Skip to main content

How does Cyber Crucible relate to the EU AI Act?

Short answer: Cyber Crucible uses AI only during development (its Genetic AI discovery work) and runs fixed, deterministic heuristics at runtime — there is no live AI model making decisions on the customer's endpoint. So Cyber Crucible does not place a high-risk or general-purpose AI system into the customer's environment. The customer remains responsible for assessing its own obligations under the EU AI Act, whose requirements are phasing in through 2026–2027.

Why the architecture matters here

  • No runtime AI system deployed to the customer. The endpoint runs deterministic kernel heuristics, not a live model — so there is no on-device AI system for the customer to classify and govern under the Act.
  • Development-time only. The AI work happens in Cyber Crucible's internal development environment, on internal research datasets; no customer content, credentials, or keys are used to train, feed, or tune a model.
  • Transparency. Because runtime behavior is deterministic and testable rather than probabilistic, it is straightforward to describe and document.

The honest boundary

Cyber Crucible does not claim the product is "EU AI Act compliant," and it does not make that determination for a customer. This page describes how the product works so a customer's own AI Act assessment can account for it accurately. This is not legal advice.