{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 2,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/obligations.json",
  "self": "https://aigovernanceengineer.com/api/v1/obligations.json",
  "source": "https://aigovernanceengineer.com/obligations",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "obligations": [
    {
      "id": "AIGE-OBL-EUAIA-ART3-1",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art3-1",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art3-1.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 3(1)",
      "obligation": "EU AI Act Art. 3(1) AI system definition (scope of the Act)",
      "requirement": "Scope: decide, system by system, whether it is an AI system under the Art. 3(1) definition before any other duty is assessed",
      "artefact": "Definitional decision record in the registry: definition applied, elements found, excluded family if any, reason, decider, date",
      "layers": [
        2
      ],
      "dutyHolder": "Provider + deployer (scoping)",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2025-02-02",
      "appliesStatus": "in-force",
      "appliesNote": "2025-02-02 (Chapter I)",
      "milestones": [],
      "systemClass": [
        "all-ai-systems"
      ],
      "patterns": [
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        },
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART4",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art4.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 4",
      "obligation": "EU AI Act Art. 4 AI literacy",
      "requirement": "AI literacy: take measures to support the development of AI literacy among staff and operators",
      "artefact": "Literacy programme as code; role-based training records; onboarding gates",
      "layers": [
        1
      ],
      "dutyHolder": "Provider + deployer",
      "scope": null,
      "authority": "Provider/deployer duty; national MSA",
      "appliesFrom": "2025-02-02",
      "appliesStatus": "in-force",
      "appliesNote": "2025-02-02; reworded 2026-07-27 (in force)",
      "milestones": [
        {
          "date": "2026-07-27",
          "systemClass": [],
          "note": "Omnibus rewording in force: providers and deployers take measures to support AI literacy"
        }
      ],
      "systemClass": [
        "all-ai-systems"
      ],
      "patterns": [
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        }
      ],
      "crosswalkTopics": [
        "governance-accountability",
        "ai-literacy"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART4A",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art4a.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 4a",
      "obligation": "EU AI Act Art. 4a lawful basis for special-category data in bias detection",
      "requirement": "Lawful basis to process special-category data for bias detection in high-risk systems, with pseudonymisation and deletion once bias is corrected",
      "artefact": "Data governance controls; pseudonymisation and retention-as-code; data card noting basis and deletion",
      "layers": [
        2
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA / DPAs",
      "appliesFrom": "2026-07-27",
      "appliesStatus": "in-force",
      "appliesNote": "2026-07-27 (new, in force)",
      "milestones": [],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "crosswalkTopics": [
        "data-governance",
        "fairness-non-discrimination",
        "privacy-data-protection"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART5",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art5.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 5",
      "obligation": "EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans)",
      "requirement": "Prohibited practices; new bans on AI-generated non-consensual intimate imagery (NCII) and CSAM",
      "artefact": "Policy-as-code blocklist; input/output guardrails; refusal and abuse detection",
      "layers": [
        1,
        4
      ],
      "dutyHolder": "Provider + deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2025-02-02",
      "appliesStatus": "in-force",
      "appliesNote": "2026-12-02 (new bans); earlier prohibitions from 2025-02-02",
      "milestones": [
        {
          "date": "2026-12-02",
          "systemClass": [
            "prohibited"
          ],
          "note": "New bans on AI-generated NCII and CSAM apply"
        }
      ],
      "systemClass": [
        "prohibited"
      ],
      "patterns": [
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [
        "runtime-guardrails",
        "prohibited-practices"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART6",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art6",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art6.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 6",
      "obligation": "EU AI Act Art. 6 classification of high-risk AI systems (incl. the Annex III route)",
      "requirement": "Classification rules for high-risk AI systems, incl. the Annex III (standalone) route and Annex I (safety-component) route",
      "artefact": "Risk-tiering as code; high-risk classification decision record; register entry flagging Annex III status",
      "layers": [
        1,
        2
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "The Annex I (safety-component) route applies"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        }
      ],
      "crosswalkTopics": [
        "inventory-registration"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART6-3",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art6-3",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art6-3.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 6(3)–(4)",
      "obligation": "EU AI Act Art. 6(3)–(4) documented non-high-risk assessment and registration",
      "requirement": "A provider that finds an Annex III system not high-risk under the Art. 6(3) filter documents the assessment before placing it on the market and registers it under Art. 49(2); a system that profiles natural persons is always high-risk",
      "artefact": "Classification decision record (Annex III point, Art. 6(3) condition, explicit profiling flag); Art. 49(2) registration entry pushed from the registry",
      "layers": [
        1,
        2
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [],
      "systemClass": [
        "high-risk-annex-iii"
      ],
      "patterns": [
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART9",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art9.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 9",
      "obligation": "EU AI Act Art. 9 risk management system",
      "requirement": "Risk management system across the high-risk lifecycle",
      "artefact": "Risk register as code; threat models; linkage to FRIA and eval results",
      "layers": [
        1,
        3
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        },
        {
          "id": "pattern-adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        },
        {
          "id": "pattern-fria-as-code",
          "title": "FRIA-as-Code",
          "url": "https://aigovernanceengineer.com/patterns/fria-as-code"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        }
      ],
      "crosswalkTopics": [
        "risk-management",
        "impact-assessment",
        "robustness-security-evals"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART10",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art10.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 10",
      "obligation": "EU AI Act Art. 10 data and data governance",
      "requirement": "Data and data governance; representative, relevant, error-checked datasets",
      "artefact": "Data cards; lineage; bias and quality tests in CI",
      "layers": [
        2,
        3
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "id": "pattern-dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        }
      ],
      "crosswalkTopics": [
        "data-governance",
        "fairness-non-discrimination"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART11",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art11.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 11",
      "obligation": "EU AI Act Art. 11 technical documentation (Annex IV)",
      "requirement": "Technical documentation (Annex IV) drawn up and kept up to date",
      "artefact": "AIBOM (CycloneDX ML-BOM, SPDX 3.0 AI); auto-generated technical documentation; model cards",
      "layers": [
        2
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        },
        {
          "id": "pattern-aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        },
        {
          "id": "pattern-model-card-as-control-evidence",
          "title": "Model Card as Control Evidence",
          "url": "https://aigovernanceengineer.com/patterns/model-card-as-control-evidence"
        }
      ],
      "crosswalkTopics": [
        "documentation-transparency"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART12",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art12.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 12",
      "obligation": "EU AI Act Art. 12 record-keeping and logging",
      "requirement": "Record-keeping: automatic logging of events over the system's lifetime",
      "artefact": "Structured, signed logs; OpenTelemetry traces; tamper-evident event store",
      "layers": [
        4
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        },
        {
          "id": "pattern-agent-identity--scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        }
      ],
      "crosswalkTopics": [
        "logging-traceability"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART13",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art13.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 13",
      "obligation": "EU AI Act Art. 13 transparency and information to deployers",
      "requirement": "Transparency and provision of information to deployers",
      "artefact": "Instructions for use as code; model and data cards; capability and limitation notes",
      "layers": [
        2
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-model-card-as-control-evidence",
          "title": "Model Card as Control Evidence",
          "url": "https://aigovernanceengineer.com/patterns/model-card-as-control-evidence"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        }
      ],
      "crosswalkTopics": [
        "documentation-transparency",
        "explainability"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART14",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art14.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 14",
      "obligation": "EU AI Act Art. 14 human oversight",
      "requirement": "Human oversight designed into the system",
      "artefact": "Human-in-the-loop checkpoints; kill switch; override and escalation paths",
      "layers": [
        4
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        },
        {
          "id": "pattern-kill-switch--circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        },
        {
          "id": "pattern-agent-identity--scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        },
        {
          "id": "pattern-human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        }
      ],
      "crosswalkTopics": [
        "human-oversight",
        "agent-identity-autonomy"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART15",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art15.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 15",
      "obligation": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
      "requirement": "Accuracy, robustness and cybersecurity",
      "artefact": "Eval gate; adversarial red-team suite; robustness and security controls; regression evals",
      "layers": [
        3,
        4
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "id": "pattern-adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        },
        {
          "id": "pattern-runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        },
        {
          "id": "pattern-kill-switch--circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        },
        {
          "id": "pattern-agent-identity--scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        },
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "crosswalkTopics": [
        "runtime-guardrails",
        "robustness-security-evals"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART15-4",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15-4",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art15-4.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 15(4)",
      "obligation": "EU AI Act Art. 15(4) feedback loops in systems that continue to learn",
      "requirement": "Systems that continue to learn after placing on the market are built to eliminate or reduce the risk of biased outputs feeding future inputs (feedback loops), with mitigation measures",
      "artefact": "Feedback-loop fairness monitor; retraining-data bias check; agent memory write gate with provenance and rollback to a known-good snapshot",
      "layers": [
        3,
        4
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "id": "pattern-adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        },
        {
          "id": "pattern-runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        },
        {
          "id": "pattern-kill-switch--circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        },
        {
          "id": "pattern-agent-identity--scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        },
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART16-L",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art16-l",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art16-l.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 16(l)",
      "obligation": "EU AI Act Art. 16(l) accessibility requirements for high-risk AI systems",
      "requirement": "Providers ensure the high-risk system complies with the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882",
      "artefact": "Accessibility test results for every notice, instruction and explanation shown to people, run in the pipeline; accessible explanation templates",
      "layers": [
        2,
        3
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART17",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art17.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 17",
      "obligation": "EU AI Act Art. 17 quality management system",
      "requirement": "Quality management system",
      "artefact": "QMS-as-code; versioned policies; pipeline controls and change management",
      "layers": [
        1,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        }
      ],
      "crosswalkTopics": [
        "governance-accountability"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART17-1M",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17-1m",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art17-1m.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 17(1)(m)",
      "obligation": "EU AI Act Art. 17(1)(m) accountability framework within the quality management system",
      "requirement": "The QMS includes an accountability framework setting out the responsibilities of management and other staff for every aspect of the QMS",
      "artefact": "RACI as code compiled into registry owner fields and code-owner rules; committee decision records",
      "layers": [
        1,
        2
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART18",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art18",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art18.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 18",
      "obligation": "EU AI Act Art. 18 documentation keeping",
      "requirement": "Keep the technical documentation, the QMS documentation, notified-body changes and decisions and the EU declaration at the disposal of national authorities for 10 years after placing on the market",
      "artefact": "Retention-as-code for the technical file, QMS records, notified-body decisions and the EU declaration (10 years); write-once evidence store",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART19",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art19",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art19.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 19",
      "obligation": "EU AI Act Art. 19 automatically generated logs kept by the provider",
      "requirement": "Keep the automatically generated logs under the provider's control for a period appropriate to the intended purpose, at least six months unless other law provides otherwise",
      "artefact": "Log-retention policy as code (at least six months, set by intended purpose); tamper-evident log store",
      "layers": [
        4,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART20",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art20",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art20.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 20",
      "obligation": "EU AI Act Art. 20 corrective actions and duty of information",
      "requirement": "A provider with reason to consider a high-risk system non-conforming immediately brings it into conformity, withdraws, disables or recalls it and informs distributors and deployers; where the system presents a risk, it investigates and informs the market-surveillance authority",
      "artefact": "CAPA record; withdraw, disable or recall runbook; notification of distributors and deployers",
      "layers": [
        1,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART22",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art22",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art22.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 22",
      "obligation": "EU AI Act Art. 22 authorised representative of non-EU high-risk providers",
      "requirement": "A provider established outside the Union appoints, by written mandate, an authorised representative in the Union before making the system available; the representative keeps the declaration, documentation and certificate for 10 years",
      "artefact": "Written mandate; 10-year copies of the declaration, technical documentation and certificate; authority contact route",
      "layers": [
        5
      ],
      "dutyHolder": "Non-EU provider + authorised representative",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART23",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art23",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art23.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 23",
      "obligation": "EU AI Act Art. 23 obligations of importers",
      "requirement": "Before placing a high-risk system on the market, the importer verifies the conformity assessment, the Annex IV documentation, the CE marking, the declaration and instructions and the authorised representative, and keeps copies for 10 years",
      "artefact": "Import verification record against each check; 10-year document copies",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "Importer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART24",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art24",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art24.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 24",
      "obligation": "EU AI Act Art. 24 obligations of distributors",
      "requirement": "Before making a high-risk system available, the distributor verifies the CE marking, the declaration and the instructions, and holds back, withdraws or recalls a system it considers non-conforming",
      "artefact": "Distribution check record; hold, withdraw or recall workflow",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "Distributor",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART25",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art25.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 25",
      "obligation": "EU AI Act Art. 25 responsibilities along the AI value chain",
      "requirement": "Responsibilities along the AI value chain: when a distributor, importer or deployer becomes a provider, and the information a provider must pass to actors downstream",
      "artefact": "Value-chain due-diligence gate; provider/deployer responsibility allocation; AIBOM and model/data cards collected from upstream providers",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "Provider + value-chain actors",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        }
      ],
      "crosswalkTopics": [
        "supply-chain",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART26",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art26.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 26",
      "obligation": "EU AI Act Art. 26 deployer obligations for high-risk systems",
      "requirement": "Deployer obligations for high-risk systems: use per the instructions for use (Art. 26(1)); the paragraph rows below break out oversight, input data, monitoring, logs and notices",
      "artefact": "Deployment registry; monitoring hooks; assigned oversight and logging retention",
      "layers": [
        2,
        4
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [
        "logging-traceability",
        "human-oversight",
        "supply-chain",
        "incident-monitoring",
        "ai-literacy",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART26-2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art26-2.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 26(2)",
      "obligation": "EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority",
      "requirement": "Deployers assign human oversight to natural persons with the necessary competence, training and authority, and the necessary support",
      "artefact": "Oversight assignment in the registry; role-based training records with expiry; approver roster per checkpoint class with authority to pause or refuse",
      "layers": [
        1,
        4
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART26-4",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-4",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art26-4.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 26(4)",
      "obligation": "EU AI Act Art. 26(4) input data relevant and sufficiently representative",
      "requirement": "To the extent the deployer controls the input data, it ensures the data are relevant and sufficiently representative for the intended purpose",
      "artefact": "Input-data checks against the population in the deployment record; drift monitors on inputs",
      "layers": [
        2,
        3
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART26-5",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art26-5.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 26(5)",
