The bank that puts an AI tool near a credit decision writes three files at once: one for the AI Act, one for DORA, one the data protection officer already keeps. Most of their content depends on one fact: what does the vendor hold, and what does it operate? A vendor who holds nothing and operates nothing leaves the deployer a file made of facts in its own infrastructure. A vendor who hosts leaves a file made of clauses in somebody else’s contract.

The deployer is the bank

The AI Act lists, among its high-risk uses, AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with an exception for fraud detection.[1] The bank operating such a system is the deployer, and Article 26 says what that means: use the system according to the provider’s instructions, assign human oversight to natural persons with the competence, training and authority to exercise it, monitor its operation, and keep the logs it generates for at least six months where those logs are under the bank’s control.[2]

The provider owes the other half. Article 12 requires a high-risk system to allow the automatic recording of events over its lifetime, and Article 13 requires it to ship with instructions for use.[3] The deployer’s file begins with two documents the vendor hands over: the instructions, and what the system records and where.

Under their control

Read Article 26 again: the deployer keeps the logs to the extent they are under its control.[2:1] That clause is the hinge of the whole file. If the logs sit in the vendor’s cloud, the deployer’s control is a contractual promise. If they sit on the deployer’s own disks, control is a fact the deployer can show a supervisor without asking anyone.

A record of prompts and completions is a transcript of what the model said. A supervisor asking why a loan was refused needs a record of what was done: which data was read, which rule applied, who approved. A trail that can be re-run is evidence. A trail that can only be read is a story.

Human oversight needs a name

Article 26 says natural persons, with authority.[2:2] A human validating several hundred machine proposals in a working day validates nothing; he is a signature apparatus attached to a process he cannot examine.[4] The oversight the bank documents is a person, named, with the standing to refuse the proposal and the time to read it. A decision with no name at the foot of it is weather.[5]

If every action already carries a name by construction, the oversight section describes what the system does. If the name has to be added afterwards by a review procedure, the section describes a ritual, and the supervisor will ask how often the ritual is skipped.

DORA: the register, the contract, the exit

DORA asks financial entities to manage ICT third-party risk and to keep a register of information on every contractual arrangement for ICT services provided by a third party.[6] Those contracts carry provisions the regulation names: where the service is provided and where data is processed and stored, the entity’s rights of access, inspection and audit, and termination rights with an exit strategy.[7]

For a hosted AI service, each provision is negotiated, because each describes something the vendor holds. For software installed and operated by the bank on its own infrastructure, the register entry still exists, and the compliance function decides how the arrangement is classified. What changes is the content. Data location is the bank’s own datacentre. The audit right is the bank’s own operations team reading the bank’s own logs. The exit strategy is the runbook the team already runs, because the software keeps working when the vendor is gone.

Infrastructure vendors are publishing their own answers. CockroachDB argues that the database beneath an AI agent must carry append-only audit storage, identity attribution and residency enforcement before deployment, because none of it can be retrofitted for an examiner.[8] Teleport argues that agentic systems demand identity-native audit events tying every action to one immutable identity, and that static documentation is no evidence.[9]

GDPR: the DPO decides

Where a vendor processes personal data on the bank’s behalf, Article 28 of the GDPR requires a contract with the terms the article lists.[10] Software installed and operated by the controller on its own infrastructure, with the vendor holding no data, is a different position from a hosted service. Which position a deployment is in is the data protection officer’s call, made on one fact: does the vendor ever hold, receive or access the data? The useful vendor gives an answer the DPO can verify from the bank’s network rather than a clause the DPO has to trust.

Who writes each line

  • Instructions for use and the record-keeping description. The vendor provides, the deployer keeps.[3:1]
  • Human oversight. The deployer writes it, one name per decision, with authority to refuse.[2:3]
  • Logs. The system records, the deployer retains, where the logs are under its control.[2:4]
  • Register entry, data location, audit rights, exit. The deployer writes them; their content depends on where the software runs.[6:1]
  • Article 28 assessment. The DPO.[10:1]

Every line is written faster when the vendor holds nothing, operates nothing, and every action carries a name. Auditability will prove to be a weapon: what the world will demand within five years is available to sell today, and the European instinct to treat it as paperwork is the only thing squandering it.[11]

What Galahad refuses

We do not host your data. We do not run a control plane your deployment depends on. We do not certify your compliance on your behalf, because compliance is the deployer’s file, and a vendor who claims to carry it has misread the regulation. The deployment model is what carries the compliance: your infrastructure, your jurisdiction, your accreditation covering the environment you install into. GDPR and the AI Act are met on those terms, and every control is named rather than asserted.

Monarch installs inside your infrastructure, under your accounts, your keys and your jurisdiction. We operate no hosting for your data. Bring your DPO and your DORA register to the demonstration. See it on your data.


  1. Regulation (EU) 2024/1689, Annex III, point 5(b). Source ↩︎

  2. Regulation (EU) 2024/1689, Article 26, obligations of deployers of high-risk AI systems. Source ↩︎ ↩︎ ↩︎ ↩︎ ↩︎

  3. Regulation (EU) 2024/1689, Article 12, record-keeping, and Article 13, transparency and provision of information to deployers. Source ↩︎ ↩︎

  4. Machines of Consequence, thesis 8. Read it ↩︎

  5. Machines of Consequence, thesis 11. Read it ↩︎

  6. Regulation (EU) 2022/2554, Article 28, general principles of ICT third-party risk, including the register of information. Source ↩︎ ↩︎

  7. Regulation (EU) 2022/2554, Article 30, key contractual provisions. Source ↩︎

  8. Cockroach Labs, “DORA Compliance for AI Agents: Database Requirements Before Deployment”. Source ↩︎

  9. Teleport, “Guide: DORA Compliance Evidence for Agentic AI”. Source ↩︎

  10. Regulation (EU) 2016/679, Article 28, processor. Source ↩︎ ↩︎

  11. Machines of Consequence, thesis 47. Read it ↩︎