Evidence to support your assessment · not a certification
Regulatory evidence packs for AI agents
One export per framework: every clause where the records Agent Trust Cloud keeps are relevant, and for each, what was found in the period you choose — decisions with their inputs, refusals, human approvals, kill-switch records, behaviour findings, safety test reports, spend controls and incidents. Clauses that need evidence Agent Trust Cloud does not hold are marked as outside its scope rather than left for someone to assume.
7 packs
- EU AI Act — 7 clauses, from Regulation (EU) 2024/1689 on EUR-Lex
- ISO/IEC 42001 — 9 clauses, from ISO/IEC 42001:2023 (iso.org)
- NIST AI RMF — 6 clauses, from NIST AI 100-1
- SOC 2 — 6 clauses, from AICPA 2017 Trust Services Criteria (revised points of focus 2022)
- DORA — 7 clauses, from Regulation (EU) 2022/2554 on EUR-Lex
- HIPAA Security Rule — 7 clauses, from 45 CFR Part 164 Subpart C (eCFR)
- Insurance-ready report — 8 questions
This pack lists records kept by Agent Trust Cloud that are relevant to the clauses shown. It is evidence to support your own assessment. It is not a compliance determination, a certification, an audit opinion or legal advice, and the clause mapping is Agent Trust Cloud’s reading of each text, which your assessor may read differently.
A pack from the worked example
Built in your browser from the worked estate in the console, by the same code a workspace export runs.
Records found for 6 of 7; none in the period for 0; 1 outside what Agent Trust Cloud records.
| Clause | Status | Records |
|---|---|---|
| Art. 4 AI literacy Staff dealing with AI systems have sufficient AI literacy. | Outside what Agent Trust Cloud records | — |
| Art. 12 Record-keeping High-risk systems allow automatic recording of events (logs) over their lifetime. | Records found | Append-only evidence ledger: 96; Per-action decision records: 21 |
| Art. 14 Human oversight High-risk systems can be effectively overseen by people, including to intervene or stop them. | Records found | Human approvals with approver: 1; Kill switch and quarantine records: 1 |
| Art. 26(2) Deployer: human oversight assigned Deployers assign oversight to people with the competence, training and authority to do it. | Records found | Named accountable owners: 5; Human approvals with approver: 1 |
| Art. 26(5) Deployer: monitoring Deployers monitor operation and act on risks, including suspending use. | Records found | Behaviour anomaly findings: 0; Kill switch and quarantine records: 1; Refused actions: 7 |
| Art. 26(6) Deployer: keep logs Deployers keep automatically generated logs under their control for at least six months. | Records found | Append-only evidence ledger: 96; Per-action decision records: 21 |
| Art. 73 Reporting serious incidents Serious incidents are reported to authorities. | Records found | Incident dossiers: 1 |
Insurance-ready AI evidence report
Cyber and AI liability renewal questionnaires ask the same eight things: which agents you run, who owns them, what limits them, whether a person approves high-risk actions, whether you can stop one, whether they are tested before release, what went wrong, and whether you can prove it. The insurance report answers each from your records.
HIPAA
The HIPAA Security Rule pack maps the technical safeguards in 45 CFR 164.312 to agent records. Agent Trust Cloud does not currently process PHI under a BAA; see HIPAA and AI agents for how to use it without sending PHI.