Governance and compliance
Governance in BRAIAN means controls enforced by the runtime and evidence produced by it. Policies constrain what agents may do, the audit log records what they did, and evaluation shows how behaviour changed between versions. This section maps those mechanisms to the EU AI Act, the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP).
Evidence produced by the runtime
- Records of automated decisions with inputs, outputs and the model version used.
- Human oversight records: who approved what, when, and with which amendment.
- Policy change history, including who activated a control in which environment.
- Evaluation results per process version, showing behaviour changes over time.
Mapping to obligations
- EU AI Act
- Human oversight, logging, transparency of automated decisions and technical documentation of the deployed system.
- GDPR
- Lawful processing boundaries, data minimisation through field policies, and records of processing activities.
- Swiss nFADP
- Processing within Swiss residency boundaries and disclosure of automated individual decisions.
- ISO/IEC 27001 and 42001
- ÆTERION is preparing for certification against both standards; no certification is held today.
Division of responsibility
ÆTERION supplies the software, its controls and the evidence it produces. The customer decides which processes are automated, which thresholds apply and who approves escalations. Regulatory classification of a use case remains with the organisation deploying it.
