The EU AI Act, NIST AI RMF and ISO/IEC 42001 each ask a deployer of AI a version of the same seven questions: what do you run, who answers for it, can a human overrule it, can you produce the record, do you know the impact, can you respond on the clock, and are you still watching after deployment. Lares answers all seven from your own live traffic.
References are at the theme level, where the obligations are stable. Your counsel maps clauses; Lares supplies what the clauses want to see.
| The question | Where it is asked | What Lares gives you |
|---|---|---|
| Do you know every AI agent you run? | EU AI Act Art. 26 deployer duties NIST AI RMF Map ISO/IEC 42001 AI asset inventory |
A live inventory built from traffic, not a spreadsheet. Every agent Lares observes, the registry of agents you declared, and the diff between them: unregistered (shadow) agents surfaced the moment they act, and declared agents that never appear, flagged as dormant credentials. |
| Is a named human accountable for each one? | EU AI Act Art. 26 oversight assigned to people with competence and authority NIST AI RMF Govern ISO/IEC 42001 roles and responsibilities |
An owner on every agent. Declared in your registry, claimed in the console, or inferred from the identity the agent signs in with. Agents with no owner are a counted, visible gap with a one-click claim workflow, and decisions about an agent route to its owner. |
| Can a human overrule the machine? | EU AI Act Art. 14 and 26 human oversight NIST AI RMF Govern, Manage |
The verdict is always a person's. The engine only ever suspects; a named person confirms or dismisses, and that name goes in the record. Responses are pre-staged and reversible, and Lares acts alone only where you dialed it, per asset class, with thresholds. |
| Can you produce the record? | EU AI Act Art. 12, 19 and 26 logging and retention NIST AI RMF Measure ISO/IEC 42001 event logging |
An append-only decision log that shows its own integrity. Every detection, verdict, action and rollback, hash-chained so an edit, a gap or a reorder is visible, verifiable on demand, exportable as JSONL, and streamed to your SIEM as it happens. |
| Do you know what an incident would cost? | NIST AI RMF Map, Measure ISO/IEC 42001 impact assessment |
Findings arrive priced, on your numbers. You declare the crown-jewel assets and their value; Lares grounds each finding to them over observed reachability and attaches a loss band with its assumptions stated. Lares never invents a dollar figure. |
| Can you detect and respond on the clock? | EU AI Act Art. 73 serious-incident reporting NIS2 Art. 23 timelines NIST AI RMF Manage ISO/IEC 42001 incident handling |
Evidence-backed findings with a response attached. Plain-English evidence, one recommended containment with a tested undo, tickets raised in Jira or ServiceNow, alert mirrors to your SIEM and email, and the who-did-what-when your incident report needs. |
| Are you still watching after deployment? | EU AI Act Art. 26 and 72 post-market monitoring NIST AI RMF Measure |
Every agent is watched against its own learned normal. Behavior that quietly widens needs an explicit sign-off; it is never silently absorbed into the baseline. New agent versions re-learn under the same declared boundary. |
The fastest way to check this crosswalk is to watch the loop run: see an unregistered agent surface, claim its owner, confirm a finding, and export the record.