EU AI Act
Regulation (EU) 2024/1689 - Article 12 application: 2 December 2027 (Annex III) / 2 August 2028 (Annex I)
Article 113(c) of the consolidated EU AI Act applies Chapter III, Sections 1 to 3, except Article 6(5), from 2 December 2027 to high-risk systems under Article 6(2) (Annex III), and from 2 August 2028 to systems under Article 6(1) (Annex I). These dates include Article 12. They do not defer every obligation in the Act. Article 50 transparency obligations apply from 2 August 2026. The Commission's Article 50 guidance describes a limited grace period until 2 December 2026 for marking and detection requirements on systems placed on the market before 2 August 2026. That grace period does not apply to all Article 50 duties. GPAI model obligations under Articles 51 to 56 apply from 2 August 2025, subject to the Act's transitional provisions.
Asqav signs submitted agent-action records with ML-DSA signatures and generates Article 12 and Article 14 reports with PDF export. These records support review of a deployment; a receipt or report does not establish legal compliance or prove that every action was recorded.
The Asqav receipt format is profiled in IETF Internet-Draft draft-marques-asqav-compliance-receipts, which binds the underlying signed-receipt format to Articles 12 and 26 of the EU AI Act with field-level MUST clauses.
Requirements
| Article | Requirement | Asqav binding |
|---|---|---|
| Art. 9 | Continuous risk management across the AI system lifecycle. | Policy enforcement can gate integrated agent actions. The signed audit trail records actions submitted for signing. |
| Art. 12 | Automatic event logging with traceability. | Submitted action records are signed with ML-DSA. Article 12 reports are available through the API. |
| Art. 13 | Operational transparency for deployers. | Signed action history preserves the submitted action details and recorded timestamps for review. Audit export is available. |
| Art. 14 | Effective human oversight and override. | Multi-key human approval for sensitive actions, instant agent revocation, policy guardrails. Article 14 reports on demand. |
| Art. 17 | Quality management with record-keeping procedures. | Systematic audit trail and compliance reporting feed QMS documentation. |
| Art. 19 | Retain automatically generated logs for at least six months. | EU AI Act mode applies a minimum 184-day receipt-retention floor, with longer applicable floors taking precedence. Retain signed exports and verification material for later checks; signatures make changes to signed bytes detectable. |
| Art. 26 | Deployers must monitor operation and retain logs. | Audit export supports retention. Receipt holders can check signed bytes against trusted public keys; access to the hosted verification endpoint follows receipt visibility. |
Bring-your-own KMS, customer-owned storage, and air-gapped on-prem mode are all available for institutions with no-egress requirements. Full mapping detail in the docs.