ZizkaDB supports EU AI Act compliance
ZizkaDB is built and operated by an EU entity, ZIZKA AI S.L. (Málaga, Spain). Its causal event log, human-oversight tooling, and data-erasure controls are designed to give providers and deployers of AI agent systems the operational evidence the EU AI Act expects — without becoming a compliance program in itself.
Overview
The EU AI Act (Regulation (EU) 2024/1689) entered into force in August 2024, with obligations phasing in through 2026–2027 depending on a system's risk classification. It places record-keeping, transparency, and human-oversight duties on providers and deployers of AI systems — obligations that are hardest to meet when an agent's decision history lives only in scattered application logs.
ZizkaDB stores every agent decision, tool call, and outcome as a causally-linked event. Because that history is queryable, inspectable, and erasable by design, it maps directly onto several of the Act's technical requirements — summarized below.
Article mapping
How ZizkaDB's existing capabilities relate to specific AI Act provisions. Citations are the relevant articles to review with your legal team, not an exhaustive compliance checklist.
| Requirement | Articles | How ZizkaDB supports it |
|---|---|---|
| Automatic logging & traceability | Art. 12Art. 26(5)–(6) | Agents log every event continuously, and sessions reconstruct complete timelines. Configurable, per-tenant log retention supports ongoing deployer monitoring on self-hosted or managed deployments. |
| Evidence for risk assessment & post-market monitoring | Art. 12(2)Art. 72Art. 79 | Causal lineage (why()), behavioral baselines, and drift signals help detect operational anomalies, investigate incidents, and support post-market monitoring and risk management processes. |
| Transparency for deployers | Art. 13 | Dashboards, APIs, SDKs, semantic search, and point-in-time retrieval (at()) make agent behavior fully inspectable — avoiding opaque, vendor-managed memory stores. |
| Human oversight | Art. 14Art. 26 | Operators can inspect full action chains, reconstruct system state at any point in time, identify behavioral drift, and intervene using evidence rather than screenshots or manual records. |
| Technical documentation & conformity evidence | Art. 11Arts. 8–9, 17 | Logged histories provide auditable evidence that supports technical documentation and compliance reporting. ZizkaDB complements — it does not replace — formal risk management or notified-body assessments. |
| Accuracy, robustness & cybersecurity | Art. 15 | Tenant isolation, scoped API keys, tamper-evident event checksums, and self-hosted / VPC deployment options strengthen the security and operational integrity of your AI system. |
| Personal data management alongside the AI Act | GDPR | Operated by an EU entity with a published privacy policy, forget() erasure across events and vectors, marketing opt-out controls, and self-hosting options to support data-residency requirements. |
Architecture & distribution
The same open-core engine runs across every deployment mode, so the compliance posture above holds whether you self-host or use managed cloud.
Operational database
- Model agnostic — works with any LLM provider
- Pre-built embeddings pipeline for semantic search
Distribution
- Self-hosted SDKs — Python, npm, MCP, LangChain, CrewAI
- Managed cloud — Pro and Team plans
- Design partnerships for SMEs
- AGPL-3.0 license, with a commercial Enterprise license (VPC deployment + SLA) for organizations that need it
Data protection & GDPR
The AI Act's record-keeping duties sit alongside your existing GDPR obligations, not in place of them. ZizkaDB is built to satisfy both together:
- Operated by an EU entity, ZIZKA AI S.L. (Málaga, Spain), under a published privacy policy
forget()deletes matching events and their vector embeddings together, by metadata filter- Marketing opt-out controls for contacts stored in ZizkaDB
- Self-hosting and Enterprise VPC options for organizations with data-residency requirements
Important disclaimer
FAQ
Contact
Questions about how ZizkaDB fits your compliance program, or need a signed DPA for procurement?
| Enterprise & compliance | /enterprise#contact |
| Privacy policy | /privacy |
| founder@zizka.ai |