Compliance — turning agent execution into evidence.

Compliance — turning agent execution into evidence.

Compliance — turning agent execution into evidence.

Frameworks tell you what to control. Waxell records whether the control actually held.

Frameworks tell you what to control. Waxell records whether the control actually held.

Waxell Compliance is the mapping between agent governance controls and the frameworks auditors ask about — NIST AI RMF and the EU AI Act — producing a durable execution record for every policy decision, rather than a questionnaire answered once a year.

Waxell Compliance is the mapping between agent governance controls and the frameworks auditors ask about — NIST AI RMF and the EU AI Act — producing a durable execution record for every policy decision, rather than a questionnaire answered once a year.

Most AI compliance work produces documents. Policies get written, reviewed, filed, and then the agents run anyway — and when an auditor asks what actually happened on a Tuesday in March, the answer is a spreadsheet and a shrug. Waxell inverts that. Policies are enforced at execution, and every evaluation leaves a record. When a framework asks whether you have human oversight over high-risk decisions, the answer is not a policy document. It is the log of every approval hold, who cleared it, and when.

Most AI compliance work produces documents. Policies get written, reviewed, filed, and then the agents run anyway — and when an auditor asks what actually happened on a Tuesday in March, the answer is a spreadsheet and a shrug. Waxell inverts that. Policies are enforced at execution, and every evaluation leaves a record. When a framework asks whether you have human oversight over high-risk decisions, the answer is not a policy document. It is the log of every approval hold, who cleared it, and when.

FREE TO START. 2-LINE SETUP.

WITHOUT IT

Framework obligations live in a GRC tool, disconnected from what the agents do. Evidence is assembled by hand before each audit, from logs that were never designed to answer the question being asked.

WITH IT

The control and the evidence are the same object. A policy that fires produces the record that proves it fired. Audit preparation becomes an export, not a project.

What do NIST AI RMF and the EU AI Act actually require of AI agents?

What do NIST AI RMF and the EU AI Act actually require of AI agents?

What do NIST AI RMF and the EU AI Act actually require of AI agents?

NIST AI RMF is a voluntary, non-certifiable framework for managing AI risk. The EU AI Act is binding regulation, with obligations attaching to high-risk systems. Neither offers a vendor certification — and neither should be presented as one.

How does Waxell map to the NIST AI RMF?

How does Waxell map to the NIST AI RMF?

How does Waxell map to the NIST AI RMF?

Function What the framework asks for Waxell policy categories Evidence produced
NIST AI RMF 1.0 — core functions
Function 1 Govern Accountability, documented policy, and oversight across the AI lifecycle. The cross-cutting function that makes the other three repeatable.
Control Compliance Identity Delegation Approval
Versioned policy definitions and their full change history. Policies are first-class objects applied by reference — changed once, changed everywhere, with no code deploy.
Function 2 Map Frame the system, its operating context, and the stakeholders accountable for it.
Identity Data Access Context Management
Agent inventory and the reachable surface of each agent. Device-level AI inventory via Waxell Endpoints
Function 3 Measure Assess, analyse and benchmark identified risks using repeatable methods.
Quality Grounding Reasoning Input Validation
Evaluator runs, datasets and experiments, against captured execution traces. Execution traces — Waxell Observe
Function 4 Manage Allocate risk-treatment resources and apply controls to prioritised risks.
Kill Rate-Limit Cost Safety Content Privacy Network
The enforcement decision record — which rule fired, on which call, with what outcome, evaluated before execution proceeds.
NIST AI RMF is voluntary and has no certification scheme. No organisation is certified against it. This table maps Waxell's policy categories to the framework's four core functions and names the artifact each one produces for an assessor. Mapping is at function level; the AI RMF Playbook breaks each function into categories and subcategories.

How does Waxell map to EU AI Act obligations?

How does Waxell map to EU AI Act obligations?

How does Waxell map to EU AI Act obligations?

Scoped to obligations on high-risk systems. Waxell is not itself a high-risk AI system — this maps what Waxell produces for customers deploying agents that are.

