{"data":{"slug":"ai-audit-evidence-tracker","title":"AI Audit Evidence Tracker","type":"register","formats":["xlsx"],"topics":["evidence","governance"],"frameworks":["iso-42001","nist-ai-rmf","eu-ai-act"],"short":"Every piece of evidence the recorded controls expect, one row each, with owner, status, location and review date, so an audit or certification starts from a complete list.","covers":{"frameworks":["iso-42001","nist-ai-rmf"]},"version":1,"dataset_version":"bb068ecd9dad","generated_at":"2026-09-28T10:04:00+00:00","citations":105,"downloads":2,"files":[{"format":"xlsx","filename":"ai-audit-evidence-tracker-v1.xlsx","bytes":23438,"url":"https://aipolicytracker.org/templates/ai-audit-evidence-tracker#download"}],"url":"https://aipolicytracker.org/templates/ai-audit-evidence-tracker","inside":["Evidence tracker: control, evidence expected, kind, owner, status, location, last reviewed","Status colouring for missing and available evidence","Controls sheet: every control on record with its duties and framework references"],"legal_basis":["iso-42001","us-nist-ai-rmf"],"caveat":null,"covered_obligations":[{"slug":"australia-vaiss-accountability-and-risk-management","title":"Establish accountability processes and a risk-management process (guardrails 1 and 2)","policy":"australia-voluntary-ai-safety-standard","source_reference":"Guardrails 1 and 2","url":"https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management"},{"slug":"australia-vaiss-testing-human-control-transparency","title":"Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)","policy":"australia-voluntary-ai-safety-standard","source_reference":"Guardrails 4, 5 and 6","url":"https://aipolicytracker.org/obligations/australia-vaiss-testing-human-control-transparency"},{"slug":"australia-vaiss-contestability-supply-chain-records","title":"Provide contestability, supply-chain transparency and records (guardrails 7 to 9)","policy":"australia-voluntary-ai-safety-standard","source_reference":"Guardrails 7, 8 and 9","url":"https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records"},{"slug":"us-california-sb-53-frontier-ai-framework","title":"Large frontier developers must publish a frontier AI framework","policy":"us-california-sb-53","source_reference":"Business and Professions Code, Chapter 25.1 (as added by SB 53)","url":"https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework"},{"slug":"us-california-sb-53-critical-safety-incident-reporting","title":"Report critical safety incidents to the Office of Emergency Services","policy":"us-california-sb-53","source_reference":"Business and Professions Code, Chapter 25.1 (as added by SB 53)","url":"https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting"},{"slug":"us-california-sb-53-transparency-report","title":"Frontier developers must publish a transparency report before deploying a new frontier model","policy":"us-california-sb-53","source_reference":"Business and Professions Code Section 22757.12 (as added by SB 53)","url":"https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report"},{"slug":"us-california-sb-53-catastrophic-risk-assessment-summaries","title":"Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state","policy":"us-california-sb-53","source_reference":"Business and Professions Code Section 22757.12 (as added by SB 53)","url":"https://aipolicytracker.org/obligations/us-california-sb-53-catastrophic-risk-assessment-summaries"},{"slug":"us-california-sb-53-whistleblower-protections","title":"Frontier developers must protect employees who report catastrophic-risk concerns","policy":"us-california-sb-53","source_reference":"Labor Code Section 1107 (as added by SB 53)","url":"https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections"},{"slug":"us-colorado-admt-advance-notice","title":"Notify consumers before automated decision-making technology influences a consequential decision","policy":"us-colorado-automated-decision-making-technology-act","source_reference":null,"url":"https://aipolicytracker.org/obligations/us-colorado-admt-advance-notice"},{"slug":"us-colorado-admt-adverse-decision-disclosure","title":"Disclose the use of the technology and the principal reasons after an adverse consequential decision","policy":"us-colorado-automated-decision-making-technology-act","source_reference":null,"url":"https://aipolicytracker.org/obligations/us-colorado-admt-adverse-decision-disclosure"},{"slug":"us-colorado-admt-human-review","title":"Offer