One record, read against thirteen frameworks. Each card below says what the framework actually requires, what is in force today and what is not, and which fields of the record bear on it. Most readers need three or four of these, so pick your sector. ← Back to home
Showing all thirteen. Nothing here is hidden by a filter, only set aside.
No agentic-AI rule in force
OCC model risk guidance: agentic AI out of scope
Bulletin 2026-13 (MRM Revised Guidance, Apr 2026) · Spring 2026 Semiannual Risk Perspective
OCC Bulletin 2026-13 revised interagency model risk management guidance but explicitly excluded generative and agentic AI from scope, on the basis that these technologies are "novel and rapidly evolving." The OCC's Spring 2026 Semiannual Risk Perspective then named agentic AI as a supervisory priority. Banks operate under both: a formal framework that excludes their agents, and active examination focus on those same agents. The agencies have signaled a forthcoming RFI specific to AI.
A PlainReal™ record closes the gap. Per-decision evidence: policy_version_hash, principal_identity, signing_attestation, model_version_hash, registry_validation_status. Verifiable using only the published public key.
Addresses:
model_version_hash · policy_version_hash · signing_attestation · registry_validation_status · principal_identityRead Bulletin 2026-13 ↗
Proposed rule · comment period closed June 9, 2026
FinCEN AML/CFT Program NPRM
Docket FINCEN-2026-0034 · RIN 1506-AB72 · Proposed effectiveness standard for AML/CFT programs
FinCEN has proposed replacing the process-based AML/CFT program standard with an effectiveness-based one. It is a proposed rule, not a final one, and it does not name cryptographic evidence or single out AI-driven decisions. What it changes is the burden: an effectiveness standard is argued with evidence, and a log your own team can edit is weak support for a claim that your program worked.
Published · May 26, 2026
PlainReal is on the federal record. We filed a public comment on this NPRM proposing the tamper-evident per-decision evidence standard the rule needs. Now live on regulations.gov, docket FINCEN-2026-0034.
Read the comment ↗
Addresses: principal_identity · policy_version_hash · tool_call_log · causality_chain_hash · execution_result
Active enforcement risk
NYDFS Part 500
AI systems for NY-licensed covered entities
Part 500 applies to NY-licensed covered entities and is a cybersecurity regulation. It does not name AI agent decisions or cryptographic evidence.
What a record gives you is an audit trail for a decision an examiner can check without taking your word for it.
Annex III deferred to 2 Dec 2027
EU AI Act Article 12
Automatic event logging for high-risk AI systems · US fintechs with EU customers are caught
Article 12 requires automatic event logging with traceability appropriate to the intended purpose. For high-risk decisions, tamper-evidence is what gives logs evidentiary weight in regulatory or judicial proceedings.
Auto-instrument mode records every LLM call made through the instrumented client, with zero code changes.
Deferred to 2 Dec 2027 · 10-year retention
EU AI Act Annex IV
Technical documentation under Article 11 · 10-year retention under Article 18
Annex IV defines the 9-section technical documentation that providers of high-risk AI systems must prepare under Article 11 and retain for ten years under Article 18. This is a provider obligation. If you build or substantially modify a high-risk system, you become a provider under the Act and carry it. The bundle covers system design, data governance, performance metrics, risk management, lifecycle changes, applied standards, and post-market monitoring.
Where per-decision evidence is relevant is post-market monitoring (Section 9): a tamper-evident record of how the deployed system actually decided over time. A PlainReal record supplies that decision-level evidence; it does not replace the broader technical file.
Addresses:
policy_version_hash · causality_chain_hash · model_version_hash · execution_result · signing_attestationRead Article 11 ↗
In force now
GDPR Article 22
Accountability for automated decisions affecting individuals
Article 22 governs automated decision-making affecting individuals and requires documented accountability.
A PlainReal record provides that documentation: which model, which policy, which input, which output. All signed and independently verifiable.
Addresses:
principal_identity · policy_version_hash · execution_resultRead Article 22 ↗
Criteria, not controls
SOC 2 CC6.1 and CC4.1, with NIST SP 800-53
Non-human identity authorization · Processing integrity · AU-10 non-repudiation · COSAiS agentic overlay
SOC 2 states criteria, not controls: an organisation defines its own controls and an auditor tests them against those criteria. Nothing here is a control PlainReal satisfies on your behalf. NIST SP 800-53 AU-10 addresses non-repudiation of principal actions.
A PlainReal record binds the acting principal into an Ed25519-signed artifact that cannot be altered or disavowed after the fact. The substrate signs; the principal does not, so the record proves what was recorded about the actor rather than that the actor personally signed anything. Whether that evidences your CC6.1 and CC4.1 controls is your auditor’s judgement.
The COSAiS project at NIST is developing SP 800-53 control overlays for autonomous agent systems.
