Body of Knowledge · Chapter 08

08. Regulatory map (obligation → artefact → layer)

This chapter is the reverse index of every “Maps to” line in the book: for each obligation it names the engineering artefact that satisfies or supports it and the stack layer the artefact lives in.

v0.2 · Updated 2026-09-14 · 18 min read · 3,525 words · CC BY 4.0

Every other chapter maps forward — a capability, then the obligations it touches. This chapter maps backward — an obligation, then the artefact and the layer that answer it. The unit of the map is a row: an obligation, the engineering artefact that produces the evidence for it, and one of the five stack layers (chapter 04): 1 Govern-as-Code · 2 Inventory & Transparency · 3 Evals & Red Teaming as Evidence · 4 Runtime Controls & Observability · 5 Assurance & Continuous Compliance. The map is a crosswalk for finding the artefact that answers a question, not a certificate that the artefact makes you compliant.

How to read this map

Read each row as a sentence: this obligation is answered by this artefact, which lives in this layer. Three cautions apply throughout.

  • Mappings are illustrative, not a claim of conformity. No artefact in this book guarantees compliance, and no standard cited here confers a presumption of conformity (see “What is NOT harmonised yet”). An artefact supports and evidences an obligation; the legal judgement of conformity stays with lawyers, notified bodies and authorities.
  • Dates are the post-Omnibus dates. Every EU AI Act date below reflects Regulation (EU) 2026/1744, the Digital Omnibus on AI, of 8 July 2026 (OJ L, 24 July 2026), in force 27 July 20261222. Where the Omnibus moved a date, the moved date is shown; where it did not, the row says so.
  • The competent authority differs by regime. For general-purpose AI (GPAI) the supervisor is the AI Office, and GPAI fines are formal Commission decisions under Article 10134. For high-risk systems the supervisors are national market-surveillance authorities, whose penalties run under Article 994. The map states the authority per row so the reader knows who asks.

EU AI Act, post-Omnibus

High-risk obligations (Articles 9–15, 17, 26, 27, 49, 71, 72, 73) apply to Annex III systems from 2 December 2027 and to Annex I embedded systems from 2 August 2028, both deferred by the Omnibus from 2 August 2026 and 2 August 2027 respectively12. The GPAI obligations (Articles 53, 55) have applied since 2 August 2025, with Commission enforcement powers live since 2 August 20263. Transparency (Article 50) went live on 2 August 2026 and was not moved5. Legacy public-authority high-risk systems keep their original 2 August 2030 date2.

The Duty holder column names who the obligation binds, which is a different axis from who enforces it. The high-risk design-and-build duties — Articles 9 to 15 and 17 — fall on the provider; Articles 26 and 27 fall on the deployer; Articles 4, 5 and 50 bind both; and Articles 53 and 55 bind the GPAI provider. This matters for the engineer because the artefacts you can produce depend on which hat your organisation wears: a deployer cannot draw up the provider’s technical documentation, but it must run the Article 26 monitoring and the Article 27 FRIA — and when the model is procured, most of the provider-side evidence becomes something you collect rather than produce (see the Vendor / Model Due-Diligence Gate in chapter 05).