meaningful human review of an adverse consequential decision","policy":"us-colorado-automated-decision-making-technology-act","source_reference":null,"url":"https://aipolicytracker.org/obligations/us-colorado-admt-human-review"},{"slug":"us-colorado-admt-record-keeping","title":"Keep records of consequential decisions influenced by the technology for three years","policy":"us-colorado-automated-decision-making-technology-act","source_reference":null,"url":"https://aipolicytracker.org/obligations/us-colorado-admt-record-keeping"},{"slug":"us-colorado-admt-developer-documentation","title":"Developers must supply deployers with documentation of the technology","policy":"us-colorado-automated-decision-making-technology-act","source_reference":null,"url":"https://aipolicytracker.org/obligations/us-colorado-admt-developer-documentation"},{"slug":"eu-ai-act-prohibited-practices","title":"Do not deploy or provide AI for prohibited practices","policy":"eu-ai-act","source_reference":"Article 5","url":"https://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices"},{"slug":"eu-ai-act-ai-literacy","title":"Ensure AI literacy of staff operating AI systems","policy":"eu-ai-act","source_reference":"Article 4","url":"https://aipolicytracker.org/obligations/eu-ai-act-ai-literacy"},{"slug":"eu-ai-act-risk-management-system","title":"Establish a risk management system for high-risk AI","policy":"eu-ai-act","source_reference":"Article 9","url":"https://aipolicytracker.org/obligations/eu-ai-act-risk-management-system"},{"slug":"eu-ai-act-data-governance","title":"Apply data governance and quality criteria to training, validation and testing data","policy":"eu-ai-act","source_reference":"Article 10","url":"https://aipolicytracker.org/obligations/eu-ai-act-data-governance"},{"slug":"eu-ai-act-technical-documentation","title":"Draw up technical documentation before placing a high-risk system on the market","policy":"eu-ai-act","source_reference":"Article 11 and Annex IV","url":"https://aipolicytracker.org/obligations/eu-ai-act-technical-documentation"},{"slug":"eu-ai-act-record-keeping","title":"Design high-risk systems to log events automatically","policy":"eu-ai-act","source_reference":"Article 12; Article 26(6) for deployers","url":"https://aipolicytracker.org/obligations/eu-ai-act-record-keeping"},{"slug":"eu-ai-act-transparency-to-deployers","title":"Provide deployers with clear instructions for use","policy":"eu-ai-act","source_reference":"Article 13","url":"https://aipolicytracker.org/obligations/eu-ai-act-transparency-to-deployers"},{"slug":"eu-ai-act-human-oversight","title":"Enable and assign effective human oversight","policy":"eu-ai-act","source_reference":"Article 14; Article 26(2) for deployers","url":"https://aipolicytracker.org/obligations/eu-ai-act-human-oversight"},{"slug":"eu-ai-act-accuracy-robustness-cybersecurity","title":"Achieve appropriate accuracy, robustness and cybersecurity","policy":"eu-ai-act","source_reference":"Article 15","url":"https://aipolicytracker.org/obligations/eu-ai-act-accuracy-robustness-cybersecurity"},{"slug":"eu-ai-act-quality-management-system","title":"Operate a quality management system","policy":"eu-ai-act","source_reference":"Article 17","url":"https://aipolicytracker.org/obligations/eu-ai-act-quality-management-system"},{"slug":"eu-ai-act-conformity-assessment-registration","title":"Complete conformity assessment, CE marking and EU database registration","policy":"eu-ai-act","source_reference":"Articles 43, 47, 48 and 49; Annex VIII","url":"https://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration"},{"slug":"eu-ai-act-deployer-obligations","title":"Use high-risk AI as instructed, monitor it and inform affected people","policy":"eu-ai-act","source_reference":"Article 26","url":"https://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations"},{"slug":"eu-ai-act-fundamental-rights-impact-assessment","title":"Carry out a fundamental rights impact assessment before deployment","policy":"eu-ai-act","source_reference":"Article 27","url":"https://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment"},{"slug":"eu-ai-act-transparency-article-50","title":"Disclose AI interaction and label synthetic content","policy":"eu-ai-act","source_reference":"Article 