The AI governance framework landscape
72 major AI governance laws, standards, frameworks and assurance instruments — what each one covers, how it differs from the ones next to it, and which of them this platform can actually evaluate your systems against. Reviewed 2026-08-30.
What "covered" honestly means
Most vendors publish a single count of frameworks "supported". That number conflates two very different things: instruments a platform can check your system against, and instruments it has heard of. These are separated here, and the separation is the point.
| Status | Count | What it means |
|---|---|---|
| Rules mapped | 38 | A full entry in the regulation catalogue, with executable requirements this platform evaluates your systems against. |
| Used elsewhere | 3 | Used by the platform outside the regulation catalogue — in the risk methodology or the threat matrix — but not as a rules-carrying entry. |
| Named, not separate | 3 | Named inside another framework's description rather than tracked as its own assessable instrument. |
| Tracked, not mapped | 28 | Part of the tracked landscape with no rule mapping yet. Not a claim that nothing internally maps to it. |
"Tracked, not mapped" is not a claim that nothing internally maps to an instrument. It means there is no standalone, executable entry for it — so this page does not pretend there is.
What gets mapped next, and why
The expansion order below comes from the source comparison's own recommendations, not from what would be quickest to add. Each of these needs real requirement mapping against the primary text before it can move to "Rules mapped" — an entry with invented requirements would be worse than no entry.
| Priority | Instruments |
|---|---|
| P0 Immediate — closes a gap enterprises are asked about today |
NIST AI 600-1 — Generative AI Profile ISO/IEC 38507:2022 — Governance implications of AI ISO/IEC 42005:2025 — AI System Impact Assessment Singapore Model AI Governance Framework for Generative AI Singapore Model AI Governance Framework for Agentic AI (v1.5, 2026) AI Verify — AI Governance Testing Framework EU General-Purpose AI Code of Practice (2025) |
| P1 Next — broadens international and lifecycle coverage |
ISO/IEC 5338:2023 — AI system life cycle processes ISO/IEC 5259-5:2025 — Data quality governance for analytics and ML ISO/IEC TR 24027:2021 — Bias in AI systems ISO/IEC TR 24028:2020 — Trustworthiness in AI UNESCO Recommendation on the Ethics of Artificial Intelligence Council of Europe Framework Convention on AI, Human Rights, Democracy and Rule of Law Council of Europe HUDERIA Methodology G7 Hiroshima AI Process Comprehensive Policy Framework / Code of Conduct Hiroshima AI Process Reporting Framework Japan AI Guidelines for Business Ver. 1.2 (2026) Australia Guidance for AI Adoption (2025) India AI Governance Guidelines (2025) |
| P2 Later — depth on practical baselines and engineering standards |
IEEE/ISO/IEC 24748-7000:2022 — Ethical concerns during system design IEEE 7001-2021 — Transparency of Autonomous Systems IEEE 7003-2024 — Algorithmic Bias Considerations UK AI Management Essentials (AIME) UK AI Cyber Security Code of Practice UK Algorithmic Transparency Recording Standard (ATRS) |
Binding law & regulation · 23
Enforceable statutes, regulations and supervisory rules.
1 EU Artificial Intelligence Act (Regulation (EU) 2024/1689)
Rules mappedBinding law — EU / extraterritorial
What it covers. Risk-tiered horizontal AI law covering prohibited practices, high-risk systems, transparency and general-purpose AI obligations.
How it differs. Unlike NIST or ISO, it is legally enforceable and attaches duties to provider/deployer roles, conformity assessment and market access.
2 General Data Protection Regulation (GDPR)
Rules mappedBinding law — EU / EEA
What it covers. Personal-data governance, lawful processing, profiling and safeguards around automated decisions.
How it differs. It governs personal data rather than AI as a technology; an AI system can be compliant with the AI Act yet still fail GDPR duties.
