Sources & Verification
Method context: the pre-registered benchmark study →
Every claim in this tool resolves to one of the source layers below, and every legal or standards node carries — or visibly lacks — a verification date. Nothing here is backdated to look authoritative. If a node has no verification date, the badge on it says so.
Source layers
The regulation and standards backbone: which legal acts exist, which bodies issue them, and how the AI Act interlocks with the wider digital acquis.
The architectural translation: how an obligation becomes a concrete design decision rather than a policy document.
The agentic layer: autonomy degrees, the four-mode oversight taxonomy and the regulatory design constraints specific to agents.
The two-dimensional compliance map, the sector use-case catalogues and the seven-layer reference architecture the profiles are derived from.
The US state-law patchwork, the Art. 6(3) filter, cryptographic logging and the production oversight patterns (Trinity Defense, Guardian Agents, HITL).
The Service-as-a-Software operating model: the four-stage compliant pipeline, the ISO 42001 control loop, the mandatory artifact set and the rollout roadmap.
Community input on outcome-based scaling of autonomous agentic workflows in regulated enterprise ecosystems.
The market layer: 116 named products across the seven-layer agentic stack, each with a sub-category, a description and the regulatory alignments its vendor or the compilation claims. Aggregated, works-cited research — the claims are recorded as claims and are the most disputable content in the graph.
How we verify
Principle: Every legal act and standard in this graph is a moving target. A node without a lastVerified date is a claim, not a fact.
Process: Quarterly deepsearch sweep over all nodes with status fields + event-driven re-verification whenever (a) a community dispute is opened on a node, (b) a monitored feed reports a change touching a node's source, or (c) a release is prepared. Each sweep bumps lastVerified even when nothing changed — absence of change is also a finding.
When something changes: When a node's status changes (e.g. prEN → EN published, or an article amended by an Omnibus), all edges incident to that node are flagged 'review-pending' for the next curator pass; profile derivations show a currency warning until cleared.
Automated freshness pipeline
Three walker agents run inside the app every week: they read the monitored feeds, scan for use cases the catalogue misses, and re-check the graph against itself. They file proposals — they never change the graph.
Checks the monitored regulatory feeds for changes to legal status, deadlines, sanctions and standard lifecycle stages, and proposes dated updates to the instruments already in the graph.
Scans enforcement news, enterprise deployments, vendor launches, case studies and incidents in regulated sectors for use cases the catalogue does not yet describe.
Re-runs the integrity and consistency battery over the graph, reports every violation, and verifies the single stalest claim against its own authoritative source.
Tracks technology-capability shifts relevant to compliance — hosting and residency developments (sovereign clouds, confidential computing, the EU data boundary), identity and verification methods, and agentic-architecture capabilities — and proposes updates to the hosting fields on vendor-category examples and to affected component, pattern and blueprint nodes.
Watches the vendor landscape for new entrants, discontinued products, changed hosting models and changed compliance claims, and proposes updates to the market examples already recorded — always as disputable observations, never as certifications.
Finds the article-level provision behind duty-creating edges that carry no citation yet, and files each find as a curator proposal that attaches the provision to that exact edge — or an explicit “no provision found” verdict for the curator to check, re-base or remove the edge. It never writes to the graph and never raises the coverage metric by itself.
Agents research and propose; every change is decided by a human curator and logged in the changelog. Read every run report →
Monitored feeds
Re-verification is driven by these feeds plus any community dispute opened on a node.
- Official Journal of the EU (OJEU) — harmonised-standard citations & amending acts
- European Parliament Legislative Observatory — Omnibus & EHDS procedure files (the AILD file is closed: the proposal was withdrawn in the Commission's 2025 work programme; watched only for a successor)
- CEN-CENELEC JTC 21 work programme & standards trackers
- EU AI Office guidance, delegated & implementing acts
- National layer: BSI publications, DAkkS accreditations, TÜV AI.Lab assessments
- Council of Europe CETS 225 ratification count
- Taiwan AI Basic Act promulgation and effective date
- Brazil Chamber of Deputies vote on PL 2338/2023
- Canada Bill C-36 legislative progress
- Indonesia draft Presidential Regulation on AI
- Switzerland end-2026 sectoral AI consultation draft
- India DPDP Act phase-in deadlines
Currency coverage — the honest number
The remaining claims are published as unverified rather than given an invented date. That is a deliberate choice: an unverified badge is information, a fabricated date is not. See the per-node worklist → The graph in numbers →
Auditing a single claim
Open any entry in the graph explorer to see its status, verification date, status note and every edge that derives from it. Disagree with it? Dispute it from its detail panel — a dispute triggers re-verification and is recorded in the changelog. Curators run the deep-search sweep that keeps these dates moving.
The graph is open to use and to inspect claim by claim: every node, every citation and every reasoning trace is publicly browsable, and each conclusion you run exports as your own dossier, test plan or evidence work list. What we do not offer is a bulk download of the graph itself — inspection is per claim, not per copy.
References
Every legal instrument, national policy and standard the graph relies on, listed in full and generated from the graph itself — so this chapter cannot drift from what the tool actually reasons over. Articles are nested under their parent act. 300 of 367 entries resolve to a primary public source; the rest carry no link because no authoritative URL pattern applies, not because none was looked for.
Target market(s)European UnionUnited States (federal)change
Reorders the instrument groups below so your selected markets come first.
