Resources · Frameworks

The instruments, and what answers them.

The horizontal law, the management standards, the voluntary codes and the control sets the discipline is built against — then the reverse index that names, for each obligation, the engineering artefact that evidences it and the layer it lives in.

Frameworks

14 instruments — laws, standards, codes and control sets. External links open the canonical source.

Framework Type Issuer Summary
EU AI Act (post-Omnibus) law European Union The EU's horizontal, risk-tiered law for AI (Regulation (EU) 2024/1689), amended by the Digital Omnibus (Regulation (EU) 2026/1744). High-risk Annex III obligations apply from 2 December 2027; Annex I embedded systems from 2 August 2028.
GPAI Code of Practice code European Commission The voluntary instrument (published 10 July 2025) providers use to demonstrate compliance with the GPAI obligations until harmonised standards exist. Three chapters: Safety and Security, Transparency and Copyright.
ISO/IEC 42001 standard ISO/IEC The AI management-system (AIMS) standard (2023); Annex A groups control objectives into nine areas (A.2–A.10). It is a management-system standard, not the Article 17 QMS, and its European adoption confers no presumption of conformity.
ISO/IEC 42005 standard ISO/IEC Guidance for AI system impact assessment (2025); the natural companion to EU AI Act Article 27 (FRIA) and ISO/IEC 42001 Annex A.5.
NIST AI RMF framework NIST The AI Risk Management Framework 1.0 (January 2023; there is no 2.0). Voluntary and US-origin, it organises risk work into four functions — Govern, Map, Measure, Manage — that map cleanly onto the five-layer stack.
CSA AI Controls Matrix (AICM) v1.1 controls Cloud Security Alliance A control framework (published 22 June 2026) defining 247 control objectives across 18 domains, spanning governance, data, model and runtime, with crosswalks to ISO 42001 and NIST AI RMF.
CSA STAR for AI framework Cloud Security Alliance The assurance and certification programme built on the AICM, with a self-assessment tier, an automated "Valid-AI-ted" tier and a Level 2 combining third-party ISO/IEC 42001 certification with the validated assessment.
OWASP Top 10 for Agentic Applications 2026 framework OWASP GenAI Security Project The agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents) that the runtime controls are built against.
OWASP Top 10 for LLM Applications 2026 framework OWASP GenAI Security Project The LLM threat catalogue, including Excessive Agency at #3, answered by prompt-injection and output-handling controls and an eval gate.
OWASP Agent Control Standard (ACS) standard OWASP GenAI Security Project A standard for expressing agent controls as machine-readable control definitions the stack consumes directly.
OWASP AIBOM standard OWASP GenAI Security Project The AI bill-of-materials format and generator, producing CycloneDX ML-BOM and SPDX 3.0 AI output at build.
California SB 53 (TFAIA) law State of California A frontier-AI transparency law in force 1 January 2026, binding large frontier developers (models above ~10^26 FLOP; developer revenue over USD 500M) to publish a safety framework and report critical incidents to the state.
New York RAISE Act law State of New York Frontier-developer safety and disclosure duties for large frontier developers; reported to take effect 1 January 2027 (verify enactment: awaiting final state action at time of writing).
EN 18286:2026 standard CEN-CENELEC The Article 17 QMS standard, published July 2026 — the first JTC 21 AI Act standard to reach publication — but not yet cited in the Official Journal, so it carries no presumption of conformity.

Obligation → artefact → layer

43 rows, grouped by framework. Read each as a sentence: this obligation is answered by this artefact, which lives in this layer. Filter by the layer you are building.

Heat index Obligations mapped, framework × stack layer. Select a cell, a row or a column to filter the table below.
Framework
Filter by layer

