{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/crosswalk.json",
  "self": "https://aigovernanceengineer.com/api/v1/crosswalk.json",
  "source": "https://aigovernanceengineer.com/resources/crosswalk",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "topics": [
    {
      "id": "risk-management",
      "name": "Risk management",
      "summary": "Identifying, analysing and treating AI risks across the lifecycle, and keeping the treatment current as the system and its context change.",
      "layers": [
        1,
        3
      ]
    },
    {
      "id": "governance-accountability",
      "name": "Governance and accountability",
      "summary": "The policies, roles and accountability structures that put a named owner behind every AI decision and control.",
      "layers": [
        1
      ]
    },
    {
      "id": "impact-assessment",
      "name": "Impact assessment",
      "summary": "Assessing an AI system's impact on fundamental rights, individuals and society before and during deployment.",
      "layers": [
        1,
        2
      ]
    },
    {
      "id": "data-governance",
      "name": "Data governance",
      "summary": "Governing the data an AI system trains on and processes: lawful sourcing, quality, lineage and protection of personal and input data.",
      "layers": [
        2,
        3
      ]
    },
    {
      "id": "documentation-transparency",
      "name": "Documentation and transparency",
      "summary": "Technical documentation, disclosures and content labelling that make an AI system legible to regulators, deployers and users.",
      "layers": [
        2
      ]
    },
    {
      "id": "inventory-registration",
      "name": "Inventory and registration",
      "summary": "Keeping an inventory of AI systems and agents and, where required, registering or filing them with the authorities.",
      "layers": [
        2
      ]
    },
    {
      "id": "logging-traceability",
      "name": "Logging and traceability",
      "summary": "Automatic, tamper-evident logs and records that make an AI system's behaviour reconstructable after the fact.",
      "layers": [
        4
      ]
    },
    {
      "id": "human-oversight",
      "name": "Human oversight",
      "summary": "Human-in-the-loop checkpoints, approval gates and the ability to intervene in or stop an AI system.",
      "layers": [
        4
      ]
    },
    {
      "id": "runtime-guardrails",
      "name": "Runtime guardrails",
      "summary": "Controls that constrain an AI system while it runs: input/output filtering, tool-invocation limits, isolation and memory management.",
      "layers": [
        4
      ]
    },
    {
      "id": "robustness-security-evals",
      "name": "Robustness, security and evaluations",
      "summary": "Testing an AI system for accuracy, robustness, security and adversarial failure, including red-teaming and sandbox validation.",
      "layers": [
        3,
        4
      ]
    },
    {
      "id": "incident-monitoring",
      "name": "Incident response and monitoring",
      "summary": "Post-market monitoring, incident detection and reporting, and the complaint channels that surface real-world failures.",
      "layers": [
        5
      ]
    },
    {
      "id": "supply-chain",
      "name": "Supply chain and third parties",
      "summary": "Allocating responsibility along the AI value chain and managing risks from third-party models, data, tools and technical supporters.",
      "layers": [
        2,
        5
      ]
    },
    {
      "id": "prohibited-practices",
      "name": "Prohibited practices",
      "summary": "Uses of AI that a jurisdiction bans outright or a framework treats as unacceptable, and the intake controls that keep them out of the portfolio.",
      "layers": [
        1
      ]
    },
    {
      "id": "fairness-non-discrimination",
      "name": "Fairness and non-discrimination",
      "summary": "Detecting and correcting bias in data, models and outcomes, and the lawful handling of the sensitive data that bias testing needs.",
      "layers": [
        2,
        3
      ]
    },
    {
      "id": "privacy-data-protection",
      "name": "Privacy and data protection",
      "summary": "Lawful basis, minimisation, privacy by design and the privacy attacks specific to models, wherever an AI system touches personal data.",
      "layers": [
        1,
        2,
        4
      ]
    },
    {
      "id": "explainability",
      "name": "Explainability and right to explanation",
      "summary": "Explaining a model and an individual output to the people who use it or are affected by it, and the legal rights to an explanation and to contest.",
      "layers": [
        2,
        4
      ]
    },
    {
      "id": "ai-literacy",
      "name": "AI literacy and competence",
      "summary": "Making sure the people who build, operate, oversee and use an AI system have the knowledge their role needs, with a record that shows it.",
      "layers": [
        1
      ]
    },
    {
      "id": "conformity-assessment",
      "name": "Conformity assessment and certification",
      "summary": "Demonstrating conformity before market entry, independent audit and certification, and the standards that carry a presumption of conformity.",
      "layers": [
        5
      ]
    },
    {
      "id": "gpai-foundation-models",
      "name": "GPAI and foundation models",
      "summary": "Duties that attach to general-purpose and foundation models themselves: documentation for downstream providers, evaluation, and systemic-risk management.",
      "layers": [
        2,
        3
      ]
    },
    {
      "id": "ip-copyright",
      "name": "IP and copyright",
      "summary": "Lawful access to training content, honouring rights reservations, and keeping outputs from reproducing protected works.",
      "layers": [
        2
      ]
    },
    {
      "id": "agent-identity-autonomy",
      "name": "Agent identity and autonomy",
      "summary": "Giving each agent its own identity and scoped permissions, bounding what it may do on its own, and keeping a human able to stop it.",
      "layers": [
        2,
        4
      ]
    },
    {
      "id": "content-provenance",
      "name": "Content provenance and deepfakes",
      "summary": "Marking synthetic content so it can be detected, labelling deepfakes for the people who see them, and verifying where content came from.",
      "layers": [
        2,
        4
      ]
    },
    {
      "id": "sandboxes-real-world-testing",
      "name": "Sandboxes and real-world testing",
      "summary": "Supervised regulatory sandboxes and testing in real-world conditions, with the plans, consent records and reversal paths they require.",
      "layers": [
        3
      ]
    },
    {
      "id": "environmental-impact",
      "name": "Environmental impact",
      "summary": "Measuring and reporting the energy and resource use of training and running AI systems, and weighing it in design decisions.",
      "layers": [
        2,
        5
      ]
    },
    {
      "id": "deployment-change-decommissioning",
      "name": "Deployment, change and decommissioning",
      "summary": "Putting a system into service, controlling changes that alter its risk, and withdrawing or retiring it safely when it no longer performs as intended.",
      "layers": [
        4,
        5
      ]
    }
  ],
  "columns": [
    {
      "id": "eu",
      "label": "EU AI Act",
      "frameworks": [
        "eu-ai-act"
      ]
    },
    {
      "id": "gpai",
      "label": "GPAI Code",
      "frameworks": [
        "gpai-code-of-practice"
      ]
    },
    {
      "id": "gdpr",
      "label": "GDPR",
      "frameworks": [
        "gdpr"
      ]
    },
    {
      "id": "iso",
      "label": "ISO/IEC 42001",
      "frameworks": [
        "iso-42001"
      ]
    },
    {
      "id": "iso-more",
      "label": "ISO/IEC 42005 · 23894 · 42006",
      "frameworks": [
        "iso-42005",
        "iso-23894",
        "iso-42006"
      ]
    },
    {
      "id": "nist",
      "label": "NIST AI RMF",
      "frameworks": [
        "nist-ai-rmf"
      ]
    },
    {
      "id": "csa",
      "label": "CSA AICM",
      "frameworks": [
        "csa-aicm"
      ]
    },
    {
      "id": "owasp",
      "label": "OWASP GenAI",
      "frameworks": [
        "owasp-llm-top-10",
        "owasp-agentic-top-10"
      ]
    },
    {
      "id": "kr",
      "label": "Korea AI Basic Act",
      "frameworks": [
        "kr-ai-basic-act"
      ]
    },
    {
      "id": "uk",
      "label": "United Kingdom",
      "frameworks": [
        "uk-duaa",
        "uk-atrs"
      ]
    },
    {
      "id": "sg",
      "label": "Singapore",
      "frameworks": [
        "sg-genai-framework",
        "sg-agentic-framework"
      ]
    },
    {
      "id": "intl",
      "label": "Treaty and soft law",
      "frameworks": [
        "coe-cets-225",
        "oecd-ai-principles",
        "g7-hiroshima-coc"
      ]
    },
    {
      "id": "gao",
      "label": "GAO AI Accountability",
      "frameworks": [
        "us-gao-ai-accountability"
      ]
    },
    {
      "id": "cen",
      "label": "CEN-CENELEC",
      "frameworks": [
        "en-18286",
        "pren-18228",
        "pren-18229-1"
      ]
    },
    {
      "id": "cn",
      "label": "China",
      "frameworks": [
        "cn-tc260-framework",
        "cn-genai-measures",
        "cn-deep-synthesis",
        "cn-algo-recommendation",
        "cn-content-labelling",
        "cn-gbt-45654"
      ]
    }
  ],
  "references": [
    {
      "topic": "risk-management",
      "framework": "eu-ai-act",
      "reference": "Art. 9",
      "label": "Art. 9",
      "title": "Risk management system",
      "strength": "core",
      "verified": true,
      "note": "Iterative, lifecycle risk management; the backbone of the risk register.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9",
      "obligationId": "AIGE-OBL-EUAIA-ART9"
    },
    {
      "topic": "risk-management",
      "framework": "iso-42001",
      "reference": "6.1.2",
      "label": "6.1.2",
      "title": "AI risk assessment",
      "strength": "core",
      "verified": true,
      "note": "Planning-stage AI risk assessment.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "iso-42001",
      "reference": "6.1.3",
      "label": "6.1.3",
      "title": "AI risk treatment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "iso-42001",
      "reference": "8.2",
      "label": "8.2",
      "title": "AI risk assessment (operation)",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "iso-42001",
      "reference": "8.3",
      "label": "8.3",
      "title": "AI risk treatment (operation)",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "iso-42001",
      "reference": "A.6",
      "label": "A.6",
      "title": "AI system life cycle",
      "strength": "related",
      "verified": true,
      "note": "Lifecycle controls operationalise the risk treatment.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MAP 1",
      "label": "MAP 1",
      "title": "MAP 1: Context is established and understood",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MAP 5",
      "label": "MAP 5",
      "title": "MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 1",
      "label": "MANAGE 1",
      "title": "MANAGE 1: AI risks based on assessments and other analytical output are prioritized, responded to, and managed",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2",
      "label": "MEASURE 2",
      "title": "MEASURE 2: AI systems are evaluated for trustworthy characteristics",
      "strength": "related",
      "verified": true,
      "note": "Measurement feeds the risk picture.",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "risk-management",
      "framework": "cn-tc260-framework",
      "reference": "2",
      "label": "TC260 2",
      "title": "Classification of AI safety risks",
      "strength": "core",
      "verified": true,
      "note": "Three-way taxonomy: inherent / application / secondary (derivative) safety risks; printed p. 54.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "risk-management",
      "framework": "cn-tc260-framework",
      "reference": "Summary table",
      "label": "TC260 Summary table",
      "title": "Risks × technological × governance measures",
      "strength": "core",
      "verified": true,
      "note": "Maps each risk class to its countermeasures; printed pp. 107-108.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "risk-management",
      "framework": "cn-tc260-framework",
      "reference": "5.3.19",
      "label": "TC260 5.3.19",
      "title": "Re-assessment on material change",
      "strength": "related",
      "verified": true,
      "note": "Re-run the risk assessment when the system materially changes; printed p. 104.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "risk-management",
      "framework": "cn-genai-measures",
      "reference": "Art. 17",
      "label": "GenAI Art. 17",
      "title": "Security assessment and algorithm filing",
      "strength": "related",
      "verified": true,
      "note": "Security assessment for services with public-opinion attributes; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "risk-management",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 27",
      "label": "AlgoRec Art. 27",
      "title": "Security assessment",
      "strength": "related",
      "verified": true,
      "note": "Security assessment for recommendation services with public-opinion or social-mobilization capacity; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "governance-accountability",
      "framework": "eu-ai-act",
      "reference": "Art. 17",
      "label": "Art. 17",
      "title": "Quality management system",
      "strength": "core",
      "verified": true,
      "note": "The QMS that assigns and documents responsibilities.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_17",
      "obligationId": "AIGE-OBL-EUAIA-ART17"
    },
    {
      "topic": "governance-accountability",
      "framework": "eu-ai-act",
      "reference": "Art. 4",
      "label": "Art. 4",
      "title": "AI literacy",
      "strength": "related",
      "verified": true,
      "note": "Staff competence underpins accountable operation.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4",
      "obligationId": "AIGE-OBL-EUAIA-ART4"
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "5.1",
      "label": "5.1",
      "title": "Leadership and commitment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "5.2",
      "label": "5.2",
      "title": "AI policy",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "5.3",
      "label": "5.3",
      "title": "Roles, responsibilities and authorities",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "A.2",
      "label": "A.2",
      "title": "Policies related to AI",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A2"
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "A.3",
      "label": "A.3",
      "title": "Internal organization",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A3"
    },
    {
      "topic": "governance-accountability",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 1",
      "label": "GOVERN 1",
      "title": "GOVERN 1: Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "governance-accountability",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 2",
      "label": "GOVERN 2",
      "title": "GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "governance-accountability",
      "framework": "cn-tc260-framework",
      "reference": "4",
      "label": "TC260 4",
      "title": "Comprehensive governance measures",
      "strength": "core",
      "verified": true,
      "note": "Organisational and institutional governance measures; printed p. 85.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "governance-accountability",
      "framework": "cn-tc260-framework",
      "reference": "5.3.12",
      "label": "TC260 5.3.12",
      "title": "Traceable chain of responsibility",
      "strength": "core",
      "verified": true,
      "note": "A traceable responsibility chain across the lifecycle; printed p. 103.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "governance-accountability",
      "framework": "cn-genai-measures",
      "reference": "Art. 9",
      "label": "GenAI Art. 9",
      "title": "Provider responsibility as content producer",
      "strength": "core",
      "verified": true,
      "note": "Providers bear network-information content-producer responsibility; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "governance-accountability",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 7",
      "label": "AlgoRec Art. 7",
      "title": "Algorithm-security responsibility system",
      "strength": "core",
      "verified": true,
      "note": "Providers establish algorithm-security management systems; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "governance-accountability",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 7",
      "label": "DeepSyn Art. 7",
      "title": "Information-security responsibility system",
      "strength": "core",
      "verified": true,
      "note": "Providers establish management systems (registration, review, ethics, data and personal-information protection); CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "impact-assessment",
      "framework": "eu-ai-act",
      "reference": "Art. 27",
      "label": "Art. 27",
      "title": "Fundamental rights impact assessment for high-risk AI systems",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-fria-as-code",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_27",
      "obligationId": "AIGE-OBL-EUAIA-ART27"
    },
    {
      "topic": "impact-assessment",
      "framework": "eu-ai-act",
      "reference": "Art. 9",
      "label": "Art. 9",
      "title": "Risk management system",
      "strength": "related",
      "verified": true,
      "note": "Risk management and the FRIA cross-reference each other.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9",
      "obligationId": "AIGE-OBL-EUAIA-ART9"
    },
    {
      "topic": "impact-assessment",
      "framework": "iso-42001",
      "reference": "6.1.4",
      "label": "6.1.4",
      "title": "AI system impact assessment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "iso-42001",
      "reference": "8.4",
      "label": "8.4",
      "title": "AI system impact assessment (operation)",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "iso-42001",
      "reference": "A.5",
      "label": "A.5",
      "title": "Assessing impacts of AI systems",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-fria-as-code",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A5"
    },
    {
      "topic": "impact-assessment",
      "framework": "nist-ai-rmf",
      "reference": "MAP 3",
      "label": "MAP 3",
      "title": "MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs are understood",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "impact-assessment",
      "framework": "nist-ai-rmf",
      "reference": "MAP 5",
      "label": "MAP 5",
      "title": "MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "impact-assessment",
      "framework": "cn-tc260-framework",
      "reference": "Appendix 1",
      "label": "TC260 Appendix 1",
      "title": "Grading principles",
      "strength": "core",
      "verified": true,
      "note": "Grading principles for classifying risk; printed pp. 109-112.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "impact-assessment",
      "framework": "cn-tc260-framework",
