The EU AI Act (Regulation (EU) 2024/1689) arrives as a first-class assessment framework, and the release pipeline itself gains cryptographic provenance via Gleipnir anchoring.
Wardex positions itself as the European release gate — built from the ground up for NIS2, DORA, CRA, and the emerging EU compliance standard. The EU AI Act is the next regulatory surface European teams must evidence, and v2.4.0 makes it assessable with the same catalog-driven model as the existing frameworks.
Separately, the release flow itself needed provenance. The v2.2.2 technology preview shipped a detached signed manifest; v2.4.0 turns provenance into a built-in, anchorable step using the Gleipnir consensus engine.
A new catalog pkg/catalog/eu_ai_act.yaml registers 31 controls covering all key articles of the regulation:
| Area | Articles covered |
|---|---|
| Prohibited practices | Art. 5 |
| Risk management system | Art. 9 |
| Data governance | Art. 10 |
| Technical documentation | Art. 11 / 18 |
| Transparency & provision of information | Art. 13 |
| Human oversight | Art. 14 |
| Accuracy, robustness & cybersecurity | Art. 15 |
| Provider / deployer obligations | Art. 16 / 17 / 26 / 29 |
| Fundamental rights impact assessment | Art. 27 |
| General-purpose AI (GPAI) | Art. 51–55 |
| Post-market monitoring & incident reporting | Art. 72 / 73 |
Assess against it like any other framework:
wardex assess controls.yaml --framework eu_ai_act
# or evaluate a policy bundle directly
wardex --framework eu_ai_act ./frameworks/eu_ai_act/*.yml
An example policy file ships at frameworks/eu_ai_act/ai_controls.yml.
Every release now produces a chain seal — a SHA-256 hash of all release artifacts, anchored to an immutable Sparse Merkle Tree consensus log via the embedded Gleipnir engine.
The wardex provenance seal command walks a directory, hashes each artifact, computes a chain hash, and submits it to the configured anchor:
$ wardex provenance seal --dir ./dist --label "release-v2.4.0" -o chain-seal-v2.4.0.json
Chain seal written to: chain-seal-v2.4.0.json
Total files: 5
Chain hash: 65aac744...
Anchored: release-v2.4.0 (block ~0)
The resulting chain-seal-v2.4.0.json records each artifact's SHA-256 alongside the anchored chain hash. Anyone can later verify the release tree matches what was anchored.
The gRPC provenance driver (with its protobuf dependency) was isolated behind the grpc build tag to prevent a protobuf init panic when the backend is not used. To build with the remote anchor:
go build -tags grpc ./...
By default, gleipnir-embedded runs the consensus engine in-process; noop is the dry-run fallback.
-tags grpc avoids loading a heavy init path for users who only need the embedded or noop backend.The EU AI Act demands demonstrable risk management across the AI lifecycle. Wardex v2.4.0 lets teams assess that lifecycle with the same auditable, cryptographically-sealed model used for NIS2 and CRA — and the release that delivers it is itself anchored.
go install github.com/had-nu/wardex/v2@latest
Checksums, SBOMs, and the chain-seal manifest are available in the GitHub Release.