REGISTER · ENTRIES · OF RECORD SINCE 2026-05-07

Writing on the
obligation to evidence.

A register of statutory readings and architecture entries, each one independently verifiable without contacting Warrant. Every entry below carries sub-clause citations in the same paragraph as the claim, and a primary-source URL in the footer.

ENTRIES OF RECORD
35
published 2026-05-07 · 2026-05-09
Every entry carries sub-clause-level citations anchored to a primary-source URL.
REGIMES COVERED
35
across 6 jurisdictions
EU AI Act · NYDFS · SR 26-2 · FCA · RBI · SEBI · India DPDP · MAS · NIST AI RMF.
SUB-CLAUSE CITED
Yes
every entry
Article number, paragraph number, page where applicable. 99.5% precision threshold before merge.
CADENCE
2 / wk
Tue pillars · Fri hubs
Pillars 4000+ words. Hubs 1500-2500. Same eval suite as the evidence engine.
VOLUME 02 · 2026 · OPEN ENTRIES
№ 45
2026-07-25
Is there a standard for EU AI Act Article 12 logging yet?
No. prEN 18229-1, AI trustworthiness framework — Part 1: Logging, sits at CEN Enquiry stage 40.20 from 28 May 2026 under CEN-CENELEC JTC 21 Working Group 4. ISO/IEC 24970 is at FDIS with a catalogue status of under development, its final text registered 18 May 2026. Zero AI Act harmonised standards have been referenced in the Official Journal. Article 40(1) confines the presumption of conformity to Section 2 of Chapter III, which leaves the Article 26 deployer duties outside it — so no standard can ever transfer them. Regulation (EU) 2026/1744 dropped the Commission's proposed readiness condition for fixed dates.
STANDARDS TRACK · ART 12 · ART 40~12-min · warrant compliance
№ 43
2026-06-19
How long must EU AI Act Article 12 logs be kept?
At least six months. Article 12(1) is a logging-capability duty — the system must technically allow for the automatic recording of events over its lifetime — and it sets no retention number: Article 19(1) fixes the provider floor and Article 26(6) the matching deployer floor, each at a period appropriate to the intended purpose of at least six months. Six months is a minimum, not a target — MiFID II runs five to seven years and the Medical Device Regulation ten to fifteen for implantables. A reader who quotes Article 12 for a retention number is quoting the wrong article.
EU AI ACT · ART 12 · RETENTION~11-min · warrant compliance
№ 42
2026-06-12
Who must label AI-generated content? Article 50 and the new Code of Practice.
The Code of Practice on Transparency of AI-Generated Content, published 10 June 2026 by the AI Office: Section 1 maps the provider marking duty under Article 50(2), Section 2 the deployer disclosure duty under Article 50(4). The obligations apply 2 August 2026 — not deferred by the Omnibus — with a transitional period to 2 December 2026 for systems already on the market, and Article 99(4) penalties at EUR 15M or 3 percent of worldwide turnover. The human-review exemption read as what it is: a process claim that has to exist as a record.
EU AI ACT · ART 50 · TRANSPARENCY~11-min · warrant compliance
№ 41
2026-06-04
How do you produce audit-ready evidence for an autonomous AI agent?
What audit-ready evidence for an autonomous agent must contain and be: a per-action record that names the governing obligation, captures the authorisation for each action, is recorded automatically rather than by a developer remembering to log, and is independently verifiable without contacting Warrant. Framed as the requirement, mapped to the EU AI Act Article 12 logging-capability duty and, separately, to the Article 19(1) six-month retention floor.
EVIDENCE · HOW-TO~10-min · warrant compliance
№ 40
2026-06-04
What records must an AI agent keep to satisfy a regulator?
The record set a deployer must retain: the Article 12(1) duty that the system technically allow automatic event recording over its lifetime, the separate Article 19(1) and Article 26(6) six-month retention floor, and the NYDFS 23 NYCRR § 500.6(a)(2) audit trail read as Warrant's inference from the regulation. SR 26-2 documentation practice sits alongside as voluntary governance: it is supervisory guidance, non-compliance is not independently enforceable, and its footnote 3 places agentic AI outside its scope. The regulator's questions mapped to the artefact and the clause that demands it.
