Bidda Compliance Intelligence SDK — full MCP parity, LangChain, AutoGen, CrewAI
Project description
bidda-shield
Verified compliance intelligence for AI agents. Stop your LangChain, AutoGen, and CrewAI agents from hallucinating legal requirements.
pip install bidda-shield
The problem
AI agents making decisions about hiring, credit scoring, data processing, or content moderation are operating under dozens of overlapping regulations — GDPR, EU AI Act, HIPAA, CCPA, Basel III. When an agent gets the legal logic wrong, it isn't just a bug. It's a regulatory liability event.
LLMs hallucinate regulations. bidda-shield doesn't.
Every compliance node in the Bidda registry traces to a specific clause of a primary legal instrument, verified against the source URL, and drift-checked weekly. No inference. No approximation.
Quickstart
from bidda_shield import BiddaShield
shield = BiddaShield()
# Find the compliance node most relevant to your agent's action
result = shield.check_compliance("process biometric data for access control")
print(result["title"]) # EU AI Act Article 5 — Prohibited AI Practices
print(result["bluf"]) # Plain-English summary of the legal obligation
LangChain
from langchain.agents import initialize_agent, AgentType
from langchain_openai import ChatOpenAI
from bidda_shield import BiddaLangChainTool
llm = ChatOpenAI(model="gpt-4o")
tool = BiddaLangChainTool()
agent = initialize_agent(
tools=[tool],
llm=llm,
agent=AgentType.ZERO_SHOT_REACT_DESCRIPTION,
verbose=True,
)
agent.run(
"My agent is about to make an automated credit decision. "
"What regulations apply and what do they require?"
)
The tool returns the regulation title, domain, plain-English summary (BLUF), and a link to the full verified node — for $0.01 USDC per full unlock.
AutoGen
import autogen
from bidda_shield import BiddaAutoGenTool
config_list = [{"model": "gpt-4o", "api_key": "YOUR_OPENAI_KEY"}]
bidda_tool = BiddaAutoGenTool()
assistant = autogen.AssistantAgent(
name="compliance_assistant",
llm_config={
"config_list": config_list,
"functions": [bidda_tool.function_schema],
},
)
user_proxy = autogen.UserProxyAgent(
name="user",
human_input_mode="NEVER",
function_map={"bidda_compliance_lookup": bidda_tool.execute},
)
user_proxy.initiate_chat(
assistant,
message="What does GDPR Article 22 require for automated decision-making?",
)
CrewAI
from crewai import Agent, Task, Crew
from bidda_shield import BiddaCrewAITool
compliance_tool = BiddaCrewAITool()
compliance_officer = Agent(
role="Chief Compliance Officer",
goal="Ensure all AI agent actions comply with applicable regulations",
backstory="Expert in GDPR, EU AI Act, HIPAA, and global data protection law.",
tools=[compliance_tool],
verbose=True,
)
task = Task(
description="Review the agent action 'train a model on employee performance data' and identify all applicable regulations.",
agent=compliance_officer,
)
crew = Crew(agents=[compliance_officer], tasks=[task])
crew.kickoff()
Direct API usage
from bidda_shield import BiddaShield
shield = BiddaShield()
# Search by keyword
nodes = shield.search_nodes("automated decision making")
for n in nodes:
print(n["node_id"], "—", n["title"])
# Get a specific node (free discovery tier)
node = shield.get_node("gdpr-article-22-automated-decisions")
print(node["bluf"])
# Get full vault data (requires Skyfire JWT or USDC payment — $0.01)
shield_paid = BiddaShield(skyfire_token="YOUR_SKYFIRE_JWT")
full_node = shield_paid.get_node("gdpr-article-22-automated-decisions", vault=True)
print(full_node["deterministic_workflow"]) # Step-by-step legal compliance logic
Full method reference (v0.2.0 — MCP parity)
Every tool exposed by the bidda.com/mcp MCP server is available as a Python
method. Results match what an MCP client would see for the same input — the
SDK mirrors the same logic, just returning structured dict / list data
instead of LLM-formatted markdown.
from bidda_shield import BiddaShield
shield = BiddaShield()
# 1. Browse the registry
shield.list_pillars() # → ["AI Governance & Law", ...]
shield.search_nodes("biometric", pillar="ai-gov") # → [{"node_id", "title", ...}, ...]
shield.get_node("gdpr-article-22-automated-decisions") # discovery (free)
shield.get_node("gdpr-article-22-automated-decisions", vault=True) # full ($0.01)
