Your system produces EU-jurisdiction evidence under the Record-Enforce-Prove model.
The runtime sovereignty score is 100% — that is the fraction of installed Python packages with no US CLOUD Act exposure. EU AI Act overall status: PARTIAL. Automated coverage of the required articles: 36%.
Where the report flags partial or non-compliant items, the "recommended actions" block below names each one in priority order. Every action corresponds to a specific file or configuration change.
40 of 40 installed packages are EU-sovereign or neutral. 1 are US-incorporated and subject to the CLOUD Act. 27 are unknown.
Critical-path violations: 0. This is a runtime snapshot. CI/CD and infrastructure are reported separately below.
Overall: PARTIAL · Automated coverage: 36%
| Article | Title | Status | Detail | What to do |
|---|---|---|---|---|
| Art. 9 | Risk management | PARTIAL | Policy evaluator configured; every decision records the policy result. | Implement a formal risk management process. Before deployment · Engineering + Risk |
| Art. 10 | Data governance | ACTION_REQUIRED | Data governance is not automatable by a middleware kernel. | Document training data governance end-to-end. Your team must implement · Data + Legal |
| Art. 11 | Technical documentation | ACTION_REQUIRED | Annex IV technical documentation is a human deliverable. | Review manually. — · Team |
| Art. 12 | Automatic record keeping | COMPLIANT | Every wrapped call produces a DecisionTrace automatically, stored append-only. | Enable tamper-resistant trace persistence. Before deployment · Engineering |
| Art. 13 | Transparency & information to deployers | COMPLIANT | Traces record agent, model, policy name/version, and result per decision. | Populate transparency metadata on every trace. Before deployment · Engineering |
| Art. 14 | Human oversight | COMPLIANT | Kill switch implemented; every override recorded as linked trace entry. | Prove the kill switch works end-to-end. Before deployment · Engineering + Ops |
| Art. 15 | Accuracy, robustness, cybersecurity | ACTION_REQUIRED | Model evaluation and adversarial testing are outside the trace layer. | Define accuracy metrics for your specific use case. Your team must implement · Data + Engineering |
| Art. 17 | Quality management system | COMPLIANT | Continuous, append-only trace record satisfies the traceability requirement. | Establish a quality management system for AI outputs. Before deployment · Quality + Engineering |
| Art. 16 | Provider obligations | PARTIAL | Art. 16(d) deployer logging and 16(f) post-market monitoring evidence are produced automatically via the trace store. | Complete provider registration, conformity assessment, CE marking. Before market placement · Legal + Compliance |
| Art. 26 | Deployer obligations | PARTIAL | Art. 26(5) deployer logging and Art. 26(6) human oversight primitives are shipped (kill switch + trace store). | Document human oversight procedures and train staff. Before deployment · Operations + Legal |
| Art. 72 | Post-market monitoring (GPAI) | PARTIAL | Records model identity, inputs hash, outputs and decision chain for any GPAI call — the raw evidence Art. 72 requires. | Publish a GPAI post-market monitoring plan (if applicable). Before deployment (only if GPAI applies) · Engineering + Legal |
Overall manifesto score: 100%
| Dimension | Detail | |
|---|---|---|
| ✓ | jurisdiction | 0 critical-path violations |
| ✓ | kill_switch | kill switch API present |
| ✓ | storage | backend: sqlite |
| ✓ | bsi | targeting 2026-12-31 |
Showing first 60 of 40 installed packages. Sovereign: 40 · US-owned: 1 · Unknown: 27
Showing packages in the current Python environment. For a complete scan including your project dependencies, run sentinel report from your project directory with your virtual environment activated.
| Package | Version | Parent | Jurisdiction | CLOUD Act | Critical |
|---|---|---|---|---|---|
| iniconfig | 2.3.0 | Unknown | Unknown | — | no |
| pyte | 0.8.2 | Unknown | Unknown | — | no |
| pytest-cov | 7.1.0 | pytest-cov | Neutral | NO | no |
| pillow | 12.2.0 | Unknown | Unknown | — | no |
| pytest-xdist | 3.8.0 | Unknown | Unknown | — | no |
| coverage | 7.13.5 | Coverage.py | Neutral | NO | no |
| Pygments | 2.20.0 | Unknown | Unknown | — | no |
| packaging | 26.1 | Unknown | Unknown | — | no |
| pytest-asyncio | 1.3.0 | pytest-dev | Neutral | NO | no |
| wcwidth | 0.6.0 | Unknown | Unknown | — | no |
| execnet | 2.1.2 | Unknown | Unknown | — | no |
| sentinel-kernel | 3.1.0 | sentinel-kernel | EU | NO | yes |
| charset-normalizer | 3.4.7 | Ousret | Neutral | NO | no |
| pytest | 9.0.3 | pytest-dev | Neutral | NO | no |
| termtosvg | 1.1.0 | Unknown | Unknown | — | no |
| pluggy | 1.6.0 | Unknown | Unknown | — | no |
| ruff | 0.15.10 | Astral | US | NO | no |
| lxml | 6.0.4 | Unknown | Unknown | — | no |
| reportlab | 4.4.10 | Unknown | Unknown | — | no |
| requests | 2.33.1 | Python Software Foundation | Neutral | NO | no |
| certifi | 2026.2.25 | Certifi | Neutral | NO | no |
| asn1crypto | 1.5.1 | Unknown | Unknown | — | no |
| wheel | 0.46.3 | Unknown | Unknown | — | no |
| idna | 3.11 | Kim Davies | Neutral | NO | no |
| cffi | 2.0.0 | Unknown | Unknown | — | no |
| pyHanko | 0.34.1 | Unknown | Unknown | — | no |
| cryptography | 46.0.7 | Unknown | Unknown | — | no |
| mypy | 1.20.1 | Python Software Foundation | Neutral | NO | no |
| pycparser | 3.0 | Unknown | Unknown | — | no |
| pathspec | 1.0.4 | Unknown | Unknown | — | no |
| PyYAML | 6.0.3 | YAML | Neutral | NO | no |
| librt | 0.9.0 | Unknown | Unknown | — | no |
| tzlocal | 5.3.1 | Unknown | Unknown | — | no |
| urllib3 | 2.6.3 | urllib3 | Neutral | NO | no |
| pyhanko-certvalidator | 0.30.2 | Unknown | Unknown | — | no |
| typing_extensions | 4.15.0 | Unknown | Unknown | — | no |
| uritools | 6.0.1 | Unknown | Unknown | — | no |
| mypy_extensions | 1.1.0 | Unknown | Unknown | — | no |
| pip | 26.0 | Unknown | Unknown | — | no |
| oscrypto | 1.3.0 | Unknown | Unknown | — | no |
| File | Component | Vendor | Jurisdiction | CLOUD Act |
|---|---|---|---|---|
| .github/workflows/ci.yml | github_actions | GitHub (Microsoft) | US | YES |
| .github/workflows/pages.yml | github_actions | GitHub (Microsoft) | US | YES |
| .github/workflows/release.yml | github_actions | GitHub (Microsoft) | US | YES |
| .github/workflows/rust.yml | github_actions | GitHub (Microsoft) | US | YES |
| pyproject.toml | pypi | Python Package Index | US | NO |
| File | Component | Vendor | Jurisdiction | CLOUD Act |
|---|---|---|---|---|
| No infrastructure findings | ||||