Nestack Agent Care
Industries / Automotive / Vehicle cyber agent

Automotive AI agent · Vehicle cyber

Vehicle Cybersecurity & Software-Update AI Agent

Assemble the CSMS, SUMS and supply-chain evidence each approval and declaration rests on, track the renewal and filing clocks, and hold the file for the officer who signs it under oath.

4–6 weeksTypical delivery
Your stackDeployment
Pre-declarationOfficer signs
Agent CareAfter launch

What this agent does

Assembles the file, not the signature on it

In
01

A component is sourced, and its SBOM, supplier answers and VCS position are pulled onto the model-year file.

02

A part number holds while the Wi-Fi module behind it changes, and the file is reopened, not left as filed.

Reason
03

A model year opens, and the declaration clock is set to sixty days before its first import or first sale.

04

An inaccuracy is discovered, and a sixty-day revised-declaration clock starts against the filing already made.

05

A CSMS certificate is issued, and renewal is scheduled from its date of deliverance, not from the audit.

Decide
06

An annual report falls due, and SOC and supplier incidents are gathered with the vulnerability record, not after.

07

An OTA campaign is staged, and the RXSWIN register is reconciled against it before release, not after.

Out
08

A file is assembled, and the evidence, the open gaps and the officer's amendments are held to the model year.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent assembles the file; a duly authorised designee signs the BIS Declaration of Conformity, certifying under 18 U.S.C. 1001.

Example workflow

One component, sourcing to signature

AgentHuman
1Component record receivedItem master, supplier declaration, SBOM export or engineering release
2Evidence assembledSBOMs, HBOMs, supplier answers and prior declarations, each with its named source
3Scope and evidence proposedIn-scope position, evidence gaps, clock dates and confidence
4Controls appliedCompleteness checks, model-year indexing, three-limb prompts and confidence threshold
No human action required

Stages 1 to 4 run unaided, and nothing is filed at any of them — the agent is assembling, and the officer's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the cybersecurity officer.

Low confidence

Adds a trade-counsel read first.

Officer approval

The file is held with its evidence, its open gaps and the confidence.

Approve · Amend · Send to counsel review
Approved — released to the signer
6Compliance systems updatedOnly where write access and approval policy allow it
7Outcome evaluatedAmendment rate, gap closure, authority queries and revised declarations
Amendments

Every officer amendment is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Signing or filing the Declaration of Conformity.
Certifying a supplier sits outside the three-limb test.
Declaring the CSMS or SUMS to an Approval Authority.
Deciding that a discovered change is not material.
Automation boundaryAgent acts unaided
Assemble the SBOM and HBOM evidence each field calls for for the named owner.
Carry each supplier answer with the question it answers.
Track the certificate, model-year and reporting clocks.
Flag the gaps the officer should weigh, and hold the file for them.
Any write happens inside the boundaries agreed at implementation, never ahead of the signature.
Reporting new cyber-attacks to the Approval Authority.
Releasing an OTA campaign to the fleet.
Deciding an RXSWIN change needs a new approval.
Changes to scope rules, clocks or filing boundaries.

Example output

One component, annotated

Everything the agent assembles is attached to the record it was drawn from.

Evidence output · single componentIllustrative example
Component
Description
Supplied
Proposed scope
Confidence
Supplier answer
Telematics modem
Cellular modem module, MY2027 telematics unit
4 May 2026
VCS hardware, in scope
91%
Ownership answered, only
As receivedTaken from the item master and the supplier's declaration — nothing on this side is inferred.
Evidence used Supplier declaration Hardware BOM entry Purchase-order record
Why this scopeIt is a modem above 450 MHz, so the software carve-outs do not reach it.
ActionApproveAmendSend to counsel review
What the score decidesBelow the configured threshold the file picks up a counsel read before the officer.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every componentFrom the item master
03Evidence

Assemble against your rules

Draw on the SBOMs and supplier answers on file, and the regulation text in force on the day.

01Approved path

Someone signs under oath

Routine components arrive with their evidence gathered and a scope position proposed.

02Human review

Send review to the exposed lines

Components with an unanswered limb and low-confidence positions are marked, so the officer's read starts where exposure concentrates.

04Build an evidence trail

The component, the supplier answer it rests on and the officer who declared stay on the file.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

PLM and item masterTeamcenter · PTC Windchill
SAP · Dassault ENOVIA
Software supply chainSBOM registries · CycloneDX
SPDX · artefact repositories
Cyber operationsVSOC · vulnerability tracking
Incident and CVE feeds

Agent

Vehicle cyber and SUMS

Reads the component
Assembles the file
Holds for signature

Approval and releaseType-approval records
OTA campaigns · RXSWIN
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the declaration

Six layers, the innermost nearest the model. What none of them holds is named in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modePull the agent back to evidence collection when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, scope-rule and clock-configuration changes.Track
L4TraceabilityRecord the source data, the file, the gaps, the amendments and the approval.Record
L3Officer approvalHold files for the named officer; it governs release, not whether a sworn declaration is true.Gate
L2Policy guardrailsTest files against the configured scope and evidence rules; a missing field returns the file.Restrict
L1Confidence thresholdsRoute low-confidence files to a counsel read before the officer sees them.Require review
Model coreEvidence assembled — scope position, gaps, clock dates and confidence
L1 – L2Test whether a file may stand
L3Puts the release in an officer's hands
L4 – L5Keep the component and the supplier answer behind it
L6Drops to evidence collection when signals degrade

