Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles
← Back
Banking & Insurance

Algorithmic Portfolio Execution & Advisory

Limited Risk (Transparency)UnverifiedDiscuss / dispute

Trade execution against target parameters, automated conflict-of-interest analysis, generated client advisory communications and full attribution logging of every model inference.

Classification rationale: Retail-facing advice engages Reg BI and the fiduciary standard; the proposed PDA rules require conflicts embedded in a covered technology to be eliminated or neutralised, not merely disclosed. Under 204-2 and 17a-4 every recommendation, prompt and inference is a record that must be WORM-archived and attributed to a supervising person.
Evaluate risk & value →Open in graph

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.

pricingBasis points on automated AUM + usage/compute tier
oversightPre-set trade thresholds and kill-switches; named supervisor attribution on every recommendation

Compliance brief

This use case is limited-risk under the EU AI Act (Limited Risk (Transparency)); transparency obligations apply.

What is owed

  • Art. 50. Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
  • Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.
  • Art. 25. A deployer becomes the provider (full Art.

Dates that bind

  • 2026-08-02General applicability + Art. 50. Transparency obligations for chatbots, deepfakes and synthetic content; EU-level enforcement begins.
  • 2026-12-02Additional prohibitions. Additional bans (deepfake CSAM et al.) and transition period for synthetic content under Art. 50(2).

Maximum exposure

  • SEC Advisers Act Rule 204-2 (Books & Records): SEC enforcement, deficiency letters, books-and-records penalties.
  • SEC Predictive Data Analytics Rules (withdrawn 2025): No rule in force — withdrawn before adoption. Existing fiduciary duty, Reg BI and books-and-records obligations continue to carry the same subject matter in examinations.
  • SEC Regulation Best Interest: SEC/FINRA enforcement, restitution, censure.
  • SEC Rule 17a-4 (US Records Retention): SEC enforcement; multi-hundred-million-dollar off-channel/recordkeeping penalties are routine.
  • FINRA Rule 4511 (General Books & Records): FINRA disciplinary action, fines and supervisory findings.
  • EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
  • DORA: Administrative penalties; periodic penalty payments for critical third parties

First five actions

  1. Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
  2. Commission and confirm the Art. 50, Art. 4, Art. 25 obligations named above as active workstreams with an accountable owner.
  3. Stand up the named oversight design — Mode 2 — with a documented human-review procedure.
  4. Produce the technical documentation and evidence artefacts already mapped to this use case (Synthetic-Content Labelling / Watermarking, Zero-Data-Retention Vendor Binding, WORM / Immutable Audit Vault) before they are requested.
  5. Put 2026-08-02 — General applicability + Art. 50 — into the compliance calendar with an owner and lead time.

Terms used above: · · ·

Applicable Regulations (10)

