AIAI GROUNDED

TRUST & SAFETY POLICY LIBRARY

Trace every control to its source.

A public, versioned map of the laws, voluntary frameworks, threat knowledge bases, and industry examples that inform AI Grounded’s control design.

Public information menu 14 pages

Reference, not certification.

This library is a public research and engineering reference. It is not legal advice, a certification, an attestation that AI Grounded complies with every listed source, or an endorsement by any government, standards body, MITRE, Google, or Meta. A law applies only when its facts, role, territory, service, and current text place an activity in scope.

Registry 2026.08.09.1 · reviewed . Machine-readable sources and controls are available from the public policy API.

Source registry

Filters preserve the distinction between binding law, voluntary guidance, living threat knowledge, and company-published examples. Each card links to the originating publisher rather than a secondary summary.

Showing 20 of 20 authoritative or clearly identified benchmark sources.

Binding if in scopeEuropean Union

Artificial Intelligence Act — Regulation (EU) 2024/1689

European Union

A risk-based AI law with staged duties for prohibited practices, AI literacy, general-purpose AI, transparency, and high-risk systems. Applicability depends on role, system, use, and territorial scope.

Effective / released
Aug 1, 2024
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · INV-01 · AGNT-01 · HUM-01 · TRNS-01 · AUD-01
Read the official source
Binding if in scopeEuropean Union

Digital Services Act — Regulation (EU) 2022/2065

European Union

Establishes tiered duties for in-scope intermediary and platform services, including notice-and-action, reasons for moderation decisions, complaints, transparency, and safeguards for recommender systems.

Effective / released
Feb 17, 2024
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · MOD-01 · HUM-01 · REDR-01 · TRNS-01 · AUD-01
Read the official source
Binding if in scopeUnited Kingdom

Online Safety Act 2023

United Kingdom

Creates staged, proportionate safety duties for in-scope user-to-user and search services, including risk assessment, reporting, complaints, terms, and action on known illegal content.

Effective / released
Mar 17, 2025
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · MOD-01 · HUM-01 · REDR-01 · IR-01 · AUD-01
Read the official source
Binding if in scopeEuropean Union

General Data Protection Regulation — Regulation (EU) 2016/679

European Union

Governs in-scope personal-data processing through lawful basis, purpose limitation, minimization, security, individual rights, impact assessment, and safeguards for significant automated decisions.

Effective / released
May 25, 2018
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · DATA-01 · HUM-01 · REDR-01 · TRNS-01 · IR-01
Read the official source
Binding if in scopeUnited States

Children’s Online Privacy Protection Act and Rule

U.S. Federal Trade Commission

Applies in defined circumstances involving personal information from children under 13 and includes parental notice and consent, minimization, security, access, retention, and deletion duties.

Effective / released
Apr 21, 2000
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · DATA-01 · MOD-01 · HUM-01 · TRNS-01
Read the official source
Binding if in scopeUnited States

18 U.S.C. § 2258A — provider reporting requirements

U.S. House of Representatives, Office of the Law Revision Counsel

Sets defined CyberTipline reporting and preservation duties for qualifying providers after actual knowledge of covered facts or circumstances; it does not create a general monitoring duty.

Effective / released
Oct 13, 2008
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · DATA-01 · HUM-01 · IR-01 · AUD-01
Read the official source
Voluntary frameworkGlobal

Artificial Intelligence Risk Management Framework 1.0

U.S. National Institute of Standards and Technology

A voluntary, rights-preserving framework organized around Govern, Map, Measure, and Manage. NIST states that version 1.0 is under revision, so implementations should track changes.

Effective / released
Jan 26, 2023
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · INV-01 · DATA-01 · AGNT-01 · HUM-01 · TRNS-01 · AUD-01
Read the official source
Voluntary frameworkGlobal

AI RMF: Generative Artificial Intelligence Profile — NIST AI 600-1

U.S. National Institute of Standards and Technology

Extends the AI RMF with generative-AI risks and actions spanning information integrity, confabulation, harmful content, privacy, information security, bias, and intellectual property.

Effective / released
Jul 26, 2024
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · DATA-01 · THRT-01 · AGNT-01 · MOD-01 · TRNS-01 · AUD-01
Read the official source
Voluntary frameworkGlobal

Cybersecurity Framework 2.0

U.S. National Institute of Standards and Technology

Organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond, and Recover, with added emphasis on governance and supply-chain risk.

Effective / released
Feb 26, 2024
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · INV-01 · AUTH-01 · DATA-01 · SDLC-01 · IR-01 · RES-01 · AUD-01
Read the official source
Voluntary frameworkGlobal

Incident Response Recommendations — NIST SP 800-61 Rev. 3

U.S. National Institute of Standards and Technology

A CSF 2.0 community profile for preparing, detecting, responding, recovering, communicating, and continuously improving incident response.

