Governance Workspace
What you must prove to deploy
Every requirement below maps to a real obligation under the EU AI Act, NIST AI RMF, US OMB M-24-10, ISO/IEC 42001, or Singapore IMDA. Owners must produce signed, portable evidence — not slide decks.
Thesis ·AGProtocol is the continuous verification and governance infrastructure layer institutions require before autonomous AI agents are allowed to operate inside procurement-sensitive and regulated environments.
Compliance score
● 16 passed● 5 in review● 1 action needed○ 3 available
Frameworks covered
EU AI Act
NIST AI RMF
OMB M-24-10
ISO/IEC 42001
IMDA Model AI Gov
Last full audit
8 days ago
Next quarterly: Aug 12, 2026
Owner & legal entity
Legal name: MunicipalAI Inc.
EIN: 12-3456789 · DUNS: 07-842-1199
Jurisdiction: Delaware, USA
DPO: dpo@municipalai.example
Data residency: EU (eu-central-1) · US (us-east-1) failover
eIDAS root: 0x8f1a...c4d2
EU AI Act DB ID: EU-AIAct-DB-2026-04419
Beneficial owners & coverage
- Andrei — Product / Governance / GTM50%
- Gabe — Infrastructure / Provenance50%
Insurance: Munich Re Specialty · AI-Liability 2026-A · $10M aggregate
Subprocessors: Cloudflare Workers, Supabase EU, Anthropic, OpenAI, Base L2 (Coinbase)
Incorporation docs: Delaware Cert. of Incorporation · Operating Agreement v3 · EIN Letter (IRS)
KYC verified
25 of 25
- Verified legal entity & beneficial ownersPassedOwner: LegalProvider is an identifiable legal entity with KYC'd beneficial owners ≥25%.EU AI Act · Art. 16 (Provider obligations)ISO/IEC 42001 · Cl. 5.1 LeadershipKYC packCert. of IncorporationUBO registerLast updated: 12 days ago
- EU authorised representativePassedOwner: LegalNon-EU providers appoint an EU-based authorised representative before placing on market.EU AI Act · Art. 22Mandate agreementRep contact on fileLast updated: 21 days ago
- Qualified electronic signature (eIDAS)PassedOwner: GabeAll declarations are signed with a QES tied to the legal entity.EU AI Act · Art. 47 (Declaration of conformity)eIDAS root certQES audit logLast updated: 3 days ago
- AI liability insurance in forcePassedOwner: LegalActive policy covering AI-caused harm with adequate aggregate.OMB M-24-10 · §5(c) Risk mgmt minimumPolicy declarationCarrier confirmationLast updated: 1 mo ago
- Risk classification with rationalePassedOwner: AndreiDocument why the system is high-risk (Annex III) or limited risk, with mitigations.EU AI Act · Art. 6 + Annex IIINIST AI RMF · MAP 1.1 / 5.1Risk classification memoAnnex III mappingLast updated: 5 days ago
- Risk management system (lifecycle)PassedOwner: AndreiA documented, iterative RMS covering identification, estimation, mitigation across the lifecycle.EU AI Act · Art. 9ISO/IEC 42001 · Cl. 6.1RMS policy v2.1Quarterly review minutesLast updated: 9 days ago
- Technical documentation (Annex IV)In reviewOwner: GabeComplete technical file: architecture, training data, metrics, known limitations.EU AI Act · Art. 11 + Annex IVSystem card v3Architecture diagramEval reportLast updated: Yesterday
- Fundamental Rights Impact AssessmentAction neededOwner: LegalPublic-sector deployers complete a FRIA before first use.EU AI Act · Art. 27FRIA reportStakeholder consultation logLast updated: Overdue · 4 days
- Data Protection Impact AssessmentPassedOwner: LegalGDPR Art. 35 DPIA covering automated decision-making and profiling.EU AI Act · Art. 26(9)DPIA v2DPO sign-offLast updated: 2 weeks ago
- Quality management systemIn reviewOwner: AndreiOperational QMS covering change-control, testing, release.EU AI Act · Art. 17ISO/IEC 42001 · Cl. 8QMS handbookChange-control log
- Training & validation data governancePassedOwner: GabeData is relevant, representative, free of obvious bias, lawfully sourced.EU AI Act · Art. 10NIST AI RMF · MAP 2.3DatasheetBias auditSource licensesLast updated: 11 days ago
- Content & model provenance (C2PA)PassedOwner: GabeOutputs carry a C2PA manifest tying them to a signed model + run.EU AI Act · Art. 50 (GPAI disclosure)IMDA Model AI Gov · ProvenanceC2PA manifestSigned model hashEAS attestationLast updated: Today
- GPAI upstream disclosureAvailableOwner: AndreiFoundation-model providers and versions disclosed; copyright policy honored.EU AI Act · Art. 53Upstream model registryCopyright policy
- Key management & rotationPassedOwner: SecuritySigning keys and API credentials are HSM-backed and rotated on schedule.ISO/IEC 42001 · A.7OMB M-24-10 · §5(b)KMS policyLast rotation logLast updated: 6 days ago
- Automatic event loggingPassedOwner: GabeAll inferences, tool calls and custody transitions are logged and tamper-evident.EU AI Act · Art. 12Append-only logDAG root anchorLast updated: Today
- Effective human oversightPassedOwner: AndreiHumans can interpret outputs, override, and stop the agent at any time.EU AI Act · Art. 14NIST AI RMF · MANAGE 2.3Oversight runbookKill-switch testReviewer trainingLast updated: 8 days ago
- Accuracy, robustness & cybersecurityPassedOwner: SecurityAdversarial, prompt-injection and permission-escalation testing with measurable thresholds.EU AI Act · Art. 15NIST AI RMF · MEASURE 2.7Red-team reportAdversarial evalLast updated: 4 days ago
- Serious incident reporting (15 days)In reviewOwner: LegalProcess to report serious incidents to the market-surveillance authority within 15 days.EU AI Act · Art. 73Incident SOPNotification template
- User-facing transparencyPassedOwner: AndreiEnd-users are informed they are interacting with an AI system and of its limits.EU AI Act · Art. 13 + 50UI disclosure copyLimitations notice
- Conformity assessment & CE markingIn reviewOwner: LegalHigh-risk system passed conformity assessment and bears CE marking.EU AI Act · Art. 43 + 48Notified body reportCE declaration
- EU AI Act database registrationPassedOwner: LegalHigh-risk system registered in the EU public database before placing on market.EU AI Act · Art. 49 + 71Registration IDPublic listing URLLast updated: 30 days ago
- US federal AI use-case inventoryAvailableOwner: LegalRights/safety-impacting uses listed in agency AI use-case inventory.OMB M-24-10 · §3Inventory entryCAIO sign-off
- Post-market monitoring planPassedOwner: AndreiActive plan to monitor performance and harms after deployment.EU AI Act · Art. 72ISO/IEC 42001 · Cl. 9PMM planQuarterly metrics reportLast updated: 18 days ago
- IMDA AI Verify report (SG)AvailableOwner: AndreiIndependent IMDA AI Verify testing for Singapore deployments.IMDA Model AI Gov · Testing FrameworkAI Verify report
- ISO/IEC 42001 AIMS certificationIn reviewOwner: AndreiCertified AI management system audited by an accredited body.ISO/IEC 42001 · FullStage-2 audit reportCertificate
Next best actions
- Fundamental Rights Impact Assessment — EU AI Act Art. 27
- GPAI upstream disclosure — EU AI Act Art. 53
- US federal AI use-case inventory — OMB M-24-10 §3