Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

Sources & Verification

Method context: the pre-registered benchmark study →

Every claim in this tool resolves to one of the source layers below, and every legal or standards node carries — or visibly lacks — a verification date. Nothing here is backdated to look authoritative. If a node has no verification date, the badge on it says so.

45 claims still need a dated source. The worklist is public and each item is a small, self-contained task. Help verify the graph →
Graph v2.21.0 · 2026-09-22 · 11 source layers · 12 monitored feeds

Source layers

1
European AI Regulation, Standards Landscape & Compliance Frameworks (systematic analysis)

The regulation and standards backbone: which legal acts exist, which bodies issue them, and how the AI Act interlocks with the wider digital acquis.

2
Compliance by Design in European AI System Architectures (decision handbook)

The architectural translation: how an obligation becomes a concrete design decision rather than a policy document.

3
System Architecture & Regulatory Design for Agentic AI (RDA framework)

The agentic layer: autonomy degrees, the four-mode oversight taxonomy and the regulatory design constraints specific to agents.

4
Regulated AI in Europe & USA — A Practitioner's Guide (book: two-dimensional compliance map, use-case catalogues, seven-layer reference architecture)

The two-dimensional compliance map, the sector use-case catalogues and the seven-layer reference architecture the profiles are derived from.

5
Architectural Paradigms for Regulated Agentic AI (July 2026): US state-law patchwork, Art. 6(3) filter, cryptographic logging, Trinity Defense / Guardian Agents / HITL production patterns

The US state-law patchwork, the Art. 6(3) filter, cryptographic logging and the production oversight patterns (Trinity Defense, Guardian Agents, HITL).

6
Strategic Evaluation of Service-as-a-Software AI Workflows in Regulated Markets (Aug 2026): productized-service operating model, vertical workflow taxonomy, four-stage compliant pipeline, ISO 42001 AIMS control loop, mandatory compliance-artifact set, four-phase roadmap.

The Service-as-a-Software operating model: the four-stage compliant pipeline, the ISO 42001 control loop, the mandatory artifact set and the rollout roadmap.

7
Service as Software in Regulated Enterprise Ecosystems — autonomous agentic workflows, regulatory compliance and outcome-based scaling (community input, Aug 2026)

Community input on outcome-based scaling of autonomous agentic workflows in regulated enterprise ecosystems.

8
Seven-layer agentic enterprise stack taxonomy (Engagement / Capabilities / Data) — adapted from the Al-Risk.ai / Agentico.ai agentic enterprise stack model (2025).

The market layer: 116 named products across the seven-layer agentic stack, each with a sub-category, a description and the regulatory alignments its vendor or the compilation claims. Aggregated, works-cited research — the claims are recorded as claims and are the most disputable content in the graph.

9
Enterprise Architecture and Vendor Ecosystem for Regulated, Agentic and Generative AI Systems, aggregated research, 2026-08; vendor claims pending community verification.
10
Comprehensive Enterprise Knowledge Graph Mapping and Compliance Database for the Agentic AI Tech Stack (aggregated research compilation, Aug 2026; works-cited style, ~80 vendors across seven layers with claimed regulatory alignments)
11
Target-jurisdiction research pass (verified 2026-08-11): AI, data-protection and content instruments for CN, KR, JP, VN, SG, IN, AU, TW, ID, AE, SA, AF-AU, NG, ZA, KE, EG, RW, GB, CA, BR, CH plus the GLOBAL bridge layer (ISO/IEC 42001 family, OECD AI Principles, G7 Hiroshima, CoE CETS 225).

How we verify

Principle: Every legal act and standard in this graph is a moving target. A node without a lastVerified date is a claim, not a fact.

Process: Quarterly deepsearch sweep over all nodes with status fields + event-driven re-verification whenever (a) a community dispute is opened on a node, (b) a monitored feed reports a change touching a node's source, or (c) a release is prepared. Each sweep bumps lastVerified even when nothing changed — absence of change is also a finding.

When something changes: When a node's status changes (e.g. prEN → EN published, or an article amended by an Omnibus), all edges incident to that node are flagged 'review-pending' for the next curator pass; profile derivations show a currency warning until cleared.

Automated freshness pipeline

Three walker agents run inside the app every week: they read the monitored feeds, scan for use cases the catalogue misses, and re-check the graph against itself. They file proposals — they never change the graph.

Regulatory WatchMondays 04:30 UTC

Checks the monitored regulatory feeds for changes to legal status, deadlines, sanctions and standard lifecycle stages, and proposes dated updates to the instruments already in the graph.

2026-09-21·failed·0 findings·0 proposals
Use-Case ScoutWednesdays 04:30 UTC

Scans enforcement news, enterprise deployments, vendor launches, case studies and incidents in regulated sectors for use cases the catalogue does not yet describe.

2026-09-21·failed·0 findings·0 proposals
Graph ReflectionFridays 04:30 UTC

Re-runs the integrity and consistency battery over the graph, reports every violation, and verifies the single stalest claim against its own authoritative source.

2026-09-21·completed·12 findings·0 proposals
Technology WatchTuesdays 04:30 UTC

Tracks technology-capability shifts relevant to compliance — hosting and residency developments (sovereign clouds, confidential computing, the EU data boundary), identity and verification methods, and agentic-architecture capabilities — and proposes updates to the hosting fields on vendor-category examples and to affected component, pattern and blueprint nodes.

