Compliance

Compliance is a byproduct of being the record.

Nobody buys attestation to pass an audit. But once an independent, signed, hash-chained account of agent behavior exists, the audit stops being a reconstruction project. Chain-of-custody proof exports straight to the auditor, instead of being rebuilt in a spreadsheet six months later.

/001 · WHY NOWREGULATION LANDS BEFORE THE TOOLING

The question shifts from can the agent act to can you prove what it did.

The EU AI Act, NIST AI RMF, ISO/IEC 42001, and SEC disclosure all arrive before the tooling does. Insurers are already precluding coverage for AI incidents without controls. A Fortune 500 will run 150,000+ agents by 2028, up from fewer than 15 in 2025.

You cannot observe your way to chain of custody.

An audit trail written by the actor is still the actor's account of itself.

/002 · THE FRAMEWORKSWHAT EXPORTS TO THE AUDITOR

Four regimes. One artifact.

Each of these asks a version of the same question, and the Decision Trace is the same answer in four formats. Nothing here requires a separate compliance module. It is the record, exported.

EU AI ACT

What it asks for. Record-keeping and automatic logging for high-risk AI systems, traceability of system behavior across its lifecycle, and human oversight that can be evidenced rather than asserted.

What Behavry hands over. A signed, hash-chained event stream per agent, per workflow, with delegation lineage back to a human principal. Because the ledger is append-only, the export proves completeness as well as integrity, which is the part a log file cannot do.

NIST AI RMF

What it asks for. Govern, Map, Measure, Manage. In practice the hard one is Measure: demonstrating that deployed AI behaves within its documented envelope, with evidence a third party can inspect.

What Behavry hands over. Behavioral trajectory per agent, deviation from its established baseline, and the policy decision attached to every consequential action. The measurement is a byproduct of enforcement, not a separate reporting exercise.

ISO/IEC 42001

What it asks for. An AI management system with documented controls, operational records, and internal audit evidence, in the same shape ISO 27001 asks for information security.

What Behavry hands over. The control is the OPA policy, the record is the Decision Trace, and the internal audit evidence is the ledger. All three are the same system, so the control and the evidence for the control never drift apart.

SEC DISCLOSURE

What it asks for. Timely, accurate disclosure of material cybersecurity incidents, and a description of the processes for assessing and managing them.

What Behavry hands over. Incident scope determined from the record rather than estimated from partial logs. When an agent crosses four systems at 2am, the trace already spans all four, which is the difference between a disclosure you can defend and one you are guessing at.

/003 · WHY THIS RECORD COUNTSINDEPENDENCE AND COMPLETENESS

Two properties an audit cannot do without.

Independent of the actor

Behavry signs the Decision Trace from a control plane the agent, its vendor, and your SIEM cannot reach. Finance has external auditors for the same reason: an actor cannot attest to itself, and a self-produced trail is testimony from the party under examination.

Proves completeness, not just integrity

Every entry carries the previous hash in an append-only ledger, so a removed or altered event breaks the chain. Nobody can hand an auditor a curated subset and call it the record. Selectively shown logs are exactly what an audit, an incident, or a courtroom cannot rely on.

WHO READS THE EXPORT/AUDIT evidence a director can rely on/LEGAL discovery becomes a retrieval, not a reconstruction/REGULATOR verifiable without our involvement/UNDERWRITER the evidence that lets you price the risk

/004 · VERIFYNO ACCOUNT · NO LOGIN · NO TRUST REQUIRED

Your auditor does not have to trust us either.

An auditor, a regulator, or an underwriter confirms any decision in the export without an account and without our involvement. That is the whole point of putting the signature outside the actor.

GET /api/v1/public/verify?hash=<event-hash>

200 OK
{ "verified": true }
VERIFY A TRACE → SOC 2 and ISO 27001 control mapping on /trust →

Say yes to autonomous agents. With proof.

BOOK A BRIEFING →