Company · Compliance
Agent evidence under the EU AI Act (Art. 12)
The AI Act obligations arrive in stages (high-risk: December 2027 or August 2028 under the Digital Omnibus) — and the regulator's question will be the same: show me, tamper-evidently, what your AI agents were allowed to do and did. Can you export — or will you have to reconstruct?
Article 12 requires automatic, tamper-evident recording of AI decisions, documented human oversight and the ability to stop a system — with fines up to 7% of global revenue. Mandact is the authorization and evidence layer for exactly that: every agent action is checked against your rules, every decision (every no, every human approval with a second factor) lands in a hash-chained evidence log an auditor can recompute without us. Entry is evidence-only: 30 days of pure witnessing, zero intervention in your agents — after which you know what enforcement needs.
Use cases
Tamper-evident recording
Append-only chain, hash-linked per organization, timestamp-bound — an agent cannot alter its own entries (Art. 12, literally).
Human oversight, on the record
Escalation above a threshold, approval only with a second factor, form-bound cases at the signing station (MD-404) — every intervention becomes part of the chain.
Stop capability, proven
The kill switch freezes the portfolio atomically; from the next request every agent gets a no — including a chain entry proving you COULD stop.
Regulator export
Verified chain snapshot, independently checkable via the public verification key — no trust in Mandact required.
ROI argument
The compliance budget already exists; a single passed audit replaces weeks of internal log archaeology. Entry without deployment risk (evidence-only).
The receipt checker at /en/verify shows independent verification live — the same mechanics your auditor uses.