2026-09-21·failed·0 findings·0 proposals
Vendor WatchThursdays 04:30 UTC

Watches the vendor landscape for new entrants, discontinued products, changed hosting models and changed compliance claims, and proposes updates to the market examples already recorded — always as disputable observations, never as certifications.

2026-09-21·failed·0 findings·0 proposals
Evidence SourcingMondays 06:30 UTC

Finds the article-level provision behind duty-creating edges that carry no citation yet, and files each find as a curator proposal that attaches the provision to that exact edge — or an explicit “no provision found” verdict for the curator to check, re-base or remove the edge. It never writes to the graph and never raises the coverage metric by itself.

2026-09-21·failed·0 findings·0 proposals

Agents research and propose; every change is decided by a human curator and logged in the changelog. Read every run report →

Monitored feeds

Re-verification is driven by these feeds plus any community dispute opened on a node.

Currency coverage — the honest number

314 / 359legal & standards claims with a verification date (87%)
312 / 359with a lifecycle status (87%)
0verified more than 90 days ago (due for re-sweep)
26 / 39evidence artefacts declaring a verifiability level (67%)

The remaining claims are published as unverified rather than given an invented date. That is a deliberate choice: an unverified badge is information, a fabricated date is not. See the per-node worklist → The graph in numbers →

Auditing a single claim

Open any entry in the graph explorer to see its status, verification date, status note and every edge that derives from it. Disagree with it? Dispute it from its detail panel — a dispute triggers re-verification and is recorded in the changelog. Curators run the deep-search sweep that keeps these dates moving.

The graph is open to use and to inspect claim by claim: every node, every citation and every reasoning trace is publicly browsable, and each conclusion you run exports as your own dossier, test plan or evidence work list. What we do not offer is a bulk download of the graph itself — inspection is per claim, not per copy.

References

Every legal instrument, national policy and standard the graph relies on, listed in full and generated from the graph itself — so this chapter cannot drift from what the tool actually reasons over. Articles are nested under their parent act. 300 of 367 entries resolve to a primary public source; the rest carry no link because no authoritative URL pattern applies, not because none was looked for.

Target market(s)European UnionUnited States (federal)change

Reorders the instrument groups below so your selected markets come first.

Target market(s)

Where will this system be used or placed on the market? The conclusion is derived for these jurisdictions — instruments that bind only elsewhere are left out.

Europe
North America
Latin America
Asia-Pacific
Middle East
Africa

Selected: European Union, United States (federal) · thin-coverage jurisdictions need verification

