· Regulatory framework

AI agent compliance frameworks.

The European Union's AI Act — formally Regulation (EU) 2024/1689 — the EU AI Act — is the first horizontal regulation of artificial intelligence systems. It assigns each AI application a risk tier and concentrates its binding obligations on the providers of systems classified as “high-risk” under Annex III (biometrics, critical infrastructure, education, employment, essential services, law enforcement and migration) and on general-purpose AI models with systemic risk. Provably is built so a partner operator can credibly discharge those obligations at the layer where a human verifier meets an AI agent.

High-risk system obligations. Providers of high-risk AI systems must establish a risk-management system across the full lifecycle (Article 9), maintain the technical documentation described in Article 11 — including the intended purpose, design choices, and data governance measures — and operate post-market monitoring so that serious incidents and malfunctions are logged and reviewed. Training, validation and test datasets must be relevant, representative, and free of errors to the extent required by Article 10, and the system itself must meet the accuracy, robustness, and cybersecurity benchmarks set out in Article 15 before deployment.

Human oversight (Article 14). Article 14 requires that high-risk AI systems be designed so that natural persons assigned to oversight can properly understand the system's capacities and limitations, detect signalled anomalies, decide not to use the system in a given situation, and intervene — including by aborting the operation — where the model behaves in an unexpected way. The verifier is therefore not a passive observer but a control point with the authority and the interface to override the automated decision. Provably's protocol is engineered around that requirement: each receipt lists the verifier identity and the timestamp at which the human attested to the counterparty, so an auditor can reconstruct who decided what, and when.

Transparency and conformity. Providers must register high-risk systems in the EU database (Article 49), affix the CE marking (Article 48), and supply instructions for use that explain the system's purpose, its accuracy levels, and the foreseeable risks of misuse. The obligations on importers, distributors and deployers cascade from those on the provider, which is why verification cannot be delegated to an opaque downstream service. Full text of the regulation is available on EUR-Lex at eur-lex.europa.eu/eli/reg/2024/1689/oj.

· Regulatory framework

NIST AI Risk Management Framework 1.0.

The NIST AI Risk Management Framework 1.0 (NIST AI RMF 1.0) is a voluntary US government framework organised around four core functions — Govern, Map, Measure, and Manage — that help organisations identify, analyse and manage the risks of AI systems across their full lifecycle. It is intended to align with emerging US federal AI guidance and to complement sectoral obligations, and it is widely adopted as a baseline for trustworthy AI governance. Full text of the framework is published on the NIST Information Technology Laboratory site at nist.gov/itl/ai-risk-management-framework.

Voluntary core functions. Govern establishes the policies, processes, roles and accountability an organisation uses to manage AI risk at the portfolio level; Map establishes the context, frames the risks for each AI system, and identifies the affected actors and use cases; Measure applies quantitative, qualitative or mixed-method techniques to analyse, benchmark and monitor AI risk and its impacts; and Manage allocates resources and mitigation plans to act on the risks the prior functions surface. Together they form a continuous improvement loop rather than a one-time certification, which makes the framework a natural complement to the binding obligations of the EU AI Act for organisations operating on both sides of the Atlantic.

· Regulatory framework

ISO/IEC 42001:2023 AI management system.

ISO/IEC 42001:2023 is the first certifiable AI management system standard and gives organisations a single, auditable way to govern the responsible use of artificial intelligence. It defines an AI Management System (AIMS) structured around the Plan–Do–Check–Act cycle, so policies, risk treatment, performance evaluation and continual improvement live in one integrated loop rather than ad-hoc reviews. For operators that already document controls for the EU AI Act or the NIST AI RMF, the standard provides a third-party-recognised framework for confirming that those controls are in place and maintained. The full text is published by ISO at iso.org/standard/42001.

