Spaces:
Sleeping
Sleeping
Deploy ReguAI: Neuro-Symbolic AI GRC & Automated Conformity Assessment Engine
Browse files- .gitignore +1 -0
- data/active_learning_triplets.jsonl +0 -1
- data/benchmarks/case_studies_catalog.json +746 -25
- data/synthetic_systems/compliant_adaptive_stem_tutor.json +13 -0
- data/synthetic_systems/compliant_adas_lane_keeping.json +13 -0
- data/synthetic_systems/compliant_cardiac_triage_samd.json +13 -0
- data/synthetic_systems/compliant_digital_forensics.json +13 -0
- data/synthetic_systems/compliant_fairhire_screening.json +13 -0
- data/synthetic_systems/compliant_mortgage_underwriting.json +13 -0
- data/synthetic_systems/compliant_open_frontier_llm.json +13 -0
- data/synthetic_systems/compliant_virtual_presenter_deepfake.json +13 -0
- data/synthetic_systems/compliant_warehouse_logistics_optimizer.json +13 -0
- data/synthetic_systems/non_compliant_derma_diagnostics.json +13 -0
- data/synthetic_systems/non_compliant_water_scada.json +13 -0
- data/synthetic_systems/prohibited_biometric_categorization_beliefs.json +13 -0
- data/synthetic_systems/prohibited_subliminal_gambling_nudge.json +13 -0
- scratch/inspect_catalog.py +19 -0
- scratch/test_all_cases.py +44 -0
- scripts/expand_benchmark_catalog.py +969 -0
- src/extraction/gliner_extractor.py +3 -3
- src/extraction/parser.py +20 -20
- tests/test_case_catalog.py +29 -0
.gitignore
CHANGED
|
@@ -10,3 +10,4 @@ ENV/
|
|
| 10 |
.vscode/
|
| 11 |
*.swp
|
| 12 |
.DS_Store
|
|
|
|
|
|
| 10 |
.vscode/
|
| 11 |
*.swp
|
| 12 |
.DS_Store
|
| 13 |
+
scratch/
|
data/active_learning_triplets.jsonl
CHANGED
|
@@ -21,4 +21,3 @@
|
|
| 21 |
{"timestamp": "2026-09-21T14:47:50.118531+00:00", "auditor_id": "compliance_lead_01", "claim_id": "clm_test_99", "anchor_text": "Verified operational override in production dashboard.", "positive_label": "HUMAN_OVERSIGHT", "negative_label": "IRRELEVANT_TEXT", "verified_assertion_status": "IMPLEMENTED", "auditor_notes": "Verified operational override in production dashboard."}
|
| 22 |
{"timestamp": "2026-09-21T14:48:40.951594+00:00", "auditor_id": "compliance_lead_01", "claim_id": "clm_test_99", "anchor_text": "Verified operational override in production dashboard.", "positive_label": "HUMAN_OVERSIGHT", "negative_label": "IRRELEVANT_TEXT", "verified_assertion_status": "IMPLEMENTED", "auditor_notes": "Verified operational override in production dashboard."}
|
| 23 |
{"timestamp": "2026-09-21T15:05:44.655438+00:00", "auditor_id": "compliance_lead_01", "claim_id": "clm_test_99", "anchor_text": "Verified operational override in production dashboard.", "positive_label": "HUMAN_OVERSIGHT", "negative_label": "IRRELEVANT_TEXT", "verified_assertion_status": "IMPLEMENTED", "auditor_notes": "Verified operational override in production dashboard."}
|
| 24 |
-
{"timestamp": "2026-09-21T15:15:16.103685+00:00", "auditor_id": "compliance_lead_01", "claim_id": "clm_test_99", "anchor_text": "Verified operational override in production dashboard.", "positive_label": "HUMAN_OVERSIGHT", "negative_label": "IRRELEVANT_TEXT", "verified_assertion_status": "IMPLEMENTED", "auditor_notes": "Verified operational override in production dashboard."}
|
|
|
|
| 21 |
{"timestamp": "2026-09-21T14:47:50.118531+00:00", "auditor_id": "compliance_lead_01", "claim_id": "clm_test_99", "anchor_text": "Verified operational override in production dashboard.", "positive_label": "HUMAN_OVERSIGHT", "negative_label": "IRRELEVANT_TEXT", "verified_assertion_status": "IMPLEMENTED", "auditor_notes": "Verified operational override in production dashboard."}
|
| 22 |
{"timestamp": "2026-09-21T14:48:40.951594+00:00", "auditor_id": "compliance_lead_01", "claim_id": "clm_test_99", "anchor_text": "Verified operational override in production dashboard.", "positive_label": "HUMAN_OVERSIGHT", "negative_label": "IRRELEVANT_TEXT", "verified_assertion_status": "IMPLEMENTED", "auditor_notes": "Verified operational override in production dashboard."}
|
| 23 |
{"timestamp": "2026-09-21T15:05:44.655438+00:00", "auditor_id": "compliance_lead_01", "claim_id": "clm_test_99", "anchor_text": "Verified operational override in production dashboard.", "positive_label": "HUMAN_OVERSIGHT", "negative_label": "IRRELEVANT_TEXT", "verified_assertion_status": "IMPLEMENTED", "auditor_notes": "Verified operational override in production dashboard."}
|
|
|
data/benchmarks/case_studies_catalog.json
CHANGED
|
@@ -8,7 +8,7 @@
|
|
| 8 |
"domains": [
|
| 9 |
{
|
| 10 |
"domain_id": "healthcare_samd",
|
| 11 |
-
"domain_name": "
|
| 12 |
"statutory_category": "Annex I (MDR/IVDR) & Annex III Point 5(a)",
|
| 13 |
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2017/745 (MDR)",
|
| 14 |