180 instruments · 134 articles · 53 standards · citation coverage in numbers →

EU53European Unionbinding horizontal AI law

  1. AILD — COM(2022) 496, withdrawn withdrawn — no longer law
    AI Liability Directive (withdrawn) · verified 2026-08-07 · no public source resolved
  2. AML Package (AMLR/AMLA) in force
    AML Package (AMLR/AMLA) · verified 2026-09-05 · no public source resolved
  3. CER Directive (Critical Entities Resilience) · verified 2026-09-10 · EUR-Lex
  4. Consumer Credit Directive II (CCD2) · verified 2026-09-10 · EUR-Lex
  5. CSDDD (Corporate Sustainability Due Diligence) · verified 2026-09-05 · EUR-Lex
  6. Cyber Resilience Act · verified 2026-09-05 · EUR-Lex
  7. Data Act · no verification date · EUR-Lex
  8. Data Governance Act · verified 2026-09-05 · EUR-Lex
  9. Digital Services Act · verified 2026-09-05 · EUR-Lex
  10. DORA · verified 2026-09-05 · EUR-Lex
  11. Drinking Water Directive (EU) 2020/2184 · verified 2026-09-15 · EUR-Lex
  12. Regulation (EC) No 561/2006 on the harmonisation of certain social legislation relating to road transport in force
    Driving Times, Breaks and Rest Periods — Regulation (EC) No 561/2006 · verified 2026-09-18 · no public source resolved
  13. European Health Data Space Regulation in force
    EHDS · verified 2026-09-05 · no public source resolved
  14. eIDAS 2 (EUDI / Trust Services) · verified 2026-08-04 · EUR-Lex
  15. Electricity Directive (EU) 2019/944 · verified 2026-09-18 · EUR-Lex
  16. ePrivacy Directive · verified 2026-09-05 · EUR-Lex
  17. EU AI Act · verified 2026-08-12 · EUR-Lex
  18. Regulation (EU) No 537/2014 on specific requirements regarding statutory audit of public-interest entities in force
    EU Audit Regulation (537/2014) — Public-Interest Entity Statutory Audits · verified 2026-09-18 · no public source resolved
  19. EU Clinical Trials Regulation (536/2014) · verified 2026-09-18 · EUR-Lex
  20. EU Digital Accessibility Directives (EAA & WAD) · verified 2026-09-10 · EUR-Lex
  21. EU DSM Copyright Directive (TDM, Arts 3–4) · verified 2026-09-06 · EUR-Lex
  22. EU Dual-Use Export Control Regulation (EU) 2021/821 · verified 2026-09-21 · EUR-Lex
  23. Commission Delegated Regulation (EU) 2024/1366 of 11 March 2024 supplementing Regulation (EU) 2019/943 by establishing a network code on sector-specific rules for cybersecurity aspects of cross-border electricity flows in force
    EU Electricity Cybersecurity Network Code (NCCS) · verified 2026-09-10 · no public source resolved
  24. Council Directive 2000/78/EC of 27 November 2000 establishing a general framework for equal treatment in employment and occupation (anchor act) — bundled for the employment scope with Council Directive 2000/43/EC of 29 June 2000 implementing the principle of equal treatment between persons irrespective of racial or ethnic origin, and Directive 2006/54/EC of the European Parliament and of the Council of 5 July 2006 on the implementation of the principle of equal opportunities and equal treatment of men and women in matters of employment and occupation (recast) in force
    EU Employment Equality Directives (2000/78 et al.) · verified 2026-09-11 · no public source resolved
  25. Council Directive 2004/113/EC of 13 December 2004 implementing the principle of equal treatment between men and women in the access to and supply of goods and services (OJ L 373, 21.12.2004, pp. 37–43) — bundled with Council Directive 2000/43/EC of 29 June 2000 implementing the principle of equal treatment between persons irrespective of racial or ethnic origin (OJ L 180, 19.7.2000, pp. 22–26), Art. 3(1)(e)–(h) in force
    EU Equal Treatment Directives (Goods, Services, Social Protection) · verified 2026-09-11 · no public source resolved
  26. EU Insurance Distribution Directive (IDD) · verified 2026-09-18 · EUR-Lex
  27. EU Political Advertising Regulation (EU) 2024/900 · verified 2026-09-21 · EUR-Lex
  28. EU Visa Code (Regulation (EC) No 810/2009) · verified 2026-09-07 · EUR-Lex
  29. GDPR · verified 2026-09-05 · EUR-Lex
  30. General Product Safety Regulation · no verification date · EUR-Lex
  31. Law Enforcement Directive (EU) 2016/680 · verified 2026-09-07 · EUR-Lex
  32. Machinery Regulation · verified 2026-09-05 · EUR-Lex
  33. MDR / IVDR · verified 2026-09-05 · EUR-Lex
  34. Mortgage Credit Directive (MCD) · verified 2026-09-21 · EUR-Lex
  35. NIS2 Directive · verified 2026-09-05 · EUR-Lex
  36. Council Directive 89/391/EEC of 12 June 1989 on the introduction of measures to encourage improvements in the safety and health of workers at work in force
    OSH Framework Directive 89/391/EEC · verified 2026-09-15 · no public source resolved
  37. Platform Work Directive (EU) 2024/2831 · verified 2026-09-15 · EUR-Lex
  38. Platform-to-Business Regulation (EU) 2019/1150 · verified 2026-09-18 · EUR-Lex
  39. Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication in force
    PSD2 RTS on Strong Customer Authentication (SCA-RTS) · verified 2026-09-10 · no public source resolved
  40. Commission Delegated Regulation (EU) 2022/30 of 29 October 2021 supplementing Directive 2014/53/EU (Radio Equipment Directive) with regard to the application of the essential requirements referred to in Article 3(3), points (d), (e) and (f) in force
    RED Cybersecurity Delegated Regulation (EU) 2022/30 · verified 2026-09-15 · no public source resolved
  41. Revised Product Liability Directive · verified 2026-08-17 · EUR-Lex
  42. Unfair Commercial Practices Directive · verified 2026-09-05 · EUR-Lex
  43. Regulation (EU) No 952/2013 of the European Parliament and of the Council of 9 October 2013 laying down the Union Customs Code in force
    Union Customs Code - Regulation (EU) No 952/2013 · verified 2026-09-21 · no public source resolved
  44. Working Time Directive 2003/88/EC · verified 2026-09-15 · EUR-Lex

