← Explore
How does CueCrux help with the EU AI Act?

explorer

How does CueCrux help with the EU AI Act?

The compliance machinery is the same machinery everything runs on

agent proposes an action

deploy · delete · write · spend

risk class

declared on the plan or work item

low · proceeds

action runs

signed CROWN receipt minted

high · stops

human gate

passport-attributed approval · timeout cannot auto-approve · refusal fails closed

the gate becomes a signed fact

who approved, when, at which tier

Both branches end on the same hash-linked chain. An auditor cannot tell a quiet day from a deleted one: gaps are detectable, not deniable.

The CueCrux position on compliance is unusual: the compliance machinery is the same machinery everything runs on. There is no separate audit mode that behaves differently when the regulator is watching.

The controls map to the obligations of the Act as engineering, not paperwork. Plans and work items carry risk classes. High-risk actions route through human gates that cannot auto-approve past a timeout: if no human decides, nothing proceeds, and the gate decision lands as a signed fact. Logging is hash-chained CROWN receipts, giving the record-keeping, traceability and transparency that Articles 9, 10, 12, 13, 14, 15 and 50 assume, in a form that verifies offline. Erasure is GDPR Article 17 scoped forget with a dry-run, so you can preview exactly what a deletion touches before executing it, and the deletion itself is on the record.

Because these are runtime controls rather than a reporting layer, the evidence accumulates as a side effect of normal operation. When an audit asks how a decision was made, the answer already exists as a chain of receipts: the risk class, the gate, the approver, the action, the cost.

One deliberate limit: CueCrux supplies engineering controls, not a legal opinion. Your counsel decides how the articles apply to your systems; the machinery makes sure that whatever they decide can be demonstrated.