EU AI Act
source (as amended) ↗EUR-LexAmended by Regulation (EU) 2026/1744. Verified 16 Aug 2026: the popular mirrors have not yet been updated — artificialintelligenceact.eu still serves the unamended 13 June 2024 text with no disclaimer, and the Commission's AI Act Service Desk pages still show pre-omnibus text with a visible omnibus disclaimer. Read the OJ or consolidated text on EUR-Lex.Horizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Art. 50 → 2 Aug 2026, Annex III → 2 Dec 2027, Annex I → 2 Aug 2028). (Digital Omnibus: Regulation (EU) 2026/1744, in force 27 July 2026).
39 components31 articles / obligations68 triggering use casesopen in graph WORM / Immutable Audit Vault
71% of use casesAppend-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
HITL Escalation Queue & Review UI
54% of use casesHITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
Kill Switch / Graceful Degradation
54% of use casesOperator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
Confidence Scoring & Threshold Gate
49% of use casesComputes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.
Explainability API (SHAP/LIME/CoT)
47% of use casesFeature attributions for classical ML, reasoning-trace summaries for GenAI — feeds the human reviewer and the technical file.
Bias Testing & Data Quality Pipeline
46% of use casesRepresentativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.
Data Lineage & Versioning
44% of use casesProvenance tracking of datasets, features and embeddings; write-time attribution (source, actor, timestamp, confidence).
OpenTelemetry / FCoT Tracing
35% of use casesHierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.
Trust & Risk Dual Scoring
31% of use casesEscalation triggers built from two independent signals, because raw model confidence is uncalibrated: calibrated trust scores (prompt relevance, similarity to historic successes, cross-model consistency) plus deterministic risk scores (sensitive categories, transaction value, protected data) — either crossing its threshold forces human review.
Output Rails / Groundedness Check
29% of use casesFaithfulness scoring of answers against retrieved sources; deterministic fallback instead of hallucination; schema-validated structured output.
PII Scrubbing / DLP-NER Layer
29% of use casesAutomated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.
Adverse-Decision Reason Generator
28% of use casesPractice-derived component: converts feature attributions (SHAP or an equivalent attribution method) into an individually understandable, legally defensible explanation of an adverse decision — the role the AI system played, the main elements the decision rested on, and counterfactual scenarios stating what would have had to differ for a different outcome. Reason codes are generated from the decisioning path, not from a marketing template, and every issued letter is retained with the model version and the attribution run behind it. Honesty condition: a reason is only usable if acting on it would actually change the outcome, which non-monotonic feature interactions can break (see the post-hoc instability threat).
Retrieval Rails (ACL-aware RAG)
28% of use casesRelevance, freshness and per-user permission checks on every retrieved chunk; curated, versioned index.
Deterministic Policy Engine (OPA / Cedar)
26% of use casesPolicy-as-code decision point (PDP) with enforcement points (PEP) in front of every tool call: versioned policies in Git, microsecond evaluation, typed action schemas — authorization decided outside the model's reasoning space, never in the prompt.
Multi-Model Router & Fallback Abstraction
26% of use casesAbstraction layer decoupling application logic from model providers: dynamic routing on capability, cost, latency SLA and regulatory constraint (sensitive-data classes pinned to ZDR private/VPC endpoints or on-prem open-weight instances); real-time health monitoring with automatic fallback to secondary endpoints or local fine-tuned models on outage/latency spikes. Discharges resilience duties (DORA-class), prevents provider lock-in, and makes model deprecations a routing-table change instead of a re-architecture. Router decisions are logged into the decision trace — model version per event is an audit-packet field.
Input Rails / Prompt Shields
24% of use casesPre-model validation of user input: injection detection, topic blocking, encoding checks.