      "reference": "2.2",
      "label": "TC260 2.2",
      "title": "Safety risks in the application of AI",
      "strength": "related",
      "verified": true,
      "note": "Application-layer risks to assess (agentic, embodied, cybersecurity, content, personal information, real-world); printed p. 60.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "impact-assessment",
      "framework": "cn-genai-measures",
      "reference": "Art. 17",
      "label": "GenAI Art. 17",
      "title": "Security assessment",
      "strength": "core",
      "verified": true,
      "note": "Pre-deployment security assessment for public-opinion services; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "data-governance",
      "framework": "eu-ai-act",
      "reference": "Art. 10",
      "label": "Art. 10",
      "title": "Data and data governance",
      "strength": "core",
      "verified": true,
      "note": "Training, validation and test data quality and governance.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
      "obligationId": "AIGE-OBL-EUAIA-ART10"
    },
    {
      "topic": "data-governance",
      "framework": "eu-ai-act",
      "reference": "Art. 4a",
      "label": "Art. 4a",
      "title": "Special-category data for bias detection",
      "strength": "related",
      "verified": true,
      "note": "Post-Omnibus new article: a lawful basis to process special-category data to detect and correct bias.",
      "url": null,
      "obligationId": "AIGE-OBL-EUAIA-ART4A"
    },
    {
      "topic": "data-governance",
      "framework": "iso-42001",
      "reference": "A.7",
      "label": "A.7",
      "title": "Data for AI systems",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A7"
    },
    {
      "topic": "data-governance",
      "framework": "iso-42001",
      "reference": "A.4",
      "label": "A.4",
      "title": "Resources for AI systems",
      "strength": "related",
      "verified": true,
      "note": "Data as a governed resource.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A4"
    },
    {
      "topic": "data-governance",
      "framework": "nist-ai-rmf",
      "reference": "MAP 2",
      "label": "MAP 2",
      "title": "MAP 2: Categorization of the AI system is performed",
      "strength": "related",
      "verified": true,
      "note": "Data categorisation and provenance.",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "data-governance",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.10",
      "label": "MEASURE 2.10",
      "title": "MEASURE 2.10: Privacy risk of the AI system is examined and documented",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "data-governance",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.11",
      "label": "MEASURE 2.11",
      "title": "MEASURE 2.11: Fairness and bias are evaluated and results are documented",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "data-governance",
      "framework": "cn-tc260-framework",
      "reference": "2.1.3",
      "label": "TC260 2.1.3",
      "title": "Data safety risks",
      "strength": "core",
      "verified": true,
      "note": "Inherent data risks (quality, poisoning, leakage); printed p. 57.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "data-governance",
      "framework": "cn-tc260-framework",
      "reference": "5.1",
      "label": "TC260 5.1",
      "title": "Model R&D safety guidelines",
      "strength": "related",
      "verified": true,
      "note": "Training-data governance during model R&D; printed p. 95.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "data-governance",
      "framework": "cn-genai-measures",
      "reference": "Art. 7",
      "label": "GenAI Art. 7",
      "title": "Training-data lawful sourcing",
      "strength": "core",
      "verified": true,
      "note": "Lawful sources, IP and personal-information compliance for training data; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "data-governance",
      "framework": "cn-genai-measures",
      "reference": "Art. 8",
      "label": "GenAI Art. 8",
      "title": "Data-annotation standards",
      "strength": "core",
      "verified": true,
      "note": "Clear, specific annotation rules and quality checks; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "data-governance",
      "framework": "cn-genai-measures",
      "reference": "Art. 11",
      "label": "GenAI Art. 11",
      "title": "Protection of user input and records",
      "strength": "core",
      "verified": true,
      "note": "No unlawful retention of user input and usage records; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "data-governance",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 14",
      "label": "DeepSyn Art. 14",
      "title": "Training-data management",
      "strength": "core",
      "verified": true,
      "note": "Providers and technical supporters secure training data and personal information; CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "data-governance",
      "framework": "cn-gbt-45654",
      "reference": "Corpus security",
      "label": "GB/T 45654 Corpus security",
      "title": "Training-corpus (data) security requirements",
      "strength": "core",
      "verified": false,
      "note": "GB/T 45654-2025 corpus-security requirements (TC260-003 predecessor §5). The official listing shows the standard as current (issued 2025-04-25, implemented 2025-11-01; checked 2026-09-24), but the full text is only offered there as an image preview, so the clause id is not verified against it.",
      "url": "https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F67D3F376E0A0A0FF5317FB36B32A30A",
      "obligationId": "AIGE-OBL-CN-GBT45654"
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 11",
      "label": "Art. 11",
      "title": "Technical documentation",
      "strength": "core",
      "verified": true,
      "note": "Annex IV technical documentation.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_11",
      "obligationId": "AIGE-OBL-EUAIA-ART11"
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 13",
      "label": "Art. 13",
      "title": "Transparency and provision of information to deployers",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_13",
      "obligationId": "AIGE-OBL-EUAIA-ART13"
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 53",
      "label": "Art. 53",
      "title": "Obligations for providers of general-purpose AI models",
      "strength": "core",
      "verified": true,
      "note": "Model documentation and training-content summary for GPAI providers.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
      "obligationId": "AIGE-OBL-EUAIA-ART53"
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 50",
      "label": "Art. 50",
      "title": "Transparency obligations for providers and deployers of certain AI systems",
      "strength": "related",
      "verified": true,
      "note": "User-facing disclosure and machine-readable content marking.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_50",
      "obligationId": "AIGE-OBL-EUAIA-ART50"
    },
    {
      "topic": "documentation-transparency",
      "framework": "iso-42001",
      "reference": "7.5",
      "label": "7.5",
      "title": "Documented information",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "iso-42001",
      "reference": "A.6",
      "label": "A.6",
      "title": "AI system life cycle",
      "strength": "core",
      "verified": true,
      "note": "Lifecycle documentation.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "documentation-transparency",
      "framework": "iso-42001",
      "reference": "A.8",
      "label": "A.8",
      "title": "Information for interested parties",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A8"
    },
    {
      "topic": "documentation-transparency",
      "framework": "nist-ai-rmf",
      "reference": "MAP 1",
      "label": "MAP 1",
      "title": "MAP 1: Context is established and understood",
      "strength": "related",
      "verified": true,
      "note": "Documenting context and intended use.",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "documentation-transparency",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.8",
      "label": "MEASURE 2.8",
      "title": "MEASURE 2.8: Risks associated with transparency and accountability are examined and documented",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-content-labelling",
      "reference": "Art. 4",
      "label": "Label Art. 4",
      "title": "Explicit labels for generated content",
      "strength": "core",
      "verified": true,
      "note": "Visible labels on AI-generated and synthetic content; CAC text.",
      "url": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
      "obligationId": "AIGE-OBL-CN-LABEL"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-content-labelling",
      "reference": "Art. 5",
      "label": "Label Art. 5",
      "title": "Implicit (metadata) labels",
      "strength": "core",
      "verified": true,
      "note": "Implicit labels embedded in file metadata; CAC text.",
      "url": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
      "obligationId": "AIGE-OBL-CN-LABEL"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-genai-measures",
      "reference": "Art. 12",
      "label": "GenAI Art. 12",
      "title": "Labelling of generated content",
      "strength": "core",
      "verified": true,
      "note": "Label generated images and video per the Deep Synthesis rules; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-genai-measures",
      "reference": "Art. 19",
      "label": "GenAI Art. 19",
      "title": "Disclosure to regulators",
      "strength": "related",
      "verified": true,
      "note": "Disclose training-data sources, scale and labelling mechanisms on request; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 16",
      "label": "DeepSyn Art. 16",
      "title": "Implicit technical labels",
      "strength": "core",
      "verified": true,
      "note": "Non-disruptive technical marks on synthetic content; CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 17",
      "label": "DeepSyn Art. 17",
      "title": "Conspicuous labels for confusable content",
      "strength": "core",
      "verified": true,
      "note": "Prominent labels where synthetic media could mislead; CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 16",
      "label": "AlgoRec Art. 16",
      "title": "Notice that recommendation is used",
      "strength": "related",
      "verified": true,
      "note": "Conspicuously inform users that algorithmic recommendation is in use; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "documentation-transparency",
      "framework": "cn-gbt-45654",
      "reference": "Content labelling",
      "label": "GB/T 45654 Content labelling",
      "title": "Generated-content labelling requirements",
      "strength": "related",
      "verified": false,
      "note": "GB/T 45654-2025 content-labelling requirements (aligned with the 2025 Labelling Measures). The official listing shows the standard as current (issued 2025-04-25, implemented 2025-11-01; checked 2026-09-24), but the full text is only offered there as an image preview, so the clause id is not verified against it.",
      "url": "https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F67D3F376E0A0A0FF5317FB36B32A30A",
      "obligationId": "AIGE-OBL-CN-GBT45654"
    },
    {
      "topic": "inventory-registration",
      "framework": "eu-ai-act",
      "reference": "Art. 49",
      "label": "Art. 49",
      "title": "Registration",
      "strength": "core",
      "verified": true,
      "note": "Registration of high-risk systems in the EU database.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_49",
      "obligationId": "AIGE-OBL-EUAIA-ART49-71"
    },
    {
      "topic": "inventory-registration",
      "framework": "eu-ai-act",
      "reference": "Art. 71",
      "label": "Art. 71",
      "title": "EU database for high-risk AI systems",
      "strength": "core",
      "verified": true,
      "note": "The EU database that registration feeds.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_71",
      "obligationId": "AIGE-OBL-EUAIA-ART49-71"
    },
    {
      "topic": "inventory-registration",
      "framework": "eu-ai-act",
      "reference": "Art. 6",
      "label": "Art. 6",
      "title": "Classification rules for high-risk AI systems",
      "strength": "related",
      "verified": true,
      "note": "Classification decides what must be registered.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_6",
      "obligationId": "AIGE-OBL-EUAIA-ART6"
    },
    {
      "topic": "inventory-registration",
      "framework": "iso-42001",
      "reference": "A.4",
      "label": "A.4",
      "title": "Resources for AI systems",
      "strength": "core",
      "verified": true,
      "note": "Resource and asset inventory of AI systems.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A4"
    },
    {
      "topic": "inventory-registration",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 1.6",
      "label": "GOVERN 1.6",
      "title": "GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-agent-registry",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "inventory-registration",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 24",
      "label": "AlgoRec Art. 24",
      "title": "Algorithm filing",
      "strength": "core",
      "verified": true,
      "note": "File within ten working days via the algorithm-filing system (public-opinion services); CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "inventory-registration",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 19",
      "label": "DeepSyn Art. 19",
      "title": "Filing for public-opinion services",
      "strength": "core",
      "verified": true,
      "note": "Filing per the Algorithm Recommendation rules; CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "inventory-registration",
      "framework": "cn-genai-measures",
      "reference": "Art. 17",
      "label": "GenAI Art. 17",
      "title": "Algorithm filing",
      "strength": "core",
      "verified": true,
      "note": "Algorithm filing alongside the security assessment; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "inventory-registration",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.2",
      "label": "TC260 App. 2 II.2",
      "title": "Identity and access management",
      "strength": "related",
      "verified": true,
      "note": "Identity and permissions per agent; printed pp. 120-121.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "inventory-registration",
      "framework": "cn-tc260-framework",
      "reference": "4.4.1",
      "label": "TC260 4.4.1",
      "title": "CII registration and filing",
      "strength": "related",
      "verified": true,
      "note": "Registration/filing for critical information infrastructure; printed p. 91.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "logging-traceability",
      "framework": "eu-ai-act",
      "reference": "Art. 12",
      "label": "Art. 12",
      "title": "Record-keeping",
      "strength": "core",
      "verified": true,
      "note": "Automatic logging over the system lifetime.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_12",
      "obligationId": "AIGE-OBL-EUAIA-ART12"
    },
    {
      "topic": "logging-traceability",
      "framework": "eu-ai-act",
      "reference": "Art. 26",
      "label": "Art. 26",
      "title": "Obligations of deployers of high-risk AI systems",
      "strength": "related",
      "verified": true,
      "note": "Deployers keep the logs the system generates.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
      "obligationId": "AIGE-OBL-EUAIA-ART26"
    },
    {
      "topic": "logging-traceability",
      "framework": "iso-42001",
      "reference": "A.6",
      "label": "A.6",
      "title": "AI system life cycle",
      "strength": "core",
      "verified": true,
      "note": "Lifecycle event logs.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "logging-traceability",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 4",
      "label": "MANAGE 4",
      "title": "MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "logging-traceability",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 3",
      "label": "MEASURE 3",
      "title": "MEASURE 3: Mechanisms for tracking identified AI risks over time are in place",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "logging-traceability",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.6",
      "label": "TC260 App. 2 II.6",
      "title": "Continuous monitoring and auditing",
      "strength": "core",
      "verified": true,
      "note": "Log management and auditing for agents; printed pp. 124-125.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "logging-traceability",
      "framework": "cn-tc260-framework",
      "reference": "5.3.6",
      "label": "TC260 5.3.6",
      "title": "Logs kept and audited",
      "strength": "core",
      "verified": true,
      "note": "Keep logs at least six months and audit them; printed p. 102.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "logging-traceability",
      "framework": "cn-content-labelling",
      "reference": "Art. 5",
      "label": "Label Art. 5",
      "title": "Implicit metadata labels",
      "strength": "related",
      "verified": true,
      "note": "Metadata labels support content traceability; CAC text.",
      "url": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
      "obligationId": "AIGE-OBL-CN-LABEL"
    },
    {
      "topic": "human-oversight",
      "framework": "eu-ai-act",
      "reference": "Art. 14",
      "label": "Art. 14",
      "title": "Human oversight",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-human-in-the-loop-gate",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_14",
      "obligationId": "AIGE-OBL-EUAIA-ART14"
    },
    {
      "topic": "human-oversight",
      "framework": "eu-ai-act",
      "reference": "Art. 26",
      "label": "Art. 26",
      "title": "Obligations of deployers of high-risk AI systems",
      "strength": "related",
      "verified": true,
      "note": "Deployers assign the humans who oversee the system.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
      "obligationId": "AIGE-OBL-EUAIA-ART26"
    },
    {
      "topic": "human-oversight",
      "framework": "iso-42001",
      "reference": "A.9",
      "label": "A.9",
      "title": "Use of AI systems",
      "strength": "core",
      "verified": true,
      "note": "Oversight of AI systems in use.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A9"
    },
    {
      "topic": "human-oversight",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 2.4",
      "label": "MANAGE 2.4",
      "title": "MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-human-in-the-loop-gate",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "human-oversight",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 3.2",
      "label": "GOVERN 3.2",
      "title": "GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "human-oversight",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.3",
      "label": "TC260 App. 2 II.3",
      "title": "Strengthen human approval",
      "strength": "core",
      "verified": true,
      "note": "Human approval checkpoints, tamper-proof approval logs, deny-by-default; printed pp. 121-122.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "human-oversight",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 17",
      "label": "AlgoRec Art. 17",
