The dated record behind the compliance pages, published so you can check it rather than take it. Each entry carries the instrument, its status, a link to the primary source, and — the part most vendor timelines omit — an explicit statement of what a Provael run does not establish for that instrument.
Verified against EUR-Lex, ISO, NIST, A3 (Automate), CSET
Next dated obligationLast dated obligation · EU Cyber Resilience Act
--days:--hrs:--minIn force since 11 September 2026
—Regulation (EU) 2024/2847
On this date, reporting obligations apply.
“Next” is measured against , the date this site’s evidence was last pinned — the build carries no wall clock, by design, so it cannot ask what today is. The clock’s own entries were last verified against primary sources on , which is the older of the two and is the number to judge this page by — it is the OLDEST of the per-entry dates, derived rather than set, so re-checking one instrument cannot refresh the whole clock. Re-verified within 30 days of the date above; past 90 days the build fails.2 of 12 entries were re-read against primary sources on 2026-09-12, including the corrigendum that governs the Machinery Regulation date; the remainder still carry 2026-08-19.
Not legal advice. This is dated editorial data, not a legal opinion. Verify against the primary official source before relying on any date. A date on this page has been wrong before and was corrected in public — see errata. If you hold a signed attestation bundle, check there before relying on a date inside it.
The timeline
Dated obligations, soonest first
Dates are the applicable date for the provision named, not the date the instrument entered into force — those differ, often by years, and the applicable date is the one a programme plans against.
PublishedInternational (ISO)
ISO 10218-1/-2:2025
ISO 10218-1:2025 · ISO 10218-2:2025 (industrial robot safety, incl. cybersecurity)
Cybersecurity clauses — requirements added to the extent they apply to industrial robot safety; IEC 62443 appears only in the informative Bibliography
Published February 2025 (ISO catalogue records 2025-02; secondary sources commonly cite 5 February). A publication date, not an entry-into-force date.
What Provael supports
Adversarial-robustness evidence for the policy driving an industrial robot, mappable to a 10218-2 system assessment.
US industrial-robot safety, incl. the new cybersecurity provisions
Parts 1 and 2 are the US national adoption of ISO 10218-1:2025 and ISO 10218-2:2025, reproducing them in their entirety, and replace ANSI/RIA R15.06-2012, which is withdrawn. Part 3 (Use of Industrial Robot Cells) is NOT an ISO adoption: it was developed in the United States with input from Canadian experts, so a US reader gets a clause set ISO 10218 does not contain.
What Provael supports
The same adversarial-robustness evidence mappable to an ISO 10218-2 system assessment.
Framework Act on the Development of AI and Establishment of Trust (AI Basic Act)
High-impact AI obligations, Art. 34(1): risk-management plan, human management and supervision, safety-and-reliability documentation
Promulgated 21 January 2025 and in force 22 January 2026, one year later, under its own Addenda Art. 1, alongside its Enforcement Decree; the digital-medical-device part of Art. 2(4)(d) from 24 January 2026. The first enforceable comprehensive AI statute outside the EU. The Act itself defers nothing: its Addenda carry no provision postponing the penalty articles, so the widely repeated one-year grace before administrative fines is an MSIT enforcement-policy position rather than a statutory deferral.
What Provael supports
Adversarial-robustness evidence for a high-impact AI system's risk-management and human-oversight documentation.
What it does not establish
No Korean conformity or registration position; not legal advice.
Who is responsible
AI business operator placing a high-impact system on the Korean market.
General application date 2 August 2026, retained by Regulation (EU) 2026/1744. Two further prohibited practices (non-consensual intimate imagery and CSAM) apply from 2 December 2026.
What Provael supports
Nothing directly — this entry exists so the clock is not misread as 'the AI Act does not apply yet'.
What it does not establish
Not a compliance position on any Article 50 obligation.
Software and AI systems are 'products'; lowered evidentiary burden; disclosure duties
Published OJ 18 November 2024; in force 8 December 2024; Member States must transpose by 9 December 2026. Applies to products placed on the market or put into service after 9 December 2026.
What Provael supports
Documented adversarial-robustness testing at the time of placing on the market — evidence toward the state-of-the-art and due-diligence positions a manufacturer will need to argue, and a dated artefact for the disclosure obligation.
What it does not establish
Does not establish a defence, does not determine defectiveness, and is not legal advice.
