The problem

Adoption outran governance, and the authority is now named.

Companies adopted AI far faster than they adopted the ability to prove that their AI is governed. In a Gartner survey published on 30 September 2026, 54% of organisations had no defined approach to limiting what AI agents can access, or relied on access rules written for people.

Meanwhile the enforcement architecture stopped being prospective. Germany's KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG) entered into force on 29 July 2026, making the Bundesnetzagentur the market surveillance authority for the AI Act and Germany's single point of contact under it, with sector regulators retaining competence in their fields. The German NIS2 implementation act has been in force since 6 December 2025 and expanded the regulated population from roughly 4,500 to around 29,500 entities, according to the BSI. Management must implement and oversee the risk measures, attend regular training, and is liable to the entity for culpable breaches.

The gap between how fast AI arrived and how slowly governance followed is the market. The gap between that and a named enforcing authority is the urgency.

How it works

Consume. Grade. Confirm. Generate.

An obligation will be discharged by evidence, graded on how that evidence was obtained, confirmed by a named human, and rendered into a filing that can be reproduced on demand.

1. Consume

It will take in evidence produced by live measurement, such as the findings Cyron AI Security records, and by contained probes, rather than questionnaire answers. Its evidence will come from runtime behaviour after deployment, exactly the stage most compliance tooling never reaches.

2. Grade

Evidence is not a boolean. It will be ordered by how it was obtained, and the ordering will determine what it can settle. For every duty class the system will state which grade is necessary and which is sufficient.

3. Confirm

A named qualified human will confirm each mapping, and a second named human will sign the attestation. A language model may draft narrative; it will never author the interpretation.

4. Generate

It will produce the filing itself: technical documentation, the Statement of Applicability, the gap register. Any rendered filing will regenerate byte-for-byte from the ledger plus pinned versions.

What it will answer

Six questions it will answer with a record rather than an opinion.

These are the answers the finished system is designed to give, stated so you can test it against them.

"Which obligations apply to us?"

It will return a reviewed, attested applicability determination naming your role, risk classification and subject scope, with its own version and its own named reviewer.

"Which of them are discharged, and by what?"

For each duty element, it will show whether it is discharged, by which evidence, under which crosswalk rule and rule-set version, confirmed by which named human, and until when.

"What is not discharged, and whose fault is it?"

Every unmet duty will be attributed: a condition in your environment, a Cyron condition, or an unmet regulatory precondition. Never silence.

"How current is this?"

Every discharge will carry its freshness window, its binding constraint, and the next event that will decay it.

"Prove it."

Any rendered filing will regenerate byte-for-byte from the ledger plus pinned versions, and any attestation will be verifiable against the exact discharge set it bound.

"What happens when something changes?"

A change upstream will propagate as a decay signal, void exactly the attestations it should, and name what must be re-reviewed. Nothing will go quietly stale.

Framework coverage

Depth before breadth.

Version one will cover the EU AI Act and ISO/IEC 42001, decomposed into individual duty elements. The corpus model is designed to be framework-agnostic, so a third framework will be a corpus addition rather than a re-architecture.

FrameworkWhat the product will produceWho reads it
EU AI Act — applicability and roleAttested determination of provider, deployer, importer or distributor, with risk classification and its recorded basisLegal, compliance, the board
EU AI Act — Article 15 robustness and cybersecurityDischarge records backed by measured security evidence, with a reproducible account of how it was obtainedAuditor, market surveillance authority
EU AI Act — Annex IV technical documentationGenerated technical documentation with every claim traced to its source evidenceNotified body, product and quality management
ISO/IEC 42001Statement of Applicability and AI management system evidence, with unmet duties attributedCertification body, CISO
Cross-frameworkGap register naming, for each unmet duty, whose condition prevents itInternal audit, risk, remediation owners

These are the outputs version one is designed to produce, stated so you can test the finished product against them.

