DocsEU AI Act Evidence

EU AI Act Evidence Mapping

Compliance

AKIOS Pro maps evidence records to EU AI Act obligations. Regulated teams can demonstrate compliance for high-risk AI systems deployed in agent workflows.

Framework Overview#

The EU AI Act establishes obligations for providers and deployers of AI systems. For agent workflows, the relevant obligations fall under transparency, risk management, record keeping, and human oversight. AKIOS Pro provides the structured evidence layer to demonstrate these controls with independently reviewable records.

Regulatory context

AI Act obligations broadly apply from 2 August 2026, with exceptions for certain provisions. This document describes technical evidence mappings, not legal advice. Organizations should consult legal counsel for compliance determinations specific to their deployment.

Article Mappings#

Each article maps to specific AKIOS Pro evidence outputs that can be generated, exported, and presented during audits.

Article 12

Record keeping

Obligation: High-risk AI systems must automatically record events (logs) during operation. Records must be comprehensive and retained for regulatory inspection.

Evidence: AKIOS Pro captures every agent session as a structured trace: model used, prompt and completion data, tool calls and results, policy evaluation decisions, and human review actions. Traces are timestamped with nanosecond precision, immutable after capture, and retained per configurable organization policy.

Export: Trace export with session correlation. Evidence pack with control mapping to Art. 12.

Article 13

Transparency and provision of information

Obligation: Deployers must be informed about AI system capabilities, limitations, and risks. Documentation must be clear and accessible.

Evidence: AKIOS Pro generates human-readable evidence packs that document what the AI system did, which data it accessed, how decisions were reached, and which controls were applied. Packs include model identification, data processing descriptions, and risk summary.

Export: Evidence pack in HTML or PDF format with cover page, table of contents, and framework mapping summary.

Article 14

Human oversight

Obligation: High-risk AI systems must enable effective human oversight. Oversight measures must be built into the system before deployment.

Evidence: Findings track every high-risk action requiring human review: escalation path, reviewer identity, approval or rejection decision, and timestamp. Review SLA violations are captured as findings. Human-in-the-loop events are recorded in the trace with full context.

Export: Oversight report: all review actions with decisions, time-to-review metrics, and SLA compliance summary.

Article 15

Accuracy, robustness, cybersecurity

Obligation: High-risk AI systems must perform consistently, be resilient to errors, and be secure against adversarial exploitation.

Evidence: AKIOS Pro monitors for anomalies: cost spikes, behavioral loops, unexpected tool access, policy violations, and PII exposure. These are recorded as findings with severity classification. Security events and policy enforcement actions are captured in the audit trail.

Export: Anomaly and incident report: all security findings with severity distribution, remediation status, and trend analysis.

Article 16

Obligations of providers (summarized)

Obligation: Providers must ensure conformity assessment, technical documentation, and quality management systems.

Evidence: AKIOS Pro evidence packs provide the documentation layer for conformity assessments. Trace records, policy evaluations, and review trails demonstrate that the system was monitored and governed during operation.

Export: Technical documentation package: architecture description, evidence model, control mappings, and deployment configuration.

Article 29

Obligations of deployers

Obligation: Deployers must use AI systems in accordance with instructions, monitor for risks, and maintain logs.

Evidence: Deployers use AKIOS Pro evidence packs to demonstrate that agent workflows are monitored, governed, and subject to human oversight. Retention controls ensure logs are maintained per regulatory requirements. Purge attestations demonstrate compliance with data minimization obligations.

Export: Deployer compliance report: evidence collection status, retention policy, monitoring coverage, and oversight summary.

Article 55

Fundamental rights impact assessments

Obligation: Deployers of high-risk AI systems must conduct fundamental rights impact assessments.

Evidence: Traces and findings provide the data needed for impact assessments: PII exposure across sessions, policy violation patterns, escalation frequency, demographic coverage, and remediation history. Structured evidence supports thorough and reproducible assessments.

Export: Impact assessment data pack: PII exposure report, policy violation analysis, escalation patterns, and remediation metrics.

Evidence Flow#

Observe

AKIOS Pro connects beside the agent stack and captures LLM calls, tool activity, policy events, and review actions in real-time. No agent code changes required.

Detect

PII patterns (50+ across 7 categories), policy violations, cost anomalies, behavioral loops, and missing reviews are detected and recorded as structured findings with confidence scores.

Map

Every trace and finding is mapped to the relevant EU AI Act articles and other control frameworks. Mappings are pre-built and configurable per organization.

Export

Evidence packs are generated with traces, findings, control mappings, and retention attestations. Available in JSON, HTML, and PDF formats for regulatory submissions and internal audit.

Other Regulatory Frameworks#

Beyond the EU AI Act, AKIOS Pro evidence model maps to the major frameworks that regulated enterprises operate under.

GDPR

PII findings, data processing records, retention controls, review trails, deletion attestations for data subject rights and data minimization obligations (Articles 5, 17, 32).

SOC 2

Access controls, monitoring, anomaly detection, incident response, and audit trail evidence mapped to trust services criteria (CC6, CC7).

HIPAA

ePHI access logs, audit controls (164.312), access controls (164.312), integrity controls (164.312), person authentication for covered entities and business associates.

ISO 42001

AI management system evidence: risk assessments, monitoring records, incident response, continuous improvement documentation, and conformity assessment support.