The instrument library

Install it, and you get the record for everything a record can carry, plus a dated list of exactly which obligations your records evidence and which they do not.

Not you are compliant. Nobody can sell that, and the sentence that makes this worth buying is the second half rather than the first: you will know, before somebody asks, which of the six things Colorado's Rule 7.7 wants you can actually produce.

Why not “install and you are compliant”

Because it is false, and because this library exists to catch exactly that claim in other people's products. The census reads ten systems and publishes what they cannot do. A tool from the same author that quietly implied a compliance verdict would end the only asset the work has, the first time an assessor checked.

Compliance is a judgement about a particular deployment by somebody qualified to make it. This maps, and it does not conclude.

Rule 7.7, item by item, honestly

Colorado's proposed Rule 7.7 requires a record showing six things when a meaningful human review is conducted. It is the sharpest test available because it is specific, it is dated, and it applies on 1 January 2027.

What the rule wantsWhat an install delivers
The reviewer identity Yes, where the approval path hands over an authenticated session. The record carries the approver and identity_source, which says whether the identity was resolved from authentication or supplied by the caller. It cannot invent an identity that was never captured.
Review timestamps Yes. With the standing caveat that a timestamp is written by the party whose conduct is in question, which is issue #49 and is not solved.
A written justification Yes, where the approval path captures one. The format carries a reason.
Whether the reviewer approved, modified or overrode No. This is a gap in the format, not in any framework it reads. See below.
Primary evidence available to the reviewer No, and not from here. Only the interface that rendered it knows what a person was shown. Nothing installed downstream can find out, and of six agent frameworks read, no approval object asserts it.
Reviewer authority and training, and their access to the system's intended use and limitations Never. Attributes of a person in HR and identity systems, and a fact about what a console displayed. No record format produces them and none should claim to.

Two of six are mechanical. One depends on the deployer's own interface. Two are not facts about a decision at all. And one is this library's own to close.

The one owed

verdict is permitted or refused. The Testimony Record cannot express “modified” either, which means a reviewer who changed an action before allowing it is recorded as having approved it unchanged. That is issue #88, disclosed in the Colorado comment and in the testimony that went with it.

It matters more than any other row above. Rule 7.7 asks for the distinction twice, and then makes it evidentiary: an override that fully reverses a decision indicates that human review was meaningful. The rule keys its conclusion to a signal the format cannot yet emit. Three of five agent frameworks read cannot emit it either, which is why this is a real market rather than a deficiency peculiar to one product. This library is the only one of the four that publishes the gap about itself.

What comes with an install

  1. A record, written where the deployer already is, from what their own systems emit. Nothing leaves their environment: the loop makes no network calls and the pack carries no telemetry, and both are tested rather than asserted.
  2. A gap report, dated and per obligation. Which rows a deployer's records evidence, which they do not, and which are not answerable from records at all. That third category is the one nobody else says, and it is the one that stops an assessor wasting a week.
  3. A bundle an assessor can check alone, without the vendor, without a login, and without trusting the library that produced it.
  4. The same thing again next quarter, against the text as it then reads.
  5. The answer across every text at once, and which of them are law today. Twenty instruments, and most deployers are subject to more than one.
  6. The answer across every record at once, against every text at once. One file, checked against all twenty in a single pass, sorted by whether each currently binds.
  7. A way to close the gap, not only measure it. The free adapter for a deployer's framework, the exact wiring snippet, and a check chained straight onto the record it just produced.
  8. Proof that the maintenance is real, not asserted. A diff between two committed versions of the same reading: obligations added, obligations removed, whether the text now binds when it did not before.

The question one text at a time cannot answer

Reading one instrument is the right shape for advising on Colorado specifically and the wrong shape for the first question a deployer actually asks, which is not what does this text want but does anybody require this of me yet.

