Overview
The EU Artificial Intelligence Act (EU 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It entered into force in August 2024 and applies a tiered, risk-based approach - imposing the most stringent requirements on AI systems used in high-stakes contexts. For providers and deployers of high-risk AI systems, the Act creates extensive documentation, logging, and audit obligations that must be met before deployment and maintained throughout the system’s operational lifetime. ROOTKey addresses the core evidentiary challenge of the AI Act: the requirement to demonstrate, with verifiable evidence, that an AI system was developed, assessed, deployed, and monitored in accordance with the regulation - and that the records supporting that demonstration have not been altered after the fact.Risk Classification
High-risk AI systems are listed in Annex III of the Act, including:
- Biometric identification and categorisation systems
- AI used in critical infrastructure management
- AI in education (student assessment, admission)
- AI in employment (recruitment, performance evaluation)
- AI in access to essential services (credit scoring, insurance)
- AI in law enforcement (crime prediction, evidence evaluation)
- AI in border control and migration
- AI in administration of justice
Article-Level Coverage
Article 9 - Risk Management System
Article 9 requires providers to establish and maintain a documented risk management system throughout the AI system’s lifecycle.Article 10 - Data and Data Governance
Article 10 requires training, validation, and testing data to be subject to documented governance practices.Article 11 - Technical Documentation
Article 11 requires providers to draw up technical documentation before placing a high-risk AI system on the market. That documentation must be kept up to date throughout the system’s lifetime.Article 12 - Record-Keeping
Article 12 requires high-risk AI systems to automatically log events throughout their operation - to the extent necessary to ensure post-market monitoring and investigation of incidents.Article 12 is the strongest ROOTKey alignment in the EU AI Act. The requirement for tamper-evident, automatically generated logs that cannot be modified - and that are accessible to authorities - is precisely what blockchain anchoring provides structurally, not by policy.
Article 13 - Transparency and Provision of Information
Article 13 requires providers to ensure high-risk AI systems are sufficiently transparent to allow deployers to interpret and use outputs correctly.Article 14 - Human Oversight
Article 14 requires high-risk AI systems to be designed to allow effective human oversight, and requires deployers to implement oversight measures.Article 17 - Quality Management System
Article 17 requires providers to implement a quality management system covering the full AI lifecycle.Article 61 - Post-Market Monitoring
Article 61 requires providers to implement post-market monitoring plans and collect data from deployed high-risk AI systems.Obligations by Role
Conformity Assessment and CE Marking
Before a high-risk AI system can be placed on the EU market, it must undergo a conformity assessment. ROOTKey supports the evidence layer:Compliance Timeline
Request an EU AI Act compliance review
We’ll classify your AI systems by risk tier, map the applicable obligations, and design a ROOTKey implementation for your logging, documentation, and conformity evidence architecture.
AI System Integrity use case
Full implementation guide for AI Act-compliant model provenance, decision logging, and human oversight records.