SEC Advisers Act Rule 204-2 (Books & Records) (17 CFR 275.204-2 (Advisers Act books and records))
in-force · verified 2026-08-06 source eCFR
Registered investment advisers must preserve records of recommendations, advisory communications and the data behind them. Where an AI agent evaluates portfolios, drafts client communications or generates recommendations, its inferences and prompts become advisory records that need an attribution chain to a named supervising person — generic system service accounts are not acceptable.
Sanctions: SEC enforcement, deficiency letters, books-and-records penalties.
SEC Predictive Data Analytics Rules (withdrawn 2025)
withdrawn · verified 2026-08-07
Withdrawn proposal for Exchange Act Rule 15l-2 and Advisers Act Rule 211(h)(2)-4, which would have covered any 'covered technology' — algorithm, model, correlation matrix or computational process that optimises, predicts or guides investor behaviour. Firms would have had to inventory covered technologies, test them for conflicts of interest, and eliminate or neutralise any optimisation putting the firm's interest ahead of the client, with disclosure and consent explicitly insufficient as a remedy. The conflicts analysis remains the clearest articulation of the supervisory concern even though the rule text is no longer pending.
Sanctions: No rule in force — withdrawn before adoption. Existing fiduciary duty, Reg BI and books-and-records obligations continue to carry the same subject matter in examinations.
SEC Regulation Best Interest (17 CFR 240.15l-1)
in-force · verified 2026-08-06 source eCFR
Broker-dealers must act in the retail customer's best interest at the time a recommendation is made, with care, disclosure, conflict and compliance obligations. Automated recommendation engines inherit the full standard, including documented conflict mitigation.
Sanctions: SEC/FINRA enforcement, restitution, censure.
SEC Rule 17a-4 (US Records Retention) (17 CFR 240.17a-4)
unverified · no verification date source eCFR
Broker-dealer record retention: electronic records must be preserved in non-rewriteable, non-erasable (WORM) or audit-trail form, indexed and reproducible on demand. Retention is tiered, not flat — 17a-4(a) requires six years for blotters, ledgers and customer account records, while 17a-4(b) requires three years for the broader category of communications, trade confirmations and supporting records.
Sanctions: SEC enforcement; multi-hundred-million-dollar off-channel/recordkeeping penalties are routine.
FINRA Rule 4511 (General Books & Records) (FINRA Rule 4511)
unverified · no verification date
Requires member firms to preserve books and records not otherwise specified for at least six years in a format compliant with SEA Rule 17a-4(f).
Sanctions: FINRA disciplinary action, fines and supervisory findings.
EU AI Act (Regulation (EU) 2024/1689)
unverified · no verification date source EUR-Lex
Horizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Annex III → 2 Dec 2027, Annex I → 2 Aug 2028).
Sanctions: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
DORA (Regulation (EU) 2022/2554)
unverified · no verification date source EUR-Lex
Digital operational resilience for the financial sector: ICT third-party risk (CTPP oversight), change management, resilience testing — applies to AI-based trading, credit and KYC systems.
Sanctions: Administrative penalties; periodic penalty payments for critical third parties
Art. 50 — Transparency Duties
unverified · no verification date source artificialintelligenceact.eu
Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
Art. 26 — Deployer Obligations
unverified · no verification date source artificialintelligenceact.eu
Use per instructions, assign competent human oversight, input-data control, log retention ≥ 6 months, inform workers, incident duty.
Art. 12 — Record-Keeping / Logging
unverified · no verification date source artificialintelligenceact.eu
Automatic, tamper-evident event logging over the system lifetime, serving three regulatory objectives: risk identification (Art. 79), post-market monitoring (Art. 72) and deployer oversight (Art. 26(5)). Deployers retain logs ≥ 6 months; financial institutions fold them into statutory internal audit documentation. A bolted-on logging wrapper does not satisfy the requirement — logging must be core architecture.

Legal Obligations (3)

Art. 50 — Transparency Duties
Disclose AI interaction to natural persons; machine-readable marking of synthetic content; deepfake labelling; emotion-recognition disclosure.
unverified · no verification date read the article artificialintelligenceact.eu
Art. 4 — AI Literacy
Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems. In force since 2 Feb 2025.
unverified · no verification date read the article artificialintelligenceact.eu
Art. 25 — Value Chain / Role Flip
A deployer becomes the provider (full Art. 8–17 duties) by re-branding, changing intended purpose, or making a substantial modification — e.g. deep fine-tuning or wiring a model into autonomous agent toolchains.
unverified · no verification date read the article artificialintelligenceact.eu

Control Objectives (1)

obligation (article) → operationalized_by → control objective → satisfied_by → component/pattern; control objective → evidenced_by → evidence artifact
Art. 50
AI Interaction & Content Disclosure
Natural persons are informed they interact with an AI system, and generated/manipulated content carries both human-visible labels and machine-readable provenance (C2PA-class) that survives publication pipelines. Testable: disclosure presence across all interaction surfaces; watermark validity sampling post-publication; deepfake-path red-team (does stripped metadata get caught at the gate?).
evidenced by: Guardrail Telemetry & Sanitization Records
Art. 4
control layer: community mandate — propose objectives
Art. 25
control layer: community mandate — propose objectives
Take this into your GRC tooling
A control mapping your ISO/IEC 42001 or CSA AICM workbook can ingest, and an Annex IV skeleton to start the technical file from. Indicative mappings only — cells we are not confident about are exported empty rather than filled in.