ArticleObligationEngineering artefactLayerDuty holderApplies (post-Omnibus)Authority
Art. 4AI literacy: take measures to support the development of AI literacy among staff and operatorsLiteracy programme as code; role-based training records; onboarding gates1Provider + deployer2026-07-27 (reworded, in force) 6Provider/deployer duty; national MSA
Art. 4aLawful basis to process special-category data for bias detection in high-risk systems, with pseudonymisation and deletion once bias is correctedData governance controls; pseudonymisation and retention-as-code; data card noting basis and deletion2Provider2026-07-27 (new, in force) 2National MSA / DPAs
Art. 5Prohibited practices; new bans on AI-generated non-consensual intimate imagery (NCII) and CSAMPolicy-as-code blocklist; input/output guardrails; refusal and abuse detection1 · 4Provider + deployer2026-12-02 (new bans); earlier prohibitions from 2025-02-02 2National MSA
Art. 9Risk management system across the high-risk lifecycleRisk register as code; threat models; linkage to FRIA and eval results1 · 3Provider2027-12-02 (Annex III) 1National MSA
Art. 10Data and data governance; representative, relevant, error-checked datasetsData cards; lineage; bias and quality tests in CI2 · 3Provider2027-12-02 (Annex III) 1National MSA
Art. 11Technical documentation (Annex IV) drawn up and kept up to dateAIBOM (CycloneDX ML-BOM, SPDX 3.0 AI); auto-generated technical documentation; model cards2Provider2027-12-02 (Annex III) 1National MSA
Art. 12Record-keeping: automatic logging of events over the system’s lifetimeStructured, signed logs; OpenTelemetry traces; tamper-evident event store4Provider2027-12-02 (Annex III) 1National MSA
Art. 13Transparency and provision of information to deployersInstructions for use as code; model and data cards; capability and limitation notes2Provider2027-12-02 (Annex III) 1National MSA
Art. 14Human oversight designed into the systemHuman-in-the-loop checkpoints; kill switch; override and escalation paths4Provider2027-12-02 (Annex III) 1National MSA
Art. 15Accuracy, robustness and cybersecurityEval gate; adversarial red-team suite; robustness and security controls; regression evals3 · 4Provider2027-12-02 (Annex III) 1National MSA
Art. 17Quality management systemQMS-as-code; versioned policies; pipeline controls and change management1 · 5Provider2027-12-02 (Annex III) 1National MSA
Art. 26Deployer obligations for high-risk systems (use per instructions, monitoring, human oversight)Deployment registry; monitoring hooks; assigned oversight and logging retention2 · 4Deployer2027-12-02 (Annex III) 1National MSA
Art. 27Fundamental Rights Impact Assessment (FRIA) for deployers of Annex III systemsFRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA1 · 2Deployer2027-12-02 (Annex III) 7National MSA
Art. 49 / Art. 71Registration of high-risk systems in the EU databaseAgent/model registry with an API that feeds registration; owner and status per entry2Provider; public-authority deployer2027-12-02 (Annex III) 1National MSA; Commission (database)
Art. 50Transparency for certain AI systems: chatbot disclosure; marking and labelling of synthetic contentContent labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner4 · 2Provider + deployer2026-08-02; marking grace for existing systems to 2026-12-02 5National MSA
Art. 53GPAI provider obligations, incl. a public summary of training content on an AI Office templateModel cards; training-content summary; AIBOM and dataset provenance2GPAI providerObligations from 2025-08-02; enforcement from 2026-08-02 3AI Office
Art. 55GPAI models with systemic risk: model evaluation incl. adversarial testing; Union-level risk assessment; serious-incident reporting; cybersecurity of the modelEval and red-team suite; incident pipeline; weight-security controls; threat model3 · 4 · 5GPAI provider (systemic risk)Obligations from 2025-08-02; enforcement from 2026-08-02 3AI Office
Art. 72Post-market monitoring for high-risk systemsContinuous assurance telemetry; monitoring plan; drift and performance signals5Provider2027-12-02 (Annex III) 1National MSA
Art. 73Serious-incident reporting for high-risk systems (no later than 15 days; 2 days if widespread; 10 days on death)Incident detection and triage pipeline; reporting-clock automation; evidence capture5 · 4Provider2027-12-02 (Annex III) 1National MSA

Two cross-cutting provisions frame the penalties. Under Art. 101, the Commission may fine GPAI providers up to 3% of worldwide annual turnover or EUR 15 million, whichever is higher34. Under the Omnibus’s new Art. 75a75d, the AI Office gains investigation powers backed by periodic penalty payments of up to 5% of average daily turnover per day for a continuing breach, in force since 27 July 20268. High-risk administrative fines run under Art. 99 (ceilings of 7%, 3% and 1% of turnover depending on the breach), imposed by national authorities4.

GPAI Code of Practice

The GPAI Code of Practice, published 10 July 2025, is the voluntary instrument providers use to demonstrate compliance with the GPAI obligations until harmonised standards exist. It has three chapters910.

ChapterWhat it asks forEngineering artefactLayer
Safety and Security (systemic-risk models only)A Safety and Security Framework; model evaluations incl. adversarial testing; systemic-risk assessment and mitigation; serious-incident reporting; model and infrastructure securityEval and red-team suite; adversarial testing harness; incident pipeline; weight-security controls3 · 4 · 5
TransparencyUp-to-date model documentation for the AI Office and downstream deployersModel cards; structured model documentation; AIBOM2
CopyrightA policy to comply with Union copyright law, incl. respecting reservations of rightsTraining-data provenance and licence records; policy-as-code for source filtering1 · 2

The Code is voluntary; signing it is one route to demonstrating compliance, not a legal presumption of conformity9. Signatory status is dynamic and counted per the Commission’s official list10.

