Skip to content
Back to home

§ COMPLIANCE · EU AI ACT

EU AI Act compliance with Execlave

Article-by-article mapping of Execlave controls to the EU AI Act. Not legal advice — an engineering reference for teams that need evidence an auditor will accept.

§ 01

Scope

Who the Act applies to and what Execlave takes off your plate.

Regulation (EU) 2024/1689 creates a risk-tiered framework for AI systems placed on the EU market. High-risk systems (Annex III) carry the heaviest obligations: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy and robustness, cybersecurity, and post-market monitoring. Providers of general-purpose AI models face a separate set of obligations that began 2 August 2025.

This page is a practical engineering reference. It pairs the articles most operators actually care about with the Execlave control that produces the evidence an auditor will ask for.

§ 02

Article-by-article mapping

One card per article. Where an article has multiple sub-clauses, we cover the ones that are implementable at runtime.

Article 9 — Risk management

  • 19 built-in policy types covering prompt injection, data access, cost, quality, tools, response groundedness, OPA Rego, and agent lineage.
  • Four enforcement modes — monitor, warn, require_approval, block.
  • Incident tracking with severity, timeline, and resolution workflow.
  • Budget enforcement at the agent and organisation level.
EvidenceSigned compliance report (policy inventory + incident timeline) — GET /api/v1/compliance/report, §03 below.

Article 10 — Data governance

  • SDK PII scrubbing across 14 categories before data leaves your process.
  • Input sanitisation middleware on every ingest endpoint.
  • EU data residency on enterprise tier — storage and processing inside the EU.
EvidenceData-access lineage spans on each trace (sources, fields, classifications — never values). See Data Access Lineage.

Article 12 — Record-keeping

  • Every agent execution traced with input, output, model, tokens, cost, latency.
  • Append-only audit log; UPDATE/DELETE blocked at DB trigger level.
  • Hash-chained entries — tampering is detectable offline.
  • Retention configurable up to 10 years (Article 19 aligned).
EvidenceAudit-log CSV/JSON export for any window; hash chain verifiable offline without contacting Execlave.

Article 13 — Transparency

  • Every enforcement decision carries a human-readable reason and rule IDs.
  • Agent cards expose capabilities, tools, and policy summary.
EvidenceTrace export — each enforcement decision with its reason and rule IDs; agent passport for system description.

Article 14 — Human oversight

  • Kill switch from dashboard or Slack.
  • require_approval mode halts execution until a human decides.
  • Approval expiry (default 30m) prevents indefinitely hung requests.
  • Real-time dashboard view of every pending decision.
EvidenceApproval records — human identity, timestamp, decision — in the audit log; see approval workflows.

Article 15 — Accuracy, robustness, cybersecurity

  • Client-side and server-side prompt-injection scanning with severity scoring.
  • Semantic enforcement tiers beyond pattern matching.
  • Quality thresholds enforced per policy.
  • Circuit breaker in both SDKs; PostgreSQL RLS for tenant isolation.
EvidenceInjection-scan verdicts on traces; red-team gate results per agent release.

Article 17 — Quality management

  • Policy versioning with before/after audit entries.
  • Prompt versioning captured in the SDK for every trace.
  • Deployment tracking as a first-class entity with approval trail.
EvidencePolicy version history — before/after audit entries for every change, exportable per policy.

Article 19 — Automatically generated logs

  • Default 1-year retention; 10 years on enterprise.
  • CSV and JSON exports for any window.
  • RSA-SHA256 signed PDF/HTML reports for regulator-facing disclosure.
EvidenceSigned report carries its own signatureInfo (signature, public key, algorithm) and verifies offline — §03 below.

Article 26 — Deployer obligations

  • Per-agent request volume, token, and cost metering.
  • EWMA anomaly detection with seasonal decomposition.
  • Webhook / Slack alerts on configurable thresholds.
EvidenceUsage metering exports + SIEM stream (Splunk, Sentinel); serious-incident runbook in the incident response workflow.

Article 50 — Transparency to end users

  • SDK emits a provenance header on every response for downstream watermarking.
  • Agent identity surfaced for user-facing disclosure banners.
EvidenceProvenance header documented in the SDK reference; per-trace agent identity in every export.

