Framework · AI regulation
EU AI Act readiness and record-keeping.
The EU AI Act is the first comprehensive AI regulation, and financial services is named in it: creditworthiness and insurance risk-pricing systems are high-risk uses. Its record-keeping, logging, and oversight obligations are exactly the evidence Meilynx produces from live traffic.
Log, retain, oversee, control.
For high-risk systems the Act's operational core is evidential: events recorded automatically, logs kept by the deployer, humans in the oversight loop, and use constrained to what was intended.
- Automatic event logging across the system's lifetime (Article 12).
- Deployer log retention — the logs your high-risk systems generate stay under your control (Article 26).
- Human oversight with the authority to intervene (Articles 14 and 26).
- Use per instructions and ongoing monitoring — deployment stays inside the assessed envelope.
Each obligation, to a control.
A specific Meilynx control for each deployer-side obligation, and the artifact it produces.
EU AI Act → Meilynx controls
| Requirement | How Meilynx maps | Examination artifact |
|---|---|---|
Automatic recording of events over the system's lifetime EU AI Act · Art. 12 | Every AI request, response, and governance decision is captured inline at the proxy and sealed into a tamper-evident, hash-chained audit trail — logging as a property of the traffic path, not a per-application retrofit. | Hash-chained event log per AI system |
Deployers keep the logs their high-risk systems generate EU AI Act · Art. 26(6) | Captured logs persist in a retention-locked, write-once store under your control, with retention periods you set to your legal basis — the record survives staff churn, vendor churn, and time. | Retention-locked log archive |
Use and monitor the system per the provider's instructions EU AI Act · Art. 26(1), (5) | Policy-as-code constrains which models, tools, and data classes each team may use, enforced inline on every call — and the monitoring telemetry shows the constraint operating, not just existing on paper. | Policy snapshot + enforcement records |
Human oversight of high-risk AI use EU AI Act · Art. 14, 26(2) | Supervisory review queues, approval gates on agent actions, and two-party waiver workflows put named humans in the loop — each decision appended to the same audit chain. | Supervisory-review log |
Know which AI systems you operate, and in what role EU AI Act · scoping | The inventory of models and AI systems in use is derived from live traffic, so scoping decisions — which systems are high-risk, which are minimal-risk — start from what actually runs, not from a survey. | AI system inventory, generated from traffic |
Automatic recording of events over the system's lifetime
EU AI Act · Art. 12
Maps to · Every AI request, response, and governance decision is captured inline at the proxy and sealed into a tamper-evident, hash-chained audit trail — logging as a property of the traffic path, not a per-application retrofit.
Examination artifact · Hash-chained event log per AI system
Deployers keep the logs their high-risk systems generate
EU AI Act · Art. 26(6)
Maps to · Captured logs persist in a retention-locked, write-once store under your control, with retention periods you set to your legal basis — the record survives staff churn, vendor churn, and time.
Examination artifact · Retention-locked log archive
Use and monitor the system per the provider's instructions
EU AI Act · Art. 26(1), (5)
Maps to · Policy-as-code constrains which models, tools, and data classes each team may use, enforced inline on every call — and the monitoring telemetry shows the constraint operating, not just existing on paper.
Examination artifact · Policy snapshot + enforcement records
Human oversight of high-risk AI use
EU AI Act · Art. 14, 26(2)
Maps to · Supervisory review queues, approval gates on agent actions, and two-party waiver workflows put named humans in the loop — each decision appended to the same audit chain.
Examination artifact · Supervisory-review log
Know which AI systems you operate, and in what role
EU AI Act · scoping
Maps to · The inventory of models and AI systems in use is derived from live traffic, so scoping decisions — which systems are high-risk, which are minimal-risk — start from what actually runs, not from a survey.
Examination artifact · AI system inventory, generated from traffic
What you show a supervisor.
The audit trail renders into a package aligned to the Act's evidential obligations — the systems in use, the logs they generated, the oversight applied, and a record a reviewer can verify independently.
In the package
- AI system inventory, auto-populated from traffic.
- Event logs per system across the reporting period.
- Supervisory-review and approval records.
- SHA-256 integrity hash over the audit chain.
The EU AI Act and finance.
Does the EU AI Act apply to financial-services firms?
Yes, squarely. Annex III names AI systems used to evaluate creditworthiness of natural persons and for risk assessment and pricing in life and health insurance as high-risk. Beyond those named uses, any EU-operating firm deploying AI faces the Act's transparency, oversight, and record-keeping obligations on the timeline the Act sets — with the high-risk regime applying from August 2026.
Is the Meilynx EU AI Act preset a conformity assessment?
No. The preset supports readiness and record-keeping: it maps the Act's logging, retention, oversight, and usage-control obligations to specific Meilynx controls and produces the evidence those obligations require. Conformity assessment is a separate regulatory process with its own actors — Meilynx makes the record-keeping side of it defensible.
We deploy third-party models — aren't the obligations the provider's problem?
Only partly. The Act assigns deployers their own obligations — using systems per instructions, ensuring human oversight, keeping the logs the system generates, and monitoring operation. Because Meilynx sits in your traffic path, it produces deployer-side evidence for third-party models without any provider cooperation.
See exactly what an examiner receives
Download a sample examination package — model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.