cybiont publishes controls with bounded claims. Whether a control contributes to a regulated organisation's obligations depends on that organisation's role, intended use, risk assessment, deployment, and wider control environment. This page is a bounded source map, not certification or legal advice.
Publicly checkable now
- The signed AI-response record includes a valid bundle, a tampered negative control, an offline verifier, and explicit claim limits.
- A successful verification establishes the signed commitments described on that page. It does not attest model execution, continuous device presence, firmware appraisal, or performance.
- The browser DLP is a prototype and not a production system, matching the warning in its shipped manifest.
- The wider compliance-ledger and governance-workflow components are prototypes. Trusted execution is an architecture concept whose implementation is deployment- and partner-specific.
No completed independent security assessment or authority approval is published on this site. Those outcomes are not claimed. Any pilot must identify the available artefacts, claims, limits, and acceptance criteria in writing before work starts.
Primary regulatory sources
FINMA
FINMA Guidance 08/2024 draws supervised institutions' attention to AI risks and FINMA's supervisory observations. It addresses governance, risk management, transparency, and proportionality to an institution's size, complexity, structure, and risk profile. It is a Guidance, not a FINMA Circular, and it does not approve cybiont or prescribe this evidence format.
The public response-record package may be assessed as one technical control within a wider internal control system. It does not establish that the wider system meets FINMA expectations.
Regulation (EU) 2024/1689
Applicability of the EU AI Act depends on the actor, system, and intended use. Under Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, the relevant high-risk provisions for Annex III systems apply from 2 December 2027 and those for Annex I systems from 2 August 2028.
The Commission's Article 50 transparency guidelines describe provenance and authenticity techniques as examples; they do not require providers to keep a full provenance chain or content history. The public package is therefore described only as a control an auditor can evaluate and rely on within its stated scope, not as EU AI Act compliance.
Data protection
Swiss and EU data-protection duties are deployment-specific. Client-held records can support a control design, but data location or customer custody alone does not establish compliance with the Swiss Federal Act on Data Protection or the GDPR.