From "what did the model say?"
to "who authorized this action?"
Once an agent can refund a customer, change DNS, or deploy code, the question becomes: who authorized this, on what evidence, and can we prove it six months from now?
Automatic-recording obligation in force. Penalty €15M or 3% global turnover.
First inspections in early 2026 surfaced third-party-AI gaps across the EU bank panel.
Cyber-insurance endorsement strips AI from default CGL coverage. Insurers want signed attestations.
US national-bank examiners aligning with the EU posture. Buyers preparing now.
Not a replacement.
A layer that didn't exist.
Nomos sits one layer below the framework, the registry, the APM, and the security stack, at the decision layer where authorization, evidence, and provability happen.
Observability answers "what did the agent do?" after the fact. Security answers "was something attacked?" in real time. Nomos answers a different question: "was this decision allowed, by whom, on what policy, with what evidence, and can a regulator replay it six months from now?"
Eight subsystems
lifted upstream.
Nomos packages depend on Orchetron primitives via cross-repo workspace:*. The same DAP wire bytes, the same SHA-256 hash, the same Ed25519 signature value, proven byte-for-byte by the SDK fixture round-trip test.
A self-host Orchetron customer can graduate to Nomos managed cloud by swapping implementations of the same interfaces. No fork. No migration tax.
Compliance,
exported.
Each framework engine produces a signed regulator-ready bundle deterministically from the evidence chain. Identical inputs → identical archive bytes → identical SHA-256, verified across all 7 frameworks.
Whoever signs
when the agent fails.
Not the CISO. Not the ML platform lead. The check-signer is whoever bears liability, General Counsel, Chief Risk Officer, CFO, or a Chief AI Officer reporting to one of them.
EU regulated finance
Tier 1–2 EU bank, insurer, or DORA-scoped fintech. EU AI Act + DORA + ISO CG 40 47/48 stack on the same buyer, no other ICP has three forcing functions concurrent.
US healthcare
Health systems, payers, healthtech with PHI exposure. HIPAA · OCR · Joint Commission drive the audit trail. Fully managed with BAA, Nomos governs the decision, PHI never leaves the customer.
US federal · regulated
Federal agencies, defense contractors with CUI, regulated utilities. FedRAMP · OMB M-24-10 · EO 14110. Self-host with sovereign anchor and formal-methods artifacts that hold up to NSA review.
Written down.
Not implied.
The rules below are load-bearing. They constrain pricing, packaging, and licensing across every phase. They are how a buyer can trust the ten-year arc, not just this quarter.
- × No BSL / SSPL / ELv2 relicense. Orchetron stays MIT, forever.
- × No single-cloud captive deploy of the open fabric.
- × No invented competitor data, every claim cited to a primary source.
- × No Nomos-branded model marketplace or agent framework. We govern existing ones.
- × No middleware between you and the regulator. Verification is offline against your key.
- → Free self-host on Orchetron, unlimited, MIT.
- → Free managed tier,100k governed decisions / month.
- → Managed, consumption per governed decision, public commitment.
- → Enterprise, adds SOC 2 II, ISO 42001, indemnification, FedRAMP path.
- → Annual-commit discount available; transparent step-pricing.