Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 45 profiles

Standards & guidance lifecycle

A harmonised standard only shifts the burden of proof once it is cited in the Official Journal of the EU. Until then it is good practice, not a presumption of conformity. This view tracks where each standard actually stands.

Only an OJEU citation shifts the burden of proofOnly the stage 'cited in the OJEU' grants a presumption of conformity (AI Act Art. 40). Publication as an EN does not. Measured state: 0 of 9 AI Act standard candidates in this graph are cited in the Official Journal, 1 are published as EN — so no candidate currently grants a presumption of conformity.

First harmonised European standard for the AI Act

EN 18286:2026 (AI quality management, Art. 17)published 2026-07-31no presumptionprimary source

First harmonised European standard for the AI Act. Not yet cited in the OJEU, so no presumption of conformity yet.

EN 18286:2026

CEN-CENELEC JTC 21 core programme

Per-stage counts as of 2026-06 — recorded from a tracker, labelled as a secondary source, not read out of a CEN work-programme extract.

9
core deliverables
3
public enquiry
5
drafting
0
cited in the ojeu
Behind planThe standardisation request M/593 originally aimed at deliverables before the first high-risk application dates; with 0 of 9 core deliverables cited in the OJEU as of June 2026, the programme is behind that plan.

Target, not a promise: CEN target: prioritized deliverables available in Q4 2026 — a target, not a promise. Acceleration package agreed October 2025, including skipping the formal vote after a positive enquiry.

Lifecycle by stage

DraftingPublic enquiryFormal votePublished (EN)Cited in the OJEU
Drafting (4)

Working draft inside the technical committee; no public commitment on content.

  • JTC 21 Technical Package (prEN 18228/18229/18281–83)Draftingno presumptiondraft · verified 2026-08-17secondary source
    CEN/CENELEC JTC 21

    CEN-CENELEC JTC 21 technical package under standardisation request M/593 (prEN 18228 trustworthiness, 18229 risk management, 18281–83 CV/NLP evaluation et al.); staged drafts, none OJEU-cited yet — Annex III applicability (Dec 2027) is Omnibus-coupled to their availability.

    Status note: Programme node for the JTC 21 core package. Per-stage counts (9 core deliverables: 3 at enquiry, 5 in drafting, 0 OJEU-cited, as of June 2026) come from a secondary tracker and are labelled as such; CEN targets prioritized deliverables in Q4 2026 after the October 2025 acceleration package.

  • prEN 18283 (Bias Treatment)Draftingno presumptiondraft · verified 2026-08-11secondary source
    CEN/CENELEC JTC 21

    Bias-treatment deliverable of the JTC 21 core package — operational target for the Art. 10 data-governance duties on bias.

    Status note: In drafting as of June 2026. Stage from a secondary tracker, not from a CEN work-programme extract.

  • prEN 18284 (Data Sets and Data Governance)Draftingno presumptiondraft · verified 2026-08-11secondary source
    CEN/CENELEC JTC 21

    Data-set and data-governance deliverable of the JTC 21 core package — the concrete evidence path for Art. 10.

    Status note: In drafting as of June 2026. Stage from a secondary tracker, not from a CEN work-programme extract.

  • prEN ISO/IEC 12792 (Transparency Taxonomy)Draftingno presumptiondraft · verified 2026-08-04
    ISO/IEC SC 42 / CEN-CENELEC JTC 21

    Transparency taxonomy for AI systems: structured disclosure of system composition, data provenance, capabilities and limitations. The harmonised-norm candidate backing Art. 13 instructions-for-use and deployer-information duties — defines what a complete transparency package must contain.

    Status note: Draft (prEN/CD) stage taken from the JTC 21 work-programme tracker, not from a CEN work-programme extract — no sourceKind claimed.

Public enquiry (3)

Draft out for national comment; content can still change materially.

  • prEN 18228 (AI Risk Management)Public enquiryno presumptionenquiry · verified 2026-08-11secondary source
    CEN/CENELEC JTC 21

    AI risk-management requirements deliverable of the JTC 21 core package — the harmonised-standard candidate behind Art. 9.

    Status note: At enquiry; the public enquiry ran to end-July 2026. Stage from a secondary tracker (June 2026), not from a CEN work-programme extract.

  • prEN 18229-1 (Trustworthiness Framework, part 1)Public enquiryno presumptionenquiry · verified 2026-08-11secondary source
    CEN/CENELEC JTC 21

    Part 1 of the JTC 21 trustworthiness deliverable — the framework layer other prEN 18xxx documents build on.

    Status note: At enquiry as of June 2026. Stage from a secondary tracker, not from a CEN work-programme extract.

  • prEN 18282 (AI Conformity Assessment)Public enquiryno presumptionenquiry · verified 2026-08-11secondary source
    CEN/CENELEC JTC 21

    Conformity-assessment deliverable of the JTC 21 core package — the assessment procedure behind Art. 43.

    Status note: At enquiry as of June 2026. Stage from a secondary tracker, not from a CEN work-programme extract.

Formal vote (1)

Weighted vote of the national members. CEN's acceleration package allows skipping this step after a positive enquiry.

