Help center
How Kanonik supports your AI-governance work.
A precise statement of what Kanonik does, maps to, and deliberately does not do.
A precise statement of what Kanonik does and does not do, against the frameworks your buyers and auditors care about. Kanonik supports your compliance work and maps to specific clauses. It does not provide compliance with any framework, and it does not certify you against any standard. That distinction is the whole point of this article, because a technical reviewer will test for it.
The four things standards bodies are converging on
Across the recent agent-governance work, four expectations recur for any system that acts on its own. Here is where Kanonik maps, and where it does not:
- A complete decision-chain audit. Logging of every action a system takes, including why it chose the path it did. Kanonik maps here directly: the append-only, tamper-evident record captures the proposal, what was considered, the rule applied, the verdict, the reasoning, and the model and prompt version. This is the strongest single alignment.
- Meaningful human oversight at the decision point. Kanonik maps here: no change takes effect without a named human approval, recorded as part of the trail.
- Verification of the documented control against what actually happened. Kanonik maps here: an independent check runs on the server, before approval, and cannot be bypassed by the system being checked.
- Agent identity and least-privilege. Partial. Kanonik authenticates the connecting client and gates writes behind approval; richer agent-identity standards are an active area we track rather than claim.
How this lines up with named frameworks
- EU AI Act. This is binding law; its high-risk provisions carry record-keeping and human-oversight obligations (for example, the record-keeping article). Kanonik produces the decision-chain record and the human-approval evidence that support those obligations. Kanonik does not make you compliant with the Act, and being in scope is a determination only you and your counsel can make.
- ISO/IEC 42001. A certifiable standard for an AI management system. Kanonik's record, verification, and approval evidence support an AI management system. Kanonik is not ISO/IEC 42001 certified, and using it does not certify you.
- NIST AI RMF and the NIST agent-standards work. Voluntary US frameworks. Kanonik aligns to their decision-chain and oversight expectations. Notably, NIST has named the Model Context Protocol among candidate agent standards, and Kanonik is MCP-native, so this alignment is an architectural fact rather than a marketing one.
Framework names, effective dates, and clause numbers move. Verify any specific citation against the primary source before you put it in an audit response or a contract.
What Kanonik does not do
It does not collect your evidence for you, automate a certification, or stand in for legal advice on whether a given law applies to you. It produces the accountability record for AI-made changes, and maps that record to the clauses your auditor will ask about. The framework is yours to meet; Kanonik is built to help you prove you did.
More help
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.