AI law obligations, each with an id you can cite.
The rows of the regulatory map, one page each: the clause, who it binds, when it applies, the engineering artefact that evidences it and the stack layer that artefact lives in. The ids do not change when the wording or the dates do.
182 obligations, 76 instruments
Each id reads AIGE-OBL-<instrument>-<clause> and is never
reused. The rows come from chapter 08; the same
data is in the obligation matrix and in the open data API.
Statuses are as of each row's review date. Deferred means an amending act moved the date later (the Digital Omnibus for the EU high-risk duties); Draft or proposed means the instrument is not final.
EU AI Act
50 rows- EU AI Act Art. 3(1) AI system definition (scope of the Act)
AIGE-OBL-EUAIA-ART3-1In forceL2 - EU AI Act Art. 4 AI literacy
AIGE-OBL-EUAIA-ART4In forceL1 - EU AI Act Art. 4a lawful basis for special-category data in bias detection
AIGE-OBL-EUAIA-ART4AIn forceL2 - EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans)
AIGE-OBL-EUAIA-ART5In forceL1 L4 - EU AI Act Art. 6 classification of high-risk AI systems (incl. the Annex III route)
AIGE-OBL-EUAIA-ART6DeferredL1 L2 - EU AI Act Art. 6(3)–(4) documented non-high-risk assessment and registration
AIGE-OBL-EUAIA-ART6-3DeferredL1 L2 - EU AI Act Art. 9 risk management system
AIGE-OBL-EUAIA-ART9DeferredL1 L3 - EU AI Act Art. 10 data and data governance
AIGE-OBL-EUAIA-ART10DeferredL2 L3 - EU AI Act Art. 11 technical documentation (Annex IV)
AIGE-OBL-EUAIA-ART11DeferredL2 - EU AI Act Art. 12 record-keeping and logging
AIGE-OBL-EUAIA-ART12DeferredL4 - EU AI Act Art. 13 transparency and information to deployers
AIGE-OBL-EUAIA-ART13DeferredL2 - EU AI Act Art. 14 human oversight
AIGE-OBL-EUAIA-ART14DeferredL4 - EU AI Act Art. 15 accuracy, robustness and cybersecurity
AIGE-OBL-EUAIA-ART15DeferredL3 L4 - EU AI Act Art. 15(4) feedback loops in systems that continue to learn
AIGE-OBL-EUAIA-ART15-4DeferredL3 L4 - EU AI Act Art. 16(l) accessibility requirements for high-risk AI systems
AIGE-OBL-EUAIA-ART16-LDeferredL2 L3 - EU AI Act Art. 17 quality management system
AIGE-OBL-EUAIA-ART17DeferredL1 L5 - EU AI Act Art. 17(1)(m) accountability framework within the quality management system
AIGE-OBL-EUAIA-ART17-1MDeferredL1 L2 - EU AI Act Art. 18 documentation keeping
AIGE-OBL-EUAIA-ART18DeferredL2 L5 - EU AI Act Art. 19 automatically generated logs kept by the provider
AIGE-OBL-EUAIA-ART19DeferredL4 L5 - EU AI Act Art. 20 corrective actions and duty of information
AIGE-OBL-EUAIA-ART20DeferredL1 L5 - EU AI Act Art. 22 authorised representative of non-EU high-risk providers
AIGE-OBL-EUAIA-ART22DeferredL5 - EU AI Act Art. 23 obligations of importers
AIGE-OBL-EUAIA-ART23DeferredL2 L5 - EU AI Act Art. 24 obligations of distributors
AIGE-OBL-EUAIA-ART24DeferredL2 L5 - EU AI Act Art. 25 responsibilities along the AI value chain
AIGE-OBL-EUAIA-ART25DeferredL2 L5 - EU AI Act Art. 26 deployer obligations for high-risk systems
AIGE-OBL-EUAIA-ART26DeferredL2 L4 - EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority
AIGE-OBL-EUAIA-ART26-2DeferredL1 L4 - EU AI Act Art. 26(4) input data relevant and sufficiently representative
