sipi.bot · compliance
EU AI Act compliance for agent spend governance
The EU AI Act classifies AI systems in financial decision-making as high-risk. Autonomous agents authorizing payments trigger governance requirements under Articles 9-14.
What EU AI Act requires for agent spend
Under the EU AI Act (effective 2026), agent-triggered payments trigger Article 9 risk management, Article 10 data governance, Article 11 technical documentation, and Article 14 human oversight. A deterministic pre-spend firewall with human-in-the-loop escalation satisfies the governance baseline.
How sipi.bot maps to EU AI Act controls
| Requirement | sipi.bot capability | Evidence |
|---|---|---|
| Documented policy gate | evaluate_spend in <5ms against rules | Policy version per decision |
| Immutable audit log | Tamper-evident decision log | Full JSON audit trail |
| Human escalation | FLAGGED → approval queue | Queue history with reviewer ID |
| Access control | Agent-key-scoped policies | Auth + authorization log |
Frequently asked questions
What does EU AI Act require for agent spend?
A documented, enforced policy gate on every autonomous transaction, with an immutable audit trail and human escalation. sipi.bot evaluates every transaction against your rules in <5ms, logs the decision with policy version, and queues flagged transactions for human review.
Is sipi.bot certified for this?
sipi.bot is not a certifying body. It provides the technical controls — deterministic evaluation, audit logging, human escalation — that satisfy these governance requirements. Your auditor maps these to the framework criteria.
How do I produce audit evidence?
The sipi.bot audit log exports every decision (transaction, amount, merchant, rule triggers, verdict, policy version, timestamp) as structured JSON. This log is tamper-evident and can be fed into SOC 2, ISO 27001, or GDPR audit trails.