Skip to content
Confir.
Tools & Comparisons

Snowflake Cortex and the EU AI Act: Governed Data Doesn't Make You Compliant

AI Tool Compliance4 August 2026· 11 min read

Build with Snowflake Cortex LLM functions or ML? Under the EU AI Act you are the provider (Article 16). Governed data helps Article 10, never replaces it.

You run a COMPLETE call over a tagged, masked, access-controlled table and assume your warehouse governance has already discharged the EU AI Act. It has not. Regulation (EU) 2024/1689 regulates the AI system you composed and its intended purpose — not the SQL function, the compute, or the column tags you applied for GDPR. This page covers who the provider is, how to classify the system, and why governed data is a head start on the evidence, never a substitute for the obligation.


Cortex runs AI inside your warehouse — and the Act attaches to the system, not the SQL

Snowflake Cortex brings LLM functions (such as COMPLETE, SENTIMENT, EXTRACT_ANSWER, TRANSLATE), Cortex Analyst, Cortex Search, and Cortex ML to the data already sitting in your governed warehouse — inference runs where the data lives, often a single SQL statement away — which gets systems built and put into service faster than governance review catches them.

Like SageMaker and Vertex, Cortex is infrastructure. The Act regulates the AI system as defined in Article 3(1) and classifies it by intended purpose under Article 6 and the Annexes — never the warehouse, the compute, or the SQL function you called. So the right question is never "does Cortex comply?" Ask instead what AI system you have built on governed data, for what purpose, and what decision it influences.


Provider or deployer? The Cortex fork depends on what you build

You build a system under your own name — you are the provider (Article 16)

Article 3(3) defines a provider as one who develops an AI system and puts it into service under its own name or trademark. Wire a Cortex LLM function or Cortex ML model into a product or an internal decision flow under your own name, and Article 16 makes you the provider — carrying risk management (Article 9), data governance (Article 10), documentation (Article 11), oversight (Article 14), conformity assessment (Article 43), and the rest of the high-risk stack.

You only call a hosted function unmodified — deployer duties (Article 26)

Call a hosted Cortex LLM function — COMPLETE on a foundation model, say — unmodified and under your own authority, and you are a deployer under Article 26: follow the provider's instructions, keep Article 14 oversight real, and retain logs for at least six months.

The role shifts under Article 25 — name, modification, or purpose change

Article 25 governs role shifts: putting your name on a high-risk system, making a substantial modification (Article 3(23)), or changing the intended purpose so it becomes high-risk turns a deployer into a provider — and a provider outside the Union must appoint an EU authorised representative under Article 22. The differentiator against SageMaker and Vertex: Cortex often blends both layers in one query — a hosted foundation model (Snowflake or the model provider carries the upstream layer) feeding a decision pipeline you designed (where you are the provider). Classify the system you composed, not the function you called.


Classify the system by intended purpose, not by the platform

High-risk via Annex III (stand-alone) — Article 6(2)

A stand-alone system is high-risk under Article 6(2) when it performs an Annex III function. The points most relevant to warehouse-native analytics: Annex III point 5 essential services — 5(b) creditworthiness and credit scoring (fraud detection excluded), 5(d) life and health insurance risk assessment and pricing; point 4 employment — 4(a) recruitment, 4(b) in-employment decisions and monitoring; point 2 critical-infrastructure safety components. Separately, Article 5 prohibitions bite regardless of tier: Article 5(1)(f) bans emotion recognition in the workplace and education, and Article 5(1)(g) bans biometric categorisation inferring sensitive attributes — relevant the moment Cortex text or sentiment functions point at employee communications.

The Article 6(3) filter and the not-high-risk majority

Article 6(3) can pull an Annex III system back out of high-risk where it performs only a narrow procedural task, improves a previously completed human activity, detects deviations without replacing human assessment, or does preparatory work — but never where it profiles natural persons. Document the assessment and still register under Article 49. Most warehouse analytics built on Cortex is not high-risk: churn scoring, demand forecasting, summarisation, internal search, marketing segmentation. There the realistic duties are Article 4 AI literacy, Article 10 data discipline, and Article 50 transparency where output reaches third parties.

