EU AI Act Compliance Statement

Version 2.3 · Last updated 2026-05-02
For informational purposes only — not legal advice.

Operator: TUARA KURI LIMITED
Trading as: AgenticRail
Jurisdiction: New Zealand (serving global users, including the European Union)
Contact: hello@agenticrail.nz

1. Overview

AgenticRail is a deterministic execution control system that validates, sequences, and either allows or halts actions submitted by client systems.

AgenticRail does not:

AgenticRail does:

Evidence: 913,079 enforcement decisions across 1M requests with zero errors (April 2026 pressure test). 114,096 sealed sequences. All receipts publicly verifiable at report.agenticrail.nz. Compliance matrix covering 60+ AI governance frameworks at agenticrail.nz/compliance.

2. Article Mapping

AgenticRail directly satisfies the following EU AI Act articles:

Risk Management. The gate is the risk management control — enforcement at infrastructure level. Every ALLOW is a risk acceptance with a cryptographic receipt. Every DENY is a risk mitigation with a recorded reason.

Data Governance. Receipt chains prove the operational pipeline was followed. Bias or anomalies in the pipeline are visible in the receipt log — structural evidence, not procedural documentation.

Technical Documentation. Receipt chains ARE the living technical documentation. Every system version, enforcement decision, and policy change is recorded as a signed receipt. The report generator produces an Article 11-ready compliance report in seconds.

Record-Keeping. Receipts are generated at decision time by the infrastructure layer, not the application. HMAC-signed. Chained. Immutable. This satisfies the "automatically recorded, tamper-evident logging" requirement structurally.

Transparency. The public verification portal at report.agenticrail.nz lets deployers independently verify enforcement. No access to provider systems needed.

Human Oversight. The gate IS the oversight mechanism. If a step fails, nothing proceeds. Human oversight is enforced architecturally — fail-closed design.

Post-Market Monitoring. Every receipt is post-market monitoring evidence, automatically recorded at infrastructure level. 1M-request test data publicly available.

3. System Classification

AgenticRail is positioned as:

AgenticRail:

4. Role Under the EU AI Act

Under the EU AI Act, AgenticRail acts as a technical enforcement layer used by the deployer of an AI system.

The Client using AgenticRail is considered the Deployer of the AI system and is responsible for regulatory classification and compliance.

AgenticRail:

AgenticRail does not determine the purpose or risk level of your AI system.

5. Separation of Responsibility

AgenticRail responsibilitiesClient responsibilities
Validating payload structureDefining system purpose
Enforcing sequence orderDetermining whether their system is high-risk
Applying policy constraintsEnsuring lawful use
Preventing invalid or out-of-order executionImplementing human oversight
Providing verifiable sequence recordsEnsuring data protection compliance (GDPR)

AgenticRail enforces structure. The Client defines meaning and use.

6. How We Support Your Compliance

EU AI Act RequirementHow AgenticRail Helps
Article 9 — Risk managementThe gate is the risk management control — enforcement at infrastructure level
Article 11 — Technical documentationReceipt chains are the living technical documentation; report generator produces Article 11-ready reports
Article 12 — Record-keepingEvery action produces a verifiable, HMAC-signed, tamper-evident sealed sequence record
Article 13 — TransparencyPublic verification portal at report.agenticrail.nz; deployers can verify independently
Article 14 — Human oversightALLOW decisions are not guarantees; fail-closed design enforces oversight architecturally
Article 17 — Quality managementDeterministic enforcement reduces unpredictability
Article 72 — Post-market monitoringEvery receipt is post-market monitoring evidence, automatically recorded
Annex IV — Technical documentationReceipt chains and compliance reports contribute to Annex IV audit trails

AgenticRail does not replace compliance obligations. It provides structural evidence that system actions followed a deterministic, auditable process.

7. High-Risk AI Systems — Your Obligations

If you use AgenticRail within a high-risk AI system (e.g., employment, credit scoring, critical infrastructure), you must:

AgenticRail:

AgenticRail does not accept liability for failure to comply with applicable laws.

8. Risk Mitigation by Design

AgenticRail contributes to safer AI operation through:

MechanismWhat it does
Deterministic enforcementstrict sequence validation, function/action matching, fail-closed behaviour
Execution constraintsprevents uncontrolled execution and step bypass
Replay protectionnonce validation prevents duplicate execution
Structural validationrejects invalid or malformed actions
Sequence sealingcompleted sequences are permanently closed; no re-entry

These mechanisms reduce unintended execution, inconsistent state transitions, and uncontrolled system behaviour.

9. Transparency and Explainability

AgenticRail provides:

However:

Transparency at the application level remains the responsibility of the Client.

10. Human Oversight

AgenticRail does not replace human oversight.

Clients must review decisions where appropriate, implement escalation or fallback logic, and ensure humans remain accountable for outcomes.

AgenticRail is a control checkpoint, not a decision-maker.

11. Data Protection Alignment (GDPR)

AgenticRail is designed to:

As outlined in the Privacy Policy:

AgenticRail is designed to minimise personal data processing and does not rely on personal data for core system operation.

12. Prohibited and Unsafe Uses

AgenticRail must not be used:

Unauthorised use may result in suspension of API access.

13. Limitations

AgenticRail:

It enforces structure, not truth.

14. Ongoing Compliance Approach

AgenticRail will:

15. Governing Principle

AgenticRail enforces structure, not meaning.
It determines whether an action is allowed.
It does not determine whether an action is correct, lawful, or appropriate.

A tool that supports compliant AI operation, not a compliance service or legal advisor.

16. Contact

For compliance-related enquiries: hello@agenticrail.nz

This statement is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for your specific obligations under the EU AI Act and other applicable laws.

Document Fingerprint — SHA-256 — v2.3
0cba0860e3b35b9698995829d218a0d4d99091c662207947244dc1ea15173b6b
Independently reproducible: SHA-256 of the canonical document source (UTF-8, LF line endings) held by TUARA KURI LIMITED. Auditors and regulators may reference this fingerprint to identify the exact statement in force at any point in time.

Version: 2.3 · Effective date: 2026-05-02 · Operator: TUARA KURI LIMITED · NZBN 9429052428098