VOUCH is the first multi-agent substrate where the EU AI Act Art. 12 evidence requirements are outputs of the system, not post-hoc additions. The 8 required fields are populated by EvidencePacket::build() and verified by vouch-verify.
Reg 2024/1689
EU AI Act
Art. 12 record-keeping · 8/8 fields populated · verifier requires ≥7/8. Coverage gate is hard, not opt-in.
EU 2022/2554
DORA
Art. 16 ICT incident logging via the same hash chain. BAAAR HALT triggers the 72h DORA Art. 17 reporting clock.
1.0 · G/M/M/M
NIST AI RMF
Per-decision audit trail = the Manage function. Govern / Map / Measure traced in the evidence chain.
2026 · ASI01–ASI10
OWASP Agentic
Prompt injection, sensitive disclosure, tool misuse mitigated inside the BAAAR gate's FindingKind conditions.
#
Art. 12 field
VOUCH source
Example value
1
start_time
ISO 8601 UTC at decision window open
2026-06-19T11:43:12Z
2
end_time
ISO 8601 UTC at decision window close
2026-06-19T11:43:14Z
3
reference_database
Dataset id used for vendor lookup
stanford-invoicenet-50
4
input_data
Invoice id (decision subject)
inv-001
5
decision_id
UUID per decision
00000000-0000-0000-0000-000000000001
6
policy_version
Agent policy hash
apohara-vouch-1
7
hash_chain_prev
BLAKE3 root of previous packet
0x0000…0000 (genesis)
8
natural_person_id
Required parameter per commit ef9db13 · tenant-scoped
operator@stark.example