EU AI Act · Art 9 · Art 14 · HITL · WASM Runtime

The AI Oversight Magistrate

Five Spartan ephors held authority over even the kings. Ephor puts that constitutional oversight layer inside your AI agent infrastructure — policy gates, tamper-evident audit chains, and Human-in-the-Loop controls enforced at the point of execution.

Get Early Access See how it works
8 EU AI Act Articles Covered
Zero External DB Dependencies
WASM Component Model
100% Tamper-Evident Chain

Platform Capabilities

Governance as Code — Not as Afterthought

Every capability is embedded in the agent runtime via WASM components. No sidecar agents. No post-hoc audits. Compliance happens where the decision does.

Policy Gate

Every agent action passes through a WASM policy evaluator before execution. Define rules in composable policy-as-code; any violation triggers an instant hold — not a retrospective flag. Ship with confidence that your agent cannot violate its own policy envelope.

WIT · policy.evaluate

Tamper-Evident Audit Chain

Every captured action is linked into a SHA-256 hash chain. Append-only, verifiable from any entry. Your compliance team gets an immutable record of every decision the AI made — not logs you could edit, but a chain you can prove.

SHA-256 · append-only · chain-valid

Human-in-the-Loop Controls

High-risk actions are automatically held pending human approval. Reviewers decide via browser console, Pharo IDE widget, or any HTTP client. SLA timers enforce safe-default behaviour on timeout. Article 14 of the EU AI Act requires this for high-risk systems.

Art 14 · HITL · SLA-aware

Evidence Pack Export

Generate a structured evidence bundle for any time window: audit entries, policy snapshots, reviewer decisions, and chain integrity proof. Hand it to your conformity assessment body without bespoke tooling. Your GPAI system documentation is always current.

Art 11 · Art 47 · JSON + PDF

PII Guard & Data Minimisation

Configurable PII scrubbing runs at capture time, before the entry enters the chain. Define which fields are sensitive; Ephor redacts them in the canonical record while keeping the audit structure intact. Data governance and audit governance in one pipeline.

Art 10 · GDPR-aligned · configurable

Risk Monitoring Dashboard

Real-time visibility into agent risk levels, pending approvals, SLA burn-down, and chain integrity. Know your risk posture at a glance — not from a weekly report produced three weeks after the incident.

Art 9 · Art 72 · live · SLA

Architecture

Five Stages — One Oversight Layer

Every agent action passes through Ephor's five-stage pipeline. Like the five ephors of Sparta, each stage holds authority over the next.

01
Capture
Agent action intercepted before execution. Session, class, action, arguments logged.
entry:created
02
Evaluate
WASM policy engine scores risk. Low risk passes immediately; high risk triggers a hold.
policy:eval
03
Hold
Art 14 HITL: reviewer notified. SLA timer starts. Agent waits.
HITL:pending
04
Decide
Reviewer approves, denies, or SLA expires → safe default blocks the action.
decision:stored
05
Chain
Entry appended to the SHA-256 hash chain. Immutable. Verifiable. Audit-ready.
chain:valid ✓

"Compliance should be runtime-verifiable, not audit-retrospective. Ephor makes EU AI Act adherence a property of the system — not of the spreadsheet that documents it."
Ephor Engineering
Regulatory Mapping

EU AI Act Coverage Matrix

Every Article maps to a concrete, implemented Ephor capability — not a policy intention.

ArticleRequirementEphor FeatureStatus
Art 9Risk management system — continuous identification and mitigation throughout lifecyclePolicy gate + risk-level capture on every action; real-time dashboard; configurable hold thresholdsImplemented
Art 10Data governance — data quality, minimisation, and documentation for training and operationPII scrubbing at capture time; data-minimisation config per agent class; field-level redactionImplemented
Art 11Technical documentation — comprehensive system documentation maintained and currentEvidence pack export: policy snapshots, audit entries, reviewer decisions, chain proofImplemented
Art 12Record-keeping — automatic logging of operations for post-market monitoringTamper-evident SHA-256 hash chain; append-only; chain-valid verification on every queryImplemented
Art 13Transparency — users must be informed they are interacting with an AI systemAgent-class identification stamped on every captured action; disclosure fields in audit recordImplemented
Art 14Human oversight — high-risk systems must allow humans to intervene and overrideHITL hold → reviewer approval/denial → SLA timeout safe-default; browser console + Pharo widget + HTTP APIImplemented
Art 47Declaration of conformity — providers must draw up and maintain conformity documentationStructured evidence pack exportable on demand; maps to GPAI conformity assessment requirementsImplemented
Art 72Post-market monitoring — continuous monitoring of high-risk AI systems in productionReal-time risk dashboard; SLA burn-down alerts; chain integrity monitoring; reviewer consoleImplemented

Integration

Drop In. Ship Compliant.

Ephor runs as a sidecar or embedded WASM component. Any HTTP client, MCP host, or Pharo/Smalltalk image integrates in minutes.

Ephor Quick-Start
# 1. Start the governance node
docker compose -f demo/docker-compose.yml up --build

# 2. Capture an agent action
curl -X POST http://localhost:9800/capture \
  -H 'Content-Type: application/json' \
  -d '{{"session_id":"s1","agent_class":"PaymentAgent",
     "action":"payment.send","arguments":["amount=50000"]}}'

# 3. Request human approval (Art 14 hold, 5-min SLA)
curl -X POST http://localhost:9800/oversight/request-approval \
  -d '{{"entry_id":"...","risk_level":"high","sla_ms":300000}}'

# 4. Reviewer decides via browser console — http://localhost:9200
# 5. Agent polls until: approved / denied / timeout → safe-default

Early Access

Be First to Govern

Ephor is in limited early access. We're working with teams building high-risk AI systems under the EU AI Act — payment agents, medical decision aids, HR screening, credit scoring.

  • ✓ Hands-on onboarding call with the core team
  • ✓ Integration support for your agent framework
  • ✓ Influence the roadmap before GA
  • ✓ Priority access to evidence pack tooling
  • ✓ No commitment — evaluate on your own terms

No spam. We respond within 21 days.