  • FprEN ISO/IEC 24970 (AI Logging)Formal voteno presumptionformal-vote · verified 2026-08-17primary source
    CEN/CENELEC JTC 21 / ISO

    Specifies event logging in AI systems — the concrete implementation target for Art. 12 record-keeping.

    Status note: ISO/IEC FDIS 24970 at stage 50.00 (FDIS registered 18 May 2026); not yet published as an International Standard. FprEN stage at CEN/CENELEC — field spec already used as de-facto target schema for Art. 12 logging.

Published (EN) (10)

Adopted and published as a European standard — usable as state of the art, but no legal presumption yet.

  • C2PA Content CredentialsPublished (EN)no presumptionpublished · verified 2026-08-17primary source
    Coalition for Content Provenance and Authenticity

    Open technical standard for cryptographically signed content provenance: manifests binding origin, toolchain and edit history to media assets. The de-facto machine-readable implementation path for Art. 50 synthetic-content marking (machine-readable format + detectability duty) — visible labels satisfy the human side, C2PA manifests the machine side. Verification at publication gates produces the disclosure evidence stream.

    Status note: Specification 2.4 (April 2026). Conformance Program and official C2PA Trust List launched mid-2025; Interim Trust List frozen 1 January 2026.

  • EN 18286:2026 (QMS for AI Act)Published (EN)no presumptionpublished · verified 2026-08-17primary source
    CEN/CENELEC JTC 21

    Harmonised-norm candidate translating Art. 17 QMS into a product-focused governance framework; mappings to ISO 9001 and ISO/IEC 42001 Annex A (Annexes C & D); published as EN 18286:2026 in July 2026, OJEU citation (and with it the presumption of conformity) still pending.

    Status note: Published 31 July 2026 — the first harmonised European standard for the AI Act (Art. 17 QMS). NOT yet cited in the Official Journal, so it does not yet confer a presumption of conformity. Re-confirmed 17 August 2026: the Commission's AI Act standardisation page (last updated 3 August 2026) still places OJEU citation after CEN-CENELEC publication and Commission assessment, and records no AI standard as cited — it describes prEN 18286 only at the 30 October 2025 public-enquiry step, so treat its process statement as authoritative and its stage statement as out of date. It does not state the negative in terms, and the Official Journal itself could NOT be checked from this environment (EUR-Lex returned a bot challenge), so no claim is made here about OJ publications during 10-17 August 2026. Status stays "published" and presumptionOfConformity stays false.

  • Gartner AI TRiSMPublished (EN)no presumptionpublished · verified 2026-08-06
    Gartner

    AI Trust, Risk and Security Management — industry framework formalizing continuous AI oversight across four pillars: governance (inventory, AI-BOM, decision rights, change approval), trustworthiness & fairness (explainability, bias), reliability (drift, hallucination metrics), security management (prompt injection, model inversion, poisoning, leakage). No legal force; its value is the architecture it implies — the four-layer enterprise stack and the first/second-line separation this graph models as bp-trism and pat-lines-defense.

    Status note: "Published" here means a vendor framework publication, not a standardisation lifecycle stage — no sourceKind claimed.

  • IEC 61508 — Functional safety of E/E/PE safety-related systemsPublished (EN)no presumptionpublished · verified 2026-08-15
    IEC

    The base functional-safety standard: safety lifecycle, safety integrity levels (SIL) and systematic-capability requirements for electrical/electronic/programmable electronic safety-related systems. Referenced here for the safety-component reading of grid control; sector derivatives (e.g. IEC 61511, IEC 62443 for security) are not asserted as harmonised under the AI Act.

  • IEC 62304:2006+AMD1:2015 (Medical device software life cycle)Published (EN)no presumptionpublished · verified 2026-08-17primary source
    IEC/ISO

    Medical device software — software life-cycle processes: software safety classification (A/B/C), development planning, architecture, unit verification, integration and system testing, release, maintenance and problem resolution, and management of SOUP/off-the-shelf components. The recognised life-cycle spine for MDR software, and the process framework a notified body expects an AI-based diagnostic to be built inside.

  • IMDA Agentic AI Governance Framework (SG)Published (EN)no presumptionpublished · verified 2026-08-04primary source
    IMDA Singapore

    Model AI Governance Framework for Agentic AI (Jan 2026, updated Jun 2026) — first state-issued agentic-specific guidance: bounded autonomy levels, action-space and interface restrictions, human-in-command checkpoints, automation-bias controls, logging & attribution expectations. No legal force in the EU, but the most concrete public benchmark for Art. 14-style oversight design of agent systems.

  • ISO 14971:2019 (Risk management for medical devices)Published (EN)no presumptionpublished · verified 2026-08-17primary source
    ISO/TC 210

    Application of risk management to medical devices: risk-management plan and file, hazard identification, risk estimation and control, residual-risk evaluation, benefit-risk determination and production/post-production information. It is the risk framework the MDR presumes and the natural counterpart to AI Act Art. 9 for clinical AI — one risk file, two regimes reading it.

