{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/frameworks.json",
  "self": "https://aigovernanceengineer.com/api/v1/frameworks.json",
  "source": "https://aigovernanceengineer.com/resources/frameworks",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "frameworks": [
    {
      "id": "eu-ai-act",
      "name": "EU AI Act (post-Omnibus)",
      "short": "EU AI Act",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
      "summary": "The EU's horizontal, risk-tiered law for AI (Regulation (EU) 2024/1689), amended by the Digital Omnibus (Regulation (EU) 2026/1744). High-risk Annex III obligations apply from 2 December 2027; Annex I embedded systems from 2 August 2028.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-ai-act",
      "obligations": [
        "AIGE-OBL-EUAIA-ART3-1",
        "AIGE-OBL-EUAIA-ART4",
        "AIGE-OBL-EUAIA-ART4A",
        "AIGE-OBL-EUAIA-ART5",
        "AIGE-OBL-EUAIA-ART6",
        "AIGE-OBL-EUAIA-ART6-3",
        "AIGE-OBL-EUAIA-ART9",
        "AIGE-OBL-EUAIA-ART10",
        "AIGE-OBL-EUAIA-ART11",
        "AIGE-OBL-EUAIA-ART12",
        "AIGE-OBL-EUAIA-ART13",
        "AIGE-OBL-EUAIA-ART14",
        "AIGE-OBL-EUAIA-ART15",
        "AIGE-OBL-EUAIA-ART15-4",
        "AIGE-OBL-EUAIA-ART16-L",
        "AIGE-OBL-EUAIA-ART17",
        "AIGE-OBL-EUAIA-ART17-1M",
        "AIGE-OBL-EUAIA-ART18",
        "AIGE-OBL-EUAIA-ART19",
        "AIGE-OBL-EUAIA-ART20",
        "AIGE-OBL-EUAIA-ART22",
        "AIGE-OBL-EUAIA-ART23",
        "AIGE-OBL-EUAIA-ART24",
        "AIGE-OBL-EUAIA-ART25",
        "AIGE-OBL-EUAIA-ART26",
        "AIGE-OBL-EUAIA-ART26-2",
        "AIGE-OBL-EUAIA-ART26-4",
        "AIGE-OBL-EUAIA-ART26-5",
        "AIGE-OBL-EUAIA-ART26-6",
        "AIGE-OBL-EUAIA-ART26-7",
        "AIGE-OBL-EUAIA-ART26-11",
        "AIGE-OBL-EUAIA-ART27",
        "AIGE-OBL-EUAIA-ART43",
        "AIGE-OBL-EUAIA-ART43-4",
        "AIGE-OBL-EUAIA-ART47",
        "AIGE-OBL-EUAIA-ART48",
        "AIGE-OBL-EUAIA-ART49-71",
        "AIGE-OBL-EUAIA-ART50",
        "AIGE-OBL-EUAIA-ART52",
        "AIGE-OBL-EUAIA-ART53",
        "AIGE-OBL-EUAIA-ART53-1C",
        "AIGE-OBL-EUAIA-ART54",
        "AIGE-OBL-EUAIA-ART55",
        "AIGE-OBL-EUAIA-ART60",
        "AIGE-OBL-EUAIA-ART72",
        "AIGE-OBL-EUAIA-ART73",
        "AIGE-OBL-EUAIA-ART73-6",
        "AIGE-OBL-EUAIA-ART75-1A",
        "AIGE-OBL-EUAIA-ART86",
        "AIGE-OBL-EUAIA-ART87"
      ]
    },
    {
      "id": "gpai-code-of-practice",
      "name": "GPAI Code of Practice",
      "short": "GPAI Code",
      "type": "code",
      "issuer": "European Commission",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
      "summary": "The voluntary instrument (published 10 July 2025) providers use to demonstrate compliance with the GPAI obligations until harmonised standards exist. Three chapters: Safety and Security, Transparency and Copyright.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-gpai-code-of-practice",
      "obligations": [
        "AIGE-OBL-GPAICOP-SAFETY",
        "AIGE-OBL-GPAICOP-TRANSPARENCY",
        "AIGE-OBL-GPAICOP-COPYRIGHT",
        "AIGE-OBL-GPAICOP-SAFETY-C9",
        "AIGE-OBL-GPAICOP-SAFETY-APP1"
      ]
    },
    {
      "id": "gdpr",
      "name": "General Data Protection Regulation (EU) 2016/679",
      "short": "GDPR",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
      "summary": "The EU data-protection regulation, applying since 25 May 2018. It applies alongside the AI Act whenever an AI system processes personal data: lawful basis, minimisation, DPIA, automated decisions, data subject rights and breach notification.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-gdpr",
      "obligations": [
        "AIGE-OBL-GDPR-ART5-1B",
        "AIGE-OBL-GDPR-ART6",
        "AIGE-OBL-GDPR-ART7",
        "AIGE-OBL-GDPR-ART9",
        "AIGE-OBL-GDPR-ART13-14",
        "AIGE-OBL-GDPR-ART15-1H",
        "AIGE-OBL-GDPR-ART15-17-21",
        "AIGE-OBL-GDPR-ART22",
        "AIGE-OBL-GDPR-ART25",
        "AIGE-OBL-GDPR-ART5-2",
        "AIGE-OBL-GDPR-ART28",
        "AIGE-OBL-GDPR-ART30",
        "AIGE-OBL-GDPR-ART33-34",
        "AIGE-OBL-GDPR-ART35-36",
        "AIGE-OBL-GDPR-ART44-49"
      ]
    },
    {
      "id": "eu-nis2",
      "name": "NIS2 Directive (EU) 2022/2555",
      "short": "NIS2",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng",
      "summary": "The EU cyber-security directive for essential and important entities: risk-management measures (incl. business continuity and supply-chain security) and significant-incident reporting on a 24-hour, 72-hour and one-month clock. Member States apply their measures from 18 October 2024.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-nis2",
      "obligations": [
        "AIGE-OBL-NIS2-ART21-2",
        "AIGE-OBL-NIS2-ART23"
      ]
    },
    {
      "id": "eu-dora",
      "name": "Digital Operational Resilience Act (EU) 2022/2554",
      "short": "DORA",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng",
      "summary": "The EU regulation on the digital operational resilience of financial entities, applying since 17 January 2025: ICT risk management, major ICT-related incident reporting and the management of ICT third-party risk, including AI and model services.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-dora",
      "obligations": [
        "AIGE-OBL-DORA-ART19",
        "AIGE-OBL-DORA-ART28"
      ]
    },
    {
      "id": "eu-cra",
      "name": "Cyber Resilience Act (EU) 2024/2847",
      "short": "CRA",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "summary": "The EU regulation on cyber-security requirements for products with digital elements. Its reporting of actively exploited vulnerabilities and severe incidents (Article 14) applies from 11 September 2026; the rest from 11 December 2027.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-cra",
      "obligations": [
        "AIGE-OBL-CRA-ART14"
      ]
    },
    {
      "id": "eu-pld",
      "name": "Product Liability Directive (EU) 2024/2853",
      "short": "EU PLD",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng",
      "summary": "The revised EU strict-liability regime for defective products. Software, including AI systems, is a product; it applies to products placed on the market or put into service after 9 December 2026, the transposition deadline.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-pld",
      "obligations": [
        "AIGE-OBL-PLD-ART4",
        "AIGE-OBL-PLD-ART9-10",
        "AIGE-OBL-PLD-ART11-2"
      ]
    },
    {
      "id": "eu-dsm",
      "name": "Directive (EU) 2019/790 on copyright in the Digital Single Market",
