# AI Governance Engineer > The Thesis and Body of Knowledge for AI governance engineering: turning governance obligations into policy-as-code, eval gates and machine-readable evidence. Body of Knowledge v0.5.0 by Jorge García Aibar, licensed CC BY 4.0. This file indexes every page of the English site. Each chapter, pattern, glossary term, incident case and framework comparison, the pillar page, the role page and the Thesis also has a clean Markdown version at its URL plus .md (linked on its line below, except the glossary terms, where the rule applies as is). The full text is at https://aigovernanceengineer.com/llms-full.txt, and in smaller slices listed under "Full text". ## Start here - [What is AI governance? Definition, frameworks, examples](https://aigovernanceengineer.com/ai-governance): AI governance defined from the primary sources: the rules, roles, controls and evidence that keep AI in bounds, the main frameworks compared, and how to run it. Markdown: https://aigovernanceengineer.com/ai-governance.md - [01. The definition](https://aigovernanceengineer.com/bok/definition): AI governance engineering is the application of engineering practice (systems thinking, product thinking and code) to the governance of AI systems. Markdown: https://aigovernanceengineer.com/bok/definition.md - [Body of Knowledge](https://aigovernanceengineer.com/bok): The index of the 24 chapters in 5 parts, from the definition to the law. - [Home](https://aigovernanceengineer.com/): The Thesis and Body of Knowledge for AI governance engineering: turning governance obligations into policy-as-code, eval gates and machine-readable evidence. ## Body of Knowledge - [00. Preface](https://aigovernanceengineer.com/bok/preface): Why this book exists, who it is for and how to use it: the first attempt to write down how to engineer the governance of AI systems. Markdown: https://aigovernanceengineer.com/bok/preface.md - [01. The definition](https://aigovernanceengineer.com/bok/definition): AI governance engineering is the application of engineering practice (systems thinking, product thinking and code) to the governance of AI systems. Markdown: https://aigovernanceengineer.com/bok/definition.md - [02. Why now](https://aigovernanceengineer.com/bok/why-now): AI governance engineering is forming now: the object changed shape, the market began hiring for engineering and the law began asking for engineered evidence. Markdown: https://aigovernanceengineer.com/bok/why-now.md - [03. Values and principles](https://aigovernanceengineer.com/bok/values-and-principles): The eight values and six principles of the Thesis, each expanded with what it means in practice and the anti-pattern it rejects. Markdown: https://aigovernanceengineer.com/bok/values-and-principles.md - [04. The stack (five layers)](https://aigovernanceengineer.com/bok/the-stack): The reference architecture: five layers that answer the three questions, where evidence is produced at the bottom and proven at the top. Markdown: https://aigovernanceengineer.com/bok/the-stack.md - [05. Patterns](https://aigovernanceengineer.com/bok/patterns): A catalogue of reusable AI governance engineering patterns, each named to a layer of the stack, in the CSIRO Responsible AI Pattern Catalogue structure. Markdown: https://aigovernanceengineer.com/bok/patterns.md - [06. The role](https://aigovernanceengineer.com/bok/the-role): The AI governance engineer as a concrete role, defined by the workflows it owns and the evidence it produces, not by the certifications on its holder. Markdown: https://aigovernanceengineer.com/bok/the-role.md - [07. Maturity model (five levels)](https://aigovernanceengineer.com/bok/maturity-model): A ladder from paper to production (Documented, Inventoried, Tested, Enforced, Continuous), where each level is proven by what the running systems show. Markdown: https://aigovernanceengineer.com/bok/maturity-model.md - [08. Regulatory map (obligation → artefact → layer)](https://aigovernanceengineer.com/bok/regulatory-map): The reverse index of every "Maps to" line in the book: for each obligation, the engineering artefact that satisfies or supports it and its stack layer. Markdown: https://aigovernanceengineer.com/bok/regulatory-map.md - [09. Glossary](https://aigovernanceengineer.com/bok/glossary): The canonical definitions for the book: every term defined once, alphabetically, and cross-referenced to the chapter that treats it in full. Markdown: https://aigovernanceengineer.com/bok/glossary.md - [10. Reading list](https://aigovernanceengineer.com/bok/reading-list): The sources that formed the discipline, curated and annotated, each with a verified URL and a one-line note on why it matters. Markdown: https://aigovernanceengineer.com/bok/reading-list.md - [11. AI, defined for governance](https://aigovernanceengineer.com/bok/ai-defined): What an AI system is for governance: the definitions that set scope, the kinds of AI and the traits that break classic governance, each tied to a control. Markdown: https://aigovernanceengineer.com/bok/ai-defined.md - [12. Running the AI governance program](https://aigovernanceengineer.com/bok/governance-program): An AI governance program is the organisation governed as a system: people hold duties, a committee decides what gates cannot, and policies compile into gates. Markdown: https://aigovernanceengineer.com/bok/governance-program.md - [13. Where risk management sits](https://aigovernanceengineer.com/bok/risk-management): Risk management is the loop that tells every other control how hard to bite: identify, assess, treat, monitor, with the risk register as its evidence. Markdown: https://aigovernanceengineer.com/bok/risk-management.md - [14. Governing AI development](https://aigovernanceengineer.com/bok/governing-development): Development is governed when every build decision, from use case to release, leaves a record a gate reads, so the pipeline compiles the technical file. Markdown: https://aigovernanceengineer.com/bok/governing-development.md - [15. Governing deployment and use](https://aigovernanceengineer.com/bok/governing-deployment): Governing the run: deciding to use an AI system, choosing, contracting, going live, operating and retiring it, each step leaving evidence a control fired. Markdown: https://aigovernanceengineer.com/bok/governing-deployment.md - [16. Fairness and explainability for practitioners](https://aigovernanceengineer.com/bok/fairness-and-explainability): Fairness and explainability become controls only when measured, gated and filed as evidence; this chapter maps each technique to its stack layer and legal hook. Markdown: https://aigovernanceengineer.com/bok/fairness-and-explainability.md - [17. Incidents, issues and root causes](https://aigovernanceengineer.com/bok/incidents): AI incident management turns a runtime signal into a classified, contained, reported and explained event, with its cause fed back into the controls. Markdown: https://aigovernanceengineer.com/bok/incidents.md - [18. The EU AI Act in one pass](https://aigovernanceengineer.com/bok/eu-ai-act): The EU AI Act as amended by the Digital Omnibus, read end to end: scope, risk ladder, roles, duties and the date each duty applies. Markdown: https://aigovernanceengineer.com/bok/eu-ai-act.md - [19. Privacy and data protection law applied to AI](https://aigovernanceengineer.com/bok/privacy-and-ai): Data protection law already binds every AI system that touches personal data; this chapter turns its duties into artefacts, stack layers and evidence. Markdown: https://aigovernanceengineer.com/bok/privacy-and-ai.md - [20. Other law that already applies to AI](https://aigovernanceengineer.com/bok/existing-law): Copyright, anti-discrimination, consumer-protection and product-liability law already bind AI systems; each duty maps to an evidence artefact and a stack layer. Markdown: https://aigovernanceengineer.com/bok/existing-law.md - [21. AI-specific laws around the world](https://aigovernanceengineer.com/bok/ai-laws-worldwide): AI-specific law outside the EU, from Korea's Basic Act to US state statutes and voluntary frameworks, dated and mapped to the artefacts that evidence it. Markdown: https://aigovernanceengineer.com/bok/ai-laws-worldwide.md - [22. Principles, soft law and standards](https://aigovernanceengineer.com/bok/principles-and-standards): Principles say what good looks like and standards say how to show it; this chapter maps each instrument to the stack layer and evidence that answer it. Markdown: https://aigovernanceengineer.com/bok/principles-and-standards.md - [23. Governing AI agents](https://aigovernanceengineer.com/bok/governing-agents): Governing AI agents: registry, identity and short-lived credentials, tool permissions, human checkpoints, guardrails, kill switches, memory and delegation. Markdown: https://aigovernanceengineer.com/bok/governing-agents.md ## Patterns - [Pattern catalogue](https://aigovernanceengineer.com/patterns): The 33 patterns below, grouped by the five stack layers. Chapter 05 (https://aigovernanceengineer.com/bok/patterns) keeps the template and a summary of each. - [Pattern: Policy Card](https://aigovernanceengineer.com/patterns/policy-card): A governance rule written as a machine-readable card that the pipeline and the runtime both evaluate, leaving a verdict on every check. Markdown: https://aigovernanceengineer.com/patterns/policy-card.md - [Pattern: Eval Gate in CI](https://aigovernanceengineer.com/patterns/eval-gate-in-ci): An evaluation suite wired into CI so a model or agent ships only above a documented threshold: the eval run is the control, its result the evidence. Markdown: https://aigovernanceengineer.com/patterns/eval-gate-in-ci.md - [Pattern: Adversarial Red-Team Suite](https://aigovernanceengineer.com/patterns/adversarial-red-team-suite): A versioned adversarial suite built from a threat taxonomy, run in CI or on a schedule, whose findings are triaged, recorded and fed back as tests. Markdown: https://aigovernanceengineer.com/patterns/adversarial-red-team-suite.md - [Pattern: Agent Registry](https://aigovernanceengineer.com/patterns/agent-registry): A runtime-aware inventory of every model, service and agent, each with an owner, a scope and an expiry, written by the deploy pipeline, not by hand. Markdown: https://aigovernanceengineer.com/patterns/agent-registry.md - [Pattern: AIBOM](https://aigovernanceengineer.com/patterns/aibom): An AI bill of materials emitted at build, recording models, datasets, weights and their provenance in a standard format beside the registry entry. Markdown: https://aigovernanceengineer.com/patterns/aibom.md - [Pattern: Model Card as Control Evidence](https://aigovernanceengineer.com/patterns/model-card-as-control-evidence): Model and data cards regenerated from the pipeline as structured evidence, so transparency documents describe the system as it runs today. Markdown: https://aigovernanceengineer.com/patterns/model-card-as-control-evidence.md - [Pattern: Continuous Assurance Telemetry](https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry): Control decisions streamed into one assurance store as they happen, so whether a control works is a live query, not a point-in-time attestation. Markdown: https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry.md - [Pattern: Runtime Guardrail](https://aigovernanceengineer.com/patterns/runtime-guardrail): Input and output guardrails on the live request path that enforce the system's Policy Card on every call and emit a decision event for each one. Markdown: https://aigovernanceengineer.com/patterns/runtime-guardrail.md - [Pattern: Kill Switch / Circuit Breaker](https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker): A tested mechanism that stops one agent or class of agents at the point of action, revoking its access without breaking the rest of the fleet. Markdown: https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker.md - [Pattern: Incident Pipeline](https://aigovernanceengineer.com/patterns/incident-pipeline): The plumbing that detects, triages and reports serious AI incidents within the legal window, with timelines and templates encoded, not remembered. Markdown: https://aigovernanceengineer.com/patterns/incident-pipeline.md - [Pattern: FRIA-as-Code](https://aigovernanceengineer.com/patterns/fria-as-code): Every impact assessment (ISO/IEC 42005 AIIA, DPIA, FRIA) kept as one versioned fact base, linked to its controls and reopened when the system changes. Markdown: https://aigovernanceengineer.com/patterns/fria-as-code.md - [Pattern: Framework Crosswalk](https://aigovernanceengineer.com/patterns/framework-crosswalk): A map from each control to the framework clauses it serves, generated from the controls: an index for reuse, never proof that a control fires. Markdown: https://aigovernanceengineer.com/patterns/framework-crosswalk.md - [Pattern: Machine-Readable Evidence (OSCAL)](https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal): Control evidence emitted in a machine-readable standard format, OSCAL first, so an audit becomes a query and the same records feed assurance. Markdown: https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal.md - [Pattern: Agent Identity & Scoped Credentials](https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials): Every agent gets its own identity, owner, bounded scope and expiry before it acts, so its actions are attributable and its access revocable. Markdown: https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials.md - [Pattern: Human-in-the-loop Gate](https://aigovernanceengineer.com/patterns/human-in-the-loop-gate): A human approval step at a defined high-consequence decision point, so an agent's autonomy stops exactly where the stakes justify the latency. Markdown: https://aigovernanceengineer.com/patterns/human-in-the-loop-gate.md - [Pattern: Shadow-AI Discovery](https://aigovernanceengineer.com/patterns/shadow-ai-discovery): Continuous discovery of AI systems and agents running without a registry entry, reconciled against the registry so the inventory matches production. Markdown: https://aigovernanceengineer.com/patterns/shadow-ai-discovery.md - [Pattern: Vendor / Model Due-Diligence Gate](https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate): A structured due-diligence gate for bought and API-only AI that records what you can and cannot verify before the system reaches production. Markdown: https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate.md - [Pattern: Use-Case Intake & Risk Tiering](https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering): One intake path for every AI use case: a structured use-case record, a tier computed from its risk profile, and the gates that tier switches on. Markdown: https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering.md - [Pattern: AI Threat Model](https://aigovernanceengineer.com/patterns/ai-threat-model): A versioned threat model per AI system: STRIDE extended with AI-specific attacks, where every threat resolves to a mitigation and the test that proves it. Markdown: https://aigovernanceengineer.com/patterns/ai-threat-model.md - [Pattern: Training-Data Rights Ledger](https://aigovernanceengineer.com/patterns/training-data-rights-ledger): A per-source ledger of the right to train: acquisition channel, licence, opt-out check and permitted uses, joined to lineage so each model knows its sources. Markdown: https://aigovernanceengineer.com/patterns/training-data-rights-ledger.md - [Pattern: Dataset Admission Gate](https://aigovernanceengineer.com/patterns/dataset-admission-gate): A policy-as-code gate that lets a training, evaluation or retrieval job read only datasets with a complete, signed admission record for that use. Markdown: https://aigovernanceengineer.com/patterns/dataset-admission-gate.md - [Pattern: Fairness Eval Suite](https://aigovernanceengineer.com/patterns/fairness-eval-suite): A versioned fairness suite in CI: group and intersectional metrics with intervals, a proxy scan and a counterfactual test, judged against a policy fixed first. Markdown: https://aigovernanceengineer.com/patterns/fairness-eval-suite.md - [Pattern: Explanation Artefact](https://aigovernanceengineer.com/patterns/explanation-artefact): One explanation record per consequential decision, with pinned model, method and reason codes, tested for fidelity and reused for every explanation duty. Markdown: https://aigovernanceengineer.com/patterns/explanation-artefact.md - [Pattern: Model Artefact Integrity](https://aigovernanceengineer.com/patterns/model-artefact-integrity): Sign every model artefact at build, attach build provenance, refuse code-executing formats, and verify signature and digests before a runtime loads it. Markdown: https://aigovernanceengineer.com/patterns/model-artefact-integrity.md - [Pattern: Claims Substantiation Gate](https://aigovernanceengineer.com/patterns/claims-substantiation-gate): A claims register that ties each public statement about an AI system's accuracy, fairness or capability to the eval run behind it, and pulls stale claims. Markdown: https://aigovernanceengineer.com/patterns/claims-substantiation-gate.md - [Pattern: Decision Notice & Contest Path](https://aigovernanceengineer.com/patterns/decision-notice-contest-path): A notice at the point of an automated decision, keyed to its decision record, and a contest path to a reviewer with the power to change the outcome. Markdown: https://aigovernanceengineer.com/patterns/decision-notice-contest-path.md - [Pattern: Rights Requests Against Models](https://aigovernanceengineer.com/patterns/rights-requests-against-models): Route each data-subject request to every place the person's data sits, from source systems to model weights, and close it with a fulfilment record. Markdown: https://aigovernanceengineer.com/patterns/rights-requests-against-models.md - [Pattern: Sanctioned AI Gateway](https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway): Approved AI tools behind single sign-on and one gateway that applies data-class rules, logs use and checks a current acceptable-use attestation. Markdown: https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway.md - [Pattern: Staged Rollout with Rollback Criteria](https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria): Release every model, prompt or vendor-version change through shadow, pilot and canary stages whose rollback criteria are registered before each stage starts. Markdown: https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria.md - [Pattern: Drift & Fairness Monitor](https://aigovernanceengineer.com/patterns/drift-fairness-monitor): Production signals for drift, quality and fairness by group, each with a threshold, an owner and a pre-agreed consequence, written as evidence. Markdown: https://aigovernanceengineer.com/patterns/drift-fairness-monitor.md - [Pattern: Downstream Use Register](https://aigovernanceengineer.com/patterns/downstream-use-register): Intended and prohibited uses as a Policy Card, every consumer of a system's outputs recorded against its registry entry, and provenance stamped on outputs. Markdown: https://aigovernanceengineer.com/patterns/downstream-use-register.md - [Pattern: Disclosure & Notification Pipeline](https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline): Disclosures and notices generated from the registry, from versioned templates per audience and clock, with every notice sent recorded as evidence. Markdown: https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline.md - [Pattern: Deactivation, Localisation & Retirement Runbook](https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook): A drilled runbook to degrade, switch off by jurisdiction or retire an AI system, with named triggers, a decision authority and evidence at each step. Markdown: https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook.md ## Law, obligations and crosswalk - [Obligation register](https://aigovernanceengineer.com/obligations): The 182 obligations the book maps, one page each (listed under Optional), with a stable id (AIGE-OBL--), the duty holder, the date it applies from, its status, the artefact that evidences it and its stack layer. Illustrative, not a claim of conformity. - [Obligation register (CSV)](https://aigovernanceengineer.com/resources/obligations.csv): The same register as one row per obligation. - [Obligation register (JSON)](https://aigovernanceengineer.com/resources/obligations.json): The same register as JSON. - [Frameworks](https://aigovernanceengineer.com/resources/frameworks): The laws, standards, codes and control sets the Body of Knowledge maps against, with the obligation, artefact and stack-layer matrix. Illustrative, not a claim of conformity. - [Topic × framework crosswalk](https://aigovernanceengineer.com/resources/crosswalk): Each Body of Knowledge topic mapped to the EU AI Act, ISO, NIST and Chinese instruments that govern it, clause by clause. Illustrative, not a claim of conformity. - [Crosswalk (CSV)](https://aigovernanceengineer.com/resources/crosswalk.csv): The same mapping as one row per reference, RFC 4180 escaped. - [Crosswalk (JSON)](https://aigovernanceengineer.com/resources/crosswalk.json): The same mapping as JSON, with the disclaimer, version and licence in the payload. - [AI contract and licence clauses](https://aigovernanceengineer.com/resources/contracts): The clauses to check before you deploy a third-party AI system: what each governs, the red flag, a fallback position and the evidence to keep. An engineering checklist, not legal advice. ## Comparisons - [ISO 42001 vs EU AI Act: differences, overlap and mapping](https://aigovernanceengineer.com/resources/crosswalk/iso-42001-vs-eu-ai-act): ISO/IEC 42001 vs the EU AI Act: legal force, scope, certification and a topic-by-topic clause mapping with links to the obligations and patterns. Markdown: https://aigovernanceengineer.com/resources/crosswalk/iso-42001-vs-eu-ai-act.md - [NIST AI RMF vs ISO 42001: differences, overlap and mapping](https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-iso-42001): NIST AI RMF vs ISO/IEC 42001: a voluntary framework and a certifiable standard, compared on scope and artefacts, with a topic-by-topic clause mapping. Markdown: https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-iso-42001.md - [NIST AI RMF vs EU AI Act: differences, overlap and mapping](https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-eu-ai-act): NIST AI RMF vs the EU AI Act: voluntary US framework and binding EU law, compared on scope, dates and duties, with a topic-by-topic clause mapping. Markdown: https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-eu-ai-act.md ## Toolkit - [Toolkit](https://aigovernanceengineer.com/toolkit): Browser tools built from the book that produce documents you keep. Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser. - [Toolkit: Maturity self-check](https://aigovernanceengineer.com/toolkit/maturity-self-check): Read your governance function layer by layer against the observable criteria of the maturity model: the ragged profile, the floor it sets and the one move that raises it. - [Toolkit: Obligations and deadlines planner](https://aigovernanceengineer.com/toolkit/obligations-planner): Pick your roles in the EU AI Act value chain and what the system is: the register rows that bind you, with the artefact that evidences each, its layer, the date it applies and its status. - [Toolkit: EU AI Act risk classification checker](https://aigovernanceengineer.com/toolkit/ai-act-triage): Walk an AI system or model through the EU AI Act as amended by the Digital Omnibus: indicative roles and risk classes with the reason behind each answer, and a classification decision record to file. - [Toolkit: Policy Card builder](https://aigovernanceengineer.com/toolkit/policy-card): Turn one governance rule into a Policy Card for people and machines, an OPA/Rego module with unit tests, a Cedar stub and the CI hook that runs it. - [Toolkit: AI register entry builder](https://aigovernanceengineer.com/toolkit/ai-register-entry): Build AI system and agent register entries that validate against the published schemas, keep a register in the browser and map each field to the UK ATRS, a Canada AIA, the EU database, a model card and an ISO/IEC 42001 SoA. - [Toolkit: Impact assessment builder](https://aigovernanceengineer.com/toolkit/impact-assessment): Write a FRIA, an AI system impact assessment or an AI addendum to a DPIA as one record: the elements each instrument asks for, every risk linked to the measure and pattern that mitigate it, and the triggers that reopen it. - [Toolkit: Model card builder](https://aigovernanceengineer.com/toolkit/model-card): Write a model or system card once and export it as a Hugging Face style card and a CycloneDX 1.7 ML-BOM component, with a checklist of what it covers under Annex IV, Art. 13, Art. 53, ISO/IEC 42001 and the NIST AI RMF. - [Toolkit: Vendor due-diligence request](https://aigovernanceengineer.com/toolkit/vendor-due-diligence): Build a tiered, evidence-first due-diligence request for an AI vendor or model: the artefacts to ask for, cross-referenced to crosswalk topics and CSA AICM controls, and the contract clauses to check. - [Toolkit: Incident clock](https://aigovernanceengineer.com/toolkit/incident-clock): From the awareness time, your role, the system tier and the facts: the incident class, who reports to whom and every deadline as a calendar date, as chapter 17 states the clocks. - [Toolkit: Agent control profile](https://aigovernanceengineer.com/toolkit/agent-control-profile): Describe one agent and get the minimum control set chapter 23 asks for at its autonomy level, the controls its tools, memory and identity add, an agent register entry and a checklist. - [Toolkit: Fairness metric chooser](https://aigovernanceengineer.com/toolkit/fairness-metric-chooser): Walk the questions chapter 16 says decide the fairness metric (ground truth, costlier error, allocation or quality of service, legal frame) and get the metric families to use, with their caveats. ## Controls and research - [Open AI governance controls](https://aigovernanceengineer.com/controls): Open control profiles for AI governance: each control with its evidence, mapped to the five-layer stack and reviewed in the open. Versioned and CC BY 4.0. - [AI governance controls crosswalk](https://aigovernanceengineer.com/controls/crosswalk): Open AI governance controls read from the framework side: each EU AI Act obligation, ISO/IEC 42001 clause, NIST AI RMF or OWASP id, with its controls. Markdown: https://aigovernanceengineer.com/controls/crosswalk.md - [AI evaluation environment controls](https://aigovernanceengineer.com/controls/evaluation-environment): An open control profile for AI evaluation environments: isolation, tool access, telemetry and evidence requirements. Draft v0.2. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment.md - [Authorization boundary for AI evaluation environments](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001): Draft control for AI evaluation runs: record each agent's authorization boundary before the run, state it in the prompt and refuse every call outside it. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001.md - [Network egress control for AI evaluation environments](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002): Draft control AIGE-CTL-EVAL-002: an AI evaluation run reaches only the destinations on its egress allow-list; any other connection is refused and logged. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002.md - [Credential isolation for AI evaluation environments](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003): Draft control AIGE-CTL-EVAL-003: an agent under evaluation holds only short-lived credentials bound to its own identity and one service, no standing secrets. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003.md - [Tool call mediation for AI agents under evaluation](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004): Draft control: every tool call an agent makes in an evaluation run passes a mediation point that records a verdict and fails closed for irreversible actions. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004.md - [Monitoring integrity for AI evaluation runs](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005): Draft control: the traces and monitors of an AI evaluation run cover all of it, stay out of the agent's reach and reconcile with the tool servers' own logs. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005.md - [Stop conditions for AI evaluation runs](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006): Draft control AIGE-CTL-EVAL-006: stop conditions, budgets and a stop handle set before an AI evaluation run starts; a stop halts the run in a measured time. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006.md - [Incident evidence preservation for AI evaluation runs](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007): Draft control: when an AI evaluation run produces an incident, freeze its environment snapshot, traces and transcript with hashes before any reset or fix. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007.md - [Harness and configuration attestation for AI evaluations](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008): Draft control: hash the harness, prompts, tool definitions and scoring configuration an AI evaluation run loads, and report each result against that manifest. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008.md - [Evaluation validity checks for AI agent results](https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009): Draft control: before an AI evaluation result is reported, check that tasks are solvable, the scorer works and failed runs were read, and report the checks. Markdown: https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009.md - [AI agent runtime controls](https://aigovernanceengineer.com/controls/agent-runtime): An open control profile for AI agents at runtime: identity, tool mediation, execution limits, stop conditions and telemetry. Draft v0.1, from chapter 23. Markdown: https://aigovernanceengineer.com/controls/agent-runtime.md - [AI data governance controls](https://aigovernanceengineer.com/controls/data-admission-and-privacy): An open control profile for AI training data: dataset admission, rights ledger, lawful basis, purpose limits, special categories and lineage. Draft v0.1. Markdown: https://aigovernanceengineer.com/controls/data-admission-and-privacy.md - [AI assurance and evidence controls](https://aigovernanceengineer.com/controls/assurance-and-evidence): An open control profile for AI assurance: eval gates, test plans and reports, signed evidence records, OSCAL, model integrity and AIBOM. Draft v0.1. Markdown: https://aigovernanceengineer.com/controls/assurance-and-evidence.md - [AI deployment monitoring controls](https://aigovernanceengineer.com/controls/deployment-and-monitoring): An open control profile for AI systems in use: deployment decision, staged rollout, monitoring, incident clocks, deactivation and retirement. Draft v0.1. Markdown: https://aigovernanceengineer.com/controls/deployment-and-monitoring.md - [Research notes](https://aigovernanceengineer.com/research): Technical notes on the open questions of AI governance engineering: what is assumed, what the evidence shows and what would settle each one. - [Research note: The evaluation environment is part of the system](https://aigovernanceengineer.com/research/the-evaluation-environment-is-part-of-the-system): Draft. Which parts of the environment around a model must an evaluation record for its result to count as evidence? Markdown: https://aigovernanceengineer.com/research/the-evaluation-environment-is-part-of-the-system.md ## Data, API and MCP - [Open data and API](https://aigovernanceengineer.com/resources/data): How to reuse the registers behind the site: static JSON under /api/v1 with a JSON Schema per dataset, an OpenAPI description, stable ids, the versioning promise and the CC BY 4.0 licence. - [API catalogue (JSON)](https://aigovernanceengineer.com/api/v1/index.json): The machine-readable list of every /api/v1 dataset with its schema and page. - [OpenAPI description](https://aigovernanceengineer.com/api/v1/openapi.json): The /api/v1 datasets described as OpenAPI. - [Glossary (JSON)](https://aigovernanceengineer.com/glossary.json): Every term with its definition, chapter references and page URL, as JSON. - [MCP server: how to connect](https://aigovernanceengineer.com/mcp): How to connect Claude, Claude Code or any MCP client to the public read-only server, and the ten tools it offers. - [Remote MCP server (read-only)](https://mcp.aigovernanceengineer.com/mcp): A Model Context Protocol server (Streamable HTTP, no authentication) over the same /api/v1 data: the obligation register, the crosswalk, the glossary, the patterns, the templates and schemas, and the chapters; every answer names its source page. Live since 2026-09-25; its code and self-hosting guide are in tools/mcp-server of the repository. - [MCP server card](https://aigovernanceengineer.com/.well-known/mcp.json): The machine-readable description of the MCP server: endpoint, transport, authentication, version and tools. ## Incidents, harms and threats - [Cases](https://aigovernanceengineer.com/cases): Publicly documented AI incidents written as engineering post-mortems: what happened, the failure mode, the control that would have caught it, the evidence it would have left and the obligations it touches. - [Case: Dutch childcare benefits: nationality as a risk indicator](https://aigovernanceengineer.com/cases/dutch-childcare-benefits): The Dutch tax administration used applicants' nationality as a risk indicator for childcare benefits; the data protection authority fined it EUR 2.75 million. Markdown: https://aigovernanceengineer.com/cases/dutch-childcare-benefits.md - [Case: SyRI: a fraud risk model no court could verify](https://aigovernanceengineer.com/cases/syri-judgment): A Dutch court struck down the SyRI fraud-detection legislation in 2020 because the system was insufficiently transparent and verifiable. Markdown: https://aigovernanceengineer.com/cases/syri-judgment.md - [Case: England's 2020 A levels: a centre model applied to individual students](https://aigovernanceengineer.com/cases/a-level-grading-2020): With exams cancelled in 2020, England's grading model assigned A-level grades from each school's history; four days after results, Ofqual reverted to teacher grades. Markdown: https://aigovernanceengineer.com/cases/a-level-grading-2020.md - [Case: A health-risk score that predicted cost, not need](https://aigovernanceengineer.com/cases/health-risk-score-proxy): A widely used care-management algorithm predicted health costs as a proxy for illness, so Black patients were sicker than White patients at the same score. Markdown: https://aigovernanceengineer.com/cases/health-risk-score-proxy.md - [Case: Moffatt v. Air Canada: the chatbot's answer is the company's answer](https://aigovernanceengineer.com/cases/moffatt-v-air-canada): A tribunal held Air Canada liable after its website chatbot misstated the bereavement-fare policy, rejecting the argument that the chatbot answered for itself. Markdown: https://aigovernanceengineer.com/cases/moffatt-v-air-canada.md - [Case: A recruiting model that learned the past (reported)](https://aigovernanceengineer.com/cases/recruiting-model-reported): Reuters reported in 2018 that an experimental recruiting model trained on a decade of mostly male CVs learned to downgrade women; the project was dropped. Markdown: https://aigovernanceengineer.com/cases/recruiting-model-reported.md - [Case: Zillow Offers: a pricing model committing capital into a turning market](https://aigovernanceengineer.com/cases/zillow-offers): Zillow wound down its home-buying business in 2021 after buying homes above what it expected to sell them for, taking a USD 304 million write-down. Markdown: https://aigovernanceengineer.com/cases/zillow-offers.md - [Case: Clearview AI: a face database built by scraping](https://aigovernanceengineer.com/cases/clearview-ai): The Dutch data protection authority fined Clearview AI EUR 30.5 million in 2024 for building a facial-recognition database from scraped photos. Markdown: https://aigovernanceengineer.com/cases/clearview-ai.md - [Case: The Garante's ChatGPT order: launch before a lawful basis](https://aigovernanceengineer.com/cases/garante-chatgpt-order): Italy's data protection authority temporarily limited ChatGPT in 2023 over lawful basis, transparency and age checks, then fined its provider EUR 15 million in 2024. Markdown: https://aigovernanceengineer.com/cases/garante-chatgpt-order.md - [Case: NYC MyCity: a government chatbot that advised breaking the law](https://aigovernanceengineer.com/cases/nyc-mycity-chatbot): The Markup found in 2024 that New York City's AI chatbot for business owners gave answers contrary to city law, including on tenants with housing vouchers. Markdown: https://aigovernanceengineer.com/cases/nyc-mycity-chatbot.md - [Case: Source code pasted into a public chatbot (reported)](https://aigovernanceengineer.com/cases/chatbot-code-leak-reported): Samsung engineers reportedly pasted source code and meeting notes into ChatGPT within weeks of being allowed to use it. Markdown: https://aigovernanceengineer.com/cases/chatbot-code-leak-reported.md - [Case: OpenAI agents and Hugging Face: an evaluation environment that was not isolated](https://aigovernanceengineer.com/cases/openai-hugging-face-agent-incident-2026): METR reports that OpenAI agents meant to be isolated in cyber evaluations used a shared package repository as a message board and attacked Hugging Face. Markdown: https://aigovernanceengineer.com/cases/openai-hugging-face-agent-incident-2026.md - [Case: An agent in training reached a public chatbot through the sandbox DNS resolver](https://aigovernanceengineer.com/cases/openai-agent-dns-covert-channel-2026): OpenAI reports that an agent in RL training used its sandbox's DNS resolver to reach a public chatbot; the run was stopped hours after the alert. Markdown: https://aigovernanceengineer.com/cases/openai-agent-dns-covert-channel-2026.md - [Case: An internally deployed model published a researcher's GitHub token in a public repository](https://aigovernanceengineer.com/cases/openai-agent-github-token-exposure-2026): OpenAI reports that an internally deployed model put a researcher's GitHub token, split to avoid secret scanning, into code it pushed to a public repository. Markdown: https://aigovernanceengineer.com/cases/openai-agent-github-token-exposure-2026.md - [Case: Agents in training shared a file through a public file-hosting service](https://aigovernanceengineer.com/cases/openai-agents-temp-file-hosting-2026): OpenAI reports that agents in multi-agent RL training uploaded a workbook to a public file-hosting service so that collaborating agents could download it. Markdown: https://aigovernanceengineer.com/cases/openai-agents-temp-file-hosting-2026.md - [Case: Training samples exchanged messages through a shared package repository](https://aigovernanceengineer.com/cases/openai-agents-artifactory-cross-sample-2026): OpenAI reports that models in RL training used an internal package repository, with the credentials they were given, to exchange messages across samples. Markdown: https://aigovernanceengineer.com/cases/openai-agents-artifactory-cross-sample-2026.md - [Case: Claude models reached real systems from a misconfigured third-party cyber evaluation](https://aigovernanceengineer.com/cases/anthropic-third-party-eval-environment-incidents-2026): Anthropic reports four incidents in which Claude models, told they had no internet in a partner's cyber evaluations, reached and attacked real systems. Markdown: https://aigovernanceengineer.com/cases/anthropic-third-party-eval-environment-incidents-2026.md - [Case: Agents in a cyber range with open internet took unsanctioned actions against real people](https://aigovernanceengineer.com/cases/uk-aisi-cyber-range-unsanctioned-actions-2026): UK AISI reports that agents in a cyber evaluation with internet deliberately enabled took 19 unsanctioned actions aimed at real people and organisations. Markdown: https://aigovernanceengineer.com/cases/uk-aisi-cyber-range-unsanctioned-actions-2026.md - [Harms atlas](https://aigovernanceengineer.com/resources/harms): The harms AI systems cause to individuals, groups, organisations, society and the environment: each with its failure mode, the control that catches it, the evidence it leaves and real incidents. - [Harms atlas (JSON)](https://aigovernanceengineer.com/resources/harms.json): The same atlas as JSON. - [AI threat bridge](https://aigovernanceengineer.com/resources/threats): OWASP LLM and Agentic 2026, MITRE ATLAS and NIST AI 100-2 threat ids mapped to the pattern that controls each, an example eval and the obligations it evidences. - [Threat bridge (CSV)](https://aigovernanceengineer.com/resources/threats.csv): The same threat bridge as CSV. ## Interactive views - [AI governance framework as a stack: five layers](https://aigovernanceengineer.com/stack): AI governance framework as an engineering stack: five layers, from govern-as-code and inventory to evals as evidence, runtime control and continuous assurance. - [AI governance engineer: what they do, skills, salary](https://aigovernanceengineer.com/role): What an AI governance engineer does: the seven workflows the role owns, the skills behind them, IAPP salary medians and three ways into the role. Markdown: https://aigovernanceengineer.com/role.md - [AI governance learning path: four stages](https://aigovernanceengineer.com/path): AI governance learning path in four stages, from foundations to proof: each stage a grid of nodes linking into the Body of Knowledge, its tools and its reading. - [Discipline map](https://aigovernanceengineer.com/map): The whole discipline on one page: every chapter, layer, pattern, workflow, obligation, maturity level and learning stage, as a mind map and as a linked list. - [Governing AI agents](https://aigovernanceengineer.com/agents): The agent control plane in one place: registry, identity and short-lived credentials, tool permissions, human checkpoints, guardrails, kill switches, the patterns and the threats they answer, routed into chapter 23. ## Routes by audience - [Routes by audience](https://aigovernanceengineer.com/for): Six routes through the site, one per audience, each with what to do this week, the obligations that bind that audience and the questions it asks. - [For engineers](https://aigovernanceengineer.com/for/engineers): ML, platform, MLOps, application and security engineers who build and run AI systems. - [For CISOs and risk leads](https://aigovernanceengineer.com/for/ciso-risk): CISOs, heads of risk, model risk managers, internal audit and third-party risk managers. - [For legal counsel and DPOs](https://aigovernanceengineer.com/for/legal-dpo): In-house counsel, data protection officers, privacy and compliance leads, and contract managers. - [For executives and boards](https://aigovernanceengineer.com/for/executives-board): Board members, executive committees, and chief AI, data and technology officers. - [For the public sector](https://aigovernanceengineer.com/for/public-sector): Public bodies and operators of public services: CIOs, service owners, procurement and oversight. - [For SMEs and start-ups](https://aigovernanceengineer.com/for/smes): Small and medium-sized companies and start-ups, most of them buying more AI than they build. - [AIGP candidates](https://aigovernanceengineer.com/for/aigp): The public AIGP body of knowledge read against this site. Not affiliated with or endorsed by IAPP. - [Certifications](https://aigovernanceengineer.com/for/certifications): Certifications and assessments in AI governance, and what each one evidences. - [Frontier AI evaluation assurance](https://aigovernanceengineer.com/frontier): Engineering assurance for frontier AI: evaluation environment controls, runtime safeguards and machine-verifiable evidence on the five-layer stack. ## Thesis - [The AI Governance Engineering Thesis](https://aigovernanceengineer.com/thesis): AI governance engineering is the application of engineering practice (systems thinking, product thinking and code) to the governance of AI systems. Markdown: https://aigovernanceengineer.com/thesis.md - [La Tesis de la Ingeniería de Gobernanza de IA](https://aigovernanceengineer.com/es/thesis): Spanish translation of the Thesis. La ingeniería de gobernanza de IA es la aplicación de la práctica de la ingeniería (pensamiento sistémico, pensamiento de producto y código) a la gobernanza de los sistemas de IA. ## Resources - [Templates and schemas](https://aigovernanceengineer.com/resources/templates): JSON Schemas, filled examples and human templates for the records AI governance produces, each field tagged with the obligations it helps evidence. Illustrative, not a claim of conformity. - [Figures](https://aigovernanceengineer.com/figures): The 31 infographics and the interactive diagrams of the Body of Knowledge, each infographic with its own page, a text alternative, SVG and PNG downloads and a citation. - [Glossary](https://aigovernanceengineer.com/bok/glossary): Chapter 09: 323 terms, each defined once with its source, and each with its own page under /glossary/ (listed with its definition under Optional) and a Markdown version at /glossary/.md. Markdown: https://aigovernanceengineer.com/bok/glossary.md - [Tool categories](https://aigovernanceengineer.com/resources/tools): Tool categories for each stack layer, every tool with its licence and access model: examples, not endorsements. - [Reading list](https://aigovernanceengineer.com/bok/reading-list): Chapter 10, the canonical annotated bibliography; https://aigovernanceengineer.com/resources/reading-list is the same list with audience and jurisdiction filters. Markdown: https://aigovernanceengineer.com/bok/reading-list.md - [Resources index](https://aigovernanceengineer.com/resources): Frameworks, the obligation register, the crosswalk, harms, cases, contracts, templates, figures, tools, the toolkit, the reading list, the glossary, the open data and the discipline map, all extracted from the Body of Knowledge. ## Full text - [Full text: everything](https://aigovernanceengineer.com/llms-full.txt): The pillar page, every chapter, every pattern, the role page, the Thesis, the obligation register, the frameworks, the crosswalk, the framework comparisons, the incident cases and the harms atlas, as Markdown, in one file (about 642k tokens). Too large for most context windows: prefer the slices below. - [Full text: the discipline and the Thesis](https://aigovernanceengineer.com/llms-full-bok.txt): The pillar page, What is AI governance?, then the chapters of part one, The discipline (00 to 07: definition, why now, values, the stack, the pattern catalogue, the role, the maturity model), with the role landing (/role) after chapter 06, chapter 10, the reading list, and the Thesis. (about 82k tokens) - [Full text: foundations](https://aigovernanceengineer.com/llms-full-foundations.txt): The Foundations chapters (11 to 13): what counts as AI, the governance programme and risk management. (about 