EU AI Act - Attestation Registry
Post-quantum, tamper-evident proof of origin, safety, and compliance for high-risk AI - anchored with ML-DSA-65 (FIPS 204) on COGNITUM.
What this registry is - and is not
It proves (verifiably):
- a provider signed a specific evidence artefact (integrity + authorship),
- at a specific time (immutable timestamp),
- and it has not been altered since - durable across the quantum transition.
It does NOT:
- make an AI system “compliant”, or grant a CE marking or presumption of conformity,
- replace the Article 43 conformity assessment or a notified body,
- assess the truth of the evidence - that stays with the provider and the competent authorities. COGNITUM is not a notified body.
Not legal advice. Classification and obligations under Regulation (EU) 2024/1689 must be confirmed with qualified counsel.
Verify an attestation
Enter an attestation id (AICA-…) to check its proof against the ledger.
What a provider anchors
Three evidence pillars, each a signed digest of an off-chain artefact (never the artefact itself).
- Origin - provider identity, model & data lineage, AI bill-of-materials, C2PA output marking (Art 50).
- Safety - risk management (Art 9), accuracy/robustness/cybersecurity (Art 15), bias, human oversight (Art 14).
- Compliance - technical documentation (Art 11/Annex IV), conformity assessment (Art 43), EU declaration of conformity (Art 47), CE marking, EU-database id (Art 49).
On-chain: digests + status + metadata only - never technical files or personal data (GDPR-by-design; withdrawal is a status flip, not deletion).
Where the standards stand
Why this is evidence, not a compliance certificate - and how conformity works today.
- No harmonised standard is cited in the Official Journal yet. So no “presumption of conformity” (Art 40) is available to anyone - us included. The CEN-CENELEC JTC 21 deliverables (EN 18286, prEN 18228/18229/18282/18284) are still drafts, and no Art 41 common specification has been adopted.
- Conformity is shown directly. Against the essential requirements (Art 8–15) and the Art 43 assessment, documented to the generally-acknowledged state of the art: ISO/IEC 42001, 23894, 42005, 24029, 5259; NIST AI RMF; and the Act’s own Annexes IV/V.
- This registry anchors that evidence. It does not certify compliance, grant a CE marking, or perform a conformity assessment.
- Forward-compatible. The harmonised-standards and common-specifications fields stay empty until an Art 40 standard is OJ-cited or the Commission adopts Art 41 common specs - then providers re-anchor referencing them.
Anchored attestations
Public, tamper-evident. Digests + status only - safe to browse.
Loading…
Standards synced: Regulation (EU) 2024/1689 · W3C Verifiable Credentials · C2PA · ISO/IEC 42001 / 23894 / 42005 · CycloneDX ML-BOM · FIPS 204 (ML-DSA-65). Aligns with CEN-CENELEC JTC 21 drafts - no harmonised standard is yet cited in the Official Journal, so nothing here grants a presumption of conformity.