These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.
Vaara

Vaara is an open-source governance and evidence layer for AI agents. It checks each action an agent takes against a defined policy and produces a verifiable record of what the agent did and why. After an incident, regulators, auditors or customers may ask an organisation to prove exactly what its AI agent did. Ordinary logs cannot settle such questions, because the organisation that keeps them could have altered them. Vaara addresses this by producing tamper-evident records that an independent party can verify without trusting the organisation. It is designed to help deployers assemble evidence for obligations such as record-keeping and human oversight under the EU AI Act. Vaara does not certify compliance.
Before a governed action runs, Vaara scores its risk and decides whether to allow it, block it or escalate it for human review. The risk score adapts as the actual outcomes of past actions are reported back. Vaara connects to agents through adapters for frameworks such as LangChain, CrewAI and the OpenAI Agents SDK. It can also act as a proxy for Model Context Protocol (MCP) servers. A shadow mode records decisions without enforcing them, so organisations can test policies first.
Each decision, action and outcome is written to a hash-chained audit trail, in which any change to a past record becomes detectable. Records can be signed, timestamped and verified offline using only a public key. Vaara can also generate evidence reports mapped to EU AI Act articles, which flag where evidence is insufficient. It is written in Python and released under the AGPL-3.0 licence, with a commercial licence also available.
About the tool
You can click on the links to see the associated tools
Developing organisation(s):
Tool type(s):
Objective(s):
Impacted stakeholders:
Purpose(s):
Target sector(s):
Country/Territory of origin:
Lifecycle stage(s):
Type of approach:
Maturity:
Usage rights:
License:
Target groups:
Target users:
Stakeholder group:
Validity:
Enforcement:
Geographical scope:
People involved:
Required skills:
Technology platforms:
Programming languages:
Tags:
- ai compliance
- runtime oversight
- agentic ai
- ai act article 14
- tool-call governance
- adversarial classifier
- agent safety
- human-in-the-loop
Github stars:
- 14
Github forks:
- 1
Use Cases
Would you like to submit a use case for this tool?
If you have used this tool, we would love to know more about your experience.
Add use case




























