ISO 42001, SOC 2, GDPR DPIA, and AI FRIA — everything your legal, risk, and engineering teams need to deploy AI agents in regulated environments.
ISO/IEC 42001 is the first international standard for AI management systems. It requires organizations to document AI objectives, risk assessments, and governance controls — and to demonstrate that those controls actually work in production.
AgentTrust OS maps directly to ISO 42001's requirements: Trust Certify generates pre-production evidence, Trust Runtime enforces governance controls, and Trust Audit produces the documentation your certifying body needs.
High-risk AI systems under the EU AI Act require a Fundamental Rights Impact Assessment (FRIA) before deployment. This covers bias, fairness, transparency, and accountability obligations — with documented evidence of control.
AgentTrust OS generates the behavioral evidence your FRIA needs: Trust Certify documents how the agent behaves under adversarial conditions, Trust Runtime proves controls are enforced at execution, Trust Audit provides the accountability trail required for high-risk systems.
SOC 2 was designed for traditional software. Adding LLMs and agentic systems creates new evidence requirements under the Trust Services Criteria — especially Security, Availability, and Confidentiality.
AgentTrust OS produces SOC 2-compatible control evidence: Trust Certify provides pre-deployment testing records, Trust Runtime generates continuous control operation logs, and Trust Audit exports formatted reports your auditor can review directly.
GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) when processing is likely to result in high risk to individual rights. Agentic AI systems — which access, process, and act on personal data autonomously — trigger this requirement in most enterprise deployments.
AgentTrust OS provides the data access logs, permission evidence, and processing records your DPO needs to complete and defend a DPIA for AI agent deployments.
Why AI for Security and Security for AI can no longer be separate tracks — and what it takes to close the control gap.
Read more →GDPRHow to structure a DPIA for agentic systems under Article 35 — with evidence requirements and documentation templates.
Read more →SOC 2How to close the evidence gap when your auditor asks how you control an AI agent's behavior.
Read more →Enterprise plans include full audit pack exports, compliance report templates, and legal review coordination.