Compliance crosswalk

Evidence for the frameworks
your board already asked about.

The EU AI Act, NIST AI RMF and ISO/IEC 42001 each ask a deployer of AI a version of the same seven questions: what do you run, who answers for it, can a human overrule it, can you produce the record, do you know the impact, can you respond on the clock, and are you still watching after deployment. Lares answers all seven from your own live traffic.

⚖️ A tool does not make you compliant, and we will never claim it does. This page shows where Lares produces the operational evidence an auditor or regulator asks for. The program, the policies and the legal interpretation stay yours; bring this crosswalk to that conversation.
The seven questions

One table, three frameworks.

References are at the theme level, where the obligations are stable. Your counsel maps clauses; Lares supplies what the clauses want to see.

The questionWhere it is askedWhat Lares gives you
Do you know every AI agent you run? EU AI Act Art. 26 deployer duties
NIST AI RMF Map
ISO/IEC 42001 AI asset inventory
A live inventory built from traffic, not a spreadsheet. Every agent Lares observes, the registry of agents you declared, and the diff between them: unregistered (shadow) agents surfaced the moment they act, and declared agents that never appear, flagged as dormant credentials.
Is a named human accountable for each one? EU AI Act Art. 26 oversight assigned to people with competence and authority
NIST AI RMF Govern
ISO/IEC 42001 roles and responsibilities
An owner on every agent. Declared in your registry, claimed in the console, or inferred from the identity the agent signs in with. Agents with no owner are a counted, visible gap with a one-click claim workflow, and decisions about an agent route to its owner.
Can a human overrule the machine? EU AI Act Art. 14 and 26 human oversight
NIST AI RMF Govern, Manage
The verdict is always a person's. The engine only ever suspects; a named person confirms or dismisses, and that name goes in the record. Responses are pre-staged and reversible, and Lares acts alone only where you dialed it, per asset class, with thresholds.
Can you produce the record? EU AI Act Art. 12, 19 and 26 logging and retention
NIST AI RMF Measure
ISO/IEC 42001 event logging
An append-only decision log that shows its own integrity. Every detection, verdict, action and rollback, hash-chained so an edit, a gap or a reorder is visible, verifiable on demand, exportable as JSONL, and streamed to your SIEM as it happens.
Do you know what an incident would cost? NIST AI RMF Map, Measure
ISO/IEC 42001 impact assessment
Findings arrive priced, on your numbers. You declare the crown-jewel assets and their value; Lares grounds each finding to them over observed reachability and attaches a loss band with its assumptions stated. Lares never invents a dollar figure.
Can you detect and respond on the clock? EU AI Act Art. 73 serious-incident reporting
NIS2 Art. 23 timelines
NIST AI RMF Manage
ISO/IEC 42001 incident handling
Evidence-backed findings with a response attached. Plain-English evidence, one recommended containment with a tested undo, tickets raised in Jira or ServiceNow, alert mirrors to your SIEM and email, and the who-did-what-when your incident report needs.
Are you still watching after deployment? EU AI Act Art. 26 and 72 post-market monitoring
NIST AI RMF Measure
Every agent is watched against its own learned normal. Behavior that quietly widens needs an explicit sign-off; it is never silently absorbed into the baseline. New agent versions re-learn under the same declared boundary.
In each framework's own words

Where Lares sits in your program.

EU AI Act

You as the deployer, Art. 26 lens
  • Oversight, monitoring and log duties fall on you even when the model is a vendor's. Lares evidences all three from your own traffic.
  • Human oversight is a person with authority, not a checkbox: the named verdict and owner routing are that person, on the record.
  • Art. 73's incident clock starts when you know. Detection with priced impact and an exportable record is how you know early and report cleanly.

NIST AI RMF

The four functions, operationally
  • Govern: the agent registry, owner accountability, and response policy you dial per asset class.
  • Map: the live inventory and the reachability join from each agent to the assets that matter.
  • Measure: continuous behavioral monitoring, drift needing sign-off, and the tamper-evident log.
  • Manage: graduated, reversible response, and dismissals feeding back into detection tuning.

ISO/IEC 42001

The operational layer of an AIMS
  • An AI management system needs an inventory, assigned roles, impact assessment, operational logging and incident handling.
  • Lares is the evidence layer under those clauses for the agents you run: the registry, owners, loss bands and the decision log map one-to-one.
  • Your policies and management review stay in your AIMS; Lares gives the auditor the operational records behind them.
Also relevant: NIS2 and DORA. Both treat AI agents as what they are, software with credentials inside your estate. NIS2's risk-management measures (Art. 21) and reporting timelines (Art. 23), and DORA's ICT incident management for financial entities, are served by the same evidence: the inventory, the tamper-evident log, and incident records with impact attached. If your regulator asks "how do you govern autonomous software acting on production systems", this crosswalk is the answer's spine.

Bring your auditor. Bring your counsel.

The fastest way to check this crosswalk is to watch the loop run: see an unregistered agent surface, claim its owner, confirm a finding, and export the record.