AIGE-OBL-EUAIA-ART26-4DeferredL2 L3 - EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider
AIGE-OBL-EUAIA-ART26-5DeferredL2 L4 L5 - EU AI Act Art. 26(6) deployer retention of automatically generated logs
AIGE-OBL-EUAIA-ART26-6DeferredL4 L5 - EU AI Act Art. 26(7) informing workers before workplace use
AIGE-OBL-EUAIA-ART26-7DeferredL2 - EU AI Act Art. 26(11) informing people subject to Annex III decisions
AIGE-OBL-EUAIA-ART26-11DeferredL2 L4 - EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA)
AIGE-OBL-EUAIA-ART27DeferredL1 L2 - EU AI Act Art. 43 conformity assessment
AIGE-OBL-EUAIA-ART43DeferredL1 L5 - EU AI Act Art. 43(4) new conformity assessment on substantial modification
AIGE-OBL-EUAIA-ART43-4DeferredL1 L5 - EU AI Act Art. 47 EU declaration of conformity
AIGE-OBL-EUAIA-ART47DeferredL2 L5 - EU AI Act Art. 48 CE marking
AIGE-OBL-EUAIA-ART48DeferredL2 L5 - EU AI Act Art. 49/71 registration of high-risk systems in the EU database
AIGE-OBL-EUAIA-ART49-71DeferredL2 - EU AI Act Art. 50 transparency for certain AI systems
AIGE-OBL-EUAIA-ART50In forceL4 L2 - EU AI Act Art. 52 notification of a GPAI model meeting the systemic-risk threshold
AIGE-OBL-EUAIA-ART52In forceL2 L5 - EU AI Act Art. 53 GPAI provider obligations
AIGE-OBL-EUAIA-ART53In forceL2 - EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations
AIGE-OBL-EUAIA-ART53-1CIn forceL1 L2 L5 - EU AI Act Art. 54 authorised representative of non-EU GPAI providers
AIGE-OBL-EUAIA-ART54In forceL5 - EU AI Act Art. 55 GPAI models with systemic risk
AIGE-OBL-EUAIA-ART55In forceL3 L4 L5 - EU AI Act Art. 60 testing in real-world conditions outside sandboxes
AIGE-OBL-EUAIA-ART60In forceL3 L4 - EU AI Act Art. 72 post-market monitoring
AIGE-OBL-EUAIA-ART72DeferredL5 - EU AI Act Art. 73 serious-incident reporting
AIGE-OBL-EUAIA-ART73DeferredL5 L4 - EU AI Act Art. 73(6) incident investigation without altering the system
AIGE-OBL-EUAIA-ART73-6DeferredL4 L5 - EU AI Act Art. 75(1a) serious incidents reported to the AI Office
AIGE-OBL-EUAIA-ART75-1ADeferredL2 L5 - EU AI Act Art. 86 right to explanation of individual decision-making
AIGE-OBL-EUAIA-ART86DeferredL2 L4 L5 - EU AI Act Art. 87 reporting of infringements and protection of reporting persons
AIGE-OBL-EUAIA-ART87In forceL1 L5
GPAI Code of Practice
5 rows- Safety and Security (systemic-risk models only)
AIGE-OBL-GPAICOP-SAFETYNo date VoluntaryL3 L4 L5 - Transparency
AIGE-OBL-GPAICOP-TRANSPARENCYNo date VoluntaryL2 - Copyright
AIGE-OBL-GPAICOP-COPYRIGHTNo date VoluntaryL1 L2 - Safety and Security Commitment 9: serious-incident reporting
AIGE-OBL-GPAICOP-SAFETY-C9No date VoluntaryL4 L5 - Safety and Security Appendix 1.3 and 1.4: autonomy, tool use and loss of control as systemic risks
AIGE-OBL-GPAICOP-SAFETY-APP1No date VoluntaryL3 L5
GDPR
15 rows- GDPR Art. 5(1)(b) and 6(4) purpose limitation
AIGE-OBL-GDPR-ART5-1BIn forceL1 L2 - GDPR Art. 6 lawful basis per processing moment
AIGE-OBL-GDPR-ART6In forceL2 - GDPR Art. 7 conditions for consent and its withdrawal
AIGE-OBL-GDPR-ART7In forceL2 L5 - GDPR Art. 9 special categories, incl. inferred sensitive data
AIGE-OBL-GDPR-ART9In forceL1 L3 L4 - GDPR Arts. 13–14 transparency to data subjects
