§ 1 · WHAT IS WARRANT
the artefact and the audience.
q.01 · what is warrant
what is Warrant?
Warrant is regulator-grade attestation infrastructure for AI agents in regulated industries. you upload an AI agent's execution trace; Warrant returns a PDF that maps each action of the agent to specific paragraphs of regulation. each package is a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant. designed for the EU AI Act high-risk application window (deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus; Regulation (EU) 2026/1744, OJ 24 July 2026), the NYDFS Industry Letter scope (16 October 2024), and the SR 26-2 model risk discipline, which superseded SR 11-7 on 17 April 2026.
deep-dive · /about
q.02 · the artefact
what does the artefact look like?
a 12 KB PDF with article-level citations on every action. each package is a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant. an auditor can confirm it on a laptop without installing anything Warrant-specific.
source · /blog/four-layer-evidence-stack · sample · /verify?id=7de85ceaeac42a47
q.03 · audience
who is Warrant for?
providers and deployers of AI agents in regulated industries · lending, advisory, insurance, healthcare triage, KYC, fraud detection, retail trading. specifically the compliance officer, model risk function, internal audit, and counsel who will be asked to produce evidence to a regulator. not for consumer chatbot deployments where no obligation attaches to the output.
see · /regulators · samples · eu-fintech.pdf
q.04 · version
what version of Warrant is live today?
v0.4 demo. three sample traces (lending, advisory, KYC) produce a record mapped to a specific EU AI Act obligation end-to-end. no checkout, no self-serve account, no SaaS billing at v0.4. engagement is design-partner only via [email protected].
roadmap · q.31
q.05 · access
can i sign up for Warrant today?
there is no checkout at v0.4. design partners are accepted via [email protected] with one paragraph describing the AI agent in production, the regulator that will read the evidence, and the trace volume. public sample packages, each independently verifiable without contacting Warrant, are open at warrant.build/verify with no account.
contact · [email protected] · verifier · /verify
§ 2 · REGULATORY FRAMEWORKS
what we map · article-level, or not at all.
q.06 · eu ai act art. 12
what does EU AI Act Article 12 require?
Article 12 of Regulation (EU) 2024/1689 binds providers of high-risk AI systems to design and develop the system so it automatically records events (logs) over the lifetime of the system. the capability must enable identification of risk situations under Article 79(1), facilitate post-market monitoring under Article 72, and support deployer monitoring under Article 26(5). general application of the Annex III high-risk obligations is deferred from 2026-08-02 to 2027-12-02 by the Digital Omnibus (Regulation (EU) 2026/1744, OJ L 2026/1744, 24 July 2026); Article 19(1) sets a retention floor of at least six months.
source · EUR-Lex CELEX:32024R1689 · deep-dive · /blog/eu-ai-act-article-12
q.07 · nydfs § 500.6
what does NYDFS § 500.6 require?
23 NYCRR § 500.6(a)(2) requires Covered Entities to securely maintain systems that, to the extent applicable and based on the Risk Assessment, include audit trails designed to detect and respond to Cybersecurity Events that have a reasonable likelihood of materially harming any material part of normal operations. the 16 October 2024 NYDFS Industry Letter applies this to AI systems and treats standard API call logs as insufficient on their own.
source · dfs.ny.gov · deep-dive · /regulators/nydfs-part-500
q.08 · sr 26-2
what does SR 26-2 require for AI models?
SR 26-2 (Federal Reserve / OCC / FDIC, 17 April 2026, OCC Bulletin 2026-13) is the current model risk guidance; it supersedes and replaces SR 11-7 (2011) and SR 21-8, principles-based and risk-tailored, most relevant to banks above USD 30 billion in assets. the model definition the lineage established — a quantitative method, system, or approach applying statistical, economic, financial, or mathematical theories — carries forward, and the guidance is organised as model development and model use (§ IV), model validation and monitoring (§ V), governance and controls (§ VI), and vendor and other third-party products (§ VII), with "effective challenge" defined in § III. Agentic and generative systems sit outside that perimeter: § II footnote 3 places generative AI and agentic AI models outside the scope of the guidance. Excluded systems route to the bank's general risk management and governance practices, and footnote 1 keeps supervisory action live for unsafe or unsound practices — so the evidence burden does not disappear with the carve-out.
source · federalreserve.gov · deep-dive · /regulators/sr-11-7
q.09 · fca consumer duty
what does FCA Consumer Duty require for AI?