US50United States (federal)binding data/sector law only

  1. ADA Title I & ADEA (US employment anti-discrimination) · verified 2026-09-10 · Cornell LII
  2. Bank Secrecy Act / FinCEN Program Rules · no verification date · Cornell LII
  3. California Penal Code, Part 1, Title 15, Chapter 1.5 (Invasion of Privacy), §§ 630-638.55 in force
    California Invasion of Privacy Act - CIPA (Cal. Penal Code §§ 630-638.55) · verified 2026-09-21 · no public source resolved
  4. CFAA & Anti-Scraping Regimes · no verification date · Cornell LII
  5. COPPA Rule (16 CFR Part 312) · verified 2026-09-15 · eCFR
  6. ECOA / CFPB Adverse-Action Regime in force
    ECOA / CFPB Adverse-Action Regime · verified 2026-09-05 · no public source resolved
  7. EEOC / Title VII Algorithmic Fairness (US) · verified 2026-08-17 · eCFR
  8. Fair Housing Act (US) · verified 2026-09-15 · Cornell LII
  9. Fair Labor Standards Act (Wage & Hour) · verified 2026-09-21 · Cornell LII
  10. False Claims Act · verified 2026-09-18 · Cornell LII
  11. FCRA — US Fair Credit Reporting Act · verified 2026-09-10 · Cornell LII
  12. Title 21 Code of Federal Regulations Part 11 – Electronic Records; Electronic Signatures in force
    FDA 21 CFR Part 11 (Electronic Records; Electronic Signatures) · verified 2026-09-18 · no public source resolved
  13. Title 21 Code of Federal Regulations Part 312 – Investigational New Drug Application, Subpart B § 312.32 (IND Safety Reporting) in force
    FDA 21 CFR Part 312 (IND Safety Reporting) · verified 2026-09-18 · no public source resolved
  14. FDA SaMD / Digital Health regulatory framework unverified — help verify
    FDA oversight of Software as a Medical Device (US) · verified 2026-08-15 · no public source resolved
  15. Federal Wiretap Act / ECPA (18 U.S.C. §§ 2510-2523) · verified 2026-09-21 · Cornell LII
  16. FINRA Rule 4511 in force
    FINRA Rule 4511 (General Books & Records) · no verification date · no public source resolved
  17. Florida Statutes, Chapter 934 (Security of Communications; Surveillance), §§ 934.03 and 934.10 in force
    Florida Security of Communications - Fla. Stat. ch. 934 (§§ 934.03, 934.10) · verified 2026-09-21 · no public source resolved
  18. FTC Act §5 & Endorsement / AI-Claims Guidance in force
    FTC Act §5 & Endorsement / AI-Claims Guidance · verified 2026-08-17 · no public source resolved
  19. FTC Safeguards Rule (16 CFR Part 314) · verified 2026-09-21 · eCFR
  20. 45 CFR § 84.84, HHS rule implementing Section 504 of the Rehabilitation Act for recipients of HHS financial assistance enacted — not yet applicable
    HHS Section 504 Web and Mobile Accessibility Rule (US) · verified 2026-09-18 · no public source resolved
  21. HIPAA (US Health Privacy) in force
    HIPAA (US Health Privacy) · verified 2026-08-04 · no public source resolved
  22. IRC § 6672 — Trust Fund Recovery Penalty · verified 2026-09-21 · Cornell LII
  23. NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers (adopted by the NAIC Executive (EX) Committee and Plenary, 4 December 2023) in force
    NAIC Model Bulletin on Use of AI Systems by Insurers · verified 2026-09-18 · no public source resolved
  24. OSH Act General Duty Clause (US) · verified 2026-09-18 · Cornell LII
  25. PCAOB Release No. 2024-007, Amendments Related to Aspects of Designing and Performing Audit Procedures that Involve Technology-Assisted Analysis of Information in Electronic Form, SEC-approved via Release No. 34-100774 in force
    PCAOB Technology-Assisted Analysis Standards (AS 1105 / AS 2301) · verified 2026-09-18 · no public source resolved
  26. RESPA / Regulation X (Settlement Services) · verified 2026-09-18 · eCFR
  27. Sarbanes-Oxley Act (SOX §302 / §404) · verified 2026-08-06 · Cornell LII
  28. SEC Advisers Act Rule 204-2 (Books & Records) · verified 2026-08-06 · eCFR
  29. 17 C.F.R. §§ 270.31a-1, 270.31a-2 and 270.31a-3 — Rules 31a-1, 31a-2 and 31a-3 under section 31 of the Investment Company Act of 1940 (15 U.S.C. 80a-30) in force
    SEC Investment Company Act Rules 31a-1 to 31a-3 (Fund Books & Records) · verified 2026-09-18 · no public source resolved
  30. SEC Predictive Data Analytics Rules (withdrawn 2025) withdrawn — no longer law
    SEC Predictive Data Analytics Rules (withdrawn 2025) · verified 2026-09-04 · no public source resolved
  31. SEC Regulation Best Interest · verified 2026-08-06 · eCFR
  32. 17 C.F.R. § 210.2-01 — Qualifications of Accountants (Regulation S-X, Rule 2-01) in force
    SEC Regulation S-X Rule 2-01 — Auditor Independence · verified 2026-09-18 · no public source resolved
  33. SEC Rule 17a-4 (US Records Retention) · no verification date · eCFR
  34. State unauthorized-practice-of-law (UPL) statutes and bar authorized-practice opinions restricting preparation of conveyancing instruments and conduct of real-estate closings to licensed attorneys or attorney-supervised staff (e.g. N.C. Gen. Stat. 84-4 to 84-8; NC State Bar Authorized Practice Advisory Opinion 2002-1) in force
    State Unauthorized Practice of Law Restrictions on Real-Estate Closings (US) · verified 2026-09-18 · no public source resolved
  35. TAKE IT DOWN Act / 18 U.S.C. § 2258A (platform duties) · verified 2026-09-11 · Cornell LII
  36. TCPA / FCC AI-Voice Rules (US) · no verification date · Cornell LII
  37. TILA-RESPA Integrated Disclosure Rule (TRID) · verified 2026-09-21 · eCFR
  38. US CLOUD Act (18 U.S.C. §2523 / §2713) · verified 2026-08-09 · Cornell LII
  39. Export Administration Regulations, 15 CFR Parts 730-774 (violations: 15 CFR § 764.2; knowledge: 15 CFR § 772.1) in force
    US Export Administration Regulations (EAR) · verified 2026-09-21 · no public source resolved
  40. USA PATRIOT Act §326 (CIP) · verified 2026-08-06 · eCFR

