Regulation (EU) 2024/1689Article 50 · In force since 02 Aug 2026Annex III · 02 Dec 2027

The EU AI Act asks for records you do not currently keep.

Article 50 transparency obligations are now in active legal effect across the European Union. High-risk obligations under Annex III become enforceable in December 2027 following the Digital Omnibus agreement.

Five requirements, and how Gateplex meets them.

Mandate & articleSpecific runtime control
Article 12, record-keepingAutomatic logging of every agent action, with the input, rule evaluated, verdict, and timestamp written to a hash-chained record.
Article 14, human oversightRules can require approval, holding the action as PENDING_APPROVAL until a named reviewer decides. The decision is recorded against their identity.
Article 50, transparencyAgent interactions and their governance outcomes are recorded and exportable, so disclosure obligations can be evidenced rather than asserted.
Traceability over the lifecycleRule changes are written to a separate rule audit log, so the policy in force at any past moment can be reconstructed.
Evidence on demandCompliance reports export mapped to the article they satisfy, including hash chain verification status.
Regulatory advisory

Scope reaches beyond the EU.

Organizations deploying public or customer-facing AI agents are legally bound by these disclosure and traceability rules today. The Act applies to providers and deployers whose AI output is used within the European Union, regardless of where the organisation is established.

Penalties reach up to 35 million euro or 7 percent of total worldwide annual turnover for prohibited practices, and up to 15 million euro or 3 percent for other breaches, whichever is higher.

The EU is not the only regulator asking.

Qatar

Qatar Central Bank AI Guideline

Governance, explainability, and oversight expectations for AI used by supervised institutions.

Saudi Arabia

SAMA Counter-Fraud Framework, Section 3.8(d)(8)

Requires that machine learning or AI systems are not a black box and are capable of being audited.

Saudi Arabia

NCA ECC-2:2024 and AI Cybersecurity Guidelines

Essential Cybersecurity Controls in force, with AI-specific guidance in draft.

United Arab Emirates

DIFC Regulation 10

Obligations covering autonomous and semi-autonomous systems processing personal data.

EU AI Act Compliance Mode.

Applying the EU AI Act Article 12 Pack configures logging, retention, and export formatting against the record-keeping obligations, and turns on human approval for the rule classes most likely to be treated as high-risk. Evidence is produced as a by-product of enforcement rather than assembled afterwards.

Find out where you stand before the deadline.