Control Tower v0.2.12

Compliance: EU AI Act, NIST AI RMF, ISO/IEC 42001

Compliance (Enterprise, admins) sets your AI coding assistants and agents against three frameworks, using what Control Tower records: your inventory, each agent's permissions, your gates and approvals, your logs and audit trail. It shows where each requirement stands, says what to do about the gaps, and produces an evidence pack to hand your assessor.

  • EU AI Act: Regulation (EU) 2024/1689. Record-keeping (Art. 12), human oversight (Art. 14), robustness and cybersecurity (Art. 15), the deployer duties of Art. 26 (oversight by competent people, monitoring, keeping logs at least six months), and the articles that are the organisation's to evidence (AI literacy, impact assessments, transparency).
  • NIST AI RMF 1.0 (NIST AI 100-1): the Govern, Measure and Manage subcategories a gateway gives evidence for, such as the AI system inventory (GOVERN 1.6), roles (GOVERN 2.1), security and resilience (MEASURE 2.7), and deactivation (MANAGE 2.4).
  • ISO/IEC 42001:2023: monitoring (9.1), internal audit (9.2), and the Annex A controls for roles (A.3.2), resources (A.4.2), operation and monitoring (A.6.2.6), event logs (A.6.2.8), responsible and intended use (A.9.2, A.9.4), and suppliers (A.10.3). ISO's text isn't public, so requirements are described in our own words: check them against your copy of the standard.

This is evidence for an assessment, not a certification or legal advice. Which obligations apply depends on your role (provider or deployer) and your systems' risk class.

Where each requirement stands

Each requirement is matched to checks computed from this installation's data for the period you choose (30 to 365 days):

CheckMet when
InventoryAgents and assistants go through Control Tower, and it lists them with the models, tools and people behind them
OwnershipEvery agent has an owner (Keys)
Least privilegeEvery active agent is limited to named models and tools
Human approvalAt least one gate asks a person before an action goes through
ApproversAt least two people can approve and intervene; nobody approves their own request
LoggingCalls are recorded, with who made them
Log retentionCalls are kept at least six months (CT_RETENTION_DAYS 183 or more, or 0)
Audit trailThe audit log's hash chain verifies
Copy outside Control TowerThe audit log is sent to your SIEM
Data protectionAn inspect gate checks what's sent to models and tools
IdentityPeople sign in through single sign-on
MonitoringAlert rules send to a channel
DeactivationEnforcement is on, so an agent, a laptop or a person can be stopped at once
SuppliersThe model providers in use are known, and agents reach no others through Control Tower

A requirement is met when all its checks are, partly met when some are, and a gap when one is. Requirements no gateway can evidence (an impact assessment, staff training) are shown as the organisation's, so the register is complete. Click a requirement for its checks and what to do next.

The evidence pack

Evidence pack downloads a Markdown document (print it to PDF, or paste it into your GRC tool's notes) for the framework and period on screen:

  • the register: each requirement, its status and the evidence;
  • each requirement in detail, with what to do about gaps;
  • the records: every agent with its owner, team and permissions, the apps people used, each agent's paths with requests, refusals and holds, the gates, who approved and denied, the audit chain's verification, retention, single sign-on and alerts.

JSON gives the same, for a GRC tool or a script. Each download is recorded in the audit log (compliance.evidence_exported) with who took it and the document's SHA-256 (also in the response's x-ct-sha256 header), so a copy handed to an assessor can be checked against it.

API

GET /admin/api/compliance?framework=eu-ai-act&days=90
GET /admin/api/compliance/evidence?framework=iso-42001&days=90&format=md|json

framework is eu-ai-act, nist-ai-rmf or iso-42001. Admins only; it needs an Enterprise license.