Standards & Evidence

C2PA Content Credentials
Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.
published · verified 2026-08-06
evidence for: Art. 50 · Art. 50 — Transparency Duties
IEEE CertifAIEd™
Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
unverified · no verification date
evidence for: EU AI Act
FprEN ISO/IEC 24970 (AI Logging)
Specifies event logging in AI systems — the concrete implementation target for Art. 12 record-keeping.
formal-vote · verified 2026-08-04 publisher ISO
evidence for: Art. 12 — Record-Keeping / Logging
TAGOF (Audit-as-Code)
Operationalizes governance as code in CI/CD: policy-as-code enforcement, continuous runtime telemetry and automatically generated audit evidence — the execution layer that replaces periodic audits with continuous assurance.
unverified · no verification date
evidence for: Art. 12 — Record-Keeping / Logging

Architecture Blueprint

Sovereign Resilient Enterprise Pattern
For regulated finance / high-sensitivity workloads: EU-jurisdiction or EUCS-High+ cloud, confidential computing, BYOK via external HSM, multi-region failover, full FCoT/OpenTelemetry tracing, DORA-grade third-party auditing.
Mode 2 — Supervised Autonomy
Execution within a delay window during which a human can intervene; dominant mode in well-designed regulated production systems.

Required Technical Components (13)

Synthetic-Content Labelling / Watermarking
Synthetic-content labelling & watermarking: visible disclosure plus machine-readable provenance (C2PA Content Credentials) embedded in generated images, audio and video; metadata identifying artificial origin survives common transformations. Discharges Art. 50(2)/(4) for deepfakes and synthetic media; verification telemetry (watermark presence/validity checks at publication gates) is the corresponding evidence stream.
from: Art. 50
Zero-Data-Retention Vendor Binding
Sensitive inference is contractually and technically restricted to endpoints under zero-data-retention and non-training terms, evidenced per vendor and re-validated annually.
from: Art. 25
WORM / Immutable Audit Vault
Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
from: SEC Rule 17a-4 (US Records Retention) · FINRA Rule 4511 (General Books & Records)
Multi-Region Failover & Resilience Testing
DORA-grade continuity: regional redundancy, chaos testing, exit strategies for critical third parties.
from: DORA · Sovereign Resilient Enterprise Pattern
Vendor & Model Due-Diligence Kit
Scoring model: jurisdiction (CLOUD Act exposure), zero-data-retention, BYOK support, audit evidence (C5/AIC4/ISO 42001/EN 18286:2026), tenant isolation.
from: DORA · Sovereign Resilient Enterprise Pattern
Confidential Computing Enclaves
AMD SEV / Intel TDX: data protected from the cloud operator even in memory during inference.
from: Sovereign Resilient Enterprise Pattern
BYOK via External HSM
Customer-controlled key sovereignty; cascaded encryption independent of the cloud provider.
from: Sovereign Resilient Enterprise Pattern
OpenTelemetry / FCoT Tracing
Hierarchical trace spans for every sub-task, prompt, retrieved document and API call — the reconstructible decision path for Art. 12/14 and PLD disclosure.
from: Sovereign Resilient Enterprise Pattern
Bitemporal Memory (GDPR×Art.12)
valid_from/valid_to + transaction time on every record: GDPR erasure removes data from the active retrieval path while the HMAC-chained immutable log survives for Art. 12 / PLD defence; tenant-scoped partitions allow physical scrub of PII.
from: Sovereign Resilient Enterprise Pattern
Sovereign Context Layer
Governed runtime workspace operationalizing Art. 10: traceable lineage for every RAG chunk and training record at execution time, canonical version-controlled business glossary (documents Art. 10(2)(d) baseline assumptions), and continuous data-quality monitoring with threshold alerts and logged remediation for the Art. 10(3) 'error-free and complete' standard.
from: Sovereign Resilient Enterprise Pattern
Isolated Tenant Storage Enclave
Per-client storage boundary for raw payloads, intermediate artefacts and outputs, so no tenant data is co-mingled or reachable across engagements.
from: Sovereign Resilient Enterprise Pattern
Zero-Trust Ingestion Gateway
Authenticated, policy-checked entry point for client payloads; enforces tenant identity, schema validation and rate limits before any data reaches an inference path.
from: Sovereign Resilient Enterprise Pattern
Local Perimeter Execution (MCP)
Execution agents run inside the corporate perimeter and reach tools through the Model Context Protocol instead of shipping raw records to third-party model endpoints. Context is scoped to the minimum attributes the task needs, which is how data minimisation (GDPR Art. 5(1)(c)) and Art. 25 privacy-by-design survive multi-tool agent orchestration.
from: Sovereign Resilient Enterprise Pattern

