EU AI Act

Regulation (EU) 2024/1689 - Article 12 application: 2 December 2027 (Annex III) / 2 August 2028 (Annex I)

Article 113(c) of the consolidated EU AI Act applies Chapter III, Sections 1 to 3, except Article 6(5), from 2 December 2027 to high-risk systems under Article 6(2) (Annex III), and from 2 August 2028 to systems under Article 6(1) (Annex I). These dates include Article 12. They do not defer every obligation in the Act. Article 50 transparency obligations apply from 2 August 2026. The Commission's Article 50 guidance describes a limited grace period until 2 December 2026 for marking and detection requirements on systems placed on the market before 2 August 2026. That grace period does not apply to all Article 50 duties. GPAI model obligations under Articles 51 to 56 apply from 2 August 2025, subject to the Act's transitional provisions.

Asqav signs submitted agent-action records with ML-DSA signatures and generates Article 12 and Article 14 reports with PDF export. These records support review of a deployment; a receipt or report does not establish legal compliance or prove that every action was recorded.

The Asqav receipt format is profiled in IETF Internet-Draft draft-marques-asqav-compliance-receipts, which binds the underlying signed-receipt format to Articles 12 and 26 of the EU AI Act with field-level MUST clauses.

Requirements

Article Requirement Asqav binding
Art. 9 Continuous risk management across the AI system lifecycle. Policy enforcement can gate integrated agent actions. The signed audit trail records actions submitted for signing.
Art. 12 Automatic event logging with traceability. Submitted action records are signed with ML-DSA. Article 12 reports are available through the API.
Art. 13 Operational transparency for deployers. Signed action history preserves the submitted action details and recorded timestamps for review. Audit export is available.
Art. 14 Effective human oversight and override. Multi-key human approval for sensitive actions, instant agent revocation, policy guardrails. Article 14 reports on demand.
Art. 17 Quality management with record-keeping procedures. Systematic audit trail and compliance reporting feed QMS documentation.
Art. 19 Retain automatically generated logs for at least six months. EU AI Act mode applies a minimum 184-day receipt-retention floor, with longer applicable floors taking precedence. Retain signed exports and verification material for later checks; signatures make changes to signed bytes detectable.
Art. 26 Deployers must monitor operation and retain logs. Audit export supports retention. Receipt holders can check signed bytes against trusted public keys; access to the hosted verification endpoint follows receipt visibility.

Bring-your-own KMS, customer-owned storage, and air-gapped on-prem mode are all available for institutions with no-egress requirements. Full mapping detail in the docs.