Effective / released
Apr 3, 2025
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · IR-01 · RES-01 · AUD-01
Read the official source
Voluntary frameworkGlobal

Secure Software Development Practices for Generative AI — NIST SP 800-218A

U.S. National Institute of Standards and Technology

Adds AI-model development practices to the Secure Software Development Framework for model producers, AI-system producers, and acquirers.

Effective / released
Jul 26, 2024
Registry review
Aug 9, 2026
Mapped controls
INV-01 · DATA-01 · THRT-01 · SDLC-01 · RES-01 · AUD-01
Read the official source
Voluntary frameworkGlobal

Shifting the Balance of Cybersecurity Risk: Secure by Design

CISA and international partners

Calls on technology makers to own customer security outcomes, practice meaningful transparency and accountability, and make product security a leadership responsibility.

Effective / released
Oct 25, 2023
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · AUTH-01 · SDLC-01 · IR-01 · RES-01 · AUD-01
Read the official source
Voluntary frameworkGlobal

Guidelines for Secure AI System Development

UK NCSC, CISA, and international partners

Lifecycle guidance for secure AI design, development, deployment, operation, and maintenance, including supply-chain and model-specific threats.

Effective / released
Nov 27, 2023
Registry review
Aug 9, 2026
Mapped controls
INV-01 · AUTH-01 · DATA-01 · THRT-01 · SDLC-01 · AGNT-01 · IR-01 · RES-01
Read the official source
Voluntary frameworkGlobal

AI Cyber Security Code of Practice

UK Department for Science, Innovation and Technology

A voluntary baseline and implementation guide addressing cybersecurity risks across the AI lifecycle while future international standardization work continues.

Effective / released
Jan 31, 2025
Registry review
Aug 9, 2026
Mapped controls
GOV-01 · INV-01 · DATA-01 · THRT-01 · SDLC-01 · IR-01 · RES-01
Read the official source
Threat knowledge baseGlobal

MITRE ATLAS

MITRE

A living knowledge base of adversary tactics, techniques, mitigations, and case studies for predictive, generative, and agentic AI systems.

Effective / released
Living source
Registry review
Aug 9, 2026
Mapped controls
INV-01 · AUTH-01 · DATA-01 · THRT-01 · SDLC-01 · AGNT-01 · IR-01
Read the official source
Threat knowledge baseGlobal

MITRE ATT&CK 19.1

MITRE

A versioned knowledge base of observed enterprise, mobile, and industrial-control adversary behavior used to structure conventional platform threat modeling and detection coverage.

Effective / released
Apr 28, 2026
Registry review
Aug 9, 2026
Mapped controls
INV-01 · AUTH-01 · THRT-01 · SDLC-01 · IR-01 · RES-01
Read the official source
Industry benchmarkGlobal

Google Transparency Center

Google

A corporate reference for public policy directories, reporting channels, combined automated and specialist review, appeals, and aggregate enforcement reporting. It is not an independent standard.

Effective / released
Living source
Registry review
Aug 9, 2026
Mapped controls
MOD-01 · HUM-01 · REDR-01 · TRNS-01 · AUD-01
Read the official source
Industry benchmarkGlobal

Secure AI Framework

Google

A practitioner-oriented corporate framework mapping risks and controls across data, infrastructure, models, applications, and agentic systems. It does not establish certification.

Effective / released
Living source
Registry review
Aug 9, 2026
Mapped controls
INV-01 · AUTH-01 · DATA-01 · THRT-01 · SDLC-01 · AGNT-01 · RES-01
Read the official source
Industry benchmarkGlobal

Community Standards and transparency resources

Meta

A corporate benchmark for organizing platform conduct rules, enforcement explanations, reporting, and transparency. These company policies are changeable and are not law or independent assurance.

Effective / released
Living source
Registry review
Aug 9, 2026
Mapped controls
MOD-01 · HUM-01 · REDR-01 · TRNS-01 · AUD-01
Read the official source
Industry benchmarkGlobal

AI System Cards

Meta

A corporate example of explaining how ranking and generative systems work, what signals affect outputs, and what controls are available to people.

Effective / released
Living source
Registry review
Aug 9, 2026
Mapped controls
INV-01 · HUM-01 · TRNS-01 · AUD-01
Read the official source

Control taxonomy

These controls are concise design outcomes. Source mappings show why a control is included; they do not transform a voluntary reference into a legal requirement.

GOV-01 · Governance and source versioning

Assign an accountable owner; record source, jurisdiction, status, version, decision, review date, and release digest; require human approval before a policy update takes effect.

Primary mappings: eu-ai-act · eu-dsa · uk-online-safety-act · nist-ai-rmf · nist-csf-2 · cisa-secure-by-design

INV-01 · Model, agent, and service inventory

Record purpose, steward, model, data, tools, permissions, learning mode, risk tier, prohibited uses, dependencies, and shutdown authority for every operational system.

