Compliance

Built for the human-oversight era.

Regulators now expect a human in the loop before automated systems act — and evidence that oversight happened. Proof is designed to support both: approvals on channels people actually answer, recorded as signed, offline-verifiable tokens.

Proofproof.holdings · oversight record
Oversight RecordNº 2026-0014
subjectAdverse credit decision · applicant #4471
systemcredit-model v3 — solely automated
controlhuman review required before the decision takes effect
reviewed+370 691 •• •99 · via WhatsApp · 14:02:07 UTC
authorityEU AI Act Art. 14 · GDPR Art. 22
verdictOversight recordedthe review itself is signed — not a screenshot
Minted
action · ES256

The regulatory docket

The dates your roadmap already lives under

36+ jurisdictions, one requirement: a human in the loop before an automated decision stands — and a record that it happened.

  1. In force
    EU
    GDPR · Art. 22

    A person may not be subject to a solely automated decision with legal or similarly significant effect — human intervention must be available on request.

  2. In force
    UK
    UK GDPR · Arts. 22A–22D

    The Data (Use and Access) Act replaced Article 22 on 5 February 2026: significant automated decisions are permitted, but safeguards are mandatory — people must be able to obtain human intervention, make representations, and contest the decision.

  3. In force
    US
    NYC Local Law 144

    Automated employment decision tools require an independent bias audit and advance notice to candidates — an automated decision alone is not enough.

  4. In force
    CH
    Swiss FADP · Art. 21

    Switzerland’s revised data protection law: automated individual decisions must be disclosed, and the person can ask for the decision to be reviewed by a human.

  5. In force
    CA
    Quebec Law 25

    Quebec requires businesses to inform people when a decision is based exclusively on automated processing — and to offer a path to a human who can review it.

  6. In force
    KR
    Korea PIPA · Art. 37-2

    South Korea’s privacy law grants the right to refuse, or demand a human explanation of, fully automated decisions that significantly affect a person.

  7. In force
    US
    Utah AI Policy Act

    Consumers must be told when they are interacting with generative AI in regulated services — disclosure on request, upfront for regulated professions.

  8. In force
    IL
    Israel Privacy Law · Amendment 13

    Israel’s modernized privacy law sharpens regulatory enforcement over automated processing of personal data; the regulator’s AI guidance is principles-based.

  9. In force
    JP
    Japan AI Promotion Act

    Japan’s first AI law sets a light-touch national governance baseline — an "endeavor to cooperate" duty and transparency expectations rather than hard oversight mandates or penalties today.

  10. Guidance
    SG
    Singapore Model AI Framework

    Singapore’s PDPC framework recommends human-over-the-loop controls scaled to risk. Not binding — but the governance reference point for the region.

  11. In force
    KR
    Korea AI Basic Act

    Korea’s AI Basic Act (in force 22 January 2026) imposes duties on high-impact AI — employment, loans, healthcare and more — including risk management, explainability, and human-oversight mechanisms.

  12. Aug 2026
    EU
    EU AI Act · Art. 50

    Transparency obligations apply: people must be told when they interact with an AI system, and AI-generated content must be disclosed (machine-readable marking grace period runs to December 2, 2026).

  13. Dec 2026
    AU
    Australia Privacy Amendment

    Australia’s Privacy Act amendments require privacy policies to disclose automated decisions that significantly affect individuals — transparency first, with broader reform still moving.

  14. Jan 2027
    US
    Colorado AI Act · revised

    Colorado repealed and replaced its 2024 act (SB 26-189, May 2026): deployers of automated decision-making technology must give clear notice, explain adverse outcomes, and offer meaningful human reconsideration of consequential decisions.

  15. Dec 2027
    EU
    EU AI Act · Art. 14

    Human oversight becomes mandatory for high-risk AI systems: humans must be able to understand, intervene in, and override the system (deferred from 2026 by the Digital Omnibus, adopted June 2026).

Why this matters now

Strip the jurisdictions away and every text asks for the same two things

Requirement 01

A human able to intervene before the system acts.

Proof of Action delivers the approval on the channels people already answer — Telegram or WhatsApp — so the checkpoint happens in seconds, not in the next sprint. A queue nobody opens is oversight on paper only.

Requirement 02

Evidence that the oversight actually happened.

Every approval mints a signed ES256 token — who decided what, when, over which channel. An auditor verifies it offline against our published JWKS: no Proof account, no API call, no trust in screenshots.

How Proof maps to the obligations

Every obligation, an instrument you can hand an auditor

No vendor hands you compliance. What Proof issues is the oversight mechanic and the signed evidence trail the rules keep asking for.

Human oversight & intervention

EU AI Act Art. 14 · GDPR Art. 22 · Colorado

Human-in-the-loop approval gates before irreversible actions, on channels people answer.

action · ES256
Proof of Action

Supply-chain & agent authority

NIS2 Art. 21(2)(d) supply chain · agent authority

Signed, scoped, revocable statements of which agents, packages and endpoints a domain you control authorized.

delegation · ES256
Proof of Delegation

Demonstrable audit trail

Art. 14(4) records · accountability

Signed ES256 tokens for every decision — verifiable offline via the public JWKS, holdable for years.

control · ES256
Proof of Control

Put a human in the loop this week

Your first approval gate is one API call — and every decision after it leaves a signed token you can show an auditor.

Product positioning, not legal advice. Consult your counsel on how these rules apply to you.