Governance
EU
Imminent

EU AI Act (Regulation (EU) 2024/1689)

The world's most consequential AI law; turnover-based fines. Art. 12 logging + Art. 19 log keeping + Art. 14 human oversight map directly to RECORD + ALLOW.

Read the authoritative text — EUR-Lex — Official Journal of the European Union

Human oversight — intervene/override/halt

Art. 14
Fully covered
Allow

… to intervene in the operation of the high-risk AI system or interrupt the system through a ‘stop’ button or a similar procedure that allows the system to come to a halt in a safe state.Art. 14(4)(e)

HITL gate + deny + override at the enforcement point.

Automatic event logging, ≥6-mo retention

Art. 12 / 26(6)
Fully covered
Record

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.Art. 12(1)

Merkle+TSA signed audit + configurable retention; agent identity gives traceability.

Log immutability hardening

Art. 12
Fully covered
Record

In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for … identifying situations that may result in the high-risk AI system presenting a risk …Art. 12(2)

WORM append-only + content-hash-at-ingest shipped; HSM key anchoring staged.

Log keeping — retention ≥ 6 months

Art. 19 / 26(6)
Fully covered
Record

Providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control. Without prejudice to applicable Union or national law, the logs shall be kept for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in the applicable Union or national law, in particular in Union law on the protection of personal data.Art. 19(1)

Signed enforcement receipts with configurable retention; the Team (365-day) and Enterprise (custom) tiers clear the six-month floor for providers and deployers alike.

Risk management system

Art. 9
Your process
Process

A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems.Art. 9(1)

This one is your organization's own process; VisIQ supplies the evidence behind it. We feed enforcement telemetry into the RM system; we are not the RM system.

Data & data governance

Art. 10
Partial
Isolate

Training, validation and testing data sets shall be subject to data governance and management practices appropriate for the intended purpose of the high-risk AI system.Art. 10(2)

Partially covered today — Runtime data minimization/redaction; training-data quality/bias governance is yours.

Technical documentation

Art. 11
Your process
Record

The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date. The technical documentation shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the requirements set out in this Section …Art. 11(1)

This one is your organization's own process; VisIQ supplies the evidence behind it. We generate runtime evidence that feeds the conformity file, not the dossier itself.

Accuracy / robustness / cybersecurity

Art. 15
Partial
Isolate

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle.Art. 15(1)

Partially covered today — Scope confinement + cyber controls; model-accuracy validation is yours.

QMS + conformity + CE + registration

Arts. 17/43/48/49
Your process
Process

Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation.Art. 17(1)

This one is your organization's own process; VisIQ supplies the evidence behind it. Quality system / notified-body conformity / CE marking are governance processes.

Fundamental Rights Impact Assessment

Art. 27
Your process
Process

Prior to deploying a high-risk AI system … deployers that are bodies governed by public law, or are private entities providing public services … shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:Art. 27(1)

This one is your organization's own process; VisIQ supplies the evidence behind it. The FRIA is a customer document.