Applicable Regulations (6)
EU AI Act (Regulation (EU) 2024/1689)Horizontal, risk-based product-safety law for AI systems and GPAI models. Extraterritorial market-place principle. Staged applicability 2025–2030 (Digital Omnibus: Annex III → 2 Dec 2027, Annex I → 2 Aug 2028).
Sanctions: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
NIS2 Directive (Directive (EU) 2022/2555)Cyber-resilience duties for essential/important entities: supply-chain risk management, incident response, 24h early warning / 72h notification. AI components count as operational IT in scope.
Sanctions: Up to €10m or 2% of worldwide annual turnover
Cyber Resilience Act (Regulation (EU) 2024/2847)Security-by-design for products with digital elements over the full lifecycle: vulnerability management, patching, SBOM. Complements AI Act Art. 15 at product level.
Sanctions: Up to €15m or 2.5% of worldwide annual turnover
Data Act (Regulation (EU) 2023/2854)Access and re-use rights for (industrial) data, switching and interoperability duties — affects data sourcing for RAG pipelines and connected products.
Revised Product Liability Directive (Directive (EU) 2024/2853)Extends strict defect liability to standalone software and AI — including systems that continue learning post-deployment. Covers physical harm, property damage, psychological health impairment and non-professional data loss; disclosure duties and rebuttable defect presumption shift the burden of proof toward the injured party. Makes reconstructible decision evidence an economic necessity.
Sector Safety Regimes (EASA / ERA / NERC CIP)unverified · no verification date
Domain safety regulators whose regimes AI must complement, never replace: EASA (aviation), ERA (rail), NERC CIP (North American grid security). Predictive systems support — they do not substitute — mandated physical maintenance and protection duties.
Legal Obligations (12)
Art. 9 — Risk ManagementContinuous, iterative risk-management system across the whole lifecycle: identify, estimate, evaluate, mitigate; testing incl. against misuse.
Art. 10 — Data GovernanceQuality criteria for training/validation/test data: relevance, representativeness, error-freeness, bias detection & mitigation, data-governance procedures.
Art. 11 — Technical DocumentationAnnex IV technical file before placing on market: system description, architecture, capabilities/limitations, risk measures — kept up to date.
Art. 12 — Record-Keeping / LoggingAutomatic, tamper-evident event logging over the system lifetime, serving three regulatory objectives: risk identification (Art. 79), post-market monitoring (Art. 72) and deployer oversight (Art. 26(5)). Deployers retain logs ≥ 6 months; financial institutions fold them into statutory internal audit documentation. A bolted-on logging wrapper does not satisfy the requirement — logging must be core architecture.
Art. 13 — Transparency to DeployersInstructions for use: capabilities, limitations, intended purpose, human-oversight measures, expected accuracy.
Art. 14 — Human OversightEffective human oversight by qualified, trained natural persons with real authority to intervene, override and stop; interface duties (interpretability, automation-bias countermeasures); oversight must be commensurate with autonomy level. Competence and authority of the overseers is itself a testable control objective — training records and oversight protocols are its evidence.
Art. 15 — Accuracy, Robustness, CybersecurityAppropriate accuracy levels, resilience against errors and adversarial attacks (data poisoning, evasion, prompt injection), declared metrics.
Art. 17 — Quality Management SystemProduct-focused QMS for providers: strategy, design controls, data management, post-market monitoring — target of EN 18286:2026, the first AI Act harmonised-standard candidate to be published; presumption of conformity applies only once it is cited in the OJEU, which is still pending.
Art. 43 — Conformity AssessmentTwo pathways: internal control self-assessment (Annex VI) for most Annex III systems (HR, credit, education) — provider verifies QMS (Art. 17), technical file (Annex IV) and design consistency; notified-body assessment (Annex VII) mandatory for safety components in harmonised products (medical devices, aviation, rail) and remote biometric identification. Harmonised standards in the OJEU give presumption of conformity.