FCA Consumer Duty (PS22/9, FG22/5) introduces the Consumer Principle (PRIN 2.1.1R) requiring firms to act to deliver good outcomes for retail customers. the cross-cutting rules and four outcomes (products and services, price and value, consumer understanding, consumer support) bind the firm to evidence its outcomes. AI agents acting on a retail customer fall inside the perimeter; the firm must be able to produce evidence that the agent's decision delivered a good outcome on each metric.
source · fca.org.uk · PS22/9 · deep-dive · /regulators/fca-consumer-duty
q.10 · rbi free-ai
what is the RBI FREE-AI framework?
the Reserve Bank of India Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) was released on 2025-08-13. it articulates seven sutras (principles) for regulated entities deploying AI in lending, customer service, fraud detection, and credit scoring · trust, fairness, transparency, accountability, security, governance, resilience. the framework expects institutional ownership of AI risk and an audit trail traceable to the obligation.
source · rbidocs.rbi.org.in · deep-dive · /regulators/india
q.11 · sebi retail algo
what is the SEBI Retail Algorithmic Trading Framework deadline?
the Securities and Exchange Board of India Retail Algorithmic Trading Framework is mandatory from 2026-04-01. it requires unique algo-id registration with the exchange, audit trails of every algo-driven decision, and registration of strategies above the white-listed catalogue. stockbrokers and trading platforms providing algo facilities to retail investors are in scope.
source · sebi.gov.in · deep-dive · /regulators/india
q.12 · india dpdp
what does India DPDP Act 2023 require?
the Digital Personal Data Protection Act 2023 establishes the role of Data Fiduciary, requires lawful purpose for processing personal data of Data Principals, mandates breach notification to the Data Protection Board and to the affected Data Principal, and provides rights of access and correction. Significant Data Fiduciaries carry additional obligations including a Data Protection Officer and Data Protection Impact Assessment. AI agents processing personal data of Indian residents fall inside the perimeter.
source · meity.gov.in · deep-dive · /regulators/india
q.13 · singapore
does Warrant map Singapore MAS?
no, and this page said otherwise until 2026-07-28. MAS published its proposed Guidelines on AI Risk Management as consultation paper P017-2025; a consultation paper is a draft, and Warrant does not put draft instruments on the record. The older FEAT principles are guidance rather than a binding instrument with citable clause numbers, so they are not mapped either. When the guidelines are issued in final form, Singapore becomes a jurisdiction we can cite, and this answer changes.
index · /regulators
q.14 · scope
which regulators does Warrant currently map?
Warrant maps agent actions to enacted, publicly citable regulation: the EU AI Act (Articles 12, 13, 14, 15 and Annex IV), the UK FCA Consumer Duty, NYDFS Part 500, and India's SEBI algorithmic-trading circular and DPDP Act 2023. Every one of those citations resolves to text on the regulator's own domain, and any reviewer can open it. We do not put paywalled standards, superseded guidance, draft consultations or repealed statutes on the record. Four further sources are mapped and labelled non-binding: US Federal Reserve SR 26-2, which is supervisory guidance rather than binding regulation and whose § II footnote 3 places generative and agentic AI outside its scope; the RBI's FREE-AI committee report; NIST AI RMF; and ISO/IEC 42001. Each is mapped at the article or clause level, never at the level of the instrument as a whole.
index · /regulators
§ 3 · HOW EVIDENCE IS BUILT
a record mapped to a specific obligation · evaluated.
q.15 · trace to evidence
how does Warrant turn a trace into evidence?
Warrant reads the AI agent's execution trace, identifies the domain, jurisdictions, and regimes in scope, assesses each action against the classified purpose, and attaches per-action obligations with article-level citations and compliance status. the output is a record mapped to a specific EU AI Act obligation that an auditor can confirm independently without contacting Warrant. the internal method is disclosed to design partners under NDA.
how · /blog/four-layer-evidence-stack
q.16 · mapping quality
how does Warrant keep the mapping quality high?
by making every claim checkable rather than by asserting a score. the mapping is judged at the article level, so each cited obligation resolves to a specific paragraph of the primary source that a reviewer can open. there is no gold-set score behind it yet — see q.18 — which is exactly why the citations are built to be checked by the reader instead of vouched for by us.
essay · /blog/regulator-grade-evals
q.17 · reproducible check
can two people confirm a package and get the same answer?
yes. each package is a record mapped to a specific EU AI Act obligation, built so any party checking it reaches the same result independently, whatever tooling they use. two reviewers confirming the same package arrive at the same answer without contacting Warrant. the internal method that makes the check reproducible is disclosed to design partners under NDA.
category · /regulators · see · q.24 · without trust
q.18 · gold-set agreement
how does Warrant measure mapping agreement?
it does not yet, and until 2026-07-28 this page implied it did. There is no labelled gold set on disk and no two-annotator pass has been run, so Warrant has no agreement statistic and quotes none. What is checked today is narrower and verifiable: every cited clause must exist in the corpus, and every corpus entry must resolve to the regulator's own text. A measured agreement figure, with the size of the set it was computed over, is in progress.
eval suite · q.19 · /trust
q.19 · regression
what is in the Warrant eval suite?
a harness and five declared cases, four of which point at fixture traces not yet written. one hand-crafted trace exists, drawn from the lending sample. no graded run has been executed, so the suite has produced no agreement, accuracy or precision figure and this page publishes none. the four surfaces the suite is designed around, and the reason the numbers are absent rather than estimated, are set out in the eval note.
samples · eu-fintech.pdf · us-fintech.pdf · india-fintech.pdf
§ 4 · INDEPENDENT VERIFICATION
a record anyone can confirm without contacting Warrant.
