Updated: October 6, 2026 · Source-first reference130 documented agents & platforms · No paid rankings

AgentenTrust 2.0 · EU Evidence Layer

Which evidence is actually documented for EU AI Act and GDPR questions?

Direct answer: AgentenCode maps field-level product evidence to relevant governance and legal contexts. It shows what is documented, the scope in which it applies, when it was checked and which primary source supports it. It does not label an AI agent as “EU AI Act compliant” or “GDPR compliant” based on isolated features.

36normalized trust controls
802documented trust signals
130agent profiles
4evidence pillars

EU AI Act

Control points instead of a compliance label.

AgentenTrust surfaces evidence related to logging, human oversight, transparency, robustness and cybersecurity. A mapping means that the field can be relevant to an assessment. It does not mean a particular legal obligation automatically applies to every product or deployment.

EU AI Act on EUR-Lex ↗

GDPR

Separate data questions instead of one broad claim.

Residency, customer-data training, retention, DPAs, subprocessors, processing scope and security controls are stored as separate evidence fields. No single documented feature can establish GDPR compliance for a concrete use case.

GDPR on EUR-Lex ↗

EU Control Map

36 controls with explicit EU and GDPR context.

The cards describe semantic mappings. Concrete agent values come from the shared governance dataset and remain bound to scope, verification date and primary source. A control can be documented, explicitly negative, carry a documented value, or remain unknown.

Privacy & data

Data Residency

privacy.residency.available

Whether the provider publicly documents data residency for the relevant product or plan scope.

GDPR Art. 5
Privacy & data

Customer-selectable region

privacy.residency.customer_region_selectable

Whether customers can select a documented processing or hosting region for the relevant scope.

GDPR Art. 5
Privacy & data

Documented region

privacy.residency.region

Which region or regions are explicitly named by the primary source.

GDPR Art. 5
Privacy & data

Customer data used for training

privacy.training.customer_data

Whether the primary source explicitly says customer data is or is not used for model training.

GDPR Art. 5
Security & access

Encryption at rest

security.encryption.at_rest

Documented encryption of stored data within the stated product scope.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

Encryption in transit

security.encryption.in_transit

Documented encryption for data in transit.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

Customer-managed keys

security.customer_managed_key

Whether customer-managed encryption keys or BYOK are documented.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

SOC 2 Type II

security.soc2_type2

Whether SOC 2 Type II coverage is publicly documented for the relevant product scope.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

SAML SSO

governance.sso.saml

Documented support for SAML single sign-on.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

OIDC SSO

governance.sso.oidc

Documented support for OIDC single sign-on.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

SCIM

governance.scim

Documented support for SCIM provisioning.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

RBAC

governance.rbac

Documented role-based access control.

EU AI Act Art. 15 · GDPR Art. 32
Security & access

Custom roles

governance.custom_roles

Documented custom or granular administrative roles.

EU AI Act Art. 15 · GDPR Art. 32
Human control

Human approval

governance.human_approval

Documented human approval inside an agentic workflow.

EU AI Act Art. 14
Human control

Pre-action approval

governance.approval.pre_action

Documented approval before a consequential or sensitive action is executed.

EU AI Act Art. 14
Human control

Human oversight

governance.human_oversight

Documented mechanisms for human oversight of agent behavior.

EU AI Act Art. 14
Human control

Permission controls

governance.permission_controls

Documented permission controls for agents or workflows.

EU AI Act Art. 14
Human control

Policy controls

governance.policy_controls

Documented policy controls that constrain agents or actions.

EU AI Act Art. 14
Human control

Tool permissions

governance.tool_permissions

Documented controls over which tools an agent may use.

EU AI Act Art. 14
Human control

Action permissions

governance.action_permissions

Documented controls over which external actions an agent may execute.

EU AI Act Art. 14
Human control

Delegation controls

governance.delegation_controls

Documented limits on delegation to other agents or components.

EU AI Act Art. 14
Human control

Kill switch

governance.kill_switch

Documented ability to stop or disable agentic execution.

EU AI Act Art. 14
Human control

Rollback

governance.rollback

Documented rollback or recovery after agent actions.

EU AI Act Art. 14
Auditability & traceability

Audit logs

governance.audit_logs.available

Whether audit or compliance logs are publicly documented.