      "obligation": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
      "requirement": "Deployers monitor operation per the instructions; on reason to consider a risk they inform the provider or distributor and the authority and suspend use; a serious incident goes to the provider first, and Art. 73 applies to the deployer if the provider cannot be reached",
      "artefact": "Monitoring plan with signal owners; tested suspension path (feature flag, traffic switch); provider incident contact in the registry; pre-filled risk and serious-incident notices",
      "layers": [
        2,
        4,
        5
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART26-6",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-6",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art26-6.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 26(6)",
      "obligation": "EU AI Act Art. 26(6) deployer retention of automatically generated logs",
      "requirement": "Deployers keep the logs under their control for a period appropriate to the intended purpose, at least six months unless other law provides otherwise",
      "artefact": "Retention-as-code schedule; tamper-evident log store; legal hold while an incident is open",
      "layers": [
        4,
        5
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART26-7",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-7",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art26-7.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 26(7)",
      "obligation": "EU AI Act Art. 26(7) informing workers before workplace use",
      "requirement": "Before putting a high-risk system into service at the workplace, deployers who are employers inform workers' representatives and the affected workers",
      "artefact": "Worker-information record dated before first use and linked to the registry entry; HR intake trigger for Annex III point 4 systems",
      "layers": [
        2
      ],
      "dutyHolder": "Deployer (employer)",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART26-11",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-11",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art26-11.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 26(11)",
      "obligation": "EU AI Act Art. 26(11) informing people subject to Annex III decisions",
      "requirement": "Deployers of Annex III systems that make or assist decisions about natural persons inform those persons that they are subject to the system",
      "artefact": "AI-use notice at the decision point; notice templates versioned as code; notice delivery log",
      "layers": [
        2,
        4
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii"
      ],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART27",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art27",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art27.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 27",
      "obligation": "EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA)",
      "requirement": "Fundamental Rights Impact Assessment (FRIA) for deployers of Annex III systems",
      "artefact": "FRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA",
      "layers": [
        1,
        2
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii"
      ],
      "patterns": [
        {
          "id": "pattern-fria-as-code",
          "title": "FRIA-as-Code",
          "url": "https://aigovernanceengineer.com/patterns/fria-as-code"
        },
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        }
      ],
      "crosswalkTopics": [
        "impact-assessment"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART43",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art43.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 43",
      "obligation": "EU AI Act Art. 43 conformity assessment",
      "requirement": "Conformity assessment before placing on the market (internal control, or a notified body for Annex III point 1 biometrics)",
      "artefact": "Conformity-assessment workflow; internal-control or notified-body evidence pack; traceability to Annex IV documentation",
      "layers": [
        1,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [
        "conformity-assessment",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART43-4",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43-4",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art43-4.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 43(4)",
      "obligation": "EU AI Act Art. 43(4) new conformity assessment on substantial modification",
      "requirement": "A system already assessed undergoes a new conformity assessment on substantial modification; changes pre-determined in the technical documentation of a system that continues to learn are not substantial modifications",
      "artefact": "Change-classification policy on merge; pre-determined change envelope as code; reassessment trigger in the registry",
      "layers": [
        1,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART47",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art47",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art47.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 47",
      "obligation": "EU AI Act Art. 47 EU declaration of conformity",
      "requirement": "EU declaration of conformity drawn up on completing the assessment",
      "artefact": "Auto-generated EU declaration of conformity from the evidence; CE-marking record",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [
        "conformity-assessment"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART48",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art48",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art48.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 48",
      "obligation": "EU AI Act Art. 48 CE marking",
      "requirement": "Affix the CE marking visibly, legibly and indelibly (a digital marking for digitally provided systems), followed by the notified body's number where applicable",
      "artefact": "CE-marking record (physical or digital) generated with the EU declaration; notified-body number where applicable",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART49-71",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art49-71.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 49 / Art. 71",
      "obligation": "EU AI Act Art. 49/71 registration of high-risk systems in the EU database",
      "requirement": "Registration of high-risk systems in the EU database",
      "artefact": "Agent/model registry with an API that feeds registration; owner and status per entry",
      "layers": [
        2
      ],
      "dutyHolder": "Provider; public-authority deployer",
      "scope": null,
      "authority": "National MSA; Commission (database)",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii"
      ],
      "patterns": [
        {
          "id": "pattern-agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        },
        {
          "id": "pattern-shadow-ai-discovery",
          "title": "Shadow-AI Discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        },
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        }
      ],
      "crosswalkTopics": [
        "inventory-registration"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART50",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art50.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 50",
      "obligation": "EU AI Act Art. 50 transparency for certain AI systems",
      "requirement": "Transparency for certain AI systems: chatbot disclosure; marking and labelling of synthetic content",
      "artefact": "Content labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner",
      "layers": [
        4,
        2
      ],
      "dutyHolder": "Provider + deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2026-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "2026-08-02; marking grace for existing systems to 2026-12-02",
      "milestones": [
        {
          "date": "2026-12-02",
          "systemClass": [],
          "note": "Marking grace for existing systems ends"
        }
      ],
      "systemClass": [
        "transparency-art50"
      ],
      "patterns": [
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        }
      ],
      "crosswalkTopics": [
        "documentation-transparency",
        "content-provenance"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART52",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art52",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art52.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 52",
      "obligation": "EU AI Act Art. 52 notification of a GPAI model meeting the systemic-risk threshold",
      "requirement": "Notify the Commission without delay, and within two weeks, once a GPAI model meets the Art. 51(1)(a) condition or it becomes known that it will",
      "artefact": "Compute ledger per model lineage with a planned-compute threshold alert; notification record filed within two weeks",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "GPAI provider",
      "scope": null,
      "authority": "AI Office",
      "appliesFrom": "2025-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "Obligations from 2025-08-02; enforcement from 2026-08-02",
      "milestones": [
        {
          "date": "2026-08-02",
          "systemClass": [],
          "note": "Commission enforcement powers apply"
        },
        {
          "date": "2027-08-02",
          "systemClass": [],
          "note": "GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))"
        }
      ],
      "systemClass": [
        "gpai-systemic"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART53",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art53.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 53",
      "obligation": "EU AI Act Art. 53 GPAI provider obligations",
      "requirement": "GPAI provider obligations, incl. a public summary of training content on an AI Office template",
      "artefact": "Model cards; training-content summary; AIBOM and dataset provenance",
      "layers": [
        2
      ],
      "dutyHolder": "GPAI provider",
      "scope": null,
      "authority": "AI Office",
      "appliesFrom": "2025-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "Obligations from 2025-08-02; enforcement from 2026-08-02",
      "milestones": [
        {
          "date": "2026-08-02",
          "systemClass": [],
          "note": "Commission enforcement powers apply"
        },
        {
          "date": "2027-08-02",
          "systemClass": [],
          "note": "GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))"
        }
      ],
      "systemClass": [
        "gpai"
      ],
      "patterns": [
        {
          "id": "pattern-aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        },
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        }
      ],
      "crosswalkTopics": [
        "documentation-transparency",
        "gpai-foundation-models",
        "ip-copyright",
        "environmental-impact"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART53-1C",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53-1c",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art53-1c.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 53(1)(c)",
      "obligation": "EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations",
      "requirement": "GPAI providers put in place a policy to comply with Union copyright law, incl. identifying and complying with reservations of rights under Art. 4(3) of Directive (EU) 2019/790",
      "artefact": "Versioned copyright policy; crawler decision logs; training-data rights ledger with the reservation-check result",
      "layers": [
        1,
        2,
        5
      ],
      "dutyHolder": "GPAI provider",
      "scope": null,
      "authority": "AI Office",
      "appliesFrom": "2025-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "Obligations from 2025-08-02; enforcement from 2026-08-02",
      "milestones": [
        {
          "date": "2026-08-02",
          "systemClass": [],
          "note": "Commission enforcement powers apply"
        },
        {
          "date": "2027-08-02",
          "systemClass": [],
          "note": "GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))"
        }
      ],
      "systemClass": [
        "gpai"
      ],
      "patterns": [
        {
          "id": "pattern-aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        },
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART54",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art54",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art54.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 54",
      "obligation": "EU AI Act Art. 54 authorised representative of non-EU GPAI providers",
      "requirement": "A GPAI provider established outside the Union appoints, by written mandate, an authorised representative before placing the model on the Union market; the representative keeps the Annex XI documentation for 10 years",
      "artefact": "Written mandate; Annex XI documentation copy kept 10 years; AI Office contact route",
      "layers": [
        5
      ],
      "dutyHolder": "Non-EU GPAI provider + authorised representative",
      "scope": null,
      "authority": "AI Office",
      "appliesFrom": "2025-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "Obligations from 2025-08-02; enforcement from 2026-08-02",
      "milestones": [
        {
          "date": "2026-08-02",
          "systemClass": [],
          "note": "Commission enforcement powers apply"
        },
        {
          "date": "2027-08-02",
          "systemClass": [],
          "note": "GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))"
        }
      ],
      "systemClass": [
        "gpai"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART55",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art55.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 55",
      "obligation": "EU AI Act Art. 55 GPAI models with systemic risk",
      "requirement": "GPAI models with systemic risk: model evaluation incl. adversarial testing; Union-level risk assessment; serious-incident reporting; cybersecurity of the model",
      "artefact": "Eval and red-team suite; incident pipeline on the Commission serious-incident reporting template; weight-security controls; threat model",
      "layers": [
        3,
        4,
        5
      ],
      "dutyHolder": "GPAI provider (systemic risk)",
      "scope": null,
      "authority": "AI Office",
      "appliesFrom": "2025-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "Obligations from 2025-08-02; enforcement from 2026-08-02",
      "milestones": [
        {
          "date": "2026-08-02",
          "systemClass": [],
          "note": "Commission enforcement powers apply"
        },
        {
          "date": "2027-08-02",
          "systemClass": [],
          "note": "GPAI models placed on the market before 2025-08-02 comply by this date (Art. 111(3))"
        }
      ],
      "systemClass": [
        "gpai-systemic"
      ],
      "patterns": [
        {
          "id": "pattern-eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "id": "pattern-adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        },
        {
          "id": "pattern-incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        },
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        }
      ],
      "crosswalkTopics": [
        "robustness-security-evals",
        "incident-monitoring",
        "gpai-foundation-models"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART60",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art60.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 60",
      "obligation": "EU AI Act Art. 60 testing in real-world conditions outside sandboxes",
      "requirement": "Testing of high-risk (Annex III) AI systems in real-world conditions outside AI regulatory sandboxes",
      "artefact": "Real-world testing plan; Art. 61 informed-consent records; test monitoring, logging and incident hooks",
      "layers": [
        3,
        4
      ],
      "dutyHolder": "Provider / prospective provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2026-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "2026-08-02",
      "milestones": [],
      "systemClass": [
        "high-risk-annex-iii"
      ],
      "patterns": [
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        }
      ],
      "crosswalkTopics": [
        "robustness-security-evals",
        "sandboxes-real-world-testing"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART72",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art72.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 72",
      "obligation": "EU AI Act Art. 72 post-market monitoring",
      "requirement": "Post-market monitoring for high-risk systems",
      "artefact": "Continuous assurance telemetry; monitoring plan; drift and performance signals",
      "layers": [
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "id": "pattern-incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        },
        {
          "id": "pattern-machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "crosswalkTopics": [
        "incident-monitoring"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART73",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art73.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 73",
      "obligation": "EU AI Act Art. 73 serious-incident reporting",
      "requirement": "Serious-incident reporting for high-risk systems, on the deadlines of chapter 08's reporting-clock table",
      "artefact": "Incident detection and triage pipeline; reporting-clock automation; evidence capture",
      "layers": [
        5,
        4
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        }
      ],
      "crosswalkTopics": [
        "incident-monitoring"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART73-6",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73-6",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art73-6.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 73(6)",
      "obligation": "EU AI Act Art. 73(6) incident investigation without altering the system",
      "requirement": "After reporting a serious incident the provider investigates without delay (risk assessment, corrective action) and does not alter the system in a way that may affect the evaluation of causes before informing the authorities",
      "artefact": "Evidence-preservation step: model, prompt, policy and retrieval-index snapshots; sealed traces; fix shipped on a new version",
      "layers": [
        4,
        5
      ],
      "dutyHolder": "Provider",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [
        {
          "id": "pattern-incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART75-1A",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art75-1a",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art75-1a.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 75(1a)",
      "obligation": "EU AI Act Art. 75(1a) serious incidents reported to the AI Office",
      "requirement": "Providers of high-risk systems under the AI Office's exclusive competence (systems built on their own GPAI model, and systems in designated very large online platforms or search engines) report serious incidents to the AI Office, with Art. 73(2) to (9) applying mutatis mutandis",
      "artefact": "Incident pipeline routing by a registry competence flag (national MSA or AI Office)",
      "layers": [
        2,
        5
      ],
      "dutyHolder": "Provider (systems under AI Office competence)",
      "scope": null,
      "authority": "AI Office",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III); new by the Omnibus (reading, verify)",
      "milestones": [
        {
          "date": "2028-08-02",
          "systemClass": [
            "high-risk-annex-i"
          ],
          "note": "Applies to Annex I embedded (product safety-component) systems"
        },
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii",
        "high-risk-annex-i"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART86",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art86",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art86.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 86",
      "obligation": "EU AI Act Art. 86 right to explanation of individual decision-making",
      "requirement": "A person subject to a deployer's decision based on an Annex III system (except point 2) with legal or similarly significant adverse effects may obtain clear and meaningful explanations of the system's role and the main elements of the decision, where Union law does not already give the right",
      "artefact": "Explanation record per decision (system and model version, reason codes, determinative or advisory role, human decider); request-handling workflow and response log",
      "layers": [
        2,
        4,
        5
      ],
      "dutyHolder": "Deployer",
      "scope": null,
      "authority": "National MSA",
      "appliesFrom": "2027-12-02",
      "appliesStatus": "deferred",
      "appliesNote": "2027-12-02 (Annex III); Chapter IX applies from 2026-08-02, but the right needs a classified Annex III system (reading, verify)",
      "milestones": [
        {
          "date": "2030-08-02",
          "systemClass": [],
          "note": "Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))"
        }
      ],
      "systemClass": [
        "high-risk-annex-iii"
      ],
      "patterns": [
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-EUAIA-ART87",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art87",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art87.json",
      "framework": "EU AI Act",
      "frameworkId": "eu-ai-act",
      "clause": "Art. 87",
      "obligation": "EU AI Act Art. 87 reporting of infringements and protection of reporting persons",
      "requirement": "Directive (EU) 2019/1937 applies to reports of AI Act infringements and to the protection of the people who make them",
      "artefact": "Internal reporting channel run as a case system with the directive's clocks encoded; sealed reporter identity; retaliation monitoring; routing to the incident pipeline",
      "layers": [
        1,
        5
      ],
      "dutyHolder": "Legal entities with internal reporting channels under Directive (EU) 2019/1937",
      "scope": null,
      "authority": "Authorities designated under Directive (EU) 2019/1937",
      "appliesFrom": "2026-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "2026-08-02 (general application date)",
      "milestones": [],
      "systemClass": [