50","url":"https://aipolicytracker.org/obligations/eu-ai-act-transparency-article-50"},{"slug":"eu-ai-act-gpai-provider-obligations","title":"Meet general-purpose AI model provider obligations","policy":"eu-ai-act","source_reference":"Article 53 and Annexes XI–XII","url":"https://aipolicytracker.org/obligations/eu-ai-act-gpai-provider-obligations"},{"slug":"eu-ai-act-gpai-systemic-risk","title":"Manage systemic risk for high-impact general-purpose models","policy":"eu-ai-act","source_reference":"Articles 51, 52 and 55","url":"https://aipolicytracker.org/obligations/eu-ai-act-gpai-systemic-risk"},{"slug":"eu-ai-act-post-market-monitoring","title":"Operate a post-market monitoring system","policy":"eu-ai-act","source_reference":"Article 72","url":"https://aipolicytracker.org/obligations/eu-ai-act-post-market-monitoring"},{"slug":"eu-ai-act-serious-incident-reporting","title":"Report serious incidents to market surveillance authorities","policy":"eu-ai-act","source_reference":"Article 73","url":"https://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting"},{"slug":"eu-ai-act-importer-distributor-obligations","title":"Verify conformity before importing or distributing high-risk AI","policy":"eu-ai-act","source_reference":"Articles 23 and 24","url":"https://aipolicytracker.org/obligations/eu-ai-act-importer-distributor-obligations"},{"slug":"eu-ai-act-art-16-provider-obligations","title":"Providers must meet the full set of provider duties for high-risk AI","policy":"eu-ai-act","source_reference":"Article 16","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations"},{"slug":"eu-ai-act-art-18-documentation-keeping","title":"Providers must keep high-risk AI documentation for ten years","policy":"eu-ai-act","source_reference":"Article 18","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-18-documentation-keeping"},{"slug":"eu-ai-act-art-19-provider-log-retention","title":"Providers must retain automatically generated logs under their control","policy":"eu-ai-act","source_reference":"Article 19","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-19-provider-log-retention"},{"slug":"eu-ai-act-art-20-corrective-actions-and-information","title":"Providers must take corrective action and inform the supply chain about non-conforming high-risk AI","policy":"eu-ai-act","source_reference":"Article 20","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-20-corrective-actions-and-information"},{"slug":"eu-ai-act-art-21-cooperation-with-authorities","title":"Providers must supply conformity evidence and log access to authorities on request","policy":"eu-ai-act","source_reference":"Article 21","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities"},{"slug":"eu-ai-act-art-22-authorised-representative","title":"Non-EU providers must appoint an EU authorised representative for high-risk AI","policy":"eu-ai-act","source_reference":"Article 22","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-22-authorised-representative"},{"slug":"eu-ai-act-art-25-value-chain-becoming-provider","title":"Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI","policy":"eu-ai-act","source_reference":"Article 25(1) and 25(2)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-25-value-chain-becoming-provider"},{"slug":"eu-ai-act-art-25-4-written-agreements-with-component-suppliers","title":"Providers of high-risk AI must have written agreements with suppliers of components, tools and services","policy":"eu-ai-act","source_reference":"Article 25(4)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-25-4-written-agreements-with-component-suppliers"},{"slug":"eu-ai-act-art-6-4-non-high-risk-assessment-documentation","title":"Providers must document and register a conclusion that an Annex III system is not high-risk","policy":"eu-ai-act","source_reference":"Article 6(4); Article 49(2)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-6-4-non-high-risk-assessment-documentation"},{"slug":"eu-ai-act-art-26-4-deployer-input-data","title":"Deployers must ensure input data they control is relevant and representative","policy":"eu-ai-act","source_reference":"Article 26(4)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-26-4-deployer-input-data"},{"slug":"eu-ai-act-art-26-5-deployer-monitoring-and-suspension","title":"Deployers must monitor high-risk AI, suspend use on risk and report serious incidents","policy":"eu-ai-act","source_reference":"Article 