AIGE-OBL-GDPR-ART13-14In forceL2 - GDPR Art. 15(1)(h) access to meaningful information about the logic involved
AIGE-OBL-GDPR-ART15-1HIn forceL4 L5 - GDPR Arts. 15–17 and 21 data subject rights against trained models
AIGE-OBL-GDPR-ART15-17-21In forceL4 L5 - GDPR Art. 22 solely automated decisions and their safeguards
AIGE-OBL-GDPR-ART22In forceL4 L5 - GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default
AIGE-OBL-GDPR-ART25In forceL1 L3 - GDPR Art. 5(2) accountability for a model anonymity claim
AIGE-OBL-GDPR-ART5-2In forceL3 L5 - GDPR Art. 28 processors, incl. AI vendors
AIGE-OBL-GDPR-ART28In forceL2 L5 - GDPR Art. 30 records of processing activities
AIGE-OBL-GDPR-ART30In forceL2 L5 - GDPR Arts. 33–34 personal data breach notification
AIGE-OBL-GDPR-ART33-34In forceL4 L5 - GDPR Arts. 35–36 DPIA and prior consultation
AIGE-OBL-GDPR-ART35-36In forceL1 L2 - GDPR Arts. 44–49 international transfers, incl. remote inference
AIGE-OBL-GDPR-ART44-49In forceL1 L4 L5
NIS2
2 rows- NIS2 Art. 21(2)(c)–(d) business continuity and supply-chain security
AIGE-OBL-NIS2-ART21-2In forceL4 L5 - NIS2 Art. 23 significant-incident reporting
AIGE-OBL-NIS2-ART23In forceL5
DORA
2 rows- DORA Art. 19 major ICT-related incident reporting
AIGE-OBL-DORA-ART19In forceL5 - DORA Art. 28(3) and 28(8) register of ICT third-party arrangements and exit strategies
AIGE-OBL-DORA-ART28In forceL2 L5
Cyber Resilience Act
1 rows- Cyber Resilience Act Art. 14 reporting of actively exploited vulnerabilities and severe incidents
AIGE-OBL-CRA-ART14In forceL4 L5
EU Product Liability Directive
3 rows- Applies laterL1 L5
- EU Product Liability Directive Arts. 9–10 disclosure of evidence and presumption of defect
AIGE-OBL-PLD-ART9-10Applies laterL2 L3 L5 - EU Product Liability Directive Art. 11(2) no later-defect defence for software, its updates or missing safety updates in the manufacturer's control
AIGE-OBL-PLD-ART11-2Applies laterL3 L4 L5
DSM Directive
1 rows- DSM Directive Art. 4(3) text-and-data-mining reservations
AIGE-OBL-DSM-ART4-3In forceL1 L2
Digital Services Act
2 rows- Digital Services Act Art. 25 no deceptive or manipulative interface design
AIGE-OBL-DSA-ART25In forceL3 L5 - Digital Services Act Art. 27 recommender system transparency
AIGE-OBL-DSA-ART27In forceL2 L4
UCPD
1 rows- UCPD Arts. 5–7 and Annex I unfair and misleading commercial practices, incl. fake reviews
AIGE-OBL-UCPD-ART5-7In forceL1 L3 L4
Platform Work Directive
1 rows- Platform Work Directive Arts. 7 and 9–11 automated monitoring and decision-making systems
AIGE-OBL-PWD-ART7-11Applies laterL1 L2 L3 L5
Consumer Credit Directive
1 rows- Consumer Credit Directive Art. 18(8) human intervention in automated creditworthiness assessment
AIGE-OBL-CCD2-ART18-8Applies laterL3 L4 L5
ISO/IEC 42001
9 rows- A.2 Policies related to AI
AIGE-OBL-ISO42001-A2No date VoluntaryL1 - A.3 Internal organization
AIGE-OBL-ISO42001-A3No date VoluntaryL1 L2 - A.4 Resources for AI systems
AIGE-OBL-ISO42001-A4No date VoluntaryL2 - A.5 Assessing impacts of AI systems
AIGE-OBL-ISO42001-A5No date VoluntaryL1 L3 - A.6 AI system life cycle
AIGE-OBL-ISO42001-A6No date VoluntaryL1 L3 L4 - A.7 Data for AI systems
AIGE-OBL-ISO42001-A7No date VoluntaryL2 L3 - A.8 Information for interested parties
