Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant.
drop your AI agent's execution trace. get a record mapped to a specific EU AI Act obligation, and to NYDFS Part 500, the FCA Consumer Duty, SEBI and India's DPDP Act. in 60 seconds.
one PDF. the trace's actions, mapped per-action to the article numbers that govern them — a record mapped to a specific EU AI Act obligation. it is independently verifiable without contacting Warrant, so any auditor can confirm it for themselves.
one trace in, one PDF out. the record states, per action the agent took, whether it stayed within purpose, whether the obligation was met, and the article number that governs it — a record mapped to a specific EU AI Act obligation.
end-to-end target on the sample traces · 60 seconds. trace truncation cap · 80,000 characters. the resulting record is independently verifiable without contacting Warrant.
Warrant maps agent actions to enacted, publicly citable regulation: the EU AI Act (Articles 12, 13, 14, 15 and Annex IV), the UK FCA Consumer Duty, NYDFS Part 500, and India's SEBI algorithmic-trading circular and DPDP Act 2023. Every one of those citations resolves to text on the regulator's own domain, and any reviewer can open it. We do not put paywalled standards, superseded guidance, draft consultations or repealed statutes on the record. Four further sources are mapped and labelled non-binding: US Federal Reserve SR 26-2, the RBI's FREE-AI committee report, NIST AI RMF and ISO/IEC 42001. Each card below carries the state the regime is actually in.
Reg. (EU) 2024/1689, Art. 12(1) · Art. 13 · automatic event recording over the lifetime of high-risk systems. enforcement 2027-12-02 (deferred from 2026-08-02; Omnibus, Regulation (EU) 2026/1744). penalty up to 3% turnover or €15M under Art. 99(4).
Art. 12(1) · Art. 13 · enforcement 2027-12-02 (deferred from 2026-08-02; Omnibus, Regulation (EU) 2026/1744) · penalty 3% turnover or €15M (Art. 99(4))Reg. (EU) 2024/1689, Art. 13 § 1–3 · transparency obligations toward downstream deployers. instructions for use, capabilities, limitations, oversight measures.
Art. 13(1) · Art. 13(2) · Art. 13(3) · enforcement 2027-12-02 (deferred from 2026-08-02; Omnibus, Regulation (EU) 2026/1744)Principles for Businesses Sourcebook · Principle 12 and PRIN 2A. outcomes monitoring, support for retail customers, adverse-action disclosure. PS22/9 published 27 July 2022.
PRIN 2.1.1R · Principle 12 · PS22/923 NYCRR Part 500 · cybersecurity-event notification, annual notice of compliance, covered-entity exemption thresholds. Oct 2024 industry letter applies the rule to AI deployments. the corpus carries no § 500.6 sub-clause, so a package reports the Part 500 audit trail as classified and not evaluated rather than citing that clause.
§ 500.17(a) · § 500.17(b) · § 500.19Revised Guidance on Model Risk Management, issued 17 April 2026 by the Federal Reserve, OCC and FDIC · it supersedes and replaces SR 11-7 (4 April 2011) and SR 21-8, and the Fed withdrew the SR 11-7 page on supersession, so Warrant cites only SR 26-2. It is an interagency supervisory letter, not an enforceable rule, and as of that 17 April 2026 letter its footnote 3 places generative and agentic models outside its scope. Mapped and labelled, never cited as binding: evidence for an autonomous agent is framed as governance, never as a model-risk claim.
SR 26-2 · Fed / OCC / FDIC · 17 April 2026 · supervisory guidance, not bindingReserve Bank of India · Framework for Responsible and Ethical Enablement of AI · the report of a committee, placed on the RBI website 13 August 2025. seven sutras and 26 recommendations, 13 of them addressed to the RBI, Government, regulators or industry bodies rather than to regulated entities. the Reserve Bank has adopted no instrument giving it force: no direction, no compliance date. mapped and labelled, never cited as a statutory obligation.
RBI FREE-AI · 13 Aug 2025 · committee report, not adoptedSecurities and Exchange Board of India · Retail Algorithmic Trading Framework. February 2025 circular plus September 2025 extension. mandatory 1 April 2026. today is post-enforcement.
Feb 2025 + Sep 2025 circulars · mandatory 1 April 2026Digital Personal Data Protection Act 2023 · § 8(2) a data processor engaged only under a valid contract · § 8(6) intimation of a personal data breach to the Board and each affected data principal. the Act is enacted, but both sections sit in the eighteen-month tranche of G.S.R. 843(E) of 13 November 2025 — 14 May 2027 on the conservative reading — so the substantive duties are not yet operative.
DPDP Act 2023 · § 8(2) processor contract · § 8(6) breach intimation · duties commence 14 May 2027NIST AI Risk Management Framework 1.0 · GOVERN, MAP, MEASURE, MANAGE. Voluntary and labelled as such on every record: it is not enforceable on its own, and Warrant never presents it as a binding obligation.
NIST AI 100-1 · voluntary · not enforceableanyone can, in under a minute, with no account and no API key. paste a package id or upload the PDF. the artefact is independently verifiable without contacting Warrant. it passes or it fails. there is no third option.
Yes. Package 7de85ceaeac42a47 was entered into the public record on 2026-05-06 against an EU/DE-BaFin lending trace, and independently confirmed the same day.
It is a record mapped to a specific EU AI Act obligation.
Anyone with an internet connection can confirm it is independently verifiable without contacting Warrant.
7de85ceaeac42a47
A record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant.
we name the perimeter so the regulator can read it. the artefact is precise about what it asserts and silent on what it does not.
High-risk AI systems shall technically allow for the automatic recording of events ('logs') over the lifetime of the system. Regulation (EU) 2024/1689 · Article 12(1) · 13 June 2024
three steps from one sentence in Article 12(1) to the EUR 15 million ceiling. Article 12 binds the system. Article 16(a) reads it back as a provider obligation — providers shall "ensure that their high-risk AI systems are compliant with the requirements set out in Section 2", and Article 12 sits in that Section. Article 99(4)(a) then sets the fineable consequence for "obligations of providers pursuant to Article 16" at the higher of EUR 15 million or 3 percent of total worldwide annual turnover.
one trace JSON, one PDF, sixty seconds. independently verifiable without contacting Warrant. the citations name the article. the artefact reads in court.
Compliance officer, deployer engineer, regulator, builder — tell us who you are and we'll write back within 48h. Two fields. No sequence drip. No newsletter.