ISO/IEC 42001 and 42005

ISO/IEC 42001:2023 is the AI management-system (AIMS) standard; its Annex A groups control objectives into nine areas (A.2A.10). It is a management-system standard, not the Article 17 QMS, and its European adoption (EN ISO/IEC 42001:2026) confers no presumption of conformity1112.

Annex A areaFocusEngineering artefactLayer
A.2 Policies related to AIAI policy set and its governancePolicy-as-code library; versioned policy repository1
A.3 Internal organizationRoles, responsibilities, reportingOperating model; RACI; ownership in the registry1 · 2
A.4 Resources for AI systemsData, tooling, compute, human resources documentedResource inventory; AIBOM; environment manifests2
A.5 Assessing impacts of AI systemsImpact assessment processImpact assessment as code; FRIA/DPIA linkage (ISO/IEC 42005)1 · 3
A.6 AI system life cycleResponsible design, development, deploymentPipeline controls; eval gates; change management1 · 3 · 4
A.7 Data for AI systemsData quality, provenance, preparationData cards; lineage; data quality tests2 · 3
A.8 Information for interested partiesTransparency and reporting to stakeholdersModel/data cards; machine-readable disclosures2
A.9 Use of AI systemsResponsible-use controls and monitoringRuntime guardrails; usage telemetry4
A.10 Third-party and customer relationshipsManaging supplier and customer responsibilitiesSupplier AIBOM; contractual and technical control mapping2 · 5

ISO/IEC 42005:2025 provides guidance for AI system impact assessment and is the natural companion to Article 27 (FRIA) and Annex A.513.

Maps to: these controls are realised through layers 1, 2 and 3 of the stack; the impact-assessment control (A.5 / ISO 42005) supports EU AI Act Art. 27. Mappings are illustrative, not a claim of conformity.

NIST AI RMF

The NIST AI Risk Management Framework 1.0 (January 2023; there is no 2.0) organises risk work into four functions. It is voluntary and US-origin, and it maps cleanly onto the five-layer stack14.

FunctionWhat it asks forEngineering artefactLayer
GOVERNA culture and structure for managing AI riskPolicy-as-code; operating model; registry ownership1 · 2
MAPContext and risk framing for each AI systemThreat models; use-case and impact mapping; data/model cards2 · 3
MEASUREAnalyse, benchmark and monitor riskEval gates; adversarial red-team suite; metrics per failure mode3
MANAGEPrioritise, respond and recoverRuntime guardrails; incident pipeline; continuous assurance4 · 5

CSA AICM and STAR for AI

The Cloud Security Alliance’s AI Controls Matrix (AICM) v1.1, published 22 June 2026, defines 247 control objectives across 18 domains, and the STAR for AI programme (with an agentic-certification track) provides the assurance scheme around it15.

CSA artefactWhat it isEngineering artefactLayer
AICM v1.1247 control objectives across 18 domains, spanning governance, data, model and runtimeControl catalogue mapped to policy-as-code and evals; crosswalk to ISO 42001 / NIST AI RMF1 · 3 · 5
STAR for AIAssurance and certification programme, incl. proposed agent controlsMachine-readable evidence submission; continuous assurance telemetry5

OWASP GenAI Security Project

OWASP’s GenAI Security Project supplies the threat vocabulary the controls are built against, plus two formats — the Agent Control Standard and an AIBOM — that the stack consumes directly1617.

OWASP artefactWhat it isEngineering artefactLayer
Top 10 for Agentic Applications 2026Agent threat catalogue (ASI01 Agent Goal Hijack … ASI10 Rogue Agents)Agent threat model; adversarial evals; runtime guardrails; kill switch3 · 4
Top 10 for LLM Applications 2026LLM threat catalogue (incl. Excessive Agency at #3)Prompt-injection and output-handling controls; eval gate3 · 4
Agent Control Standard (ACS)A standard for expressing agent controlsMachine-readable control definitions for agents1 · 4
AIBOMAI bill-of-materials format and generatorAIBOM at build (CycloneDX ML-BOM, SPDX 3.0 AI)2

US frontier-developer laws

Two US state laws bind only large frontier developers, not general deployers — a narrower scope than the EU AI Act’s risk-tiering. They ask frontier developers to publish safety frameworks and report critical incidents to the state1819.