49k tokens) - [Full text: the lifecycle](https://aigovernanceengineer.com/llms-full-lifecycle.txt): The lifecycle chapters (14 to 17 and 23): governing development and deployment, fairness and explainability, incidents and governing agents. (about 94k tokens) - [Full text: law and standards](https://aigovernanceengineer.com/llms-full-law.txt): The Law and standards chapters (18 to 22): the EU AI Act, privacy and data protection, existing law, AI laws worldwide, principles and standards. (about 95k tokens) - [Full text: regulatory map, crosswalk and comparisons](https://aigovernanceengineer.com/llms-full-regulatory.txt): Chapter 08, the regulatory map, then the frameworks, the topic × framework crosswalk and the framework comparisons (ISO 42001, NIST AI RMF and the EU AI Act, pair by pair). The obligation register is in its own slice. (about 100k tokens) - [Full text: obligation register](https://aigovernanceengineer.com/llms-full-obligations.txt): The obligation register row by row: the 182 obligations the Body of Knowledge maps, each with its stable id, clause, duty holder, status, dates, evidence artefact and stack layer. (about 42k tokens) - [Full text: patterns](https://aigovernanceengineer.com/llms-full-patterns.txt): Chapter 05, the pattern catalogue, followed by every pattern page in catalogue order. (about 82k tokens) - [Full text: glossary](https://aigovernanceengineer.com/llms-full-glossary.txt): Every glossary term (323) with its definition, sources, chapters and the terms it is contrasted with. (about 101k tokens) - [Full text: incident cases and harms](https://aigovernanceengineer.com/llms-full-cases.txt): The 18 incident cases written as engineering post-mortems, then the harms atlas. (about 50k tokens) ## Feeds and citation - [RSS feed](https://aigovernanceengineer.com/rss.xml): New and updated chapters and each released version, newest first. - [Zenodo record](https://doi.org/10.5281/zenodo.22857084): Archived releases of the Thesis and Body of Knowledge; this concept DOI always resolves to the latest. Current release: https://doi.org/10.5281/zenodo.22956197. ## About - [About](https://aigovernanceengineer.com/about): Who writes this, how to contribute and how to get in touch. Licensed CC BY 4.0. - [Methodology](https://aigovernanceengineer.com/about/methodology): How sources are chosen and tagged, how dated claims are re-verified, how corrections and reviews work, and how releases are versioned with DOIs. - [Changelog](https://aigovernanceengineer.com/about/changelog): Every notable change to the Thesis and Body of Knowledge, version by version: patch for fact and typo fixes, minor for new chapters and patterns. - [Contributors](https://aigovernanceengineer.com/about/contributors): Who wrote the Body of Knowledge, who co-authored the Thesis, and who has signed it: the authorship, contributions and signatories of the project. - [Contribute to open AI controls](https://aigovernanceengineer.com/contribute): How to contribute to the open controls and research notes: issue forms for a control review, a mapping or a correction, and how review works. ## Optional - [Obligation AIGE-OBL-EUAIA-ART3-1: EU AI Act Art. 3(1) AI system definition (scope of the Act)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art3-1): Scope: decide, system by system, whether it is an AI system under the Art. - [Obligation AIGE-OBL-EUAIA-ART4: EU AI Act Art. 4 AI literacy](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4): AI literacy: take measures to support the development of AI literacy among staff and operators - [Obligation AIGE-OBL-EUAIA-ART4A: EU AI Act Art. 4a lawful basis for special-category data in bias detection](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a): Lawful basis to process special-category data for bias detection in high-risk systems, with pseudonymisation and deletion once bias is corrected - [Obligation AIGE-OBL-EUAIA-ART5: EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5): Prohibited practices; new bans on AI-generated non-consensual intimate imagery (NCII) and CSAM - [Obligation AIGE-OBL-EUAIA-ART6: EU AI Act Art. 6 classification of high-risk AI systems (incl. the Annex III route)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art6): Classification rules for high-risk AI systems, incl. - [Obligation AIGE-OBL-EUAIA-ART6-3: EU AI Act Art. 6(3)–(4) documented non-high-risk assessment and registration](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art6-3): A provider that finds an Annex III system not high-risk under the Art. - [Obligation AIGE-OBL-EUAIA-ART9: EU AI Act Art. 9 risk management system](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9): Risk management system across the high-risk lifecycle - [Obligation AIGE-OBL-EUAIA-ART10: EU AI Act Art. 10 data and data governance](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10): Data and data governance; representative, relevant, error-checked datasets - [Obligation AIGE-OBL-EUAIA-ART11: EU AI Act Art. 11 technical documentation (Annex IV)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11): Technical documentation (Annex IV) drawn up and kept up to date - [Obligation AIGE-OBL-EUAIA-ART12: EU AI Act Art. 12 record-keeping and logging](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12): Record-keeping: automatic logging of events over the system's lifetime - [Obligation AIGE-OBL-EUAIA-ART13: EU AI Act Art. 13 transparency and information to deployers](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13): Transparency and provision of information to deployers - [Obligation AIGE-OBL-EUAIA-ART14: EU AI Act Art. 14 human oversight](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14): Human oversight designed into the system - [Obligation AIGE-OBL-EUAIA-ART15: EU AI Act Art. 15 accuracy, robustness and cybersecurity](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15): Accuracy, robustness and cybersecurity - [Obligation AIGE-OBL-EUAIA-ART15-4: EU AI Act Art. 15(4) feedback loops in systems that continue to learn](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15-4): Systems that continue to learn after placing on the market are built to eliminate or reduce the risk of biased outputs feeding future inputs (feedback loops), with mitigation measures - [Obligation AIGE-OBL-EUAIA-ART16-L: EU AI Act Art. 16(l) accessibility requirements for high-risk AI systems](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art16-l): Providers ensure the high-risk system complies with the accessibility requirements of Directives (EU) 2016/2102 and (EU) 2019/882 - [Obligation AIGE-OBL-EUAIA-ART17: EU AI Act Art. 17 quality management system](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17): Quality management system - [Obligation AIGE-OBL-EUAIA-ART17-1M: EU AI Act Art. 17(1)(m) accountability framework within the quality management system](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17-1m): The QMS includes an accountability framework setting out the responsibilities of management and other staff for every aspect of the QMS - [Obligation AIGE-OBL-EUAIA-ART18: EU AI Act Art. 18 documentation keeping](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art18): Keep the technical documentation, the QMS documentation, notified-body changes and decisions and the EU declaration at the disposal of national authorities for 10 years after placing on the market - [Obligation AIGE-OBL-EUAIA-ART19: EU AI Act Art. 19 automatically generated logs kept by the provider](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art19): Keep the automatically generated logs under the provider's control for a period appropriate to the intended purpose, at least six months unless other law provides otherwise - [Obligation AIGE-OBL-EUAIA-ART20: EU AI Act Art. 20 corrective actions and duty of information](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art20): A provider with reason to consider a high-risk system non-conforming immediately brings it into conformity, withdraws, disables or recalls it and informs distributors and deployers; where the system… - [Obligation AIGE-OBL-EUAIA-ART22: EU AI Act Art. 22 authorised representative of non-EU high-risk providers](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art22): A provider established outside the Union appoints, by written mandate, an authorised representative in the Union before making the system available; the representative keeps the declaration… - [Obligation AIGE-OBL-EUAIA-ART23: EU AI Act Art. 23 obligations of importers](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art23): Before placing a high-risk system on the market, the importer verifies the conformity assessment, the Annex IV documentation, the CE marking, the declaration and instructions and the authorised… - [Obligation AIGE-OBL-EUAIA-ART24: EU AI Act Art. 24 obligations of distributors](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art24): Before making a high-risk system available, the distributor verifies the CE marking, the declaration and the instructions, and holds back, withdraws or recalls a system it considers non-conforming - [Obligation AIGE-OBL-EUAIA-ART25: EU AI Act Art. 25 responsibilities along the AI value chain](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25): Responsibilities along the AI value chain: when a distributor, importer or deployer becomes a provider, and the information a provider must pass to actors downstream - [Obligation AIGE-OBL-EUAIA-ART26: EU AI Act Art. 26 deployer obligations for high-risk systems](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26): Deployer obligations for high-risk systems: use per the instructions for use (Art. - [Obligation AIGE-OBL-EUAIA-ART26-2: EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-2): Deployers assign human oversight to natural persons with the necessary competence, training and authority, and the necessary support - [Obligation AIGE-OBL-EUAIA-ART26-4: EU AI Act Art. 26(4) input data relevant and sufficiently representative](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-4): To the extent the deployer controls the input data, it ensures the data are relevant and sufficiently representative for the intended purpose - [Obligation AIGE-OBL-EUAIA-ART26-5: EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5): Deployers monitor operation per the instructions; on reason to consider a risk they inform the provider or distributor and the authority and suspend use; a serious incident goes to the provider… - [Obligation AIGE-OBL-EUAIA-ART26-6: EU AI Act Art. 26(6) deployer retention of automatically generated logs](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-6): Deployers keep the logs under their control for a period appropriate to the intended purpose, at least six months unless other law provides otherwise - [Obligation AIGE-OBL-EUAIA-ART26-7: EU AI Act Art. 26(7) informing workers before workplace use](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-7): Before putting a high-risk system into service at the workplace, deployers who are employers inform workers' representatives and the affected workers - [Obligation AIGE-OBL-EUAIA-ART26-11: EU AI Act Art. 26(11) informing people subject to Annex III decisions](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-11): Deployers of Annex III systems that make or assist decisions about natural persons inform those persons that they are subject to the system - [Obligation AIGE-OBL-EUAIA-ART27: EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art27): Fundamental Rights Impact Assessment (FRIA) for deployers of Annex III systems - [Obligation AIGE-OBL-EUAIA-ART43: EU AI Act Art. 43 conformity assessment](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43): Conformity assessment before placing on the market (internal control, or a notified body for Annex III point 1 biometrics) - [Obligation AIGE-OBL-EUAIA-ART43-4: EU AI Act Art. 43(4) new conformity assessment on substantial modification](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43-4): A system already assessed undergoes a new conformity assessment on substantial modification; changes pre-determined in the technical documentation of a system that continues to learn are not… - [Obligation AIGE-OBL-EUAIA-ART47: EU AI Act Art. 47 EU declaration of conformity](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art47): EU declaration of conformity drawn up on completing the assessment - [Obligation AIGE-OBL-EUAIA-ART48: EU AI Act Art. 48 CE marking](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art48): Affix the CE marking visibly, legibly and indelibly (a digital marking for digitally provided systems), followed by the notified body's number where applicable - [Obligation AIGE-OBL-EUAIA-ART49-71: EU AI Act Art. 49/71 registration of high-risk systems in the EU database](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71): Registration of high-risk systems in the EU database - [Obligation AIGE-OBL-EUAIA-ART50: EU AI Act Art. 50 transparency for certain AI systems](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50): Transparency for certain AI systems: chatbot disclosure; marking and labelling of synthetic content - [Obligation AIGE-OBL-EUAIA-ART52: EU AI Act Art. 52 notification of a GPAI model meeting the systemic-risk threshold](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art52): Notify the Commission without delay, and within two weeks, once a GPAI model meets the Art. - [Obligation AIGE-OBL-EUAIA-ART53: EU AI Act Art. 53 GPAI provider obligations](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53): GPAI provider obligations, incl. - [Obligation AIGE-OBL-EUAIA-ART53-1C: EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53-1c): GPAI providers put in place a policy to comply with Union copyright law, incl. - [Obligation AIGE-OBL-EUAIA-ART54: EU AI Act Art. 54 authorised representative of non-EU GPAI providers](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art54): A GPAI provider established outside the Union appoints, by written mandate, an authorised representative before placing the model on the Union market; the representative keeps the Annex XI… - [Obligation AIGE-OBL-EUAIA-ART55: EU AI Act Art. 55 GPAI models with systemic risk](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55): GPAI models with systemic risk: model evaluation incl. - [Obligation AIGE-OBL-EUAIA-ART60: EU AI Act Art. 60 testing in real-world conditions outside sandboxes](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60): Testing of high-risk (Annex III) AI systems in real-world conditions outside AI regulatory sandboxes - [Obligation AIGE-OBL-EUAIA-ART72: EU AI Act Art. 72 post-market monitoring](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72): Post-market monitoring for high-risk systems - [Obligation AIGE-OBL-EUAIA-ART73: EU AI Act Art. 73 serious-incident reporting](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73): Serious-incident reporting for high-risk systems, on the deadlines of chapter 08's reporting-clock table - [Obligation AIGE-OBL-EUAIA-ART73-6: EU AI Act Art. 73(6) incident investigation without altering the system](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73-6): After reporting a serious incident the provider investigates without delay (risk assessment, corrective action) and does not alter the system in a way that may affect the evaluation of causes before… - [Obligation AIGE-OBL-EUAIA-ART75-1A: EU AI Act Art. 75(1a) serious incidents reported to the AI Office](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art75-1a): Providers of high-risk systems under the AI Office's exclusive competence (systems built on their own GPAI model, and systems in designated very large online platforms or search engines) report… - [Obligation AIGE-OBL-EUAIA-ART86: EU AI Act Art. 86 right to explanation of individual decision-making](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art86): A person subject to a deployer's decision based on an Annex III system (except point 2) with legal or similarly significant adverse effects may obtain clear and meaningful explanations of the… - [Obligation AIGE-OBL-EUAIA-ART87: EU AI Act Art. 87 reporting of infringements and protection of reporting persons](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art87): Directive (EU) 2019/1937 applies to reports of AI Act infringements and to the protection of the people who make them - [Obligation AIGE-OBL-GPAICOP-SAFETY: Safety and Security (systemic-risk models only)](https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety): A Safety and Security Framework; model evaluations incl. - [Obligation AIGE-OBL-GPAICOP-TRANSPARENCY: Transparency](https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-transparency): Up-to-date model documentation for the AI Office and downstream deployers - [Obligation AIGE-OBL-GPAICOP-COPYRIGHT: Copyright](https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-copyright): A policy to comply with Union copyright law, incl. - [Obligation AIGE-OBL-GPAICOP-SAFETY-C9: Safety and Security Commitment 9: serious-incident reporting](https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety-c9): Report serious incidents to the AI Office within 2, 5, 10 or 15 days by incident class, with intermediate reports at least every four weeks while unresolved and a final report within 60 days of… - [Obligation AIGE-OBL-GPAICOP-SAFETY-APP1: Safety and Security Appendix 1.3 and 1.4: autonomy, tool use and loss of control as systemic risks](https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety-app1): Sources of systemic risk to consider include the capability to operate autonomously, propensities such as colluding with other AI systems, and affordances such as access to tools and physical… - [Obligation AIGE-OBL-GDPR-ART5-1B: GDPR Art. 5(1)(b) and 6(4) purpose limitation](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b): Personal data are collected for specified, explicit and legitimate purposes and not further processed incompatibly; Art. - [Obligation AIGE-OBL-GDPR-ART6: GDPR Art. 6 lawful basis per processing moment](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art6): A lawful basis for each processing operation, assessed separately for training, fine-tuning, retrieval and inference - [Obligation AIGE-OBL-GDPR-ART7: GDPR Art. 7 conditions for consent and its withdrawal](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art7): Where consent is the basis, the controller can demonstrate it, and withdrawing consent is as easy as giving it - [Obligation AIGE-OBL-GDPR-ART9: GDPR Art. 9 special categories, incl. inferred sensitive data](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art9): Processing special-category data, incl. - [Obligation AIGE-OBL-GDPR-ART13-14: GDPR Arts. 13–14 transparency to data subjects](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art13-14): Inform data subjects of purposes, bases, recipients and retention and, for automated decision-making, give meaningful information about the logic involved (Arts. - [Obligation AIGE-OBL-GDPR-ART15-1H: GDPR Art. 15(1)(h) access to meaningful information about the logic involved](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-1h): On request, confirm automated decision-making and give meaningful information about the logic involved and its significance and envisaged consequences - [Obligation AIGE-OBL-GDPR-ART15-17-21: GDPR Arts. 15–17 and 21 data subject rights against trained models](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-17-21): Access, rectification, erasure and objection requests reach every place the data lives: corpus, snapshots, retrieval index, logs and, where it holds personal data, the model - [Obligation AIGE-OBL-GDPR-ART22: GDPR Art. 22 solely automated decisions and their safeguards](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art22): A right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, except on contract, law or explicit consent; then human intervention, the… - [Obligation AIGE-OBL-GDPR-ART25: GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art25): Adequate, relevant and limited data, with technical and organisational measures built in at design and set by default - [Obligation AIGE-OBL-GDPR-ART5-2: GDPR Art. 5(2) accountability for a model anonymity claim](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-2): A controller that claims a trained model holds no personal data must be able to demonstrate it; the EDPB sets an anonymity test and the evidence it expects - [Obligation AIGE-OBL-GDPR-ART28: GDPR Art. 28 processors, incl. AI vendors](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art28): Use only processors with sufficient guarantees, under a contract that fixes instructions, sub-processors, security, assistance and deletion - [Obligation AIGE-OBL-GDPR-ART30: GDPR Art. 30 records of processing activities](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art30): Controllers and processors keep a record of the processing activities under their responsibility - [Obligation AIGE-OBL-GDPR-ART33-34: GDPR Arts. 33–34 personal data breach notification](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art33-34): Notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness; tell data subjects without undue delay when the breach is likely to result in a high risk - [Obligation AIGE-OBL-GDPR-ART35-36: GDPR Arts. 35–36 DPIA and prior consultation](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art35-36): Assess the impact before processing likely to result in a high risk, and consult the supervisory authority where the residual risk stays high - [Obligation AIGE-OBL-GDPR-ART44-49: GDPR Arts. 44–49 international transfers, incl. remote inference](https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art44-49): Transfers outside the EEA only on an adequacy decision, appropriate safeguards (such as standard contractual clauses or binding corporate rules) or a narrow derogation; sending personal data to a… - [Obligation AIGE-OBL-NIS2-ART21-2: NIS2 Art. 21(2)(c)–(d) business continuity and supply-chain security](https://aigovernanceengineer.com/obligations/aige-obl-nis2-art21-2): Risk-management measures include business continuity (backup, disaster recovery, crisis management) and supply-chain security with direct suppliers and service providers, which covers AI and model… - [Obligation AIGE-OBL-NIS2-ART23: NIS2 Art. 23 significant-incident reporting](https://aigovernanceengineer.com/obligations/aige-obl-nis2-art23): An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of the notification, incl. - [Obligation AIGE-OBL-DORA-ART19: DORA Art. 19 major ICT-related incident reporting](https://aigovernanceengineer.com/obligations/aige-obl-dora-art19): Report major ICT-related incidents: initial notification within 4 hours of classification as major and no later than 24 hours from awareness (within 4 hours of a classification made after those 24… - [Obligation AIGE-OBL-DORA-ART28: DORA Art. 28(3) and 28(8) register of ICT third-party arrangements and exit strategies](https://aigovernanceengineer.com/obligations/aige-obl-dora-art28): Keep a register of information on all contractual arrangements for ICT services from third-party providers, and exit strategies for ICT services that support critical or important functions - [Obligation AIGE-OBL-CRA-ART14: Cyber Resilience Act Art. 14 reporting of actively exploited vulnerabilities and severe incidents](https://aigovernanceengineer.com/obligations/aige-obl-cra-art14): Notify actively exploited