Regulation
EU AI Act
From 2 August 2026 the record-keeping, security and human-oversight obligations for high-risk AI systems apply. What they have in common is that every one of them asks for evidence.
What is at stake here.
The logging has to be automatic
A high-risk system has to record events automatically over its lifetime. A chat transcript does not meet that: it carries no record of why a decision was taken.
The provider's security is not your control
A model's own safety training is the provider's decision and changes with each version. The control you are accountable for has to live in a layer of its own.
Human oversight needs visibility
For a person to intervene they must be able to see what happened. Oversight of a flow nobody can see exists only on paper.
Why it is not optional
The obligation sits with you, not with the model provider.
Where a legal duty is the reason, the article is named. No penalty figures and no circular numbers — those change, and a marketing page is the wrong place to be wrong about them.
Record-keeping is an evidence obligation
Automatic record-keeping for high-risk systems is set out in the Regulation's record-keeping article. The existence of the record is looked for as much as the control itself.
Cybersecurity is named explicitly
Accuracy, robustness and cybersecurity form a heading of their own for high-risk systems. Defending against prompt injection falls under it.
The date is close, and it is phased
The Regulation applies in phases; most obligations for high-risk systems take effect on 2 August 2026. Which phase covers you depends on how your system is classified.
Use cases
What actually happens in the day's work.
These are mechanisms, not case studies. Each one is a concrete thing somebody does, and what the chain does about it.
An auditor asks for the record
Situation
Someone asks which decisions the system took in a given period, and what they rested on.
What happens
Every decision is written as an event: who asked, from which department, which rule fired, what was masked, when. A date-ranged evidence pack is produced as PDF or CSV.
The data must not leave the EU
Situation
The model in use is in the cloud, on servers in another jurisdiction.
What happens
In local-model mode no request leaves the machine; where cloud is used, personal data is masked at the prompt before it is sent.
The model provider changes
Situation
Cost or contract terms force a change of provider. Do the compliance controls have to be rebuilt?
What happens
No. The control layer sits in front of the model; changing provider is a setting, and leaves the policy and the record untouched.
The answer
Which part of the product responds.
Configuration
Recommended starting posture.
These are starting recommendations; the final policy is written with you during setup.
- If the policy cannot be read
- stop
- Deployment
- VPC inside the EU, or on-premise
The rules get written together
The rules for this sector are written with you during onboarding: blocked phrases, the competitor list and the entity rules are set against your own processes. Instead of adapting someone else's template, you start with a policy that is genuinely yours — and it goes live only after being tried in the simulation that runs without saving.
Other regulation pages
Let's talk through your own scenario.
In a 30-minute technical session we run your prompts and your policy through it live.