      "short": "DSM Directive",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/dir/2019/790/oj/eng",
      "summary": "The EU copyright directive whose Article 4 text-and-data-mining exception applies only where rightholders have not reserved their works, for online content by machine-readable means. The AI Act points GPAI providers to it (Art. 53(1)(c)).",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-dsm",
      "obligations": [
        "AIGE-OBL-DSM-ART4-3"
      ]
    },
    {
      "id": "eu-dsa",
      "name": "Digital Services Act (EU) 2022/2065",
      "short": "DSA",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng",
      "summary": "The EU regulation on intermediary services, applying in full since 17 February 2024. For online platforms it bans deceptive or manipulative interface design and requires the main parameters of recommender systems to be explained.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-dsa",
      "obligations": [
        "AIGE-OBL-DSA-ART25",
        "AIGE-OBL-DSA-ART27"
      ]
    },
    {
      "id": "eu-ucpd",
      "name": "Unfair Commercial Practices Directive 2005/29/EC",
      "short": "UCPD",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/dir/2005/29/oj/eng",
      "summary": "The EU consumer-protection directive against unfair, misleading and aggressive commercial practices, whose blacklist was extended to fake and unverified consumer reviews by Directive (EU) 2019/2161. It reaches AI-generated claims, reviews and chatbot answers.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-ucpd",
      "obligations": [
        "AIGE-OBL-UCPD-ART5-7"
      ]
    },
    {
      "id": "eu-platform-work",
      "name": "Platform Work Directive (EU) 2024/2831",
      "short": "Platform Work Directive",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/dir/2024/2831/oj/eng",
      "summary": "The EU directive on platform work, including the first EU rules on algorithmic management: limits on data processing, transparency, human oversight and human review of automated monitoring and decision-making systems. Transposition by 2 December 2026.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-platform-work",
      "obligations": [
        "AIGE-OBL-PWD-ART7-11"
      ]
    },
    {
      "id": "eu-ccd2",
      "name": "Consumer Credit Directive (EU) 2023/2225",
      "short": "CCD2",
      "type": "law",
      "issuer": "European Union",
      "url": "https://eur-lex.europa.eu/eli/dir/2023/2225/oj/eng",
      "summary": "The revised EU consumer credit directive. Its creditworthiness rules give consumers a right to human intervention, an explanation and a review where the assessment involves automated processing; Member States apply it from 20 November 2026.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-eu-ccd2",
      "obligations": [
        "AIGE-OBL-CCD2-ART18-8"
      ]
    },
    {
      "id": "iso-42001",
      "name": "ISO/IEC 42001",
      "short": "ISO 42001",
      "type": "standard",
      "issuer": "ISO/IEC",
      "url": null,
      "summary": "The AI management-system (AIMS) standard (2023); Annex A groups control objectives into nine areas (A.2–A.10). It is a management-system standard, not the Article 17 QMS, and its European adoption confers no presumption of conformity.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-iso-42001",
      "obligations": [
        "AIGE-OBL-ISO42001-A2",
        "AIGE-OBL-ISO42001-A3",
        "AIGE-OBL-ISO42001-A4",
        "AIGE-OBL-ISO42001-A5",
        "AIGE-OBL-ISO42001-A6",
        "AIGE-OBL-ISO42001-A7",
        "AIGE-OBL-ISO42001-A8",
        "AIGE-OBL-ISO42001-A9",
        "AIGE-OBL-ISO42001-A10"
      ]
    },
    {
      "id": "iso-42005",
      "name": "ISO/IEC 42005",
      "short": "ISO 42005",
      "type": "standard",
      "issuer": "ISO/IEC",
      "url": "https://www.iso.org/standard/44545.html",
      "summary": "Guidance for AI system impact assessment (2025); the natural companion to EU AI Act Article 27 (FRIA) and ISO/IEC 42001 Annex A.5.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-iso-42005",
      "obligations": [
        "AIGE-OBL-ISO42005-IA"
      ]
    },
    {
      "id": "iso-42006",
      "name": "ISO/IEC 42006:2025",
      "short": "ISO 42006",
      "type": "standard",
      "issuer": "ISO/IEC",
      "url": "https://www.iso.org/standard/42006",
      "summary": "Requirements for bodies providing audit and certification of AI management systems (2025). It builds on ISO/IEC 17021-1 and sets the competence and consistency a certification body must meet to credibly certify an organisation to ISO/IEC 42001: in short, who may credibly certify you to 42001.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-iso-42006",
      "obligations": [
        "AIGE-OBL-ISO42006-CB"
      ]
    },
    {
      "id": "iso-23894",
      "name": "ISO/IEC 23894:2023",
      "short": "ISO 23894",
      "type": "standard",
      "issuer": "ISO/IEC",
      "url": "https://www.iso.org/standard/77304.html",
      "summary": "Guidance on AI risk management (2023), adapting ISO 31000 to AI. It gives organisations a process for identifying, analysing and treating AI-specific risk; a companion to EU AI Act Article 9 and the NIST AI RMF.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-iso-23894",
      "obligations": [
        "AIGE-OBL-ISO23894-RISK"
      ]
    },
    {
      "id": "iso-22989",
      "name": "ISO/IEC 22989:2022",
      "short": "ISO 22989",
      "type": "standard",
      "issuer": "ISO/IEC",
      "url": "https://www.iso.org/standard/74296.html",
      "summary": "AI concepts and terminology (2022): the shared vocabulary for AI systems, the AI system life cycle and AI stakeholder roles that the other SC 42 standards and many registries reuse.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-iso-22989",
      "obligations": [
        "AIGE-OBL-ISO22989-CONCEPTS"
      ]
    },
    {
      "id": "nist-ai-rmf",
      "name": "NIST AI RMF",
      "short": "NIST AI RMF",
      "type": "framework",
      "issuer": "NIST",
      "url": "https://www.nist.gov/itl/ai-risk-management-framework",
      "summary": "The AI Risk Management Framework 1.0 (January 2023; there is no 2.0). Voluntary and US-origin, it organises risk work into four functions (Govern, Map, Measure, Manage) that map cleanly onto the five-layer stack.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-nist-ai-rmf",
      "obligations": [
        "AIGE-OBL-NISTRMF-GOVERN",
        "AIGE-OBL-NISTRMF-MAP",
        "AIGE-OBL-NISTRMF-MEASURE",
        "AIGE-OBL-NISTRMF-MANAGE"
      ]
    },
    {
      "id": "nist-ai-agent-standards",