        "all-ai-systems"
      ],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus"
    },
    {
      "id": "AIGE-OBL-GPAICOP-SAFETY",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gpaicop-safety.json",
      "framework": "GPAI Code of Practice",
      "frameworkId": "gpai-code-of-practice",
      "clause": "Safety and Security chapter",
      "obligation": "Safety and Security (systemic-risk models only)",
      "requirement": "A Safety and Security Framework; model evaluations incl. adversarial testing; systemic-risk assessment and mitigation; serious-incident reporting; model and infrastructure security",
      "artefact": "Eval and red-team suite; adversarial testing harness; incident pipeline; weight-security controls",
      "layers": [
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2025-07-10",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "risk-management",
        "governance-accountability",
        "runtime-guardrails",
        "robustness-security-evals",
        "incident-monitoring",
        "gpai-foundation-models"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#gpai-code-of-practice"
    },
    {
      "id": "AIGE-OBL-GPAICOP-TRANSPARENCY",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-transparency",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gpaicop-transparency.json",
      "framework": "GPAI Code of Practice",
      "frameworkId": "gpai-code-of-practice",
      "clause": "Transparency chapter",
      "obligation": "Transparency",
      "requirement": "Up-to-date model documentation for the AI Office and downstream deployers",
      "artefact": "Model cards; structured model documentation; AIBOM",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2025-07-10",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "documentation-transparency",
        "supply-chain",
        "gpai-foundation-models",
        "environmental-impact"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#gpai-code-of-practice"
    },
    {
      "id": "AIGE-OBL-GPAICOP-COPYRIGHT",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-copyright",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gpaicop-copyright.json",
      "framework": "GPAI Code of Practice",
      "frameworkId": "gpai-code-of-practice",
      "clause": "Copyright chapter",
      "obligation": "Copyright",
      "requirement": "A policy to comply with Union copyright law, incl. respecting reservations of rights",
      "artefact": "Training-data provenance and licence records; policy-as-code for source filtering",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2025-07-10",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "data-governance",
        "ip-copyright"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#gpai-code-of-practice"
    },
    {
      "id": "AIGE-OBL-GPAICOP-SAFETY-C9",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety-c9",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gpaicop-safety-c9.json",
      "framework": "GPAI Code of Practice",
      "frameworkId": "gpai-code-of-practice",
      "clause": "Safety and Security, Commitment 9",
      "obligation": "Safety and Security Commitment 9: serious-incident reporting",
      "requirement": "Report serious incidents to the AI Office within 2, 5, 10 or 15 days by incident class, with intermediate reports at least every four weeks while unresolved and a final report within 60 days of resolution; keep the records at least five years",
      "artefact": "Incident pipeline on the Commission template fields; per-class clocks; five-year retention policy; downstream reporting channel",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Signatory providers of GPAI models with systemic risk",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2025-07-10",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#gpai-code-of-practice"
    },
    {
      "id": "AIGE-OBL-GPAICOP-SAFETY-APP1",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety-app1",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gpaicop-safety-app1.json",
      "framework": "GPAI Code of Practice",
      "frameworkId": "gpai-code-of-practice",
      "clause": "Safety and Security, Appendix 1.3 and 1.4",
      "obligation": "Safety and Security Appendix 1.3 and 1.4: autonomy, tool use and loss of control as systemic risks",
      "requirement": "Sources of systemic risk to consider include the capability to operate autonomously, propensities such as colluding with other AI systems, and affordances such as access to tools and physical systems and the level of human oversight; loss of control is a specified systemic risk",
      "artefact": "Provider evaluations of autonomy and tool use, requested at the vendor due-diligence gate and filed with the agent registry entry",
      "layers": [
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Signatory providers of GPAI models with systemic risk (deployers request the evidence)",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2025-07-10",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#gpai-code-of-practice"
    },
    {
      "id": "AIGE-OBL-GDPR-ART5-1B",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art5-1b.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 5(1)(b) and 6(4)",
      "obligation": "GDPR Art. 5(1)(b) and 6(4) purpose limitation",
      "requirement": "Personal data are collected for specified, explicit and legitimate purposes and not further processed incompatibly; Art. 6(4) sets the compatibility test for reuse, such as training on data collected for another purpose",
      "artefact": "Purpose tags on datasets; purpose-match policy in training and indexing pipelines; compatibility assessment record",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "id": "pattern-dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART6",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art6",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art6.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 6",
      "obligation": "GDPR Art. 6 lawful basis per processing moment",
      "requirement": "A lawful basis for each processing operation, assessed separately for training, fine-tuning, retrieval and inference",
      "artefact": "Basis registry per dataset and stage; versioned legitimate-interest assessment",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART7",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art7",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art7.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 7",
      "obligation": "GDPR Art. 7 conditions for consent and its withdrawal",
      "requirement": "Where consent is the basis, the controller can demonstrate it, and withdrawing consent is as easy as giving it",
      "artefact": "Consent-purpose log joined to datasets and model versions; withdrawal propagated to the pipelines",
      "layers": [
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART9",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art9",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art9.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 9",
      "obligation": "GDPR Art. 9 special categories, incl. inferred sensitive data",
      "requirement": "Processing special-category data, incl. biometric data for unique identification, is prohibited unless an Art. 9(2) condition applies, which reaches sensitive data a model infers",
      "artefact": "Proxy test in CI; inference policy with a runtime output classifier; Art. 9(2) condition record",
      "layers": [
        1,
        3,
        4
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART13-14",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art13-14",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art13-14.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Arts. 13–14",
      "obligation": "GDPR Arts. 13–14 transparency to data subjects",
      "requirement": "Inform data subjects of purposes, bases, recipients and retention and, for automated decision-making, give meaningful information about the logic involved (Arts. 13(2)(f), 14(2)(g))",
      "artefact": "Notice generated from the registry entry; model card; automated-decision notice per system",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART15-1H",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-1h",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art15-1h.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 15(1)(h)",
      "obligation": "GDPR Art. 15(1)(h) access to meaningful information about the logic involved",
      "requirement": "On request, confirm automated decision-making and give meaningful information about the logic involved and its significance and envisaged consequences",
      "artefact": "Per-request explanation generated from the decision record; system-level automated-decision notice",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART15-17-21",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-17-21",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art15-17-21.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Arts. 15–17 and 21",
      "obligation": "GDPR Arts. 15–17 and 21 data subject rights against trained models",
      "requirement": "Access, rectification, erasure and objection requests reach every place the data lives: corpus, snapshots, retrieval index, logs and, where it holds personal data, the model",
      "artefact": "Request workflow across corpus, snapshots, retrieval index, logs and weights; fulfilment record",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART22",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art22",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art22.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 22",
      "obligation": "GDPR Art. 22 solely automated decisions and their safeguards",
      "requirement": "A right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, except on contract, law or explicit consent; then human intervention, the right to express a view and to contest (Art. 22(3))",
      "artefact": "Decision record with reason codes; contest channel and human review log; appeal outcomes by group",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART25",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art25",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art25.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 5(1)(c) and 25",
      "obligation": "GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default",
      "requirement": "Adequate, relevant and limited data, with technical and organisational measures built in at design and set by default",
      "artefact": "Feature justification record; PII and special-category filters; retention as code",
      "layers": [
        1,
        3
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART5-2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art5-2.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 5(2)",
      "obligation": "GDPR Art. 5(2) accountability for a model anonymity claim",
      "requirement": "A controller that claims a trained model holds no personal data must be able to demonstrate it; the EDPB sets an anonymity test and the evidence it expects",
      "artefact": "Anonymity evidence pack; membership-inference and extraction evals in the eval gate",
      "layers": [
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller (model developer)",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART28",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art28",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art28.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 28",
      "obligation": "GDPR Art. 28 processors, incl. AI vendors",
      "requirement": "Use only processors with sufficient guarantees, under a contract that fixes instructions, sub-processors, security, assistance and deletion",
      "artefact": "AI vendor clause checklist in the due-diligence gate (no training, retention, region, sub-processors, change notice)",
      "layers": [
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller; processor",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART30",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art30",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art30.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Art. 30",
      "obligation": "GDPR Art. 30 records of processing activities",
      "requirement": "Controllers and processors keep a record of the processing activities under their responsibility",
      "artefact": "Records generated per processing moment from the registry and data cards",
      "layers": [
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller; processor",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART33-34",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art33-34",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art33-34.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Arts. 33–34",
      "obligation": "GDPR Arts. 33–34 personal data breach notification",
      "requirement": "Notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness; tell data subjects without undue delay when the breach is likely to result in a high risk",
      "artefact": "Personal-data-breach branch of the incident pipeline with its own 72-hour timer; data-subject notice template",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller (the processor notifies the controller)",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART35-36",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art35-36",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art35-36.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Arts. 35–36",
      "obligation": "GDPR Arts. 35–36 DPIA and prior consultation",
      "requirement": "Assess the impact before processing likely to result in a high risk, and consult the supervisory authority where the residual risk stays high",
      "artefact": "AI DPIA template with AI-specific fields, cross-referenced by the FRIA; recorded decision when no DPIA is needed",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": "Controller",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-fria-as-code",
          "title": "FRIA-as-Code",
          "url": "https://aigovernanceengineer.com/patterns/fria-as-code"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-GDPR-ART44-49",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art44-49",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-gdpr-art44-49.json",
      "framework": "GDPR",
      "frameworkId": "gdpr",
      "clause": "Arts. 44–49",
      "obligation": "GDPR Arts. 44–49 international transfers, incl. remote inference",
      "requirement": "Transfers outside the EEA only on an adequacy decision, appropriate safeguards (such as standard contractual clauses or binding corporate rules) or a narrow derogation; sending personal data to a model hosted outside the EEA can be a transfer",
      "artefact": "Transfer register; residency and routing policy as code; transfer impact assessment",
      "layers": [
        1,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controller; processor",
      "authority": "National data protection authority",
      "appliesFrom": "2018-05-25",
      "appliesStatus": "in-force",
      "appliesNote": "In force; applies from 2018-05-25",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#the-gdpr"
    },
    {
      "id": "AIGE-OBL-NIS2-ART21-2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nis2-art21-2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nis2-art21-2.json",
      "framework": "NIS2",
      "frameworkId": "eu-nis2",
      "clause": "Art. 21(2)(c)–(d)",
      "obligation": "NIS2 Art. 21(2)(c)–(d) business continuity and supply-chain security",
      "requirement": "Risk-management measures include business continuity (backup, disaster recovery, crisis management) and supply-chain security with direct suppliers and service providers, which covers AI and model services",
      "artefact": "Continuity plan for AI dependencies with tested fallbacks; supplier assessments for model and platform providers",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Essential and important entities",
      "authority": "National competent authority (NIS2)",
      "appliesFrom": "2024-10-18",
      "appliesStatus": "in-force",
      "appliesNote": "Member States apply their measures from 2024-10-18; binds through national law",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#cyber-security-and-incident-reporting-law"
    },
    {
      "id": "AIGE-OBL-NIS2-ART23",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nis2-art23",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nis2-art23.json",
      "framework": "NIS2",
      "frameworkId": "eu-nis2",
      "clause": "Art. 23",
      "obligation": "NIS2 Art. 23 significant-incident reporting",
      "requirement": "An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of the notification, incl. the root cause",
      "artefact": "Per-regime clock on the incident record; significance determination with an owner; cause coding reused in the final report",
      "layers": [
        5
      ],
      "dutyHolder": null,
      "scope": "Essential and important entities",
      "authority": "CSIRT or competent authority",
      "appliesFrom": "2024-10-18",
      "appliesStatus": "in-force",
      "appliesNote": "Member States apply their measures from 2024-10-18; binds through national law",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#cyber-security-and-incident-reporting-law"
    },
    {
      "id": "AIGE-OBL-DORA-ART19",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-dora-art19",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-dora-art19.json",
      "framework": "DORA",
      "frameworkId": "eu-dora",
      "clause": "Art. 19",
      "obligation": "DORA Art. 19 major ICT-related incident reporting",
      "requirement": "Report major ICT-related incidents: initial notification within 4 hours of classification as major and no later than 24 hours from awareness (within 4 hours of a classification made after those 24 hours), intermediate report within 72 hours of the initial notification, final report within one month of the latest intermediate report",
      "artefact": "Classification record with a timestamp; per-regime clock; consistent cause coding for recurring-incident aggregation",
      "layers": [
        5
      ],
      "dutyHolder": null,
      "scope": "Financial entities",
      "authority": "Financial competent authority",
      "appliesFrom": "2025-01-17",
      "appliesStatus": "in-force",
      "appliesNote": "Applies from 2025-01-17; time limits in Delegated Regulation (EU) 2025/301",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#cyber-security-and-incident-reporting-law"
    },
    {
      "id": "AIGE-OBL-DORA-ART28",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-dora-art28",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-dora-art28.json",
      "framework": "DORA",
      "frameworkId": "eu-dora",
      "clause": "Art. 28(3) and 28(8)",
      "obligation": "DORA Art. 28(3) and 28(8) register of ICT third-party arrangements and exit strategies",
      "requirement": "Keep a register of information on all contractual arrangements for ICT services from third-party providers, and exit strategies for ICT services that support critical or important functions",
      "artefact": "Register entries for AI and model services; exit plan and exit-drill record",
      "layers": [
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "Financial entities",
      "authority": "Financial competent authority",
      "appliesFrom": "2025-01-17",
      "appliesStatus": "in-force",
      "appliesNote": "Applies from 2025-01-17",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#cyber-security-and-incident-reporting-law"
    },
    {
      "id": "AIGE-OBL-CRA-ART14",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cra-art14",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cra-art14.json",
      "framework": "Cyber Resilience Act",
      "frameworkId": "eu-cra",
      "clause": "Art. 14",
      "obligation": "Cyber Resilience Act Art. 14 reporting of actively exploited vulnerabilities and severe incidents",
      "requirement": "Notify actively exploited vulnerabilities and severe incidents through the single reporting platform: early warning within 24 hours, notification within 72 hours, final report 14 days after a fix is available (vulnerability) or one month after the notification (incident)",
      "artefact": "Vulnerability and incident clocks on the incident record; submission through the single reporting platform",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Manufacturers of products with digital elements",
      "authority": "Coordinating CSIRT and ENISA",
      "appliesFrom": "2026-09-11",
      "appliesStatus": "in-force",
      "appliesNote": "Art. 14 applies from 2026-09-11; the rest of the Regulation from 2027-12-11",
      "milestones": [
        {
          "date": "2027-12-11",
          "systemClass": [],
          "note": "The rest of the Regulation applies"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#cyber-security-and-incident-reporting-law"
    },
    {
      "id": "AIGE-OBL-PLD-ART4",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-pld-art4",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-pld-art4.json",
      "framework": "EU Product Liability Directive",
      "frameworkId": "eu-pld",
      "clause": "Art. 4(1)",
      "obligation": "EU Product Liability Directive Art. 4(1) software, incl. AI systems, as a product",
      "requirement": "Software is a product, so the manufacturer of an AI system is strictly liable for damage caused by a defect in a product placed on the market or put into service after 2026-12-09",
      "artefact": "Defect-liability review at design; contractual recourse; residual risk in the register",
      "layers": [
        1,
        5
      ],
      "dutyHolder": null,
      "scope": "Manufacturers and other economic operators",
      "authority": "National courts",
      "appliesFrom": "2026-12-09",
      "appliesStatus": "applies-later",
      "appliesNote": "Products placed on the market or put into service after 2026-12-09 (Art. 2(1)); transposition by 2026-12-09",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-PLD-ART9-10",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-pld-art9-10",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-pld-art9-10.json",
      "framework": "EU Product Liability Directive",
      "frameworkId": "eu-pld",
      "clause": "Arts. 9–10",
      "obligation": "EU Product Liability Directive Arts. 9–10 disclosure of evidence and presumption of defect",
      "requirement": "A court can order the defendant to disclose relevant evidence at its disposal; failing to disclose it is one of the conditions under which the product is presumed defective",
