{
  "$schema": "provael-regulatory-clock/1",
  "note": "Structured, dated, source-linked regulatory clock. Machine-readable record of the facts the compliance pages cite. NOT legal advice; dated editorial data - verify against the primary source before relying on it. The compliance pages currently carry the same verified values inline in src/data/compliance.ts; wiring the pages to read from this file is a recommended follow-up.",
  "lastVerified": "2026-08-19",
  "verifiedAgainst": [
    "EUR-Lex",
    "ISO",
    "NIST",
    "A3 (Automate)",
    "CSET"
  ],
  "disclaimer": "Not legal advice. This is dated editorial data, not a legal opinion. Verify against the primary official source before relying on any date.",
  "entries": [
    {
      "id": "eu-ai-act-art15",
      "framework": "EU AI Act",
      "title": "Regulation (EU) 2024/1689 - Article 15 (accuracy, robustness, cybersecurity)",
      "instrument": "Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)",
      "provision": "Article 15; applied to high-risk product-embedded AI systems (Annex I). NOTE: Regulation (EU) 2026/1744 moved Machinery Regulation (EU) 2023/1230 from AI Act Annex I Section A to Section B, so AI Act Chapter III (including Article 15) no longer applies DIRECTLY to AI-enabled machinery.",
      "status": "amended-in-force",
      "statusNote": "Regulation (EU) 2026/1744: Parliament 16 June 2026, Council 29 June 2026, published OJ 24 July 2026, in force 27 July 2026.",
      "applicableDate": "2028-08-02",
      "supersededStatutoryDate": "2027-08-02",
      "standaloneAnnexIIIDate": "2027-12-02",
      "machineryPathway": "For machinery, the AI-robustness requirements are carried across by Commission delegated acts amending Annex III of Regulation (EU) 2023/1230, applicable by 2 August 2028 — not by direct application of AI Act Chapter III.",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng",
      "secondarySource": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
      "lastVerified": "2026-09-06",
      "editorNote": "2 August 2027 was the statutory application date for product-embedded high-risk AI; Regulation (EU) 2026/1744 defers it to 2 August 2028 and moves stand-alone Annex III high-risk to 2 December 2027. It also adds two prohibited practices (non-consensual intimate imagery and CSAM) from 2 December 2026. Now settled law, not pending publication.",
      "provaelSupports": "A measured attack-success rate with a 95% Wilson CI and a benign control is candidate evidence toward Art. 15 robustness documentation.",
      "provaelDoesNotEstablish": "Does not establish conformity, is not certification, and is not a notified-body opinion.",
      "responsibleActor": "Provider of the high-risk AI system / product manufacturer (and a notified body where a third-party route applies).",
      "verificationNote": "Re-read on EUR-Lex on 6 September 2026. Regulation (EU) 2026/1744 (Digital Omnibus on AI) was published in the Official Journal on 24 July 2026 and enters into force \"on the third day following that of its publication\" (recital 46). Recital 40 sets 2 December 2027 for stand-alone Annex III high-risk systems and 2 August 2028 for product-embedded Annex I systems. All three dates on this entry are the Regulation's own."
