EU AI Act GDPR ISO/IEC 42001 NIST AI RMF

AI Governance & Compliance

Provenance exists so you can use natural-language analytics without losing defensibility. Here's how we align with the frameworks your compliance team cares about.

Frameworks we build for

Provenance produces deterministic, auditable analytics outputs. That design choice isn't accidental — it's what these regulations require when AI touches decision-making.

EU AI Act

Regulation (EU) 2024/1689

The world's first comprehensive AI law. Entered into force August 2024, with obligations phasing in through 2027. Mandates transparency, traceability, and human oversight for AI systems involved in decision-making.

  • Article 13 — Technical documentation and traceability. Provenance logs every step from question to output as a reviewable execution plan
  • Article 14 — Human oversight. The Receipt is designed for human review before any output enters a decision workflow
  • Article 9 — Risk management and monitoring. Deterministic execution means the same query always produces the same plan — auditable and reproducible
  • Article 50 — Transparency obligations. Every Provenance output explicitly documents that AI was used for intent parsing, while execution is deterministic

GDPR

Regulation (EU) 2016/679

The General Data Protection Regulation governs how personal data is processed. When analytics queries touch personal data, GDPR requires explainability, documentation, and purpose limitation.

  • Article 22 — Right to explanation for automated decisions. Provenance's Receipt shows exactly which data was queried, how it was joined, and what parameters drove the result
  • Article 35 — Data Protection Impact Assessments. Full lineage and parameter logging provide the documentation DPIAs require
  • Article 25 — Privacy by design. Provenance runs inside your data perimeter — queries execute on your infrastructure, not ours
  • Articles 13-14 — Transparency. Every output includes the complete execution path, making it clear how personal data was processed

ISO/IEC 42001

AI Management System

The international standard for AI management systems. Requires structured documentation, risk treatment, and accountability throughout the AI lifecycle.

  • AI risk assessment — Deterministic execution eliminates the "black box" risk class. The plan is inspectable before it runs
  • Lifecycle documentation — Every query generates a persistent, exportable artifact (Receipt) covering inputs, plan, parameters, and outputs
  • Continuous monitoring — Reproducible reruns let you verify that outputs remain consistent as underlying data changes
  • Accountability — The Receipt creates a chain of evidence from the person who asked the question to the data that answered it

NIST AI RMF

AI Risk Management

The NIST AI Risk Management Framework provides voluntary guidance for managing AI risks. Increasingly referenced by US and international regulators as a baseline for trustworthy AI systems.

  • Govern — Provenance embeds governance into the analytics workflow itself, not as an external review layer
  • Map — Dataset lineage and parameter capture map exactly which data sources contributed to each output
  • Measure — Deterministic execution creates a stable baseline. Re-run any query to verify consistency
  • Manage — The exportable Receipt gives risk and compliance teams a concrete artifact to review, approve, or escalate

How we think about governed analytics

These aren't aspirational. They're architectural decisions embedded in how Provenance works.

Principle 01

Determinism over probabilism

AI parses intent. Execution is deterministic. Same question, same data, same answer. No hidden prompt roulette.

Principle 02

Evidence by default

Every output ships with its Receipt — the queries, parameters, joins, and intermediate artifacts that produced it. Audit-ready from the start.

Principle 03

Your perimeter, your data

Provenance runs inside your infrastructure. Data doesn't leave your boundary. Governance without the data residency headache.

Principle 04

Designed for interoperability

We align with emerging standards for AI documentation and risk management. No vendor lock-in on your compliance artifacts.

Principle 05

Human review, not human bypass

The Receipt exists so a human can review the work before it enters a decision. We build tools for oversight, not autopilot.

Principle 06

Regulation as catalyst

We see the EU AI Act and emerging regulation as the reason to build analytics infrastructure people can actually trust and defend.

Our commitment

As an EU-based company operating under Greek and European law, we build Provenance to the standard we'd want for our own compliance. Governed analytics shouldn't require a separate compliance workstream — it should come with the answer.

Want to see how Provenance fits your governance requirements?

Explore Provenance Talk to us

For detailed legal documentation, see our policy pages:

Privacy Policy Terms of Use