The deadline is not upcoming. It passed.
MEASURED 2 August 2026 — full application of the high-risk obligations (Articles 9–17 for providers, Article 26 for deployers) under Regulation (EU) 2024/1689. Automatic event logging under Article 12 is now enforceable law for in-scope systems, and deployers carry the mirror duty to keep those logs for at least six months. Maximum penalties under the Act reach €35M or 7% of global turnover for the most serious infringements.
Every required audit-trail field, mapped to a receipt field
2026 audit-trail checklists for SOX, HIPAA, the EU AI Act, FFIEC, and PCI DSS v4.0 converge on the same twelve fields. Each maps to a field a GovernedAction/v1 receipt already carries:
| Required audit-trail field | GovernedAction/v1 receipt binding |
|---|---|
| Timestamp (NTP-synced, UTC) | issued_at — UTC issuance time inside the signed envelope |
| Unique decision ID | action_id — unique per gated action |
| Authenticated human identity | approver — approval tier and identity, where a human gate fired |
| AI system identity and version | subject digest + source revision binding |
| Model identity and version | Model/provider provenance recorded per response |
| Inputs received, with source attribution | Evidence references bound into the payload digest |
| Policy, rule, or prompt invoked | policy_gates — the gates traversed, by name and version |
| Reasoning in human-readable language | Bounded loop trace attached to the receipt |
| Output produced | Output digest inside the signed subject |
| Action taken downstream | admission result — admitted, held, or denied, with the executed effect |
| Human review / approval identity | Approval record at the caller's tier |
| Tamper-evident integrity proof | DSSE envelope, ECDSA P-256 signature, hash-chained ledger — alter one byte and offline verification fails |
Prove it without talking to us
Offline verification, no server in the trust path
Take any receipt to /verify. The check runs entirely in your browser against the published keys. Tamper a byte and watch it fail. No SZL server decides anything — that is the difference between a governance dashboard and governance proof.
Adversarial test suite
The GovernedAction/v1 format ships with a public adversarial suite — 64 held proof-of-concept attacks against the receipt claim — plus PASS/FAIL-labeled conformance vectors so you can test your own verifier against ours.
Honest boundaries
- NOT LEGAL ADVICE SZL Holdings builds technical infrastructure. Whether your system is in scope of Annex III, and what your full obligations are, is a question for your counsel.
- CONFORMANCE ≠ CERTIFICATION An Article 12 conformance profile is a technical mapping, not a certification. No notified body has certified anything here, and we say so.
- MEASURED Receipts verify offline against published keys today. That specific claim you can test yourself, right now, at /verify.
Start
The 30-day Governed Evidence Pilot wires one of your agent workflows end to end: policy gates on every action, signed hash-chained receipts, ten controls mapped to ISO/IEC 42001, the EU AI Act, and NIST AI RMF, an auditor export bundle, and an external adversarial review — fixed scope, fixed price, measurable acceptance in writing up front.