      "artefact": "Defence file per release: AIBOM with hashes, eval history, failure-mode analysis, signed logs, instructions for use, kept for the liability period",
      "layers": [
        2,
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Manufacturers, incl. providers of AI systems and substantial modifiers",
      "authority": "National courts",
      "appliesFrom": "2026-12-09",
      "appliesStatus": "applies-later",
      "appliesNote": "Products placed on the market or put into service after 2026-12-09",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-PLD-ART11-2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-pld-art11-2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-pld-art11-2.json",
      "framework": "EU Product Liability Directive",
      "frameworkId": "eu-pld",
      "clause": "Art. 11(2)",
      "obligation": "EU Product Liability Directive Art. 11(2) no later-defect defence for software, its updates or missing safety updates in the manufacturer's control",
      "requirement": "The manufacturer cannot rely on the defect arising after placing on the market where it is due to software, incl. its updates or upgrades, or to missing safety updates, that remain within its control",
      "artefact": "Change log; regression evals per release; patch decision records; versioned warnings",
      "layers": [
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Manufacturers",
      "authority": "National courts",
      "appliesFrom": "2026-12-09",
      "appliesStatus": "applies-later",
      "appliesNote": "Products placed on the market or put into service after 2026-12-09",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-DSM-ART4-3",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-dsm-art4-3.json",
      "framework": "DSM Directive",
      "frameworkId": "eu-dsm",
      "clause": "Art. 4(3)",
      "obligation": "DSM Directive Art. 4(3) text-and-data-mining reservations",
      "requirement": "The general text-and-data-mining exception applies only where rightholders have not expressly reserved use in an appropriate manner, such as machine-readable means for content made publicly available online",
      "artefact": "Crawler policy-as-code honouring reservations; training-data rights ledger with the reservation-check result, method and date",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": "Anyone mining works, incl. model developers",
      "authority": "National courts",
      "appliesFrom": "2021-06-07",
      "appliesStatus": "in-force",
      "appliesNote": "Transposition deadline 2021-06-07",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-DSA-ART25",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsa-art25",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-dsa-art25.json",
      "framework": "Digital Services Act",
      "frameworkId": "eu-dsa",
      "clause": "Art. 25",
      "obligation": "Digital Services Act Art. 25 no deceptive or manipulative interface design",
      "requirement": "Online platforms do not design, organise or operate their interfaces in a way that deceives or manipulates users or impairs their free and informed decisions",
      "artefact": "Interface review record; red-team eval for manipulative outputs",
      "layers": [
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Providers of online platforms",
      "authority": "Digital Services Coordinator; the Commission for very large platforms",
      "appliesFrom": "2024-02-17",
      "appliesStatus": "in-force",
      "appliesNote": "Applies from 2024-02-17",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-DSA-ART27",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsa-art27",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-dsa-art27.json",
      "framework": "Digital Services Act",
      "frameworkId": "eu-dsa",
      "clause": "Art. 27",
      "obligation": "Digital Services Act Art. 27 recommender system transparency",
      "requirement": "Online platforms set out in their terms the main parameters of their recommender systems and any options users have to modify them",
      "artefact": "Recommender parameter card generated from the ranking configuration; log of the options offered to users",
      "layers": [
        2,
        4
      ],
      "dutyHolder": null,
      "scope": "Providers of online platforms",
      "authority": "Digital Services Coordinator; the Commission for very large platforms",
      "appliesFrom": "2024-02-17",
      "appliesStatus": "in-force",
      "appliesNote": "Applies from 2024-02-17",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-UCPD-ART5-7",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-ucpd-art5-7",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-ucpd-art5-7.json",
      "framework": "UCPD",
      "frameworkId": "eu-ucpd",
      "clause": "Arts. 5–7 and Annex I",
      "obligation": "UCPD Arts. 5–7 and Annex I unfair and misleading commercial practices, incl. fake reviews",
      "requirement": "No commercial practice contrary to professional diligence, or misleading, that distorts the average consumer's decisions, incl. AI-generated claims and chatbot answers; stating that reviews are genuine without reasonable checks, and false reviews, are blacklisted (Annex I points 23b and 23c)",
      "artefact": "Claims register linked to eval results; review-provenance checks; chatbot answer evals on product claims",
      "layers": [
        1,
        3,
        4
      ],
      "dutyHolder": null,
      "scope": "Traders dealing with consumers",
      "authority": "National consumer-protection authorities",
      "appliesFrom": "2007-12-12",
      "appliesStatus": "in-force",
      "appliesNote": "Applies from 2007-12-12; review points added by Directive (EU) 2019/2161",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-PWD-ART7-11",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-pwd-art7-11",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-pwd-art7-11.json",
      "framework": "Platform Work Directive",
      "frameworkId": "eu-platform-work",
      "clause": "Arts. 7 and 9–11",
      "obligation": "Platform Work Directive Arts. 7 and 9–11 automated monitoring and decision-making systems",
      "requirement": "Limits on the personal data platforms may process through automated systems, transparency about those systems, human oversight with an impact evaluation at least every two years, and explanation and human review of decisions",
      "artefact": "Registry of automated systems with their main parameters; data-category deny list; two-yearly impact evaluation; explanation and human review log",
      "layers": [
        1,
        2,
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Digital labour platforms",
      "authority": "National labour and data protection authorities",
      "appliesFrom": "2026-12-02",
      "appliesStatus": "applies-later",
      "appliesNote": "Transposition by 2026-12-02 (Art. 29)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-CCD2-ART18-8",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-ccd2-art18-8",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-ccd2-art18-8.json",
      "framework": "Consumer Credit Directive",
      "frameworkId": "eu-ccd2",
      "clause": "Art. 18(8)",
      "obligation": "Consumer Credit Directive Art. 18(8) human intervention in automated creditworthiness assessment",
      "requirement": "Where the creditworthiness assessment involves automated processing, the consumer may request human intervention, a clear explanation of the assessment and its logic, and a review of the decision",
      "artefact": "Explanation artefact per model version; review path and log",
      "layers": [
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Creditors",
      "authority": "National competent authorities",
      "appliesFrom": "2026-11-20",
      "appliesStatus": "applies-later",
      "appliesNote": "Member States apply their measures from 2026-11-20 (Art. 48)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#liability-copyright-consumer-and-sector-law"
    },
    {
      "id": "AIGE-OBL-ISO42001-A2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a2.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.2",
      "obligation": "A.2 Policies related to AI",
      "requirement": "AI policy set and its governance",
      "artefact": "Policy-as-code library; versioned policy repository",
      "layers": [
        1
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        }
      ],
      "crosswalkTopics": [
        "governance-accountability"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A3",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a3",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a3.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.3",
      "obligation": "A.3 Internal organization",
      "requirement": "Roles, responsibilities, reporting",
      "artefact": "Operating model; RACI; ownership in the registry",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "governance-accountability"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A4",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a4.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.4",
      "obligation": "A.4 Resources for AI systems",
      "requirement": "Data, tooling, compute, human resources documented",
      "artefact": "Resource inventory; AIBOM; environment manifests",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "data-governance",
        "inventory-registration"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A5",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a5",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a5.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.5",
      "obligation": "A.5 Assessing impacts of AI systems",
      "requirement": "Impact assessment process",
      "artefact": "Impact assessment as code; FRIA/DPIA linkage (ISO/IEC 42005)",
      "layers": [
        1,
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "crosswalkTopics": [
        "impact-assessment",
        "fairness-non-discrimination"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A6",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a6.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.6",
      "obligation": "A.6 AI system life cycle",
      "requirement": "Responsible design, development, deployment",
      "artefact": "Pipeline controls; eval gates; change management",
      "layers": [
        1,
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [
        "risk-management",
        "documentation-transparency",
        "logging-traceability",
        "runtime-guardrails",
        "robustness-security-evals",
        "sandboxes-real-world-testing",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A7",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a7.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.7",
      "obligation": "A.7 Data for AI systems",
      "requirement": "Data quality, provenance, preparation",
      "artefact": "Data cards; lineage; data quality tests",
      "layers": [
        2,
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "id": "pattern-dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        }
      ],
      "crosswalkTopics": [
        "data-governance",
        "privacy-data-protection"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A8",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a8.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.8",
      "obligation": "A.8 Information for interested parties",
      "requirement": "Transparency and reporting to stakeholders",
      "artefact": "Model/data cards; machine-readable disclosures",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        }
      ],
      "crosswalkTopics": [
        "documentation-transparency",
        "incident-monitoring",
        "explainability"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A9",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a9.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.9",
      "obligation": "A.9 Use of AI systems",
      "requirement": "Responsible-use controls and monitoring",
      "artefact": "Runtime guardrails; usage telemetry",
      "layers": [
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        }
      ],
      "crosswalkTopics": [
        "human-oversight",
        "runtime-guardrails",
        "prohibited-practices",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42001-A10",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42001-a10.json",
      "framework": "ISO/IEC 42001",
      "frameworkId": "iso-42001",
      "clause": "A.10",
      "obligation": "A.10 Third-party and customer relationships",
      "requirement": "Managing supplier and customer responsibilities",
      "artefact": "Supplier AIBOM; contractual and technical control mapping",
      "layers": [
        2,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary management-system standard (2023); no presumption of conformity",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        }
      ],
      "crosswalkTopics": [
        "supply-chain"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42006-CB",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42006-cb",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42006-cb.json",
      "framework": "ISO/IEC 42006",
      "frameworkId": "iso-42006",
      "clause": "ISO/IEC 42006:2025",
      "obligation": "ISO/IEC 42006:2025 requirements for AIMS certification bodies",
      "requirement": "Requirements for bodies auditing and certifying AI management systems (who may credibly certify you to 42001)",
      "artefact": "Accredited certification scope; auditor-competence evidence; certificate register",
      "layers": [
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary standard (2025)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "conformity-assessment"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO23894-RISK",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso23894-risk",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso23894-risk.json",
      "framework": "ISO/IEC 23894",
      "frameworkId": "iso-23894",
      "clause": "ISO/IEC 23894:2023",
      "obligation": "ISO/IEC 23894:2023 guidance on AI risk management",
      "requirement": "Guidance on AI risk management (companion to ISO 31000)",
      "artefact": "Risk register as code; AI risk taxonomy; linkage to EU AI Act Art. 9 and the NIST AI RMF",
      "layers": [
        1,
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary guidance (2023)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "risk-management"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO42005-IA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42005-ia",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso42005-ia.json",
      "framework": "ISO/IEC 42005",
      "frameworkId": "iso-42005",
      "clause": "ISO/IEC 42005:2025",
      "obligation": "ISO/IEC 42005:2025 guidance for AI system impact assessment",
      "requirement": "Guidance for assessing the impacts of an AI system on individuals, groups and society across its life cycle (companion to Art. 27 and Annex A.5)",
      "artefact": "Impact assessment as code from a template; FRIA and DPIA cross-references; re-assessment triggers",
      "layers": [
        1,
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary guidance (2025)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-model-card-as-control-evidence",
          "title": "Model Card as Control Evidence",
          "url": "https://aigovernanceengineer.com/patterns/model-card-as-control-evidence"
        },
        {
          "id": "pattern-fria-as-code",
          "title": "FRIA-as-Code",
          "url": "https://aigovernanceengineer.com/patterns/fria-as-code"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-ISO22989-CONCEPTS",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso22989-concepts",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-iso22989-concepts.json",
      "framework": "ISO/IEC 22989",
      "frameworkId": "iso-22989",
      "clause": "ISO/IEC 22989:2022",
      "obligation": "ISO/IEC 22989:2022 AI concepts, terminology and stakeholder roles",
      "requirement": "A shared vocabulary for AI concepts, the AI system life cycle and AI stakeholder roles",
      "artefact": "Registry field names and role vocabulary aligned to the standard's terms; glossary cross-references",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary standard (2022)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#isoiec-42001-42005-and-42006"
    },
    {
      "id": "AIGE-OBL-NISTRMF-GOVERN",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nistrmf-govern.json",
      "framework": "NIST AI RMF",
      "frameworkId": "nist-ai-rmf",
      "clause": "GOVERN",
      "obligation": "GOVERN",
      "requirement": "A culture and structure for managing AI risk",
      "artefact": "Policy-as-code; operating model; registry ownership",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary (AI RMF 1.0, January 2023)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        },
        {
          "id": "pattern-continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "id": "pattern-framework-crosswalk",
          "title": "Framework Crosswalk",
          "url": "https://aigovernanceengineer.com/patterns/framework-crosswalk"
        },
        {
          "id": "pattern-machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        },
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        },
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [
        "governance-accountability",
        "inventory-registration",
        "human-oversight",
        "supply-chain",
        "risk-management",
        "incident-monitoring",
        "prohibited-practices",
        "fairness-non-discrimination",
        "ai-literacy",
        "ip-copyright",
        "agent-identity-autonomy",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#nist-ai-rmf"
    },
    {
      "id": "AIGE-OBL-NISTRMF-MAP",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nistrmf-map.json",
      "framework": "NIST AI RMF",
      "frameworkId": "nist-ai-rmf",
      "clause": "MAP",
      "obligation": "MAP",
      "requirement": "Context and risk framing for each AI system",
      "artefact": "Threat models; use-case and impact mapping; data/model cards",
      "layers": [
        2,
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary (AI RMF 1.0, January 2023)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        },
        {
          "id": "pattern-aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        },
        {
          "id": "pattern-model-card-as-control-evidence",
          "title": "Model Card as Control Evidence",
          "url": "https://aigovernanceengineer.com/patterns/model-card-as-control-evidence"
        },
        {
          "id": "pattern-fria-as-code",
          "title": "FRIA-as-Code",
          "url": "https://aigovernanceengineer.com/patterns/fria-as-code"
        },
        {
          "id": "pattern-shadow-ai-discovery",
          "title": "Shadow-AI Discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        },
        {
          "id": "pattern-vendor--model-due-diligence-gate",
          "title": "Vendor / Model Due-Diligence Gate",
          "url": "https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate"
        },
        {
          "id": "pattern-use-case-intake--risk-tiering",
          "title": "Use-Case Intake & Risk Tiering",
          "url": "https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering"
        },
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "id": "pattern-dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        }
      ],
      "crosswalkTopics": [
        "risk-management",
        "impact-assessment",
        "data-governance",
        "documentation-transparency",
        "supply-chain",
        "human-oversight",
        "ai-literacy",
        "ip-copyright"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#nist-ai-rmf"
    },
    {
      "id": "AIGE-OBL-NISTRMF-MEASURE",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nistrmf-measure.json",
      "framework": "NIST AI RMF",
      "frameworkId": "nist-ai-rmf",
      "clause": "MEASURE",
      "obligation": "MEASURE",
      "requirement": "Analyse, benchmark and monitor risk",
      "artefact": "Eval gates; adversarial red-team suite; metrics per failure mode",
      "layers": [
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary (AI RMF 1.0, January 2023)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "id": "pattern-adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        },
        {
          "id": "pattern-model-card-as-control-evidence",
          "title": "Model Card as Control Evidence",
          "url": "https://aigovernanceengineer.com/patterns/model-card-as-control-evidence"
        },
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "crosswalkTopics": [
        "risk-management",
        "data-governance",
        "documentation-transparency",
        "logging-traceability",
        "robustness-security-evals",
        "fairness-non-discrimination",
        "privacy-data-protection",
        "explainability",
        "conformity-assessment",
        "sandboxes-real-world-testing",
        "environmental-impact"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#nist-ai-rmf"
    },
    {
      "id": "AIGE-OBL-NISTRMF-MANAGE",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nistrmf-manage.json",
      "framework": "NIST AI RMF",
      "frameworkId": "nist-ai-rmf",
      "clause": "MANAGE",
      "obligation": "MANAGE",
      "requirement": "Prioritise, respond and recover",
      "artefact": "Runtime guardrails; incident pipeline; continuous assurance",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary (AI RMF 1.0, January 2023)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "id": "pattern-runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        },
        {
          "id": "pattern-kill-switch--circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        },
        {
          "id": "pattern-incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        },
        {
          "id": "pattern-machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        },
        {
          "id": "pattern-agent-identity--scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        },
        {
          "id": "pattern-human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        },
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        },
        {
          "id": "pattern-staged-rollout-with-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        },
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [
        "risk-management",
        "logging-traceability",
        "human-oversight",