"domain_summary": "AI Software as a Medical Device (SaMD) used for diagnostic classification, patient risk stratification, and emergency medical triage.",
|
|
@@ -53,7 +53,7 @@
|
|
| 53 |
]
|
| 54 |
},
|
| 55 |
"conformity_procedure": "Annex VII: Notified Body Assessment combined with MDR Notified Body audit",
|
| 56 |
-
"fine_exposure_tier": "Tier 2 (
|
| 57 |
},
|
| 58 |
"auditor_guidance": {
|
| 59 |
"intended_purpose": "Automated thoracic CT nodule segmentation and malignancy risk stratification.",
|
|
@@ -74,12 +74,132 @@
|
|
| 74 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 75 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 76 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 77 |
}
|
| 78 |
]
|
| 79 |
},
|
| 80 |
{
|
| 81 |
"domain_id": "employment_hr",
|
| 82 |
-
"domain_name": "
|
| 83 |
"statutory_category": "Annex III Point 4",
|
| 84 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 4(a) & 4(b)",
|
| 85 |
"domain_summary": "AI systems used for recruitment, CV screening, job candidate evaluation, task allocation, and worker performance monitoring.",
|
|
@@ -117,10 +237,10 @@
|
|
| 117 |
]
|
| 118 |
},
|
| 119 |
"conformity_procedure": "Annex VI: Internal Control Assessment",
|
| 120 |
-
"fine_exposure_tier": "Tier 2 (
|
| 121 |
},
|
| 122 |
"auditor_guidance": {
|
| 123 |
-
"intended_purpose": "Autonomous
|
| 124 |
"common_pitfalls": "Historic gender and demographic bias encoded in legacy recruitment datasets; lack of explicit human intervention kill switch before candidates are rejected.",
|
| 125 |
"remediation_guidance": "Perform disparate impact parity analysis (Four-Fifths rule / Equal Opportunity Difference) and require mandatory HR officer approval for all candidate rejections."
|
| 126 |
},
|
|
@@ -138,12 +258,72 @@
|
|
| 138 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 139 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 140 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 141 |
}
|
| 142 |
]
|
| 143 |
},
|
| 144 |
{
|
| 145 |
"domain_id": "banking_finance",
|
| 146 |
-
"domain_name": "
|
| 147 |
"statutory_category": "Annex III Point 5",
|
| 148 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 5(b) & 5(c)",
|
| 149 |
"domain_summary": "AI systems used to evaluate creditworthiness of natural persons, establish credit scores, or price risk in life and health insurance.",
|
|
@@ -181,7 +361,7 @@
|
|
| 181 |
]
|
| 182 |
},
|
| 183 |
"conformity_procedure": "Annex VI: Internal Control Assessment",
|
| 184 |
-
"fine_exposure_tier": "Tier 2 (
|
| 185 |
},
|
| 186 |
"auditor_guidance": {
|
| 187 |
"intended_purpose": "Consumer credit underwriting predicting loan default risk probabilities.",
|
|
@@ -202,12 +382,72 @@
|
|
| 202 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 203 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 204 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 205 |
}
|
| 206 |
]
|
| 207 |
},
|
| 208 |
{
|
| 209 |
"domain_id": "transport_safety",
|
| 210 |
-
"domain_name": "
|
| 211 |
"statutory_category": "Annex I & Annex III Point 2",
|
| 212 |
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2019/2144 (General Vehicle Safety)",
|
| 213 |
"domain_summary": "AI safety components in autonomous and semi-autonomous vehicles, collision avoidance, and automated emergency braking (AEB).",
|
|
@@ -245,7 +485,7 @@
|
|
| 245 |
]
|
| 246 |
},
|
| 247 |
"conformity_procedure": "Vehicle Type Approval (UN ECE / Regulation (EU) 2019/2144)",
|
| 248 |
-
"fine_exposure_tier": "Tier 2 (
|
| 249 |
},
|
| 250 |
"auditor_guidance": {
|
| 251 |
"intended_purpose": "Safety component for automated emergency braking in commercial transport trucks.",
|
|
@@ -266,12 +506,71 @@
|
|
| 266 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 267 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 268 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 269 |
}
|
| 270 |
]
|
| 271 |
},
|
| 272 |
{
|
| 273 |
"domain_id": "critical_infrastructure",
|
| 274 |
-
"domain_name": "
|
| 275 |
"statutory_category": "Annex III Point 2(a)",
|
| 276 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 2(a)",
|
| 277 |
"domain_summary": "AI systems used as safety components in the management and operation of critical digital infrastructure, electricity, water, or gas grids.",
|
|
@@ -307,7 +606,7 @@
|
|
| 307 |
]
|
| 308 |
},
|
| 309 |
"conformity_procedure": "Annex VI: Internal Control Assessment + NIS 2 Directive compliance",
|
| 310 |
-
"fine_exposure_tier": "Tier 2 (
|
| 311 |
},
|
| 312 |
"auditor_guidance": {
|
| 313 |
"intended_purpose": "Predicting transmission grid frequency instability and automating substation load shedding.",
|
|
@@ -328,12 +627,68 @@
|
|
