EVE AI Core
The Infrastructure of No.
For high-risk AI systems, the EU AI Act (Regulation (EU) 2024/1689) expects risk management, record-keeping, human oversight, and traceability — not just documentation. EVE AI Core supplies the runtime layer: it enforces policy on each high-risk decision and captures automatic, tamper-evident, signed evidence that maps to those obligations. EVE provides the technical controls; your compliance conclusion stays yours.
Updated · Maintained by the EVE NeuroSystems engineering team · Reviewed by Jamaurice Holt, Founder
The EU AI Act sets obligations for “high-risk” AI systems that go beyond writing a policy: risk management, automatic record-keeping, transparency, human oversight, and accuracy/robustness expectations that have to hold at runtime. Software that helps with this has to do more than store documents — it has to enforce controls when a decision is made and capture evidence that survives scrutiny later.
EVE AI Core is the runtime component. It enforces policy on each high-risk decision, keeps an automatic tamper-evident record of what happened, and supports a human-in-the-loop checkpoint before consequential actions run. It does not replace your legal analysis or your management system — it provides the technical controls and the evidence they call for.
A plain-language mapping of common high-risk obligations to concrete EVE mechanisms. This is a control mapping, not legal advice.
| EU AI Act obligation | In short | How EVE AI Core supports it |
|---|---|---|
| Article 9 — Risk management | Ongoing risk controls across the lifecycle | Per-decision risk scoring and deterministic policy enforcement at runtime |
| Article 12 — Record-keeping / logging | Automatic logging of events over the system’s lifetime | Automatic, tamper-evident, timestamped signed record of every governed decision |
| Article 13 — Transparency | Traceable, interpretable operation | Each decision records the inputs, verdict, and policy version that applied |
| Article 14 — Human oversight | People can intervene and override | Propose → approve → execute with role-based access; BLOCK / MODIFY before action |
| Article 15 — Accuracy & robustness | Consistent, resilient behaviour | Deterministic, fail-closed decision path; the same inputs always yield the same verdict |
The pack version in force is bound into each decision’s signed evidence, so you can demonstrate which rules governed a specific decision at the time — central to Article 12 record-keeping and to answering a supervisory-authority question about a past decision.
The EU AI Act’s hardest expectations land at the moment a high-risk system acts. EVE CoreGuard is a pre-execution gate: each high-risk decision is risk-scored and evaluated against the versioned policy pack, and the gate returns a deterministic ALLOW, BLOCK, or MODIFY before the action runs. The path is fail-closed — if evaluation cannot complete, the action is refused, not allowed through.
That runtime posture is what turns “we have a policy” into “the policy was enforced on this decision.” It is the same mechanism described on the deterministic AI governance and AI governance runtime pages, applied to high-risk obligations.
Article 12 expects high-risk systems to keep automatic logs over their lifetime. EVE AI Core produces an Ed25519-signed, timestamped certificate for every governed decision, hash-chained into a tamper-evident trail aggregated under signed Merkle roots. Records are automatic (a by-product of enforcement), independently verifiable offline, and deterministically replayable.
For an auditor or supervisory authority, that means the record is something they can check rather than something they must trust — and because the policy version is embedded, the log shows not just what happened but which rules governed it.
Article 14 expects people to be able to oversee and intervene. EVE routes consequential high-risk actions through a propose → approve → execute workflow with role-based access control, so a designated person authorizes them before they run — and the approval (or rejection) is itself recorded in the signed evidence. The gate can also BLOCK or MODIFY an action outright when policy requires it.
Oversight becomes a control in the decision path rather than a paragraph in a manual. Combined with the Article 12 record, you can show both that a human could intervene and that, on a specific decision, the oversight step occurred.
EVE AI Core is a runtime enforcement and evidence layer. It is not legal advice, a conformity assessment, or a substitute for your management system, your technical documentation, or your counsel’s determination that a system is compliant. It provides technical controls and audit-grade evidence that map to specific obligations — and it pairs naturally with an AI governance platform and a GRC/ISO 42001 program that manage the wider process.
Bring a high-risk use case and we will walk it through the gate: the enforcement decision, the human-oversight checkpoint, and the tamper-evident, timestamped record you can verify offline. Controlled pilot from $37,500.
Start lighter: the API reference, the whitepaper, or verify a sample signed decision.
Article mappings describe how EVE AI Core technical controls align to obligations in Regulation (EU) 2024/1689; they are engineering controls and evidence, not legal advice or a determination of compliance. Consult your own counsel. Documented as of . Related: AI compliance software · AI governance platform.