Art. 72/73 — Post-Market Monitoring & IncidentsPost-market monitoring plan and serious-incident reporting (15 days; 2 days for widespread infringement) to market-surveillance authorities.
Art. 26 — Deployer ObligationsUse per instructions, assign competent human oversight, input-data control, log retention ≥ 6 months, inform workers, incident duty.
Art. 47/48 — CE Marking & Declaration of ConformityAfter passing conformity assessment: written EU Declaration of Conformity (retained 10 years) and visible, indelible CE marking — for digital systems a digital CE mark accessible via UI or machine-readable code; notified-body number displayed where one was involved.
Standards & Evidence
ISO/IEC 23894 (AI Risk Management)AI risk-management guidance extending ISO 31000 — feeds the Art. 9 risk-management system.
evidence for: Art. 9
NIST AI RMF 1.0Govern–Map–Measure–Manage risk framework; Map/Measure functions populate the Art. 9 risk register with quantified values; the transatlantic mapping reference.
unverified · no verification date
evidence for: Art. 9
JTC 21 Technical Package (prEN 18228/18229/18281–83)CEN-CENELEC JTC 21 technical package under standardisation request M/593 (prEN 18228 trustworthiness, 18229 risk management, 18281–83 CV/NLP evaluation et al.); staged drafts, none OJEU-cited yet — Annex III applicability (Dec 2027) is Omnibus-coupled to their availability.
draft · verified 2026-08-04
evidence for: Art. 9 · Art. 10
FAIR-AIR / FAIR-MAMAI extension of Factor Analysis of Information Risk: Expected Financial Loss = Loss Event Frequency (threat frequency × vulnerability) × Loss Magnitude (primary + secondary), run as Monte Carlo distributions — the standard bridge from technical AI failure modes to board-level monetary exposure.
unverified · no verification date
evidence for: Art. 9
NIST AI 600-1 (GenAI Profile)Companion profile to the AI RMF covering twelve GenAI-specific failure modes — confabulation, prompt injection, value-chain propagation and others — as the technical checklist behind Map/Measure for generative systems.
unverified · no verification date
evidence for: Art. 9 · Art. 15
Gartner AI TRiSMAI Trust, Risk and Security Management — industry framework formalizing continuous AI oversight across four pillars: governance (inventory, AI-BOM, decision rights, change approval), trustworthiness & fairness (explainability, bias), reliability (drift, hallucination metrics), security management (prompt injection, model inversion, poisoning, leakage). No legal force; its value is the architecture it implies — the four-layer enterprise stack and the first/second-line separation this graph models as bp-trism and pat-lines-defense.
published · verified 2026-08-06
evidence for: Art. 9
ISO/IEC 5259 (Data Quality for ML)Five-part data-quality framework (governance, process, management) — direct evidence path for Art. 10 representativeness and completeness.
evidence for: Art. 10
EN ISO/IEC 22989 (AI Concepts)Published terminology and concepts standard — the shared vocabulary layer for documentation and audits.
evidence for: Art. 11
FprEN ISO/IEC 24970 (AI Logging)Specifies event logging in AI systems — the concrete implementation target for Art. 12 record-keeping.
evidence for: Art. 12
TAGOF (Audit-as-Code)Operationalizes governance as code in CI/CD: policy-as-code enforcement, continuous runtime telemetry and automatically generated audit evidence — the execution layer that replaces periodic audits with continuous assurance.
unverified · no verification date
evidence for: Art. 12
prEN ISO/IEC 12792 (Transparency Taxonomy)Transparency taxonomy for AI systems: structured disclosure of system composition, data provenance, capabilities and limitations. The harmonised-norm candidate backing Art. 13 instructions-for-use and deployer-information duties — defines what a complete transparency package must contain.
evidence for: Art. 13
OWASP Agentic Security (AST10 / Core Risks)Threat framework for autonomous agents: tool misuse, excessive agency, confused-deputy, memory poisoning — with AIVSS scoring.