      "title": "User option to switch off",
      "strength": "related",
      "verified": true,
      "note": "Users can opt out of algorithmic recommendation; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "human-oversight",
      "framework": "cn-genai-measures",
      "reference": "Art. 10",
      "label": "GenAI Art. 10",
      "title": "User guidance and protection",
      "strength": "related",
      "verified": true,
      "note": "Disclose scope of use and protect minors from over-reliance; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "eu-ai-act",
      "reference": "Art. 5",
      "label": "Art. 5",
      "title": "Prohibited AI practices",
      "strength": "related",
      "verified": true,
      "note": "Prohibitions enforced as input/output guardrails.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5",
      "obligationId": "AIGE-OBL-EUAIA-ART5"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "eu-ai-act",
      "reference": "Art. 15",
      "label": "Art. 15",
      "title": "Accuracy, robustness and cybersecurity",
      "strength": "related",
      "verified": true,
      "note": "Robustness and security controls that also act at runtime.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_15",
      "obligationId": "AIGE-OBL-EUAIA-ART15"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "iso-42001",
      "reference": "A.9",
      "label": "A.9",
      "title": "Use of AI systems",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-runtime-guardrail",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A9"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "iso-42001",
      "reference": "A.6",
      "label": "A.6",
      "title": "AI system life cycle",
      "strength": "related",
      "verified": true,
      "note": "Operational controls in the run phase.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 2",
      "label": "MANAGE 2",
      "title": "MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by relevant AI actors",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-runtime-guardrail",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.5",
      "label": "TC260 App. 2 II.5",
      "title": "Dynamic runtime management",
      "strength": "core",
      "verified": true,
      "note": "Runtime guardrails, memory isolation and sandbox isolation for agents; printed pp. 123-124.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "cn-tc260-framework",
      "reference": "3.2.1",
      "label": "TC260 3.2.1",
      "title": "Technological countermeasures for agentic AI",
      "strength": "core",
      "verified": true,
      "note": "Agentic-AI technical countermeasures; printed p. 77.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "cn-genai-measures",
      "reference": "Art. 10",
      "label": "GenAI Art. 10",
      "title": "Guided, bounded use",
      "strength": "core",
      "verified": true,
      "note": "Bound the service scope and guide reasonable use; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "cn-genai-measures",
      "reference": "Art. 14",
      "label": "GenAI Art. 14",
      "title": "Stop unlawful generation",
      "strength": "core",
      "verified": true,
      "note": "Stop generation and transmission of unlawful content; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 10",
      "label": "DeepSyn Art. 10",
      "title": "Input and output review",
      "strength": "core",
      "verified": true,
      "note": "Technical or manual review of user inputs and synthetic outputs; CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 8",
      "label": "AlgoRec Art. 8",
      "title": "Periodic algorithm review",
      "strength": "related",
      "verified": true,
      "note": "Regularly review the algorithm mechanisms, models and data; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 9",
      "label": "AlgoRec Art. 9",
      "title": "Feature database for unlawful content",
      "strength": "related",
      "verified": true,
      "note": "Maintain a feature library to identify unlawful and harmful information; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "eu-ai-act",
      "reference": "Art. 15",
      "label": "Art. 15",
      "title": "Accuracy, robustness and cybersecurity",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-adversarial-red-team-suite",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_15",
      "obligationId": "AIGE-OBL-EUAIA-ART15"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "eu-ai-act",
      "reference": "Art. 55",
      "label": "Art. 55",
      "title": "Obligations for providers of general-purpose AI models with systemic risk",
      "strength": "core",
      "verified": true,
      "note": "Model evaluations and adversarial testing for systemic-risk GPAI.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_55",
      "obligationId": "AIGE-OBL-EUAIA-ART55"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "eu-ai-act",
      "reference": "Art. 60",
      "label": "Art. 60",
      "title": "Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes",
      "strength": "related",
      "verified": true,
      "note": "Real-world testing plan and controls.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_60",
      "obligationId": "AIGE-OBL-EUAIA-ART60"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "iso-42001",
      "reference": "A.6",
      "label": "A.6",
      "title": "AI system life cycle",
      "strength": "core",
      "verified": true,
      "note": "Verification and validation in the lifecycle; see pattern: /bok/patterns#pattern-eval-gate-in-ci",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "iso-42001",
      "reference": "9.1",
      "label": "9.1",
      "title": "Monitoring, measurement, analysis and evaluation",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "robustness-security-evals",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2",
      "label": "MEASURE 2",
      "title": "MEASURE 2: AI systems are evaluated for trustworthy characteristics",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-eval-gate-in-ci",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "cn-tc260-framework",
      "reference": "3",
      "label": "TC260 3",
      "title": "Technological countermeasures",
      "strength": "core",
      "verified": true,
      "note": "Technical measures across model, algorithm and data; printed p. 73.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.6",
      "label": "TC260 App. 2 II.6",
      "title": "Sandbox validation and red teaming",
      "strength": "core",
      "verified": true,
      "note": "Sandbox validation, red teaming and auditing for agents; printed pp. 124-125.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "cn-tc260-framework",
      "reference": "5.3.14",
      "label": "TC260 5.3.14",
      "title": "Resilience",
      "strength": "related",
      "verified": true,
      "note": "System resilience requirement; printed p. 103.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 15",
      "label": "DeepSyn Art. 15",
      "title": "Technology management and algorithm verification",
      "strength": "core",
      "verified": true,
      "note": "Regular audit, assessment and verification of the synthesis-algorithm mechanisms; CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 20",
      "label": "DeepSyn Art. 20",
      "title": "Security assessment of new products",
      "strength": "core",
      "verified": true,
      "note": "Security assessment before launching public-opinion products; CAC text.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "cn-genai-measures",
      "reference": "Art. 17",
      "label": "GenAI Art. 17",
      "title": "Security assessment",
      "strength": "related",
      "verified": true,
      "note": "Pre-deployment security assessment; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "cn-gbt-45654",
      "reference": "Security assessment",
      "label": "GB/T 45654 Security assessment",
      "title": "Security-assessment requirements for generative AI services",
      "strength": "core",
      "verified": false,
      "note": "GB/T 45654-2025 security-assessment requirements (TC260-003 predecessor §8 and Annex A risk list). The official listing shows the standard as current (issued 2025-04-25, implemented 2025-11-01; checked 2026-09-24), but the full text is only offered there as an image preview, so the clause id is not verified against it.",
      "url": "https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F67D3F376E0A0A0FF5317FB36B32A30A",
      "obligationId": "AIGE-OBL-CN-GBT45654"
    },
    {
      "topic": "incident-monitoring",
      "framework": "eu-ai-act",
      "reference": "Art. 72",
      "label": "Art. 72",
      "title": "Post-market monitoring by providers and post-market monitoring plan",
      "strength": "core",
      "verified": true,
      "note": "Continuous post-market monitoring.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_72",
      "obligationId": "AIGE-OBL-EUAIA-ART72"
    },
    {
      "topic": "incident-monitoring",
      "framework": "eu-ai-act",
      "reference": "Art. 73",
      "label": "Art. 73",
      "title": "Reporting of serious incidents",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-incident-pipeline",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_73",
      "obligationId": "AIGE-OBL-EUAIA-ART73"
    },
    {
      "topic": "incident-monitoring",
      "framework": "eu-ai-act",
      "reference": "Art. 55",
      "label": "Art. 55",
      "title": "Obligations for providers of general-purpose AI models with systemic risk",
      "strength": "related",
      "verified": true,
      "note": "Systemic-risk incident tracking and reporting.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_55",
      "obligationId": "AIGE-OBL-EUAIA-ART55"
    },
    {
      "topic": "incident-monitoring",
      "framework": "iso-42001",
      "reference": "A.8",
      "label": "A.8",
      "title": "Information for interested parties",
      "strength": "core",
      "verified": true,
      "note": "Incident communication to interested parties.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A8"
    },
    {
      "topic": "incident-monitoring",
      "framework": "iso-42001",
      "reference": "10.2",
      "label": "10.2",
      "title": "Nonconformity and corrective action",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "incident-monitoring",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 4",
      "label": "MANAGE 4",
      "title": "MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-continuous-assurance-telemetry",
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "incident-monitoring",
      "framework": "cn-tc260-framework",
      "reference": "5.3.7",
      "label": "TC260 5.3.7",
      "title": "Real-time risk monitoring",
      "strength": "core",
      "verified": true,
      "note": "Real-time monitoring of AI risks in operation; printed p. 102.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "incident-monitoring",
      "framework": "cn-tc260-framework",
      "reference": "5.3.18",
      "label": "TC260 5.3.18",
      "title": "Incident reporting",
      "strength": "core",
      "verified": true,
      "note": "Report safety incidents; printed p. 104.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "incident-monitoring",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.6",
      "label": "TC260 App. 2 II.6",
      "title": "Emergency plans",
      "strength": "related",
      "verified": true,
      "note": "Emergency plans within continuous monitoring for agents; printed pp. 124-125.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "incident-monitoring",
      "framework": "cn-genai-measures",
      "reference": "Art. 14",
      "label": "GenAI Art. 14",
      "title": "Handle and report unlawful content",
      "strength": "core",
      "verified": true,
      "note": "Stop, rectify and report unlawful content and optimise the model; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "incident-monitoring",
      "framework": "cn-genai-measures",
      "reference": "Art. 15",
      "label": "GenAI Art. 15",
      "title": "Complaint and reporting mechanism",
      "strength": "core",
      "verified": true,
      "note": "Accessible complaint and report channels with published timelines; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "incident-monitoring",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 7",
      "label": "AlgoRec Art. 7",
      "title": "Security management and emergency response",
      "strength": "related",
      "verified": true,
      "note": "Management systems include emergency response; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "supply-chain",
      "framework": "eu-ai-act",
      "reference": "Art. 25",
      "label": "Art. 25",
      "title": "Responsibilities along the AI value chain",
      "strength": "core",
      "verified": true,
      "note": "See pattern: /bok/patterns#pattern-vendor--model-due-diligence-gate",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_25",
      "obligationId": "AIGE-OBL-EUAIA-ART25"
    },
    {
      "topic": "supply-chain",
      "framework": "eu-ai-act",
      "reference": "Art. 26",
      "label": "Art. 26",
      "title": "Obligations of deployers of high-risk AI systems",
      "strength": "related",
      "verified": true,
      "note": "Deployer duties toward upstream providers.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
      "obligationId": "AIGE-OBL-EUAIA-ART26"
    },
    {
      "topic": "supply-chain",
      "framework": "iso-42001",
      "reference": "A.10",
      "label": "A.10",
      "title": "Third-party and customer relationships",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A10"
    },
    {
      "topic": "supply-chain",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 6",
      "label": "GOVERN 6",
      "title": "GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "supply-chain",
      "framework": "nist-ai-rmf",
      "reference": "MAP 4",
      "label": "MAP 4",
      "title": "MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "supply-chain",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 3",
      "label": "MANAGE 3",
      "title": "MANAGE 3: AI risks and benefits from third-party entities are managed",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "supply-chain",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.4",
      "label": "TC260 App. 2 II.4",
      "title": "Supply chain and tool management",
      "strength": "core",
      "verified": true,
      "note": "Supply-chain and tool-invocation management for agents; printed pp. 122-123.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "supply-chain",
      "framework": "cn-tc260-framework",
      "reference": "4.4.4",
      "label": "TC260 4.4.4",
      "title": "Open-source ecosystem",
      "strength": "related",
      "verified": true,
      "note": "Governance of the open-source AI ecosystem; printed p. 92.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "supply-chain",
      "framework": "cn-genai-measures",
      "reference": "Art. 7",
      "label": "GenAI Art. 7",
      "title": "Lawful data and model sources",
      "strength": "related",
      "verified": true,
      "note": "Upstream training-data (and model) sourcing must be lawful; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "supply-chain",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 14",
      "label": "DeepSyn Art. 14",
      "title": "Providers and technical supporters",
      "strength": "related",
      "verified": true,
      "note": "Providers and their technical supporters share training-data duties (a value-chain relationship); CAC text. Draft mapped this to Art. 7, but Art. 14 is the article that names technical supporters.",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "risk-management",
      "framework": "eu-ai-act",
      "reference": "Art. 3",
      "label": "Art. 3",
      "title": "Definitions",
      "strength": "related",
      "verified": true,
      "note": "Points (12) intended purpose, (13) reasonably foreseeable misuse and (23) substantial modification set the scope of the risk file.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_3",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "iso-42001",
      "reference": "6.1.4",
      "label": "6.1.4",
      "title": "AI system impact assessment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "iso-23894",
      "reference": "6.4",
      "label": "23894 6.4",
      "title": "Risk assessment",
      "strength": "core",
      "verified": false,
      "note": "Clause as listed in the INCITS/AI revised crosswalk between ISO/IEC 23894 and the AI RMF (2025-08-14, on NIST's AI Resource Center); the ISO text was not opened.",
      "url": "https://www.iso.org/standard/77304.html",
      "obligationId": "AIGE-OBL-ISO23894-RISK"
    },
    {
      "topic": "risk-management",
      "framework": "iso-23894",
      "reference": "6.5",
      "label": "23894 6.5",
      "title": "Risk treatment",
      "strength": "core",
      "verified": false,
      "note": "Clause as listed in the INCITS/AI revised crosswalk between ISO/IEC 23894 and the AI RMF (2025-08-14, on NIST's AI Resource Center); the ISO text was not opened.",
      "url": "https://www.iso.org/standard/77304.html",
      "obligationId": "AIGE-OBL-ISO23894-RISK"
    },
    {
      "topic": "risk-management",
      "framework": "iso-23894",
      "reference": "6.6",
      "label": "23894 6.6",
      "title": "Monitoring and review",
      "strength": "related",
      "verified": false,
      "note": "Clause as listed in the INCITS/AI revised crosswalk between ISO/IEC 23894 and the AI RMF (2025-08-14, on NIST's AI Resource Center); the ISO text was not opened.",
      "url": "https://www.iso.org/standard/77304.html",
      "obligationId": "AIGE-OBL-ISO23894-RISK"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 1.3",
      "label": "GOVERN 1.3",
      "title": "GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MAP 1.5",
      "label": "MAP 1.5",
      "title": "MAP 1.5: Organizational risk tolerances are determined and documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 1.3",
      "label": "MANAGE 1.3",
      "title": "MANAGE 1.3: Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 1.4",
      "label": "MANAGE 1.4",
      "title": "MANAGE 1.4: Negative residual risks to both downstream acquirers of AI systems and end users are documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "risk-management",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 3",
      "label": "MEASURE 3",
      "title": "MEASURE 3: Mechanisms for tracking identified AI risks over time are in place",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "risk-management",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C1",
      "label": "Safety C1",
      "title": "Commitment 1: Safety and Security Framework",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "risk-management",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C3",
      "label": "Safety C3",
      "title": "Commitment 3: Systemic risk analysis",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "risk-management",
      "framework": "csa-aicm",
      "reference": "GRC-02",
      "label": "GRC-02",
      "title": "Risk Management Program",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "risk-management",
      "framework": "csa-aicm",
      "reference": "MDS-12",
      "label": "MDS-12",
