The de-facto control vocabulary for agent security — the field manual auditors and procurement read against. Highest primitive-fit: its controls are inherently runtime.
The de-facto US financial-sector AI rulebook. FINRA's 2026 autonomous-agent guidance maps near 1:1 to our primitives.
The world's most consequential AI law; turnover-based fines. Art. 12 logging + Art. 19 log keeping + Art. 14 human oversight map directly to RECORD + ALLOW.
A federated framework whose binding controls are inherently runtime and decision-point — the hardest human-in-the-loop mandates.
The sharpest cross-cutting EU lever on agentic decisioning — and our single strongest fit. The AEPD 'rule of 2' reads like a runtime spec.
The world's first certifiable AI Management System standard. Our runtime layer is the control-execution + audit-evidence engine that earns the certificate.
The de-facto US governance baseline and the named safe harbor in Texas TRAIGA. The agentic extensions push our exact primitives to the center.
The de-facto US B2B SaaS procurement gate. Our continuous, signed telemetry is the natural evidence engine for a Type II program.
The most concrete EU supply-chain lever on agent/AI vendors selling into finance. In active enforcement; our RECORD/ISOLATE feed the Register + incident clock.
A fragmented patchwork regulating automated decision-making. The patchwork itself drives demand for a centralized, per-jurisdiction policy-enforcement layer.
With the AI Liability Directive withdrawn, the primary EU liability channel for autonomous-agent harm — and it converts our signed audit trail into a litigation defence.