EU AI ACT · RECORDS · RETENTION~10-min · warrant compliance
№ 39
2026-06-04
What is a per-action evidence record for an AI agent?
The definition: a record that states, for each action an AI agent took, which regulatory obligation governed it and whether the action satisfied it — independently verifiable without contacting Warrant. The deliverable layer a regulator reads in place of telemetry, mapped across EU AI Act Article 12, Annex III and the FCA Consumer Duty, with NYDFS, SEBI, MAS and India DPDP classified and reported in scope and SR 26-2 and RBI FREE-AI carried as non-binding governance context.
CATEGORY · PER-ACTION RECORD~11-min · warrant compliance
№ 38
2026-06-04
What audit trail must an AI agent produce for NYDFS Part 500 and SR 11-7?
Standard inference and LLM API logs do not satisfy a NYDFS 23 NYCRR § 500.6(a)(2) audit trail, read as Warrant's inference from the regulation. SR 26-2 asks nothing of the agent at all: it is supervisory guidance, not binding regulation, and its footnote 3 places generative and agentic AI outside its scope. The five questions a regulator asks — what the agent accessed, when, under what authority, under what constraints, with what result — mapped to the per-action record, with EU AI Act Annex III creditworthiness as the cross-over.
US · NYDFS 500 · SR 26-2~12-min · warrant compliance
№ 37
2026-06-04
Does the EU AI Act require a separate record for every autonomous agent action?
Article 12 of Regulation (EU) 2024/1689 requires high-risk AI systems to technically allow for the automatic recording of events over the lifetime of the system. An autonomous agent does not act once. It chains actions, each a separate event. Article 12 prescribes the logging of relevant events; it does not name a unit. Reading it against the Annex III high-risk determination, Warrant records per action rather than per session — an implementation choice, not a statutory one. What that means for retention under Article 19, traceability under Article 12(2), and the penalty exposure under Article 99(4).
EU AI ACT · ART. 12 · AGENTIC~12-min · warrant compliance
№ 36
2026-05-22
EU AI Act high-risk classification, draft guidelines.
The Commission's 19 May 2026 draft guidelines on the classification of high-risk AI systems under Article 6, open for stakeholder consultation until 23 June 2026, 22:00 CET. Paragraph 75 of the Annex III chapter names agentic AI directly: where linked actions in conjunction serve an intended high-risk purpose, the unit of assessment is the system, not the step. Two routes in, one filter mechanism with a profiling floor, an intended-purpose deeming rule, and a deployer-becomes-provider trigger. Calendar moved to 2 December 2027 under the Omnibus, content unchanged.
EU · ART 6 · DRAFT GUIDELINES~11-min · warrant compliance
№ 34
2026-05-11
CFPB AI guidance, line by line.
CFPB Circular 2022-03 on ECOA adverse-action notices when AI is used. 2023 chatbot supervisory highlights. 2024 interagency AVM rule. CFPB Circular 2024-06 on algorithmic scores. The US Federal consumer-finance regulator's position on AI explainability and UDAAP exposure for lending, mortgage, and chatbot agents.
US-FEDERAL · CFPB · ECOA REG B~11-min · warrant compliance
№ 33
2026-05-11
PIPL + CAC AI rules, line by line.
China Personal Information Protection Law (PIPL, effective 2021-11-01) + CAC Generative AI Measures (2023-08-15) + Deep Synthesis Provisions (2023-01-10). Article 24 automated decision-making. Articles 38-43 cross-border transfer. Articles 55-56 PIPIA. The APAC privacy stack with extraterritorial reach and RMB 50M / 5% turnover penalty ceiling.
CHINA · PIPL + CAC~13-min · warrant compliance
№ 32
2026-05-11
OWASP LLM Top 10, line by line.
The OWASP Top 10 for Large Language Model Applications (2025 edition). Ten applied security categories from prompt injection through unbounded consumption. Cross-references to NIST AI 100-2 attack taxonomy and EU AI Act Article 15(5) cybersecurity obligation. The engineering checklist that translates the taxonomy into a build-time audit.
ENGINEERING · OWASP LLM TOP 10~14-min · warrant engineering
№ 30
2026-05-11
EU AI Act Article 27, line by line.
