Open Source SDK
MITThe runtime primitives. Self-hosted, no account required.
- guard(), loop(), budget(), side_effect(), requestOversight()
- Append-only JSONL evidence stream — Art. 12 event recording
- HMAC-SHA256 hash chain in the Python SDK; TypeScript parity on the roadmap
- Token usage extraction across OpenAI, Anthropic, Mistral, Vercel AI SDK, Mastra, LangChain
- Python framework adapters for LangGraph and CrewAI
- Zero outbound network by default — emits wherever you configure
Control Starter
most teams pick thisThe managed compliance backbone. Hosted in Frankfurt.
- Hosted compliance posture dashboard for the Control backbone
- Annex IV bundle generator — @fuze-ai/agent-annex-iv
- FRIA drafts from evidence span attributes — @fuze-ai/agent-fria
- Article 73 incident report builder — @fuze-ai/agent-incident
- Deployer monitoring surface (Art. 26): runs, agent health, retention, admin audit log
- EU data residency — Frankfurt region
- Evidence remains independently verifiable with the open-source verifier
Control Enterprise
customFor teams that need on-prem, sovereign providers, or a negotiated DPA.
- On-prem deployment via @fuze-ai/agent-sovereign-terraform
- Sovereign provider adapters: Mistral, Scaleway, OVHcloud — @fuze-ai/agent-providers
- Custom Article hooks and policy adapters (Cerbos integration available)
- KMS-backed Ed25519 signing — @fuze-ai/agent-signing-kms
- Procurement and DPA white-glove — negotiated Master Services Agreement
- Direct contact during the August 2026 enforcement window
What’s included
What you get at each level.
Grouped by where each capability lives — in the open-source SDK, added by the managed Control backbone, or only available on Enterprise terms. No checkmark matrix; if it’s not in the paragraph below, it isn’t shipping.
In every tier
The open-source primitives
Adds with Control
Hosted backbone and compliance packages
Adds with Enterprise
Sovereign deployment and procurement support
What Fuze does and does not do
Who is responsible for what.
Fuze provides tooling and evidence. We are not a regulator, an auditor, or a notified body. Using Fuze does not by itself make any AI system compliant with the EU AI Act, GDPR, or any other regulation. Under Art. 25(4) we are a component supplier.
Under the EU AI Act, the deployer (and the provider, if you place a system on the market) holds the regulatory obligations. Under the GDPR, the controller determines purposes and means of processing. In all of these roles, you are responsible for your compliance posture. Fuze produces the evidence and workflows that help you meet it.
The Services are provided “as is” without warranty. Aggregate liability is capped at fees paid in the preceding twelve months, which for free-tier users is zero. See Terms of Service §10–§12 and the deployer-vs-provider guide.
Nothing on this page or in the Services constitutes legal advice. Engage qualified EU counsel for advice on your specific compliance obligations.
FAQ
Questions teams ask before signing up.
Is the SDK actually free, or is this a trial?
Genuinely free. The fuze-ai SDK and the surrounding @fuze-ai/* packages are MIT-licensed. Read the source, fork it, run it locally, emit evidence to your own store. No account, no time limit, no feature lockouts. The managed Control tiers are a separate product on top.
When will the Control tiers have firm pricing?
They’re in private beta and pricing isn’t finalised yet. We’ll publish numbers when we’re confident the envelope reflects how teams actually use the backbone. If you need indicative figures for procurement now, email us.
Does using Fuze make my AI system EU AI Act compliant?
No. Fuze provides tooling and evidence. The deployer (and provider, if you place a system on the market) is responsible for compliance. Fuze produces signed, hash-chained evidence that your obligations are being met, but the obligations remain yours. See Terms of Service §10 and the deployer-vs-provider guide.
Where does the data live?
The open-source SDK runs in your infrastructure — evidence emits wherever you configure, and no data leaves your environment by default. The managed Control backbone is hosted in Frankfurt. Enterprise customers can run the backbone on-prem via @fuze-ai/agent-sovereign-terraform or route inference through sovereign providers (Mistral, Scaleway, OVHcloud).
Can I take my evidence with me?
Yes. Evidence is hash-chained and Ed25519-signed, and the audit log format is a published spec. If you stop using the managed Control backbone, the evidence you generated remains independently verifiable with the open-source verifier.
We have a Master Services Agreement template. Will you sign it?
Probably yes — that’s the Enterprise tier. We handle DPA, MSA, and procurement directly. Email hello@fuze-ai.tech with the template and we’ll come back.
Next
Start with the classifier or talk to compliance.
If you’re not sure whether the Act applies to your agent, start with the risk classifier. If you already know it does and you want the managed backbone, reach out.