What it will refuse to be

Stating the refusals is what makes the positioning falsifiable.

A statement of what a system is not is more binding than a statement of what it is, because you can hold us to it.

It will not be a questionnaire

No control will be discharged because a customer asserted it. A single asserted control in the discharge path collapses the entire claim, because an auditor will find it and ask what else was asserted.

It will not be a model-generated mapping

The answer to "who decided this evidence discharges this duty" will be a named person and a dated artefact. If it were a model, the mapping would be indefensible as soon as it was challenged.

It will not be a dashboard that goes green

A compliance product whose natural resting state is a clean report will produce a clean report from an empty evidence stream. Its resting state will be an explicit, attributed account of what is not known.

It will not be a ticketing system

Workflow state, ownership, priority and due dates are deliberately left out. It will record what is true and who said so, not what somebody intends to do about it. It will export a gap list; what you do with it is another system's job.

Deployment

Sovereign and air-gapped by design.

The entire loop is designed to run on your premises with no outbound network path, including the language model that will draft narrative. For buyers in defence, public sector, healthcare, energy and finance this is often a procurement precondition rather than a preference.

  • Designed for single-tenant, on-premise, fully air-gapped deployment
  • Corpus and rule-set updates will arrive as signed bundles
  • The drafting model will run locally; nothing about your environment will be sent outward
  • Attestations will be cryptographically bound to the evidence set they cover

Where it sits in the loop

Cyron AI Compliance will be the evidence layer. Cyron API Security sees what reaches your APIs. Cyron AI Security measures what your agents do and records the findings. Cyron AI Compliance will turn those records into attested regulatory filings.

Each will deploy independently. Fed by runtime measurement, it will discharge duties on graded evidence; where only an assertion exists, the filing will record it as an assertion rather than presenting it as proof.

See all three products
FAQ

Questions compliance teams ask first.

The dominant category of compliance tooling is assertion-based: a control is marked satisfied because a person ticked a box saying it is satisfied. That is adequate for a management review and inadequate for an auditor, a notified body or a market surveillance authority, all of whom are trained to ask what evidence supports the tick. Cyron AI Compliance will refuse to discharge any obligation on the basis of an assertion.
Version one will cover the EU AI Act and ISO/IEC 42001, decomposed into individual duty elements. Depth before breadth: the corpus model is designed to be framework-agnostic, so a third framework will be a corpus addition rather than a re-architecture.
No. The answer to who decided that a piece of evidence discharges a duty will always be a named person and a dated artefact. A language model may draft narrative; it will never author the interpretation. Each mapping will be confirmed by a named qualified human and each attestation signed by a second.
A discharge will be valid only inside a freshness window and will decay as the system or the threat surface changes. An attestation will be cryptographically bound to the exact evidence set it covers and will void when that evidence changes. A change upstream will propagate as a decay signal, void exactly the attestations it should, and name what must be re-reviewed. Nothing will go quietly stale.
They will be sold and deployed separately. Cyron AI Compliance will be strongest when fed by runtime measurement from Cyron AI Security, because that is what supplies evidence graded above assertion level. Where a duty can only be supported by an assertion, the filing will record it as an assertion rather than presenting it as proof.
No, and no software honestly can. It will tell you which duty elements are discharged, by what evidence, confirmed by whom and until when, and it will name every duty that is not discharged, along with whose condition prevents it. That determination is made by people and, ultimately, by an authority. Cyron AI Compliance will produce the record they ask for.
The entire loop is designed to run on your premises with no outbound network path, including the language model that will draft narrative. For German and European buyers in defence, public sector, healthcare, energy and finance this is often a procurement precondition rather than a preference.
It is in development. Design partner conversations are open now, and our advisory practice delivers the same outcomes as an engagement in the meantime.

Be ready before the authority asks.

Join the design partners shaping Cyron AI Compliance, or start now with an applicability determination and a governance readiness assessment from our advisory practice.