EU AI Act compliance for AI agents

EU AI Act compliance for AI agents: logging you can prove, not just retain

Article 12 requires automatic, lifetime event logging for high-risk AI systems. Article 26 makes deployers retain those logs at least six months. Neither says the logs may be silently editable — and if they can be, their evidentiary value is zero.

DataShield gives every governed agent tool call a scoped authorization decision and a place in a SHA-256 hash chain with Ed25519-signed checkpoints. Verification distinguishes tampering, insertion, deletion, and truncation — and you can run it yourself, today, without a signup.

Evidence-grade governance Sensitive records are tokenized at ingest; agents query tokens over MCP; each call is authorized and sealed into a tamper-evident, verifiable audit chain. Regulated data systems ID 8834 → TOK_5b7e… Tokenize at ingest Tokenized dataset scope ≤ ceiling tool call High-risk AI system EU AI Act Art. 12 Art. 26 log retention ISO/IEC 42001 EVIDENCE LANE Ed25519 checkpoint verify_chain → VALID signed checkpoints — deletion detectable

AI agent audit trail compliance: what regulated deployers actually need

Logs that prove, not just record

A log that can be silently altered proves nothing. DataShield's audit chain is hash-linked row by row, with signed checkpoints that are themselves chained — so even checkpoint deletion is detectable. Key rotation fails closed. Designed to map to EU AI Act Art. 12/26 and HIPAA §164.312(b). Verify a sample chain.

Authorization per tool call

Every governed tool call passes token scope ceiling, authority tier, and a mid-session revocation re-check before metered dispatch — attributed to agent identity. Break-glass emergency access expires itself, revokes mid-session, and can't be quietly deleted from the log. See Auth.

Data minimization by construction

EDPB Opinion 28/2024 names pseudonymization as a GDPR mitigation. DataShield tokenizes identifiers at ingest with deterministic, join-preserving tokens, generalizes quasi-identifiers to k-anonymity, and makes detokenization a privileged, audited operation. Erasure is crypto-shred — the audit chain survives it. See Ontology.

EU AI Act Article 12 logging requirements and ISO 42001, stated accurately

Commission fining powers begin August 2, 2026, with penalties up to €35M or 7% of turnover — but the Digital Omnibus defers Annex III high-risk classification to December 2027, and embedded medical AI to August 2028. We won't fearmonger the deadline. What's already load-bearing: Art. 12 lifetime event logging and Art. 26 deployer log retention remain in force, and they're the audit-evidence anchor for every high-risk deployment plan.

ISO/IEC 42001 is becoming a procurement requirement in its own right, and Colorado's AI Act makes NIST AI RMF / ISO 42001 alignment an affirmative defense. Both frameworks converge on the same question every audit asks: prove what happened, when, by which agent, against which policy. DataShield's answer is a record — per-tool-call metering with agent attribution, sealed into a chain whose verification report schema is published verbatim on the architecture page.

Independence matters to regulated buyers. Lakera went to Check Point, Portkey to Palo Alto, Prompt Security to SentinelOne, CalypsoAI to F5. The neutral governance layer is disappearing into platform vendors. DataShield deploys self-hosted or in your VPC, with your keys — see Security.

What stays load-bearing under the EU AI Act and ISO 42001 EU AI Act penalties reach 35 million euro or 7 percent of turnover, with Commission fining powers from 2 August 2026. Regardless of deadline changes, Article 12 lifetime event logging and Article 26 deployer log retention remain in force, ISO/IEC 42001 is becoming a procurement requirement whose report must point at real controls, and the Colorado AI Act makes NIST AI RMF and ISO 42001 alignment an affirmative defense. The deadline may move; the evidence obligation does not. WHAT STAYS LOAD-BEARING €35M or 7% of turnover EU AI Act · Commission fining from Aug 2, 2026 Art. 12 and Art. 26 remain in force lifetime event logging and deployer log retention ISO/IEC 42001 is a procurement bar the report has to point at controls that exist Colorado AI Act: alignment is a defense NIST AI RMF / ISO 42001 as an affirmative defense The deadline may move. The evidence obligation does not.

ISO 42001 needs infrastructure, not just a report

GRC platforms automate the documentation of AI governance: framework mappings, policy templates, attestation collection. What they cannot do is BE the control. ISO 42001's Annex A asks for AI event logging, access control, and data management — those controls have to exist in your infrastructure before any tool can attest to them.

DataShield is the layer the report points at: the tamper-evident event log an auditor can re-verify without trusting anyone, the per-tool-call access control the checkbox claims, and the tokenization and crypto-shred that make the data-management clause true. Keep your GRC platform — point it at controls that verify themselves.

ISO 42001 needs infrastructure, not just a report ISO/IEC 42001 Annex A asks for controls that must exist before any tool can attest to them: AI event logging that is tamper-evident and re-verifiable without trust, access control enforced per tool call and revocable mid-session, and data management that tokenizes at ingest and crypto-shreds on erasure. GRC platforms document governance; DataShield is the control the report points at. THE REPORT VS THE CONTROL ISO 42001 Annex A asks for controls that must exist before any tool can attest to them: AI event logging Tamper-evident, re-verifiable without trust Access control Per-tool-call, revocable mid-session Data management Tokenize at ingest, crypto-shred on erasure GRC documents governance. DataShield is the control it points at.

Regulated-industry buyer questions

Does DataShield make our AI system EU AI Act compliant?

No vendor can — compliance spans risk management, oversight, and documentation that belong to you. DataShield supplies the technical substrate for the logging and access-control obligations: Art. 12-style automatic event logging with tamper evidence, retention that stays verifiable, and per-call authorization records.

How is this different from shipping logs to our SIEM?

SIEM logs are mutable — an admin or attacker can edit them and nothing detects it. DataShield's chain makes every row hash-linked with signed, chained checkpoints, so verification mathematically distinguishes tampering, insertion, deletion, and truncation. SIEM export can sit alongside; the chain is the evidence.

Can we satisfy GDPR erasure without destroying our audit trail?

Yes. Actor identifiers are HMAC-committed in the chain, and erasure is crypto-shred — destroy the key material and the personal data becomes irrecoverable while the chain still verifies end to end.

What exactly gets logged per agent action?

Each governed tool call records the agent identity, the token scope it ran under, the authority-tier decision, the revocation re-check, and metering — then seals the record into the chain. The full dispatch pipeline and the ChainVerifyReport schema are published on the architecture page.

What DataShield retires for regulated-industry agents Three mechanisms and the cost each retires: a tamper-evident event log an auditor can re-verify without trusting you; per-tool-call access control that is the control rather than the checkbox claim; and tokenization with crypto-shred so GDPR erasure keeps the audit chain valid. It runs self-hosted or in your VPC, with your keys. WHAT THE SPEND RETIRES Tamper-evident event log An auditor re-verifies without trusting you Per-tool-call access control The control, not just the checkbox claim Tokenize and crypto-shred GDPR erasure that keeps the chain valid Self-hosted or in your VPC, with your keys.
Calculate your ROI

Lifetime logging with tamper evidence, authorization per tool call, erasure without evidence loss — on your infrastructure.

Explore the Demo Center

You've seen the proof

Ready for a number? Scope your deployment and we'll price it against your own economics.

Get your quote →