Article 27 of Regulation (EU) 2024/1689 sets the fundamental rights impact assessment obligation for high-risk AI deployers. Article 26(9) is the trigger. Six contents elements under 27(1)(a)-(f). The AI Office template under 27(5). Notification to market surveillance authority under 27(3). Sister piece to Article 26 deployer obligations.
EU AI ACT · ART. 27~11-min · warrant compliance
№ 29
2026-05-11
EU AI Act Article 15, line by line.
Article 15 of Regulation (EU) 2024/1689 binds providers of high-risk AI systems to design and develop the system to achieve an appropriate level of accuracy, robustness, and cybersecurity, and to perform consistently across the lifecycle. Accuracy levels declared in the Article 13 instructions for use. Resilience covers errors, faults, inconsistencies, fail-safe and redundancy. Cybersecurity covers data poisoning, model poisoning, model evasion, confidentiality attacks. The technical-quality bar of the EU AI Act.
EU AI ACT · ART. 15~13-min · warrant compliance
№ 28
2026-05-11
EU AI Act Article 9, line by line.
Article 9 of Regulation (EU) 2024/1689 binds providers of high-risk AI systems to establish, implement, document, and maintain a risk management system as a continuous iterative process planned and run throughout the entire lifecycle. Ten paragraphs covering the four-step process, residual-risk acceptability, real-world testing under Article 60, minors and vulnerable groups, and integration with the Article 17 quality management system.
EU AI ACT · ART. 9~12-min · warrant compliance
№ 27
2026-05-11
EU AI Act Article 26, line by line.
Article 26 of Regulation (EU) 2024/1689 binds deployers of high-risk AI systems. Twelve paragraphs covering use per the Article 13 instructions for use, competent staff for human oversight under Article 14(3)(b), input data relevance, monitoring and serious-incident reporting, log retention floor of six months, workplace-AI worker notification, data-subject notification, public-authority registration under Annex VIII, the DPIA cross-reference, and the Article 27 fundamental-rights impact assessment trigger.
EU AI ACT · ART. 26~13-min · warrant compliance
№ 26
2026-05-11
EU AI Act Article 14, line by line.
Article 14 of Regulation (EU) 2024/1689 binds providers of high-risk AI systems to design and develop the system so it can be effectively overseen by natural persons. The five oversight capabilities the natural person must have, listed verbatim. The four-eyes principle in Article 14(5) for biometric identification under Annex III(1). Sister piece to the Article 12 / Article 13 / Annex IV reads.
EU AI ACT · ART. 14~12-min · warrant compliance
№ 25
2026-05-09
Colorado AI Act + CCPA ADMT regulations, line by line.
Colorado AI Act (SB24-205, signed 17 May 2024) and California CCPA ADMT regulations (CPPA, finalised 24 July 2025). Two state-level frameworks for automated decision-making technology in 2026. Reasonable-care duty, consumer notice obligations, opt-out rights, and risk-assessment requirements.
US-STATE · COLORADO + CALIFORNIA~13-min · warrant compliance
№ 23
2026-05-09
EU AI Act Annex IV, line by line.
Article 11 of Regulation (EU) 2024/1689 obliges every provider of a high-risk AI system to draw up technical documentation before placing the system on the Union market. Annex IV defines, in nine sections, what the documentation must contain. Application 2 December 2027 (deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus; Regulation (EU) 2026/1744, OJ 24 July 2026).
EU AI ACT · ANNEX IV~12-min · warrant compliance
№ 22
2026-05-09
GDPR Article 22, line by line.
Regulation (EU) 2016/679 Article 22. The data subject's right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subject. Read against AI agents in production.
GDPR · ART. 22~13-min · warrant compliance
№ 21
2026-05-09
HIPAA + healthcare AI, line by line.
HIPAA Privacy Rule (45 CFR Part 164 Subpart E) and Security Rule (Subpart C) read against AI agents handling protected health information. Minimum-necessary, business-associate-agreement, audit-control, and breach-notification obligations applied to the AI deployment perimeter.
HIPAA · 45 CFR § 164~12-min · warrant compliance
№ 19
2026-05-09
India DPDP Act 2023, line by line.
Digital Personal Data Protection Act 2023. Section 8 obligations · DPDP Rules 2025 (notified 13 Nov 2025) · Rule 7 breach-notification 72 hours. DPB constituted under § 18 (Chapter V). Substantive obligations commence at the eighteen-month mark of G.S.R. 843(E) of 13 Nov 2025 — 14 May 2027 on the conservative reading — so they are not yet in force.
