Framework · AI regulation
EU AI Act readiness and record-keeping.
The EU AI Act names financial services directly: creditworthiness and insurance risk-pricing systems are high-risk uses. Its record-keeping, logging, and oversight obligations are the evidence Meilynx produces from live traffic.
Log, retain, oversee, control.
For high-risk systems the Act's core is evidential: automatic logging, deployer-kept logs, human oversight, and use within the intended envelope.
- Automatic event logging across the system's lifetime (Article 12).
- Deployer log retention: the logs your high-risk systems generate stay under your control (Article 26).
- Human oversight with the authority to intervene (Articles 14 and 26).
- Use per instructions and ongoing monitoring, so deployment stays inside the assessed envelope.
- Obligations already in force: AI literacy (Article 4), transparency (Article 50), and diligence over general-purpose AI providers (Article 53) apply today; the deferred high-risk regime follows from December 2027.
Each obligation, to a control.
A specific Meilynx control for each deployer-side obligation, and the artifact it produces.
EU AI Act → Meilynx controls
| Requirement | How Meilynx maps | Examination artifact |
|---|---|---|
Automatic recording of events over the system's lifetime EU AI Act · Art. 12 | AI requests, responses, and governance decisions are captured inline at the proxy and sealed into a tamper-evident, hash-chained audit trail. Logging becomes a property of the traffic path. | Hash-chained event log per AI system |
Deployers keep the logs their high-risk systems generate EU AI Act · Art. 26(6) | Captured logs persist in a retention-locked, write-once store under your control, with retention periods you set to your legal basis. | Retention-locked log archive |
Use and monitor the system per the provider's instructions EU AI Act · Art. 26(1), (5) | Policy-as-code constrains which models, tools, and data classes each team may use, enforced inline on every call. Monitoring telemetry shows the constraint operating. | Policy snapshot + enforcement records |
Human oversight of high-risk AI use EU AI Act · Art. 14, 26(2) | Supervisory review queues, approval gates on agent actions, and two-party waiver workflows put named humans in the loop. Each decision is appended to the same audit chain. | Supervisory-review log |
Transparency for AI that interacts with people, in force since August 2026 EU AI Act · Art. 50 | Disclosure and content marking are obligations your product surfaces carry, so the preset records them as attested controls, with proxy telemetry evidencing the volume of AI interactions they cover. The Digital Omnibus left Article 50 on its original timeline. | Attested transparency controls + interaction telemetry |
Know which AI systems you operate, and in what role EU AI Act · scoping | The inventory of models and AI systems in use is derived from live traffic, so scoping decisions on which systems are high-risk and which are minimal-risk start from what actually runs. | AI system inventory, generated from traffic |
Automatic recording of events over the system's lifetime
EU AI Act · Art. 12
Maps to · AI requests, responses, and governance decisions are captured inline at the proxy and sealed into a tamper-evident, hash-chained audit trail. Logging becomes a property of the traffic path.
Examination artifact · Hash-chained event log per AI system
Deployers keep the logs their high-risk systems generate
EU AI Act · Art. 26(6)
Maps to · Captured logs persist in a retention-locked, write-once store under your control, with retention periods you set to your legal basis.
Examination artifact · Retention-locked log archive
Use and monitor the system per the provider's instructions
EU AI Act · Art. 26(1), (5)
Maps to · Policy-as-code constrains which models, tools, and data classes each team may use, enforced inline on every call. Monitoring telemetry shows the constraint operating.
Examination artifact · Policy snapshot + enforcement records
Human oversight of high-risk AI use
EU AI Act · Art. 14, 26(2)
Maps to · Supervisory review queues, approval gates on agent actions, and two-party waiver workflows put named humans in the loop. Each decision is appended to the same audit chain.
Examination artifact · Supervisory-review log
Transparency for AI that interacts with people, in force since August 2026
EU AI Act · Art. 50
Maps to · Disclosure and content marking are obligations your product surfaces carry, so the preset records them as attested controls, with proxy telemetry evidencing the volume of AI interactions they cover. The Digital Omnibus left Article 50 on its original timeline.
Examination artifact · Attested transparency controls + interaction telemetry
Know which AI systems you operate, and in what role
EU AI Act · scoping
Maps to · The inventory of models and AI systems in use is derived from live traffic, so scoping decisions on which systems are high-risk and which are minimal-risk start from what actually runs.
Examination artifact · AI system inventory, generated from traffic
What you show a supervisor.
The audit trail renders into a package aligned to the Act's evidential obligations: the systems in use, the logs they generated, the oversight applied, and a record a reviewer can verify.
In the package
- AI system inventory, auto-populated from traffic.
- Event logs per system across the reporting period.
- Supervisory-review and approval records.
- SHA-256 integrity hash over the audit chain.
The EU AI Act and finance.
Does the EU AI Act apply to financial-services firms?
Yes. Annex III names AI systems used to evaluate the creditworthiness of natural persons, and for risk assessment and pricing in life and health insurance, as high-risk. Any EU-operating firm deploying AI also faces the Act's transparency, oversight, and record-keeping obligations. The Annex III high-risk regime applies from December 2027 following the 2026 Digital Omnibus deferral.
Is the Meilynx EU AI Act preset a conformity assessment?
No. The preset supports readiness and record-keeping: it maps the Act's logging, retention, oversight, and usage-control obligations to specific Meilynx controls and produces the evidence those obligations require. Conformity assessment is a separate regulatory process with its own actors; Meilynx makes the record-keeping side of it defensible.
We deploy third-party models. Aren't the obligations the provider's problem?
Only partly. The Act assigns deployers their own obligations: using systems per instructions, ensuring human oversight, keeping the logs the system generates, and monitoring operation. Because Meilynx sits in your traffic path, it produces deployer-side evidence for third-party models without any provider cooperation.
Build the evidence.
See exactly what an examiner receives
Request a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.