> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beyondguard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# BeyondGuard Compliance: EU AI Act and OWASP LLM Top 10

> Map BeyondGuard controls to EU AI Act requirements and OWASP LLM Top 10 to support your organization's AI compliance and audit obligations.

Regulatory requirements for AI — including the EU AI Act and the OWASP LLM Top 10 — demand that organizations do more than deploy AI responsibly in principle; they must demonstrate active, documented controls over their AI systems. BeyondGuard provides the enforcement infrastructure and the evidence trail your compliance and legal teams need to meet these obligations, turning security controls into auditable compliance artifacts.

## EU AI Act

The EU AI Act establishes a risk-based regulatory framework for artificial intelligence systems operating in or affecting the European Union. Understanding where your AI applications fall within this framework is the first step toward meeting your obligations.

**Risk classification** is central to the EU AI Act. High-risk AI systems — including those used in consequential decisions affecting individuals, and AI systems deployed in regulated sectors such as banking and financial services — are subject to mandatory technical controls, human oversight requirements, and extensive documentation obligations. If your organization deploys AI in these contexts, BeyondGuard's controls are directly relevant to your compliance posture.

**BeyondGuard provides** the following capabilities in support of EU AI Act compliance:

* **Audit logs** of all AI interactions, policy decisions, and guard actions — providing the interaction history required for accountability and incident investigation
* **Policy enforcement evidence** — documented records showing that defined security policies were active and enforced at the time of each interaction
* **Threat event reporting** — structured logs of detected and blocked threats, demonstrating that active cybersecurity controls were in place

**Relevant EU AI Act obligations covered** by BeyondGuard deployments include:

* **Transparency** — BeyondGuard's Control Plane maintains a complete record of how AI interactions were evaluated and what actions were taken
* **Human oversight** — Threat Event dashboards and Observation Mode give human operators visibility into AI behavior, supporting oversight requirements
* **Robustness and cybersecurity** — BeyondGuard's guard layer directly implements the technical cybersecurity controls required for high-risk AI systems

## OWASP LLM Top 10 Coverage

The OWASP LLM Top 10 is the authoritative reference for security risks in large language model applications. BeyondGuard maps its guard controls directly to each OWASP category, giving you a clear compliance posture against this framework.

| OWASP Category                       | BeyondGuard Control                    |
| ------------------------------------ | -------------------------------------- |
| LLM01: Prompt Injection              | Prompt Guard                           |
| LLM02: Sensitive Info Disclosure     | Output Guard (PII detection)           |
| LLM03: Supply Chain                  | Data Guard, model integrity monitoring |
| LLM04: Data & Model Poisoning        | Data Guard                             |
| LLM05: Improper Output Handling      | Output Guard                           |
| LLM06: Excessive Agency              | Agent Guard                            |
| LLM07: System Prompt Leakage         | Prompt Guard                           |
| LLM08: Vector & Embedding Weaknesses | Data Guard                             |
| LLM09: Misinformation                | Output Guard                           |
| LLM10: Unbounded Consumption         | Agent Guard (loop detection)           |

For detailed descriptions of each OWASP LLM category and the specific detection capabilities BeyondGuard applies to each, see [OWASP LLM Top 10 Mapped to BeyondGuard Controls](/resources/owasp-llm-top10).

## Audit Logs and Evidence

BeyondGuard's Control Plane maintains comprehensive, tamper-evident audit logs that capture every significant event in your AI security posture:

* **Interaction logs** — a record of every prompt evaluated, every response inspected, and every agent action monitored
* **Policy decision logs** — for each threat event, the specific policy rule that triggered, the confidence score, and the enforcement action taken
* **Guard action logs** — a timestamped record of every block, redaction, or flag performed by BeyondGuard guards
* **Policy change logs** — an audit trail of all configuration changes to policies, thresholds, and guard modes

These logs are available for export in structured formats suitable for ingestion into your SIEM, GRC platform, or compliance reporting toolchain. Retention periods are configurable to meet your regulatory requirements.

## Governance at L4 and L5

BeyondGuard's maturity model includes two governance-focused tiers that go beyond operational security controls to support enterprise compliance programs.

At **L4 (Governance)**, BeyondGuard provides compliance dashboards that aggregate threat event data, policy coverage, and guard performance metrics into structured reports aligned to regulatory frameworks including the EU AI Act and OWASP LLM Top 10.

At **L5 (Continuous)**, automated reporting workflows generate scheduled compliance reports and alert your compliance team to policy drift, coverage gaps, or threat trend changes that may affect your regulatory standing.

Organizations in regulated sectors — including banking and financial services — benefit most from reaching L4 or L5 maturity, where the compliance evidence generation becomes systematic rather than manual.
