Updated on 21 September 2026. Originally published in April, this article has been corrected to reflect the application timeline and distinguish record-keeping duties from a blanket requirement for cryptographic anchoring.
An AI suggests changing a delivery date. Your business needs to know which information supports the proposal, who can decide and what will happen after approval.
Start with the actual use
AI Act obligations depend on factors including the use case, risk classification and the company’s role. The current EU timeline lists 2 December 2027 for Annex III high-risk systems and 2 August 2028 for relevant systems in regulated Annex I products. Other obligations already apply. A single high-risk deadline for every AI application would be misleading. Official EU implementation timeline.
Traceability needs context
For high-risk systems, Article 12 requires the technical ability to record events automatically. It does not establish a general requirement for a blockchain, hash chains or an external cryptographic notary. These can be implementation choices whose suitability must be assessed for the specific use. Article 12 in the AI Act Service Desk.
For an operational case, a reviewable record connects the source and its state, the proposal, the responsible person, approval and the subsequently confirmed result. Technical evidence does not replace missing information or a required legal assessment.
What HEINI contributes
HEINI connects operational sources, proposals and approvals in the same case. Together, we assess the data paths, roles and evidence your use needs. The agreed product scope matters; a blog article does not prove every capability is enabled for every customer.
Begin with a real decision
Choose a case that currently stalls between email, ERP and approval. Establish who owns the source, who can decide and how execution will be confirmed. That gives you a workflow you can review.
Explore HEINI’s working principles and security information or review your own case together.