Appearance
Changelog
New features, improvements, and fixes in the Modulos platform.
2026
August 25, 2026
- added Claude Console joins the Runtime Inspection Sources — connect with an Anthropic Admin API key to run tests on Claude usage, cost, and adoption metrics (tool acceptance rate, lines of code added, active users, sessions, and more), and let Scout report on usage, spend, and organization posture. Like every Source, it starts disabled until an organization admin enables it under Organization → Source Connectors
- added Geographic Scope on project creation — optionally mark where the system will be used (EU, UK, US, APAC, LATAM, MEA, or Global); the selection becomes part of the project context Scout uses in conversations and risk quantification
- added CCPA ADMT Regulations framework pair (templates 1.0.32) — MFF-29 assesses one automated decisionmaking technology (ADMT) under the California Privacy Protection Agency's CCPA regulations across eight requirements: the coverage determination with the three-part human-involvement test and the closed significant-decision list, the Pre-use Notice, the opt-out of ADMT, the human-appeal route, the hiring and work-allocation exceptions on their conditions, access to ADMT, the Article 10 risk assessment for the ADMT, and the service-provider, third-party and ADMT-supplier duties; OFF-29 covers the organization's ADMT request-handling infrastructure, the human-involvement and human-appeal capability, the risk-assessment program with the April 1 submissions of risk-assessment information to the Agency, the notice, purpose-compatibility and contract program, and the California ADMT regulatory watch
- added Thirteen new California-specific Controls implement the duties, one per requirement; none is shared with another framework. A new CCPA Role tag (Business using ADMT; Service provider or contractor; Third party; ADMT supplier; deliberately non-exclusive) marks which duties attach in which role. Consumers include California-resident employees, job applicants, independent contractors, and students. Article 11 compliance is due no later than January 1, 2027 for a business that used ADMT for a significant decision before that date, and at any time a business uses ADMT for a significant decision on or after it; risk assessments have been required since January 1, 2026, with December 31, 2027 for continuing pre-2026 processing and April 1, 2028 for the Agency filing covering assessments conducted in 2026 and 2027; the framework will be updated if the Agency revisits the ADMT provisions
- improved EU AI Act precision update (templates 1.0.32) — all 76 Requirements and the 22 EU-specific Controls of MFF-1/OFF-1 re-verified sentence by sentence against the consolidated Regulation (EU) 2024/1689 as amended by the Digital Omnibus: application dates state both Chapter III routes (2 December 2027 for Annex III, 2 August 2028 for Annex I Section A, with the Article 2(2) rule for Section B products), the general-purpose AI chapter follows the amended compliance architecture (presumption of conformity only from harmonized standards cited in the Official Journal; Codes of Practice with the limited effect of amended Article 56(6)), authorized-representative, importer, distributor, deployer and transparency texts carry the Regulation's actors and triggers, and every full-text reference points to the consolidated version
- changed EU AI Act Requirements renamed to the Regulation's defined term — "Authorised Representative" replaces "EU Representative" on MRF-37, MRF-114–116, MRF-128 and MRF-130–131; MRF-48 becomes "Relevant and Sufficiently Representative Input Data", MRF-55 "Informing Natural Persons Subject to a High-Risk AI System", and Control MCF-177 "Appointing Authorised Representative". The six Article 50 transparency Requirements now carry the Transparency use-case tag instead of High Risk, so they scope in for every AI system the Article covers
August 24, 2026
- added Mention notifications — @mentioning a user in a comment on a Control, Requirement, Asset Card, Policy, or Policy Version now sends them a dedicated notification that links to the comment; each mention type can be toggled under Notification Preferences → Collaboration
- added AI usage visibility — the new AI Usage tab on Organization Settings shows the percentage of the monthly AI quota consumed, with a state badge for approaching or exceeded limits
- added Quarterly test schedules — Runtime Inspection tests can now run quarterly (first day of January, April, July, and October) in addition to daily, weekly, and monthly
- added Job creation gains Select all in the entity picker and a Create and Run button that triggers the first run immediately; Run Details now shows what each step ran and the entity's own result badge
