AI Governance & Conformity · OpenChainGraph v0.4

AI Governance & Conformity for Financial Services

The governance layer for the AI systems themselves: EU AI Act high-risk conformity for financial AI (Annex III: credit scoring, insurance pricing, financial-standing) plus agentic AI governance and GPAI classification. Four new tools (ART-64–67) across 8 aig-* chains compose the existing AI-Act/model-risk point tools into a verifiable, hash-anchored conformity lifecycle: classify → provider conformity pack → deployer FRIA + monitoring → fairness → audit. Reflexive tie to the agent-economy runtime: the same agents that transact on that runtime are AI systems that must be governed today.

GPAI Arts 53-55 IN FORCE 2 Aug 2025 Art 5 prohibited practices IN FORCE 2 Aug 2025 Art 4 AI literacy IN FORCE 2 Feb 2025 Annex III high-risk · PREPARE-AHEAD 2 Dec 2027 Art 27 FRIA · PREPARE-AHEAD 2 Dec 2027 Digital Omnibus · verify formal adoption EU AI Act Reg. 2024/1689 AI Governance Colorado SB 21-169 · US Insurance Bias IN FORCE NAIC AIS 2024 · US Insurer AI Readiness IETF draft-sharif-agent-audit-trail-00
Cluster ③ ↔ Cluster Ⓐ cross-link: Art-239 BIFSG bias testing and the insurance-ai-bias-attestation chain bridge AI Governance (③) and Fair Lending & Adverse Action (Ⓐ). US-licensed insurers running credit-based algorithms face obligations under both Colorado SB 21-169 / Reg 10-1-1 and ECOA disparate-impact rules. See Fair Lending guide →
✅ DO NOW: Four obligations are IN FORCE as of today (2026-06-20): GPAI/foundation-model obligations (Arts 53–55, including systemic-risk 10^25 FLOP, enforceable 2 Aug 2025, explicitly UNCHANGED by the Digital Omnibus). Art 5 prohibited AI practices (IN FORCE 2 Aug 2025, €35M/7%, the Act's highest penalty). Art 4 AI literacy for providers and deployers (IN FORCE 2 Feb 2025). DORA ICT risk (fully enforced 17 Jan 2025). If you provide or deploy a GPAI model or use AI in a way that could constitute a prohibited practice, action is required NOW.
⚠ PREPARE-AHEAD: Annex III high-risk obligations (Arts 9–15), Art 27 FRIA, and Art 72 post-market monitoring confirmed for 2 Dec 2027 by the Digital Omnibus (provisional agreement 7 May 2026). Verify formal-adoption status. The deferral takes legal effect only if the Omnibus is formally adopted/published before 2 Aug 2026; otherwise the original 2 Aug 2026 date applies. Start preparation now: 18 months of runway against confirmed obligations.
EDUCATIONAL: All outputs are decision-support drafts. Not legal conformity certificates. Verify all Article/Annex references against EU AI Act (Reg. 2024/1689) consolidated text at eur-lex.europa.eu/eli/reg/2024/1689/oj and current Digital Omnibus formal-adoption status.
Lifecycle vs point tools: the uniqueness fix. Five existing tools (art-05 + catalog 327/333/451/452) are standalone point assessments. This hub composes them into a hash-anchored conformity lifecycle: classify (ART-64) → provider Annex IV pack (ART-65) → deployer FRIA + monitoring (ART-66) → agentic-AI governance (ART-67) → fairness → audit. The reused tools become lifecycle stages; their reframe role is stated on every chain page. This is not a re-skin; it is the conformity lifecycle those point tools individually cannot provide.

DO NOW: in-force obligations

These tools address obligations already enforceable. Start here regardless of the Annex III high-risk timeline.
ART-64 · agent_guardrail_mandate
EU AI Act High-Risk Fit & Classification Diagnostic
Screens Art 5 prohibited practices (€35M, in force), Art 4 AI literacy (in force), GPAI applicability (in force) FIRST, then classifies Annex III high-risk status. Grades readiness across 12 dimensions + emits "do now" vs "prepare-ahead" checklists. Routes to the right aig-* chain.
run_ai_act_highrisk_fit IN FORCE (triage)
ART-67 · model_governance
Agentic AI Risk & GPAI Governance Classifier
Co-flagship and strongest in-force anchor. Classifies autonomy tier + GPAI/systemic-risk obligations (Arts 53–55, IN FORCE 2 Aug 2025). Maps Art 50 transparency, Art 14 HNP oversight, and downstream Annex III interaction. The reflexive tie to the agent-economy runtime rails.
classify_agentic_ai_risk IN FORCE · GPAI Arts 53-55