3 Illinois Biometric Information Privacy Act (BIPA)
Rules mappedBinding law — Illinois, USA
What it covers. Consent, notice, retention and handling of biometric identifiers and information.
How it differs. Much narrower than broad AI frameworks, but materially higher litigation exposure because it targets biometric processing specifically.
4 Illinois HB 3773 — AI in Employment (IHRA amendment)
Rules mappedBinding law — Illinois, USA
What it covers. Employment use of AI, notice and discrimination-related duties.
How it differs. A domain-specific employment rule; it does not provide an enterprise-wide AI management system.
5 Brazilian AI Bill (PL 2338/2023)
Rules mappedProposed / evolving law — Brazil
What it covers. National risk-based AI governance proposal with rights, duties and risk classification.
How it differs. Comparable in ambition to the EU AI Act but jurisdiction-specific and still dependent on legislative evolution.
6 California CCPA/CPRA ADMT Regulations + AB 2013
Rules mappedLaw / regulation — California, USA
What it covers. Automated decision-making/privacy obligations plus training-data transparency requirements for generative AI developers.
How it differs. Combines privacy/consumer-rights controls with AI transparency rather than creating a single comprehensive AI management law.
7 Ontario AI Hiring Disclosure + Bill 194
Rules mappedLaw / public-sector and employment rules — Ontario, Canada
What it covers. AI-related hiring disclosure and public-sector digital/AI transparency and accountability requirements.
How it differs. Sector/use-case specific; narrower than ISO 42001 or NIST and more prescriptive for covered Ontario activities.
8 Quebec Law 25 — Automated Decision-Making
Rules mappedBinding privacy law — Quebec, Canada
What it covers. Notice and transparency duties for decisions based exclusively on automated processing, with privacy governance requirements.
How it differs. Focused on individual privacy and automated decisions rather than full AI lifecycle governance.
9 Canada Directive on Automated Decision-Making + Algorithmic Impact Assessment
Rules mappedBinding government directive — Canada — federal institutions
What it covers. Algorithmic Impact Assessment, transparency, explanation, testing and oversight for federal automated decision systems.
How it differs. Public-sector-specific and impact-level driven; it is not a private-sector enterprise framework.
10 PIPEDA + OPC Generative-AI Principles
Rules mappedLaw + regulatory guidance — Canada — federal private sector
What it covers. Privacy, consent, accountability, transparency and responsible handling of personal information in AI/GenAI.
How it differs. Privacy-centric rather than a full AI risk/management system.
15 China Algorithm, Deep Synthesis & Generative AI Measures
Rules mappedBinding regulations — China
What it covers. Algorithm recommendation, deep synthesis and generative-AI service duties including content, security, labeling and provider controls.
How it differs. More service/content-control oriented than NIST/ISO and highly jurisdiction-specific.
16 Colorado ADMT Act (SB 26-189)
Rules mappedBinding state law — Colorado, USA
What it covers. Automated decision systems used for consequential decisions, with consumer protections and developer/deployer duties.
How it differs. Outcome/use-case oriented rather than enterprise-wide management-system governance.
17 Colorado SB 21-169 — AI / External Data in Insurance
Rules mappedBinding law + regulation — Colorado, USA — insurance
What it covers. Prevention of unfair discrimination from external consumer data, algorithms and predictive models in insurance.
How it differs. Narrow insurance fairness regime with strong testing/governance implications, not a general AI framework.
18 Digital Operational Resilience Act (DORA)
Rules mappedBinding law — EU — financial entities
What it covers. ICT risk management, resilience, incident reporting, third-party risk and testing for financial entities.
How it differs. Not AI-specific; it governs operational technology risk that AI systems and vendors may fall within.
24 NYC Local Law 144 — Automated Employment Decision Tools
Rules mappedBinding local law — New York City, USA
What it covers. Bias audit, public notice and disclosure obligations for automated employment decision tools.
How it differs. Highly specific employment-use law; its independent bias-audit requirement is more concrete than broad principles frameworks.
