How SimpliKeys (SK) relates to the identity-relevant obligations of the EU AI Act — a capability view, not legal advice
Regulation (EU) 2024/1689 · Prepared mid-2026 · Operational capability view, not legal advice or a compliance assertion
Coverage of the 15 IAM-relevant obligations
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in phases. The high-risk obligations these articles fall under were set to apply from 2 August 2026. The Digital Omnibus (provisional agreement May 2026; formal adoption and Official Journal publication expected July 2026) would defer stand-alone Annex III high-risk obligations to 2 December 2027 — but until it is published, 2 August 2026 remains the legally binding date.
ONLY the identity-relevant dimensions of Articles 12 (record-keeping), 14 (human oversight) and 26 (deployer obligations), for high-risk AI systems. The vast majority of the Act — risk management, data governance, documentation, conformity assessment, registration and more — is out of scope for an identity platform and binds the provider and/or deployer, not the IAM tool; a representative set is listed as N/A below.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
This is an operational capability view, NOT legal advice and NOT a compliance assertion. No identity capability satisfies an AI Act article on its own — which is why nothing here is rated 'Supports'. SimpliKeys helps operationalize parts of Articles 12, 14 and 26 at the identity layer; conformity for a high-risk system still requires the provider's and deployer's broader obligations.
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Binds: provider (design); deployer relies. High-risk AI must be designed so a human can intervene in and interrupt its operation through a stop function or similar procedure.
What SimpliKeys provides
Provides a real-time interrupt at the identity layer — terminates the session an identity operates within and invalidates the credentials it presents, across every connected system, from SK Control.
Scope boundary
SimpliKeys delivers the identity/session-layer interrupt. Whether it halts a given AI system depends on that system's actions flowing through SimpliKeys-mediated identities; the system's built-in stop design and wider oversight are the provider's and deployer's.
Binds: provider/deployer. Overseers must be able to understand, monitor and correctly interpret the high-risk system's operation and output.
What SimpliKeys provides
Gives assigned overseers live session monitoring, screen recording and playback, so they can observe an AI agent's activity as it is produced.
Scope boundary
Supplies the observation surface for agent activity. Interpreting the AI's outputs and decisions, and the overseer's competence to do so, sit in the AI system and the deployer — not in SimpliKeys.
Binds: deployer/overseer. The overseer can decide not to use the output, or to override, reverse or stop it.
What SimpliKeys provides
Gates sensitive AI operations behind step-up authentication and policy-driven session controls, requiring explicit human approval before they proceed.
Scope boundary
Provides the access-layer gate that can hold or stop an operation pending approval. The judgement to override or disregard the output is the human overseer's.
Binds: deployer. The deployer assigns oversight to natural persons with the necessary competence, training, authority and support.
What SimpliKeys provides
Governs the access and roles for oversight personnel — role-based access with least privilege, segregation-of-duties conflict detection, and periodic access certification for oversight roles.
Scope boundary
Manages who holds the oversight access and keeps it clean. The competence, training, authority and the assignment decision itself are the deployer's.
Binds: deployer. The deployer monitors operation per the instructions for use and informs the provider/authorities of risks and serious incidents.
What SimpliKeys provides
Monitors identity and access activity continuously with AI-driven behavioural analytics and anomaly detection, and forwards events to SIEM/SOAR.
Scope boundary
Supplies identity-layer monitoring signals and evidence. Monitoring the AI system's operation against its instructions, and the incident-reporting process to the provider/authorities, are the deployer's.
Binds: deployer. The deployer keeps the logs automatically generated by the high-risk AI system, to the extent under its control, for at least six months.
What SimpliKeys provides
Retains the identity and access logs it generates in tamper-evident storage, with configurable retention that defaults beyond six months and scales to multi-year regimes.
Scope boundary
Covers retention of the identity/access portion of the logs. Logs the AI system generates outside SimpliKeys' path must be retained by other means; the deployer owns the overall obligation.
Binds: provider (design). High-risk AI must technically allow automatic recording of events over its lifetime, sufficient to identify risk situations and support post-market monitoring.
What SimpliKeys provides
Captures every authentication, authorization decision, privileged operation and session event with device, location, identity and decision context; behavioural analytics flag impossible travel, abnormal volumes, concurrent sessions and lateral movement.
Scope boundary
Provides the identity/access-event record substrate. The AI system's own event logging — inputs, outputs and model-level events — is a provider design obligation outside SimpliKeys.
Binds: deployer (good practice). Not a single named article, but accountability, oversight and logging for autonomous AI agents underpin Articles 12, 14 and 26 in agentic deployments.
What SimpliKeys provides
Treats every AI agent, copilot and autonomous workflow as a first-class non-human identity — unique provenance, scoped just-in-time credentials, continuous behavioural monitoring, automated rotation and an audit trail attributed to the agent, not the human who deployed it.
Scope boundary
Establishes the identity-accountability layer those articles assume for agentic AI. It underpins, but does not by itself satisfy, any specific obligation.
Binds: provider. Establish and maintain a continuous risk management system across the AI lifecycle.
What SimpliKeys provides
—
Scope boundary
Core provider obligation; not an identity control.
Binds: provider. Ensure quality, relevance and governance of training/validation/test data, including bias examination.
What SimpliKeys provides
—
Scope boundary
Data/ML governance obligation; outside identity.
Binds: provider. Maintain detailed technical documentation demonstrating conformity.
What SimpliKeys provides
—
Scope boundary
Documentation obligation; not a tool function.
Binds: provider. Design for transparency and provide instructions for use to deployers.
What SimpliKeys provides
—
Scope boundary
Outside identity.
Binds: provider. Ensure appropriate accuracy, robustness and cybersecurity of the AI system itself.
What SimpliKeys provides
SimpliKeys is general security infrastructure, not a property of the AI system.
Scope boundary
Concerns the AI system's own properties; not an identity control.
Binds: provider. Conformity assessment, EU declaration of conformity, CE marking and EU-database registration.
What SimpliKeys provides
—
Scope boundary
Regulatory process; not a tool function.
Binds: deployer. Certain deployers must perform a fundamental-rights impact assessment before deploying high-risk AI.
What SimpliKeys provides
—
Scope boundary
Governance/assessment obligation; outside identity.
Built from SimpliKeys' May 2026 product brief and the EU AI Act (Reg. (EU) 2024/1689) as understood in mid-2026, with Digital Omnibus changes provisional/pending. An operational capability view, NOT legal advice and NOT a compliance assertion. No identity capability satisfies an AI Act article on its own; most of the Act is out of scope for an IAM platform. Verify against the actual product, the final regulatory text, and qualified counsel.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo