The EU AI Act

Where our products stand under the EU AI Act, article by article.

The EU AI Act and security tooling

Evidence

Cyberdroid AI Detection and Cyberdroid AI Investigation, the AI layer of the ARRTECH Security Suite, record the evidence behind every output. The people you assign to oversight see what each output rests on, so they can interpret or disregard it. Neither product changes your estate.

Articles

Annex III lists safety components of critical infrastructure, and systems that monitor and evaluate workers’ behaviour, as high-risk. Recital 55 excludes components “intended to be used solely for cybersecurity purposes” from safety components. This page claims no classification for either product, and the rows below describe the design either way.

Article 14 asks that people can interpret a high-risk system’s output, disregard or override it, and stop it. Every AI Detection finding shows its observed value, baseline, score and threshold. You can hold delivery of any AI Investigation reply without relying on the model.

Article 14 names automation bias, the pull to over-rely on an output. A score in AI Detection ranks your queue and is never a verdict. Telemetry health beside every output shows when the evidence behind it was incomplete.

Article 12 asks high-risk systems to log events automatically over their lifetime. AI Detection records each detector’s promotion and rollback. AI Investigation records every request as Task, Pending approval, Refused or Rate-limited, with an operation id and a reason.

Article 15 asks high-risk systems to resist attempts to alter their use or outputs, naming model evasion and poisoning. In AI Investigation, authority sits in policy, not the model, so text that persuades the model cannot approve work or add a recipient.

For high-risk systems, deployers assign oversight to people with the competence, training and authority to use it, and employers inform workers’ representatives first. Those duties stay with you. Our products supply the evidence, records and approval points those people work from.

Dates

Dates follow Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. The clauses we cite show how our design relates to each framework.

Now

Prohibited practices and the AI literacy duty have applied since Feb 2, 2025. As amended on Jul 27, 2026, the literacy duty asks providers and deployers to support their staff’s AI literacy. Article 50 transparency duties have applied since Aug 2, 2026.

Next

Requirements for high-risk systems listed in Annex III, including human oversight and deployer duties, apply from Dec 2, 2027. Requirements for high-risk systems in products under Annex I apply from Aug 2, 2028.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.