28 South Korea AI Basic Act
Rules mappedBinding framework law — South Korea
What it covers. National AI governance framework covering high-impact/generative AI duties and industrial development.
How it differs. Combines innovation policy and risk obligations rather than following the EU’s exact conformity model.
29 Texas Responsible AI Governance Act (TRAIGA)
Rules mappedBinding state law — Texas, USA
What it covers. Prohibitions and governance rules for specified AI practices, with public-sector and consumer-facing implications.
How it differs. State-law compliance overlay; less comprehensive than EU AI Act and different from voluntary risk frameworks.
32 FCA Consumer Duty (PRIN 2A)
Rules mappedBinding conduct rules — United Kingdom — retail financial services
What it covers. Requires firms to deliver good outcomes for retail customers; AI use can affect products, support, value and consumer understanding.
How it differs. Not an AI framework; it is an outcomes rule that constrains how AI may be used in customer journeys.
34 Equal Credit Opportunity Act / Regulation B — Adverse Action
Rules mappedBinding law / regulation — United States — credit
What it covers. Nondiscrimination and specific-reason adverse-action requirements for credit decisions, including AI-assisted decisions.
How it differs. Rights/credit-law overlay; not a general AI governance program.
35 Fair Credit Reporting Act (FCRA)
Rules mappedBinding law — United States — consumer reports
What it covers. Accuracy, permissible purpose, disclosure and adverse-action duties involving consumer reports.
How it differs. Data/use-rights law that can govern AI inputs/decisions without being AI-specific.
36 Title VII / ADA applied to AI hiring tools (EEOC)
Rules mappedBinding civil-rights law + enforcement guidance — United States — employment
What it covers. Employment nondiscrimination and disability/accommodation rules as applied to algorithmic hiring and employment tools.
How it differs. Civil-rights compliance layer; focuses on outcomes and protected classes rather than AI system architecture.
70 U.S. OMB M-25-21 — Accelerating Federal Use of AI through Innovation, Governance, and Public Trust
Tracked, not mappedBinding federal agency policy — United States — federal government
What it covers. Federal agency governance for AI use, including responsible adoption, risk safeguards, leadership/accountability and public trust.
How it differs. Government-internal governance policy rather than private-sector law; directly relevant to federal AI programs and vendors.
71 U.S. OMB M-25-22 — Driving Efficient Acquisition of AI in Government
Tracked, not mappedBinding federal procurement policy — United States — federal government
What it covers. Requirements and principles for acquiring AI competitively, responsibly and with attention to vendor lock-in, privacy and government data.
How it differs. Procurement-specific governance, filling a third-party/vendor management gap not covered by general AI principles alone.
ISO/IEC standards · 10
The international standards family — management systems, risk, impact assessment, lifecycle, data quality and bias.
20 ISO/IEC 23894:2023 — AI Risk Management
Rules mappedInternational standard / guidance — Global
What it covers. AI-specific guidance for identifying, assessing, treating and monitoring risk, aligned with ISO 31000.
How it differs. Risk-management guidance only; unlike ISO 42001 it is not an AI management-system certification standard.
22 ISO/IEC 42001:2023 — AI Management System (AIMS)
Rules mappedCertifiable management-system standard — Global
What it covers. Organization-wide AI management system covering leadership, planning, risk, lifecycle controls, performance evaluation and improvement.
How it differs. Unlike NIST, it is structured as a certifiable management system; unlike the EU AI Act, it is voluntary unless contractually required.
39 ISO 31000:2018 — Risk Management Guidelines
Used elsewhereInternational risk-management standard — Global
What it covers. Enterprise risk-management principles and process used as the parent model for risk identification, analysis, treatment and monitoring.
How it differs. Generic enterprise risk standard, not AI-specific. It provides the risk architecture that ISO/IEC 23894 specializes for AI.
