← Explore
How does CueCrux map to the EU AI Act?

explorer

How does CueCrux map to the EU AI Act?

The compliance machinery is the machinery everything runs on

agent proposes an action

deploy · delete · write · spend

risk class

declared on the plan or work item

low · proceeds

action runs

signed CROWN receipt minted

high · stops

human gate

passport-attributed approval · timeout cannot auto-approve · refusal fails closed

the gate becomes a signed fact

who approved, when, at which tier

Both branches end on the same hash-linked chain. An auditor cannot tell a quiet day from a deleted one: gaps are detectable, not deniable.

Most AI compliance offerings are documentation layers: templates, registers and attestations maintained next to the system they describe. The weakness is structural, because a record kept beside the machinery can drift from what the machinery actually did. CueCrux takes the opposite approach. The controls the EU AI Act contemplates are the same mechanisms every CueCrux agent action runs through daily, so the compliance evidence is the operational record.

The mapping is concrete. Plans and work items carry risk classes, so risk classification is a property of the work itself rather than a spreadsheet about it. High-risk actions route through human gates that cannot auto-approve past a timeout: absent a human decision, the action does not proceed, and the decision lands as a signed fact. Every state mutation is logged in a hash-chained, tamper-evident trail that verifies offline. Refusals produce signed RefusalReceipts with reason codes, documenting controls operating rather than merely existing. Together this machinery addresses the ground covered by Articles 9, 10, 12, 13, 14, 15 and 50: risk management, data governance, record-keeping, transparency, human oversight, robustness, and transparency of AI-generated content, where C2PA output attestation is available behind a default-off flag.

Data subject rights are engineered too. GDPR Article 17 erasure is implemented as scoped forget with a dry-run, so deletion is previewable, deliberate and receipted.

One sentence of honesty that matters: these are engineering controls, not a legal opinion. CueCrux will not tell you whether your system is high-risk or which obligations attach to it; your counsel does that. What CueCrux ensures is that when counsel decides what must be evidenced, the evidence already exists, is already signed, and can be verified by someone who does not trust you.