DO NOW: US insurance AI bias obligations

Colorado SB 21-169 (in force since 2022) and NAIC AIS guidance (2024) apply now to US-licensed insurers using algorithmic decision-making. Annual Dec 1 attestation deadline.
ART-239 · test_bifsg_bias_thresholds
BIFSG Bias Threshold Tester
Tests aggregate regression statistics against Colorado SB 21-169 / Reg 10-1-1 thresholds. Two-prong: statistical (p<0.05 AND ≥5pp marginal effect) + premium prong (≥5% above group avg). ZERO PII — all inputs are aggregate statistics only. Outputs bias_detected flag and next Dec 1 attestation deadline.
test_bifsg_bias_thresholds IN FORCE · CO SB 21-169 · Dec 1 annual
ART-240 · assess_naic_ais_program_readiness
NAIC AIS Program Readiness Assessor
Scores AI program readiness across the 6 NAIC AIS Evaluation Tool dimensions (governance, risk management, data management, model documentation, human oversight, fairness testing). 0–18 composite. GREEN ≥78%, YELLOW ≥44%, RED <44%. Identifies priority gaps for remediation.
assess_naic_ais_program_readiness IN FORCE · NAIC AIS 2024

PREPARE-AHEAD: high-risk lifecycle (2 Dec 2027, verify)

Annex III high-risk conformity, Art 27 FRIA, and Art 72 post-market monitoring. Start now: 18 months of preparation runway against confirmed obligations.
ART-65 · model_governance
AI Act Conformity Pack Builder
Flagship provider tool. Assembles Annex IV technical documentation, validates conformity route (internal control vs notified body), checks CE-marking and EU Declaration of Conformity readiness. Answers: "is my high-risk financial AI ready to CE-mark?" Decision-support draft.
build_ai_conformity_pack PREPARE-AHEAD 2 Dec 2027
ART-66 · compliance_mandate
FRIA & Post-Market Monitoring Plan Builder
Flagship deployer tool. Builds an Art 27 FRIA + Art 72 post-market monitoring plan + Art 12 logging + Art 14 oversight + Art 73 incident path for a bank or insurer deploying a high-risk AI system. Decision-support draft.
build_fria_monitoring_plan PREPARE-AHEAD 2 Dec 2027

PREPARE-AHEAD: AI decision logs & audit trails (2 Dec 2027, verify)

Art 12(2) logging, Annex III obligation classification, and IETF AAT chain-linked audit trail validation. Start preparation now against confirmed 2027 enforcement.
ART-236 · build_ai_decision_log_record
Art 12(2) AI Decision Log Record Builder
Builds EU AI Act Art 12(2)-conformant AI decision log records. Captures model identity, input/output SHA-256 digests, override flags, decision outcome, retention months (≥6), and chain linkage via sha256_prev_record. Completeness scored across 12 required fields. Subject reference is a structural field only — never a real identity.
build_ai_decision_log_record PREPARE-AHEAD 2 Dec 2027
ART-237 · validate_agent_audit_trail
IETF Agent Audit Trail Validator
Validates chain-linked agent audit trail records per IETF draft-sharif-agent-audit-trail-00 (AAT). Checks action_class, outcome, trust_level enum membership; 64-hex sha256_prev_record linkage; ECDSA signature presence. Emits conformance_result (CONFORMANT / PARTIAL / NON_CONFORMANT) and aat_completeness_score (0–1).
validate_agent_audit_trail PREPARE-AHEAD · EU AI Act Art 12(2)
ART-238 · classify_annex3_decisioning_obligations
Annex III Decisioning Obligations Classifier
Classifies Art 12(2) logging, Art 26(6) FRIA, and Art 27(1) EU DB registration obligations for Annex III FS high-risk AI (5(b) credit scoring / 5(c) insurance pricing and risk assessment). Exits OUT_OF_SCOPE for non-high-risk systems. Flags Digital Omnibus proposed deferral (2027-12-02 vs original 2026-08-02).
classify_annex3_decisioning_obligations PREPARE-AHEAD 2 Dec 2027

Chains: aig-* (11 chains)

