Built for the AI regulatory era
FirstHelm gives you the controls regulators are starting to require — and the records to prove you use them.
EU AI Act
Timeline
- August 2024 — entered into force
- February 2025 — prohibited practices apply
- August 2025 — GPAI obligations apply
- August 2026 — high-risk obligations and full enforcement begin
How FirstHelm maps to it
- Art. 14 (Human oversight) — approval gates and interventions keep a human able to oversee, interrupt, and steer every high-risk action.
- Art. 12 (Record-keeping) — the audit trail records every agent action, decision, and intervention, exportable on demand.
- Transparency — activity logging and the auto-generated compliance report document how agents operate.
Penalties for non-compliance can reach €35 million or 7% of global annual turnover.
United Kingdom
The UK follows a pro-innovation, principles-based AI regulatory approach. FirstHelm aligns with UK GDPR and the Data Protection Act 2018, supporting accountability, record-keeping, and human oversight obligations.
ISO/IEC 42001 — AI management systems
FirstHelm supports the Plan-Do-Check-Act cycle: define constraints and missions (Plan), enforce them in operation (Do), review analytics and metrics (Check), and adjust autonomy tiers (Act) — the building blocks for an AI management system certification.
NIST AI RMF
FirstHelm supports the four core functions: Govern (organisation profile, roles), Map (agent inventory, mission portfolio), Measure (metrics, cost and token tracking), and Manage (interventions, kill switch, constraints).
SOC 2 Type II
Control categories in place include access control (RBAC, SSO), audit logging, availability monitoring, and change management. See the Security and Status pages.
FCA — UK financial services
For firms authorised by the Financial Conduct Authority, FirstHelm evidences the operational controls supervisors look for in AI deployment:
- SYSC 6.1 — Risk management. Constraints and violation history demonstrate that AI risk-management policies and procedures are enforced in operation.
- SYSC 4.1 — Governance. Approval gates and approver identities evidence sound governance and apportionment of responsibilities.
- SM&CR — Accountability. The approval ledger serves as supporting evidence of senior-manager accountability for AI activities.
- Consumer Duty. Constraint-breach monitoring helps firms evidence that they are delivering good outcomes for retail customers.
- Operational resilience (PS21/3). Intervention records evidence the ability to respond to and remain resilient against disruptions; impact tolerance remains a firm-side document.
Compliance mapping
| Regulation | Requirement | FirstHelm capability | Where to see it |
|---|---|---|---|
| EU AI Act | Art. 14 — Human oversight | Approval gates + interventions | Approvals, Activity Log |
| EU AI Act | Art. 12 — Record-keeping | Immutable audit trail export | Activity Log, Settings → Compliance |
| EU AI Act | Transparency obligations | Activity logging + compliance report | Analytics, Compliance Report |
| UK GDPR / DPA 2018 | Records of processing | Audit trail + approval records | Settings → Compliance |
| ISO/IEC 42001 | AI management system (PDCA) | Constraints, metrics, review | Constraints, Analytics |
| NIST AI RMF | Govern / Map / Measure / Manage | Agent inventory, metrics, interventions | Agents, Analytics, Approvals |
| SOC 2 Type II | Access control, audit, availability | RBAC, audit trail, uptime | Status, Security |
| FCA (UK) | SYSC 6.1 risk management | Constraints + violation history | Constraints, Analytics |
| FCA (UK) | SYSC 4.1 governance | Approvals + approver identities | Approvals, Activity Log |
| FCA (UK) | SM&CR accountability | Approval ledger as supporting evidence | Approvals, Settings |
| FCA (UK) | Consumer Duty | Constraint-breach monitoring | Constraints, Analytics |
| FCA (UK) | Operational resilience (PS21/3) | Intervention records + impact tolerance | Activity Log, Approvals |
See your compliance readiness
Generate audit-ready evidence mapped to EU AI Act, ISO 42001, SOC 2, UK GDPR, NIST AI RMF, and FCA — computed live from your agent operations.
FirstHelm Technologies Ltd is committed to maintaining its own compliance programme. This page describes the capabilities customers use for their own compliance — it is not legal advice or a certification.
For compliance, EU AI Act, or ISO 42001 enquiries, contact compliance@firsthelm.dev.