EU AI Act Art. 12
Auditability & traceability

Audit-log retention

governance.audit_logs.retention_days

Documented retention period for audit or compliance logs.

EU AI Act Art. 12
Auditability & traceability

Audit log API

governance.audit_logs.api

Whether audit logs can be retrieved programmatically through an API.

EU AI Act Art. 12
Auditability & traceability

SIEM export

governance.audit_logs.siem_export

Whether export or integration with SIEM systems is documented.

EU AI Act Art. 12
Auditability & traceability

Observability

observability.available

Whether observability or monitoring capabilities are documented.

EU AI Act Art. 12
Auditability & traceability

Tracing

observability.tracing

Whether execution traces are documented for agentic runs.

EU AI Act Art. 12
Auditability & traceability

Action-level audit

governance.audit_logs.action_level

Whether individual agent actions can be traced at audit level.

EU AI Act Art. 12
Privacy & data

Data retention / retention policy

privacy.retention.policy

Documented retention or deletion logic for relevant customer or product data.

GDPR Art. 5
Privacy & data

DPA / data processing agreement

privacy.dpa.available

Whether a Data Processing Agreement is publicly documented for the relevant scope.

GDPR Art. 28
Privacy & data

Subprocessor list

privacy.subprocessors.list_available

Whether the provider publishes a current list of subprocessors for the relevant scope.

GDPR Art. 28
Privacy & data

Data processing / deployment scope

privacy.processing.scope

The product, plan, region or deployment scope to which a privacy or processing statement actually applies.

GDPR Art. 5 · GDPR Art. 28
Security & access

Secrets / credential handling

security.secrets.credential_handling

Documented handling of secrets, tokens or credentials in the relevant agent or platform scope.

EU AI Act Art. 15 · GDPR Art. 32
Auditability & traceability

Activity history

governance.activity_history.available

Whether an activity or execution history is documented for relevant agent actions.

EU AI Act Art. 12

Interpretation rules

Unknown is not false — and scope is part of the fact.

Unknown stays unknown

If AgentenCode cannot find sufficiently specific public evidence, the field remains unknown. Missing documentation is not converted into a negative claim.

False requires evidence

A negative value is stored only when a reliable primary source explicitly documents non-availability, a prohibition or another negative state.

Scope matters

Enterprise-only evidence remains enterprise-only. Plan, region, hosting mode, channel and administrative configuration can materially change what a documented control means.

Primary sources lead

Official product, security, privacy, legal and technical documentation has priority. Third-party summaries do not silently become product facts.

How to use AgentenTrust in due diligence

Start with the controls that matter for your deployment: identity, permissions, data handling, auditability and human control. Use AgentenCode to see which points are publicly documented and which are still evidence gaps. Then verify the exact plan, region, tenant configuration and contractual terms with the provider before making a procurement, security or legal decision.

For example, “SAML SSO is documented” is useful evidence about enterprise access control. It is not proof that every plan has SAML, that the implementation meets your internal policy, or that the product is legally suitable for a particular processing activity. The same rule applies to data residency, human approval, audit logs and every other control.

AgentenTrust supports due diligence; it does not replace it. Legal obligations depend on role, use case, data, risk classification and deployment context. Security also depends on configuration and operational practice, not only documented product features.

Machine-readable evidence

The visible EU layer is backed by structured public datasets. governance.json contains agent-level governance signals; eu-controls-en.json exposes the English control map; trust-controls.json defines the normalized control taxonomy. This keeps the human-readable page, the comparison tools and machine-readable evidence aligned.

Field-level trust history is stored separately from the current state. When a verified field changes after the baseline, the history model can preserve its previous value, new value, scope, verification date and source rather than silently overwriting the past.

Frequently asked questions

Does AgentenCode say whether an AI agent is EU AI Act compliant?

No. AgentenCode shows documented product and governance evidence and maps controls to relevant legal contexts. Whether a legal obligation applies depends on the specific system and use case.

Does EU data residency automatically mean GDPR compliance?

No. Data residency is one evidence field. It does not by itself establish lawful processing, transfer compliance, processor obligations, retention rules or security adequacy.

Why can a control be Unknown?

Because public evidence may be missing, too broad, plan-specific or ambiguous. AgentenCode keeps that uncertainty visible instead of guessing.

Can providers submit corrections?

Yes, but corrections are evaluated against the same source-first methodology. A provider relationship or submission does not buy a positive status or ranking.