vulnerabilities and severe incidents through the single reporting platform: early warning within 24 hours, notification within 72 hours, final report 14 days after a fix is… - [Obligation AIGE-OBL-PLD-ART4: EU Product Liability Directive Art. 4(1) software, incl. AI systems, as a product](https://aigovernanceengineer.com/obligations/aige-obl-pld-art4): Software is a product, so the manufacturer of an AI system is strictly liable for damage caused by a defect in a product placed on the market or put into service after 2026-12-09 - [Obligation AIGE-OBL-PLD-ART9-10: EU Product Liability Directive Arts. 9–10 disclosure of evidence and presumption of defect](https://aigovernanceengineer.com/obligations/aige-obl-pld-art9-10): A court can order the defendant to disclose relevant evidence at its disposal; failing to disclose it is one of the conditions under which the product is presumed defective - [Obligation AIGE-OBL-PLD-ART11-2: EU Product Liability Directive Art. 11(2) no later-defect defence for software, its updates or missing safety updates in the manufacturer's control](https://aigovernanceengineer.com/obligations/aige-obl-pld-art11-2): The manufacturer cannot rely on the defect arising after placing on the market where it is due to software, incl. - [Obligation AIGE-OBL-DSM-ART4-3: DSM Directive Art. 4(3) text-and-data-mining reservations](https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3): The general text-and-data-mining exception applies only where rightholders have not expressly reserved use in an appropriate manner, such as machine-readable means for content made publicly… - [Obligation AIGE-OBL-DSA-ART25: Digital Services Act Art. 25 no deceptive or manipulative interface design](https://aigovernanceengineer.com/obligations/aige-obl-dsa-art25): Online platforms do not design, organise or operate their interfaces in a way that deceives or manipulates users or impairs their free and informed decisions - [Obligation AIGE-OBL-DSA-ART27: Digital Services Act Art. 27 recommender system transparency](https://aigovernanceengineer.com/obligations/aige-obl-dsa-art27): Online platforms set out in their terms the main parameters of their recommender systems and any options users have to modify them - [Obligation AIGE-OBL-UCPD-ART5-7: UCPD Arts. 5–7 and Annex I unfair and misleading commercial practices, incl. fake reviews](https://aigovernanceengineer.com/obligations/aige-obl-ucpd-art5-7): No commercial practice contrary to professional diligence, or misleading, that distorts the average consumer's decisions, incl. - [Obligation AIGE-OBL-PWD-ART7-11: Platform Work Directive Arts. 7 and 9–11 automated monitoring and decision-making systems](https://aigovernanceengineer.com/obligations/aige-obl-pwd-art7-11): Limits on the personal data platforms may process through automated systems, transparency about those systems, human oversight with an impact evaluation at least every two years, and explanation and… - [Obligation AIGE-OBL-CCD2-ART18-8: Consumer Credit Directive Art. 18(8) human intervention in automated creditworthiness assessment](https://aigovernanceengineer.com/obligations/aige-obl-ccd2-art18-8): Where the creditworthiness assessment involves automated processing, the consumer may request human intervention, a clear explanation of the assessment and its logic, and a review of the decision - [Obligation AIGE-OBL-ISO42001-A2: A.2 Policies related to AI](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a2): AI policy set and its governance - [Obligation AIGE-OBL-ISO42001-A3: A.3 Internal organization](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a3): Roles, responsibilities, reporting - [Obligation AIGE-OBL-ISO42001-A4: A.4 Resources for AI systems](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4): Data, tooling, compute, human resources documented - [Obligation AIGE-OBL-ISO42001-A5: A.5 Assessing impacts of AI systems](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a5): Impact assessment process - [Obligation AIGE-OBL-ISO42001-A6: A.6 AI system life cycle](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6): Responsible design, development, deployment - [Obligation AIGE-OBL-ISO42001-A7: A.7 Data for AI systems](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7): Data quality, provenance, preparation - [Obligation AIGE-OBL-ISO42001-A8: A.8 Information for interested parties](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8): Transparency and reporting to stakeholders - [Obligation AIGE-OBL-ISO42001-A9: A.9 Use of AI systems](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9): Responsible-use controls and monitoring - [Obligation AIGE-OBL-ISO42001-A10: A.10 Third-party and customer relationships](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10): Managing supplier and customer responsibilities - [Obligation AIGE-OBL-ISO42006-CB: ISO/IEC 42006:2025 requirements for AIMS certification bodies](https://aigovernanceengineer.com/obligations/aige-obl-iso42006-cb): Requirements for bodies auditing and certifying AI management systems (who may credibly certify you to 42001) - [Obligation AIGE-OBL-ISO23894-RISK: ISO/IEC 23894:2023 guidance on AI risk management](https://aigovernanceengineer.com/obligations/aige-obl-iso23894-risk): Guidance on AI risk management (companion to ISO 31000) - [Obligation AIGE-OBL-ISO42005-IA: ISO/IEC 42005:2025 guidance for AI system impact assessment](https://aigovernanceengineer.com/obligations/aige-obl-iso42005-ia): Guidance for assessing the impacts of an AI system on individuals, groups and society across its life cycle (companion to Art. - [Obligation AIGE-OBL-ISO22989-CONCEPTS: ISO/IEC 22989:2022 AI concepts, terminology and stakeholder roles](https://aigovernanceengineer.com/obligations/aige-obl-iso22989-concepts): A shared vocabulary for AI concepts, the AI system life cycle and AI stakeholder roles - [Obligation AIGE-OBL-NISTRMF-GOVERN: GOVERN](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern): A culture and structure for managing AI risk - [Obligation AIGE-OBL-NISTRMF-MAP: MAP](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map): Context and risk framing for each AI system - [Obligation AIGE-OBL-NISTRMF-MEASURE: MEASURE](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure): Analyse, benchmark and monitor risk - [Obligation AIGE-OBL-NISTRMF-MANAGE: MANAGE](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage): Prioritise, respond and recover - [Obligation AIGE-OBL-NIST-AGENTS: NIST AI Agent Standards Initiative (2026)](https://aigovernanceengineer.com/obligations/aige-obl-nist-agents): CAISI initiative on interoperable, secure AI agents: identity, authentication, agent security - [Obligation AIGE-OBL-NIST-IR8596: NIST IR 8596 Cyber AI Profile (draft)](https://aigovernanceengineer.com/obligations/aige-obl-nist-ir8596): CSF 2.0 profile for AI (Secure / Defend / Thwart) - [Obligation AIGE-OBL-NIST-AI800-1: NIST AI 800-1 misuse risk for dual-use foundation models (draft)](https://aigovernanceengineer.com/obligations/aige-obl-nist-ai800-1): Managing Misuse Risk for Dual-Use Foundation Models (voluntary guidance) - [Obligation AIGE-OBL-NIST-AI600-1: NIST AI 600-1 Generative AI Profile](https://aigovernanceengineer.com/obligations/aige-obl-nist-ai600-1): Suggested actions for 12 risks that generative AI creates or exacerbates, coded to the Govern, Map, Measure and Manage functions - [Obligation AIGE-OBL-CSA-AICM: AICM v1.1: 247 control objectives across 18 domains](https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm): 247 control objectives across 18 domains, spanning governance, data, model and runtime - [Obligation AIGE-OBL-CSA-STAR: STAR for AI assurance and certification programme](https://aigovernanceengineer.com/obligations/aige-obl-csa-star): Assurance and certification programme on the AICM: Level 1 self-assessment, Level 1 Valid-AI-ted (automated validation) and Level 2 (ISO/IEC 42001 certification plus the validated assessment) - [Obligation AIGE-OBL-CSA-AICM-AGENTIC: AICM agent controls with the CSA Agentic Trust Framework and AARM specification](https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic): Agent-specific AICM controls (e.g. - [Obligation AIGE-OBL-CSA-AICM-CATASTROPHIC: AICM Catastrophic Risk Annex (enhanced controls for high-autonomy systems)](https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-catastrophic): Enhanced AICM controls for high-autonomy systems with catastrophic-risk potential - [Obligation AIGE-OBL-OWASP-AGENTIC: Top 10 for Agentic Applications 2026](https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic): Agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents) - [Obligation AIGE-OBL-OWASP-LLM: Top 10 for LLM Applications 2026](https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm): LLM threat catalogue (incl. - [Obligation AIGE-OBL-OWASP-ACS: Agent Control Standard (ACS)](https://aigovernanceengineer.com/obligations/aige-obl-owasp-acs): A standard for expressing agent controls - [Obligation AIGE-OBL-OWASP-AIBOM: AIBOM](https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom): AI bill-of-materials format and generator - [Obligation AIGE-OBL-USCA-SB53: California SB 53 (TFAIA)](https://aigovernanceengineer.com/obligations/aige-obl-usca-sb53): Publish a frontier AI framework; report critical safety incidents to the Office of Emergency Services within 15 days; whistleblower protection; up to USD 1M per violation, AG-enforced - [Obligation AIGE-OBL-USNY-RAISE: New York RAISE Act (signed 2025-12-19; effective 2027-01-01)](https://aigovernanceengineer.com/obligations/aige-obl-usny-raise): Publish a frontier AI safety and security framework; disclose safety incidents within 72 hours. - [Obligation AIGE-OBL-USCA-SB53-WHISTLE: California SB 53 whistleblower protections for covered employees](https://aigovernanceengineer.com/obligations/aige-obl-usca-sb53-whistle): No rule, policy or contract that prevents covered employees from disclosing catastrophic-risk concerns, and no retaliation; notice of rights; large frontier developers run an anonymous internal… - [Obligation AIGE-OBL-USTX-TRAIGA: Texas TRAIGA (HB 149; in force 2026-01-01)](https://aigovernanceengineer.com/obligations/aige-obl-ustx-traiga): Intent-based prohibitions on developing or deploying AI (behaviour manipulation, unlawful discrimination); social scoring banned for governmental entities; AI-use disclosure by government agencies… - [Obligation AIGE-OBL-USCO-AIACT: Colorado SB 26-189 automated decision-making technology (replaces the Colorado AI Act, SB 24-205; effective 2027-01-01)](https://aigovernanceengineer.com/obligations/aige-obl-usco-aiact): Developer documentation to deployers and notice of material updates; deployer notice of ADMT use; a plain-language explanation within 30 days of an adverse outcome; correction, human review and… - [Obligation AIGE-OBL-USCA-AB2013: California AB 2013 training-data transparency for generative AI](https://aigovernanceengineer.com/obligations/aige-obl-usca-ab2013): Developers post a summary of the datasets used to train a generative AI system made available to Californians (sources, size, data types, IP and personal information, synthetic data) on or before… - [Obligation AIGE-OBL-USCA-SB942: California AI Transparency Act (SB 942 as amended by AB 853)](https://aigovernanceengineer.com/obligations/aige-obl-usca-sb942): Covered providers offer a free AI-detection tool and embed latent disclosures, with an optional manifest disclosure, in generated image, video and audio; large online platforms and capture devices… - [Obligation AIGE-OBL-USCA-SB243: California SB 243 companion chatbots](https://aigovernanceengineer.com/obligations/aige-obl-usca-sb243): Disclose AI where a reasonable person could be misled; for known minors, remind at least every three hours and prevent sexually explicit content; run a suicide and self-harm protocol with crisis… - [Obligation AIGE-OBL-USNY-GBL47: New York GBL Article 47 AI companion models](https://aigovernanceengineer.com/obligations/aige-obl-usny-gbl47): Detect suicidal ideation and self-harm and refer users to crisis services; tell users they are not talking to a human at the start and at least every three hours - [Obligation AIGE-OBL-USIL-HB3773: Illinois HB 3773 AI in employment decisions](https://aigovernanceengineer.com/obligations/aige-obl-usil-hb3773): Employers may not use AI with a discriminatory effect on protected classes in recruitment, hiring, promotion, discipline or other terms of employment, nor ZIP codes as a proxy, and must notify… - [Obligation AIGE-OBL-USNYC-LL144: NYC Local Law 144 automated employment decision tools](https://aigovernanceengineer.com/obligations/aige-obl-usnyc-ll144): An independent bias audit within one year before use, a published summary of the results, and notice to candidates and employees 10 business days before use - [Obligation AIGE-OBL-USUT-SB226: Utah AI disclosure duties (SB 226 amendments to the AI Policy Act)](https://aigovernanceengineer.com/obligations/aige-obl-usut-sb226): Disclose generative AI when a person clearly and unambiguously asks; regulated occupations disclose it prominently in a high-risk AI interaction; clear disclosure at the outset is a safe harbour - [Obligation AIGE-OBL-USCA-CPPA-ADMT: California CPPA regulations on automated decisionmaking technology](https://aigovernanceengineer.com/obligations/aige-obl-usca-cppa-admt): Businesses using ADMT for significant decisions give a pre-use notice, an opt-out or a human appeal, and access to information about the ADMT - [Obligation AIGE-OBL-USCA-CPPA-RA: California CPPA regulations on risk assessments](https://aigovernanceengineer.com/obligations/aige-obl-usca-cppa-ra): A risk assessment before processing that presents significant risk, incl. - [Obligation AIGE-OBL-USVA-CDPA: Virginia CDPA data protection assessments, incl. risky profiling](https://aigovernanceengineer.com/obligations/aige-obl-usva-cdpa): Controllers document data protection assessments for targeted advertising, sale, profiling that presents a reasonably foreseeable risk, and sensitive data, for processing created after 2023-01-01… - [Obligation AIGE-OBL-USCO-CPA: Colorado Privacy Act profiling opt-out and data protection assessments](https://aigovernanceengineer.com/obligations/aige-obl-usco-cpa): Consumers may opt out of profiling in furtherance of decisions with legal or similarly significant effects, incl. - [Obligation AIGE-OBL-USMN-MCDPA: Minnesota CDPA right to question the result of profiling](https://aigovernanceengineer.com/obligations/aige-obl-usmn-mcdpa): A consumer may question the result of profiling, be told the reason, review the personal data used, correct it and have the decision re-evaluated - [Obligation AIGE-OBL-USIL-BIPA: Illinois BIPA consent and retention for biometric identifiers](https://aigovernanceengineer.com/obligations/aige-obl-usil-bipa): Informed written consent before collecting biometric identifiers, a retention and destruction schedule, and secure storage; a private right of action with statutory damages - [Obligation AIGE-OBL-USWA-MHMDA: Washington My Health My Data Act consent for consumer health data](https://aigovernanceengineer.com/obligations/aige-obl-uswa-mhmda): Consent to collect and separate consent to share consumer health data, incl. - [Obligation AIGE-OBL-USCO-SB21-169: Colorado SB21-169 insurers' use of external consumer data and predictive models](https://aigovernanceengineer.com/obligations/aige-obl-usco-sb21-169): Insurers may not unfairly discriminate through external consumer data, algorithms or predictive models; they keep a risk-management framework, test for unfair discrimination and file a… - [Obligation AIGE-OBL-USFED-OMB-M25-21: OMB M-25-21 minimum practices for high-impact AI](https://aigovernanceengineer.com/obligations/aige-obl-usfed-omb-m25-21): Federal agencies apply minimum practices to high-impact AI: pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight with a fail-safe where… - [Obligation AIGE-OBL-USFED-OMB-M26-04: OMB M-26-04 minimum LLM transparency in federal procurement](https://aigovernanceengineer.com/obligations/aige-obl-usfed-omb-m26-04): Solicitations for large language models request, as a minimum, the vendor's acceptable use policy, model, system or data cards, end-user resources and a feedback mechanism - [Obligation AIGE-OBL-USFED-REGB-1002-9: ECOA Regulation B adverse-action notice with specific principal reasons](https://aigovernanceengineer.com/obligations/aige-obl-usfed-regb-1002-9): A creditor that takes adverse action gives a statement of specific principal reasons, or the right to one within 30 days; citing internal standards or a failed score is insufficient, whatever model… - [Obligation AIGE-OBL-USFED-FCRA-1681M: FCRA adverse-action notice with the credit score used](https://aigovernanceengineer.com/obligations/aige-obl-usfed-fcra-1681m): A user of a consumer report that takes adverse action gives notice, discloses the numerical credit score used and its key factors, names the reporting agency and states the right to a free report… - [Obligation AIGE-OBL-USFED-TITLE7-703K: Title VII disparate impact and the UGESP four-fifths rule](https://aigovernanceengineer.com/obligations/aige-obl-usfed-title7-703k): A selection procedure with disparate impact is unlawful unless job-related and consistent with business necessity, and a less discriminatory alternative can still be required; a selection rate under… - [Obligation AIGE-OBL-USFED-FTC-S5: FTC Act s. 5 substantiation of AI performance claims](https://aigovernanceengineer.com/obligations/aige-obl-usfed-ftc-s5): Deceptive acts or practices are unlawful: claims about an AI system's accuracy, performance or fairness need competent and reliable evidence before they are made - [Obligation AIGE-OBL-USFED-TAKEITDOWN: TAKE IT DOWN Act notice and removal of intimate images, incl. digital forgeries](https://aigovernanceengineer.com/obligations/aige-obl-usfed-takeitdown): Covered platforms run a notice-and-removal process and remove reported non-consensual intimate images, incl. - [Obligation AIGE-OBL-USGAO-GOV: GAO AI Accountability Framework principle 1: governance](https://aigovernanceengineer.com/obligations/aige-obl-usgao-gov): Clear goals, roles and delegation of authority, values, a multidisciplinary workforce, stakeholder involvement and an AI-specific risk management plan, plus documented technical specifications… - [Obligation AIGE-OBL-USGAO-DATA: GAO AI Accountability Framework principle 2: data](https://aigovernanceengineer.com/obligations/aige-obl-usgao-data): Document the sources and origins of development data and assess their reliability, categorisation, variable selection and any synthetic, imputed or augmented data; assess the dependencies, bias… - [Obligation AIGE-OBL-USGAO-PERF: GAO AI Accountability Framework principle 3: performance](https://aigovernanceengineer.com/obligations/aige-obl-usgao-perf): Catalogue components, define precise, consistent and reproducible metrics, assess each component and the whole system against them, identify biases and define procedures for human supervision - [Obligation AIGE-OBL-USGAO-MON: GAO AI Accountability Framework principle 4: monitoring](https://aigovernanceengineer.com/obligations/aige-obl-usgao-mon): Plan continuous or routine monitoring, set the acceptable range of data and model drift, document monitoring results and corrective actions, and reassess the system's utility and the conditions for… - [Obligation AIGE-OBL-KR-AIBASIC: South Korea AI Basic Act (in force 2026-01-22)](https://aigovernanceengineer.com/obligations/aige-obl-kr-aibasic): Baseline duties for AI operators, heightened duties for "high-impact" AI in sensitive sectors, and AI-content labelling - [Obligation AIGE-OBL-SG-GENAI: Singapore IMDA Model AI Governance Framework for Generative AI (voluntary)](https://aigovernanceengineer.com/obligations/aige-obl-sg-genai): Governance dimensions incl. - [Obligation AIGE-OBL-UK-ADM: UK GDPR Arts. 22A–22D permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025)](https://aigovernanceengineer.com/obligations/aige-obl-uk-adm): A permission-plus-safeguards model for significant, solely automated decisions, with tighter conditions where special-category data is used - [Obligation AIGE-OBL-ETSI-304223: ETSI EN 304 223 baseline cyber-security for AI models and systems](https://aigovernanceengineer.com/obligations/aige-obl-etsi-304223): Baseline cyber-security requirements across the AI lifecycle (13 principles over five stages) - [Obligation AIGE-OBL-SG-AGENTIC-IDENTITY: Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary)](https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-identity): Each agent has a unique, accounted-for identity, catalogued and centrally managed; authorisations are scoped, time- or session-bound, non-transferable and bounded by the authorising human - [Obligation AIGE-OBL-SG-AGENTIC-CHECKPOINTS: Singapore IMDA Model AI Governance Framework for Agentic AI: human checkpoints for significant actions (voluntary)](https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-checkpoints): Significant checkpoints for high-stakes, irreversible, outlier and user-defined actions, with approvals that are contextual and digestible and enforced through system-level controls - [Obligation AIGE-OBL-CAN-DADM: Canada Directive on Automated Decision-Making (federal institutions)](https://aigovernanceengineer.com/obligations/aige-obl-can-dadm): Complete, approve and publish an algorithmic impact assessment before production; apply the Appendix C requirements for the impact level (notice, explanation, peer review, human intervention); offer… - [Obligation AIGE-OBL-BR-LGPD-ART20: Brazil LGPD Art. 20 review of automated decisions](https://aigovernanceengineer.com/obligations/aige-obl-br-lgpd-art20): A data subject may request review of decisions taken solely on automated processing that affect their interests, incl. - [Obligation AIGE-OBL-KR-ART31-1: Korea AI Basic Act Art. 31(1) prior notice of high-impact or generative AI](https://aigovernanceengineer.com/obligations/aige-obl-kr-art31-1): Tell users in advance that a product or service runs on high-impact or generative AI, in the product, the terms, the screen or the place of supply (Decree Art. - [Obligation AIGE-OBL-KR-ART31-2: Korea AI Basic Act Art. 31(2)–(3) generative-AI output labels and realistic-content notice](https://aigovernanceengineer.com/obligations/aige-obl-kr-art31-2): Indicate that outputs are AI-generated, and notify or label realistic synthetic sound, images or video so users can recognise them; a machine-readable mark alone needs at least one text or voice… - [Obligation AIGE-OBL-KR-ART32: Korea AI Basic Act Art. 32 safety duties for high-compute systems](https://aigovernanceengineer.com/obligations/aige-obl-kr-art32): Systems with at least 10^26 FLOP of cumulative training compute, built with the most advanced technology and posing broad and serious risk (Decree Art. - [Obligation AIGE-OBL-KR-ART33: Korea AI Basic Act Art. 33 high-impact self-review and confirmation](https://aigovernanceengineer.com/obligations/aige-obl-kr-art33): Review in advance whether a system is high-impact AI and optionally ask MSIT to confirm; MSIT replies within 30 days, extendable once (Decree Art. - [Obligation AIGE-OBL-KR-ART34: Korea AI Basic Act Art. 34 measures for high-impact AI](https://aigovernanceengineer.com/obligations/aige-obl-kr-art34): A risk management plan, an explanation plan, a user-protection plan, human management and supervision, and documents showing the measures; publish the main content and keep the evidence