US-CO4United States — Coloradobinding horizontal AI law

  1. Colorado SB 26-189 enacted — not yet applicable
    Colorado ADMT Act (SB 26-189) · verified 2026-08-17 · leg.colorado.gov
  2. Colorado SB 24-205 repealed — not applicable law
    Colorado AI Act · verified 2026-08-12 · no public source resolved
  3. Colorado Chatbot Safety Act (HB 26-1263) · verified 2026-08-17 · leg.colorado.gov
  4. Colorado HB 24-1130, Privacy of Biometric Identifiers & Data, amending the Colorado Privacy Act (C.R.S. 6-1-1314), effective 1 July 2025 in force
    Colorado Privacy Act — Biometric Identifiers (HB 24-1130, C.R.S. 6-1-1314) · verified 2026-09-15 · no public source resolved

US-IL4thinUnited States — Illinoisbinding data/sector law only

  1. Illinois AI Video Interview Act · verified 2026-08-15 · ilga.gov
  2. Illinois Biometric Information Privacy Act (BIPA) · verified 2026-08-15 · ilga.gov
  3. 775 ILCS 5/2-102(L), added by Public Act 103-0804 (HB 3773) in force
    Illinois Human Rights Act — AI in Employment Decisions · verified 2026-09-10 · no public source resolved
  4. Prescription Drug Affordability Act, Public Act 104-0027 (eff. 1 July 2025; entire Act effective 1 January 2026), Article XXXIIB of the Illinois Insurance Code, 215 ILCS 5/513b1 et seq. in force
    Illinois Prescription Drug Affordability Act (PBM Reform) · verified 2026-09-21 · no public source resolved

US-NY3United States — New Yorkbinding data/sector law only

  1. New York General Business Law Article 47, §§ 1700-1704 in force
    New York AI Companion Models Law (GBL Art. 47) · verified 2026-09-18 · no public source resolved
  2. New York RAISE Act enacted — not yet applicable
    New York RAISE Act · verified 2026-09-05 · no public source resolved
  3. NYC Local Law 144 (AEDT) in force
    NYC Local Law 144 (AEDT) · verified 2026-08-12 · no public source resolved

GLOBAL5Cross-jurisdictionsoft-law framework

  1. Council of Europe Framework Convention on AI (CETS 225) signed — entry into force not confirmed
  2. European Patent Convention (EPC 2000), Art. 60(1) (right to a European patent), Art. 81 and Rule 19 (designation of the inventor), Art. 90(3) and (5) and Rule 60(1) (examination and refusal); Guidelines for Examination in the European Patent Office, 2026 edition, General Part 5 (The use of artificial intelligence) and Part A-III, 5 (Designation of inventor); Legal Board of Appeal decision J 8/20 (DABUS) of 21 December 2021 in force
    EPC Inventor Designation & EPO Guidelines on AI-Assisted Submissions · verified 2026-09-22 · no public source resolved
  3. ICH Harmonised Guideline for Good Clinical Practice E6(R2) (Step 5, 2016) and E6(R3) (Step 4, 6 Jan 2025; EU-effective 23 July 2025) in force
    ICH E6 Good Clinical Practice Guideline (R2/R3) · verified 2026-09-18 · no public source resolved
  4. National Tax Codes & OECD BEPS / Pillar Two in force
    National Tax Codes & OECD BEPS / Pillar Two · verified 2026-08-06 · no public source resolved
  5. Sector Safety Regimes (EASA / ERA / NERC CIP) in force
    Sector Safety Regimes (EASA / ERA / NERC CIP) · no verification date · no public source resolved

DE10thinGermanybinding horizontal AI law

  1. § 201 Strafgesetzbuch (StGB) - Verletzung der Vertraulichkeit des Wortes (violation of the confidentiality of the spoken word) in force
    § 201 StGB - Verletzung der Vertraulichkeit des Wortes (DE) · verified 2026-09-21 · no public source resolved
  2. Strafgesetzbuch (StGB) § 203 Verletzung von Privatgeheimnissen, in der Fassung der Bekanntmachung vom 13. November 1998 (BGBl. I S. 3322), zuletzt geändert durch Artikel 1 des Gesetzes vom 20. März 2026 (BGBl. 2026 I Nr. 95) in force
    § 203 StGB — Violation of Private Secrets (professional secrecy, DE) · verified 2026-09-21 · no public source resolved
  3. § 26 Bundesdatenschutzgesetz (BDSG) vom 30. Juni 2017 (BGBl. I S. 2097) — Datenverarbeitung für Zwecke des Beschäftigungsverhältnisses in force
    § 26 BDSG — Beschäftigtendatenschutz (DE) · verified 2026-09-11 · no public source resolved
  4. Energiewirtschaftsgesetz (EnWG) § 41a, as amended 23 December 2025 (BGBl. 2025 I Nr. 347) in force
    § 41a EnWG — dynamic and load-variable electricity tariffs (DE) · verified 2026-09-18 · no public source resolved
  5. § 87(1) No. 6 BetrVG — Works-Council Co-Determination · verified 2026-08-17 · gesetze-im-internet.de
  6. Allgemeines Gleichbehandlungsgesetz (AGG) vom 14. August 2006 (BGBl. I S. 1897), zuletzt geändert durch Artikel 15 des Gesetzes vom 22. Dezember 2023 (BGBl. 2023 I Nr. 414) in force
    AGG (German General Equal Treatment Act) · verified 2026-09-10 · no public source resolved
  7. Kündigungsschutzgesetz (KSchG) in der Fassung der Bekanntmachung vom 25. August 1969 (BGBl. I S. 1317), zuletzt geändert durch Art. 2 des Gesetzes vom 14. Juni 2021 (BGBl. I S. 1762), § 1; Betriebsverfassungsgesetz (BetrVG) in der Fassung der Bekanntmachung vom 25. September 2001 (BGBl. I S. 2518), §§ 95 (Abs. 2a eingefügt durch das Betriebsrätemodernisierungsgesetz vom 14. Juni 2021, BGBl. I S. 1762, in Kraft seit 18. Juni 2021) und 102 in force
  8. Sozialgesetzbuch (SGB) Fünftes Buch (V) - Gesetzliche Krankenversicherung - (Artikel 1 des Gesetzes v. 20. Dezember 1988, BGBl. I S. 2477), § 106d Abrechnungsprüfung in der vertragsärztlichen Versorgung in force
    SGB V § 106d - Billing Review in Contract-Physician Care · verified 2026-09-18 · no public source resolved
  9. Steuerberatungsgesetz (StBerG) in der Fassung der Bekanntmachung vom 4. November 1975 (BGBl. I S. 2735), zuletzt geändert durch Artikel 1 des Gesetzes vom 29. Juni 2026 (BGBl. 2026 I Nr. 197) in force
    Steuerberatungsgesetz (StBerG) — Tax Advisers Act (DE) · verified 2026-09-21 · no public source resolved