      "name": "NIST AI Agent Standards Initiative",
      "short": "NIST Agents",
      "type": "framework",
      "issuer": "NIST (CAISI)",
      "url": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure",
      "summary": "A NIST Center for AI Standards and Innovation initiative (launched 17 February 2026) to develop interoperable, secure standards for AI agents, spanning agent identity, authentication, authorisation and agent security.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-nist-ai-agent-standards",
      "obligations": [
        "AIGE-OBL-NIST-AGENTS"
      ]
    },
    {
      "id": "nist-ir-8596",
      "name": "NIST IR 8596 Cyber AI Profile (draft)",
      "short": "NIST IR 8596",
      "type": "framework",
      "issuer": "NIST",
      "url": "https://csrc.nist.gov/pubs/ir/8596/iprd",
      "summary": "A draft Cybersecurity Framework (CSF 2.0) profile for AI, the Cyber AI Profile, organised around Secure, Defend and Thwart. Initial preliminary draft released 16 December 2025 (comments closed 30 January 2026); still in draft as of 2026-09-24.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-nist-ir-8596",
      "obligations": [
        "AIGE-OBL-NIST-IR8596"
      ]
    },
    {
      "id": "nist-ai-800-1",
      "name": "NIST AI 800-1 (draft)",
      "short": "NIST AI 800-1",
      "type": "framework",
      "issuer": "NIST",
      "url": "https://www.nist.gov/news-events/news/2025/01/updated-guidelines-managing-misuse-risk-dual-use-foundation-models",
      "summary": "Draft voluntary guidance (Managing Misuse Risk for Dual-Use Foundation Models) for identifying, measuring and mitigating the misuse risk of dual-use foundation models across the AI lifecycle. Second public draft January 2025; still in draft as of 2026-09-24.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-nist-ai-800-1",
      "obligations": [
        "AIGE-OBL-NIST-AI800-1"
      ]
    },
    {
      "id": "nist-ai-600-1",
      "name": "NIST AI 600-1 Generative AI Profile",
      "short": "NIST AI 600-1",
      "type": "framework",
      "issuer": "NIST",
      "url": "https://doi.org/10.6028/NIST.AI.600-1",
      "summary": "The AI RMF profile for generative AI (26 July 2024): 12 risks that generative AI creates or exacerbates and suggested actions coded to the Govern, Map, Measure and Manage functions. Voluntary.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-nist-ai-600-1",
      "obligations": [
        "AIGE-OBL-NIST-AI600-1"
      ]
    },
    {
      "id": "csa-aicm",
      "name": "CSA AI Controls Matrix (AICM) v1.1",
      "short": "CSA AICM",
      "type": "controls",
      "issuer": "Cloud Security Alliance",
      "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
      "summary": "A control framework (published 22 June 2026) defining 247 control objectives across 18 domains, spanning governance, data, model and runtime, with crosswalks to ISO 42001 and NIST AI RMF.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-csa-aicm",
      "obligations": [
        "AIGE-OBL-CSA-AICM",
        "AIGE-OBL-CSA-AICM-AGENTIC",
        "AIGE-OBL-CSA-AICM-CATASTROPHIC"
      ]
    },
    {
      "id": "csa-star-for-ai",
      "name": "CSA STAR for AI",
      "short": "CSA STAR",
      "type": "framework",
      "issuer": "Cloud Security Alliance",
      "url": "https://cloudsecurityalliance.org/star/ai",
      "summary": "The assurance and certification programme built on the AICM, with a self-assessment tier, an automated \"Valid-AI-ted\" tier and a Level 2 combining third-party ISO/IEC 42001 certification with the validated assessment.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-csa-star-for-ai",
      "obligations": [
        "AIGE-OBL-CSA-STAR"
      ]
    },
    {
      "id": "owasp-agentic-top-10",
      "name": "OWASP Top 10 for Agentic Applications 2026",
      "short": "OWASP Agentic",
      "type": "framework",
      "issuer": "OWASP GenAI Security Project",
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
      "summary": "The agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents) that the runtime controls are built against.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-owasp-agentic-top-10",
      "obligations": [
        "AIGE-OBL-OWASP-AGENTIC"
      ]
    },
    {
      "id": "owasp-llm-top-10",
      "name": "OWASP Top 10 for LLM Applications 2026",
      "short": "OWASP LLM",
      "type": "framework",
      "issuer": "OWASP GenAI Security Project",
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
      "summary": "The LLM threat catalogue, including Excessive Agency at #3, answered by prompt-injection and output-handling controls and an eval gate.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-owasp-llm-top-10",
      "obligations": [
        "AIGE-OBL-OWASP-LLM"
      ]
    },
    {
      "id": "owasp-acs",
      "name": "OWASP Agent Control Standard (ACS)",
      "short": "OWASP ACS",
      "type": "standard",
      "issuer": "OWASP GenAI Security Project",
      "url": "https://genai.owasp.org/resource/agent-control-standard-acs/",
      "summary": "A standard for expressing agent controls as machine-readable control definitions the stack consumes directly.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-owasp-acs",
      "obligations": [
        "AIGE-OBL-OWASP-ACS"
      ]
    },
    {
      "id": "owasp-aibom",
      "name": "OWASP AIBOM",
      "short": "OWASP AIBOM",
      "type": "standard",
      "issuer": "OWASP GenAI Security Project",
      "url": "https://genai.owasp.org/initiatives/ai-sbom-initiative/",
      "summary": "The AI bill-of-materials format and generator, producing CycloneDX ML-BOM and SPDX 3.0 AI output at build.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-owasp-aibom",
      "obligations": [
        "AIGE-OBL-OWASP-AIBOM"
      ]
    },
    {
      "id": "ca-sb-53",
      "name": "California SB 53 (TFAIA)",
      "short": "California SB 53",
      "type": "law",
      "issuer": "State of California",
      "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
      "summary": "A frontier-AI transparency law in force 1 January 2026, binding large frontier developers (models above ~10^26 FLOP; developer revenue over USD 500M) to publish a frontier AI framework, and every frontier developer to report critical safety incidents to the California Office of Emergency Services within 15 days.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ca-sb-53",
      "obligations": [
        "AIGE-OBL-USCA-SB53",
        "AIGE-OBL-USCA-SB53-WHISTLE"
      ]
    },
    {
      "id": "ny-raise-act",
      "name": "New York RAISE Act",