AIGE-OBL-ISO42001-A8No date VoluntaryL2 - A.9 Use of AI systems
AIGE-OBL-ISO42001-A9No date VoluntaryL4 - A.10 Third-party and customer relationships
AIGE-OBL-ISO42001-A10No date VoluntaryL2 L5
ISO/IEC 42006
1 rows- ISO/IEC 42006:2025 requirements for AIMS certification bodies
AIGE-OBL-ISO42006-CBNo date VoluntaryL5
ISO/IEC 23894
1 rows- ISO/IEC 23894:2023 guidance on AI risk management
AIGE-OBL-ISO23894-RISKNo date VoluntaryL1 L3
ISO/IEC 42005
1 rows- ISO/IEC 42005:2025 guidance for AI system impact assessment
AIGE-OBL-ISO42005-IANo date VoluntaryL1 L3
ISO/IEC 22989
1 rows- ISO/IEC 22989:2022 AI concepts, terminology and stakeholder roles
AIGE-OBL-ISO22989-CONCEPTSNo date VoluntaryL2
NIST AI RMF
5 rows- GOVERN
AIGE-OBL-NISTRMF-GOVERNNo date VoluntaryL1 L2 - MAP
AIGE-OBL-NISTRMF-MAPNo date VoluntaryL2 L3 - MEASURE
AIGE-OBL-NISTRMF-MEASURENo date VoluntaryL3 - MANAGE
AIGE-OBL-NISTRMF-MANAGENo date VoluntaryL4 L5 - NIST AI 600-1 Generative AI Profile
AIGE-OBL-NIST-AI600-1No date VoluntaryL1 L3
NIST (agent, cyber and misuse work)
3 rows- NIST AI Agent Standards Initiative (2026)
AIGE-OBL-NIST-AGENTSNo date Draft or proposedL3 L4 - NIST IR 8596 Cyber AI Profile (draft)
AIGE-OBL-NIST-IR8596No date Draft or proposedL3 L4 - NIST AI 800-1 misuse risk for dual-use foundation models (draft)
AIGE-OBL-NIST-AI800-1No date Draft or proposedL3
CSA AICM / STAR for AI
4 rows- AICM v1.1: 247 control objectives across 18 domains
AIGE-OBL-CSA-AICMNo date VoluntaryL1 L3 L5 - STAR for AI assurance and certification programme
AIGE-OBL-CSA-STARNo date VoluntaryL5 - AICM agent controls with the CSA Agentic Trust Framework and AARM specification
AIGE-OBL-CSA-AICM-AGENTICNo date VoluntaryL1 L4 - AICM Catastrophic Risk Annex (enhanced controls for high-autonomy systems)
AIGE-OBL-CSA-AICM-CATASTROPHICNo date VoluntaryL4 L5
OWASP GenAI Security Project
4 rows- Top 10 for Agentic Applications 2026
AIGE-OBL-OWASP-AGENTICNo date VoluntaryL3 L4 - Top 10 for LLM Applications 2026
AIGE-OBL-OWASP-LLMNo date VoluntaryL3 L4 - Agent Control Standard (ACS)
AIGE-OBL-OWASP-ACSNo date VoluntaryL1 L4 - AIBOM
AIGE-OBL-OWASP-AIBOMNo date VoluntaryL2
US frontier-developer laws
3 rows- California SB 53 (TFAIA)
AIGE-OBL-USCA-SB53In forceL5 L4 - New York RAISE Act (signed 2025-12-19; effective 2027-01-01)
AIGE-OBL-USNY-RAISEApplies laterL5 L4 - California SB 53 whistleblower protections for covered employees
AIGE-OBL-USCA-SB53-WHISTLEIn forceL1 L5
US state AI laws
9 rows- Texas TRAIGA (HB 149; in force 2026-01-01)
AIGE-OBL-USTX-TRAIGAIn forceL1 L4 - Colorado SB 26-189 automated decision-making technology (replaces the Colorado AI Act, SB 24-205; effective 2027-01-01)
AIGE-OBL-USCO-AIACTApplies laterL2 L4 L5 - California AB 2013 training-data transparency for generative AI
AIGE-OBL-USCA-AB2013In forceL2 - California AI Transparency Act (SB 942 as amended by AB 853)
AIGE-OBL-USCA-SB942In forceL3 L4 - California SB 243 companion chatbots
AIGE-OBL-USCA-SB243In forceL1 L4 L5 - New York GBL Article 47 AI companion models
AIGE-OBL-USNY-GBL47In forceL4 L5 - Illinois HB 3773 AI in employment decisions
AIGE-OBL-USIL-HB3773In forceL2 L3 L4 - NYC Local Law 144 automated employment decision tools
