Version 2.3 · Last updated 2026-05-02
For informational purposes only — not legal advice.
Operator: TUARA KURI LIMITED
Trading as: AgenticRail
Jurisdiction: New Zealand (serving global users, including the European Union)
Contact: hello@agenticrail.nz
AgenticRail is a deterministic execution control system that validates, sequences, and either allows or halts actions submitted by client systems.
AgenticRail does not:
AgenticRail does:
Evidence: 913,079 enforcement decisions across 1M requests with zero errors (April 2026 pressure test). 114,096 sealed sequences. All receipts publicly verifiable at report.agenticrail.nz. Compliance matrix covering 60+ AI governance frameworks at agenticrail.nz/compliance.
AgenticRail directly satisfies the following EU AI Act articles:
Article 9 Risk Management. The gate is the risk management control — enforcement at infrastructure level. Every ALLOW is a risk acceptance with a cryptographic receipt. Every DENY is a risk mitigation with a recorded reason.
Article 10 Data Governance. Receipt chains prove the operational pipeline was followed. Bias or anomalies in the pipeline are visible in the receipt log — structural evidence, not procedural documentation.
Article 11 Technical Documentation. Receipt chains ARE the living technical documentation. Every system version, enforcement decision, and policy change is recorded as a signed receipt. The report generator produces an Article 11-ready compliance report in seconds.
Article 12 Record-Keeping. Receipts are generated at decision time by the infrastructure layer, not the application. HMAC-signed. Chained. Immutable. This satisfies the "automatically recorded, tamper-evident logging" requirement structurally.
Article 13 Transparency. The public verification portal at report.agenticrail.nz lets deployers independently verify enforcement. No access to provider systems needed.
Article 14 Human Oversight. The gate IS the oversight mechanism. If a step fails, nothing proceeds. Human oversight is enforced architecturally — fail-closed design.
Article 72 Post-Market Monitoring. Every receipt is post-market monitoring evidence, automatically recorded at infrastructure level. 1M-request test data publicly available.
AgenticRail is positioned as:
AgenticRail:
Under the EU AI Act, AgenticRail acts as a technical enforcement layer used by the deployer of an AI system.
The Client using AgenticRail is considered the Deployer of the AI system and is responsible for regulatory classification and compliance.
AgenticRail:
AgenticRail does not determine the purpose or risk level of your AI system.
| AgenticRail responsibilities | Client responsibilities |
|---|---|
| Validating payload structure | Defining system purpose |
| Enforcing sequence order | Determining whether their system is high-risk |
| Applying policy constraints | Ensuring lawful use |
| Preventing invalid or out-of-order execution | Implementing human oversight |
| Providing verifiable sequence records | Ensuring data protection compliance (GDPR) |
AgenticRail enforces structure. The Client defines meaning and use.
| EU AI Act Requirement | How AgenticRail Helps |
|---|---|
| Article 9 — Risk management | The gate is the risk management control — enforcement at infrastructure level |
| Article 11 — Technical documentation | Receipt chains are the living technical documentation; report generator produces Article 11-ready reports |
| Article 12 — Record-keeping | Every action produces a verifiable, HMAC-signed, tamper-evident sealed sequence record |
| Article 13 — Transparency | Public verification portal at report.agenticrail.nz; deployers can verify independently |
| Article 14 — Human oversight | ALLOW decisions are not guarantees; fail-closed design enforces oversight architecturally |
| Article 17 — Quality management | Deterministic enforcement reduces unpredictability |
| Article 72 — Post-market monitoring | Every receipt is post-market monitoring evidence, automatically recorded |
| Annex IV — Technical documentation | Receipt chains and compliance reports contribute to Annex IV audit trails |
AgenticRail does not replace compliance obligations. It provides structural evidence that system actions followed a deterministic, auditable process.
If you use AgenticRail within a high-risk AI system (e.g., employment, credit scoring, critical infrastructure), you must:
AgenticRail:
AgenticRail does not accept liability for failure to comply with applicable laws.
AgenticRail contributes to safer AI operation through:
| Mechanism | What it does |
|---|---|
| Deterministic enforcement | strict sequence validation, function/action matching, fail-closed behaviour |
| Execution constraints | prevents uncontrolled execution and step bypass |
| Replay protection | nonce validation prevents duplicate execution |
| Structural validation | rejects invalid or malformed actions |
| Sequence sealing | completed sequences are permanently closed; no re-entry |
These mechanisms reduce unintended execution, inconsistent state transitions, and uncontrolled system behaviour.
AgenticRail provides:
REPLAY_NONCE, SEQUENCE_VIOLATION, SEALED_SEQUENCE, ACTION_NOT_ALLOWED, STALE_TIMESTAMP)sequence_id can be independently verified at report.agenticrail.nzHowever:
Transparency at the application level remains the responsibility of the Client.
AgenticRail does not replace human oversight.
Clients must review decisions where appropriate, implement escalation or fallback logic, and ensure humans remain accountable for outcomes.
AgenticRail is a control checkpoint, not a decision-maker.
AgenticRail is designed to:
As outlined in the Privacy Policy:
AgenticRail is designed to minimise personal data processing and does not rely on personal data for core system operation.
AgenticRail must not be used:
Unauthorised use may result in suspension of API access.
AgenticRail:
It enforces structure, not truth.
AgenticRail will:
AgenticRail enforces structure, not meaning.
It determines whether an action is allowed.
It does not determine whether an action is correct, lawful, or appropriate.
A tool that supports compliant AI operation, not a compliance service or legal advisor.
For compliance-related enquiries: hello@agenticrail.nz
This statement is for informational purposes only and does not constitute legal advice. Consult qualified legal counsel for your specific obligations under the EU AI Act and other applicable laws.