LawScopeObligationEngineering artefactLayer
California SB 53 (TFAIA), in force 2026-01-01Large frontier developers (models trained above ~10^26 FLOP; developer revenue over USD 500M)Publish a safety and security framework; report critical safety incidents to the state; whistleblower protection; up to USD 1M per violation, AG-enforcedPublished safety framework; incident pipeline reporting to the state; transparency artefacts5 · 4
New York RAISE ActLarge frontier developersFrontier safety and disclosure duties; reported to take effect 2027-01-01 (verify enactment: awaiting final state action at time of writing)Safety framework; incident and disclosure pipeline5

What is NOT harmonised yet

The map has a hole, and it is important to state it plainly rather than paper over it.

  • No harmonised standard is cited in the Official Journal. As of 2026-09-10, Article 40’s presumption of conformity is available to no one, because no harmonised standard has been OJ-cited20.
  • EN 18286 is published but not cited. The Article 17 QMS standard EN 18286:2026 was published in July 2026 — the first JTC 21 AI Act standard to reach publication — but it is not yet cited in the Official Journal, so it carries no presumption of conformity21. The Article 9 (risk), Article 12 (logging) and Article 15 (cybersecurity) standards were still at the Enquiry stage, targeting the end of 202620.
  • ISO/IEC 42001 is not the Article 17 QMS. Certifying to EN ISO/IEC 42001:2026 evidences an AI management system; it does not confer an AI Act presumption of conformity, because it is not a harmonised standard and its scope differs from the Article 17 QMS1112.
  • The Code of Practice is voluntary. Signing the GPAI Code is a way to demonstrate compliance with GPAI obligations; it is not a legal presumption of conformity9.

The practical reading: for the period this edition covers, you cannot buy a presumption of conformity off the shelf. The obligation-to-artefact rows above are how a governance function evidences the obligation on its own merits while the harmonised standards are still being written.

Maps to: this chapter is the reverse index for the whole book; every EU AI Act article, the GPAI Code of Practice, ISO/IEC 42001 and 42005, NIST AI RMF, CSA AICM, OWASP GenAI/Agentic and the two US frontier laws named above map onto the five-layer stack (chapter 04) and the pattern catalogue (chapter 05). Mappings are illustrative, not a claim of conformity.

