Alignment can be claimed. We hand over receipts.
The rules for AI logging are being written now — and the Ledger was built against the full texts, not the blog posts. Everything on this page is documented and available to your counsel under NDA.
ISO/IEC 24970 — AI system logging
Clause-by-clause conformance review against the full DIS text: every applicable requirement met, several exceeded — including the optional "additional functions" list, which reads like an inventory of our tables.
prEN 18229-1 — EU harmonized standard
Reviewed against the full CEN Enquiry draft, whose Annex ZA maps to AI Act Articles 11–12. No gaps found; the standard's reference-in-place-of-payload pattern is literally our architecture.
NIST SP 800-53 & AI RMF
Designed to the audit-and-integrity controls of NIST SP 800-53 Rev. 5 — AU-9(2)/(3), AU-10(3), AU-11, SI-7(6) — with FIPS 180-4 SHA-256, and operationalizing the oversight and provenance actions of the NIST AI RMF and its Generative AI Profile (MAP 3.5, MS-2.8-003, MS-4.2-004). Alignment, not certification.
OpenTelemetry GenAI
Native intake of the gen_ai.* semantic conventions your stack already emits, trace identities preserved. The Ledger joins your observability; it doesn't fork it.
What the rules ask. What the Ledger answers.
| The obligation | What it requires | How the Ledger answers |
|---|---|---|
| EU AI Act Art. 12 (in force for high-risk AI) | Automatic recording of events over the system lifetime; ≥6-month retention | Automatic sealed capture; retention defaults measured in years, with lawful destruction that leaves proof |
| EU AI Act Art. 14 (human oversight) | Evidence of effective human oversight | Reviews sealed as chained records — approver, sections cited, reason — not editable notes |
| SEC exam focus (17a-4 / 204-2 class) | Attributable, tamper-evident records; multi-year retention | Two-plane tamper-resistant ledger, externally time-anchored; export built for examiners |
| Fannie Mae LL-2026-04 | Disclose on request what AI is used, for what, with what safeguards | The chain of custody is the disclosure: what ran, what it relied on, who oversaw it |
| GDPR erasure vs. evidence duty | Destroy personal data and keep defensible records | Delete the data, keep the proof — fingerprint custody with tombstoned destruction |
This table is a summary, not legal advice. The underlying documents — both conformance reviews, the wire contract, failure semantics, and the technical documentation pack — are written for exactly the person your counsel will send. Request the conformance reviews.