Skip to main content
Connic
Back to Legal

EU AI Act Compliance

Last updated: July 30, 2026

Update: AI Omnibus Timeline (July 2026)
The AI Omnibus, Regulation (EU) 2026/1744, entered into force on July 27, 2026. It sets December 2, 2027 for stand-alone high-risk systems and August 2, 2028 for high-risk systems embedded in regulated products. Article 50 duties generally apply from August 2, 2026. Providers of generative systems already on the market have until December 2, 2026 to meet Article 50(2)'s machine-readable marking duty. See the current high-risk timeline and Article 50 guidance.

The EU Artificial Intelligence Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on August 1, 2024 and introduces a risk-based approach to regulating AI systems, with obligations phased in between February 2025 and August 2028.

Connic is built to make the technical compliance layer easier to configure, operate, and evidence. We meet the obligations applicable to our platform and give customers approvals, traces, guardrails, audit history, and documentation to support their own EU AI Act programs. The obligations that apply to each party still depend on its legal role and use case.

Our Role Under the EU AI Act

The EU AI Act defines a provider as an organization that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority, except for personal, non-professional use. These roles depend on the facts, not simply on which infrastructure an AI system runs on.

  • Connic as a managed platform: We provide the infrastructure for deploying, running, and monitoring AI agents. Providing that infrastructure does not, by itself, determine the statutory role for every AI system deployed on it.
  • Model choice by design: Customers can select EU-hosted connic/* models or configure BYOK providers. GPAI model-provider obligations under Articles 51-56 remain with the relevant model provider. This does not transfer system-level provider or deployer duties to the selected model provider.
  • Supporting customer responsibilities: Depending on how you build, brand, offer, or use an agent, you may be a provider, deployer, or both. Connic gives you practical tooling, controls, and evidence to support the obligations that apply to your use case.

Risk Classification

The EU AI Act is often summarized through four practical risk categories. These are useful for orientation, but the obligations that apply depend on the system, its intended purpose, and each party's role:

Unacceptable Risk (Prohibited)
AI systems that pose a clear threat to fundamental rights are banned entirely. This includes social scoring, subliminal manipulation, real-time biometric identification in public spaces, and emotion recognition in workplaces or educational institutions. Connic's Terms of Use explicitly prohibit deploying agents for any of these purposes.
High Risk
Specific systems listed in Annex I or Annex III—including some uses in regulated products, biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice—can be high-risk. Classification turns on intended purpose and applicable exceptions. When your agent is high-risk, Connic provides the platform capabilities below to support your compliance.
Specific Transparency Duties
Article 50 assigns specific provider and deployer duties for direct interaction, synthetic-output marking, deepfakes, and certain public-interest text. The precise disclosure or marking duty depends on the system and role; it is not a blanket label requirement for every AI-generated output.
Other AI Systems
Systems outside the prohibited, high-risk, and specific transparency categories generally avoid the Act's high-risk requirements. Other AI Act duties, general laws, and voluntary codes of conduct may still be relevant to the particular system or organization.

Prohibited Practices

Since February 2, 2025, the EU AI Act's prohibitions on unacceptable-risk AI practices are in effect. In alignment with Article 5 of the Act, the Connic platform must not be used to deploy agents that:

  • Use subliminal, manipulative, or deceptive techniques to distort behavior in ways that cause significant harm
  • Exploit vulnerabilities of specific groups (age, disability, socio-economic situation)
  • Classify or score individuals based on social behavior or personal characteristics, leading to detrimental treatment (social scoring)
  • Assess or predict the risk of criminal offenses based solely on profiling or personality traits
  • Build or expand facial recognition databases through untargeted scraping of images
  • Infer emotions of individuals in workplace or educational settings, except for medical or safety purposes
  • Perform real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, outside of narrowly defined exceptions

These prohibitions are enforced through our Terms of Use and our acceptable use policies. Violations may result in immediate suspension of service.

AI Literacy

Article 4 has applied since February 2, 2025. As amended by the AI Omnibus, it requires providers and deployers to take measures that support the development of AI literacy among staff and others operating AI systems on their behalf, without requiring a guaranteed level for each individual.

Connic supports AI literacy in several ways:

  • Comprehensive documentation: Our documentation covers agent configuration, deployment, connectors, observability, and platform capabilities in detail so teams understand how agents work and how to operate them responsibly.
  • Transparent agent behavior: The observability features in our platform make agent execution traceable, helping users understand what steps an agent took and what each recorded step used or returned.
  • Agent templates: Our agent template library includes examples and documentation that help teams understand best practices for responsible AI agent deployment.

Transparency

Article 50 assigns different transparency duties to providers and deployers. Providers of systems that interact directly with people generally must design them so users are informed, while providers of generative systems have machine-readable marking duties for synthetic outputs, subject to exceptions. Deployers have disclosure duties for deepfakes and certain public-interest text. Connic gives teams customer-controlled building blocks for the duties that apply:

  • AI disclosure support: When agents interact with end users (e.g. via webhooks, email, or Telegram), you can include clear AI disclosure notices in your agent's system prompt and output formatting.
  • Content disclosure configuration: For deepfakes or relevant public-interest text, you can configure visible disclosures in the agent's prompts and output format. Machine-readable markings required of providers under Article 50(2) must be supplied by the selected model or application layer.
  • Configuration evidence: Connic agent definitions record model selection, tool access, and system instructions, giving teams a concrete basis for system documentation through the agent configuration system.

Human Oversight

Article 14 requires providers of high-risk AI systems to design them for effective human oversight. Article 26 requires deployers of high-risk systems to assign competent people to carry out that oversight and use the measures provided. Connic makes these controls practical.

