In U-CogNet, AI Act compliance is not a PDF bolted on after the fact — it is the architecture, and it is cryptographically signed. We map the high-risk obligations (Articles 9–15) to the concrete mechanism that implements each, with an honest status — including what is not yet covered.
Requirement: automatic logging of events over the system's lifetime, enabling traceability of each decision.
Every decision is routed through the integrated gate and appended to a tamper-evident, ed25519-signed audit trail — action, per-gate scores, reasons, verdict. Automatic, per-decision, cross-modal; not a log we promise to keep.
Verify a signed decisionRequirement: measures so a human can oversee, interpret, intervene and stop.
The gate withholds on a hard veto, flags low-confidence cases for human review, and abstains when uncertain instead of guessing. Self-modification is fail-closed — it cannot proceed without the ethical brain's affirmation.
Requirement: a continuous, iterative risk-management system.
Every decision passes through six ontological evaluators (Ananke irreversibility, Constitution, Goodhart, Ethics, Coherence, Mnemosyne) on a shared manifold; self-modification is gated fail-closed. The documented hazard-log process is being written around the runtime gates.
See the signed security benchmarkRequirement: appropriate accuracy and robustness; declared metrics; resilience to attack.
Declared, held-out metrics with temperature-scaled calibration and out-of-distribution detection. Adversarial robustness is now measured: a sovereign, signed prompt-injection benchmark drove attack success to 0% — and surfaced an over-block that we then fixed and re-measured.
See the signed security benchmarkRequirement: transparent operation and information to deployers.
Evidence-first outputs carry provenance and a signed reasoning summary; the calibrated probability and the abstention decision are surfaced to the user. The formal Instructions-for-Use document (Annex IV) is in progress.
Requirement: training, validation and test data governance and quality.
Leakage-aware, lesion-grouped splits avoid the classic dermoscopy data leakage; documented provenance; class weighting for imbalance. The formal data-governance record (representativeness, bias examination) is in progress.
Requirement: technical documentation per Annex IV.
The audit module produces signed audit bundles and a measured performance report. Assembling the full Annex IV technical file is in progress.
No competitor walks into a regulator's room and says: our Article 12 record-keeping is an ed25519-signed, per-decision audit trail the system produces by construction; our Article 14 oversight is a gate that withholds and a system that abstains when uncertain. Compliance-by-architecture turns the conversation from “trust us” into “verify the signature” — and you can, right now, in your browser.
These are process and legal obligations on the provider — not code — and are exactly what a regulatory sandbox, qualified counsel and a notified body deliver. We name them openly.
Quality Management System (Art. 17)
Conformity assessment + CE marking + EU declaration of conformity (Arts. 43, 47)
Registration in the EU database (Art. 49)
Post-market monitoring + serious-incident reporting (Arts. 72, 73)
Clinical / human-factors validation to clinical grade (our v1 substrate is strong, not yet clinical-grade)
If you assess, fund or partner on trustworthy AI under the AI Act, the evidence above is verifiable today. Let's talk.
Get in touch