Scope
AAES is a client-operated governance layer for enterprise AI agents. It governs tool use and actions routed through AAES, not prompts or model completions.
These pages describe the product. They are not a certification or a legal opinion. AAES does not certify that a client has met a regulator's requirements. The client remains the regulated entity.
Enforcement requires control of the agent's credential path. Work that bypasses AAES is invisible. Observation is not enforcement.
Looking for the pre-built vendor packs instead? Those live in the Capability Library: registration templates for vendors such as Stripe, Slack, and GitHub, with the review state of each pack shown honestly. The Evidence Library documents what AAES governs and records; the Capability Library lists what ships for each vendor. They are different documents for different questions.
Product evidence
Use these pages to scope a runtime evidence pack for evaluation: what AAES governs, what it records, how integrity is checked, and which tests need to be run in the client's environment.
Scope and status
Enforcement requires control of the agent's credential path. Work that bypasses AAES is invisible. Observation is not enforcement. No SOC 2 report exists. A hosted offering is not available. No production adoption is claimed.
Controls
Named approval, permitted capabilities, scoped grants, budget ceilings, fail-closed journal writes, and sealed records. Budget ceilings do not cap vendor spending outside AAES.
Verification
Sealed, hash-chained action records and offline integrity checks. A valid record does not prove a complete action history or a successful external-world outcome. The default deployment has zero independent witnesses.
Trust model
What AAES can and cannot enforce, what happens if a component is compromised or unavailable, and what you keep if you stop using AAES.
Capability matrix
How credentials are held, which actions AAES can enforce, and what is implemented. Dated and checked by automated site tests against the daemon's custody wiring.
Evaluation
Control-evaluation scope and exit conditions. Results from a client's test tenant are produced during a scoped evaluation. Evaluation binaries are supplied through evaluation; the core repository is private.
Native adapters are tested against local servers speaking vendor API formats, not live vendor tenants. Live tenant validation happens during a design partnership. See security disclosures for the stated internal checks and their limits.
Framework references
Voluntary frameworks and community lists a reviewer may cite. These notes describe action-layer records a reviewer can inspect; none is a scorecard of the framework and none claims conformity.
AIUC-1 · AAES record properties
Seven selected properties, what each record shows, and the remaining gaps. Not a scorecard of the AIUC-1 standard.
ISO/IEC 42001
The certifiable AI management-system standard. Which action-layer records may serve as documented information in a client's own AIMS. AAES is not a certified product.
NIST AI Risk Management Framework
NIST AI RMF 1.0 is voluntary technical guidance. This note describes action-layer records a reviewer can inspect.
OWASP Top 10 for LLM Applications
A community awareness list, not a standard. Where action-layer controls relate to Excessive Agency, Unbounded Consumption and Prompt Injection, with the limits stated.
Jurisdiction context
Narrow, dated notes on instruments a risk team in each jurisdiction may ask about, with each instrument's exact status and the limits of what AAES records establish. Each note shows its own review date. Hong Kong and Singapore are the primary markets; the remaining notes are listed alphabetically. Not legal advice.
Hong Kong
Primary market
Instrument status as reviewed (PDPO, PCPD framework and compliance checks, agentic-AI guidance, the SFC circular) with the limits of what AAES records establish.
Singapore
Primary market
Instrument status as reviewed (IMDA's agentic-AI framework, the MAS proposal on AI risk management, PDPA, FEAT) with the limits of what AAES records establish.
Australia
Voluntary AI guidance, the Privacy Act automated-decision transparency duty commencing December 2026, and APRA's CPS 230 / CPS 234 for regulated entities.
European Union
The AI Act's staged application (with the Digital Omnibus now in force and high-risk dates deferred) GDPR's automated-decision rules, and DORA for financial entities.
Japan
The AI Promotion Act in force since September 2025 (a promotion statute without penalties) and APPI for personal data.
Switzerland
No comprehensive AI statute; the revised FADP applies to AI, FINMA Guidance 08/2024 sets expectations for supervised institutions, and Council of Europe convention implementation is pending.
United Arab Emirates
Three overlapping regimes (federal PDPL, DIFC, and ADGM) plus the Central Bank's 2026 guidance on responsible AI in financial services.
United Kingdom
Sectoral regulation without a comprehensive AI statute: FCA/PRA operational resilience, critical third parties, SM&CR accountability, and UK GDPR automated-decision rules.
United States
No comprehensive federal AI statute; an executive-order push against state laws, and binding state and municipal instruments in Texas, California, Illinois, New York City and elsewhere.
Design-partner appendix
The design-partner appendix is private material under NDA, not a public download. Instrument-specific memos (including DORA) are NDA-only.
Evaluation
Start with the evaluation scope, then examine the credential path, controls, and evidence in the client's environment. Internal checks do not establish production validation or independent certification.
Read the evaluation procedure · Discuss the appendix under NDA
Related pages: Library: https://aaes.ai/library.html · Evaluation: https://aaes.ai/library/evaluation.html · Scope an evaluation: https://aaes.ai/contact.html?ref=library-evaluation · NDA appendix inquiry: https://aaes.ai/contact.html?ref=library-appendix · Security disclosures: https://aaes.ai/legal/security.html