    },
    {
      "id": "eu-machinery-regulation",
      "framework": "EU Machinery Regulation",
      "title": "Regulation (EU) 2023/1230",
      "instrument": "Regulation (EU) 2023/1230 (replaces Directive 2006/42/EC)",
      "provision": "Article 54; safety components with self-evolving behaviour pulled into conformity assessment",
      "status": "adopted-applies",
      "statusNote": "Adopted; applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023).",
      "applicableDate": "2027-01-20",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2023/1230/oj",
      "secondarySource": "https://eur-lex.europa.eu/eli/reg/2023/1230/corrigendum/2023-07-04/oj/eng",
      "lastVerified": "2026-08-20",
      "editorNote": "The nearest binding embodied-AI deadline. Some secondary sources cite an incorrect January date; the correct application date is 20 January 2027.",
      "provaelSupports": "Evidence that an AI-driven safety function resists instruction- and perception-level manipulation in simulation, with a measured redirection rate and CI, feeding the technical documentation for a conformity assessment.",
      "provaelDoesNotEstablish": "Not a conformity assessment, not a certificate; Provael is not a notified body.",
      "responsibleActor": "Manufacturer of the machinery / safety component (and a notified body for the third-party route).",
      "verificationNote": "Re-read at CELEX 32023R1230 AND its corrigendum 32023R1230R(01). This matters and is easy to get wrong in one specific direction: the UNCORRECTED OJ text of Art. 54 carries an earlier January date, and the corrigendum replaces it with 20 January 2027. Reading only the original text yields the wrong answer, which is why check-facts forbids that earlier string from appearing anywhere on this site — including in this note. Article 20(10) re-read 20 August 2026 in the consolidated text at CELEX 02023R1230-20260727: Article 20 has ten paragraphs and paragraph 10 is the AI-Act bridge quoted in aiHarmonisedBridge. Not re-verified on 6 September 2026: the reading that day returned the Regulation’s identity and OJ citation but stopped before Article 54, and the corrected 20 January 2027 date is the whole point of this entry.",
      "aiHarmonisedBridge": "Article 20(10) — the bridge that keeps the interval workable. Verbatim: \"Until harmonised standards or common specifications are referenced or adopted pursuant to this Article as regards high-risk AI systems, high-risk AI systems within the scope of this Regulation which comply with the relevant harmonised standards referenced, or common specifications adopted pursuant to Articles 40 and, respectively, 41 of Regulation (EU) 2024/1689 shall be presumed to be in conformity with the essential health and safety requirements set out in Annex III to this Regulation as regards high-risk AI systems.\"",
      "aiHarmonisedBridgeSource": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02023R1230-20260727",
      "aiAnnexIIIDelegatedActsBy": "2028-08-02",
      "evidenceGapNote": "Between 2027-01-20 (this Regulation applies) and 2028-08-02 (the delegated acts amending its Annex III apply), AI-driven machinery needs robustness evidence while no AI-specific harmonised standard under THIS Regulation yet exists to produce it against. Article 20(10) bridges the interval by borrowing the AI Act's standards; it does not fill it. The gap is wider than the dates alone say (checked 13 September 2026): no implementing decision citing any harmonised standard under this Regulation had been published, the first list is expected in Q4 2026 from a gap analysis of Directive-era standards, and no standard had been submitted for its cybersecurity or AI requirements (ibf-solutions, 25 August 2026; secondary). The one AI-adjacent standard on course to exist on 20 January 2027 is prEN 50742, Safety of machinery - Protection against corruption (CLC/TC 44X), written for EHSR 1.1.9 and 1.2.1: formal vote expected September 2026, publication planned November 2026 (secondary). The functional-safety texts for AI elements - ISO/IEC TS 22440-1/-2/-3, the successor to ISO/IEC TR 5469 - were at Committee Draft with publication expected in 2027, and IEC 61508 Edition 3 was at CDV with publication expected early 2027 (secondary). Under the AI Act itself, zero harmonised standards were cited in the Official Journal as of 3 August 2026 (Commission standardisation page; primary), so the Article 20(10) bridge had nothing to borrow yet."