Addresses:
AU-10 · authorization_token_id · execution_result · policy_version_hashRead SP 800-53 ↗
Active 2026 audit cycles
SOC 2 CC8.1 Change Management
AICPA Trust Services Criteria · change management
CC8.1 requires that every change to a production system be authorized and approved before deployment, with documented attribution to an accountable individual. Whether an AI decision record evidences a change-management criterion is a judgement for your auditor, not a claim we make for you. They want every model promotion traced back to a named approver. None of this is formally codified in the Trust Services Criteria. Auditors are mapping AI risk to CC8.1 against working interpretations.
SOC 2 expects privileged actions to be attributable to an accountable individual, not to an autonomous agent or a generic system account. A PlainReal record names the agent that acted and the policy version that authorized the action. The model version is recorded inline so attribution survives any future model swap. The same artifact maps to CC8.1 and to Annex IV documentation, with overlap into ISO 42001 clause 8.
Addresses:
principal_identity · policy_version_hash · model_version_hash · sdk_hash_layer · signing_attestationRead trust criteria ↗
In force February 2, 2026
FDA 21 CFR Part 820 (QMSR)
Quality Management System Regulation · ISO 13485:2016 incorporated by reference
FDA's amended Part 820 took effect February 2, 2026 as the Quality Management System Regulation (QMSR), incorporating ISO 13485:2016 by reference. The regulation requires risk-based decisions across the quality management system, with documented evidence supporting each one. For AI medical device software, FDA's separate AI/ML guidance adds two layers on top: Good Machine Learning Practice for development discipline, and predetermined change control plans for pre-authorized model updates.
For agentic AI in regulated healthcare workflows, the record provides per-decision evidence cryptographically signed at decision time and attributable to a specific agent under a specific policy version. Each artifact is independently verifiable using only the published public key.
Addresses:
model_version_hash · sdk_hash_layer · policy_version_hash · signing_attestation · principal_identityRead QMSR ↗
In force · Rule update expected 2026
HIPAA § 164.312(b)
Audit controls for AI agent access to electronic protected health information
The proposed 2025 Security Rule amendments would significantly strengthen audit logging requirements for AI agent interactions with ePHI. Under the proposed amendments, every agent decision touching patient data would require a record of who authorized it, what input it received, and what it produced. Mutable logs do not satisfy this requirement.
A PlainReal record captures the hash of inputs, not the inputs themselves, keeping PHI out of the artifact.
Worked example
An agent flags 12,000 patients for care-gap outreach. HHS OCR opens an investigation and asks for the audit trail: which decision identified each patient, what data it accessed, under which policy version, with what authorization. Logs that show the agent ran do not show what it was authorized to access, or whether the input was the one approved. A PlainReal record does.
In force · FDA regulated industries
21 CFR Part 11
FDA electronic records and audit trails for AI in drug development, clinical trials, and medical devices
Any AI system that creates or modifies GxP records must log which model version acted, on what input, producing what output, with a timestamp.
A PlainReal record captures all of this in a single signed artifact that addresses Part 11 audit trail requirements for AI-driven decisions in pharmaceutical and clinical contexts.
Addresses:
model_version_hash · input_hash · execution_result · created_atRead CFR Part 11 ↗
Effective Jan 1, 2027
Colorado ADMT Act (SB 26-189)
Colorado SB 26-189 · Automated decision-making technology · Notice and transparency
Colorado SB 26-189, signed May 14, 2026, replaces the original Colorado AI Act. It requires deployers of automated decision-making technology to give consumers notice when AI materially influences consequential decisions covering employment, housing, lending, healthcare, and legal services. Consumers have the right to appeal those decisions and to know what information the system used. The law takes effect January 1, 2027, with enforcement contingent on attorney general rulemaking. It is currently subject to a federal court challenge (xAI v. Weiser, with DOJ intervention) that could delay or narrow it.
A PlainReal record provides the per-decision evidence that supports consumer notice and appeal rights: what policy governed the decision, what input the model received, and what the outcome was. All fields are independently verifiable.
Addresses:
principal_identity · policy_version_hash · execution_result · causality_chain_hashRead SB 26-189 ↗
In effect June 2, 2026
White House EO 14409 · Section 4
EO "Promoting Advanced AI Innovation and Security" · June 2, 2026 · AI agent enforcement
Section 4 of the Executive Order directs the Attorney General to prioritize enforcement of federal criminal statutes against anyone who uses AI agents to unlawfully access data or information subsequently used for a criminal or unlawful purpose. No new criminal authority is created. The order sharpens enforcement of laws already on the books, including 18 U.S.C. 1028 (identity fraud), 1030 (computer fraud), and 1343 (wire fraud).
In any prosecution or defense involving an AI agent, both sides will need a tamper-evident, independently verifiable record of what the agent actually did: which identity authorized it, what actions it took, and what the causality chain was. That is what a PlainReal record is.
Addresses:
principal_identity · causality_chain_hash · evidence_tier · action_typeRead the EO ↗