| 328 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 329 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 330 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 331 |
}
|
| 332 |
]
|
| 333 |
},
|
| 334 |
{
|
| 335 |
"domain_id": "education_training",
|
| 336 |
-
"domain_name": "
|
| 337 |
"statutory_category": "Annex III Point 3",
|
| 338 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 3(a) & 3(b)",
|
| 339 |
"domain_summary": "AI systems used for student admission, assignment, grading, and monitoring or detecting prohibited behaviour of students during tests.",
|
|
@@ -370,7 +725,7 @@
|
|
| 370 |
]
|
| 371 |
},
|
| 372 |
"conformity_procedure": "Annex VI: Internal Control Assessment",
|
| 373 |
-
"fine_exposure_tier": "Tier 2 (
|
| 374 |
},
|
| 375 |
"auditor_guidance": {
|
| 376 |
"intended_purpose": "Automated webcam gaze tracking and cheating detection during remote university exams.",
|
|
@@ -391,12 +746,72 @@
|
|
| 391 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 392 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 393 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 394 |
}
|
| 395 |
]
|
| 396 |
},
|
| 397 |
{
|
| 398 |
"domain_id": "justice_law_enforcement",
|
| 399 |
-
"domain_name": "
|
| 400 |
"statutory_category": "Annex III Points 6 & 8",
|
| 401 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 6(a) & Point 8",
|
| 402 |
"domain_summary": "AI systems used for individual criminal risk assessments, recidivism forecasting, evidence evaluation, and assisting judicial authorities.",
|
|
@@ -433,7 +848,7 @@
|
|
| 433 |
]
|
| 434 |
},
|
| 435 |
"conformity_procedure": "Annex VI: Internal Control Assessment + Fundamental Rights Impact Assessment (FRIA, Art. 27)",
|
| 436 |
-
"fine_exposure_tier": "Tier 2 (
|
| 437 |
},
|
| 438 |
"auditor_guidance": {
|
| 439 |
"intended_purpose": "Predicting defendant failure-to-appear and re-arrest probability for arraignment judges.",
|
|
@@ -454,13 +869,73 @@
|
|
| 454 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 455 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 456 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 457 |
}
|
| 458 |
]
|
| 459 |
},
|
| 460 |
{
|
| 461 |
"domain_id": "frontier_gpai",
|
| 462 |
-
"domain_name": "
|
| 463 |
-
"statutory_category": "Chapter V (Articles 51
|
| 464 |
"legal_basis": "Regulation (EU) 2024/1689, Chapter V, Articles 51, 52, 53, 55",
|
| 465 |
"domain_summary": "General-purpose AI models, frontier LLMs trained on > 10^25 FLOPs, systemic risk mitigations, and copyright opt-out enforcement.",
|
| 466 |
"case_studies": [
|
|
@@ -495,7 +970,7 @@
|
|
| 495 |
]
|
| 496 |
},
|
| 497 |
"conformity_procedure": "AI Office Code of Practice / Independent Red-Teaming Attestation",
|
| 498 |
-
"fine_exposure_tier": "Tier 2 (
|
| 499 |
},
|
| 500 |
"auditor_guidance": {
|
| 501 |
"intended_purpose": "Multi-modal frontier foundation LLM deployed for downstream enterprise reasoning and code generation.",
|
|
@@ -516,15 +991,69 @@
|
|
| 516 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 517 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 518 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 519 |
}
|
| 520 |
]
|
| 521 |
},
|
| 522 |
{
|
| 523 |
"domain_id": "prohibited_practices",
|
| 524 |
-
"domain_name": "
|
| 525 |
"statutory_category": "Chapter II, Article 5",
|
| 526 |
"legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(a)-(h)",
|
| 527 |
-
"domain_summary": "Strictly illegal AI systems causing unacceptable risk to fundamental human rights, subject to fatal ban and
|
| 528 |
"case_studies": [
|
| 529 |
{
|
| 530 |
"case_id": "prohibited_emotion_recognition_workplace",
|
|
@@ -551,7 +1080,7 @@
|
|
| 551 |
]
|
| 552 |
},
|
| 553 |
"conformity_procedure": "IMMEDIATE CEASE / PROHIBITED FROM UNION MARKET",
|
| 554 |
-
"fine_exposure_tier": "Tier 1 (
|
| 555 |
},
|
| 556 |
"auditor_guidance": {
|
| 557 |
"intended_purpose": "Continuous automated facial micro-expression analysis to infer employee attentiveness and classroom student engagement.",
|
|
@@ -598,7 +1127,7 @@
|
|
| 598 |
]
|
| 599 |
},
|
| 600 |
"conformity_procedure": "IMMEDIATE CEASE / PROHIBITED FROM UNION MARKET",
|
| 601 |
-
"fine_exposure_tier": "Tier 1 (
|
| 602 |
},
|
| 603 |
"auditor_guidance": {
|
| 604 |
"intended_purpose": "Evaluating citizen trustworthiness based on social behavior and administrative compliance to allocate public benefits.",
|
|
@@ -619,12 +1148,107 @@
|
|
| 619 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 620 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 621 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 622 |
}
|
| 623 |
]
|
| 624 |
},
|
| 625 |
