Live demo of the Axiom Audit Portal. Data is synthetic but representative of a real assessment.
Recommended Assessment Outcome
BLOCK
Residual Non-Conformity Index
ELEVATED
Score: 2.39
(Unwitnessed ÷ Total) × Severity × Staleness
Passing
42
of 137 requirements
Findings
10
open findings
EU AI Act risk tier determines which conformity obligations apply. Select the classification that matches this AI system.
AI systems in Annex III areas that pose significant risks to health, safety, or fundamental rights. Requires third-party or internal conformity assessment.
Obligations
Full conformity assessment required: risk management (Art. 9), data governance (Art. 10), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy & robustness (Art. 15), post-market monitoring (Art. 72).
Annex III Categories
Loading risk register...
Loading checklist...
AI Governance
| Procedure | Family | Title | Severity | Verdict | Last Witnessed | Verify |
|---|---|---|---|---|---|---|
| AI-GRD.1 | AI | Guardrail Enforcement — Required Safety Filters Active Found {factor_b} active safety guardrails (required: {factor_a}). EU AI Act Art. 9(2)(a) requires suitable risk management measures to identify and mitigate risks. NIST AI RMF MANAGE 4.1 requires risk treatments. Guardrail enforcement: {verdict_word}met. Required Guardrails: 1Active Guardrails: 0 Open 81d | CAT II | FAIL | 7/13/2026 | Verify → |
| AI-HITL.3 | AI | Overseer Identity Capture - Reviewer Identified Per Decision Overseer identity capture is {verdict_word}active. EU AI Act Art. 12(2)(d) requires logs to include identification of natural persons involved in verification of results. NIST AI RMF GOVERN 1.1 requires traceable oversight. Identity Capture Required: 0.5Identity Captured: 1 Open 177d (overdue) | — | FAIL | 4/8/2026 | Verify → |
| AI-EXPL.1 | AI | Explanation Generation Explanation generation is {verdict_word}active. EU AI Act Art. 13(1) requires high-risk AI systems to be sufficiently transparent to enable deployers to interpret output. NIST AI RMF MEASURE 2.5 requires interpretability measures. Explanation Required: 0.5Explanation Generated: 1 Frameworks:CO-SB-26-189EU-AI-ACTFIVE-EYES-AGENTICHEALTH-INS-AIISO-42001KR-AI-BASICMD-HB-895NIST-AI-RMFSR-11-7 Open 175d (overdue) | — | FAIL | 4/10/2026 | Verify → |
| AI-GRD.2 | AI | Content Safety Filter — Output Classification Passed Content safety filter {verdict_word}passed. EU AI Act Art. 9(4)(b) requires risk management to address reasonably foreseeable misuse including harmful outputs. NIST AI RMF GOVERN 1.5 requires ongoing policy compliance assessment. Clean Expected: 0.5Refusal Detected: 1 Open 174d (overdue) | — | FAIL | 4/12/2026 | Verify → |
| AI-FAIR.2 | AI | Fairness Calibration Fairness calibration score is {factor_b} against a minimum of {factor_a}. EU AI Act Art. 9(4)(a) requires elimination or reduction of risks. NIST AI RMF MAP 2.3 requires mapping AI impacts to affected populations. Score {verdict_word}meets minimum. Min Calibration Score: 0.5Actual Calibration: 1 Open 173d (overdue) | — | FAIL | 4/13/2026 | Verify → |
| AI-EXPL.2 | AI | Confidence Scoring Model confidence score is {factor_b} against a minimum of {factor_a}. EU AI Act Art. 13(3)(b)(ii) requires disclosure of the degree of accuracy. NIST AI RMF MAP 2.3 requires confidence calibration. Score {verdict_word}meets threshold. Min Confidence Score: 0.5Actual Confidence: 1 Open 172d (overdue) | — | FAIL | 4/13/2026 | Verify → |
| AI-GOV.3 | AI | Approved Model Registry Approved model registry is {verdict_word}current. EU AI Act Art. 49 requires registration of high-risk AI systems in the EU database. NIST 800-53 CM-8 requires a system component inventory including version and risk classification. Registry Required: 0.5Registry Active: 1 Open 171d (overdue) | — | FAIL | 4/14/2026 | Verify → |
| AI-EMRG.1 | AI | Emergency Override Lifecycle Witnessing Emergency override is {verdict_word}authorized: trigger type {factor_a} (0=e-stop, 1=operator, 2=escalation, 3=responder), authorization level {factor_b} (0=operator, 1=supervisor, 2=manager, 3=responder), fallback state {factor_c} (0=safe, 1=legacy, 2=manual, 3=degraded, 4=shutdown). EU AI Act Art. 14 requires human override capability for high-risk AI. IEC 61511 requires logged, auditable override events. Trigger Type: 2Authorization Level: 0 Open 81d | — | FAIL | 7/13/2026 | Verify → |
| AI-DRIFT.2 | AI | Consequence-Mapped Drift Threshold Response Drift consequence response is {verdict_word}proportional: drift magnitude {factor_a}, consequence category {factor_b} (0=safety, 1=environmental, 2=financial, 3=operational, 4=reputational), response action {factor_c} (0=notify, 1=monitor, 2=throttle, 3=circuit-break, 4=failover, 5=shutdown). EU AI Act Art. 9(2)(b) requires continuous risk estimation. OCC 2026-13 requires materiality-mapped drift tracking with graduated responses. Drift Magnitude: 38Consequence Category: 3Response Action: 2 Open 81d | — | FAIL | 7/13/2026 | Verify → |
| AI-ASSESS.1 | AI | Champion-Challenger Assessment Witnessing Champion-challenger assessment is {verdict_word}within acceptance criteria: {factor_a} inputs processed, max divergence {factor_b}/1000, threshold breached = {factor_c} (1=yes, 0=no). EU AI Act Art. 15 requires post-market monitoring. OCC 2026-13 requires versioned challenger runs with documented sign-off. Inputs Processed: 8000Max Divergence (x1000): 142Threshold Breached: 1 | — | FAIL | 7/13/2026 | Verify → |
| AI-MCP.2 | AI | Tool Integrity Attestation MCP tool integrity is {verdict_word}intact: schema hash {factor_a}, invocation #{factor_b}, drift detected = {factor_c} (0=none, 1=drift). OWASP Agentic MCP-03 (Tool Poisoning) requires schema integrity monitoring between invocations. | — | UNKNOWN | — | — |
| AI-REACH.1 | AI | Hazard Reachability Attestation Hazard reachability is {verdict_word}mitigated: {factor_b} of {factor_a} assessed hazards confirmed mitigated, method {factor_c} (0=manual, 1=automated, 2=vendor_attested). EU AI Act Art. 53 requires risk identification. ISO 42001 6.1.2 requires risk assessment. | — | UNKNOWN | — | — |
| AI-MCP.3 | AI | Server Authentication Attestation MCP server authentication is {verdict_word}active: method {factor_a} (0=none, 1=api_key, 2=oauth, 3=mtls, 4=did), validity {factor_b}s, mutual auth = {factor_c}. OWASP Agentic MCP-07 requires server authentication. NIST 800-53 IA-9 requires service identification. | — | UNKNOWN | — | — |
| AI-DATA.3 | AI | Training Data Statistics Training data statistics are {verdict_word}recorded: {factor_a} total samples, {factor_b} features, class balance ratio = {factor_c} (x1000, e.g., 850 = 85%). EU AI Act Art. 10(3) requires documentation of training data properties and statistical characteristics. | — | UNKNOWN | — | — |
| AI-DATA.4 | AI | Training Data PII Lifecycle Training data PII lifecycle event is {verdict_word}recorded: {factor_a} records affected, event completed = {factor_b} (1=yes, 0=partial/failed), event type code {factor_c} (0=unspecified, 1=pseudonymization, 2=anonymization, 3=access_restriction, 4=deletion, 5=encryption). EU AI Act Art. 10(5) requires data governance. GDPR Art. 25 requires data protection by design. | — | UNKNOWN | — | — |
| AI-MCP.4 | AI | Server Discovery Attestation MCP server discovery is {verdict_word}complete: method {factor_a} (0=manual, 1=dns-sd, 2=mdns, 3=registry, 4=network), {factor_b} servers found, {factor_c} unauthorized (shadow servers). OWASP Agentic MCP-09 requires authorized server inventory. NIST 800-53 CM-8 requires component inventory. | — | UNKNOWN | — | — |
| AI-GOV.6 | AI | AI Risk Management Scope Definition AI risk management scope definition is {verdict_word}documented. NIST AI RMF GOVERN 1.3 requires a documented scope definition including which AI systems are in scope, their intended purposes, deployment contexts, and risk tolerances. NIST 800-53 SA-3 requires system development lifecycle planning that defines scope boundaries. | — | UNKNOWN | — | — |
