I’m mapping HUQAN against current AI governance requirements. The precise claim is not “HUQAN is compliant”; it is technical evidence and enforcement infrastructure for selected controls. EU AI Act: Art. 9 — policy/risk gates, action-risk classification and fail-closed block/review/dry-run decisions can support risk mitigation. Arts. 11–12 — evidence, provenance, audit logs and Trust Receipts can provide technical decision context and traceability. Art. 14 — approval boundaries and human-review escalation support a human-oversight control surface. Art. 15 — deterministic verification, contradiction checks, the action firewall and isolation can help address specific accuracy, robustness and action-safety risks. Arts. 17–20 and 26 — audit and re-verification records can feed quality and deployer processes, but do not replace QMS, incident reporting or deployer obligations. GDPR: local-first operation, workspace isolation and bounded audit metadata can support minimisation, security and accountability. HUQAN does not decide legal basis, perform a DPIA, manage data-subject rights or define retention. NIST AI RMF / ISO 42001: HUQAN can provide evidence for a broader risk-management programme or AI Management System; it is not a certification. The actual compliance conclusion still depends on the use case, role, data processing, jurisdiction and organisation-wide process. Are your AI-powered applications ready for these compliance requirements? https://github.com/ali-ulu/huqan