        "runtime-guardrails",
        "incident-monitoring",
        "supply-chain",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#nist-ai-rmf"
    },
    {
      "id": "AIGE-OBL-NIST-AGENTS",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nist-agents.json",
      "framework": "NIST (agent, cyber and misuse work)",
      "frameworkId": "nist-ai-agent-standards",
      "clause": "AI Agent Standards Initiative",
      "obligation": "NIST AI Agent Standards Initiative (2026)",
      "requirement": "CAISI initiative on interoperable, secure AI agents: identity, authentication, agent security",
      "artefact": "Agent registry; non-human-identity controls; agent authentication and authorisation; adversarial agent evals",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Initiative launched 2026-02-17 by NIST CAISI",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#nist-ai-rmf"
    },
    {
      "id": "AIGE-OBL-NIST-IR8596",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-ir8596",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nist-ir8596.json",
      "framework": "NIST (agent, cyber and misuse work)",
      "frameworkId": "nist-ir-8596",
      "clause": "IR 8596",
      "obligation": "NIST IR 8596 Cyber AI Profile (draft)",
      "requirement": "CSF 2.0 profile for AI (Secure / Defend / Thwart)",
      "artefact": "AI-system security controls; runtime observability; threat detection mapped to CSF 2.0",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Draft: initial preliminary draft 2025-12-16, still the current version as of 2026-09-24",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#nist-ai-rmf"
    },
    {
      "id": "AIGE-OBL-NIST-AI800-1",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-ai800-1",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nist-ai800-1.json",
      "framework": "NIST (agent, cyber and misuse work)",
      "frameworkId": "nist-ai-800-1",
      "clause": "AI 800-1",
      "obligation": "NIST AI 800-1 misuse risk for dual-use foundation models (draft)",
      "requirement": "Managing Misuse Risk for Dual-Use Foundation Models (voluntary guidance)",
      "artefact": "Misuse red-team suite; capability and dangerous-capability evals; safety framework",
      "layers": [
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Draft: second public draft January 2025, no final version as of 2026-09-24",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#nist-ai-rmf"
    },
    {
      "id": "AIGE-OBL-NIST-AI600-1",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-ai600-1",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-nist-ai600-1.json",
      "framework": "NIST AI RMF",
      "frameworkId": "nist-ai-600-1",
      "clause": "AI 600-1",
      "obligation": "NIST AI 600-1 Generative AI Profile",
      "requirement": "Suggested actions for 12 risks that generative AI creates or exacerbates, coded to the Govern, Map, Measure and Manage functions",
      "artefact": "Generative-AI eval suites named after the profile's action ids (e.g. confabulation, information integrity); a risk-register entry per profile risk",
      "layers": [
        1,
        3
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2024-07-26",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#newer-nist-ai-work"
    },
    {
      "id": "AIGE-OBL-CSA-AICM",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-csa-aicm.json",
      "framework": "CSA AICM / STAR for AI",
      "frameworkId": "csa-aicm",
      "clause": "AICM v1.1",
      "obligation": "AICM v1.1: 247 control objectives across 18 domains",
      "requirement": "247 control objectives across 18 domains, spanning governance, data, model and runtime",
      "artefact": "Control catalogue mapped to policy-as-code and evals; crosswalk to ISO 42001 / NIST AI RMF",
      "layers": [
        1,
        3,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; v1.1 published 2026-06-22",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        },
        {
          "id": "pattern-agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        },
        {
          "id": "pattern-aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        },
        {
          "id": "pattern-continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "id": "pattern-kill-switch--circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        },
        {
          "id": "pattern-framework-crosswalk",
          "title": "Framework Crosswalk",
          "url": "https://aigovernanceengineer.com/patterns/framework-crosswalk"
        },
        {
          "id": "pattern-agent-identity--scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        },
        {
          "id": "pattern-shadow-ai-discovery",
          "title": "Shadow-AI Discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        }
      ],
      "crosswalkTopics": [
        "risk-management",
        "governance-accountability",
        "impact-assessment",
        "data-governance",
        "documentation-transparency",
        "inventory-registration",
        "logging-traceability",
        "human-oversight",
        "runtime-guardrails",
        "robustness-security-evals",
        "incident-monitoring",
        "supply-chain",
        "prohibited-practices",
        "fairness-non-discrimination",
        "privacy-data-protection",
        "explainability",
        "ai-literacy",
        "conformity-assessment",
        "gpai-foundation-models",
        "ip-copyright",
        "agent-identity-autonomy",
        "content-provenance",
        "sandboxes-real-world-testing",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#csa-aicm-and-star-for-ai"
    },
    {
      "id": "AIGE-OBL-CSA-STAR",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-star",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-csa-star.json",
      "framework": "CSA AICM / STAR for AI",
      "frameworkId": "csa-star-for-ai",
      "clause": "STAR for AI",
      "obligation": "STAR for AI assurance and certification programme",
      "requirement": "Assurance and certification programme on the AICM: Level 1 self-assessment, Level 1 Valid-AI-ted (automated validation) and Level 2 (ISO/IEC 42001 certification plus the validated assessment)",
      "artefact": "Machine-readable evidence submission; continuous assurance telemetry",
      "layers": [
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary assurance and certification programme",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#csa-aicm-and-star-for-ai"
    },
    {
      "id": "AIGE-OBL-CSA-AICM-AGENTIC",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-csa-aicm-agentic.json",
      "framework": "CSA AICM / STAR for AI",
      "frameworkId": "csa-aicm",
      "clause": "Agent controls (AICM v1.1, ATF, AARM)",
      "obligation": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
      "requirement": "Agent-specific AICM controls (e.g. IAM-18 Agent Access Restriction, AIS-11 Agents Security Boundaries), with the Agentic Trust Framework v1 (earned autonomy tiers) and the AARM runtime-interception specification",
      "artefact": "Agent-specific control definitions; policy-as-code for agent scope and tools; runtime guardrails",
      "layers": [
        1,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; AICM v1.1 published 2026-06-22, Agentic Trust Framework v1 in February 2026; the \"Agentic Control Supplement\" of earlier editions could not be matched to a CSA primary document as of 2026-09-24 (verify)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#csa-aicm-and-star-for-ai"
    },
    {
      "id": "AIGE-OBL-CSA-AICM-CATASTROPHIC",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-catastrophic",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-csa-aicm-catastrophic.json",
      "framework": "CSA AICM / STAR for AI",
      "frameworkId": "csa-aicm",
      "clause": "Catastrophic Risk Annex",
      "obligation": "AICM Catastrophic Risk Annex (enhanced controls for high-autonomy systems)",
      "requirement": "Enhanced AICM controls for high-autonomy systems with catastrophic-risk potential",
      "artefact": "Enhanced controls for high-autonomy systems; kill switch and oversight controls; pilot-audit evidence",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; meant to be proven through pilot audits",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#csa-aicm-and-star-for-ai"
    },
    {
      "id": "AIGE-OBL-OWASP-AGENTIC",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-owasp-agentic.json",
      "framework": "OWASP GenAI Security Project",
      "frameworkId": "owasp-agentic-top-10",
      "clause": "Top 10 for Agentic Applications 2026",
      "obligation": "Top 10 for Agentic Applications 2026",
      "requirement": "Agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents)",
      "artefact": "Agent threat model; adversarial evals; runtime guardrails; kill switch",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary (2026 edition)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        },
        {
          "id": "pattern-eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "id": "pattern-adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        },
        {
          "id": "pattern-agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        },
        {
          "id": "pattern-runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        },
        {
          "id": "pattern-kill-switch--circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        },
        {
          "id": "pattern-agent-identity--scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        },
        {
          "id": "pattern-human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        },
        {
          "id": "pattern-shadow-ai-discovery",
          "title": "Shadow-AI Discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        },
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        },
        {
          "id": "pattern-deactivation-localisation--retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        }
      ],
      "crosswalkTopics": [
        "human-oversight",
        "robustness-security-evals",
        "supply-chain",
        "agent-identity-autonomy"
      ],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#owasp-genai-security-project"
    },
    {
      "id": "AIGE-OBL-OWASP-LLM",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-owasp-llm.json",
      "framework": "OWASP GenAI Security Project",
      "frameworkId": "owasp-llm-top-10",
      "clause": "Top 10 for LLM Applications 2026",
      "obligation": "Top 10 for LLM Applications 2026",
      "requirement": "LLM threat catalogue (incl. Excessive Agency at #3)",
      "artefact": "Prompt-injection and output-handling controls; eval gate",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary (2026 edition)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-ai-threat-model",
          "title": "AI Threat Model",
          "url": "https://aigovernanceengineer.com/patterns/ai-threat-model"
        },
        {
          "id": "pattern-dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "id": "pattern-model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "id": "pattern-rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "id": "pattern-sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        },
        {
          "id": "pattern-downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        }
      ],
      "crosswalkTopics": [
        "data-governance",
        "runtime-guardrails",
        "robustness-security-evals",
        "supply-chain",
        "privacy-data-protection",
        "agent-identity-autonomy",
        "content-provenance"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#owasp-genai-security-project"
    },
    {
      "id": "AIGE-OBL-OWASP-ACS",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-acs",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-owasp-acs.json",
      "framework": "OWASP GenAI Security Project",
      "frameworkId": "owasp-acs",
      "clause": "ACS",
      "obligation": "Agent Control Standard (ACS)",
      "requirement": "A standard for expressing agent controls",
      "artefact": "Machine-readable control definitions for agents",
      "layers": [
        1,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-framework-crosswalk",
          "title": "Framework Crosswalk",
          "url": "https://aigovernanceengineer.com/patterns/framework-crosswalk"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#owasp-genai-security-project"
    },
    {
      "id": "AIGE-OBL-OWASP-AIBOM",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-owasp-aibom.json",
      "framework": "OWASP GenAI Security Project",
      "frameworkId": "owasp-aibom",
      "clause": "AIBOM",
      "obligation": "AIBOM",
      "requirement": "AI bill-of-materials format and generator",
      "artefact": "AIBOM at build (CycloneDX ML-BOM, SPDX 3.0 AI)",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#owasp-genai-security-project"
    },
    {
      "id": "AIGE-OBL-USCA-SB53",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usca-sb53",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usca-sb53.json",
      "framework": "US frontier-developer laws",
      "frameworkId": "ca-sb-53",
      "clause": "SB 53",
      "obligation": "California SB 53 (TFAIA)",
      "requirement": "Publish a frontier AI framework; report critical safety incidents to the Office of Emergency Services within 15 days; whistleblower protection; up to USD 1M per violation, AG-enforced",
      "artefact": "Published safety framework; incident pipeline reporting to the state; transparency artefacts",
      "layers": [
        5,
        4
      ],
      "dutyHolder": null,
      "scope": "Frontier developers (models trained above ~10^26 FLOP); the framework duty binds large frontier developers (developer revenue over USD 500M)",
      "authority": null,
      "appliesFrom": "2026-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "In force 2026-01-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#frontier-developer-laws"
    },
    {
      "id": "AIGE-OBL-USNY-RAISE",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usny-raise",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usny-raise.json",
      "framework": "US frontier-developer laws",
      "frameworkId": "ny-raise-act",
      "clause": "S6953B",
      "obligation": "New York RAISE Act (signed 2025-12-19; effective 2027-01-01)",
      "requirement": "Publish a frontier AI safety and security framework; disclose safety incidents within 72 hours. A chapter amendment signed 2026-03-27 sets the effective date at 2027-01-01 and creates an oversight office within the New York Department of Financial Services (DFS)",
      "artefact": "Published frontier AI safety framework; 72-hour incident and disclosure pipeline reporting to the DFS oversight office",
      "layers": [
        5,
        4
      ],
      "dutyHolder": null,
      "scope": "Frontier developers (models trained above 10^26 operations) report incidents within 72 hours; the framework duty binds large frontier developers (annual revenue over USD 500M); thresholds of the chapter amendment signed 2026-03-27",
      "authority": null,
      "appliesFrom": "2027-01-01",
      "appliesStatus": "applies-later",
      "appliesNote": "Signed 2025-12-19; effective 2027-01-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#frontier-developer-laws"
    },
    {
      "id": "AIGE-OBL-USCA-SB53-WHISTLE",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usca-sb53-whistle",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usca-sb53-whistle.json",
      "framework": "US frontier-developer laws",
      "frameworkId": "ca-sb-53",
      "clause": "SB 53 (Labor Code 1107–1107.2)",
      "obligation": "California SB 53 whistleblower protections for covered employees",
      "requirement": "No rule, policy or contract that prevents covered employees from disclosing catastrophic-risk concerns, and no retaliation; notice of rights; large frontier developers run an anonymous internal process with monthly updates to the reporter, shared with officers and directors at least quarterly",
      "artefact": "Anonymous internal reporting channel with status updates; notice acknowledgment records; quarterly summary to officers and directors",
      "layers": [
        1,
        5
      ],
      "dutyHolder": null,
      "scope": "Frontier developers; the anonymous process binds large frontier developers",
      "authority": null,
      "appliesFrom": "2026-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "In force 2026-01-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#frontier-developer-laws"
    },
    {
      "id": "AIGE-OBL-USTX-TRAIGA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-ustx-traiga",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-ustx-traiga.json",
      "framework": "US state AI laws",
      "frameworkId": "tx-traiga",
      "clause": "HB 149",
      "obligation": "Texas TRAIGA (HB 149; in force 2026-01-01)",
      "requirement": "Intent-based prohibitions on developing or deploying AI (behaviour manipulation, unlawful discrimination); social scoring banned for governmental entities; AI-use disclosure by government agencies and health care providers; a regulatory sandbox; Attorney-General enforcement; local AI rules preempted",
      "artefact": "Prohibited-use policy-as-code; AI-use disclosure controls; complaint and incident handling",
      "layers": [
        1,
        4
      ],
      "dutyHolder": null,
      "scope": "Developers and deployers doing business in Texas",
      "authority": null,
      "appliesFrom": "2026-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "In force 2026-01-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-19",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USCO-AIACT",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usco-aiact",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usco-aiact.json",
      "framework": "US state AI laws",
      "frameworkId": "co-ai-act",
      "clause": "SB 26-189 (replacing SB 24-205)",
      "obligation": "Colorado SB 26-189 automated decision-making technology (replaces the Colorado AI Act, SB 24-205; effective 2027-01-01)",
      "requirement": "Developer documentation to deployers and notice of material updates; deployer notice of ADMT use; a plain-language explanation within 30 days of an adverse outcome; correction, human review and reconsideration; records kept at least three years. SB 26-189 (signed 2026-05-14) repealed and re-enacted SB 24-205, whose duty of care against algorithmic discrimination had been delayed to 2026-06-30 and whose enforcement a federal court had blocked",
      "artefact": "ADMT inventory; developer documentation pack; notice and adverse-outcome explanation templates; human-review queue; three-year record store",
      "layers": [
        2,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Developers and deployers of ADMT in consequential decisions",
      "authority": "Attorney General (Consumer Protection Act)",
      "appliesFrom": "2027-01-01",
      "appliesStatus": "applies-later",
      "appliesNote": "SB 26-189 signed 2026-05-14, effective 2027-01-01; it replaces SB 24-205",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USCA-AB2013",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usca-ab2013",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usca-ab2013.json",
      "framework": "US state AI laws",
      "frameworkId": "ca-ab-2013",
      "clause": "AB 2013",
      "obligation": "California AB 2013 training-data transparency for generative AI",
      "requirement": "Developers post a summary of the datasets used to train a generative AI system made available to Californians (sources, size, data types, IP and personal information, synthetic data) on or before 2026-01-01 and on each substantial modification",
      "artefact": "Data card per dataset, published at release; training-data rights ledger",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": "Developers of generative AI systems released since 2022-01-01",
      "authority": null,
      "appliesFrom": "2026-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "Documentation due on or before 2026-01-01 and on each substantial modification",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USCA-SB942",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usca-sb942",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usca-sb942.json",
      "framework": "US state AI laws",
      "frameworkId": "ca-sb-942",
      "clause": "SB 942 as amended by AB 853",
      "obligation": "California AI Transparency Act (SB 942 as amended by AB 853)",
      "requirement": "Covered providers offer a free AI-detection tool and embed latent disclosures, with an optional manifest disclosure, in generated image, video and audio; large online platforms and capture devices follow later",
      "artefact": "Provenance pipeline writing latent metadata; public detection endpoint; platform-side provenance display",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": "Covered providers of public generative AI systems; large online platforms; capture-device makers",
      "authority": null,
      "appliesFrom": "2026-08-02",
      "appliesStatus": "in-force",
      "appliesNote": "Operative 2026-08-02; platform duties 2027-01-01; capture devices 2028-01-01",
      "milestones": [
        {
          "date": "2027-01-01",
          "systemClass": [],
          "note": "Large online platform duties apply"
        },
        {
          "date": "2028-01-01",
          "systemClass": [],
          "note": "Capture-device duties apply"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USCA-SB243",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usca-sb243",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usca-sb243.json",
      "framework": "US state AI laws",
      "frameworkId": "ca-sb-243",
      "clause": "SB 243",
      "obligation": "California SB 243 companion chatbots",
      "requirement": "Disclose AI where a reasonable person could be misled; for known minors, remind at least every three hours and prevent sexually explicit content; run a suicide and self-harm protocol with crisis referral; annual reports from 2027-07-01",
      "artefact": "Companion-mode policy; reminder timer; crisis-referral classifier and log; annual report",
      "layers": [
        1,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Operators of companion chatbots",
      "authority": "Private right of action",
      "appliesFrom": "2026-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "Chaptered 2025-10-13; in force 2026-01-01 as a non-urgency statute (verify); annual reports from 2027-07-01",
      "milestones": [
        {
          "date": "2027-07-01",
          "systemClass": [],