- improved FINMA AI Governance precision update (templates 1.0.31) — the fourteen Requirements and three FINMA-specific Controls of MFF-22/OFF-22 now keep the supervisory registers of Guidance 08/2024 apart: what FINMA expects (the proportionate alignment of governance, risk management, and controls with the institution's AI risk profile), what it observed and assessed in its ongoing supervision (reported with the guidance's own qualifiers), and the existing technology-neutral, principle-based financial market law that carries the obligations the guidance itself does not create. Enumerations track the guidance's own wording — the three risk-classification considerations (materiality, specific risks, probability of materialization), the complete proportionality factors including the institution's structure, and the section 2.7 observations on independent review — and mechanics the Controls provide beyond the guidance's words, such as review rhythms and fallback testing, are labeled as the framework's supporting practice. Descriptions of reused shared Controls now say what those Controls do and do not carry for this framework
- changed Partially quantified risks now contribute the value of their quantified threats to risk totals, limit utilization, and the top-risks chart, instead of counting only when every threat is quantified
August 23, 2026
- improved NYC Local Law 144 content precision update (templates 1.0.31) — the requirement and Control texts now state the adopted rules' conditions in full: the simplified-output definition as a prediction or classification, the cumulative selection and scoring calculation sets with the full-sample median score, the complete independent-auditor tests with their during-the-audit qualifiers, the under-2-percent condition for excluding a category from the impact-ratio calculations with the published justification, count, and rate, the covered populations (candidates for employment and employees being considered for promotion, with New York City residence for the notice and disclosure audiences), the covered-use qualifiers on the posting and its six-month tail, and the data-transparency request route scoped to the three specified items with mandatory disclosure outside the statutory withholding grounds. Positions stated only in the Department of Consumer and Worker Protection's FAQ are attributed as the Department's stated guidance, and audit and disclosure duties are attributed throughout to the employer or employment agency, the actors the law names
- improved Colorado SB 26-189 content precision update (templates 1.0.31) — the requirement and control texts across all twelve requirements and twelve Colorado-specific Controls now state the statutory conditions with their gates and routes: the section 6-1-1702(5) applicability gate for developer duties, the two pre-use notice routes with the public-posting option, the FERPA and federal health-privacy channels with their conditions, the covered-entity financial-assistance disclosure branch, the creditor federal-credit-notice branch, the insurer branch with its deemed-compliance predicate, the mandatory versus discretionary Attorney General and insurance-commissioner rulemaking, both enforcement cure mechanics, the fault-allocation rules for discrimination actions, and the anti-indemnification rule reaching every contract between a developer and a deployer. Practices the framework recommends beyond the statute's own commands are labeled as supporting practice, with assessment surfaces keyed to the statutory outcomes they serve. A sixth watch marker, CO-WATCH-AG-PART17-RULES, tracks the Attorney General's discretionary authority to adopt rules implementing or clarifying any part of part 17
August 15, 2026
- added Colorado SB 26-189 framework pair (templates 1.0.30) — MFF-28 assesses one covered automated decision-making technology across seven requirements: coverage and role determination, the developer transparency package and update notices, the deployer pre-use notice at points of consumer interaction, the post-adverse-outcome disclosures within 30 days with their sectoral routes, consumer correction and meaningful human review, and compliance records with their liability-evidence dimension; OFF-28 covers the organization's notice and disclosure infrastructure with the accessibility duty, the meaningful-human-review capability, the deployer records program, the liability posture and contract hygiene under the relative-fault rules and the void-indemnification provision (with its developer carve-out and insurance unaffected), and the Colorado rulemaking and codification watch
- added Twelve new Colorado-specific Controls implement the statutory duties and the framework's supporting coverage, organization-capability, liability-evidence, and regulatory-watch practices; one shared transparency Control (MCF-171) supports the pre-use notice. A new ADMT Role tag (Developer, Deployer; deliberately non-exclusive) marks the developer and deployer branches; it does not encode every sectoral capacity (MRF-485 and MRF-486 also carry direct HIPAA covered-entity duties, and MRF-486 the insurer fallback). Customer duties apply to consequential decisions made on or after January 1, 2027 (the rulemaking authorities and the other provisions listed in Section 5(2) took effect on passage); the framework will be updated when the mandatory Attorney General rules are adopted
