European · EU AI Act · Chapter III

AI Act readiness — compliance by architecture, with proof.

In U-CogNet, AI Act compliance is not a PDF bolted on after the fact — it is the architecture, and it is cryptographically signed. We map the high-risk obligations (Articles 9–15) to the concrete mechanism that implements each, with an honest status — including what is not yet covered.

Implemented in code
Partial · documentation
Process / legal
Art. 12
Implemented in code

Record-keeping & traceability

Requirement: automatic logging of events over the system's lifetime, enabling traceability of each decision.

Every decision is routed through the integrated gate and appended to a tamper-evident, ed25519-signed audit trail — action, per-gate scores, reasons, verdict. Automatic, per-decision, cross-modal; not a log we promise to keep.

Verify a signed decision
Art. 14
Implemented in code

Human oversight

Requirement: measures so a human can oversee, interpret, intervene and stop.

The gate withholds on a hard veto, flags low-confidence cases for human review, and abstains when uncertain instead of guessing. Self-modification is fail-closed — it cannot proceed without the ethical brain's affirmation.

Art. 9
Implemented in code

Risk-management system

Requirement: a continuous, iterative risk-management system.

Every decision passes through six ontological evaluators (Ananke irreversibility, Constitution, Goodhart, Ethics, Coherence, Mnemosyne) on a shared manifold; self-modification is gated fail-closed. The documented hazard-log process is being written around the runtime gates.

See the signed security benchmark
Art. 15
Implemented in code

Accuracy, robustness & cybersecurity

Requirement: appropriate accuracy and robustness; declared metrics; resilience to attack.

Declared, held-out metrics with temperature-scaled calibration and out-of-distribution detection. Adversarial robustness is now measured: a sovereign, signed prompt-injection benchmark drove attack success to 0% — and surfaced an over-block that we then fixed and re-measured.

See the signed security benchmark
Art. 13
Partial · documentation

Transparency to deployers

Requirement: transparent operation and information to deployers.

Evidence-first outputs carry provenance and a signed reasoning summary; the calibrated probability and the abstention decision are surfaced to the user. The formal Instructions-for-Use document (Annex IV) is in progress.

Art. 10
Partial · documentation

Data & data governance

Requirement: training, validation and test data governance and quality.

Leakage-aware, lesion-grouped splits avoid the classic dermoscopy data leakage; documented provenance; class weighting for imbalance. The formal data-governance record (representativeness, bias examination) is in progress.

Art. 11
Partial · documentation

Technical documentation

Requirement: technical documentation per Annex IV.

The audit module produces signed audit bundles and a measured performance report. Assembling the full Annex IV technical file is in progress.

From “trust us” to “verify the signature”

No competitor walks into a regulator's room and says: our Article 12 record-keeping is an ed25519-signed, per-decision audit trail the system produces by construction; our Article 14 oversight is a gate that withholds and a system that abstains when uncertain. Compliance-by-architecture turns the conversation from “trust us” into “verify the signature” — and you can, right now, in your browser.

Honest gaps (beyond the model)

These are process and legal obligations on the provider — not code — and are exactly what a regulatory sandbox, qualified counsel and a notified body deliver. We name them openly.

  • Quality Management System (Art. 17)

  • Conformity assessment + CE marking + EU declaration of conformity (Arts. 43, 47)

  • Registration in the EU database (Art. 49)

  • Post-market monitoring + serious-incident reporting (Arts. 72, 73)

  • Clinical / human-factors validation to clinical grade (our v1 substrate is strong, not yet clinical-grade)

Research preview · engineering evidence to support an AI Act conformity process — not a conformity declaration. Legal classification, conformity assessment and CE marking require qualified counsel / a notified body; the AESIA regulatory sandbox (Spain) is the supervised path to get there.

Building the EU's verifiable AI

If you assess, fund or partner on trustworthy AI under the AI Act, the evidence above is verifiable today. Let's talk.

Get in touch