          "note": "Annual reports to the Office of Suicide Prevention begin"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USNY-GBL47",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usny-gbl47",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usny-gbl47.json",
      "framework": "US state AI laws",
      "frameworkId": "ny-gbl-47",
      "clause": "GBL Art. 47 (§§ 1700–1704)",
      "obligation": "New York GBL Article 47 AI companion models",
      "requirement": "Detect suicidal ideation and self-harm and refer users to crisis services; tell users they are not talking to a human at the start and at least every three hours",
      "artefact": "Crisis-referral classifier and log; notice timer",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Operators of AI companions",
      "authority": "Attorney General (civil penalties up to USD 15,000 per day)",
      "appliesFrom": "2025-11-05",
      "appliesStatus": "in-force",
      "appliesNote": "In force 2025-11-05, as reported (verify)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USIL-HB3773",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usil-hb3773",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usil-hb3773.json",
      "framework": "US state AI laws",
      "frameworkId": "il-hb-3773",
      "clause": "HB 3773",
      "obligation": "Illinois HB 3773 AI in employment decisions",
      "requirement": "Employers may not use AI with a discriminatory effect on protected classes in recruitment, hiring, promotion, discipline or other terms of employment, nor ZIP codes as a proxy, and must notify employees and applicants",
      "artefact": "AI-in-HR inventory; adverse-impact eval per protected class; notice record",
      "layers": [
        2,
        3,
        4
      ],
      "dutyHolder": null,
      "scope": "Employers",
      "authority": "Illinois Department of Human Rights",
      "appliesFrom": "2026-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "Effective 2026-01-01 (P.A. 103-0804); implementing rules in draft, as reported",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USNYC-LL144",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usnyc-ll144",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usnyc-ll144.json",
      "framework": "US state AI laws",
      "frameworkId": "nyc-ll-144",
      "clause": "Local Law 144 of 2021",
      "obligation": "NYC Local Law 144 automated employment decision tools",
      "requirement": "An independent bias audit within one year before use, a published summary of the results, and notice to candidates and employees 10 business days before use",
      "artefact": "Impact-ratio eval by sex, race/ethnicity and intersectional category; published audit summary; notice record",
      "layers": [
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Employers and employment agencies using AEDTs for New York City roles",
      "authority": "Department of Consumer and Worker Protection",
      "appliesFrom": "2023-07-05",
      "appliesStatus": "in-force",
      "appliesNote": "Enforced since 2023-07-05",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        },
        {
          "id": "pattern-drift--fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USUT-SB226",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usut-sb226",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usut-sb226.json",
      "framework": "US state AI laws",
      "frameworkId": "ut-ai-disclosure",
      "clause": "Utah Code 13-75 (SB 226)",
      "obligation": "Utah AI disclosure duties (SB 226 amendments to the AI Policy Act)",
      "requirement": "Disclose generative AI when a person clearly and unambiguously asks; regulated occupations disclose it prominently in a high-risk AI interaction; clear disclosure at the outset is a safe harbour",
      "artefact": "Disclosure component with an interaction-risk flag; conversation log showing the disclosure",
      "layers": [
        4
      ],
      "dutyHolder": null,
      "scope": "Suppliers using generative AI in consumer transactions; regulated occupations",
      "authority": "Division of Consumer Protection",
      "appliesFrom": "2025-05-07",
      "appliesStatus": "in-force",
      "appliesNote": "Effective 2025-05-07; the AI Policy Act (Title 13, Chapter 72) is repealed on 2027-07-01",
      "milestones": [
        {
          "date": "2027-07-01",
          "systemClass": [],
          "note": "The AI Policy Act (Title 13, Chapter 72) is repealed"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-state-ai-laws"
    },
    {
      "id": "AIGE-OBL-USCA-CPPA-ADMT",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usca-cppa-admt",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usca-cppa-admt.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "ca-cppa-regs",
      "clause": "CCPA regulations (ADMT)",
      "obligation": "California CPPA regulations on automated decisionmaking technology",
      "requirement": "Businesses using ADMT for significant decisions give a pre-use notice, an opt-out or a human appeal, and access to information about the ADMT",
      "artefact": "ADMT register; pre-use notice; opt-out or appeal workflow; ADMT access response",
      "layers": [
        2,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Businesses subject to the CCPA",
      "authority": "California Privacy Protection Agency",
      "appliesFrom": "2027-01-01",
      "appliesStatus": "applies-later",
      "appliesNote": "Regulations effective 2026-01-01; ADMT duties from 2027-01-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USCA-CPPA-RA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usca-cppa-ra",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usca-cppa-ra.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "ca-cppa-regs",
      "clause": "CCPA regulations (risk assessments)",
      "obligation": "California CPPA regulations on risk assessments",
      "requirement": "A risk assessment before processing that presents significant risk, incl. using ADMT for significant decisions; attestations and summaries submitted to the Agency",
      "artefact": "Risk assessment per triggering activity; submission record",
      "layers": [
        5
      ],
      "dutyHolder": null,
      "scope": "Businesses subject to the CCPA",
      "authority": "California Privacy Protection Agency",
      "appliesFrom": "2026-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "Effective 2026-01-01; attestations and summaries due 2028-04-01",
      "milestones": [
        {
          "date": "2028-04-01",
          "systemClass": [],
          "note": "Attestations and summaries due to the Agency"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USVA-CDPA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usva-cdpa",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usva-cdpa.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "va-cdpa",
      "clause": "§ 59.1-580",
      "obligation": "Virginia CDPA data protection assessments, incl. risky profiling",
      "requirement": "Controllers document data protection assessments for targeted advertising, sale, profiling that presents a reasonably foreseeable risk, and sensitive data, for processing created after 2023-01-01, and give them to the Attorney General on request",
      "artefact": "Assessment template per processing activity; profiling register",
      "layers": [
        1,
        5
      ],
      "dutyHolder": null,
      "scope": "Controllers",
      "authority": "Attorney General",
      "appliesFrom": "2023-01-01",
      "appliesStatus": "in-force",
      "appliesNote": "Processing created after 2023-01-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USCO-CPA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usco-cpa",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usco-cpa.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "co-privacy-act",
      "clause": "SB21-190",
      "obligation": "Colorado Privacy Act profiling opt-out and data protection assessments",
      "requirement": "Consumers may opt out of profiling in furtherance of decisions with legal or similarly significant effects, incl. through a universal opt-out mechanism; controllers run data protection assessments for processing that presents a heightened risk",
      "artefact": "Opt-out flag honoured at inference; assessment template; intake data-class flags",
      "layers": [
        1,
        2,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controllers",
      "authority": "Attorney General and district attorneys",
      "appliesFrom": "2023-07-01",
      "appliesStatus": "in-force",
      "appliesNote": "Effective 2023-07-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USMN-MCDPA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usmn-mcdpa",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usmn-mcdpa.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "mn-cdpa",
      "clause": "§ 325M.14, subd. 1(g)",
      "obligation": "Minnesota CDPA right to question the result of profiling",
      "requirement": "A consumer may question the result of profiling, be told the reason, review the personal data used, correct it and have the decision re-evaluated",
      "artefact": "Reason-and-review workflow with re-evaluation on corrected data",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controllers",
      "authority": "Attorney General",
      "appliesFrom": "2025-07-31",
      "appliesStatus": "in-force",
      "appliesNote": "Effective 2025-07-31",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USIL-BIPA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usil-bipa",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usil-bipa.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "il-bipa",
      "clause": "740 ILCS 14",
      "obligation": "Illinois BIPA consent and retention for biometric identifiers",
      "requirement": "Informed written consent before collecting biometric identifiers, a retention and destruction schedule, and secure storage; a private right of action with statutory damages",
      "artefact": "Written-consent capture; retention schedule as code; destruction log",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": "Private entities",
      "authority": "Private right of action",
      "appliesFrom": "2008-10-03",
      "appliesStatus": "in-force",
      "appliesNote": "Effective 2008-10-03 (P.A. 95-994)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USWA-MHMDA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-uswa-mhmda",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-uswa-mhmda.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "wa-mhmda",
      "clause": "RCW 19.373",
      "obligation": "Washington My Health My Data Act consent for consumer health data",
      "requirement": "Consent to collect and separate consent to share consumer health data, incl. data derived or extrapolated by algorithms or machine learning, and a signed authorisation for any sale",
      "artefact": "Separate consent records for collection and sharing; signed sale authorisation; intake flags for derived health data",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": "Regulated entities",
      "authority": "Attorney General (Consumer Protection Act)",
      "appliesFrom": "2024-03-31",
      "appliesStatus": "in-force",
      "appliesNote": "From 2024-03-31; small businesses from 2024-06-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USCO-SB21-169",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usco-sb21-169",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usco-sb21-169.json",
      "framework": "US state privacy and sector laws",
      "frameworkId": "co-sb21-169",
      "clause": "SB21-169",
      "obligation": "Colorado SB21-169 insurers' use of external consumer data and predictive models",
      "requirement": "Insurers may not unfairly discriminate through external consumer data, algorithms or predictive models; they keep a risk-management framework, test for unfair discrimination and file a chief-risk-officer attestation under rules adopted per line of insurance",
      "artefact": "Inventory of external data sources and models; disparity testing; chief-risk-officer attestation record",
      "layers": [
        2,
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Insurers",
      "authority": "Colorado Commissioner of Insurance",
      "appliesFrom": "2021-09-07",
      "appliesStatus": "in-force",
      "appliesNote": "Act effective 2021-09-07; duties bind through rules per line of insurance, none effective before 2023-01-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#state-privacy-and-sector-laws"
    },
    {
      "id": "AIGE-OBL-USFED-OMB-M25-21",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usfed-omb-m25-21",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usfed-omb-m25-21.json",
      "framework": "US federal law",
      "frameworkId": "us-omb-m-25-21",
      "clause": "M-25-21 §4(b)",
      "obligation": "OMB M-25-21 minimum practices for high-impact AI",
      "requirement": "Federal agencies apply minimum practices to high-impact AI: pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight with a fail-safe where practicable, remedies or appeals, and consultation of end users, documented within 365 days",
      "artefact": "Use-case inventory entry; pre-deployment test report; AI impact assessment; monitoring plan; appeal path",
      "layers": [
        2,
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "US federal agencies (their AI vendors by contract)",
      "authority": "OMB; agency Chief AI Officers",
      "appliesFrom": "2025-04-03",
      "appliesStatus": "in-force",
      "appliesNote": "Issued 2025-04-03; practices documented within 365 days",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-law-that-already-reaches-ai"
    },
    {
      "id": "AIGE-OBL-USFED-OMB-M26-04",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usfed-omb-m26-04",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usfed-omb-m26-04.json",
      "framework": "US federal law",
      "frameworkId": "us-omb-m-26-04",
      "clause": "M-26-04",
      "obligation": "OMB M-26-04 minimum LLM transparency in federal procurement",
      "requirement": "Solicitations for large language models request, as a minimum, the vendor's acceptable use policy, model, system or data cards, end-user resources and a feedback mechanism",
      "artefact": "Acceptable use policy; model, system or data cards; end-user resources; feedback channel",
      "layers": [
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "US federal agencies and LLM vendors",
      "authority": "OMB",
      "appliesFrom": "2025-12-11",
      "appliesStatus": "in-force",
      "appliesNote": "Issued 2025-12-11; agency policies updated by 2026-03-11",
      "milestones": [
        {
          "date": "2026-03-11",
          "systemClass": [],
          "note": "Agency procurement policies updated"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-law-that-already-reaches-ai"
    },
    {
      "id": "AIGE-OBL-USFED-REGB-1002-9",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usfed-regb-1002-9",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usfed-regb-1002-9.json",
      "framework": "US federal law",
      "frameworkId": "us-ecoa-reg-b",
      "clause": "12 CFR 1002.9",
      "obligation": "ECOA Regulation B adverse-action notice with specific principal reasons",
      "requirement": "A creditor that takes adverse action gives a statement of specific principal reasons, or the right to one within 30 days; citing internal standards or a failed score is insufficient, whatever model made the decision",
      "artefact": "Reason-code service versioned with the model; reason-code fidelity eval; notice template",
      "layers": [
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Creditors",
      "authority": "CFPB and the prudential regulators",
      "appliesFrom": "2011-12-21",
      "appliesStatus": "in-force",
      "appliesNote": "Long-standing duty; the CFPB's Regulation B text dates from 2011-12-21 (76 FR 79445)",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-explanation-artefact",
          "title": "Explanation Artefact",
          "url": "https://aigovernanceengineer.com/patterns/explanation-artefact"
        },
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-law-that-already-reaches-ai"
    },
    {
      "id": "AIGE-OBL-USFED-FCRA-1681M",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usfed-fcra-1681m",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usfed-fcra-1681m.json",
      "framework": "US federal law",
      "frameworkId": "us-fcra",
      "clause": "15 U.S.C. 1681m(a)",
      "obligation": "FCRA adverse-action notice with the credit score used",
      "requirement": "A user of a consumer report that takes adverse action gives notice, discloses the numerical credit score used and its key factors, names the reporting agency and states the right to a free report and to dispute",
      "artefact": "Score and key-factor record per adverse decision; notice template",
      "layers": [
        4
      ],
      "dutyHolder": null,
      "scope": "Users of consumer reports",
      "authority": "CFPB and FTC",
      "appliesFrom": "2011-07-21",
      "appliesStatus": "in-force",
      "appliesNote": "Credit-score disclosure in force since the designated transfer date, 2011-07-21",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-law-that-already-reaches-ai"
    },
    {
      "id": "AIGE-OBL-USFED-TITLE7-703K",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usfed-title7-703k",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usfed-title7-703k.json",
      "framework": "US federal law",
      "frameworkId": "us-title-vii-ugesp",
      "clause": "Title VII s. 703(k); 29 CFR 1607.4(D)",
      "obligation": "Title VII disparate impact and the UGESP four-fifths rule",
      "requirement": "A selection procedure with disparate impact is unlawful unless job-related and consistent with business necessity, and a less discriminatory alternative can still be required; a selection rate under four-fifths of the highest group's rate is generally regarded as evidence of adverse impact",
      "artefact": "Adverse-impact-ratio eval per group with counts and confidence intervals; job-relatedness validation; alternatives search log",
      "layers": [
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Employers",
      "authority": "EEOC; courts",
      "appliesFrom": "1978-08-25",
      "appliesStatus": "in-force",
      "appliesNote": "UGESP adopted 1978-08-25 (43 FR 38295); s. 703(k) since 1991-11-21",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-law-that-already-reaches-ai"
    },
    {
      "id": "AIGE-OBL-USFED-FTC-S5",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usfed-ftc-s5",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usfed-ftc-s5.json",
      "framework": "US federal law",
      "frameworkId": "us-ftc-act",
      "clause": "FTC Act s. 5 (15 U.S.C. 45)",
      "obligation": "FTC Act s. 5 substantiation of AI performance claims",
      "requirement": "Deceptive acts or practices are unlawful: claims about an AI system's accuracy, performance or fairness need competent and reliable evidence before they are made",
      "artefact": "Claims register linked to current eval runs; substantiation gate on release copy",
      "layers": [
        1,
        3,
        5
      ],
      "dutyHolder": null,
      "scope": "Businesses making AI claims",
      "authority": "Federal Trade Commission",
      "appliesFrom": "1938-03-21",
      "appliesStatus": "in-force",
      "appliesNote": "Deception prong since the Wheeler-Lea Act of 1938-03-21; applied to AI accuracy claims in 2025",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-law-that-already-reaches-ai"
    },
    {
      "id": "AIGE-OBL-USFED-TAKEITDOWN",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usfed-takeitdown",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usfed-takeitdown.json",
      "framework": "US federal law",
      "frameworkId": "us-take-it-down",
      "clause": "Pub. L. 119-12, s. 3",
      "obligation": "TAKE IT DOWN Act notice and removal of intimate images, incl. digital forgeries",
      "requirement": "Covered platforms run a notice-and-removal process and remove reported non-consensual intimate images, incl. AI-generated forgeries, and known identical copies within 48 hours of a valid request",
      "artefact": "Takedown pipeline with a 48-hour clock, owner and log; matching of identical copies",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Covered platforms",
      "authority": "Federal Trade Commission",
      "appliesFrom": "2026-05-19",
      "appliesStatus": "in-force",
      "appliesNote": "Enacted 2025-05-19; the notice-and-removal process was due by 2026-05-19",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-law-that-already-reaches-ai"
    },
    {
      "id": "AIGE-OBL-USGAO-GOV",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usgao-gov",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usgao-gov.json",
      "framework": "US federal audit and oversight",
      "frameworkId": "us-gao-ai-accountability",
      "clause": "principle 1 (governance), practices 1.1 to 1.9",
      "obligation": "GAO AI Accountability Framework principle 1: governance",
      "requirement": "Clear goals, roles and delegation of authority, values, a multidisciplinary workforce, stakeholder involvement and an AI-specific risk management plan, plus documented technical specifications, compliance with applicable law and transparency to external stakeholders",
      "artefact": "Registry entry with owner and intended purpose; RACI; risk register as code; compliance mapping; published system card",
      "layers": [
        1,
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "Federal agencies and other entities; auditors and third-party assessors",
      "authority": "U.S. Government Accountability Office; inspectors general",
      "appliesFrom": "2021-06-30",
      "appliesStatus": "voluntary",
      "appliesNote": "Non-binding audit framework; published 2021-06-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "risk-management",
        "governance-accountability",
        "impact-assessment",
        "documentation-transparency",
        "ai-literacy",
        "conformity-assessment"
      ],
      "reviewed": "2026-09-27",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-audit-and-oversight"
    },
    {
      "id": "AIGE-OBL-USGAO-DATA",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usgao-data",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usgao-data.json",
      "framework": "US federal audit and oversight",
      "frameworkId": "us-gao-ai-accountability",
      "clause": "principle 2 (data), practices 2.1 to 2.8",
      "obligation": "GAO AI Accountability Framework principle 2: data",
