Session
Compliance Is an Architecture Problem: Agentic AI Under the EU AI Act
Regulation arrives as a document and lands as a design constraint. If you are building agents that touch European customers, personal data, or decisions with consequences, then the AI Act and the GDPR do not belong at the end of your delivery pipeline. They belong on your architecture diagram.
This session translates obligation into engineering.
Where does data actually go when you call a hosted model, and what does that mean for residency and for your processor agreements? What does meaningful human oversight look like expressed as code, rather than as a sentence in a policy document? How do you explain a decision that emerged from eleven tool calls and four model invocations, months later, to somebody who is neither technical nor friendly? What has to be logged, for how long, and how do you log enough to defend a decision without quietly building a surveillance archive of your own users?
We will work through concrete patterns. Risk tiering that determines architecture rather than paperwork. Audit trails as first-class domain objects instead of log lines. Human oversight modelled as a state machine rather than bolted on as a confirmation dialog. Data minimisation enforced at the prompt boundary. And what genuinely changes when you move from a hosted model to one you run yourself, including the parts that get harder.
I am an engineer and not a lawyer, and I will be clear about that line throughout. This is about the architecture that makes compliance achievable, not legal advice.
Takeaways
- Turning regulatory obligations into concrete architectural requirements
- Audit trail and traceability design for multi-step agent runs
- Human oversight as a designed system state rather than a user interface afterthought
- Data residency and minimisation decisions at the model boundary
- How to open this conversation with legal early enough that it speeds you up
Preferred duration: 45 minutes including Q&A. Can be delivered in 30 or 60 minutes on request.
Target audience: architects, engineering leaders, and platform or security engineers building AI features for European markets or regulated industries. No legal background required.
Level: intermediate.
Note: presented from an engineering perspective. I am not a lawyer and the session does not offer legal advice; it covers the architecture and engineering practices that make compliance achievable.
Technical requirements: my own laptop (USB-C / HDMI).
First public delivery: not yet delivered.
Marc Arndt
VP Engineering and Architecture at Evana AG
Heidelberg, Germany
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top