letopis/AI Act
ENFORCEMENT LIVE · 2 AUG 2026HIGH-RISK · 2 DEC 2027

The EU AI Act is clumsy. Producing the evidence for it shouldn't be.

Every deliverable the Act asks a software team for is a question about the past: who supervised this, for how long, on whose authority, and why is it built this way.

A compliance project answers those with archaeology. letopis answers them with a lookup — the answer was recorded on the day.

THE DEADLINE NOBODY PUT ON A SLIDE
11 SEP 2026

The AI Act moved. The Cyber Resilience Act did not.

Article 14 gives you 24 hours to file an early warning on an actively exploited vulnerability, 72 for the full notification,14 days for a root-cause report.

It reaches backwards, too — the duty covers everything already on the market. On that clock, knowing what changed and why is the difference between filing and guessing.

ARTICLE BY ARTICLE

Six provisions, and which book writes the answer.

Annex IV §2(b) — via Art. 11, technical documentation
The design specifications: the key design choices, including the rationale and assumptions made, and the trade-offs behind the technical solutions adopted.
A dated, attributable record of each design decision and the option you rejected — captured when it was made, not reconstructed by whoever is still on the team.
zavet
Art. 14 · Art. 26(2) — human oversight
The system is overseen by natural persons who are competent, trained and actually able to intervene.
Evidence that a human supervised this change, and for how many minutes — instead of a policy PDF asserting in general that humans supervise.
dira + proba
Art. 17 — quality management system
Design control and design verification, change control, and procedures for keeping the records that prove both.
Per merged change: CI state at the merge commit, a review by someone other than the author, recorded decisions respected, branch protection not bypassed.
proba
Art. 12 · 19 · 26(6) — record-keeping & retention
Automatic recording of events, traceable over the lifetime of the system, retained and produced on request.
Records that are tamper-evident and non-repudiable — signed at capture on the workstation, append-only afterwards, and still legible in six months or ten years.
the chain
Art. 25 · Art. 43(4) — substantial modification
Modify a high-risk system substantially and you inherit the provider's obligations for it.
Knowing exactly what changed, when, and on whose authority — including the refactor an agent made at 02:40 that no human ever opened.
the chain
Art. 73 — serious incident reporting
Report a serious incident to the authority without undue delay — 15 days at the outside, but two if the infringement is widespread or the incident risks serious injury, and ten where someone has died.
Reconstructing the decision and change history of one subsystem in an afternoon./zavet:why answers with citations; a wiki search does not.
zavet /zavet:why
THE HALF NOBODY HAS

There are two AIs in your product, and only one of them is being logged.

Every AI Act tool on the market instruments the model your users talk to. Almost nothing instruments the models that wrote the code.

THE MODEL IN YOUR PRODUCT
Runtime logging, evals, guardrails. Article 12 territory — a crowded market, and not what dira does.
THE MODELS THAT BUILT IT
Who supervised the agent, for how long, which harness, against which recorded decision. letopis was in the room when it happened.
WHAT LETOPIS WILL NOT CLAIM

A chronicle has no opinions — least of all legal ones.

It cannot tell you whether you are high-risk, and no dashboard can certify you as compliant. What it removes is the archaeology: the interviews, the guessed dates, the rationale written in August about a March decision.

Start recording before you need the record.

dira is free forever for solo work and open source.

Start tracking free →