EU AI Act Article 50, enforced 2 August 2026

Prove the AI. At every output.

Heartbeat signs every output of one AI deployment. When the AI behaves correctly, the pulse is steady. When it drifts, the pulse changes, the receipts show it, the ledger keeps the record. The proof is yours, and it never pings out.

Heartbeat™ · pulse steady
Alive
deployment · your-deployment-01
last beat · just now
signed · hash-chained
auditor-verifiable, no contact with us

Any auditor checks the chain themselves, with an open script.

A doctor takes the pulse before reading the chart.

Heartbeat is that, for AI. Every governed output is a beat: a signed receipt.

The beats hash-chain into a ledger any auditor can verify with an open-source script, without ever contacting you. Steady pulse, the AI is behaving. Changed pulse, it drifted, and the ledger shows the moment it happened. The evidence is the byproduct of running the AI, not a report assembled afterward.

A bell jar over a beating light: one AI deployment, its pulse attested.

The exposure is already on your books.

Article 50 carries penalties up to a set share of global annual turnover, per violation; confirm the figure for your case with counsel. Logs on a server you administer cannot prove they are contemporaneous, which is the one thing a regulator asks.

Heartbeat is twelve months of continuously signed, hash-chained evidence any auditor can verify. Against the exposure, the license is a rounding error.

The license buys the evidence, not a verdict on the fine.

The world has already ruled on AI without proof.

Courts have recognized privilege risk when confidential data passes through third-party AI

Privilege waived through AI servers.

A federal court held privilege can be waived when client data passes through third-party AI servers, and the firm could not prove the AI use was scoped or contained.

A signed receipt is that proof, produced locally, with nothing pinging out.

UnitedHealth, nH Predict litigation

AI claims denials at scale.

The complaint cites the absence of a verifiable artifact for each AI-assisted denial, and the difficulty of reconstructing what the system did at the moment of each one.

A per-decision receipt gives every denial an audit artifact reviewers verify themselves.

Italian Garante v. Replika, 2023

Emergency ban over harm to minors.

Italy's regulator banned the service after finding it failed to protect minors. No verifiable evidence of age-adaptive governance existed at the time of review.

The signed stream is evidence a regulator inspects directly, without taking the operator's word.

One pulse layer. Many surfaces.

The architecture does not care what the AI is doing. It cares that every governed output leaves a beat. The buyer and the regulation change with the surface, the license shape does not.

Legal AIEvery prompt and output gets a beat. Privilege survives because the receipts prove the work was scoped and contained, locally. ABA Rules 1.1 and 1.6.
BiotechEach AI-assisted decision is a signed beat with a verifiable timestamp, inside the validated environment. 21 CFR Part 11, EU GMP Annex 11.
SemiconductorEvery governed output stays inside the controlled boundary. The verifier confirms it without ever seeing the content. ITAR, EAR.
HealthcareEvery AI-assisted decision leaves an audit artifact a compliance officer can produce on demand. HIPAA.
FinancialA signed record for every model decision, mapped to the records supervision already draws on. SEC, FINRA.

It is infrastructure, not a certifier.

It does not certify your compliance. It makes the evidence you bring to it. Evidence, not certification.

You produce signed evidence. You and your auditor interpret it. You and your regulator settle it. No certifier sits in your chain, so there is no opinion to challenge in court. We hold nothing of yours. You hold the keys. You hold the evidence. We hold the filings; the USPTO allowed the first claims in July 2026. The verifier is public for anyone to check, never a lever we can pull on you.

Where it sits.

The pulse, and the memory.

Heartbeat is the pulse of one AI surface: every output a signed beat. The Witness is the whole estate's memory: every moment across every tool, with the human decision sealed beside it. The beat proves the machine ran clean. The memory answers for everything it ran.

One pulse. Five surfaces. The same signed receipt.

The architecture does not care what the AI is doing. It cares that every output leaves a beat.

