§ Enterprise
Regulatory conformance
for agentic AI systems.
Maxwell produces deterministic, machine-checkable evidence of conformance with the EU AI Act, DORA, NIST AI RMF, ISO 42001 — artefacts your auditors can accept and your regulators can read.
§ 01 — Regulatory mapping
Every invariant.
Every framework.
Each AG- invariant carries a full mapping to the specific article and control it satisfies. Compliance evidence generated automatically in every CI run.
§ 02 — From Regulation to Code
From Regulation to Code — What Maxwell Verifies.
Each EU AI Act obligation maps to specific Maxwell invariants that are verified on every deployment.
| REGULATORY OBLIGATION | WHAT THE REGULATOR EXPECTS | WHAT MAXWELL PROVES | KEY INVARIANTS |
|---|---|---|---|
| Art. 9 / Risk Management | Continuous, systematic controls for foreseeable AI risks | Every loop is bounded. Every LLM call has error handling. Every external call has a timeout. | AG-001, AG-002, AG-004 |
| Art. 10 / Data Governance | Data provenance tracked and declared | Every data input has a declared source. External inputs are snapshotted at decision time. | AG-032, AG-014 |
| Art. 12 / Record-Keeping | Automatic logging over system lifetime | Every execution path — including the "happy path" — passes through a structured log. No decision bypasses the audit trail. | AG-006, AG-017 |
| Art. 13 / Transparency | System behaviour is explainable and stable | Model version is fixed — behaviour cannot change without an explicit deployment. Every decision has a declared owner. | AG-012, AG-008 |
| Art. 14 / Human Oversight | Humans can effectively intervene | Error handlers contain meaningful logic (no silent failures). High-impact actions have human override gates. | AG-007, AG-009 |
| Art. 15 / Accuracy & Robustness | System is resilient and outputs are reliable | Agent outputs are validated before reaching production systems. Low-confidence outputs branch to review. Fallbacks are deterministic. | AG-005, AG-020, AG-021 |
∎ This mapping is embedded in every Maxwell rule definition. The audit report references the specific article for each finding. When the regulator asks “how do you comply with Article 15?”, you hand them the report section — not a policy document.
§ 03 — Pilot programme
30-day structured pilot.
Your codebase. Our engine.
We run structured pilots with EU fintech and healthtech teams. One agent system, one codebase, one Maxwell scan — producing a full Provenance artefact your team can evaluate and your compliance function can review.
Book a pilot conversation →