Start with ai-governance-fit to classify and route. Each chain follows the TCM/DTC/WTS/AER pattern: run stages over MCP or in-browser, pass execution_hash forward, export the terminal artifact. Aggregate everything in ai-governance-audit-pack. Three additional chains cover AI decision log conformance, US insurance AI bias attestation, and IETF AAT audit trail validation.
ai-governance-fit · 1 node · DO NOW
EU AI Act High-Risk Fit & Classification Diagnostic
Single-node entry point. Screens in-force obligations first (Art 5, Art 4, GPAI), grades Annex III classification, routes to the right aig-* chain.
→ ART-64
ai-governance-gpai-agentic · 3 nodes · DO NOW
Agentic AI & GPAI Governance
GPAI/systemic-risk classification (ART-67) + agent identity (art-04) + MCP self-attestation (art-33). GPAI Arts 53–55 IN FORCE since Aug 2025. Reflexive tie to the agent-economy runtime.
→ ART-67 · art-04 · art-33
ai-governance-fairness-bias · 3 nodes · DO NOW
Fair-Lending & AI Bias Assessment
Fair-lending bias (452) + credit model performance (ml-02) + subgroup anomaly detection (ml-01). Non-discrimination obligations apply now under existing law.
→ 452 · ml-02 · ml-01
ai-governance-resilience-overlap · 3 nodes · DO NOW (DORA)
AI-as-ICT Resilience (DORA × AI Act)
DORA readiness for the AI system as ICT (art-29) + Art 15 robustness/cyber conformity (ART-65) + combined evidence integrity (cry-04). DORA fully enforced Jan 2025.
→ art-29 · ART-65 · cry-04
ai-governance-conformity · 3 nodes · PREPARE-AHEAD
AI Act High-Risk Conformity Pack (Provider)
Annex IV technical documentation + CE/DoC (ART-65) + Article 9 risk-management system (333) + conformity assessment (art-05). Flagship provider lifecycle. Decision-support draft.
→ ART-65 · 333 · art-05
ai-governance-fria-monitoring · 3 nodes · PREPARE-AHEAD
Deployer FRIA & Post-Market Monitoring
Art 27 FRIA + Art 72 monitoring (ART-66) + SR 11-7 model-risk evidence (451) + audit receipt (cry-05). Flagship deployer lifecycle. Decision-support draft.
→ ART-66 · 451 · cry-05
ai-governance-credit-ai-conformity · 3 nodes · PREPARE-AHEAD
Credit-Scoring AI Conformity & FRIA
Credit-scoring conformity (art-05) + risk-class confirmation (327) + deployer FRIA (ART-66). The Annex III credit-scoring vertical end-to-end. Decision-support draft.
→ art-05 · 327 · ART-66
ai-governance-audit-pack · 3 nodes · Convergence terminal
AI Governance Conformity Audit Pack
Convergence terminal. Merkle integrity over the AI-governance decision set (cry-04) → Merkle-root receipt (cry-05) → regulator/notified-body cover memo (ptg-01). Any aig-* chain can feed in.
→ cry-04 · cry-05 · ptg-01
ai-decision-log-conformance · 3 nodes · GATED · PREPARE-AHEAD
AI Decision Log Conformance
Gated chain. Annex III FS obligations classifier (ART-238) gates on is_high_risk=false → exits OUT_OF_SCOPE. High-risk confirmed: Art 12(2) log record builder (ART-236) → IETF AAT audit trail validator (ART-237). Full-stack EU AI Act Art 12/26/27 conformance.
◆ ART-238 (gate) → ART-236 → ART-237
insurance-ai-bias-attestation · 2 nodes · GATED · US IN FORCE
Insurance AI Bias Attestation
Gated chain. BIFSG bias tester (ART-239) gates on bias_detected=true → routes to NAIC AIS readiness assessor (ART-240). Default (no bias detected): exits as attestation pass. Colorado SB 21-169 Dec 1 annual attestation + NAIC AIS gap remediation.
◆ ART-239 (gate) → ART-240
agent-audit-trail-conformance · 2 nodes · Linear · PREPARE-AHEAD
Agent Audit Trail Conformance
Linear two-step chain. Art 12(2) AI decision log record builder (ART-236) → IETF AAT chain-linked audit trail validator (ART-237). End-to-end agent audit trail conformance for EU AI Act high-risk FS AI systems. No gate; both steps always execute.
→ ART-236 → ART-237

Chain topology

ai-governance-fit (ART-64) · entry point ├──→ ai-governance-gpai-agentic (DO NOW · GPAI Arts 53-55 in force) ├──→ ai-governance-fairness-bias (DO NOW · non-discrimination) ├──→ ai-governance-resilience-overlap (DO NOW · DORA) ├──→ ai-governance-conformity (PREPARE-AHEAD · provider lifecycle) ├──→ ai-governance-fria-monitoring (PREPARE-AHEAD · deployer lifecycle) ├──→ ai-governance-credit-ai-conformity (PREPARE-AHEAD · credit vertical) └──→ (all) → ai-governance-audit-pack (convergence terminal) AI decision logs + US insurance AI bias ai-decision-log-conformance ◆ GATE: ART-238 (is_high_risk=false → end) → ART-236 → ART-237 insurance-ai-bias-attestation ◆ GATE: ART-239 (bias_detected=true → ART-240; default → end) agent-audit-trail-conformance LINEAR: ART-236 → ART-237

