STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
12 INSTRUMENTS · LAST VERIFIED 2026-08-19

Every date, with its source and its limits.

The dated record behind the compliance pages, published so you can check it rather than take it. Each entry carries the instrument, its status, a link to the primary source, and — the part most vendor timelines omit — an explicit statement of what a Provael run does not establish for that instrument.

Next dated obligationLast dated obligation · EU Cyber Resilience Act

—Regulation (EU) 2024/2847

On this date, reporting obligations apply.

The timeline

Dated obligations, soonest first

Dates are the applicable date for the provision named, not the date the instrument entered into force — those differ, often by years, and the applicable date is the one a programme plans against.

  1. PublishedInternational (ISO)

    ISO 10218-1/-2:2025

    ISO 10218-1:2025 · ISO 10218-2:2025 (industrial robot safety, incl. cybersecurity)

    Cybersecurity clauses — requirements added to the extent they apply to industrial robot safety; IEC 62443 appears only in the informative Bibliography

    Published February 2025 (ISO catalogue records 2025-02; secondary sources commonly cite 5 February). A publication date, not an entry-into-force date.

    What Provael supports
    Adversarial-robustness evidence for the policy driving an industrial robot, mappable to a 10218-2 system assessment.
    What it does not establish
    Not conformity to ISO 10218; not a certificate.
    Who is responsible
    Robot integrator / system assessor.

    ISO 10218-1/-2:2025, 5 February 2025 — Primary source ISO 10218-1/-2:2025 — Secondary source verified 2026-09-06

  2. PublishedUS

    ANSI/A3 R15.06-2025

    ANSI/A3 R15.06-2025 (Parts 1+2) / ANSI/A3 R15.06-3-2025 (Part 3)

    US industrial-robot safety, incl. the new cybersecurity provisions

    Parts 1 and 2 are the US national adoption of ISO 10218-1:2025 and ISO 10218-2:2025, reproducing them in their entirety, and replace ANSI/RIA R15.06-2012, which is withdrawn. Part 3 (Use of Industrial Robot Cells) is NOT an ISO adoption: it was developed in the United States with input from Canadian experts, so a US reader gets a clause set ISO 10218 does not contain.

    What Provael supports
    The same adversarial-robustness evidence mappable to an ISO 10218-2 system assessment.
    What it does not establish
    Not conformity to R15.06; not a certificate.
    Who is responsible
    Robot integrator / system assessor (US).

    ANSI/A3 R15.06-2025, 21 August 2025 — Primary source ANSI/A3 R15.06-2025 — Secondary source verified 2026-09-06

  3. In forceKR

    Korea AI Framework Act

    Framework Act on the Development of AI and Establishment of Trust (AI Basic Act)

    High-impact AI obligations, Art. 34(1): risk-management plan, human management and supervision, safety-and-reliability documentation

    Promulgated 21 January 2025 and in force 22 January 2026, one year later, under its own Addenda Art. 1, alongside its Enforcement Decree; the digital-medical-device part of Art. 2(4)(d) from 24 January 2026. The first enforceable comprehensive AI statute outside the EU. The Act itself defers nothing: its Addenda carry no provision postponing the penalty articles, so the widely repeated one-year grace before administrative fines is an MSIT enforcement-policy position rather than a statutory deferral.

    What Provael supports
    Adversarial-robustness evidence for a high-impact AI system's risk-management and human-oversight documentation.
    What it does not establish
    No Korean conformity or registration position; not legal advice.
    Who is responsible
    AI business operator placing a high-impact system on the Korean market.

    Korea AI Framework Act, 22 January 2026 — Primary source Korea AI Framework Act — Secondary source Korea AI Framework Act, 22 January 2026 — Provael crosswalk verified 2026-09-12

  4. Applies nowEU

    EU AI Act

    Regulation (EU) 2024/1689 — general application, transparency, governance and penalties

    Article 50 transparency; governance framework; notifying authorities; penalties

    General application date 2 August 2026, retained by Regulation (EU) 2026/1744. Two further prohibited practices (non-consensual intimate imagery and CSAM) apply from 2 December 2026.

