Skip to main content
Compliance teams ask how an AI agent is overseen and how its actions are recorded. This page maps Parmana to the provisions they cite: the EU AI Act’s human oversight and record keeping articles, the NIST AI Risk Management Framework, ISO/IEC 42001, and the Reserve Bank of India’s IT and AI guidance. What Parmana is, for these purposes. Parmana is not itself an AI system. It sits between an AI agent and the systems it acts on, refuses any action a person has not approved, and signs a record of each action and each refusal. It is a technical measure a provider or deployer of an AI system can use to meet oversight and logging obligations for the actions an agent takes. It does not make a system compliant on its own, it does not cover the model, and this page is not legal advice. Ratings, as on the OWASP mapping:
  • Supports: Parmana provides a technical measure that meets the requirement for actions that go through it, with evidence you can check.
  • Partly: Parmana provides part of it. The rest is named.
  • Organizational: the requirement is about people, training or process. Parmana can record it, not do it.
Evidence refers to sections of docs/CLAIMS.md, threats in THREAT-MODEL.md, and attack scenarios you can run with npm run evaluate -- EV-xx (Evaluate Parmana).

EU AI Act

Articles 12, 14 and 26 apply to high-risk AI systems. Under the Digital Omnibus on AI, in force since July 2026, the high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Check the current text and your system’s classification with counsel.

NIST AI Risk Management Framework (AI RMF 1.0)

ISO/IEC 42001 (AI management system), Annex A

Reserve Bank of India (RBI)

For banks, NBFCs and payment system operators using AI agents, for example an agent that issues refunds through the Paytm connector (Connectors). Three RBI texts are relevant, with different status:
  • The Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (7 November 2023, in force from 1 April 2024) is binding on the banks, NBFCs, credit information companies and all India financial institutions it names.
  • The FREE-AI Committee report (Framework for Responsible and Ethical Enablement of AI, 13 August 2025) makes 26 recommendations. It is a committee report, not a direction.
  • The draft Guidance on Regulatory Principles for Model Risk Management, 2026 (24 June 2026, consultation closed 24 July 2026) covers AI and machine learning models. It is a draft; check the final text.
Provisions are summarized, not quoted, and FREE-AI recommendations are given a number only where it was confirmed. Read the source texts.

Reading this page

  • Only actions that go through Parmana are covered. Give agents credentials only to Parmana, so it is the one route to your systems.
  • Each rating has evidence you can check: run the attack scenarios, read the claim and its tests.
  • Open issues that matter here: approvers are not yet limited to particular actions or policies (G-50); facts an agent declares are not checked against another system and can only refuse (G-51). See Limitations.
  • This is a mapping, not a certification or legal opinion. The provisions are summarized; read the source texts: Regulation (EU) 2024/1689, NIST AI RMF 1.0 and ISO/IEC 42001:2023, the RBI IT Governance Master Direction and the FREE-AI report.