Regulation coverage Every regulation in the graph resolves into concrete technical components — through an article obligation, a control objective, a design pattern or an evidence artefact that a component must produce. Pick a regulation to see its technical surface, how each component is derived, and in which of the triggering use cases it is actually part of the required stack. The gap counts show where the graph reaches a component that no use case yet requires — those are open contribution targets, not settled answers. Open the full graph →
Regulations (38) EU AI Act 28 comp · 34 UC · 28 gaps AML Package (AMLR/AMLA) 23 comp · 3 UC · 15 gaps USA PATRIOT Act §326 (CIP) 23 comp · 2 UC · 14 gaps National Tax Codes & OECD BEPS / Pillar Two 16 comp · 1 UC SEC Predictive Data Analytics Rules (withdrawn 2025) 16 comp · 1 UC SEC Regulation Best Interest 16 comp · 1 UC Colorado AI Act 15 comp · 3 UC · 8 gaps ECOA / CFPB Adverse-Action Regime 15 comp · 1 UC EHDS 14 comp · 4 UC · 14 gaps MDR / IVDR 14 comp · 3 UC · 14 gaps Data Act 14 comp · 2 UC · 14 gaps FTC Act §5 & Endorsement / AI-Claims Guidance 13 comp · 3 UC · 8 gaps ePrivacy Directive 12 comp · 3 UC · 7 gaps Data Governance Act 7 comp · 1 UC NYC Local Law 144 (AEDT) 7 comp · 1 UC GDPR 6 comp · 24 UC · 6 gaps DORA 6 comp · 9 UC · 6 gaps NIS2 Directive 5 comp · 4 UC · 5 gaps Digital Services Act 5 comp · 2 UC General Product Safety Regulation 4 comp · 1 UC Machinery Regulation 4 comp · 1 UC Sector Safety Regimes (EASA / ERA / NERC CIP) 4 comp · 1 UC New York RAISE Act 4 comp · 0 UC HIPAA (US Health Privacy) 3 comp · 4 UC · 3 gaps eIDAS 2 (EUDI / Trust Services) 3 comp · 0 UC Cyber Resilience Act 2 comp · 6 UC · 2 gaps Revised Product Liability Directive 2 comp · 6 UC · 2 gaps AI Liability Directive (withdrawn) 2 comp · 3 UC · 1 gaps Sarbanes-Oxley Act (SOX §302 / §404) 2 comp · 3 UC SEC Advisers Act Rule 204-2 (Books & Records) 2 comp · 2 UC Bank Secrecy Act / FinCEN Program Rules 2 comp · 1 UC SEC Rule 17a-4 (US Records Retention) 1 comp · 4 UC Unfair Commercial Practices Directive 1 comp · 4 UC · 1 gaps FINRA Rule 4511 (General Books & Records) 1 comp · 3 UC CSDDD (Corporate Sustainability Due Diligence) 1 comp · 2 UC · 1 gaps CFAA & Anti-Scraping Regimes 1 comp · 1 UC TCPA / FCC AI-Voice Rules (US) 1 comp · 1 UC EEOC / Title VII Algorithmic Fairness (US) 1 comp · 0 UC Machinery Regulation source ↗ EUR-Lex Safety requirements for machinery incl. AI-driven safety functions; Annex I gateway into AI Act high-risk for embedded systems.
4 components0 articles / obligations1 triggering use casesopen in graph Kill Switch / Graceful Degradation 100% of use cases Operator stop controls and degraded-mode fallbacks; real-time override (veto) channels for HOTL operation.
practice-derived 1 triggering use case require Kill Switch / Graceful Degradation SBOM & Dependency Management 100% of use cases Software bill of materials incl. model weights and datasets; automated vulnerability patching pipeline.
practice-derived 1 triggering use case require SBOM & Dependency Management Secure Boot & Hardened Runtime 100% of use cases Verified boot chain and hardened runtimes for edge/IoT deployments per CRA security-by-design.
practice-derived 1 triggering use case require Secure Boot & Hardened Runtime Unified Incident-Response Runbook 100% of use cases One procedure reconciling AI Act Art. 73, GDPR Art. 33 (72h), DORA and NIS2 (24h/72h) timelines and recipients.
practice-derived 1 triggering use case require Unified Incident-Response Runbook