Which rulebook asks for what, and what KnowMyAgents answers today.
Honest scores, dated. No certification is claimed.
The dates — the only place on this site they appear
As of 22 September 2026 · re-verified monthly · owner: Shine Xavier, PrimeThoughts Innovation.
| Instrument | Date | What it means |
|---|---|---|
| EU AI Act — in force | 1 Aug 2024 | The clock started; obligations phase in from here. |
| EU AI Act — transparency duties (Art. 50) | 2 Aug 2026 | People must be told when they interact with an AI system. |
| EU AI Act — Art. 50(2) marking, legacy generative systems | 2 Dec 2026 | Generative systems already on the market before 2 Aug 2026 get until this date for the machine-readable marking duty only; every other Art. 50 obligation stays on the August date. |
| EU Digital Omnibus — in force | 27 Jul 2026 | Moved the high-risk deadlines below. |
| EU AI Act — Annex III high-risk obligations | 2 Dec 2027 | Record-keeping (Art. 12) and human oversight (Art. 14) become enforceable for Annex III systems. |
| EU AI Act — Annex I high-risk obligations | 2 Aug 2028 | The same duties for product-embedded AI. |
| EU AI Act — deployer log retention (Art. 26) | ≥ 6 months | Deployers keep the automatically generated logs. |
| EU AI Act — penalties | up to 7 % | Of global turnover, for the most serious breaches. |
| EC-Council Agentic-AI Defence & Governance (ADG) | 29 May 2026 | Launched, with twelve minimum controls for agents. |
| OWASP Top 10 for Agentic Applications | 9 Dec 2025 | Released. |
| Singapore IMDA MGF for Agentic AI | 22 Jan 2026 | Published; updated 20 May 2026. |
| India — DPDP Rules notified | 13–14 Nov 2025 | The DPDP Act's operating rules. |
| US — AI Kill Switch Act | 23 Jul 2026 | Introduced. Not passed. |
Framework by framework · all requirements → in-scope requirements
Two scores per rulebook: first against everything it asks — including duties no identity layer can own, like model testing — then against the requirements an identity-and-governance layer can be responsible for. The first keeps us honest; the second says how well we do the job we claim. Every score is a link to the method and the requirement-by-requirement table in the scorecard PDF.
EU AI Act52 % · 75 %
- Demands of agents
- Automatic event recording (Art. 12), human oversight that can interrupt (Art. 14), transparency to people (Art. 50).
- Covered today
- Per-agent identity, hash-chained tamper-evident records, revocation as the interrupt, the responsible human on every log line.
- Not covered
- Model-level duties: risk classification of your system, conformity assessment, technical documentation of the model itself.
- Evidence you can export
- The per-agent record with its hash chain, from your own machine.
EC-Council ADG — twelve minimum controls47 % · 67 % · identity surface 100 %
- Demands of agents
- Identity, least privilege, kill switch, audit, and eight more controls across the agent lifecycle.
- Covered today
- Every identity-surface control: one passport per agent, proof of key possession per call, one-revocation stop, attributed records.
- Not covered
- Controls that live inside the agent or its training: memory hygiene, tool-supply-chain vetting, model red-teaming.
- Evidence you can export
- The inventory of agents and their passports; refusal and admission history per agent.
NIST AI RMF58 % · 67 %
- Demands of agents
- Govern, map, measure, manage: know what is running, bound it, and be able to show both.
- Covered today
- The live inventory (including unregistered callers), rules checked on every call, the attributed record.
- Not covered
- Measurement of model behaviour: accuracy, bias, robustness testing.
- Evidence you can export
- The agent inventory and per-agent decision history.
ISO/IEC 4200154 % · 72 %
- Demands of agents
- An AI management system: roles, controls, operational records, continual review.
- Covered today
- The operational-control layer: named responsibility per agent, enforced limits, reviewable records.
- Not covered
- The management system itself — policies, impact assessments, audits are yours to run.
- Evidence you can export
- Operating records for the controls this layer enforces.
OWASP Agentic Top 1053 % · 81 %
- Demands of agents
- Defences against the ten agentic risks, from identity abuse to unbounded autonomy.
- Covered today
- The identity-and-authorisation risks: credential theft (key-bound passports), impersonation (per-call proof), runaway agents (budgets, revocation).
- Not covered
- Risks inside the prompt-and-model loop: injection resistance, memory poisoning.
- Evidence you can export
- Refusal telemetry: what was attempted and turned away.
Identity standards — NIST SP 800-63-4, eIDAS 2.089 %
- Demands of agents
- Verifiable identity, proof of possession, revocation, selective disclosure.
- Covered today
- The same rails the EU digital wallet runs on — SD-JWT credentials, DID anchoring, status lists — applied to agents.
- Not covered
- Human identity proofing; people stay in your existing directory.
- Evidence you can export
- Each passport and its verification result.
GDPR and India's DPDP Act50 % · 75 %
- Demands of agents
- Accountability for automated processing, data minimisation, records of processing.
- Covered today
- Attribution of every agent action to a responsible human; call content never leaves your network, so the processing record stays yours.
- Not covered
- Lawful-basis analysis, consent management, subject-rights workflows.
- Evidence you can export
- Per-agent processing records from your own machine.
DORA and NIS258 % · 67 %
- Demands of agents
- Operational resilience: know your ICT actors, contain incidents, keep evidence.
- Covered today
- Stopping one agent everywhere in minutes without rotating keys; enforcement that survives the console going dark; the tamper-evident record.
- Not covered
- Incident-reporting workflows and third-party risk management.
- Evidence you can export
- The containment history: what was revoked, when, and what it stopped.
Singapore MGF for Agentic AI67 %
- Demands of agents
- Human accountability, bounded autonomy, observability across the agent lifecycle.
- Covered today
- The named human per agent, budgets and rules as the bounds, the record as the observability.
- Not covered
- Testing and assurance of agent behaviour before deployment.
- Evidence you can export
- The accountability chain per agent, exportable.
Scored 0 to 3 per requirement against the pilot kit, September 2026. A self-assessment, not an audit. No single product satisfies a whole rulebook.
What we do not claim
- No certification is held — none is claimed, here or anywhere.
- Evidence-pack export is designed, not shipped.
- The product has no opinion on fairness testing, model evaluation or training data.