The data behind the site, as files you can build on.

Every register on this site is published as static JSON under a versioned path, with a JSON Schema per file, an OpenAPI description and a CC BY 4.0 licence. No key, no account, no rate limit of ours: fetch it, cache it, cite it.

Endpoints

All paths are relative to https://aigovernanceengineer.com/api/v1. Start from the catalogue (index.json) or the OpenAPI 3.1 description (openapi.json).

Endpoint What it holds Schema Page
obligations.json Every obligation → artefact → stack-layer row of the regulatory map, with stable ids, ISO application dates, status, system classes, patterns and review dates. v2 Obligation register
frameworks.json The laws, standards, codes and control sets the regulatory map covers, with the ids of their obligation rows. v1 Frameworks
crosswalk.json Twelve governance topics against the clauses of the EU AI Act, ISO/IEC 42001, the NIST AI RMF and the Chinese instruments, joined to the obligation register. v1 Topic crosswalk
glossary.json The canonical terms of the discipline, parsed from chapter 09, with their chapter references. v1 Glossary
patterns.json The reusable patterns of chapter 05, with their home layer, the frameworks their "Maps to" line names and the obligation rows that list them. v1 Pattern catalogue index
maturity.json The five-level maturity model of chapter 07, Documented → Continuous, with its typical evidence. v1 Maturity model
path.json The four-stage learning path: nodes, prerequisites, internal links and external resources. v1 Learning path
chapters.json The chapters of the Body of Knowledge in reading order, with their part, summary and takeaways. v1 Body of Knowledge chapters
jurisdictions.json The AI-specific legal landscape by jurisdiction: how binding each regime is and the instruments behind it, each dated. v1 AI laws by jurisdiction
harms.json Harms by level with the failure mode, the controlling pattern, the evidence it leaves, the stack layers, the MIT AI Risk Repository taxonomy codes and real incidents. v1 AI harms atlas
cases.json Publicly documented AI incidents written as engineering post-mortems, with the control that would have caught them, the evidence it would have left and the obligations they touch; some carry an incident note (system boundary, control assumptions, controls by moment, evidence requirements, related open controls, open questions), null where not written. v1 Incident cases
contracts.json The AI vendor-contract clauses to check (what each governs, the red flag, a fallback and the evidence to keep) and the model-licence families. v1 Contract clauses and licence families
roles.json Operator roles across regimes (EU AI Act, Colorado, Texas, Korea, ISO/IEC 22989), with duties, the nearest EU AI Act role and the events that make an actor a provider. v1 Value-chain roles
threats.json External AI threat ids (OWASP LLM 2026, OWASP Agentic 2026, MITRE ATLAS, NIST AI 100-2) mapped to the controlling patterns, example evals, obligation ids, ISO/IEC 42001 Annex A, CSA AICM domains, NIST SP 800-218A tasks and COSAiS use cases. v1 Threat bridge
controls.json Open control profiles: draft control specifications for AI evaluation environments and agents at runtime, each reference control with its objective, failure modes, enforcement points, verification, evidence, mappings and sources. Illustrative, not a claim of conformity. v1 Open control profiles
obligations/{id}.json One obligation, keyed by its id in lower case (182 files). v2 Obligation register
controls/{id}.json One reference control, keyed by its id in lower case (79 files). Draft control specifications, open for technical review. v1 Open control profiles

The envelope

Every file wraps its data in the same top-level fields:

  • notice: the disclaimer above, with the Body of Knowledge version.
  • version: the Body of Knowledge version the file was built from (0.5.0).
  • license and licenseUrl: CC BY 4.0 and its deed.
  • schemaVersion and schema: the shape version and the JSON Schema the file validates against.
  • self and source: the file's own URL and the page that renders the same data.
  • citation: the title, authors and DOIs to cite (see below).

Schemas are JSON Schema draft 2020-12, one per file, at https://aigovernanceengineer.com/api/v1/schemas/<name>.json: obligations , frameworks , crosswalk , glossary , patterns , maturity , path , chapters , jurisdictions , harms , cases , contracts , roles , threats , controls , obligation , control , index . Every record is a closed object: a field is always present, and absent values are null or an empty list, never missing.

Obligation ids

Each obligation carries an id of the form AIGE-OBL-<INSTRUMENT>-<CLAUSE>, for example AIGE-OBL-EUAIA-ART9. Ids use upper-case letters, digits and hyphens only (the pattern is ^AIGE-OBL-[A-Z0-9]+(?:-[A-Z0-9]+)+$); URLs use the same id in lower case.

  • An id is assigned once. New wording, a moved date, a better artefact or a changed layer keeps the id.
  • A removed row keeps its id reserved; it is never reused for another obligation.
  • A split row keeps the id on the part that carries the original meaning; the new part gets a new id.

