How does governing MCP server access satisfy EU AI Act requirements?

Kastra enforces governing MCP server access at the moment of execution and writes a signed evidence record for every MCP request. Auditors get a complete, append-only trail of who attempted what, what policy fired, why the decision was made, and what data was touched. This evidence maps directly to EU AI Act, NIST AI RMF, SOC 2 control families.