Aegis Live audit ledger
New assessment

Framework

Five stages, one continuous loop.

The Aegis Framework is deliberately small. Five stages, applied proportionately, mapped to the obligations you already carry.

  1. Stage 01

    Inventory

    You cannot govern what you cannot see. We build a live register of models, datasets, vendors and use cases with named accountable owners.

  2. Stage 02

    Assess

    Each use case is tiered on impact, autonomy and reversibility. Tiering drives how much scrutiny it earns — nothing more, nothing less.

  3. Stage 03

    Test

    Evaluations matched to the tier: accuracy, subgroup performance, robustness, adversarial behaviour, and human-override effectiveness.

  4. Stage 04

    Control

    Approval gates, disclosure requirements, logging, and fallbacks written as controls, with owners and evidence for each one.

  5. Stage 05

    Monitor

    Drift, complaint and incident signals routed to the people who can pause a system, with periodic reassessment on a fixed cadence.

Regulatory & standards watch

What is actually in force right now

Current as of August 2026. Each control in the framework maps to at least one of these instruments, and every mapping carries a dated source.

EU AI ActIn force 27 Jul 2026

Amended by the AI Omnibus

Regulation (EU) 2026/1744 moved core Annex III high-risk obligations to 2 Dec 2027 and Annex I product-embedded high-risk AI to 2 Aug 2028. Prohibitions and AI-literacy duties have applied since 2 Feb 2025; GPAI obligations since 2 Aug 2025; Article 50 transparency since 2 Aug 2026. Full roll-out is foreseen by 2 Aug 2028.

Commission implementation timeline →
ISO/IEC 42001Published 2023

AI management system — certifiable

The certifiable AI management system standard: AI policy, roles, risk and impact treatment, lifecycle controls and continual improvement. ISO/IEC 42006 now sets the accreditation requirements for the bodies that certify against it, so certificates are becoming comparable.

ISO/IEC 42001 overview →
ISO/IEC 23894 + 4200523894:2023 · 42005:2025

Risk and impact assessment

23894 adapts ISO 31000 risk management to AI; 42005 gives the process for AI system impact assessment — scope, affected individuals, benefits and harms, documentation and timing across the lifecycle. Together they underpin our Assess stage.

ISO/IEC 42005 overview →
NIST AI RMFRMF 1.0 · GenAI Profile (AI 600-1)

Voluntary US framework

Govern, Map, Measure, Manage — plus the Generative AI Profile's risk actions for foundation-model use. We use it to structure evidence for US and multinational programmes that are not directly AI Act-scoped.

NIST AI RMF →
ISO/IEC 27001:2022Amd 1:2024 (climate action)

Information security baseline

The 2022 revision's 93 Annex A controls — threat intelligence, secure development, cloud service security, data masking, monitoring — are the security floor beneath any AI control. ISO/IEC 27701 extends it to privacy; transition to the 2022 edition is complete.

ISO/IEC 27001 overview →
AI security testingOWASP LLM Top 10 · NIST AI 100-2

Adversarial assurance

Prompt injection, insecure output handling, supply-chain and data-poisoning risks tested against the OWASP Top 10 for LLM applications, with NIST's adversarial ML taxonomy (AI 100-2e2025) framing evasion, poisoning and privacy attacks in evaluation scope.

OWASP LLM Top 10 →

Principles we won't trade away

  • Proportionate scrutiny — high-impact systems get depth, low-impact ones get speed.
  • Evidence over assertion — a claim without a test result is not a control.
  • Human accountability — every model has a person, not a committee, who owns it.
  • Governance that survives launch day and the next model version.