Plan–Do–Check–Act AIMS structure. Clause 4 places the AIMS in the context of the organisation — its purpose, its interested parties, and the scope of the AI activities it covers — and Clause 5 establishes the leadership and top-management accountability that the standard requires. Clause 6 (Planning) addresses AI risks, opportunities, and the statement of applicability for the controls Annex A lists; Clause 7 (Support) governs resources, competence, awareness, communication and documented information; Clause 8 (Operation) covers operational planning and the execution of AI-specific controls; Clause 9 (Performance evaluation) sets out monitoring, measurement, internal audit and management review; and Clause 10 (Improvement) requires corrective action and continual improvement of the AIMS, so a verifier can trace how an operator closes the loop between an identified AI risk and the change made to address it.

· Regulatory framework

Algorithmic Accountability Act.

The Algorithmic Accountability Act (H.R. 6580) is a congressional proposal that would require companies deploying automated decision systems to conduct impact assessments of those systems' risks, accuracy, and bias before deployment. Introduced repeatedly in the US House of Representatives without enactment to date, the bill is aimed at giving the Federal Trade Commission authority to study and report on algorithmic harms and at requiring covered entities to publish documentation on how their automated systems affect consumers. Full text and current bill status are available on Congress.gov at congress.gov/bill/117th-congress/house-bill/6580.

Automated decision system impact assessments. If enacted, the bill would direct the Federal Trade Commission to identify covered automated decision systems and require their deployers to evaluate, on a recurring basis, the system's purpose, the data it consumes, the accuracy and fairness of its outputs, and the steps taken to mitigate identified harms. The impact-assessment framework the bill sketches is closer in spirit to the EIA regimes emerging in the EU and Canada than to a product-safety regime, and it is intended to give consumers documented transparency into how consequential algorithmic decisions are made about them. For US operators that already document controls for the EU AI Act or the NIST AI RMF, the proposal would close a domestic gap by binding the same risk-evaluation discipline to in-scope deployments on US soil.

· Regulatory framework

OECD AI Principles.

The OECD AI Principles, first adopted in 2019 by the OECD Council and updated in 2024 to address generative AI, are the first intergovernmental standard on AI and the policy backbone for many national AI strategies. They set out five values-based principles for trustworthy AI — inclusive growth, human-centered values, transparency, robustness, and accountability — that signatories commit to respect when designing and operating AI systems. Endorsed by the G20 and adopted by more than forty-seven OECD members and partner economies, the principles serve as a common reference point that national AI strategies, including those shaping the EU AI Act and the NIST AI RMF, draw upon. Full text and the 2024 update are published on the OECD AI policy observatory at oecd.ai/en/ai-principles.

G20 endorsement and 2024 update. Originally adopted by the OECD Council in May 2019 and welcomed by the G20 under the Japanese presidency, the principles were refreshed in May 2024 to extend the same values to generative AI systems and to clarify how transparency, robustness and accountability apply to foundation models. With more than forty-seven adherents spanning OECD members and partner economies, the framework carries policy weight even where it is not legally binding, and it is the most-cited intergovernmental reference in national AI strategies.

· Regulatory framework

Interim Measures for the Management of Generative AI Services (CAC, 2023).

The Interim Measures for the Management of Generative AI Services, issued by the Cyberspace Administration of China in July 2023 and effective 15 August 2023, are the first national-level regulation to govern generative AI services offered to the Chinese public. They require providers to complete a security assessment with the CAC before launch, to add visible content labeling to AI-generated text, image, audio and video outputs, and to demonstrate that their training data was sourced lawfully and respects the rights of data subjects. The measures apply to any generative AI service whose output is reachable by users in mainland China, and they couple the security assessment, content labeling and data training obligations with personal liability for the provider’s responsible personnel. Full text is published on the CAC website at cac.gov.cn/2023-07/13/c_1690898327029107.htm.

