EU AI Act: Article 50 transparency live 2 August 2026  ·  Annex III high-risk (Article 12, Article 9) fixed at 2 December 2027 See obligations →

Illustrative Scenario · Financial Services · EMEA

From governance intent to cryptographic proof, in 90 days.

Reference architecture · Regulated financial institution profile

Illustrative deployment scenario (non-customer, reference architecture). This scenario models how a regulated EMEA financial institution would deploy UTP to close its Article 12 evidence gap. Flows, timelines, and technical outcomes are representative of the protocol's design. This is not a specific customer engagement.

The situation

A regulated EMEA financial institution is using AI-driven credit decisioning at scale, processing high volumes of loan applications annually. Internal governance and a reputable AI risk management platform are in place. Policy documents exist. Approval workflows are documented.

The problem surfaces during a pre-examination review: when asked to produce the actual evidence that the AI has operated as documented — the specific decision records, the governing policy at time of decision, the outcome with a verifiable timestamp — the existing governance stack cannot provide it. Dashboards show aggregate statistics. The underlying decision records are stored in a mutable operational database with no cryptographic integrity.

The EU AI Act's Article 12 mandatory logging obligation is now fixed at 2 December 2027, and FCA Consumer Duty is already active. The gap is still material: whatever date logging starts, there will be no audit trail for any decision made before that date, which is exactly what a pre-examination review or regulator investigation would ask for first.

The deployment

KairoNull integrates with the institution's existing credit decisioning pipeline via REST API. No changes to the underlying AI models. No changes to the core loan origination system. A single API call is added at the point where each credit decision is produced, capturing the decision event before it is written to the operational database.

The integration passes security review in 14 days. End-to-end testing completes in 21 days. Production traffic is onboarded in 90 days from contract signature.

90
Days to production
0
Model changes required
100%
Chain integrity at launch

The outcome

At go-live, every credit decision produced by the institution's AI systems is captured as a cryptographic evidence record — model identity, governing policy version, input context hash, outcome, timestamp — chained in an append-only ledger. Any record can be independently verified against the chain using nothing but its SHA-256 hash.

When the institution's internal audit team requests a sample of decision records for their next examination pack, the evidence report is generated in minutes. Every record includes chain height, policy reference, and verification hash. The audit team has evidence they can hand directly to a regulator.

In a similar position?

Book a 30-minute evidence briefing. We'll walk through your specific AI systems, identify the evidence gap, and scope a deployment that fits your timeline.

Book an evidence briefing →