Skip to content

Regulation

EU AI Act

From 2 August 2026 the record-keeping, security and human-oversight obligations for high-risk AI systems apply. What they have in common is that every one of them asks for evidence.

What is at stake here.

01

The logging has to be automatic

A high-risk system has to record events automatically over its lifetime. A chat transcript does not meet that: it carries no record of why a decision was taken.

02

The provider's security is not your control

A model's own safety training is the provider's decision and changes with each version. The control you are accountable for has to live in a layer of its own.

03

Human oversight needs visibility

For a person to intervene they must be able to see what happened. Oversight of a flow nobody can see exists only on paper.

Why it is not optional

The obligation sits with you, not with the model provider.

Where a legal duty is the reason, the article is named. No penalty figures and no circular numbers — those change, and a marketing page is the wrong place to be wrong about them.

01

Record-keeping is an evidence obligation

Automatic record-keeping for high-risk systems is set out in the Regulation's record-keeping article. The existence of the record is looked for as much as the control itself.

02

Cybersecurity is named explicitly

Accuracy, robustness and cybersecurity form a heading of their own for high-risk systems. Defending against prompt injection falls under it.

03

The date is close, and it is phased

The Regulation applies in phases; most obligations for high-risk systems take effect on 2 August 2026. Which phase covers you depends on how your system is classified.

Use cases

What actually happens in the day's work.

These are mechanisms, not case studies. Each one is a concrete thing somebody does, and what the chain does about it.

An auditor asks for the record

Situation

Someone asks which decisions the system took in a given period, and what they rested on.

What happens

Every decision is written as an event: who asked, from which department, which rule fired, what was masked, when. A date-ranged evidence pack is produced as PDF or CSV.

The data must not leave the EU

Situation

The model in use is in the cloud, on servers in another jurisdiction.

What happens

In local-model mode no request leaves the machine; where cloud is used, personal data is masked at the prompt before it is sent.

The model provider changes

Situation

Cost or contract terms force a change of provider. Do the compliance controls have to be rebuilt?

What happens

No. The control layer sits in front of the model; changing provider is a setting, and leaves the policy and the record untouched.

Configuration

Recommended starting posture.

These are starting recommendations; the final policy is written with you during setup.

If the policy cannot be read
stop
Deployment
VPC inside the EU, or on-premise

The rules get written together

The rules for this sector are written with you during onboarding: blocked phrases, the competitor list and the entity rules are set against your own processes. Instead of adapting someone else's template, you start with a policy that is genuinely yours — and it goes live only after being tried in the simulation that runs without saving.

Other regulation pages

    Let's talk through your own scenario.

    In a 30-minute technical session we run your prompts and your policy through it live.