Compliance
Built for the human-oversight era.
Regulators now expect a human in the loop before automated systems act — and evidence that oversight happened. Proof is designed to support both: approvals on channels people actually answer, recorded as signed, offline-verifiable tokens.
The regulatory docket
The dates your roadmap already lives under
36+ jurisdictions, one requirement: a human in the loop before an automated decision stands — and a record that it happened.
- In forceEUGDPR · Art. 22
A person may not be subject to a solely automated decision with legal or similarly significant effect — human intervention must be available on request.
- In forceUKUK GDPR · Arts. 22A–22D
The Data (Use and Access) Act replaced Article 22 on 5 February 2026: significant automated decisions are permitted, but safeguards are mandatory — people must be able to obtain human intervention, make representations, and contest the decision.
- In forceUSNYC Local Law 144
Automated employment decision tools require an independent bias audit and advance notice to candidates — an automated decision alone is not enough.
- In forceCHSwiss FADP · Art. 21
Switzerland’s revised data protection law: automated individual decisions must be disclosed, and the person can ask for the decision to be reviewed by a human.
- In forceCAQuebec Law 25
Quebec requires businesses to inform people when a decision is based exclusively on automated processing — and to offer a path to a human who can review it.
- In forceKRKorea PIPA · Art. 37-2
South Korea’s privacy law grants the right to refuse, or demand a human explanation of, fully automated decisions that significantly affect a person.
- In forceUSUtah AI Policy Act
Consumers must be told when they are interacting with generative AI in regulated services — disclosure on request, upfront for regulated professions.
- In forceILIsrael Privacy Law · Amendment 13
Israel’s modernized privacy law sharpens regulatory enforcement over automated processing of personal data; the regulator’s AI guidance is principles-based.
- In forceJPJapan AI Promotion Act
Japan’s first AI law sets a light-touch national governance baseline — an "endeavor to cooperate" duty and transparency expectations rather than hard oversight mandates or penalties today.
- GuidanceSGSingapore Model AI Framework
Singapore’s PDPC framework recommends human-over-the-loop controls scaled to risk. Not binding — but the governance reference point for the region.
- In forceKRKorea AI Basic Act
Korea’s AI Basic Act (in force 22 January 2026) imposes duties on high-impact AI — employment, loans, healthcare and more — including risk management, explainability, and human-oversight mechanisms.
- Aug 2026EUEU AI Act · Art. 50
Transparency obligations apply: people must be told when they interact with an AI system, and AI-generated content must be disclosed (machine-readable marking grace period runs to December 2, 2026).
- Dec 2026AUAustralia Privacy Amendment
Australia’s Privacy Act amendments require privacy policies to disclose automated decisions that significantly affect individuals — transparency first, with broader reform still moving.
- Jan 2027USColorado AI Act · revised
Colorado repealed and replaced its 2024 act (SB 26-189, May 2026): deployers of automated decision-making technology must give clear notice, explain adverse outcomes, and offer meaningful human reconsideration of consequential decisions.
- Dec 2027EUEU AI Act · Art. 14
Human oversight becomes mandatory for high-risk AI systems: humans must be able to understand, intervene in, and override the system (deferred from 2026 by the Digital Omnibus, adopted June 2026).
Why this matters now
Strip the jurisdictions away and every text asks for the same two things
A human able to intervene before the system acts.
Proof of Action delivers the approval on the channels people already answer — Telegram or WhatsApp — so the checkpoint happens in seconds, not in the next sprint. A queue nobody opens is oversight on paper only.
Evidence that the oversight actually happened.
Every approval mints a signed ES256 token — who decided what, when, over which channel. An auditor verifies it offline against our published JWKS: no Proof account, no API call, no trust in screenshots.
How Proof maps to the obligations
Every obligation, an instrument you can hand an auditor
No vendor hands you compliance. What Proof issues is the oversight mechanic and the signed evidence trail the rules keep asking for.
Human oversight & intervention
EU AI Act Art. 14 · GDPR Art. 22 · Colorado
Human-in-the-loop approval gates before irreversible actions, on channels people answer.
Supply-chain & agent authority
NIS2 Art. 21(2)(d) supply chain · agent authority
Signed, scoped, revocable statements of which agents, packages and endpoints a domain you control authorized.
Demonstrable audit trail
Art. 14(4) records · accountability
Signed ES256 tokens for every decision — verifiable offline via the public JWKS, holdable for years.
Put a human in the loop this week
Your first approval gate is one API call — and every decision after it leaves a signed token you can show an auditor.
Product positioning, not legal advice. Consult your counsel on how these rules apply to you.