EU53European Unionbinding horizontal AI law
- AILD — COM(2022) 496, withdrawn withdrawn — no longer law
- Art. 19 — Valuation · verified 2026-09-18 · EUR-Lex
- AML Package (AMLR/AMLA) in force
- Art. 13 — resilience measures of critical entities · verified 2026-09-06 · EUR-Lex
- Art. 18 — Obligation to assess the creditworthiness of the consumer · verified 2026-09-11 · EUR-Lex
- Art. 6(1)(ea) — personalised-pricing disclosure · verified 2026-09-18 · EUR-Lex
- Directive (EU) 2024/1760 in force
- Regulation (EU) 2024/2847 in force
- CRA Art. 14 — Vulnerability & Severe-Incident Reporting · verified 2026-08-11 · digital-strategy.ec.europa.eu
- Regulation (EU) 2023/2854 in force
- Regulation (EU) 2022/868 in force
- Regulation (EU) 2022/2065 in force
- DSA Art. 17 — Statement of reasons · verified 2026-08-15 · EUR-Lex
- DSA Art. 20 — Internal complaint-handling system · verified 2026-08-15 · EUR-Lex
- Regulation (EU) 2022/2554 in force
- DORA Art. 19 — Major ICT-Incident Reporting · verified 2026-08-11 · EUR-Lex
- Art. 7(1)(b) and Art. 9 — risk-based approach; risk assessment and management of the supply system by water suppliers · verified 2026-09-15 · EUR-Lex
- Regulation (EC) No 561/2006 on the harmonisation of certain social legislation relating to road transport in force
- Art. 10(2) — undertaking's organisational duty · verified 2026-09-18 · EUR-Lex
- European Health Data Space Regulation in force
- Art. 11 — dynamic and fixed-price contract duties · verified 2026-09-18 · EUR-Lex
- Directive 2002/58/EC in force
- Regulation (EU) 2024/1689 in force
- Art. 4 — AI Literacy · unverified · EUR-Lex
- Art. 5 — Prohibited Practices · unverified · EUR-Lex
- Art. 5(1)(c) — Social scoring · verified 2026-08-26 · artificialintelligenceact.eu
- Art. 5(1)(d) — Predicting criminal offences from profiling alone · verified 2026-09-07 · EUR-Lex
- Art. 5(1)(e) — Untargeted scraping of facial images · verified 2026-08-26 · artificialintelligenceact.eu
- Art. 5(1)(f) — Emotion inference at work and in education · verified 2026-08-12 · artificialintelligenceact.eu
- Art. 5(1)(g) — Biometric categorisation of sensitive attributes · verified 2026-08-26 · artificialintelligenceact.eu
- Art. 6 — Classification rules for high-risk AI systems · verified 2026-08-16 · EUR-Lex
- Art. 6(3) — High-Risk Exemption Filter · unverified · EUR-Lex
- Art. 9 — Risk Management · unverified · artificialintelligenceact.eu
- Art. 10 — Data Governance · unverified · artificialintelligenceact.eu
- Art. 11 — Technical Documentation · unverified · artificialintelligenceact.eu
- Art. 12 — Record-Keeping / Logging · verified 2026-08-12 · artificialintelligenceact.eu
- Art. 13 — Transparency to Deployers · unverified · artificialintelligenceact.eu
- Art. 14 — Human Oversight · unverified · artificialintelligenceact.eu
- Art. 15 — Accuracy, Robustness, Cybersecurity · unverified · artificialintelligenceact.eu
- Art. 16 — Obligations of providers of high-risk AI systems · verified 2026-08-15 · artificialintelligenceact.eu
- Art. 17 — Quality Management System · unverified · artificialintelligenceact.eu
- Art. 22 — Authorised Representatives (High-Risk Providers) · verified 2026-09-10 · EUR-Lex
- Art. 25 — Value Chain / Role Flip · unverified · artificialintelligenceact.eu
- Art. 26 — Deployer Obligations · verified 2026-08-12 · artificialintelligenceact.eu
- Art. 27 — Fundamental Rights Impact Assessment · verified 2026-08-11 · artificialintelligenceact.eu
- Art. 43 — Conformity Assessment · verified 2026-08-17 · artificialintelligenceact.eu
- Art. 47/48 — CE Marking & Declaration of Conformity · unverified · artificialintelligenceact.eu
- Art. 49 — Registration in the EU database · verified 2026-08-15 · artificialintelligenceact.eu
- Art. 50 — Transparency Duties · verified 2026-08-16 · EUR-Lex
- Art. 53 — Obligations for providers of general-purpose AI models · verified 2026-08-17 · artificialintelligenceact.eu
- Art. 54 — Authorised Representatives (GPAI Providers) · verified 2026-09-10 · EUR-Lex
- Art. 72/73 — Post-Market Monitoring & Incidents · verified 2026-08-11 · ai-act-service-desk.ec.europa.eu
- Art. 85 — Right to lodge a complaint with a market surveillance authority · verified 2026-08-17 · digital-strategy.ec.europa.eu
- Art. 86 — Right to explanation of individual decision-making · verified 2026-08-17 · artificialintelligenceact.eu
- Regulation (EU) No 537/2014 on specific requirements regarding statutory audit of public-interest entities in force
- Article 5 - Prohibition of the provision of non-audit services · verified 2026-09-18 · EUR-Lex
- Article 58 – Archiving of the clinical trial master file · verified 2026-09-18 · legislation.gov.uk
- EAA Art. 2 — scope, read with WAD Art. 1(2) and Art. 4 · verified 2026-09-10 · EUR-Lex
