Positioning
Where SOV fits
SOV is intended to sit alongside existing schemes, platforms and internal controls, not to replace them. No functional comparison against any named scheme or product has been performed.
Complementary to
Agent assurance schemes
AIUC-1 and similar schemes address agent assurance from their own scope and governance. SOV describes a resource record and its change conditions.
Organisational management systems
ISO/IEC 42001 addresses how an organisation manages AI. SOV addresses a single declared resource, its authority envelope and its evidence.
Identity, authorization and workload platforms
These enforce who or what may call a system at runtime. SOV records what was declared and checked about the resource, not runtime enforcement.
Internal GRC, risk, audit and security controls
Internal controls own the decision. SOV aims to give those controls a structured, inspectable input.
Not an alternative to
- Statutory certification.
- Organisational ISO certification.
- Runtime access control.
- A model card.
- A penetration test.
- Legal advice.
On the EU AI Act
The AI Act is risk-based. Most AI systems fall into the minimal or no-risk category. Certain Annex III high-risk use cases have an extended transition period until 2 December 2027, while high-risk AI systems embedded in regulated products under Annex I have an extended transition period until 2 August 2028.
Not every enterprise agent is high-risk, and SOV does not establish AI Act compliance.
European Commission source ↗See also what an SOV record does not tell you.