26(5)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-26-5-deployer-monitoring-and-suspension"},{"slug":"eu-ai-act-art-26-7-worker-information","title":"Employers must inform workers and their representatives before using high-risk AI at work","policy":"eu-ai-act","source_reference":"Article 26(7)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-26-7-worker-information"},{"slug":"eu-ai-act-art-26-8-public-authority-registration-before-use","title":"Public authorities must register their use of high-risk AI and must not use unregistered systems","policy":"eu-ai-act","source_reference":"Article 26(8); Article 49(3) and 49(4)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-26-8-public-authority-registration-before-use"},{"slug":"eu-ai-act-art-26-9-dpia-using-provider-information","title":"Deployers must use the provider's transparency information in their data protection impact assessment","policy":"eu-ai-act","source_reference":"Article 26(9)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information"},{"slug":"eu-ai-act-art-26-10-post-remote-biometric-identification-authorisation","title":"Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually","policy":"eu-ai-act","source_reference":"Article 26(10)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-26-10-post-remote-biometric-identification-authorisation"},{"slug":"eu-ai-act-art-26-11-notice-to-affected-persons","title":"Deployers must tell natural persons that a high-risk AI system is used in decisions about them","policy":"eu-ai-act","source_reference":"Article 26(11)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-26-11-notice-to-affected-persons"},{"slug":"eu-ai-act-art-50-2-synthetic-content-marking","title":"Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way","policy":"eu-ai-act","source_reference":"Article 50(2)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-50-2-synthetic-content-marking"},{"slug":"eu-ai-act-art-50-3-emotion-recognition-notice","title":"Deployers of emotion recognition or biometric categorisation must inform exposed persons","policy":"eu-ai-act","source_reference":"Article 50(3)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-50-3-emotion-recognition-notice"},{"slug":"eu-ai-act-art-50-4-deepfake-and-public-interest-text-disclosure","title":"Deployers must disclose deepfakes and AI-generated text published on matters of public interest","policy":"eu-ai-act","source_reference":"Article 50(4)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-50-4-deepfake-and-public-interest-text-disclosure"},{"slug":"eu-ai-act-art-52-systemic-risk-notification","title":"Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold","policy":"eu-ai-act","source_reference":"Article 52(1)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-52-systemic-risk-notification"},{"slug":"eu-ai-act-art-53-gpai-technical-and-downstream-documentation","title":"Providers of GPAI models must maintain technical documentation and inform downstream providers","policy":"eu-ai-act","source_reference":"Article 53(1)(a) and 53(1)(b); Annexes XI and XII","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-53-gpai-technical-and-downstream-documentation"},{"slug":"eu-ai-act-art-54-gpai-authorised-representative","title":"Non-EU providers of GPAI models must appoint an EU authorised representative","policy":"eu-ai-act","source_reference":"Article 54","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-54-gpai-authorised-representative"},{"slug":"eu-ai-act-art-55-systemic-risk-incident-reporting","title":"Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office","policy":"eu-ai-act","source_reference":"Article 55(1)(c)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-incident-reporting"},{"slug":"eu-ai-act-art-55-systemic-risk-cybersecurity","title":"Providers of systemic-risk GPAI models must secure the model and its infrastructure","policy":"eu-ai-act","source_reference":"Article 55(1)(d)","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-cybersecurity"},{"slug":"eu-ai-act-art-86-right-to-explanation","title":"Deployers must explain individual decisions taken with high-risk AI on request","policy":"eu-ai-act","source_reference":"Article 86","url":"https://aipolicytracker.org/obligations/eu-ai-act-art-86-right-to-explanation"},{"slug":"india-dpdp-consent-and-notice","title":"Process personal