EU AI Act and ValGuard: runtime controls for high-risk LLM agents

How deterministic validation, audit trails, and fail-closed gates map to operational AI Act concerns. Not legal advice or a conformity assessment.

The EU AI Act sets obligations that vary by risk tier and use case. This page maps ValGuard's runtime controls to operational questions reviewers ask about logging, human oversight, and failing closed. It is not legal advice, a conformity assessment, or a claim that ValGuard makes a system Act-compliant by itself.

What ValGuard covers in this context

ValGuard is a runtime validation and policy-enforcement layer for LLM calls and agent steps. Deterministic rules run on every completion before the next model, tool, or customer-facing action. Audit rows carry rule IDs. Shadow mode measures would-blocks before enforce.

Act-oriented concernValGuard mechanismLimit
Traceability of model outputs that drive actionsPer-request validation audit with rule IDsDoes not replace full system logging
Preventing known-bad structured actionsFail-closed block / reask on packsOnly encoded rules fire
Human oversight hooksPlaybook branches and human approval where configuredNot a full case-management system
Pre-production evaluationShadow mode on hosted or Enterprise self-hostHosted shadow still processes content

Suggested control mapping (engineering)

  1. Inventory high-risk agent steps (refunds, eligibility, medical messaging, credit).
  2. Attach schema, policy, and domain packs; start in shadow.
  3. Enforce with fail-closed on those paths.
  4. Export audit evidence for reviewers; keep payload logging policy explicit. Trust.
  5. Prefer Enterprise self-host when residency requires VPC. Self-host docs.

Related packs and policies

Honest limits

  • ValGuard does not classify your system under the Act.
  • Fluent false claims without a rule signature can pass.
  • Cloud provider choice and training-data obligations sit outside this product.
  • Assessments and legal opinions stay with your counsel and notified bodies where required.

Diagram

flowchart LR
  A[Agent / app] --> V[ValGuard rules]
  V -->|pass| T[Tool / customer action]
  V -->|block| H[Human oversight path]
  V --> L[Audit with rule IDs]

Next step

Contact for enterprise diligence, or start quickstart in shadow mode on one high-risk agent.