{
|
| 626 |
"domain_id": "limited_risk_generative",
|
| 627 |
-
"domain_name": "
|
| 628 |
"statutory_category": "Chapter IV, Article 50",
|
| 629 |
"legal_basis": "Regulation (EU) 2024/1689, Article 50(1) & 50(2)",
|
| 630 |
"domain_summary": "AI systems directly interacting with natural persons (chatbots) and generative synthetic audio/video systems requiring transparency disclosures.",
|
|
@@ -656,7 +1280,7 @@
|
|
| 656 |
]
|
| 657 |
},
|
| 658 |
"conformity_procedure": "Self-Declaration Transparency Disclosure (No Notified Body required)",
|
| 659 |
-
"fine_exposure_tier": "Tier 3 (
|
| 660 |
},
|
| 661 |
"auditor_guidance": {
|
| 662 |
"intended_purpose": "Natural language conversational agent assisting retail bank customers with routine inquiries.",
|
|
@@ -677,12 +1301,61 @@
|
|
| 677 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 678 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 679 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 680 |
}
|
| 681 |
]
|
| 682 |
},
|
| 683 |
{
|
| 684 |
"domain_id": "minimal_risk",
|
| 685 |
-
"domain_name": "
|
| 686 |
"statutory_category": "Title IX, Article 95",
|
| 687 |
"legal_basis": "Regulation (EU) 2024/1689, Article 95",
|
| 688 |
"domain_summary": "Unconstrained AI systems such as spam filters, recommender systems, and inventory optimizers with voluntary adherence to European Codes of Conduct.",
|
|
@@ -733,6 +1406,54 @@
|
|
| 733 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 734 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 735 |
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 736 |
}
|
| 737 |
]
|
| 738 |
}
|
|
|
|
| 8 |
"domains": [
|
| 9 |
{
|
| 10 |
"domain_id": "healthcare_samd",
|
| 11 |
+
"domain_name": "\ud83c\udfe5 Healthcare & Medical SaMD",
|
| 12 |
"statutory_category": "Annex I (MDR/IVDR) & Annex III Point 5(a)",
|
| 13 |
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2017/745 (MDR)",
|
| 14 |
"domain_summary": "AI Software as a Medical Device (SaMD) used for diagnostic classification, patient risk stratification, and emergency medical triage.",
|
|
|
|
| 53 |
]
|
| 54 |
},
|
| 55 |
"conformity_procedure": "Annex VII: Notified Body Assessment combined with MDR Notified Body audit",
|
| 56 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 57 |
},
|
| 58 |
"auditor_guidance": {
|
| 59 |
"intended_purpose": "Automated thoracic CT nodule segmentation and malignancy risk stratification.",
|
|
|
|
| 74 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 75 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 76 |
}
|
| 77 |
+
},
|
| 78 |
+
{
|
| 79 |
+
"case_id": "non_compliant_derma_diagnostics",
|
| 80 |
+
"title": "DermaCheck-Direct - Autonomous D2C Melanoma Classifier (MDR Class IIb)",
|
| 81 |
+
"system_id": "samd-derma-02",
|
| 82 |
+
"statutory_tier": "High-Risk (Annex I, Medical Device - Article 6(1))",
|
| 83 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & MDR Class IIb",
|
| 84 |
+
"expected_conformity": "NON-CONFORMANT (FAILED)",
|
| 85 |
+
"file_path": "data/synthetic_systems/non_compliant_derma_diagnostics.json",
|
| 86 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 87 |
+
"regulatory_requirements": {
|
| 88 |
+
"mandatory_articles": [
|
| 89 |
+
"Article 9",
|
| 90 |
+
"Article 10",
|
| 91 |
+
"Article 10(2)(f)",
|
| 92 |
+
"Article 11",
|
| 93 |
+
"Article 12",
|
| 94 |
+
"Article 13",
|
| 95 |
+
"Article 14",
|
| 96 |
+
"Article 15"
|
| 97 |
+
],
|
| 98 |
+
"harmonized_frameworks": {
|
| 99 |
+
"nist_ai_rmf": [
|
| 100 |
+
"GOVERN-1.2",
|
| 101 |
+
"MEASURE-2.11",
|
| 102 |
+
"MANAGE-2.2"
|
| 103 |
+
],
|
| 104 |
+
"iso_42001": [
|
| 105 |
+
"Clause 6.1.2",
|
| 106 |
+
"Control A.8.4",
|
| 107 |
+
"Control A.9.2"
|
| 108 |
+
],
|
| 109 |
+
"gdpr": [
|
| 110 |
+
"Article 9 Special Category Health Data",
|
| 111 |
+
"Article 22 Automated Profiling"
|
| 112 |
+
]
|
| 113 |
+
},
|
| 114 |
+
"conformity_procedure": "Annex VII: Notified Body Conformity Assessment combined with MDR Class IIb audit",
|
| 115 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 116 |
+
},
|
| 117 |
+
"auditor_guidance": {
|
| 118 |
+
"intended_purpose": "Consumer-facing automated melanoma screening app providing direct diagnostic risk scores.",
|
| 119 |
+
"common_pitfalls": "Attempting to bypass MDR/AI Act high-risk classification via superficial 'informational only' disclaimers while marketing diagnostic capabilities; catastrophic bias across Fitzpatrick skin types.",
|
| 120 |
+
"remediation_guidance": "Restructure application flow to require mandatory dermatologist tele-triage confirmation; conduct multi-center clinical validation across diverse skin phototypes; establish ISO 14971 PMS."
