Sources & Verification
Every claim in this tool resolves to one of the source layers below, and every legal or standards node carries — or visibly lacks — a verification date. Nothing here is backdated to look authoritative. If a node has no verification date, the badge on it says so.
Source layers
The regulation and standards backbone: which legal acts exist, which bodies issue them, and how the AI Act interlocks with the wider digital acquis.
The architectural translation: how an obligation becomes a concrete design decision rather than a policy document.
The agentic layer: autonomy degrees, the four-mode oversight taxonomy and the regulatory design constraints specific to agents.
The two-dimensional compliance map, the sector use-case catalogues and the seven-layer reference architecture the profiles are derived from.
The US state-law patchwork, the Art. 6(3) filter, cryptographic logging and the production oversight patterns (Trinity Defense, Guardian Agents, HITL).
The Service-as-a-Software operating model: the four-stage compliant pipeline, the ISO 42001 control loop, the mandatory artifact set and the rollout roadmap.
Community input on outcome-based scaling of autonomous agentic workflows in regulated enterprise ecosystems.
How we verify
Principle: Every legal act and standard in this graph is a moving target. A node without a lastVerified date is a claim, not a fact.
Process: Quarterly deepsearch sweep over all nodes with status fields + event-driven re-verification whenever (a) a community dispute is opened on a node, (b) a monitored feed reports a change touching a node's source, or (c) a release is prepared. Each sweep bumps lastVerified even when nothing changed — absence of change is also a finding.
When something changes: When a node's status changes (e.g. prEN → EN published, or an article amended by an Omnibus), all edges incident to that node are flagged 'review-pending' for the next curator pass; profile derivations show a currency warning until cleared.
Monitored feeds
Re-verification is driven by these feeds plus any community dispute opened on a node.
- Official Journal of the EU (OJEU) — harmonised-standard citations & amending acts
- European Parliament Legislative Observatory — Omnibus & EHDS procedure files (the AILD file is closed: the proposal was withdrawn in the Commission's 2025 work programme; watched only for a successor)
- CEN-CENELEC JTC 21 work programme & standards trackers
- EU AI Office guidance, delegated & implementing acts
- National layer: BSI publications, DAkkS accreditations, TÜV AI.Lab assessments
Currency coverage — the honest number
The remaining claims are published as unverified rather than given an invented date. That is a deliberate choice: an unverified badge is information, a fabricated date is not. See the per-node worklist → The graph in numbers →
Auditing a single claim
Open any entry in the graph explorer to see its status, verification date, status note and every edge that derives from it. Disagree with it? Dispute it from its detail panel — a dispute triggers re-verification and is recorded in the changelog. Curators run the deep-search sweep that keeps these dates moving.
References
Every legal instrument and standard the graph relies on, listed in full and generated from the graph itself — so this chapter cannot drift from what the tool actually reasons over. Articles are nested under their parent act. 57 of 89 entries resolve to a primary public source; the rest carry no link because no authoritative URL pattern applies, not because none was looked for.