    },
    {
      "id": "iso-10218",
      "framework": "ISO 10218-1/-2:2025",
      "title": "ISO 10218-1:2025 · ISO 10218-2:2025 (industrial robot safety, incl. cybersecurity)",
      "instrument": "ISO 10218-1:2025 / ISO 10218-2:2025",
      "provision": "Cybersecurity clauses — requirements added to the extent they apply to industrial robot safety; IEC 62443 appears only in the informative Bibliography",
      "status": "published",
      "statusNote": "Published February 2025 (ISO catalogue records 2025-02; secondary sources commonly cite 5 February). A publication date, not an entry-into-force date.",
      "applicableDate": "2025-02-05",
      "jurisdiction": "International (ISO)",
      "primarySource": "https://www.iso.org/standard/73933.html",
      "secondarySource": "https://www.iso.org/standard/73934.html",
      "lastVerified": "2026-09-06",
      "editorNote": "The 2025 revision added cybersecurity provisions for the first time and incorporated ISO/TS 15066:2016's power-and-force-limiting requirements. US national adoption is ANSI/A3 R15.06-2025 (see that entry).",
      "provaelSupports": "Adversarial-robustness evidence for the policy driving an industrial robot, mappable to a 10218-2 system assessment.",
      "provaelDoesNotEstablish": "Not conformity to ISO 10218; not a certificate.",
      "responsibleActor": "Robot integrator / system assessor.",
      "verificationNote": "Re-read on iso.org itself on 6 September 2026, in a browser rather than by automated fetch (the site answers 403 to the latter, which is why earlier verifications of this entry were weaker and said so). The catalogue record for ISO 10218-1:2025 shows Status: Published, Publication date: 2025-02, Edition 3, Stage 60.60 (International Standard published). The February 2025 date is therefore ISO's own; the 5 February day is from secondary sources and is not carried as a verified value. On the cyber question, see errata E-2026-07: the 2025 revision ADDS cybersecurity requirements to the extent they apply to industrial robot safety; IEC 62443 is not in Clause 2 Normative references and appears only in the informative Bibliography."
    },
    {
      "id": "iso-25785-1",
      "framework": "ISO 25785-1",
      "title": "ISO/CD 25785-1 — Robotics: safety requirements for dynamically stable industrial mobile robots (legged, wheeled, or other forms of locomotion) — Part 1: Robots",
      "instrument": "ISO/CD 25785-1 (ISO/TC 299 Working Group 12)",
      "provision": "The first Type-C standard aimed at robots with actively controlled stability — the balance-and-fall hazards a legged machine has and a statically stable one does not.",
      "status": "committee-draft-not-published",
      "statusNote": "Committee Draft. CD registered 8 May 2026; CD consultation opened 12 May 2026. No fixed publication date.",
      "applicableDate": null,
      "jurisdiction": "International",
      "primarySource": "https://www.iso.org/standard/91469.html",
      "secondarySource": null,
      "lastVerified": "2026-09-06",
      "editorNote": "Recorded because it is the adjacent gap to the Machinery Regulation's: a humanoid builder placing a machine on the EU market has ISO 10218-1/-2:2025 and nothing else that speaks to dynamic stability. NOTE the stage moved: this site previously described 25785-1 as a Working Draft, which was a stage out of date. CD is later than WD and is a material difference — a CD is out for committee consultation, a WD is not.",
      "provaelSupports": "Nothing toward conformity: there is no stable clause to cite. The humanoid attack family produces an anticipatory adversarial-robustness baseline that exists ahead of the standard.",
      "provaelDoesNotEstablish": "No conformity position of any kind against a text that is not published, and no prediction of what the published text will require.",
      "responsibleActor": "Manufacturer of the dynamically stable industrial mobile robot.",
      "verificationNote": "Re-read on iso.org itself on 6 September 2026, in a browser (the site answers 403 to automated fetch). The record shows Status: Under development, Stage 30.60 (close of comment period), Edition 1, Technical Committee ISO/TC 299, designation ISO/CD 25785-1. The stage number is now taken from the record rather than inferred from a catalogue listing, which is what the previous note flagged as the weak part of this citation. The WG 12 attribution is from ISO/TC 299's own committee structure and is not shown on the standard's record."
