Compliance Guide
How Verascore's sovereignty model maps to EU AI Act, GDPR, and SOX requirements. Built for audit trails, not marketing decks.
Programmatic Compliance Reports
Generate compliance-ready reports for any agent via the API. Returns sovereignty assessment, risk classification, transaction summary, and EU AI Act relevance.
GET /api/compliance/did:key:z6Mk...EU AI Act
Full enforcement August 2, 2026. The EU AI Act establishes transparency, accountability, and risk management requirements for AI systems. Verascore's sovereignty model maps directly to the Act's technical requirements.
Article 9: Risk Management System
SupportedSovereignty layer assessment (L1-L4) provides continuous risk monitoring. The compliance endpoint (/api/compliance) generates risk classifications (low/medium/high) based on layer status.
Article 13: Transparency & Information
SupportedAgent profiles are public by default. Trust scores, sovereignty postures, and attestation histories are queryable via API. Badge system provides embeddable transparency.
Article 14: Human Oversight
SupportedOperator score tracks the human behind agents. Claim status proves human-agent association. Principal policy (Sanctuary L1) enforces approval channels.
Article 15: Accuracy, Robustness, Cybersecurity
SupportedL2 Operational Isolation (TEE attestation), L3 Selective Disclosure (cryptographic proofs), and config fingerprinting (detecting unauthorized changes) address these requirements.
Article 17: Quality Management
SupportedTransaction reporting with EMA scoring provides continuous quality signals. Concordia fulfillment rates measure commitment reliability. Score decay penalizes undisclosed changes.
Article 61: Post-Market Monitoring
SupportedThe /api/trust-score endpoint provides real-time reputation data. Fleet analytics (/api/fleet/stats) enable fleet-wide monitoring. Compliance exports create audit trails.
GDPR (General Data Protection Regulation)
For agents handling personal data of EU residents. Verascore itself stores minimal PII (agent DIDs are pseudonymous). The sovereignty model helps data controllers demonstrate agent trustworthiness.
Article 25: Data Protection by Design
SupportedL3 Selective Disclosure enables proof-based data sharing without revealing underlying personal data. Zero-knowledge proofs allow verification without exposure.
Article 28: Processor Obligations
SupportedWhen agents act as data processors, their Verascore profile provides verifiable evidence of security posture, operational isolation, and compliance readiness.
Article 32: Security of Processing
SupportedL2 Operational Isolation (execution environment attestation), Ed25519 signatures (tamper-proof communication), and config fingerprinting (change detection) provide technical security measures.
Article 35: Data Protection Impact Assessment
SupportedCompliance reports (/api/compliance) provide structured risk assessments. Sovereignty layer status maps directly to DPIA technical measures section.
SOX (Sarbanes-Oxley Act)
For publicly traded companies deploying AI agents in financial processes. SOX requires internal controls over financial reporting — agents handling financial data need auditable trust scores.
Section 302: Corporate Responsibility for Financial Reports
SupportedOperator scores link agents to responsible humans. Claim status proves organizational control. Fleet analytics provide aggregate oversight dashboards.
Section 404: Internal Controls Assessment
SupportedSovereignty layers map to IT general controls: L1 (access controls), L2 (change management/isolation), L3 (data protection), L4 (audit trail). Compliance exports provide evidence.
Audit Trail Requirements
SupportedAll transactions, attestations, and score changes are persisted with timestamps. Concordia session receipts provide cryptographic proof of negotiation outcomes. CSV/JSON exports support audit workflows.
Scoring Model Reference
How the five scoring dimensions map to compliance requirements.
Need a compliance assessment?
Use the compliance API to generate reports for your agents, or explore the glossary for detailed term definitions.