Regulatory coverage

Technical evidence coverage for regulated AI workflows.

AuthenChain is a technical evidence layer for AI outputs. It helps teams preserve provenance, integrity, traceability, audit context, chain of custody, verification results, and dispute evidence without presenting those artifacts as a legal compliance decision.

AuthenChain provides technical evidence for AI output provenance, integrity, traceability, audit, chain of custody, verification, and dispute workflows. AuthenChain does not provide legal advice and does not determine legal compliance.
Evidence layer

What AuthenChain can technically support

Coverage starts with signed evidence. Customers still own legal interpretation, workflow governance, disclosure decisions, human review, privacy review, model risk, and final business decisions.

Provenance

Sign final AI output evidence with issuer, timestamp, content hash, model context, trace ID, and canonical metadata.

Integrity

Detect when submitted evidence no longer matches the signed hash, payload, trust-root context, or expected field hashes.

Traceability

Connect signed records to regulatory metadata, risk context, audit events, Evidence Packs, Trust Root Management, and review workflows.

Verification

Let reviewers verify Evidence Packs through public `/verify` without requiring internal dashboard access.

Status legend

How to read the coverage status

The same status model is used across the public page, documentation, procurement answers, and GTM material.

StatusMeaningClaim boundary
supportedAuthenChain currently provides a direct technical evidence artifact or workflow.State the artifact and verifier behavior. Do not convert technical proof into a legal conclusion.
partially supportedAuthenChain provides relevant evidence, but customer process records or legal review are still required.Explain both the AuthenChain evidence and the customer-owned missing pieces.
customer-ownedThe obligation, decision, process, or control belongs primarily to the customer.AuthenChain may preserve customer-supplied evidence, but does not decide the control.
futureThe capability is planned, possible, or separately scoped, but not current product coverage.Do not present as available without a later release and review.
out of scopeThe area is outside AuthenChain product responsibility.Do not imply AuthenChain provides this outcome.
Framework coverage

Regulatory and standards mapping

These sections summarize current public positioning. They describe technical evidence support, not legal sufficiency or certification.

EU AI Act

partially supported
AuthenChain support

Supports evidence readiness for transparency, traceability, audit, Article 50-style disclosure metadata, high-risk audit trail support, policy-versioned risk context, trust-root review, and dispute workflows.

Customer-owned work

Legal role, applicability, risk classification, notice design, human oversight, conformity work, technical documentation, post-market monitoring, and regulator communication.

Brazil PL 2338/2023

partially supported
AuthenChain support

Supports monitoring and preparation evidence for transparency, accountability, traceability, audit review, human review evidence, dispute evidence, and minimization patterns.

Customer-owned work

Tracking final legal text, local legal advice, LGPD alignment, sector duties, final obligations, and customer governance after enactment and official guidance.

NIST AI RMF

partially supported
AuthenChain support

Maps technical evidence artifacts to Govern, Map, Measure, and Manage workflows where provenance, policy-versioned risk context, verification, packaging, reporting, and investigation evidence are useful.

Customer-owned work

The AI risk management program, risk appetite, model risk assessment, measurement, monitoring, remediation, risk treatment, and management decisions.

NIST Generative AI Profile

partially supported
AuthenChain support

Supports provenance, integrity, transparency evidence, model/provider traceability, misuse dispute review, synthetic-content metadata, and human review records.

Customer-owned work

Model quality, accuracy, robustness, cybersecurity, privacy, safety, bias, fairness, misuse controls, red teaming, and risk treatment.

ISO/IEC 42001

partially supported
AuthenChain support

Provides evidence artifacts that may support a customer-operated AI management system review, management review inputs, audit preparation, and access governance evidence.

Customer-owned work

Establishing, operating, auditing, and certifying the AI management system, including policies, objectives, risk assessment, internal audit, and corrective action.

ISO/IEC 23894

partially supported
AuthenChain support

Supports evidence around AI risk context, risk review, monitoring, treatment tracking, change review, recurring reports, and signed review artifacts.

Customer-owned work

Risk criteria, risk owners, risk analysis, risk treatment decisions, lifecycle governance, communication, and risk acceptance.

Implemented evidence

Current evidence surfaces

These are current technical surfaces that can support regulatory evidence workflows when correctly integrated and enabled for the customer workflow.

signed provenance payloads
canonical content hashes and field hashes
regulatory metadata validation
policy-versioned risk classification suggestions
signed risk context binding
Evidence Packs
public `/verify` workflow
public trust-root state
Trust Root Management
Forensic Access
Audit Explorer
monthly technical evidence reports
controlled delivery packages
delivery integrations
reviewer statements
submission readiness packages
Node.js/TypeScript SDK, Python SDK, CLI, and mock mode
Limitations

Clear boundaries

AuthenChain's value is defensible technical evidence. Regulatory outcomes remain fact-specific and customer-owned.

Not a compliance certificate

Evidence Packs, public verification, reports, reviewer statements, trust-root records, and audit timelines are technical evidence artifacts. They can support customer review, but they do not replace counsel, governance, audit, certification, regulator review, or customer decision-making.

AuthenChain does not provide
  • AuthenChain does not provide legal advice or determine whether a customer, workflow, model, output, or AI system meets legal requirements.
  • AuthenChain does not decide EU AI Act role, risk tier, Article 50 applicability, disclosure sufficiency, human oversight adequacy, or sector-specific obligations.
  • AuthenChain does not certify SOC 2, ISO 27001, ISO/IEC 42001, customer compliance, model quality, fairness, safety, truthfulness, or regulator acceptance.
  • AuthenChain does not file reports with regulators or communicate with authorities on behalf of a customer.
  • Verification proves technical integrity against signed evidence. It does not prove factual correctness or business decision quality.
Next steps

Use coverage together with implementation evidence

The best implementation path is narrow: choose one accountable AI workflow, sign the final output, verify a tamper case, export an Evidence Pack, and assign customer-owned governance responsibilities.

Regulatory Coverage | AuthenChain - AuthenChain