GB4United Kingdombinding data/sector law only

  1. Crime and Policing Act 2026 (GB) · verified 2026-08-11 · osborneclarke.com
  2. Online Safety Act 2023 (GB) · verified 2026-08-11 · ofcom.org.uk
  3. The Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 (SI 2018/952), assimilated law as amended by SI 2022/1097 and SI 2025/557 in force
  4. UK GDPR / DPA 2018 as amended by DUAA 2025 · verified 2026-08-11 · legislation.gov.uk

CH2Switzerlandbinding data/sector law only

  1. Federal Council AI regulation decision (CH) · verified 2026-09-04 · admin.ch
  2. Revised FADP (CH) · verified 2026-08-11 · edoeb.admin.ch

CA5Canadabinding data/sector law only

  1. AIDA — Bill C-27 (CA) withdrawn — no longer law
    AIDA — Bill C-27 (CA) · verified 2026-08-11 · srinstitute.utoronto.ca
  2. Digital Platform Workers' Rights Act, 2022, S.O. 2022, c. 7, Sched. 1 in force
    Digital Platform Workers' Rights Act, 2022 (Ontario, CA) · verified 2026-09-18 · no public source resolved
  3. PIPEDA (CA) · verified 2026-08-11 · priv.gc.ca
  4. Quebec Law 25 (CA) · verified 2026-08-11 · cai.gouv.qc.ca

BR2Brazilbinding data/sector law only

  1. LGPD 13.709/2018 (BR) · verified 2026-08-11 · gov.br
  2. PL 2338/2023 AI framework (BR) pending — not yet law
    PL 2338/2023 AI framework (BR) · verified 2026-08-11 · loc.gov

CN7Chinabinding horizontal AI law

  1. AI-Generated Synthetic Content Labeling Measures (CN) · verified 2026-08-11 · chinalawtranslate.com
  2. Algorithmic Recommendation Provisions (CN) · verified 2026-08-11 · chinalawtranslate.com
  3. Amended Cybersecurity Law — AI provisions (CN) · verified 2026-08-11 · loc.gov
  4. Data Security Law (CN) · verified 2026-08-11 · chinalawtranslate.com
  5. Deep Synthesis Provisions (CN) · verified 2026-08-11 · chinalawtranslate.com
  6. Interim Measures for Generative AI Services (CN) · verified 2026-08-11 · chinalawtranslate.com
  7. PIPL (CN) · verified 2026-08-11 · chinalawtranslate.com

AU4Australiabinding data/sector law only

  1. Mandatory AI guardrails proposals paper (AU) · verified 2026-08-11 · consult.industry.gov.au
  2. National AI Plan (AU) · verified 2026-09-04 · piperalderman.com.au
  3. Online Safety Amendment (Social Media Minimum Age) Act 2024 (No. 127, 2024), inserting Part 4A into the Online Safety Act 2021 in force
    Online Safety Amendment (Social Media Minimum Age) Act 2024 (AU) · verified 2026-09-18 · no public source resolved
  4. Privacy Act 1988 + 2024 Amendment (AU) · verified 2026-08-11 · oaic.gov.au

IN2Indiabinding data/sector law only

  1. DPDP Act 2023 (IN) · verified 2026-08-11 · static.pib.gov.in
  2. IT Act 2000 + Intermediary Guidelines 2021 (IN) · verified 2026-08-11 · meity.gov.in

ID2thinIndonesiabinding data/sector law only

  1. Draft Presidential Regulation on AI (ID) · verified 2026-08-11 · asianews.network
  2. PDP Law 27/2022 (ID) · verified 2026-08-11 · asianews.network

JP2Japanbinding horizontal AI law

  1. AI Promotion Act (JP) · verified 2026-08-11 · gov-online.go.jp
  2. APPI (JP) in force
    APPI (JP) · verified 2026-08-11 · ppc.go.jp

