← Back to Trust, Compliance & AI Operations
EU AI Act

Most teams are writing an AI policy. The Act asks them to prove it ran.

The Act applies in phases from 2 August 2026. The teams that struggle will not be the ones without a policy. They will be the ones who cannot show how their AI actually behaved in production.

By Costile · June 2026 · 5 minute read

There is a familiar pattern whenever a new regulation arrives. A working group forms, a policy document gets written, a slide deck explains the company's commitment, and everyone moves on. The EU AI Act will not be satisfied by any of that, because it does not ask what you intend to do. It asks what your systems actually did.

The Act (Regulation 2024/1689) entered into force in August 2024, and its main rules apply from 2 August 2026. Article 6(1) high-risk systems and corresponding obligations follow on 2 August 2027. If your organisation deploys AI in hiring, customer decisioning, critical operations, or any other Annex III category, you are in scope, and the law reaches you based on where the system is used rather than where the company is registered. A team in San Francisco serving European users is as exposed as a team in Berlin.

The Act does not grade your intentions. It asks for two concrete things: a documented process for managing risk across the life of the system, and an automatic, traceable record of how that system behaved in production. Most teams have neither today.

Article 9 is not a policy you write once. It is a process that has to keep running.

Article 9 asks for a risk management system that operates continuously across the life of the AI system, not a document filed at launch and then forgotten. The expectation is that you identify the ways a system can behave badly, watch for those behaviours in production, and show that when something drifted you noticed and responded. A policy that says risk is managed is not the same thing as evidence that it was.

Article 12 is the part most teams cannot produce on demand.

Article 12 asks for automatic record-keeping: logs that capture how the system behaved over its lifetime, traceable back to the events that produced them. For most teams this is the hard one, because the record either does not exist or is scattered across provider dashboards, application logs, and spreadsheets that nobody can assemble into a coherent account of who did what, when, and why.

The good news is that your production traffic is already the evidence.

The work that produces this evidence is not a separate compliance project bolted onto engineering. It is a by-product of running your AI well. If your agent and model traffic already flows through a layer that attributes every call to an owner, watches for behaviour that drifts from what you expect, and keeps a traceable record of it, then your Article 9 process and your Article 12 record largely build themselves.

That is the layer Costile provides. Because your traffic already runs through it, every call is logged and attributed to an API key, an agent, and a team, and every anomaly is captured with its cause and a recommended fix. The risk management in Article 9 and the record-keeping in Article 12 stop being a documentation exercise and become a report you can already produce.

The deadline is the only variable left.

The rules are written, the categories are defined, and the penalties, up to 15 million euros or 3 percent of global annual turnover, are set. The one thing still moving toward you is the date. For most organisations the first real test will not be a regulator. It will be an enterprise procurement team asking for AI governance evidence you do not have, or a board member asking how the AI stack is controlled and the honest answer being that nobody is quite sure.

You do not need a new compliance project. You need to be able to prove how your AI behaved, and that is a record you should already be keeping.

Sources

See what the evidence looks like.

The compliance page walks through how Costile maps to the risk management and record-keeping the Act expects. The demo shows the same data in a working dashboard: spend by owner, agent incidents, and a traceable record of what happened.

Read how Costile maps to the Act · Open the demo

← Back to Trust, Compliance & AI Operations