- article obligationArt. 15 — Accuracy, Robustness, Cybersecurity → Input Rails / Prompt ShieldsArt. 15 — Accuracy, Robustness, Cybersecurity
- control objectiveArt. 15 — Accuracy, Robustness, Cybersecurity → CO: Runtime Injection Defense → Input Rails / Prompt ShieldsArt. 15 — Accuracy, Robustness, CybersecurityCO: Runtime Injection Defense
- evidence artefactArt. 15 — Accuracy, Robustness, Cybersecurity → Guardrail Telemetry & Sanitization Records → produced by Input Rails / Prompt ShieldsArt. 15 — Accuracy, Robustness, CybersecurityGuardrail Telemetry & Sanitization Records
Synthetic-Content Labelling / Watermarking
24% of use casesSynthetic-content labelling & watermarking: visible disclosure plus machine-readable provenance (C2PA Content Credentials) embedded in generated images, audio and video; metadata identifying artificial origin survives common transformations. Discharges Art. 50(2)/(4) for deepfakes and synthetic media; verification telemetry (watermark presence/validity checks at publication gates) is the corresponding evidence stream.
Watchdog Supervisor & Rate Limiting
19% of use casesCost/iteration caps, loop detection, anomaly-triggered mandatory approval (CodeBuddy 'suspicious command override').
Sovereign Context Layer
15% of use casesGoverned runtime workspace operationalizing Art. 10: traceable lineage for every RAG chunk and training record at execution time, canonical version-controlled business glossary (documents Art. 10(2)(d) baseline assumptions), and continuous data-quality monitoring with threshold alerts and logged remediation for the Art. 10(3) 'error-free and complete' standard.
Agent Identity & Access (IdP)
13% of use casesPer-agent identities, short-lived scoped tokens, OBO flow enforcement — the identity substrate of agentic zero trust.
Central Credential Vault
13% of use casesAgents never hold target-system keys; the gateway injects centrally managed credentials after policy checks.
Model Drift & Accuracy Monitor
13% of use casesContinuous evaluation against golden sets and sampled human verdicts; raises drift alerts and feeds the recertification cycle.
AI Register & Model Registry / Factsheets
12% of use casesAI register & model registry: central inventory of every model, agent, RAG pipeline and embedded third-party SaaS AI across the estate, with factsheets per asset. v2.0 duty: every application — internal, open-source or procured — continuously publishes a machine-readable AI-BOM and Factsheet into the register; an asset without a current AI-BOM is an inventory gap, not a formality. Feeds Colorado AIA/ LL144 disclosure duties and the Art. 11 technical file; the enforcement backstop is Shadow-AI discovery on the risk register.
Vendor & Model Due-Diligence Kit
12% of use casesScoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.
Confidential Computing Enclaves
12% of use casesAMD SEV / Intel TDX: data protected from the cloud operator even in memory during inference.
PII/PHI Redaction & Tokenisation Engine
10% of use casesThe engine behind inline tokenisation: pre-model interception that replaces identifiers with reversible tokens before a payload leaves the isolation boundary, plus a detokenisation gate that re-identifies only for authorised callers inside the boundary and logs every re-identification. Complements the DLP/NER scrubbing layer, which blocks or masks rather than preserving reversible reference.
Agent Memory Record Store
7% of use casesAgent conversational and working memory managed as a books-and-records object rather than a cache: retention schedules per regime, immutability where records rules demand it, deletion paths for erasure requests that do not break the audit trail, and export in a form a supervisor can read. Where an agent's memory carries a business communication or a decision rationale, it is a record — the storage tier does not decide that.
Interface Transparency & Content-Marking Layer
6% of use casesThe disclosure surface at the engagement layer: an AI-interaction notice on every channel a natural person can reach (web, app, voice, chat, social, marketplace), machine-readable provenance marking on generated or manipulated output, and a disclosure record per interaction that can be produced on request. Sits at the interface, not in the model — a model-side label that the frontend drops is not a disclosure.
SBOM & Dependency Management
6% of use casesSoftware bill of materials incl. model weights and datasets; automated vulnerability patching pipeline.
Tool-Use Boundary Proxy
6% of use casesEvery agent action leaves through one interception point that validates the call against a declared schema and an allow-list of permitted effects, rejects out-of-contract arguments, and records the attempt whether it passed or not. Turns 'the agent may call the payment API' into 'the agent may call this method, with these fields, inside these limits'.