| AI-GOV.7 | AI | AI Governance Resource Allocation AI governance resource allocation is {verdict_word}documented. NIST AI RMF GOVERN 2.2 requires adequate resources (budget, staffing, compute) allocated for AI risk management activities. NIST 800-53 PM-3 requires information security resource planning. | — | UNKNOWN | — | — |
| AI-RISK.1 | AI | AI Risk Identification and Categorization AI risk identification and categorization is {verdict_word}complete. NIST AI RMF MAP 2.1 requires identified risk sources with assigned categories and documented residual risk acceptance decisions. NIST 800-53 RA-2 requires security categorization of information systems including AI components. | — | UNKNOWN | — | — |
| AI-IR.1 | AI | AI Incident Response Capability AI incident response capability is {verdict_word}operational. NIST AI RMF MANAGE 3.1 requires real-time incident detection and response procedures for AI system failures. NIST 800-53 IR-8 requires an incident response plan covering AI-specific scenarios including model recall, guardrail bypass, and data contamination. | — | UNKNOWN | — | — |
| AI-IMPACT.1 | AI | AI Societal Impact Assessment AI societal impact assessment is {verdict_word}complete. NIST AI RMF MAP 5.2 requires community and societal-level impact assessment beyond individual bias metrics. NIST 800-53 RA-3 requires risk assessment that considers broader organizational and societal impacts. | — | UNKNOWN | — | — |
| AI-RAG.2 | AI | Context Relevance Scoring RAG context relevance is {verdict_word}assessed: similarity threshold {factor_a}/1000, average similarity {factor_b}/1000, {factor_c} chunks below threshold. EU AI Act Art. 10(2) requires data governance covering data quality and relevance. NIST AI RMF MEASURE 2.6 requires traceability of AI system outputs. | — | UNKNOWN | — | — |
| AI-MDL.5 | AI | Weight File Integrity Model weight file integrity is {verdict_word}verified: hash match = {factor_b} (1=match, 0=mismatch). EU AI Act Art. 15(4) requires resilience against unauthorized modification. NIST AI RMF MANAGE 1.3 requires model integrity verification. | — | UNKNOWN | — | — |
| AI-MDL.6 | AI | Adapter Stack Attestation Adapter stack is {verdict_word}attested: {factor_a} adapters loaded, all verified = {factor_b} (1=yes, 0=no). EU AI Act Art. 12(2)(b) requires version and lineage tracking. NIST AI RMF MAP 2.3 requires documentation of AI system components. | — | UNKNOWN | — | — |
| AI-MDL.7 | AI | Quantization Attestation Model quantization is {verdict_word}attested: method code {factor_c} (0=FP32, 1=FP16, 2=BF16, 3=INT8, 4=INT4, 5=GPTQ, 6=AWQ, 7=GGUF). EU AI Act Art. 15(3) requires performance consistency documentation. NIST AI RMF MEASURE 2.5 requires computational accuracy assessment. | — | UNKNOWN | — | — |
| AI-SKILL.2 | AI | Memory Context Binding Memory context is {verdict_word}bound: {factor_a} memory sources active, all identified = {factor_b} (1=yes, 0=anonymous). EU AI Act Art. 12(2)(a) requires logging of reference data sources. NIST AI RMF MAP 3.5 requires data provenance documentation. | — | UNKNOWN | — | — |
| AI-SKILL.3 | AI | Reward Model Binding Reward model is {verdict_word}bound: identified = {factor_b} (1=yes, 0=unknown). EU AI Act Art. 9(4)(a) requires risk identification including alignment mechanisms. NIST AI RMF MEASURE 2.6 requires traceability of output scoring. | — | UNKNOWN | — | — |
| AI-HW.3 | AI | TPM Platform Attestation TPM platform integrity is {verdict_word}attested: {factor_a} PCR registers read, all non-zero = {factor_b} (1=healthy, 0=uninitialized/tampered), reserved {factor_c}. Proves host firmware has not been tampered with via hardware root of trust. NIST 800-53 SC-12 requires cryptographic key establishment. EU AI Act Art. 15(4) requires cybersecurity measures. | — | UNKNOWN | — | — |
| AI-TRUST.2 | AI | Trust Credential Presentation Trust handshake is {verdict_word}recorded: {factor_a} checks performed, {factor_b} passed, result {factor_c} (1=granted, 0=denied). Bilateral evidence of agent-to-agent trust verification. EU AI Act Art. 12 requires record-keeping for inter-system interactions. NIST AI RMF GOVERN 1.4 requires risk-proportional access controls. | — | UNKNOWN | — | — |
| AI-CHAIN.2 | AI | Chain Trust Degradation Chain trust degradation is {verdict_word}recorded: previous trust = {factor_a}, new trust = {factor_b}, degradation delta = {factor_c}. EU AI Act Art. 9 requires risk management through multi-agent chains. NIST AI RMF GOVERN 1.3 requires trust level tracking across handoffs. | — | UNKNOWN | — | — |
| AI-FAIR.3 | AI | Bias Audit Witnessing Bias audit is {verdict_word}recorded: {factor_a} demographic groups tested, {factor_b} disparities found, max disparity = {factor_c} (x10, e.g., 125 = 12.5%). EU AI Act Art. 10(2)(f) requires examination of bias. NIST AI RMF MAP 2.3 requires bias identification across demographic groups. | — | UNKNOWN | — | — |
| AI-ENV.2 | AI | Dependency Manifest Attestation Dependency manifest is {verdict_word}attested: {factor_a} dependencies counted, all pinned = {factor_b} (1=yes, 0=no), {factor_c} known vulnerabilities. EU AI Act Art. 11 requires technical documentation. EO 14028 requires software supply chain integrity. | — | UNKNOWN | — | — |
| AI-BASE.1 | AI | Agent Behavioral Baseline Agent behavioral baseline is {verdict_word}recorded: {factor_a} behavioral dimensions measured, within envelope = {factor_b} (1=yes, 0=drift), mode {factor_c} (0=establishing, 1=monitoring, 2=drift_detected, 3=baseline_reset). EU AI Act Art. 9(2)(b) requires continuous monitoring of AI system performance. NIST AI RMF MEASURE 2.6 requires measurement of AI system trustworthiness over time. | — | UNKNOWN | — | — |
| AI-LIC.1 | AI | License Provenance License provenance is {verdict_word}verified: {factor_a} license components checked, all compliant = {factor_b} (1=yes, 0=violation detected), license type code {factor_c} (0=permissive, 1=copyleft, 2=proprietary, 3=dual, 4=openmdw, 5=unknown). EU AI Act Art. 53(1)(d) requires transparency of training data and model licensing for GPAI providers. NIST AI RMF GOVERN 1.7 requires documenting legal and licensing constraints. | — | UNKNOWN | — | — |
| AI-REDTEAM.1 | AI | Adversarial Test Campaign Adversarial test campaign is {verdict_word}recorded: {factor_a} attack scenarios executed, {factor_b} successfully mitigated, coverage category code {factor_c} (0=prompt_injection, 1=jailbreak, 2=data_poisoning, 3=model_extraction, 4=membership_inference, 5=adversarial_examples, 6=supply_chain, 7=denial_of_service, 8=output_manipulation, 9=privilege_escalation, 10=comprehensive). EO 14110 requires red-team testing of foundation models. EU AI Act Art. 9(7) requires testing including adversarial testing. | — | UNKNOWN | — | — |
| AI-MULTI.1 | AI | Multi-Agent Delegation Multi-agent delegation is {verdict_word}recorded: {factor_a} delegation depth (hops from human), {factor_b} permissions granted, time bound {factor_c} minutes (0=unbounded). EU AI Act Art. 9 requires risk management for autonomous delegation chains. NIST AI RMF GOVERN 1.3 requires documenting roles and responsibilities across agent boundaries. | — | UNKNOWN | — | — |
| AI-INCIDENT.1 | AI | Incident Reporting Incident report is {verdict_word}recorded: severity code {factor_a} (1=low, 2=medium, 3=high, 4=critical), authority notified = {factor_b} (1=yes, 0=no), incident type code {factor_c} (0=safety, 1=rights, 2=security, 3=performance, 4=bias, 5=other). EU AI Act Art. 62 requires reporting serious incidents. NIST AI RMF MANAGE 3.2 requires incident communication. | — | UNKNOWN | — | — |