  • ISO/IEC 42001:2023 (AIMS)Published (EN)no presumptionpublished · verified 2026-08-17primary source
    ISO/IEC JTC 1/SC 42

    ISO/IEC 42001:2023 — certifiable AI management system (Annex SL harmonized structure, PDCA logic, synergy discount when an ISO 27001 ISMS exists). Clauses 4–10 plus Annex A controls (control count 38 vs 39 is a live community dispute — counting method differs by edition/guide). Covers an estimated 40–50% of AI Act organizational duties; organizational certificate, no product presumption of conformity.

  • ISO/IEC TS 4213 (ML Performance Measurement)Published (EN)no presumptionpublished · verified 2026-08-04primary source
    ISO/IEC JTC 1/SC 42

    Assessment of machine-learning classification performance: standardized metrics, test-set discipline, reporting format. The metric backbone for Art. 15 'declared accuracy' — test reports that cite it are comparable across vendors and audits.

    Status note: Published as Technical Specification (TS 4213:2022); evolution toward a full International Standard tracked via the currency sweep.

  • OWASP Top 10 for LLM Apps (2026)Published (EN)no presumptionpublished · verified 2026-08-17primary source
    OWASP

    The de-facto technical security standard for GenAI applications; maps to Art. 10/14/15 and ISO 42001 Annex A controls.

    Status note: OWASP Top 10 for LLM Applications 2026, released 3 August 2026 and described by OWASP as the latest community-driven guide, with updated rankings, expanded threat coverage and mappings to NIST, MITRE ATLAS, CWE and the OWASP Top 10 for Agentic Applications; OWASP continues to list the 2025 and 2023/24 editions separately. The release page does not enumerate the ten entries, does not state a version number and does not state supersession in terms — the individual risk entries in this node have NOT been re-verified against the 2026 text and must not be renumbered or restated until the 2026 PDF is read.

No stage recorded (35)

Frameworks and guidance documents outside the European standardisation pipeline, plus open verification debt. Listed rather than hidden. help record their stage →

  • AI Verify + Project Moonshot (SG)
  • ANSSI SecNumCloud
  • BSI AIC4
  • BSI C3A (Criteria for Cloud Computing Autonomy)
  • BSI C5:2026
  • BSI GenAI Criteria Catalogue
  • DIN SPEC 92001-1/-2/-3
  • EN ISO/IEC 22989 (AI Concepts)
  • ENISA Multilayer Framework & AI Threat Landscape
  • FAIR-AIR / FAIR-MAM
  • G7 Hiroshima Code of Conduct
  • ICO Guidance on AI and Data Protection (GB)
  • IEEE CertifAIEd™
  • IFRS / US GAAP Reporting Assurance
  • India AI Governance Guidelines (MeitY)
  • ISO/IEC 23894 (AI Risk Management)
  • ISO/IEC 24029 (NN Robustness)
  • ISO/IEC 27001:2022 + A.8.28
  • ISO/IEC 42005 (AI Impact Assessment)
  • ISO/IEC 42006 (Audit Bodies)
  • ISO/IEC 5259 (Data Quality for ML)
  • MAS FEAT Principles + Veritas (SG)
  • METI/MIC AI Guidelines for Business v1.0 (JP)
  • Model AI Governance Framework for Generative AI (SG)
  • Model AI Governance Framework, 2nd ed. (SG)
  • NIST AI 600-1 (GenAI Profile)
  • NIST AI RMF 1.0
  • NIST SP 800-218 (SSDF)
  • OECD AI Principles
  • OWASP Agentic Security (AST10 / Core Risks)
  • Pro-innovation AI framework (GB)
  • SDAIA AI Ethics Principles v2 + GenAI Guidelines (SA)
  • TAGOF (Audit-as-Code)
  • UAE AI Charter + National AI Strategy 2031
  • Voluntary AI Safety Standard (AU)

Enforcement infrastructure

8 / 27
Member States that had notified a single point of contact (as of 2026-03; deadline was 2025-08-02)

As of March 2026 only 8 of 27 Member States had notified their single point of contact; the deadline was 2 August 2025.

secondary source
unknown
AI Act notified bodies — no authoritative public count

No authoritative public count of AI Act notified bodies exists. We render this as unknown rather than quoting a number from a secondary aggregation.

Application dates as fixed by the Digital Omnibus

Regulation (EU) 2026/1744 (Digital Omnibus) — in force since 2026-07-27. Council adoption 29 June 2026, published in the Official Journal 24 July 2026. primary source

These high-risk application dates are fixed by the Omnibus; the graph's AI Act timeline is reconciled against this act. 2 December 2026 is NOT the Art. 50 application date: Art. 50 applies from 2 August 2026. 2 December 2026 carries two narrower meanings, kept separate above — the end of the Art. 50(2) marking grace period for generative systems placed on the market before 2 August 2026, and the application date of the two new Art. 5 prohibitions.

General-purpose AI

GPAI model obligations have been applicable since 2 August 2025; the GPAI Code of Practice was published on 10 July 2025 with 21 signatories. primary source

What the watch walker is looking for

Proposed changes land in the curator queue — see the agent run reports → · regulatory calendar → · incident-reporting router →

Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.