KR2South Koreabinding horizontal AI law

  1. AI Framework Act (KR) · verified 2026-08-11 · loc.gov
  2. PIPA (KR) · verified 2026-08-11 · pipc.go.kr

VN2Vietnambinding horizontal AI law

  1. Law on Digital Technology Industry (VN) · verified 2026-08-11 · dfdl.com
  2. Standalone AI Law (VN) · verified 2026-08-11 · connectontech.bakermckenzie.com

SG1Singaporesoft-law framework

  1. PDPA (SG) in force
    PDPA (SG) · verified 2026-08-11 · pdpc.gov.sg

TW1thinTaiwanbinding AI law passed — not yet in force

  1. AI Basic Act (TW) · verified 2026-08-11 · bakermckenzie.com

SA1Saudi Arabiabinding data/sector law only

  1. PDPL (SA) in force
    PDPL (SA) · verified 2026-08-11 · sdaia.gov.sa

EG2thinEgyptbinding data/sector law only

  1. Egypt AI Strategy 2025–2030 · verified 2026-08-11 · oecd.ai
  2. PDPL 151/2020 (EG) · verified 2026-08-11 · oecd.ai

KE2thinKenyabinding data/sector law only

  1. Data Protection Act 2019 (KE) unverified — help verify
    Data Protection Act 2019 (KE) · verified 2026-08-11 · no public source resolved
  2. Kenya AI Strategy 2025–2030 · verified 2026-08-11 · ict.go.ke

NG2Nigeriabinding data/sector law only

  1. National AI Strategy (NG) · verified 2026-08-11 · oecd.ai
  2. Nigeria Data Protection Act 2023 · verified 2026-08-11 · ndpc.gov.ng

ZA2South Africabinding data/sector law only

  1. Draft National AI Policy (ZA) withdrawn — no longer law
    Draft National AI Policy (ZA) · verified 2026-09-04 · globalcompliancenews.com
  2. POPIA (ZA) · verified 2026-08-11 · inforegulator.org.za

AF-AU1thinAfrican Union (continental)strategy only

  1. AU Continental AI Strategy · verified 2026-08-11 · au.int

Standards & frameworks

ISO/IEC
  • Application of risk management to medical devices: risk-management plan and file, hazard identification, risk estimation and control, residual-risk evaluation, benefit-risk determination and production/post-production information. It is the risk framework the MDR presumes and the natural counterpart to AI Act Art. 9 for clinical AI — one risk file, two regimes reading it.

    open in graph · published · verified 2026-08-17 · ISO
  • AI risk-management guidance extending ISO 31000 — feeds the Art. 9 risk-management system.

    open in graph · no verification date · ISO
  • Robustness assessment of neural networks incl. formal methods (part 2) — supports Art. 15 evidence.

    open in graph · no verification date · ISO
  • Information-security management; control A.8.28 (secure coding) is the natural anchor for AI code-generation and QA workflows alongside ISO 42001.

    open in graph · no verification date · ISO
  • ISO/IEC 42001:2023 — certifiable AI management system (Annex SL harmonized structure, PDCA logic, synergy discount when an ISO 27001 ISMS exists). Clauses 4–10 plus Annex A controls (control count 38 vs 39 is a live community dispute — counting method differs by edition/guide). Covers an estimated 40–50% of AI Act organizational duties; organizational certificate, no product presumption of conformity.

    open in graph · published · verified 2026-08-17 · ISO
  • Guidance for AI system impact assessments — supports DPIA/FRIA-style analyses.

    open in graph · no verification date · ISO
  • Requirements for bodies auditing/certifying AIMS — accreditation basis (e.g. DAkkS) for ISO 42001 certificates.

    open in graph · no verification date · ISO
  • Five-part data-quality framework (governance, process, management) — direct evidence path for Art. 10 representativeness and completeness.

    open in graph · no verification date · ISO
  • Assessment of machine-learning classification performance: standardized metrics, test-set discipline, reporting format. The metric backbone for Art. 15 'declared accuracy' — test reports that cite it are comparable across vendors and audits.

    open in graph · published · verified 2026-08-04 · ISO
CEN/CENELEC
DIN
  • DIN SPEC 92001-1/-2/-3

    AI life-cycle quality metamodel: functionality, robustness (adversarial & corruption), traceability/explainability — German operationalisation for Art. 15.

    open in graph · no verification date · no public source resolved
BSI
  • BSI AIC4

    AI Cloud Service Compliance Criteria Catalogue: security & robustness, performance, reliability, data management, explainability, bias — audited via ISAE 3000; vendor trust evidence.

    open in graph · no verification date · no public source resolved
  • BSI C5:2026

    Cloud compliance catalogue (168 requirements): post-quantum crypto, confidential computing, container security — infrastructure evidence layer for NIS2/CRA/Art. 15; binding baseline from June 2027.

    open in graph · no verification date · no public source resolved
  • BSI GenAI Criteria Catalogue

    Criteria for integrating external generative models via API: named AI owner, central AI register, case-by-case risk analysis, multi-stage input/output validation, least privilege, prompt/permission separation.

    open in graph · no verification date · no public source resolved
NIST
  • NIST SP 800-218 (SSDF)

    Secure Software Development Framework: practices for provenance, review and vulnerability handling of generated and third-party code; SSDF-AI companion covers AI-assisted development.

    open in graph · no verification date · no public source resolved
OWASP
  • OWASP Agentic Security (AST10 / Core Risks)

