The EU AI Act is rolling out in phases, with many provisions already in full force. Harmful practices—such as social scoring and cognitive manipulation—have been fully banned since 2025, and companies are required to clearly inform users if their product includes AI features or AI-generated content as of August 2026. Even stricter requirements for high-risk categories, such as healthcare, education, or financial services, will be seen as a phased rollout over the next couple of years.
Teams shipping AI in the EU has an urgent need to demonstrate compliance, but this can be a difficult bar to clear. For many, prompts are hardcoded, model changes don't go through an approval process, and there’s no audit trail beyond Git history.
LaunchDarkly is the runtime control platform for AI development, enabling teams to control who sees changes, monitor how they perform in production, and adapt in real time. It also provides a centralized governance and control layer so that organizations can meet stringent compliance standards while maintaining release velocity.
Here, we’ll walk through four core requirements of the EU AI Act—and explore the LaunchDarkly capabilities that support each of them.
Ongoing risk management across the AI lifecycle
The Act requires a continuous, documented risk management process throughout your AI system's lifecycle—not a one-time check at launch. Regulators expect evidence that you're actively identifying and mitigating risks as your system evolves, which is a meaningfully different standard than a pre-release audit.
LaunchDarkly offers Experimentation features that let you test prompt and model changes against real-world conditions before broad release, measuring how changes affect cost, latency, and output quality. Guarded Releases build on this capability by adding automated pass/fail rules that function as a continuous safety net. If a change causes latency to spike or output quality to degrade beyond a defined threshold, it gets automatically surfaced and rolled back before a user ever complains.
Once changes are live, online evals keep watch continuously. Judges score model outputs against built-in dimensions like accuracy, relevance, and toxicity, as well as custom criteria that reflect what "good" means for your specific product. When a score or metric breaches a threshold, Adaptive Triggers close the loop by automatically switching to a pre-defined fallback configuration in real time, without waiting for a human to make the call.
These features help you transform risk management from a one-time audit into a live system that monitors, evaluates, and responds as your system evolves.
Built-in human oversight of AI behavior
Article 14 of the Act is direct: your AI must be designed so that humans can understand, monitor, and intervene in its behavior. That means oversight has to be built into both your AI and the systems you use to ship it—not promised in a policy and left to good intentions.
Approval workflows in LaunchDarkly help ensure that no prompt, model, or parameter change goes live without a designated reviewer signing off first. Admins can use these workflows in tandem with Custom Roles to define who has the authority to approve different categories of changes, so the right human is in the loop for the right decision.
LaunchDarkly also gives users the ability to intervene when something goes wrong at runtime. If a model starts producing unacceptable outputs or a prompt starts behaving unexpectedly, an authorized team member can update AI behavior from a dashboard without opening a PR and redeploying.
Together, these capabilities help provide the structured human oversight required by the Act.
Full change history of AI systems
Articles 18 and 19 of the Act effectively require what you might call model tracking: the ability to demonstrate a complete, accurate record of what your system was doing and why, at any point in its history. This means that every change to your AI system must be logged, documented, and retrievable on demand. When a regulator asks what prompt your product was using on a specific date, "let me check with the engineer who made that change" isn't an answer.
When configs live in LaunchDarkly rather than in code, every change—whether to prompt versions, model selections, or parameters—is automatically timestamped and attributed to the person who made it. This means you don’t have to scramble through Git history to reconstruct what happened.
Immediate corrective action
Article 20 requires providers to take immediate corrective action if their AI system presents a risk. If your AI presents a risk, you can’t wait to address it until the next sprint.
With LaunchDarkly, teams can change prompts, models, and guardrails without having to redeploy. This means that if a model starts producing outputs that fall outside acceptable bounds, the fix can be live in seconds. And if the model provider itself goes down, SDK-side fallbacks help ensure the system reverts to a predefined state rather than an undefined one. The AI doesn't enter an unknown or potentially dangerous state just because a dependency became unreachable.
This is what the Act is actually asking for: not a policy that says you'll act quickly, but a system that makes "quickly" technically achievable.
Make runtime control part of your compliance infrastructure
The EU AI Act is here, and the time to get compliant is now. The teams best positioned when regulators come asking are the ones that already know what changed, who approved it, and can fix it in seconds.
LaunchDarkly can help build the infrastructure that, when paired with good processes and a legal certification, helps you meet regulatory standards, demonstrate compliance, and act quickly when you need to.
Want to see how this could work at your organization? Talk to us.
















