
faq-enterprise
How does CueCrux map to the EU AI Act?
Enterprise FAQ
agent proposes an action
deploy · delete · write · spend
risk class
declared on the plan or work item
low · proceeds
action runs
signed CROWN receipt minted
high · stops
human gate
passport-attributed approval · timeout cannot auto-approve · refusal fails closed
the gate becomes a signed fact
who approved, when, at which tier
Both branches end on the same hash-linked chain. An auditor cannot tell a quiet day from a deleted one: gaps are detectable, not deniable.
CueCrux's position is deliberate: we provide engineering controls, not a legal opinion. What makes the controls credible is that the compliance machinery is the same machinery everything runs on; there is no separate audit mode that might drift from production reality.
The mapping, control by control:
- Risk classes attach to plans and work items, so higher-risk agent work is identified before it runs, not categorised afterwards.
- Human gates on high-risk items cannot auto-approve past a timeout. An unattended gate stays shut; oversight (Art. 14) is enforced by mechanism, not by policy document.
- Hash-chained logging provides the record-keeping, traceability, and transparency posture behind Arts. 9, 10, 12, 13, 15, and the disclosure duties of Art. 50: signed receipts on an append-only spine, verifiable offline by a regulator without trusting us or you.
- GDPR Article 17 is handled by scoped forget with dry-run, receipted so erasure is provable.
Your counsel decides what your obligations are. CueCrux makes the evidence for meeting them a by-product of normal operation.