    },
    {
      "id": "eu-cyber-resilience-act",
      "framework": "EU Cyber Resilience Act",
      "title": "Regulation (EU) 2024/2847",
      "instrument": "Regulation (EU) 2024/2847",
      "provision": "Vulnerability handling, SBOM, security updates; reporting duties phase in ahead of full application",
      "status": "in-force",
      "statusNote": "Reporting obligations (Art. 14) have applied since 11 September 2026, and ENISA's Single Reporting Platform went live at initial operating capability the same day. Full application 11 December 2027.",
      "applicableDate": "2027-12-11",
      "reportingDate": "2026-09-11",
      "reportingProvision": "Article 14 — reporting obligations for actively exploited vulnerabilities and severe incidents",
      "reportingSubDeadlines": [
        {
          "within": "24 hours",
          "hours": 24,
          "requirement": "Early warning notification to the CSIRT designated as coordinator and to ENISA."
        },
        {
          "within": "72 hours",
          "hours": 72,
          "requirement": "Main notification, adding general information on the vulnerability or incident and any corrective or mitigating measures taken."
        },
        {
          "within": "14 days",
          "hours": 336,
          "requirement": "Final report on an actively exploited vulnerability (Art. 14(2)(c)) - due 14 days after a corrective or mitigating measure is available, not 14 days after awareness."
        },
        {
          "within": "one month",
          "hours": 720,
          "requirement": "Final report on a severe incident (Art. 14(4)(c)) - due one month after the 72-hour incident notification was submitted, NOT after a measure becomes available."
        }
      ],
      "reportingSubDeadlinesSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "reportingSubDeadlinesSourceLabel": "Article 14, Regulation (EU) 2024/2847 (Official Journal)",
      "reportingSubDeadlinesSourceNote": "MUST stay on eur-lex.europa.eu, and scripts/check-clock-sources.mjs fails the build if it moves. E-2026-04: these four rows were first transcribed from the Commission's CRA summary, whose phrasing does not carry the Art. 14(2)(c) / Art. 14(4)(c) distinction, and the incident branch was published with the vulnerability branch's start point. The correction moved this field to the OJ text. On 6 September 2026 it was moved back to the summary to resolve a label mismatch on /compliance/cra-incident-reporting - the wrong half of that mismatch. A secondary source is fine for FINDING a fact and not for PINNING one.",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "secondarySource": "https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act",
      "lastVerified": "2026-09-12",
      "editorNote": "Two different duties, and Provael is on the voluntary side of both. For a robot manufacturer the Act is binding: Article 14 reporting has applied to the installed base since 11 September 2026 (Art. 69(3)) and the product requirements apply to products placed on the market from 11 December 2027. Provael itself, as a non-monetised Apache-2.0 project, is outside the Act's scope - the Commission's first CRA guidance (approved 27 July 2026) confirms non-commercial free and open-source software is not 'made available on the market', and the open-source steward duties of Article 24 (from 11 December 2027, Art. 71(2)) attach to legal persons supporting software intended for commercial activity. Provael's SBOM, coordinated disclosure policy and security.txt are therefore voluntary alignment with the Act's vulnerability-handling expectations, not compliance with a duty it owes. Checked 13 September 2026.",
      "provaelSupports": "SBOM per release, a coordinated vulnerability-disclosure policy, and an RFC 9116 security.txt.",
      "provaelDoesNotEstablish": "A policy-attack result is not a vulnerability-handling process, and Article 14 is about the process. Article 14 obliges the manufacturer to NOTIFY actively exploited vulnerabilities and severe incidents to ENISA and the coordinating CSIRT on a fixed clock (24h / 72h / 14 days); a Provael run produces neither that process nor those notifications, and cannot start, satisfy or evidence that clock. CRA compliance remains a product-level obligation on the responsible economic operator.",
      "responsibleActor": "Manufacturer / economic operator placing the product on the EU market.",
      "verificationNote": "CELEX 32024R2847: \"shall apply from 11 December 2027\", with Article 14 reporting obligations applying from 11 September 2026. Sub-deadlines re-verified against the OJ text on 1 September 2026: the two final-report deadlines run from DIFFERENT events - Art. 14(2)(c) 14 days after a corrective or mitigating measure is available, Art. 14(4)(c) one month after the incident notification under Art. 14(4)(b) was submitted. Art. 69(3) is an express derogation from 69(2): Article 14 applies to all in-scope products placed on the market before 11 December 2027, so the reporting duty covers the installed base while the product requirements do not."