AIGE-OBL-USNYC-LL144In forceL3 L5 - Utah AI disclosure duties (SB 226 amendments to the AI Policy Act)
AIGE-OBL-USUT-SB226In forceL4
US state privacy and sector laws
8 rows- California CPPA regulations on automated decisionmaking technology
AIGE-OBL-USCA-CPPA-ADMTApplies laterL2 L4 L5 - California CPPA regulations on risk assessments
AIGE-OBL-USCA-CPPA-RAIn forceL5 - Virginia CDPA data protection assessments, incl. risky profiling
AIGE-OBL-USVA-CDPAIn forceL1 L5 - Colorado Privacy Act profiling opt-out and data protection assessments
AIGE-OBL-USCO-CPAIn forceL1 L2 L4 L5 - Minnesota CDPA right to question the result of profiling
AIGE-OBL-USMN-MCDPAIn forceL4 L5 - Illinois BIPA consent and retention for biometric identifiers
AIGE-OBL-USIL-BIPAIn forceL1 L2 - Washington My Health My Data Act consent for consumer health data
AIGE-OBL-USWA-MHMDAIn forceL1 L2 - Colorado SB21-169 insurers' use of external consumer data and predictive models
AIGE-OBL-USCO-SB21-169In forceL2 L3 L5
US federal law
7 rows- OMB M-25-21 minimum practices for high-impact AI
AIGE-OBL-USFED-OMB-M25-21In forceL2 L3 L4 L5 - OMB M-26-04 minimum LLM transparency in federal procurement
AIGE-OBL-USFED-OMB-M26-04In forceL2 L5 - ECOA Regulation B adverse-action notice with specific principal reasons
AIGE-OBL-USFED-REGB-1002-9In forceL3 L4 L5 - FCRA adverse-action notice with the credit score used
AIGE-OBL-USFED-FCRA-1681MIn forceL4 - Title VII disparate impact and the UGESP four-fifths rule
AIGE-OBL-USFED-TITLE7-703KIn forceL3 L5 - FTC Act s. 5 substantiation of AI performance claims
AIGE-OBL-USFED-FTC-S5In forceL1 L3 L5 - TAKE IT DOWN Act notice and removal of intimate images, incl. digital forgeries
AIGE-OBL-USFED-TAKEITDOWNIn forceL4 L5
US federal audit and oversight
4 rows- GAO AI Accountability Framework principle 1: governance
AIGE-OBL-USGAO-GOVVoluntaryL1 L2 L5 - GAO AI Accountability Framework principle 2: data
AIGE-OBL-USGAO-DATAVoluntaryL2 L3 - GAO AI Accountability Framework principle 3: performance
AIGE-OBL-USGAO-PERFVoluntaryL3 L4 - GAO AI Accountability Framework principle 4: monitoring
AIGE-OBL-USGAO-MONVoluntaryL4 L5
Other jurisdictions
9 rows- South Korea AI Basic Act (in force 2026-01-22)
AIGE-OBL-KR-AIBASICGrace periodL1 L2 L4 - No date VoluntaryL2 L3 L4
- UK GDPR Arts. 22A–22D permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025)
AIGE-OBL-UK-ADMIn forceL4 L2 - ETSI EN 304 223 baseline cyber-security for AI models and systems
AIGE-OBL-ETSI-304223No date VoluntaryL4 - Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary)
AIGE-OBL-SG-AGENTIC-IDENTITYNo date VoluntaryL2 L4 - Singapore IMDA Model AI Governance Framework for Agentic AI: human checkpoints for significant actions (voluntary)
AIGE-OBL-SG-AGENTIC-CHECKPOINTSNo date VoluntaryL4 L5 - Canada Directive on Automated Decision-Making (federal institutions)
AIGE-OBL-CAN-DADMIn forceL1 L2 L5 - Brazil LGPD Art. 20 review of automated decisions
AIGE-OBL-BR-LGPD-ART20In forceL4 L5 - UK DMCC Act 2024 banned practices: fake and concealed-incentive reviews
AIGE-OBL-UK-DMCC-S225In forceL1 L4
South Korea AI Basic Act
7 rows- Korea AI Basic Act Art. 31(1) prior notice of high-impact or generative AI
