# ProofChain — EU AI Act Regulatory Positioning

## The Clock

| Date | Event | ProofChain Status |
|---|---|---|
| **Feb 2025** | Prohibited AI practices banned | Not applicable (minimal-risk system) |
| **Aug 2025** | GPAI model rules applied | Not applicable (not a GPAI provider) |
| **Aug 2, 2026** | Art. 50 Deployer Transparency | ✅ COMPLIANT — agent content labeled |
| **Dec 2, 2026** | Art. 50 Provider Marking | ✅ READY — AI-generated content tagged |
| **Dec 2, 2027** | High-Risk Annex III provisions | Not applicable — but OUR CUSTOMERS need this |
| **Aug 2, 2028** | High-Risk Annex I (regulated products) | Not applicable — medical/industrial only |

## ProofChain's Classification

**Minimal-Risk AI System** under Regulation (EU) 2024/1689.

Rationale:
- ProofChain does not make decisions affecting health, safety, or fundamental rights
- It is infrastructure for recording, verifying, and reporting agent actions
- It does not fall into any Annex III high-risk category
- It operates as a record-keeping and compliance automation tool

## What ProofChain Provides to High-Risk Deployers

ProofChain's customers ARE the ones facing high-risk requirements. Here's how ProofChain maps to their obligations:

| EU AI Act Article | Requirement | ProofChain Coverage |
|---|---|---|
| Art. 9 | Risk management system | Automated risk posture assessment from audit trail |
| Art. 10 | Data governance | HXMP encrypted, tamper-evident data provenance |
| Art. 11 | Technical documentation | Auto-generated Annex IV documentation from on-chain records |
| Art. 12 | Record-keeping (logs) | **Core feature** — HXMP audit trail IS the record-keeping system |
| Art. 13 | Transparency | AgentID identity + action metadata in every record |
| Art. 14 | Human oversight | Full audit trail enables human review of every agent decision |
| Art. 15 | Accuracy, robustness, cybersecurity | Cryptographic verification, X1 chain integrity |

## The 72-Hour Window

Article 12 requires "automatic recording of events (logs)" for high-risk AI systems. When a serious incident occurs, the provider has 72 hours to report.

**Without ProofChain:** Scramble through log files, database queries, and screenshots. Hope nothing was overwritten.

**With ProofChain:** Query the HXMP audit trail. Every action — intent, context, decision, outcome — timestamped, cryptographically signed, and immutable on X1. Export as a compliance report. Done in 15 minutes.

## Intent-to-Execution Evidence Chain (IEEC)

The IEEC pattern (introduced in the OpenKedge protocol) cryptographically links five elements:

1. **Intent** — What was the agent asked to do?
2. **Context** — What state was the system in?
3. **Policy Decision** — What rules were evaluated?
4. **Execution Boundaries** — What permissions did the agent have?
5. **Actual Outcome** — What happened?

ProofChain captures all five elements in every HXMP memo record. This IS the IEEC implementation.

## Forward-Looking: Post-Quantum

NIS2 is pushing toward post-quantum cryptography migration targets of 2030/2035. HXMP's encryption layer should plan for a PQC migration path. This is noted but not yet implemented — current encryption (XChaCha20-Poly1305) is adequate for the regulatory horizon.

## Regulatory Contact

For questions about ProofChain's regulatory posture:
- **DPO:** `dpo@proofchain.us`
- **Live verification:** `https://agentid-app.vercel.app/api/verify?wallet=FKwU1im523MSGnuJG6YLHEZu4rUGj3xqxHJ6ipQMBG9B`

---

*This document was generated by ProofChain on X1. Verifiable. Not legal advice. Consult qualified EU counsel.*