Who runs these chains

The AI-Act supply chain from GPAI provider to market-surveillance authority.
Tier 1: AI assurance firms + notified bodies
The verifiers
Big Four AI assurance practices, specialist AI audit firms, and notified bodies that certify high-risk systems. Primary chains: ai-governance-conformity, ai-governance-audit-pack. An endorsed artifact becomes a conformity-evidence standard.
Tier 2: Banks & insurers (providers + deployers)
The primary buyer
Model-risk, compliance, and AI-governance teams at lenders and insurers running high-risk credit/insurance AI. Primary chains: ai-governance-conformity, ai-governance-fria-monitoring, ai-governance-fairness-bias, ai-governance-credit-ai-conformity, ai-governance-resilience-overlap.
Tier 3: GPAI + agentic-AI platforms
The upstream
Foundation-model and agentic-platform providers with GPAI/systemic obligations (in force now). Primary chain: ai-governance-gpai-agentic. The reflexive tie to the agent-economy runtime buyers.
Tier 4: AI governance + RegTech vendors
The embedders (M&A-relevant)
AI governance, model-risk, and compliance-automation vendors embedding aig-* chains as MCP tools. The fastest-growing adjacency (~40% CAGR AI governance TAM). A hash-anchored conformity-evidence layer is what AI-governance tooling lacks.

Related: decision-receipt crosswalk

How the OCG artifact maps onto the record-keeping requirements of Art 12(2), ECOA Reg B §1002.12, ASC 815, and IETF AAT, field by field.
Crosswalk guide · Art 12 / Reg B / ASC 815 / AAT
OCG Artifact as Decision Receipt
Field-by-field alignment map: execution_hash (§4), policy_parameters (§12), kernel identity (§17), RFC 3161 anchor (§20), VC/SD-JWT exports (§13.11/§13.12) vs. the four decision-record regimes. Alignment map, not a conformance claim.
Crosswalk guide
EU AI Act (Reg. 2024/1689): eur-lex.europa.eu/eli/reg/2024/1689/oj. Arts 4, 5, 6 + Annex III, 9–15, 26–27 (FRIA), 43/47/48, 50–55, Annex IV. Verify before citing.
GPAI Code of Practice: EU AI Office. Verify current version and draft status.
Digital Omnibus on AI (provisional agreement 7 May 2026): Annex III high-risk → 2 Dec 2027. Legal effect on formal adoption before 2 Aug 2026; else original 2 Aug 2026 applies. Monitor Official Journal.
DORA (Reg. 2022/2554): Fully enforced 17 Jan 2025. RoI consolidated deadline 30 Apr 2026. First TLPT notifications late 2026/early 2027.
Penalties: Art 5 prohibited practices, up to €35M / 7% global turnover. GPAI violations, up to €15M / 3%. Verify against consolidated text.
Colorado SB 21-169 / Reg 10-1-1 (2023): Prohibits unfair discrimination in insurance based on external consumer data and AI. Two-prong bias test: statistical (p<0.05 AND ≥5pp marginal effect) and premium (≥5% above group avg). Annual Dec 1 attestation for affected Colorado-licensed carriers. Verify current enforcement scope with Colorado DOI.
NAIC AI Model Bulletin (2020 / 2023 update) & AIS Evaluation Tool (2024): Non-binding guidance on responsible AI use in insurance. AIS = AI System Use Evaluation. 6 dimensions, 0–18 composite score. Voluntary but increasingly cited in market conduct examinations. Verify adoption status in your state jurisdiction.
IETF draft-sharif-agent-audit-trail-00: Proposes a standard schema for agent audit trail records including action_class, outcome, trust_level enumerations and sha256 chain linkage. Verify current draft status and IETF adoption trajectory before citing in regulatory submissions.
Cross-cluster: Cluster ③ (AI Governance) ↔ Cluster Ⓐ (Fair Lending & Adverse Action): see guide-fair-lending.html for ECOA/HMDA disparate-impact tools that complement art-239 BIFSG bias testing.
OpenChainGraph v0.4 · Suite · Agent Economy Runtime · Spec v0.4 · Zero PII · CC BY 4.0