Primary mappings: eu-ai-act · nist-ai-rmf · nist-csf-2 · nist-800-218a · ncsc-secure-ai · mitre-atlas

AUTH-01 · Least privilege and bounded authority

Use scoped credentials, short-lived capability grants, tool and network allowlists, rate limits, step-up approval, separation of duties, and immediate revocation.

Primary mappings: nist-csf-2 · cisa-secure-by-design · ncsc-secure-ai · mitre-atlas · google-saif

DATA-01 · Data rights, provenance, and integrity

Limit collection to a recorded purpose; preserve attribution and licensing; apply retention and deletion; sign trusted revisions; isolate sensitive data; and detect poisoning or manipulation.

Primary mappings: eu-gdpr · us-coppa · nist-genai-profile · nist-800-218a · ncsc-secure-ai

THRT-01 · Threat-informed AI security

Map AI-specific behaviors to ATLAS and conventional platform behaviors to ATT&CK; test prompt injection, poisoned data, malicious memory, model theft, tool abuse, and supply-chain compromise.

Primary mappings: nist-genai-profile · nist-800-218a · ncsc-secure-ai · mitre-atlas · mitre-attack · google-saif

SDLC-01 · Secure lifecycle and supply chain

Maintain software and AI bills of materials, signed artifacts, dependency and secret controls, staged releases, adversarial testing, rollback, vulnerability handling, and secure defaults.

Primary mappings: nist-csf-2 · nist-800-218a · cisa-secure-by-design · ncsc-secure-ai · uk-ai-cyber-code

AGNT-01 · Governed learning and agent change

Keep RL and non-RL agents inside an immutable policy envelope. Learning may produce a proposal, but cannot change production policy, identity, permissions, code, or weights without evaluation and human approval.

Primary mappings: eu-ai-act · nist-ai-rmf · nist-genai-profile · ncsc-secure-ai · mitre-atlas · google-saif

MOD-01 · Content and conduct safety

Publish clear rules and proportionate workflows for threats, exploitation, self-harm, terrorism, harassment, scams, impersonation, malware, and coordinated manipulation without treating a model score as guilt.

Primary mappings: eu-dsa · uk-online-safety-act · nist-genai-profile · google-transparency · meta-community-standards

HUM-01 · Meaningful human review

Require trained human review for permanent restrictions, sensitive identity findings, threat attribution, external disclosure, or government referral; provide specialists for high-risk cases.

Primary mappings: eu-ai-act · eu-gdpr · eu-dsa · uk-online-safety-act · google-transparency · meta-community-standards

REDR-01 · Reasons, appeals, and correction

Prefer graduated and reversible action, provide understandable reasons, offer accessible appeal and independent re-review, and restore or correct decisions when evidence changes.

Primary mappings: eu-dsa · eu-gdpr · uk-online-safety-act · google-transparency · meta-community-standards

TRNS-01 · AI and recommendation transparency

Identify agents and synthetic content, publish model or system cards, explain material ranking factors and sponsorship, and provide meaningful feed and personalization controls.

Primary mappings: eu-ai-act · eu-dsa · nist-ai-rmf · nist-genai-profile · google-transparency · meta-system-cards

IR-01 · Incident response and reviewed escalation

Classify, contain, preserve only necessary evidence, validate jurisdiction and legal authority, require an authorized human for external reports, and document every disclosure decision.

Primary mappings: us-2258a · nist-csf-2 · nist-800-61r3 · cisa-secure-by-design · ncsc-secure-ai

RES-01 · Resilience, isolation, and recovery

Provide kill switches, tool isolation, rate limits, immutable recovery points, fail-closed sensitive actions, graceful degradation, exercised playbooks, and post-incident improvement.

Primary mappings: nist-csf-2 · nist-800-61r3 · nist-800-218a · cisa-secure-by-design · ncsc-secure-ai

AUD-01 · Measurement and public accountability

Measure prevalence, false outcomes, appeal reversals, response times, agent-policy violations, incidents, and control effectiveness; publish aggregate methods and results without exposing people.

Primary mappings: eu-ai-act · eu-dsa · nist-ai-rmf · nist-csf-2 · google-transparency · meta-community-standards

How updates enter the policy engine

  1. Retrieve only an attributed source and record its version, jurisdiction, and review date.
  2. Generate a proposed difference without changing a live rule or agent permission.
  3. Test the proposal against rights, safety, security, and false-positive scenarios.
  4. Require an accountable human to approve a signed, reversible release.
  5. Publish the new registry version, digest, rationale, and next review date.

AI agents may monitor sources and draft changes. They may not publish policy, expand their own authority, make sensitive factual accusations, or contact government authorities autonomously.