      "short": "New York RAISE",
      "type": "law",
      "issuer": "State of New York",
      "url": "https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models",
      "summary": "A frontier-AI safety law (S6953B) binding large frontier developers to publish a safety framework and every frontier developer to report critical safety incidents. Signed 19 December 2025 and effective 1 January 2027 after a March 2026 chapter amendment, with oversight in an office within the New York Department of Financial Services (DFS).",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ny-raise-act",
      "obligations": [
        "AIGE-OBL-USNY-RAISE"
      ]
    },
    {
      "id": "ca-ab-2013",
      "name": "California AB 2013 (training-data transparency)",
      "short": "California AB 2013",
      "type": "law",
      "issuer": "State of California",
      "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240AB2013",
      "summary": "A California law (chaptered 28 September 2024) requiring developers of generative AI systems made available to Californians to post a summary of their training datasets on or before 1 January 2026 and on each substantial modification.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ca-ab-2013",
      "obligations": [
        "AIGE-OBL-USCA-AB2013"
      ]
    },
    {
      "id": "ca-sb-942",
      "name": "California AI Transparency Act (SB 942 as amended by AB 853)",
      "short": "California SB 942",
      "type": "law",
      "issuer": "State of California",
      "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB853",
      "summary": "A California provenance law: covered providers of public generative AI systems offer a free detection tool and embed latent disclosures in generated image, video and audio from 2 August 2026; large online platforms follow from 1 January 2027 and capture devices from 1 January 2028.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ca-sb-942",
      "obligations": [
        "AIGE-OBL-USCA-SB942"
      ]
    },
    {
      "id": "ca-sb-243",
      "name": "California SB 243 (companion chatbots)",
      "short": "California SB 243",
      "type": "law",
      "issuer": "State of California",
      "url": "https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB243",
      "summary": "A California law on companion chatbots (chaptered 13 October 2025): AI disclosure, three-hourly reminders and content limits for known minors, a suicide and self-harm protocol, annual reports from 1 July 2027 and a private right of action.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ca-sb-243",
      "obligations": [
        "AIGE-OBL-USCA-SB243"
      ]
    },
    {
      "id": "ca-cppa-regs",
      "name": "California CPPA regulations (ADMT, risk assessments, cybersecurity audits)",
      "short": "California CPPA",
      "type": "law",
      "issuer": "State of California",
      "url": "https://cppa.ca.gov/announcements/2025/20250923.html",
      "summary": "Regulations under the California Consumer Privacy Act, approved on 23 September 2025 and effective 1 January 2026: automated decisionmaking technology duties for significant decisions from 1 January 2027, risk assessments, and cybersecurity audits phased from 2028.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ca-cppa-regs",
      "obligations": [
        "AIGE-OBL-USCA-CPPA-ADMT",
        "AIGE-OBL-USCA-CPPA-RA"
      ]
    },
    {
      "id": "ny-gbl-47",
      "name": "New York General Business Law Article 47 (AI companion models)",
      "short": "New York GBL Art. 47",
      "type": "law",
      "issuer": "State of New York",
      "url": "https://www.nysenate.gov/legislation/laws/GBS/A47",
      "summary": "A New York law on AI companion models: a protocol to detect suicidal ideation and self-harm and refer users to crisis services, and a notice that the user is not talking to a human at the start and at least every three hours, enforced by the Attorney General.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ny-gbl-47",
      "obligations": [
        "AIGE-OBL-USNY-GBL47"
      ]
    },
    {
      "id": "il-hb-3773",
      "name": "Illinois HB 3773 (AI in employment)",
      "short": "Illinois HB 3773",
      "type": "law",
      "issuer": "State of Illinois",
      "url": "https://www.ilga.gov/legislation/publicacts/fulltext.asp?Name=103-0804",
      "summary": "An amendment to the Illinois Human Rights Act (Public Act 103-0804), effective 1 January 2026: employers may not use AI with a discriminatory effect on protected classes, nor ZIP codes as a proxy, and must notify employees and applicants.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-il-hb-3773",
      "obligations": [
        "AIGE-OBL-USIL-HB3773"
      ]
    },
    {
      "id": "nyc-ll-144",
      "name": "New York City Local Law 144 (automated employment decision tools)",
      "short": "NYC LL 144",
      "type": "law",
      "issuer": "City of New York",
      "url": "https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page",
      "summary": "A New York City law, enforced since 5 July 2023: an independent bias audit of an automated employment decision tool within one year before use, a published summary of the results and notices to candidates and employees.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-nyc-ll-144",
      "obligations": [
        "AIGE-OBL-USNYC-LL144"
      ]
    },
    {
      "id": "ut-ai-disclosure",
      "name": "Utah AI disclosure law (AI Policy Act as amended by SB 226)",
      "short": "Utah AI disclosure",
      "type": "law",
      "issuer": "State of Utah",
      "url": "https://le.utah.gov/Session/2025/bills/enrolled/SB0226.pdf",
      "summary": "Utah's generative-AI disclosure duties, re-enacted by SB 226 with effect from 7 May 2025: disclosure when a person clearly asks, prominent disclosure in high-risk interactions by regulated occupations, and a safe harbour for clear disclosure; the AI Policy Act itself is repealed on 1 July 2027.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-ut-ai-disclosure",
      "obligations": [
        "AIGE-OBL-USUT-SB226"
      ]
    },
    {
      "id": "co-sb21-169",
      "name": "Colorado SB21-169 (insurers' use of external consumer data)",
      "short": "Colorado SB21-169",
      "type": "law",
      "issuer": "State of Colorado",
      "url": "https://leg.colorado.gov/bills/sb21-169",
      "summary": "A Colorado law (effective 7 September 2021) barring insurers from unfair discrimination through external consumer data, algorithms and predictive models, with a risk-management framework, testing and a chief-risk-officer attestation under rules adopted per line of insurance.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-co-sb21-169",