data only with valid consent or a legitimate use, after notice","policy":"india-dpdp-act","source_reference":"Sections 4 to 7","url":"https://aipolicytracker.org/obligations/india-dpdp-consent-and-notice"},{"slug":"india-dpdp-security-and-breach-notification","title":"Implement reasonable security safeguards and notify breaches","policy":"india-dpdp-act","source_reference":"Section 8(5) and 8(6); DPDP Rules on breach intimation","url":"https://aipolicytracker.org/obligations/india-dpdp-security-and-breach-notification"},{"slug":"india-dpdp-significant-data-fiduciary-duties","title":"Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits","policy":"india-dpdp-act","source_reference":"Section 10","url":"https://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties"},{"slug":"india-ai-guidelines-principles-and-risk-based-governance","title":"Adopt the guiding principles and risk-based governance (voluntary)","policy":"india-ai-governance-guidelines","source_reference":"Guiding principles and recommendations sections","url":"https://aipolicytracker.org/obligations/india-ai-guidelines-principles-and-risk-based-governance"},{"slug":"nepal-privacy-act-consent-and-purpose","title":"Collect and use personal information only with consent and for the stated purpose","policy":"nepal-individual-privacy-act","source_reference":"Chapter on collection and protection of personal information (reviewer to cite sections)","url":"https://aipolicytracker.org/obligations/nepal-privacy-act-consent-and-purpose"},{"slug":"nepal-ai-policy-responsible-ai-principles","title":"Government bodies to promote ethical, responsible and inclusive AI (policy commitment)","policy":"nepal-national-ai-policy","source_reference":"Policy objectives and strategies (to be confirmed against the official text)","url":"https://aipolicytracker.org/obligations/nepal-ai-policy-responsible-ai-principles"},{"slug":"us-new-york-city-local-law-144-bias-audit","title":"Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool","policy":"us-new-york-city-local-law-144-automated-employment-decision-tools","source_reference":"NYC Administrative Code Section 20-871(a)(1); 6 RCNY Section 5-301","url":"https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-bias-audit"},{"slug":"us-new-york-city-local-law-144-publish-audit-summary","title":"Employers and employment agencies must publish a summary of the bias audit results","policy":"us-new-york-city-local-law-144-automated-employment-decision-tools","source_reference":"NYC Administrative Code Section 20-871(a)(2); 6 RCNY Section 5-302","url":"https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-publish-audit-summary"},{"slug":"us-new-york-city-local-law-144-candidate-notice","title":"Employers and employment agencies must notify candidates and employees before an automated tool is used","policy":"us-new-york-city-local-law-144-automated-employment-decision-tools","source_reference":"NYC Administrative Code Section 20-871(b)(1) and (b)(2); 6 RCNY Section 5-303","url":"https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-candidate-notice"},{"slug":"us-new-york-city-local-law-144-alternative-process-request","title":"Employers and employment agencies must let candidates request an alternative selection process or accommodation","policy":"us-new-york-city-local-law-144-automated-employment-decision-tools","source_reference":"NYC Administrative Code Section 20-871(b)(1); 6 RCNY Section 5-303","url":"https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-alternative-process-request"},{"slug":"us-new-york-city-local-law-144-data-policy-disclosure","title":"Employers and employment agencies must disclose the data collected and their retention policy for the tool","policy":"us-new-york-city-local-law-144-automated-employment-decision-tools","source_reference":"NYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-303","url":"https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-data-policy-disclosure"},{"slug":"singapore-mgf-internal-governance","title":"Establish internal governance structures and measures for AI","policy":"singapore-model-ai-governance-framework","source_reference":"Second edition, Part on internal governance structures and measures","url":"https://aipolicytracker.org/obligations/singapore-mgf-internal-governance"},{"slug":"singapore-mgf-human-involvement","title":"Determine