      "title": "Open Model Risk Assessment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "risk-management",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 34(1)(1)",
      "label": "Art. 34(1)(1)",
      "title": "Risk management plan for high-impact AI",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "risk-management",
      "framework": "uk-atrs",
      "reference": "2.5.2",
      "label": "ATRS 2.5.2",
      "title": "Risks and mitigations",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "sg-agentic-framework",
      "reference": "2.1",
      "label": "Agentic 2.1",
      "title": "Assess and bound the risks upfront",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "coe-cets-225",
      "reference": "Art. 16",
      "label": "CoE Art. 16",
      "title": "Risk and impact management framework",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "oecd-ai-principles",
      "reference": "1.5(c)",
      "label": "OECD 1.5(c)",
      "title": "Systematic risk management at each lifecycle phase",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "risk-management",
      "framework": "pren-18228",
      "reference": "prEN 18228",
      "label": "prEN 18228",
      "title": "AI risk management (draft; supports Art. 9)",
      "strength": "core",
      "verified": false,
      "note": "Draft European standard; stage as reported by Genorma on 2026-09-24 (secondary); the draft text is not public.",
      "url": "https://genorma.com/en/standards/pren-18228",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "eu-ai-act",
      "reference": "Art. 87",
      "label": "Art. 87",
      "title": "Reporting of infringements and protection of reporting persons",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_87",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "gdpr",
      "reference": "Art. 5(2)",
      "label": "Art. 5(2)",
      "title": "Accountability",
      "strength": "core",
      "verified": true,
      "note": "The controller must demonstrate compliance, including any claim that a model is anonymous.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_5",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "7.2",
      "label": "7.2",
      "title": "Competence",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "9.2",
      "label": "9.2",
      "title": "Internal audit",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "9.3",
      "label": "9.3",
      "title": "Management review",
      "strength": "core",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "iso-42001",
      "reference": "10.1",
      "label": "10.1",
      "title": "Continual improvement",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 4",
      "label": "GOVERN 4",
      "title": "GOVERN 4: Organizational teams are committed to a culture that considers and communicates AI risk",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "governance-accountability",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 5",
      "label": "GOVERN 5",
      "title": "GOVERN 5: Processes are in place for robust engagement with relevant AI actors",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "governance-accountability",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C8",
      "label": "Safety C8",
      "title": "Commitment 8: Systemic risk responsibility allocation",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "governance-accountability",
      "framework": "csa-aicm",
      "reference": "GRC-01",
      "label": "GRC-01",
      "title": "Governance Program Policy and Procedures",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "governance-accountability",
      "framework": "csa-aicm",
      "reference": "GRC-06",
      "label": "GRC-06",
      "title": "Governance Responsibility Model",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "governance-accountability",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 36",
      "label": "Art. 36",
      "title": "Domestic representative",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "governance-accountability",
      "framework": "uk-atrs",
      "reference": "2.1",
      "label": "ATRS 2.1",
      "title": "Owner and responsibility",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "sg-genai-framework",
      "reference": "1",
      "label": "GenAI 1",
      "title": "Accountability",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "governance-accountability",
      "framework": "sg-agentic-framework",
      "reference": "2.2.1",
      "label": "Agentic 2.2.1",
      "title": "Clear allocation of responsibilities within and outside the organisation",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "coe-cets-225",
      "reference": "Art. 9",
      "label": "CoE Art. 9",
      "title": "Accountability and responsibility",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "oecd-ai-principles",
      "reference": "1.5",
      "label": "OECD 1.5",
      "title": "Accountability",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 5",
      "label": "G7 Action 5",
      "title": "Develop, implement and disclose AI governance and risk-management policies",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "governance-accountability",
      "framework": "en-18286",
      "reference": "EN 18286",
      "label": "EN 18286",
      "title": "Quality management system for EU AI Act regulatory purposes",
      "strength": "related",
      "verified": true,
      "note": "Published July 2026; supports Art. 17. No Official Journal citation, so no presumption of conformity, as of 2026-09-24.",
      "url": "https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "gdpr",
      "reference": "Art. 35",
      "label": "Art. 35",
      "title": "Data protection impact assessment",
      "strength": "core",
      "verified": true,
      "note": "The DPIA is the privacy twin of the FRIA; an AI DPIA adds training sources, memorisation and inference risks.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_35",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "gdpr",
      "reference": "Art. 36",
      "label": "Art. 36",
      "title": "Prior consultation",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_36",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "iso-42005",
      "reference": "5.8",
      "label": "42005 5.8",
      "title": "Performing the AI system impact assessment",
      "strength": "core",
      "verified": false,
      "note": "Clause as listed in the INCITS/AI crosswalk against the DIS of ISO/IEC 42005 (2025-08-14, on NIST's AI Resource Center); numbering not checked against the published 2025 text.",
      "url": "https://www.iso.org/standard/44545.html",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "iso-42005",
      "reference": "6.8",
      "label": "42005 6.8",
      "title": "Actual and reasonably foreseeable impacts",
      "strength": "core",
      "verified": false,
      "note": "Clause as listed in the INCITS/AI crosswalk against the DIS of ISO/IEC 42005 (2025-08-14, on NIST's AI Resource Center); numbering not checked against the published 2025 text.",
      "url": "https://www.iso.org/standard/44545.html",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "iso-42005",
      "reference": "5.12",
      "label": "42005 5.12",
      "title": "Monitoring and review",
      "strength": "related",
      "verified": false,
      "note": "Clause as listed in the INCITS/AI crosswalk against the DIS of ISO/IEC 42005 (2025-08-14, on NIST's AI Resource Center); numbering not checked against the published 2025 text.",
      "url": "https://www.iso.org/standard/44545.html",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "csa-aicm",
      "reference": "GRC-10",
      "label": "GRC-10",
      "title": "AI Impact Assessment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "impact-assessment",
      "framework": "csa-aicm",
      "reference": "DSP-09",
      "label": "DSP-09",
      "title": "Data Protection Impact Assessment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "impact-assessment",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 35",
      "label": "Art. 35",
      "title": "Impact assessment (best-effort duty)",
      "strength": "core",
      "verified": true,
      "note": "Operators shall endeavour to assess the effect of high-impact AI on fundamental rights.",
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "impact-assessment",
      "framework": "uk-atrs",
      "reference": "2.5.1",
      "label": "ATRS 2.5.1",
      "title": "Impact assessments",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "impact-assessment",
      "framework": "coe-cets-225",
      "reference": "Art. 16",
      "label": "CoE Art. 16",
      "title": "Risk and impact management framework",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "eu-ai-act",
      "reference": "Art. 10(2)(f)–(g)",
      "label": "Art. 10(2)(f)–(g)",
      "title": "Examination for possible biases; measures to detect, prevent and mitigate them",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
      "obligationId": "AIGE-OBL-EUAIA-ART10"
    },
    {
      "topic": "data-governance",
      "framework": "eu-ai-act",
      "reference": "Art. 53",
      "label": "Art. 53",
      "title": "Obligations for providers of general-purpose AI models",
      "strength": "related",
      "verified": true,
      "note": "Art. 53(1)(d): public summary of the content used for training, on the AI Office template.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "eu-ai-act",
      "reference": "Art. 53(1)(c)",
      "label": "Art. 53(1)(c)",
      "title": "Copyright policy, including rights reservations",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "eu-ai-act",
      "reference": "Art. 5(1)(e)",
      "label": "Art. 5(1)(e)",
      "title": "Prohibited: untargeted scraping of facial images",
      "strength": "related",
      "verified": true,
      "note": "Facial-recognition databases built by untargeted scraping of the internet or CCTV are banned; a sourcing rule for data pipelines.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "gpai-code-of-practice",
      "reference": "Copyright 1.1–1.5",
      "label": "Copyright 1.1–1.5",
      "title": "Commitment 1: Copyright policy (Measures 1.1 to 1.5)",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
      "obligationId": "AIGE-OBL-GPAICOP-COPYRIGHT"
    },
    {
      "topic": "data-governance",
      "framework": "gdpr",
      "reference": "Art. 5(1)(c)",
      "label": "Art. 5(1)(c)",
      "title": "Data minimisation",
      "strength": "core",
      "verified": true,
      "note": "Minimisation argued feature by feature for training, retrieval, logs and eval sets.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_5",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "gdpr",
      "reference": "Art. 25",
      "label": "Art. 25",
      "title": "Data protection by design and by default",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_25",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "gdpr",
      "reference": "Art. 9",
      "label": "Art. 9",
      "title": "Processing of special categories of personal data",
      "strength": "related",
      "verified": true,
      "note": "Sits beside AI Act Art. 4a on bias-detection processing; inferred sensitive data counts.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_9",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "iso-42001",
      "reference": "A.7.3",
      "label": "A.7.3",
      "title": "Acquisition of data",
      "strength": "core",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A7"
    },
    {
      "topic": "data-governance",
      "framework": "csa-aicm",
      "reference": "DSP-20",
      "label": "DSP-20",
      "title": "Data Provenance and Transparency",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "data-governance",
      "framework": "csa-aicm",
      "reference": "DSP-21",
      "label": "DSP-21",
      "title": "Data Poisoning Prevention & Detection",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "data-governance",
      "framework": "owasp-llm-top-10",
      "reference": "LLM05:2026",
      "label": "LLM05:2026",
      "title": "Data and Model Poisoning",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "data-governance",
      "framework": "uk-atrs",
      "reference": "2.4.3",
      "label": "ATRS 2.4.3",
      "title": "Development data specification",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "data-governance",
      "framework": "sg-genai-framework",
      "reference": "2",
      "label": "GenAI 2",
      "title": "Data",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 86",
      "label": "Art. 86",
      "title": "Right to explanation of individual decision-making",
      "strength": "related",
      "verified": true,
      "note": "Transparency that reaches the affected person: reason codes and an appeal route.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_86",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 18",
      "label": "Art. 18",
      "title": "Documentation keeping",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_18",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 43",
      "label": "Art. 43",
      "title": "Conformity assessment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_43",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 53(1)(d)",
      "label": "Art. 53(1)(d)",
      "title": "Public summary of the content used for training",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "eu-ai-act",
      "reference": "Art. 50(2), 50(4)",
      "label": "Art. 50(2), 50(4)",
      "title": "Machine-readable marking of synthetic content; disclosure of deep fakes",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_50",
      "obligationId": "AIGE-OBL-EUAIA-ART50"
    },
    {
      "topic": "documentation-transparency",
      "framework": "gpai-code-of-practice",
      "reference": "Transparency 1.1",
      "label": "Transparency 1.1",
      "title": "Drawing up and keeping up-to-date model documentation",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118120",
      "obligationId": "AIGE-OBL-GPAICOP-TRANSPARENCY"
    },
    {
      "topic": "documentation-transparency",
      "framework": "gpai-code-of-practice",
      "reference": "Transparency 1.2",
      "label": "Transparency 1.2",
      "title": "Providing relevant information",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118120",
      "obligationId": "AIGE-OBL-GPAICOP-TRANSPARENCY"
    },
    {
      "topic": "documentation-transparency",
      "framework": "gdpr",
      "reference": "Arts. 13–14",
      "label": "Arts. 13–14",
      "title": "Information to be provided to the data subject",
      "strength": "core",
      "verified": true,
      "note": "Notice versioned with the model card; Art. 14 covers scraped or licensed training data.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_13",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "gdpr",
      "reference": "Art. 30",
      "label": "Art. 30",
      "title": "Records of processing activities",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_30",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "nist-ai-rmf",
      "reference": "MAP 1.6",
      "label": "MAP 1.6",
      "title": "MAP 1.6: System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "documentation-transparency",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.9",
      "label": "MEASURE 2.9",
      "title": "MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "documentation-transparency",
      "framework": "csa-aicm",
      "reference": "MDS-03",
      "label": "MDS-03",
      "title": "Model Documentation",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "documentation-transparency",
      "framework": "csa-aicm",
      "reference": "MDS-04",
      "label": "MDS-04",
      "title": "Model Documentation Requirements",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "documentation-transparency",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 31",
      "label": "Art. 31",
      "title": "Transparency: prior notice, output labelling, realistic synthetic content",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "documentation-transparency",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 34(1)(2)",
      "label": "Art. 34(1)(2)",
      "title": "Explanation plan: result, main criteria, training-data overview",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "documentation-transparency",
      "framework": "uk-atrs",
      "reference": "Tier 1",
      "label": "ATRS Tier 1",
      "title": "Summary information",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "uk-atrs",
      "reference": "2.2",
      "label": "ATRS 2.2",
      "title": "Description and rationale",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "sg-genai-framework",
      "reference": "3",
      "label": "GenAI 3",
      "title": "Trusted Development and Deployment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "documentation-transparency",
      "framework": "coe-cets-225",
      "reference": "Art. 14(2)",
      "label": "CoE Art. 14(2)",
      "title": "Documentation sufficient to contest decisions; complaint to authorities",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "coe-cets-225",
      "reference": "Art. 15(2)",
      "label": "CoE Art. 15(2)",
      "title": "Notification of interaction with an AI system",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "oecd-ai-principles",
      "reference": "1.3",
      "label": "OECD 1.3",
      "title": "Transparency and explainability",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "documentation-transparency",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 3",
      "label": "G7 Action 3",
      "title": "Publicly report capabilities, limitations and domains of use",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "inventory-registration",
      "framework": "eu-ai-act",
      "reference": "Art. 3(1)",
      "label": "Art. 3(1)",
      "title": "Definition of an AI system",
      "strength": "related",
      "verified": true,
      "note": "The definition decides which systems enter the inventory at all; the Commission guidelines list the excluded families.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_3",
      "obligationId": null
    },
    {
      "topic": "inventory-registration",
      "framework": "eu-ai-act",
      "reference": "Art. 52",
      "label": "Art. 52",
      "title": "Procedure",
      "strength": "related",
      "verified": true,
      "note": "Notification of GPAI models that meet the systemic-risk condition.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_52",
      "obligationId": null
    },
    {
      "topic": "inventory-registration",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 1.7",
      "label": "GOVERN 1.7",
      "title": "GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "inventory-registration",
      "framework": "csa-aicm",
      "reference": "STA-08",
      "label": "STA-08",
      "title": "Supply Chain Inventory",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "inventory-registration",
      "framework": "csa-aicm",
      "reference": "IAM-03",
      "label": "IAM-03",
      "title": "Identity Inventory",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "inventory-registration",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 33",
      "label": "Art. 33",
      "title": "Confirmation of high-impact AI",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "inventory-registration",
