78%
of organisations have no policy for creating or removing AI agent identities
Source: Cloud Security Alliance and Oasis Security, The State of Non-Human Identity and AI Security, January 2026Rule47 gives every agent a verified identity, an approved purpose and limits it cannot break. Consequential actions routed through Rule47 get a verdict before they run.
Why now
78%
of organisations have no policy for creating or removing AI agent identities
Source: Cloud Security Alliance and Oasis Security, The State of Non-Human Identity and AI Security, January 202680%
of unauthorised agent transactions through 2028 will be internal policy violations, not external attacks
Source: Gartner, Market Guide for Guardian Agents, 202551%
of organisations have no clear ownership over their AI agents
Source: Cloud Security Alliance and Oasis Security, The State of Non-Human Identity and AI Security, January 2026Only 34%
apply the same security controls to AI agents as to human workers
Source: Okta, AI Agents at Work 2026: Securing the agentic enterprise4 layers of agent control
Rule47 binds every governed agent to a verified identity, approved purpose, enforced limits and runtime control.
Every agent gets a verified, unique identity bound to a named human owner. No anonymous agents operate in your systems.
Why it matters
The foundation. Without identity, nothing is enforceable or auditable.
An approved scope of work in plain language. The agent carries its approved purpose: it knows what it may do, what it must refuse and when it needs a human.
Why it matters
This is policy as identity. The rules travel with the agent, not only in a policy document.
Approved tools, targets, spending caps, data access scopes. Limits are enforced at runtime, not as guidance in a PDF.
Why it matters
Prevents overreach at the moment of action, not in a post-incident review.
Consequential actions routed through Rule47 get one of four verdicts: ALLOW, ASK HUMAN, BLOCK or PAUSE AGENT. Every decision becomes evidence.
Why it matters
For high-risk AI systems, EU AI Act Article 14 requires effective human oversight. Rule47 helps create operational evidence of that oversight.
The Rule47 constitution
4 Layers + 7 Rules = Rule47. The minimum controls for any AI agent in production.
The four verdicts
The reason is written in plain language. Your team and your auditor read the same thing.
Inside purpose, rights and limits. The action runs.
Over the limit or something changed. A person decides.
Outside the approved purpose or scope. The action never runs.
The agent was changed without approval. It stops itself.
How it's different
Your identity provider establishes who the agent is. Rule47 determines whether this specific action is permitted within its approved purpose.
Other tools list your agents and replay what happened. Rule47 decides whether the action happens at all.
Each agent carries its approved profile. It can explain its own rules. If it is changed without approval, it pauses itself.
Built in Hamburg, Germany. Designed for EU AI Act, GDPR and data sovereignty from day one. Not a US product with a European region.
Compliance
Article 50 transparency duties of the EU AI Act are live since 2 August 2026. High-risk system obligations arrive in December 2027. And the AI Act is only one of them: GDPR, ISO standards, SOC 2 and internal AI policies all demand the same thing. Rule47 produces the evidence each of them asks for, while your agents work, not after an auditor asks.
A named person approves scope and decides on every held action. (Art. 14)
Purpose and limits are versioned. Unapproved changes pause the agent. (Art. 9)
Complete, exportable record of every decision and approval. (Art. 12, 50)
Agent profiles stay current as living system records, not static PDFs. (Art. 11)
Beyond the AI Act
Purpose limitation, data minimisation and a records trail for every automated decision. (Art. 5, 22, 30)
Agent inventories, approved purpose and versioned controls map to AI management system requirements.
Access control, change detection and logging aligned to information security management controls.
Decision records and approval evidence map to security, availability and processing integrity criteria.
Identity, evaluation and governance of agents support the Govern, Map, Measure and Manage functions.
Built and hosted in Germany. Agent data stays in the EU under your control.
How it works
Add an agent in minutes, or let it register itself.
A named owner approves purpose, rights and spending limit.
Each action is checked against the approved profile in real time.
Every decision becomes exportable evidence.
Illustrative prototype workflow
Trigger
Schedule
Weekdays 07:00
Agent
Invoice Agent
Rule47 check
Identity · Limit
ALLOW
Action
Send payment
ERP · SAP
Designed to integrate with
Orchestration
Identity
Agents