EU AI Act Annex III: 2 December 2027. See what it requires →

Compliance as the output of your system

Map signed technical evidence to control objectives—not compliance claims.

8 frameworks

Pre-mapped controls

12 articles

EU AI Act mapping scope

1 click

Generated evidence pack

Not certification

Evidence supports your audit

One evidence stream. Multiple control mappings.

SOC 2 Type II

CC7.1 · CC7.2 · CC7.3 · CC7.4 · CC7.5CC6.1 · CC6.6

Maps signed decision evidence and supported enforcement boundaries to selected CC7 and CC6 criteria.

EU AI Act

Art. 5 · 9 · 12 · 14 · 17 · 18 · 19 · 20 · 26 · 72 · 73 · 86

Maps technical controls and evidence to 12 relevant articles. Applicability and the risk-management system remain customer and counsel determinations.

GDPR

Art. 25Art. 32Art. 33

PII detection and configured block/redact behavior can support privacy controls on supported routes.

ISO 42001

AI management system controls

Maps policy, approval, and decision-evidence capabilities to selected AI management controls.

NIST AI RMF

Govern · Map · Measure · Manage

Maps relevant policy and evidence capabilities across Govern, Map, Measure, and Manage.

OWASP LLM Top 10

LLM01 · LLM02 · LLM06

Known-pattern scanning, configured output policy, and PII controls can contribute evidence on supported routes.

HIPAA

PHI detection · configured block/redact

Configured PII handling can support PHI controls on supported scanning routes. Obsvr does not make a deployment HIPAA compliant.

CCPA

PII handling · Right to deletion

Configured PII handling and deletion workflows can support customer privacy programs.

Not a sprint before the audit

01

Integrate once

Wrap the client explicitly, or use the Node import hook for supported provider modules.

02

Controls run continuously

Supported enforcing routes run policy before dispatch; tested tool gates verify zero denied executions, while tracing-only callbacks and sampled clean events remain identified separately.

03

Evidence generates itself

Generate a ZIP containing control mappings, hashes, integrity material, incident history, operating data, and an auditor guide.

Generate the evidence package on demand

audit-2026-05-01.zip · SHA256 verifiedGenerated
README_FOR_AUDITORS.mdPlain-English guide - what each folder proves and how to run verification
MANIFEST.jsonSHA-256 hash of every file in the package - tampering is immediately detectable
summary.jsonMachine-readable summary: event counts, PII detections, incident counts, date range
00_scope_summary.txtProse narrative of controls active, event volume, and PII detections over the period
01_scope_and_manifest/controls-mapping.json + scope-summary.json, pre-mapped to SOC 2 (CC7/CC6.1/CC6.6), EU AI Act, ISO 42001, NIST AI RMF, and the OWASP LLM Top 10
02_integrity_and_merkle/daily-roots.csv, verify_merkle.py, verification.log, ANCHORING_STATUS.md
03_storage_config/Live S3 Object Lock and retention settings; governance mode permits bypass by specifically authorized AWS principals
04_access_control/IAM role mapping, bucket policy, access summary, recent access sample
05_incidents_and_alerts/incidents.json, incident-response.md with root cause + MTTR, detection-rules.md
06_samples_and_exports/sample-hashed-events.csv, events-summary.csv, logging-scope.md
07_operating_effectiveness/daily-uptime.csv, monthly-summary.csv with p50/p90/p99 latency and error rates
08_tools_and_vendors/mcp-tool-inventory.json/.md - the MCP tools exposed to the model at discovery with per-tool poisoning flags (point-in-time), cited from ISO 42001 A.9.4 and OWASP LLM06
09_model_provenance/model-timeline.json/.md - which model + policy version was live over time, each segment sealed by an anchored root (EU AI Act Art. 12 + Art. 86)

Questions auditors actually ask

"Can you prove your logs haven't been tampered with?"

The SDK verifier checks retained client-chain integrity and reports signed gap markers when present. The evidence pack adds daily Merkle roots, external anchors, and offline verification material. Deployment coverage and abrupt process loss remain separate questions rather than being inferred from a valid chain.

"Show me your control mapping to SOC 2 CC7."

The generated control mapping links relevant Obsvr evidence to selected CC7 and CC6 criteria. It supports the auditor's assessment; it does not establish your full control environment by itself.

"What happened during your last incident and how long did it take to resolve?"

Obsvr events can contribute timestamps, verdicts, reasons, and integrity evidence. Your incident process remains responsible for containment, root cause, notifications, and the final narrative.

"How do you demonstrate EU AI Act Article 18 documentation requirements?"

The mapping covers 12 relevant articles and identifies where Obsvr can contribute technical evidence. Applicability, retention, risk management, and legal compliance remain customer responsibilities.

Article-by-article mapping. Not certification.

EU AI Act

12 Articles Mapped

Each row identifies evidence Obsvr can contribute. Your legal, risk, and operating controls remain part of compliance.

Annex III: 2 Dec 2027 · regulated products: 2 Aug 2028

Control mapping
ArticleRequirementObsvr contributionStatus
Art. 5Prohibited AI PracticesPolicy rules can block configured prohibited actions on supported enforcing routesMapped
Art. 9Risk Management SystemCustomer-managed governance - obsvr supplies the running controls and signed evidence that feed itCustomer-managed
Art. 12Record-Keeping & LoggingSigned records for emitted calls and agent activity on supported routesMapped
Art. 14Human Oversight ControlsPolicy-triggered approval and escalation controlsMapped
Art. 17Quality Management SystemPolicy controls with evidence export for QMS documentationMapped
Art. 18Documentation KeepingHosted beta export can organize signed records and hash manifests; retention is customer-configuredMapped
Art. 19Automatically Generated LogsTamper-evident emitted records with configurable retention and explicit loss accountingMapped
Art. 20Post-Market MonitoringEmitted-event monitoring and policy telemetry can support post-market reviewMapped
Art. 26Deployer ObligationsPrincipal-aware policy controls and signed decision evidenceMapped
Art. 72Incident ReportingPolicy events and hooks can feed customer incident workflowsMapped
Art. 73Serious Incident ReportingEscalation hooks and signed evidence can support incident documentationMapped
Art. 86Right to ExplanationVersioned reason codes and signed records for emitted governed decisionsMapped