Scope is complete
The platform can identify which models, agents, applications and use cases are in scope — including systems discovered after approval.
AI COMPLIANCE PLATFORM · EU AI ACT · ISO 42001 · NIST AI RMF
Know what is in scope, classify the risk, record approvals and controls, and continuously turn live model and agent activity into evidence an auditor can inspect.
Or email sales@kosmoy.com.
AI compliance breaks down when the inventory, risk assessment, policy and production evidence live in different systems. Teams then reconstruct the story manually: what the AI system was meant to do, who approved it, which controls applied and whether those controls actually ran.
Kosmoy keeps one connected record. AI use cases, systems, models, agents and owners define the scope. Risk classification and approvals define the obligations and policy. The AI Gateway and Action Capsules supply runtime evidence — calls, guardrail decisions, budgets, overrides, human review and agent actions.
Framework bundles map that same record to the EU AI Act, ISO/IEC 42001 and NIST AI RMF. A new framework changes the mapping and export, not the instrumentation. Human accountability stays explicit: the platform can automate collection and workflow, but it records rather than replaces legal interpretation and risk acceptance.
Use cases, applications, models, agents, owners, providers, data classes and lifecycle state in one evidence base.
Qualification, operator role, risk tier and obligations linked directly to the system and its controls.
Business, technical, risk and compliance decisions recorded with actor, time, scope and outcome.
Gateway and Action Capsule events show which identity, guardrail, budget, route or containment policy actually ran.
EU AI Act, ISO/IEC 42001 and NIST AI RMF views generated from the same operational source record.
Export the evidence structure an assessor needs or feed the record into the enterprise's existing GRC workflow.
Enterprise buying criteria
A checklist can document intent. A compliance platform should also connect every requirement to an owned system, an active control and a verifiable production record.
The platform can identify which models, agents, applications and use cases are in scope — including systems discovered after approval.
Risk class, operator role and framework requirements link to the exact system, owner and decision history.
Approvals, access, guardrails, budgets, human review and containment exist as active controls, not only policy statements.
Runtime calls, policy events, overrides and agent actions enter the record as the system operates.
Legal interpretation, risk acceptance and final approvals remain attributed to named people and roles.
Every claim in an export can be traced back to the underlying inventory record, decision or runtime event.
Inventory and classification establish the scope. Policy and runtime events establish what was controlled. Framework bundles organise the same facts for different assessors.
Models, agents, applications, owners, providers and data classes.
Use case, operator role, risk tier and the obligations that follow.
Approvals, access rules, guardrails, budgets and runtime boundaries.
Calls, policy decisions, overrides, approvals and agent actions.
Evidence outputs
Commercial clarity
Commercial scope reflects the number and diversity of governed workloads, the framework bundles required, the deployment boundary and whether runtime enforcement is included alongside inventory and workflow.
The main sizing factors
An AI compliance platform connects the enterprise's AI inventory, risk classification, approvals, runtime controls and evidence. It should show which systems are in scope, what obligations apply, which controls are active, what happened in production and what an auditor can verify — without rebuilding the record from tickets and spreadsheets before every review.
Kosmoy maps one operational record to the EU AI Act, ISO/IEC 42001 and NIST AI RMF. The framework bundle changes the control mapping and export structure; the underlying systems, owners, approvals, policy events and runtime evidence remain the same.
Kosmoy can continuously collect inventory and runtime evidence, apply configured policy, route approvals and map records into framework structures. Accountability, legal interpretation, risk acceptance and final approval remain human decisions. The platform records who made them, when and against which system.
A five-step workflow captures qualification, system information, operator role, risk class and the obligations that follow. The classification remains linked to the use case, owner, models, agents, controls and evidence rather than becoming a separate spreadsheet.
The export can include the scoped system inventory, ownership and approvals, risk classification, applicable controls, runtime and guardrail events, overrides, human-review records and evidence references arranged for the chosen framework. The same source events can also feed an existing GRC platform.
No. Kosmoy is the AI-specific operational evidence layer. It records what AI systems and agents exist, what policy governed them and what they did. Framework exports and integrations feed the enterprise's broader GRC, risk and audit processes.
Enterprise proof
Kosmoy works with regulated and operationally critical organizations, including Banca d’Italia and Leonardo.


Bring a real use case. We will walk through scope, risk classification, controls, runtime events and the resulting EU AI Act, ISO 42001 or NIST AI RMF evidence.
Or email sales@kosmoy.com.