    What Provael supports
    Nothing directly — this entry exists so the clock is not misread as 'the AI Act does not apply yet'.
    What it does not establish
    Not a compliance position on any Article 50 obligation.
    Who is responsible
    Provider / deployer as applicable per obligation.

    EU AI Act, 2 August 2026 — Primary source EU AI Act — Secondary source verified 2026-08-19

  5. Adopted, transposition pendingEU

    EU Product Liability Directive

    Directive (EU) 2024/2853 (revised product liability)

    Software and AI systems are 'products'; lowered evidentiary burden; disclosure duties

    Published OJ 18 November 2024; in force 8 December 2024; Member States must transpose by 9 December 2026. Applies to products placed on the market or put into service after 9 December 2026.

    What Provael supports
    Documented adversarial-robustness testing at the time of placing on the market — evidence toward the state-of-the-art and due-diligence positions a manufacturer will need to argue, and a dated artefact for the disclosure obligation.
    What it does not establish
    Does not establish a defence, does not determine defectiveness, and is not legal advice.
    Who is responsible
    Manufacturer / importer / authorised representative (and, for a component, its manufacturer).

    EU Product Liability Directive, 9 December 2026 — Primary source verified 2026-09-06

  6. Adopted, applies fromEU

    EU Machinery Regulation

    Regulation (EU) 2023/1230

    Article 54; safety components with self-evolving behaviour pulled into conformity assessment

    Adopted; applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023).

    What Provael supports
    Evidence that an AI-driven safety function resists instruction- and perception-level manipulation in simulation, with a measured redirection rate and CI, feeding the technical documentation for a conformity assessment.
    What it does not establish
    Not a conformity assessment, not a certificate; Provael is not a notified body.
    Who is responsible
    Manufacturer of the machinery / safety component (and a notified body for the third-party route).

    EU Machinery Regulation, 20 January 2027 — Primary source EU Machinery Regulation — Secondary source verified 2026-08-20

  7. In forceEU

    EU Cyber Resilience Act

    Regulation (EU) 2024/2847

    Vulnerability handling, SBOM, security updates; reporting duties phase in ahead of full application

    Reporting obligations (Art. 14) have applied since 11 September 2026, and ENISA's Single Reporting Platform went live at initial operating capability the same day. Full application 11 December 2027.

    Article 14 — reporting obligations for actively exploited vulnerabilities and severe incidents — from

    1. 24 hoursEarly warning notification to the CSIRT designated as coordinator and to ENISA.
    2. 72 hoursMain notification, adding general information on the vulnerability or incident and any corrective or mitigating measures taken.
    3. 14 daysFinal report on an actively exploited vulnerability (Art. 14(2)(c)) - due 14 days after a corrective or mitigating measure is available, not 14 days after awareness.
    4. one monthFinal report on a severe incident (Art. 14(4)(c)) - due one month after the 72-hour incident notification was submitted, NOT after a measure becomes available.

    EU Cyber Resilience Act reporting sub-deadlines — Article 14, Regulation (EU) 2024/2847 (Official Journal)

    What Provael supports
    SBOM per release, a coordinated vulnerability-disclosure policy, and an RFC 9116 security.txt.
    What it does not establish
    A policy-attack result is not a vulnerability-handling process, and Article 14 is about the process. Article 14 obliges the manufacturer to NOTIFY actively exploited vulnerabilities and severe incidents to ENISA and the coordinating CSIRT on a fixed clock (24h / 72h / 14 days); a Provael run produces neither that process nor those notifications, and cannot start, satisfy or evidence that clock. CRA compliance remains a product-level obligation on the responsible economic operator.
    Who is responsible
    Manufacturer / economic operator placing the product on the EU market.

