Register AI agents, issue cryptographic Digital Agent Certificates, block prompt injection in real time, and monitor behavioural drift — all in one compliance-grade platform built for the EU AI Act era.
From £2.50 per agent-check. Free tier available.
Every AI agent in your organisation passes through a structured lifecycle from registration to decommission.
Declare agent archetype, scope, data categories accessed, and responsible owner. Stored in the immutable agent registry.
Auto-classify into one of 7 archetypes (Data Analyst, Customer Service, Code Writer, Decision Engine, etc.) and assign a base risk tier.
Issue a short-TTL X.509 Digital Agent Certificate from TrustVerify's CA. Certificate embeds agent ID, archetype, scope hash, and expiry.
Every inbound request screened for prompt injection in <5ms using 40+ pattern signatures and semantic models (BR-017).
JWT-level scope check ensures the agent accesses only data categories declared at registration. Scope creep triggers alert BR-019.
First 72-hour warm-up period establishes the agent's normal call pattern, volume, and data access profile.
Continuous comparison of live behaviour against baseline. Statistical anomaly detection flags deviations (BR-018).
Every flag, block, or certificate revocation written to an immutable audit log with timestamp, rule fired, and context hash.
High-severity flags route to a human reviewer via webhook or in-platform queue. Agent can be paused pending decision.
Before TTL expiry, agents must re-attest scope and pass a fresh PromptGuard-2 check. Drift-flagged agents are blocked from renewal.
Graceful decommission revokes all active DACs, purges session keys, and archives the agent's audit trail (JMLSG 7-year retention).
Generate an RPT-016 Agent Compliance Report on demand — suitable for regulator submission or internal governance review.
Short-TTL X.509 certificates that cryptographically identify every AI agent. Revocable instantly. Embeds archetype, scope hash, and responsible owner.
40+ injection pattern signatures + semantic anomaly detection. Screens every inbound request in under 5ms. Protects against direct, indirect, and multi-hop injection.
72-hour baseline warm-up, then continuous statistical monitoring. Flags scope creep, unusual call volumes, and unexpected external connections (BR-018).
Agents auto-classified: Data Analyst, Customer Service, Code Writer, Decision Engine, Content Generator, Orchestrator, or Autonomous Executor — each with a tailored risk profile.
KYA's pipeline maps directly to Articles 9, 12, 13, 14, and 15. Generate an RPT-016 compliance report on demand for regulator submissions.
Every certificate event, flag, block, and escalation written to a tamper-evident log. 7-year JMLSG retention. Exportable for legal hold.
KYA's pipeline maps directly to the EU AI Act's obligations for high-risk AI systems.
| Article | Obligation | KYA Implementation |
|---|---|---|
| Art. 9 | Risk management system | Agent registration, risk classification (7 archetypes × 4 tiers) |
| Art. 12 | Record-keeping & logging | Immutable audit log for every flag, block, and certificate event |
| Art. 13 | Transparency | DAC embeds scope, archetype, and responsible owner — human-readable |
| Art. 14 | Human oversight | Escalation queue + agent pause controls |
| Art. 15 | Accuracy & robustness | Drift monitoring (BR-018) + PromptGuard-2 (BR-017) |
KYA is TrustVerify's AI governance framework, pioneering the UK Know Your Agent standard for agent identity, certification, and behavioural compliance. Every AI agent is registered, certified with a short-TTL X.509 Digital Agent Certificate (DAC), and continuously monitored for prompt-injection attacks and behavioural drift.
A DAC is a short-TTL X.509 certificate that uniquely identifies an AI agent. Issued by TrustVerify's certificate authority, presented on every API call, and instantly revocable if the agent is decommissioned or flagged. Certificates expire after a configurable TTL (default 24 hours) to limit blast radius.
PromptGuard-2 analyses every incoming request in real time, scoring it against 40+ injection pattern signatures and semantic anomaly models. Malicious instructions embedded in user content, tool outputs, or retrieved documents are flagged and blocked before they reach the agent's reasoning layer.
BR-018 monitors each agent's API call patterns, data access scope, and response characteristics over time. Deviations from the registered baseline — new data categories accessed, unusual call volumes, unexpected external connections — trigger an alert and optionally pause the agent pending review.
KYA's 12-point pipeline maps directly to EU AI Act obligations for high-risk AI systems: agent registration (Art. 9 risk management), audit logs (Art. 12 record-keeping), human oversight controls (Art. 14), and accuracy/robustness monitoring (Art. 15). TrustVerify maintains the compliance mapping as the Act's implementing regulations evolve.
The EU AI Act is in force. KYA gives you the audit trail, the certificates, and the monitoring to prove compliance — today.
From £2.50/agent-check. Free tier available. No credit card required.