EU AI Act
Most of the Act asks what you did. Have the answer.
Almost every company using AI is a deployer, not a provider, and a deployer's obligations are about oversight, records and telling people what is going on. Akumi records which models ran, for which purpose, in which region and under whose oversight, and builds the deployer record from it. What the Act asks you to decide stays yours.
roles · records · oversight
The last two are yours. No platform can hold them for you.
The hard part is not the rule. It is showing what you did.
A deployer has to know which AI systems it is using, keep them under human oversight, hold on to the logs, and be able to say what ran and why. Most teams cannot answer the first question, because AI arrived through five applications and nobody kept a list. The obligation is not difficult. Reconstructing a year of behaviour from provider dashboards is.
What is built in
The record writes itself.
Three of a deployer's duties turn into evidence rather than paperwork, because the platform is the thing that ran the model.
You know what you are running
Every model call from every product writes one line: which model, which region, which services applied, and under which policy. The inventory is a query, not a survey.
The logs are kept
The audit trail is retained for the window your policy sets and exported for a date range, so "keep the logs" is a setting rather than a project.
Oversight has something to look at
A person reviewing the system sees what actually ran, including what was refused, rather than a description of what was supposed to happen.
Which service does what
The evidence comes from the services.
Nothing here is a compliance module bolted on the side. The record is a by-product of the services that served the request.
- Audit TrailOne metadata-only line per request, from every product.
- Compliance CenterThe deployer record, built from those lines.
- Model RouterWhich models are allowed for which data, enforced per request.
- Inference APIThe EU-resident models the record describes.
- ObservabilityWhat each stage did, when a reviewer asks.
- FirewallPersonal data pseudonymized before any external call.
The honest split
A platform cannot deploy your system for you.
The Act puts duties on the organization using the AI, and most of them are decisions about your own system. Here is what we can and cannot do.
Classification is yours
Whether your use is high-risk, subject to transparency duties, or neither depends on what you built and who it affects. We cannot tell you, and a tool that offers to is guessing.
Oversight is people
Human oversight is a person with the authority and the training to intervene. We give that person the record. We cannot be that person.
Telling your users is your interface
Where the Act asks you to disclose that someone is dealing with AI, or to mark generated content, that lives in your product, not in ours.
This is not a certification
The deployer record is your own document, generated from evidence. It is not an audit, an attestation or a third-party certificate, and we will not present it as one.
FAQ
Questions people ask about the AI Act.
- Are we a provider or a deployer?
- If you use an AI system in your own operations rather than placing one on the market, you are a deployer. Most companies calling a model through an API are. Where your product changes what the system does, take advice rather than a default.
- Does using Akumi make us compliant?
- No. It gives you the records and controls a deployer needs, and it does not decide how your system is classified or who oversees it.
- What does the deployer record contain?
- Which models were used, for which purpose, in which region and under whose oversight, assembled from the audit trail rather than written from memory.
- How long are the logs kept?
- For the retention window your plan sets and your policy chooses, and they export for a date range.
- What about the models themselves?
- Obligations that fall on whoever built and placed a model on the market are theirs, not yours and not ours. What you can show is which of them you used, and when.
Start here
Start the record before you need it.
Create a key and the trail starts filling from the first request. The deployer record builds itself from it, or talk to us about your obligations.