|
| 121 |
+
},
|
| 122 |
+
"file_sha256": "0501529ffc36b2fc8ef295eacf6cd05dbec686283532e530f718f96b0fb3600c",
|
| 123 |
+
"provenance": {
|
| 124 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 125 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 126 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 127 |
+
"celex": "32024R1689",
|
| 128 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 129 |
+
"statutory_quote_sha256": "5dcc4a383d81f69e7988c97f6e6e2d5b85bcd096ebd033df9cb198b12433d785",
|
| 130 |
+
"spec_file_sha256": "0501529ffc36b2fc8ef295eacf6cd05dbec686283532e530f718f96b0fb3600c",
|
| 131 |
+
"prov_o_entity": "urn:reguai:benchmark:case:non_compliant_derma_diagnostics",
|
| 132 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 133 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 134 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 135 |
+
}
|
| 136 |
+
},
|
| 137 |
+
{
|
| 138 |
+
"case_id": "compliant_cardiac_triage_samd",
|
| 139 |
+
"title": "PulseGuard-ICU - Real-Time Cardiac Arrhythmia Telemetry (MDR Class IIb)",
|
| 140 |
+
"system_id": "samd-cardiac-03",
|
| 141 |
+
"statutory_tier": "High-Risk (Annex I, Medical Device - Article 6(1))",
|
| 142 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & MDR Class IIb",
|
| 143 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 144 |
+
"file_path": "data/synthetic_systems/compliant_cardiac_triage_samd.json",
|
| 145 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 146 |
+
"regulatory_requirements": {
|
| 147 |
+
"mandatory_articles": [
|
| 148 |
+
"Article 9",
|
| 149 |
+
"Article 10",
|
| 150 |
+
"Article 10(2)(f)",
|
| 151 |
+
"Article 11",
|
| 152 |
+
"Article 12",
|
| 153 |
+
"Article 13",
|
| 154 |
+
"Article 14",
|
| 155 |
+
"Article 15"
|
| 156 |
+
],
|
| 157 |
+
"harmonized_frameworks": {
|
| 158 |
+
"nist_ai_rmf": [
|
| 159 |
+
"GOVERN-1.1",
|
| 160 |
+
"MAP-1.5",
|
| 161 |
+
"MEASURE-2.11",
|
| 162 |
+
"MANAGE-2.2"
|
| 163 |
+
],
|
| 164 |
+
"iso_42001": [
|
| 165 |
+
"Clause 6.1.2",
|
| 166 |
+
"Control A.6.2",
|
| 167 |
+
"Control A.8.4",
|
| 168 |
+
"Control A.9.2"
|
| 169 |
+
],
|
| 170 |
+
"gdpr": [
|
| 171 |
+
"Article 9(2)(h) Health Treatment",
|
| 172 |
+
"Article 32 Security of Processing"
|
| 173 |
+
]
|
| 174 |
+
},
|
| 175 |
+
"conformity_procedure": "Annex VII: Notified Body Assessment under MDR Class IIb & AI Act Article 43",
|
| 176 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 177 |
+
},
|
| 178 |
+
"auditor_guidance": {
|
| 179 |
+
"intended_purpose": "ICU real-time cardiac arrhythmia warning and telemetry classification.",
|
| 180 |
+
"common_pitfalls": "Failure to address alarm fatigue; lack of validation on diverse pacing modalities.",
|
| 181 |
+
"remediation_guidance": "Maintain continuous eQMS post-market surveillance and quarterly clinician feedback reviews."
|
| 182 |
+
},
|
| 183 |
+
"file_sha256": "0cd879508b3a084d82aaeac884546ee1f4a4baaac93fd424ca33207a1d42b826",
|
| 184 |
+
"provenance": {
|
| 185 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 186 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 187 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 188 |
+
"celex": "32024R1689",
|
| 189 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 190 |
+
"statutory_quote_sha256": "5dcc4a383d81f69e7988c97f6e6e2d5b85bcd096ebd033df9cb198b12433d785",
|
| 191 |
+
"spec_file_sha256": "0cd879508b3a084d82aaeac884546ee1f4a4baaac93fd424ca33207a1d42b826",
|
| 192 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_cardiac_triage_samd",
|
| 193 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 194 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 195 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 196 |
+
}
|
| 197 |
}
|
| 198 |
]
|
| 199 |
},
|
| 200 |
{
|
| 201 |
"domain_id": "employment_hr",
|
| 202 |
+
"domain_name": "\ud83d\udcbc Employment, HR & Workforce Management",
|
| 203 |
"statutory_category": "Annex III Point 4",
|
| 204 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 4(a) & 4(b)",
|
| 205 |
"domain_summary": "AI systems used for recruitment, CV screening, job candidate evaluation, task allocation, and worker performance monitoring.",
|
|
|
|
| 237 |
]
|
| 238 |
},
|
| 239 |
"conformity_procedure": "Annex VI: Internal Control Assessment",
|
| 240 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 241 |
},
|
| 242 |
"auditor_guidance": {
|
| 243 |
+
"intended_purpose": "Autonomous r\u00e9sum\u00e9 ingestion, semantic ranking, and interview invitation generation.",
|
| 244 |
"common_pitfalls": "Historic gender and demographic bias encoded in legacy recruitment datasets; lack of explicit human intervention kill switch before candidates are rejected.",
|
| 245 |
"remediation_guidance": "Perform disparate impact parity analysis (Four-Fifths rule / Equal Opportunity Difference) and require mandatory HR officer approval for all candidate rejections."