43 ISO/IEC 38507:2022 — Governance implications of AI
Tracked, not mappedInternational governance standard — Global
What it covers. Guidance for boards and governing bodies on directing and overseeing organizational use of AI.
How it differs. Board/governing-body focus is distinct from ISO 42001’s management-system requirements and ISO 23894’s risk process.
44 ISO/IEC 42005:2025 — AI System Impact Assessment
Named, not separateInternational standard — Global
What it covers. Structured AI system impact assessment focused on effects on individuals, groups and society across the lifecycle.
How it differs. Goes deeper on impact assessment than ISO 42001/23894 and aligns with emerging regulatory AIA requirements.
45 ISO/IEC 42006:2025 — AIMS audit and certification bodies
Named, not separateInternational conformity-assessment standard — Global
What it covers. Requirements for bodies that audit and certify AI management systems against ISO/IEC 42001.
How it differs. Targets certifiers rather than ordinary AI developers/deployers; important for assurance credibility and certification ecosystem design.
46 ISO/IEC 5338:2023 — AI system life cycle processes
Tracked, not mappedInternational lifecycle standard — Global
What it covers. Defines AI-specific lifecycle processes for development, acquisition, operation and improvement.
How it differs. Process-engineering/lifecycle standard rather than governance principles; strengthens stage-gate and lifecycle evidence.
47 ISO/IEC 5259-5:2025 — Data quality governance for analytics and ML
Tracked, not mappedInternational data-governance standard — Global
What it covers. Governance framework for directing and overseeing data quality used in analytics and machine learning.
How it differs. Targets data-quality governance specifically, an area often treated only as one control inside broader AI frameworks.
48 ISO/IEC TR 24027:2021 — Bias in AI systems
Tracked, not mappedTechnical report / guidance — Global
What it covers. Bias sources, measurement and treatment across the AI lifecycle.
How it differs. More technically focused on bias assessment than broad fairness principles.
49 ISO/IEC TR 24028:2020 — Trustworthiness in AI
Tracked, not mappedTechnical report / guidance — Global
What it covers. Trustworthiness topics including transparency, explainability, reliability, safety, security, privacy and resilience.
How it differs. A cross-cutting trustworthiness reference rather than a management-system or legal framework.
NIST · 2
The US voluntary framework family, including the generative-AI profile.
23 NIST AI Risk Management Framework 1.0
Rules mappedVoluntary framework — United States / global reference
What it covers. Govern, Map, Measure and Manage functions for trustworthy AI risk management across the lifecycle.
How it differs. Outcome-based and flexible; less prescriptive than ISO 42001 and not legally binding like the EU AI Act.
42 NIST AI 600-1 — Generative AI Profile
Named, not separateVoluntary NIST profile — United States / global reference
What it covers. GenAI-specific companion to NIST AI RMF that identifies risks and suggested risk-management actions for generative AI.
How it differs. Adds GenAI-specific risks and actions that the generic AI RMF does not spell out.
IEEE standards · 3
Ethical design, transparency and algorithmic-bias engineering standards.
50 IEEE/ISO/IEC 24748-7000:2022 — Ethical concerns during system design
Tracked, not mappedInternational ethical-design process standard — Global
What it covers. Process for eliciting ethical values and tracing them into requirements, risk treatment and system design.
How it differs. Operationalizes ethics during engineering rather than leaving ethics as high-level principles.
51 IEEE 7001-2021 — Transparency of Autonomous Systems
Tracked, not mappedIEEE standard — Global
What it covers. Defines measurable/testable transparency levels for autonomous systems.
How it differs. More testable and system-specific than general transparency principles in OECD/NIST/ISO.
52 IEEE 7003-2024 — Algorithmic Bias Considerations
Tracked, not mappedIEEE standard — Global
What it covers. Processes and methods to address algorithmic bias, validation data and application boundaries.
How it differs. Adds detailed bias engineering and validation practices beyond high-level fairness obligations.
