Reference, not certification.
This library is a public research and engineering reference. It is not legal advice, a certification, an attestation that AI Grounded complies with every listed source, or an endorsement by any government, standards body, MITRE, Google, or Meta. A law applies only when its facts, role, territory, service, and current text place an activity in scope.
Registry 2026.08.09.1 · reviewed . Machine-readable sources and controls are available from the public policy API.
Source registry
Filters preserve the distinction between binding law, voluntary guidance, living threat knowledge, and company-published examples. Each card links to the originating publisher rather than a secondary summary.
Showing 20 of 20 authoritative or clearly identified benchmark sources.
Artificial Intelligence Act — Regulation (EU) 2024/1689
European Union
A risk-based AI law with staged duties for prohibited practices, AI literacy, general-purpose AI, transparency, and high-risk systems. Applicability depends on role, system, use, and territorial scope.
- Effective / released
- Aug 1, 2024
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · INV-01 · AGNT-01 · HUM-01 · TRNS-01 · AUD-01
Digital Services Act — Regulation (EU) 2022/2065
European Union
Establishes tiered duties for in-scope intermediary and platform services, including notice-and-action, reasons for moderation decisions, complaints, transparency, and safeguards for recommender systems.
- Effective / released
- Feb 17, 2024
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · MOD-01 · HUM-01 · REDR-01 · TRNS-01 · AUD-01
Online Safety Act 2023
United Kingdom
Creates staged, proportionate safety duties for in-scope user-to-user and search services, including risk assessment, reporting, complaints, terms, and action on known illegal content.
- Effective / released
- Mar 17, 2025
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · MOD-01 · HUM-01 · REDR-01 · IR-01 · AUD-01
General Data Protection Regulation — Regulation (EU) 2016/679
European Union
Governs in-scope personal-data processing through lawful basis, purpose limitation, minimization, security, individual rights, impact assessment, and safeguards for significant automated decisions.
- Effective / released
- May 25, 2018
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · DATA-01 · HUM-01 · REDR-01 · TRNS-01 · IR-01
Children’s Online Privacy Protection Act and Rule
U.S. Federal Trade Commission
Applies in defined circumstances involving personal information from children under 13 and includes parental notice and consent, minimization, security, access, retention, and deletion duties.
- Effective / released
- Apr 21, 2000
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · DATA-01 · MOD-01 · HUM-01 · TRNS-01
18 U.S.C. § 2258A — provider reporting requirements
U.S. House of Representatives, Office of the Law Revision Counsel
Sets defined CyberTipline reporting and preservation duties for qualifying providers after actual knowledge of covered facts or circumstances; it does not create a general monitoring duty.
- Effective / released
- Oct 13, 2008
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · DATA-01 · HUM-01 · IR-01 · AUD-01
Artificial Intelligence Risk Management Framework 1.0
U.S. National Institute of Standards and Technology
A voluntary, rights-preserving framework organized around Govern, Map, Measure, and Manage. NIST states that version 1.0 is under revision, so implementations should track changes.
- Effective / released
- Jan 26, 2023
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · INV-01 · DATA-01 · AGNT-01 · HUM-01 · TRNS-01 · AUD-01
AI RMF: Generative Artificial Intelligence Profile — NIST AI 600-1
U.S. National Institute of Standards and Technology
Extends the AI RMF with generative-AI risks and actions spanning information integrity, confabulation, harmful content, privacy, information security, bias, and intellectual property.
- Effective / released
- Jul 26, 2024
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · DATA-01 · THRT-01 · AGNT-01 · MOD-01 · TRNS-01 · AUD-01
Cybersecurity Framework 2.0
U.S. National Institute of Standards and Technology
Organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond, and Recover, with added emphasis on governance and supply-chain risk.
- Effective / released
- Feb 26, 2024
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · INV-01 · AUTH-01 · DATA-01 · SDLC-01 · IR-01 · RES-01 · AUD-01
Incident Response Recommendations — NIST SP 800-61 Rev. 3
U.S. National Institute of Standards and Technology
A CSF 2.0 community profile for preparing, detecting, responding, recovering, communicating, and continuously improving incident response.
- Effective / released
- Apr 3, 2025
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · IR-01 · RES-01 · AUD-01
Secure Software Development Practices for Generative AI — NIST SP 800-218A
U.S. National Institute of Standards and Technology
Adds AI-model development practices to the Secure Software Development Framework for model producers, AI-system producers, and acquirers.