How Nestack evaluates it

Evaluate the evidence workflow — not only the file at the end.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the file the officer signs
Depth of coverage ▼
E1Final-output evaluationDid the assembled evidence match what the field actually requires?
E2Step-level evaluationDid the agent use the right BOM, supplier answer and regulation version?
E3Tool evaluationDid it read and write the correct component and the correct field?
E4Confidence calibrationDo low-confidence files actually attract more officer amendments?
E5Slice evaluationHow does performance change across specific component groups?
E6Business outcomeHow many files needed an amendment, or a revised declaration after filing?
Floor — the exposure the signer answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, placed at the stage each one originates.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
ZT-03

EU calendar read as GB

A GB type planned against the EU's 7 July 2024 date.

Stage gathersItem master, SBOMs, supplier answers and clocks
02 · Reasoning2 modes
ZT-04

Exclusion misapplied

Software carve-out applied to a hardware item.

ZT-06

Ownership answer only

A three-limb test closed on a cap-table screen.

Stage proposesScope position, gaps, clock dates and confidence
03 · Tool / write2 modes
ZT-02

Clock read as a task

Discovery logged, and the sixty-day clock lapses.

ZT-05

Model-year carry-over

MY2028 imports run against an MY2027 filing.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
ZT-01

Unsupported assertion

A declaration field rests on an unverified supplier reply.

Stage returnsThe file the officer signs and BIS receives
05 · Change / Version1 mode
ZT-07

Silent scope regression

A rule or model change narrows what is flagged in scope.

Stage tracksModel, prompt, scope rules and clock config
Sev-1 · acts outside the filing boundary Sev-2 · a wrong field reaches the declaration Sev-3 · source degrades, file routes to review

Affected slices

One vehicle type can carry the exposure

A fleet-wide evidence-currency figure can look settled while a small number of vehicle types carry most of the unanswered supply chain. Nestack reports the amendment rate by slice, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Tier-2 substituted parts9.3%3.7× Review
Third-country suppliers6.4%2.6× Review
Model-year rollovers4.5%1.8× Watch
Single-source stock parts2.3%0.9× Normal
Bar: amendment-rate lift vs. single-source-part baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

Every cycle ends by adding a case

A cycle is closed when the unsupported declaration is a case the next release must survive. That suite is what the next file assembled is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Amendment rate rises in a component slice.

02Diagnose

The module whose firmware nobody upstream would put in writing is read back to a single cause.

03Improve

The change leaves with a version on it and the components that found it attached.

04Verify

While a touched declaration case is unresolved, the release does not open.

05Learn

It is held permanently, and the evidence rules shift with it.

Learn → DetectThe return edge. The next file is assembled against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence workflow, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Compliance workflow discovery and boundary definition.
02Item-master and supplier-portal assessment.
03Scope, evidence and reporting-clock rule mapping.
04Component-data ingestion and normalisation.
05Evidence assembly and source binding.
06Confidence scoring and gap routing.
07Cybersecurity officer approval.
08Compliance and PLM system integration.
09Evidence and audit cases.
10Guardrails and declaration controls.
11Component-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne vehicle type, one market ProductionProduction compliance systems AdvancedMultiple types / authorities
Introduced at Pilot
Assembly to your parts and rules
Officer approval
Evidence-currency baseline
Introduced at Production
Reporting by vehicle type
Approval workflow in your systems
Approved write-back
Supplier-portal integration
Introduced at Advanced
Multiple regimes and calendars
Multi-stage compliance approvals
High component volume
Multi-authority approval controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your item master and component BOMs Component-data ingestion and evidence mappingWeek 1
02Representative declarations already filed Evidence baseline and source bindingWeek 2
03Your scope rules and reporting clocks Scope, evidence and reporting-clock rule mappingWeek 1
04Access to relevant APIs, feeds or exports Item-master and supplier-portal assessment, then integration setupWeek 2
05Declarations you would not want sworn Supply-chain cases and failure-mode testingWeek 4
06What no declaration may assert Confidence scoring, gap routing, guardrails and declaration controlsWeek 3
07A named cybersecurity officer to approve Officer approval workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

Bands are set by the approval calendar, not by the plan, so week 5 carries two phases.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Compliance workflow discovery, rule mapping and the automation boundary W2Item-master integration and the evidence baseline W3Evidence workflow, confidence logic and approval controls W4Evaluation suite, scope and clock checks and failure-mode testing W5Supplier-portal integration, pilot components and targeted corrections W6One type approval assembled under the cybersecurity officer, then handover
Reading the bandEach band covers only the weeks its work is named in. The week 5 overlap is real, not padding.
At the end of W6Once the approval validates, Agent Care owns the running agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Automotive AI agent

Build a vehicle cyber and SUMS agent around your approval calendar.

There is no US analogue to R155 — but under §791.318 a wilful violation reaches criminal exposure for a natural person. Show us your file and the officer who would sign it.

Nestack Agents · Vehicle cyber & SUMSAGT-AUT-13 · Agent Care available after launch