EU AI Act

19 rows
Obligation Artefact Layers Chapter
EU AI Act Art. 4 AI literacy Literacy programme as code; role-based training records; onboarding gates ch. 08 →
EU AI Act Art. 4a lawful basis for special-category data in bias detection Data governance controls; pseudonymisation and retention-as-code; data card noting basis and deletion ch. 08 →
EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) Policy-as-code blocklist; input/output guardrails; refusal and abuse detection ch. 08 →
EU AI Act Art. 9 risk management system Risk register as code; threat models; linkage to FRIA and eval results ch. 08 →
EU AI Act Art. 10 data and data governance Data cards; lineage; bias and quality tests in CI ch. 08 →
EU AI Act Art. 11 technical documentation (Annex IV) AIBOM (CycloneDX ML-BOM, SPDX 3.0 AI); auto-generated technical documentation; model cards ch. 08 →
EU AI Act Art. 12 record-keeping and logging Structured, signed logs; OpenTelemetry traces; tamper-evident event store ch. 08 →
EU AI Act Art. 13 transparency and information to deployers Instructions for use as code; model and data cards; capability and limitation notes ch. 08 →
EU AI Act Art. 14 human oversight Human-in-the-loop checkpoints; kill switch; override and escalation paths ch. 08 →
EU AI Act Art. 15 accuracy, robustness and cybersecurity Eval gate; adversarial red-team suite; robustness and security controls; regression evals ch. 08 →
EU AI Act Art. 17 quality management system QMS-as-code; versioned policies; pipeline controls and change management ch. 08 →
EU AI Act Art. 26 deployer obligations for high-risk systems Deployment registry; monitoring hooks; assigned oversight and logging retention ch. 08 →
EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA) FRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA ch. 08 →
EU AI Act Art. 49/71 registration of high-risk systems in the EU database Agent/model registry with an API that feeds registration; owner and status per entry ch. 08 →
EU AI Act Art. 50 transparency for certain AI systems Content labelling and machine-readable marking (C2PA-style); chatbot disclosure banner ch. 08 →
EU AI Act Art. 53 GPAI provider obligations Model cards; training-content summary; AIBOM and dataset provenance ch. 08 →
EU AI Act Art. 55 GPAI models with systemic risk Eval and red-team suite; incident pipeline; weight-security controls; threat model ch. 08 →
EU AI Act Art. 72 post-market monitoring Continuous assurance telemetry; monitoring plan; drift and performance signals ch. 08 →
EU AI Act Art. 73 serious-incident reporting Incident detection and triage pipeline; reporting-clock automation; evidence capture ch. 08 →

GPAI Code of Practice

3 rows
Obligation Artefact Layers Chapter
Safety and Security (systemic-risk models only) Eval and red-team suite; adversarial testing harness; incident pipeline; weight-security controls ch. 08 →
Transparency Model cards; structured model documentation; AIBOM ch. 08 →
Copyright Training-data provenance and licence records; policy-as-code for source filtering ch. 08 →

ISO/IEC 42001

9 rows
Obligation Artefact Layers Chapter
A.2 Policies related to AI Policy-as-code library; versioned policy repository ch. 08 →
A.3 Internal organization Operating model; RACI; ownership in the registry ch. 08 →
A.4 Resources for AI systems Resource inventory; AIBOM; environment manifests ch. 08 →
A.5 Assessing impacts of AI systems Impact assessment as code; FRIA/DPIA linkage (ISO/IEC 42005) ch. 08 →
A.6 AI system life cycle Pipeline controls; eval gates; change management ch. 08 →
A.7 Data for AI systems Data cards; lineage; data quality tests ch. 08 →
A.8 Information for interested parties Model/data cards; machine-readable disclosures ch. 08 →
A.9 Use of AI systems Runtime guardrails; usage telemetry ch. 08 →
A.10 Third-party and customer relationships Supplier AIBOM; contractual and technical control mapping ch. 08 →

NIST AI RMF

4 rows
Obligation Artefact Layers Chapter
GOVERN Policy-as-code; operating model; registry ownership ch. 08 →
MAP Threat models; use-case and impact mapping; data/model cards ch. 08 →
MEASURE Eval gates; adversarial red-team suite; metrics per failure mode ch. 08 →
MANAGE Runtime guardrails; incident pipeline; continuous assurance ch. 08 →

CSA AICM / STAR for AI

2 rows
Obligation Artefact Layers Chapter
AICM v1.1 — 247 control objectives across 18 domains Control catalogue mapped to policy-as-code and evals; crosswalk to ISO 42001 / NIST AI RMF ch. 08 →
STAR for AI — assurance and certification programme Machine-readable evidence submission; continuous assurance telemetry ch. 08 →

OWASP GenAI Security Project

4 rows
Obligation Artefact Layers Chapter
Top 10 for Agentic Applications 2026 Agent threat model; adversarial evals; runtime guardrails; kill switch ch. 08 →
Top 10 for LLM Applications 2026 Prompt-injection and output-handling controls; eval gate ch. 08 →
Agent Control Standard (ACS) Machine-readable control definitions for agents ch. 08 →
AIBOM AIBOM at build (CycloneDX ML-BOM, SPDX 3.0 AI) ch. 08 →

US frontier-developer laws

2 rows
Obligation Artefact Layers Chapter
California SB 53 (TFAIA) Published safety framework; incident pipeline reporting to the state; transparency artefacts ch. 08 →
New York RAISE Act Safety framework; incident and disclosure pipeline ch. 08 →