Security assessment, content labeling, and data training compliance. A provider of a generative AI service that serves users in mainland China must submit its model and service to a security assessment with the CAC before public release, including the algorithm filing described in Article 17 and the registration of the public-facing service under the accompanying CAC rules. AI-generated content — text, images, audio, video and any other synthetic output the service produces — must be labelled in a way that is conspicuous to the user, so that downstream consumers and platforms can distinguish machine-generated from human-generated material. The provider must also demonstrate that its training data was sourced lawfully: pre-training and fine-tuning datasets must come from channels that respect copyright, personal information, and the other rights protected under Chinese law, and providers must keep the records needed to substantiate the lawful-source claim during the security assessment. The measures took effect on 15 August 2023 and are enforced alongside China’s Personal Information Protection Law, Cybersecurity Law and Interim Measures on Deep Synthesis, so a China-facing operator has to discharge the security assessment, the content labeling obligation, and the training-data lawful-source requirement as one coordinated compliance programme rather than three independent ones.

· Regulatory framework

Model AI Governance Framework (Singapore IMDA/PDPC, 2020).

The Model AI Governance Framework, published by Singapore’s Infocomm Media Development Authority (IMDA) and Personal Data Protection Commission (PDPC) in the second edition of 2020, sets out the leading voluntary governance model for AI deployments in the Asia-Pacific region and is widely adopted by enterprises that operate AI systems at scale. It rests on two guiding principles — that decisions made by AI should be explainable, transparent, and fair, and that AI solutions should be human-centric — and pairs each principle with implementation guidance covering internal governance, risk management, and the human review of automated decisions. Full text is published on the PDPC site at pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework.

Explainable, transparent and fair decisions. The first guiding principle requires that AI-driven decisions be explainable, transparent, and fair, which the framework operationalises through model cards, algorithm-agnostic documentation, and a structured review process that lets a deployer surface and remedy the data, feature and outcome biases that arise in production. The model governance lifecycle IMDA and the PDPC describe progresses from use-case intake through data provenance, feature selection, training, evaluation, deployment and ongoing monitoring, with each stage producing the evidence a human reviewer needs to challenge an automated outcome and to rebuild the audit trail end to end.

Human-centric AI and Asia-Pacific adoption. The second guiding principle positions AI solutions as human-centric, orienting every implementation decision around the impact on the people who are subject to or affected by the system. The framework doubles as the reference document most Asia-Pacific enterprises adopt when they map their AI controls to a published voluntary standard, so a verifier reconciling a Provably receipt with an operator’s wider governance programme will typically encounter the IMDA/PDPC model as the regional baseline alongside the EU AI Act, the NIST AI RMF and the OECD AI Principles.

· Regulatory framework

Artificial Intelligence and Data Act (AIDA, Canada, Bill C-27).

The Artificial Intelligence and Data Act (AIDA), introduced as Part 1 of Bill C-27 in the Canadian Parliament, is Canada's first federal legislation specifically dedicated to regulating artificial intelligence systems and is being framed as a risk-based regime that concentrates binding obligations on providers of high-impact AI systems. It requires those providers to conduct impact assessments before deploying a high-impact system, to put in place monitoring and mitigation measures for biased or harmful outputs, and to meet transparency obligations including disclosing AI-generated content to end users. Full text of the enacted-in-principle framework and current bill status is published on the Innovation, Science and Economic Development Canada site at ist.canada.ca/en/artificial-intelligence-and-data-act.

Risk-based regulation of high-impact AI systems. The Act classifies AI systems by risk tier and applies its most stringent obligations to high-impact systems — those used in decisions about employment, healthcare, financial services, justice, and other consequential contexts — while leaving lower-risk systems under lighter requirements. Providers of high-impact systems must establish a risk-management framework, maintain technical documentation, and operate post-market monitoring so serious incidents and malfunctions are logged, reviewed, and remediated over the system lifecycle.

Impact assessments and transparency obligations. Before deploying a high-impact AI system a provider must conduct an impact assessment that documents the system purpose, the data it consumes, the foreseeable harms, and the mitigation measures put in place; the assessment must be kept current and made available to the regulator on request. The Act also imposes transparency obligations — including informing end users when they are interacting with an AI system and labeling AI-generated content — so a downstream consumer or auditor can reconstruct why a given automated decision was made.

New regulatory frameworks ship alongside new endpoints and attestation surfaces. See the recent updates in our changelog for the changes that justify the latest framework coverage.