      "requirement": "Document the sources and origins of development data and assess their reliability, categorisation, variable selection and any synthetic, imputed or augmented data; assess the dependencies, bias, security and privacy of the data used in operation",
      "artefact": "Dataset datasheet with lineage; data-quality and representativeness evals; data-flow map",
      "layers": [
        2,
        3
      ],
      "dutyHolder": null,
      "scope": "Federal agencies and other entities; auditors and third-party assessors",
      "authority": "U.S. Government Accountability Office; inspectors general",
      "appliesFrom": "2021-06-30",
      "appliesStatus": "voluntary",
      "appliesNote": "Non-binding audit framework; published 2021-06-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "data-governance",
        "supply-chain",
        "fairness-non-discrimination",
        "privacy-data-protection"
      ],
      "reviewed": "2026-09-27",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-audit-and-oversight"
    },
    {
      "id": "AIGE-OBL-USGAO-PERF",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usgao-perf",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usgao-perf.json",
      "framework": "US federal audit and oversight",
      "frameworkId": "us-gao-ai-accountability",
      "clause": "principle 3 (performance), practices 3.1 to 3.9",
      "obligation": "GAO AI Accountability Framework principle 3: performance",
      "requirement": "Catalogue components, define precise, consistent and reproducible metrics, assess each component and the whole system against them, identify biases and define procedures for human supervision",
      "artefact": "Eval suite with versioned metrics per component and system; bias eval; human-oversight procedure",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": "Federal agencies and other entities; auditors and third-party assessors",
      "authority": "U.S. Government Accountability Office; inspectors general",
      "appliesFrom": "2021-06-30",
      "appliesStatus": "voluntary",
      "appliesNote": "Non-binding audit framework; published 2021-06-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "documentation-transparency",
        "inventory-registration",
        "human-oversight",
        "robustness-security-evals",
        "fairness-non-discrimination"
      ],
      "reviewed": "2026-09-27",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-audit-and-oversight"
    },
    {
      "id": "AIGE-OBL-USGAO-MON",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-usgao-mon",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-usgao-mon.json",
      "framework": "US federal audit and oversight",
      "frameworkId": "us-gao-ai-accountability",
      "clause": "principle 4 (monitoring), practices 4.1 to 4.5",
      "obligation": "GAO AI Accountability Framework principle 4: monitoring",
      "requirement": "Plan continuous or routine monitoring, set the acceptable range of data and model drift, document monitoring results and corrective actions, and reassess the system's utility and the conditions for scaling it",
      "artefact": "Monitoring plan with drift thresholds; monitoring log with corrective actions; periodic review record",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Federal agencies and other entities; auditors and third-party assessors",
      "authority": "U.S. Government Accountability Office; inspectors general",
      "appliesFrom": "2021-06-30",
      "appliesStatus": "voluntary",
      "appliesNote": "Non-binding audit framework; published 2021-06-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "logging-traceability",
        "incident-monitoring",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-27",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#federal-audit-and-oversight"
    },
    {
      "id": "AIGE-OBL-KR-AIBASIC",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-aibasic",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-aibasic.json",
      "framework": "Other jurisdictions",
      "frameworkId": "kr-ai-basic-act",
      "clause": "AI Basic Act",
      "obligation": "South Korea AI Basic Act (in force 2026-01-22)",
      "requirement": "Baseline duties for AI operators, heightened duties for \"high-impact\" AI in sensitive sectors, and AI-content labelling",
      "artefact": "Risk register for high-impact AI; AI-use notification; AI-content labelling",
      "layers": [
        1,
        2,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT announced a guidance period of at least one year that holds back fact-finding and fines except in exceptional cases, while the duties apply",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "risk-management",
        "governance-accountability",
        "impact-assessment",
        "documentation-transparency",
        "inventory-registration",
        "logging-traceability",
        "human-oversight",
        "robustness-security-evals",
        "incident-monitoring",
        "explainability",
        "conformity-assessment",
        "gpai-foundation-models",
        "content-provenance"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-jurisdictions"
    },
    {
      "id": "AIGE-OBL-SG-GENAI",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-genai",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-sg-genai.json",
      "framework": "Other jurisdictions",
      "frameworkId": "sg-genai-framework",
      "clause": "Model AI Governance Framework for Generative AI",
      "obligation": "Singapore IMDA Model AI Governance Framework for Generative AI (voluntary)",
      "requirement": "Governance dimensions incl. testing, transparency, incident reporting, security and content provenance",
      "artefact": "Eval suite; model cards; content provenance and watermarking",
      "layers": [
        2,
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published May 2024",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "governance-accountability",
        "data-governance",
        "documentation-transparency",
        "robustness-security-evals",
        "incident-monitoring",
        "privacy-data-protection",
        "explainability",
        "ai-literacy",
        "conformity-assessment",
        "gpai-foundation-models",
        "ip-copyright",
        "content-provenance",
        "environmental-impact"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-jurisdictions"
    },
    {
      "id": "AIGE-OBL-UK-ADM",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-uk-adm",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-uk-adm.json",
      "framework": "Other jurisdictions",
      "frameworkId": "uk-duaa",
      "clause": "UK GDPR Arts. 22A–22D",
      "obligation": "UK GDPR Arts. 22A–22D permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025)",
      "requirement": "A permission-plus-safeguards model for significant, solely automated decisions, with tighter conditions where special-category data is used",
      "artefact": "ADM safeguards: meaningful-human-review path, contest and representation channel, decision notice",
      "layers": [
        4,
        2
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": "2026-02-05",
      "appliesStatus": "in-force",
      "appliesNote": "In force 2026-02-05",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-decision-notice--contest-path",
          "title": "Decision Notice & Contest Path",
          "url": "https://aigovernanceengineer.com/patterns/decision-notice-contest-path"
        }
      ],
      "crosswalkTopics": [
        "human-oversight",
        "privacy-data-protection",
        "explainability"
      ],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#united-kingdom"
    },
    {
      "id": "AIGE-OBL-ETSI-304223",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-etsi-304223",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-etsi-304223.json",
      "framework": "Other jurisdictions",
      "frameworkId": "etsi-en-304-223",
      "clause": "EN 304 223",
      "obligation": "ETSI EN 304 223 baseline cyber-security for AI models and systems",
      "requirement": "Baseline cyber-security requirements across the AI lifecycle (13 principles over five stages)",
      "artefact": "AI-system security controls across the lifecycle; supply-chain and AIBOM checks; runtime hardening",
      "layers": [
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Published (V2.1.1, Dec 2025); a voluntary standard",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-jurisdictions"
    },
    {
      "id": "AIGE-OBL-SG-AGENTIC-IDENTITY",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-identity",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-sg-agentic-identity.json",
      "framework": "Other jurisdictions",
      "frameworkId": "sg-agentic-framework",
      "clause": "Agentic AI framework v1.5: identity and authorisations",
      "obligation": "Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary)",
      "requirement": "Each agent has a unique, accounted-for identity, catalogued and centrally managed; authorisations are scoped, time- or session-bound, non-transferable and bounded by the authorising human",
      "artefact": "Agent registry with a workload identity per agent; delegated, short-lived credentials never broader than the user",
      "layers": [
        2,
        4
      ],
      "dutyHolder": null,
      "scope": "Organisations deploying agents",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; version 1.5 published 2026-05-20",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-jurisdictions"
    },
    {
      "id": "AIGE-OBL-SG-AGENTIC-CHECKPOINTS",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-checkpoints",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-sg-agentic-checkpoints.json",
      "framework": "Other jurisdictions",
      "frameworkId": "sg-agentic-framework",
      "clause": "Agentic AI framework v1.5: human checkpoints",
      "obligation": "Singapore IMDA Model AI Governance Framework for Agentic AI: human checkpoints for significant actions (voluntary)",
      "requirement": "Significant checkpoints for high-stakes, irreversible, outlier and user-defined actions, with approvals that are contextual and digestible and enforced through system-level controls",
      "artefact": "Checkpoint classes in the tool gateway; approval log; oversight metrics",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Organisations deploying agents",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; version 1.5 published 2026-05-20",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-jurisdictions"
    },
    {
      "id": "AIGE-OBL-CAN-DADM",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-can-dadm",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-can-dadm.json",
      "framework": "Other jurisdictions",
      "frameworkId": "canada-dadm",
      "clause": "Directive on Automated Decision-Making",
      "obligation": "Canada Directive on Automated Decision-Making (federal institutions)",
      "requirement": "Complete, approve and publish an algorithmic impact assessment before production; apply the Appendix C requirements for the impact level (notice, explanation, peer review, human intervention); offer recourse and report on effectiveness",
      "artefact": "Published AIA rendered from a shared impact fact base; notice and explanation templates; peer-review record; recourse path; re-assessment triggers as code",
      "layers": [
        1,
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "Canadian federal institutions",
      "authority": "Treasury Board of Canada Secretariat",
      "appliesFrom": "2019-04-01",
      "appliesStatus": "in-force",
      "appliesNote": "In effect since 2019-04-01; modified 2025-06-24; earlier systems complied by 2026-06-24",
      "milestones": [
        {
          "date": "2025-06-24",
          "systemClass": [],
          "note": "Current version of the directive"
        },
        {
          "date": "2026-06-24",
          "systemClass": [],
          "note": "Systems procured before 2025-06-24 meet the updated requirements"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-jurisdictions"
    },
    {
      "id": "AIGE-OBL-BR-LGPD-ART20",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-br-lgpd-art20",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-br-lgpd-art20.json",
      "framework": "Other jurisdictions",
      "frameworkId": "br-lgpd",
      "clause": "LGPD Art. 20",
      "obligation": "Brazil LGPD Art. 20 review of automated decisions",
      "requirement": "A data subject may request review of decisions taken solely on automated processing that affect their interests, incl. profiling, and the controller gives clear information on the criteria and procedures used",
      "artefact": "Review workflow; statement of criteria and procedures per system",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Controllers",
      "authority": "ANPD (national data protection authority)",
      "appliesFrom": "2020-09-18",
      "appliesStatus": "in-force",
      "appliesNote": "In force 2020-09-18 (verify); administrative sanctions from 2021-08-01",
      "milestones": [
        {
          "date": "2021-08-01",
          "systemClass": [],
          "note": "Administrative sanctions (Arts. 52 to 54) apply"
        }
      ],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#other-jurisdictions"
    },
    {
      "id": "AIGE-OBL-KR-ART31-1",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-art31-1",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-art31-1.json",
      "framework": "South Korea AI Basic Act",
      "frameworkId": "kr-ai-basic-act",
      "clause": "Art. 31(1)",
      "obligation": "Korea AI Basic Act Art. 31(1) prior notice of high-impact or generative AI",
      "requirement": "Tell users in advance that a product or service runs on high-impact or generative AI, in the product, the terms, the screen or the place of supply (Decree Art. 23(1)); a missing notice is finable (Art. 43)",
      "artefact": "Notice component in UI, terms and contracts; notice inventory per user surface",
      "layers": [
        2,
        4
      ],
      "dutyHolder": null,
      "scope": "AI business operators",
      "authority": "MSIT",
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT holds back fact-finding and fines for a guidance period of at least one year, while the duty applies",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#south-korea-article-by-article"
    },
    {
      "id": "AIGE-OBL-KR-ART31-2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-art31-2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-art31-2.json",
      "framework": "South Korea AI Basic Act",
      "frameworkId": "kr-ai-basic-act",
      "clause": "Art. 31(2)–(3)",
      "obligation": "Korea AI Basic Act Art. 31(2)–(3) generative-AI output labels and realistic-content notice",
      "requirement": "Indicate that outputs are AI-generated, and notify or label realistic synthetic sound, images or video so users can recognise them; a machine-readable mark alone needs at least one text or voice notice (Decree Art. 23(2)–(3))",
      "artefact": "Provenance pipeline: visible label or machine-readable mark plus at least one text or voice notice",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": "Operators providing generative AI",
      "authority": "MSIT",
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT holds back fact-finding and fines for a guidance period of at least one year, while the duty applies",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-disclosure--notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#south-korea-article-by-article"
    },
    {
      "id": "AIGE-OBL-KR-ART32",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-art32",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-art32.json",
      "framework": "South Korea AI Basic Act",
      "frameworkId": "kr-ai-basic-act",
      "clause": "Art. 32",
      "obligation": "Korea AI Basic Act Art. 32 safety duties for high-compute systems",
      "requirement": "Systems with at least 10^26 FLOP of cumulative training compute, built with the most advanced technology and posing broad and serious risk (Decree Art. 24), identify, assess and mitigate risks across the lifecycle and report the results to MSIT",
      "artefact": "Lifecycle risk register; safety-incident monitoring; results report to MSIT",
      "layers": [
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Operators of qualifying high-compute systems",
      "authority": "MSIT",
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT holds back fact-finding and fines for a guidance period of at least one year, while the duty applies",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#south-korea-article-by-article"
    },
    {
      "id": "AIGE-OBL-KR-ART33",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-art33",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-art33.json",
      "framework": "South Korea AI Basic Act",
      "frameworkId": "kr-ai-basic-act",
      "clause": "Art. 33",
      "obligation": "Korea AI Basic Act Art. 33 high-impact self-review and confirmation",
      "requirement": "Review in advance whether a system is high-impact AI and optionally ask MSIT to confirm; MSIT replies within 30 days, extendable once (Decree Art. 25)",
      "artefact": "Classification decision record per system: Art. 2(4) area, risk rationale, training-data overview, MSIT reply",
      "layers": [
        1,
        2
      ],
      "dutyHolder": null,
      "scope": "AI business operators",
      "authority": "MSIT",
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT holds back fact-finding and fines for a guidance period of at least one year, while the duty applies",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#south-korea-article-by-article"
    },
    {
      "id": "AIGE-OBL-KR-ART34",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-art34",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-art34.json",
      "framework": "South Korea AI Basic Act",
      "frameworkId": "kr-ai-basic-act",
      "clause": "Art. 34",
      "obligation": "Korea AI Basic Act Art. 34 measures for high-impact AI",
      "requirement": "A risk management plan, an explanation plan, a user-protection plan, human management and supervision, and documents showing the measures; publish the main content and keep the evidence for five years (Decree Art. 27)",
      "artefact": "Risk management, explanation and user-protection plans; named human overseer; published summary; five-year evidence store",
      "layers": [
        1,
        2,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Operators of high-impact AI",
      "authority": "MSIT",
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT holds back fact-finding and fines for a guidance period of at least one year, while the duty applies",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#south-korea-article-by-article"
    },
    {
      "id": "AIGE-OBL-KR-ART35",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-art35",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-art35.json",
      "framework": "South Korea AI Basic Act",
      "frameworkId": "kr-ai-basic-act",
      "clause": "Art. 35",
      "obligation": "Korea AI Basic Act Art. 35 fundamental-rights impact assessment (best effort)",
      "requirement": "Endeavour to assess the effect on fundamental rights before providing high-impact AI, covering the seven elements of Decree Art. 28",
      "artefact": "Impact assessment carrying the seven decree elements",
      "layers": [
        1,
        5
      ],
      "dutyHolder": null,
      "scope": "Operators of high-impact AI",
      "authority": "MSIT",
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT holds back fact-finding and fines for a guidance period of at least one year, while the duty applies",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#south-korea-article-by-article"
    },
    {
      "id": "AIGE-OBL-KR-ART36",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-kr-art36",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-kr-art36.json",
      "framework": "South Korea AI Basic Act",
      "frameworkId": "kr-ai-basic-act",
      "clause": "Art. 36",
      "obligation": "Korea AI Basic Act Art. 36 domestic representative",
      "requirement": "An operator with no address or establishment in Korea that meets a decree threshold (revenue, AI-service revenue, daily users or a past fine; Decree Art. 29) designates a domestic representative in writing and reports it to MSIT",
      "artefact": "Designation filed with MSIT; evidence-access runbook for the representative",
      "layers": [
        5
      ],
      "dutyHolder": null,
      "scope": "Foreign AI business operators above a threshold",
      "authority": "MSIT",
      "appliesFrom": "2026-01-22",
      "appliesStatus": "grace",
      "appliesNote": "In force 2026-01-22; MSIT holds back fact-finding and fines for a guidance period of at least one year, while the duty applies",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#south-korea-article-by-article"
    },
    {
      "id": "AIGE-OBL-UK-DMCC-S225",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-uk-dmcc-s225",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-uk-dmcc-s225.json",
      "framework": "Other jurisdictions",
      "frameworkId": "uk-dmcc",
      "clause": "DMCC Act 2024 s. 225; Sch. 20 para. 13",
      "obligation": "UK DMCC Act 2024 banned practices: fake and concealed-incentive reviews",
      "requirement": "Unfair commercial practices are prohibited, and Schedule 20 bans submitting or commissioning fake consumer reviews and concealed-incentive reviews, which reaches reviews generated by AI",
      "artefact": "Policy blocking review generation; review-provenance log",
      "layers": [
        1,
        4
      ],
      "dutyHolder": null,
      "scope": "Traders",
      "authority": "Competition and Markets Authority",
      "appliesFrom": "2025-04-06",
      "appliesStatus": "in-force",
      "appliesNote": "In force 2025-04-06",
      "milestones": [],
      "systemClass": [],
      "patterns": [
        {
          "id": "pattern-claims-substantiation-gate",
          "title": "Claims Substantiation Gate",
          "url": "https://aigovernanceengineer.com/patterns/claims-substantiation-gate"
        }
      ],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#united-kingdom"
    },
    {
      "id": "AIGE-OBL-CN-ALGOREC",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-algorec",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-algorec.json",
      "framework": "China",
      "frameworkId": "cn-algo-recommendation",
      "clause": "CAC Order No. 9",
      "obligation": "Provisions on Algorithmic Recommendation (in force 2022-03-01)",
