What happened
Why this matters more than the other four
docs/eu-ai-act-compliance.md alongside their existing documentation.
This isn't a theoretical contribution. Dify deployers in the EU now have a starting point for AI Act compliance that didn't exist yesterday. It maps their actual features to actual regulatory requirements, identifies the specific gaps (knowledge base data provenance, Article 50 user disclosure, human oversight for high-risk applications), and tells them what Dify handles versus what they need to handle themselves.
The pattern
What's different now
AI Trace Auditor is open source (Apache 2.0). The merged PR is langgenius/dify#33838.