- added NYC Local Law 144 framework (templates 1.0.29) — MFF-27 assesses one automated employment decision tool used to screen candidates for employment or employees for promotion in New York City across six requirements: the AEDT applicability determination, the annual independent bias audit with its selection-rate, scoring-rate, and impact-ratio calculations, the audit data requirements, the public posting of the audit date, summary, and distribution date, the 10-business-day notice to candidates and employees who reside in New York City, and the data-transparency disclosures. App-only: no organization-level twin, no scoping questionnaire, no new tag family
- added Four new Local Law 144 Controls — the independent AEDT bias audit, the public disclosure of bias audit results, the pre-use notice to candidates and employees, and the AEDT data transparency disclosures; five further Controls reused from the existing estate (risk tiering, data bias assessment, model fairness metrics, model bias assessment, transparent deployment at workplace), shared with other templates: four with the EU AI Act, two with NIST AI RMF, three with IEEE 7003
August 6, 2026
- added Snowflake joins the Runtime Inspection Sources — connect with an account identifier and programmatic access token to run tests on metrics from your Snowflake data warehouse
- added Connection health for Sources — the Sources table on
Project → Settings → Sourcesnow shows whether each configured Source is Healthy, Broken, Unknown, or Not applicable, checked automatically when you open the page
August 4, 2026
- added Cyber Resilience Act framework pair (templates 1.0.28) — MFF-26 assesses one AI-enabled product with digital elements across scoping, classification and the conformity route (including the Article 12 high-risk-AI interplay), the cybersecurity risk assessment, the thirteen Annex I product-security properties with risk-based applicability, vulnerability handling and SBOM, the support period, user information, technical documentation, and CE marking; OFF-26 covers the organization's manufacturer capabilities, the Article 14 reporting ladders (applying from 11 September 2026), post-market corrective action, records, and the conditional authorized-representative, importer, distributor, and open-source software steward roles
- added 22 new CRA Controls, including the two Article 14 reporting-ladder Controls with the 24-hour, 72-hour, and final-report deadlines; 87 further Controls reused from the existing estate, with substantial overlap into ISO 27001, NIS2, DORA, ISO 42001, and EN 18286
- added Three new tag categories for CRA scoping and navigation — CRA Role, CRA Product Category, and CRA Phase
July 28, 2026
- changed EU AI Act content verified line by line against the published Digital Omnibus (Regulation (EU) 2026/1744, OJ L, 24.7.2026) — every Digital Omnibus reference now cites the final regulation, and one deadline that changed between the adopted and the published text is corrected: notified bodies already notified under Annex I Section A legislation must apply for AI Act designation by 28 January 2028 (Article 43(3))
- changed Conformity assessment (Article 43) and post-market monitoring (Article 72) now state both dates that matter — the articles apply from 2 August 2026, while the duties fall due with the deferred high-risk obligations (2 December 2027 for Annex III, 2 August 2028 for Annex I Section A)
- changed The safety-component boundary is stated exactly as enacted — the exclusion covers the non-safety-related aspects of user assistance, performance optimization, service efficiency, automation or convenience or quality control, and components whose failure or malfunctioning endangers health and safety remain safety components (Articles 3(14), 6(1a)-(1c))
- added Transitional coverage on the AI System Classification requirement — legacy high-risk systems are caught only if their designs change significantly after the Chapter III dates, and high-risk systems intended for use by public authorities must comply by 2 August 2030 (Article 111(2))
- changed Precision fixes throughout the EU AI Act frameworks — the Article 25 value-chain written agreement stated as the joint duty of provider and supplier, with the provider and operator obligations under Article 25(2) and (4) added to the Article 99(4) fine tier, authorized-representative duties per Article 54(3), documentation and assessment requests pointed to national competent authorities, and notes on the new Articles 60a and 75(1e)
July 23, 2026
- changed The read-only project role is now called Viewer (previously Auditor). The rename is a UI label change; the role's permissions are unchanged.
