Evidence work in progress. No compliance outcome claimed.
AgentGuard is developing local action-control and evidence contracts. The current public artifacts do not establish conformity with APRA CPS 230, the EU AI Act, or ISO/IEC 42001. They also do not establish acceptance by any regulator, board, assessor, or independent certifier.
What the public artifacts do not prove.
Repository source can show exact contracts, package manifests, compatibility adapters, and tests. It cannot by itself establish a deployed control, complete event coverage, non-bypassability, or a third party’s acceptance.
- No regulator or assessor acceptance claim
- No certification or legal-conformity claim
- No complete runtime-coverage claim
- No production or fleet claim
- No public performance or reliability claim
- No human-approval workflow in V1
- No public evidence-pack approval
Contracts first. Claims only after proof.
Bind the artifact
Identify the exact package, version, topology, policy, and action being evaluated.
Exercise the boundary
Test direct, alternate, disabled-hook, forged, replayed, and failure paths against an owned canary.
Publish the limits
Report samples, failures, exclusions, provenance, and host-compromise limits with the result.
Current public status package contracts available for inspection compatibility adapters available for inspection broker topology proof pending production evidence not claimed compliance outcome not claimed third-party acceptance not claimed
A source to assess, not an outcome to assume.
The official implementation timeline is available from the EU AI Act Service Desk for teams determining which obligations apply. AgentGuard does not claim that its current packages satisfy those obligations or replace legal, risk, or conformity assessment.
- Risk management
- Art. 9
- Data governance
- Art. 10
- Technical documentation
- Art. 11
- Record keeping
- Art. 12
- Transparency
- Art. 13
- Human oversight
- Art. 14
No certification claim.
ISO/IEC 42001 defines requirements for an AI management system. AgentGuard’s current repository is not a certification, does not establish conformity, and does not make an assessor’s decision for an operator.
Technical operators testing a narrow boundary.
Agent operators
Teams that can identify a consequential action and remove the raw capability from the calling agent.
Security engineers
Reviewers who can test identity separation, bypass paths, permit use, failure semantics, and local evidence.
Risk owners
People who need limitations and evidence provenance stated before deciding whether a control fits their environment.