International principles & treaties · 8
Intergovernmental principles, treaty frameworks and multilateral codes.
21 OECD AI Principles
Rules mappedIntergovernmental principles — Global / OECD adherents
What it covers. Human-centric trustworthy AI principles plus policy recommendations for governments.
How it differs. High-level values and policy direction, not an auditable control catalogue or certification scheme.
53 UNESCO Recommendation on the Ethics of Artificial Intelligence
Tracked, not mappedIntergovernmental ethics standard — Global / UNESCO member states
What it covers. Human-rights-centered ethics framework covering fairness, privacy, transparency, human oversight, sustainability, accountability and policy actions.
How it differs. Broader societal and human-rights lens than enterprise risk frameworks; includes sustainability and public policy dimensions.
54 Council of Europe Framework Convention on AI, Human Rights, Democracy and Rule of Law
Tracked, not mappedLegally binding international treaty framework — Council of Europe parties / signatories
What it covers. Treaty-level obligations to align AI lifecycle activities with human rights, democracy and the rule of law.
How it differs. Unlike voluntary ethics frameworks, this creates an international legal governance layer centered on fundamental rights.
55 Council of Europe HUDERIA Methodology
Tracked, not mappedHuman-rights risk and impact assessment methodology — Europe / adaptable globally
What it covers. Methodology for assessing AI impacts on human rights, democracy and rule of law; includes the COBRA model.
How it differs. Deeper rights-impact methodology than generic AI risk assessments.
56 G7 Hiroshima AI Process Comprehensive Policy Framework / Code of Conduct
Tracked, not mappedInternational voluntary governance framework — G7 + global reference
What it covers. Guiding principles and voluntary code of conduct for advanced AI systems, including risk testing, incident handling, transparency and security.
How it differs. Frontier/advanced-AI focused, sitting between high-level principles and company safety frameworks.
57 Hiroshima AI Process Reporting Framework
Tracked, not mappedVoluntary reporting / accountability framework — G7 / OECD
What it covers. Operational reporting mechanism for organizations implementing the Hiroshima Code of Conduct.
How it differs. Turns voluntary principles into comparable transparency and accountability disclosures.
58 ASEAN Guide on AI Governance and Ethics (2024)
Tracked, not mappedRegional voluntary governance guide — ASEAN
What it covers. Practical governance guidance for organizations developing and deploying traditional AI, designed for regional interoperability.
How it differs. Regional implementation guide similar in spirit to Singapore’s model but designed for ASEAN-wide alignment.
59 Expanded ASEAN Guide on AI Governance and Ethics — Generative AI (2025)
Tracked, not mappedRegional GenAI governance guide — ASEAN
What it covers. GenAI policy guidance across accountability, data, deployment, incident reporting, testing, security, provenance, safety research and public good.
How it differs. Extends ASEAN governance specifically for GenAI ecosystem risks.
National frameworks & guidance · 24
Country-level voluntary frameworks, guidance and public-sector policy.
11 Canada Voluntary Code of Conduct on Advanced Generative AI
Rules mappedVoluntary code — Canada
What it covers. Responsible development and management of advanced generative AI, including safety, fairness, transparency and monitoring.
How it differs. GenAI-specific and voluntary; more focused than ISO 42001 and less formal than a certifiable management system.
12 Artificial Intelligence and Data Act (AIDA, Bill C-27) — lapsed
Rules mappedHistorical / lapsed proposal — Canada
What it covers. Former proposed federal high-impact AI regime.
How it differs. Unlike live frameworks, it is not currently an enforceable compliance target; its value is historical/contextual.
13 OSFI Guideline E-23 — Model Risk Management
Rules mappedRegulatory guidance — Canada — federally regulated financial institutions
What it covers. Lifecycle model risk governance, validation, inventory, controls and oversight for models including AI/ML.
How it differs. Sector-specific model risk framework; stronger validation/governance emphasis than general AI ethics frameworks.