July 6, 2026
- changed EU AI Act framework updated for the Digital Omnibus (Regulation (EU) 2026/1744, in force from 27 July 2026) — enforcement dates revised across Requirements, with high-risk Annex III obligations applying from 2 December 2027, Annex I product-safety obligations from 2 August 2028, and the new Article 5 prohibitions from 2 December 2026
- added Two new prohibited practices under Article 5 — AI systems that generate or manipulate non-consensual intimate imagery, and AI systems that generate AI child sexual abuse material
- added New Article 4a Requirement covering the legal basis for processing special-category personal data to detect and correct bias, at both application and organization level
- changed Many EU AI Act Requirements renamed to article-anchored titles (for example, "Art. 5 — Prohibited AI practices") so they map more directly to their Article in the Official Journal text
- changed Rewritten audit guidance for EU AI Act-specific Controls — each now sets out what the regulation requires, key considerations, what would fail the Control, related Controls, and the Evidence an auditor expects
- changed EU AI Act scoping questionnaire updated for the Digital Omnibus thresholds — guidance revised throughout and the third-party conformity assessment question reworded to ask whether the assessment is required for health and safety reasons (per Article 6(1c); question set and flow unchanged)
July 4, 2026
- changed ISO 27001, ISO 27701, and ISO 42001 framework overhaul — every Requirement now names its exact clause or Annex reference and summarizes what the clause requires in plain language, with the shared Clauses 4–10 Requirements linking to the matching Requirement in the other ISO standards
- changed ISO 27001 and ISO 27701 application frameworks restructured to group Annex A Controls under theme and table Requirements (Organizational, People, Physical, and Technological Controls; PII controller, processor, and joint Controls)
- added Full descriptions, assessment questions, and audit guidance for all ISO 42001 Controls, plus a new Annex A.10.4 Customers Control
- changed Shared management-system Controls now read naturally under every standard, with a climate-change relevance Control under clause 4.1 of all three per the 2024 amendments
- changed ISO 27701 updated to the published 2025 edition
June 11, 2026
- added Risk Quantification timeseries view
- changed NIS2 & DORA framework templates - legal refactor with new tag scheme
June 9, 2026
- fixed Org-user role assignment when the user is already a platform user
June 3, 2026
- added Historical Risk Quantification table
- added Risk Agent structured output
May 14, 2026
- fixed Framework project progress calculation
May 5, 2026
- added Generate Evidence PDF from EU AI Act manual settings scoping
- added Risk Agent - Past runs historical view
- added EU AI Act Settings - default tag assignments
- changed On-demand validation for EU AI Act Settings
- fixed EU AI Act manual setting - preview warnings unified
May 3, 2026
- added Manual EU AI Act scoping in Project settings with two-step preview/apply flow
- added Risk Utilization sortable on Projects list
- changed Scout Agent - Connector and Source metadata included in LLM context
- changed Evidence preview - inline image zoom and Fit Width default for PDFs
- changed Owners list - deactivated-user indicators
- changed Policy acknowledgement user experience improvements
- fixed EU AI Act Settings - chip labels, tooltips, and preview counts
April 22, 2026
- added Associated Controls view inside Policy archive
- changed Invited-user modal now displays role assignments
April 21, 2026
- added Filter Controls by linked Policy
- changed Evidence preview migrated to unified file viewer
- changed Projects table - new columns, sorting (incl. AI Lifecycle Stage), and persisted column visibility
- fixed Project compliance progress chart - calculations update
April 19, 2026
- changed Multiple Project Owners visible in Projects table
April 17, 2026
- added Lifecycle Stage and Risk Limit columns on Projects table
April 16, 2026
- added New Project ownership model with multiple Owners at the same time
- fixed User selection dropdowns now limited to activated Users
April 14, 2026
- added Risk Quantification time series - "Value Over Time" visualization
- added Attach Policies as Evidence for Controls
- added Multi-repository selection in Scout Agent chat
- added Scout Agent tool to query Policies linked to Controls
- changed Control status auto-updates when linked Runtime Inspections fail
- changed Scout Agent UI/UX improvements
- changed Organizational User Roles UI/UX improvements
April 7, 2026
- added Possibility to link Policies to Compliance Controls
- added Policy Acknowledgement history tab in My Tasks
- changed Policy PDF and content indexing for Scout Agent
- changed Clearer UX for expired GitHub Connector in Scout Agent
- changed GitHub Connector automatic reconnection when app is already installed
April 6, 2026
- changed GitHub Connector migrated from OAuth App to GitHub App to improve performance and usability.
