EU AI Act
Regulation (EU) 2024/1689 - High-risk AI system obligations: 2 December 2027 (standalone Annex III) / 2 August 2028 (Annex I embedded) - pending Council adoption and OJ publication
The EU AI Act (Regulation 2024/1689) is the first comprehensive AI regulation. A Digital Omnibus amendment, the subject of a provisional political agreement on 7 May 2026 and approved by the European Parliament on 16 June 2026 (423 in favour, 57 against, 174 abstentions), would defer high-risk AI system obligations to two-tier application dates: 2 December 2027 for standalone high-risk systems listed in Annex III, and 2 August 2028 for AI systems embedded as safety components covered by EU sectoral legislation (Annex I). At the time of writing these dates are pending formal Council adoption and Official Journal publication, so treat them as proposed rather than settled. GPAI model obligations under Articles 51-56 were not deferred and remain in force from 2 August 2025.
Asqav signs every agent action with ML-DSA signatures and generates Article 12 and Article 14 compliance reports with PDF export.
The Asqav receipt format is profiled in IETF Internet-Draft draft-marques-asqav-compliance-receipts, which binds the underlying signed-receipt format to Articles 12 and 26 of the EU AI Act with field-level MUST clauses.
Requirements
| Article | Requirement | Asqav binding |
|---|---|---|
| Art. 9 | Continuous risk management across the AI system lifecycle. | Policy enforcement gates agent actions. Immutable audit trail captures every action for monitoring. |
| Art. 12 | Automatic event logging with traceability. | Every action signed with ML-DSA. Article 12 compliance reports generated via API. |
| Art. 13 | Operational transparency for deployers. | Signed action history shows what each agent did, when, and why. Audit export available. |
| Art. 14 | Effective human oversight and override. | Multi-key human approval for sensitive actions, instant agent revocation, policy guardrails. Article 14 reports on demand. |
| Art. 17 | Quality management with record-keeping procedures. | Systematic audit trail and compliance reporting feed QMS documentation. |
| Art. 19 | Retain automatically generated logs for at least six months. | Configurable retention: 30 days on Free, custom on Enterprise. Cryptographic proofs prevent tampering. |
| Art. 26 | Deployers must monitor operation and retain logs. | Audit export for retention. Any log entry can be independently verified at the public verification endpoint. |
Bring-your-own KMS, customer-owned storage, and air-gapped on-prem mode are all available for institutions with no-egress requirements. Full mapping detail in the docs.