Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Runtime evidence for the EU AI Act and AESIA guidance


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19785
Topic starter  

TL;DR: Spain’s AESIA guidance turns EU AI Act compliance into an evidence problem: high-risk AI providers must show continuous risk control, logging, robustness, and human oversight, and AccuKnox frames runtime prompt firewalls plus red teaming as the mechanism that produces that proof. For practitioners, the shift is from policy statements to enforceable controls with audit trails.

NHIMG editorial — based on content published by AccuKnox: Spain’s AI Act asks for evidence, not intentions

By the numbers:

Questions worth separating out

Q: How should security teams prove that a high-risk AI system is actually controlled at runtime?

A: They should produce evidence from the live control path, not rely on policy documents.

Q: Why do policy documents fall short for EU AI Act compliance evidence?

A: Because the EU AI Act is concerned with continuous control of risk, robustness, and record-keeping across the lifecycle.

Q: What are the signs that AI governance controls are only paper-based?

A: Common signs include missing prompt-level logs, no record of blocked responses, no evidence that red-team findings were closed in production, and no trace from control decision to audit record.

Practitioner guidance

  • Build runtime evidence into AI governance Define the evidence your high-risk AI system must produce during normal operation, including prompt decisions, blocked outputs, and escalation events.
  • Place policy enforcement inline with the model Use an enforcement layer between the application and the model so unsafe prompts can be blocked before generation, not analysed after the fact.
  • Run red teaming on every material model change Retest prompts, retrieval paths, and output handling whenever the model, system prompt, or surrounding application changes.

What's in the full article

AccuKnox's full article covers the operational detail this post intentionally leaves for the source:

  • How the prompt firewall enforces policy between users, applications, and the model in live traffic
  • The mapping between AI Act obligations, AESIA guidance, and runtime control evidence
  • Why the same enforcement model can support ENS traceability in Spanish public-sector deployments
  • The vendor's framing of red teaming as an operational proof mechanism rather than a one-time test

👉 Read AccuKnox’s analysis of Spain’s AI Act runtime evidence requirements →

Runtime evidence for the EU AI Act and AESIA guidance?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19376
 

Evidence, not intention, is now the decisive standard for AI governance. The EU AI Act and AESIA guidance together move compliance away from paper controls and toward runtime proof. That matters because AI systems are evaluated on what they do continuously, not what a policy says they should do once. For practitioners, the discipline shifts toward control observability and traceable enforcement, not static approval workflows.

A question worth separating out:

Q: How do EU AI Act requirements differ from traditional security controls in practice?

A: Traditional security controls often focus on access, hardening, or periodic review. The AI Act adds a continuous evidentiary requirement around lifecycle risk management, human oversight, logging, and robustness. That means teams must design controls that both enforce policy and generate records a supervisor or auditor can inspect.

👉 Read our full editorial: Runtime evidence for Spain’s AI Act: what AESIA guidance changes



   
ReplyQuote
Share: