← Explore
AI Regulation

domain

AI Regulation

The EU AI Act as engineering controls, not a legal opinion

Most EU AI Act tooling is documentation software: it helps you describe controls. CueCrux takes the other route: the compliance machinery is the same machinery everything runs on, so the controls are not described, they operate.

The mapping is direct. Risk classes attach to plans and work items (Article 9's risk-management posture). Retrieval and state changes run over governed, receipted data paths (Article 10). Hash-chained, signed logging is the substrate itself, not an export (Article 12). Receipts and refusal receipts make system behaviour explainable to a deployer (Article 13). Human gates that cannot auto-approve past a timeout give Article 14 oversight an enforcement mechanism rather than a checkbox. Verification, robustness, and tamper-rejection are release-blocking engineering gates (Article 15). C2PA output attestation, behind a default-off flag, addresses Article 50 transparency for generated content.

GDPR travels with it: Article 17 erasure is scoped forget with a dry-run preview, receipted like everything else.

None of this is a legal opinion, and CueCrux does not sell one. It is the position that when a market surveillance authority asks you to demonstrate oversight and traceability, the correct answer is a replay, and replays require machinery that was running before the question arrived. For cited answers on the regulatory text itself, WikiCrux is live and every answer opens its sources.