the appropriate level of human involvement in AI decisions","policy":"singapore-model-ai-governance-framework","source_reference":"Second edition, Part on human involvement in AI-augmented decision-making","url":"https://aipolicytracker.org/obligations/singapore-mgf-human-involvement"},{"slug":"singapore-mgf-operations-management","title":"Manage data quality, model development and monitoring across the lifecycle","policy":"singapore-model-ai-governance-framework","source_reference":"Second edition, Part on operations management","url":"https://aipolicytracker.org/obligations/singapore-mgf-operations-management"},{"slug":"singapore-mgf-genai-incident-reporting-and-provenance","title":"Report incidents and mark AI-generated content (generative AI framework)","policy":"singapore-model-ai-governance-framework","source_reference":"Generative AI framework, dimensions on incident reporting and content provenance","url":"https://aipolicytracker.org/obligations/singapore-mgf-genai-incident-reporting-and-provenance"},{"slug":"singapore-pdpc-consent-or-exception-for-ai-data","title":"Identify consent or an applicable PDPA exception before using personal data in AI","policy":"singapore-pdpc-ai-advisory-guidelines","source_reference":"Advisory guidelines, sections on consent, business improvement and research exceptions","url":"https://aipolicytracker.org/obligations/singapore-pdpc-consent-or-exception-for-ai-data"},{"slug":"singapore-pdpc-ai-notification","title":"Notify individuals about the use of personal data in AI recommendations and decisions","policy":"singapore-pdpc-ai-advisory-guidelines","source_reference":"Advisory guidelines, section on notification obligation","url":"https://aipolicytracker.org/obligations/singapore-pdpc-ai-notification"},{"slug":"south-korea-ai-basic-act-art-31-advance-notice-of-high-impact-and-generative-ai","title":"AI business operators must notify users in advance that a product or service runs on high-impact or generative AI","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 31(1)","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-advance-notice-of-high-impact-and-generative-ai"},{"slug":"south-korea-ai-basic-act-art-31-generative-output-labelling-and-deepfake-notice","title":"AI business operators must label generative AI output and clearly flag realistic synthetic media","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 31(2) and 31(3)","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-generative-output-labelling-and-deepfake-notice"},{"slug":"south-korea-ai-basic-act-art-32-safety-measures-for-high-performance-ai","title":"Operators of AI above the compute threshold must run lifecycle risk management and report safety results","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 32","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-32-safety-measures-for-high-performance-ai"},{"slug":"south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan","title":"Operators of high-impact AI must establish and operate a risk management plan","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 34(1)","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan"},{"slug":"south-korea-ai-basic-act-art-34-high-impact-ai-explanation-measures","title":"Operators of high-impact AI must be able to explain outputs and the main criteria behind them","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 34(1)","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-explanation-measures"},{"slug":"south-korea-ai-basic-act-art-34-high-impact-ai-human-oversight","title":"Operators of high-impact AI must ensure human management and supervision","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 34(1)","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-human-oversight"},{"slug":"south-korea-ai-basic-act-art-34-high-impact-ai-user-protection-and-documentation","title":"Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 34(1)","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-user-protection-and-documentation"},{"slug":"south-korea-ai-basic-act-art-35-high-impact-ai-impact-assessment","title":"Operators of high-impact AI should assess its impact on fundamental rights before use","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 35","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-35-high-impact-ai-impact-assessment"},{"slug":"south-korea-ai-basic-act-art-36-domestic-representative","title":"Foreign