Connic provides several capabilities to support meaningful human oversight:

Approval gates
The approvals system allows you to require human review and confirmation before agents execute sensitive actions, ensuring a human remains in the loop for consequential decisions.
Real-time monitoring
The observability dashboard provides real-time visibility into agent runs, including status, duration, tool calls, and token usage, enabling operators to monitor agent behavior as it happens.
Run inspection
Every agent execution produces a detailed trace of recorded LLM calls, tool invocations, inputs, and outputs, making the execution path inspectable. Captured model reasoning appears when configured and returned by the provider.
Agent evaluation
The judges system enables automated quality evaluation of agent outputs, adding a layer of programmatic oversight alongside human review.

Data Governance

Article 10 of the EU AI Act requires that training, validation, and testing data for high-risk AI systems meets quality criteria and is subject to appropriate governance practices. While Connic does not train AI models, we support data governance across the agent lifecycle:

  • No training on customer data: Data processed through Connic is never used to train, fine-tune, or improve AI models. Your data is used solely to execute your agents as configured.
  • Data minimization: Agents process only the data necessary for their designated tasks. You control what data your agents access through tool configuration and environment variables.
  • Data residency: You choose your project's data region at creation time. The selected region controls where primary Customer Personal Data is stored and processed, subject to your plan and settings. As described in our Data Processing Agreement, limited processing may occur elsewhere for support or infrastructure maintenance, with applicable transfer safeguards. Model-provider processing follows your chosen provider and configuration.
  • Retention controls: Agent execution logs are retained according to your subscription tier. Data is deleted in accordance with our Privacy Policy and Data Processing Agreement.
  • Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). See our Security page for full details.

Record-Keeping & Audit Trails

Articles 12, 19, and 26 distribute logging and record-retention duties across providers and deployers of high-risk systems. Connic's observability and audit tooling give teams the execution evidence and change history needed to support those duties:

  • Comprehensive execution logs: Every agent run records its trigger source, available input and output data, model, tool calls, duration, token usage, and final status.
  • Structured traces: Agent executions produce hierarchical traces showing the execution path from initial prompt through each recorded tool call and LLM interaction to final output. Provider-returned reasoning is displayed when available.
  • Version history: Agent configurations are version-controlled through Git, providing a full history of changes to agent definitions, system prompts, tools, and settings.
  • Usage tracking: The usage dashboard provides aggregated metrics on agent activity, costs, and performance over time.
  • Immutable audit history: Project audit logs preserve configuration and approval events in an immutable history, giving reviewers evidence of who changed or approved what.
  • Programmatic evidence access: Project-scoped REST API permissions let you retrieve run records, structured traces, and audit-log data for external monitoring and governance workflows.

Risk Management

Article 9 of the EU AI Act requires providers of high-risk AI systems to establish and maintain a risk management system. As a deployer, Article 26 requires you to use high-risk AI systems in accordance with their instructions for use and to monitor their operation. Connic supports these requirements through:

  • Testing and validation: The testing framework allows you to validate agent behavior before deployment, ensuring agents perform as expected across representative scenarios.
  • Environment separation: The environments system supports staging and production separation, enabling you to test agents safely before deploying them to production.
  • Automated evaluation: The judges system allows you to define quality criteria and automatically evaluate agent outputs against them, catching regressions or unexpected behavior.
  • Incident monitoring: Real-time alerting on failed runs and anomalous behavior helps you identify and address issues promptly.
  • Rollback capability: Git-based deployments support instant rollback to previous versions if a new agent version exhibits unexpected behavior.

Security & Robustness

Article 15 of the EU AI Act requires high-risk AI systems to achieve appropriate levels of accuracy, robustness, and cybersecurity. Our platform's security posture is designed to support these requirements:

  • Container isolation: Each customer's agents run in isolated containers with strict resource limits, preventing cross-tenant interference.
  • Ephemeral execution: Agent execution environments are destroyed after use, minimizing the persistence of sensitive data.
  • Secrets management: API keys and credentials are encrypted at rest and injected securely at runtime, never stored in code or logs.
  • Infrastructure certifications: Our cloud providers maintain SOC 2 Type II, ISO 27001, and PCI DSS certifications.

For comprehensive details on our security measures, see our Security page.

Penalties Under the EU AI Act
Under Article 99, maximum administrative fines include €35 million or 7% of worldwide annual turnover for prohibited-practice violations, €15 million or 3% for specified operator obligations, and €7.5 million or 1% for supplying incorrect, incomplete, or misleading information. For undertakings, the higher ceiling applies; for SMEs, including startups, the lower ceiling applies. Actual penalties depend on the circumstances. Connic's approvals, traces, testing, and access controls help teams build a more defensible deployment and evidence trail.

Shared Responsibility

EU AI Act compliance is a shared responsibility between Connic and our customers. As a general guide:

ResponsibilityConnicCustomer
Platform infrastructure security
Logging, observability, and audit trail tooling
Human oversight and approval gate features
Classifying your AI use cases by risk level
Conducting fundamental rights impact assessments
Ensuring appropriate AI disclosure to end users
Configuring human oversight for high-risk uses
Complying with GPAI model provider requirementsModel provider
Need EU AI Act evidence before launch?

Bring the agent use case, risk category, human-oversight requirement, and logging obligations. We will map those to Connic approvals, traces, audit logs, and deployer documentation.

Talk through EU AI Act readiness

Questions About EU AI Act Compliance?

If you have questions about how the EU AI Act applies to your use of Connic, or if you need our available compliance documentation or help mapping requirements to Connic's platform controls, please contact us: