Regulation (EU) 2024/1689

ZizkaDB supports EU AI Act compliance

ZizkaDB is built and operated by an EU entity, ZIZKA AI S.L. (Málaga, Spain). Its causal event log, human-oversight tooling, and data-erasure controls are designed to give providers and deployers of AI agent systems the operational evidence the EU AI Act expects — without becoming a compliance program in itself.

View article mappingTalk to us

Overview

The EU AI Act (Regulation (EU) 2024/1689) entered into force in August 2024, with obligations phasing in through 2026–2027 depending on a system's risk classification. It places record-keeping, transparency, and human-oversight duties on providers and deployers of AI systems — obligations that are hardest to meet when an agent's decision history lives only in scattered application logs.

ZizkaDB stores every agent decision, tool call, and outcome as a causally-linked event. Because that history is queryable, inspectable, and erasable by design, it maps directly onto several of the Act's technical requirements — summarized below.

Article mapping

How ZizkaDB's existing capabilities relate to specific AI Act provisions. Citations are the relevant articles to review with your legal team, not an exhaustive compliance checklist.

RequirementArticlesHow ZizkaDB supports it
Automatic logging & traceability
Art. 12Art. 26(5)–(6)
Agents log every event continuously, and sessions reconstruct complete timelines. Configurable, per-tenant log retention supports ongoing deployer monitoring on self-hosted or managed deployments.
Evidence for risk assessment & post-market monitoring
Art. 12(2)Art. 72Art. 79
Causal lineage (why()), behavioral baselines, and drift signals help detect operational anomalies, investigate incidents, and support post-market monitoring and risk management processes.
Transparency for deployers
Art. 13
Dashboards, APIs, SDKs, semantic search, and point-in-time retrieval (at()) make agent behavior fully inspectable — avoiding opaque, vendor-managed memory stores.
Human oversight
Art. 14Art. 26
Operators can inspect full action chains, reconstruct system state at any point in time, identify behavioral drift, and intervene using evidence rather than screenshots or manual records.
Technical documentation & conformity evidence
Art. 11Arts. 8–9, 17
Logged histories provide auditable evidence that supports technical documentation and compliance reporting. ZizkaDB complements — it does not replace — formal risk management or notified-body assessments.
Accuracy, robustness & cybersecurity
Art. 15
Tenant isolation, scoped API keys, tamper-evident event checksums, and self-hosted / VPC deployment options strengthen the security and operational integrity of your AI system.
Personal data management alongside the AI Act
GDPR
Operated by an EU entity with a published privacy policy, forget() erasure across events and vectors, marketing opt-out controls, and self-hosting options to support data-residency requirements.

Architecture & distribution

The same open-core engine runs across every deployment mode, so the compliance posture above holds whether you self-host or use managed cloud.

Operational database

  • Model agnostic — works with any LLM provider
  • Pre-built embeddings pipeline for semantic search
Built with time-tested engines
PostgreSQLpgvectorQdrantOllama (self-hosted)

Distribution

  • Self-hosted SDKs — Python, npm, MCP, LangChain, CrewAI
  • Managed cloud — Pro and Team plans
  • Design partnerships for SMEs
  • AGPL-3.0 license, with a commercial Enterprise license (VPC deployment + SLA) for organizations that need it

Data protection & GDPR

The AI Act's record-keeping duties sit alongside your existing GDPR obligations, not in place of them. ZizkaDB is built to satisfy both together:

  • Operated by an EU entity, ZIZKA AI S.L. (Málaga, Spain), under a published privacy policy
  • forget() deletes matching events and their vector embeddings together, by metadata filter
  • Marketing opt-out controls for contacts stored in ZizkaDB
  • Self-hosting and Enterprise VPC options for organizations with data-residency requirements

Important disclaimer

This page explains how ZizkaDB's existing features can support your organization's EU AI Act conformity work. It is general product information, not legal advice, and does not by itself constitute a conformity assessment, a Quality Management System, or CE marking. Your actual obligations depend on your AI system's risk classification and your role as provider or deployer (Art. 6, Annex III) — consult qualified legal counsel to confirm what applies to your organization.

FAQ

Does using ZizkaDB make our AI system “AI Act compliant”?

No single tool grants full compliance. ZizkaDB provides record-keeping, traceability, and human-oversight evidence that support your broader compliance program — it doesn't replace risk classification, a quality management system, or a conformity assessment.

Is ZizkaDB a substitute for a formal risk assessment?

No. ZizkaDB supplies the operational evidence (logs, causal chains, drift signals) that a risk assessment or post-market monitoring process can draw on. The assessment itself still requires your own governance process, and for high-risk systems, qualified legal and technical review.

Which AI Act obligations does ZizkaDB primarily help with?

Mainly record-keeping (Article 12), transparency for deployers (Article 13), human oversight (Article 14), and deployer monitoring duties (Article 26). See the article mapping above for the full picture.

Where is our data stored?

It depends on your deployment: self-hosted keeps everything in your own infrastructure, managed cloud runs on infrastructure operated by ZIZKA AI S.L. (an EU entity), and Enterprise VPC deploys single-tenant inside your own cloud account.

How do we exercise erasure rights under GDPR?

Call forget() with a metadata filter, or use the dashboard. It deletes matching events and their vector embeddings together, not just the primary record.

Contact

Questions about how ZizkaDB fits your compliance program, or need a signed DPA for procurement?

Enterprise & compliance/enterprise#contact
Privacy policy/privacy
Emailfounder@zizka.ai
Cookie and Privacy Consent
We use cookies/local storage for essential site functionality and to improve the product. You can accept or decline — you’ll still have full access either way. Privacy policy.