Resources · Frameworks
The instruments, and what answers them.
The horizontal law, the management standards, the voluntary codes and the control sets the discipline is built against — then the reverse index that names, for each obligation, the engineering artefact that evidences it and the layer it lives in.
Frameworks
14 instruments — laws, standards, codes and control sets. External links open the canonical source.
| Framework | Type | Issuer | Summary |
|---|---|---|---|
| EU AI Act (post-Omnibus) | law | European Union | The EU's horizontal, risk-tiered law for AI (Regulation (EU) 2024/1689), amended by the Digital Omnibus (Regulation (EU) 2026/1744). High-risk Annex III obligations apply from 2 December 2027; Annex I embedded systems from 2 August 2028. |
| GPAI Code of Practice | code | European Commission | The voluntary instrument (published 10 July 2025) providers use to demonstrate compliance with the GPAI obligations until harmonised standards exist. Three chapters: Safety and Security, Transparency and Copyright. |
| ISO/IEC 42001 | standard | ISO/IEC | The AI management-system (AIMS) standard (2023); Annex A groups control objectives into nine areas (A.2–A.10). It is a management-system standard, not the Article 17 QMS, and its European adoption confers no presumption of conformity. |
| ISO/IEC 42005 | standard | ISO/IEC | Guidance for AI system impact assessment (2025); the natural companion to EU AI Act Article 27 (FRIA) and ISO/IEC 42001 Annex A.5. |
| NIST AI RMF | framework | NIST | The AI Risk Management Framework 1.0 (January 2023; there is no 2.0). Voluntary and US-origin, it organises risk work into four functions — Govern, Map, Measure, Manage — that map cleanly onto the five-layer stack. |
| CSA AI Controls Matrix (AICM) v1.1 | controls | Cloud Security Alliance | A control framework (published 22 June 2026) defining 247 control objectives across 18 domains, spanning governance, data, model and runtime, with crosswalks to ISO 42001 and NIST AI RMF. |
| CSA STAR for AI | framework | Cloud Security Alliance | The assurance and certification programme built on the AICM, with a self-assessment tier, an automated "Valid-AI-ted" tier and a Level 2 combining third-party ISO/IEC 42001 certification with the validated assessment. |
| OWASP Top 10 for Agentic Applications 2026 | framework | OWASP GenAI Security Project | The agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents) that the runtime controls are built against. |
| OWASP Top 10 for LLM Applications 2026 | framework | OWASP GenAI Security Project | The LLM threat catalogue, including Excessive Agency at #3, answered by prompt-injection and output-handling controls and an eval gate. |
| OWASP Agent Control Standard (ACS) | standard | OWASP GenAI Security Project | A standard for expressing agent controls as machine-readable control definitions the stack consumes directly. |
| OWASP AIBOM | standard | OWASP GenAI Security Project | The AI bill-of-materials format and generator, producing CycloneDX ML-BOM and SPDX 3.0 AI output at build. |
| California SB 53 (TFAIA) | law | State of California | A frontier-AI transparency law in force 1 January 2026, binding large frontier developers (models above ~10^26 FLOP; developer revenue over USD 500M) to publish a safety framework and report critical incidents to the state. |
| New York RAISE Act | law | State of New York | Frontier-developer safety and disclosure duties for large frontier developers; reported to take effect 1 January 2027 (verify enactment: awaiting final state action at time of writing). |
| EN 18286:2026 | standard | CEN-CENELEC | The Article 17 QMS standard, published July 2026 — the first JTC 21 AI Act standard to reach publication — but not yet cited in the Official Journal, so it carries no presumption of conformity. |
Obligation → artefact → layer
43 rows, grouped by framework. Read each as a sentence: this obligation is answered by this artefact, which lives in this layer. Filter by the layer you are building.
