Changelog
What changed in each release of the Opencomplai CLI and engine, from the project's CHANGELOG on GitHub.
v0.9.1
Latest- The four Python services now write structured JSON logs (one object per line), honour LOG_LEVEL, and log errors they used to swallow, without logging client input.
- The adversarial evaluator recognises more refusal-suppression prompts and refusal phrasings.
- configure_telemetry() in opencomplai-core now also sets up JSON logging.
- risk-engine: override idempotency keys containing spaces no longer break the duplicate check.
- opencomplai check --sign signs with your key or fails with a clear error, and the signature now survives push to the dashboard.
- check writes JUnit, SARIF and a Markdown job summary for CI, and ships with a GitHub Action and a GitLab CI/CD template.
- check -m runs several manifests in one go, one report per system.
- New commands: diff, rules changelog, deployer-pack, incident and agents.
- ISO/IEC 42001 as a native, attestation-led framework pack, DORA and EBA citations next to EU AI Act articles, and GPAI provider templates.
- Upgrading from 0.8: read the 0.9 upgrade guide first; a few changes are breaking.
- Assess one system against several frameworks side by side: list them in compliance_targets and gaps and check --with-gaps produce one report per framework.
- NIST AI RMF results are still derived from your EU AI Act evidence through a crosswalk, and the dashboard now says so on the report.
- Failing CI on NIST AI RMF gaps is opt-in: add a gate section to opencomplai.yaml or pass check --gate NIST_AI_RMF. Without it, exit codes are unchanged.
- Mark a requirement as not applicable, with your reason, and it is waived instead of reported as a gap.
- The dashboard report has a framework switcher; paid plans see every framework.
- Rule explanations now list matched keywords in the same order on every run.
- opencomplai check now gates on the checker's verdict: a prohibited-practice classification exits with code 3 and a high-risk one with code 1, so the build fails either way.
- docs generate now works out of the box from a plain pip install — it previously failed with a missing-module error.
- Gap and recommendation reports now read Windows-generated files correctly, including PowerShell and Command Prompt encodings.
- Pushing a compliance artifact to the hosted dashboard from a 0.7.0 install is no longer incorrectly rejected.
- Transparency-obligation checks now cite the correct EU AI Act article.
- check --with-gaps now checks your actual repository, so results can show real gaps instead of always "unverified".
- New opencomplai fria generate command drafts a fundamental-rights impact assessment (EU AI Act Art. 27) from your system data.
- New opencomplai qms generate command produces a quality-management document with per-section evidence status.
- NIST AI RMF results are now derived from your EU AI Act evaluation via a framework crosswalk (coverage is partial today).
- Gap reports now also cite the matching ISO/IEC 42001 clause next to each EU AI Act article.
- docs generate now refuses to produce an invalid high-risk dossier by default, so problems surface before the document ships.
- The Python SDK now re-exports the compliance result types directly, so you don't need to reach into the core package.
- Dashboard dossier-envelope producer (docs generate --push)
- Documentation truth pass — the README and CI integration guide now match what the commands actually do
- Shared EU AI Act checker golden vectors verified against both the OSS and vendored engines
- CI/security hardening: pinned dependencies, live CI badges (replacing static ones), security floors, a weekly dependency audit, and a working Node CI pipeline
- Per-tenant ledger sequencing and a payload-bound hash chain close cross-tenant isolation and chain-tamper gaps
- Fixed the AI classifier crashing on non-finite risk-area/timeout values
- Fixed --ai-intent silently disabling itself when routed through the zero-setup ONNX backend
- Vercel gateway adapter is now type-checked and tested end to end
- EU AI Act obligations now track as ControlInstance objects (owner, evidence, freshness, state) across runs instead of resetting every scan
- New opencomplai controls status command
- Annex IV dossier generator now pulls in real scan/eval results instead of leaving sections empty — and still refuses to invent content it wasn't given
- Human-in-the-loop halt/resume flow (approve/resume)
- New Art. 17 and Art. 9 gap probes
- Breaking: the eval bridge was renamed with no aliases for the old identifiers
- Fail-closed scanner defaults (refuses symlinks, enforces numeric file/byte caps)
- Artifact probes for Arts. 9, 13, 14, 16, 24, 43, plus an MCP/agent detector
- Four compile-checked Python remediation templates via opencomplai recommend
- Working eval-bridge MVP and a local opencomplai serve loopback dashboard
- opencomplai, opencomplai-cli, opencomplai-core and opencomplai-ai are now published to PyPI, so pip install opencomplai installs the full stack without a source checkout.
- Deterministic, rule-based EU AI Act risk classification engine
- Developer CLI with contractual exit codes so CI can branch on status without parsing JSON
- Canonical CI artifact (compliance-artifact.json)
- Hosted multi-tenant path: gateway, risk engine, evidence vault, doc generator, egress proxy
- Air-gap-ready Docker Compose stack
Full release history is also available in CHANGELOG.md on GitHub.