# Compliance

Source: https://www.primust.com/compliance
HTML title: Compliance And Regulations — Primust
Meta description: Primust maps governed runs to regulatory bundles and framework obligations including EU AI Act, SOC 2, HIPAA, FDA Part 11, AML/BSA, GDPR, DORA, NIST AI RMF, and ISO 42001.

← Primust · Compliance
# The regulator's language is _cryptographic evidence_.

Primust binds governed runs to regulatory bundles and framework mappings, then emits evidence another party can verify independently.

§ 01 — Premise

## The regulator's language is _cryptographic evidence_, not logs.

Every regulated surface — AI, finance, healthcare, operational resilience — asks the same underlying question: _how do we know the declared controls actually ran?_ A screenshot, a dashboard, or a self-reported log can't answer it. A VPEC can.

Primust ships named regulatory bundles and framework mappings. Each one binds governed runs to specific articles, rules, or control objectives. One click in the dashboard binds your runs to the ones that apply.

§ 02 — Featured

## EU AI Act. _High-risk rules phase in August 2, 2026._

Under the current EU implementation timeline, high-risk AI system obligations for Annex III systems and transparency rules apply from August 2, 2026. The `eu_ai_act_art12_v1` bundle maps to Articles 9, 10, 12, 13, 14, and 17 — so every governed run produces a VPEC with the correct regulatory context, retention policy, and risk classification baked in.

A notified body or auditor may ask for evidence stronger than self-reported logs. Primust produces cryptographic evidence they can verify independently.

View Article map ↓

Bundle · eu_ai_act_art12_v1

covers Arts 9, 10, 12, 13, 14, 17

retention 10 years

risk class EU_HIGH_RISK

floor Execution

§ 03 — Annex III scope

## If your AI does any of these, _you need a real evidence path._

The EU AI Act example matters because the affected workflows are ordinary enterprise workflows: credit, insurance, hiring, education, infrastructure, public-sector decisions, and other high-impact systems.

01

Credit scoring and creditworthiness

02

Employment and worker management

03

Access to education

04

Essential services and insurance

05

Biometric identification

06

Critical infrastructure

07

Law enforcement

08

Migration and border control

09

Administration of justice

10

Democratic processes

§ 04 — The gap

## What you have. _What reviewers need._

What the obligation asks for

Records tied to specific lifecycle events

Inputs and outputs sufficient to identify risk

Human oversight and quality-management evidence

Retention long enough for later supervisory review

What teams usually have

Mutable application logs operated by the same team

Dashboard screenshots and exported CSVs

Vendor or internal attestations written after the fact

Point-in-time audit reports that do not bind each run

What Primust produces

Signed VPEC per governed run

Committed inputs, outputs, controls, and gaps

Proof floor and provable surface carried in the artifact

Evidence Packs assembled from credentials the reviewer can verify

§ 05 — EU AI Act map

## Map Articles 9, 10, 12, 13, 14, and 17 _to the evidence Primust emits._

The EU AI Act is the detailed example because it shows the shape of the product: declared controls, automatic records, input commitments, human oversight, retention, and a verifier another party can run offline.

Article

Requirement

Primust evidence

Level

Art. 9

Risk management system with ongoing monitoring

VPEC per governed run, with declared controls and gaps attached to the run record

Execution

Art. 10

Data governance and quality criteria

input_commitment_hash and dataset/control commitments without disclosing raw data

Mathematical

Art. 12

Automatic event logging throughout lifecycle

signed VPECs with independent timestamps and verifier-readable event fields

Execution

Art. 12(1)(b)

Input data records sufficient to identify risk

input commitments tied to the specific run, policy pack, and credential timestamp

Mathematical

Art. 13

Transparency and capability disclosure

provable_surface_breakdown and explicit gap ledger for what was and was not proven

Execution

Art. 14

Human oversight capacity

Witnessed proof when reviewer identity, decision, and timestamp are part of the run

Witnessed

Art. 17

Quality management record-keeping

period Evidence Packs assembled from VPECs and mapped to the approved control plan

Execution

§ 06 — Regulations

## Regulatory bundles and framework mappings. _One binding model._

Install and bind with `primust init --policy ` — or select interactively in the dashboard setup flow at `app.primust.com/setup/regulations`.