DPDP ACT 2023~14-min · warrant compliance
№ 18
2026-05-09
SEBI Retail Algorithmic Trading Framework, line by line.
SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/0000013 (4 Feb 2025) + extension CIR/P/2025/132 (30 Sep 2025). Universal applicability to all stock brokers wef 1 April 2026. Glide-path milestones verbatim from SEBI PDFs.
SEBI · RETAIL ALGO~12-min · warrant compliance
№ 16
2026-05-09
the stochastic evidence problem.
An LLM is non-deterministic by design. A regulator audit is deterministic by definition. Four moves narrow the gap: RFC 8785 JCS canonicalisation, a pinned pipeline configuration hashed into the signed bytes, eval-set anchoring, residual-uncertainty disclosure. The canonical form is deterministic by specification. Whether the model stages replay identically is unmeasured, classification accuracy is not measured, and no figure for either is published here.
ENGINEERING · STOCHASTIC~12-min · warrant engineering
№ 15
2026-05-09
OECD principles, ISO/IEC 24028, and the AIGP body of knowledge.
Three references compliance officers reach for before opening any binding regulator. OECD AI Principles (2019/2024) · ISO/IEC 24028:2020 trustworthiness vocabulary · IAPP AIGP body of knowledge (since March 2024).
OECD · ISO 24028 · AIGP~10-min · warrant compliance
№ 14
2026-05-09
NIST AI RMF 1.0 + Generative AI Profile, line by line.
Four functions: GOVERN · MAP · MEASURE · MANAGE. NIST AI 100-1 (Jan 2023) + NIST AI 600-1 GenAI Profile (Jul 2024). Cited in Executive Order 14110 and OMB M-24-10. Crosswalks with ISO/IEC 42001 and OECD.
NIST AI RMF~13-min · warrant compliance
№ 13
2026-05-09
ISO/IEC 42001:2023, line by line.
First international AI management system standard. Published 18 Dec 2023. AIMS analogous to ISO 27001 for infosec. 38 controls in Annex A. Likely backbone of CEN-CENELEC harmonised standards for EU AI Act conformity.
ISO/IEC 42001:2023~14-min · warrant compliance
№ 12
2026-05-09
EU AI Act Article 13, line by line.
Article 12 binds the provider to log. Article 13 binds the same provider to give the deployer instructions sufficient to interpret those logs. The two articles are paired obligations: the artefact and the manual to read it. Application 2 December 2027 (deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus; Regulation (EU) 2026/1744, OJ 24 July 2026).
EU AI ACT · ART. 13~11-min · warrant compliance
№ 11
2026-05-09
SR 26-2 + SR 11-7, line by line.
Federal Reserve / OCC / FDIC interagency guidance on model risk management. SR 26-2 (17 April 2026) supersedes SR 11-7 (2011) and SR 21-8, principles-based and risk-tailored. Read against an AI agent inside a US bank, footnote 3 puts the agent outside scope: the four-pillar discipline still reaches every conventional model the agent calls, and the agent's own per-decision record is a bar the bank sets for itself.
SR 26-2 · SR 11-7~13-min · warrant compliance
№ 10
2026-05-09
FCA Consumer Duty Principle 12, line by line.
Five sub-principles of PRIN 2A. One Handbook chapter. Principle 12 binds every UK retail-facing firm to deliver good outcomes; PRIN 2A breaks the principle into operative duties. Read against an AI agent making customer-facing decisions, the four outcomes become evidence-of-record obligations.
FCA · PRIN 2A~14-min · warrant compliance
№ 24
2026-05-08
EU AI Act, Digital Omnibus, 2026-05-07.
Velocity reading on the Digital Omnibus on AI, agreed 2026-05-07 and since published as Regulation (EU) 2026/1744 (OJ 24 July 2026). Annex III standalone high-risk application moves from 2 August 2026 to 2 December 2027. Annex I embedded high-risk to 2 August 2028 (subject to Article 2(13)). The operative transparency duties in Article 50(1) to (6) are not deferred and apply from 2 August 2026, while Article 50(7) was replaced by Article 1(20) of the same regulation; the new Article 111(4) transitional gives systems placed on the market before that date until 2 December 2026 to comply with Article 50(2). The adopted calendar is the operative one.