| AI-PERF.1 | AI | Performance Metrics Performance metrics are {verdict_word}recorded: {factor_a} metrics evaluated, {factor_b} passing, benchmark type code {factor_c} (0=accuracy, 1=precision, 2=recall, 3=f1, 4=auc, 5=custom). EU AI Act Art. 15(1) requires declared accuracy levels. NIST AI RMF MEASURE 2.5 requires performance measurement. | — | UNKNOWN | — | — |
| AI-ROBUST.1 | AI | Robustness Testing Robustness testing is {verdict_word}recorded: {factor_a} perturbations tested, {factor_b} survived, perturbation type code {factor_c} (0=noise, 1=corruption, 2=missing_data, 3=out_of_distribution, 4=edge_case, 5=adversarial_input). EU AI Act Art. 15(3) requires resilience against errors and inconsistencies. NIST AI RMF MEASURE 2.6. | — | UNKNOWN | — | — |
| AI-CYBER.1 | AI | Cybersecurity Attestation Cybersecurity assessment is {verdict_word}recorded: {factor_a} controls assessed, {factor_b} compliant, framework code {factor_c} (0=nist_csf, 1=iso27001, 2=owasp, 3=cis, 4=custom). EU AI Act Art. 15(4) requires appropriate cybersecurity. NIST Cybersecurity Framework. | — | UNKNOWN | — | — |
| AI-AUTO.1 | AI | Automated Decision Notification Automated decision notification is {verdict_word}recorded: {factor_a} decisions made, {factor_b} human reviewed, decision type code {factor_c} (0=credit, 1=employment, 2=insurance, 3=benefits, 4=legal, 5=other). GDPR Art. 22 requires notification of automated decisions with legal effects. EU AI Act Art. 14 requires human oversight. | — | UNKNOWN | — | — |
| AI-DUALUSE.1 | AI | Dual-Use Model Classification Dual-use model classification is {verdict_word}recorded: classification code {factor_a} (0=standard, 1=dual_use, 2=high_impact), reporting status code {factor_b} (0=not_required, 1=pending, 2=notified, 3=acknowledged), {factor_c} days since classification. EO 14110 Sec 4(a) requires reporting dual-use foundation models. NIST AI RMF GOVERN 1.1. | — | UNKNOWN | — | — |
| AI-ORCH.1 | AI | Orchestration Topology Attestation Orchestration topology is {verdict_word}recorded. Topology: {factor_a} (0=sequential, 1=parallel, 2=hierarchical, 3=hybrid, 4=mesh), agents: {factor_b}, dependency depth: {factor_c}. NIST AI RMF GOVERN 1.3 requires documenting multi-agent coordination patterns. EU AI Act Art. 9 requires risk management for AI systems. | — | UNKNOWN | — | — |
| AI-ORCH.2 | AI | Inter-Agent Handoff Attestation Inter-agent handoff is {verdict_word}recorded. Permission delta: {factor_c} (1=escalation, 0=lateral, -1=restriction). NIST AI RMF GOVERN 1.3 requires tracking delegation between AI components. EU AI Act Art. 9 requires documenting AI system interactions. | — | UNKNOWN | — | — |
| AI-CTX.1 | AI | Context Window Management Attestation Context window management is {verdict_word}within bounds. Tokens before: {factor_a}, after: {factor_b}, eviction method: {factor_c} (0=none, 1=truncation, 2=summarization, 3=sliding window, 4=priority eviction). NIST AI RMF MEASURE 2.6 requires transparency of context handling. EU AI Act Art. 13 requires transparency measures. | — | UNKNOWN | — | — |
| AI-SAND.1 | AI | Sandbox Enforcement Attestation Sandbox enforcement is {verdict_word}clean. Tools declared: {factor_a}, invoked: {factor_b}, violations: {factor_c}. NIST 800-53 SA-11(8) requires software fault isolation. EU AI Act Art. 15 requires cybersecurity measures for high-risk AI systems. This procedure witnesses the harness's own report; cross-reference AI-TOOL.1 for independent verification. | — | UNKNOWN | — | — |
| AI-GATE.1 | AI | Eval Gate Decision Attestation Eval gate decision is {verdict_word}above threshold. Total evals: {factor_a}, passed: {factor_b}, gate score: {factor_c}/100. NIST AI RMF MEASURE 2.5 requires documented evaluation criteria. EU AI Act Art. 9(7) requires testing appropriate to the intended purpose of the AI system. | — | UNKNOWN | — | — |
| AI-A2A.1 | AI | Task Delegation Lifecycle Attestation A2A task delegation is {verdict_word}witnessed: state code {factor_a} (0=submitted, 1=working, 2=input_required, 3=completed, 4=failed, 5=canceled, 6=rejected), latency {factor_b}ms, delegation depth {factor_c}. EU AI Act Art. 9 requires risk management across AI system interactions. NIST AI RMF GOVERN 1.3 requires accountability for delegated operations. | — | UNKNOWN | — | — |
| AI-SUPPLY.1 | AI | Supply Chain Risk Supply chain risk is {verdict_word}assessed: {factor_a} suppliers assessed, {factor_b} compliant, risk level code {factor_c} (0=low, 1=medium, 2=high, 3=critical). NIST AI RMF MEASURE 3.1 requires supply chain risk metrics. G7/CISA SBOM-AI. EO 14028. | — | UNKNOWN | — | — |
| AI-PMM.1 | AI | Post-Market Monitoring Post-market monitoring is {verdict_word}recorded: {factor_a} checks run, {factor_b} anomalies detected, monitoring type code {factor_c} (0=performance, 1=fairness, 2=safety, 3=security, 4=comprehensive). EU AI Act Art. 72 requires post-market monitoring system. NIST AI RMF MANAGE 4.1. | — | UNKNOWN | — | — |
| AI-AUTO.2 | AI | Autonomous Generation Depth Autonomous generation depth is {verdict_word}within limits: max allowed depth = {factor_a}, observed depth = {factor_b}, human gate present = {factor_c} (1=yes, 0=autonomous). EU AI Act Art. 14 requires human oversight proportionate to risk. NIST AI RMF GOVERN 1.5 requires organizational policies for autonomous systems. EO 14110 Sec. 3 addresses recursive AI generation risks. | — | UNKNOWN | — | — |
| AI-AUDIT.2 | AI | External Timestamp Attestation External timestamp attestation is {verdict_word}verified: {factor_a} anchors in batch, TSA verified = {factor_b} (1=yes, 0=no), TSA provider code {factor_c} (0=none, 1=freetsa, 2=digicert, 3=sectigo, 4=custom). EU AI Act Art. 12(1) requires tamper-evident logging. NIST AI RMF GOVERN 1.4 requires organizational accountability. RFC 3161 timestamping provides non-repudiation. | — | UNKNOWN | — | — |
| AI-A2A.2 | AI | Agent Card Discovery Attestation Agent card discovery is {verdict_word}verified: method {factor_a} (0=direct_url, 1=well_known, 2=registry, 3=referral), {factor_b} agents discovered, {factor_c} with verifiable credentials. EU AI Act Art. 13 requires transparency measures. Five Eyes Agentic FE-5 requires agent identity verification. | — | UNKNOWN | — | — |
| AI-A2A.3 | AI | Context Chain Linking Attestation Context chain linking is {verdict_word}recorded: {factor_a} tasks in chain, {factor_c} distinct agents participating. EU AI Act Art. 9 requires traceable risk management across multi-agent interactions. Five Eyes Agentic FE-6 requires chain-of-custody tracking. | — | UNKNOWN | — | — |
| AI-MCP.5 | AI | OAuth Token Binding Attestation OAuth token binding is {verdict_word}enforced: event type {factor_a} (0=discovery through 7=revocation), {factor_b} scopes, binding strength {factor_c} (0=none, 1=session, 2=dpop, 3=mtls). OWASP Agentic MCP-07 requires token binding. EU AI Act Art. 15(3) requires access control measures. | — | UNKNOWN | — | — |
| AI-DECOM.1 | AI | AI System Decommissioning Lifecycle Witness AI system decommissioning is {verdict_word}complete: {factor_b} of {factor_a} downstream dependencies resolved, disposal method {factor_c} (0=archived, 1=destroyed, 2=isolated, 3=transferred). EU AI Act Art. 9 requires lifecycle risk management. ISO 42001 8.2 requires operational planning. | — | UNKNOWN | — | — |
| AI-METAGOV.1 | AI | Governance Infrastructure Attestation Governance infrastructure attestation is {verdict_word}recorded: {factor_a} governance components attested, {factor_b} policies verified, configuration hash present = {factor_c} (1=yes, 0=no). Governance systems must attest their own configuration using the same protocol they enforce on governed systems. | — | UNKNOWN | — | — |