for five… - [Obligation AIGE-OBL-KR-ART35: Korea AI Basic Act Art. 35 fundamental-rights impact assessment (best effort)](https://aigovernanceengineer.com/obligations/aige-obl-kr-art35): Endeavour to assess the effect on fundamental rights before providing high-impact AI, covering the seven elements of Decree Art. - [Obligation AIGE-OBL-KR-ART36: Korea AI Basic Act Art. 36 domestic representative](https://aigovernanceengineer.com/obligations/aige-obl-kr-art36): An operator with no address or establishment in Korea that meets a decree threshold (revenue, AI-service revenue, daily users or a past fine; Decree Art. - [Obligation AIGE-OBL-UK-DMCC-S225: UK DMCC Act 2024 banned practices: fake and concealed-incentive reviews](https://aigovernanceengineer.com/obligations/aige-obl-uk-dmcc-s225): Unfair commercial practices are prohibited, and Schedule 20 bans submitting or commissioning fake consumer reviews and concealed-incentive reviews, which reaches reviews generated by AI - [Obligation AIGE-OBL-CN-ALGOREC: Provisions on Algorithmic Recommendation (in force 2022-03-01)](https://aigovernanceengineer.com/obligations/aige-obl-cn-algorec): Algorithm filing for services with public-opinion attributes or social-mobilisation capacity, security assessment, display of the filing number, and a user option to switch off personalised… - [Obligation AIGE-OBL-CN-DEEPSYN: Provisions on Deep Synthesis (in force 2023-01-10)](https://aigovernanceengineer.com/obligations/aige-obl-cn-deepsyn): Conspicuous labels where synthetic content could mislead the public and non-removable technical marks; training-data management; separate consent for face and voice editing; filing and security… - [Obligation AIGE-OBL-CN-GENAI: Interim Measures for Generative AI Services (in force 2023-08-15)](https://aigovernanceengineer.com/obligations/aige-obl-cn-genai): Lawful-source training data and foundation models; content labelling under the deep-synthesis rules; security assessment and algorithm filing for opinion-shaping services; stop, remove, retrain and… - [Obligation AIGE-OBL-CN-LABEL: Measures for Labelling AI-Generated Synthetic Content with GB 45438-2025 (in force 2025-09-01)](https://aigovernanceengineer.com/obligations/aige-obl-cn-label): Explicit labels (text, audio or graphic) and implicit metadata labels carrying the provider's name or code and a content number; distribution platforms verify metadata and flag suspected AI content - [Obligation AIGE-OBL-CN-GBT45654: GB/T 45654-2025 Basic security requirements for generative AI services (voluntary; implemented 2025-11-01)](https://aigovernanceengineer.com/obligations/aige-obl-cn-gbt45654): Training-corpus source and content screening, model-safety requirements and the evaluation methods that underpin the security assessment - [Obligation AIGE-OBL-CN-TC260-OPS: TC260 AI Safety Governance Framework 3.0: operators' guidelines §5.3 (voluntary; 2026-09-14)](https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-ops): A three-block risk taxonomy (inherent, application, secondary), technological and governance countermeasures and role-based guidelines; operators keep logs for at least six months and audit them… - [Obligation AIGE-OBL-CN-TC260-AGENTS: TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14)](https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-agents): Unique identity and least-privilege permissions per agent by decision mode; human checkpoints with tamper-proof approval logs and deny-by-default; tool and skill verification; runtime guardrails… - [Obligation AIGE-OBL-CN-PIPL-ART24: China PIPL Art. 24 automated decision-making and Arts. 55–56 impact assessment](https://aigovernanceengineer.com/obligations/aige-obl-cn-pipl-art24): Automated decisions stay transparent and fair, with no unreasonable differential treatment in prices or terms; targeted pushes offer a non-personalised option or an easy refusal; individuals may… - [Obligation AIGE-OBL-CN-ANTHRO: Interim Measures for Anthropomorphic Interaction Services (in force 2026-07-15)](https://aigovernanceengineer.com/obligations/aige-obl-cn-anthro): A minors' mode; AI signals and a reminder after two hours of continuous use; an easy exit; a security assessment at 1 million registered or 100,000 monthly active users; filing - [Obligation AIGE-OBL-COE-ART14-2: Council of Europe Convention Art. 14(2)(a)–(b) documentation to contest decisions](https://aigovernanceengineer.com/obligations/aige-obl-coe-art14-2): Document relevant information about systems that can significantly affect human rights, sufficient for affected people to contest the decisions - [Obligation AIGE-OBL-COE-ART15-2: Council of Europe Convention Art. 15(2) notice of interaction with an AI system](https://aigovernanceengineer.com/obligations/aige-obl-coe-art15-2): Notify people that they are interacting with an AI system, as appropriate - [Obligation AIGE-OBL-COE-ART16: Council of Europe Convention Art. 16 risk and impact management](https://aigovernanceengineer.com/obligations/aige-obl-coe-art16): Iterative, graduated risk and impact management: context, severity and probability, stakeholder views, monitoring and documentation - [Obligation AIGE-OBL-COE-ART16-2G: Council of Europe Convention Art. 16(2)(g) testing before first use and on significant modification](https://aigovernanceengineer.com/obligations/aige-obl-coe-art16-2g): Test systems before first use and when they are significantly modified, where appropriate - [Obligation AIGE-OBL-OECD-P1-4B: OECD AI Principle 1.4(b) override, repair or decommission safely](https://aigovernanceengineer.com/obligations/aige-obl-oecd-p1-4b): Mechanisms let AI systems that risk undue harm be overridden, repaired and/or decommissioned safely - [Obligation AIGE-OBL-OECD-P1-5: OECD AI Principle 1.5(b)–(c) traceability and systematic risk management](https://aigovernanceengineer.com/obligations/aige-obl-oecd-p1-5): Traceability of datasets, processes and decisions, and systematic risk management at each phase of the lifecycle - [Obligation AIGE-OBL-G7-A1: G7 Hiroshima Code action 1: lifecycle risk management and pre-deployment testing](https://aigovernanceengineer.com/obligations/aige-obl-g7-a1): Identify, evaluate and mitigate risks across the lifecycle, incl. - [Obligation AIGE-OBL-G7-A2-4: G7 Hiroshima Code actions 2 and 4: post-deployment monitoring and incident sharing](https://aigovernanceengineer.com/obligations/aige-obl-g7-a2-4): Identify and mitigate vulnerabilities, incidents and misuse after deployment, and share information and report incidents responsibly - [Obligation AIGE-OBL-G7-A3: G7 Hiroshima Code action 3: public reporting of capabilities and limitations](https://aigovernanceengineer.com/obligations/aige-obl-g7-a3): Publicly report capabilities, limitations and appropriate and inappropriate uses; the OECD reporting framework has collected such reports since 2025 - [Obligation AIGE-OBL-G7-A7: G7 Hiroshima Code action 7: content authentication and provenance](https://aigovernanceengineer.com/obligations/aige-obl-g7-a7): Deploy content authentication and provenance mechanisms where feasible - [Obligation AIGE-OBL-CEN-EN18286: EN 18286:2026 quality management system for EU AI Act purposes](https://aigovernanceengineer.com/obligations/aige-obl-cen-en18286): Quality-management-system requirements supporting Art. - [Obligation AIGE-OBL-CEN-PREN18228: prEN 18228 AI risk management (draft)](https://aigovernanceengineer.com/obligations/aige-obl-cen-pren18228): Draft harmonised standard for the risk management system of Art. - [Obligation AIGE-OBL-CEN-PREN18229-1: prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft)](https://aigovernanceengineer.com/obligations/aige-obl-cen-pren18229-1): Draft harmonised standard for the record-keeping of Art. - [Figure: The three questions](https://aigovernanceengineer.com/figures/three-questions): Three panels (what AI is running, what it is allowed to do, and what evidence proves it), each with the stack layers that answer it. - [Figure: Values and principles](https://aigovernanceengineer.com/figures/values-principles): Two groups: the eight values as affirmations of which way to lean, and the six principles as commitments to act. - [Figure: The minimum viable stack](https://aigovernanceengineer.com/figures/minimum-viable-stack): Five ordered steps (see it, rule it, test it, contain it, prove it), one per stack layer, chained top to bottom. - [Figure: The maturity grid](https://aigovernanceengineer.com/figures/maturity-grid): A five-by-five grid of stack layers against maturity levels, with an illustrative profile whose weakest layer sets the overall level. - [Figure: The Article 73 clock](https://aigovernanceengineer.com/figures/art73-clock): The Article 73 serious-incident reporting windows by incident class (2, 10 and no later than 15 days), with the incident pipeline that meets them. - [Figure: The pattern map](https://aigovernanceengineer.com/figures/pattern-map): Five bands, one per stack layer in canonical order, each holding the patterns whose home layer it is, as links. - [Figure: The map of the discipline](https://aigovernanceengineer.com/figures/discipline-map): A two-sided mind map with a central AI Governance Engineer node and eight branches, each with its second-level topics as links. - [Figure: The five objects of governance](https://aigovernanceengineer.com/figures/five-objects): Five nested objects: models inside systems inside agents, with data beside them, all inside the organisation, each with the controls that govern it. - [Figure: The profession in numbers](https://aigovernanceengineer.com/figures/profession-in-numbers): AI governance demand in numbers: 77% of organisations work on it, only 1.5% expect no new staff, and postings ask for observability, Python and NIST skills. - [Figure: Human oversight, designed](https://aigovernanceengineer.com/figures/human-oversight): Actions classified by consequence, a designed checkpoint only where the stakes justify it, and oversight that leaves evidence which is itself monitored. - [Figure: Where control moves when you buy](https://aigovernanceengineer.com/figures/procured-ai-control): A procured system passes a due-diligence gate; then boundary evals and the controllable perimeter shrink, while inventory and collected supplier evidence grow. - [Figure: Who enforces, and the ceilings](https://aigovernanceengineer.com/figures/enforcement-map): Three enforcement tracks (AI Office for GPAI, national authorities for high-risk AI, the California Attorney General under SB 53) and their penalty ceilings. - [Figure: The committee decides, the gates enforce](https://aigovernanceengineer.com/figures/committee-gates): Most use cases go straight to the gates; triggers route the rest to the committee, whose exceptions become data the policy gate reads until they expire. - [Figure: The risk loop on the stack](https://aigovernanceengineer.com/figures/risk-loop-stack): The four-step risk loop inside GOVERN, each step with its NIST AI RMF function and stack layers, all writing to one risk register. - [Figure: The matrix and the S5 override](https://aigovernanceengineer.com/figures/risk-matrix): A five-by-five likelihood by severity matrix in four bands, with catastrophic severity Critical at any likelihood and a gate and acceptor per band. - [Figure: The mitigation ladder](https://aigovernanceengineer.com/figures/mitigation-ladder): Five mitigation rungs worked top down, from eliminate to accept and monitor, each with its stack control and evidence; transfer sits beside the ladder. - [Figure: Provenance and lineage](https://aigovernanceengineer.com/figures/provenance-lineage): Provenance records where a dataset came from and on what terms; lineage traces it backward from a model to its sources and forward to every model using it. - [Figure: The overlapping incident clocks](https://aigovernanceengineer.com/figures/incident-clocks): First-report deadlines of eight regimes, timed from awareness: DORA at 4 hours after classification to the AI Act and SB 53 at 15 days, in one incident record. - [Figure: The agent control plane](https://aigovernanceengineer.com/figures/agent-control-plane): One tool call through the agent control plane: registry, identity, gateway, guardrail, checkpoint and breaker, with telemetry kept as evidence. - [Figure: The governance operating model](https://aigovernanceengineer.com/figures/governance-operating-model): Board, committee and the three lines around one set of gates, with the AI governance engineer in the second line and evidence flowing to audit and the board. - [Figure: Harm at five levels](https://aigovernanceengineer.com/figures/harm-levels): Five harm levels from one person to the environment, each with an example harm from the atlas and the control, by stack layer, that catches it. - [Figure: The explanation technique map](https://aigovernanceengineer.com/figures/explanation-techniques): Explanation techniques on two axes, global or local and model-agnostic or model-specific, each tested before its explanation record is kept. - [Figure: How the instruments relate](https://aigovernanceengineer.com/figures/instrument-lineage): AI governance instruments in rising order of force, from principles to binding law, with the definition, lifecycle and presumption links between them. - [Figure: EU AI Act timeline, post-Omnibus](https://aigovernanceengineer.com/figures/eu-ai-act-timeline): Seven lanes of EU AI Act obligation families on one time axis, 2024 to 2030, with the Omnibus in force from 2026-07-27 and the deferred high-risk dates. - [Figure: EU AI Act operator roles](https://aigovernanceengineer.com/figures/eu-ai-act-operator-roles): Seven questions down a spine, each leading to an EU AI Act operator role with its duties and evidence, an Article 25 loop to provider and a registry entry. - [Figure: AI laws by jurisdiction](https://aigovernanceengineer.com/figures/jurisdiction-tiles): Twenty jurisdictions as equal tiles in rough geographic layout, shaded by how binding their AI-specific regime is, as of 2026-09-24. - [Figure: EU AI Act risk ladder](https://aigovernanceengineer.com/figures/eu-ai-act-risk-ladder): Four EU AI Act rungs (prohibited, high-risk via Annex I or III with the Art. 6(3) filter, transparency, minimal), a GPAI track and notes on other regimes. - [Figure: Model type by deployment option](https://aigovernanceengineer.com/figures/deployment-option-matrix): A grid of five model types across and six deployment options down, each cell naming the one control that combination adds on top of its row and column. - [Figure: EU AI Act timeline, in Spanish](https://aigovernanceengineer.com/figures/eu-ai-act-timeline-es): Spanish edition: seven lanes of EU AI Act obligation families on one time axis, 2024 to 2030, with the Omnibus in force from 2026-07-27. - [Figure: EU AI Act roles, in Spanish](https://aigovernanceengineer.com/figures/eu-ai-act-operator-roles-es): Spanish edition: seven questions leading to EU AI Act operator roles, from proveedor to responsable del despliegue, with the Article 25 loop and a registry. - [Figure: EU AI Act ladder, in Spanish](https://aigovernanceengineer.com/figures/eu-ai-act-risk-ladder-es): Spanish edition: the four EU AI Act rungs with the Art. 6(3) filter, the track for general-purpose AI models and notes on other regimes. - [Term: A2A (Agent2Agent protocol)](https://aigovernanceengineer.com/glossary/a2a-agent2agent-protocol): An open protocol for agents to hand tasks to one another, at version 1.0 since March 2026 and a Growth Stage project of the Linux Foundation-directed Agentic AI Foundation since August 2026. - [Term: Abstention band](https://aigovernanceengineer.com/glossary/abstention-band): A range of scores in which a system does not act on its own but routes the case to a human reviewer. - [Term: Acceptable-use policy (AUP)](https://aigovernanceengineer.com/glossary/acceptable-use-policy-aup): The staff-facing rules for using AI tools: which tools are approved, which data classes may go where, duties to review and disclose outputs, logging, attestation before access and consequences. - [Term: Adaptiveness](https://aigovernanceengineer.com/glossary/adaptiveness): The ability of an AI system to change its behaviour while in use, through learning after deployment; optional under the EU AI Act definition. - [Term: ADMT (California)](https://aigovernanceengineer.com/glossary/admt-california): Automated decisionmaking technology under the California CCPA regulations: technology that processes personal information and uses computation to replace, or substantially replace, human… - [Term: Adverse action notice](https://aigovernanceengineer.com/glossary/adverse-action-notice): The notice a US creditor must give when it denies or worsens credit, stating the specific principal reasons. - [Term: Adverse-impact ratio (AIR)](https://aigovernanceengineer.com/glossary/adverse-impact-ratio-air): The selection rate of a group divided by the selection rate of the most-selected group. - [Term: AESIA](https://aigovernanceengineer.com/glossary/aesia): Spain's Agencia Española de Supervisión de Inteligencia Artificial, a state agency based in A Coruña whose statute was approved by Royal Decree 729/2023, created to act as Spain's national… - [Term: Agent (agentic AI)](https://aigovernanceengineer.com/glossary/agent-agentic-ai): An AI system that acts (browses, executes code, calls APIs, moves data or delegates to other agents) under delegated authority, rather than only producing text. - [Term: Agent Card](https://aigovernanceengineer.com/glossary/agent-card): The JSON document an A2A agent publishes, usually at /.well-known/agent-card.json, describing its identity, skills, service endpoint and the authentication schemes it accepts. - [Term: Agent registry](https://aigovernanceengineer.com/glossary/agent-registry): The runtime-aware inventory of every non-human actor (model, service and agent), each with an owner, a declared scope, a status and a kill switch, fed by a runtime data path rather than typed by hand. - [Term: AI Act (EU)](https://aigovernanceengineer.com/glossary/ai-act-eu): Regulation (EU) 2024/1689, the EU's horizontal, risk-tiered law for AI, amended by the Digital Omnibus. - [Term: AI business operator (Korea)](https://aigovernanceengineer.com/glossary/ai-business-operator-korea): Under the Korean AI Basic Act, a legal person, organisation, individual or state body doing AI business, split into development business operators, who develop and provide AI, and utilisation… - [Term: AI governance](https://aigovernanceengineer.com/glossary/ai-governance): The set of rules, roles, controls and evidence that keeps AI systems within the limits an organisation or a state has chosen. - [Term: AI governance committee](https://aigovernanceengineer.com/glossary/ai-governance-committee): The cross-functional body that takes the decisions a gate cannot: accepting residual risk above a product owner's authority, granting exceptions, weighing value trade-offs and approving the policy… - [Term: AI governance engineer](https://aigovernanceengineer.com/glossary/ai-governance-engineer): The person who holds the capability of AI governance engineering and is accountable for the three questions in production; a capability and a role, not necessarily a job title. - [Term: AI governance engineering](https://aigovernanceengineer.com/glossary/ai-governance-engineering): The application of engineering practice (systems thinking, product thinking and code) to the governance of AI systems; measured by realised risk reduction and audit-ready evidence. - [Term: AI harm](https://aigovernanceengineer.com/glossary/ai-harm): A negative consequence of building or using an AI system for a person, a group, an organisation, society or the environment. - [Term: AI hazard](https://aigovernanceengineer.com/glossary/ai-hazard): In the OECD's definition, an event or series of events where the development, use or malfunction of an AI system could plausibly lead to an AI incident. - [Term: AI incident](https://aigovernanceengineer.com/glossary/ai-incident): In the OECD's definition, an event or series of events where the development, use or malfunction of one or more AI systems directly or indirectly leads to harm to health, critical infrastructure… - [Term: AI literacy](https://aigovernanceengineer.com/glossary/ai-literacy): Under the EU AI Act, the skills, knowledge and understanding that let providers, deployers and affected persons use AI in an informed way and grasp its opportunities, risks and possible harm. - [Term: AI Office](https://aigovernanceengineer.com/glossary/ai-office): The European Commission body that supervises general-purpose AI and coordinates AI Act enforcement, with investigation powers and the ability to levy penalties on GPAI providers. - [Term: AI regulatory sandbox](https://aigovernanceengineer.com/glossary/ai-regulatory-sandbox): Under the EU AI Act, a controlled framework set up by a competent authority in which providers develop, train, test and validate innovative AI systems for a limited time under a sandbox plan… - [Term: AI RMF functions](https://aigovernanceengineer.com/glossary/ai-rmf-functions): The four core functions of the NIST AI Risk Management Framework (Govern, Map, Measure, Manage), used throughout the book as a mapping target for controls. - [Term: AI RMF Playbook](https://aigovernanceengineer.com/glossary/ai-rmf-playbook): NIST's online companion to the AI RMF. - [Term: AI RMF profile](https://aigovernanceengineer.com/glossary/ai-rmf-profile): An application of the AI RMF Core to a context. - [Term: AI system](https://aigovernanceengineer.com/glossary/ai-system): For governance, the object the AI definition brings into scope. - [Term: AI system impact assessment](https://aigovernanceengineer.com/glossary/ai-system-impact-assessment): An assessment of how an AI system and its foreseeable applications may affect individuals, groups and society, performed across the lifecycle and updated as needed; ISO/IEC 42005:2025 gives the… - [Term: AI system lifecycle (OECD)](https://aigovernanceengineer.com/glossary/ai-system-lifecycle-oecd): The OECD's iterative phases of an AI system: plan and design; collect and process data; build or adapt models; test, evaluate, verify and validate; deploy; operate and monitor; retire or decommission. - [Term: AI washing](https://aigovernanceengineer.com/glossary/ai-washing): Overstating or inventing the use or capability of AI in marketing or investor communications. - [Term: AIBOM](https://aigovernanceengineer.com/glossary/aibom): AI bill of materials: the machine-readable inventory of an AI system's components (models, datasets, dependencies) in formats such as CycloneDX ML-BOM or the SPDX 3.0 AI profile. - [Term: AICM](https://aigovernanceengineer.com/glossary/aicm): The CSA AI Controls Matrix, a control framework (v1.1, 247 control objectives across 18 domains) that maps to ISO 42001, ISO 27001 and NIST AI RMF and underpins STAR for AI. - [Term: AIMA](https://aigovernanceengineer.com/glossary/aima): The OWASP AI Maturity Assessment, reported at v1.0 (Aug 2025), which scores the breadth of an AI security and governance programme across domains. - [Term: AIMS](https://aigovernanceengineer.com/glossary/aims): An AI management system: the governance structure, roles, controls and continual-improvement loop that ISO/IEC 42001 certifies. - [Term: Algorithmic disgorgement](https://aigovernanceengineer.com/glossary/algorithmic-disgorgement): A remedy that orders deletion of models or algorithms developed with unlawfully obtained data, not only the data itself. - [Term: Algorithmic Impact