Society & Economicsarticle2026-08-17

Local Execution and a Verifiable Audit Record as Compliance Substrate: A Self-Hostable Inference Runtime under the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744), the GDPR, the Cyber Resilience Act, DORA and NIS2

Open access0 citations

Abstract

Most organisations add a large language model to a product by sending each request to a model hosted by a third party. For a product that processes personal data, confidential records, or that falls within the high-risk category of the EU AI Act, that convenience carries three compliance liabilities that surface only when the organisation must demonstrate compliance rather than assert it: the request is usually an international transfer of personal data under Chapter V of the GDPR; the record of what the system did is held, and shaped, by a third party the organisation does not control; and the organisation that answers for an automated decision often cannot show, to someone who does not simply trust it, that the record of that decision is complete and unaltered. This paper argues that running the model on infrastructure the organisation controls, and keeping a record whose integrity can be independently verified, changes each of these three questions at its root. The argument rests on one distinction that is easy to miss: an inference runtime is infrastructure, whereas the legal obligations of the AI Act and the GDPR fall on the provider or deployer of the AI system and on the model - not on the software that runs it. A runtime therefore cannot satisfy a compliance obligation; it can only make the deployer's compliance achievable or impossible. Within that boundary, the paper maps concrete capabilities - local and offline execution; a tamper-evident audit record with configurable retention; a frozen, independently verified audit-record format (PALA-1 v1.0) available as a standalone verifier; a published software bill of materials; and signed build provenance — onto the specific, named obligations they materially assist: the transfer rules of the GDPR and Schrems II; the record-keeping duty of Article 12 of the AI Act; the integrity, security, and storage-limitation duties of Articles 5(1)(f), 32 and 5(1)(e) of the GDPR; the vulnerability-handling and secure-development requirements of the Cyber Resilience Act; and the third-party-risk and supply-chain requirements of DORA and NIS2. The project's logging capability is additionally mapped to the emerging ISO/IEC 24970 standard on AI system logging, the route by which conformity with the AI Act's logging obligation is expected to be demonstrated once that standard is harmonised. The paper is deliberately explicit about the obligations a runtime cannot address - human oversight, informing users, risk management, data governance, and conformity assessment - because in this field credibility is earned by naming the boundary, not by claiming across it.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-17

Authors: Oleksandr Verteletskyi