Skip to main content

Compliance Mapping

CAR is designed to align with major AI governance and security frameworks.

EU AI Act

RequirementCAR Control
Risk classificationTrust tiers (T0–T7) map to risk levels
Human oversightCapability levels (L0–L2 require human approval)
TransparencyAI Nutrition Labels, petnames, trust indicators
Technical documentationAttestation chain, audit trails
Data governanceDomain restrictions, output schema binding
Max autonomy ceilingRegulatory ceiling enforcement (T4 max)

NIST AI Risk Management Framework

FunctionCAR Mapping
GovernGovernance domain (G), policy engine integration
MapDomain taxonomy, capability level classification
MeasureTrust scoring (0–1000), behavioral metrics
ManageRuntime tier adjustments, revocation SLAs

ISO 42001 (AI Management System)

ClauseCAR Implementation
Leadership & planningOrganizational context hierarchy
Support & resourcesAgent registration, attestation
OperationTrust engine, ceiling enforcement
Performance evaluationBehavioral monitoring, drift detection
ImprovementProvenance tracking, tier transitions

OWASP Top 10 for Agentic Applications

RiskCAR Mitigation
Prompt InjectionDomain boundaries + instruction integrity
Insecure OutputOutput schema binding, level-gated execution
Training Data PoisoningAttestation chain verification
Model DoSTrust-tier rate limits
Supply ChainExtension verification, TEE attestation
Sensitive Info DisclosureDomain restrictions, prohibited patterns
Insecure Plugin DesignScope reduction enforcement
Excessive AgencyLevel-appropriate approval workflows
OverrelianceTrust tier UI indicators
Model TheftDID-based identity, TEE binding

SOC 2 Type II

Trust Service CriteriaCAR Control
SecurityDPoP tokens, TEE binding, pairwise DIDs
AvailabilityRevocation SLAs, failover
Processing IntegrityBehavioral monitoring, drift detection
ConfidentialityDomain restrictions, output binding
PrivacyPairwise DIDs, context authentication

HIPAA (Healthcare)

For agents operating in healthcare domains (Domain H):

RequirementCAR Control
Access controlsDomain H + minimum T3 tier
Audit trailsFull action history with Cognigate
PHI handlingOutput schema binding + prohibited patterns
Breach notificationRevocation + webhook alerts
BAA requirementsAttestation with HIPAA extension (#hipaa)

Implementation Checklist

Phase 1: Foundation (Weeks 1–4)

  • Implement CAR string parsing and validation
  • Set up agent registration with ANS
  • Configure DPoP token issuance
  • Deploy basic trust scoring

Phase 2: Certification (Weeks 5–8)

  • Establish certification authority
  • Implement attestation lifecycle
  • Configure regulatory ceiling enforcement
  • Enable behavioral monitoring

Phase 3: Governance (Weeks 9–12)

  • Deploy Cognigate policy engine
  • Implement semantic governance controls
  • Configure audit trail retention
  • Enable extension protocol

Phase 4: Production (Weeks 13–16)

  • Achieve SH-2 security level minimum
  • Complete compliance mapping documentation
  • Conduct third-party security audit
  • Enable full revocation SLA enforcement