The EU AI Act is the first major regulation that requires organisations to test, evaluate and document AI systems using real‑world conditions. It is no longer acceptable to rely on prompt testing, curated demos or idealised examples. The Act requires evidence, not assumptions.
Any organisation deploying high‑risk AI must now prove:
These requirements cannot be met with traditional testing. They demand workflow‑based evaluation that reflects how AI is actually used by real people, under real pressure, in real environments.
The Act exposes a fundamental industry problem: most AI systems are tested in conditions that do not resemble production. This creates a gap between expected behaviour and actual behaviour — the gap where failures, liabilities and regulatory breaches occur.
Real‑world testing closes that gap. It reveals:
This is the level of evidence regulators expect, and the level organisations must produce to remain compliant.
The LLM Inquisitor Methodology provides a practical, repeatable and workflow‑aligned approach to testing AI systems in ways that meet the Act’s expectations. It is designed for real‑world evaluation.
The methodology supports compliance by enabling:
It gives organisations the evidence they need to deploy AI safely, legally and with confidence.
Many organisations are searching for a single tool that will test their AI system, confirm compliance and generate the required documentation. This expectation comes from other regulated domains, where one scanner or checklist is enough.
The EU AI Act does not work that way.
AI systems are behavioural, dynamic and context‑dependent. Their outputs change with prompts, updates, workflows and user interaction. Because of this, no single tool can certify compliance. The Act requires evidence of how your system behaves in real‑world conditions — not a dashboard, not a static audit, not a one‑click scan.
If you want to comply with the Act, you need a testing methodology, not a compliance tool.
A methodology provides:
This is what the Act expects, and it is the part most organisations are missing. Compliance comes from how you test, not what you install.
The EU AI Act is built around one expectation: organisations must show how their AI systems behave in real‑world conditions. Governance and documentation matter, but neither replaces behavioural evidence. Without testing, there is nothing meaningful to verify.
Regulators look for three things:
This is why testing is the core of compliance. It reveals drift, instability, failure modes and workflow‑specific risks — the issues that lead to regulatory breaches.
Compliance is not achieved through checklists or dashboards. It is achieved through evidence of behaviour, gathered through disciplined, repeatable testing.
Organisations preparing for compliance can use the following practical resources from Inquisitor Labs:
A structured, question‑driven tool to determine whether the Act applies to your system and what obligations follow.
EU AI Act Compliance Starter Pack
A practical, fast‑start guide covering system categories, documentation requirements, organisational readiness and real‑world obligations.
This book provides the complete methodology, detailed examples and practical guidance for meeting the Act’s testing, documentation and monitoring requirements.
Many organisations believe the EU AI Act does not apply to them. This is almost always due to the wording used in headlines and summaries. Terms like high risk, critical infrastructure or financial services lead people to assume that only specialised industries are affected.
The reality is far simpler. If AI is knowingly or unknowingly used in making a decision that affects an EU citizen, the organisation is in scope. It does not matter whether the company is in a regulated sector or whether the AI system is formally deployed.
Common examples include sorting CVs, drafting appraisal emails, preparing internal reviews or submitting almost any kind of formal application or assessment. If AI touches the workflow, the Act applies.
The obligations come from the decisions AI influences, not the sector you operate in.
Shadow workflows occur when employees use AI informally, casually or privately to make their work faster or easier. This includes freely available chatbots, browser extensions, mobile apps or any AI tool used outside official channels.
Most organisations have no idea this is happening. Fewer still have asked their staff directly. Even fewer have checked whether AI is being used in ways that create legal exposure under the EU AI Act.
The risk is simple. If an employee uses AI to help produce or influence a decision that affects an EU citizen, the organisation is in scope - even if management did not approve the AI, did not know it was being used or did not intend for AI to be part of the workflow.
The solution is equally simple. Ask employees whether they use AI informally. Document the answers. Test the workflows for accuracy and compliance. If everything is documented and the workflows are robustly evaluated, the organisation will meet its obligations under the Act.
Shadow workflows are not a technical problem. They are a behavioural and organisational one. They are also a major product opportunity.
The EU AI Act is the first major regulation of its kind, but it will not be the last. The UK, US and Canada are already drafting legislation that mirrors its focus on testing, evaluation, documentation and oversight.
Preparing for the EU AI Act prepares you for global compliance.
For deeper, practical guidance on specific parts of the Act, see the following pages:
Each page provides focused, practical guidance designed for developers and organisations preparing for compliance.
(C) William Argo