14 Canadian AI Standards (CSA ISO/IEC 42001 & 23894, CAN/DGSI 101)
Rules mappedStandards / guidance — Canada
What it covers. Canadian adoption and use of international AI management/risk standards plus domestic guidance.
How it differs. A standards layer rather than a statute; supports consistency and assurance without itself creating broad legal penalties.
19 EU Financial Supervisors AI Guidance (EBA, ESMA, EIOPA)
Rules mappedSupervisory guidance — EU — financial services
What it covers. Supervisory expectations for AI use in financial services, including governance, consumer protection and model risk.
How it differs. Sector supervisory layer that sits on top of horizontal EU law and financial rules.
25 NY DFS Circular Letter No. 7 (2024) — AI in Underwriting & Pricing
Rules mappedRegulatory guidance — New York, USA — insurance
What it covers. Governance and anti-discrimination expectations for insurers using AI/external data in underwriting and pricing.
How it differs. Insurance supervisory expectations, not a horizontal AI law.
26 Singapore Model AI Governance Framework
Rules mappedVoluntary framework — Singapore / international reference
What it covers. Practical organizational governance for traditional AI: internal structures, human involvement, operations management and stakeholder communication.
How it differs. More implementation-oriented than high-level ethics principles, but older than Singapore’s GenAI and Agentic AI extensions.
27 MAS FEAT Principles + AI Model Risk Management Guidance
Rules mappedRegulatory / supervisory guidance — Singapore — financial institutions
What it covers. Fairness, Ethics, Accountability and Transparency plus model risk practices for financial institutions.
How it differs. Financial-sector and outcome-focused; narrower than general AI management systems.
30 UK pro-innovation AI framework + ICO guidance
Rules mappedPrinciples-based regulatory framework + guidance — United Kingdom
What it covers. Cross-sector principles implemented through existing regulators, supplemented by privacy/data-protection guidance.
How it differs. Decentralized and regulator-led rather than one horizontal AI statute.
31 PRA SS1/23 — Model Risk Management Principles for Banks
Rules mappedSupervisory statement — United Kingdom — banks
What it covers. Bank model risk governance, model identification, development, validation, governance and controls.
How it differs. Model-risk specific and sector-regulated; AI is governed as part of broader model risk.
33 SR 26-2 — Interagency Model Risk Management Guidance
Rules mappedBanking guidance — United States — banking
What it covers. Model risk governance and validation expectations for banking organizations.
How it differs. Sector model-risk guidance, emphasizing validation and effective challenge rather than AI ethics broadly.
37 Financial Services AI Risk Management Framework (FS AI RMF)
Rules mappedVoluntary sector framework — United States — financial services
What it covers. Financial-services-specific AI risk management practices aligned with sector governance needs.
How it differs. Sector-tailored adaptation of broader AI risk principles.
38 NAIC Model Bulletin on the Use of AI Systems by Insurers
Rules mappedState-adopted model guidance — United States — insurance
What it covers. Insurer governance programs, controls and documentation to prevent unfair trade/discrimination from AI systems.
How it differs. Insurance-specific governance layer adopted through state supervisory practice, not a universal federal rule.
60 Singapore Model AI Governance Framework for Generative AI
Tracked, not mappedVoluntary GenAI governance framework — Singapore / global reference
What it covers. Nine-dimension framework for a trusted GenAI ecosystem across model development, accountability, security, content provenance and other controls.
How it differs. More current and GenAI-specific than the traditional Singapore Model AI Governance Framework already catalogued.
61 Singapore Model AI Governance Framework for Agentic AI (v1.5, 2026)
Tracked, not mappedVoluntary agentic-AI governance framework — Singapore / global reference
What it covers. Guidance on bounding agent powers, human accountability, lifecycle technical controls, third-party/multi-agent risk and user responsibility.
How it differs. One of the first governance frameworks focused specifically on autonomous/agentic AI rather than static models.
