Your system meets EU sovereignty requirements.
The runtime sovereignty score is 98% — that is the fraction of installed Python packages with no US CLOUD Act exposure. EU AI Act overall status: PARTIAL. Automated coverage of the required articles: 50%.
Where the report flags partial or non-compliant items, the "recommended actions" block below names each one in priority order. Every action corresponds to a specific file or configuration change.
108 of 110 installed packages are EU-sovereign or neutral. 3 are US-incorporated and subject to the CLOUD Act. 80 are unknown.
Critical-path violations: 0. This is a runtime snapshot. CI/CD and infrastructure are reported separately below.
Overall: PARTIAL · Automated coverage: 50%
| Article | Title | Status | Detail | What to do |
|---|---|---|---|---|
| Art. 9 | Risk management | PARTIAL | Policy evaluator configured; every decision records the policy result. | Configure a PolicyEvaluator — SimpleRuleEvaluator or LocalRegoEvaluator. |
| Art. 10 | Data governance | ACTION_REQUIRED | Data governance is not automatable by a middleware kernel. | Data governance is a human process — see docs/bsi-profile.md. |
| Art. 11 | Technical documentation | ACTION_REQUIRED | Annex IV technical documentation is a human deliverable. | Review manually. |
| Art. 12 | Automatic record keeping | COMPLIANT | Every wrapped call produces a DecisionTrace automatically, stored append-only. | Enable storage backend for append-only trace persistence. |
| Art. 13 | Transparency & information to deployers | COMPLIANT | Traces record agent, model, policy name/version, and result per decision. | Populate agent, model, and policy metadata on every trace. |
| Art. 14 | Human oversight | COMPLIANT | Kill switch implemented; every override recorded as linked trace entry. | Test the kill switch with engage_kill_switch() before go-live. |
| Art. 15 | Accuracy, robustness, cybersecurity | ACTION_REQUIRED | Model evaluation and adversarial testing are outside the trace layer. | Configure accuracy thresholds and human review workflows. |
| Art. 17 | Quality management system | COMPLIANT | Continuous, append-only trace record satisfies the traceability requirement. | Run sentinel compliance check as part of CI on every release. |
Overall manifesto score: 100%
| Dimension | Detail | |
|---|---|---|
| ✓ | jurisdiction | 0 critical-path violations |
| ✓ | kill_switch | kill switch API present |
| ✓ | storage | backend: sqlite |
| ✓ | bsi | targeting 2026-12-31 |
Showing first 60 of 110 installed packages. Sovereign: 108 · US-owned: 3 · Unknown: 80
| Package | Version | Parent | Jurisdiction | CLOUD Act | Critical |
|---|---|---|---|---|---|
| typing_extensions | 4.15.0 | Unknown | Unknown | — | no |
| pip | 26.0.1 | Unknown | Unknown | — | no |
| cffi | 2.0.0 | Unknown | Unknown | — | no |
| ptyprocess | 0.7.0 | Unknown | Unknown | — | no |
| opentelemetry-exporter-otlp-proto-http | 1.41.0 | Unknown | Unknown | — | no |
| uv | 0.11.6 | Unknown | Unknown | — | no |
| idna | 3.11 | Kim Davies | Neutral | NO | no |
| charset-normalizer | 3.4.7 | Ousret | Neutral | NO | no |
| mypy_extensions | 1.1.0 | Unknown | Unknown | — | no |
| stack-data | 0.6.3 | Unknown | Unknown | — | no |
| httpcore | 1.0.9 | Encode | Neutral | NO | no |