- Arts. 2(d), 3 and 7 - illegal access 'without right'; tools used for committing offences · verified 2026-09-21 · EUR-Lex
- Art. 4(3) — TDM exception subject to rightholder opt-out · verified 2026-09-11 · EUR-Lex
- Art. 4 - Authorisation for non-listed dual-use items (end-use catch-all) and the exporter's duty to notify · verified 2026-09-21 · EUR-Lex
- Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 by establishing a network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows in force
- Art. 26 — Cybersecurity risk management at entity level (with Art. 24 identification and Art. 29 controls) · verified 2026-09-10 · EUR-Lex
- Council Directive 2000/78/EC of 27 November 2000 establishing a general framework for equal treatment in employment and occupation (anchor act) — bundled for the employment scope with Council Directive 2000/43/EC of 29 June 2000 implementing the principle of equal treatment between persons irrespective of racial or ethnic origin, and Directive 2006/54/EC of the European Parliament and of the Council of 5 July 2006 on the implementation of the principle of equal opportunities and equal treatment of men and women in matters of employment and occupation (recast) in force
- Art. 2(2)(b) — indirect discrimination through apparently neutral criteria · verified 2026-09-11 · EUR-Lex
- Council Directive 2004/113/EC of 13 December 2004 implementing the principle of equal treatment between men and women in the access to and supply of goods and services (OJ L 373, 21.12.2004, pp. 37–43) — bundled with Council Directive 2000/43/EC of 29 June 2000 implementing the principle of equal treatment between persons irrespective of racial or ethnic origin (OJ L 180, 19.7.2000, pp. 22–26), Art. 3(1)(e)–(h) in force
- Art. 2(b) — indirect discrimination through apparently neutral criteria · verified 2026-09-06 · EUR-Lex
- Art 20 IDD — demands-and-needs test, personalised recommendation and 'fair and personal analysis' · verified 2026-09-18 · legislation.gov.uk
- Article 24a - Internal organisation of statutory auditors and audit firms · verified 2026-09-18 · EUR-Lex
- Directive 2009/48/EC Art. 10 — essential safety requirements before placing a toy on the market · verified 2026-09-15 · EUR-Lex
- Art. 21 — examination of an application · verified 2026-09-07 · EUR-Lex
- Art. 109 — emergency communications and the single European emergency number 112 · verified 2026-09-15 · EUR-Lex
- Regulation (EU) 2016/679 in force
- GDPR Art. 9 — Special Categories of Personal Data · verified 2026-08-17 · EUR-Lex
- GDPR Art. 17 — Erasure · unverified · EUR-Lex
- GDPR Art. 22 — Automated Decisions · unverified · EUR-Lex
- GDPR Art. 25 — Data Protection by Design · unverified · EUR-Lex
- GDPR Art. 27 — EU Representative · verified 2026-09-10 · EUR-Lex
- GDPR Art. 32 — Security of Processing · verified 2026-08-17 · EUR-Lex
- GDPR Art. 33/34 — Personal-Data Breach Notification · verified 2026-08-11 · EUR-Lex
- GDPR Art. 35 — DPIA · unverified · EUR-Lex
- GDPR Art. 88 — Processing in the Employment Context · verified 2026-08-17 · EUR-Lex
- Regulation (EU) 2023/988 in force
- Art. 6(1)(c)–(d), 6(3) — mandatory drowsiness/distraction warning systems; closed-loop data, no third-party access · verified 2026-09-15 · EUR-Lex
- Art. 11 — automated individual decision-making · verified 2026-09-07 · EUR-Lex
- Directive 2006/42/EC on machinery, as it remains in force until repeal by Regulation (EU) 2023/1230 in force
- Art. 5(1) — manufacturer obligations · verified 2026-09-18 · EUR-Lex
- Regulation (EU) 2023/1230 in force
- Regulations (EU) 2017/745 & 2017/746 in force
- Art. 18 — Obligation to assess the creditworthiness of the consumer · verified 2026-09-21 · EUR-Lex
- Directive (EU) 2022/2555 in force
- NIS2 Art. 23 — Significant-Incident Reporting · verified 2026-08-11 · EUR-Lex
- NIS2 Art. 32 — Supervision of Essential Entities (Ex-Ante) · verified 2026-09-10 · EUR-Lex
- NIS2 Art. 33 — Supervision of Important Entities (Ex-Post) · verified 2026-09-10 · EUR-Lex
- Council Directive 89/391/EEC of 12 June 1989 on the introduction of measures to encourage improvements in the safety and health of workers at work in force
- Art. 6 — employer's general obligations (adapting work to the individual; consultation on new technologies) · verified 2026-09-15 · EUR-Lex
- Directive (EU) 2024/2831 of the European Parliament and of the Council of 23 October 2024 on improving working conditions in platform work enacted — not yet applicable
- Arts 9–11 — transparency on, human oversight of and human review of automated monitoring and decision-making systems · verified 2026-09-15 · EUR-Lex
- Art. 5 — ranking transparency · verified 2026-09-18 · EUR-Lex
- Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication in force