AI business operators above the threshold must designate a domestic representative in Korea","policy":"south-korea-framework-act-on-the-development-of-artificial-intelligence-and-establishment-of-a-foundation-for","source_reference":"Article 36","url":"https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-36-domestic-representative"},{"slug":"us-texas-responsible-ai-governance-act-traiga-government-agency-ai-interaction-disclosure","title":"Government agencies must disclose to consumers that they are interacting with an AI system","policy":"us-texas-responsible-ai-governance-act-traiga","source_reference":"Business and Commerce Code Section 551.051","url":"https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-agency-ai-interaction-disclosure"},{"slug":"us-texas-responsible-ai-governance-act-traiga-health-care-ai-disclosure","title":"Health-care providers must disclose the use of AI in patient services","policy":"us-texas-responsible-ai-governance-act-traiga","source_reference":"Business and Commerce Code Section 551.051","url":"https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-health-care-ai-disclosure"},{"slug":"us-texas-responsible-ai-governance-act-traiga-manipulation-prohibition","title":"Developers and deployers must not use AI to incite self-harm, harm to others or crime","policy":"us-texas-responsible-ai-governance-act-traiga","source_reference":"Business and Commerce Code Section 551.052","url":"https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-manipulation-prohibition"},{"slug":"us-texas-responsible-ai-governance-act-traiga-government-social-scoring-prohibition","title":"Governmental entities must not use AI for social scoring","policy":"us-texas-responsible-ai-governance-act-traiga","source_reference":"Business and Commerce Code Section 551.053","url":"https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-social-scoring-prohibition"},{"slug":"us-texas-responsible-ai-governance-act-traiga-government-biometric-identification-prohibition","title":"Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights","policy":"us-texas-responsible-ai-governance-act-traiga","source_reference":"Business and Commerce Code Section 551.054","url":"https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-biometric-identification-prohibition"},{"slug":"us-texas-responsible-ai-governance-act-traiga-unlawful-discrimination-prohibition","title":"Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class","policy":"us-texas-responsible-ai-governance-act-traiga","source_reference":"Business and Commerce Code Section 551.056","url":"https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-unlawful-discrimination-prohibition"},{"slug":"us-texas-responsible-ai-governance-act-traiga-sexual-content-and-csam-prohibition","title":"Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes","policy":"us-texas-responsible-ai-governance-act-traiga","source_reference":"Business and Commerce Code Section 551.057","url":"https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-sexual-content-and-csam-prohibition"},{"slug":"uae-pdpl-automated-decision-objection","title":"Respect the right to object to automated decision-making without human intervention","policy":"uae-personal-data-protection-law","source_reference":"Article on data-subject rights relating to automated processing (reviewer to cite article number)","url":"https://aipolicytracker.org/obligations/uae-pdpl-automated-decision-objection"},{"slug":"uae-pdpl-impact-assessment-new-technologies","title":"Conduct a data protection impact assessment for high-risk processing using new technologies","policy":"uae-personal-data-protection-law","source_reference":"Article on data protection impact assessment (reviewer to cite article number)","url":"https://aipolicytracker.org/obligations/uae-pdpl-impact-assessment-new-technologies"},{"slug":"uae-ai-strategy-ethics-and-governance-commitment","title":"Government commitment to AI ethics, governance and regulation (strategy objective)","policy":"uae-national-ai-strategy-2031","source_reference":"Strategy objectives on governance and ethics (reviewer to cite the section)","url":"https://aipolicytracker.org/obligations/uae-ai-strategy-ethics-and-governance-commitment"},{"slug":"uk-principles-safety-security-robustness","title":"Ensure AI systems are safe, secure