    EU Cyber Resilience Act, 11 December 2027 — Primary source EU Cyber Resilience Act — Secondary source verified 2026-09-12

  8. Amended, in forceEU

    EU AI Act

    Regulation (EU) 2024/1689 - Article 15 (accuracy, robustness, cybersecurity)

    Article 15; applied to high-risk product-embedded AI systems (Annex I). NOTE: Regulation (EU) 2026/1744 moved Machinery Regulation (EU) 2023/1230 from AI Act Annex I Section A to Section B, so AI Act Chapter III (including Article 15) no longer applies DIRECTLY to AI-enabled machinery.

    Regulation (EU) 2026/1744: Parliament 16 June 2026, Council 29 June 2026, published OJ 24 July 2026, in force 27 July 2026.

    For machinery, the AI-robustness requirements are carried across by Commission delegated acts amending Annex III of Regulation (EU) 2023/1230, applicable by 2 August 2028 — not by direct application of AI Act Chapter III.

    What Provael supports
    A measured attack-success rate with a 95% Wilson CI and a benign control is candidate evidence toward Art. 15 robustness documentation.
    What it does not establish
    Does not establish conformity, is not certification, and is not a notified-body opinion.
    Who is responsible
    Provider of the high-risk AI system / product manufacturer (and a notified body where a third-party route applies).

    EU AI Act, 2 August 2028 — Primary source EU AI Act — Secondary source verified 2026-09-06

No deadline

Frameworks with no fixed date

Kept on the page and labelled rather than dropped. "There is no deadline" is a fact a programme needs, and omitting these would make the list above read as a complete set of obligations when 4 of 12 entries are not deadlines at all.

  • Committee Draft, not publishedInternational

    ISO 25785-1

    ISO/CD 25785-1 — Robotics: safety requirements for dynamically stable industrial mobile robots (legged, wheeled, or other forms of locomotion) — Part 1: Robots

    No fixed applicable date

    What Provael supports
    Nothing toward conformity: there is no stable clause to cite. The humanoid attack family produces an anticipatory adversarial-robustness baseline that exists ahead of the standard.
    What it does not establish
    No conformity position of any kind against a text that is not published, and no prediction of what the published text will require.

    ISO 25785-1 — Primary source verified 2026-09-06

  • Voluntary frameworkUS (voluntary, international use)

    NIST AI RMF

    NIST AI 100-1 · Generative AI Profile (NIST AI 600-1)

    No fixed applicable date

    What Provael supports
    A measured ASR with a CI and a benign control as the Measure-function evidence; a CI red-team gate for the Manage function.
    What it does not establish
    The AI RMF is not certifiable; Provael provides evidence, not conformity.

    NIST AI RMF — Primary source NIST AI RMF — Secondary source verified 2026-09-06

  • Maintained standard seriesInternational (IEC/ISA)

    IEC 62443

    IEC 62443 (series)

    No fixed applicable date

    What Provael supports
    Per-channel adversarial-robustness evidence framed against the SL model, foldable into a 62443-3-3 assessment.
    What it does not establish
    Not an SL certification.

    IEC 62443 — Primary source IEC 62443 — Secondary source verified 2026-09-06

  • Open initiativeUS

    NIST AI Agent Standards Initiative

    NIST CAISI AI Agent Standards Initiative (autonomous AI agents)

    No fixed applicable date

    What Provael supports
    Nothing yet. Provael measures a VLA policy's adversarial robustness in simulation; if the initiative's security-controls work later reaches embodied agents, that evidence would be the kind of input it calls for.
    What it does not establish
    Not conformity, not a certificate, not participation in the initiative, and no claim that NIST recognises Provael or its metric.

    NIST AI Agent Standards Initiative — Primary source NIST AI Agent Standards Initiative — Secondary source verified 2026-09-06

How to use it

What this page is, and is not

It is dated editorial data, maintained by hand and re-verified against primary sources. It is not legal advice and not a compliance determination. Every entry names the primary source precisely so you can stop trusting this page at the moment it matters.

For how each instrument maps onto a Provael artifact, see the standards crosswalk. For the machinery pathway specifically, see Machinery Regulation 2027.