- Art. 2 — General authentication requirements (transaction monitoring mechanism) · verified 2026-09-10 · EUR-Lex
- Commission Delegated Regulation (EU) 2022/30 of 29 October 2021 supplementing Directive 2014/53/EU (Radio Equipment Directive) with regard to the application of the essential requirements referred to in Article 3(3), points (d), (e) and (f) in force
- Art. 1 — scope: internet-connected radio equipment; equipment processing personal data (childcare, toys, wearables) · verified 2026-09-15 · EUR-Lex
- Directive (EU) 2024/2853 in force
- Regulation (EU) No 952/2013 of the European Parliament and of the Council of 9 October 2013 laying down the Union Customs Code in force
- Art. 15 - Provision of information to the customs authorities (responsibility for the accuracy of declarations) · verified 2026-09-21 · EUR-Lex
- Arts 3, 5, 6(b) — daily rest, weekly rest, 48-hour average week · verified 2026-09-15 · EUR-Lex
US50United States (federal)binding data/sector law only
- 29 U.S.C. § 623(a) — age discrimination in hiring and employment terms · verified 2026-09-12 · Cornell LII
- 42 U.S.C. § 12112(b)(6) — screen-out selection criteria · verified 2026-09-10 · Cornell LII
- 28 CFR Part 35, Subpart H (§ 35.200), DOJ Title II accessibility rule as amended by Interim Final Rule 2026-07663 enacted — not yet applicable
- § 35.200(b)(1) — WCAG 2.1 AA duty · verified 2026-09-18 · eCFR
- California Penal Code, Part 1, Title 15, Chapter 1.5 (Invasion of Privacy), §§ 630-638.55 in force
- Cal. Penal Code § 631(a) - Reading or learning the contents of a communication without the consent of all parties · verified 2026-09-21 · leginfo.legislature.ca.gov
- 18 U.S.C. §1030 in force
- 31 CFR § 10.22 — Diligence as to accuracy · verified 2026-09-21 · Cornell LII
- 16 CFR § 312.5 — verifiable parental consent before collecting personal information from children · verified 2026-09-15 · eCFR
- 21 CFR 1306.04(a) — Corresponding Responsibility · verified 2026-09-21 · Cornell LII
- ECOA / CFPB Adverse-Action Regime in force
- 42 U.S.C. § 3604(a)–(b) — refusal to rent, making a dwelling unavailable, discriminatory terms · verified 2026-09-15 · Cornell LII
- 29 U.S.C. § 207(a)(1): Maximum hours (overtime compensation) · verified 2026-09-21 · Cornell LII
- 31 U.S.C. § 3729(a) - Liability for Certain Acts · verified 2026-09-18 · Cornell LII
- § 1681m(a) — adverse action notice when a consumer report is used · verified 2026-09-06 · Cornell LII
- Title 21 Code of Federal Regulations Part 11 – Electronic Records; Electronic Signatures in force
- § 11.10 – Controls for closed systems · verified 2026-09-18 · Cornell LII
- Title 21 Code of Federal Regulations Part 312 – Investigational New Drug Application, Subpart B § 312.32 (IND Safety Reporting) in force
- § 312.32 – IND safety reporting · verified 2026-09-18 · Cornell LII
- FDA SaMD / Digital Health regulatory framework unverified — help verify
- 18 U.S.C. § 2511(1)(a), (2)(d) - Interception prohibited; party and prior-consent exception · verified 2026-09-21 · govinfo.gov
- FINRA Rule 4511 in force
- Florida Statutes, Chapter 934 (Security of Communications; Surveillance), §§ 934.03 and 934.10 in force
- Fla. Stat. § 934.03(1)(a), (2)(d) - Interception prohibited; lawful with the prior consent of all parties · verified 2026-09-21 · flsenate.gov
- 49 U.S.C. § 14916(a) - Registration and financial security required to provide brokerage services · verified 2026-09-21 · Cornell LII
- FTC Act §5 & Endorsement / AI-Claims Guidance in force
- 16 CFR § 314.1(b) — Scope: financial institutions under FTC jurisdiction, including tax preparation firms · verified 2026-09-21 · Cornell LII
- 45 CFR § 84.84, HHS rule implementing Section 504 of the Rehabilitation Act for recipients of HHS financial assistance enacted — not yet applicable
- § 84.84(b)(1) — WCAG 2.1 AA duty for HHS-funded recipients · verified 2026-09-18 · eCFR
- HIPAA (US Health Privacy) in force
- HIPAA Breach Notification Rule · verified 2026-08-11 · hhs.gov
- 26 U.S.C. § 6672(a): Trust Fund Recovery Penalty · verified 2026-09-21 · Cornell LII
- 26 CFR § 301.7216-3 — Disclosure or use permitted only with the taxpayer's consent · verified 2026-09-21 · Cornell LII
- NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers (adopted by the NAIC Executive (EX) Committee and Plenary, 4 December 2023) in force
- Section 3 AIS Program Guidelines — life-cycle coverage and third-party AI Systems (¶1.6, ¶1.8, ¶4.0-4.3) · verified 2026-09-18 · content.naic.org
- § 654(a)(1) — General Duty Clause · verified 2026-09-18 · govinfo.gov
- PCAOB Release No. 2024-007, Amendments Related to Aspects of Designing and Performing Audit Procedures that Involve Technology-Assisted Analysis of Information in Electronic Form, SEC-approved via Release No. 34-100774 in force
