← Back to the live archive

SME & AI

AI Act: A decision needs an explanation.

How traceable sources, records and human oversight help – and why cryptography alone does not establish compliance.

The decision stays with you.
Illustration · example workflow

Updated on 21 September 2026. Originally published in April, this article has been corrected to reflect the application timeline and distinguish record-keeping duties from a blanket requirement for cryptographic anchoring.

An AI suggests changing a delivery date. Your business needs to know which information supports the proposal, who can decide and what will happen after approval.

Start with the actual use

AI Act obligations depend on factors including the use case, risk classification and the company’s role. The current EU timeline lists 2 December 2027 for Annex III high-risk systems and 2 August 2028 for relevant systems in regulated Annex I products. Other obligations already apply. A single high-risk deadline for every AI application would be misleading. Official EU implementation timeline.

Traceability needs context

For high-risk systems, Article 12 requires the technical ability to record events automatically. It does not establish a general requirement for a blockchain, hash chains or an external cryptographic notary. These can be implementation choices whose suitability must be assessed for the specific use. Article 12 in the AI Act Service Desk.

For an operational case, a reviewable record connects the source and its state, the proposal, the responsible person, approval and the subsequently confirmed result. Technical evidence does not replace missing information or a required legal assessment.

What HEINI contributes

HEINI connects operational sources, proposals and approvals in the same case. Together, we assess the data paths, roles and evidence your use needs. The agreed product scope matters; a blog article does not prove every capability is enabled for every customer.

Begin with a real decision

Choose a case that currently stalls between email, ERP and approval. Establish who owns the source, who can decide and how execution will be confirmed. That gives you a workflow you can review.

Explore HEINI’s working principles and security information or review your own case together.