Governance
EU
Imminent

EU AI Act (Regulation (EU) 2024/1689)

The world's most consequential AI law; turnover-based fines. Art. 12 logging + Art. 19 log keeping + Art. 14 human oversight map directly to RECORD + ALLOW.

Read the authoritative text, EUR-Lex — Official Journal of the European Union

Human oversight: intervene/override/halt

Art. 14
Fully covered
Allow

… to intervene in the operation of the high-risk AI system or interrupt the system through a ‘stop’ button or a similar procedure that allows the system to come to a halt in a safe state.Art. 14(4)(e)

How VisIQ helps comply

HITL gate + deny at the enforcement point, plus a per-agent kill switch that terminally blocks the agent in any mode.

Automatic event logging + retention

Art. 12 / 26(6)
Fully covered
Record

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.Art. 12(1)

How VisIQ helps comply

Merkle+TSA signed audit; the signed receipts sit outside the plan retention window while the queryable log follows it: 30 days on the default tier, 365 on Team, custom on Enterprise.

Log immutability hardening

Art. 12
Fully covered
Record

In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for … identifying situations that may result in the high-risk AI system presenting a risk …Art. 12(2)

How VisIQ helps comply

The signed receipt chain is append-only with a content hash fixed at ingest; the queryable decision log itself stays mutable, and HSM key anchoring is staged.

Log keeping: retention ≥ 6 months

Art. 19 / 26(6)
Fully covered
Record

Providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control. Without prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in the applicable Union or national law, in particular in Union law on the protection of personal data.Art. 19(1)

How VisIQ helps comply

Signed enforcement receipts are never swept by retention; the queryable decision log follows the plan window: 365 days on Team, custom on Enterprise, 30 days on the default tier.

Risk management system

Art. 9
Your process
Process

A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.Art. 9(1)

How VisIQ supports your process

This one is your organization's own process; VisIQ supplies the evidence behind it. We feed enforcement telemetry into the RM system; we are not the RM system.

Data & data governance

Art. 10
Your process
Isolate

Training, validation and testing data sets shall be subject to data governance and management practices appropriate for the intended purpose of the high-risk AI system.Art. 10(2)

How VisIQ supports your process

This one is your organization's own process; VisIQ supplies the evidence behind it. Data-set quality, bias examination and provenance are design-time duties on your training pipeline; runtime enforcement does not reach them.

Technical documentation

Art. 11
Your process
Record

The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date. The technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section …Art. 11(1)

How VisIQ supports your process

This one is your organization's own process; VisIQ supplies the evidence behind it. We generate runtime evidence that feeds the conformity file, not the dossier itself.

Accuracy / robustness / cybersecurity

Art. 15
Partial
Isolate

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.Art. 15(1)

How VisIQ helps comply

Partially covered today, Scope-confined rules plus a pre-action system-prompt-protection backstop that denies extraction/override attempts regardless of the matched rule; model accuracy and robustness validation are yours.

QMS + conformity + CE + registration

Arts. 17/43/48/49
Your process
Process

Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation.Art. 17(1)

How VisIQ supports your process

This one is your organization's own process; VisIQ supplies the evidence behind it. Quality system / notified-body conformity / CE marking are governance processes.

Fundamental Rights Impact Assessment

Art. 27
Your process
Process

Prior to deploying a high-risk AI system … deployers that are bodies governed by public law, or are private entities providing public services … shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:Art. 27(1)

How VisIQ supports your process

This one is your organization's own process; VisIQ supplies the evidence behind it. The FRIA is a customer document.