| Framework | |||||
|---|---|---|---|---|---|
EU AI Act
19 rows| Obligation | Artefact | Layers | Chapter |
|---|---|---|---|
| EU AI Act Art. 4 AI literacy | Literacy programme as code; role-based training records; onboarding gates | ch. 08 → | |
| EU AI Act Art. 4a lawful basis for special-category data in bias detection | Data governance controls; pseudonymisation and retention-as-code; data card noting basis and deletion | ch. 08 → | |
| EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) | Policy-as-code blocklist; input/output guardrails; refusal and abuse detection | ch. 08 → | |
| EU AI Act Art. 9 risk management system | Risk register as code; threat models; linkage to FRIA and eval results | ch. 08 → | |
| EU AI Act Art. 10 data and data governance | Data cards; lineage; bias and quality tests in CI | ch. 08 → | |
| EU AI Act Art. 11 technical documentation (Annex IV) | AIBOM (CycloneDX ML-BOM, SPDX 3.0 AI); auto-generated technical documentation; model cards | ch. 08 → | |
| EU AI Act Art. 12 record-keeping and logging | Structured, signed logs; OpenTelemetry traces; tamper-evident event store | ch. 08 → | |
| EU AI Act Art. 13 transparency and information to deployers | Instructions for use as code; model and data cards; capability and limitation notes | ch. 08 → | |
| EU AI Act Art. 14 human oversight | Human-in-the-loop checkpoints; kill switch; override and escalation paths | ch. 08 → | |
| EU AI Act Art. 15 accuracy, robustness and cybersecurity | Eval gate; adversarial red-team suite; robustness and security controls; regression evals | ch. 08 → | |
| EU AI Act Art. 17 quality management system | QMS-as-code; versioned policies; pipeline controls and change management | ch. 08 → | |
| EU AI Act Art. 26 deployer obligations for high-risk systems | Deployment registry; monitoring hooks; assigned oversight and logging retention | ch. 08 → | |
| EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA) | FRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA | ch. 08 → | |
| EU AI Act Art. 49/71 registration of high-risk systems in the EU database | Agent/model registry with an API that feeds registration; owner and status per entry | ch. 08 → | |
| EU AI Act Art. 50 transparency for certain AI systems | Content labelling and machine-readable marking (C2PA-style); chatbot disclosure banner | ch. 08 → | |
| EU AI Act Art. 53 GPAI provider obligations | Model cards; training-content summary; AIBOM and dataset provenance | ch. 08 → | |
| EU AI Act Art. 55 GPAI models with systemic risk | Eval and red-team suite; incident pipeline; weight-security controls; threat model | ch. 08 → | |
| EU AI Act Art. 72 post-market monitoring | Continuous assurance telemetry; monitoring plan; drift and performance signals | ch. 08 → | |
| EU AI Act Art. 73 serious-incident reporting | Incident detection and triage pipeline; reporting-clock automation; evidence capture | ch. 08 → |
GPAI Code of Practice
3 rows| Obligation | Artefact | Layers | Chapter |
|---|---|---|---|
| Safety and Security (systemic-risk models only) | Eval and red-team suite; adversarial testing harness; incident pipeline; weight-security controls | ch. 08 → | |
| Transparency | Model cards; structured model documentation; AIBOM | ch. 08 → | |
| Copyright | Training-data provenance and licence records; policy-as-code for source filtering | ch. 08 → |
ISO/IEC 42001
9 rows| Obligation | Artefact | Layers | Chapter |
|---|---|---|---|
| A.2 Policies related to AI | Policy-as-code library; versioned policy repository | ch. 08 → | |
| A.3 Internal organization | Operating model; RACI; ownership in the registry | ch. 08 → | |
| A.4 Resources for AI systems | Resource inventory; AIBOM; environment manifests | ch. 08 → | |
| A.5 Assessing impacts of AI systems | Impact assessment as code; FRIA/DPIA linkage (ISO/IEC 42005) | ch. 08 → | |
| A.6 AI system life cycle | Pipeline controls; eval gates; change management | ch. 08 → | |
| A.7 Data for AI systems | Data cards; lineage; data quality tests | ch. 08 → | |
| A.8 Information for interested parties | Model/data cards; machine-readable disclosures | ch. 08 → | |
| A.9 Use of AI systems | Runtime guardrails; usage telemetry | ch. 08 → | |
| A.10 Third-party and customer relationships | Supplier AIBOM; contractual and technical control mapping | ch. 08 → |
NIST AI RMF
4 rows| Obligation | Artefact | Layers | Chapter |
|---|---|---|---|
| GOVERN | Policy-as-code; operating model; registry ownership | ch. 08 → | |
| MAP | Threat models; use-case and impact mapping; data/model cards | ch. 08 → | |
| MEASURE | Eval gates; adversarial red-team suite; metrics per failure mode | ch. 08 → | |
| MANAGE | Runtime guardrails; incident pipeline; continuous assurance | ch. 08 → |
CSA AICM / STAR for AI
2 rows| Obligation | Artefact | Layers | Chapter |
|---|---|---|---|
| AICM v1.1 — 247 control objectives across 18 domains | Control catalogue mapped to policy-as-code and evals; crosswalk to ISO 42001 / NIST AI RMF | ch. 08 → | |
| STAR for AI — assurance and certification programme | Machine-readable evidence submission; continuous assurance telemetry | ch. 08 → |
OWASP GenAI Security Project
4 rows| Obligation | Artefact | Layers | Chapter |
|---|---|---|---|
| Top 10 for Agentic Applications 2026 | Agent threat model; adversarial evals; runtime guardrails; kill switch | ch. 08 → | |
| Top 10 for LLM Applications 2026 | Prompt-injection and output-handling controls; eval gate | ch. 08 → | |
| Agent Control Standard (ACS) | Machine-readable control definitions for agents | ch. 08 → | |
| AIBOM | AIBOM at build (CycloneDX ML-BOM, SPDX 3.0 AI) | ch. 08 → |