Lex Custis, an AI Act compliance engine
Key point
Lex Custis, an open-source compliance engine for EU AI Act compliance, has been released.
Details
Lex Custis has been released as an open-source compliance engine for addressing EU AI Act high-risk AI system requirements.
Key features are as follows.
- Provides tamper-proof audit logs using HMAC-SHA-256-based per-organization hash chains and HKDF-derived subkeys.
- Generates Annex IV technical documentation packages, bundling Art. 11, 12, 15, 53, 73 items into signed manifest bundles.
- Includes Art. 73 incident response workflows, supporting classification, SLA tracking, and JSON export for regulatory submissions.
- Can run on Mistral by default or with self-hosted Ollama.
- Has a multi-tenant architecture, and states that tenant isolation is verified through CI integration tests.
- Targets an installation time of about 10 minutes via Docker Compose.
The author explained that AGPL-3.0 was adopted so that distributors must maintain auditability, and stated that a commercial license is also offered.
Links to the repository and documentation were released together, and the project added that it is still in an early stage.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.