Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx

Framework · AI regulation

EU AI Act readiness and record-keeping.

The EU AI Act names financial services directly: creditworthiness and insurance risk-pricing systems are high-risk uses. Its record-keeping, logging, and oversight obligations are the evidence Meilynx produces from live traffic.

What the Act requires

Log, retain, oversee, control.

For high-risk systems the Act's core is evidential: automatic logging, deployer-kept logs, human oversight, and use within the intended envelope.

  • Automatic event logging across the system's lifetime (Article 12).
  • Deployer log retention: the logs your high-risk systems generate stay under your control (Article 26).
  • Human oversight with the authority to intervene (Articles 14 and 26).
  • Use per instructions and ongoing monitoring, so deployment stays inside the assessed envelope.
  • Obligations already in force: AI literacy (Article 4), transparency (Article 50), and diligence over general-purpose AI providers (Article 53) apply today; the deferred high-risk regime follows from December 2027.
How Meilynx maps

Each obligation, to a control.

A specific Meilynx control for each deployer-side obligation, and the artifact it produces.

EU AI Act → Meilynx controls

Automatic recording of events over the system's lifetime

EU AI Act · Art. 12

Maps to · AI requests, responses, and governance decisions are captured inline at the proxy and sealed into a tamper-evident, hash-chained audit trail. Logging becomes a property of the traffic path.

Examination artifact · Hash-chained event log per AI system

Deployers keep the logs their high-risk systems generate

EU AI Act · Art. 26(6)

Maps to · Captured logs persist in a retention-locked, write-once store under your control, with retention periods you set to your legal basis.

Examination artifact · Retention-locked log archive

Use and monitor the system per the provider's instructions

EU AI Act · Art. 26(1), (5)

Maps to · Policy-as-code constrains which models, tools, and data classes each team may use, enforced inline on every call. Monitoring telemetry shows the constraint operating.

Examination artifact · Policy snapshot + enforcement records

Human oversight of high-risk AI use

EU AI Act · Art. 14, 26(2)

Maps to · Supervisory review queues, approval gates on agent actions, and two-party waiver workflows put named humans in the loop. Each decision is appended to the same audit chain.

Examination artifact · Supervisory-review log

Transparency for AI that interacts with people, in force since August 2026

EU AI Act · Art. 50

Maps to · Disclosure and content marking are obligations your product surfaces carry, so the preset records them as attested controls, with proxy telemetry evidencing the volume of AI interactions they cover. The Digital Omnibus left Article 50 on its original timeline.

Examination artifact · Attested transparency controls + interaction telemetry

Know which AI systems you operate, and in what role

EU AI Act · scoping

Maps to · The inventory of models and AI systems in use is derived from live traffic, so scoping decisions on which systems are high-risk and which are minimal-risk start from what actually runs.

Examination artifact · AI system inventory, generated from traffic

The evidence

What you show a supervisor.

The audit trail renders into a package aligned to the Act's evidential obligations: the systems in use, the logs they generated, the oversight applied, and a record a reviewer can verify.

In the package

  • AI system inventory, auto-populated from traffic.
  • Event logs per system across the reporting period.
  • Supervisory-review and approval records.
  • SHA-256 integrity hash over the audit chain.
FAQ

The EU AI Act and finance.

Does the EU AI Act apply to financial-services firms?

Yes. Annex III names AI systems used to evaluate the creditworthiness of natural persons, and for risk assessment and pricing in life and health insurance, as high-risk. Any EU-operating firm deploying AI also faces the Act's transparency, oversight, and record-keeping obligations. The Annex III high-risk regime applies from December 2027 following the 2026 Digital Omnibus deferral.

Is the Meilynx EU AI Act preset a conformity assessment?

No. The preset supports readiness and record-keeping: it maps the Act's logging, retention, oversight, and usage-control obligations to specific Meilynx controls and produces the evidence those obligations require. Conformity assessment is a separate regulatory process with its own actors; Meilynx makes the record-keeping side of it defensible.

We deploy third-party models. Aren't the obligations the provider's problem?

Only partly. The Act assigns deployers their own obligations: using systems per instructions, ensuring human oversight, keeping the logs the system generates, and monitoring operation. Because Meilynx sits in your traffic path, it produces deployer-side evidence for third-party models without any provider cooperation.

Examination package

See exactly what an examiner receives

Request a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.