Evidence Library

Evidence Library

Public notes on what AAES governs, what it records, and how to check an export.

Last reviewed:

StagePublic review
What is publicProduct evidence, framework and jurisdiction notes
What is notNDA appendix

Scope

AAES is a client-operated governance layer for enterprise AI agents. It governs tool use and actions routed through AAES, not prompts or model completions.

These pages describe the product. They are not a certification or a legal opinion. AAES does not certify that a client has met a regulator's requirements. The client remains the regulated entity.

Enforcement requires control of the agent's credential path. Work that bypasses AAES is invisible. Observation is not enforcement.

Looking for the pre-built vendor packs instead? Those live in the Capability Library: registration templates for vendors such as Stripe, Slack, and GitHub, with the review state of each pack shown honestly. The Evidence Library documents what AAES governs and records; the Capability Library lists what ships for each vendor. They are different documents for different questions.

Read the scope and status

Product evidence

Use these pages to scope a runtime evidence pack for evaluation: what AAES governs, what it records, how integrity is checked, and which tests need to be run in the client's environment.

Native adapters are tested against local servers speaking vendor API formats, not live vendor tenants. Live tenant validation happens during a design partnership. See security disclosures for the stated internal checks and their limits.

Framework references

Voluntary frameworks and community lists a reviewer may cite. These notes describe action-layer records a reviewer can inspect; none is a scorecard of the framework and none claims conformity.

Jurisdiction context

Narrow, dated notes on instruments a risk team in each jurisdiction may ask about, with each instrument's exact status and the limits of what AAES records establish. Each note shows its own review date. Hong Kong and Singapore are the primary markets; the remaining notes are listed alphabetically. Not legal advice.

Hong Kong

Primary market

Instrument status as reviewed (PDPO, PCPD framework and compliance checks, agentic-AI guidance, the SFC circular) with the limits of what AAES records establish.

Singapore

Primary market

Instrument status as reviewed (IMDA's agentic-AI framework, the MAS proposal on AI risk management, PDPA, FEAT) with the limits of what AAES records establish.

Australia

Voluntary AI guidance, the Privacy Act automated-decision transparency duty commencing December 2026, and APRA's CPS 230 / CPS 234 for regulated entities.

European Union

The AI Act's staged application (with the Digital Omnibus now in force and high-risk dates deferred) GDPR's automated-decision rules, and DORA for financial entities.

Japan

The AI Promotion Act in force since September 2025 (a promotion statute without penalties) and APPI for personal data.

Switzerland

No comprehensive AI statute; the revised FADP applies to AI, FINMA Guidance 08/2024 sets expectations for supervised institutions, and Council of Europe convention implementation is pending.

United Arab Emirates

Three overlapping regimes (federal PDPL, DIFC, and ADGM) plus the Central Bank's 2026 guidance on responsible AI in financial services.

United Kingdom

Sectoral regulation without a comprehensive AI statute: FCA/PRA operational resilience, critical third parties, SM&CR accountability, and UK GDPR automated-decision rules.

United States

No comprehensive federal AI statute; an executive-order push against state laws, and binding state and municipal instruments in Texas, California, Illinois, New York City and elsewhere.

Design-partner appendix

The design-partner appendix is private material under NDA, not a public download. Instrument-specific memos (including DORA) are NDA-only.

Contact AAES about the design-partner appendix under NDA

Evaluation

Start with the evaluation scope, then examine the credential path, controls, and evidence in the client's environment. Internal checks do not establish production validation or independent certification.

Read the evaluation procedure · Discuss the appendix under NDA

Scope an evaluation