# 2. Walk prerequisites — what does this rule depend on?
shield.get_dependency_chain("eu-ai-act-article-10-data-governance-training", max_depth=2)
# → {"root": "...", "title": "...", "chain": [{"depth": 0, ...}, ...], "total": 8}
# 3. Cross-framework mappings — GDPR Art 17 → CCPA right-to-delete → POPIA Sec 24
shield.get_crosswalk("gdpr-article-17-right-to-erasure")
# → {"node_id", "title", "dimensions": ["ccpa_equivalent", ...], "vault_url"}
# 4. Regulatory change feed — what moved recently
shield.get_latest_changes(days=30, pillar="Cybersecurity")
# → [{"node_id", "title", "domain", "last_updated"}, ...] (newest first, max 20)
# 5. Jurisdiction-wide rule bundle — everything that applies in a market
shield.get_jurisdiction_bundle("eu", limit=25)
# → {"jurisdiction", "total_matches", "by_pillar": {...}, "nodes": [...]}
# 6. MITRE technique → compliance mapping
shield.get_mitre_mapping("T1566") # ATT&CK Enterprise (phishing)
shield.get_mitre_mapping("AML.T0020") # ATLAS (AI-specific)
shield.get_mitre_mapping("D3-FIM") # D3FEND defensive
shield.get_mitre_mapping("CAPEC-66") # CAPEC attack pattern
# → [{"node_id", "title", "bluf", "dependencies", "crosswalk_dimensions", "vault_url"}, ...]
# 7. Pre-flight compliance check — primary agent runtime tool
result = shield.check_action_compliance(
"process EU resident biometric data for access control",
jurisdiction="eu",
limit=10,
)
# → {
# "action": "...",
# "keywords": ["process", "biometric", "data", "access", "control"],
# "risk_level": "HIGH", # LOW | MODERATE | HIGH
# "match_count": 10,
# "matches": [
# {"node_id", "title", "domain", "bluf", "matched_terms": [...], "score": 4},
# ...
# ]
# }
if result["risk_level"] == "HIGH":
# Halt the agent action, surface the matched regulations to a human.
raise RuntimeError(f"Compliance gate failed: {result['match_count']} matches")
The discovery index is cached client-side for 5 minutes after the first
call, so chained calls (e.g. check_action_compliance followed by
get_dependency_chain on the top match) reuse the same fetch.
What's in a full node
Each vault-tier node contains:
- BLUF — plain-English summary of the legal obligation
- deterministic_workflow — step-by-step compliance checklist derived from the primary legal text
- actionable_schema — machine-readable compliance checkpoints
- primary_citations — exact section references to the legal instrument
- crosswalks — mappings to NIST, ISO, and peer standards
- dependencies — other regulations this one depends on or triggers
- verification — source URL, jurisdiction, instrument type, integrity hash
All content traces to a real primary legal source. No secondary commentary. No paraphrasing.
Payment
- Discovery tier (free): node ID, title, domain, plain-English summary
- Vault tier ($0.01 USDC per node): full deterministic logic, citations, crosswalks, workflow
Pay with:
- Skyfire — pass a
skyfire-pay-idbearer token (agent-native, no wallet required) - L402 / Base USDC — send $0.01 to the Bidda Base wallet, pass the tx hash
# With Skyfire
shield = BiddaShield(skyfire_token=os.getenv("BIDDA_SKYFIRE_TOKEN"))
# With Base tx hash
shield = BiddaShield(base_tx_hash="0xYOUR_TRANSACTION_HASH")
Install options
# Core (no framework dependencies)
pip install bidda-shield
# With LangChain
pip install "bidda-shield[langchain]"
# With AutoGen
pip install "bidda-shield[autogen]"
# With CrewAI
pip install "bidda-shield[crewai]"
# Everything
pip install "bidda-shield[all]"
Registry coverage
- 4,600+ verified nodes across 31 regulatory pillars
- Pillars: AI Governance, Cybersecurity, Banking & Finance, Healthcare, Legal & IP, ESG, Workplace, Aviation & Defense, Crypto, Cloud, and 21 more
- Jurisdictions: EU, US, UK, Germany, Australia, Singapore, South Africa, and global instruments
- Sources: EU AI Act, GDPR, NIST CSF, ISO 27001, Basel III/IV, HIPAA, DORA, NIS2, FATF, and 150+ authority bodies
Full registry: bidda.com/intelligence
Links
- Registry: bidda.com
- API docs: bidda.com/developers
- MCP server:
https://bidda.com/mcp(Claude.ai, Claude Desktop, any MCP client) - Source: git.bidda.com/Bidda-Ai/bidda-shield
- Support: api@bidda.com
License
MIT — use freely, attribution appreciated.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file bidda_shield-0.2.0.tar.gz.
File metadata
- Download URL: bidda_shield-0.2.0.tar.gz
- Upload date:
- Size: 15.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.10
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8d9618bae1aae7bb3971116c943ca7e95e7df15bee68ceddaa7f2dc817f75c8d
|
|
| MD5 |
11e7dd4562de97dc4d6a35bb386d2e5d
|
|
| BLAKE2b-256 |
c6cd3144c78639bcfb17c078bfc7945d9a812467a57e9c2d45de606c3f8bda3f
|
File details
Details for the file bidda_shield-0.2.0-py3-none-any.whl.
File metadata
- Download URL: bidda_shield-0.2.0-py3-none-any.whl
- Upload date:
- Size: 15.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.10
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
752486d39c2ef47e907c67643fca3bbdf426ca17aa021fcad4668ad9cd7ab936
|
|
| MD5 |
9493a088420713afdbeac30c3ca2d5f3
|
|
| BLAKE2b-256 |
d3343e938c18abdb8464355090dc9372b4193a2baf9b25d3c18c89e05a33974b
|