    },
    {
      "id": "nist-ai-rmf",
      "framework": "NIST AI RMF",
      "title": "NIST AI 100-1 · Generative AI Profile (NIST AI 600-1)",
      "instrument": "Voluntary framework",
      "provision": "Measure (2.7 - AI system security and resilience is evaluated) and Manage functions",
      "status": "voluntary-referenced",
      "statusNote": "Voluntary; widely referenced by auditors and US procurement. AI RMF 1.0 (NIST AI 100-1, released 26 January 2023) remains the current version and is under revision as part of the White House AI Action Plan, so the version an auditor cites today may not be the one they cite next year.",
      "applicableDate": null,
      "jurisdiction": "US (voluntary, international use)",
      "primarySource": "https://www.nist.gov/itl/ai-risk-management-framework",
      "secondarySource": "https://csrc.nist.gov/pubs/ai/100/2/e2025/final",
      "lastVerified": "2026-09-06",
      "editorNote": "Voluntary yardstick; no binding date.",
      "provaelSupports": "A measured ASR with a CI and a benign control as the Measure-function evidence; a CI red-team gate for the Manage function.",
      "provaelDoesNotEstablish": "The AI RMF is not certifiable; Provael provides evidence, not conformity.",
      "responsibleActor": "The organisation operating the AI system.",
      "verificationNote": "Re-verified against nist.gov on 6 September 2026. The page states AI RMF 1.0 was released 26 January 2023, is \"intended for voluntary use\", and \"is being revised as part of the White House AI Action Plan\". It also lists the Generative AI Profile (NIST AI 600-1, 26 July 2024) and a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure (7 April 2026). NIST AI 100-2e2025, the adversarial-ML taxonomy this project maps onto, is NOT referenced from that page and is cited here from its own CSRC record, which is the secondary source on this entry."
    },
    {
      "id": "iec-62443",
      "framework": "IEC 62443",
      "title": "IEC 62443 (series)",
      "instrument": "Multi-part standard series",
      "provision": "Security Levels (SL 1-4) for industrial automation and control systems",
      "status": "series-maintained",
      "statusNote": "Actively maintained series; referenced by industrial-security assessors.",
      "applicableDate": null,
      "jurisdiction": "International (IEC/ISA)",
      "primarySource": "https://www.iec.ch/cyber-security",
      "secondarySource": "https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards",
      "lastVerified": "2026-09-06",
      "editorNote": "A measured ASR under defined attack channels is evidence toward a target SL for the policy layer.",
      "provaelSupports": "Per-channel adversarial-robustness evidence framed against the SL model, foldable into a 62443-3-3 assessment.",
      "provaelDoesNotEstablish": "Not an SL certification.",
      "responsibleActor": "Integrator / asset owner.",
      "verificationNote": "Re-read on iec.ch on 6 September 2026, in a browser (the site answers 403 to automated fetch). The page states IEC TC 65 publishes IEC 62443 \"for operational technology found in industrial and critical infrastructure\" as a \"series of publications that specify security requirements for industrial automation and control systems (IACS)\", and that IECEE runs an Industrial Cyber Security Programme certifying against it. The SL 1-4 structure named in this entry's provision is from IEC 62443-3-3 and is NOT stated on that landing page; the ISA listing carried as the secondary source shows the series spanning 2007 to 2025 (ISA-TR62443-2-2-2025 is the most recent part listed), which is the evidence for \"actively maintained\"."
