On February 9, 2026 the U.S. Treasury, the Cyber Risk Institute, and more than 100 financial institutions published the Financial Services AI Risk Management Framework: 230 control objectives adapting the NIST AI RMF to banks, insurers, and investment firms. It is voluntary today, and built to become what examiners reference tomorrow.
We read the Risk and Control Matrix. Over half of its control objectives are satisfied not by having a policy, but by producing evidence — documentation, records, logs, artifacts expected to withstand audit and supervisory review. The framework is, in its own reviewers' words, an information governance engineering exercise.
Most of that evidence is ordinary. A versioned policy with approval signatures satisfies dozens of controls, and a document repository handles it. But a specific set of controls asks for something a repository cannot honestly give: evidence carrying provenance, verifiable timestamps, and data lineage. A repository can display a timestamp. It cannot prove it did not backdate one. That is the gap, and it is exactly the gap Rubric Custody closes.
The AI framework is new. The obligation is not. The CRI Profile — the financial sector's established control standard, mapped to the regulators above — already requires it: RS.AN-06, "actions performed during an investigation are recorded, and the records' integrity and provenance are preserved"; RS.AN-07.01, forensic data "preserved in a manner supporting integrity, provenance, and evidentiary value"; DE.CM-09.01, "integrity checking mechanisms to verify... information integrity and provenance." Custody satisfies the evidence dimension of each, and exceeds the checksums the last one names — because its integrity check does not depend on the institution's own systems staying honest.
The revised eIDAS regulation expands the EU's roster of recognised trust services beyond signatures, seals, and timestamps. Among the new categories is the electronic ledger: a trust service that records sequences of electronic data while ensuring their integrity and accurate chronological ordering. That is a legal description of what Rubric Custody does. Every record is hash-committed in sequence, its integrity checkable by any party, its chronological position fixed by public consensus rather than by the operator's clock.
Rubric is aligned with the electronic ledger trust service category. It is not a qualified trust service provider under eIDAS, and does not claim qualified status. What the framework establishes is that the property Custody delivers, tamper-evident chronological ordering verifiable by a third party, is now a recognised category of trust service across all 27 member states, with legal weight attaching to records that carry it. For EU deployers of AI systems, that is the difference between evidence that is technically sound and evidence a regulator has a legal vocabulary for.
See a record verify against a public ledger, in your browser, with no account and no trust in us.
Verify a record →