← Primust · Compliance

The regulator's language is cryptographic evidence.

Primust binds governed runs to regulatory bundles and framework mappings, then emits evidence another party can verify independently.

§ 01Premise

The regulator's language is cryptographic evidence, not logs.

Every regulated surface — AI, finance, healthcare, operational resilience — asks the same underlying question: how do we know the declared controls actually ran? A screenshot, a dashboard, or a self-reported log can't answer it. A VPEC can.

Primust ships named regulatory bundles and framework mappings. Each one binds governed runs to specific articles, rules, or control objectives. One click in the dashboard binds your runs to the ones that apply.

§ 02Featured

EU AI Act. High-risk rules phase in August 2, 2026.

Under the current EU implementation timeline, high-risk AI system obligations for Annex III systems and transparency rules apply from August 2, 2026. The eu_ai_act_art12_v1 bundle maps to Articles 9, 10, 12, 13, 14, and 17 — so every governed run produces a VPEC with the correct regulatory context, retention policy, and risk classification baked in.

A notified body or auditor may ask for evidence stronger than self-reported logs. Primust produces cryptographic evidence they can verify independently.

View Article map ↓
Bundle · eu_ai_act_art12_v1
coversArts 9, 10, 12, 13, 14, 17
retention10 years
risk classEU_HIGH_RISK
floorExecution
§ 03Annex III scope

If your AI does any of these, you need a real evidence path.

The EU AI Act example matters because the affected workflows are ordinary enterprise workflows: credit, insurance, hiring, education, infrastructure, public-sector decisions, and other high-impact systems.

01
Credit scoring and creditworthiness
02
Employment and worker management
03
Access to education
04
Essential services and insurance
05
Biometric identification
06
Critical infrastructure
07
Law enforcement
08
Migration and border control
09
Administration of justice
10
Democratic processes
§ 04The gap

What you have. What reviewers need.

What the obligation asks for
Records tied to specific lifecycle events
Inputs and outputs sufficient to identify risk
Human oversight and quality-management evidence
Retention long enough for later supervisory review
What teams usually have
Mutable application logs operated by the same team
Dashboard screenshots and exported CSVs
Vendor or internal attestations written after the fact
Point-in-time audit reports that do not bind each run
What Primust produces
Signed VPEC per governed run
Committed inputs, outputs, controls, and gaps
Proof floor and provable surface carried in the artifact
Evidence Packs assembled from credentials the reviewer can verify
§ 05EU AI Act map

Map Articles 9, 10, 12, 13, 14, and 17 to the evidence Primust emits.

The EU AI Act is the detailed example because it shows the shape of the product: declared controls, automatic records, input commitments, human oversight, retention, and a verifier another party can run offline.

Article
Requirement
Primust evidence
Level
Art. 9
Risk management system with ongoing monitoring
VPEC per governed run, with declared controls and gaps attached to the run record
Execution
Art. 10
Data governance and quality criteria
input_commitment_hash and dataset/control commitments without disclosing raw data
Mathematical
Art. 12
Automatic event logging throughout lifecycle
signed VPECs with independent timestamps and verifier-readable event fields
Execution
Art. 12(1)(b)
Input data records sufficient to identify risk
input commitments tied to the specific run, policy pack, and credential timestamp
Mathematical
Art. 13
Transparency and capability disclosure
provable_surface_breakdown and explicit gap ledger for what was and was not proven
Execution
Art. 14
Human oversight capacity
Witnessed proof when reviewer identity, decision, and timestamp are part of the run
Witnessed
Art. 17
Quality management record-keeping
period Evidence Packs assembled from VPECs and mapped to the approved control plan
Execution
§ 06Regulations

Regulatory bundles and framework mappings. One binding model.

Install and bind with primust init --policy <bundle_id> — or select interactively in the dashboard setup flow at app.primust.com/setup/regulations.

