Governance & Compliance
VeriSwarm maps to 27 compliance frameworks out of the box — federal AI (EU AI Act, NIST AI RMF, ISO 42001, OWASP), the US state AI wave, healthcare SUD records, insurance (NAIC + Colorado DOI), financial services (NYDFS, SEC, CFPB, OCC), legal tech (ABA + FRCP), and consumer-facing AI (CA SB 243, CA AI Transparency, FTC §5). Per-tenant reports via API — hand them to your auditor, not your engineering team. One attestation export across every framework and every model your fleet runs on.
For the record-keeping obligation most teams underestimate, see how VeriSwarm maps to EU AI Act Article 12’s logging requirement specifically.
The definitive security risk list for AI agent systems. VeriSwarm maps to all 10 risks — 7 fully covered, 3 partial with a documented roadmap.
GET /v1/compliance/owasp-attestationFull coverage map→EU regulation on artificial intelligence. Article 50 transparency (AI-interaction and principal disclosure, synthetic-content marking) and GPAI enforcement are live as of August 2, 2026. High-risk Annex III obligations apply December 2, 2027 and Annex I embedded-product obligations August 2, 2028, per the Digital Omnibus on AI (Reg. (EU) 2026/1744, in force July 27, 2026).
GET /v1/compliance/eu-ai-actTake the EU check→Repealed-and-reenacted by SB 26-189: a transparency + consumer-rights regime over 'covered ADMT' (automated decision-making technology) that materially influences a consequential decision. Pre-use notice, post-adverse-outcome explanation, meaningful human review, and 3-year recordkeeping. Operative compliance date 2027-01-01. Enforcement of the predecessor regime is stayed pending xAI v. Weiser (D. Colo.); the 2027-01-01 operative date stands but carries litigation risk.
GET /v1/compliance/colorado-ai-actTake the Colorado check→Consolidated coverage for eleven state conversational-AI safety laws (NE, WA, ID, OR, HI, CO, TN, WY, RI, GA, IA). Disclosure, crisis intervention, minor protections, and companion-chatbot safeguards — Hawaii, Tennessee, Wyoming, and Colorado obligations are already live.
GET /v1/compliance/us-state-conversational-aiEffective 2026-04-17New York's transparency and incident-reporting framework for large frontier-model developers. 72-hour and 24-hour critical-incident windows.
GET /v1/compliance/ny-raise-actEffective 2027-01-01First in force of the new wave. Annual framework, pre-deployment transparency reports, 15-day / 24-hour incident reporting, and whistleblower protections. Civil penalties up to $1M per violation.
GET /v1/compliance/california-sb-53Effective 2026-01-01Illinois's AI Safety Measures Act — the first state law mandating an annual independent third-party AI safety audit for large frontier developers, paired with a catastrophic-risk safety framework and critical-incident reporting.
GET /v1/compliance/il-sb-315Effective 2027-01-01Connecticut's omnibus AI act: AI disclosure, synthetic-content provenance, automated-employment-decision safeguards, and companion-chatbot rules — the chatbot provisions go live October 1, 2026.
GET /v1/compliance/ct-sb-5Effective 2026-10-01South Korea's AI Basic Act — the first comprehensive non-EU AI regime. Generative-AI output labeling is already enforceable; high-impact risk management, human oversight, and recordkeeping obligations phase in under the MSIT grace period.
GET /v1/compliance/korea-ai-basic-actEffective 2026-01-22Joint CISA/NSA/Five Eyes guidance for agentic AI deployments: per-agent cryptographic identity, least-privilege tool access, configuration/supply-chain scanning, behavioral monitoring, and attributable, tamper-evident action logging.
GET /v1/compliance/cisa-agentic-aiEffective 2026-04-30US federal framework for AI risk management. Four core functions: Govern, Map, Measure, Manage.
GET /v1/compliance/nist-ai-rmfEffective 2023-01-26International standard for AI management systems. Covers organizational context through continual improvement.
GET /v1/compliance/iso-42001Effective 2023-12-18Federal confidentiality regime for substance use disorder treatment records. Stricter than HIPAA on consent and re-disclosure. On HHS OCR's 2026 'what we are watching' list.
GET /v1/compliance/42-cfr-part-2Effective 2026-02-16National Association of Insurance Commissioners model for state-level AI governance of insurers. Twenty-four states plus DC have adopted; departments are issuing market-conduct exam questions against it.
GET /v1/compliance/naic-model-bulletinEffective 2024-01-01Colorado Division of Insurance regulation distinct from the general Colorado AI Act. Mandates algorithm inventory, quantitative bias testing, risk-tier controls, and an annual compliance report filed with the DOI.
GET /v1/compliance/colorado-reg-10-1-1Effective 2025-10-15New York Department of Financial Services cybersecurity regulation extended via the October 2024 AI Industry Letter. Covers NY-licensed banks, insurers, and investment advisers operating AI in production.
GET /v1/compliance/nydfs-part-500Effective 2024-10-16Anti-fraud framework for SEC-registered investment advisers. After the March 2024 enforcement sweep against AI-washing, the SEC requires substantiation for every AI marketing claim.
GET /v1/compliance/sec-section-206Effective 2024-03-18Equal Credit Opportunity Act applied to AI-driven credit decisions. The CFPB's 2023 circular makes clear that 'the model is too complex' is not a §1002.9 defense. State AGs (NY, CO, CA) coordinate enforcement.
GET /v1/compliance/cfpb-ecoa-reg-bEffective 2023-09-19Federal model risk management framework extended to AI by the OCC's 2024 guidance. Applies to all OCC-supervised banks (national + federal savings associations) using AI in credit, fraud, AML, or customer-facing flows.
GET /v1/compliance/occ-sr-11-7Effective 2011-04-04American Bar Association ethics framework for lawyers using AI. Each state bar publishes its own AI opinion under these rules; California, Florida, and New York have already issued formal opinions.
GET /v1/compliance/aba-model-rulesEffective 2023-11-01Federal Rules of Civil Procedure sanctions framework for inadequately-checked AI filings. The Oregon $110K sanction precedent (Jan 2026) sets the current floor; every federal filing relying on AI must show pre-submission verification.
GET /v1/compliance/frcp-rule-11Effective 1983-08-01California's companion-chatbot statute. Mandates AI disclosure, self-harm/suicide safety protocols, minor safeguards, and creates a private right of action with statutory damages.
GET /v1/compliance/ca-sb-243Effective 2026-01-01California's content-provenance and AI-disclosure law for covered providers. Requires AI content marking, a detection tool, conversational AI disclosure, and records-of-use retention.
GET /v1/compliance/ca-ai-transparency-actEffective 2026-01-01Federal Trade Commission deceptive-practices enforcement. Operation AI Comply has produced five enforcement priority lanes; the bulletin applies to any business making AI claims to US consumers.
GET /v1/compliance/ftc-section-5Effective 2024-09-25Texas's intent-based AI governance law: prohibited-use limits, government/healthcare AI-interaction disclosure, and a NIST-RMF safe harbor.
GET /v1/compliance/tx-traigaEffective 2026-01-01Illinois Human Rights Act amendment governing AI in employment: discriminatory-effect ban, ZIP-code-proxy ban, and AI-use notice (notice rules pending final IDHR rulemaking).
GET /v1/compliance/il-hb-3773Effective 2026-01-01California's generative-AI training-data disclosure law: a publicly posted 12-element dataset summary, captured and audited (several controls are manual attestation).
GET /v1/compliance/ca-ab-2013Effective 2026-01-01Every framework is available as a per-tenant API endpoint. Generate evidence packages with a single API call — no spreadsheets required.