Regulatory / EU AI Act

Meridian and the EU AI Act — retention-controlled records for governance posture

Obligations differ by role — providers, deployers, importers, and distributors each carry their own. Meridian's retention-controlled records and attribution provenance support the governance-records posture the Act expects.

What it expects

As of August 2026

  • Providers, deployers, importers, and distributors carry different obligations depending on role and system classification
  • Relevant obligations may include transparency notices for certain AI interactions, technical documentation and logging for high-risk systems, and governance records
  • Certain provisions have applied since 2025; the timetable for standalone high-risk obligations was formally revised in 2026, moving them to December 2, 2027. Validate applicable dates against your role and system classification
  • US organizations may be in scope when placing systems on the EU market, putting them into service in the EU, or where output is used in the EU — a counsel question

How Meridian supports it

ExpectationMeridian capabilityEvidence artifact
Governance records and operational documentationRetention-controlled ledger history with attribution provenanceAudit Evidence Export; report history
Visibility into AI systems and vendors in useAI systems and AI-related vendors detected in connected billing and usage sourcesAgent estate report; vendor detail
Ongoing operational evidenceContinuous metering, spend, and anomaly reportingBoard Pack; Risk & Anomaly report

For high-risk systems, Article 12-style logging must be designed into the system itself and align with the Act's logging criteria. Meridian's finance-side records supplement provider and deployer technical documentation and system logs; they do not substitute for them.

Why billing-derived records hold up

A billing-derived inventory is a high-confidence view of the AI services visible in your connected billing and usage sources. It surfaces attributable and unattributed spend with evidence — and helps teams identify what sits outside it: bundled SaaS features, free tools, centrally contracted services, or unmanaged use.

See it in your environment

Free two-week read-only assessment, or Zero-Access Assessment (file-based, no credentials).

FAQ

Are we in scope from the US?
Possibly — when placing systems on the EU market, putting them into service in the EU, or where output is used in the EU. Counsel should determine applicability for your systems and roles.
Does Meridian classify our systems as high-risk?
No. Meridian does not classify AI systems or determine regulatory applicability. It produces inventory and governance records your program uses.