Independent Agent Assurance · EU AI Act ready
The agents you deploy are about to need independent evidence.
The EU AI Act now runs on two clocks. The Digital Omnibus (adopted June 2026) moved the high-risk obligations to 2 December 2027 — but the Article 50 transparency obligations were not moved: they apply, with penalties, from 2 August 2026. Either way, deployers must oversee and monitor the AI systems they run — and most of those systems are third-party agents you didn’t build and can’t fully see inside. Hlido is the independent, evidence-backed, continuously-updated assessment layer for exactly those agents: hundreds of already tested against a public, reproducible methodology.
Live, independent transparency-readiness signal across the full reviewed register โ evidence-backed, not vendor self-attested. Open the register โ
Building an agent? The provider fix list publishes, per agent, the observable public-surface changes that would let us verify a signal we currently cannot — free, no contact required, re-probed within a week of a change.
The readiness gap is real — and the clock is fixed
Only about a fifth of teams report proficiency in AI risk management (Economist Impact), and appliedAI found 40% of enterprise AI systems couldn’t even be clearly classified under the Act’s risk tiers. The bottleneck isn’t the technology — seven independent 2026 reports converge on the same conclusion: it’s the agentic-AI governance gap.
The EU’s new AI labels are optional. The duty behind them isn’t.
In June 2026 the Commission published a free set of icons for labelling AI-generated content — a basic “AI” mark, a Fully AI-Generated variant and a Partially AI-Modified variant. They are a user-tested, ready-made way to present the Article 50(4) disclosure that becomes mandatory on 2 August 2026 for deepfakes and AI-generated public-interest text. But the icons themselves are optional — and using one does not by itself make a disclosure compliant. The duty is the thing to get right; the label is just how you show it.
What the final Code of Practice actually requires of providers (published 10 June 2026; Commission and AI Board confirmed it as an adequate compliance tool on 9 July 2026): outputs must carry two machine-readable marking layers — digitally signed, time-stamped metadata and an imperceptible watermark — with watermarking mandatory for free-form text over 200 tokens. The earlier drafts’ “provenance certificate” alternative was dropped. The signature window closed on 22 July 2026; signatories are listed publicly and gain a presumption of compliance. Systems already on the market before 2 August 2026 have until 2 December 2026 to bring their machine-readable marking into conformity.
This is exactly the layer Hlido measures from the outside: every reviewed agent’s register entry carries an independent marking-readiness signal — does the vendor publish a machine-readable marking/provenance statement (C2PA, Content Credentials, signed metadata, imperceptible watermark), does it offer a free detection tool, and (once the AI Office publishes the list) is it a Code of Practice signatory. Self-declared labels are not verification; the register shows who can actually evidence the duty.
Why this is hard to do yourself
EU AI Act, Article 26 — obligations of deployers (applies to high-risk systems from 2 December 2027, post-Omnibus). Deployers of high-risk AI must monitor the operation of the system and act on the risks it surfaces. When the system is a third-party agent, you owe ongoing, defensible evidence about something you don’t control and can’t self-attest credibly — and the evidence trail you’ll need in 2027 is built from testing that starts now.
Self-evaluation tools test your own prompts with your own data — useful, but not independent, and not something a regulator or your own risk committee will accept at face value. A point-in-time procurement questionnaire goes stale the moment the vendor ships a new version. What the Act actually asks for is continuous, independent, evidenced assessment — the one thing you structurally cannot produce about a third party from the inside.
What Hlido gives you
Independent · evidence-backed · longitudinal · machine-readable. The four things a deployer monitoring obligation needs, and the four things an in-house eval can’t be.
Independent assessment per agent
A reproducible scorecard against a public methodology, plus a claim-audit table mapping every vendor marketing claim to PASS / FAIL / UNVERIFIED with the evidence behind it.
Continuous drift & incident watch
We re-test on new releases and alert you on score drift, tier change, or a logged reliability incident — so “monitor the operation” isn’t a once-a-year scramble.
Governance-grade evidence, dated
Signed, timestamped evidence (screenshots, scorecard history, incident log) you can hand to your risk committee or auditor — the longitudinal record of what an agent did and when.
Pulls straight into your stack
Every assessment is JSON over REST and MCP, so your GRC tooling, agents, and dashboards consume it directly — no PDF archaeology.
Assess your agent stack
Tell us which third-party agents you deploy. We’ll come back with their current independent assessment, what’s already in the corpus, and what an ongoing assurance arrangement would cover.
Hlido provides independent third-party assessment evidence to support your due-diligence and deployer-monitoring work. It is not a legal compliance certification, and Hlido is not a notified conformity-assessment body. Article references are to the EU AI Act for context; confirm your specific obligations with qualified counsel. Methodology overview: /methodology/ · what’s public: registry JSON.