meilynx

Framework · AI regulation

EU AI Act readiness and record-keeping.

The EU AI Act is the first comprehensive AI regulation, and financial services is named in it: creditworthiness and insurance risk-pricing systems are high-risk uses. Its record-keeping, logging, and oversight obligations are exactly the evidence Meilynx produces from live traffic.

What the Act requires

Log, retain, oversee, control.

For high-risk systems the Act's operational core is evidential: events recorded automatically, logs kept by the deployer, humans in the oversight loop, and use constrained to what was intended.

  • Automatic event logging across the system's lifetime (Article 12).
  • Deployer log retention — the logs your high-risk systems generate stay under your control (Article 26).
  • Human oversight with the authority to intervene (Articles 14 and 26).
  • Use per instructions and ongoing monitoring — deployment stays inside the assessed envelope.
How Meilynx maps

Each obligation, to a control.

A specific Meilynx control for each deployer-side obligation, and the artifact it produces.

EU AI Act → Meilynx controls

Automatic recording of events over the system's lifetime

EU AI Act · Art. 12

Maps to · Every AI request, response, and governance decision is captured inline at the proxy and sealed into a tamper-evident, hash-chained audit trail — logging as a property of the traffic path, not a per-application retrofit.

Examination artifact · Hash-chained event log per AI system

Deployers keep the logs their high-risk systems generate

EU AI Act · Art. 26(6)

Maps to · Captured logs persist in a retention-locked, write-once store under your control, with retention periods you set to your legal basis — the record survives staff churn, vendor churn, and time.

Examination artifact · Retention-locked log archive

Use and monitor the system per the provider's instructions

EU AI Act · Art. 26(1), (5)

Maps to · Policy-as-code constrains which models, tools, and data classes each team may use, enforced inline on every call — and the monitoring telemetry shows the constraint operating, not just existing on paper.

Examination artifact · Policy snapshot + enforcement records

Human oversight of high-risk AI use

EU AI Act · Art. 14, 26(2)

Maps to · Supervisory review queues, approval gates on agent actions, and two-party waiver workflows put named humans in the loop — each decision appended to the same audit chain.

Examination artifact · Supervisory-review log

Know which AI systems you operate, and in what role

EU AI Act · scoping

Maps to · The inventory of models and AI systems in use is derived from live traffic, so scoping decisions — which systems are high-risk, which are minimal-risk — start from what actually runs, not from a survey.

Examination artifact · AI system inventory, generated from traffic

The evidence

What you show a supervisor.

The audit trail renders into a package aligned to the Act's evidential obligations — the systems in use, the logs they generated, the oversight applied, and a record a reviewer can verify independently.

In the package

  • AI system inventory, auto-populated from traffic.
  • Event logs per system across the reporting period.
  • Supervisory-review and approval records.
  • SHA-256 integrity hash over the audit chain.
FAQ

The EU AI Act and finance.

Does the EU AI Act apply to financial-services firms?

Yes, squarely. Annex III names AI systems used to evaluate creditworthiness of natural persons and for risk assessment and pricing in life and health insurance as high-risk. Beyond those named uses, any EU-operating firm deploying AI faces the Act's transparency, oversight, and record-keeping obligations on the timeline the Act sets — with the high-risk regime applying from August 2026.

Is the Meilynx EU AI Act preset a conformity assessment?

No. The preset supports readiness and record-keeping: it maps the Act's logging, retention, oversight, and usage-control obligations to specific Meilynx controls and produces the evidence those obligations require. Conformity assessment is a separate regulatory process with its own actors — Meilynx makes the record-keeping side of it defensible.

We deploy third-party models — aren't the obligations the provider's problem?

Only partly. The Act assigns deployers their own obligations — using systems per instructions, ensuring human oversight, keeping the logs the system generates, and monitoring operation. Because Meilynx sits in your traffic path, it produces deployer-side evidence for third-party models without any provider cooperation.

Examination package

See exactly what an examiner receives

Download a sample examination package — model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.