q.20 · confirm a package
how can an auditor confirm a package is genuine?
each package is a record mapped to a specific EU AI Act obligation, built so an auditor can confirm it is genuine without contacting Warrant. the check runs on a laptop and does not depend on Warrant being online or on any third party. the internal method behind the check is disclosed to design partners under NDA.
verifier · /verify · essay · /blog/four-layer-evidence-stack
q.21 · when it was created
how does Warrant show when a package was created?
each package carries an independently checkable bound on when it existed, so a reviewer can confirm the package was not created after the fact · the package cannot be passed off as older or newer than it is. no trusted third party is required to make that check, and it does not depend on Warrant being online. the internal method behind it is disclosed to design partners under NDA.
see · q.23 · what it establishes
q.22 · package origin
how does a reviewer know a package came from Warrant?
each package is a record mapped to a specific EU AI Act obligation, and its origin is independently verifiable without contacting Warrant. a reviewer can confirm the package's authorship and that packages stay confirmable over time, including historical ones. the internal method behind that assurance is disclosed to design partners under NDA.
verifier · /verify
§ 5 · WHAT A CHECK ESTABLISHES
confirmable by anyone with a laptop.
q.23 · what it establishes
what does confirming a package establish?
confirming a package establishes that it is a record mapped to a specific EU AI Act obligation, that it has not been altered, and that it existed before the time it claims. the confirmation is independently verifiable without contacting Warrant and runs on a laptop. the internal method behind the check is disclosed to design partners under NDA.
verifier · /verify · spec · /blog/four-layer-evidence-stack
q.24 · without trust
how do i confirm a package without trusting Warrant?
each package is independently verifiable without contacting Warrant · the confirmation requires no Warrant infrastructure and no warrant.build availability. an auditor can run it on their own machine and reach the same result Warrant would. the internal method behind the check is disclosed to design partners under NDA.
verifier · /verify
q.25 · honest limits
what does confirming a package NOT prove?
it does not prove the AI agent itself was correct. it does not prove the regulator-citation mapping is final or contested-proof. it does not prove the trace was produced by the deployer claimed. it does not prove the agent acted lawfully under any specific interpretation. confirming a package establishes that it is a record mapped to a specific EU AI Act obligation, unaltered and existing before the time it claims · the chain of custody, not the merits.
see · q.27 · law firm · q.28 · notified body
q.26 · timing
how long does an evidence package take to produce?
end-to-end target on the sample traces is 60 seconds. the result is a record mapped to a specific EU AI Act obligation: each agent action carried with its article-level citation and compliance status. the package is downloadable inside the 60-second window, and it becomes independently verifiable without contacting Warrant shortly after.
how · /blog/four-layer-evidence-stack
§ 6 · SCOPE
what we hold · and what we don't.
q.27 · scope
is Warrant a law firm?
no. Warrant is not a law firm, does not provide legal advice, and is not a notified body under the EU AI Act (Article 43 conformity assessment is out of scope). the package cites obligations and supports an audit; it does not adjudicate whether a specific deployment is compliant. customers should retain qualified counsel for legal interpretation.
see · /about · /trust
q.28 · scope
is Warrant a notified body?
no. notified bodies are designated under Article 28 of Regulation (EU) 2024/1689 by EU member-state notifying authorities to perform third-party conformity assessment of high-risk AI systems under Article 43. Warrant is not designated and does not perform conformity assessment. Warrant produces evidence the provider can put before a notified body, an internal audit, or a national competent authority under Article 21.
source · EUR-Lex · Article 28
q.29 · controls
does Warrant comply with SOC 2?
not today. Warrant does not hold SOC 2, HIPAA BAA, ISO 27001, or PCI DSS certification at v0.4. the roadmap is published at warrant.build/trust and no certification is claimed that has not been issued. customers under SOC 2 obligations of their own can rely on each package being independently verifiable without contacting Warrant for the integrity of the artefact itself.
controls · /trust
q.30 · privacy
does Warrant store my AI agent's trace data?
no. the trace is processed in-memory, the PDF is delivered, and the working copy is discarded. only the package_id and the metadata that keeps each package independently verifiable without contacting Warrant are retained. customer trace bodies are not retained at v0.4. trust controls are published at warrant.build/trust.
see · /trust
q.31 · roadmap
what is the v0.5 → v1 roadmap?
v0.5 adds per-tenant package origin and regulator-corpus pinning per package. v1 adds the deployer-side ingest agent, multi-region durability, the per-tenant audit portal, and a public mapping-quality leaderboard. target dates are not published.
trust · /trust
q.32 · how to start
how do i produce a Warrant package today?
drop your AI agent's execution trace JSON at warrant.build/demo. Warrant classifies the regime, extracts per-action records, assesses authorisation against the classified purpose, and maps each action to article-level obligations. a record mapped to a specific EU AI Act obligation returns in roughly 60 seconds with a 16-character package_id, independently verifiable without contacting Warrant at warrant.build/verify.
open · /demo · verify · /verify