Early access — cascade metrics are real (derived from canonical token telemetry); the operator field is a curated seed. Learn more about the data
◈ Compliance

AI Compliance Standards and Operator Evaluation

NIST AI RMF and the EU AI Act require auditable AI evaluation. SigRank provides governed operator evaluation with cryptographic provenance — ed25519-signed snapshots, content-free telemetry, and the Yield metric.

The AI compliance landscape

AI compliance standards are converging on a common requirement: organizations must be able to demonstrate what their AI systems do, how they are evaluated, and with what provenance. The NIST AI Risk Management Framework (AI RMF) organizes this into Govern, Map, Measure, and Manage functions. The EU AI Act classifies AI systems by risk tier and requires conformity assessment for high-risk systems. Both frameworks demand auditable evaluation — not just “we tested it” but “here is what we measured, how, and when, with evidence.”

Most compliance effort has focused on the model, output, and safety layers. The operator layer — whether the humans driving the AI are driving it well — has been unmeasured. That is a compliance gap: you cannot fully govern AI risk if you cannot measure operator performance. SigRank closes it with governed, provenance-backed operator evaluation.

How SigRank provides governed operator evaluation

SigRank gives compliance teams three things they need. First, auditable measurement: four token pillars (input, output, cache-read, cache-write) and the yield metric Υ = cache_read × output / input² computed from signed data. Second, cryptographic provenance: every snapshot is ed25519-signed on-device and verified server-side, so you can prove the token counts came from a real session without revealing what was in the session. Third, privacy by design: no prompt content is ever read or stored, so there is no content to protect or leak.

This is exactly what a NIST AI RMF “Measure” function requires for the operator layer — and what an EU AI Act conformity assessment needs for auditable operator performance. SigRank does not replace the compliance framework; it provides the governed operator evaluation that the framework calls for.

Privacy compliance

SigRank is content-free by design. It captures token counts only and never reads or stores prompt content. This means there is no personally identifiable content to protect — the data is token counts, not conversation text. Snapshots are signed on-device, so operators control their own data submission. Operators appear on the public leaderboard under codenames; real identities are never shown. Content-free telemetry is the privacy standard that makes operator evaluation possible without the privacy risks of reading prompts.

Explore the category

FAQ

What are AI compliance standards?
Regulatory and voluntary frameworks requiring auditable AI evaluation. NIST AI RMF (Govern, Map, Measure, Manage) and the EU AI Act (risk-tiered conformity assessment) are the most influential.
How does SigRank help with compliance?
Governed operator evaluation with cryptographic provenance. ed25519-signed snapshots, the Yield metric, content-free telemetry. An auditable, provenance-backed record of operator performance.
How does SigRank fit into the NIST AI RMF?
It serves the “Measure” function for the operator layer — continuous, auditable measurement via content-free token telemetry. ed25519 signatures provide the provenance the “Govern” function requires.
Is SigRank privacy-compliant?
Yes. Token counts only — never prompt content. No personally identifiable content to protect. Snapshots signed on-device; operators control submission. Codenames on the leaderboard, not real identities.