      "framework": "uk-atrs",
      "reference": "Tier 1",
      "label": "ATRS Tier 1",
      "title": "Summary information (the published record)",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "logging-traceability",
      "framework": "eu-ai-act",
      "reference": "Art. 26(6)",
      "label": "Art. 26(6)",
      "title": "Deployers keep the automatically generated logs",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
      "obligationId": "AIGE-OBL-EUAIA-ART26"
    },
    {
      "topic": "logging-traceability",
      "framework": "eu-ai-act",
      "reference": "Art. 19",
      "label": "Art. 19",
      "title": "Automatically generated logs",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_19",
      "obligationId": null
    },
    {
      "topic": "logging-traceability",
      "framework": "iso-42001",
      "reference": "A.6.2.8",
      "label": "A.6.2.8",
      "title": "AI system recording of event logs",
      "strength": "core",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "logging-traceability",
      "framework": "csa-aicm",
      "reference": "LOG-09",
      "label": "LOG-09",
      "title": "Log Records",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "logging-traceability",
      "framework": "csa-aicm",
      "reference": "LOG-12",
      "label": "LOG-12",
      "title": "Transaction/Activity Logging",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "logging-traceability",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 34(1)(5)",
      "label": "Art. 34(1)(5)",
      "title": "Documents showing the measures taken",
      "strength": "core",
      "verified": true,
      "note": "The enforcement decree keeps the evidence for five years.",
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "logging-traceability",
      "framework": "sg-agentic-framework",
      "reference": "2.3.3",
      "label": "Agentic 2.3.3",
      "title": "When deploying, continuously monitor and test",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "logging-traceability",
      "framework": "oecd-ai-principles",
      "reference": "1.5(b)",
      "label": "OECD 1.5(b)",
      "title": "Traceability of datasets, processes and decisions",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "logging-traceability",
      "framework": "pren-18229-1",
      "reference": "prEN 18229-1",
      "label": "prEN 18229-1",
      "title": "AI trustworthiness framework, Part 1: logging (draft; supports Art. 12)",
      "strength": "core",
      "verified": false,
      "note": "Draft European standard; stage as reported by Genorma on 2026-09-24 (secondary); the draft text is not public.",
      "url": "https://genorma.com/en/standards/pren-18229-1",
      "obligationId": null
    },
    {
      "topic": "human-oversight",
      "framework": "eu-ai-act",
      "reference": "Art. 14(4)(b)",
      "label": "Art. 14(4)(b)",
      "title": "Awareness of automation bias",
      "strength": "related",
      "verified": true,
      "note": "Gate logs approver, time to decide and override rate so degrading oversight is visible.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_14",
      "obligationId": "AIGE-OBL-EUAIA-ART14"
    },
    {
      "topic": "human-oversight",
      "framework": "gdpr",
      "reference": "Art. 22",
      "label": "Art. 22",
      "title": "Automated individual decision-making, including profiling",
      "strength": "core",
      "verified": true,
      "note": "Human intervention and contest for solely automated significant decisions.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_22",
      "obligationId": null
    },
    {
      "topic": "human-oversight",
      "framework": "nist-ai-rmf",
      "reference": "MAP 3.5",
      "label": "MAP 3.5",
      "title": "MAP 3.5: Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "human-oversight",
      "framework": "csa-aicm",
      "reference": "GRC-15",
      "label": "GRC-15",
      "title": "Human supervision",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "human-oversight",
      "framework": "owasp-agentic-top-10",
      "reference": "ASI09",
      "label": "ASI09",
      "title": "Human-Agent Trust Exploitation",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "obligationId": "AIGE-OBL-OWASP-AGENTIC"
    },
    {
      "topic": "human-oversight",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 34(1)(4)",
      "label": "Art. 34(1)(4)",
      "title": "Human management and supervision",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "human-oversight",
      "framework": "uk-duaa",
      "reference": "Art. 22C",
      "label": "UK GDPR Art. 22C",
      "title": "Safeguards for automated decision-making",
      "strength": "core",
      "verified": true,
      "note": "Inserted into the UK GDPR by DUAA s. 80: information, representations, human intervention and contest.",
      "url": "https://www.legislation.gov.uk/ukpga/2025/18/section/80",
      "obligationId": "AIGE-OBL-UK-ADM"
    },
    {
      "topic": "human-oversight",
      "framework": "uk-atrs",
      "reference": "2.3.2",
      "label": "ATRS 2.3.2",
      "title": "Human review",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "human-oversight",
      "framework": "sg-agentic-framework",
      "reference": "2.2.2",
      "label": "Agentic 2.2.2",
      "title": "Design for meaningful human oversight",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "human-oversight",
      "framework": "coe-cets-225",
      "reference": "Art. 8",
      "label": "CoE Art. 8",
      "title": "Transparency and oversight",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "human-oversight",
      "framework": "oecd-ai-principles",
      "reference": "1.2(b)",
      "label": "OECD 1.2(b)",
      "title": "Human agency and oversight safeguards",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "runtime-guardrails",
      "framework": "eu-ai-act",
      "reference": "Art. 5(1)(a)–(b)",
      "label": "Art. 5(1)(a)–(b)",
      "title": "Manipulative techniques; exploitation of vulnerabilities",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5",
      "obligationId": "AIGE-OBL-EUAIA-ART5"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C5",
      "label": "Safety C5",
      "title": "Commitment 5: Safety mitigations",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "csa-aicm",
      "reference": "TVM-13",
      "label": "TVM-13",
      "title": "Guardrails",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "csa-aicm",
      "reference": "AIS-09",
      "label": "AIS-09",
      "title": "Input Validation",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "csa-aicm",
      "reference": "AIS-10",
      "label": "AIS-10",
      "title": "Output Validation",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "owasp-llm-top-10",
      "reference": "LLM01:2026",
      "label": "LLM01:2026",
      "title": "Prompt Injection",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "owasp-llm-top-10",
      "reference": "LLM10:2026",
      "label": "LLM10:2026",
      "title": "Improper Output Handling",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "owasp-llm-top-10",
      "reference": "LLM06:2026",
      "label": "LLM06:2026",
      "title": "Unbounded Consumption",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "runtime-guardrails",
      "framework": "sg-agentic-framework",
      "reference": "2.3.1",
      "label": "Agentic 2.3.1",
      "title": "During design and development, use technical controls",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "robustness-security-evals",
      "framework": "eu-ai-act",
      "reference": "Art. 15(3)",
      "label": "Art. 15(3)",
      "title": "Declared accuracy levels and metrics",
      "strength": "related",
      "verified": true,
      "note": "Declared metrics become the eval baseline; calibration is measured in the gate.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_15",
      "obligationId": "AIGE-OBL-EUAIA-ART15"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "eu-ai-act",
      "reference": "Art. 9",
      "label": "Art. 9",
      "title": "Risk management system",
      "strength": "related",
      "verified": true,
      "note": "Art. 9(8): testing against prior defined metrics and probabilistic thresholds, before placing on the market.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9",
      "obligationId": "AIGE-OBL-EUAIA-ART9"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "eu-ai-act",
      "reference": "Art. 42(3)",
      "label": "Art. 42(3)",
      "title": "Presumption of conformity for cybersecurity (Cyber Resilience Act)",
      "strength": "related",
      "verified": true,
      "note": "Added by the Digital Omnibus (Reg. (EU) 2026/1744): CRA conformity counts for the Art. 15 cybersecurity requirement.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_42",
      "obligationId": null
    },
    {
      "topic": "robustness-security-evals",
      "framework": "gpai-code-of-practice",
      "reference": "Safety 3.2",
      "label": "Safety 3.2",
      "title": "Measure 3.2: Model evaluations",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C6",
      "label": "Safety C6",
      "title": "Commitment 6: Security mitigations",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "gdpr",
      "reference": "Art. 32",
      "label": "Art. 32",
      "title": "Security of processing",
      "strength": "related",
      "verified": true,
      "note": "Privacy-attack evals (membership inference, extraction) as evidence of appropriate security.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_32",
      "obligationId": null
    },
    {
      "topic": "robustness-security-evals",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.7",
      "label": "MEASURE 2.7",
      "title": "MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.1",
      "label": "MEASURE 2.1",
      "title": "MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 1",
      "label": "MEASURE 1",
      "title": "MEASURE 1: Appropriate methods and metrics are identified and applied",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "csa-aicm",
      "reference": "MDS-06",
      "label": "MDS-06",
      "title": "Adversarial Attack Analysis",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "csa-aicm",
      "reference": "MDS-07",
      "label": "MDS-07",
      "title": "Robustness against Adversarial Attack / Model Hardening",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "csa-aicm",
      "reference": "AIS-05",
      "label": "AIS-05",
      "title": "Application Security Testing",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "owasp-llm-top-10",
      "reference": "LLM01:2026",
      "label": "LLM01:2026",
      "title": "Prompt Injection",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "owasp-agentic-top-10",
      "reference": "ASI05",
      "label": "ASI05",
      "title": "Unexpected Code Execution (RCE)",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "obligationId": "AIGE-OBL-OWASP-AGENTIC"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 32(1)",
      "label": "Art. 32(1)",
      "title": "Safety duties for AI above the compute threshold",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "sg-genai-framework",
      "reference": "5",
      "label": "GenAI 5",
      "title": "Testing and Assurance",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "sg-genai-framework",
      "reference": "6",
      "label": "GenAI 6",
      "title": "Security",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "sg-agentic-framework",
      "reference": "2.3.2",
      "label": "Agentic 2.3.2",
      "title": "Before deploying, test agents",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "robustness-security-evals",
      "framework": "coe-cets-225",
      "reference": "Art. 16(2)(g)",
      "label": "CoE Art. 16(2)(g)",
      "title": "Testing before first use and when significantly modified",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "robustness-security-evals",
      "framework": "oecd-ai-principles",
      "reference": "1.4",
      "label": "OECD 1.4",
      "title": "Robustness, security and safety",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "robustness-security-evals",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 1",
      "label": "G7 Action 1",
      "title": "Identify, evaluate and mitigate risks across the lifecycle, including testing",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "incident-monitoring",
      "framework": "eu-ai-act",
      "reference": "Art. 26(5)",
      "label": "Art. 26(5)",
      "title": "Deployer monitoring, informing the provider and suspending use",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
      "obligationId": "AIGE-OBL-EUAIA-ART26"
    },
    {
      "topic": "incident-monitoring",
      "framework": "eu-ai-act",
      "reference": "Art. 3(49)",
      "label": "Art. 3(49)",
      "title": "Definition of serious incident",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_3",
      "obligationId": null
    },
    {
      "topic": "incident-monitoring",
      "framework": "eu-ai-act",
      "reference": "Art. 20",
      "label": "Art. 20",
      "title": "Corrective actions and duty of information",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_20",
      "obligationId": null
    },
    {
      "topic": "incident-monitoring",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C9",
      "label": "Safety C9",
      "title": "Commitment 9: Serious incident reporting",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "incident-monitoring",
      "framework": "gpai-code-of-practice",
      "reference": "Safety 3.5",
      "label": "Safety 3.5",
      "title": "Measure 3.5: Post-market monitoring",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "incident-monitoring",
      "framework": "gdpr",
      "reference": "Arts. 33–34",
      "label": "Arts. 33–34",
      "title": "Notification and communication of a personal data breach",
      "strength": "core",
      "verified": true,
      "note": "A 72-hour clock beside AI Act Art. 73; AI adds regurgitation, inversion and prompt-injection breaches.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_33",
      "obligationId": null
    },
    {
      "topic": "incident-monitoring",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 4.3",
      "label": "MANAGE 4.3",
      "title": "MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "incident-monitoring",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 2.4",
      "label": "MANAGE 2.4",
      "title": "MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "incident-monitoring",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 4.3",
      "label": "GOVERN 4.3",
      "title": "GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "incident-monitoring",
      "framework": "csa-aicm",
      "reference": "SEF-07",
      "label": "SEF-07",
      "title": "Incident Management and Response",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "incident-monitoring",
      "framework": "csa-aicm",
      "reference": "SEF-08",
      "label": "SEF-08",
      "title": "Security Breach Notification",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "incident-monitoring",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 32(1)",
      "label": "Art. 32(1)",
      "title": "Safety duties for AI above the compute threshold",
      "strength": "core",
      "verified": true,
      "note": "Risk monitoring and a response system for AI above the compute threshold.",
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "incident-monitoring",
      "framework": "sg-genai-framework",
      "reference": "4",
      "label": "GenAI 4",
      "title": "Incident Reporting",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "incident-monitoring",
      "framework": "sg-agentic-framework",
      "reference": "2.3.3",
      "label": "Agentic 2.3.3",
      "title": "When deploying, continuously monitor and test",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "incident-monitoring",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 2",
      "label": "G7 Action 2",
      "title": "Identify and mitigate vulnerabilities, incidents and misuse after deployment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "incident-monitoring",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 4",
      "label": "G7 Action 4",
      "title": "Responsible information sharing and reporting of incidents",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "eu-ai-act",
      "reference": "Art. 25(4)",
      "label": "Art. 25(4)",
      "title": "Written agreement with third-party suppliers",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_25",
      "obligationId": "AIGE-OBL-EUAIA-ART25"
    },
    {
      "topic": "supply-chain",
      "framework": "eu-ai-act",
      "reference": "Art. 22",
      "label": "Art. 22",
      "title": "Authorised representatives of providers of high-risk AI systems",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_22",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "eu-ai-act",
      "reference": "Art. 23",
      "label": "Art. 23",
      "title": "Obligations of importers",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_23",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "eu-ai-act",
      "reference": "Art. 24",
      "label": "Art. 24",
      "title": "Obligations of distributors",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_24",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "eu-ai-act",
      "reference": "Art. 54",
      "label": "Art. 54",
      "title": "Authorised representatives of providers of general-purpose AI models",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_54",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "gpai-code-of-practice",
      "reference": "Transparency 1.2",
      "label": "Transparency 1.2",
      "title": "Providing relevant information",
      "strength": "related",
      "verified": true,
      "note": "Information for downstream providers that integrate the model into their AI systems.",
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118120",
      "obligationId": "AIGE-OBL-GPAICOP-TRANSPARENCY"
    },
    {
      "topic": "supply-chain",
      "framework": "gdpr",
      "reference": "Art. 28",
      "label": "Art. 28",
      "title": "Processor",
      "strength": "core",
      "verified": true,
      "note": "AI vendor contracts: no-training clauses, retention, region, sub-processors, change notice.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_28",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "gdpr",
      "reference": "Arts. 44–46",
      "label": "Arts. 44–46",
      "title": "Transfers to third countries",
      "strength": "related",
      "verified": true,
      "note": "Remote inference endpoints and vendor telemetry outside the EEA are transfers.",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_44",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 3.1",
      "label": "MANAGE 3.1",
      "title": "MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "supply-chain",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 6.2",
      "label": "GOVERN 6.2",
      "title": "GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "supply-chain",
      "framework": "csa-aicm",
      "reference": "STA-10",
      "label": "STA-10",
      "title": "Supply Chain Risk Management",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "supply-chain",
      "framework": "csa-aicm",