Privileged legal AIOne legal or productivity AI deployment inside a firm. Answers ABA Model Rules 1.1 and 1.6 and the privilege-waiver risk. Every prompt and output gets a signed beat, and privilege survives because the record proves the work was scoped and contained, locally.
Validated pharmaOne AI assistant inside a GxP-validated system. Answers 21 CFR Part 11 and EU GMP Annex 11. Every AI-assisted decision is a signed beat with a verifiable timestamp, and inspectors verify the chain.
Export-controlled designOne design assistant inside an export-controlled environment under ITAR and EAR. Every governed output stays inside the boundary, and the receipt is the evidence that controlled material never left.
Cleanroom and bio-manufacturingOne AI advising on release or environmental-monitoring decisions. Answers GMP and ISO 14644 reconstructability. When an event is investigated, the chain is the record.
Consumer AI in EuropeOne consumer-facing AI tool. Answers EU AI Act Article 50 transparency and synthetic-content marking. The evidence is the byproduct, not a report written afterward.

How the proof works

Three steps, one architecture.

Govern at the moment of output. It deploys inside your environment, bound to your license. Every AI output passes through it, and the decision to allow, refuse, hold, or escalate is made on local computation alone. The capability is local or it does not run.

Issue the receipt as a byproduct. Each governed event produces a signed receipt, chained to the one before it. Tamper-evident, append-only, signed on your machine. Nothing pings out, and nothing leaves.

Hand the proof to whoever asks. Export the bundle, and your auditor, counsel, or regulator runs the public verifier against your key. The chain matches or it does not. You never call us, and we never see your data.

Proof you can hold, made where the data lives, sent nowhere.

Clean answers.

The questions buyers ask first.

What counts as one AI surface?

One stable AI deployment with one identifier: a legal-AI deployment, a productivity-suite AI tenant, an enterprise model endpoint, an internal RAG, a customer-facing chatbot, a drug-discovery assistant. Heartbeat binds to that one deployment and signs every governance event from it. Three surfaces need three licenses. One surface serving a million queries needs one.

Does this make me EU AI Act compliant?

No. It produces verifiable evidence for one bound AI deployment, which is what an auditor or regulator needs to check governance of that deployment. Compliance is a posture across your whole estate. This is one strong piece of evidence in that picture.

Is this a compliance certification?

No, and that distinction protects you. We are infrastructure. You generate the signed evidence, you and your auditor interpret it, you and your regulator settle it. No certifier sits in your chain whose opinion can be challenged in court. You hold the keys. You hold the evidence, and the verifier is public for anyone to check.

What happens if the AI drifts?

The signed record shows it, contemporaneously. The product does not decide what drift means. Your team, your auditor, your counsel, or your regulator interpret it. The point is that the evidence is there, signed and verifiable, before anyone asks.

What support is included?

The software, the documentation, the install guide, the audit-defense playbook, and the open-source verifier, delivered at purchase. It self-installs. Support contracts, SLAs, and consulting are separate engagements.

How is this different from Vanta, Drata, or Credo AI?

Those sell policy dashboards and checklist tooling to prepare for certifications. None produces a verifiable evidence stream a regulator can check independently. Heartbeat is the substrate underneath that question. We compete with the absence of evidence, not with dashboards.

What does my engineering team have to do?

Install it and point your AI pipeline at a single endpoint. About one engineer-day for a team that already runs containers. The public verifier confirms the integration is correct before you ever show evidence to a regulator.

Does it phone home?

No. It runs entirely on your infrastructure. The signing key is generated on your machine and never leaves it. No telemetry, no analytics, no remote update. Block all outbound traffic at your firewall and it still works.

What happens if my license expires?

It keeps running. New outputs stop being covered by the Heartbeat Attested mark, but every receipt signed before expiry stays valid and verifiable forever. A lapse creates a gap going forward, never backward.

What if EU AI Act enforcement changes?

The same evidence stream is responsive to NIST AI RMF, FDA and EMA principles, EU GMP Annex 11, ISO 42001, and the US state AI acts. The infrastructure you buy for one cliff defends you under the next.

Who is behind it?

Regulayer, Inc. Patents pending; the estate is held by the inventor with counsel of record.

What is the difference between Heartbeat Attested and Regulayer?

Heartbeat covers one bound AI deployment. Regulayer covers the whole estate, adding fleet aggregation, drift monitoring, and the broader claim set. Start with Heartbeat on one surface, add more over time.

Steady when it behaves. Provable when it drifts.