
explorer
How does CueCrux help with the EU AI Act?
The compliance machinery is the same machinery everything runs on
agent proposes an action
deploy · delete · write · spend
risk class
declared on the plan or work item
low · proceeds
action runs
signed CROWN receipt minted
high · stops
human gate
passport-attributed approval · timeout cannot auto-approve · refusal fails closed
the gate becomes a signed fact
who approved, when, at which tier
Both branches end on the same hash-linked chain. An auditor cannot tell a quiet day from a deleted one: gaps are detectable, not deniable.
The CueCrux position on compliance is unusual: the compliance machinery is the same machinery everything runs on. There is no separate audit mode that behaves differently when the regulator is watching.
The controls map to the obligations of the Act as engineering, not paperwork. Plans and work items carry risk classes. High-risk actions route through human gates that cannot auto-approve past a timeout: if no human decides, nothing proceeds, and the gate decision lands as a signed fact. Logging is hash-chained CROWN receipts, giving the record-keeping, traceability and transparency that Articles 9, 10, 12, 13, 14, 15 and 50 assume, in a form that verifies offline. Erasure is GDPR Article 17 scoped forget with a dry-run, so you can preview exactly what a deletion touches before executing it, and the deletion itself is on the record.
Because these are runtime controls rather than a reporting layer, the evidence accumulates as a side effect of normal operation. When an audit asks how a decision was made, the answer already exists as a chain of receipts: the risk class, the gate, the approver, the action, the cost.
One deliberate limit: CueCrux supplies engineering controls, not a legal opinion. Your counsel decides how the articles apply to your systems; the machinery makes sure that whatever they decide can be demonstrated.