The instrument codes in use:

Code Instrument
EUAIA EU AI Act
GPAICOP GPAI Code
GDPR GDPR
NIS2 NIS2
DORA DORA
CRA CRA
PLD EU PLD
DSM DSM Directive
DSA DSA
UCPD UCPD
PWD Platform Work Directive
CCD2 CCD2
ISO42001 ISO 42001
ISO42006 ISO 42006
ISO23894 ISO 23894
ISO42005 ISO 42005
ISO22989 ISO 22989
NISTRMF NIST AI RMF
NIST NIST Agents · NIST IR 8596 · NIST AI 800-1 · NIST AI 600-1
CSA CSA AICM · CSA STAR
OWASP OWASP Agentic · OWASP LLM · OWASP ACS · OWASP AIBOM
USCA California SB 53 · California AB 2013 · California SB 942 · California SB 243 · California CPPA
USNY New York RAISE · New York GBL Art. 47
USTX Texas TRAIGA
USCO Colorado ADMT · Colorado Privacy Act · Colorado SB21-169
USIL Illinois HB 3773 · Illinois BIPA
USNYC NYC LL 144
USUT Utah AI disclosure
USVA Virginia CDPA
USMN Minnesota CDPA
USWA Washington MHMDA
USFED OMB M-25-21 · OMB M-26-04 · ECOA / Reg. B · FCRA · Title VII / UGESP · FTC Act s. 5 · TAKE IT DOWN Act
USGAO GAO AI Accountability
KR Korea AI Act
SG Singapore GenAI · Singapore Agentic
UK UK DUAA · UK DMCC Act
ETSI ETSI EN 304 223
CAN Canada DADM
BR Brazil LGPD
CN China Algo. Rec. · China Deep Synthesis · China GenAI Measures · China AI Labelling · GB/T 45654 · TC260 Framework 3.0 · China PIPL · China Anthropomorphic
COE CoE Convention
OECD OECD AI Principles
G7 G7 Code
CEN EN 18286 · prEN 18228 · prEN 18229-1

Versioning and stability

  • The path is the contract. Everything under /api/v1/ keeps its URL and its meaning for as long as v1 exists. A breaking change ships under a new path, and the old one stays up alongside it.
  • Fields are added, not taken away. Within a schemaVersion, a file may gain fields; no field is removed, renamed or retyped. A breaking change to one file bumps its schemaVersion and is recorded in the changelog.
  • The data moves with the book. Files are rebuilt on every release; the version field says which edition of the Body of Knowledge they come from, and each obligation carries the date it was last reviewed.
  • The older downloads stay. /resources/obligations.json and its CSV keep their URLs. They moved to schemaVersion 2 in v0.5.0: appliesFrom became an ISO date (or null) and the former free text moved to appliesNote. The CSV keeps its first seven columns in place and appends the new ones.

Access

The files are static. They are served with Access-Control-Allow-Origin: *, so a browser application on any origin can read them, and with Cache-Control: public, max-age=3600. There is no key and no authentication. Please cache what you fetch; the data changes with releases, not by the minute.

# The catalogue
curl -s https://aigovernanceengineer.com/api/v1/index.json

# One obligation, by its id in lower case
curl -s https://aigovernanceengineer.com/api/v1/obligations/aige-obl-euaia-art9.json

# Every EU AI Act obligation that applies on a given date (jq)
curl -s https://aigovernanceengineer.com/api/v1/obligations.json \
  | jq '.obligations[] | select(.frameworkId == "eu-ai-act" and .appliesFrom != null
        and .appliesFrom <= "2027-12-02") | {id, appliesFrom, appliesStatus}'

Other files that predate the API and stay where they are:

Remote MCP server (read-only)

The same data is served to AI assistants by a read-only Model Context Protocol server: it answers questions about the obligation register, the crosswalk, the glossary, the patterns, the templates and schemas and the chapters, and every answer names the page it was read from. It holds no data of its own, needs no account and stores nothing about the people who call it. Its endpoint is https://mcp.aigovernanceengineer.com/mcp (Streamable HTTP, no authentication), live since 2026-09-25; see the MCP server page for how to connect a client. The server's code, its tools and a guide to run it yourself are in tools/mcp-server of the repository.

claude mcp add --transport http aige https://mcp.aigovernanceengineer.com/mcp

How to cite

The data is part of the archived Body of Knowledge, not a separate deposit. Cite the release DOI 10.5281/zenodo.22956197 (this version) or the concept DOI 10.5281/zenodo.22857084 (always the latest), and name the file and the date you fetched it. For a single obligation, cite its id and its page: every obligation page carries its own citation block. Attribution under CC BY 4.0: Jorge García Aibar.

Cite this dataset

García Aibar, J. (2026). Open data and API [Data set]. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/resources/data. CC BY 4.0

BibTeX

@misc{aige2026dataset,
  author       = {Jorge García Aibar},
  title        = {{Open data and API}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/resources/data},
  note         = {Version 0.5.0}
}