    },
    {
      "id": "eu-product-liability-directive",
      "framework": "EU Product Liability Directive",
      "title": "Directive (EU) 2024/2853 (revised product liability)",
      "instrument": "Directive (EU) 2024/2853 (repeals Directive 85/374/EEC)",
      "provision": "Software and AI systems are 'products'; lowered evidentiary burden; disclosure duties",
      "status": "adopted-transposition-pending",
      "statusNote": "Published OJ 18 November 2024; in force 8 December 2024; Member States must transpose by 9 December 2026. Applies to products placed on the market or put into service after 9 December 2026.",
      "applicableDate": "2026-12-09",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng",
      "secondarySource": null,
      "lastVerified": "2026-09-06",
      "editorNote": "The nearest EU deadline after the Machinery Regulation, and the one that bites hardest on an AI-driven robot: a defective-product claim no longer needs to prove the mechanism, and software counts as a product. Non-commercial free and open-source software is out of scope.",
      "provaelSupports": "Documented adversarial-robustness testing at the time of placing on the market — evidence toward the state-of-the-art and due-diligence positions a manufacturer will need to argue, and a dated artefact for the disclosure obligation.",
      "provaelDoesNotEstablish": "Does not establish a defence, does not determine defectiveness, and is not legal advice.",
      "responsibleActor": "Manufacturer / importer / authorised representative (and, for a component, its manufacturer).",
      "verificationNote": "Re-read on EUR-Lex on 6 September 2026. Article 2(1) confirms the Directive applies to products \"placed on the market or put into service after 9 December 2026\", which is the date this entry carries. The transposition deadline in the same words (\"bring into force ... by 9 December 2026\") was checked on 19 August 2026 at CELEX 32024L2853 and falls beyond the excerpt returned on this reading, so it is carried from that check rather than re-confirmed today."
    },
    {
      "id": "eu-ai-act-general-application",
      "framework": "EU AI Act",
      "title": "Regulation (EU) 2024/1689 — general application, transparency, governance and penalties",
      "instrument": "Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744",
      "provision": "Article 50 transparency; governance framework; notifying authorities; penalties",
      "status": "applies",
      "statusNote": "General application date 2 August 2026, retained by Regulation (EU) 2026/1744. Two further prohibited practices (non-consensual intimate imagery and CSAM) apply from 2 December 2026.",
      "applicableDate": "2026-08-02",
      "additionalDate": "2026-12-02",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
      "secondarySource": "https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng",
      "lastVerified": "2026-08-19",
      "editorNote": "Recorded because the high-risk deferral to 2027/2028 is often misread as deferring the whole Act. Transparency, governance and penalties still bite from 2 August 2026.",
      "provaelSupports": "Nothing directly — this entry exists so the clock is not misread as 'the AI Act does not apply yet'.",
      "provaelDoesNotEstablish": "Not a compliance position on any Article 50 obligation.",
      "responsibleActor": "Provider / deployer as applicable per obligation.",
      "verificationNote": "CELEX 32026R1744 confirms the 2 August 2026 general application date is retained, and that the amendment itself applies from 27 July 2026. Not re-verified on 6 September 2026: Regulation (EU) 2026/1744 was re-read that day and confirmed its own OJ, entry-into-force and Annex I / Annex III dates, but the retention of the 2 August 2026 general application date and the 2 December 2026 prohibited practices were not in the text returned, and this entry is not re-dated on a reading that did not reach them."