- AS 1105 / AS 2301 amendments - technology-assisted analysis · verified 2026-09-18 · assets.pcaobus.org
- 12 CFR 1024.14 - Prohibition against kickbacks and unearned fees · verified 2026-09-18 · consumerfinance.gov
- SEC Release 33-11216 — Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure in force
- SEC Form 8-K Item 1.05 — Material Cybersecurity Incident · verified 2026-08-11 · sec.gov
- 17 C.F.R. §§ 270.31a-1, 270.31a-2 and 270.31a-3 — Rules 31a-1, 31a-2 and 31a-3 under section 31 of the Investment Company Act of 1940 (15 U.S.C. 80a-30) in force
- Rule 31a-2(a) — Preservation of ledgers and NAV-computation schedules · verified 2026-09-18 · Cornell LII
- SEC Predictive Data Analytics Rules (withdrawn 2025) withdrawn — no longer law
- 17 CFR 240.15l-1 in force
- 17 C.F.R. § 210.2-01 — Qualifications of Accountants (Regulation S-X, Rule 2-01) in force
- Rule 2-01(c)(4)(ii) - Financial information systems design and implementation · verified 2026-09-18 · Cornell LII
- 17 CFR 240.17a-4 in force
- State unauthorized-practice-of-law (UPL) statutes and bar authorized-practice opinions restricting preparation of conveyancing instruments and conduct of real-estate closings to licensed attorneys or attorney-supervised staff (e.g. N.C. Gen. Stat. 84-4 to 84-8; NC State Bar Authorized Practice Advisory Opinion 2002-1) in force
- Non-lawyer document preparation / closing-conduct prohibition · verified 2026-09-18 · ncbar.gov
- 47 U.S.C. § 223a(a)(3) — 48-hour removal incl. known identical copies · verified 2026-09-11 · Cornell LII
- 47 U.S.C. §227 in force
- 12 CFR § 1026.19(e) — Loan Estimate: timing and good-faith tolerances · verified 2026-09-21 · Cornell LII
- 18 U.S.C. §2523 / §2713 (CLOUD Act) in force
- 19 U.S.C. § 1484(a)(1) - Importer of record: entry and classification with reasonable care · verified 2026-09-21 · Cornell LII
- Export Administration Regulations, 15 CFR Parts 730-774 (violations: 15 CFR § 764.2; knowledge: 15 CFR § 772.1) in force
- 15 CFR § 764.2 - Violations (prohibited conduct, acting with knowledge of a violation, false statements in export control documents) · verified 2026-09-21 · Cornell LII
- 35 U.S.C. § 184(a) - Foreign-filing licence for inventions made in the United States · verified 2026-09-22 · Cornell LII
- OFAC Framework, root cause VI - Sanctions Screening Software or Filter Faults · verified 2026-09-21 · ofac.treasury.gov
- 37 CFR § 11.18(b) - Certification on presenting any paper to the USPTO (reasonable inquiry) · verified 2026-09-22 · Cornell LII
US-CO4United States — Coloradobinding horizontal AI law
- Colorado SB 26-189 enacted — not yet applicable
- Colorado SB 24-205 repealed — not applicable law
- Colorado HB 26-1263 — Conversational Artificial Intelligence Service Operator Requirements enacted — not yet applicable
- Colorado HB 24-1130, Privacy of Biometric Identifiers & Data, amending the Colorado Privacy Act (C.R.S. 6-1-1314), effective 1 July 2025 in force
- C.R.S. 6-1-1314 — biometric policy, notice and consent; restricted employer purposes · verified 2026-09-15 · leg.colorado.gov
US-IL4thinUnited States — Illinoisbinding data/sector law only
- 820 ILCS 42 in force
- 740 ILCS 14 in force
- 775 ILCS 5/2-102(L), added by Public Act 103-0804 (HB 3773) in force
- 775 ILCS 5/2-102(L) — AI in employment decisions · verified 2026-09-10 · duanemorris.com
- Prescription Drug Affordability Act, Public Act 104-0027 (eff. 1 July 2025; entire Act effective 1 January 2026), Article XXXIIB of the Illinois Insurance Code, 215 ILCS 5/513b1 et seq. in force
- Prescription Drug Affordability Act — spread-pricing and steering ban; 100% rebate and fee pass-through · verified 2026-09-21 · idoi.illinois.gov
US-NY3United States — New Yorkbinding data/sector law only
- New York General Business Law Article 47, §§ 1700-1704 in force
- §§ 1701-1702 — crisis protocol and non-human disclosure · verified 2026-09-18 · nysenate.gov
- New York RAISE Act enacted — not yet applicable
- NYC Local Law 144 (AEDT) in force
GLOBAL5Cross-jurisdictionsoft-law framework
- Council of Europe Framework Convention on AI (CETS 225) signed — entry into force not confirmed
- European Patent Convention (EPC 2000), Art. 60(1) (right to a European patent), Art. 81 and Rule 19 (designation of the inventor), Art. 90(3) and (5) and Rule 60(1) (examination and refusal); Guidelines for Examination in the European Patent Office, 2026 edition, General Part 5 (The use of artificial intelligence) and Part A-III, 5 (Designation of inventor); Legal Board of Appeal decision J 8/20 (DABUS) of 21 December 2021 in force
- Art. 81 EPC - Designation of the inventor · verified 2026-09-22 · epo.org
