{
  "openapi": "3.1.0",
  "jsonSchemaDialect": "https://json-schema.org/draft/2020-12/schema",
  "info": {
    "title": "AI Governance Engineer open data API",
    "version": "1.0.0",
    "summary": "Static, read-only JSON datasets from the AI Governance Engineer Body of Knowledge.",
    "description": "Static files regenerated on every release of the site; no authentication, no rate limit beyond the host's, CORS open. Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity).",
    "license": {
      "name": "CC BY 4.0",
      "url": "https://creativecommons.org/licenses/by/4.0/"
    },
    "contact": {
      "name": "Jorge García Aibar",
      "url": "https://aigovernanceengineer.com/resources/data"
    }
  },
  "externalDocs": {
    "description": "Documentation, stability promise and citation",
    "url": "https://aigovernanceengineer.com/resources/data"
  },
  "servers": [
    {
      "url": "https://aigovernanceengineer.com/api/v1"
    }
  ],
  "paths": {
    "/index.json": {
      "get": {
        "operationId": "getIndex",
        "summary": "The API catalogue",
        "responses": {
          "200": {
            "description": "The datasets, schemas and this description.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/index.json"
                }
              }
            }
          }
        }
      }
    },
    "/obligations.json": {
      "get": {
        "operationId": "getObligations",
        "summary": "Obligation register",
        "description": "Every obligation → artefact → stack-layer row of the regulatory map, with stable ids, ISO application dates, status, system classes, patterns and review dates.",
        "responses": {
          "200": {
            "description": "Obligation register (schema version 2).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/obligations.json"
                }
              }
            }
          }
        }
      }
    },
    "/frameworks.json": {
      "get": {
        "operationId": "getFrameworks",
        "summary": "Frameworks",
        "description": "The laws, standards, codes and control sets the regulatory map covers, with the ids of their obligation rows.",
        "responses": {
          "200": {
            "description": "Frameworks (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/frameworks.json"
                }
              }
            }
          }
        }
      }
    },
    "/crosswalk.json": {
      "get": {
        "operationId": "getCrosswalk",
        "summary": "Topic crosswalk",
        "description": "Twelve governance topics against the clauses of the EU AI Act, ISO/IEC 42001, the NIST AI RMF and the Chinese instruments, joined to the obligation register.",
        "responses": {
          "200": {
            "description": "Topic crosswalk (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/crosswalk.json"
                }
              }
            }
          }
        }
      }
    },
    "/glossary.json": {
      "get": {
        "operationId": "getGlossary",
        "summary": "Glossary",
        "description": "The canonical terms of the discipline, parsed from chapter 09, with their chapter references.",
        "responses": {
          "200": {
            "description": "Glossary (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/glossary.json"
                }
              }
            }
          }
        }
      }
    },
    "/patterns.json": {
      "get": {
        "operationId": "getPatterns",
        "summary": "Pattern catalogue index",
        "description": "The reusable patterns of chapter 05, with their home layer, the frameworks their \"Maps to\" line names and the obligation rows that list them.",
        "responses": {
          "200": {
            "description": "Pattern catalogue index (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/patterns.json"
                }
              }
            }
          }
        }
      }
    },
    "/maturity.json": {
      "get": {
        "operationId": "getMaturity",
        "summary": "Maturity model",
        "description": "The five-level maturity model of chapter 07, Documented → Continuous, with its typical evidence.",
        "responses": {
          "200": {
            "description": "Maturity model (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/maturity.json"
                }
              }
            }
          }
        }
      }
    },
    "/path.json": {
      "get": {
        "operationId": "getPath",
        "summary": "Learning path",
        "description": "The four-stage learning path: nodes, prerequisites, internal links and external resources.",
        "responses": {
          "200": {
            "description": "Learning path (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/path.json"
                }
              }
            }
          }
        }
      }
    },
    "/chapters.json": {
      "get": {
        "operationId": "getChapters",
        "summary": "Body of Knowledge chapters",
        "description": "The chapters of the Body of Knowledge in reading order, with their part, summary and takeaways.",
        "responses": {
          "200": {
            "description": "Body of Knowledge chapters (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/chapters.json"
                }
              }
            }
          }
        }
      }
    },
    "/jurisdictions.json": {
      "get": {
        "operationId": "getJurisdictions",
        "summary": "AI laws by jurisdiction",
        "description": "The AI-specific legal landscape by jurisdiction: how binding each regime is and the instruments behind it, each dated.",
        "responses": {
          "200": {
            "description": "AI laws by jurisdiction (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/jurisdictions.json"
                }
              }
            }
          }
        }
      }
    },
    "/harms.json": {
      "get": {
        "operationId": "getHarms",
        "summary": "AI harms atlas",
        "description": "Harms by level with the failure mode, the controlling pattern, the evidence it leaves, the stack layers, the MIT AI Risk Repository taxonomy codes and real incidents.",
