Skip to content

AI Act Compliance · For deployers

Inherit compliance.
By architecture, not by documentation.

By integrating ELYSÉA CERVEAU, you automatically receive the timestamped logs, complete traceability, and exportable audit report the AI Act requires of deployers — no configuration needed, no additional infrastructure.

Integrate the SDK →Compliance dashboard →

What the AI Act requires of you

Obligations applicable
to conversational AI deployers.

As a deployer (operator under the AI Act), you bear responsibility for the compliance of your AI system towards your users. These four articles have a direct translation in your infrastructure.

Art. 5

Prohibited AI practices — P3, P4

Systems using subliminal techniques or exploiting vulnerabilities to alter human behaviour. CERVEAU's prohibitions P3 (manipulation) and P4 (dependency) cover this perimeter structurally.

Art. 50

AI transparency and identification

Any conversational AI must identify itself as AI. CERVEAU's prohibition P8 enforces this in the pipeline — not configurable by the operator, the Guardian rejects any attempt to bypass it through configuration.

Art. 12

Log retention and record-keeping

High-risk AI systems must retain automatic operation logs. ELYSÉA emits a timestamped HMAC-SHA256 signed log at every interaction — 6-month minimum retention guaranteed by architecture.

Art. 13

Transparency and documentation

Deployers must be able to document their compliance. The ELYSÉA dashboard generates an exportable compliance report (timestamped PDF) presentable to any regulatory authority.


What ELYSÉA provides from integration

Automatic inheritance.
Zero additional configuration.

01

Automatic log at every call

Each interaction produces a timestamped log with the constraintsEnforced (triggered floors), the Guardian posture, and any guardianViolations. No configuration required — it is inherent to the pipeline.

02

Tamper-proof audit trail

Each entry is linked to an HMAC-SHA256 signature emitted by the Core before any storage. It covers the timestamp, appId, constraints, and posture. Verifiable by an external auditor without access to your infrastructure.

03

6-month retention — AI Act

Logs are retained for a minimum of 6 months (AI Act obligation). The Extended plan retains 12 months. Retention is managed Core-side — no log infrastructure to deploy on your end.

04

Compliance report export

The builder dashboard generates a timestamped PDF report over any chosen period — filtered interactions, triggered floors, counters, attested integrity. Presentable to a regulator, DPO, or AI Act auditor.

> ATTESTATION EMITTED — 2026-07-12T09:14:23.441Z

appIdapp_a40a8bd4-008c-4ef4-aef7-b9666d6846a8
constraintsEnforced["dependency"]
guardianViolations["dependency"]
postureblocked
attestation7f3a9c2e4b1d… (HMAC-SHA256)

Honest scope

What we provide.
What we do not claim.

ELYSÉA provides technical proof of architectural compliance — the logs, traceability, and integrity signature. Full regulatory compliance remains your legal responsibility.

ELYSÉA is not an AI Act high-risk certification body. We provide tools exploitable by your internal or external auditors — not the certification itself.

ELYSÉA does not cover obligations that fall under your internal governance (your own GDPR, impact analysis, data policy) — only the technical guarantees of the pipeline.

Traceability is in the pipeline.
Not on your to-do list.

sk_test_ available immediately via the developer portal. Logs active from the first call.

SDK & Pricing →Compare approaches →Compliance dashboard →Talk to the team →