Fidacy is an external, deterministic control with a tamper-evident audit and signed verdicts — the architecture regulators and risk teams ask for. Below is the dual EU/US mapping. These are alignment claims: Fidacy provides the evidence artifacts; your institution maps them to its own obligations.
The de-facto US framework for trustworthy AI, built on four core functions. Fidacy supplies concrete mechanisms and evidence under each.
GOVERNVersioned, activatable risk policies with every change recorded; an admin audit log of who changed what, when. Decisions reference the exact policy version that produced them.
MAPKnow-Your-Agent identity resolution by RFC 7638 thumbprint plus decision classification — each action is mapped to an agent, a mandate, and a risk context before it is scored.
MEASUREA deterministic Trust Score with the exact signals behind it, backtesting against historical traffic, and per-decision metrics (rates, confidences, rejection reasons).
MANAGEFail-safe degradation to review on any fault, webhooks for human-in-the-loop handling, a signed verdict for every decision, and a hash-chained audit trail anchored to Bitcoin for after-the-fact review.
Where audit evidence gets adjudicated, control by control. Coverage is honest: full means evidenced end to end for gated actions, partial means evidenced with named limits, moderate means supporting evidence only.
{{ row.control }}
{{ row.req }}
{{ row.mech }}
{{ row.coverage }}Released Feb 19, 2026: 230 control objectives across 7 risk domains and 4 adoption stages, voluntary and industry-led, structurally aligned with NIST AI RMF. Fidacy does not certify against it — no one does. It provides the evidence artifacts an institution maps to its own control objectives: signed verdicts, the policy-version record, the tamper-evident audit chain, decision metrics, and backtests. Because the FS AI RMF aligns with NIST, the mapping above carries directly into a Treasury-framework control narrative.
SB 26-189 (signed May 14, 2026, effective Jan 1, 2027) regulates automated decision-making technology in "consequential decisions" — explicitly including financial services — under a disclosure model. Fidacy supplies what a deployer needs: developer disclosure, testing documentation (backtests, decision metrics), audit cooperation via the re-verifiable trail, and indemnification terms in the enterprise agreement.
Fidacy is built for automated decisioning in a high-risk-adjacent context, where the law expects governance, record-keeping, and human oversight. The append-only, hash-chained audit trail — sealed with Merkle anchors and re-verifiable offline — is the non-repudiable evidence automated-decision systems are expected to keep. Fail-safe degradation to review and the webhook path give the human-oversight hooks the Act calls for.
Under the 2026 Digital Omnibus, Art. 50 chatbot transparency applies Aug 2, 2026; high-risk record-keeping (Annex III) was deferred to Dec 2, 2027. Fidacy is not the high-risk system — it is the external control and evidence layer for the economic actions an AI system takes.
{{ row.control }}
{{ row.req }}
{{ row.mech }}
{{ row.coverage }}The full mapping, including notes and gap narratives, is published machine-readable at fidacy.com/compliance/mappings.json — a GRC tool or an AI assistant can consume it directly.
Read this honestly. These are alignment claims, not a certification and not legal advice. Coverage describes the evidence artifacts Fidacy supplies for the gated slice of your system; mapping them to your institution's obligations is your compliance team's call.
GDPR. Fidacy minimizes personal data on the decision path — the optional reasoning layer receives only non-sensitive signals, never raw PII or payment credentials. Residency, retention, and erasure live in Data Protection; a DPA is available on request.
One mechanism, many frameworks. The same primitives — signed verdicts, a versioned policy record, and a tamper-evident audit chain — are the evidence that satisfies the EU AI Act, maps to NIST and the Treasury FS AI RMF, and backs Colorado ADMT disclosures. You instrument once and answer to all of them.