Article 72 — Post-market monitoring

  • Continuous trace collection over the agent's lifetime — every execution, not a sample.
  • EWMA anomaly detection with seasonal decomposition flags performance deviation from baseline.
  • Drift signal detects behavioral change — new tool usage, denial-rate shifts, new data classes — and can downgrade the agent's autonomy on high-severity drift.
  • Alerting on violation bursts and budget burn via email, Slack, or webhook.
EvidenceDrift signal events + anomaly detections, streamable to your SIEM (Splunk, Sentinel) as the monitoring-plan record.
§ 03

Generating an EU AI Act report

The compliance export endpoint produces a signed, time-bounded report mapping evidence back to each Article.

Signed compliance report request (admin role)

GET /api/v1/compliance/report?from=2026-01-01&to=2026-03-31&frameworks=eu_ai_act&format=jsonAuthorization: Bearer exe_prod_... # format=html and format=pdf return the rendered document as a download;# format=json returns the signed, machine-readable report below.

JSON response (abridged)

{  "data": {    "frameworks": ["eu_ai_act"],    "auditPackage": {      "chainValid": true,      "totalEntries": 18342,      "packageHash": "9f2c…e41a"    },    "signatureInfo": {      "signature": "MEUCIQ…(base64)",      "publicKey": "-----BEGIN PUBLIC KEY-----…",      "algorithm": "RSA-SHA256-PSS",      "signedAt": "2026-04-01T00:00:00.000Z"    }  },  "meta": { "savedReportId": "…" }}

The JSON report embeds everything needed for verification: signatureInfo carries the RSA-SHA256 (PSS padding) signature over the canonical report payload, the signing public key, and the timestamp, while auditPackage.chainValid attests the underlying audit log's hash chain. A third party can verify the package offline with any standard RSA library, or via the verification endpoint:

Signature verification

POST /api/v1/compliance/verify-signatureContent-Type: application/json { "report": { …the report object… }, "signature": "MEUCIQ…", "publicKey": "-----BEGIN PUBLIC KEY-----…" } # → { "data": { "valid": true, "verifiedAt": "2026-04-01T00:00:05.123Z" } }
§ 04

Deadlines

The dates that belong on your roadmap.

DateApplies toWhat to have ready
2 February 2025Any AI system placed on the EU marketProhibited-use controls (social scoring, manipulative profiling, predictive policing, untargeted biometric scraping, real-time public biometric ID) plus AI literacy obligations.
2 August 2025Providers of general-purpose AI modelsTechnical documentation, training-data summary, downstream-operator cooperation, copyright-compliance policy. GPAI models already on the market by this date have until 2 Aug 2027.
2 August 2026 (as adopted)Providers and deployers of high-risk AI systems under Annex IIIFull Article 9–17 stack: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, post-market monitoring. This is the date in the Act as adopted — see the proposed Omnibus postponement below.
2 December 2027 (proposed)Providers and deployers of high-risk AI systems under Annex IIIPostponed date under the provisional May 2026 "Omnibus" simplification agreement. Not yet binding — it takes effect only once formally adopted and published in the EU Official Journal. Until then, plan against the 2 August 2026 date above.
2 August 2027High-risk AI that is a safety component of a regulated product under Annex I (medical devices, machinery, IVDs, etc.)Conformity assessment aligned with the existing product-safety regime, plus the full high-risk stack. Pre-existing GPAI models also reach their compliance deadline on this date.
§ 05

Engineering checklist

A pragmatic subset to tackle first. Execlave ships each of the below out of the box.

Eight controls that move the needle

  • Every tool call passes through a policy engine with a recorded decision.
  • Every override approval is tied to a human identity and a timestamp.
  • Audit logs are append-only and retained ≥ 1 year, ideally 10.
  • PII is hashed at the boundary — never stored in the trace body.
  • A kill switch can stop any agent within seconds.
  • Every released agent has a prompt version, a policy version, a deployment record.
  • Compliance reports are generated on demand and verifiable offline.
  • An SBOM is produced for every SDK release and archived for 10 years.

If you build this yourself, budget 3–6 months and a dedicated engineer.

EU AI Act compliance — Execlave Docs