The Annex I product route and the Section B carve-out

If a Cortex ML model is a safety component of a regulated product, the product route under Article 6(1) and Annex I applies. For Annex I Section A (machinery, medical devices under MDR 2017/745 and IVDR 2017/746), Article 43(3) routes conformity through the sectoral acts. For Annex I Section B (motor vehicles under Regulation (EU) 2018/858, aviation, rail, marine), Article 2(2) means only Article 6(1), Articles 102–109, and Article 112 apply directly — never the Articles 8–15, 16, and 43 stack.


Article 10 and Article 12: governed data helps, but never discharges the duty

Why warehouse governance is an input to Article 10, not a substitute

Article 10 requires training, validation, and testing datasets for high-risk systems to be relevant, representative, as error-free as possible, and complete, with examination for bias and gaps — a substantive data-quality obligation about the data feeding the decision. Snowflake's native governance — object tagging, column-level masking, row access policies, and ACCESS_HISTORY lineage — is a genuine head start on that evidence: it shows provenance, access control, and lineage of the columns feeding a Cortex function. But these are confidentiality controls; they do not establish representativeness, error-minimisation, or bias examination, which remain yours to perform and document. And because you compose the system from governed tables, there is no upstream provider to inherit Article 10 from — the obligation is yours in full. The warehouse gives you the evidence trail, not the conclusion.

Designing Cortex pipelines for Article 12 traceability

Article 12 requires high-risk systems to technically allow automatic event logging over a lifetime appropriate to the intended purpose. Cortex inference inside the warehouse is a natural logging surface: design pipelines so prediction inputs, model and function versions, outputs, and oversight events are captured from the outset — query history and ACCESS_HISTORY help. Article 11 and Annex IV documentation, retained ten years under Article 18, must still cover the model, data provenance, and the Cortex configuration; Article 15 accuracy and robustness sits at the system level, which warehouse hardening does not discharge.


Snowflake is your platform, not your conformity assessor

Snowflake's certifications and attestations cover its own platform layer and data residency. They are not a conformity assessment under Article 43 of the system you composed — the provider performs and signs that. Most stand-alone Annex III systems use the Annex VI internal self-assessment route, ending in the Article 47 EU Declaration of Conformity and Article 49 registration; biometrics generally require the Annex VII notified-body route.

Where you consume a hosted foundation model through a Cortex LLM function, the Chapter V GPAI obligations (Articles 51–55, in force since 2 August 2025) sit with that model's provider, not with you as a downstream caller. Making API or SQL calls does not cross the Article 51 systemic-risk presumption — the 10^25 FLOPs threshold targets the trainer. Confir's coverage of GPAI provider obligations is partial and on the roadmap, not complete. For public-body deployers, and private deployers in creditworthiness (5(b)) and insurance pricing (5(d)), Article 27 adds a mandatory Fundamental Rights Impact Assessment on top of the provider stack.


Worked example: a mid-size insurer scores claims with Cortex on its governed warehouse

Helvana Versicherung, an EU health-and-life insurer of roughly 900 employees and around €310 million turnover, runs Cortex Analyst and a Cortex ML model directly on its governed claims-and-policy warehouse to assess risk and price life and health cover.

The intended purpose is insurance risk assessment and pricing for natural persons — Annex III point 5(d) — so the system is high-risk under Article 6(2), and because it profiles persons the Article 6(3) exemption is unavailable. Helvana composed it under its own name, making it the provider under Article 16; its underwriters are internal deployers, so it wears both hats and Article 27 applies. With turnover above the SME thresholds, the Article 99(6) cap does not apply. Its column tags, masking, and ACCESS_HISTORY lineage give strong Article 10 provenance and Article 12 logging foundations — but it must still prove representativeness and bias examination and sign its own Article 43 assessment.