AIGE-OBL-KR-ART31-1Grace periodL2 L4 - Korea AI Basic Act Art. 31(2)–(3) generative-AI output labels and realistic-content notice
AIGE-OBL-KR-ART31-2Grace periodL3 L4 - Korea AI Basic Act Art. 32 safety duties for high-compute systems
AIGE-OBL-KR-ART32Grace periodL3 L4 L5 - Korea AI Basic Act Art. 33 high-impact self-review and confirmation
AIGE-OBL-KR-ART33Grace periodL1 L2 - Korea AI Basic Act Art. 34 measures for high-impact AI
AIGE-OBL-KR-ART34Grace periodL1 L2 L4 L5 - Grace periodL1 L5
- Korea AI Basic Act Art. 36 domestic representative
AIGE-OBL-KR-ART36Grace periodL5
China
9 rows- Provisions on Algorithmic Recommendation (in force 2022-03-01)
AIGE-OBL-CN-ALGORECIn forceL1 L2 L4 - Provisions on Deep Synthesis (in force 2023-01-10)
AIGE-OBL-CN-DEEPSYNIn forceL2 L3 L4 - Interim Measures for Generative AI Services (in force 2023-08-15)
AIGE-OBL-CN-GENAIIn forceL2 L3 L4 L5 - Measures for Labelling AI-Generated Synthetic Content with GB 45438-2025 (in force 2025-09-01)
AIGE-OBL-CN-LABELIn forceL3 L4 - GB/T 45654-2025 Basic security requirements for generative AI services (voluntary; implemented 2025-11-01)
AIGE-OBL-CN-GBT45654VoluntaryL3 L5 - TC260 AI Safety Governance Framework 3.0: operators' guidelines §5.3 (voluntary; 2026-09-14)
AIGE-OBL-CN-TC260-OPSNo date VoluntaryL1 L4 L5 - TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14)
AIGE-OBL-CN-TC260-AGENTSNo date VoluntaryL2 L3 L4 L5 - China PIPL Art. 24 automated decision-making and Arts. 55–56 impact assessment
AIGE-OBL-CN-PIPL-ART24In forceL2 L4 L5 - In forceL1 L2 L4 L5
Treaty and international soft law
10 rows- Council of Europe Convention Art. 14(2)(a)–(b) documentation to contest decisions
AIGE-OBL-COE-ART14-2No date Draft or proposedL2 L5 - Council of Europe Convention Art. 15(2) notice of interaction with an AI system
AIGE-OBL-COE-ART15-2No date Draft or proposedL4 - Council of Europe Convention Art. 16 risk and impact management
AIGE-OBL-COE-ART16No date Draft or proposedL1 L2 L4 - Council of Europe Convention Art. 16(2)(g) testing before first use and on significant modification
AIGE-OBL-COE-ART16-2GNo date Draft or proposedL3 - OECD AI Principle 1.4(b) override, repair or decommission safely
AIGE-OBL-OECD-P1-4BNo date VoluntaryL2 L4 - OECD AI Principle 1.5(b)–(c) traceability and systematic risk management
AIGE-OBL-OECD-P1-5No date VoluntaryL1 L5 - No date VoluntaryL3
- No date VoluntaryL4 L5
- No date VoluntaryL2
- No date VoluntaryL4
CEN-CENELEC JTC 21
3 rows- EN 18286:2026 quality management system for EU AI Act purposes
AIGE-OBL-CEN-EN18286No date VoluntaryL1 L5 - prEN 18228 AI risk management (draft)
AIGE-OBL-CEN-PREN18228No date Draft or proposedL1 L3 L5 - prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft)
AIGE-OBL-CEN-PREN18229-1No date Draft or proposedL4
How the ids work
An id is assigned once. New wording, a moved date or a better artefact keeps the id; a removed row keeps its id reserved, so it is never reused; a split row keeps the id on the part that carries the original meaning. The instrument codes and the full stability promise are on the open data page. The frameworks page describes all 77 instruments the map covers, including those with no row of their own.