ozDNA

Use case · Autonomous compliance agent

Immortal MLRO

An autonomous compliance agent running on the ozDNA Council oversight runtime. It classifies each decision by risk, escalates the high-risk ones to a multi-model vote with a veto, writes every step to an append-only, hash-chained ledger, and hands an auditor a signed attestation.

EU AI Act Art. 9 Art. 12 Art. 13 Art. 14 MASAK / CASP context

The problem

Oversight is manual, spend is flat, and the evidence is scattered

A Money Laundering Reporting Officer signs off on decisions a machine already made — but the reasoning, the model votes, and the trail that a regulator will ask for live in three different places, if they exist at all.

01

AI spend is disproportionate to risk — the same model cost is paid whether a decision is routine or high-stakes.

02

Human oversight is manual and unrecorded — a sign-off happens, but the mechanism that produced it is not itself software.

03

The evidence a regulator asks for is scattered — decision, rationale, and outcome are not one traceable, tamper-evident record.

How it works

Classify → Route → Oversee → Prove

The Immortal MLRO is the same four-stage runtime, wired to an anti-money-laundering workflow. Low-risk work goes to the cheapest sufficient model; a high-risk decision is escalated to the Council — where a 5× token cost is a deliberate insurance premium, not waste.

STEP 1

Classify

DT 5.0

Each case is placed on a risk tier — routine screening vs. a decision that carries regulatory weight.

STEP 2

Route

Risk-proportionate

Low risk → the cheapest model that clears the bar. High risk → the Council.

STEP 3

Oversee

Council

Multi-model vote with a veto and a fail-closed judge. Automation-over-reliance is designed out.

STEP 4

Prove

Ledger → Attestation

Decision, votes, rationale and outcome are written to an append-only, hash-chained log and rendered as an attestation.

The distinctive part

Each component implements a specific AI Act article

This is not a compliance narrative bolted onto a product. Each runtime component maps to an obligation — and the mapping is the product.

ozDNA componentAI Act articleWhat it implements
DT 5.0Art. 9Risk management — work is placed on a risk tier continuously, across the lifecycle.
CouncilArt. 14Human oversight in software — a stop/veto authority and a guard against over-reliance on automation.
LedgerArt. 12Record-keeping — automatic event logging that is traceable and tamper-evident.
AttestationArt. 13Transparency — the decision's rationale and its limits, presented to a deployer or auditor.

ozDNA implements, operationalises and evidences these obligations. It makes no absolute compliance claim — that determination rests with the deployer and its regulator. Timeline anchors: Art. 50 transparency duties apply 2 Aug 2026; Annex III high-risk areas 2 Dec 2027; systems embedded in regulated products 2 Aug 2028. Dates should be re-verified before any public material ships.

Live evidence

A single decision, as it leaves the Ledger

A redacted, illustrative attestation — the append-only record for one high-risk decision the Council reviewed.

attestation · immortal-mlroSEALED · APPEND-ONLY
decision_id   imr-2026-08-04-7Q31
risk_tier     HIGH  (DT 5.0 · Art. 9)
workflow      AML transaction review
routed_to     Council  (Art. 14)
council_vote  4 approve · 1 veto  →  HELD (fail-closed)
rationale     counterparty pattern matched a high-risk typology;
             one model raised an unresolved sanctions-list ambiguity.
outcome       escalated to human MLRO; not auto-cleared
recorded      2026-08-04T09:41:22Z  (Ledger · Art. 12)
prev_hash     a91f…c40d
this_hash     3e77…8b12  (hash-chained, append-only)
attested_to   deployer + auditor  (Art. 13)
Illustrative mock, values redacted. No real case data. The veto path — a decision held rather than cleared — is the point: the record shows oversight actually bit.

Who it's for

Regulated operators under real audit pressure

Built for the compliance-officer-and-CTO pair who decide together — the material has to speak both languages: the obligation and the integration.

Crypto-asset service providers (CASP) Regulated fintechs Obliged AML entities

Next step

Request a compliance audit

Tell us which AI systems you run. The audit output is itself a classification report — the product demonstrates itself.

Submissions reach us by email — no CRM, no tracking beyond the form itself.