        "responses": {
          "200": {
            "description": "AI harms atlas (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/harms.json"
                }
              }
            }
          }
        }
      }
    },
    "/cases.json": {
      "get": {
        "operationId": "getCases",
        "summary": "Incident cases",
        "description": "Publicly documented AI incidents written as engineering post-mortems, with the control that would have caught them, the evidence it would have left and the obligations they touch; some carry an incident note (system boundary, control assumptions, controls by moment, evidence requirements, related open controls, open questions), null where not written.",
        "responses": {
          "200": {
            "description": "Incident cases (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/cases.json"
                }
              }
            }
          }
        }
      }
    },
    "/contracts.json": {
      "get": {
        "operationId": "getContracts",
        "summary": "Contract clauses and licence families",
        "description": "The AI vendor-contract clauses to check (what each governs, the red flag, a fallback and the evidence to keep) and the model-licence families.",
        "responses": {
          "200": {
            "description": "Contract clauses and licence families (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/contracts.json"
                }
              }
            }
          }
        }
      }
    },
    "/roles.json": {
      "get": {
        "operationId": "getRoles",
        "summary": "Value-chain roles",
        "description": "Operator roles across regimes (EU AI Act, Colorado, Texas, Korea, ISO/IEC 22989), with duties, the nearest EU AI Act role and the events that make an actor a provider.",
        "responses": {
          "200": {
            "description": "Value-chain roles (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/roles.json"
                }
              }
            }
          }
        }
      }
    },
    "/threats.json": {
      "get": {
        "operationId": "getThreats",
        "summary": "Threat bridge",
        "description": "External AI threat ids (OWASP LLM 2026, OWASP Agentic 2026, MITRE ATLAS, NIST AI 100-2) mapped to the controlling patterns, example evals, obligation ids, ISO/IEC 42001 Annex A, CSA AICM domains, NIST SP 800-218A tasks and COSAiS use cases.",
        "responses": {
          "200": {
            "description": "Threat bridge (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/threats.json"
                }
              }
            }
          }
        }
      }
    },
    "/controls.json": {
      "get": {
        "operationId": "getControls",
        "summary": "Open control profiles",
        "description": "Open control profiles: draft control specifications for AI evaluation environments and agents at runtime, each reference control with its objective, failure modes, enforcement points, verification, evidence, mappings and sources. Illustrative, not a claim of conformity.",
        "responses": {
          "200": {
            "description": "Open control profiles (schema version 1).",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/controls.json"
                }
              }
            }
          }
        }
      }
    },
    "/obligations/{id}.json": {
      "get": {
        "operationId": "getObligation",
        "summary": "One obligation",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Obligation id in lower case, e.g. aige-obl-euaia-art9.",
            "schema": {
              "type": "string",
              "pattern": "^aige-obl-[a-z0-9]+(-[a-z0-9]+)+$"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The obligation with the shared envelope.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/obligation.json"
                }
              }
            }
          },
          "404": {
            "description": "No obligation has that id."
          }
        }
      }
    },
    "/controls/{id}.json": {
      "get": {
        "operationId": "getControl",
        "summary": "One reference control",
        "parameters": [
          {
            "name": "id",
            "in": "path",
            "required": true,
            "description": "Control id in lower case, e.g. aige-ctl-eval-002.",
            "schema": {
              "type": "string",
              "pattern": "^aige-ctl-[a-z0-9]+-[0-9]{3}$"
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The control with the shared envelope.",
            "content": {
              "application/json": {
                "schema": {
                  "$ref": "https://aigovernanceengineer.com/api/v1/schemas/control.json"
                }
              }
            }
          },
          "404": {
            "description": "No control has that id."
          }
        }
      }
    },
    "/schemas/{name}.json": {
      "get": {
        "operationId": "getSchema",
        "summary": "A JSON Schema (draft 2020-12)",
        "parameters": [
          {
            "name": "name",
            "in": "path",
            "required": true,
            "description": "Schema name: a dataset name, obligation, control or index.",
            "schema": {
              "type": "string",
              "enum": [
                "obligations",
                "frameworks",
                "crosswalk",
                "glossary",
                "patterns",
                "maturity",
                "path",
                "chapters",
                "jurisdictions",
                "harms",
                "cases",
                "contracts",
                "roles",
                "threats",
                "controls",
                "obligation",
                "control",
                "index"
              ]
            }
          }
        ],
        "responses": {
          "200": {
            "description": "The schema.",
            "content": {
              "application/schema+json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          }
        }
      }
    }
  }
}