      "obligations": [
        "AIGE-OBL-USCO-SB21-169"
      ]
    },
    {
      "id": "va-cdpa",
      "name": "Virginia Consumer Data Protection Act",
      "short": "Virginia CDPA",
      "type": "law",
      "issuer": "Commonwealth of Virginia",
      "url": "https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-580/",
      "summary": "Virginia's consumer privacy law. Controllers document data protection assessments for targeted advertising, sale, risky profiling and sensitive data for processing created after 1 January 2023, available to the Attorney General on request.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-va-cdpa",
      "obligations": [
        "AIGE-OBL-USVA-CDPA"
      ]
    },
    {
      "id": "co-privacy-act",
      "name": "Colorado Privacy Act (SB21-190)",
      "short": "Colorado Privacy Act",
      "type": "law",
      "issuer": "State of Colorado",
      "url": "https://leg.colorado.gov/bills/sb21-190",
      "summary": "Colorado's consumer privacy law, effective 1 July 2023: opt-outs incl. profiling in furtherance of significant decisions, data protection assessments and a universal opt-out mechanism.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-co-privacy-act",
      "obligations": [
        "AIGE-OBL-USCO-CPA"
      ]
    },
    {
      "id": "mn-cdpa",
      "name": "Minnesota Consumer Data Privacy Act",
      "short": "Minnesota CDPA",
      "type": "law",
      "issuer": "State of Minnesota",
      "url": "https://www.revisor.mn.gov/statutes/cite/325M.14",
      "summary": "Minnesota's consumer privacy law, effective 31 July 2025, whose consumer rights include questioning the result of profiling, learning the reason, reviewing and correcting the data and having the decision re-evaluated.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-mn-cdpa",
      "obligations": [
        "AIGE-OBL-USMN-MCDPA"
      ]
    },
    {
      "id": "il-bipa",
      "name": "Illinois Biometric Information Privacy Act (BIPA)",
      "short": "Illinois BIPA",
      "type": "law",
      "issuer": "State of Illinois",
      "url": "https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004&ChapterID=57",
      "summary": "The Illinois biometric privacy statute (Public Act 95-994, effective 3 October 2008): informed written consent before collecting biometric identifiers, a retention and destruction schedule and a private right of action with statutory damages.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-il-bipa",
      "obligations": [
        "AIGE-OBL-USIL-BIPA"
      ]
    },
    {
      "id": "wa-mhmda",
      "name": "Washington My Health My Data Act",
      "short": "Washington MHMDA",
      "type": "law",
      "issuer": "State of Washington",
      "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373&full=true",
      "summary": "Washington's consumer health data law (from 31 March 2024): consent to collect and separate consent to share consumer health data, including data derived by algorithms or machine learning, and a signed authorisation for any sale.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-wa-mhmda",
      "obligations": [
        "AIGE-OBL-USWA-MHMDA"
      ]
    },
    {
      "id": "us-omb-m-25-21",
      "name": "OMB Memorandum M-25-21 (federal use of AI)",
      "short": "OMB M-25-21",
      "type": "framework",
      "issuer": "United States (federal)",
      "url": "https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf",
      "summary": "The OMB memorandum of 3 April 2025 that binds US federal agencies: a definition of high-impact AI and minimum risk-management practices for it, documented within 365 days. It rescinded M-24-10.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-omb-m-25-21",
      "obligations": [
        "AIGE-OBL-USFED-OMB-M25-21"
      ]
    },
    {
      "id": "us-omb-m-26-04",
      "name": "OMB Memorandum M-26-04 (unbiased AI principles in procurement)",
      "short": "OMB M-26-04",
      "type": "framework",
      "issuer": "United States (federal)",
      "url": "https://www.whitehouse.gov/wp-content/uploads/2025/12/M-26-04-Increasing-Public-Trust-in-Artificial-Intelligence-Through-Unbiased-AI-Principles-1.pdf",
      "summary": "The OMB memorandum of 11 December 2025 implementing EO 14319: agencies updated procurement policies by 11 March 2026, and solicitations for large language models request minimum transparency from vendors.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-omb-m-26-04",
      "obligations": [
        "AIGE-OBL-USFED-OMB-M26-04"
      ]
    },
    {
      "id": "us-ecoa-reg-b",
      "name": "Equal Credit Opportunity Act, Regulation B (12 CFR 1002)",
      "short": "ECOA / Reg. B",
      "type": "law",
      "issuer": "United States (federal)",
      "url": "https://www.law.cornell.edu/cfr/text/12/1002.9",
      "summary": "The US fair-lending rule that requires a creditor taking adverse action to give the specific principal reasons, whatever the complexity of the model behind the decision.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-ecoa-reg-b",
      "obligations": [
        "AIGE-OBL-USFED-REGB-1002-9"
      ]
    },
    {
      "id": "us-fcra",
      "name": "Fair Credit Reporting Act (15 U.S.C. 1681m)",
      "short": "FCRA",
      "type": "law",
      "issuer": "United States (federal)",
      "url": "https://www.law.cornell.edu/uscode/text/15/1681m",
      "summary": "The US consumer-report statute whose adverse-action notice includes, since 21 July 2011, the numerical credit score used and its key factors.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-fcra",
      "obligations": [
        "AIGE-OBL-USFED-FCRA-1681M"
      ]
    },
    {
      "id": "us-title-vii-ugesp",
      "name": "Title VII and the Uniform Guidelines on Employee Selection Procedures",
      "short": "Title VII / UGESP",
      "type": "law",
      "issuer": "United States (federal)",
      "url": "https://www.law.cornell.edu/uscode/text/42/2000e-2",
      "summary": "US employment-discrimination law: disparate impact under Title VII s. 703(k) (Civil Rights Act of 1991) and the four-fifths rule of 29 CFR 1607.4(D), which apply to AI selection tools as to any other selection procedure.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-title-vii-ugesp",
      "obligations": [
        "AIGE-OBL-USFED-TITLE7-703K"
      ]
    },
    {
      "id": "us-ftc-act",
      "name": "FTC Act s. 5 (15 U.S.C. 45)",
      "short": "FTC Act s. 5",
      "type": "law",
      "issuer": "United States (federal)",