      "requirement": "Algorithm filing for services with public-opinion attributes or social-mobilisation capacity, security assessment, display of the filing number, and a user option to switch off personalised recommendation",
      "artefact": "Algorithm inventory with filing record and number; security-assessment evidence pack; opt-out control at runtime",
      "layers": [
        1,
        2,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": "2022-03-01",
      "appliesStatus": "in-force",
      "appliesNote": "Binding; in force 2022-03-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "risk-management",
        "governance-accountability",
        "documentation-transparency",
        "inventory-registration",
        "human-oversight",
        "runtime-guardrails",
        "incident-monitoring",
        "fairness-non-discrimination",
        "explainability"
      ],
      "reviewed": "2026-09-20",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-DEEPSYN",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-deepsyn",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-deepsyn.json",
      "framework": "China",
      "frameworkId": "cn-deep-synthesis",
      "clause": "CAC Order No. 12",
      "obligation": "Provisions on Deep Synthesis (in force 2023-01-10)",
      "requirement": "Conspicuous labels where synthetic content could mislead the public and non-removable technical marks; training-data management; separate consent for face and voice editing; filing and security assessment for opinion-shaping functions",
      "artefact": "Content-provenance pipeline (visible label plus metadata mark); training-data governance record; consent gate; pre-release security assessment",
      "layers": [
        2,
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": "2023-01-10",
      "appliesStatus": "in-force",
      "appliesNote": "Binding; in force 2023-01-10",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "governance-accountability",
        "data-governance",
        "documentation-transparency",
        "inventory-registration",
        "runtime-guardrails",
        "robustness-security-evals",
        "supply-chain",
        "content-provenance"
      ],
      "reviewed": "2026-09-20",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-GENAI",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-genai",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-genai.json",
      "framework": "China",
      "frameworkId": "cn-genai-measures",
      "clause": "CAC Order No. 15",
      "obligation": "Interim Measures for Generative AI Services (in force 2023-08-15)",
      "requirement": "Lawful-source training data and foundation models; content labelling under the deep-synthesis rules; security assessment and algorithm filing for opinion-shaping services; stop, remove, retrain and report on illegal content",
      "artefact": "Data-lineage and licensing record; eval gate on generated content; incident pipeline with a retraining loop; filing record",
      "layers": [
        2,
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": "2023-08-15",
      "appliesStatus": "in-force",
      "appliesNote": "Binding; in force 2023-08-15; applies to services offered to the public within the PRC",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "risk-management",
        "governance-accountability",
        "impact-assessment",
        "data-governance",
        "documentation-transparency",
        "inventory-registration",
        "human-oversight",
        "runtime-guardrails",
        "robustness-security-evals",
        "incident-monitoring",
        "supply-chain",
        "prohibited-practices",
        "fairness-non-discrimination",
        "privacy-data-protection",
        "ai-literacy",
        "conformity-assessment",
        "gpai-foundation-models",
        "ip-copyright",
        "content-provenance"
      ],
      "reviewed": "2026-09-20",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-LABEL",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-label",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-label.json",
      "framework": "China",
      "frameworkId": "cn-content-labelling",
      "clause": "Labelling Measures + GB 45438-2025",
      "obligation": "Measures for Labelling AI-Generated Synthetic Content with GB 45438-2025 (in force 2025-09-01)",
      "requirement": "Explicit labels (text, audio or graphic) and implicit metadata labels carrying the provider's name or code and a content number; distribution platforms verify metadata and flag suspected AI content",
      "artefact": "Provenance and watermarking pipeline emitting the GB 45438 metadata fields; platform-side detection and flagging",
      "layers": [
        3,
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": "2025-09-01",
      "appliesStatus": "in-force",
      "appliesNote": "Binding; in force 2025-09-01, the standard implemented the same day",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "documentation-transparency",
        "logging-traceability",
        "content-provenance"
      ],
      "reviewed": "2026-09-20",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-GBT45654",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-gbt45654",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-gbt45654.json",
      "framework": "China",
      "frameworkId": "cn-gbt-45654",
      "clause": "GB/T 45654-2025",
      "obligation": "GB/T 45654-2025 Basic security requirements for generative AI services (voluntary; implemented 2025-11-01)",
      "requirement": "Training-corpus source and content screening, model-safety requirements and the evaluation methods that underpin the security assessment",
      "artefact": "Corpus-screening record; eval question banks; security-assessment report",
      "layers": [
        3,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": "2025-11-01",
      "appliesStatus": "voluntary",
      "appliesNote": "Recommended (voluntary) national standard; implemented 2025-11-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "data-governance",
        "documentation-transparency",
        "robustness-security-evals"
      ],
      "reviewed": "2026-09-20",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-TC260-OPS",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-ops",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-tc260-ops.json",
      "framework": "China",
      "frameworkId": "cn-tc260-framework",
      "clause": "Framework 3.0 §5.3",
      "obligation": "TC260 AI Safety Governance Framework 3.0: operators' guidelines §5.3 (voluntary; 2026-09-14)",
      "requirement": "A three-block risk taxonomy (inherent, application, secondary), technological and governance countermeasures and role-based guidelines; operators keep logs for at least six months and audit them, monitor risk in real time, keep a traceable chain of responsibility and assess resilience (§5.3)",
      "artefact": "Risk register keyed to the framework's taxonomy; log-retention policy (six months) with audit; real-time risk monitoring; resilience assessment",
      "layers": [
        1,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2026-09-14, building on 1.0 (2024) and 2.0 (2025)",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "risk-management",
        "governance-accountability",
        "impact-assessment",
        "data-governance",
        "inventory-registration",
        "logging-traceability",
        "runtime-guardrails",
        "robustness-security-evals",
        "incident-monitoring",
        "supply-chain",
        "deployment-change-decommissioning"
      ],
      "reviewed": "2026-09-20",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-TC260-AGENTS",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-agents",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-tc260-agents.json",
      "framework": "China",
      "frameworkId": "cn-tc260-framework",
      "clause": "Framework 3.0 Appendix 2",
      "obligation": "TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14)",
      "requirement": "Unique identity and least-privilege permissions per agent by decision mode; human checkpoints with tamper-proof approval logs and deny-by-default; tool and skill verification; runtime guardrails (alert, restrict, intercept, suspend, terminate); memory isolation with no credentials in memory; mutual authentication; sandbox validation, red teaming and re-validation on major change; controlled decommissioning",
      "artefact": "Agent registry with identity and scope; approval-log store; tool allow-list with integrity checks; runtime guardrails and kill switch; memory-scope policy; decommissioning runbook",
      "layers": [
        2,
        3,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; published 2026-09-14",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [
        "inventory-registration",
        "logging-traceability",
        "human-oversight",
        "runtime-guardrails",
        "robustness-security-evals",
        "incident-monitoring",
        "supply-chain",
        "agent-identity-autonomy",
        "sandboxes-real-world-testing"
      ],
      "reviewed": "2026-09-20",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-PIPL-ART24",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-pipl-art24",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-pipl-art24.json",
      "framework": "China",
      "frameworkId": "cn-pipl",
      "clause": "PIPL Arts. 24, 55–56",
      "obligation": "China PIPL Art. 24 automated decision-making and Arts. 55–56 impact assessment",
      "requirement": "Automated decisions stay transparent and fair, with no unreasonable differential treatment in prices or terms; targeted pushes offer a non-personalised option or an easy refusal; individuals may request an explanation and refuse solely automated decisions with a significant impact; an impact assessment beforehand, kept at least three years",
      "artefact": "Explanation service and manual-decision route; non-personalised option at runtime; impact assessment record kept three years",
      "layers": [
        2,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Personal information processors",
      "authority": "CAC and other departments",
      "appliesFrom": "2021-11-01",
      "appliesStatus": "in-force",
      "appliesNote": "Binding; in force 2021-11-01",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-CN-ANTHRO",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-anthro",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cn-anthro.json",
      "framework": "China",
      "frameworkId": "cn-anthropomorphic",
      "clause": "CAC anthropomorphic interaction measures",
      "obligation": "Interim Measures for Anthropomorphic Interaction Services (in force 2026-07-15)",
      "requirement": "A minors' mode; AI signals and a reminder after two hours of continuous use; an easy exit; a security assessment at 1 million registered or 100,000 monthly active users; filing",
      "artefact": "Minors'-mode configuration; reminder timer; user-count threshold monitor; security-assessment report; filing record",
      "layers": [
        1,
        2,
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Providers of emotional-interaction AI services to the public in China",
      "authority": "CAC",
      "appliesFrom": "2026-07-15",
      "appliesStatus": "in-force",
      "appliesNote": "Binding; in force 2026-07-15",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#china"
    },
    {
      "id": "AIGE-OBL-COE-ART14-2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-coe-art14-2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-coe-art14-2.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "coe-cets-225",
      "clause": "Art. 14(2)(a)–(b)",
      "obligation": "Council of Europe Convention Art. 14(2)(a)–(b) documentation to contest decisions",
      "requirement": "Document relevant information about systems that can significantly affect human rights, sufficient for affected people to contest the decisions",
      "artefact": "Decision record per consequential output; contest path with the record attached",
      "layers": [
        2,
        5
      ],
      "dutyHolder": null,
      "scope": "Parties (states and the EU); private actors through national measures",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Not in force as of 2026-09-24; binds Parties once in force, and the EU implements it through the AI Act",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-COE-ART15-2",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-coe-art15-2",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-coe-art15-2.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "coe-cets-225",
      "clause": "Art. 15(2)",
      "obligation": "Council of Europe Convention Art. 15(2) notice of interaction with an AI system",
      "requirement": "Notify people that they are interacting with an AI system, as appropriate",
      "artefact": "Interaction disclosure enforced at runtime",
      "layers": [
        4
      ],
      "dutyHolder": null,
      "scope": "Parties (states and the EU); private actors through national measures",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Not in force as of 2026-09-24; binds Parties once in force, and the EU implements it through the AI Act",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-COE-ART16",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-coe-art16",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-coe-art16.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "coe-cets-225",
      "clause": "Art. 16(1)–(2)(a)–(f)",
      "obligation": "Council of Europe Convention Art. 16 risk and impact management",
      "requirement": "Iterative, graduated risk and impact management: context, severity and probability, stakeholder views, monitoring and documentation",
      "artefact": "Risk register as code; impact assessment linked to the registry; monitoring against a baseline",
      "layers": [
        1,
        2,
        4
      ],
      "dutyHolder": null,
      "scope": "Parties (states and the EU); private actors through national measures",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Not in force as of 2026-09-24; binds Parties once in force, and the EU implements it through the AI Act",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-COE-ART16-2G",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-coe-art16-2g",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-coe-art16-2g.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "coe-cets-225",
      "clause": "Art. 16(2)(g)",
      "obligation": "Council of Europe Convention Art. 16(2)(g) testing before first use and on significant modification",
      "requirement": "Test systems before first use and when they are significantly modified, where appropriate",
      "artefact": "Eval gate on release and on material change",
      "layers": [
        3
      ],
      "dutyHolder": null,
      "scope": "Parties (states and the EU); private actors through national measures",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Not in force as of 2026-09-24; binds Parties once in force, and the EU implements it through the AI Act",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-OECD-P1-4B",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-oecd-p1-4b",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-oecd-p1-4b.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "oecd-ai-principles",
      "clause": "principle 1.4(b)",
      "obligation": "OECD AI Principle 1.4(b) override, repair or decommission safely",
      "requirement": "Mechanisms let AI systems that risk undue harm be overridden, repaired and/or decommissioned safely",
      "artefact": "Tested kill switch; decommissioning record in the registry",
      "layers": [
        2,
        4
      ],
      "dutyHolder": null,
      "scope": "AI actors (a commitment of adhering governments)",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Non-binding; revised 2024-05-03",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-OECD-P1-5",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-oecd-p1-5",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-oecd-p1-5.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "oecd-ai-principles",
      "clause": "principle 1.5(b)–(c)",
      "obligation": "OECD AI Principle 1.5(b)–(c) traceability and systematic risk management",
      "requirement": "Traceability of datasets, processes and decisions, and systematic risk management at each phase of the lifecycle",
      "artefact": "Evidence store keyed to registry ids; risk register as code; supplier records",
      "layers": [
        1,
        5
      ],
      "dutyHolder": null,
      "scope": "AI actors (a commitment of adhering governments)",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Non-binding; revised 2024-05-03",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-G7-A1",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-g7-a1",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-g7-a1.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "g7-hiroshima-coc",
      "clause": "Action 1",
      "obligation": "G7 Hiroshima Code action 1: lifecycle risk management and pre-deployment testing",
      "requirement": "Identify, evaluate and mitigate risks across the lifecycle, incl. testing before deployment",
      "artefact": "Adversarial red-team suite; eval gate",
      "layers": [
        3
      ],
      "dutyHolder": null,
      "scope": "Organisations developing advanced AI systems",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; agreed 2023-10-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-G7-A2-4",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-g7-a2-4",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-g7-a2-4.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "g7-hiroshima-coc",
      "clause": "Actions 2 and 4",
      "obligation": "G7 Hiroshima Code actions 2 and 4: post-deployment monitoring and incident sharing",
      "requirement": "Identify and mitigate vulnerabilities, incidents and misuse after deployment, and share information and report incidents responsibly",
      "artefact": "Runtime monitoring; incident pipeline with an external-sharing branch",
      "layers": [
        4,
        5
      ],
      "dutyHolder": null,
      "scope": "Organisations developing advanced AI systems",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; agreed 2023-10-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-G7-A3",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-g7-a3",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-g7-a3.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "g7-hiroshima-coc",
      "clause": "Action 3",
      "obligation": "G7 Hiroshima Code action 3: public reporting of capabilities and limitations",
      "requirement": "Publicly report capabilities, limitations and appropriate and inappropriate uses; the OECD reporting framework has collected such reports since 2025",
      "artefact": "Model card published from the registry",
      "layers": [
        2
      ],
      "dutyHolder": null,
      "scope": "Organisations developing advanced AI systems",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; agreed 2023-10-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-G7-A7",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-g7-a7",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-g7-a7.json",
      "framework": "Treaty and international soft law",
      "frameworkId": "g7-hiroshima-coc",
      "clause": "Action 7",
      "obligation": "G7 Hiroshima Code action 7: content authentication and provenance",
      "requirement": "Deploy content authentication and provenance mechanisms where feasible",
      "artefact": "Provenance marking at output; verification test",
      "layers": [
        4
      ],
      "dutyHolder": null,
      "scope": "Organisations developing advanced AI systems",
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Voluntary; agreed 2023-10-30",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#treaty-and-international-soft-law"
    },
    {
      "id": "AIGE-OBL-CEN-EN18286",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cen-en18286",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cen-en18286.json",
      "framework": "CEN-CENELEC JTC 21",
      "frameworkId": "en-18286",
      "clause": "EN 18286:2026",
      "obligation": "EN 18286:2026 quality management system for EU AI Act purposes",
      "requirement": "Quality-management-system requirements supporting Art. 17; published but not cited in the Official Journal, so it carries no presumption of conformity",
      "artefact": "QMS processes run as pipeline stages; design and change-control evidence",
      "layers": [
        1,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "voluntary",
      "appliesNote": "Published July 2026; not cited in the Official Journal as of 2026-09-24",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#what-is-not-harmonised-yet"
    },
    {
      "id": "AIGE-OBL-CEN-PREN18228",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cen-pren18228",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cen-pren18228.json",
      "framework": "CEN-CENELEC JTC 21",
      "frameworkId": "pren-18228",
      "clause": "prEN 18228",
      "obligation": "prEN 18228 AI risk management (draft)",
      "requirement": "Draft harmonised standard for the risk management system of Art. 9",
      "artefact": "Provider risk file per system; acceptability criteria as code; control monitoring",
      "layers": [
        1,
        3,
        5
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Draft; Enquiry vote closed 2026-07-30, as reported",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#what-is-not-harmonised-yet"
    },
    {
      "id": "AIGE-OBL-CEN-PREN18229-1",
      "url": "https://aigovernanceengineer.com/obligations/aige-obl-cen-pren18229-1",
      "json": "https://aigovernanceengineer.com/api/v1/obligations/aige-obl-cen-pren18229-1.json",
      "framework": "CEN-CENELEC JTC 21",
      "frameworkId": "pren-18229-1",
      "clause": "prEN 18229-1",
      "obligation": "prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft)",
      "requirement": "Draft harmonised standard for the record-keeping of Art. 12",
      "artefact": "Logging specification per system; structured, signed event logs mapped to the draft",
      "layers": [
        4
      ],
      "dutyHolder": null,
      "scope": null,
      "authority": null,
      "appliesFrom": null,
      "appliesStatus": "pending",
      "appliesNote": "Draft; Enquiry vote closed 2026-08-20, as reported",
      "milestones": [],
      "systemClass": [],
      "patterns": [],
      "crosswalkTopics": [],
      "reviewed": "2026-09-24",
      "chapter": "https://aigovernanceengineer.com/bok/regulatory-map#what-is-not-harmonised-yet"
    }
  ]
}