A single pass across every published reading answers it: which of them ask a record to show who intervened, sorted by whether they are law on a given date. As at 13 September 2026, from the readings in this build:

  • Twelve of twenty instruments ask a record to show who intervened.
  • Four are law: Article 22(3) of the GDPR, applicable since 25 May 2018; Quebec's section 12.1, in force since 22 September 2023; Articles 22A to 22D of the UK GDPR, in force since 5 February 2026; and Article 34(1)(4) of South Korea's Framework Act, in force since 22 January 2026.
  • Two more are in effect and are not law: AIUC-1, a certification scheme, and the ICO's automated decision-making guidance, a regulator's published expectation. These are the two that ask for a record of the review itself rather than only a right to one, and neither can be enforced as one.
  • The rest is a deadline: Colorado on 1 January 2027, the EU AI Act on 2 December 2027, and two sets of Colorado rules that are filed and not yet law.

Every line of that comes from a force block in the reading it describes, and a reading whose commencement cannot be established from a held source says unknown rather than implying a date. One committed text carries a literal placeholder where its effective date belongs; the library says so rather than guessing one in.

What that reading cannot answer either

Naming which instruments ask for a signal is not the same as knowing whether a deployer's own records supply it, because it never reads a record, only the law. Checking one file against every instrument at once closes that from the other side: which of the twenty a deployer fully answers, which they partly answer, and which ask a record for nothing at all. The clause-level detail against one named instrument is still there for the deployer who already knows which law applies to them and does not want the census version of the answer.

Closing the gap, not only measuring it

The library's fourth piece is deliberately not a new paid thing. It names the free adapter for one of five frameworks (LangGraph, CrewAI, the OpenAI Agents SDK, Pydantic AI, AutoGen), prints the install line and the wiring snippet verbatim from that adapter's own README, and chains straight into a full check on the record it just produced. The adapter is MIT, standalone, and depends on nothing sold here; it makes a system able to write who approved an action, from what identity source, with what outcome, going forward. That is the one field the census found missing in nine of ten deployed agent systems.

What this does not claim, stated as plainly as everywhere else on this site. Producing that field closes exactly the gap this library measures. It does not satisfy a law's requirements about a reviewer's training, authority or independence, and no record format should claim to. The tool says this in its own output rather than leaving it to be assumed, the same discipline every reading here holds every other instrument to.

Not every deployer is asking the census question. Somebody who already knows a client operates only in Korea does not want to be told which of twenty texts might apply; they want to know what Korea's Framework Act specifically asks for. Scoping the final check to one named instrument instead of all twenty answers that directly. The install step is unchanged either way: the adapter writes one record format regardless of which law it will be read against, and it is the check, not the record, that is jurisdiction-specific.

Why it is a subscription and not a download

Not because of a licence check. Because of decay.

Colorado's rules were filed on 11 August 2026, revised on or about 23 September, and take effect on 1 January 2027. The instrument tracking them is dated and re-read when they move. A copy from last quarter does not stop working; it starts being wrong, which is the one thing a compliance buyer cannot tolerate.

That is why the statute and the proposed rules are kept as separate instruments. On any given date one of them may get re-read and the other may not, and a customer can see which. The maintenance is the product, demonstrated rather than described.

Demonstrated, not described

“The same thing again next quarter” is a promise until somebody can see it happen. A diff between two committed versions of the same reading reports the difference the way everything else in this library reports anything: obligations added, obligations removed, and whether force changed, none of it summarised from memory. The two versions are the two commits that actually touched the file, not a hand-written changelog kept alongside it, because a changelog can drift from what was actually read and a diff of the reading itself cannot.

An instrument read once and not yet re-read says so rather than inventing a predecessor to compare against, and reports exactly that.

What it is not

  • Not legal advice, and not a compliance assessment.
  • Not a certification, and not a mark anybody can display.
  • Not an opinion about any person or any deployment.
  • Not a claim that a record establishes what happened. A record establishes what was written down, and the difference between those is the whole subject of this site.

What is free and stays free

The specification, the validator, the emitter, the conformance corpus, the census rubric and the converter. A specification nobody can implement without permission is not a specification, and the position this library is sold into requires not owning the thing it is measured against.

What is sold is this library and the maintenance of it: the mapping from an obligation somebody else wrote to a signal in a record, kept current, with the reading published so a buyer can check the map rather than trust it.

Get in touch

There is no price on this page on purpose. What a licence costs depends on how many instruments and how many seats, and the honest answer to that is a conversation rather than a table. Write to troy@machinetestimony.com with what you need read and what you need checked against.