EU AI Act
source ↗EUR-LexHorizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Annex III → 2 Dec 2027, Annex I → 2 Aug 2028).
28 components17 articles / obligations34 triggering use casesopen in graph WORM / Immutable Audit Vault
62% of use casesAppend-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
Kill Switch / Graceful Degradation
56% of use casesOperator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
HITL Escalation Queue & Review UI
53% of use casesHITL escalation queue & review UI ('Human-as-a-Tool': the agent calls the human like any other tool via propose-action objects). Confidence- and risk-threshold routing, SLA timers, structured accept/modify/reject verdicts with digital reviewer signature at gate release — each verdict is itself Art. 14 evidence and feeds the active-learning loop.
Confidence Scoring & Threshold Gate
53% of use casesComputes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.
Multi-Model Router & Fallback Abstraction
50% of use casesAbstraction layer decoupling application logic from model providers: dynamic routing on capability, cost, latency SLA and regulatory constraint (sensitive-data classes pinned to ZDR private/VPC endpoints or on-prem open-weight instances); real-time health monitoring with automatic fallback to secondary endpoints or local fine-tuned models on outage/latency spikes. Discharges resilience duties (DORA-class), prevents provider lock-in, and makes model deprecations a routing-table change instead of a re-architecture. Router decisions are logged into the decision trace — model version per event is an audit-packet field.
OpenTelemetry / FCoT Tracing
47% of use casesHierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.
PII Scrubbing / DLP-NER Layer
44% of use casesAutomated detection, pseudonymisation and blocking of personal data in inputs, retrievals and outputs.
Input Rails / Prompt Shields
38% of use casesPre-model validation of user input: injection detection, topic blocking, encoding checks.
- article obligationArt. 15 — Accuracy, Robustness, Cybersecurity → Input Rails / Prompt ShieldsArt. 15 — Accuracy, Robustness, Cybersecurity
- control objectiveArt. 15 — Accuracy, Robustness, Cybersecurity → CO: Runtime Injection Defense → Input Rails / Prompt ShieldsArt. 15 — Accuracy, Robustness, CybersecurityCO: Runtime Injection Defense
- evidence artefactArt. 15 — Accuracy, Robustness, Cybersecurity → Guardrail Telemetry & Sanitization Records → produced by Input Rails / Prompt ShieldsArt. 15 — Accuracy, Robustness, CybersecurityGuardrail Telemetry & Sanitization Records
Output Rails / Groundedness Check
38% of use casesFaithfulness scoring of answers against retrieved sources; deterministic fallback instead of hallucination; schema-validated structured output.
Synthetic-Content Labelling / Watermarking
38% of use casesSynthetic-content labelling & watermarking: visible disclosure plus machine-readable provenance (C2PA Content Credentials) embedded in generated images, audio and video; metadata identifying artificial origin survives common transformations. Discharges Art. 50(2)/(4) for deepfakes and synthetic media; verification telemetry (watermark presence/validity checks at publication gates) is the corresponding evidence stream.
Retrieval Rails (ACL-aware RAG)
38% of use casesRelevance, freshness and per-user permission checks on every retrieved chunk; curated, versioned index.
Deterministic Policy Engine (OPA / Cedar)
32% of use casesPolicy-as-code decision point (PDP) with enforcement points (PEP) in front of every tool call: versioned policies in Git, microsecond evaluation, typed action schemas — authorization decided outside the model's reasoning space, never in the prompt.
Bias Testing & Data Quality Pipeline
29% of use casesRepresentativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.
Explainability API (SHAP/LIME/CoT)
29% of use casesFeature attributions for classical ML, reasoning-trace summaries for GenAI — feeds the human reviewer and the technical file.
Watchdog Supervisor & Rate Limiting
26% of use casesCost/iteration caps, loop detection, anomaly-triggered mandatory approval (CodeBuddy 'suspicious command override').
Central Credential Vault
26% of use casesAgents never hold target-system keys; the gateway injects centrally managed credentials after policy checks.
Trust & Risk Dual Scoring
26% of use casesEscalation triggers built from two independent signals, because raw model confidence is uncalibrated: calibrated trust scores (prompt relevance, similarity to historic successes, cross-model consistency) plus deterministic risk scores (sensitive categories, transaction value, protected data) — either crossing its threshold forces human review.
Data Lineage & Versioning
24% of use casesProvenance tracking of datasets, features and embeddings; write-time attribution (source, actor, timestamp, confidence).
Model Drift & Accuracy Monitor
24% of use casesContinuous evaluation against golden sets and sampled human verdicts; raises drift alerts and feeds the recertification cycle.
Sovereign Context Layer
21% of use casesGoverned runtime workspace operationalizing Art. 10: traceable lineage for every RAG chunk and training record at execution time, canonical version-controlled business glossary (documents Art. 10(2)(d) baseline assumptions), and continuous data-quality monitoring with threshold alerts and logged remediation for the Art. 10(3) 'error-free and complete' standard.
Vendor & Model Due-Diligence Kit
18% of use casesScoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.
Confidential Computing Enclaves
18% of use casesAMD SEV / Intel TDX: data protected from the cloud operator even in memory during inference.
SBOM & Dependency Management
9% of use casesSoftware bill of materials incl. model weights and datasets; automated vulnerability patching pipeline.
AI Register & Model Registry / Factsheets
6% of use casesAI register & model registry: central inventory of every model, agent, RAG pipeline and embedded third-party SaaS AI across the estate, with factsheets per asset. v2.0 duty: every application — internal, open-source or procured — continuously publishes a machine-readable AI-BOM and Factsheet into the register; an asset without a current AI-BOM is an inventory gap, not a formality. Feeds Colorado AIA/ LL144 disclosure duties and the Art. 11 technical file; the enforcement backstop is Shadow-AI discovery on the risk register.
Live Risk Register / Posture Management
3% of use casesContinuously updated risk register wired to runtime posture: threat-model deltas, open defects, control status, exposure per system. Includes Shadow-AI discovery — continuous scanning for unsanctioned agents, MCP servers and AI API usage outside the register; an unregistered agent is an unmanaged Art. 12/26 liability and the empirical driver of proportionate (not blanket) controls.
Unified Incident-Response Runbook
3% of use casesOne procedure reconciling AI Act Art. 73, GDPR Art. 33 (72h), DORA and NIS2 (24h/72h) timelines and recipients.
External Trust Anchor (Qualified Timestamp / Ledger)
0% of use casesTakes integrity proofs out of the operator's trust domain: periodic anchoring of log hash-chain heads via qualified electronic timestamps or a (qualified) electronic ledger per eIDAS 2, with signing keys held outside the operating team (key ceremony, HSM, separation of duties). Answers the insider test — a party who controls the vault cannot rewrite history without the anchor exposing it. Cost profile: anchoring is periodic and cheap; it upgrades every downstream log-based artifact at once.
AI Intake Portal & Use-Case Triage
0% of use casesThe operational front door of the translational pipeline: structured intake profile (business objective, autonomy degree, data sensitivity, deployment context, target users) → automated tier proposal (detectors + evaluator pipeline) → risk-proportionate approval workflow → register entry with AI-BOM stub. Prevents both over-engineering (blanket high-tier controls breed Shadow AI) and under-engineering (unassessed high-risk deployment). Every governance framework assumes it; almost no failed audit had one.