Frameworks roadmap

One engine. Every framework.

EU AI Act today — the deep, article-cited core that nobody else has built. ISO 42001, NIST AI RMF, SOC 2 next, on the same shared evidence core with live cross-framework coverage.

EU AI Act

Only we do this

Annex III high-risk classification, Annex IV technical docs, FRIA, transparency. The only platform with this natively.

Live

GPAI (General-Purpose AI)

Only we do this

Provider duties under Articles 53–55. Systemic-risk handling on the Enterprise tier.

Live

ISO/IEC 42001 — AI Management System

Control library + cross-walk in private beta. Ships with Release 2.

In beta

NIST AI RMF

Only we do this

Govern / Map / Measure / Manage functions tagged across existing controls. Read-only in current build.

In beta

SOC 2 (Type I, then Type II)

Shared evidence core lets one artifact satisfy SOC 2 + ISO 42001 + EU AI Act. Bundle target: Q1 2027.

Planned

ISO/IEC 27001

Bundle authoring on the same Framework Engine. Q2 2027.

Planned

GDPR + DPA tooling

Cross-walk with EU AI Act Article 27 (FRIA) controls. Q2 2027.

Planned

HIPAA

Healthcare deployers running AI in regulated workflows. Q3 2027.

Planned

PCI DSS

Release 3 module. Connector-heavy, scheduled after SOC 2 Type II.

Planned

Cross-framework coverage

Every obligation is tagged so one piece of evidence satisfies every framework that maps to it. Complete the EU AI Act and you arrive at SOC 2 and ISO 42001 with most controls already pre-satisfied. Land here, expand in software — not in another year-long engagement.