| AI-METAGOV.2 | AI | Governance Layer Registration Governance layer registration is {verdict_word}recorded: {factor_a} governance layers registered, {factor_b} validated against witness layer, registration status = {factor_c} (1=authoritative, 0=pending). Each AI governance layer must register with the non-AI witness layer before its outputs are considered authoritative. | — | UNKNOWN | — | — |
| AI-MOB.1 | AI | SIM-Bound Attestation SIM-bound attestation chain is {verdict_word}intact: binding method {factor_c} (0=none, 1=iccid, 2=imsi_hash, 3=esim_eid, 4=dual_sim), offline integrity = {factor_b} (1=intact, 0=broken). EU AI Act Art. 15(4) requires cybersecurity measures for edge AI. NIST AI RMF MANAGE 2.4 requires operational safeguards. | — | UNKNOWN | — | — |
| AI-MOB.2 | AI | Roaming Attestation Roaming policy is {verdict_word}compliant: policy disposition {factor_c} (0=allow, 1=restrict, 2=deny, 3=escalate). EU AI Act Art. 9(7) requires risk management for AI operating across jurisdictions. NIST AI RMF GOVERN 1.1 requires governance of cross-boundary operations. | — | UNKNOWN | — | — |
| AI-MOB.3 | AI | Dual-SIM Policy Enforcement Dual-SIM data residency is {verdict_word}compliant: {factor_a} active SIM profiles, routing mode {factor_c} (0=primary_only, 1=failover, 2=load_balance, 3=geo_fenced). GDPR Art. 44-49 requires lawful cross-border data transfers. NIS-2 Art. 21 requires network security measures. | — | UNKNOWN | — | — |
| AI-MOB.4 | AI | Peer-to-Peer Trust Mesh Peer-to-peer trust mesh has {factor_b} verified peers out of {factor_a} total: mesh mode {factor_c} (0=isolated, 1=relay, 2=direct, 3=broadcast). EU AI Act Art. 15(1) requires technical robustness. NIST AI RMF MANAGE 2.2 requires trustworthiness of connected systems. | — | UNKNOWN | — | — |
| AI-MOB.5 | AI | Bilateral Flush Correlation Bilateral flush correlation is {verdict_word}complete: {factor_b} of {factor_a} locally buffered anchors correlated with clearing house, flush mode {factor_c} (0=manual, 1=connectivity_restored, 2=scheduled, 3=peer_relay). EU AI Act Art. 12 requires logging integrity. NIST AI RMF MEASURE 2.5 requires measurement completeness. | — | UNKNOWN | — | — |
| AI-METAGOV.3 | AI | Policy Downgrade Detection Policy downgrade detection is {verdict_word}recorded: {factor_a} policy transitions evaluated, {factor_b} downgrades detected, enforcement status = {factor_c} (1=blocked, 0=allowed). Governance systems must enforce monotonic policy version progression and detect unauthorized downgrades. | — | UNKNOWN | — | — |
| AI-METAGOV.4 | AI | Circular Dependency Check Circular dependency check is {verdict_word}recorded: {factor_a} governance rules evaluated, {factor_b} cycles detected, validation method = {factor_c} (1=topological_sort, 0=manual). Governance rule configurations must be validated for circular dependencies before activation. | — | UNKNOWN | — | — |
| AI-METAGOV.5 | AI | Governance Authorization Governance authorization is {verdict_word}recorded: {factor_a} authorization requests processed, {factor_b} approved, signature verification = {factor_c} (1=verified, 0=unsigned). Governance configuration changes require cryptographically signed authorization from operators with appropriate authority scope. | — | UNKNOWN | — | — |
| AI-METAGOV.6 | AI | Emergency Override Attestation Emergency override attestation is {verdict_word}recorded: {factor_a} emergency changes made, {factor_b} reviewed within window, auto-witnessed = {factor_c} (1=yes, 0=no). Emergency governance changes made outside normal approval workflow must be automatically witnessed and trigger mandatory review. | — | UNKNOWN | — | — |
| AI-METAGOV.7 | AI | Governance Sync Verification Governance sync verification is {verdict_word}recorded: {factor_a} federated peers checked, {factor_b} policy equivalence confirmed, governance floor met = {factor_c} (1=yes, 0=divergence). Federated organizations must verify governance policy equivalence during trust credential exchange. | — | UNKNOWN | — | — |
| AI-METAGOV.8 | AI | Attestation Purity Verification Attestation purity verification is {verdict_word}recorded: {factor_a} source modules hashed, {factor_b} ML-free verified, purity status = {factor_c} (1=pure, 0=contaminated). Attestation engine source code must be verified to contain no machine learning inference in the witness path. | — | UNKNOWN | — | — |
| AI-RECOMM.1 | AI | AI System Re-commissioning Validation Witness AI system re-commissioning is {verdict_word}validated: {factor_b} of {factor_a} safety checks passed, type {factor_c} (0=full_validation, 1=shadow_mode, 2=limited_scope). EU AI Act Art. 72 requires post-incident validation. ISO 42001 10.2 requires corrective action verification. | — | UNKNOWN | — | — |
| AI-DENSITY.1 | AI | Witnessing Density Attestation Witnessing density is {verdict_word}sufficient: {factor_b} of {factor_a} expected anchors observed, status {factor_c} (0=sufficient, 1=insufficient, 2=degraded). EU AI Act Art. 9 requires continuous risk management. NIST AI RMF MEASURE 2.6 requires ongoing measurement. | — | UNKNOWN | — | — |
| AI-MOB.8 | AI | Network Slice Isolation Verification Network slice isolation is {verdict_word}verified: slice ID hash {factor_a}, isolation status {factor_b} (0=not verified, 1=verified), cross-slice requests blocked: {factor_c}. 3GPP TS 28.310 requires network slice lifecycle management. GSMA NG.116 requires slice isolation assurance. 3GPP TS 33.501 Sec. 6.8 governs slice security. | — | UNKNOWN | — | — |
| AI-ENG.1 | AI | Design Generation Provenance Design generation provenance is {verdict_word}recorded: {factor_a} constraints applied, {factor_b} parameters generated, design domain code {factor_c} (0=mechanical, 1=chemical, 2=electrical, 3=structural, 4=thermal, 5=pharmaceutical, 6=semiconductor, 7=custom). DO-178C 5.1 requires traceable development process. ASME V&V 10 3.1 requires model development documentation. FDA 21 CFR 11.10(a) requires system validation. | — | UNKNOWN | — | — |
| AI-ENG.2 | AI | Simulation Validation Simulation validation is {verdict_word}recorded: {factor_a} simulations run, {factor_b} passed, simulation type code {factor_c} (0=fea, 1=cfd, 2=molecular, 3=thermal, 4=electromagnetic, 5=multiphysics, 6=custom). DO-178C 6.3 requires test coverage analysis. ASME V&V 10 4.1 requires computational model validation. ISO 26262-4 requires system verification. | — | UNKNOWN | — | — |
| AI-ENG.3 | AI | Safety-Critical Review Gate Safety-critical review gate is {verdict_word}recorded: {factor_a} reviewers required, {factor_b} approved, approval type code {factor_c} (0=peer, 1=pe_stamp, 2=safety_board, 3=regulatory, 4=independent_assessor). DO-178C 7.2 requires review and analysis of outputs. FDA 21 CFR 11.10(g) requires authority checks. ISO 26262-2 requires safety management. | — | UNKNOWN | — | — |
| AI-ENG.4 | AI | Material Specification Compliance Material specification compliance is {verdict_word}recorded: {factor_a} specifications checked, {factor_b} met, standard code {factor_c} (0=asme, 1=iso, 2=astm, 3=mil_spec, 4=fda_usp, 5=iec, 6=custom). ASME V&V 10 3.3 requires requirements traceability. DO-254 5.3 requires requirements validation. ISO 26262-8 requires supporting processes. | — | UNKNOWN | — | — |
| AI-ENG.5 | AI | Design Revision Chain Design revision chain is {verdict_word}recorded: {factor_a} total revisions, {factor_b} AI-generated, chain status code {factor_c} (0=in_progress, 1=approved, 2=rejected, 3=superseded, 4=archived). DO-178C 7.3 requires configuration management. FDA 21 CFR 11.10(e) requires audit trail. ASME V&V 10 2.4 requires documentation of model history. | — | UNKNOWN | — | — |