Non-Human Identity Credential Broker
6% of use casesIssues ephemeral, per-task, narrowly scoped credentials to agents and revokes them on task completion, escalation or anomaly — the 'no standing credentials' principle in a component. Distinct from the credential vault (which holds long-lived secrets centrally): the broker's product is a credential that expires before it can be exfiltrated and reused.
Unified Incident-Response Runbook
4% of use casesOne procedure reconciling AI Act Art. 73, GDPR Art. 33 (72h), DORA and NIS2 (24h/72h) timelines and recipients.
Visual Explainability for Clinical Review
3% of use casesPractice-derived component: saliency, heatmap or region-proposal overlays rendered on the study itself, so the reviewing clinician can check the anatomical plausibility of the finding — whether the model looked where the pathology is — instead of accepting a score. Overlay stability across reconstructions is monitored, because an unstable overlay is a false assurance rather than an explanation.
- article obligationArt. 13 — Transparency to Deployers → Visual Explainability for Clinical ReviewArt. 13 — Transparency to DeployersVisual explainability for clinical review answers Art. 13 in an imaging context; conditioned for the same reason as the DICOM edges.
- article obligationArt. 14 — Human Oversight → Visual Explainability for Clinical ReviewArt. 14 — Human OversightSurfaced on CV screening in Study 6, where clinical review has no meaning.
Live Risk Register / Posture Management
1% of use casesContinuously updated risk register wired to runtime posture: threat-model deltas, open defects, control status, exposure per system. Includes Shadow-AI discovery — continuous scanning for unsanctioned agents, MCP servers and AI API usage outside the register; an unregistered agent is an unmanaged Art. 12/26 liability and the empirical driver of proportionate (not blanket) controls.
AI Intake Portal & Use-Case Triage
1% of use casesThe operational front door of the translational pipeline: structured intake profile (business objective, autonomy degree, data sensitivity, deployment context, target users) → automated tier proposal (detectors + evaluator pipeline) → risk-proportionate approval workflow → register entry with AI-BOM stub. Prevents both over-engineering (blanket high-tier controls breed Shadow AI) and under-engineering (unassessed high-risk deployment). Every governance framework assumes it; almost no failed audit had one.
Shadow-AI Discovery & Asset Inventory Scanner
1% of use casesContinuous, automated discovery of models, agents and LLM API calls across source repositories, cloud accounts, the CMDB and the employee SaaS footprint, reconciled into the AI register rather than collected by survey. It is the population-finding element: every inventory, assessment and vendor-governance duty is scoped against a set of systems, and a self-declared set is systematically short. Testable: run discovery against an estate containing one deliberately unregistered LLM integration and confirm it appears in the register within one sweep, attributed to an owner.
Sovereign Deployment Boundary
1% of use casesJurisdictional isolation as an architectural boundary: compute, storage, backups, keys, operational metadata and control-plane administration held inside the target jurisdiction and operated by personnel subject to its law. The honest caveat is the control plane and metadata — a workload can sit in-region while telemetry, support access or identity services do not. Attestation surface: BSI C5, BSI C3A, ANSSI SecNumCloud.
External Trust Anchor (Qualified Timestamp / Ledger)
0% of use casesTakes integrity proofs out of the operator's trust domain: periodic anchoring of log hash-chain heads via qualified electronic timestamps or a (qualified) electronic ledger per eIDAS 2, with signing keys held outside the operating team (key ceremony, HSM, separation of duties). Answers the insider test — a party who controls the vault cannot rewrite history without the anchor exposing it. Cost profile: anchoring is periodic and cheap; it upgrades every downstream log-based artifact at once.
Agent Discovery & Registry Endpoint
0% of use casesThe marketplace/discovery API through which external agents find, authenticate against and transact with your agents: published capability descriptors, counterparty authentication, per-counterparty rate and value limits, and a resolvable record of which external principal initiated which transaction. Without it, business-to-agent traffic is anonymous inbound automation.
- article obligationArt. 25 — Value Chain / Role Flip → Agent Discovery & Registry EndpointArt. 25 — Value Chain / Role Flipattribution across the value chain when an external agent transacts