Sources

  1. [1] “AI Omnibus enters into force” (Reg. (EU) 2026/1744, in force 2026-07-27; Annex III high-risk → 2 Dec 2027; Annex I → 2 Aug 2028; legacy public-authority → 2 Aug 2030). European Commission. 2026-07-27. https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force (verified: primary)
  2. [2] Consolidated changes after the Digital Omnibus (Art. 4a special-category data; Art. 5 NCII/CSAM from 2 Dec 2026; transitional dates). AI Act Explorer (Future of Life Institute). 2026. https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/ (verified: secondary)
  3. [3] Commission enforcement powers over GPAI providers apply from 2 August 2026; obligations since 2 August 2025 (fines up to 3% of worldwide turnover or EUR 15M under Art. 101). European Commission — AI Act Service Desk. 2026-08-02. https://ai-act-service-desk.ec.europa.eu/en/ai-act/faq/commissions-enforcement-powers-related-ai-act-obligations-providers-most-advanced-models (verified: primary)
  4. [4] EU AI Act Art. 101 (Commission fines for GPAI providers) and Art. 99 (penalties by national authorities: 7% / 3% / 1% ceilings). AI Act (Reg. (EU) 2024/1689). 2024. https://artificialintelligenceact.eu/article/101/ (verified: primary)
  5. [5] “Safer and more transparent AI” (Art. 50 transparency live 2 Aug 2026; marking grace for existing generative systems to 2 Dec 2026). European Commission. 2026-08-02. https://commission.europa.eu/news-and-media/news/safer-and-more-transparent-ai-2026-08-02_en (verified: primary)
  6. [6] “AI literacy, the Digital Omnibus and Article 4 of the AI Act” (Art. 4 reworded to “support the development of” AI literacy; applies from 27 Jul 2026). Law & Technology. 2026. https://lawandtechnology.eu/en/ai-literacy-digital-omnibus-article-4-ai-act/ (verified: secondary)
  7. [7] EU AI Act Art. 27 (FRIA for deployers of Annex III high-risk; Art. 27(4) cross-reference to a GDPR Art. 35 DPIA). AI Act (Reg. (EU) 2024/1689). 2024. https://artificialintelligenceact.eu/article/27/ (verified: primary)
  8. [8] Arts. 75a–75d: AI Office investigation powers with periodic penalty payments up to 5% of average daily turnover per day for continuing breaches (Art. 75c(5)). AI Act Explorer (Future of Life Institute). 2026. https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/ (verified: secondary)
  9. [9] GPAI Code of Practice (published 10 Jul 2025; voluntary; three chapters: Transparency, Copyright, Safety and Security). AI Act Explorer / European Commission. 2025-07-10. https://artificialintelligenceact.eu/introduction-to-code-of-practice/ (verified: primary)
  10. [10] GPAI Code of Practice — contents and signatories (Safety & Security applies to systemic-risk models; official signatory list). European Commission. 2026. https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai (verified: primary)
  11. [11] “ISO/IEC 42001 and the AI Act: why certification is not yet a presumption of conformity” (ISO 42001 AIMS ≠ Art. 17 QMS). Law & Technology. 2026. https://lawandtechnology.eu/en/iso-iec-42001-and-the-ai-act-why-certification-is-not-yet-a-presumption-of-conformity/ (verified: secondary)
  12. [12] CSA research note on EU AI Act, prEN 18286 and ISO/IEC 42001 (scope difference; EN ISO/IEC 42001:2026 not a harmonised standard). Cloud Security Alliance. 2026-04-28. https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-pren-18286-iso-42001-20260428-cs/ (verified: secondary)
  13. [13] ISO/IEC 42005:2025 — AI system impact assessment (companion to Art. 27 and ISO 42001 Annex A.5). ISO/IEC. 2025-05. https://www.iso.org/standard/44545.html (verified: secondary)
  14. [14] AI Risk Management Framework 1.0 (functions: Govern, Map, Measure, Manage). NIST. 2023-01-26. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)
  15. [15] AI Controls Matrix (AICM) v1.1 (247 control objectives, 18 domains) and STAR for AI. Cloud Security Alliance. 2026-06-22. https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1 (verified: primary)
  16. [16] Top 10 for Agentic Applications 2026 (ASI01 … ASI10). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
  17. [17] 2026 Top 10 for LLM Applications, Agent Control Standard (ACS) and AIBOM release wave. OWASP GenAI Security Project. 2026-09-01. https://genai.owasp.org/2026/09/01/owasp-genai-security-project-unveils-2026-top-10-for-llm-applications-new-agent-control-standard-and-sponsors-as-community-tops-30000-members/ (verified: primary)
  18. [18] “California’s SB 53: the first frontier AI law explained” (in force 1 Jan 2026; frontier developers over USD 500M revenue and ~10^26 FLOP; up to USD 1M/violation; AG enforcement). Future of Privacy Forum. 2026. https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/ (verified: secondary)
  19. [19] New York RAISE Act — frontier-developer safety and disclosure duties; reported to take effect 1 Jan 2027. Future of Privacy Forum / trade press. 2026. https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/ (verified: reported)
  20. [20] CEN-CENELEC JTC 21 standards tracker (no harmonised standard cited in the OJ → no Art. 40 presumption; risk/logging/cybersecurity standards at Enquiry, Q4 2026 target). CEN-CENELEC JTC 21 (via kla.digital). 2026. https://kla.digital/blog/jtc-21-standards-tracker (verified: secondary)
  21. [21] EN 18286:2026 (Art. 17 QMS) published July 2026, not yet OJ-cited. CEN-CENELEC news. 2026-07-30. https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/ (verified: secondary)
  22. [22] Regulation (EU) 2026/1744 (Digital Omnibus on AI), of 8 July 2026, amending Reg. (EU) 2024/1689 et al.; OJ L, 24 July 2026; in force 27 Jul 2026. Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)
Edit this page on GitHub
Cite this chapter

García Aibar, J. (2026). Regulatory map (obligation → artefact → layer). In AI Governance Engineering: Manifesto & Body of Knowledge (v0.2). https://aigovernanceengineer.com/bok/regulatory-map. CC BY 4.0