Compliance

Last updated: 4 September 2026

Built for the AI regulatory era

FirstHelm gives you the controls regulators are starting to require — and the records to prove you use them.

EU AI Act

Timeline

  • August 2024 — entered into force
  • February 2025 — prohibited practices apply
  • August 2025 — GPAI obligations apply
  • August 2026 — high-risk obligations and full enforcement begin

How FirstHelm maps to it

  • Art. 14 (Human oversight) — approval gates and interventions keep a human able to oversee, interrupt, and steer every high-risk action.
  • Art. 12 (Record-keeping) — the audit trail records every agent action, decision, and intervention, exportable on demand.
  • Transparency — activity logging and the auto-generated compliance report document how agents operate.

Penalties for non-compliance can reach €35 million or 7% of global annual turnover.

United Kingdom

The UK follows a pro-innovation, principles-based AI regulatory approach. FirstHelm aligns with UK GDPR and the Data Protection Act 2018, supporting accountability, record-keeping, and human oversight obligations.

ISO/IEC 42001 — AI management systems

FirstHelm supports the Plan-Do-Check-Act cycle: define constraints and missions (Plan), enforce them in operation (Do), review analytics and metrics (Check), and adjust autonomy tiers (Act) — the building blocks for an AI management system certification.

NIST AI RMF

FirstHelm supports the four core functions: Govern (organisation profile, roles), Map (agent inventory, mission portfolio), Measure (metrics, cost and token tracking), and Manage (interventions, kill switch, constraints).

SOC 2 Type II

Control categories in place include access control (RBAC, SSO), audit logging, availability monitoring, and change management. See the Security and Status pages.

FCA — UK financial services

For firms authorised by the Financial Conduct Authority, FirstHelm evidences the operational controls supervisors look for in AI deployment:

  • SYSC 6.1 — Risk management. Constraints and violation history demonstrate that AI risk-management policies and procedures are enforced in operation.
  • SYSC 4.1 — Governance. Approval gates and approver identities evidence sound governance and apportionment of responsibilities.
  • SM&CR — Accountability. The approval ledger serves as supporting evidence of senior-manager accountability for AI activities.
  • Consumer Duty. Constraint-breach monitoring helps firms evidence that they are delivering good outcomes for retail customers.
  • Operational resilience (PS21/3). Intervention records evidence the ability to respond to and remain resilient against disruptions; impact tolerance remains a firm-side document.

Compliance mapping

RegulationRequirementFirstHelm capabilityWhere to see it
EU AI ActArt. 14 — Human oversightApproval gates + interventionsApprovals, Activity Log
EU AI ActArt. 12 — Record-keepingImmutable audit trail exportActivity Log, Settings → Compliance
EU AI ActTransparency obligationsActivity logging + compliance reportAnalytics, Compliance Report
UK GDPR / DPA 2018Records of processingAudit trail + approval recordsSettings → Compliance
ISO/IEC 42001AI management system (PDCA)Constraints, metrics, reviewConstraints, Analytics
NIST AI RMFGovern / Map / Measure / ManageAgent inventory, metrics, interventionsAgents, Analytics, Approvals
SOC 2 Type IIAccess control, audit, availabilityRBAC, audit trail, uptimeStatus, Security
FCA (UK)SYSC 6.1 risk managementConstraints + violation historyConstraints, Analytics
FCA (UK)SYSC 4.1 governanceApprovals + approver identitiesApprovals, Activity Log
FCA (UK)SM&CR accountabilityApproval ledger as supporting evidenceApprovals, Settings
FCA (UK)Consumer DutyConstraint-breach monitoringConstraints, Analytics
FCA (UK)Operational resilience (PS21/3)Intervention records + impact toleranceActivity Log, Approvals

See your compliance readiness

Generate audit-ready evidence mapped to EU AI Act, ISO 42001, SOC 2, UK GDPR, NIST AI RMF, and FCA — computed live from your agent operations.

Start Free

FirstHelm Technologies Ltd is committed to maintaining its own compliance programme. This page describes the capabilities customers use for their own compliance — it is not legal advice or a certification.

For compliance, EU AI Act, or ISO 42001 enquiries, contact compliance@firsthelm.dev.

© 2026 FirstHelm Technologies Ltd · The human-first control layer for autonomous AI