|
| 246 |
},
|
|
|
|
| 258 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 259 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 260 |
}
|
| 261 |
+
},
|
| 262 |
+
{
|
| 263 |
+
"case_id": "compliant_fairhire_screening",
|
| 264 |
+
"title": "FairHire Pro - Audited Bias-Mitigated Technical Recruitment Sifter",
|
| 265 |
+
"system_id": "hr-recruitment-03",
|
| 266 |
+
"statutory_tier": "High-Risk (Annex III, Point 4(a))",
|
| 267 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 4(a)",
|
| 268 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 269 |
+
"file_path": "data/synthetic_systems/compliant_fairhire_screening.json",
|
| 270 |
+
"statutory_quote": "AI systems intended to be used for recruitment or selection of natural persons, notably to place targeted job advertisements, to screen or filter applications, and to evaluate candidates.",
|
| 271 |
+
"regulatory_requirements": {
|
| 272 |
+
"mandatory_articles": [
|
| 273 |
+
"Article 9",
|
| 274 |
+
"Article 10",
|
| 275 |
+
"Article 10(2)(f)",
|
| 276 |
+
"Article 11",
|
| 277 |
+
"Article 12",
|
| 278 |
+
"Article 13",
|
| 279 |
+
"Article 14",
|
| 280 |
+
"Article 15"
|
| 281 |
+
],
|
| 282 |
+
"harmonized_frameworks": {
|
| 283 |
+
"nist_ai_rmf": [
|
| 284 |
+
"GOVERN-1.3",
|
| 285 |
+
"MAP-2.3",
|
| 286 |
+
"MEASURE-2.11",
|
| 287 |
+
"MANAGE-3.2"
|
| 288 |
+
],
|
| 289 |
+
"iso_42001": [
|
| 290 |
+
"Control A.6.2",
|
| 291 |
+
"Control A.8.4",
|
| 292 |
+
"Control A.9.2"
|
| 293 |
+
],
|
| 294 |
+
"gdpr": [
|
| 295 |
+
"Article 22 Automated Decisions",
|
| 296 |
+
"Article 88 Employment Processing"
|
| 297 |
+
]
|
| 298 |
+
},
|
| 299 |
+
"conformity_procedure": "Annex VI: Internal Control Assessment with documented third-party bias audits",
|
| 300 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 301 |
+
},
|
| 302 |
+
"auditor_guidance": {
|
| 303 |
+
"intended_purpose": "Candidate qualification ranking and resume shortlisting for recruitment.",
|
| 304 |
+
"common_pitfalls": "Hidden proxy bias in word embeddings (e.g. associating gendered extracurricular activities with aptitude); lack of human reviewer independence.",
|
| 305 |
+
"remediation_guidance": "Conduct biannual statistical bias audits and retain candidate adverse impact logs for 3 years."
|
| 306 |
+
},
|
| 307 |
+
"file_sha256": "9b01237ffe59b96d1135e6c29fc09932c30f098de6f98dcf051ebb09fe2553e8",
|
| 308 |
+
"provenance": {
|
| 309 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 310 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 311 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 312 |
+
"celex": "32024R1689",
|
| 313 |
+
"statutory_quote": "AI systems intended to be used for recruitment or selection of natural persons, notably to place targeted job advertisements, to screen or filter applications, and to evaluate candidates.",
|
| 314 |
+
"statutory_quote_sha256": "3c4764f14ff071e389175e3676bd3852b557469139a57fa652afe25cb5dde2ad",
|
| 315 |
+
"spec_file_sha256": "9b01237ffe59b96d1135e6c29fc09932c30f098de6f98dcf051ebb09fe2553e8",
|
| 316 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_fairhire_screening",
|
| 317 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 318 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 319 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 320 |
+
}
|
| 321 |
}
|
| 322 |
]
|
| 323 |
},
|
| 324 |
{
|
| 325 |
"domain_id": "banking_finance",
|
| 326 |
+
"domain_name": "\ud83c\udfe6 Financial Services, Credit & Insurance",
|
| 327 |
"statutory_category": "Annex III Point 5",
|
| 328 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 5(b) & 5(c)",
|
| 329 |
"domain_summary": "AI systems used to evaluate creditworthiness of natural persons, establish credit scores, or price risk in life and health insurance.",
|
|
|
|
| 361 |
]
|
| 362 |
},
|
| 363 |
"conformity_procedure": "Annex VI: Internal Control Assessment",
|
| 364 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 365 |
},
|
| 366 |
"auditor_guidance": {
|
| 367 |
"intended_purpose": "Consumer credit underwriting predicting loan default risk probabilities.",
|
|
|
|
| 382 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 383 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 384 |
}
|
| 385 |
+
},
|
| 386 |
+
{
|
| 387 |
+
"case_id": "compliant_mortgage_underwriting",
|
| 388 |
+
"title": "EuroLend AI - Explainable Algorithmic Retail Mortgage Underwriting",
|
| 389 |
+
"system_id": "fin-credit-02",
|
| 390 |
+
"statutory_tier": "High-Risk (Annex III, Point 5(b))",
|
| 391 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 5(b)",
|
| 392 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 393 |
+
"file_path": "data/synthetic_systems/compliant_mortgage_underwriting.json",
|
| 394 |
+
"statutory_quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.",
|
| 395 |
+
"regulatory_requirements": {
|
| 396 |
+
"mandatory_articles": [
|
| 397 |
+
"Article 9",
|
| 398 |
+
"Article 10",
|
| 399 |
+
"Article 10(2)(f)",
|
| 400 |
+
"Article 11",
|
| 401 |
+
"Article 12",
|
| 402 |
+
"Article 13",
|
| 403 |
+
"Article 14",
|
| 404 |
+
"Article 15"
|
| 405 |
+
],
|
| 406 |
+
"harmonized_frameworks": {
|
| 407 |
+
"nist_ai_rmf": [
|
| 408 |
+
"GOVERN-1.2",
|
| 409 |
+
"MAP-1.4",
|
| 410 |
+
"MEASURE-2.11",
|
| 411 |
+
"MANAGE-2.3"
|
| 412 |
+
],
|
| 413 |
+
"iso_42001": [
|
| 414 |
+
"Clause 6.1.2",
|
| 415 |
+
"Control A.8.4",
|
| 416 |
+
"Control A.9.2"
|
| 417 |
+
],
|
| 418 |
+
"gdpr": [
|
| 419 |
+
"Article 15 Right of Access",
|
| 420 |
+
"Article 22 Automated Decision-Making"
|
| 421 |
+
]
|
| 422 |
+
},
|
| 423 |
+
"conformity_procedure": "Annex VI: Internal Control Procedure with ECB / National Competent Authority Supervision",
|
| 424 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 425 |
+
},
|
| 426 |
+
"auditor_guidance": {
|
| 427 |
+
"intended_purpose": "Credit risk evaluation and retail residential mortgage underwriting.",
|
| 428 |
+
"common_pitfalls": "Redlining via postal code proxies; black-box neural networks failing to provide meaningful explanations under GDPR Article 22.",
|
| 429 |
+
"remediation_guidance": "Ensure monotonic constraints on risk features; provide explainable SHAP/LIME counterfactuals to all rejected borrowers."
