top of page
big city with skyscrapers and airplane from below

Compliance overview

One control model.
Every jurisdiction.

AI regulation differs from country to country – but the underlying requirements are the same everywhere. EVEDY implements them as universal runtime controls and maps them to every jurisdiction you operate in.

COMPLYONCE: PROVE EVERYWHERE

What regulators demand worldwide

Whether it's the EU AI Act, Swiss privacy law, UK principles or US state statutes: the same core requirements recur across all frameworks. EVEDY enforces them once, centrally – and evidences them per country. This is an incomplete excerpt of the current compliance.

REGULATION

WHAT IT REQUIRES 

HOW EVEDY ENFORCES IT

Privacy & PII

In every jurisdiction: GDPR, revDSG, Privacy Acts, CCPA/CPRA and more

Lawful handling of personal data, data minimisation, security safeguards, individual rights.

Automatic PII redaction in prompts and responses, access control via your IAM, complete logging of every processing step.

Transparency & disclosure

Disclose AI use and automated decisions

Users and affected individuals must be able to tell where AI is involved and how decisions are made.

Marked automated decisions, disclosure policies per use case, documented decision paths.

Human oversight

Human control over consequential decisions

Critical or consequential AI outcomes require human control and the ability to intervene.

Real-time human-oversight escalation: defined cases are paused and routed to accountable owners for review.

Robustness & security

Protection against attacks, errors and unreliable outputs

AI systems must be secure, robust and controllable in their behaviour – across the entire lifecycle.

Jailbreak and prompt-injection detection, testing and evaluation of every version, continuous monitoring of non-deterministic behaviour.

Traceability & logging

Accountability towards regulators, auditors and courts

Who used which AI, when, for what – and with what result? That must be provable.

Tamper-evident audit trails per user, per agent and per regulation; export into your SIEM and audit systems.

Governance standards

ISO/IEC 42001, NIST AI RMF and your internal directives

A systematic AI management system with clear roles, processes and continuous improvement.

Standards and corporate policies are stored as machine-enforceable rules and applied automatically to every AI interaction.

As of August 2026. This overview does not constitute legal advice.

THE DIFFERENCE

From written policy to runtime enforcement

Most enterprises have AI policies. Very few can prove they are followed. EVEDY closes exactly that gap.

1

Capture the rules

Legal requirements and internal policies are modelled as machine-readable policies – synchronised from your GRC platform if you wish.

2

Enforce at runtime

Every request to a model or agent passes through EVEDY. Violations are blocked, corrected or escalated – in real time, not after the fact.

3

Prove compliance

Audit trails per user, per agent and per regulation give internal audit, the board and regulators defensible evidence at any time.

bottom of page