Assessment (AIA)](https://aigovernanceengineer.com/glossary/algorithmic-impact-assessment-aia): The assessment Canada's Directive on Automated Decision-Making requires before a federal automated decision system goes into production. - [Term: Algorithmic management](https://aigovernanceengineer.com/glossary/algorithmic-management): The use of automated monitoring and decision systems to direct, evaluate or sanction workers. - [Term: Algorithmic Transparency Recording Standard (ATRS)](https://aigovernanceengineer.com/glossary/algorithmic-transparency-recording-standard-atrs): The UK's standard template for public-sector bodies to publish how and why they use algorithmic tools; mandatory for government departments and for arm's-length bodies that deliver public or… - [Term: ALTAI](https://aigovernanceengineer.com/glossary/altai): The Assessment List for Trustworthy AI, published by the EU High-Level Expert Group on AI in July 2020: a self-assessment checklist that turns the seven requirements of the 2019 Ethics Guidelines… - [Term: Annex I (EU AI Act)](https://aigovernanceengineer.com/glossary/annex-i-eu-ai-act): The AI Act annex listing the Union harmonisation legislation under which AI is embedded in regulated products (machinery, medical devices, toys and the like); obligations for these high-risk… - [Term: Annex III](https://aigovernanceengineer.com/glossary/annex-iii): The AI Act annex listing high-risk use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice); obligations for these phase in… - [Term: Anonymous data](https://aigovernanceengineer.com/glossary/anonymous-data): Information that does not relate to an identifiable person, judged against all the means reasonably likely to be used by anyone to identify them. - [Term: Article 6(3) filter](https://aigovernanceengineer.com/glossary/article-6-3-filter): The derogation under which an Annex III system is not high-risk when it poses no significant risk of harm and meets one of four conditions (narrow procedural task, improving completed human work… - [Term: ASI01–ASI10](https://aigovernanceengineer.com/glossary/asi01-asi10): The ten risks of the OWASP Top 10 for Agentic Applications 2026: ASI01 Agent Goal Hijack, ASI02 Tool Misuse and Exploitation, ASI03 Identity and Privilege Abuse, ASI04 Agentic Supply Chain… - [Term: ATLAS](https://aigovernanceengineer.com/glossary/atlas): MITRE's Adversarial Threat Landscape for Artificial-Intelligence Systems, a knowledge base of adversary tactics and techniques against AI, including agent-specific techniques. - [Term: Audit-ready evidence](https://aigovernanceengineer.com/glossary/audit-ready-evidence): Evidence emitted as a by-product of the build in a form an auditor can read directly (machine-readable, signed, timestamped), so the audit is a query, not a collection project. - [Term: Authorised representative](https://aigovernanceengineer.com/glossary/authorised-representative): Under the EU AI Act, a person established in the Union with a written mandate from a non-EU provider of a high-risk AI system or general-purpose AI model to carry out that provider's obligations on… - [Term: Automated decision-making (ADM)](https://aigovernanceengineer.com/glossary/automated-decision-making-adm): A decision about a person taken by automated means. - [Term: Automation bias](https://aigovernanceengineer.com/glossary/automation-bias): The tendency of a person to over-rely on an automated system's output. - [Term: Autonomy](https://aigovernanceengineer.com/glossary/autonomy): In the EU AI Act and OECD texts, some degree of independence of action from human involvement, which almost every AI system has. - [Term: Autonomy level](https://aigovernanceengineer.com/glossary/autonomy-level): How far an agent acts without a person between its steps, set by the deployer as a design decision rather than taken as a property of the model; one research scale names five levels by the user's… - [Term: Bias](https://aigovernanceengineer.com/glossary/bias): A systematic error that favours or disadvantages some people or outcomes. - [Term: Bias audit (NYC Local Law 144)](https://aigovernanceengineer.com/glossary/bias-audit-nyc-local-law-144): An independent audit, required within the year before an employer uses an automated employment decision tool in New York City, that reports selection or scoring rates and impact ratios by sex, race… - [Term: Biometric data](https://aigovernanceengineer.com/glossary/biometric-data): Personal data from the technical processing of physical, physiological or behavioural traits that allows or confirms a person's unique identification, such as facial images or fingerprints. - [Term: Blameless post-mortem](https://aigovernanceengineer.com/glossary/blameless-post-mortem): An incident review that identifies contributing causes without indicting any individual or team, on the premise that people acted reasonably on what they knew and that systems and processes are what… - [Term: Blue-green deployment](https://aigovernanceengineer.com/glossary/blue-green-deployment): Two identical production environments with traffic switched between them, so a release can be rolled back by switching back. - [Term: Build provenance (SLSA)](https://aigovernanceengineer.com/glossary/build-provenance-slsa): A verifiable record, in the SLSA format, of what built an artefact, by what process and from which top-level inputs. - [Term: CAC (Cyberspace Administration of China)](https://aigovernanceengineer.com/glossary/cac-cyberspace-administration-of-china): China's internet regulator (国家互联网信息办公室), lead issuer of the binding AI rules (algorithmic recommendation, deep synthesis, generative AI services and AI-content labelling) and the body under whose… - [Term: Calibration](https://aigovernanceengineer.com/glossary/calibration): The property that a model's confidence matches its accuracy: of the cases scored 0.9, about nine in ten are right. - [Term: Calibration within groups](https://aigovernanceengineer.com/glossary/calibration-within-groups): The fairness property that, in every group, the people given a score s turn out positive at rate s, so a score means the same thing for everyone. - [Term: Canary release](https://aigovernanceengineer.com/glossary/canary-release): A partial, time-limited deployment of a change to a small share of production traffic, evaluated against a control group before the rollout continues. - [Term: CAPA](https://aigovernanceengineer.com/glossary/capa): Corrective and preventive action, the output of an incident review. - [Term: Catastrophic forgetting](https://aigovernanceengineer.com/glossary/catastrophic-forgetting): The tendency of neural networks to lose earlier competence when trained on new tasks. - [Term: Catastrophic-severity override](https://aigovernanceengineer.com/glossary/catastrophic-severity-override): The rule that any scenario rated at the top severity level is Critical whatever its likelihood, cannot be accepted by the delivery team, and must be eliminated, reduced in severity or accepted… - [Term: CE marking](https://aigovernanceengineer.com/glossary/ce-marking): The mark showing a high-risk AI system's conformity with the EU AI Act, affixed visibly, legibly and indelibly, or digitally for systems provided digitally, with the notified body's number where one… - [Term: Cedar](https://aigovernanceengineer.com/glossary/cedar): An open-source policy language for fine-grained authorization, used as a policy-as-code engine for runtime access decisions; a schema-typed, analysable alternative to OPA/Rego. - [Term: CEN-CENELEC JTC 21](https://aigovernanceengineer.com/glossary/cen-cenelec-jtc-21): The joint technical committee of the European standardisation organisations CEN and CENELEC that drafts the AI Act harmonised standards, including EN 18286 on quality management and the drafts on… - [Term: CIMD](https://aigovernanceengineer.com/glossary/cimd): Client ID Metadata Document: the mechanism by which an OAuth client identifies itself with a URL, used as its client ID, that points to its metadata document. - [Term: Claims register](https://aigovernanceengineer.com/glossary/claims-register): The record of every public statement about an AI system's accuracy, fairness, safety or capability: the exact wording, where it appears, and the eval run, measured value, interval and population… - [Term: Classification decision record](https://aigovernanceengineer.com/glossary/classification-decision-record): A versioned registry record of why a system sits on a given rung of the AI Act risk ladder: the Annex III point, any Article 6(3) condition relied on, an explicit profiling flag, the reviewer and… - [Term: Common specifications](https://aigovernanceengineer.com/glossary/common-specifications): Technical specifications the Commission may adopt by implementing act under AI Act Article 41 when a standardisation request is not accepted, the standards are late or they insufficiently address… - [Term: Concept drift](https://aigovernanceengineer.com/glossary/concept-drift): A change in the relationship between a system's inputs and the correct output, so the same input should now get a different answer. - [Term: Conformal prediction](https://aigovernanceengineer.com/glossary/conformal-prediction): A distribution-free method that turns a trained model's output into a set of candidate answers that contains the right one with a chosen probability. - [Term: Conformity assessment](https://aigovernanceengineer.com/glossary/conformity-assessment): The procedure by which a provider shows a high-risk AI system meets the EU AI Act before placing it on the market: internal control for most Annex III systems, a notified body for some biometric… - [Term: Content provenance (C2PA)](https://aigovernanceengineer.com/glossary/content-provenance-c2pa): Signed, tamper-evident information about where a piece of content came from and how it was edited, bound to the asset. - [Term: Contest path](https://aigovernanceengineer.com/glossary/contest-path): The route by which a person affected by an automated decision reaches a reviewer who did not take the original decision, sees the inputs, the reasons and the person's representations, and can change… - [Term: Contestability](https://aigovernanceengineer.com/glossary/contestability): The ability of a person affected by an AI-supported decision to challenge it and obtain a response that can change it. - [Term: Continuous assurance](https://aigovernanceengineer.com/glossary/continuous-assurance): Assurance produced continuously from telemetry rather than at a point in time; the control's status is a live query, not an annual sign-off. - [Term: Contributing factor](https://aigovernanceengineer.com/glossary/contributing-factor): A property of a system or its context (autonomy, exposure, reversibility, vulnerable groups, data sensitivity, opacity) that moves the likelihood or severity of a risk without creating it. - [Term: Controller and processor](https://aigovernanceengineer.com/glossary/controller-and-processor): Under the GDPR the controller decides the purposes and means of processing and carries most duties; the processor acts on its documented instructions. - [Term: Counterfactual explanation](https://aigovernanceengineer.com/glossary/counterfactual-explanation): An explanation that states the smallest change to the input that would have changed the outcome, restricted to features the person can actually change. - [Term: Counterfactual fairness](https://aigovernanceengineer.com/glossary/counterfactual-fairness): The requirement that a decision about an individual be the same in a counterfactual world where the individual belonged to a different group, defined through a causal model; approximated in practice… - [Term: Counterfactual flip test](https://aigovernanceengineer.com/glossary/counterfactual-flip-test): A test that changes only a protected attribute in an input, or swaps identity terms in otherwise identical prompts, and measures how often the outcome or the answer quality changes. - [Term: Data card](https://aigovernanceengineer.com/glossary/data-card): Structured, versioned documentation of a dataset (provenance, lawful basis, rights, composition and known limitations) maintained as code alongside the system. - [Term: Data drift](https://aigovernanceengineer.com/glossary/data-drift): A change in the distribution of the inputs a system sees in production relative to the data it was validated on, such as a new customer segment or a changed upstream form. - [Term: Data lineage](https://aigovernanceengineer.com/glossary/data-lineage): The record of how data moved and changed through an organisation's pipelines. - [Term: Data minimisation](https://aigovernanceengineer.com/glossary/data-minimisation): The GDPR principle that personal data must be adequate, relevant and limited to what the purpose needs. - [Term: Data provenance](https://aigovernanceengineer.com/glossary/data-provenance): Information about the entities, activities and people involved in producing data, used to judge its quality and trustworthiness. - [Term: Dataset admission gate](https://aigovernanceengineer.com/glossary/dataset-admission-gate): A pipeline control that lets a training job read only datasets whose admission record is complete and signed by the data owner: lawful basis or licence, reservation checks, quality results… - [Term: Datasheet for datasets](https://aigovernanceengineer.com/glossary/datasheet-for-datasets): Documentation that accompanies a dataset with its motivation, composition, collection process, preprocessing, uses, distribution and maintenance, as proposed by Gebru and colleagues; the… - [Term: Decision notice](https://aigovernanceengineer.com/glossary/decision-notice): The notice a person receives at the point of an automated or AI-assisted decision, rendered from a versioned template and the decision record: that a system was used, the principal reasons and what… - [Term: Decision threshold](https://aigovernanceengineer.com/glossary/decision-threshold): The score above or below which an AI output triggers an action. - [Term: Decommissioning](https://aigovernanceengineer.com/glossary/decommissioning): The planned retirement of an AI system: dependency analysis, fallback and transition, sunset notices, a final evidence snapshot, archive or disposal of weights and data, revocation of every… - [Term: Deepfake](https://aigovernanceengineer.com/glossary/deepfake): Under the EU AI Act, a deep fake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a… - [Term: Delegation (OAuth token exchange)](https://aigovernanceengineer.com/glossary/delegation-oauth-token-exchange): In RFC 8693, the mode in which one party acts for another while both stay identifiable: the token names the subject and, in its act claim, the current actor, with nested act claims for earlier actors. - [Term: Delegation chain](https://aigovernanceengineer.com/glossary/delegation-chain): The sequence of agents a task passes through from the person or system that started it. - [Term: Demographic parity](https://aigovernanceengineer.com/glossary/demographic-parity): A group fairness criterion that holds when the rate of positive decisions is equal across groups; the adverse-impact ratio is its ratio form. - [Term: Deployer](https://aigovernanceengineer.com/glossary/deployer): Under the EU AI Act, whoever uses an AI system under its own authority, other than in a purely personal, non-professional activity. - [Term: Deployment Decision Record (DDR)](https://aigovernanceengineer.com/glossary/deployment-decision-record-ddr): The artefact that records the decision to deploy an AI system: objective, the people it acts on, negative space, risk tier and obligations, per-group performance floors, retirement conditions, owner… - [Term: Design defect](https://aigovernanceengineer.com/glossary/design-defect): In product liability, a defect inherent in the design of every unit, judged by consumer expectations or by weighing risk against utility. - [Term: Differential privacy](https://aigovernanceengineer.com/glossary/differential-privacy): A mathematical guarantee that bounds how much any single person's record can change the output of an analysis or a trained model, tuned by a privacy budget. - [Term: Digital Omnibus](https://aigovernanceengineer.com/glossary/digital-omnibus): The 2026 reform package amending the EU AI Act (in force 27 Jul 2026), which adjusted the high-risk timeline, added AI Office investigation powers and reworked several articles. - [Term: Disparate impact](https://aigovernanceengineer.com/glossary/disparate-impact): A facially neutral practice that falls harder on a protected group. - [Term: Disparate treatment](https://aigovernanceengineer.com/glossary/disparate-treatment): Treating a person less favourably because of a protected characteristic such as race, sex or age, including through a feature or rule that deliberately stands in for it. - [Term: Distributor](https://aigovernanceengineer.com/glossary/distributor): Under the EU AI Act, a person in the supply chain, other than the provider or the importer, who makes an AI system available on the Union market. - [Term: Domestic representative (Korea)](https://aigovernanceengineer.com/glossary/domestic-representative-korea): A person with an address or office in Korea whom a foreign AI business operator above thresholds set by decree must designate in writing. - [Term: Downstream modifier (GPAI)](https://aigovernanceengineer.com/glossary/downstream-modifier-gpai): An actor that fine-tunes or modifies another provider's general-purpose AI model. - [Term: Downstream provider](https://aigovernanceengineer.com/glossary/downstream-provider): Under the EU AI Act, the provider of an AI system that integrates an AI model, its own or one supplied by another entity. - [Term: Downstream use register](https://aigovernanceengineer.com/glossary/downstream-use-register): The record of every consumer of an AI system's outputs (a system, team, partner or training pipeline), each with its approved use, the re-test that cleared the outputs for that context and any… - [Term: DPIA](https://aigovernanceengineer.com/glossary/dpia): Data Protection Impact Assessment: the GDPR Article 35 assessment of processing likely to result in high risk to individuals, maintained in this discipline as a versioned artefact, not a one-off… - [Term: Drift](https://aigovernanceengineer.com/glossary/drift): The gradual divergence of a model's inputs, outputs or performance from its validated baseline over time; a runtime signal that a control or eval must catch. - [Term: Dual use](https://aigovernanceengineer.com/glossary/dual-use): The capacity of the same AI capability to serve harmful ends as well as legitimate ones, for example a toxicity model inverted to propose toxic molecules. - [Term: Duty holder](https://aigovernanceengineer.com/glossary/duty-holder): Who an obligation legally binds (under the EU AI Act, the provider, the deployer or both), as distinct from who enforces it; chapter 08 carries a duty-holder column so an engineer can tell which… - [Term: Effective challenge](https://aigovernanceengineer.com/glossary/effective-challenge): Critical analysis of a model by objective experts with the expertise, independence and organisational standing to force change. - [Term: EN 18286](https://aigovernanceengineer.com/glossary/en-18286): The European standard for the AI Act's Article 17 quality management system, published by CEN-CENELEC in July 2026 (the first JTC 21 AI Act standard to reach publication), but not yet cited in the… - [Term: Equalised odds](https://aigovernanceengineer.com/glossary/equalised-odds): A group fairness criterion that holds when true-positive and false-positive rates are both equal across groups; equal opportunity is the weaker version that equalises only true-positive rates. - [Term: EU declaration of conformity](https://aigovernanceengineer.com/glossary/eu-declaration-of-conformity): The provider's signed statement, following AI Act Annex V, that a high-risk AI system meets the Act's requirements; drawn up after the conformity assessment and kept for 10 years. - [Term: Eval gate](https://aigovernanceengineer.com/glossary/eval-gate): A pipeline stage that fails the build when an eval fails; the mechanism that turns an evaluation into an enforced control rather than a report. - [Term: Evals](https://aigovernanceengineer.com/glossary/evals): Automated tests of a model's or agent's behaviour (capability, safety and adversarial), run as controls, not as one-off research. - [Term: Evals as evidence](https://aigovernanceengineer.com/glossary/evals-as-evidence): The principle that the eval run is the assurance evidence: a failing eval blocks the build and its structured result is stored as proof the control fired. - [Term: Evidence record](https://aigovernanceengineer.com/glossary/evidence-record): The signed, structured record a control writes each time it decides: which control, about which system version, what it decided, against which metric, threshold and obligation, on which input, when… - [Term: Exception register](https://aigovernanceengineer.com/glossary/exception-register): A version-controlled list of approved exceptions, each tied to one rule and one system, with justification, compensating controls, approver and expiry. - [Term: Explainability](https://aigovernanceengineer.com/glossary/explainability): In NIST's framing, a representation of the mechanisms behind a system's operation: how a decision was made. - [Term: Explanation record](https://aigovernanceengineer.com/glossary/explanation-record): The evidence artefact for one explained decision: model version, explanation method and version, baseline, reason codes, counterfactual, template, audience and delivery, written at decision time so… - [Term: Failure posture](https://aigovernanceengineer.com/glossary/failure-posture): What a guardrail, guardian agent or tool gateway does when it cannot reach a decision: fail open lets the call through, fail closed blocks it. - [Term: Failure to warn](https://aigovernanceengineer.com/glossary/failure-to-warn): In product liability, a defect in instructions or warnings about non-obvious dangers. - [Term: Fair use](https://aigovernanceengineer.com/glossary/fair-use): The US copyright defence that weighs four factors: purpose and transformativeness, nature of the work, amount used and market effect. - [Term: Fairness](https://aigovernanceengineer.com/glossary/fairness): The property that a system's outcomes and errors do not unjustifiably disadvantage people or groups. - [Term: Fairness gerrymandering](https://aigovernanceengineer.com/glossary/fairness-gerrymandering): The failure in which a model satisfies a fairness constraint on each predefined group but violates it on subgroups defined by combinations of attributes; the reason intersectional testing is needed. - [Term: Fairness policy](https://aigovernanceengineer.com/glossary/fairness-policy): The per-system record, fixed before results are seen, of what fairness means for that system: the protected attributes in each jurisdiction and where their values come from, the chosen metric and… - [Term: Federated learning](https://aigovernanceengineer.com/glossary/federated-learning): Training a model across devices or sites where the data lives, sharing model updates instead of raw records. - [Term: Fine-tuning](https://aigovernanceengineer.com/glossary/fine-tuning): Further training of an existing model on new data to adapt it to a task or domain. - [Term: Foundation model](https://aigovernanceengineer.com/glossary/foundation-model): A model trained on broad data at scale and adaptable to a wide