Compliance Matrix

Article-by-article mapping of EU AI Act requirements to Fuze features.

Coverage legend: Covers = Fuze directly satisfies | Assists = Fuze helps but doesn't fully satisfy | Outside scope = provider/deployer responsibility

High-Risk System Requirements (Art. 8-15)

ArticleDescriptionCoverage
Art. 8Compliance with requirementsAssists
Art. 9Risk Management SystemAssists
Art. 10Data and Data GovernanceOutside scope
Art. 11Technical DocumentationAssists
Art. 12Record-KeepingCovers
Art. 13Transparency to DeployersCovers (logs)
Art. 14Human OversightCovers
Art. 15RobustnessCovers

Provider and Deployer Obligations (Art. 16-27)

ArticleDescriptionCoverage
Art. 16Provider ObligationsAssists
Art. 17Quality Management SystemAssists
Art. 18Documentation KeepingAssists
Art. 19Auto-Generated LogsCovers
Art. 20Corrective ActionsAssists
Art. 26Deployer ObligationsCovers
Art. 27Fundamental Rights Impact AssessmentOutside scope

Post-Market and Incident Reporting

ArticleDescriptionCoverage
Art. 72Post-Market MonitoringCovers
Art. 73Serious Incident ReportingCovers

Other

ArticleDescriptionCoverage
Art. 50Transparency (chatbots, deepfakes)Outside scope

Summary

8 articles covered, 6 assisted, 3 outside scope.

The 3 outside scope (Art. 10 data governance, Art. 27 fundamental rights impact assessment, Art. 50 transparency labelling) require organisational processes or UI changes that no runtime safety tool can address.

Art. 12 in detail

What Fuze logs for every guarded function call:

Data PointSource
Start/end timestamps (ISO 8601)Every @guard call
Agent identityagent_id, version, model, provider
Tool call detailsName, args hash, result summary
Cost trackingTokens in/out, USD
Guard decisionsproceed, loop_detected, budget_exceeded
Human oversight eventsWho reviewed, what they decided
Side-effect statusReal-world consequences, compensation status

All records: append-only, hash-chained, minimum 6-month retention, queryable, exportable (JSON, CSV, PDF).

Art. 14 in detail

RequirementFuze Feature
Understand capabilities, monitor operationDashboard with live runs, agent health
Correctly interpret outputTrace replay with full decision context
Decide not to use outputOverride capability via dashboard
Intervene or interrupt (stop button)Kill switch: dashboard, CLI, TUI
Proportionate to riskConfigurable guard levels per agent