# Traceability

Maps the contracts in this kit to the obligations a reviewer, auditor or customer
security questionnaire will ask about.

**Read this section first, because most of it may not apply to you.**

---

## What this is

The contracts in `01-authority/`, `02-skills/`, `03-memory/` and the gates in
`04-gates/` produce written decisions and run evidence. Several regimes ask for
exactly that kind of artefact. This section says which artefact answers which
question, so you are not assembling it under time pressure the week a reviewer
asks.

## What this is not

**Not legal advice, and not a compliance certificate.** Nobody becomes compliant
by owning files. These artefacts are inputs to an assessment a qualified person
makes about your specific deployment.

**Not a claim that these obligations apply to you.** This is the part most
vendors in this space get wrong, and it is worth being blunt about: the EU AI
Act's deployer obligations in Article 26 apply to deployers of **high-risk** AI
systems. Most internal coding-agent deployments are not high-risk. Whether yours
is depends on what it does and where, and that determination is yours to make —
with advice, if the answer is not obvious.

If your deployment is not high-risk, Article 26 does not bind you, and a vendor
telling you otherwise is selling fear. The mapping is still useful: the same
artefacts answer customer security reviews, internal audit, and your own
question of whether the thing is safe to run.

---

## The three regimes covered

| File | Regime | Status |
|---|---|---|
| `eu-ai-act.md` | Regulation (EU) 2024/1689 | Article 50 transparency obligations applied from 2 August 2026 |
| `nist-ai-rmf.md` | NIST AI Risk Management Framework 1.0 | Voluntary framework, four functions |
| `iso-42001.md` | ISO/IEC 42001:2023 | Certifiable AI management system standard |

Each file states, obligation by obligation, which artefact in this kit speaks to
it and — importantly — where the kit does **not** help. A mapping that claims
full coverage is not a mapping, it is a brochure.

---

## How to use it

1. Decide whether the regime applies. `eu-ai-act.md` opens with that question
   rather than assuming the answer.
2. Read only the rows that apply to your deployment.
3. Fill the contracts those rows point at. They are the same files you would
   fill anyway; the mapping just tells you which ones a reviewer will ask for.
4. Assemble the evidence pack (`evidence-pack.md`) when someone asks. It is a
   list of what to hand over, not a new document to maintain.

---

## Keeping this honest

Regulatory text changes and guidance lands after it. Every claim in this section
carries the date it was checked and a link to the source. When you read a row
whose date is old, treat the row as a starting point and check the source before
relying on it.

Last reviewed: 2026-08-09.
