Compliance Matrix

Disclaimer: This matrix describes what Fuze supports today. Claims labelled "Partial" or "Not implemented" are on the roadmap. Labels updated: 2026-04-19.

Article-by-article mapping of EU AI Act requirements to Fuze features.

Coverage legend: Covered = Fuze directly satisfies the requirement | Partial = Fuze addresses part of the requirement; gaps noted | Not implemented = not yet available | Outside scope = provider/deployer responsibility, no runtime tool can address it

High-Risk System Requirements (Art. 8-15)

ArticleDescriptionCoverageNotes
Art. 8Compliance with requirementsOutside scopeOrganisational responsibility
Art. 9Risk Management SystemPartialRisk questionnaire + evidence upload in dashboard; no automated risk-tracking loop yet
Art. 10Data and Data GovernanceOutside scopeDeployer responsibility
Art. 11Technical DocumentationPartialAnnex IV export (PDF) available; model cards not auto-generated
Art. 12Automatic LoggingCoveredFull JSONL trace per guarded call; HMAC hash chain (Python); TS hash chain on roadmap
Art. 13Transparency to DeployersPartialTrace replay with full decision context; model cards not auto-generated
Art. 14Human OversightPartialKill switch via dashboard and CLI; approval gates not yet implemented
Art. 15RobustnessCoveredLoop detection (iteration cap, hash dedup, stalled progress), side-effect compensation with LIFO rollback, token/step/wall-clock limits

Provider and Deployer Obligations (Art. 16-27)

ArticleDescriptionCoverageNotes
Art. 16Provider ObligationsOutside scopeOrganisational responsibility
Art. 17Quality Management SystemOutside scopeOrganisational responsibility
Art. 18Documentation KeepingPartialAnnex IV export covers technical documentation; QMS records are deployer responsibility
Art. 19Auto-Generated LogsCovered (Python) / Partial (TS)Python: append-only store + HMAC hash chain; TS: append-only store, no hash chain yet
Art. 20Corrective ActionsPartialGuard events and traces surface issues; corrective workflow is deployer responsibility
Art. 26Deployer Monitoring ObligationsPartialDashboard provides runs list, agent health, trace replay; audit log of dashboard actions not yet implemented
Art. 27Fundamental Rights Impact AssessmentPartialFRIA builder is on the Pro tier roadmap; not yet available

Post-Market and Incident Reporting

ArticleDescriptionCoverageNotes
Art. 72Post-Market MonitoringPartialRuntime metrics collected (tokens, steps, latency, guard-event rate); automated drift detection not implemented
Art. 73Serious Incident ReportingNot implementedRoadmap, no automated 72h/15d filing; manual process required

GPAI Transparency

ArticleDescriptionCoverageNotes
Art. 50Transparency for GPAI outputs (chatbots, deepfakes)Not implementedDisclosure system not yet designed or built; roadmap

Summary

StatusArticles
CoveredArt. 12, Art. 15, Art. 19 (Python)
PartialArt. 9, Art. 11, Art. 13, Art. 14, Art. 18, Art. 19 (TS), Art. 20, Art. 26, Art. 27, Art. 72
Not implementedArt. 50, Art. 73
Outside scopeArt. 8, Art. 10, Art. 16, Art. 17

Art. 12 in detail

What Fuze logs for every guarded function call:

Data PointSource
Start/end timestamps (ISO 8601)Every @guard call
Agent identityagent_id, version, model, provider
Tool call detailsName, args hash (raw opt-in via log_pii), result summary
Token countsTokens in/out extracted from LLM response; USD estimate where pricing table available
Guard decisionsproceed, loop_detected, limit_exceeded
Human oversight eventsWho intervened, what they decided
Side-effect statusReal-world write flag, compensation status

All Python records: append-only, HMAC-SHA256 hash-chained, queryable, exportable (JSON, CSV, PDF). TypeScript records: append-only; hash chain on roadmap. Configurable retention minimum 6 months.

Art. 14 in detail

RequirementStatusNotes
Understand capabilities, monitor operationCoveredDashboard with live runs, agent health, trace replay
Correctly interpret outputCoveredTrace replay with full decision context
Decide not to use outputCoveredOverride capability via dashboard
Intervene or interrupt (stop button)CoveredKill switch: dashboard and CLI
Approval gates before agent proceedsNot implementedRoadmap