Delivery Stack & Pipeline Stage (10)

Service-as-a-Software delivery: the engines, patterns and artifacts this workflow needs on top of the generic obligations. See the full pipeline
Supervisor Attribution Chain
Every model inference, data interaction and client-facing artefact is bound to an authorised supervising natural person — never to a shared service account. Required for SEC Rule 204-2 attribution, SOX segregation of duties and AI Act Art. 26 deployer oversight records.
WORM / Immutable Audit Vault
Append-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
pipeline stage 4Output audit & human-in-the-loop gateway
Kill Switch / Graceful Degradation
Operator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
Confidence Scoring & Threshold Gate
Computes a probabilistic confidence score for every output and holds the transaction when the score falls below the workflow's regulatory threshold.
pipeline stage 4Output audit & human-in-the-loop gateway
Bias Testing & Data Quality Pipeline
Representativeness checks, bias metrics and mitigation per ISO/IEC 5259; versioned datasets with lineage.
AI Register & Model Registry / Factsheets
AI register & model registry: central inventory of every model, agent, RAG pipeline and embedded third-party SaaS AI across the estate, with factsheets per asset. v2.0 duty: every application — internal, open-source or procured — continuously publishes a machine-readable AI-BOM and Factsheet into the register; an asset without a current AI-BOM is an inventory gap, not a formality. Feeds Colorado AIA/ LL144 disclosure duties and the Art. 11 technical file; the enforcement backstop is Shadow-AI discovery on the risk register.
Materiality-Threshold Escalation
Autonomy is bounded by pre-configured limits — variance thresholds, disbursement caps, margin floors, confidence minima. Crossing a limit halts execution and routes the case to a named human with the synthesised context, rather than letting the agent proceed at degraded confidence.
Cognitive Orchestrator
The reasoning and control plane of an agentic workflow: goal decomposition, tool selection across enterprise APIs, confidence scoring per step, and a human-machine interface exposing progress, limitations and a global halt. It is the architectural home of AI Act Art. 14 oversight — oversight that lives only in a downstream UI cannot stop an executing agent.
Three Lines of Defense Separation
Structural separation between first-line runtime enforcement (owned by business/engineering: guardrail proxies, gateways, policy enforcement points) and second-line governance (independent GRC platform owned by risk/legal/compliance: inventory, tiering, policy definition, audit evidence), with third-line internal audit sampling both. Telemetry, drift scores and anomaly events flow first→second line as the feedback loop. Anti-pattern: coupling governance into a runtime or model vendor's stack — it blinds oversight to the rest of the estate and fails the independence test auditors apply.
Shadow-Mode Execution
Run governance controls in observe-and-score mode before enforcement: the policy engine and guardrails evaluate every agent action and log verdicts without blocking, yielding empirical false-positive/negative rates and calibrated thresholds. De-risks the enforcement cutover, produces baseline evidence for Art. 9 risk estimation, and is the standard migration path when retrofitting controls onto a live workflow.