62 AI Verify — AI Governance Testing Framework
Tracked, not mappedTesting / assurance framework and toolkit — Singapore / global reference
What it covers. Standardized tests and process checks across 11 governance principles including fairness, explainability, robustness, accountability and human agency.
How it differs. Provides executable assurance/testing, not just policy requirements.
63 Japan AI Guidelines for Business Ver. 1.2 (2026)
Tracked, not mappedNational voluntary guidance — Japan
What it covers. Non-binding guidance for AI developers, providers and business users, integrating Japan’s earlier R&D, utilization and governance guidance.
How it differs. Role-based and innovation-friendly, with strong operational guidance rather than a single punitive AI statute.
64 Australia Guidance for AI Adoption (2025)
Tracked, not mappedNational voluntary governance guidance — Australia
What it covers. Six essential practices for responsible AI governance, evolving the earlier Voluntary AI Safety Standard/10 guardrails.
How it differs. Practical adoption baseline for organizations, aligned to ISO 42001 and NIST but simplified for implementation.
65 India AI Governance Guidelines (2025)
Tracked, not mappedNational principle-based governance framework — India
What it covers. Seven-principle, risk-based and techno-legal governance framework relying on existing laws, sector regulators and new coordinating/safety institutions.
How it differs. Light-touch and principle-based rather than a new horizontal AI statute; emphasizes innovation, proportionality and existing legal mechanisms.
66 UAE AI Ethics Principles & Guidelines
Tracked, not mappedNational ethics / self-governance framework — United Arab Emirates
What it covers. Eight principles including fairness, accountability, transparency, explainability, robustness, safety, human-centered values and sustainability.
How it differs. Values/ethics-led self-governance framework with less prescriptive compliance machinery than ISO or statutory regimes.
67 UK AI Management Essentials (AIME)
Tracked, not mappedVoluntary self-assessment baseline — United Kingdom
What it covers. Practical management self-assessment distilled primarily from ISO/IEC 42001, NIST AI RMF and the EU AI Act.
How it differs. Simplifies complex frameworks into an accessible baseline, especially for SMEs; not a certification.
68 UK AI Cyber Security Code of Practice
Tracked, not mappedCybersecurity code / implementation guidance — United Kingdom
What it covers. Baseline cyber-security principles for organizations developing and deploying AI systems.
How it differs. Security-control specific; complements rather than replaces AI governance/risk frameworks.
69 UK Algorithmic Transparency Recording Standard (ATRS)
Tracked, not mappedMandatory public-sector transparency standard — United Kingdom — central government / public sector
What it covers. Standardized public disclosure of algorithmic tools, ownership, rationale, data, model details, risks, mitigations and impact assessments.
How it differs. A transparency-recording standard with mandatory scope for central government, not a general private-sector AI framework.
72 EU General-Purpose AI Code of Practice (2025)
Tracked, not mappedVoluntary compliance code under binding law — European Union
What it covers. Three chapters covering Transparency, Copyright, and Safety & Security to help GPAI providers demonstrate AI Act compliance.
How it differs. Operationalizes AI Act provider obligations for GPAI models; more detailed and model-provider-specific than the AI Act entry alone.
Security & risk taxonomies · 2
Application-security risk lists and research risk repositories.
40 OWASP Top 10 for LLM / GenAI Applications
Used elsewhereSecurity best-practice framework — Global
What it covers. Critical application-security risks for LLM/GenAI systems such as prompt injection, sensitive data disclosure, supply-chain risk and excessive agency.
How it differs. Security-focused, not a governance certification or legal framework. It fills technical control depth that policy frameworks often lack.
41 MIT AI Risk Repository
Used elsewhereRisk taxonomy / evidence repository — Global
What it covers. Living database and taxonomies of AI risks compiled from many frameworks and research sources.
How it differs. It is a risk discovery/reference corpus, not a prescriptive compliance standard.