Which rulebook asks for what, and what KnowMyAgents answers today.

Honest scores, dated. No certification is claimed.

The dates — the only place on this site they appear

As of 22 September 2026 · re-verified monthly · owner: Shine Xavier, PrimeThoughts Innovation.

InstrumentDateWhat it means
EU AI Act — in force1 Aug 2024The clock started; obligations phase in from here.
EU AI Act — transparency duties (Art. 50)2 Aug 2026People must be told when they interact with an AI system.
EU AI Act — Art. 50(2) marking, legacy generative systems2 Dec 2026Generative systems already on the market before 2 Aug 2026 get until this date for the machine-readable marking duty only; every other Art. 50 obligation stays on the August date.
EU Digital Omnibus — in force27 Jul 2026Moved the high-risk deadlines below.
EU AI Act — Annex III high-risk obligations2 Dec 2027Record-keeping (Art. 12) and human oversight (Art. 14) become enforceable for Annex III systems.
EU AI Act — Annex I high-risk obligations2 Aug 2028The same duties for product-embedded AI.
EU AI Act — deployer log retention (Art. 26)≥ 6 monthsDeployers keep the automatically generated logs.
EU AI Act — penaltiesup to 7 %Of global turnover, for the most serious breaches.
EC-Council Agentic-AI Defence & Governance (ADG)29 May 2026Launched, with twelve minimum controls for agents.
OWASP Top 10 for Agentic Applications9 Dec 2025Released.
Singapore IMDA MGF for Agentic AI22 Jan 2026Published; updated 20 May 2026.
India — DPDP Rules notified13–14 Nov 2025The DPDP Act's operating rules.
US — AI Kill Switch Act23 Jul 2026Introduced. Not passed.

Framework by framework · all requirements → in-scope requirements

Two scores per rulebook: first against everything it asks — including duties no identity layer can own, like model testing — then against the requirements an identity-and-governance layer can be responsible for. The first keeps us honest; the second says how well we do the job we claim. Every score is a link to the method and the requirement-by-requirement table in the scorecard PDF.

Demands of agents
Automatic event recording (Art. 12), human oversight that can interrupt (Art. 14), transparency to people (Art. 50).
Covered today
Per-agent identity, hash-chained tamper-evident records, revocation as the interrupt, the responsible human on every log line.
Not covered
Model-level duties: risk classification of your system, conformity assessment, technical documentation of the model itself.
Evidence you can export
The per-agent record with its hash chain, from your own machine.
EC-Council ADG — twelve minimum controls47 % · 67 % · identity surface 100 %
Demands of agents
Identity, least privilege, kill switch, audit, and eight more controls across the agent lifecycle.
Covered today
Every identity-surface control: one passport per agent, proof of key possession per call, one-revocation stop, attributed records.
Not covered
Controls that live inside the agent or its training: memory hygiene, tool-supply-chain vetting, model red-teaming.
Evidence you can export
The inventory of agents and their passports; refusal and admission history per agent.
NIST AI RMF58 % · 67 %
Demands of agents
Govern, map, measure, manage: know what is running, bound it, and be able to show both.
Covered today
The live inventory (including unregistered callers), rules checked on every call, the attributed record.
Not covered
Measurement of model behaviour: accuracy, bias, robustness testing.
Evidence you can export
The agent inventory and per-agent decision history.
ISO/IEC 4200154 % · 72 %
Demands of agents
An AI management system: roles, controls, operational records, continual review.
Covered today
The operational-control layer: named responsibility per agent, enforced limits, reviewable records.
Not covered
The management system itself — policies, impact assessments, audits are yours to run.
Evidence you can export
Operating records for the controls this layer enforces.
OWASP Agentic Top 1053 % · 81 %
Demands of agents
Defences against the ten agentic risks, from identity abuse to unbounded autonomy.
Covered today
The identity-and-authorisation risks: credential theft (key-bound passports), impersonation (per-call proof), runaway agents (budgets, revocation).
Not covered
Risks inside the prompt-and-model loop: injection resistance, memory poisoning.
Evidence you can export
Refusal telemetry: what was attempted and turned away.
Identity standards — NIST SP 800-63-4, eIDAS 2.089 %
Demands of agents
Verifiable identity, proof of possession, revocation, selective disclosure.
Covered today
The same rails the EU digital wallet runs on — SD-JWT credentials, DID anchoring, status lists — applied to agents.
Not covered
Human identity proofing; people stay in your existing directory.
Evidence you can export
Each passport and its verification result.
GDPR and India's DPDP Act50 % · 75 %
Demands of agents
Accountability for automated processing, data minimisation, records of processing.
Covered today
Attribution of every agent action to a responsible human; call content never leaves your network, so the processing record stays yours.
Not covered
Lawful-basis analysis, consent management, subject-rights workflows.
Evidence you can export
Per-agent processing records from your own machine.
DORA and NIS258 % · 67 %
Demands of agents
Operational resilience: know your ICT actors, contain incidents, keep evidence.
Covered today
Stopping one agent everywhere in minutes without rotating keys; enforcement that survives the console going dark; the tamper-evident record.
Not covered
Incident-reporting workflows and third-party risk management.
Evidence you can export
The containment history: what was revoked, when, and what it stopped.
Singapore MGF for Agentic AI67 %
Demands of agents
Human accountability, bounded autonomy, observability across the agent lifecycle.
Covered today
The named human per agent, budgets and rules as the bounds, the record as the observability.
Not covered
Testing and assurance of agent behaviour before deployment.
Evidence you can export
The accountability chain per agent, exportable.

Scored 0 to 3 per requirement against the pilot kit, September 2026. A self-assessment, not an audit. No single product satisfies a whole rulebook.

What we do not claim

Download the rulebooks scorecard (PDF) The DPA Privacy