Assurance status

Evidence work in progress. No compliance outcome claimed.

AgentGuard is developing local action-control and evidence contracts. The current public artifacts do not establish conformity with APRA CPS 230, the EU AI Act, or ISO/IEC 42001. They also do not establish acceptance by any regulator, board, assessor, or independent certifier.

Current boundary

What the public artifacts do not prove.

Repository source can show exact contracts, package manifests, compatibility adapters, and tests. It cannot by itself establish a deployed control, complete event coverage, non-bypassability, or a third party’s acceptance.

  • No regulator or assessor acceptance claim
  • No certification or legal-conformity claim
  • No complete runtime-coverage claim
  • No production or fleet claim
  • No public performance or reliability claim
  • No human-approval workflow in V1
  • No public evidence-pack approval
Review checklist
01 Exact artifact and version
02 Capability owner and caller
03 Policy authority
04 Decision and permit scope
05 Dispatch outcome scope
06 Failure semantics
07 Replay and freshness
08 Rollback state
09 Evidence provenance
10 Stated limitations
Evidence path

Contracts first. Claims only after proof.

/01

Bind the artifact

Identify the exact package, version, topology, policy, and action being evaluated.

/02

Exercise the boundary

Test direct, alternate, disabled-hook, forged, replayed, and failure paths against an owned canary.

/03

Publish the limits

Report samples, failures, exclusions, provenance, and host-compromise limits with the result.

terminal
Current public status

package contracts       available for inspection
compatibility adapters  available for inspection
broker topology proof   pending
production evidence     not claimed
compliance outcome      not claimed
third-party acceptance  not claimed
EU AI Act

A source to assess, not an outcome to assume.

The official implementation timeline is available from the EU AI Act Service Desk for teams determining which obligations apply. AgentGuard does not claim that its current packages satisfy those obligations or replace legal, risk, or conformity assessment.

Risk management
Art. 9
Data governance
Art. 10
Technical documentation
Art. 11
Record keeping
Art. 12
Transparency
Art. 13
Human oversight
Art. 14
ISO/IEC 42001

No certification claim.

ISO/IEC 42001 defines requirements for an AI management system. AgentGuard’s current repository is not a certification, does not establish conformity, and does not make an assessor’s decision for an operator.

Who should evaluate it

Technical operators testing a narrow boundary.

Agent operators

Teams that can identify a consequential action and remove the raw capability from the calling agent.

Security engineers

Reviewers who can test identity separation, bypass paths, permit use, failure semantics, and local evidence.

Risk owners

People who need limitations and evidence provenance stated before deciding whether a control fits their environment.

Inspect the artifacts before assigning assurance.