European Union
- AILD — COM(2022) 496, withdrawn
- AML Package (AMLR/AMLA)
- European Health Data Space Regulation
- Art. 4 — AI Literacy · unverified · artificialintelligenceact.eu
- Art. 5 — Prohibited Practices · unverified · artificialintelligenceact.eu
- Art. 6(3) — High-Risk Exemption Filter · unverified · artificialintelligenceact.eu
- Art. 9 — Risk Management · unverified · artificialintelligenceact.eu
- Art. 10 — Data Governance · unverified · artificialintelligenceact.eu
- Art. 11 — Technical Documentation · unverified · artificialintelligenceact.eu
- Art. 12 — Record-Keeping / Logging · unverified · artificialintelligenceact.eu
- Art. 13 — Transparency to Deployers · unverified · artificialintelligenceact.eu
- Art. 14 — Human Oversight · unverified · artificialintelligenceact.eu
- Art. 15 — Accuracy, Robustness, Cybersecurity · unverified · artificialintelligenceact.eu
- Art. 17 — Quality Management System · unverified · artificialintelligenceact.eu
- Art. 25 — Value Chain / Role Flip · unverified · artificialintelligenceact.eu
- Art. 26 — Deployer Obligations · unverified · artificialintelligenceact.eu
- Art. 43 — Conformity Assessment · unverified · artificialintelligenceact.eu
- Art. 47/48 — CE Marking & Declaration of Conformity · unverified · artificialintelligenceact.eu
- Art. 50 — Transparency Duties · unverified · artificialintelligenceact.eu
- Art. 72/73 — Post-Market Monitoring & Incidents · unverified · artificialintelligenceact.eu
- GDPR Art. 17 — Erasure · unverified · EUR-Lex
- GDPR Art. 22 — Automated Decisions · unverified · EUR-Lex
- GDPR Art. 25 — Data Protection by Design · unverified · EUR-Lex
- GDPR Art. 35 — DPIA · unverified · EUR-Lex
United States
- Colorado SB 24-205
- ECOA / CFPB Adverse-Action Regime
- FINRA Rule 4511
- FTC Act §5 & Endorsement / AI-Claims Guidance
- HIPAA (US Health Privacy)
- New York RAISE Act
- NYC Local Law 144 (AEDT)
- SEC Predictive Data Analytics Rules (withdrawn 2025)
- Sector Safety Regimes (EASA / ERA / NERC CIP)
National & international
- National Tax Codes & OECD BEPS / Pillar Two
Standards & frameworks
AI risk-management guidance extending ISO 31000 — feeds the Art. 9 risk-management system.
Robustness assessment of neural networks incl. formal methods (part 2) — supports Art. 15 evidence.
Information-security management; control A.8.28 (secure coding) is the natural anchor for AI code-generation and QA workflows alongside ISO 42001.
ISO/IEC 42001:2023 — certifiable AI management system (Annex SL harmonized structure, PDCA logic, synergy discount when an ISO 27001 ISMS exists). Clauses 4–10 plus Annex A controls (control count 38 vs 39 is a live community dispute — counting method differs by edition/guide). Covers an estimated 40–50% of AI Act organizational duties; organizational certificate, no product presumption of conformity.
Guidance for AI system impact assessments — supports DPIA/FRIA-style analyses.
Requirements for bodies auditing/certifying AIMS — accreditation basis (e.g. DAkkS) for ISO 42001 certificates.
Five-part data-quality framework (governance, process, management) — direct evidence path for Art. 10 representativeness and completeness.
Assessment of machine-learning classification performance: standardized metrics, test-set discipline, reporting format. The metric backbone for Art. 15 'declared accuracy' — test reports that cite it are comparable across vendors and audits.
- EN 18286:2026 (QMS for AI Act)
Harmonised-norm candidate translating Art. 17 QMS into a product-focused governance framework; mappings to ISO 9001 and ISO/IEC 42001 Annex A (Annexes C & D); published as EN 18286:2026 in July 2026, OJEU citation (and with it the presumption of conformity) still pending.
Published terminology and concepts standard — the shared vocabulary layer for documentation and audits.
Specifies event logging in AI systems — the concrete implementation target for Art. 12 record-keeping.
- JTC 21 Technical Package (prEN 18228/18229/18281–83)
CEN-CENELEC JTC 21 technical package under standardisation request M/593 (prEN 18228 trustworthiness, 18229 risk management, 18281–83 CV/NLP evaluation et al.); staged drafts, none OJEU-cited yet — Annex III applicability (Dec 2027) is Omnibus-coupled to their availability.
Transparency taxonomy for AI systems: structured disclosure of system composition, data provenance, capabilities and limitations. The harmonised-norm candidate backing Art. 13 instructions-for-use and deployer-information duties — defines what a complete transparency package must contain.