| AI-ENG.6 | AI | Fabrication Release Authorization Fabrication release is {verdict_word}authorized: design hash verified = {factor_a} (1=match, 0=mismatch), {factor_b} authorizations received, release type code {factor_c} (0=prototype, 1=limited_run, 2=mass_production, 3=field_modification, 4=emergency). DO-178C 5.5 requires integration verification. FDA 21 CFR 11.10(f) requires operational system checks. ISO 26262-4 7.4.4 requires production release validation. | — | UNKNOWN | — | — |
| AI-FREEZE.1 | AI | Model Parameter Freeze Attestation Model parameter freeze is {verdict_word}intact: {factor_b} of {factor_a} locked configuration items verified unchanged, scope {factor_c} (0=weights_only, 1=config_and_params, 2=full_stack). EU AI Act Art. 9(2)(b) requires controls over operational drift. NIST 800-53 CM-3 requires configuration change control. | — | UNKNOWN | — | — |
| AI-FIN.1 | AI | Agent Transaction Witnessing Agent transaction witnessing is {verdict_word}recorded: authorization type = {factor_a} (0=none, 1=pre-approved, 2=human, 3=policy, 4=budget_limit), amount = {factor_b} cents, status = {factor_c} (0=pending, 1=authorized, 2=denied, 3=escalated). EU AI Act Art. 14 requires human oversight of automated decisions. NIST AI RMF MANAGE 2.2 requires risk response tracking. | — | UNKNOWN | — | — |
| AI-LCM.1 | AI | Agent Lifecycle Witnessing Agent lifecycle event is {verdict_word}recorded: event type = {factor_a} (0=spawn, 1=checkpoint, 2=migrate, 3=terminate, 4=crash), context tokens = {factor_b}, state hash present = {factor_c} (1=yes, 0=no). EU AI Act Art. 12 requires automatic recording of events. NIST AI RMF MAP 1.3 requires lifecycle stage characterization. | — | UNKNOWN | — | — |
| AI-MOB.6 | AI | Trajectory Decision Attestation Trajectory decision is {verdict_word}attested: safety validated = {factor_b} (1=passed, 0=failed), classification {factor_c} (1=nominal, 2=cautionary, 3=degraded, 4=emergency, 5=abort). EU AI Act Annex III(3a) covers safety components of vehicles. ISO/PAS 8800 requires operational design domain validation. | — | UNKNOWN | — | — |
| AI-MOB.7 | AI | VLA Inference Witnessing VLA inference is {verdict_word}recorded: latency {factor_b}ms, succeeded = {factor_c} (1=yes, 0=exception/timeout). EU AI Act Art. 12(1) requires automatic logging of AI system operation. ISO/PAS 8800 requires real-time inference monitoring for autonomous systems. | — | UNKNOWN | — | — |
| AI-TOOL.2 | AI | Tool Permission Attestation Tool permission attestation is {verdict_word}recorded: {factor_a} tools granted, charter match = {factor_b} (1=matches, 0=drift), permission change type = {factor_c} (0=none, 1=added, 2=removed, 3=escalated). EU AI Act Art. 9 requires risk management. NIST AI RMF GOVERN 1.5 requires ongoing monitoring of AI system capabilities. | — | UNKNOWN | — | — |
| AI-JUR.1 | AI | Cross-Border Inference Routing Cross-border inference routing is {verdict_word}recorded: serving region = {factor_a} (ISO 3166 numeric), user region = {factor_b} (ISO 3166 numeric), compliance status = {factor_c} (0=unchecked, 1=compliant, 2=blocked, 3=override). EU AI Act Art. 10(5) requires data governance for cross-border processing. NIST AI RMF GOVERN 1.7 requires context-specific risk management. | — | UNKNOWN | — | — |
| AI-SAMPLE.1 | AI | Probabilistic Witnessing Summary Probabilistic witnessing summary recorded: {factor_a} inferences skipped during the sampling window. Summary anchors always PASS. EU AI Act Art. 12 requires logging completeness. NIST AI RMF MEASURE 2.6 requires measurement scope documentation. | — | UNKNOWN | — | — |
| AI-MCP.1 | AI | MCP Security Posture Attestation MCP security posture is {verdict_word}sufficient: {factor_b} of {factor_a} checks passed, score {factor_c}/100 (minimum: 75). NSA/CSA MCP Security Best Practices requires observable security posture. OWASP Agentic Top 10 covers the full threat surface. | — | UNKNOWN | — | — |
| AI-PROV.1 | AI | Model Provenance Chain Model provenance chain is {verdict_word}verified: {factor_a} links in lineage, integrity = {factor_b} (1=verified, 0=unverified), link type {factor_c} (0=training, 1=fine_tuning, 2=deployment, 3=distillation). EU AI Act Art. 11 requires technical documentation. NIST AI RMF MAP 1.1 requires data provenance. | — | UNKNOWN | — | — |
| AI-DEL.2 | AI | Delegation Boundary Attestation Delegation boundary is {verdict_word}enforced: max depth {factor_a}, actual depth {factor_b}, boundary action {factor_c} (0=blocked, 1=warned, 2=escalated, 3=allowed). EU AI Act Art. 14 requires human oversight. NIST AI RMF GOVERN 1.4 requires delegation governance. | — | UNKNOWN | — | — |
| AI-COST.1 | AI | Resource Consumption Witnessing | — | UNKNOWN | — | — |
| AI-DEL.1 | AI | Delegation Tree Witnessing | — | UNKNOWN | — | — |
| AI-CAP.1 | AI | Capability Attestation | — | UNKNOWN | — | — |
| AI-AUTO.3 | AI | Autonomy Level Transition | — | UNKNOWN | — | — |
| AI-CLR.2 | AI | Clearing Fidelity Attestation | — | UNKNOWN | — | — |
| AI-MDL.8 | AI | Model Registry Attestation Model registry integrity is {verdict_word}verified: {factor_b} of {factor_a} expected model versions confirmed present and checksum-validated. EU AI Act Art. 11 requires technical documentation. NIST 800-53 CM-3 requires configuration change control. | — | UNKNOWN | — | — |
| AI-MDL.2 | AI | Model Version Tracking — Version Identifier Recorded Model version recording is {verdict_word}active. EU AI Act Art. 12(2)(b) requires logs to include identification of the reference database. NIST AI RMF MANAGE 2.2 requires post-deployment version monitoring. Version Required: 1Version Recorded: 1Context: 1 | — | PASS | 4/8/2026 | Verify → |
| AI-LOG.1 | AI | Log Retention Compliance - Minimum 180-Day Retention Verified AI inference log retention is {factor_b} days (minimum required: {factor_a} days). EU AI Act Art. 12(3) requires deployers to keep automatically generated logs for at least six months. Retention {verdict_word}compliant. Min Retention (days): 1Actual Retention (days): 1Context: 1 | — | PASS | 4/9/2026 | Verify → |
| AI-MDL.4 | AI | Feedback Loop Control - Training Data Isolation From Biased Outputs Feedback loop isolation is {verdict_word}active. EU AI Act Art. 15(4) requires controls to prevent biased outputs from contaminating training data in systems that continue learning after deployment. NIST AI RMF MANAGE 2.2 requires ongoing risk tracking. Threshold: 1Measured: 1Delta: 1 | — | PASS | 4/11/2026 | Verify → |
| AI-GRD.3 | AI | PII Redaction PII redaction is {verdict_word}active. EU AI Act Art. 10(2)(f) requires examination of possible biases affecting health and safety, with data privacy measures. NIST AI RMF GOVERN 1.7 requires data protection processes. PII Redaction Required: 1Redaction Active: 1Context: 1 | — | PASS | 4/11/2026 | Verify → |
| AI-FAIR.1 | AI | Bias Disparity Measurement Bias disparity ratio is {factor_b} against a maximum of {factor_a}. EU AI Act Art. 10(2)(f) requires examination of possible biases in training datasets and outputs. NIST AI RMF MEASURE 2.5 requires bias evaluation across demographic groups. Disparity {verdict_word}within threshold. Max Disparity Ratio: 1Measured Disparity: 1Context: 1 | — | PASS | 4/13/2026 | Verify → |
| AI-DATA.1 | AI | Training Data Provenance Training data provenance is {verdict_word}documented. EU AI Act Art. 10(2)(a) requires documenting relevant design choices including data collection processes. NIST AI RMF MAP 3.5 requires documentation of data provenance and lineage. Documentation Required: 1Documented: 1Context: 1 | — | PASS | 4/14/2026 | Verify → |
| AI-DATA.2 | AI | Training Data License Compliance Training data license compliance is {verdict_word}verified. EU AI Act Art. 10(2)(a) requires data governance covering design choices and data origin. NIST AI RMF GOVERN 1.7 requires conformance with legal and regulatory data requirements. License Check Required: 1Verified: 1Context: 1 | — | PASS | 4/12/2026 | Verify → |