AI governance
EU AI Act
eu_ai_act_art12_v1
Articles 9, 10, 12, 13, 14, and 17 for high-risk AI systems.
NIST AI RMF
nist_ai_rmf_v1
Govern, map, measure, and manage controls for AI systems.
mapped
ISO/IEC 42001
iso_42001_v1
AI management-system controls, evidence packs, and governance records.
mapped
AIUC-1
aiuc1_v1
Enterprise AI use controls across model, agent, and tool-call surfaces.
mapped
OWASP Agentic AI
owasp_agentic_v1
Prompt injection, tool abuse, excessive agency, and containment evidence.
mapped
Financial services
SOC 2 Type II
soc2_security_v1
Security, availability, processing integrity, confidentiality, and privacy evidence.
mapped
AML / BSA / FinCEN
aml_bsa_v1
Sanctions screening, SAR lineage, and financial-crime control execution.
mapped
OCC / Fed / FDIC model risk
model_risk_v1
Model validation, fraud controls, and decision governance evidence.
mapped
CFPB / ECOA / Reg B
ecoa_reg_b_v1
Equal credit opportunity and adverse-action decision evidence without model disclosure.
mapped
GDPR Art. 22
gdpr_art22_v1
Automated decision basis and data-protection evidence with content-blind commitments.
mapped
DORA
dora_ict_v1
ICT risk management, operational resilience, and third-party dependency proof.
mapped
Insurance
NAIC AI Bulletin
naic_ai_bulletin_v1
Insurance AI governance, unfair-discrimination controls, and model-use evidence.
mapped
FINRA Reg BI / Rule 2111
finra_suitability_v1
Suitability and best-interest review evidence without disclosing customer profile data.
mapped
Insurance underwriting
insurance_underwriting_v1
Risk selection, pricing, claims adjudication, and underwriter workflow evidence.
mapped
Healthcare, pharma, and clinical
HIPAA
hipaa_security_v1
PHI access governance and privacy/security evidence without PHI transfer.
mapped
FDA 21 CFR Part 11
fda_part11_v1
Electronic records, signatures, audit trails, and retention evidence.
mapped
GCP / GMP
gxp_controls_v1
Clinical-trial, manufacturing, and batch-release control execution evidence.
mapped
FDA SaMD / EU MDR
samd_mdr_v1
AI diagnostic and software-as-medical-device governance records.
mapped
US state and workforce AI
Colorado AI Act
colorado_ai_v1
Consequential-decision risk management and impact-assessment evidence.
mapped
CCPA / CPRA
ccpa_cpra_v1
Privacy, automated-decision, access, and opt-out evidence.
mapped
NYC Local Law 144
nyc_ll144_v1
Automated employment decision tool audit and notice evidence.
mapped
Government, defense, and procurement
Federal AI procurement
federal_ai_procurement_v1
AI component provenance, model hash commitments, and supplier governance evidence.
mapped
Agency AI governance
agency_ai_governance_v1
AI safety, provenance, and declared control execution evidence for public-sector review.
mapped
Supply-chain integrity
supply_chain_v1
Dependency, vendor, and procurement control evidence tied to the run.
mapped
§ 07How it works

Select. Bind. Every governed run is evidence.

  1. Select bundles — in the dashboard setup flow, check every regulation that applies to your operating surface.
  2. Review the Obligation Plan — Primust compiles your selections into an explicit obligation + control map. Approve or waive each line, with rationale.
  3. Bind at the SDKprimust init picks up the approved control plan; every VPEC is stamped with the bundle hash and the regulations it satisfies.
  4. Ship the Evidence Pack — period-level assembly of VPECs into a signed PDF the regulator can verify offline.
# bind multiple bundles
$ primust init \
--policy eu_ai_act_art12_v1 \
--policy hipaa_privacy_v1 \
--policy soc2_security_v1
 
# assemble a period Evidence Pack
$ primust pack assemble \
--period 2026-Q2 \
--audience notified_body
§ 08Start

First compliance-bound VPEC in five minutes.

pip install primust && primust init. Sandbox key is free and unlimited. Swap to pk_live_ when you're ready to ship audit-grade evidence.