| asttokens | 3.0.1 | Unknown | Unknown | — | no |
| urllib3 | 2.6.3 | urllib3 | Neutral | NO | no |
| distlib | 0.4.0 | Unknown | Unknown | — | no |
| SecretStorage | 3.5.0 | Unknown | Unknown | — | no |
| importlib_metadata | 8.7.1 | Unknown | Unknown | — | no |
| matplotlib-inline | 0.2.1 | Unknown | Unknown | — | no |
| opentelemetry-semantic-conventions | 0.62b0 | Unknown | Unknown | — | no |
| sentinel-kernel | 2.4.0 | sentinel-kernel | EU | NO | yes |
| rich | 14.3.4 | Unknown | Unknown | — | no |
| jupyterlab_widgets | 3.0.16 | Unknown | Unknown | — | no |
| markdown-it-py | 4.0.0 | Unknown | Unknown | — | no |
| pytest-asyncio | 1.3.0 | pytest-dev | Neutral | NO | no |
| platformdirs | 4.9.6 | Unknown | Unknown | — | no |
| httpx | 0.28.1 | Encode | Neutral | NO | no |
| backoff | 2.2.1 | Unknown | Unknown | — | no |
| opentelemetry-api | 1.41.0 | CNCF | Neutral | NO | no |
| protobuf | 6.33.6 | Unknown | Unknown | — | no |
| shellingham | 1.5.4 | Unknown | Unknown | — | no |
| pycparser | 3.0 | Unknown | Unknown | — | no |
| prometheus_client | 0.25.0 | Prometheus | Neutral | NO | no |
| orjson | 3.11.8 | Unknown | Unknown | — | no |
| opentelemetry-exporter-otlp-proto-common | 1.41.0 | Unknown | Unknown | — | no |
| pyproject_hooks | 1.2.0 | Unknown | Unknown | — | no |
| hyperlink | 21.0.0 | Unknown | Unknown | — | no |
| keyring | 25.7.0 | Unknown | Unknown | — | no |
| mypy | 1.20.0 | Python Software Foundation | Neutral | NO | no |
| jsonpatch | 1.33 | Unknown | Unknown | — | no |
| widgetsnbextension | 4.0.15 | Unknown | Unknown | — | no |
| python-discovery | 1.2.2 | Unknown | Unknown | — | no |
| zstandard | 0.25.0 | Unknown | Unknown | — | no |
| Django | 6.0.4 | Unknown | Unknown | — | no |
| pytest-cov | 7.1.0 | pytest-cov | Neutral | NO | no |
| psycopg2-binary | 2.9.11 | PostgreSQL Global Dev Group | Neutral | NO | no |
| zipp | 3.23.0 | Unknown | Unknown | — | no |
| prompt_toolkit | 3.0.52 | Unknown | Unknown | — | no |
| librt | 0.9.0 | Unknown | Unknown | — | no |
| opentelemetry-sdk | 1.41.0 | CNCF | Neutral | NO | no |
| PyYAML | 6.0.3 | YAML | Neutral | NO | no |
| requests | 2.33.1 | Python Software Foundation | Neutral | NO | no |
| tomlkit | 0.14.0 | Unknown | Unknown | — | no |
| iniconfig | 2.3.0 | Unknown | Unknown | — | no |
| opentelemetry-proto | 1.41.0 | Unknown | Unknown | — | no |
| mdurl | 0.1.2 | Unknown | Unknown | — | no |
| certifi | 2026.2.25 | Certifi | Neutral | NO | no |
| grpcio | 1.80.0 | Unknown | Unknown | — | no |
| Pygments | 2.20.0 | Unknown | Unknown | — | no |
| comm | 0.2.3 | Unknown | Unknown | — | no |
| typing-inspection | 0.4.2 | Unknown | Unknown | — | no |
| langsmith | 0.7.30 | LangChain Inc. | US | YES | no |
| File | Component | Vendor | Jurisdiction | CLOUD Act |
|---|---|---|---|---|
| .github/workflows/ci.yml | github_actions | GitHub (Microsoft) | US | YES |
| .github/workflows/pages.yml | github_actions | GitHub (Microsoft) | US | YES |
| .github/workflows/release.yml | github_actions | GitHub (Microsoft) | US | YES |
| .github/workflows/rust.yml | github_actions | GitHub (Microsoft) | US | YES |
| pyproject.toml | pypi | Python Package Index | US | NO |
| File | Component | Vendor | Jurisdiction | CLOUD Act |
|---|---|---|---|---|
| No infrastructure findings | ||||