- Effective / released
- Jul 26, 2024
- Registry review
- Aug 9, 2026
- Mapped controls
- INV-01 · DATA-01 · THRT-01 · SDLC-01 · RES-01 · AUD-01
Shifting the Balance of Cybersecurity Risk: Secure by Design
CISA and international partners
Calls on technology makers to own customer security outcomes, practice meaningful transparency and accountability, and make product security a leadership responsibility.
- Effective / released
- Oct 25, 2023
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · AUTH-01 · SDLC-01 · IR-01 · RES-01 · AUD-01
Guidelines for Secure AI System Development
UK NCSC, CISA, and international partners
Lifecycle guidance for secure AI design, development, deployment, operation, and maintenance, including supply-chain and model-specific threats.
- Effective / released
- Nov 27, 2023
- Registry review
- Aug 9, 2026
- Mapped controls
- INV-01 · AUTH-01 · DATA-01 · THRT-01 · SDLC-01 · AGNT-01 · IR-01 · RES-01
AI Cyber Security Code of Practice
UK Department for Science, Innovation and Technology
A voluntary baseline and implementation guide addressing cybersecurity risks across the AI lifecycle while future international standardization work continues.
- Effective / released
- Jan 31, 2025
- Registry review
- Aug 9, 2026
- Mapped controls
- GOV-01 · INV-01 · DATA-01 · THRT-01 · SDLC-01 · IR-01 · RES-01
MITRE ATLAS
MITRE
A living knowledge base of adversary tactics, techniques, mitigations, and case studies for predictive, generative, and agentic AI systems.
- Effective / released
- Living source
- Registry review
- Aug 9, 2026
- Mapped controls
- INV-01 · AUTH-01 · DATA-01 · THRT-01 · SDLC-01 · AGNT-01 · IR-01
MITRE ATT&CK 19.1
MITRE
A versioned knowledge base of observed enterprise, mobile, and industrial-control adversary behavior used to structure conventional platform threat modeling and detection coverage.
- Effective / released
- Apr 28, 2026
- Registry review
- Aug 9, 2026
- Mapped controls
- INV-01 · AUTH-01 · THRT-01 · SDLC-01 · IR-01 · RES-01
Google Transparency Center
A corporate reference for public policy directories, reporting channels, combined automated and specialist review, appeals, and aggregate enforcement reporting. It is not an independent standard.
- Effective / released
- Living source
- Registry review
- Aug 9, 2026
- Mapped controls
- MOD-01 · HUM-01 · REDR-01 · TRNS-01 · AUD-01
Secure AI Framework
A practitioner-oriented corporate framework mapping risks and controls across data, infrastructure, models, applications, and agentic systems. It does not establish certification.
- Effective / released
- Living source
- Registry review
- Aug 9, 2026
- Mapped controls
- INV-01 · AUTH-01 · DATA-01 · THRT-01 · SDLC-01 · AGNT-01 · RES-01
Community Standards and transparency resources
Meta
A corporate benchmark for organizing platform conduct rules, enforcement explanations, reporting, and transparency. These company policies are changeable and are not law or independent assurance.
- Effective / released
- Living source
- Registry review
- Aug 9, 2026
- Mapped controls
- MOD-01 · HUM-01 · REDR-01 · TRNS-01 · AUD-01
AI System Cards
Meta
A corporate example of explaining how ranking and generative systems work, what signals affect outputs, and what controls are available to people.
- Effective / released
- Living source
- Registry review
- Aug 9, 2026
- Mapped controls
- INV-01 · HUM-01 · TRNS-01 · AUD-01
Control taxonomy
These controls are concise design outcomes. Source mappings show why a control is included; they do not transform a voluntary reference into a legal requirement.
GOV-01 · Governance and source versioning
Assign an accountable owner; record source, jurisdiction, status, version, decision, review date, and release digest; require human approval before a policy update takes effect.
Primary mappings: eu-ai-act · eu-dsa · uk-online-safety-act · nist-ai-rmf · nist-csf-2 · cisa-secure-by-design
INV-01 · Model, agent, and service inventory
Record purpose, steward, model, data, tools, permissions, learning mode, risk tier, prohibited uses, dependencies, and shutdown authority for every operational system.
Primary mappings: eu-ai-act · nist-ai-rmf · nist-csf-2 · nist-800-218a · ncsc-secure-ai · mitre-atlas
AUTH-01 · Least privilege and bounded authority
Use scoped credentials, short-lived capability grants, tool and network allowlists, rate limits, step-up approval, separation of duties, and immediate revocation.