- ICH Harmonised Guideline for Good Clinical Practice E6(R2) (Step 5, 2016) and E6(R3) (Step 4, 6 Jan 2025; EU-effective 23 July 2025) in force
- Section 5.5.3 – Validation of electronic trial data handling / computerised systems · verified 2026-09-18 · ema.europa.eu
- National Tax Codes & OECD BEPS / Pillar Two in force
- Sector Safety Regimes (EASA / ERA / NERC CIP) in force
DE10thinGermanybinding horizontal AI law
- § 201 Strafgesetzbuch (StGB) - Verletzung der Vertraulichkeit des Wortes (violation of the confidentiality of the spoken word) in force
- § 201 Abs. 1 StGB - Recording the non-publicly spoken word of another without authority · verified 2026-09-21 · gesetze-im-internet.de
- Strafgesetzbuch (StGB) § 203 Verletzung von Privatgeheimnissen, in der Fassung der Bekanntmachung vom 13. November 1998 (BGBl. I S. 3322), zuletzt geändert durch Artikel 1 des Gesetzes vom 20. März 2026 (BGBl. 2026 I Nr. 95) in force
- § 203 Abs. 3 and 4 StGB — disclosure to cooperating persons and the duty to bind them to secrecy · verified 2026-09-21 · gesetze-im-internet.de
- § 26 Bundesdatenschutzgesetz (BDSG) vom 30. Juni 2017 (BGBl. I S. 2097) — Datenverarbeitung für Zwecke des Beschäftigungsverhältnisses in force
- § 26 Abs. 1 S. 1 — Erforderlichkeit für Begründung, Durchführung, Beendigung · verified 2026-09-10 · gesetze-im-internet.de
- Energiewirtschaftsgesetz (EnWG) § 41a, as amended 23 December 2025 (BGBl. 2025 I Nr. 347) in force
- § 41a EnWG · verified 2026-09-18 · gesetze-im-internet.de
- Allgemeines Gleichbehandlungsgesetz (AGG) vom 14. August 2006 (BGBl. I S. 1897), zuletzt geändert durch Artikel 15 des Gesetzes vom 22. Dezember 2023 (BGBl. 2023 I Nr. 414) in force
- § 3 Abs. 2 — mittelbare Benachteiligung (neutral criteria or procedures) · verified 2026-09-06 · gesetze-im-internet.de
- Kündigungsschutzgesetz (KSchG) in der Fassung der Bekanntmachung vom 25. August 1969 (BGBl. I S. 1317), zuletzt geändert durch Art. 2 des Gesetzes vom 14. Juni 2021 (BGBl. I S. 1762), § 1; Betriebsverfassungsgesetz (BetrVG) in der Fassung der Bekanntmachung vom 25. September 2001 (BGBl. I S. 2518), §§ 95 (Abs. 2a eingefügt durch das Betriebsrätemodernisierungsgesetz vom 14. Juni 2021, BGBl. I S. 1762, in Kraft seit 18. Juni 2021) und 102 in force
- BetrVG § 102 Abs. 1 — Anhörung des Betriebsrats vor Kündigung · verified 2026-09-10 · gesetze-im-internet.de
- Sozialgesetzbuch (SGB) Fünftes Buch (V) - Gesetzliche Krankenversicherung - (Artikel 1 des Gesetzes v. 20. Dezember 1988, BGBl. I S. 2477), § 106d Abrechnungsprüfung in der vertragsärztlichen Versorgung in force
- § 106d Abs. 2 SGB V - Sachliche und rechnerische Richtigkeit · verified 2026-09-18 · gesetze-im-internet.de
- Steuerberatungsgesetz (StBerG) in der Fassung der Bekanntmachung vom 4. November 1975 (BGBl. I S. 2735), zuletzt geändert durch Artikel 1 des Gesetzes vom 29. Juni 2026 (BGBl. 2026 I Nr. 197) in force
- § 57 Abs. 1 StBerG — Allgemeine Berufspflichten (independence, own responsibility, conscientiousness, confidentiality) · verified 2026-09-21 · gesetze-im-internet.de
GB4United Kingdombinding data/sector law only
- Online Safety Act 2023 (GB) in force
- The Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 (SI 2018/952), assimilated law as amended by SI 2022/1097 and SI 2025/557 in force
- reg. 6 — accessibility requirement · verified 2026-09-18 · legislation.gov.uk
CH2Switzerlandbinding data/sector law only
- Revised FADP (CH) in force
CA5Canadabinding data/sector law only
- AIDA — Bill C-27 (CA) withdrawn — no longer law
- Bill C-36 — Protecting Privacy and Consumer Data Act (CA) pending — not yet law
- Digital Platform Workers' Rights Act, 2022, S.O. 2022, c. 7, Sched. 1 in force
- s. 7 — pay-transparency and assignment-factor disclosure · verified 2026-09-18 · ontario.ca
- PIPEDA (CA) in force
- Quebec Law 25 (CA) in force
BR2Brazilbinding data/sector law only
- LGPD 13.709/2018 (BR) in force
- PL 2338/2023 AI framework (BR) pending — not yet law
CN7Chinabinding horizontal AI law
- Data Security Law (CN) in force
- Deep Synthesis Provisions (CN) in force
- Personal Information Protection Law in force
AU4Australiabinding data/sector law only
- Mandatory AI guardrails proposals paper (AU) never enacted — not law
- National AI Plan (AU) voluntary
- Online Safety Amendment (Social Media Minimum Age) Act 2024 (No. 127, 2024), inserting Part 4A into the Online Safety Act 2021 in force
- s. 63D — minimum-age reasonable-steps duty · verified 2026-09-18 · legislation.gov.au
IN2Indiabinding data/sector law only
- DPDP Act 2023 (IN) in force
ID2thinIndonesiabinding data/sector law only
- PDP Law 27/2022 (ID) in force
JP2Japanbinding horizontal AI law
- AI Promotion Act (JP) in force
- APPI (JP) in force
KR2South Koreabinding horizontal AI law
- AI Framework Act ('AI Basic Act') in force