    },
    {
      "id": "kr-ai-framework-act",
      "framework": "Korea AI Framework Act",
      "title": "Framework Act on the Development of AI and Establishment of Trust (AI Basic Act)",
      "instrument": "Republic of Korea, Act No. 20676 (with Enforcement Decree)",
      "provision": "High-impact AI obligations, Art. 34(1): risk-management plan, human management and supervision, safety-and-reliability documentation",
      "status": "in-force",
      "statusNote": "Promulgated 21 January 2025 and in force 22 January 2026, one year later, under its own Addenda Art. 1, alongside its Enforcement Decree; the digital-medical-device part of Art. 2(4)(d) from 24 January 2026. The first enforceable comprehensive AI statute outside the EU. The Act itself defers nothing: its Addenda carry no provision postponing the penalty articles, so the widely repeated one-year grace before administrative fines is an MSIT enforcement-policy position rather than a statutory deferral.",
      "applicableDate": "2026-01-22",
      "jurisdiction": "KR",
      "primarySource": "https://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5%20%EB%B0%9C%EC%A0%84%EA%B3%BC%20%EC%8B%A0%EB%A2%B0%20%EA%B8%B0%EB%B0%98%20%EC%A1%B0%EC%84%B1%20%EB%93%B1%EC%97%90%20%EA%B4%80%ED%95%9C%20%EA%B8%B0%EB%B3%B8%EB%B2%95/(20676,20250121)",
      "secondarySource": "https://cset.georgetown.edu/publication/south-korea-ai-law-2025/",
      "lastVerified": "2026-09-12",
      "compliancePath": "/compliance/korea-ai-framework-act/",
      "editorNote": "Relevant to robotics, but the reach is sectoral rather than any-machine: Art. 2(4) makes a system high-impact only in an enumerated area (energy, drinking water, health care, medical devices, nuclear, biometrics for criminal investigation, employment and loan assessment, transport, public decisions, school assessment), so a VLA policy is inside the Act when deployed into one of those and a general factory arm is not enumerated. Art. 34(1)4 is Human management and supervision of high-impact AI; interruption and rollback do NOT appear in Art. 34, and the earlier wording here saying they did was wrong. Verify the current text and the fines position with Korean counsel.",
      "provaelSupports": "Adversarial-robustness evidence for a high-impact AI system's risk-management and human-oversight documentation.",
      "provaelDoesNotEstablish": "No Korean conformity or registration position; not legal advice.",
      "responsibleActor": "AI business operator placing a high-impact system on the Korean market.",
      "verificationNote": "Re-checked 12 September 2026 against the Act's own text, which upgrades the 6 September position and closes two of the three gaps it recorded. law.go.kr does have a stable per-statute URL after all: it is the Korean-language route, not the English portal, and it is now the primarySource, with perma.cc/CL3T-VHZ6 as the archived copy. READ THIS RUN, from the CSET English translation of Law No. 20676: Art. 2(4) high-impact definition and its enumerated areas, Art. 4(1) extraterritorial scope, Art. 32 compute-threshold safety duty and MSIT submission, Art. 33 advance self-review, Art. 34(1) the six high-impact duties, Art. 35 impact assessment, Art. 36 domestic representative, Art. 43 administrative fines, and the Addenda. CORRECTED AS A RESULT: the penalty deferral is not statutory, since the Addenda carry no such provision, and interruption and rollback are not Art. 34 duties. STILL NOT VERIFIED, because the Enforcement Decree text could not be retrieved this run: the compute threshold reported as 10^26 FLOPs, the domestic-representative user and revenue thresholds, any document retention period, and the one-year fines grace period. Those four are reported, not pinned. Verify with Korean counsel before relying on them."
