We do not sell regulatory panic. In 2026 the EU AI Act implementation timetable was amended by Regulation (EU) 2026/1744: obligations for Annex III high-risk systems now apply from 2 December 2027, and for Annex I systems from 2 August 2028 CLAIM: EXTERNAL VERIFICATION REQUIRED. Anyone telling you an analytics agent must be certified this quarter is selling something. What we sell instead: the earlier you have reproducible suites, invariant checks and versioned evidence trails, the cheaper every future internal audit, board review and statutory review becomes.
The mapping
| Framework | What it is | What in a bundle speaks to it | Our claim |
|---|---|---|---|
| NIST AI 100-1 AI Risk Management Framework 1.0 | Voluntary US framework: Govern, Map, Measure, Manage. | Consequence tiers and threat model (Map); invariant results with Wilson intervals, ICFY, RWAC (Measure); residual-risk acceptance formulation, recall protocol (Manage). | Evidence aligned to Measure and Manage. Earlier material cited NIST SP 1270 here by mistake; SP 1270 is Towards a Standard for Identifying and Managing Bias in AI (2022) and is not the RMF. |
| NIST AI 600-1 AI RMF: Generative AI Profile | Companion profile for generative systems. | Failure domains 13 (prompt injection), 14 (sensitive information exfiltration), 10 (catalog hallucination), 15 (cross-turn memory) map to the profile’s suggested actions on confabulation, data privacy and prompt injection. | Evidence aligned. Two of those four domains are still UNVALIDATED in our benchmark and the bundle says so. |
| NIST AI TEVV Testing, Evaluation, Verification & Validation | Empirical evaluation protocols from the NIST AI Resource Center. | Sequential testing policy, the sequestered calibration benchmark, the stratified Sev-1 gate. | Protocol adopted. |
| ISO/IEC 42001:2023 AI management system | Certifiable organisational management-system standard. | Bundles are the technical verification evidence an AIMS points to for controls on monitoring and validation of AI systems. | We are not ISO 42001 certified and a bundle does not make you so. ISO 42001 certifies organisational process, not individual query correctness. |
| IEEE 1012-2024 System, software and hardware V&V | The standard for independent verification and validation. | The Independence Charter (technical, managerial and financial independence), evidence traceability in the twelve-element assurance case. | Architected with reference to IEEE 1012 IV&V principles PENDING FORMAL THIRD-PARTY IV&V ACCREDITATION. |
| OWASP Top 10 for LLM Applications & AI Agent Security | Community threat catalogue. | Prompt injection, tool abuse, privilege escalation and memory poisoning are tested as failure domains 12, 13, 14, 15. | Coverage of the listed classes; not a penetration test. |
| EU AI Act Regulation (EU) 2024/1689 as amended by 2026/1744 | Risk-based statutory regime. | The assurance case is structured so its elements can populate Annex IV technical documentation where an analytics agent is in scope; role classification (provider vs deployer, Art. 3 / Art. 25) is assessed case by case and never assumed. | Readiness evidence only. Dates above for counsel to verify. |
Role classification, case by case
Whether an enterprise deploying a Cortex Agent is a “provider” or a “deployer” under the AI Act depends on actual modification and branding, not on a category. We assess it per engagement under a written protocol (Art. 3 and Art. 25) and record the conclusion in the assurance case. We do not classify by assumption, and we do not classify for you: that is a legal determination your counsel makes on our technical record.
What a bundle can and cannot do for an audit
Can
- Show that the agent was tested against a frozen, signed denominator on a stated date
- Show who reviewed what, with competency signatures and agreement statistics
- Show that a defect found was remediated and re-tested (the retest bundle references the original)
- Show the chain of custody: commitment, nonce, dual signature, notary record
Cannot
- Certify compliance with any statute or standard
- Replace the deployer’s own risk-management system
- Speak to domains marked UNVALIDATED beyond “defined and tested where present”
- Substitute for legal advice on role classification or deadlines