      "reference": "STA-09",
      "label": "STA-09",
      "title": "Service Bill of Material (BOM)",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "supply-chain",
      "framework": "owasp-llm-top-10",
      "reference": "LLM04:2026",
      "label": "LLM04:2026",
      "title": "Supply Chain",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "supply-chain",
      "framework": "owasp-agentic-top-10",
      "reference": "ASI04",
      "label": "ASI04",
      "title": "Agentic Supply Chain Vulnerabilities",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "obligationId": "AIGE-OBL-OWASP-AGENTIC"
    },
    {
      "topic": "supply-chain",
      "framework": "uk-atrs",
      "reference": "2.1.4",
      "label": "ATRS 2.1.4",
      "title": "Third party involvement",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "supply-chain",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 11",
      "label": "G7 Action 11",
      "title": "Implement data input measures and protect personal data and intellectual property",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "prohibited-practices",
      "framework": "eu-ai-act",
      "reference": "Art. 5",
      "label": "Art. 5",
      "title": "Prohibited AI practices",
      "strength": "core",
      "verified": true,
      "note": "The Digital Omnibus adds new prohibitions that apply from 2026-12-02.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5",
      "obligationId": "AIGE-OBL-EUAIA-ART5"
    },
    {
      "topic": "prohibited-practices",
      "framework": "iso-42001",
      "reference": "A.9.4",
      "label": "A.9.4",
      "title": "Intended use of the AI system",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A9"
    },
    {
      "topic": "prohibited-practices",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 1.1",
      "label": "GOVERN 1.1",
      "title": "GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "prohibited-practices",
      "framework": "csa-aicm",
      "reference": "GRC-09",
      "label": "GRC-09",
      "title": "Acceptable Use of the AI Service",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "prohibited-practices",
      "framework": "csa-aicm",
      "reference": "HRS-15",
      "label": "HRS-15",
      "title": "AI Acceptable Use",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "prohibited-practices",
      "framework": "sg-agentic-framework",
      "reference": "2.1.1",
      "label": "Agentic 2.1.1",
      "title": "Determine suitable use cases for agent deployment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "prohibited-practices",
      "framework": "coe-cets-225",
      "reference": "Art. 16(4)",
      "label": "CoE Art. 16(4)",
      "title": "Assess the need for a moratorium, ban or other measures for incompatible uses",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "prohibited-practices",
      "framework": "cn-genai-measures",
      "reference": "Art. 4",
      "label": "GenAI Art. 4",
      "title": "Prohibited content and baseline duties",
      "strength": "related",
      "verified": true,
      "note": "Point (1) lists content that must not be generated; points (2) to (5) set non-discrimination, IP, rights and transparency duties; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "eu-ai-act",
      "reference": "Art. 10(2)(f)–(g)",
      "label": "Art. 10(2)(f)–(g)",
      "title": "Examination for possible biases; measures to detect, prevent and mitigate them",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
      "obligationId": "AIGE-OBL-EUAIA-ART10"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "eu-ai-act",
      "reference": "Art. 4a",
      "label": "Art. 4a",
      "title": "Special-category data for bias detection",
      "strength": "core",
      "verified": true,
      "note": "Added by the Digital Omnibus; strictly necessary, pseudonymised, access-controlled and deleted after correction.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4a",
      "obligationId": "AIGE-OBL-EUAIA-ART4A"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "gdpr",
      "reference": "Art. 5(1)(a)",
      "label": "Art. 5(1)(a)",
      "title": "Lawfulness, fairness and transparency",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_5",
      "obligationId": null
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "gdpr",
      "reference": "Art. 9",
      "label": "Art. 9",
      "title": "Processing of special categories of personal data",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_9",
      "obligationId": null
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "iso-42001",
      "reference": "A.5.4",
      "label": "A.5.4",
      "title": "Assessing AI system impact on individuals or groups of individuals",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A5"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.11",
      "label": "MEASURE 2.11",
      "title": "MEASURE 2.11: Fairness and bias as identified in the MAP function are evaluated and results are documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 3.1",
      "label": "GOVERN 3.1",
      "title": "GOVERN 3.1: Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "csa-aicm",
      "reference": "GRC-11",
      "label": "GRC-11",
      "title": "Bias and Fairness Assessment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "uk-atrs",
      "reference": "2.4.2",
      "label": "ATRS 2.4.2",
      "title": "Model specification",
      "strength": "related",
      "verified": true,
      "note": "Model performance and the bias checks behind it are recorded here.",
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "coe-cets-225",
      "reference": "Art. 10",
      "label": "CoE Art. 10",
      "title": "Equality and non-discrimination",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "oecd-ai-principles",
      "reference": "1.2",
      "label": "OECD 1.2",
      "title": "Rule of law, human rights and democratic values, including fairness and privacy",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "cn-genai-measures",
      "reference": "Art. 4(2)",
      "label": "GenAI Art. 4(2)",
      "title": "Prevent discrimination in design, data, training and service",
      "strength": "core",
      "verified": true,
      "note": "Ethnicity, belief, country, region, sex, age, occupation and health; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 21",
      "label": "AlgoRec Art. 21",
      "title": "No unreasonable differential treatment in trading conditions",
      "strength": "related",
      "verified": true,
      "note": "Bars algorithmic price discrimination based on consumer preferences and habits; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "eu-ai-act",
      "reference": "Art. 59",
      "label": "Art. 59",
      "title": "Further processing of personal data in the AI regulatory sandbox",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_59",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "eu-ai-act",
      "reference": "Art. 4a",
      "label": "Art. 4a",
      "title": "Special-category data for bias detection",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4a",
      "obligationId": "AIGE-OBL-EUAIA-ART4A"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "gdpr",
      "reference": "Art. 5",
      "label": "Art. 5",
      "title": "Principles relating to processing of personal data",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_5",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "gdpr",
      "reference": "Art. 6",
      "label": "Art. 6",
      "title": "Lawfulness of processing",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_6",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "gdpr",
      "reference": "Art. 25",
      "label": "Art. 25",
      "title": "Data protection by design and by default",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_25",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "gdpr",
      "reference": "Art. 35",
      "label": "Art. 35",
      "title": "Data protection impact assessment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_35",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "iso-42001",
      "reference": "A.7",
      "label": "A.7",
      "title": "Data for AI systems",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A7"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.10",
      "label": "MEASURE 2.10",
      "title": "MEASURE 2.10: Privacy risk of the AI system as identified in the MAP function is examined and documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "csa-aicm",
      "reference": "DSP-08",
      "label": "DSP-08",
      "title": "Data Privacy by Design and Default",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "csa-aicm",
      "reference": "DSP-22",
      "label": "DSP-22",
      "title": "Privacy Enhancing Technologies",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "owasp-llm-top-10",
      "reference": "LLM02:2026",
      "label": "LLM02:2026",
      "title": "Sensitive Information Disclosure",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "uk-duaa",
      "reference": "Art. 22B",
      "label": "UK GDPR Art. 22B",
      "title": "Restrictions on automated decision-making",
      "strength": "related",
      "verified": true,
      "note": "Tighter rules where a significant decision rests on special-category data; UK GDPR as amended by DUAA s. 80.",
      "url": "https://www.legislation.gov.uk/ukpga/2025/18/section/80",
      "obligationId": "AIGE-OBL-UK-ADM"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "sg-genai-framework",
      "reference": "2",
      "label": "GenAI 2",
      "title": "Data",
      "strength": "related",
      "verified": true,
      "note": "Trusted use of personal data in training and deployment.",
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "coe-cets-225",
      "reference": "Art. 11",
      "label": "CoE Art. 11",
      "title": "Privacy and personal data protection",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "oecd-ai-principles",
      "reference": "1.2",
      "label": "OECD 1.2",
      "title": "Rule of law, human rights and democratic values, including fairness and privacy",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 11",
      "label": "G7 Action 11",
      "title": "Implement data input measures and protect personal data and intellectual property",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "privacy-data-protection",
      "framework": "cn-genai-measures",
      "reference": "Art. 7(3)",
      "label": "GenAI Art. 7(3)",
      "title": "Consent or another lawful basis for personal information in training data",
      "strength": "core",
      "verified": true,
      "note": "CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "cn-genai-measures",
      "reference": "Art. 11",
      "label": "GenAI Art. 11",
      "title": "Protection of user input and records",
      "strength": "core",
      "verified": true,
      "note": "No unnecessary collection; access, correction and deletion requests handled; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "explainability",
      "framework": "eu-ai-act",
      "reference": "Art. 86",
      "label": "Art. 86",
      "title": "Right to explanation of individual decision-making",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_86",
      "obligationId": null
    },
    {
      "topic": "explainability",
      "framework": "eu-ai-act",
      "reference": "Art. 13(3)(b)(iv)–(v)",
      "label": "Art. 13(3)(b)(iv)–(v)",
      "title": "Information relevant to explain output; performance for specific persons or groups",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_13",
      "obligationId": "AIGE-OBL-EUAIA-ART13"
    },
    {
      "topic": "explainability",
      "framework": "gdpr",
      "reference": "Art. 15(1)(h)",
      "label": "Art. 15(1)(h)",
      "title": "Meaningful information about the logic involved",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_15",
      "obligationId": null
    },
    {
      "topic": "explainability",
      "framework": "gdpr",
      "reference": "Art. 13(2)(f)",
      "label": "Art. 13(2)(f)",
      "title": "Existence of automated decision-making",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_13",
      "obligationId": null
    },
    {
      "topic": "explainability",
      "framework": "gdpr",
      "reference": "Art. 22(3)",
      "label": "Art. 22(3)",
      "title": "Right to obtain human intervention and to contest the decision",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_22",
      "obligationId": null
    },
    {
      "topic": "explainability",
      "framework": "iso-42001",
      "reference": "A.8.2",
      "label": "A.8.2",
      "title": "System documentation and information for users",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A8"
    },
    {
      "topic": "explainability",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.9",
      "label": "MEASURE 2.9",
      "title": "MEASURE 2.9: The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "explainability",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.8",
      "label": "MEASURE 2.8",
      "title": "MEASURE 2.8: Risks associated with transparency and accountability as identified in the MAP function are examined and documented",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "explainability",
      "framework": "csa-aicm",
      "reference": "GRC-13",
      "label": "GRC-13",
      "title": "Explainability Requirement",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "explainability",
      "framework": "csa-aicm",
      "reference": "GRC-14",
      "label": "GRC-14",
      "title": "Explainability Evaluation",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "explainability",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 34(1)(2)",
      "label": "Art. 34(1)(2)",
      "title": "Explanation plan: result, main criteria, training-data overview",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "explainability",
      "framework": "uk-duaa",
      "reference": "Art. 22C",
      "label": "UK GDPR Art. 22C",
      "title": "Safeguards for automated decision-making",
      "strength": "core",
      "verified": true,
      "note": "Information about the decision, representations, human intervention and contest.",
      "url": "https://www.legislation.gov.uk/ukpga/2025/18/section/80",
      "obligationId": "AIGE-OBL-UK-ADM"
    },
    {
      "topic": "explainability",
      "framework": "uk-atrs",
      "reference": "2.3.5",
      "label": "ATRS 2.3.5",
      "title": "Appeals and review",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "explainability",
      "framework": "sg-genai-framework",
      "reference": "3",
      "label": "GenAI 3",
      "title": "Trusted Development and Deployment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "explainability",
      "framework": "coe-cets-225",
      "reference": "Art. 14(2)",
      "label": "CoE Art. 14(2)",
      "title": "Documentation sufficient to contest decisions; complaint to authorities",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "explainability",
      "framework": "oecd-ai-principles",
      "reference": "1.3",
      "label": "OECD 1.3",
      "title": "Transparency and explainability",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "explainability",
      "framework": "cn-algo-recommendation",
      "reference": "Art. 17",
      "label": "AlgoRec Art. 17",
      "title": "Explain where an algorithm significantly affects user rights",
      "strength": "related",
      "verified": true,
      "note": "Third paragraph; the first two give an opt-out and control over user tags; CAC text.",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "obligationId": "AIGE-OBL-CN-ALGOREC"
    },
    {
      "topic": "ai-literacy",
      "framework": "eu-ai-act",
      "reference": "Art. 4",
      "label": "Art. 4",
      "title": "AI literacy",
      "strength": "core",
      "verified": true,
      "note": "Reworded by the Digital Omnibus: providers and deployers take measures to support AI literacy, without a guaranteed level.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4",
      "obligationId": "AIGE-OBL-EUAIA-ART4"
    },
    {
      "topic": "ai-literacy",
      "framework": "eu-ai-act",
      "reference": "Art. 26(2)",
      "label": "Art. 26(2)",
      "title": "Oversight by people with the competence, training and authority it needs",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
      "obligationId": "AIGE-OBL-EUAIA-ART26"
    },
    {
      "topic": "ai-literacy",
      "framework": "eu-ai-act",
      "reference": "Art. 95(2)(c)",
      "label": "Art. 95(2)(c)",
      "title": "Codes of conduct: promoting AI literacy",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_95",
      "obligationId": null
    },
    {
      "topic": "ai-literacy",
      "framework": "gdpr",
      "reference": "Art. 39(1)(b)",
      "label": "Art. 39(1)(b)",
      "title": "DPO tasks: awareness-raising and training of staff",
      "strength": "related",
      "verified": false,
      "note": "Read on a secondary reproduction of the GDPR; EUR-Lex refused automated access on 2026-09-24 and chapter 19 does not cite this article (verify).",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_39",
      "obligationId": null
    },
    {
      "topic": "ai-literacy",
      "framework": "iso-42001",
      "reference": "7.2",
      "label": "7.2",
      "title": "Competence",
      "strength": "core",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "ai-literacy",
      "framework": "iso-42001",
      "reference": "7.3",
      "label": "7.3",
      "title": "Awareness",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "ai-literacy",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 2.2",
      "label": "GOVERN 2.2",
      "title": "GOVERN 2.2: The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "ai-literacy",
      "framework": "nist-ai-rmf",
      "reference": "MAP 3.4",
      "label": "MAP 3.4",
      "title": "MAP 3.4: Processes for operator and practitioner proficiency with AI system performance and trustworthiness, and relevant technical standards and certifications, are defined, assessed, and documented",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "ai-literacy",
      "framework": "csa-aicm",
      "reference": "HRS-14",
      "label": "HRS-14",
      "title": "AI Competency Training",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "ai-literacy",
      "framework": "csa-aicm",
      "reference": "HRS-11",
      "label": "HRS-11",
      "title": "Security Awareness Training",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "ai-literacy",
      "framework": "uk-atrs",
      "reference": "2.3.4",
      "label": "ATRS 2.3.4",
      "title": "Required training",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gov.uk/government/publications/algorithmic-transparency-template",
      "obligationId": null
    },
    {
      "topic": "ai-literacy",
      "framework": "sg-agentic-framework",
      "reference": "2.4",
      "label": "Agentic 2.4",
      "title": "Enable end-user responsibility",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "ai-literacy",
      "framework": "sg-genai-framework",
      "reference": "9",
      "label": "GenAI 9",
      "title": "AI for Public Good",
      "strength": "related",
      "verified": true,
      "note": "Includes upskilling workers.",
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "ai-literacy",
      "framework": "cn-genai-measures",
      "reference": "Art. 10",