- added AI Lifecycle Stage field intorduced to Project creation dialog
- added Risk Quantification scenario analysis and Monte Carlo details
- added Scout Agent tool to search platform documentation for how-to questions
- added Vijil metrics search and selection in Scout Agent
- changed Threat Vector Quantification history improvements
- changed Shared Controls overlap highlighting on Framework Graph
March 31, 2026
- added NIS2 Framework (Network and Information Security Directive 2)
- added DORA Framework (Digital Operational Resilience Act)
- added Risk and Threat Vector Quantification history view
- added Export Policy to PDF
- changed Policy content file management
- changed Users notification when a new Policy acknowledgment is required
- changed Risk Quantification results page with full details
- added Vijil interactive metric endpoint for Runtime Inspection module
March 24, 2026
- added Upload PDF as Policy
- changed Policy Owner notification when a Policy renewal is approaching
March 19, 2026
- added Policy Templates - create Policies from reusable templates with framework mapping
- added Policy archive
- changed Custom titles for Scout Agent conversations
March 10, 2026
- added Policy Center - create, manage, and track compliance Policies
- added Policy workflow: draft → review → approval → active → archived
- added Policy comments and activity log
- added Policy renewal periods and acknowledgements
- added Policy acknowledgement dashboard
- added Policy Manager role in organization user management
- added Scout Agent tools for Policy Center
- added Risk Agent quantification method
- changed ISO 27001 and ISO 27701 Control content updates
- changed GDPR framework Controls updated with tailored guidance
February 13, 2026
- added Vijil integration as a Source for Scout Agent
- added Organization-level Controls to enable/disable Sources per organization (today's
Organization → Source Connectorspage) - added Organization-level Controls to enable/disable Connectors per organization (today's
Organization → Source Connectorspage) - changed Scout conversation status and loading improvements
- changed Scout chat retry mechanism for improved reliability
January 29, 2026
- added Scout can now use multiple Sources and Connectors simultaneously
- added User mentions in Scout conversations
- added AWS Infrastructure Runtime Inspection Source
- changed Graph visualization enabled in production
January 21, 2026
- added Brand new Documentation Portal www.docs.modulos.ai
January 20, 2026
- added Langfuse Connector as a Tool for Scout Agent
January 14, 2026
- changed New left side navigation for Platform UI
- added Copy answer functionality for Scout Agent
- added Scout Agent can now create Evidence from chat answers
- added Scout Agent mentions for Runtime Inspection concept
- added Langfuse Connector as a Source for Runtime Inspection module
- added Azure Connector as a Source for Runtime Inspection module
January 6, 2026
- changed Organization Currency added to Scout Agent context
January 5, 2026
- added Risk Quantification introduced to Scout Agent
- added Scout Agent context-aware greetings
2025
December 31, 2025
- added BitBucket Connector as a Tool for Scout Agent
- changed Google Drive Connector allows for specififc Files selection.