- DIN SPEC 92001-1/-2/-3
AI life-cycle quality metamodel: functionality, robustness (adversarial & corruption), traceability/explainability — German operationalisation for Art. 15.
- BSI AIC4
AI Cloud Service Compliance Criteria Catalogue: security & robustness, performance, reliability, data management, explainability, bias — audited via ISAE 3000; vendor trust evidence.
- BSI C5:2026
Cloud compliance catalogue (168 requirements): post-quantum crypto, confidential computing, container security — infrastructure evidence layer for NIS2/CRA/Art. 15; binding baseline from June 2027.
- BSI GenAI Criteria Catalogue
Criteria for integrating external generative models via API: named AI owner, central AI register, case-by-case risk analysis, multi-stage input/output validation, least privilege, prompt/permission separation.
- NIST SP 800-218 (SSDF)
Secure Software Development Framework: practices for provenance, review and vulnerability handling of generated and third-party code; SSDF-AI companion covers AI-assisted development.
- OWASP Agentic Security (AST10 / Core Risks)
Threat framework for autonomous agents: tool misuse, excessive agency, confused-deputy, memory poisoning — with AIVSS scoring.
- OWASP Top 10 for LLM Apps (2025)
The de-facto technical security standard for GenAI applications; maps to Art. 10/14/15 and ISO 42001 Annex A controls.
- ENISA Multilayer Framework & AI Threat Landscape
Three-layer good-practice model (cyber foundations → AI-specific → sectoral) and lifecycle threat landscape — the operational base for Art. 15 and CRA.
- IEEE CertifAIEd™
Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
- C2PA Content Credentials
Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.
- FAIR-AIR / FAIR-MAM
AI extension of Factor Analysis of Information Risk: Expected Financial Loss = Loss Event Frequency (threat frequency × vulnerability) × Loss Magnitude (primary + secondary), run as Monte Carlo distributions — the standard bridge from technical AI failure modes to board-level monetary exposure.
- Gartner AI TRiSM
AI Trust, Risk and Security Management — industry framework formalizing continuous AI oversight across four pillars: governance (inventory, AI-BOM, decision rights, change approval), trustworthiness & fairness (explainability, bias), reliability (drift, hallucination metrics), security management (prompt injection, model inversion, poisoning, leakage). No legal force; its value is the architecture it implies — the four-layer enterprise stack and the first/second-line separation this graph models as bp-trism and pat-lines-defense.
- IFRS / US GAAP Reporting Assurance
Recognition, measurement and disclosure rules that any AI-assembled financial statement, forecast or scenario model must satisfy. Model-generated figures need traceable inputs, documented assumptions and a reviewable reconciliation to the ledger before they enter a reporting cycle.
- IMDA Agentic AI Governance Framework (SG)
Model AI Governance Framework for Agentic AI (Jan 2026, updated Jun 2026) — first state-issued agentic-specific guidance: bounded autonomy levels, action-space and interface restrictions, human-in-command checkpoints, automation-bias controls, logging & attribution expectations. No legal force in the EU, but the most concrete public benchmark for Art. 14-style oversight design of agent systems.
- NIST AI 600-1 (GenAI Profile)
Companion profile to the AI RMF covering twelve GenAI-specific failure modes — confabulation, prompt injection, value-chain propagation and others — as the technical checklist behind Map/Measure for generative systems.
- NIST AI RMF 1.0
Govern–Map–Measure–Manage risk framework; Map/Measure functions populate the Art. 9 risk register with quantified values; the transatlantic mapping reference.
- TAGOF (Audit-as-Code)
Operationalizes governance as code in CI/CD: policy-as-code enforcement, continuous runtime telemetry and automatically generated audit evidence — the execution layer that replaces periodic audits with continuous assurance.
How to cite RAIN
RAIN — Regulated AI Navigator, knowledge graph v2.1.2, 2026-08-07, rainavigator.org (accessed 2026-08-07).