      "label": "GenAI Art. 10",
      "title": "Guide users to understand and use generative AI rationally",
      "strength": "related",
      "verified": true,
      "note": "Also protects minors from over-reliance; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "conformity-assessment",
      "framework": "eu-ai-act",
      "reference": "Art. 43",
      "label": "Art. 43",
      "title": "Conformity assessment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_43",
      "obligationId": "AIGE-OBL-EUAIA-ART43"
    },
    {
      "topic": "conformity-assessment",
      "framework": "eu-ai-act",
      "reference": "Art. 47",
      "label": "Art. 47",
      "title": "EU declaration of conformity",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_47",
      "obligationId": "AIGE-OBL-EUAIA-ART47"
    },
    {
      "topic": "conformity-assessment",
      "framework": "eu-ai-act",
      "reference": "Art. 48",
      "label": "Art. 48",
      "title": "CE marking",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_48",
      "obligationId": null
    },
    {
      "topic": "conformity-assessment",
      "framework": "eu-ai-act",
      "reference": "Art. 40",
      "label": "Art. 40",
      "title": "Harmonised standards and standardisation deliverables",
      "strength": "related",
      "verified": true,
      "note": "Presumption of conformity once a harmonised standard is cited in the Official Journal.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_40",
      "obligationId": null
    },
    {
      "topic": "conformity-assessment",
      "framework": "gdpr",
      "reference": "Art. 42",
      "label": "Art. 42",
      "title": "Certification",
      "strength": "related",
      "verified": false,
      "note": "Read on a secondary reproduction of the GDPR; EUR-Lex refused automated access on 2026-09-24 and chapter 19 does not cite this article (verify).",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_42",
      "obligationId": null
    },
    {
      "topic": "conformity-assessment",
      "framework": "iso-42001",
      "reference": "9.2",
      "label": "9.2",
      "title": "Internal audit",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": null
    },
    {
      "topic": "conformity-assessment",
      "framework": "iso-42006",
      "reference": "ISO/IEC 42006",
      "label": "ISO/IEC 42006",
      "title": "Requirements for bodies providing audit and certification of AI management systems",
      "strength": "core",
      "verified": true,
      "note": "The whole standard: who may credibly certify an organisation to ISO/IEC 42001.",
      "url": "https://www.iso.org/standard/42006",
      "obligationId": "AIGE-OBL-ISO42006-CB"
    },
    {
      "topic": "conformity-assessment",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 1.3",
      "label": "MEASURE 1.3",
      "title": "MEASURE 1.3: Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "conformity-assessment",
      "framework": "csa-aicm",
      "reference": "A&A-02",
      "label": "A&A-02",
      "title": "Independent Assessments",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "conformity-assessment",
      "framework": "csa-aicm",
      "reference": "A&A-04",
      "label": "A&A-04",
      "title": "Requirements Compliance",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "conformity-assessment",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 33",
      "label": "Art. 33",
      "title": "Confirmation of high-impact AI",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "conformity-assessment",
      "framework": "sg-genai-framework",
      "reference": "5",
      "label": "GenAI 5",
      "title": "Testing and Assurance",
      "strength": "related",
      "verified": true,
      "note": "Third-party testing and common testing standards.",
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "conformity-assessment",
      "framework": "en-18286",
      "reference": "EN 18286",
      "label": "EN 18286",
      "title": "Quality management system for EU AI Act regulatory purposes",
      "strength": "related",
      "verified": true,
      "note": "A harmonised-standard candidate for Art. 17; not cited in the Official Journal as of 2026-09-24.",
      "url": "https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/",
      "obligationId": null
    },
    {
      "topic": "conformity-assessment",
      "framework": "cn-genai-measures",
      "reference": "Art. 17",
      "label": "GenAI Art. 17",
      "title": "Security assessment and algorithm filing",
      "strength": "related",
      "verified": true,
      "note": "Services with public-opinion attributes or social-mobilisation capacity; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "eu-ai-act",
      "reference": "Art. 53",
      "label": "Art. 53",
      "title": "Obligations for providers of general-purpose AI models",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
      "obligationId": "AIGE-OBL-EUAIA-ART53"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "eu-ai-act",
      "reference": "Art. 55",
      "label": "Art. 55",
      "title": "Obligations of providers of general-purpose AI models with systemic risk",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_55",
      "obligationId": "AIGE-OBL-EUAIA-ART55"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "eu-ai-act",
      "reference": "Art. 51",
      "label": "Art. 51",
      "title": "Classification of general-purpose AI models as general-purpose AI models with systemic risk",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_51",
      "obligationId": null
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "eu-ai-act",
      "reference": "Art. 56",
      "label": "Art. 56",
      "title": "Codes of practice",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_56",
      "obligationId": null
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "gpai-code-of-practice",
      "reference": "Transparency 1.1",
      "label": "Transparency 1.1",
      "title": "Drawing up and keeping up-to-date model documentation",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118120",
      "obligationId": "AIGE-OBL-GPAICOP-TRANSPARENCY"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C1",
      "label": "Safety C1",
      "title": "Commitment 1: Safety and Security Framework",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "gpai-code-of-practice",
      "reference": "Safety 3.2",
      "label": "Safety 3.2",
      "title": "Measure 3.2: Model evaluations",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "gpai-code-of-practice",
      "reference": "Safety C7",
      "label": "Safety C7",
      "title": "Commitment 7: Safety and Security Model Reports",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
      "obligationId": "AIGE-OBL-GPAICOP-SAFETY"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "csa-aicm",
      "reference": "MDS-12",
      "label": "MDS-12",
      "title": "Open Model Risk Assessment",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "csa-aicm",
      "reference": "MDS-03",
      "label": "MDS-03",
      "title": "Model Documentation",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 32",
      "label": "Art. 32",
      "title": "Safety duties for AI above the compute threshold",
      "strength": "core",
      "verified": true,
      "note": "Applies where cumulative training compute exceeds the threshold the enforcement decree sets.",
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "sg-genai-framework",
      "reference": "8",
      "label": "GenAI 8",
      "title": "Safety and Alignment R&D",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 1",
      "label": "G7 Action 1",
      "title": "Identify, evaluate and mitigate risks across the lifecycle, including testing",
      "strength": "related",
      "verified": true,
      "note": "The whole code addresses organisations developing advanced AI systems.",
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "gpai-foundation-models",
      "framework": "cn-genai-measures",
      "reference": "Art. 7",
      "label": "GenAI Art. 7",
      "title": "Lawful data and foundation-model sources",
      "strength": "related",
      "verified": true,
      "note": "Point (1): use data and foundation models with lawful sources; CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "ip-copyright",
      "framework": "eu-ai-act",
      "reference": "Art. 53(1)(c)",
      "label": "Art. 53(1)(c)",
      "title": "Copyright policy, including rights reservations",
      "strength": "core",
      "verified": true,
      "note": "Identify and honour reservations of rights under Art. 4(3) of Directive (EU) 2019/790.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
      "obligationId": "AIGE-OBL-EUAIA-ART53"
    },
    {
      "topic": "ip-copyright",
      "framework": "eu-ai-act",
      "reference": "Art. 53(1)(d)",
      "label": "Art. 53(1)(d)",
      "title": "Public summary of the content used for training",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
      "obligationId": null
    },
    {
      "topic": "ip-copyright",
      "framework": "gpai-code-of-practice",
      "reference": "Copyright 1.1",
      "label": "Copyright 1.1",
      "title": "Draw up, keep up-to-date and implement a copyright policy",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
      "obligationId": "AIGE-OBL-GPAICOP-COPYRIGHT"
    },
    {
      "topic": "ip-copyright",
      "framework": "gpai-code-of-practice",
      "reference": "Copyright 1.2",
      "label": "Copyright 1.2",
      "title": "Reproduce and extract only lawfully accessible copyright-protected content",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
      "obligationId": "AIGE-OBL-GPAICOP-COPYRIGHT"
    },
    {
      "topic": "ip-copyright",
      "framework": "gpai-code-of-practice",
      "reference": "Copyright 1.3",
      "label": "Copyright 1.3",
      "title": "Identify and comply with rights reservations when crawling the World Wide Web",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
      "obligationId": "AIGE-OBL-GPAICOP-COPYRIGHT"
    },
    {
      "topic": "ip-copyright",
      "framework": "gpai-code-of-practice",
      "reference": "Copyright 1.4",
      "label": "Copyright 1.4",
      "title": "Mitigate the risk of copyright-infringing outputs",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
      "obligationId": "AIGE-OBL-GPAICOP-COPYRIGHT"
    },
    {
      "topic": "ip-copyright",
      "framework": "gpai-code-of-practice",
      "reference": "Copyright 1.5",
      "label": "Copyright 1.5",
      "title": "Designate a point of contact and enable the lodging of complaints",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
      "obligationId": "AIGE-OBL-GPAICOP-COPYRIGHT"
    },
    {
      "topic": "ip-copyright",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 6.1",
      "label": "GOVERN 6.1",
      "title": "GOVERN 6.1: Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "ip-copyright",
      "framework": "nist-ai-rmf",
      "reference": "MAP 4.1",
      "label": "MAP 4.1",
      "title": "MAP 4.1: Approaches for mapping AI technology and legal risks of its components, including the use of third-party data or software, are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MAP"
    },
    {
      "topic": "ip-copyright",
      "framework": "csa-aicm",
      "reference": "DSP-20",
      "label": "DSP-20",
      "title": "Data Provenance and Transparency",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "ip-copyright",
      "framework": "sg-genai-framework",
      "reference": "2",
      "label": "GenAI 2",
      "title": "Data",
      "strength": "related",
      "verified": true,
      "note": "Balancing copyright with data accessibility for training.",
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "ip-copyright",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 11",
      "label": "G7 Action 11",
      "title": "Implement data input measures and protect personal data and intellectual property",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "ip-copyright",
      "framework": "cn-genai-measures",
      "reference": "Art. 7(2)",
      "label": "GenAI Art. 7(2)",
      "title": "No infringement of IP rights in training data",
      "strength": "core",
      "verified": true,
      "note": "CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "ip-copyright",
      "framework": "cn-genai-measures",
      "reference": "Art. 4(3)",
      "label": "GenAI Art. 4(3)",
      "title": "Respect IP rights and business ethics",
      "strength": "related",
      "verified": true,
      "note": "CAC text.",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "eu-ai-act",
      "reference": "Art. 14",
      "label": "Art. 14",
      "title": "Human oversight",
      "strength": "related",
      "verified": true,
      "note": "No agent-specific article; oversight and the Art. 14(4)(e) stop duty apply to agentic high-risk systems.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_14",
      "obligationId": "AIGE-OBL-EUAIA-ART14"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 3.2",
      "label": "GOVERN 3.2",
      "title": "GOVERN 3.2: Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "csa-aicm",
      "reference": "IAM-18",
      "label": "IAM-18",
      "title": "Agent Access Restriction",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "csa-aicm",
      "reference": "AIS-11",
      "label": "AIS-11",
      "title": "Agents Security Boundaries",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "csa-aicm",
      "reference": "IAM-12",
      "label": "IAM-12",
      "title": "Unique Identities",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "owasp-agentic-top-10",
      "reference": "ASI03",
      "label": "ASI03",
      "title": "Identity and Privilege Abuse",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "obligationId": "AIGE-OBL-OWASP-AGENTIC"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "owasp-llm-top-10",
      "reference": "LLM03:2026",
      "label": "LLM03:2026",
      "title": "Excessive Agency",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "owasp-agentic-top-10",
      "reference": "ASI02",
      "label": "ASI02",
      "title": "Tool Misuse and Exploitation",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "obligationId": "AIGE-OBL-OWASP-AGENTIC"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "owasp-agentic-top-10",
      "reference": "ASI07",
      "label": "ASI07",
      "title": "Insecure Inter-Agent Communication",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "obligationId": "AIGE-OBL-OWASP-AGENTIC"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "owasp-agentic-top-10",
      "reference": "ASI10",
      "label": "ASI10",
      "title": "Rogue Agents",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "obligationId": "AIGE-OBL-OWASP-AGENTIC"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "sg-agentic-framework",
      "reference": "2.1.2",
      "label": "Agentic 2.1.2",
      "title": "Bound risks through design by defining agents limits and permissions",
      "strength": "core",
      "verified": true,
      "note": "Includes agent identity: unique, verifiable and tied to an accountable human or supervising agent.",
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "sg-agentic-framework",
      "reference": "2.2.2",
      "label": "Agentic 2.2.2",
      "title": "Design for meaningful human oversight",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.2",
      "label": "TC260 App. 2 II.2",
      "title": "Identity and access management",
      "strength": "core",
      "verified": true,
      "note": "Identity and permissions per agent; printed pp. 120-121.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "agent-identity-autonomy",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.3",
      "label": "TC260 App. 2 II.3",
      "title": "Strengthen human approval",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "content-provenance",
      "framework": "eu-ai-act",
      "reference": "Art. 50(2)",
      "label": "Art. 50(2)",
      "title": "Machine-readable marking of synthetic content",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_50",
      "obligationId": "AIGE-OBL-EUAIA-ART50"
    },
    {
      "topic": "content-provenance",
      "framework": "eu-ai-act",
      "reference": "Art. 50(4)",
      "label": "Art. 50(4)",
      "title": "Disclosure of deep fakes",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_50",
      "obligationId": "AIGE-OBL-EUAIA-ART50"
    },
    {
      "topic": "content-provenance",
      "framework": "eu-ai-act",
      "reference": "Art. 3(60)",
      "label": "Art. 3(60)",
      "title": "Definition of deep fake",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_3",
      "obligationId": null
    },
    {
      "topic": "content-provenance",
      "framework": "csa-aicm",
      "reference": "MDS-09",
      "label": "MDS-09",
      "title": "Model Signing/Ownership Verification",
      "strength": "related",
      "verified": true,
      "note": "Model provenance rather than content provenance; the signing mechanism is the same.",
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "content-provenance",
      "framework": "owasp-llm-top-10",
      "reference": "LLM07:2026",
      "label": "LLM07:2026",
      "title": "Misinformation",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "obligationId": "AIGE-OBL-OWASP-LLM"
    },
    {
      "topic": "content-provenance",
      "framework": "kr-ai-basic-act",
      "reference": "Art. 31",
      "label": "Art. 31",
      "title": "Transparency: prior notice, output labelling, realistic synthetic content",
      "strength": "core",
      "verified": true,
      "note": "Outputs labelled as generated; sound, images or video hard to tell from reality must be recognisable as AI-generated.",
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "obligationId": "AIGE-OBL-KR-AIBASIC"
    },
    {
      "topic": "content-provenance",
      "framework": "sg-genai-framework",
      "reference": "7",
      "label": "GenAI 7",
      "title": "Content Provenance",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "content-provenance",
      "framework": "g7-hiroshima-coc",
      "reference": "Action 7",
      "label": "G7 Action 7",
      "title": "Deploy content authentication and provenance mechanisms where feasible",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "obligationId": null
    },
    {
      "topic": "content-provenance",
      "framework": "cn-content-labelling",
      "reference": "Art. 4",
      "label": "Label Art. 4",
      "title": "Explicit labels for generated content",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
      "obligationId": "AIGE-OBL-CN-LABEL"
    },
    {
      "topic": "content-provenance",
      "framework": "cn-content-labelling",
      "reference": "Art. 5",
      "label": "Label Art. 5",
      "title": "Implicit (metadata) labels",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
      "obligationId": "AIGE-OBL-CN-LABEL"
    },
    {
      "topic": "content-provenance",
      "framework": "cn-deep-synthesis",
      "reference": "Art. 17",
      "label": "DeepSyn Art. 17",
      "title": "Conspicuous labels for confusable content",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "obligationId": "AIGE-OBL-CN-DEEPSYN"
    },
    {
      "topic": "content-provenance",
      "framework": "cn-genai-measures",
      "reference": "Art. 12",
      "label": "GenAI Art. 12",