    },
    {
      "id": "ansi-a3-r1506-2025",
      "framework": "ANSI/A3 R15.06-2025",
      "title": "ANSI/A3 R15.06-2025 (Parts 1+2) / ANSI/A3 R15.06-3-2025 (Part 3)",
      "instrument": "ANSI/A3 R15.06-2025 (Parts 1+2) / ANSI/A3 R15.06-3-2025 (Part 3)",
      "provision": "US industrial-robot safety, incl. the new cybersecurity provisions",
      "status": "published",
      "statusNote": "Parts 1 and 2 are the US national adoption of ISO 10218-1:2025 and ISO 10218-2:2025, reproducing them in their entirety, and replace ANSI/RIA R15.06-2012, which is withdrawn. Part 3 (Use of Industrial Robot Cells) is NOT an ISO adoption: it was developed in the United States with input from Canadian experts, so a US reader gets a clause set ISO 10218 does not contain.",
      "applicableDate": "2025-08-21",
      "jurisdiction": "US",
      "primarySource": "https://webstore.ansi.org/standards/ria/ansia3r15062025partspart",
      "secondarySource": "https://webstore.ansi.org/standards/ria/ansia3r15062025",
      "lastVerified": "2026-09-06",
      "editorNote": "The US route to the same clauses as ISO 10218:2025 — recorded so a US-market reader is not told the ISO entry is EU-only.",
      "provaelSupports": "The same adversarial-robustness evidence mappable to an ISO 10218-2 system assessment.",
      "provaelDoesNotEstablish": "Not conformity to R15.06; not a certificate.",
      "responsibleActor": "Robot integrator / system assessor (US).",
      "verificationNote": "CORRECTED on 6 September 2026 by reading the ANSI webstore records in a browser (they answer 403 to automated fetch, and the URL this entry previously cited, automate.org/a3-standards, answers 404 — a dead citation on a compliance clock). Two things were wrong. This entry named the designation ANSI/A3 R15.06-2025, whose record ANSI marks Historical and \"Revised By\" the three-part designation now carried above, which ANSI marks Most recent. And it described the standard purely as an ISO adoption, which is true of Parts 1 and 2 and not of Part 3. The 21 August 2025 date is retained as the approval date recorded when this entry was written; the ANSI records do not show a date, and secondary reporting puts availability-for-purchase in September 2025, which is downstream of approval rather than in conflict with it. Treat the day as unverified."
    },
    {
      "id": "nist-ai-agent-standards",
      "framework": "NIST AI Agent Standards Initiative",
      "title": "NIST CAISI AI Agent Standards Initiative (autonomous AI agents)",
      "instrument": "NIST Center for AI Standards and Innovation (CAISI) initiative",
      "provision": "Interoperability and security standards for AI agents capable of autonomous actions. Stated pillars: industry-led standards for AI agents, community-led interoperable agent protocols, and research into agent authentication and identity infrastructure. Accompanied by a Request for Information on AI Agent Security (comments closed 9 March 2026).",
      "status": "initiative-open",
      "statusNote": "Launched 17 February 2026. An initiative and RFI, NOT a published standard: there is no clause to conform to and no conformity route today.",
      "applicableDate": null,
      "jurisdiction": "US",
      "primarySource": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative",
      "secondarySource": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure",
      "lastVerified": "2026-09-06",
      "editorNote": "Recorded for what its published scope does NOT reach. As verified on the initiative page on 31 July 2026, the stated scope addresses autonomous SOFTWARE agents and makes no mention of robots, embodied AI, physical AI, autonomous vehicles or cyber-physical systems. That is an observation about the published scope on that date, NOT a statement that NIST has excluded embodied systems — NIST has said no such thing, and the scope may widen. Read the primary source before relying on this.",
      "provaelSupports": "Nothing yet. Provael measures a VLA policy's adversarial robustness in simulation; if the initiative's security-controls work later reaches embodied agents, that evidence would be the kind of input it calls for.",
      "provaelDoesNotEstablish": "Not conformity, not a certificate, not participation in the initiative, and no claim that NIST recognises Provael or its metric.",
      "responsibleActor": "Not yet assigned — no obligation exists under an open initiative.",
      "verificationNote": "Re-verified on the initiative page on 6 September 2026; the page's own last-updated stamp reads 14 August 2026. Still an initiative and not a standard: no published standard is listed, and the open items are the RFI on AI Agent Security (closed 9 March 2026), a draft concept paper on Software and AI Agent Identity and Authorization, and listening sessions. The scope observation stands unchanged on re-reading: the published scope addresses autonomous SOFTWARE agents and does not mention robots, embodied AI, physical AI, autonomous vehicles or cyber-physical systems. That is what the page says on this date, not a statement that NIST has excluded embodied systems."
    }
  ],
  "lastVerifiedNote": "DERIVED: the oldest per-entry lastVerified, never set by hand. The page can only claim to be as current as its least-recently-verified entry, so re-checking one instrument cannot refresh the whole clock. tests/regulatory-clock enforce this."
}