Build or Buy — Vendor Layer (5)

The graph models vendor CATEGORIES as first-class nodes and keeps named vendors as community-maintained, disputable desc content with lastVerified dates. A category is stable; a vendor list is a currency-layer object like any standard node.
Regulated Foundation-Model Platforms
Frontier commercial APIs and open-weight models under enterprise controls: zero-data-retention tiers, data isolation, fine-tuning governance, safety alignment documentation, EU-sovereign options. Exemplary (community-maintained): Anthropic Claude (ZDR enterprise tier), OpenAI GPT enterprise, Google Gemini Enterprise, Cohere (private-cloud RAG), Mistral (EU/self-hosted), Meta Llama (open-weight sovereignty). GPAI-chapter duties and vendor due diligence attach at this layer.
unverified · verified 2026-08-06 community-maintained
selection metrics: ZDR enterprise tiers, data isolation, EU-sovereign options, fine-tuning controls, safety alignment documentation
supplies: Synthetic-Content Labelling / Watermarking
AI GRC & Governance Platforms
Second-line systems of record: model/agent inventory incl. third-party SaaS AI, automated risk tiering, policy administration, cross-framework mapping & control deduplication, audit-evidence generation, intake workflows. Exemplary (community-maintained): ModelOp Center, Credo AI, IBM watsonx.governance, OneTrust, Holistic AI, Modulos (governance graph), Monitaur (insurance/lending), Fairly AI, Saidot, Trustible, Enzai, LatticeFlow (technical validation), Vanta (evidence automation), ServiceNow (intake/ITSM); data-catalog adjacency: Collibra, Alation, Informatica. Selection metrics: see meta.marketLandscape.selectionMetrics.grc.
unverified · verified 2026-08-06 community-maintained
selection metrics: multi-model/multi-cloud cataloging incl. third-party SaaS, automated risk tiering, regulatory reporting, independent-2nd-line deployability, cross-framework control deduplication
supplies: Vendor & Model Due-Diligence Kit
Secure Data Infrastructure & Vector Storage
Governed retrieval substrate: vector databases, lakehouses and catalogs with tenant/namespace isolation, RBAC + client-managed keys (CMEK), lineage into RAG chunks, air-gap options. Exemplary (community-maintained): Pinecone (serverless, SOC 2), Chroma/FAISS (self-hosted/air-gapped sovereignty), Snowflake Cortex (masking, clean rooms), Databricks Unity Catalog (end-to-end lineage), Azure AI Search, AWS OpenSearch. The Art. 10 runtime data-governance duties land here.
unverified · verified 2026-08-06 community-maintained
selection metrics: namespace/tenant isolation, RBAC + CMEK, lineage into RAG chunks, SOC 2 / ISO 27001 attestations, air-gap capability
supplies: Sovereign Context Layer · Local Perimeter Execution (MCP)
Agent Orchestration & SDLC Toolkits
Developer middleware for multi-agent networks, tool-use chains, RAG abstraction, state/memory persistence and model routing. Exemplary (community-maintained): LangChain, LlamaIndex, AutoGen, CrewAI; MCP-based tool ecosystems. Regulatory posture: orchestration code is where autonomy tiering, propose-action objects and fallback routing get implemented — the framework choice constrains which controls are cheap and which are retrofits.
unverified · verified 2026-08-06 community-maintained
selection metrics: broad model-API abstraction, state/memory management, error recovery, fallback routing hooks
supplies: Materiality-Threshold Escalation · Cognitive Orchestrator
Runtime Security & Guardrail Vendors
First-line inline enforcement: single-pass parallel input/output evaluation proxies, injection & exfiltration defense, PII masking, grounding checks, SecOps routing. Exemplary (community-maintained): Prompt Security, HiddenLayer (MLSDR), Palo Alto AI Runtime Security, AWS Bedrock Guardrails, NVIDIA NeMo Guardrails, Guardrails AI, Robust Intelligence, LLM Guard / Llama Guard OSS class. Selection metrics: single-pass latency (<20 ms class), catch rates, policy-version telemetry into the AI-BOM.
unverified · verified 2026-08-06 community-maintained
selection metrics: single-pass parallel evaluation latency (<20 ms class), injection/hallucination catch rates, SecOps/SIEM routing, policy versioning surfaced into the AI-BOM
supplies: Output Rails / Groundedness Check
Procurement rule: Derived from three-lines-of-defense separation: the second-line GRC platform must be procured and deployed independently of any first-line runtime or model vendor — a governance tool that only sees its own vendor's models cannot govern a multi-model estate, and closed third-party SaaS AI can only be governed contractually (intake, attestation, AI-BOM disclosure), never by inline inspection.
Outsourced delivery BPO · SaaS · Service-as-a-Software caveats