and robust throughout their lifecycle","policy":"uk-ai-regulation-white-paper","source_reference":"Principle 1, Part 3","url":"https://aipolicytracker.org/obligations/uk-principles-safety-security-robustness"},{"slug":"uk-principles-transparency-explainability","title":"Provide appropriate transparency and explainability","policy":"uk-ai-regulation-white-paper","source_reference":"Principle 2, Part 3","url":"https://aipolicytracker.org/obligations/uk-principles-transparency-explainability"},{"slug":"uk-principles-fairness","title":"Use AI in ways that are fair and do not discriminate unlawfully","policy":"uk-ai-regulation-white-paper","source_reference":"Principle 3, Part 3","url":"https://aipolicytracker.org/obligations/uk-principles-fairness"},{"slug":"uk-principles-accountability-governance","title":"Establish accountability and governance for AI","policy":"uk-ai-regulation-white-paper","source_reference":"Principle 4, Part 3","url":"https://aipolicytracker.org/obligations/uk-principles-accountability-governance"},{"slug":"uk-principles-contestability-redress","title":"Provide routes to contest AI outcomes and seek redress","policy":"uk-ai-regulation-white-paper","source_reference":"Principle 5, Part 3","url":"https://aipolicytracker.org/obligations/uk-principles-contestability-redress"},{"slug":"uk-ico-dpia-for-ai","title":"Carry out a data protection impact assessment for high-risk AI processing","policy":"uk-ico-ai-data-protection-guidance","source_reference":"UK GDPR Article 35; ICO guidance, accountability and governance section","url":"https://aipolicytracker.org/obligations/uk-ico-dpia-for-ai"},{"slug":"uk-ico-automated-decision-safeguards","title":"Apply safeguards to solely automated decisions with significant effects","policy":"uk-ico-ai-data-protection-guidance","source_reference":"UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025","url":"https://aipolicytracker.org/obligations/uk-ico-automated-decision-safeguards"},{"slug":"us-eo-14179-agency-review-of-prior-actions","title":"Federal agencies must review and revise actions inconsistent with the new AI policy","policy":"us-executive-order-14179","source_reference":"Section 5","url":"https://aipolicytracker.org/obligations/us-eo-14179-agency-review-of-prior-actions"},{"slug":"us-nist-ai-rmf-govern","title":"Establish AI governance policies, roles and accountability (Govern)","policy":"us-nist-ai-rmf","source_reference":"GOVERN function","url":"https://aipolicytracker.org/obligations/us-nist-ai-rmf-govern"},{"slug":"us-nist-ai-rmf-map","title":"Map context, intended use and potential impacts (Map)","policy":"us-nist-ai-rmf","source_reference":"MAP function","url":"https://aipolicytracker.org/obligations/us-nist-ai-rmf-map"},{"slug":"us-nist-ai-rmf-measure","title":"Measure and test trustworthiness characteristics (Measure)","policy":"us-nist-ai-rmf","source_reference":"MEASURE function","url":"https://aipolicytracker.org/obligations/us-nist-ai-rmf-measure"},{"slug":"us-nist-ai-rmf-manage","title":"Prioritise, respond to and monitor AI risks (Manage)","policy":"us-nist-ai-rmf","source_reference":"MANAGE function","url":"https://aipolicytracker.org/obligations/us-nist-ai-rmf-manage"},{"slug":"us-omb-m-25-21-high-impact-ai-practices","title":"Apply minimum risk-management practices to high-impact AI","policy":"us-omb-m-25-21","source_reference":"Section 4","url":"https://aipolicytracker.org/obligations/us-omb-m-25-21-high-impact-ai-practices"},{"slug":"us-omb-m-25-21-use-case-inventory","title":"Publish an annual AI use-case inventory","policy":"us-omb-m-25-21","source_reference":"Section 3","url":"https://aipolicytracker.org/obligations/us-omb-m-25-21-use-case-inventory"}],"versions":[{"version":1,"generated_at":"2026-09-28T10:04:00+00:00","dataset_version":"bb068ecd9dad","changelog":"First version, built from dataset bb068ecd9dad.","stats":{"sheets":{"Evidence tracker":79,"Controls":26},"blocks":0,"headings":0,"citations":105}}]},"meta":{"license":"CC BY 4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","disclaimer":"This template is generated from the records on aipolicytracker.org. It is an informational resource, not legal advice, and completing it does not make an organisation compliant with any law or standard. Every row that cites a duty links to the record it came from; check the official source before relying on it."}}