      "url": "https://www.law.cornell.edu/uscode/text/15/45",
      "summary": "The US prohibition of unfair or deceptive acts or practices, under which the Federal Trade Commission requires competent and reliable evidence for claims about an AI system's accuracy or performance.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-ftc-act",
      "obligations": [
        "AIGE-OBL-USFED-FTC-S5"
      ]
    },
    {
      "id": "us-take-it-down",
      "name": "TAKE IT DOWN Act (Public Law 119-12)",
      "short": "TAKE IT DOWN Act",
      "type": "law",
      "issuer": "United States (federal)",
      "url": "https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm",
      "summary": "A US federal law enacted on 19 May 2025 that criminalises knowing publication of non-consensual intimate images, including digital forgeries, and requires covered platforms to run a notice-and-removal process by 19 May 2026, removing reported images within 48 hours.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-take-it-down",
      "obligations": [
        "AIGE-OBL-USFED-TAKEITDOWN"
      ]
    },
    {
      "id": "us-gao-ai-accountability",
      "name": "GAO AI Accountability Framework (GAO-21-519SP)",
      "short": "GAO AI Accountability",
      "type": "framework",
      "issuer": "U.S. Government Accountability Office",
      "url": "https://www.gao.gov/products/gao-21-519sp",
      "summary": "An audit framework published on 30 June 2021: four principles (governance, data, performance, monitoring) and 31 key practices, each with questions for the entity and procedures for auditors and third-party assessors. Written for federal agencies and other entities; binds no one.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-us-gao-ai-accountability",
      "obligations": [
        "AIGE-OBL-USGAO-GOV",
        "AIGE-OBL-USGAO-DATA",
        "AIGE-OBL-USGAO-PERF",
        "AIGE-OBL-USGAO-MON"
      ]
    },
    {
      "id": "tx-traiga",
      "name": "Texas TRAIGA (HB 149)",
      "short": "Texas TRAIGA",
      "type": "law",
      "issuer": "State of Texas",
      "url": "https://capitol.texas.gov/tlodocs/89R/billtext/pdf/HB00149F.pdf",
      "summary": "The Texas Responsible Artificial Intelligence Governance Act (HB 149), in force 1 January 2026. Intent-based prohibitions (e.g. behaviour manipulation, unlawful discrimination, and social scoring by governmental entities), AI-use disclosure by government agencies and health care providers, and a regulatory sandbox, enforced by the Attorney General and preempting local AI rules.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-tx-traiga",
      "obligations": [
        "AIGE-OBL-USTX-TRAIGA"
      ]
    },
    {
      "id": "co-ai-act",
      "name": "Colorado ADMT law (SB 26-189, replacing SB 24-205)",
      "short": "Colorado ADMT",
      "type": "law",
      "issuer": "State of Colorado",
      "url": "https://leg.colorado.gov/bills/sb26-189",
      "summary": "Colorado's law on automated decision-making technology in consequential decisions, SB 26-189 (signed 14 May 2026, effective 1 January 2027): developer documentation, deployer notice, an explanation within 30 days of an adverse outcome, human review and three-year records. It repealed and re-enacted SB 24-205, the Colorado AI Act, whose duty of care against algorithmic discrimination had been delayed to 30 June 2026.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-co-ai-act",
      "obligations": [
        "AIGE-OBL-USCO-AIACT"
      ]
    },
    {
      "id": "kr-ai-basic-act",
      "name": "South Korea AI Basic Act",
      "short": "Korea AI Act",
      "type": "law",
      "issuer": "Republic of Korea",
      "url": "https://www.law.go.kr/LSW/lsInfoP.do?lsiSeq=268543",
      "summary": "South Korea's framework Act on AI (Basic Act on the Development of AI and the Establishment of a Foundation for Trust, Act No. 20676), in force 22 January 2026 with its Enforcement Decree. It sets baseline duties for AI operators and heightened obligations for \"high-impact\" AI in sensitive sectors; the ministry (MSIT) announced a guidance period of at least one year in which fact-finding and fines are held back except in exceptional cases, while the duties apply.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-kr-ai-basic-act",
      "obligations": [
        "AIGE-OBL-KR-AIBASIC",
        "AIGE-OBL-KR-ART31-1",
        "AIGE-OBL-KR-ART31-2",
        "AIGE-OBL-KR-ART32",
        "AIGE-OBL-KR-ART33",
        "AIGE-OBL-KR-ART34",
        "AIGE-OBL-KR-ART35",
        "AIGE-OBL-KR-ART36"
      ]
    },
    {
      "id": "uk-duaa",
      "name": "UK Data (Use and Access) Act 2025",
      "short": "UK DUAA",
      "type": "law",
      "issuer": "United Kingdom",
      "url": "https://www.legislation.gov.uk/ukpga/2025/18/section/80",
      "summary": "The UK has no horizontal AI act; it governs AI through sector regulators and the AI Security Institute. For automated decision-making, the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A–22D (in force 5 February 2026): a permission-plus-safeguards regime for significant, solely automated decisions.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-uk-duaa",
      "obligations": [
        "AIGE-OBL-UK-ADM"
      ]
    },
    {
      "id": "uk-dmcc",
      "name": "UK Digital Markets, Competition and Consumers Act 2024",
      "short": "UK DMCC Act",
      "type": "law",
      "issuer": "United Kingdom",
      "url": "https://www.legislation.gov.uk/ukpga/2024/13/section/225",
      "summary": "The UK consumer-protection regime in force since 6 April 2025: unfair commercial practices are prohibited, and Schedule 20 bans fake and concealed-incentive consumer reviews, however they are produced.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-uk-dmcc",
      "obligations": [
        "AIGE-OBL-UK-DMCC-S225"
      ]
    },
    {
      "id": "uk-atrs",
      "name": "UK Algorithmic Transparency Recording Standard (ATRS) v4.0",
      "short": "UK ATRS",
      "type": "standard",
      "issuer": "UK Government Digital Service",
      "url": "https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub",
      "summary": "A two-tier record template for public-sector algorithmic tools, mandatory for government departments and for arm's-length bodies that deliver public or frontline services under the December 2024 scope policy, and recommended across the wider public sector (as of 2026-09-24).",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-uk-atrs",
      "obligations": []
    },
    {
      "id": "sg-genai-framework",
      "name": "Singapore Model AI Governance Framework for Generative AI",