|
| 430 |
+
},
|
| 431 |
+
"file_sha256": "6e9ee00c9dda0412ba33cdca0c8a1c8acf8e83654c9db0e8745627fc89934323",
|
| 432 |
+
"provenance": {
|
| 433 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 434 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 435 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 436 |
+
"celex": "32024R1689",
|
| 437 |
+
"statutory_quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.",
|
| 438 |
+
"statutory_quote_sha256": "79978eed3683f16e8cc3ad64ec9483f34fdb772b7bf840c5221843490de934be",
|
| 439 |
+
"spec_file_sha256": "6e9ee00c9dda0412ba33cdca0c8a1c8acf8e83654c9db0e8745627fc89934323",
|
| 440 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_mortgage_underwriting",
|
| 441 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 442 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 443 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 444 |
+
}
|
| 445 |
}
|
| 446 |
]
|
| 447 |
},
|
| 448 |
{
|
| 449 |
"domain_id": "transport_safety",
|
| 450 |
+
"domain_name": "\ud83d\ude97 Automotive & Road Transport Safety",
|
| 451 |
"statutory_category": "Annex I & Annex III Point 2",
|
| 452 |
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2019/2144 (General Vehicle Safety)",
|
| 453 |
"domain_summary": "AI safety components in autonomous and semi-autonomous vehicles, collision avoidance, and automated emergency braking (AEB).",
|
|
|
|
| 485 |
]
|
| 486 |
},
|
| 487 |
"conformity_procedure": "Vehicle Type Approval (UN ECE / Regulation (EU) 2019/2144)",
|
| 488 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 489 |
},
|
| 490 |
"auditor_guidance": {
|
| 491 |
"intended_purpose": "Safety component for automated emergency braking in commercial transport trucks.",
|
|
|
|
| 506 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 507 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 508 |
}
|
| 509 |
+
},
|
| 510 |
+
{
|
| 511 |
+
"case_id": "compliant_adas_lane_keeping",
|
| 512 |
+
"title": "RoadSentry LaneAssist - Automotive Steering & Lane Departure Safety Component",
|
| 513 |
+
"system_id": "auto-adas-02",
|
| 514 |
+
"statutory_tier": "High-Risk (Annex I, Vehicle Safety Component - Article 6(1))",
|
| 515 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2019/2144 (GSR)",
|
| 516 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 517 |
+
"file_path": "data/synthetic_systems/compliant_adas_lane_keeping.json",
|
| 518 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 519 |
+
"regulatory_requirements": {
|
| 520 |
+
"mandatory_articles": [
|
| 521 |
+
"Article 9",
|
| 522 |
+
"Article 10",
|
| 523 |
+
"Article 10(2)(f)",
|
| 524 |
+
"Article 11",
|
| 525 |
+
"Article 12",
|
| 526 |
+
"Article 13",
|
| 527 |
+
"Article 14",
|
| 528 |
+
"Article 15"
|
| 529 |
+
],
|
| 530 |
+
"harmonized_frameworks": {
|
| 531 |
+
"nist_ai_rmf": [
|
| 532 |
+
"GOVERN-1.2",
|
| 533 |
+
"MAP-1.5",
|
| 534 |
+
"MEASURE-2.8",
|
| 535 |
+
"MANAGE-2.2"
|
| 536 |
+
],
|
| 537 |
+
"iso_42001": [
|
| 538 |
+
"Clause 6.1.2",
|
| 539 |
+
"Control A.8.4",
|
| 540 |
+
"Control A.9.2"
|
| 541 |
+
],
|
| 542 |
+
"gdpr": [
|
| 543 |
+
"Regulation (EU) 2019/2144 (GSR) Type Approval"
|
| 544 |
+
]
|
| 545 |
+
},
|
| 546 |
+
"conformity_procedure": "Annex VII: Combined Vehicle Type-Approval and AI Act Conformity Assessment",
|
| 547 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 548 |
+
},
|
| 549 |
+
"auditor_guidance": {
|
| 550 |
+
"intended_purpose": "Automotive lane-keeping assist safety component for passenger vehicles.",
|
| 551 |
+
"common_pitfalls": "Failing to implement instantaneous human steering override; unverified sensor behavior in severe rain or snow.",
|
| 552 |
+
"remediation_guidance": "Verify capacitive hands-on-wheel failsafe triggers; audit ASIL-B safety case documentation."