Obligation Waxell capability Evidence produced
EU AI Act — obligations on high-risk AI systems
Article 12 Record-keeping Automatic capture of LLM calls, tool calls, decisions and hand-offs, for the operating life of the system. No instrumentation of individual functions required. Four distinct records, each owned by its product: Execution traces — Waxell Observe Tool-call audit log — Waxell MCP Gateway Hand-off record — Waxell Connect Lineage causality graph — Waxell Runtime
Article 14 Human oversight Approval holds on destructive actions, human-in-the-loop routing to a named person, and kill switches at agent, workflow and session level. The approval record — what was held, who cleared it, when, and what happened next.
Article 9 Risk management system A policy engine evaluated before execution proceeds, applied uniformly across every workflow rather than reviewed after the fact. Policy definitions, change history, and the outcome of every evaluation.
Article 15 Accuracy, robustness & cybersecurity Input validation, network policy and code-execution policy, plus prompt-injection scanning of MCP tool descriptions at fingerprint time. Scan results and the record of every blocked or held call. Tool-description scanning — Waxell MCP Gateway
Article 26 Deployer obligations Configurable log retention windows, and oversight assigned to resolved identities rather than shared service accounts. Retention configuration and the identity-resolved action log.
Waxell is not itself a high-risk AI system. Obligations under the EU AI Act attach to the provider or deployer of a high-risk system. This table maps what Waxell produces for teams operating agents that fall in scope — it does not transfer the obligation, and it does not constitute a conformity assessment.

What Waxell does not do

What Waxell does not do

What Waxell does not do

Waxell does not certify anyone. NIST AI RMF is a voluntary framework with no certification scheme, and the EU AI Act’s conformity assessment applies to systems, not vendors. Waxell enforces the controls and produces the evidence; the assessment, and the responsibility, stay with you.

How does Waxell govern its own agents?

How does Waxell govern its own agents?

Every row in those tables resolves to a record you can export. Not a policy document describing what should have happened.

FAQ

Is Waxell certified against the NIST AI RMF?

No, and no vendor is. NIST AI RMF is voluntary and has no certification scheme. Waxell maps its policy categories to the framework’s four functions and produces the evidence an assessor would ask for.

Does Waxell make my AI system EU AI Act compliant?

No. Compliance obligations attach to the provider or deployer of a high-risk system. Waxell provides the record-keeping, human oversight and risk-management controls those obligations require you to have.

What evidence can I export for an audit?

Waxell Observe produces execution traces. Waxell MCP Gateway produces a payload-free tool-call audit log. Waxell Connect produces the versioned record of hand-offs. Waxell Runtime produces a lineage causality graph.

Does Waxell hold SOC 2 or ISO 27001?

For current corporate compliance status, visit the Vanta Trust Center.

When do EU AI Act high-risk obligations take effect?

High-risk obligations are expected in late 2027 following the May 2026 Omnibus deferral. Confirm the latest consolidated timing before relying on this date.

Frameworks describe the controls you should have. Waxell is where they run, and where the record of them running is kept.

Waxell

Waxell provides observability and governance for AI agents in production. Bring your own framework.

Compliance — NIST AI RMF · EU AI Act · SOC 2 Type II (in progress) · HIPAA (in progress)

Governed continuously in Vanta.

© 2026 Waxell. All rights reserved.

Patent Pending.

Waxell

Waxell provides observability and governance for AI agents in production. Bring your own framework.

Compliance — NIST AI RMF · EU AI Act · SOC 2 Type II (in progress) · HIPAA (in progress)

Governed continuously in Vanta.

© 2026 Waxell. All rights reserved.

Patent Pending.

Waxell

Waxell provides observability and governance for AI agents in production. Bring your own framework.

Compliance — NIST AI RMF · EU AI Act · SOC 2 Type II (in progress) · HIPAA (in progress)

Governed continuously in Vanta.

© 2026 Waxell. All rights reserved.

Patent Pending.