- Personal Information Protection Act in force
VN2Vietnambinding horizontal AI law
- Standalone AI Law (VN) in force
SG1Singaporesoft-law framework
- PDPA (SG) in force
TW1thinTaiwanbinding AI law passed — not yet in force
- AI Basic Act (TW) in force
AE3United Arab Emiratesbinding data/sector law only
SA1Saudi Arabiabinding data/sector law only
- PDPL (SA) in force
EG2thinEgyptbinding data/sector law only
KE2thinKenyabinding data/sector law only
- Data Protection Act 2019 (KE) unverified — help verify
NG2Nigeriabinding data/sector law only
- National AI Strategy (NG) voluntary
- Nigeria Data Protection Act 2023 in force
RW2thinRwandabinding data/sector law only
ZA2South Africabinding data/sector law only
- Draft National AI Policy (ZA) withdrawn — no longer law
- POPIA (ZA) in force
AF-AU1thinAfrican Union (continental)strategy only
- AU Continental AI Strategy voluntary
Standards & frameworks
Application of risk management to medical devices: risk-management plan and file, hazard identification, risk estimation and control, residual-risk evaluation, benefit-risk determination and production/post-production information. It is the risk framework the MDR presumes and the natural counterpart to AI Act Art. 9 for clinical AI — one risk file, two regimes reading it.
AI risk-management guidance extending ISO 31000 — feeds the Art. 9 risk-management system.
Robustness assessment of neural networks incl. formal methods (part 2) — supports Art. 15 evidence.
Information-security management; control A.8.28 (secure coding) is the natural anchor for AI code-generation and QA workflows alongside ISO 42001.
ISO/IEC 42001:2023 — certifiable AI management system (Annex SL harmonized structure, PDCA logic, synergy discount when an ISO 27001 ISMS exists). Clauses 4–10 plus Annex A controls (control count 38 vs 39 is a live community dispute — counting method differs by edition/guide). Covers an estimated 40–50% of AI Act organizational duties; organizational certificate, no product presumption of conformity.
Guidance for AI system impact assessments — supports DPIA/FRIA-style analyses.
Requirements for bodies auditing/certifying AIMS — accreditation basis (e.g. DAkkS) for ISO 42001 certificates.
Five-part data-quality framework (governance, process, management) — direct evidence path for Art. 10 representativeness and completeness.
Assessment of machine-learning classification performance: standardized metrics, test-set discipline, reporting format. The metric backbone for Art. 15 'declared accuracy' — test reports that cite it are comparable across vendors and audits.
Harmonised-norm candidate translating Art. 17 QMS into a product-focused governance framework; mappings to ISO 9001 and ISO/IEC 42001 Annex A (Annexes C & D); published as EN 18286:2026 in July 2026, OJEU citation (and with it the presumption of conformity) still pending.
Published terminology and concepts standard — the shared vocabulary layer for documentation and audits.
Specifies event logging in AI systems — the concrete implementation target for Art. 12 record-keeping.
CEN-CENELEC JTC 21 technical package under standardisation request M/593 (prEN 18228 trustworthiness, 18229 risk management, 18281–83 CV/NLP evaluation et al.); staged drafts, none OJEU-cited yet — Annex III applicability (Dec 2027) is Omnibus-coupled to their availability.
AI risk-management requirements deliverable of the JTC 21 core package — the harmonised-standard candidate behind Art. 9.
Part 1 of the JTC 21 trustworthiness deliverable — the framework layer other prEN 18xxx documents build on.
Conformity-assessment deliverable of the JTC 21 core package — the assessment procedure behind Art. 43.
Bias-treatment deliverable of the JTC 21 core package — operational target for the Art. 10 data-governance duties on bias.
Data-set and data-governance deliverable of the JTC 21 core package — the concrete evidence path for Art. 10.
Transparency taxonomy for AI systems: structured disclosure of system composition, data provenance, capabilities and limitations. The harmonised-norm candidate backing Art. 13 instructions-for-use and deployer-information duties — defines what a complete transparency package must contain.
- DIN SPEC 92001-1/-2/-3
AI life-cycle quality metamodel: functionality, robustness (adversarial & corruption), traceability/explainability — German operationalisation for Art. 15.
- BSI AIC4
AI Cloud Service Compliance Criteria Catalogue: security & robustness, performance, reliability, data management, explainability, bias — audited via ISAE 3000; vendor trust evidence.
- BSI C5:2026
Cloud compliance catalogue (168 requirements): post-quantum crypto, confidential computing, container security — infrastructure evidence layer for NIS2/CRA/Art. 15; binding baseline from June 2027.