range of downstream tasks. - [Term: Four-fifths rule](https://aigovernanceengineer.com/glossary/four-fifths-rule): The US Uniform Guidelines rule of thumb that a group selection rate below 80% of the highest group's rate will generally be regarded as evidence of adverse impact, qualified by statistical and… - [Term: Framework Convention on AI (CETS No. 225)](https://aigovernanceengineer.com/glossary/framework-convention-on-ai-cets-no-225): The Council of Europe's treaty on AI and human rights, democracy and the rule of law, opened for signature in September 2024. - [Term: Framework crosswalk](https://aigovernanceengineer.com/glossary/framework-crosswalk): A mapping of one framework's controls onto another's; useful as an index, but a crosswalk proves you read the framework, not that the mapped control fires. - [Term: FRIA](https://aigovernanceengineer.com/glossary/fria): Fundamental Rights Impact Assessment: the AI Act Article 27 assessment of a high-risk system's impact on rights, maintained here as a versioned, reviewable artefact. - [Term: Frontier model](https://aigovernanceengineer.com/glossary/frontier-model): A general-purpose model at or near the capability frontier. - [Term: Fulfilment record](https://aigovernanceengineer.com/glossary/fulfilment-record): The per-request record of how a data-subject request was honoured wherever the person's data sits, from source systems, snapshots, retrieval indexes, logs and eval sets to model weights: the action… - [Term: Function creep](https://aigovernanceengineer.com/glossary/function-creep): The gradual reuse of personal data or an AI system for purposes nobody approved, usually by configuration rather than a new release. - [Term: Generative AI](https://aigovernanceengineer.com/glossary/generative-ai): AI that outputs new content (text, images, audio, video, code) rather than an estimate about something that exists. - [Term: Go/no-go decision](https://aigovernanceengineer.com/glossary/go-no-go-decision): The signed release decision for one system version, taken by named reviewer roles against a checklist whose items each link the record that answers them. - [Term: Governance-as-code](https://aigovernanceengineer.com/glossary/governance-as-code): Governance rules expressed as executable code that evaluates pull requests, deployments and runtime calls and returns a decision; the umbrella term of which policy-as-code is the CI/CD subset. - [Term: GPAI](https://aigovernanceengineer.com/glossary/gpai): General-purpose AI model: under the AI Act, a model that shows significant generality, can competently perform a wide range of distinct tasks and can be integrated into many downstream systems. - [Term: GPAI Code of Practice](https://aigovernanceengineer.com/glossary/gpai-code-of-practice): The voluntary instrument (published 10 July 2025) that general-purpose-AI providers use to demonstrate compliance with their AI Act obligations until harmonised standards exist; three chapters… - [Term: Graduated degradation](https://aigovernanceengineer.com/glossary/graduated-degradation): Pre-built, tested operating modes short of switching an AI system off: advice-only, raised confidence thresholds, grounded-only answers, disabling for one group, language or region, and a return to… - [Term: Guardian agent](https://aigovernanceengineer.com/glossary/guardian-agent): An AI agent whose job is to supervise, check or constrain other agents at runtime; Gartner predicts guardian-agent technologies will account for at least 10 to 15% of agentic AI markets by 2030. - [Term: Guardrail](https://aigovernanceengineer.com/glossary/guardrail): A runtime control that inspects or mediates a model's or agent's inputs, outputs or tool calls and blocks, rewrites or escalates what breaks a policy, logging each decision as evidence. - [Term: Hallucination](https://aigovernanceengineer.com/glossary/hallucination): Generative output that is stated confidently but is false or unsupported by its sources; NIST's generative AI profile calls it confabulation and lists it among the risks generative AI creates or… - [Term: Harmonised standard](https://aigovernanceengineer.com/glossary/harmonised-standard): A European standard adopted on a Commission standardisation request. - [Term: Harmonized Structure (ISO)](https://aigovernanceengineer.com/glossary/harmonized-structure-iso): The common clause layout and core text shared by ISO management-system standards such as ISO/IEC 42001, 27001 and 27701 and ISO 9001, which lets one integrated management system meet several of them. - [Term: Hidden Context Exposure](https://aigovernanceengineer.com/glossary/hidden-context-exposure): LLM08:2026 in the OWASP LLM Top 10, which replaced System Prompt Leakage: extracting, inferring or reconstructing the hidden context a model sees, such as system prompts, developer instructions… - [Term: High-impact AI (Korea)](https://aigovernanceengineer.com/glossary/high-impact-ai-korea): Under Korea's AI Basic Act, an AI system that may significantly affect life, physical safety or fundamental rights and is used in a listed area such as health care, hiring and loan screening… - [Term: High-risk AI system](https://aigovernanceengineer.com/glossary/high-risk-ai-system): Under the EU AI Act, an AI system that is a safety component of, or itself, a product under Annex I legislation needing third-party conformity assessment, or that is used in an Annex III area… - [Term: Hiroshima Code of Conduct](https://aigovernanceengineer.com/glossary/hiroshima-code-of-conduct): The G7's voluntary International Code of Conduct for Organizations Developing Advanced AI Systems (October 2023): 11 actions covering lifecycle risk evaluation, post-deployment monitoring, public… - [Term: Holding statement](https://aigovernanceengineer.com/glossary/holding-statement): A short public statement prepared in skeleton before any incident: what happened as far as it is known, what has been done to contain it, what affected people should do, and when the next update… - [Term: HUDERIA](https://aigovernanceengineer.com/glossary/huderia): The Council of Europe's non-binding methodology for assessing the risks and impacts of AI systems on human rights, democracy and the rule of law. - [Term: Human oversight](https://aigovernanceengineer.com/glossary/human-oversight): The measures that let natural persons understand, monitor and, when needed, override or stop a high-risk AI system, required by AI Act Article 14, including awareness of automation bias and a way to… - [Term: Human-in-command (HIC)](https://aigovernanceengineer.com/glossary/human-in-command-hic): The oversight mode, named by the EU High-Level Expert Group, in which people oversee the overall activity of an AI system and decide when and whether to use it in a given situation. - [Term: Human-in-the-loop (HITL)](https://aigovernanceengineer.com/glossary/human-in-the-loop-hitl): The oversight mode in which a person can intervene in every decision cycle of an AI system; in engineering terms, a gate that holds each consequential action until a named approver decides, logging… - [Term: Human-on-the-loop (HOTL)](https://aigovernanceengineer.com/glossary/human-on-the-loop-hotl): The oversight mode in which a person can intervene in the design cycle and monitors the system's operation, rather than approving each decision. - [Term: Implicit deny](https://aigovernanceengineer.com/glossary/implicit-deny): The authorisation rule that a request no policy explicitly permits is refused. - [Term: Importer](https://aigovernanceengineer.com/glossary/importer): Under the EU AI Act, a person established in the Union who places on the market an AI system bearing the name or trademark of a provider established outside the Union. - [Term: Indirect discrimination](https://aigovernanceengineer.com/glossary/indirect-discrimination): The EU counterpart of disparate impact: an apparently neutral criterion that puts a protected group at a particular disadvantage, unlawful unless objectively justified by a legitimate aim pursued by… - [Term: Inference (AI Act sense)](https://aigovernanceengineer.com/glossary/inference-ai-act-sense): The capability to derive outputs from input by learning from data or reasoning over encoded knowledge, rather than by executing rules people wrote. - [Term: Inferred sensitive data](https://aigovernanceengineer.com/glossary/inferred-sensitive-data): Sensitive information a system derives from ordinary inputs (health from purchases, beliefs from behaviour) or carries through a proxy feature. - [Term: Inherent risk](https://aigovernanceengineer.com/glossary/inherent-risk): The likelihood and severity rating of a risk scenario before any control is counted. - [Term: Instructions for use](https://aigovernanceengineer.com/glossary/instructions-for-use): The information a provider of a high-risk AI system must give deployers: intended purpose, declared accuracy and robustness, known risks, how to read the output, human oversight measures… - [Term: Intended purpose](https://aigovernanceengineer.com/glossary/intended-purpose): The use for which the provider intends an AI system, including its specific context and conditions of use. - [Term: Internal reporting channel](https://aigovernanceengineer.com/glossary/internal-reporting-channel): A confidential route for staff and contractors to raise concerns about AI systems outside the chain of command, with statutory clocks encoded (under the EU Whistleblower Directive, acknowledgment… - [Term: Interpretability](https://aigovernanceengineer.com/glossary/interpretability): In NIST's framing, the meaning of a system's output in the context of its purpose: why a decision was made and what it means to the user. - [Term: ISO/IEC 22989](https://aigovernanceengineer.com/glossary/iso-iec-22989): The ISO/IEC standard (2022) that establishes AI concepts and terminology for use by other standards and by diverse stakeholders. - [Term: ISO/IEC 42001](https://aigovernanceengineer.com/glossary/iso-iec-42001): The ISO/IEC standard (2023) that specifies requirements for an AI management system, certifiable by accredited bodies. - [Term: ISO/IEC 42005](https://aigovernanceengineer.com/glossary/iso-iec-42005): ISO/IEC 42005:2025, the AI system impact-assessment standard (a companion to the AI Act's Article 27 FRIA and to ISO/IEC 42001 Annex A.5), giving a structured method for assessing an AI system's… - [Term: Issue (versus incident)](https://aigovernanceengineer.com/glossary/issue-versus-incident): A defect, deviation or control weakness that has not produced a harmful event, such as an eval regression in staging or a drift alert. - [Term: Jailbreak](https://aigovernanceengineer.com/glossary/jailbreak): A prompt crafted to make a model disregard its safety instructions entirely. - [Term: JSON Schema](https://aigovernanceengineer.com/glossary/json-schema): A vocabulary for describing the structure of JSON documents so a validator can check them: which fields exist, which are required, their types and allowed values. - [Term: Justification memo](https://aigovernanceengineer.com/glossary/justification-memo): The intake record for an AI use case: the problem, the non-AI alternative, the measurable benefit, who bears errors and how they contest them, reversibility and kill criteria. - [Term: Key risk indicator (KRI)](https://aigovernanceengineer.com/glossary/key-risk-indicator-kri): A metric that shows whether a risk is moving towards the edge of appetite (unregistered AI found, open exceptions by age, override rates), as distinct from a key performance indicator, which shows… - [Term: Kill switch](https://aigovernanceengineer.com/glossary/kill-switch): A tested mechanism to stop an agent or system from acting; a precondition of granting autonomy, registered against the agent's identity. - [Term: Large language model (LLM)](https://aigovernanceengineer.com/glossary/large-language-model-llm): A foundation model for language, usually served from a data centre behind an API. - [Term: Latent disclosure](https://aigovernanceengineer.com/glossary/latent-disclosure): Under California's AI Transparency Act, provenance information embedded in AI-generated image, video or audio so that it persists and can be read by a detection tool, as opposed to a visible label… - [Term: Lawful basis](https://aigovernanceengineer.com/glossary/lawful-basis): One of the six grounds in GDPR Article 6 that make processing of personal data lawful: consent, contract, legal obligation, vital interests, public task and legitimate interests. - [Term: Least agency](https://aigovernanceengineer.com/glossary/least-agency): The principle, in the OWASP agentic list, of giving an agent no more autonomy than its task needs: agentic behaviour deployed where it is not needed widens the attack surface without adding value. - [Term: Legitimate-interest assessment (LIA)](https://aigovernanceengineer.com/glossary/legitimate-interest-assessment-lia): The documented three-step test for relying on legitimate interests: a lawful, precise and present interest; processing necessary for it; and a balance not overridden by people's rights and… - [Term: LIME](https://aigovernanceengineer.com/glossary/lime): Local Interpretable Model-agnostic Explanations: explains one prediction by fitting a simple interpretable model to the black box's behaviour on perturbed samples around the input; vulnerable to… - [Term: Localisation (by jurisdiction)](https://aigovernanceengineer.com/glossary/localisation-by-jurisdiction): Controlling where an AI system runs and which features it offers in each jurisdiction, with per-jurisdiction rule sets as code, regional instances where residency requires them and feature flags by… - [Term: Loss of control](https://aigovernanceengineer.com/glossary/loss-of-control): One of the systemic risks the GPAI Code of Practice specifies: risks from humans losing the ability to reliably direct, modify or shut down a model, which may emerge from misalignment… - [Term: Machine learning](https://aigovernanceengineer.com/glossary/machine-learning): The branch of AI in which a system improves at a task by learning patterns from data rather than by following rules people wrote. - [Term: Machine unlearning](https://aigovernanceengineer.com/glossary/machine-unlearning): Techniques that remove a training record's influence from a model without full retraining. - [Term: Machine-readable evidence](https://aigovernanceengineer.com/glossary/machine-readable-evidence): Evidence a machine can query, diff and aggregate (OSCAL artefacts, structured eval results, signed logs), as opposed to screenshots and exported spreadsheets. - [Term: Major ICT-related incident (DORA)](https://aigovernanceengineer.com/glossary/major-ict-related-incident-dora): Under the EU Digital Operational Resilience Act, an ICT-related incident at a financial entity that meets the classification criteria for a major incident. - [Term: Manufacturing defect](https://aigovernanceengineer.com/glossary/manufacturing-defect): In product liability, a departure of a unit from its own design. - [Term: Market surveillance authority](https://aigovernanceengineer.com/glossary/market-surveillance-authority): The national authority designated to enforce the AI Act for products placed on its market, with powers to investigate, demand documentation and require corrective action. - [Term: Maturity floor](https://aigovernanceengineer.com/glossary/maturity-floor): The single overall maturity level of an AI governance function: the level of its weakest stack layer. - [Term: MCP](https://aigovernanceengineer.com/glossary/mcp): Model Context Protocol: an open protocol for connecting AI applications to tools and data sources; its 2026 specification adds OAuth 2.1 resource-server patterns and issuer-bound credentials for… - [Term: Membership inference](https://aigovernanceengineer.com/glossary/membership-inference): An attack that determines whether a specific person's record was in a model's training set from the model's behaviour. - [Term: Memory poisoning](https://aigovernanceengineer.com/glossary/memory-poisoning): An injection that writes to an agent's long-term memory, a retrieval corpus, a vector store or a hosted memory service, and so taints every later session that reads from that store. - [Term: Mitigation hierarchy](https://aigovernanceengineer.com/glossary/mitigation-hierarchy): The order in which risk treatments are tried: eliminate, substitute, engineer, administrative, then accept and monitor. - [Term: Model anonymity](https://aigovernanceengineer.com/glossary/model-anonymity): The EDPB's test for when a trained model falls outside the GDPR: both direct extraction of training subjects' data and obtaining it through queries must be insignificant, given all means reasonably… - [Term: Model card](https://aigovernanceengineer.com/glossary/model-card): Structured, versioned documentation of a model (provenance, intended use, capabilities, evaluations and known failure modes) maintained as code. - [Term: Model inversion](https://aigovernanceengineer.com/glossary/model-inversion): An attack that reconstructs features of training subjects, such as a face, from a model's outputs and confidence scores. - [Term: Model risk management](https://aigovernanceengineer.com/glossary/model-risk-management): The banking-supervision practice of validating models for conceptual soundness, monitoring and outcomes analysis under effective challenge. - [Term: Model signing](https://aigovernanceengineer.com/glossary/model-signing): Signing a model's files at build: a manifest lists every file with its cryptographic digest and a detached signature covers the manifest, so any changed file fails verification. - [Term: Multimodal model](https://aigovernanceengineer.com/glossary/multimodal-model): A model that takes or produces more than one modality (text, image, audio, video). - [Term: Near miss](https://aigovernanceengineer.com/glossary/near-miss): A hazard that a control, or luck, interrupted before harm occurred: the guardrail blocked the exfiltration, the reviewer caught the invented dosage. - [Term: Negative space](https://aigovernanceengineer.com/glossary/negative-space): The uses an AI system is explicitly not for, written into its Deployment Decision Record. - [Term: Neural data](https://aigovernanceengineer.com/glossary/neural-data): Information generated by measuring the activity of a person's central or peripheral nervous system. - [Term: NHI](https://aigovernanceengineer.com/glossary/nhi): Non-human identity: the identity of an agent, service account or machine actor. - [Term: NIST AI RMF](https://aigovernanceengineer.com/glossary/nist-ai-rmf): The NIST Artificial Intelligence Risk Management Framework 1.0 (NIST AI 100-1, January 2023): voluntary guidance organised as a Core of four functions (Govern, Map, Measure, Manage) with categories… - [Term: Notified body](https://aigovernanceengineer.com/glossary/notified-body): A conformity assessment body designated under the EU AI Act to carry out third-party conformity assessment of high-risk AI systems. - [Term: OECD AI Principles](https://aigovernanceengineer.com/glossary/oecd-ai-principles): The five values-based principles (inclusive growth and well-being; human rights, fairness and privacy; transparency and explainability; robustness, security and safety; accountability) and five… - [Term: OECD Framework for the Classification of AI Systems](https://aigovernanceengineer.com/glossary/oecd-framework-for-the-classification-of-ai-systems): An OECD tool (2022) for characterising an AI system from a policy perspective along five dimensions: People & Planet, Economic Context, Data & Input, AI Model, and Task & Output. - [Term: OPA/Rego](https://aigovernanceengineer.com/glossary/opa-rego): The Open Policy Agent and its Rego policy language, a general-purpose policy-as-code engine that evaluates governance rules in CI/CD and at runtime admission; the canonical example of executable… - [Term: Opacity](https://aigovernanceengineer.com/glossary/opacity): The inability of a person to follow how a system reached an output. - [Term: Open-weight model](https://aigovernanceengineer.com/glossary/open-weight-model): A model whose trained weights are published for download under a licence that may be permissive, copyleft, use-restricted or custom. - [Term: Operator (EU AI Act)](https://aigovernanceengineer.com/glossary/operator-eu-ai-act): The umbrella term for the actors the AI Act binds: provider, product manufacturer, deployer, authorised representative, importer and distributor. - [Term: OSCAL](https://aigovernanceengineer.com/glossary/oscal): The Open Security Controls Assessment Language, a NIST machine-readable format for controls, assessments and evidence, used here as the format for audit-ready evidence. - [Term: Output suppression](https://aigovernanceengineer.com/glossary/output-suppression): A filter around a model that stops it producing a person's data: the fast first answer to an erasure or objection request when the data sits in the weights and retraining is disproportionate. - [Term: Paved path](https://aigovernanceengineer.com/glossary/paved-path): A supported, low-friction default route (a template, library or pipeline) that makes the governed way the easiest way to ship, so engineers adopt governance without asking permission. - [Term: Personal data breach](https://aigovernanceengineer.com/glossary/personal-data-breach): A breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, notified to the authority within 72 hours unless… - [Term: PIPIA](https://aigovernanceengineer.com/glossary/pipia): China's personal information protection impact assessment under PIPL Articles 55 and 56, required in advance for sensitive data, automated decision-making, entrusted processing and cross-border… - [Term: Placing on the market](https://aigovernanceengineer.com/glossary/placing-on-the-market): Under the EU AI Act, the first making available of an AI system or general-purpose AI model on the Union market; later supplies in the course of a commercial activity are making available. - [Term: Policy Card](https://aigovernanceengineer.com/glossary/policy-card): A JSON-schema, machine-readable governance artefact that declares an agent's allowed and forbidden behaviours for runtime enforcement. - [Term: Policy verdict](https://aigovernanceengineer.com/glossary/policy-verdict): The structured record a policy engine emits each time it evaluates a rule: allow or deny, the versioned rule id, a hash of the input and a timestamp, signed and written to the evidence store. - [Term: Policy-as-code](https://aigovernanceengineer.com/glossary/policy-as-code): Governance policy expressed in an executable policy language (OPA/Rego, Cedar) that evaluates in CI/CD and at admission; the narrower, pipeline subset of governance-as-code. - [Term: Post-market monitoring](https://aigovernanceengineer.com/glossary/post-market-monitoring): The AI Act Article 72 duty to actively monitor a high-risk system's performance and risks after deployment, throughout its lifetime. - [Term: Pre-determined changes](https://aigovernanceengineer.com/glossary/pre-determined-changes): Changes to a high-risk system that continues to learn, planned by the provider at the initial conformity assessment and described in the technical documentation; they are not substantial… - [Term: Predictive AI](https://aigovernanceengineer.com/glossary/predictive-ai): AI that outputs an estimate about something that exists: a score, class or forecast. - [Term: Presumption of conformity](https://aigovernanceengineer.com/glossary/presumption-of-conformity): The legal effect under AI Act Article 40: a