      "short": "Singapore GenAI",
      "type": "framework",
      "issuer": "IMDA / AI Verify Foundation",
      "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/05/Model-AI-Governance-Framework-for-Generative-AI-May-2024-1-1.pdf",
      "summary": "Singapore's voluntary Model AI Governance Framework for Generative AI (IMDA and the AI Verify Foundation, May 2024). It sets out governance dimensions (testing, transparency, incident reporting, security and content provenance) as guidance, not law.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-sg-genai-framework",
      "obligations": [
        "AIGE-OBL-SG-GENAI"
      ]
    },
    {
      "id": "sg-agentic-framework",
      "name": "Singapore Model AI Governance Framework for Agentic AI",
      "short": "Singapore Agentic",
      "type": "framework",
      "issuer": "IMDA",
      "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
      "summary": "Voluntary guidance launched on 22 Jan 2026; version 1.5 (20 May 2026, updated 5 Jun 2026) has four dimensions: assess and bound the risks upfront, make humans meaningfully accountable, implement technical controls and processes, enable end-user responsibility.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-sg-agentic-framework",
      "obligations": [
        "AIGE-OBL-SG-AGENTIC-IDENTITY",
        "AIGE-OBL-SG-AGENTIC-CHECKPOINTS"
      ]
    },
    {
      "id": "cn-algo-recommendation",
      "name": "China Provisions on Algorithmic Recommendation (2022)",
      "short": "China Algo. Rec.",
      "type": "law",
      "issuer": "CAC, MIIT, MPS and SAMR (China)",
      "url": "https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm",
      "summary": "China's binding Provisions on Algorithmic Recommendation (CAC, MIIT, MPS and SAMR, Order No. 9), in force 1 March 2022. Algorithm filing for services with public-opinion or social-mobilisation capacity, a security assessment, display of the filing number, and a user option to switch off personalised recommendation.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-algo-recommendation",
      "obligations": [
        "AIGE-OBL-CN-ALGOREC"
      ]
    },
    {
      "id": "cn-deep-synthesis",
      "name": "China Provisions on Deep Synthesis (2023)",
      "short": "China Deep Synthesis",
      "type": "law",
      "issuer": "CAC, MIIT and MPS (China)",
      "url": "https://www.cac.gov.cn/2022-12/11/c_1672221949354811.htm",
      "summary": "China's binding Provisions on Deep Synthesis (CAC, MIIT and MPS, Order No. 12), in force 10 January 2023. Conspicuous labels where synthetic content could mislead the public and non-removable technical marks, training-data management, separate consent for face and voice editing, and filing plus a security assessment for opinion-shaping functions.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-deep-synthesis",
      "obligations": [
        "AIGE-OBL-CN-DEEPSYN"
      ]
    },
    {
      "id": "cn-genai-measures",
      "name": "China Interim Measures for Generative AI Services (2023)",
      "short": "China GenAI Measures",
      "type": "law",
      "issuer": "CAC and six other bodies (China)",
      "url": "https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm",
      "summary": "China's binding Interim Measures for Generative AI Services (CAC and six other bodies, Order No. 15), in force 15 August 2023, for services offered to the public within the PRC. Lawful-source training data and foundation models, content labelling under the deep-synthesis rules, a security assessment and algorithm filing for opinion-shaping services, and a duty to stop, remove, retrain and report on illegal content.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-genai-measures",
      "obligations": [
        "AIGE-OBL-CN-GENAI"
      ]
    },
    {
      "id": "cn-content-labelling",
      "name": "China Measures for Labelling AI-Generated Synthetic Content (2025)",
      "short": "China AI Labelling",
      "type": "law",
      "issuer": "CAC, MIIT, MPS and NRTA (China)",
      "url": "https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm",
      "summary": "China's binding Measures for Labelling AI-Generated Synthetic Content (CAC, MIIT, MPS and NRTA), in force 1 September 2025 alongside the mandatory standard GB 45438-2025. Explicit labels (text, audio or graphic) and implicit metadata labels carrying the provider's name or code and a content number; distribution platforms verify the metadata and flag suspected AI content.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-content-labelling",
      "obligations": [
        "AIGE-OBL-CN-LABEL"
      ]
    },
    {
      "id": "cn-gbt-45654",
      "name": "GB/T 45654-2025 Basic security requirements for generative AI services",
      "short": "GB/T 45654",
      "type": "standard",
      "issuer": "SAMR / SAC, drafted by TC260 (China)",
      "url": "https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F67D3F376E0A0A0FF5317FB36B32A30A",
      "summary": "GB/T 45654-2025 Basic security requirements for generative AI services (SAMR / SAC, drafted by TC260), a recommended (voluntary) national standard implemented 1 November 2025. Training-corpus source and content screening, model-safety requirements and the evaluation methods that underpin the security assessment.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-gbt-45654",
      "obligations": [
        "AIGE-OBL-CN-GBT45654"
      ]
    },
    {
      "id": "cn-tc260-framework",
      "name": "TC260 AI Safety Governance Framework 3.0",
      "short": "TC260 Framework 3.0",
      "type": "framework",
      "issuer": "TC260 under CAC guidance (China)",
      "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
      "summary": "China's voluntary AI safety governance framework (14 September 2026, building on 1.0 in 2024 and 2.0 in 2025): a three-block risk taxonomy, technological and governance countermeasures and role-based guidelines. Appendix 2 is an agentic AI risk-management framework covering identity, human checkpoints, tool control, runtime guardrails, memory, auditing and decommissioning.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-tc260-framework",
      "obligations": [
        "AIGE-OBL-CN-TC260-OPS",
        "AIGE-OBL-CN-TC260-AGENTS"
      ]
    },
    {
      "id": "cn-pipl",
      "name": "China Personal Information Protection Law (PIPL)",
      "short": "China PIPL",
      "type": "law",
      "issuer": "NPC Standing Committee (China)",
      "url": null,