Primary mappings: nist-csf-2 · cisa-secure-by-design · ncsc-secure-ai · mitre-atlas · google-saif
DATA-01 · Data rights, provenance, and integrity
Limit collection to a recorded purpose; preserve attribution and licensing; apply retention and deletion; sign trusted revisions; isolate sensitive data; and detect poisoning or manipulation.
Primary mappings: eu-gdpr · us-coppa · nist-genai-profile · nist-800-218a · ncsc-secure-ai
THRT-01 · Threat-informed AI security
Map AI-specific behaviors to ATLAS and conventional platform behaviors to ATT&CK; test prompt injection, poisoned data, malicious memory, model theft, tool abuse, and supply-chain compromise.
Primary mappings: nist-genai-profile · nist-800-218a · ncsc-secure-ai · mitre-atlas · mitre-attack · google-saif
SDLC-01 · Secure lifecycle and supply chain
Maintain software and AI bills of materials, signed artifacts, dependency and secret controls, staged releases, adversarial testing, rollback, vulnerability handling, and secure defaults.
Primary mappings: nist-csf-2 · nist-800-218a · cisa-secure-by-design · ncsc-secure-ai · uk-ai-cyber-code
AGNT-01 · Governed learning and agent change
Keep RL and non-RL agents inside an immutable policy envelope. Learning may produce a proposal, but cannot change production policy, identity, permissions, code, or weights without evaluation and human approval.
Primary mappings: eu-ai-act · nist-ai-rmf · nist-genai-profile · ncsc-secure-ai · mitre-atlas · google-saif
MOD-01 · Content and conduct safety
Publish clear rules and proportionate workflows for threats, exploitation, self-harm, terrorism, harassment, scams, impersonation, malware, and coordinated manipulation without treating a model score as guilt.
Primary mappings: eu-dsa · uk-online-safety-act · nist-genai-profile · google-transparency · meta-community-standards
HUM-01 · Meaningful human review
Require trained human review for permanent restrictions, sensitive identity findings, threat attribution, external disclosure, or government referral; provide specialists for high-risk cases.
Primary mappings: eu-ai-act · eu-gdpr · eu-dsa · uk-online-safety-act · google-transparency · meta-community-standards
REDR-01 · Reasons, appeals, and correction
Prefer graduated and reversible action, provide understandable reasons, offer accessible appeal and independent re-review, and restore or correct decisions when evidence changes.
Primary mappings: eu-dsa · eu-gdpr · uk-online-safety-act · google-transparency · meta-community-standards
TRNS-01 · AI and recommendation transparency
Identify agents and synthetic content, publish model or system cards, explain material ranking factors and sponsorship, and provide meaningful feed and personalization controls.
Primary mappings: eu-ai-act · eu-dsa · nist-ai-rmf · nist-genai-profile · google-transparency · meta-system-cards
IR-01 · Incident response and reviewed escalation
Classify, contain, preserve only necessary evidence, validate jurisdiction and legal authority, require an authorized human for external reports, and document every disclosure decision.
Primary mappings: us-2258a · nist-csf-2 · nist-800-61r3 · cisa-secure-by-design · ncsc-secure-ai
RES-01 · Resilience, isolation, and recovery
Provide kill switches, tool isolation, rate limits, immutable recovery points, fail-closed sensitive actions, graceful degradation, exercised playbooks, and post-incident improvement.
Primary mappings: nist-csf-2 · nist-800-61r3 · nist-800-218a · cisa-secure-by-design · ncsc-secure-ai
AUD-01 · Measurement and public accountability
Measure prevalence, false outcomes, appeal reversals, response times, agent-policy violations, incidents, and control effectiveness; publish aggregate methods and results without exposing people.
Primary mappings: eu-ai-act · eu-dsa · nist-ai-rmf · nist-csf-2 · google-transparency · meta-community-standards
How updates enter the policy engine
- Retrieve only an attributed source and record its version, jurisdiction, and review date.
- Generate a proposed difference without changing a live rule or agent permission.
- Test the proposal against rights, safety, security, and false-positive scenarios.
- Require an accountable human to approve a signed, reversible release.
- Publish the new registry version, digest, rationale, and next review date.
AI agents may monitor sources and draft changes. They may not publish policy, expand their own authority, make sensitive factual accusations, or contact government authorities autonomously.