| AI-HITL.2 | AI | Human Override Event Tracking Human override event logging is {verdict_word}active. EU AI Act Art. 14(4)(d) requires the ability to disregard, override, or reverse AI output. NIST AI RMF MANAGE 4.1 requires mechanisms to respond to AI incidents. Override Logging Required: 1Logging Active: 1Context: 1 | — | PASS | 4/8/2026 | Verify → |
| AI-GOV.1 | AI | AI Acceptable Use Policy AI acceptable use policy is {verdict_word}current and communicated. EU AI Act Art. 9 requires a risk management system throughout the lifecycle of a high-risk AI system. NIST 800-53 PL-4 requires rules of behavior for system users. Policy Required: 1Policy Active: 1Context: 1 | — | PASS | 4/14/2026 | Verify → |
| AI-GOV.2 | AI | Employee AI Training AI accountability training is {verdict_word}complete for all personnel with AI system access. EU AI Act Art. 4 requires providers and deployers to ensure sufficient AI literacy of staff. NIST 800-53 AT-2 requires security awareness training. Training Required: 1Training Complete: 1Context: 1 | — | PASS | 4/9/2026 | Verify → |
| AI-GOV.4 | AI | Shadow AI Incident Response Shadow AI incident response procedure is {verdict_word}documented. EU AI Act Art. 26 requires deployers to monitor AI system operation and report incidents. NIST 800-53 IR-4 requires incident handling procedures for unauthorized system usage. IR Procedure Required: 1Procedure Documented: 1Context: 1 | — | PASS | 4/13/2026 | Verify → |
| AI-GOV.5 | AI | Third-Party AI Vendor Assessment Third-party AI vendor assessments are {verdict_word}complete. EU AI Act Art. 25 establishes responsibilities along the AI value chain for distributors and deployers. NIST 800-53 SA-4 requires acquisition processes that include security requirements. Vendor Assessment Required: 1Assessments Complete: 1Context: 1 | — | PASS | 4/12/2026 | Verify → |
| AI-TOOL.1 | AI | Tool Call Witnessing Tool call {verdict_word}executed: input/output hashed, latency {factor_b}ms, result {factor_c} (1=success, 0=exception). EU AI Act Art. 14 requires human oversight of AI system actions including tool use. NIST AI RMF MANAGE 4.1 requires mechanisms for tracking AI system actions and their outcomes. Tool Called: 1Latency (ms): 9Result: 1 | — | PASS | 7/13/2026 | Verify → |
| AI-ID.1 | AI | Agent Identity Assertion Agent identity is {verdict_word}attested. The witness instance that signed this anchor has a bound identity ({factor_b} = 1 if agent_id hashed into fingerprint). EU AI Act Art. 13 requires transparency about the identity of AI system providers and deployers. NIST AI RMF GOVERN 1.1 requires clear accountability structures for AI system oversight. Identity Required: 1Identity Present: 1Context: 1 | — | PASS | 7/13/2026 | Verify → |
| AI-ACC.1 | AI | Agent Access Control Witnessing Access control decision is {verdict_word}witnessed: access granted = {factor_c} (1=granted, 0=denied), within declared scope = {factor_b} (1=yes, 0=out-of-scope). NIST 800-53 AC-4 requires enforcement of approved authorizations. EU AI Act Art. 26 requires deployers to ensure use within intended scope. Access Attempted: 1Within Scope: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-REV.1 | AI | Anchor Revocation Anchor revocation is recorded: reason code {factor_c} (0=unspecified, 1=model_recall, 2=policy_violation, 3=data_contamination, 4=consent_withdrawal, 5=regulatory_order, 6=error_correction). Revocation is always PASS (the revocation itself is valid evidence). NIST 800-53 SI-7 requires integrity verification mechanisms. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-SEC.1 | AI | Adversarial Threat Detection Security scan is {verdict_word}clean: threat score {factor_b} against threshold {factor_a}, threat type code {factor_c} (0=none, 1=prompt_injection, 2=data_poisoning, 3=model_extraction, 4=jailbreak, 5=adversarial_input). EU AI Act Art. 15 requires cybersecurity resilience. NIST AI RMF MANAGE 2.2 requires monitoring for adversarial attacks. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-SEC.2 | AI | Input Validation and Sanitization Input validation is {verdict_word}passed: accepted = {factor_b} (1=clean, 0=blocked), sanitization status {factor_c} (0=clean, 1=sanitized, 2=rejected). EU AI Act Art. 15(4) requires resilience against unauthorized manipulation. NIST 800-53 SI-10 requires information input validation. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-RAG.1 | AI | Context Retrieval Provenance RAG context retrieval is {verdict_word}witnessed: {factor_a} chunks retrieved, corpus identified = {factor_b} (1=yes, 0=anonymous). EU AI Act Art. 12(2)(a) requires logging the reference database used by AI systems. NIST AI RMF MAP 3.5 requires documentation of data provenance and lineage. Threshold: 0.94Measured: 6Delta: 2 | — | PASS | 7/13/2026 | Verify → |
| AI-SKILL.1 | AI | Skill Manifest Attestation Skill manifest is {verdict_word}attested: {factor_a} skills loaded, manifest verified = {factor_b} (1=match, 0=mismatch). EU AI Act Art. 12(2)(b) requires version tracking of AI system capabilities. NIST AI RMF GOVERN 1.7 requires capability documentation. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-HW.1 | AI | Hardware Runtime Attestation Accelerator hardware is {verdict_word}attested: {factor_a} GPUs detected, all healthy = {factor_b} (1=yes, 0=degraded/none), topology code {factor_c} (0=single, 1=multi-GPU/DGX, 2=multi-node/NVL72, 3=unknown). EU AI Act Art. 15 requires documenting the technical means of the AI system. NIST 800-53 SI-7 requires integrity verification of execution environments. Threshold: 8Measured: 1Delta: 1 | — | PASS | 7/13/2026 | Verify → |
| AI-TRUST.1 | AI | Trust Verification Agent trust verification is {verdict_word}granted: trust level {factor_c} (0=denied, 1=basic, 2=verified, 3=attested, 4=sovereign). Counterpart agent's compliance posture was verified before interaction. EU AI Act Art. 25 requires documented responsibilities along the AI value chain. NIST 800-53 AC-4 requires information flow enforcement between systems. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-CHAIN.1 | AI | Multi-Agent Chain Handoff Multi-agent chain handoff is {verdict_word}recorded: chain depth = {factor_a}, cycle bound = {factor_b} (1=yes, 0=no), handoff accepted = {factor_c} (1=yes, 0=rejected). EU AI Act Art. 9 requires risk management across system interactions. NIST AI RMF GOVERN 1.3 requires accountability for multi-component systems. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-SAFE.1 | AI | Safe State Transition Safe state transition is {verdict_word}recorded: trigger code {factor_a} (0=manual, 1=threshold, 2=chain_break, 3=policy, 4=external), {factor_b} actions suspended, recovery available = {factor_c} (1=yes, 0=no). EU AI Act Art. 9(4)(b) requires stop mechanisms and safe state transitions. Art. 14(4)(e) requires human override capability. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-CHR.1 | AI | Agent Charter Registration Agent charter is {verdict_word}registered: {factor_a} capabilities declared, {factor_b} constraints declared, charter hash present = {factor_c} (1=yes, 0=no). EU AI Act Art. 13 requires documentation of system capabilities and limitations. NIST AI RMF GOVERN 1.7 requires transparency of AI system design. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-VIO.1 | AI | Policy Violation Record Policy violation is {verdict_word}recorded: violation type code {factor_a} (0=guardrail, 1=access, 2=scope, 3=policy, 4=safety, 5=other), severity = {factor_b} (1=low, 2=medium, 3=high, 4=critical), auto-remediated = {factor_c} (1=yes, 0=escalated). EU AI Act Art. 9 requires risk management. NIST AI RMF MANAGE 4.1 requires violation tracking and response. