Article 14(4): human oversight
A person must be able to understand, override, and intervene or stop the system.
Anlyon makes the call, so it can hold it. A gated action parks for a human. Policy routes what needs review, and a rule can require N distinct approvers. N counts distinct credentials for API-key deciders and distinct users for dashboard and OAuth deciders. Halt stops the agent acting and stops anything leaving. A request another server already accepted is not recalled.
Article 12: record-keeping
Automatic logging of events relevant to risk identification and traceability.
Every run is a trace: model calls, invocations Anlyon made on the agent's behalf, approval waits and decisions, who decided, when, under which policy version. Exportable as OpenTelemetry, so your records outlive any vendor.
Article 9: risk management
Identify and control the risks the system poses in production.
Environment isolation bounds the blast radius: a staging key can't resolve to production. A protected environment needs explicit confirmation to change. Budgets cap the Anlyon operations a key may perform. Versioned action definitions let you pin what an agent version shipped with, and a rollback puts the previous definitions back for what happens next.
Anlyon provides oversight and logging capabilities. Whether your system is in scope and compliant is a determination for your counsel.