      "summary": "China's personal-information law, in force 1 November 2021: legal bases, separate consent for sensitive data, rules for automated decision-making (Art. 24) and a personal information protection impact assessment kept at least three years (Arts. 55 and 56).",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-pipl",
      "obligations": [
        "AIGE-OBL-CN-PIPL-ART24"
      ]
    },
    {
      "id": "cn-anthropomorphic",
      "name": "China Interim Measures for Anthropomorphic Interaction Services (2026)",
      "short": "China Anthropomorphic",
      "type": "law",
      "issuer": "CAC, NDRC, MIIT, MPS and SAMR (China)",
      "url": "https://www.cac.gov.cn/2026-04/10/c_1777558395078289.htm",
      "summary": "China's binding measures for AI services that offer sustained emotional interaction, in force 15 July 2026: a minors' mode, AI signals and a two-hour reminder, an easy exit, a security assessment at 1 million registered or 100,000 monthly active users, and filing.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-cn-anthropomorphic",
      "obligations": [
        "AIGE-OBL-CN-ANTHRO"
      ]
    },
    {
      "id": "canada-dadm",
      "name": "Canada Directive on Automated Decision-Making",
      "short": "Canada DADM",
      "type": "law",
      "issuer": "Government of Canada (Treasury Board)",
      "url": "https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32592",
      "summary": "The Treasury Board directive that binds Canadian federal institutions' automated decision systems (in effect since 1 April 2019; modified 24 June 2025): a published algorithmic impact assessment, impact-level requirements, notice, explanation, peer review and recourse.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-canada-dadm",
      "obligations": [
        "AIGE-OBL-CAN-DADM"
      ]
    },
    {
      "id": "br-lgpd",
      "name": "Brazil General Data Protection Law (LGPD, Lei 13.709/2018)",
      "short": "Brazil LGPD",
      "type": "law",
      "issuer": "Federative Republic of Brazil",
      "url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm",
      "summary": "Brazil's data-protection law. Its Article 20 gives data subjects a right to request review of decisions taken solely on automated processing, with clear information on the criteria and procedures used.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-br-lgpd",
      "obligations": [
        "AIGE-OBL-BR-LGPD-ART20"
      ]
    },
    {
      "id": "coe-cets-225",
      "name": "Council of Europe Framework Convention on AI (CETS No. 225)",
      "short": "CoE Convention",
      "type": "law",
      "issuer": "Council of Europe",
      "url": "https://rm.coe.int/1680afae3c",
      "summary": "A treaty on AI and human rights, democracy and the rule of law, binding on Parties once in force; not in force as of 2026-09-24. The EU implements it through the AI Act.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-coe-cets-225",
      "obligations": [
        "AIGE-OBL-COE-ART14-2",
        "AIGE-OBL-COE-ART15-2",
        "AIGE-OBL-COE-ART16",
        "AIGE-OBL-COE-ART16-2G"
      ]
    },
    {
      "id": "oecd-ai-principles",
      "name": "OECD AI Principles (Recommendation on AI, OECD/LEGAL/0449)",
      "short": "OECD AI Principles",
      "type": "framework",
      "issuer": "OECD",
      "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
      "summary": "Five values-based principles for AI actors and five recommendations to governments, revised on 3 May 2024; a non-binding intergovernmental standard.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-oecd-ai-principles",
      "obligations": [
        "AIGE-OBL-OECD-P1-4B",
        "AIGE-OBL-OECD-P1-5"
      ]
    },
    {
      "id": "g7-hiroshima-coc",
      "name": "G7 Hiroshima Process International Code of Conduct for Advanced AI Systems",
      "short": "G7 Code",
      "type": "code",
      "issuer": "G7",
      "url": "https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems",
      "summary": "Eleven voluntary actions for organisations developing advanced AI systems, from lifecycle risk management to content provenance and data protection.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-g7-hiroshima-coc",
      "obligations": [
        "AIGE-OBL-G7-A1",
        "AIGE-OBL-G7-A2-4",
        "AIGE-OBL-G7-A3",
        "AIGE-OBL-G7-A7"
      ]
    },
    {
      "id": "etsi-en-304-223",
      "name": "ETSI EN 304 223",
      "short": "ETSI EN 304 223",
      "type": "standard",
      "issuer": "ETSI",
      "url": "https://www.etsi.org/newsroom/press-releases/2627-etsi-releases-world-leading-standard-for-securing-ai/",
      "summary": "Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems (V2.1.1, December 2025). A cross-border European standard setting 13 security principles across the five stages of the AI lifecycle: a cyber-security baseline, not an EU AI Act harmonised standard.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-etsi-en-304-223",
      "obligations": [
        "AIGE-OBL-ETSI-304223"
      ]
    },
    {
      "id": "en-18286",
      "name": "EN 18286:2026",
      "short": "EN 18286",
      "type": "standard",
      "issuer": "CEN-CENELEC",
      "url": "https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/",
      "summary": "The Article 17 QMS standard, published July 2026 (the first JTC 21 AI Act standard to reach publication) but not yet cited in the Official Journal, so it carries no presumption of conformity.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-en-18286",
      "obligations": [
        "AIGE-OBL-CEN-EN18286"
      ]
    },
    {
      "id": "pren-18228",
      "name": "prEN 18228 AI risk management (draft)",
      "short": "prEN 18228",
      "type": "standard",
      "issuer": "CEN-CENELEC JTC 21",
      "url": "https://genorma.com/en/standards/pren-18228",
      "summary": "Draft harmonised standard supporting AI Act Art. 9; its Enquiry vote closed on 30 Jul 2026, as reported by Genorma on 2026-09-24.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-pren-18228",
      "obligations": [
        "AIGE-OBL-CEN-PREN18228"
      ]
    },
    {
      "id": "pren-18229-1",
      "name": "prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft)",
      "short": "prEN 18229-1",
      "type": "standard",
      "issuer": "CEN-CENELEC JTC 21",
      "url": "https://genorma.com/en/standards/pren-18229-1",
      "summary": "Draft harmonised standard supporting AI Act Art. 12; its Enquiry vote closed on 20 Aug 2026, as reported by Genorma on 2026-09-24.",
      "page": "https://aigovernanceengineer.com/resources/frameworks#fw-pren-18229-1",
      "obligations": [
        "AIGE-OBL-CEN-PREN18229-1"
      ]
    }
  ]
}