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-ENV.1 | AI | Runtime Environment Attestation Runtime environment is {verdict_word}attested: environment hash present = {factor_a} (1=yes, 0=no), container isolated = {factor_b} (1=yes, 0=no), runtime type code {factor_c} (0=bare_metal, 1=vm, 2=container, 3=serverless, 4=edge). EU AI Act Art. 11 requires technical documentation of deployment environment. NIST AI RMF GOVERN 1.2. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-MARK.1 | AI | Content Provenance Marking Content provenance marking is {verdict_word}recorded: {factor_a} content items marked, C2PA/watermark metadata attached = {factor_b} (1=yes, 0=no), content type code {factor_c} (0=text, 1=image, 2=audio, 3=video, 4=multimodal, 5=code, 6=structured). EU AI Act Art. 50(2) requires AI-generated content to be marked in a machine-readable format. GPAI Code of Practice requires transparency labelling. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-SBOM.1 | AI | AI Bill of Materials AI bill of materials is {verdict_word}documented: {factor_a} total components inventoried, {factor_b} of 7 G7 clusters documented, format code {factor_c} (0=cyclonedx, 1=spdx, 2=custom, 3=unknown). G7/CISA SBOM for AI Minimum Elements (May 2026) requires comprehensive component inventory. EU AI Act Art. 11 + Annex IV requires technical documentation of AI system composition. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-CONSENT.1 | AI | Data Subject Consent Data subject consent is {verdict_word}documented: {factor_a} subjects covered, legal basis code {factor_b} (0=consent, 1=contract, 2=legal_obligation, 3=vital_interest, 4=public_task, 5=legitimate_interest), withdrawal available = {factor_c} (1=yes, 0=no). GDPR Art. 6/7 requires documented lawful basis for processing. EU AI Act Art. 10 requires data governance including lawful basis documentation. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-DRIFT.1 | AI | Model Drift Detection Model drift is {verdict_word}detected: {factor_a} metrics evaluated, {factor_b} drifted, drift type code {factor_c} (0=data, 1=concept, 2=prediction, 3=feature, 4=label, 5=prior_probability). EU AI Act Art. 9(2)(b) requires continuous risk estimation including emerging risks during operation. NIST AI RMF MEASURE 2.6 requires measurement of AI system trustworthiness over time. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-AUDIT.1 | AI | Audit Log Integrity Audit log integrity is {verdict_word}verified: {factor_a} entries checked, integrity verified = {factor_b} (1=yes, 0=no), log format code {factor_c} (0=jsonl, 1=syslog, 2=otel, 3=custom). EU AI Act Art. 12 requires automatic recording of events with traceability. GDPR Art. 30 requires records of processing activities. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-TRANS.1 | AI | Transparency Disclosure Transparency disclosure is {verdict_word}recorded: {factor_a} disclosures made, disclosure type code {factor_b} (0=ai_usage, 1=data_processing, 2=automated_decision, 3=profiling, 4=capability_limitation), recipient type code {factor_c} (0=deployer, 1=end_user, 2=data_subject, 3=authority). EU AI Act Art. 13 requires transparency. GDPR Art. 13/14 requires information about automated processing. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-WATERMARK.1 | AI | Watermark Verification Watermark verification is {verdict_word}recorded: {factor_a} items checked, {factor_b} watermarks detected, detection method code {factor_c} (0=c2pa_verify, 1=synthid_check, 2=metadata_scan, 3=spectral_analysis, 4=classifier). EU AI Act Art. 50(2) requires machine-readable provenance that is detectable. GPAI Code of Practice requires transparency labelling. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-DPIA.1 | AI | Data Protection Impact Assessment Data protection impact assessment is {verdict_word}recorded: {factor_a} risks identified, {factor_b} mitigated, processing type code {factor_c} (0=profiling, 1=automated_decision, 2=large_scale_monitoring, 3=sensitive_data, 4=combined). GDPR Art. 35 requires DPIA for high-risk processing. EU AI Act Art. 27 requires fundamental rights impact assessment. Threshold: 1Measured: 1 | — | PASS | 6/10/2026 | Verify → |
| AI-INF.1 | AI | Inference Provenance — Prompt/Response Hash Capture Inference provenance hashing is {verdict_word}active. EU AI Act Art. 12(1) requires automatic logging of all periods of use of high-risk AI systems. NIST AI RMF MEASURE 2.5 requires measurement of AI system trustworthiness. Hash Required: 1Hashes Present: 1 | — | PASS | 4/20/2026 | Verify → |
| AI-INF.2 | AI | Inference Latency — Response Time Within Threshold Inference latency was {factor_b}ms against a {factor_a}ms threshold. EU AI Act Art. 15(3) requires AI systems to perform consistently. NIST AI RMF MEASURE 2.6 requires performance monitoring. Latency outside bounds may indicate model swaps or resource exhaustion. Latency Limit (ms): 1Actual Latency (ms): 1 | — | PASS | 4/20/2026 | Verify → |
| AI-MDL.1 | AI | Model Weight Integrity — Deployed Hash Matches Approved Model identity verification {verdict_word}confirmed. EU AI Act Art. 9(4)(a) requires identifying and analysing known and foreseeable risks including model tampering. NIST AI RMF GOVERN 1.1 requires model lifecycle governance. Hash Required: 1Hash Present: 1 | — | PASS | 4/20/2026 | Verify → |
| AI-INF.3 | AI | Inference Volume - Hourly Rate Governance Inference volume was {factor_b} against a {factor_a} hourly limit. EU AI Act Art. 12(1) requires automatic logging covering the period of each use. NIST AI RMF GOVERN 2.1 requires accountability structures. Volume Limit: 1Actual Volume: 1Context: 1 | — | PASS | 4/10/2026 | Verify → |
| AI-MDL.3 | AI | Model Drift Detection Model drift score is {factor_b} against a threshold of {factor_a}. EU AI Act Art. 72(1) requires post-market monitoring to identify risks emerging after deployment. NIST AI RMF MEASURE 2.6 requires measurement of behavioral changes. Drift Tolerance (%): 1Measured Drift (%): 1Context: 1 | — | PASS | 4/9/2026 | Verify → |
| AI-HITL.1 | AI | Human Review Completion Human review of AI decision is {verdict_word}completed. EU AI Act Art. 14(1) requires high-risk AI systems to be designed so they can be effectively overseen by natural persons. NIST AI RMF GOVERN 1.1 requires human oversight governance. Review Required: 1Review Completed: 1Context: 1 | — | PASS | 4/12/2026 | Verify → |
| AI-3.2 | AI | AI Model Inventory Attestation Required: 1Attested: 1Context: 1 CCI-000366Must maintain AI model inventory Assessment Objectives (800-53A) PARTIALTEST+EXAMINEan inventory of system components that accurately reflects the system is developed and documented; PARTIALTEST+EXAMINEan inventory of system components that includes all components within the system is developed and documented; PARTIALTEST+EXAMINEan inventory of system components that does not include duplicate accounting of components or components assigned to any other system is developed and documented; PARTIALTEST+EXAMINEsystem components are assigned to a system; PARTIALTEST+EXAMINEan inventory of system components that is at the level of granularity deemed necessary for tracking and reporting is developed and documented; PARTIALTEST+EXAMINEan inventory of system components that includes [ORGANIZATION-DEFINED] is developed and documented; PARTIALTEST+EXAMINEthe system component inventory is reviewed and updated [ORGANIZATION-DEFINED]. PARTIALTEST+EXAMINEthe inventory of system components is updated as part of component installations; PARTIALTEST+EXAMINEthe inventory of system components is updated as part of component removals; PARTIALTEST+EXAMINEthe inventory of system components is updated as part of system updates. | — | PASS | 4/11/2026 | Verify → |
Loading findings...
