André Ataíde
July 16, 2026

Wardex v2.4.0: EU AI Act Framework and Gleipnir-Anchored Releases

The EU AI Act (Regulation (EU) 2024/1689) arrives as a first-class assessment framework, and the release pipeline itself gains cryptographic provenance via Gleipnir anchoring.


Context

Wardex positions itself as the European release gate — built from the ground up for NIS2, DORA, CRA, and the emerging EU compliance standard. The EU AI Act is the next regulatory surface European teams must evidence, and v2.4.0 makes it assessable with the same catalog-driven model as the existing frameworks.

Separately, the release flow itself needed provenance. The v2.2.2 technology preview shipped a detached signed manifest; v2.4.0 turns provenance into a built-in, anchorable step using the Gleipnir consensus engine.


EU AI Act Framework (Regulation (EU) 2024/1689)

A new catalog pkg/catalog/eu_ai_act.yaml registers 31 controls covering all key articles of the regulation:

AreaArticles covered
Prohibited practicesArt. 5
Risk management systemArt. 9
Data governanceArt. 10
Technical documentationArt. 11 / 18
Transparency & provision of informationArt. 13
Human oversightArt. 14
Accuracy, robustness & cybersecurityArt. 15
Provider / deployer obligationsArt. 16 / 17 / 26 / 29
Fundamental rights impact assessmentArt. 27
General-purpose AI (GPAI)Art. 51–55
Post-market monitoring & incident reportingArt. 72 / 73

Assess against it like any other framework:

wardex assess controls.yaml --framework eu_ai_act
# or evaluate a policy bundle directly
wardex --framework eu_ai_act ./frameworks/eu_ai_act/*.yml

An example policy file ships at frameworks/eu_ai_act/ai_controls.yml.


Gleipnir-Anchored Release Flow

Every release now produces a chain seal — a SHA-256 hash of all release artifacts, anchored to an immutable Sparse Merkle Tree consensus log via the embedded Gleipnir engine.

The wardex provenance seal command walks a directory, hashes each artifact, computes a chain hash, and submits it to the configured anchor:

$ wardex provenance seal --dir ./dist --label "release-v2.4.0" -o chain-seal-v2.4.0.json
Chain seal written to: chain-seal-v2.4.0.json
  Total files:  5
  Chain hash:   65aac744...
  Anchored:     release-v2.4.0 (block ~0)

The resulting chain-seal-v2.4.0.json records each artifact's SHA-256 alongside the anchored chain hash. Anyone can later verify the release tree matches what was anchored.

gRPC driver isolation

The gRPC provenance driver (with its protobuf dependency) was isolated behind the grpc build tag to prevent a protobuf init panic when the backend is not used. To build with the remote anchor:

go build -tags grpc ./...

By default, gleipnir-embedded runs the consensus engine in-process; noop is the dry-run fallback.


Architectural Decisions

The EU AI Act demands demonstrable risk management across the AI lifecycle. Wardex v2.4.0 lets teams assess that lifecycle with the same auditable, cryptographically-sealed model used for NIS2 and CRA — and the release that delivers it is itself anchored.


Upgrade

go install github.com/had-nu/wardex/v2@latest

Checksums, SBOMs, and the chain-seal manifest are available in the GitHub Release.