentation into procedures that legislation already requires.
Open only where: Only where the product also falls under Annex I harmonisation legislation — a medical device, machinery, a vehicle and so on.
What you are asked to confirm: Name the Annex I procedure the documentation is integrated into, then check it carries the Art. 11 content as well as its own.
EU AI Act Art. 17(3)Quality management system
What the Act says — Providers already subject to quality-management obligations under sectoral Union law may include the Art. 17(1) aspects within that existing system.
Open only where: Only where sectoral UNION LAW already imposes a quality-management duty. A voluntary standard is not sectoral Union law — ISO/IEC 42001 does not open this route.
What you are asked to confirm: Name the sectoral instrument and the system it requires, then check the Art. 17(1) aspects are written into it rather than assumed.
EU AI Act Art. 17(4)Quality management system
What the Act says — For providers that are financial institutions subject to internal governance requirements under Union financial-services law, the quality-management duty is deemed fulfilled by complying with those rules — except for the aspects at Art. 17(1)(g), (h) and (i).
Open only where: Only for financial institutions subject to internal governance requirements under Union financial-services law. Points (g), (h) and (i) stay yours whatever those rules say.
What you are asked to confirm: Name the internal governance arrangements you rely on, then account separately for Art. 17(1)(g), (h) and (i), which this route does not reach.
EU AI Act Art. 26(5)Post-deployment monitoring
What the Act says — Deployers that are financial institutions subject to internal governance requirements under Union financial-services law are deemed to fulfil the monitoring obligation by complying with those arrangements.
Open only where: Only for financial institutions subject to internal governance requirements under Union financial-services law.
What you are asked to confirm: Name the internal governance arrangements that monitor this system, then check they observe it in operation rather than only at approval.
Declaring one of these prefills a form and records that you relied on it. It does not tick the obligation. Whether your own governance arrangements really reach far enough is a judgement only you can make, and the record keeps it in your name.