EU AI Act readiness with Preloop
Operational controls and evidence for teams deploying AI agents
Preloop helps teams govern AI agents in real workflows with approvals, policy enforcement, runtime visibility, budget controls, and audit trails. Those capabilities can support an AI Act readiness program by helping organizations implement operational controls and collect evidence about how AI agents are used.
The instrument is Regulation (EU) 2024/1689 (EU AI Act). Preloop does not determine whether a system is in scope, whether a use case is prohibited or high-risk, or what legal obligations apply. It is not a conformity assessment.
Not legal advice
Preloop is not a law firm. Nothing on this site is legal advice. Every regulation reference names the instrument and the article or date so you can check it against EUR-Lex yourself.
Where the Act talks about oversight and records
The following is what the text says, not a claim that Preloop satisfies it.
- Human oversight (AI Act Art. 14). High-risk AI systems are required to be designed so natural persons can oversee them effectively, including the ability to intervene. Preloop can pause a governed tool call until a named person approves or rejects it. That is operational machinery. It is not a determination that Art. 14 is met for your system.
- Automatically generated logs (AI Act Art. 12). High-risk systems must allow automatic recording of events over the system's lifetime. Preloop records attempted tool calls, policy decisions, approvals, timestamps, model spend, and outcomes on runtime sessions. That is session evidence, not a complete technical file.
- Deployer obligations (AI Act Art. 26). Deployers of high-risk systems have their own duties. Preloop can show which agent, session, model, and tool path produced an action. It does not classify you as a deployer or a provider.
- Transparency (AI Act Art. 50). Certain AI interactions must be disclosed to people. Preloop does not generate those disclosures. It can show which model served a turn so a human can write them.
Where Preloop can help
Teams using AI agents often need to answer practical questions such as:
- which actions agents are allowed to take automatically
- which actions require human approval
- which models and tools are being used in production workflows
- which runtime performed a specific action
- what happened, when it happened, and who approved it
- how operational evidence can be preserved for internal reviews and external scrutiny
Preloop helps with those operational questions by giving teams a control plane for AI agents.
Capabilities relevant to AI governance programs
Policy enforcement for AI tool use
Preloop can evaluate governed tool calls against policy rules before actions are executed. Teams can allow low-risk actions, deny unsafe actions, or require justification and approval for sensitive operations.
Human oversight workflows
When an action is high impact, Preloop can route it to the right approver and pause execution until a decision is made. This helps organizations implement practical human oversight for consequential actions.
Runtime visibility and attribution
Preloop keeps runtime activity visible so teams can understand which agent, session, model, and tool path produced a given action.
Audit trails and evidence collection
Preloop records attempted actions, policy decisions, approvals, timestamps, and outcomes. This gives teams operational evidence they can use for security reviews, incident analysis, governance reviews, and AI Act readiness work.
Model and spend controls
Preloop can route model traffic through the Preloop Gateway so teams can apply model controls, attribution, and budget visibility instead of treating model usage as a blind spot.
Where Preloop does not replace compliance work
Preloop does not determine on its own whether a system is in scope of the EU AI Act, whether a use case is prohibited or high risk, or what legal obligations apply to a specific deployment.
Organizations still need appropriate legal, policy, security, and product review processes for:
- AI system classification and risk assessment
- required documentation and governance processes
- conformity assessment or legal interpretation
- post-market obligations where applicable
- organizational policies outside the runtime control layer
A practical positioning for Preloop
Preloop helps teams implement operational AI governance controls and collect evidence that can support AI Act readiness.
That framing is stronger than claiming full compliance automation, because it is more accurate.
Related EU product-security pages
These are separate instruments. Do not treat them as one "EU compliance" pack.