EU Compliance for Autonomous AI.
The EU AI Act asks organisations to keep automatic records of what their AI systems do, to keep a human able to intervene, and to show their work to regulators. Bastion One provides the evidence and the control point those obligations depend on: a tamper-evident record of every agent action, and a deployment-level check that can allow, hold or block an action before it reaches a system of record.
The Dates That Matter
Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI (in force since July 2026). The obligations themselves did not change; several deadlines moved.
Sources: Regulation (EU) 2024/1689, Article 113 (entry into force and application), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 July 2026). Confirm the dates that apply to your systems with counsel.
What the Law Asks. How Bastion One Helps.
Each requirement below is one where organisations need proof, not intent. Bastion One is built to produce that proof as agents run.
Article 12 — Record-Keeping
High-risk AI systems must technically allow the automatic recording of events (logs) over their lifetime, so that their functioning can be traced.
Source: Regulation (EU) 2024/1689, Article 12
The AITS ledger records each agent action as it happens — inputs, the model that produced it, the decision taken — in a hash-chained, content-addressed record. Any later edit or deletion breaks the chain and is detectable.
Article 14 — Human Oversight
People overseeing a high-risk system must be able to decide not to use it, override its output, and intervene in or interrupt its operation.
Source: Regulation (EU) 2024/1689, Article 14(4)(e)
A deployment-level control point sits between an agent’s decision and its execution. Actions outside policy are held for a person or blocked before they commit, and every allow, hold and block is itself recorded.
Articles 19 & 26 — Deployer Duties and Log Retention
Deployers must use high-risk systems according to their instructions, monitor them, and keep the automatically generated logs under their control for at least six months, unless other law requires otherwise.
Source: Regulation (EU) 2024/1689, Article 19 · Article 26(6)
Policies are compiled into runtime rules the control point enforces, and the ledger streams to storage you own — your SIEM, your cloud tenancy — so retention is set by you, not by a vendor.
Articles 72 & 73 — Monitoring and Serious Incidents
Providers must monitor systems after they go to market and report serious incidents to authorities within strict time limits.
Source: Regulation (EU) 2024/1689, Article 72 · Article 73
Traceback reconstructs exactly what an agent did, in order, from the ledger — which inputs it saw, which model answered, what was allowed and what was stopped — so an incident report rests on records rather than recollection.
Article 50 — Transparency
People must be told when they interact with an AI system, and AI-generated content must be marked as such.
Source: Regulation (EU) 2024/1689, Article 50
Lineage tags record which outputs an AI system produced and from what, giving you a provenance record to support disclosure and marking decisions.
Beyond the AI Act
AI agents in Europe also touch data protection, financial resilience and cybersecurity law. The same records serve each.
GDPR
Accountability (Article 5(2)) and records of processing (Article 30), and evidence for decisions about individuals made by automated means (Article 22). Regulation (EU) 2016/679.
DORA
For financial entities: the ICT risk management framework (Article 6) and ICT-related incident management (Article 17) covering automated systems that act on production data. Regulation (EU) 2022/2554.
NIS2
For essential and important entities: cybersecurity risk-management measures (Article 21) and incident reporting (Article 23) that extend to the AI agents operating inside those environments. Directive (EU) 2022/2555.
Legal Sources & Case Law
Every obligation on this page links to the official text published on EUR-Lex, the European Union’s official legal database.
Legislation
- Regulation (EU) 2024/1689 — Artificial Intelligence Act, OJ L, 12 July 2024.
- Regulation (EU) 2026/1744 — Digital Omnibus on AI, amending Regulation (EU) 2024/1689; in force 27 July 2026.
- Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR).
- Regulation (EU) 2022/2554 — Digital Operational Resilience Act (DORA).
- Directive (EU) 2022/2555 — NIS2 Directive.
Case law of the Court of Justice of the European Union
- Case C-634/21, SCHUFA Holding (Scoring), judgment of 7 December 2023 ECLI:EU:C:2023:957 — the automated establishment of a probability value, such as a credit score, is itself an automated individual decision under Article 22(1) GDPR where a third party draws strongly on it in deciding whether to enter into, perform or end a contract with that person.
- Case C-203/22, Dun & Bradstreet Austria, judgment of 27 February 2025 ECLI:EU:C:2025:117 — a person subject to automated decision-making is entitled to an explanation of the procedure and principles actually applied to their personal data; where the controller claims trade secrets, the information is to be provided to the competent authority or court, which weighs the rights at stake.
No court has yet interpreted the Artificial Intelligence Act. The judgments above concern automated decision-making under the GDPR, which applies alongside the AI Act. Further guidance: the European Commission’s AI Act policy page.
Bastion One provides technology that supports organisations in meeting their record-keeping, human-oversight and monitoring obligations under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and related European legislation. Bastion One is not a notified body and does not perform conformity assessments or issue certifications. Responsibility for the classification of an AI system, for its conformity assessment, and for compliance with applicable law remains with the provider and the deployer of that system.
The information on this page is provided for general informational purposes only and does not constitute legal advice. Regulatory requirements and application dates are subject to change; organisations should seek advice from qualified counsel on the obligations that apply to them.
Intellectual Property
Bastion One’s technology is the subject of U.S. Patent Application Publication No. US 2026/0300452 A1 and International Publication No. WO 2026/206978 under the Patent Cooperation Treaty. Additional U.S. and international patents pending. See Intellectual Property & Legal Notices.