Who is responsible
Manufacturer / importer / authorised representative (and, for a component, its manufacturer).
Article 54; safety components with self-evolving behaviour pulled into conformity assessment
Adopted; applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023).
What Provael supports
Evidence that an AI-driven safety function resists instruction- and perception-level manipulation in simulation, with a measured redirection rate and CI, feeding the technical documentation for a conformity assessment.
What it does not establish
Not a conformity assessment, not a certificate; Provael is not a notified body.
Who is responsible
Manufacturer of the machinery / safety component (and a notified body for the third-party route).
Vulnerability handling, SBOM, security updates; reporting duties phase in ahead of full application
Reporting obligations (Art. 14) have applied since 11 September 2026, and ENISA's Single Reporting Platform went live at initial operating capability the same day. Full application 11 December 2027.
Article 14 — reporting obligations for actively exploited vulnerabilities and severe incidents — from
24 hoursEarly warning notification to the CSIRT designated as coordinator and to ENISA.
72 hoursMain notification, adding general information on the vulnerability or incident and any corrective or mitigating measures taken.
14 daysFinal report on an actively exploited vulnerability (Art. 14(2)(c)) - due 14 days after a corrective or mitigating measure is available, not 14 days after awareness.
one monthFinal report on a severe incident (Art. 14(4)(c)) - due one month after the 72-hour incident notification was submitted, NOT after a measure becomes available.
SBOM per release, a coordinated vulnerability-disclosure policy, and an RFC 9116 security.txt.
What it does not establish
A policy-attack result is not a vulnerability-handling process, and Article 14 is about the process. Article 14 obliges the manufacturer to NOTIFY actively exploited vulnerabilities and severe incidents to ENISA and the coordinating CSIRT on a fixed clock (24h / 72h / 14 days); a Provael run produces neither that process nor those notifications, and cannot start, satisfy or evidence that clock. CRA compliance remains a product-level obligation on the responsible economic operator.
Who is responsible
Manufacturer / economic operator placing the product on the EU market.
Article 15; applied to high-risk product-embedded AI systems (Annex I). NOTE: Regulation (EU) 2026/1744 moved Machinery Regulation (EU) 2023/1230 from AI Act Annex I Section A to Section B, so AI Act Chapter III (including Article 15) no longer applies DIRECTLY to AI-enabled machinery.
Regulation (EU) 2026/1744: Parliament 16 June 2026, Council 29 June 2026, published OJ 24 July 2026, in force 27 July 2026.
For machinery, the AI-robustness requirements are carried across by Commission delegated acts amending Annex III of Regulation (EU) 2023/1230, applicable by 2 August 2028 — not by direct application of AI Act Chapter III.
What Provael supports
A measured attack-success rate with a 95% Wilson CI and a benign control is candidate evidence toward Art. 15 robustness documentation.
What it does not establish
Does not establish conformity, is not certification, and is not a notified-body opinion.
Who is responsible
Provider of the high-risk AI system / product manufacturer (and a notified body where a third-party route applies).
Kept on the page and labelled rather than dropped. "There is no deadline" is a fact a programme needs, and omitting these would make the list above read as a complete set of obligations when 4 of 12 entries are not deadlines at all.
Committee Draft, not publishedInternational
ISO 25785-1
ISO/CD 25785-1 — Robotics: safety requirements for dynamically stable industrial mobile robots (legged, wheeled, or other forms of locomotion) — Part 1: Robots
No fixed applicable date
What Provael supports
Nothing toward conformity: there is no stable clause to cite. The humanoid attack family produces an anticipatory adversarial-robustness baseline that exists ahead of the standard.
What it does not establish
No conformity position of any kind against a text that is not published, and no prediction of what the published text will require.
NIST CAISI AI Agent Standards Initiative (autonomous AI agents)
No fixed applicable date
What Provael supports
Nothing yet. Provael measures a VLA policy's adversarial robustness in simulation; if the initiative's security-controls work later reaches embodied agents, that evidence would be the kind of input it calls for.
What it does not establish
Not conformity, not a certificate, not participation in the initiative, and no claim that NIST recognises Provael or its metric.
It is dated editorial data, maintained by hand and re-verified against primary sources. It is not legal advice and not a compliance determination. Every entry names the primary source precisely so you can stop trusting this page at the moment it matters.