ArticleObligation for Helvana Versicherung
Article 9Risk management with bias and disparate-impact testing
Article 10Data governance over claims and policy datasets (warehouse lineage as evidence)
Article 11 / Annex IVTechnical documentation of the Cortex model, data, and configuration
Article 12Logging of scores, overrides, and oversight via query and access history
Article 13Instructions for use
Article 14Human oversight by underwriters
Article 15Accuracy, robustness, and security
Article 27Fundamental Rights Impact Assessment
Article 43 / Annex VIInternal self-assessment route
Articles 47 / 49Declaration of Conformity and EU database registration
Articles 72–73Post-market monitoring and incident reporting

Timeline and penalties: what to plan against in 2026

Article 5 prohibitions have applied since 2 February 2025 (a further CSAM/"nudifier" prohibition and Article 50 content-marking land 2 December 2026), Article 4 AI literacy since 2 February 2025, and the GPAI obligations in Articles 51–55 since 2 August 2025.

For stand-alone high-risk Annex III systems under Article 6(2), the statute read 2 August 2026. The Digital Omnibus, adopted in June 2026 — the European Parliament passed it on 16 June 2026 and the Council adopted it on 29 June 2026 — defers that to 2 December 2027, with entry into force on Official Journal publication. The deferral uses fixed calendar dates; the "stop the clock" variant was rejected, so not everything is delayed. Product-embedded Annex I systems (Article 6(1)) read 2 August 2027, deferred under the same adopted package to 2 August 2028.

Penalty tiers are set in Article 99: prohibited practices up to €35 million or 7% of total worldwide annual turnover, whichever is higher (Article 99(3)); high-risk and most obligation breaches up to €15 million or 3% (Article 99(4)); incorrect or misleading information to authorities up to €7.5 million or 1% (Article 99(5)). For SMEs and start-ups, Article 99(6) caps the fine at the lower of the percentage or the fixed amount.


How Confir helps

Register each Cortex-built system as a separate inventory entry by intended purpose — not "Snowflake Cortex" as one line item — then classify it under Article 6 and Annex III with the Article 6(3) filter and derive the provider or deployer role. Confir generates the Article 11 and Annex IV technical documentation, the Article 47 Declaration of Conformity, and an Article 27 Fundamental Rights Impact Assessment for qualifying deployers from a single plain-English intake. The synthesis engine is deterministic and rule-based — no model inference, no hallucination — so the same intake always yields the same risk tier and role, and the rule that fired is human-readable.


Frequently asked questions

Does using Snowflake Cortex make Snowflake responsible for my EU AI Act compliance?

No. Cortex is infrastructure. Compose a system on it under your own name and Article 3(3) makes you the provider; the Article 16 duties are yours. Snowflake's attestations are not an Article 43 conformity assessment.

I build with Cortex on my own governed data — am I the provider or the deployer?

Usually the provider under Article 3(3). You are a deployer (Article 26) only when you run a hosted function unmodified under someone else's name. Build and operate it internally and you wear both hats.

My Snowflake data is already governed with tags and masking — doesn't that satisfy Article 10?

No, though it helps. Tags, masking, and ACCESS_HISTORY lineage are access controls — provenance evidence. Article 10's representativeness, error-minimisation, and bias examination remain yours to perform and document.

Is a system I build on Cortex automatically high-risk?

No. It is high-risk only if it performs an Annex III function — insurance pricing 5(d), creditworthiness 5(b), employment point 4 — under Article 6(2). Most warehouse analytics is not high-risk.

What does Article 12 logging mean for a Cortex pipeline?

Article 12 needs automatic event logging. Cortex queries are a natural logging surface: capture inputs, model and function versions, outputs, and oversight events from the outset — query history and ACCESS_HISTORY help.

When do the high-risk deadlines apply to systems built on Cortex?

The statute originally read 2 August 2026 for Annex III systems. The Digital Omnibus, adopted by Parliament and Council in June 2026, defers that to 2 December 2027 — pending Official Journal publication, expected before 2 August 2026.

What are the penalties if I misclassify a Cortex-built system?

Article 99: prohibited practices up to EUR35 million or 7% of worldwide turnover (99(3)); high-risk breaches up to EUR15 million or 3% (99(4)); misleading information up to EUR7.5 million or 1% (99(5)). SMEs capped at the lower figure (99(6)).

Manage your EU AI Act compliance in one place

Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.

Start free trial →

Keep reading