Delivery Model — BPO · SaaS · Service-as-a-Software

Spectrum
BPO: input-priced (billable hours/FTEs), linear headcount scaling, human error & attrition as primary risk
SaaS: capability-priced (software access), client operates the workload, implementation/adoption failure as primary risk
Service-as-a-Software: outcome-priced (SLA on completed work), provider-managed AI executes 60–80% of cognitive tasks with specialist supervision, algorithmic bias & non-compliance as primary risk
Caveats in regulated markets
Outcome SLAs move compliance risk onto the provider — but NOT the buyer's deployer duties: Art. 26 oversight, log retention and FRIA obligations stay with the enterprise even when execution is outsourced.
Provider role analysis is the central legal question: a productized platform that fine-tunes, re-purposes or chains models can flip into the Art. 25 provider role with full high-risk obligations.
Certified operations (ISO 42001) function as a procurement moat and shortcut third-party risk assessment — but organizational certificate ≠ product conformity (never conflate, see meta.assuranceEcosystem).
The buyer's evidence chain must reach into the provider: contractually mandated AI-BOM disclosure, ZDR certificates, bias-audit reports and logging-ledger access are the artifacts that make an outsourced workflow auditable.

Threat Profile

Cascading Multi-Agent Failure
One agent's erroneous intermediate output (hallucination, goal drift from the assigned objective over multi-step plans, poisoned context) propagates unchecked through downstream agents and triggers automated cascade decisions — emergent behavior no single-agent review ever approved, with unclear liability boundaries between agent operators. Grows with orchestration depth (central orchestrator vs decentralized message bus) and autonomy tier.
mitigate with: Guardian Agents (Runtime Policy Enforcement), Watchdog Supervisor & Rate Limiting, Per-Action Autonomy Tiering, Shadow-Mode Execution
LLM09 Misinformation
Hallucinated or wrong outputs create liability and decision risk.
mitigate with: Output Rails / Groundedness Check, Explainability API (SHAP/LIME/CoT)
Demographic Bias in Automated Screening
Name, language or geography features act as proxies for protected characteristics, producing systematically different outcomes across groups.
mitigate with: Bias Testing & Data Quality Pipeline, Algorithmic Bias & Fairness Audit Report
LLM06 Excessive Agency
Over-broad rights/functions of autonomous agents lead to uncontrolled actions.
mitigate with: MCP Gateway / Proxy, Agentic Zero Trust, Per-Action Autonomy Tiering, Trinity Defense (TCB + Command Gates + IFC), Deterministic Policy Engine (OPA / Cedar), Guardian Agents (Runtime Policy Enforcement)