EU AI Act readiness

Built for the work the AI Act actually demands.

The EU AI Act doesn't regulate models — it regulates how organizations run them: data governance, logging, transparency, human oversight, robustness. Cortex was designed around exactly those operations, so the evidence your auditors ask for is a by-product of using the platform.

EU AI ACT · READY
Data residency — your stack, your region, or on-premise
Human oversight — approval gates enforced by the runtime
Record-keeping — the audit trail is a by-product
The compliance gap

The model was never the problem.

Most enterprise AI initiatives don't fail a technical evaluation — they fail the review that comes after it. Generation is easy; accountability is hard. Three questions decide whether an AI system ships in a regulated organization, and a chat window answers none of them.

Q1

Where is the data?

One organization, one stack. Your documents, telemetry, and memory live on infrastructure dedicated to you — self-hostable, down to local voice transcription and local observability.

Q2

Who approved this?

Risky actions stop at approval gates, and every capability check, approval, and denial is recorded with actor, target, scope, and timestamp.

Q3

Why did it act?

Sessions are reconstructable: transcripts, tool calls, the policies applied, and memory recalls with their sources. Behaviour under uncertainty surfaces instead of hiding.

Mapping our capabilities

Which capability supports which obligation.

An honest mapping from the AI Act's operational requirements to what the platform actually does — so your compliance team can verify each claim on a live stack.

AI Act requirement
What it asks for
How Cortex supports the work
Article 10 · Data governance
Quality, relevance, and control of the data the AI system operates on
A dedicated stack per organization keeps data, retrieval, and telemetry inside your governance boundary. Retrieval and memory operate on your indexed sources — and self-hosted deployment keeps residency under your control.
Article 12 · Record-keeping
Automatic logging of events for traceability and post-market monitoring
Capability checks, approvals, denials, and agent actions are recorded with actor, target, scope, and timestamp — an audit trail produced by normal operation, not reconstructed after the fact.
Article 13 · Transparency
Information sufficient for deployers to interpret output and use the system appropriately
Every session is reconstructable: transcripts, tool calls, policies applied, and memory recalls with linked sources. Uncertain or refused actions surface explicitly instead of being papered over.
Article 14 · Human oversight
Humans able to monitor, intervene, and override the system in operation
Approval gates stop risky actions until a person decides — in Cortex Control, the CLI, or the chat thread itself. Capability roles cap what any agent may do, independent of who is driving it.
Article 15 · Accuracy, robustness, cybersecurity
Consistent performance, resilience, and protection against manipulation
On our open benchmark, the same model governed by Cortex resists ~47% more jailbreak attempts and meets more of the spec. Sandboxed runtimes, software-registry governance, secret redaction, and OS-level guardrails reduce the attack surface.
Annex IV · Technical documentation
Documentation of system design, capabilities, limitations, and validation
Policies, audit records, benchmark results, and reconstructable session trails produce documentation as an artifact of operation — not as a separate exercise your team has to backfill.

Cortex is not a certification, and no platform can make your AI system compliant by itself. What the architecture does is make the evidence auditors ask for — logs, approvals, provenance, residency — fall out of normal operation. We work alongside your compliance team, and our security overview is available on request.

Data residency

On-premise isn't a pricing tier. It's the design.

Cortex runs as a self-contained stack — the same architecture whether we host your dedicated environment or you run it inside your own perimeter.

cortex control plane · your-orgLIVE
ROOTalpha-omega DEDICATED · ONE ORG / ONE STACK controldashboard novaagents runtimesdeploys
Region
hel1
Plan
team
Status
healthy
Provisioned
4m 12s
Your perimeter, your rules

Everything the agents touch stays home.

Model calls go to the providers you configure with your keys; everything else — identity, retrieval, memory, observability, even voice transcription — runs locally on the stack. Operators from our side reach in only through short-lived, audited, revocable delegation.

  • +Dedicated VM, identity provider, and data boundary per organization
  • +Local speech-to-text and local observability — no third-party required
  • +Infrastructure as code — no cloud provider lock-in
  • +Root access only via short-lived, audited delegation

Bring your compliance team.

We'll walk your security and compliance stakeholders through the architecture, the audit trail, and the benchmark — on a live stack, not a slide deck.

Get started Read the security overview