    Threat framework for autonomous agents: tool misuse, excessive agency, confused-deputy, memory poisoning — with AIVSS scoring.

    open in graph · no verification date · no public source resolved
  • The de-facto technical security standard for GenAI applications; maps to Art. 10/14/15 and ISO 42001 Annex A controls.

    open in graph · published · verified 2026-08-17 · genai.owasp.org
ENISA
  • ENISA Multilayer Framework & AI Threat Landscape

    Three-layer good-practice model (cyber foundations → AI-specific → sectoral) and lifecycle threat landscape — the operational base for Art. 15 and CRA.

    open in graph · no verification date · no public source resolved
IEEE
  • IEEE CertifAIEd™

    Ethics certification (transparency, accountability, algorithmic bias, privacy) for products and professionals; interfaces with the EU ALTAI assessment list.

    open in graph · no verification date · no public source resolved
ANSSI (France)
  • French qualification scheme for cloud providers, including immunity requirements against extraterritorial law: ownership, control and operating personnel must not place the provider under a non-EU disclosure regime. The strictest publicly available sovereignty bar in the EU and the reference point most public-sector tenders converge on.

    open in graph · no verification date · cyber.gouv.fr
BSI (Germany)
  • German federal criteria catalogue for cloud autonomy: the degree to which a cloud service can be operated, maintained and recovered without dependency on a non-EU provider's staff, tooling or control plane. Read alongside C5, which addresses security rather than autonomy — a C5-attested service can still be operationally dependent.

    open in graph · no verification date · bsi.bund.de
Coalition for Content Provenance and Authenticity
  • Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.

    open in graph · published · verified 2026-08-17 · c2pa.org
FAIR Institute
  • FAIR-AIR / FAIR-MAM

    AI extension of Factor Analysis of Information Risk: Expected Financial Loss = Loss Event Frequency (threat frequency × vulnerability) × Loss Magnitude (primary + secondary), run as Monte Carlo distributions — the standard bridge from technical AI failure modes to board-level monetary exposure.

    open in graph · no verification date · no public source resolved
Gartner
  • Gartner AI TRiSM

    AI Trust, Risk and Security Management — industry framework formalizing continuous AI oversight across four pillars: governance (inventory, AI-BOM, decision rights, change approval), trustworthiness & fairness (explainability, bias), reliability (drift, hallucination metrics), security management (prompt injection, model inversion, poisoning, leakage). No legal force; its value is the architecture it implies — the four-layer enterprise stack and the first/second-line separation this graph models as bp-trism and pat-lines-defense.

    open in graph · published · verified 2026-08-06 · no public source resolved
IASB / FASB
  • IFRS / US GAAP Reporting Assurance

    Recognition, measurement and disclosure rules that any AI-assembled financial statement, forecast or scenario model must satisfy. Model-generated figures need traceable inputs, documented assumptions and a reviewable reconciliation to the ledger before they enter a reporting cycle.

    open in graph · in-force · verified 2026-08-06 · no public source resolved
IEC
  • The base functional-safety standard: safety lifecycle, safety integrity levels (SIL) and systematic-capability requirements for electrical/electronic/programmable electronic safety-related systems. Referenced here for the safety-component reading of grid control; sector derivatives (e.g. IEC 61511, IEC 62443 for security) are not asserted as harmonised under the AI Act.

    open in graph · published · verified 2026-08-15 · webstore.iec.ch
IEC/ISO
  • Medical device software — software life-cycle processes: software safety classification (A/B/C), development planning, architecture, unit verification, integration and system testing, release, maintenance and problem resolution, and management of SOUP/off-the-shelf components. The recognised life-cycle spine for MDR software, and the process framework a notified body expects an AI-based diagnostic to be built inside.

    open in graph · published · verified 2026-08-17 · ISO
IMDA Singapore
  • IMDA Agentic AI Governance Framework (SG)

    Model AI Governance Framework for Agentic AI (Jan 2026, updated Jun 2026) — first state-issued agentic-specific guidance: bounded autonomy levels, action-space and interface restrictions, human-in-command checkpoints, automation-bias controls, logging & attribution expectations. No legal force in the EU, but the most concrete public benchmark for Art. 14-style oversight design of agent systems.

    open in graph · published · verified 2026-08-04 · no public source resolved
NIST (US)
  • NIST AI 600-1 (GenAI Profile)

    Companion profile to the AI RMF covering twelve GenAI-specific failure modes — confabulation, prompt injection, value-chain propagation and others — as the technical checklist behind Map/Measure for generative systems.

    open in graph · no verification date · no public source resolved
  • NIST AI RMF 1.0

    Govern–Map–Measure–Manage risk framework; Map/Measure functions populate the Art. 9 risk register with quantified values; the transatlantic mapping reference.

    open in graph · no verification date · no public source resolved
Open framework
  • TAGOF (Audit-as-Code)

    Operationalizes governance as code in CI/CD: policy-as-code enforcement, continuous runtime telemetry and automatically generated audit evidence — the execution layer that replaces periodic audits with continuous assurance.

    open in graph · no verification date · no public source resolved
Other publishers

How to cite RAIN

RAIN — Regulated AI Navigator, knowledge graph v2.21.0, 2026-09-22, rainavigator.org (accessed 2026-09-24).