- changed Risks, Project and Organization descriptions added to Scout Agent context
December 18, 2025
- added Google Drive Connector as a Tool for Scout Agent
- changed Scout Agent context enriched with Risk data
- changed Upgrade of Rich Text Editor
December 12, 2025
- added GitHub Connector as a Tool for Scout Agent
- changed Evidence Recommendation Agents quality and performance improvements
December 2, 2025
- added Connectors and API tokens introduced to new User Settings menu
November 13, 2025
- added Risk Quantification in Public Preview
- added Scout Agent in Public Preview
- changed Clarity consent V2 implementation
October 30, 2025
- added Support for different Currencies on Organization level
- added Spanish now available as language for platform UI
October 13, 2025
- added Risk Quantification in Private Preview
- changed Scout Agent preserves historical chats
September 15, 2025
- added Scout Agent in Private Preview
September 10, 2025
- added French now available as language for platform UI
September 5, 2025
- added New GDPR Framework
August 27, 2025
- added German now available as language for platform UI
- added New ISO 27701 Framework
- added Tags added to Controls to reflect Controller and Processor roles and scopes
August 26, 2025
- changed Improved Italian translations
August 18, 2025
- added Integrations with External Sources (Datadog and Prometheus)
August 11, 2025
- added Multilanguage support, Italian now available as language for platform UI
May 28, 2025
- added New Framework OWASP Top10 for LLM released in Private Preview
May 26, 2025
- added Export of Control to PDF
- added Export of Project to PDF
May 14, 2025
- added Framework Management (update of Frameworks in Projects when new version is released)
May 9, 2025
- added New Framework ISO 27001 released in Private Preview
April 9, 2025
- added Request of deletion according to GDPR
March 13, 2025
- added Control Assessment Agent released to Public Preview
March 6, 2025
- added AI Agents disclaimers added to the platform
- changed Improved the UX of Tables and Lists
February 7, 2025
- added EU AI Act Scoping Questionnaire released in Private Preview
January 15, 2025
- added Free Starter plan introduced to the platform
- added AI Agents monitoring available via Langfuse
January 3, 2025
- changed Improved the performance of endpoints in Modulos Client
- changed AI Agents stability and performance improvements
2024
December 20, 2024
- changed User invitation flow simplified
- changed Extended the expiration time of User invitation
December 17, 2024
- fixed Fixed issue with large PDF processing by AI Agents
- changed Simplified the UX of Project creation
December 2, 2024
- changed AI Agents performance and quality improvements
- added New UI indicators to differentiate User roles
November 27, 2024
- changed Control Report added to the context of "Evidence Scoring" to improve results
- added "Control Agent" released in Private Preview
November 13, 2024
- changed Control Guidance improvements
- added Role Based Access Control (RBAC) new screen introduced:
- Overview of User own roles
- Overview of all User roles across all Projects for Organization Admins
October 30, 2024
- changed "Evidence Scoring" AI Agent performance improvements
- added AI Agents documentation
October 23, 2024
- added "Evidence Scoring" AI Agent released in Private Preview
October 14, 2024
- fixed Fixed the issue with deleting Projects from the platform
- changed UI Performance improvements
September 30, 2024
- changed Performance improvements for the Notifications event stream
- fixed "Project Not Found" errors resolved
September 26, 2024
- fixed CSV issues for Evidence upload resolved
September 19, 2024
- added Introduced Rich Text Editor for Evidence module
- added Allow to remove relationship between Control and Evidence
September 16, 2024
- added Evidence manipulation actions are now logged in the audit log
- changed SEO optimization for the documentation portal
September 4, 2024
- added Introduced on-the-fly platform version change notification
- added Introduced unique identifiers for all the Governance concepts
August 27, 2024
- changed Adjusted default Editor privileges to be able edit Assets
- added Developer Guide published. Modulos Client is a Python-based library that offers a programmatic interface to interact with the Modulos platform.
August 22, 2024
- added Capability to export Projects summary to PDF
- added Introduced expiration times to API Tokens (one hour/day/week/month/year)
August 14, 2024
- changed Token expiration time for newly invited users reduced to 24 hours
- added Introduced unique identifiers for all Risks
August 8, 2024
- added New simplified User Invitation and Management process
- added Pending User Invitations expire after 7 days
- added Cancel or Resend any pending User invitation
July 25, 2024
- added User Deactivation functionality added in User Management
July 18, 2024
- added Introduced new Rich Text Editor (TipTap) to provide better user experience
- changed Permission system updated to better reflect governance workflow
- changed Documentation portal rebranded
July 8, 2024
- changed Allow Editor role to upload / edit Evidence
- changed Significant performance improvements