Paste or upload the developer's .swt3-gate.yml file to evaluate their governance policy against the live compliance ledger.
Loading requests...
Loading interviews...
Same seed + same population = same sample. Reproducible for peer review.
Open
11
Overdue
7
Closed
66
| Procedure | Severity | Status | Days Open | Milestone |
|---|---|---|---|---|
| AI-GRD.1 | CAT II | OPEN | 81d | 9/11/2026 |
| AI-TOOL.1 | — | OPEN | 81d | 9/11/2026 |
| AI-EMRG.1 | — | OPEN | 81d | 9/11/2026 |
| AI-DRIFT.2 | — |
Models Witnessed
14
Total Inferences
189
Pass Rate
57%
Complete inventory of AI agents witnessed in this system. EU AI Act Articles 13 (Transparency) and 14 (Human Oversight) require disclosure of agent identity, capabilities, and operational boundaries.
Agents
20
Models
14
Tools Invoked
8
Violations
6
| Agent | Models | Inferences | Pass Rate | Clearing | Violations | Active Period |
|---|---|---|---|---|---|---|
▶ — | 127 | 89% | L0 Analytics | 0 | Apr 6 — Jun 10 | |
▶ — | claude-haiku-4-5 | 35 | 51% | L0 Analytics | 0 | Mar 31 — Apr 20 |
▶ — | gpt-4o | 35 | 74% | L0 Analytics | 0 | Apr 2 — Jun 10 |
▶ — | gpt-4o-mini | 28 | 57% | L0 Analytics | 0 | Mar 31 — Apr 20 |
▶ — | claude-sonnet-4-6 | 24 | 58% | L0 Analytics | 0 | Mar 31 — Apr 20 |
▶ drift-watchdog | claude-sonnet-4-20250514fraud-model-v7fraud-model-v6 | 14 | 36% | L1 Standard | 0 | Jul 13 — Jul 13 |
▶ — | demo-compliance-model-v1 | 12 | 83% | L0 Analytics | 0 | Apr 8 — Apr 15 |
▶ — | claude-3.5-sonnet | 7 | 100% | L0 Analytics | 0 | Jun 10 — Jun 10 |
▶ — | claude-sonnet-4-20250514 | 7 | 0% | L0 Analytics | 0 | Jul 13 — Jul 13 |
▶ rag-assistant | gpt-4o | 4 | 100% | L1 Standard | 0 | Jun 17 — Jul 13 |
▶ data-analyst | gpt-4o | 4 | 0% | L2 Sensitive | 4 | Jun 17 — Jul 13 |
▶ safety-monitor-v3 | gpt-4o-2025-04-16valve-controller-v2 | 4 | 50% | L1 Standard | 0 | Jul 13 — Jul 13 |
▶ doc-processor | gpt-4o-mini | 3 | 100% | L2 Sensitive | 0 | Jun 17 — Jul 13 |
▶ — | fraud-model-v7 | 3 | 0% | L0 Analytics | 0 | Jul 13 — Jul 13 |
▶ — | claude-opus-4-6 | 2 | 0% | L0 Analytics | 0 | Apr 19 — Apr 19 |
▶ support-bot | claude-sonnet-4-6 | 2 | 0% | L1 Standard | 2 | Jun 17 — Jul 13 |
▶ — | valve-controller-v2 | 2 | 0% | L0 Analytics | 0 | Jul 13 — Jul 13 |
▶ gpu-node-prod-01 | hw-nvidia-multi-gpu | 1 | 100% | L1 Standard | 0 | Jul 13 — Jul 13 |
▶ assessment-runner | gpt-4o-mini-2025-04-16 | 1 | 100% | L1 Standard | 0 | Jul 13 — Jul 13 |
▶ fraud-orchestrator | gpt-4o | 1 | 100% | L1 Standard | 0 | Jul 13 — Jul 13 |
Loading monitoring data...
0 of 1 nodes reporting. 1 node(s) stale. Review required.
EU AI Act Article 15(4) / Annex IV 2(b) · NIST AI RMF MANAGE 1.3
Nodes Reporting
0/1
Attestations
1
Coverage
0%
Silicon Vendors
1
| Node Identity | Silicon | Accelerators | Topology | Attestations | Status |
|---|---|---|---|---|---|
| gpu-node-prod-01 | NVIDIA | 8 | multi-gpu | 1 | stale |
Multi-step governance decisions with cryptographic proof at every stage. Each lifecycle tracks a complete governance sequence from initiation to resolution.
Lifecycles
7
Active
3
Resolved
4
Escalated
0
Multi-agent decision lineage with cryptographic proof at every handoff. Hover nodes for human-readable context. Click to drill down.
Chains
5
Total Nodes
10
Agents
3
Violations
2
Be among the first firms to offer SWT3 compliance assessment. Register your interest and we'll notify you when the program opens.
Get your own audit portal with cryptographic evidence, Annex IV checklist, and assessment tools. Free tier includes 90-day anchor retention and up to 1,000 inferences.
Every finding in this report is backed by a cryptographic SWT3 Witness Anchor. Anchors can be independently verified at any time using the public verification endpoint.
Axiom is a neutral evidence platform. It does not grant certifications, issue conformity assessments, or replace the professional judgment of a qualified auditor, Notified Body, or Authorizing Official. Scores, gate decisions, and recommended outcomes are computed deterministically from machine-gathered evidence and are provided for informational purposes only. The final authority on conformity or compliance rests with the designated assessment body and their professional standards.
SWT3 Protocol, Witness Anchor format, UCT Registry, and AI Witness clearing methodology are Patent Pending. © 2026 Tenable Nova LLC. All rights reserved.
| OPEN |
| 81d |
| 9/11/2026 |
| AI-GOV.3 | — | OPEN | 171d | 6/13/2026 (overdue) |
| AI-EXPL.2 | — | OPEN | 172d | 6/12/2026 (overdue) |
| AI-FAIR.2 | — | OPEN | 173d | 6/12/2026 (overdue) |
| AI-GRD.2 | — | OPEN | 174d | 6/11/2026 (overdue) |
| AI-EXPL.1 | — | OPEN | 175d | 6/9/2026 (overdue) |
| AI-4.2 | — | OPEN | 176d | 6/9/2026 (overdue) |
| AI-HITL.3 | — | OPEN | 177d | 6/7/2026 (overdue) |