unverified · no verification date
evidence for: Art. 14
IMDA Agentic AI Governance Framework (SG)Model AI Governance Framework for Agentic AI (Jan 2026, updated Jun 2026) — first state-issued agentic-specific guidance: bounded autonomy levels, action-space and interface restrictions, human-in-command checkpoints, automation-bias controls, logging & attribution expectations. No legal force in the EU, but the most concrete public benchmark for Art. 14-style oversight design of agent systems.
published · verified 2026-08-04
evidence for: Art. 14
DIN SPEC 92001-1/-2/-3AI life-cycle quality metamodel: functionality, robustness (adversarial & corruption), traceability/explainability — German operationalisation for Art. 15.
unverified · no verification date
evidence for: Art. 15
ISO/IEC 24029 (NN Robustness)Robustness assessment of neural networks incl. formal methods (part 2) — supports Art. 15 evidence.
evidence for: Art. 15
OWASP Top 10 for LLM Apps (2025)The de-facto technical security standard for GenAI applications; maps to Art. 10/14/15 and ISO 42001 Annex A controls.
unverified · no verification date
evidence for: Art. 15
ENISA Multilayer Framework & AI Threat LandscapeThree-layer good-practice model (cyber foundations → AI-specific → sectoral) and lifecycle threat landscape — the operational base for Art. 15 and CRA.
unverified · no verification date
evidence for: Art. 15 · Cyber Resilience Act
BSI C5:2026Cloud compliance catalogue (168 requirements): post-quantum crypto, confidential computing, container security — infrastructure evidence layer for NIS2/CRA/Art. 15; binding baseline from June 2027.
unverified · no verification date
evidence for: Art. 15 · NIS2 Directive
ISO/IEC TS 4213 (ML Performance Measurement)Assessment of machine-learning classification performance: standardized metrics, test-set discipline, reporting format. The metric backbone for Art. 15 'declared accuracy' — test reports that cite it are comparable across vendors and audits.
evidence for: Art. 15
BSI GenAI Criteria CatalogueCriteria for integrating external generative models via API: named AI owner, central AI register, case-by-case risk analysis, multi-stage input/output validation, least privilege, prompt/permission separation.
unverified · no verification date
evidence for: Art. 15
EN 18286:2026 (QMS for AI Act)Harmonised-norm candidate translating Art. 17 QMS into a product-focused governance framework; mappings to ISO 9001 and ISO/IEC 42001 Annex A (Annexes C & D); published as EN 18286:2026 in July 2026, OJEU citation (and with it the presumption of conformity) still pending.
published · verified 2026-08-04
evidence for: Art. 17
ISO/IEC 42001:2023 (AIMS)ISO/IEC 42001:2023 — certifiable AI management system (Annex SL harmonized structure, PDCA logic, synergy discount when an ISO 27001 ISMS exists). Clauses 4–10 plus Annex A controls (control count 38 vs 39 is a live community dispute — counting method differs by edition/guide). Covers an estimated 40–50% of AI Act organizational duties; organizational certificate, no product presumption of conformity.
evidence for: Art. 17
ISO/IEC 42006 (Audit Bodies)Requirements for bodies auditing/certifying AIMS — accreditation basis (e.g. DAkkS) for ISO 42001 certificates.
evidence for: Art. 43
IEEE CertifAIEd™Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
unverified · no verification date
evidence for: EU AI Act
NIST SP 800-218 (SSDF)Secure Software Development Framework: practices for provenance, review and vulnerability handling of generated and third-party code; SSDF-AI companion covers AI-assisted development.
unverified · no verification date
evidence for: Cyber Resilience Act
ISO/IEC 27001:2022 + A.8.28Information-security management; control A.8.28 (secure coding) is the natural anchor for AI code-generation and QA workflows alongside ISO 42001.
evidence for: Cyber Resilience Act