Prohibitions and AI literacy
Chapter I and Article 5 prohibited practices began applying, alongside Article 4 AI-literacy obligations.
Connect high-risk AI obligations to runtime records, policy decisions, human oversight, and evidence workflows without treating infrastructure as a compliance certificate.
The EU AI Act entered into force on 1 August 2024. Its requirements apply in stages, so teams should identify their role and risk category before selecting controls or evidence workflows.
Chapter I and Article 5 prohibited practices began applying, alongside Article 4 AI-literacy obligations.
Several governance, general-purpose AI, notified-body, confidentiality, and penalty provisions began applying.
Most provisions apply from August 2026; Article 6(1) product-safety high-risk obligations apply from August 2027.
The exact obligations depend on whether your organization is a provider, deployer, importer, or distributor and whether the system is prohibited, high-risk, transparency-regulated, or outside those categories.
| EU AI Act area | What a team may need to demonstrate | AxonFlow contribution |
|---|---|---|
| Article 9 risk management | Known risks, controls, testing, residual-risk decisions, and change history. | Policy enforcement and framework-oriented records can support a broader risk-management process. |
| Article 12 record keeping | Automatically generated logs appropriate to the system's intended purpose and risk. | Governed request, policy, approval, and execution records with correlation context. |
| Article 13 transparency | Capabilities, limitations, input expectations, oversight measures, and log interpretation. | Response metadata and runtime evidence can support documentation supplied to deployers. |
| Article 14 human oversight | Meaningful ability to understand, intervene, override, or stop where required. | Configured HITL queues and circuit-breaker workflows provide intervention points. |
| Article 15 accuracy, robustness, cybersecurity | Defined metrics, testing, monitoring, resilience, and security controls. | Operational records and licensed evidence workflows; model testing remains external. |
| Article 43 conformity assessment | Applicable assessment procedure and supporting technical evidence before placement or use. | Enterprise workflow APIs can organize evidence; AxonFlow does not perform or certify conformity. |
Document intended purpose, affected people, prohibited-practice screening, high-risk category, and whether you are acting as provider or deployer.
Apply policies and human review before high-impact model or tool actions, then test failure and emergency-stop behavior.
Carry correlation identifiers from governance decisions into model, gateway, and downstream system logs.
Verify that records identify the policy, actor, model or tool, decision, timestamp, approval path, and downstream effect.
Use the licensed compliance workflows for conformity, approval, policy-violation, and model-quality evidence where applicable.
Test reviewer escalation, circuit-breaker activation, rollback, and evidence preservation before production approval.
Use the Evaluation license to assess policy enforcement, human review, evidence records, and deployment boundaries before a regulated rollout.