- BSI GenAI Criteria Catalogue
Criteria for integrating external generative models via API: named AI owner, central AI register, case-by-case risk analysis, multi-stage input/output validation, least privilege, prompt/permission separation.
- NIST SP 800-218 (SSDF)
Secure Software Development Framework: practices for provenance, review and vulnerability handling of generated and third-party code; SSDF-AI companion covers AI-assisted development.
- OWASP Agentic Security (AST10 / Core Risks)
Threat framework for autonomous agents: tool misuse, excessive agency, confused-deputy, memory poisoning — with AIVSS scoring.
The de-facto technical security standard for GenAI applications; maps to Art. 10/14/15 and ISO 42001 Annex A controls.
- ENISA Multilayer Framework & AI Threat Landscape
Three-layer good-practice model (cyber foundations → AI-specific → sectoral) and lifecycle threat landscape — the operational base for Art. 15 and CRA.
- IEEE CertifAIEd™
Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.
French qualification scheme for cloud providers, including immunity requirements against extraterritorial law: ownership, control and operating personnel must not place the provider under a non-EU disclosure regime. The strictest publicly available sovereignty bar in the EU and the reference point most public-sector tenders converge on.
German federal criteria catalogue for cloud autonomy: the degree to which a cloud service can be operated, maintained and recovered without dependency on a non-EU provider's staff, tooling or control plane. Read alongside C5, which addresses security rather than autonomy — a C5-attested service can still be operationally dependent.
Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.
- FAIR-AIR / FAIR-MAM
AI extension of Factor Analysis of Information Risk: Expected Financial Loss = Loss Event Frequency (threat frequency × vulnerability) × Loss Magnitude (primary + secondary), run as Monte Carlo distributions — the standard bridge from technical AI failure modes to board-level monetary exposure.
- Gartner AI TRiSM
AI Trust, Risk and Security Management — industry framework formalizing continuous AI oversight across four pillars: governance (inventory, AI-BOM, decision rights, change approval), trustworthiness & fairness (explainability, bias), reliability (drift, hallucination metrics), security management (prompt injection, model inversion, poisoning, leakage). No legal force; its value is the architecture it implies — the four-layer enterprise stack and the first/second-line separation this graph models as bp-trism and pat-lines-defense.
- IFRS / US GAAP Reporting Assurance
Recognition, measurement and disclosure rules that any AI-assembled financial statement, forecast or scenario model must satisfy. Model-generated figures need traceable inputs, documented assumptions and a reviewable reconciliation to the ledger before they enter a reporting cycle.
The base functional-safety standard: safety lifecycle, safety integrity levels (SIL) and systematic-capability requirements for electrical/electronic/programmable electronic safety-related systems. Referenced here for the safety-component reading of grid control; sector derivatives (e.g. IEC 61511, IEC 62443 for security) are not asserted as harmonised under the AI Act.
Medical device software — software life-cycle processes: software safety classification (A/B/C), development planning, architecture, unit verification, integration and system testing, release, maintenance and problem resolution, and management of SOUP/off-the-shelf components. The recognised life-cycle spine for MDR software, and the process framework a notified body expects an AI-based diagnostic to be built inside.
- IMDA Agentic AI Governance Framework (SG)
Model AI Governance Framework for Agentic AI (Jan 2026, updated Jun 2026) — first state-issued agentic-specific guidance: bounded autonomy levels, action-space and interface restrictions, human-in-command checkpoints, automation-bias controls, logging & attribution expectations. No legal force in the EU, but the most concrete public benchmark for Art. 14-style oversight design of agent systems.
- NIST AI 600-1 (GenAI Profile)
Companion profile to the AI RMF covering twelve GenAI-specific failure modes — confabulation, prompt injection, value-chain propagation and others — as the technical checklist behind Map/Measure for generative systems.
- NIST AI RMF 1.0
Govern–Map–Measure–Manage risk framework; Map/Measure functions populate the Art. 9 risk register with quantified values; the transatlantic mapping reference.
- TAGOF (Audit-as-Code)
Operationalizes governance as code in CI/CD: policy-as-code enforcement, continuous runtime telemetry and automatically generated audit evidence — the execution layer that replaces periodic audits with continuous assurance.
Voluntary AI testing framework and toolkit, including LLM red-teaming (Project Moonshot).
Voluntary code of conduct for advanced AI developers, with an OECD reporting framework since Feb 2025.
Regulator guidance on AI and data protection, plus the 2025 AI and biometrics strategy.
Voluntary national AI governance guidelines.
Fairness, Ethics, Accountability and Transparency principles with the Veritas toolkit — voluntary, but a supervisory expectation in finance.
Voluntary business guidance, a living document aligned with ISO/IEC 42001 and the NIST AI RMF.
Voluntary generative-AI governance framework across nine dimensions.
Voluntary baseline AI governance framework.
Intergovernmental AI principles (2019, updated May 2024) — the shared vocabulary most national frameworks build on.
Five cross-sector principles applied by existing regulators (ICO, FCA, CMA, Ofcom, MHRA) — no AI statute.
Voluntary AI ethics principles and generative-AI guidelines with strong de-facto authority in government-adjacent business.
Voluntary AI charter and national strategy.
Ten voluntary guardrails for organisations deploying AI.
How to cite RAIN
RAIN — Regulated AI Navigator, knowledge graph v2.21.0, 2026-09-22, rainavigator.org (accessed 2026-09-24).