      "title": "Labelling of generated content",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "obligationId": "AIGE-OBL-CN-GENAI"
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "eu-ai-act",
      "reference": "Art. 57",
      "label": "Art. 57",
      "title": "AI regulatory sandboxes",
      "strength": "core",
      "verified": true,
      "note": "At least one national sandbox per Member State, due by 2 Aug 2027 after the Digital Omnibus (was 2 Aug 2026).",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_57",
      "obligationId": null
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "eu-ai-act",
      "reference": "Art. 58",
      "label": "Art. 58",
      "title": "Detailed arrangements for, and functioning of, AI regulatory sandboxes",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_58",
      "obligationId": null
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "eu-ai-act",
      "reference": "Art. 59",
      "label": "Art. 59",
      "title": "Further processing of personal data in the AI regulatory sandbox",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_59",
      "obligationId": null
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "eu-ai-act",
      "reference": "Art. 60",
      "label": "Art. 60",
      "title": "Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_60",
      "obligationId": "AIGE-OBL-EUAIA-ART60"
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "eu-ai-act",
      "reference": "Art. 61",
      "label": "Art. 61",
      "title": "Informed consent to participate in testing in real world conditions",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_61",
      "obligationId": null
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "iso-42001",
      "reference": "A.6.2.4",
      "label": "A.6.2.4",
      "title": "AI system verification and validation",
      "strength": "related",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.3",
      "label": "MEASURE 2.3",
      "title": "MEASURE 2.3: AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s)",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "csa-aicm",
      "reference": "AIS-13",
      "label": "AIS-13",
      "title": "AI Sandboxing",
      "strength": "related",
      "verified": true,
      "note": "Technical isolation of AI tools and plugins, not a regulatory sandbox.",
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "sg-agentic-framework",
      "reference": "2.3.2",
      "label": "Agentic 2.3.2",
      "title": "Before deploying, test agents",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "coe-cets-225",
      "reference": "Art. 13",
      "label": "CoE Art. 13",
      "title": "Safe innovation (controlled testing environments)",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "sandboxes-real-world-testing",
      "framework": "cn-tc260-framework",
      "reference": "App. 2 II.6",
      "label": "TC260 App. 2 II.6",
      "title": "Sandbox validation and red teaming",
      "strength": "related",
      "verified": true,
      "note": "Technical sandbox validation for agents, not a regulatory sandbox; printed pp. 124-125.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-AGENTS"
    },
    {
      "topic": "environmental-impact",
      "framework": "eu-ai-act",
      "reference": "Annex XI 1(2)(e)",
      "label": "Annex XI 1(2)(e)",
      "title": "Known or estimated energy consumption of the GPAI model",
      "strength": "core",
      "verified": true,
      "note": "Part of the technical documentation GPAI providers keep under Art. 53(1)(a); may be estimated from compute where unknown.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#anx_XI",
      "obligationId": "AIGE-OBL-EUAIA-ART53"
    },
    {
      "topic": "environmental-impact",
      "framework": "eu-ai-act",
      "reference": "Art. 40(2)",
      "label": "Art. 40(2)",
      "title": "Standardisation deliverables on energy and resource performance",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_40",
      "obligationId": null
    },
    {
      "topic": "environmental-impact",
      "framework": "eu-ai-act",
      "reference": "Art. 95(2)(b)",
      "label": "Art. 95(2)(b)",
      "title": "Codes of conduct: environmental sustainability",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_95",
      "obligationId": null
    },
    {
      "topic": "environmental-impact",
      "framework": "gpai-code-of-practice",
      "reference": "Transparency 1.1",
      "label": "Transparency 1.1",
      "title": "Drawing up and keeping up-to-date model documentation",
      "strength": "core",
      "verified": true,
      "note": "The Model Documentation Form asks for energy used in training and inference.",
      "url": "https://ec.europa.eu/newsroom/dae/redirection/document/118120",
      "obligationId": "AIGE-OBL-GPAICOP-TRANSPARENCY"
    },
    {
      "topic": "environmental-impact",
      "framework": "nist-ai-rmf",
      "reference": "MEASURE 2.12",
      "label": "MEASURE 2.12",
      "title": "MEASURE 2.12: Environmental impact and sustainability of AI model training and management activities as identified in the MAP function are assessed and documented",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MEASURE"
    },
    {
      "topic": "environmental-impact",
      "framework": "sg-genai-framework",
      "reference": "9",
      "label": "GenAI 9",
      "title": "AI for Public Good",
      "strength": "related",
      "verified": true,
      "note": "Includes developing AI systems sustainably.",
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "obligationId": "AIGE-OBL-SG-GENAI"
    },
    {
      "topic": "environmental-impact",
      "framework": "oecd-ai-principles",
      "reference": "1.1",
      "label": "OECD 1.1",
      "title": "Inclusive growth, sustainable development and well-being",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "eu-ai-act",
      "reference": "Art. 26",
      "label": "Art. 26",
      "title": "Obligations of deployers of high-risk AI systems",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
      "obligationId": "AIGE-OBL-EUAIA-ART26"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "eu-ai-act",
      "reference": "Art. 25",
      "label": "Art. 25",
      "title": "Responsibilities along the AI value chain",
      "strength": "related",
      "verified": true,
      "note": "A substantial modification or a changed intended purpose makes the deployer a provider.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_25",
      "obligationId": "AIGE-OBL-EUAIA-ART25"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "eu-ai-act",
      "reference": "Art. 43(4)",
      "label": "Art. 43(4)",
      "title": "New conformity assessment on substantial modification",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_43",
      "obligationId": "AIGE-OBL-EUAIA-ART43"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "eu-ai-act",
      "reference": "Art. 20",
      "label": "Art. 20",
      "title": "Corrective actions and duty of information",
      "strength": "related",
      "verified": true,
      "note": "Bring into conformity, withdraw, disable or recall.",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_20",
      "obligationId": null
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "eu-ai-act",
      "reference": "Art. 79",
      "label": "Art. 79",
      "title": "Procedure at national level for dealing with AI systems presenting a risk",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_79",
      "obligationId": null
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "eu-ai-act",
      "reference": "Art. 86",
      "label": "Art. 86",
      "title": "Right to explanation of individual decision-making",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_86",
      "obligationId": null
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "iso-42001",
      "reference": "A.9",
      "label": "A.9",
      "title": "Use of AI systems",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A9"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "iso-42001",
      "reference": "A.6.2.5",
      "label": "A.6.2.5",
      "title": "AI system deployment",
      "strength": "core",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "iso-42001",
      "reference": "A.6.2.6",
      "label": "A.6.2.6",
      "title": "AI system operation and monitoring",
      "strength": "core",
      "verified": false,
      "note": "Clause id and title as listed in the AI RMF to ISO/IEC FDIS 42001 crosswalk (contributed by Microsoft to NIST's AI Resource Center) and in CSA's AICM v1.1.1 mapping; the published ISO text was not opened.",
      "url": "https://www.iso.org/standard/42001",
      "obligationId": "AIGE-OBL-ISO42001-A6"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 2.4",
      "label": "MANAGE 2.4",
      "title": "MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "nist-ai-rmf",
      "reference": "MANAGE 4.1",
      "label": "MANAGE 4.1",
      "title": "MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-MANAGE"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "nist-ai-rmf",
      "reference": "GOVERN 1.7",
      "label": "GOVERN 1.7",
      "title": "GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://airc.nist.gov/airmf-resources/airmf/",
      "obligationId": "AIGE-OBL-NISTRMF-GOVERN"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "csa-aicm",
      "reference": "AIS-06",
      "label": "AIS-06",
      "title": "Secure Application Deployment",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "csa-aicm",
      "reference": "CCC-01",
      "label": "CCC-01",
      "title": "Change Management Policy and Procedures",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "csa-aicm",
      "reference": "DSP-02",
      "label": "DSP-02",
      "title": "Secure Disposal",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "obligationId": "AIGE-OBL-CSA-AICM"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "sg-agentic-framework",
      "reference": "2.3.3",
      "label": "Agentic 2.3.3",
      "title": "When deploying, continuously monitor and test",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "obligationId": null
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "coe-cets-225",
      "reference": "Art. 16(2)(g)",
      "label": "CoE Art. 16(2)(g)",
      "title": "Testing before first use and when significantly modified",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://rm.coe.int/1680afae3c",
      "obligationId": null
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "oecd-ai-principles",
      "reference": "1.4",
      "label": "OECD 1.4",
      "title": "Robustness, security and safety",
      "strength": "related",
      "verified": true,
      "note": "The 2024 revision asks for mechanisms to override, repair or decommission safely.",
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "obligationId": null
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "cn-tc260-framework",
      "reference": "5.3",
      "label": "TC260 5.3",
      "title": "Operators' safety guidelines",
      "strength": "related",
      "verified": true,
      "note": "Logs kept at least six months and audited; voluntary.",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "cn-tc260-framework",
      "reference": "5.3.19",
      "label": "TC260 5.3.19",
      "title": "Re-assessment on material change",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "obligationId": "AIGE-OBL-CN-TC260-OPS"
    },
    {
      "topic": "risk-management",
      "framework": "us-gao-ai-accountability",
      "reference": "1.6",
      "label": "1.6",
      "title": "Risk management: implement an AI-specific risk management plan to systematically identify, analyze, and mitigate risks",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "governance-accountability",
      "framework": "us-gao-ai-accountability",
      "reference": "1.2",
      "label": "1.2",
      "title": "Roles and responsibilities: define clear roles, responsibilities, and delegation of authority for the AI system",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "governance-accountability",
      "framework": "us-gao-ai-accountability",
      "reference": "1.1",
      "label": "1.1",
      "title": "Clear goals: define clear goals and objectives for the AI system",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "governance-accountability",
      "framework": "us-gao-ai-accountability",
      "reference": "1.3",
      "label": "1.3",
      "title": "Values: demonstrate a commitment to values and principles established by the entity",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "impact-assessment",
      "framework": "us-gao-ai-accountability",
      "reference": "1.5",
      "label": "1.5",
      "title": "Stakeholder involvement: include diverse perspectives from a community of stakeholders throughout the AI life cycle",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "data-governance",
      "framework": "us-gao-ai-accountability",
      "reference": "2.1",
      "label": "2.1",
      "title": "Sources: document sources and origins of data used to develop the models",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-DATA"
    },
    {
      "topic": "data-governance",
      "framework": "us-gao-ai-accountability",
      "reference": "2.2",
      "label": "2.2",
      "title": "Reliability: assess reliability of data used to develop the models",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-DATA"
    },
    {
      "topic": "data-governance",
      "framework": "us-gao-ai-accountability",
      "reference": "2.4",
      "label": "2.4",
      "title": "Variable selection: assess data variables used in the AI component models",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-DATA"
    },
    {
      "topic": "data-governance",
      "framework": "us-gao-ai-accountability",
      "reference": "2.5",
      "label": "2.5",
      "title": "Enhancement: assess the use of synthetic, imputed, and/or augmented data",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-DATA"
    },
    {
      "topic": "documentation-transparency",
      "framework": "us-gao-ai-accountability",
      "reference": "1.9",
      "label": "1.9",
      "title": "Transparency: enable external stakeholders to access information on the design, operation, and limitations of the AI system",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "documentation-transparency",
      "framework": "us-gao-ai-accountability",
      "reference": "3.5",
      "label": "3.5",
      "title": "Documentation: document the methods for assessment, performance metrics, and outcomes of the AI system",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-PERF"
    },
    {
      "topic": "documentation-transparency",
      "framework": "us-gao-ai-accountability",
      "reference": "1.7",
      "label": "1.7",
      "title": "Specifications: establish and document technical specifications",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "inventory-registration",
      "framework": "us-gao-ai-accountability",
      "reference": "3.1",
      "label": "3.1",
      "title": "Documentation: catalog model and non-model components, along with operating specifications and parameters",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-PERF"
    },
    {
      "topic": "logging-traceability",
      "framework": "us-gao-ai-accountability",
      "reference": "4.3",
      "label": "4.3",
      "title": "Traceability: document results of monitoring activities and any corrective actions taken",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-MON"
    },
    {
      "topic": "human-oversight",
      "framework": "us-gao-ai-accountability",
      "reference": "3.9",
      "label": "3.9",
      "title": "Human supervision: define and develop procedures for human supervision of the AI system",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-PERF"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "us-gao-ai-accountability",
      "reference": "3.7",
      "label": "3.7",
      "title": "Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-PERF"
    },
    {
      "topic": "robustness-security-evals",
      "framework": "us-gao-ai-accountability",
      "reference": "3.2",
      "label": "3.2",
      "title": "Metrics: define performance metrics that are precise, consistent, and reproducible",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-PERF"
    },
    {
      "topic": "incident-monitoring",
      "framework": "us-gao-ai-accountability",
      "reference": "4.1",
      "label": "4.1",
      "title": "Planning: develop plans for continuous or routine monitoring of the AI system",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-MON"
    },
    {
      "topic": "incident-monitoring",
      "framework": "us-gao-ai-accountability",
      "reference": "4.2",
      "label": "4.2",
      "title": "Drift: establish the range of data and model drift that is acceptable",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-MON"
    },
    {
      "topic": "supply-chain",
      "framework": "us-gao-ai-accountability",
      "reference": "2.6",
      "label": "2.6",
      "title": "Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-DATA"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "us-gao-ai-accountability",
      "reference": "2.7",
      "label": "2.7",
      "title": "Bias: assess reliability, quality, and representativeness of the data used in operation, including potential biases",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-DATA"
    },
    {
      "topic": "fairness-non-discrimination",
      "framework": "us-gao-ai-accountability",
      "reference": "3.8",
      "label": "3.8",
      "title": "Bias: identify potential biases, inequities, and other societal concerns resulting from the AI system",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-PERF"
    },
    {
      "topic": "privacy-data-protection",
      "framework": "us-gao-ai-accountability",
      "reference": "2.8",
      "label": "2.8",
      "title": "Security and privacy: assess data security and privacy for the AI system",
      "strength": "core",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-DATA"
    },
    {
      "topic": "ai-literacy",
      "framework": "us-gao-ai-accountability",
      "reference": "1.4",
      "label": "1.4",
      "title": "Workforce: recruit, develop, and retain personnel with multidisciplinary skills and experiences",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "conformity-assessment",
      "framework": "us-gao-ai-accountability",
      "reference": "1.8",
      "label": "1.8",
      "title": "Compliance: ensure the AI system complies with relevant laws, regulations, standards, and guidance",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-GOV"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "us-gao-ai-accountability",
      "reference": "4.4",
      "label": "4.4",
      "title": "Ongoing assessment: assess the utility of the AI system to ensure its relevance to the current context",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-MON"
    },
    {
      "topic": "deployment-change-decommissioning",
      "framework": "us-gao-ai-accountability",
      "reference": "4.5",
      "label": "4.5",
      "title": "Scaling: identify conditions, if any, under which the AI system may be scaled or expanded beyond its current use",
      "strength": "related",
      "verified": true,
      "note": null,
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "obligationId": "AIGE-OBL-USGAO-MON"
    }
  ]
}