EU AI ACT · OMNIBUS~9-min · warrant editorial
№ 09
2026-05-08
no agentic framework. just functions.
Warrant runs zero LangGraph, zero AutoGen, zero CrewAI. Four named stages, one model, one request handler. The architectural argument for explicit functions and typed edges over hidden control flow, hidden retries, and hidden token spend.
ARCHITECTURE · PILLAR~11-min · warrant engineering
№ 08
2026-05-08
four stages. one model.
Warrant's four-stage attestation pipeline runs every stage on claude-opus-5, ruled 2026-07-31. The model each stage runs is hashed into pipeline_config_sha256, which sits inside the signed bytes, so a model swap is a recorded provenance event and not a config edit. A representative trace costs ~$0.135 at the Anthropic price sheet as at 2026-06-24. Routing the two structure stages to a cheaper model is an open question, not a shipped optimisation.
ENGINEERING · LLM HUB~10-min · warrant engineering
№ 07
2026-05-08
the four-layer evidence stack.
observability is not the same as runtime. runtime is not the same as evidence. evidence is not the same as attestation. why splitting the perimeter into four layers is what makes the regulator accept the artefact.
ARCHITECTURE · PERIMETER~10-min · warrant engineering
№ 06
2026-05-08
evals are the moat. not the model.
a citation-precision benchmark cross-checks every sub-clause we cite against canonical regulator text. how three real bugs got caught, a model-upgrade citation regression, prompt injection inside trace data, FCA-vs-SR-11-7 cross-jurisdictional drift.
ENGINEERING · EVALS~9-min · warrant research
№ 05
2026-05-08
one agent. many jurisdictions.
the same trace classified against EU AI Act, FCA Consumer Duty, NYDFS Part 500, the SEBI Retail Algorithmic Trading Framework and India DPDP simultaneously, with SR 26-2 and the RBI FREE-AI committee report carried as non-binding governance context rather than obligations. one evidence package, citing the obligations the corpus carries and reporting the rest as classified and in scope, not evaluated, independently verifiable without contacting Warrant.
COMPLIANCE · MULTI-JURISDICTIONAL~10-min · warrant compliance
№ 03
2026-05-07
Standard API call logs do not satisfy 23 NYCRR § 500.6.
On 16 October 2024 NYDFS issued an Industry Letter on AI cybersecurity. The letter imposes no new rules. It applies 23 NYCRR Part 500 to AI, working mainly through § 500.11, and cites neither § 500.6 nor § 500.17. Reading § 500.6(a)(2) onto an AI deployment is Warrant's inference from the regulation. Read against that clause, standard API call logs and LLM inference logs do not satisfy.
23 NYCRR § 500.6(a)(2)~12-min · warrant compliance
№ 02
2026-05-07
The agent perimeter is not a metaphor anymore.
A piece on Hacker News this week framed AI agents as already-inside-the-perimeter actors. The metaphor is right. The perimeter has stopped being a network boundary and started being a logging boundary.
ESSAY~4-min · warrant editorial
№ 01
2026-05-07
EU AI Act Article 12, line by line.
Article 12(1) of Regulation (EU) 2024/1689 requires high-risk AI systems to technically allow for the automatic recording of events over the lifetime of the system. For Annex III standalone high-risk systems this obligation applies 2 December 2027 (deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus; Regulation (EU) 2026/1744, OJ 24 July 2026). The verbatim text, the in-scope determination under Annex III, the retention rules, the penalty exposure under Article 99(4).
EU AI ACT · ART. 12~13-min · warrant compliance
CANONICAL SOURCES · PRIMARY REGULATOR TEXT · 6 JURISDICTIONS · UPDATED 2026-05-08
EUR-Lex CELEX:32024R1689 · dfs.ny.gov · federalreserve.gov SR2602.pdf · sebi.gov.in · rbidocs.rbi.org.in · fca.org.uk · imda.gov.sg · meity.gov.in
Every regulatory claim resolves to one of these primary sources. No aggregator paraphrase. When a source changes, the entry is reissued as a fresh tamper-evident record and the changelog records the diff.