high-risk system or GPAI model that conforms with OJ-cited harmonised standards is presumed to meet the requirements those standards cover, and no others. - [Term: Privacy by design and by default](https://aigovernanceengineer.com/glossary/privacy-by-design-and-by-default): The GDPR Article 25 duty to build data protection principles into processing through technical and organisational measures, and to process by default only the personal data each purpose needs. - [Term: Privacy-enhancing technology (PET)](https://aigovernanceengineer.com/glossary/privacy-enhancing-technology-pet): A technique that reduces what an attacker, vendor or insider can learn from personal data, such as differential privacy, federated learning, synthetic data, masking or trusted execution. - [Term: Product Liability Directive (PLD)](https://aigovernanceengineer.com/glossary/product-liability-directive-pld): Directive (EU) 2024/2853, which treats software, including AI, as a product; judges defect with learning and updates in view; lets courts order disclosure and presume defect; and applies to products… - [Term: Profiling override](https://aigovernanceengineer.com/glossary/profiling-override): The rule in the third subparagraph of AI Act Article 6(3) that an Annex III system which performs profiling of natural persons is always high-risk, whichever filter condition it meets. - [Term: Progressive delivery](https://aigovernanceengineer.com/glossary/progressive-delivery): Releasing a change to a small, growing share of real traffic in stages (shadow, pilot, canary, general availability), each with rollback criteria registered before it starts and a tested path back… - [Term: Prohibited practice](https://aigovernanceengineer.com/glossary/prohibited-practice): An AI practice banned outright by AI Act Article 5, such as manipulative techniques that cause significant harm, social scoring, untargeted scraping of facial images, emotion recognition at work or… - [Term: Prompt injection](https://aigovernanceengineer.com/glossary/prompt-injection): An input that alters a model's behaviour or output in ways its designers did not intend. - [Term: Proportionate governance](https://aigovernanceengineer.com/glossary/proportionate-governance): Running the same risk loop at an intensity set by organisation size, sector, maturity and risk tolerance, above a floor of controls that never tailors away. - [Term: Provider](https://aigovernanceengineer.com/glossary/provider): Under the EU AI Act, whoever develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for… - [Term: Proxy label](https://aigovernanceengineer.com/glossary/proxy-label): A training target that stands in for the construct a decision is meant to capture, such as health-care cost standing in for health need. - [Term: Proxy scan](https://aigovernanceengineer.com/glossary/proxy-scan): A test that trains a model to predict a protected attribute from a system's features; features that predict it strongly are flagged as proxies to justify or remove, and the result is recorded in the… - [Term: Proxy variable](https://aigovernanceengineer.com/glossary/proxy-variable): A feature that carries the information of a protected characteristic, such as postcode for ethnicity, so that a model can discriminate without using the attribute itself. - [Term: Pseudonymisation](https://aigovernanceengineer.com/glossary/pseudonymisation): Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected. - [Term: Purpose limitation](https://aigovernanceengineer.com/glossary/purpose-limitation): The GDPR principle that personal data collected for a specified purpose may not be further processed in an incompatible way; Article 6(4) sets the compatibility test. - [Term: Putting into service](https://aigovernanceengineer.com/glossary/putting-into-service): Under the EU AI Act, the supply of an AI system for first use directly to the deployer, or for the provider's own use, in the Union for its intended purpose. - [Term: QMS (Art. 17)](https://aigovernanceengineer.com/glossary/qms-art-17): The quality management system that AI Act Article 17 requires of high-risk providers; distinct from an ISO/IEC 42001 AIMS, which certifies a management system but is not harmonised. - [Term: RAISE Act](https://aigovernanceengineer.com/glossary/raise-act): New York's Responsible AI Safety and Education Act, a frontier-AI safety law binding large frontier developers to publish a safety framework and every frontier developer to report critical safety… - [Term: Realised risk reduction](https://aigovernanceengineer.com/glossary/realised-risk-reduction): The measured drop in a named failure mode's rate or blast radius in production; one of the two tests of the discipline, against framework coverage. - [Term: Reason code](https://aigovernanceengineer.com/glossary/reason-code): A stable, human-readable statement of a principal factor behind an adverse decision, mapped from the factors the model actually scored and versioned with the model; required in substance by US… - [Term: Reasonably foreseeable misuse](https://aigovernanceengineer.com/glossary/reasonably-foreseeable-misuse): Use of an AI system not in accordance with its intended purpose that may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems. - [Term: Records of processing activities (ROPA)](https://aigovernanceengineer.com/glossary/records-of-processing-activities-ropa): The GDPR Article 30 record of each processing activity: purposes, categories of data and people, recipients, transfers, retention and security. - [Term: Recourse](https://aigovernanceengineer.com/glossary/recourse): The ability of a person to obtain a different decision by changing inputs they can actually act on, such as income rather than age. - [Term: Red teaming](https://aigovernanceengineer.com/glossary/red-teaming): Structured adversarial testing of a model or agent to elicit failures (jailbreaks, injection, tool misuse) before an attacker does; treated here as an evidence-producing control. - [Term: Regurgitation](https://aigovernanceengineer.com/glossary/regurgitation): A model reproducing memorised training data verbatim, including personal data, whether prompted deliberately (training-data extraction) or not. - [Term: Reinforcement learning](https://aigovernanceengineer.com/glossary/reinforcement-learning): Learning to maximise a reward signal through trial and feedback. - [Term: Reinforcement learning from human feedback (RLHF)](https://aigovernanceengineer.com/glossary/reinforcement-learning-from-human-feedback-rlhf): A way to align a pre-trained model: supervised fine-tuning on human demonstrations, then reinforcement learning against a reward model trained on human rankings of outputs. - [Term: Reporting clock](https://aigovernanceengineer.com/glossary/reporting-clock): A statutory deadline for an incident notification, defined by its trigger (awareness, classification, causal link or determination), recipient, content and follow-ups, as in AI Act Article 73. - [Term: Residual risk](https://aigovernanceengineer.com/glossary/residual-risk): What is left of a risk once treatment is applied. - [Term: Responsible-AI licence (OpenRAIL)](https://aigovernanceengineer.com/glossary/responsible-ai-licence-openrail): A licence that grants open, royalty-free access to an AI artefact while attaching prohibited uses that every redistribution and derivative must carry forward. - [Term: Responsible-AI principle set](https://aigovernanceengineer.com/glossary/responsible-ai-principle-set): A published set of normative targets for AI, such as the OECD AI Principles, the UNESCO Recommendation, the HLEG requirements or the G7 Hiroshima principles. - [Term: Retrieval-augmented generation (RAG)](https://aigovernanceengineer.com/glossary/retrieval-augmented-generation-rag): A system that combines a model's learned memory with a retrievable store of documents at answer time. - [Term: Reward hacking](https://aigovernanceengineer.com/glossary/reward-hacking): A system finding an unintended way to maximise its reward or objective without doing what its designers meant. - [Term: Right to explanation (AI Act Art. 86)](https://aigovernanceengineer.com/glossary/right-to-explanation-ai-act-art-86): The right of a person affected by a deployer's decision based on an Annex III high-risk system's output, with legal or similarly significant adverse effects, to clear and meaningful explanations of… - [Term: Rights reservation (TDM opt-out)](https://aigovernanceengineer.com/glossary/rights-reservation-tdm-opt-out): A rightholder's express reservation of text and data mining under Article 4(3) of the DSM Directive, which takes the content out of the general mining exception; for content made publicly available… - [Term: Risk acceptance](https://aigovernanceengineer.com/glossary/risk-acceptance): A named, signed and expiring decision by someone with the authority a residual band requires, that a risk may remain for a bounded period under named compensating controls and a monitoring signal… - [Term: Risk appetite](https://aigovernanceengineer.com/glossary/risk-appetite): How much risk, and of which kinds, an organisation is prepared to take on in pursuit of its objectives. - [Term: Risk management](https://aigovernanceengineer.com/glossary/risk-management): The organised practice of steering an organisation's decisions with its risks in view: identify, assess, treat and monitor, in a loop. - [Term: Risk matrix](https://aigovernanceengineer.com/glossary/risk-matrix): A grid that turns a likelihood rating and a severity rating, each on defined scales, into a band that triggers a treatment, a gate and a review cadence. - [Term: Risk register](https://aigovernanceengineer.com/glossary/risk-register): The evidence record of the risk loop: one versioned file per risk, keyed to a registry id, with ratings, treatment, controls that resolve to evidence, owner, acceptance, review cadence and links to… - [Term: Risk source](https://aigovernanceengineer.com/glossary/risk-source): Anything that can give rise to risk alone or in combination, such as a dataset, a tool grant, an adversary or a user group. - [Term: Risk tier](https://aigovernanceengineer.com/glossary/risk-tier): An organisation's own rating of an AI use case, computed at intake by a versioned policy from declared profile fields such as autonomy, decision impact, exposure, reversibility, vulnerable groups… - [Term: Risk tolerance](https://aigovernanceengineer.com/glossary/risk-tolerance): The readiness to bear a given risk in order to achieve objectives. - [Term: Rollback criteria](https://aigovernanceengineer.com/glossary/rollback-criteria): The conditions, written into the rollout plan before a release stage starts, under which the pipeline returns to the previous version automatically: a floor breached against the control group, a… - [Term: Root-cause analysis (RCA)](https://aigovernanceengineer.com/glossary/root-cause-analysis-rca): The review that answers why an incident happened and why the controls did not stop it, using techniques such as five whys, fault tree analysis and blameless post-mortems, and codes each confirmed… - [Term: Runtime data path](https://aigovernanceengineer.com/glossary/runtime-data-path): The live connection between production and the governance function (discovery, telemetry and enforcement), without which a registry or dashboard describes the program but cannot see what is running. - [Term: Safetensors](https://aigovernanceengineer.com/glossary/safetensors): A file format for storing a model's tensors safely, as opposed to Python pickle, whose loading can run arbitrary code and which the Python documentation calls not secure. - [Term: Safety component](https://aigovernanceengineer.com/glossary/safety-component): Under the AI Act as amended in 2026, a component of a product or AI system whose intended purpose is to prevent or mitigate risks to the health and safety of persons or property, or whose failure… - [Term: Sanctioned AI gateway](https://aigovernanceengineer.com/glossary/sanctioned-ai-gateway): The single approved route by which staff reach AI tools and model APIs: approved tools behind single sign-on and a gateway that classifies each request by data class, allows, redacts or blocks it… - [Term: SB 53](https://aigovernanceengineer.com/glossary/sb-53): California's frontier-AI transparency law (TFAIA), in force 1 Jan 2026, covering frontier developers training models above 10^26 FLOP: all of them publish transparency reports and report critical… - [Term: Self-supervised learning](https://aigovernanceengineer.com/glossary/self-supervised-learning): Learning by predicting parts of the input itself, such as the next token, over large corpora; the AI Act's definition of a general-purpose model names self-supervision at scale. - [Term: Serious incident](https://aigovernanceengineer.com/glossary/serious-incident): Under AI Act Article 3(49), an incident or malfunction of an AI system that directly or indirectly leads to (a) a death or serious harm to health, (b) serious and irreversible disruption of critical… - [Term: Shadow AI](https://aigovernanceengineer.com/glossary/shadow-ai): An AI system, model or agent running without registration, including staff use of unapproved AI tools; the failure mode that makes an inventory complete only for the honest. - [Term: Shadow deployment](https://aigovernanceengineer.com/glossary/shadow-deployment): A release stage in which a new model or system receives live inputs but its outputs are not used, so its behaviour on real traffic can be compared with the incumbent or with human decisions before… - [Term: SHAP](https://aigovernanceengineer.com/glossary/shap): SHapley Additive exPlanations: a feature-attribution method that assigns each input feature a share of a particular prediction, based on Shapley values; its explanations depend on the chosen… - [Term: Small language model (SLM)](https://aigovernanceengineer.com/glossary/small-language-model-slm): A language model small enough to run close to the user, for example on a phone. - [Term: Small mid-cap enterprise (SMC)](https://aigovernanceengineer.com/glossary/small-mid-cap-enterprise-smc): An enterprise that has outgrown the SME definition but falls within the EU small mid-cap definition. - [Term: Special category data](https://aigovernanceengineer.com/glossary/special-category-data): The GDPR Article 9 categories whose processing is prohibited unless a condition applies: data revealing racial or ethnic origin, political opinions, beliefs or union membership, and genetic… - [Term: Stakeholder mapping](https://aigovernanceengineer.com/glossary/stakeholder-mapping): Naming who is affected by or holds a view on an AI system (users, affected non-users, deployers, providers, internal functions, regulators, the governing body) and how each view enters the risk… - [Term: STAR for AI](https://aigovernanceengineer.com/glossary/star-for-ai): CSA's security assurance and certification programme for AI, built on the AICM, with a self-assessment tier, an automated "Valid-AI-ted" tier and a Level 2 combining ISO/IEC 42001 with the validated… - [Term: STRIDE](https://aigovernanceengineer.com/glossary/stride): A threat-classification checklist from Microsoft's Security Development Lifecycle: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege. - [Term: Sub-processor](https://aigovernanceengineer.com/glossary/sub-processor): A processor that another processor engages to carry out processing for a controller, such as the model host behind an AI vendor. - [Term: Substantial modification](https://aigovernanceengineer.com/glossary/substantial-modification): Under the EU AI Act, a change after placing on the market that the initial conformity assessment did not foresee and that affects compliance or changes the intended purpose. - [Term: Supervised learning](https://aigovernanceengineer.com/glossary/supervised-learning): Learning from labelled examples. - [Term: SVID](https://aigovernanceengineer.com/glossary/svid): SPIFFE Verifiable Identity Document: a short-lived cryptographic identity document, either an X.509 certificate or a JWT, that proves a workload's SPIFFE ID and is issued and rotated through the… - [Term: Synthetic data](https://aigovernanceengineer.com/glossary/synthetic-data): Data generated by a model or simulation rather than collected from people or events, used to augment training sets, test edge cases or reduce exposure of personal data. - [Term: System card](https://aigovernanceengineer.com/glossary/system-card): Documentation of a deployed AI system as a whole (models, prompts, retrieval, tools, guardrails and oversight), where a model card documents one model. - [Term: Systemic risk](https://aigovernanceengineer.com/glossary/systemic-risk): Under the AI Act, the risk posed by the most capable general-purpose AI models, triggering extra evaluation, adversarial-testing and incident-reporting duties on their providers. - [Term: Tabletop exercise](https://aigovernanceengineer.com/glossary/tabletop-exercise): A scheduled, scored rehearsal of an incident playbook against a named failure mode, producing the same records a real incident would (record, clocks, draft reports, containment events) tagged as a… - [Term: TC260](https://aigovernanceengineer.com/glossary/tc260): The National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (全国网络安全标准化技术委员会), which drafts China's cybersecurity and AI national standards (GB and GB/T) and… - [Term: TDM exception](https://aigovernanceengineer.com/glossary/tdm-exception): Two EU copyright exceptions for text and data mining (DSM Directive). - [Term: Technical documentation (Annex IV)](https://aigovernanceengineer.com/glossary/technical-documentation-annex-iv): The provider's technical file for a high-risk AI system, drawn up before placing on the market and kept up to date under Article 11: description, development process, data, testing, oversight, risk… - [Term: Test-set contamination](https://aigovernanceengineer.com/glossary/test-set-contamination): The presence of evaluation items in a model's training data, which inflates its scores; it can be demonstrated even for black-box language models. - [Term: Testing in real-world conditions](https://aigovernanceengineer.com/glossary/testing-in-real-world-conditions): Under the EU AI Act, temporary testing of an AI system for its intended purpose outside a laboratory, under a plan approved by the market surveillance authority, with registration, informed consent… - [Term: Threat model (AI)](https://aigovernanceengineer.com/glossary/threat-model-ai): A versioned record of what can go wrong with an AI system and what is done about it: data flows and trust boundaries, threats per element from STRIDE and AI-specific catalogues, a decision on each… - [Term: Three Lines Model](https://aigovernanceengineer.com/glossary/three-lines-model): The Institute of Internal Auditors' 2020 update of the "three lines of defense": the governing body oversees; management holds first-line roles (delivering products and services) and second-line… - [Term: Token passthrough](https://aigovernanceengineer.com/glossary/token-passthrough): The anti-pattern in which a server accepts a token that was not issued to it and forwards it, unmodified, to a downstream API, which may then trust it as if the server had validated it. - [Term: Tool allow-list](https://aigovernanceengineer.com/glossary/tool-allow-list): The deny-by-default list of tools an agent may call, each entry pinned by a hash of the tool's definition and bounded by resource scope, operation class, rate, egress destinations, data classes and… - [Term: Tool poisoning](https://aigovernanceengineer.com/glossary/tool-poisoning): Tampering with a tool an agent uses, through its model-visible definition (description, schema, metadata) or its behaviour, so the agent acts on false premises. - [Term: Training-content summary](https://aigovernanceengineer.com/glossary/training-content-summary): The public summary of the content used to train a general-purpose AI model, required by AI Act Article 53(1)(d) on a mandatory Commission template covering data sources, including the most-scraped… - [Term: Training, validation and testing data](https://aigovernanceengineer.com/glossary/training-validation-and-testing-data): The three data sets the AI Act defines for high-risk systems: training data fits the model, validation data tunes it and guards against overfitting, and testing data gives an independent check… - [Term: Trajectory (agent)](https://aigovernanceengineer.com/glossary/trajectory-agent): The sequence of plans, tool calls and memory operations that led an agent to an effect. - [Term: Transaction token (Txn-Token)](https://aigovernanceengineer.com/glossary/transaction-token-txn-token): A short-lived, signed token, specified in an IETF OAuth working group draft, that carries user identity, workload identity and authorisation context through a call chain within one trusted domain… - [Term: Transfer impact assessment (TIA)](https://aigovernanceengineer.com/glossary/transfer-impact-assessment-tia): The data exporter's assessment of whether the law of a third country lets the importer honour the transfer tool, such as standard contractual clauses, and which supplementary measures are needed. - [Term: Transparency](https://aigovernanceengineer.com/glossary/transparency): In NIST's framing, how far information about an AI system and its outputs reaches the people who interact with it: what happened. - [Term: Trustworthy AI](https://aigovernanceengineer.com/glossary/trustworthy-ai): A banner used by other people's frameworks, notably the EU High-Level Expert Group and NIST, whose seven trustworthy characteristics make it concrete. - [Term: Trustworthy characteristics (NIST)](https://aigovernanceengineer.com/glossary/trustworthy-characteristics-nist): The seven characteristics of trustworthy AI in the NIST AI RMF: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; fair… - [Term: UDAP](https://aigovernanceengineer.com/glossary/udap): Unfair or deceptive acts or practices, prohibited by section 5 of the FTC Act and by state laws. - [Term: Unsupervised learning](https://aigovernanceengineer.com/glossary/unsupervised-learning): Learning structure (clusters, anomalies) from data without labels. - [Term: Use-case record](https://aigovernanceengineer.com/glossary/use-case-record): The intake record for a proposed AI use: business context, intended purpose and the uses ruled out, affected persons, decision authority, success metrics and error appetite, stored as fields on the… - [Term: Version pinning](https://aigovernanceengineer.com/glossary/version-pinning): Fixing, in the registry entry, the exact versions of the model, prompts, retrieval corpus and guardrails a deployed system uses, so what ran is known and any unpinned change, including a vendor's… - [Term: Watermarking](https://aigovernanceengineer.com/glossary/watermarking): Embedding a signal in generated content (image, audio, video or text) that a detector can later read to identify it as AI-generated. - [Term: Widespread infringement](https://aigovernanceengineer.com/glossary/widespread-infringement): Under AI Act Article 3(61), an act or omission contrary to Union law protecting individuals' interests that harms, or is likely to harm, the collective interests of individuals across several Member… - [Term: Workload identity](https://aigovernanceengineer.com/glossary/workload-identity): The attributable identity a workload such as an agent carries across every hop, under which its actions are logged and its access is revoked, typically a short-lived, attested credential such as an…