AI COMPLIANCE PLATFORM · EU AI ACT · ISO 42001 · NIST AI RMF

AI compliance built from the operational record.

Know what is in scope, classify the risk, record approvals and controls, and continuously turn live model and agent activity into evidence an auditor can inspect.

AI compliance breaks down when the inventory, risk assessment, policy and production evidence live in different systems. Teams then reconstruct the story manually: what the AI system was meant to do, who approved it, which controls applied and whether those controls actually ran.

Kosmoy keeps one connected record. AI use cases, systems, models, agents and owners define the scope. Risk classification and approvals define the obligations and policy. The AI Gateway and Action Capsules supply runtime evidence — calls, guardrail decisions, budgets, overrides, human review and agent actions.

Framework bundles map that same record to the EU AI Act, ISO/IEC 42001 and NIST AI RMF. A new framework changes the mapping and export, not the instrumentation. Human accountability stays explicit: the platform can automate collection and workflow, but it records rather than replaces legal interpretation and risk acceptance.


What it does.

Scoped AI inventory

Use cases, applications, models, agents, owners, providers, data classes and lifecycle state in one evidence base.

Risk and role classification

Qualification, operator role, risk tier and obligations linked directly to the system and its controls.

Approvals and accountability

Business, technical, risk and compliance decisions recorded with actor, time, scope and outcome.

Runtime control evidence

Gateway and Action Capsule events show which identity, guardrail, budget, route or containment policy actually ran.

Framework evidence bundles

EU AI Act, ISO/IEC 42001 and NIST AI RMF views generated from the same operational source record.

GRC and auditor hand-off

Export the evidence structure an assessor needs or feed the record into the enterprise's existing GRC workflow.


Enterprise buying criteria

What an AI compliance platform should prove.

A checklist can document intent. A compliance platform should also connect every requirement to an owned system, an active control and a verifiable production record.

Scope is complete

The platform can identify which models, agents, applications and use cases are in scope — including systems discovered after approval.

Obligations are traceable

Risk class, operator role and framework requirements link to the exact system, owner and decision history.

Controls are operational

Approvals, access, guardrails, budgets, human review and containment exist as active controls, not only policy statements.

Evidence is continuous

Runtime calls, policy events, overrides and agent actions enter the record as the system operates.

Human accountability is explicit

Legal interpretation, risk acceptance and final approvals remain attributed to named people and roles.

Auditors can follow the chain

Every claim in an export can be traced back to the underlying inventory record, decision or runtime event.


One evidence pipeline, multiple frameworks.

Inventory and classification establish the scope. Policy and runtime events establish what was controlled. Framework bundles organise the same facts for different assessors.

01

Inventory

Models, agents, applications, owners, providers and data classes.

02

Classify

Use case, operator role, risk tier and the obligations that follow.

03

Enforce

Approvals, access rules, guardrails, budgets and runtime boundaries.

04

Record

Calls, policy decisions, overrides, approvals and agent actions.

Evidence outputs

  • EU AI Act dossier
  • ISO/IEC 42001 evidence
  • NIST AI RMF mapping
  • GRC and auditor exports
One operational record feeds each framework. The report changes; the evidence pipeline does not.

Commercial clarity

Scope compliance around systems, controls and evidence

Commercial scope reflects the number and diversity of governed workloads, the framework bundles required, the deployment boundary and whether runtime enforcement is included alongside inventory and workflow.

See pricing and packaging

The main sizing factors

  • AI inventory and framework coverage
  • Number and complexity of governed systems and agents
  • Workflow, evidence and integration requirements
  • Runtime gateway or containment controls included

Module questions, answered straight.

What is an AI compliance platform?

An AI compliance platform connects the enterprise's AI inventory, risk classification, approvals, runtime controls and evidence. It should show which systems are in scope, what obligations apply, which controls are active, what happened in production and what an auditor can verify — without rebuilding the record from tickets and spreadsheets before every review.

Which AI compliance frameworks does Kosmoy support?

Kosmoy maps one operational record to the EU AI Act, ISO/IEC 42001 and NIST AI RMF. The framework bundle changes the control mapping and export structure; the underlying systems, owners, approvals, policy events and runtime evidence remain the same.

What is automated and what remains a human decision?

Kosmoy can continuously collect inventory and runtime evidence, apply configured policy, route approvals and map records into framework structures. Accountability, legal interpretation, risk acceptance and final approval remain human decisions. The platform records who made them, when and against which system.

How does Kosmoy classify AI systems under the EU AI Act?

A five-step workflow captures qualification, system information, operator role, risk class and the obligations that follow. The classification remains linked to the use case, owner, models, agents, controls and evidence rather than becoming a separate spreadsheet.

What does an auditor receive?

The export can include the scoped system inventory, ownership and approvals, risk classification, applicable controls, runtime and guardrail events, overrides, human-review records and evidence references arranged for the chosen framework. The same source events can also feed an existing GRC platform.

Does Kosmoy replace our GRC tool?

No. Kosmoy is the AI-specific operational evidence layer. It records what AI systems and agents exist, what policy governed them and what they did. Framework exports and integrations feed the enterprise's broader GRC, risk and audit processes.

Enterprise proof

Built for environments where AI cannot become another unmanaged SaaS silo.

Kosmoy works with regulated and operationally critical organizations, including Banca d’Italia and Leonardo.

Banca d'Italia
Leonardo
  • Runs in your Kubernetes
  • Azure · AWS · GCP · on-prem
  • LLM · MCP · A2A
  • No mandatory vendor-hosted control plane

Trace one AI system from approval to audit evidence.

Bring a real use case. We will walk through scope, risk classification, controls, runtime events and the resulting EU AI Act, ISO 42001 or NIST AI RMF evidence.

Or email sales@kosmoy.com.