AI governance

EU AI Act

eu_ai_act_art12_v1

Articles 9, 10, 12, 13, 14, and 17 for high-risk AI systems.

article map ↓

NIST AI RMF

nist_ai_rmf_v1

Govern, map, measure, and manage controls for AI systems.

mapped

ISO/IEC 42001

iso_42001_v1

AI management-system controls, evidence packs, and governance records.

mapped

AIUC-1

aiuc1_v1

Enterprise AI use controls across model, agent, and tool-call surfaces.

mapped

OWASP Agentic AI

owasp_agentic_v1

Prompt injection, tool abuse, excessive agency, and containment evidence.

mapped

Financial services

SOC 2 Type II

soc2_security_v1

Security, availability, processing integrity, confidentiality, and privacy evidence.

mapped

AML / BSA / FinCEN

aml_bsa_v1

Sanctions screening, SAR lineage, and financial-crime control execution.

mapped

OCC / Fed / FDIC model risk

model_risk_v1

Model validation, fraud controls, and decision governance evidence.

mapped

CFPB / ECOA / Reg B

ecoa_reg_b_v1

Equal credit opportunity and adverse-action decision evidence without model disclosure.

mapped

GDPR Art. 22

gdpr_art22_v1

Automated decision basis and data-protection evidence with content-blind commitments.

mapped

DORA

dora_ict_v1

ICT risk management, operational resilience, and third-party dependency proof.

mapped

Insurance

NAIC AI Bulletin

naic_ai_bulletin_v1

Insurance AI governance, unfair-discrimination controls, and model-use evidence.

mapped

FINRA Reg BI / Rule 2111

finra_suitability_v1

Suitability and best-interest review evidence without disclosing customer profile data.

mapped

Insurance underwriting

insurance_underwriting_v1

Risk selection, pricing, claims adjudication, and underwriter workflow evidence.

mapped

Healthcare, pharma, and clinical

HIPAA

hipaa_security_v1

PHI access governance and privacy/security evidence without PHI transfer.

mapped

FDA 21 CFR Part 11

fda_part11_v1

Electronic records, signatures, audit trails, and retention evidence.

mapped

GCP / GMP

gxp_controls_v1

Clinical-trial, manufacturing, and batch-release control execution evidence.

mapped

FDA SaMD / EU MDR

samd_mdr_v1

AI diagnostic and software-as-medical-device governance records.

mapped

US state and workforce AI

Colorado AI Act

colorado_ai_v1

Consequential-decision risk management and impact-assessment evidence.

mapped

CCPA / CPRA

ccpa_cpra_v1

Privacy, automated-decision, access, and opt-out evidence.

mapped

NYC Local Law 144

nyc_ll144_v1

Automated employment decision tool audit and notice evidence.

mapped

Government, defense, and procurement

Federal AI procurement

federal_ai_procurement_v1

AI component provenance, model hash commitments, and supplier governance evidence.

mapped

Agency AI governance

agency_ai_governance_v1

AI safety, provenance, and declared control execution evidence for public-sector review.

mapped

Supply-chain integrity

supply_chain_v1

Dependency, vendor, and procurement control evidence tied to the run.

mapped

§ 07 — How it works

## Select. Bind. _Every governed run is evidence._

- **Select bundles** — in the dashboard setup flow, check every regulation that applies to your operating surface.
- **Review the Obligation Plan** — Primust compiles your selections into an explicit obligation + control map. Approve or waive each line, with rationale.
- **Bind at the SDK** — `primust init` picks up the approved control plan; every VPEC is stamped with the bundle hash and the regulations it satisfies.
- **Ship the Evidence Pack** — period-level assembly of VPECs into a signed PDF the regulator can verify offline.

# bind multiple bundles

$ primust init \

--policy eu_ai_act_art12_v1 \

--policy hipaa_privacy_v1 \

--policy soc2_security_v1

 

# assemble a period Evidence Pack

$ primust pack assemble \

--period 2026-Q2 \

--audience notified_body

§ 08 — Start

## First compliance-bound VPEC _in five minutes._

`pip install primust && primust init`. Sandbox key is free and unlimited. Swap to `pk_live_` when you're ready to ship audit-grade evidence.

Get started free Book a compliance review →
