The EU AI Act, enforced
on every request.
Fines reach 35M€ or 7% of global turnover, and the deadlines are fixed. AegisPlane checks each AI request against the Act, article by article. You get exportable evidence for every decision, built from day one.
No code changes. Live on your traffic in a day.
One control sits in front of every model your teams already call, checking each request against the standards your auditors recognize.
What is the EU AI Act?
Ship AI into the EU and the rules already apply to you. The EU AI Act (Regulation 2024/1689) is the first comprehensive law for artificial intelligence. It grades systems by risk: the higher the potential harm, the stricter the obligations, up to outright bans. It reaches any provider or deployer whose AI output is used in the EU, wherever they sit.
- Classifies AI systems into four risk tiers, from prohibited to minimal.
- Imposes transparency, documentation, and human-oversight duties on high-risk systems.
- Fines reach €35M or 7% of global annual turnover, whichever is higher.
- Extraterritorial: it reaches any organization whose AI affects people in the EU.
Four tiers. Different obligations.
The EU AI Act classifies AI systems by potential harm. Each tier carries different obligations. AegisPlane covers you across all of them.
AI systems that pose a clear threat to fundamental rights are banned outright. No exceptions.
Social scoring, subliminal manipulation, real-time biometric surveillance in public spaces.
Systems used in critical sectors must register, document, and pass conformity assessments before deployment.
Hiring tools, credit scoring, medical devices, law enforcement, critical infrastructure.
These systems must meet transparency obligations - users must know they are interacting with AI.
Chatbots, deepfake generators, emotion-recognition tools.
The vast majority of AI applications fall here. No mandatory obligations beyond good practice.
Spam filters, AI-powered search, recommendation engines, productivity tools.
One request, checked in real time
Here is one interaction. AegisPlane classifies the request, checks it against the framework, blocks what it must, and logs the decision as evidence. It happens in milliseconds, on live traffic.
Business value
- Reduces regulatory exposure in EU markets.
- Strengthens governance for higher-risk AI use cases.
- Improves readiness for legal and audit reviews.
How AegisPlane enforces the EU AI Act in the AI Control Plane
The EU AI Act ships as an article-level policy pack in the AegisPlane AI Control Plane (AICP). It runs inline on your AI traffic, no model retraining, no application code changes.
Turn it on in config
Enable the EU AI Act pack in config-as-code. AegisPlane validates it and compiles a deterministic, signed policy bundle, no code changes in your app.
Checked at the gateway
Every request and response flows through the AegisPlane gateway, where the OPA policy engine evaluates it against EU AI Act articles (Art. 5 prohibitions, Art. 50 transparency, high-risk duties). Enforcement is configurable and fail-open by default.
Guardrails + PII redaction
Two-sided guardrails catch prohibited-practice and manipulation patterns, and Presidio-based redaction strips personal data before it reaches a third-party model.
Logged as evidence
Each decision is recorded with the specific article it maps to, plus cost, latency, and quality telemetry, queryable and exportable for DPA audits and conformity assessments.
The evidence that answers the auditor's next question.
AegisPlane generates the continuous evidence that regulators, auditors, and enterprise buyers ask for: every interaction logged with its policy decision and the article it maps to. AegisPlane is not a certification body and does not certify your organization. The attestation stays with you and your auditors. What you get is the record that makes demonstrating it dramatically easier.
How it works
- 1Turn on the EU AI Act framework in your AegisPlane settings.
- 2Every AI interaction is checked against the regulation from that moment on.
- 3Evidence accumulates continuously: flagged violations, transparency logs, per-article decision records.
- 4Export the audit trail on demand (for an auditor, a regulator, or a customer questionnaire) without reconstructing anything.
Frequently asked questions
No. AegisPlane is not a certification or notified body and does not certify you. It gives you continuous article-level checks and exportable evidence that make demonstrating compliance to your auditors and regulators far less manual.
The pack focuses on the runtime-observable obligations: Article 5 prohibited practices, Article 50 transparency duties, and the high-risk classification and logging obligations that can be evaluated on live traffic.
Likely yes. The EU AI Act is extraterritorial, it applies whenever your AI system's output is used within the EU, regardless of where your company is located.
Only if you configure it to. Enforcement is fail-open by default: checks and evidence run continuously, and you decide which categories actively block versus flag-and-log.
Every policy decision is logged with its article reference and telemetry, and can be offloaded to object storage for long-term retention and export.
Why now
Continuous checks and evidence, not a stale annual assessment
Full enforcement lands August 2026. Evidence built from today beats a scramble later. Every selected framework is checked on live AI traffic and the decision is logged as evidence, so audit prep stops being a fire drill. No code changes.