|
| 553 |
+
},
|
| 554 |
+
"file_sha256": "928177f38b05a7c8c49a8d19e1f257430ce959bf1e013413275a0ae634cebad1",
|
| 555 |
+
"provenance": {
|
| 556 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 557 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 558 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 559 |
+
"celex": "32024R1689",
|
| 560 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 561 |
+
"statutory_quote_sha256": "5dcc4a383d81f69e7988c97f6e6e2d5b85bcd096ebd033df9cb198b12433d785",
|
| 562 |
+
"spec_file_sha256": "928177f38b05a7c8c49a8d19e1f257430ce959bf1e013413275a0ae634cebad1",
|
| 563 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_adas_lane_keeping",
|
| 564 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 565 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 566 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 567 |
+
}
|
| 568 |
}
|
| 569 |
]
|
| 570 |
},
|
| 571 |
{
|
| 572 |
"domain_id": "critical_infrastructure",
|
| 573 |
+
"domain_name": "\u26a1 Critical Infrastructure & Energy",
|
| 574 |
"statutory_category": "Annex III Point 2(a)",
|
| 575 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 2(a)",
|
| 576 |
"domain_summary": "AI systems used as safety components in the management and operation of critical digital infrastructure, electricity, water, or gas grids.",
|
|
|
|
| 606 |
]
|
| 607 |
},
|
| 608 |
"conformity_procedure": "Annex VI: Internal Control Assessment + NIS 2 Directive compliance",
|
| 609 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 610 |
},
|
| 611 |
"auditor_guidance": {
|
| 612 |
"intended_purpose": "Predicting transmission grid frequency instability and automating substation load shedding.",
|
|
|
|
| 627 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 628 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 629 |
}
|
| 630 |
+
},
|
| 631 |
+
{
|
| 632 |
+
"case_id": "non_compliant_water_scada",
|
| 633 |
+
"title": "HydroFlow AI - Autonomous Municipal Water Chlorination Controller",
|
| 634 |
+
"system_id": "infra-water-02",
|
| 635 |
+
"statutory_tier": "High-Risk (Annex III, Point 2(a))",
|
| 636 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 2(a)",
|
| 637 |
+
"expected_conformity": "NON-CONFORMANT (FAILED)",
|
| 638 |
+
"file_path": "data/synthetic_systems/non_compliant_water_scada.json",
|
| 639 |
+
"statutory_quote": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.",
|
| 640 |
+
"regulatory_requirements": {
|
| 641 |
+
"mandatory_articles": [
|
| 642 |
+
"Article 9",
|
| 643 |
+
"Article 10",
|
| 644 |
+
"Article 11",
|
| 645 |
+
"Article 12",
|
| 646 |
+
"Article 13",
|
| 647 |
+
"Article 14",
|
| 648 |
+
"Article 15"
|
| 649 |
+
],
|
| 650 |
+
"harmonized_frameworks": {
|
| 651 |
+
"nist_ai_rmf": [
|
| 652 |
+
"GOVERN-1.2",
|
| 653 |
+
"MANAGE-2.2",
|
| 654 |
+
"MEASURE-2.8"
|
| 655 |
+
],
|
| 656 |
+
"iso_42001": [
|
| 657 |
+
"Control A.8.4",
|
| 658 |
+
"Control A.9.2"
|
| 659 |
+
],
|
| 660 |
+
"gdpr": [
|
| 661 |
+
"NIS2 Directive (EU) 2022/2555 Alignment"
|
| 662 |
+
]
|
| 663 |
+
},
|
| 664 |
+
"conformity_procedure": "Annex VII: Notified Body Assessment for Safety Critical Infrastructure",
|
| 665 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 666 |
+
},
|
| 667 |
+
"auditor_guidance": {
|
| 668 |
+
"intended_purpose": "Autonomous chemical dosing in drinking water supply infrastructure.",
|
| 669 |
+
"common_pitfalls": "Allowing closed-loop autonomous chemical actuation without hardware fail-safe limiters; omitting human operator in the loop during off-peak hours.",
|
| 670 |
+
"remediation_guidance": "Install physical hardware interlocks preventing toxic over-dosing; isolate SCADA network under IEC 62443; enforce mandatory operator confirmation for valve adjustments."
|
| 671 |
+
},
|
| 672 |
+
"file_sha256": "7a8523ccad159e5bb64c592b7e0e7098a5bee634c167400e049b17a58253597e",
|
| 673 |
+
"provenance": {
|
| 674 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 675 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 676 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 677 |
+
"celex": "32024R1689",
|
| 678 |
+
"statutory_quote": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.",
|
| 679 |
+
"statutory_quote_sha256": "327cf2124c09cf4d5ccff5b7e6e006177f5879a1728d37e352b31c44b4344b56",
|
| 680 |
+
"spec_file_sha256": "7a8523ccad159e5bb64c592b7e0e7098a5bee634c167400e049b17a58253597e",
|
| 681 |
+
"prov_o_entity": "urn:reguai:benchmark:case:non_compliant_water_scada",
|
| 682 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 683 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 684 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 685 |
+
}
|
| 686 |
}
|
| 687 |
]
|
| 688 |
},
|
| 689 |
{
|
| 690 |
"domain_id": "education_training",
|
| 691 |
+
"domain_name": "\ud83c\udf93 Education & Vocational Training",
|
| 692 |
"statutory_category": "Annex III Point 3",
|
| 693 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 3(a) & 3(b)",
|
| 694 |
"domain_summary": "AI systems used for student admission, assignment, grading, and monitoring or detecting prohibited behaviour of students during tests.",
|
|
|
|
| 725 |
]
|
| 726 |
},
|
| 727 |
"conformity_procedure": "Annex VI: Internal Control Assessment",
|
| 728 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 729 |
},
|
| 730 |
"auditor_guidance": {
|
| 731 |
"intended_purpose": "Automated webcam gaze tracking and cheating detection during remote university exams.",
|
|
|
|
| 746 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 747 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 748 |
}
|
| 749 |
+
},
|
| 750 |
+
{
|
| 751 |
+
"case_id": "compliant_adaptive_stem_tutor",
|
| 752 |
+
"title": "AdaptiveMath - Personalized Secondary STEM Learning Assistant",
|
| 753 |
+
"system_id": "edu-tutor-02",
|
| 754 |
+
"statutory_tier": "High-Risk (Annex III, Point 3(b))",
|
| 755 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 3(b)",
|
| 756 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 757 |
+
"file_path": "data/synthetic_systems/compliant_adaptive_stem_tutor.json",
|
| 758 |
+
"statutory_quote": "AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions.",
|
| 759 |
+
"regulatory_requirements": {
|
| 760 |
+
"mandatory_articles": [
|
| 761 |
+
"Article 9",
|
| 762 |
+
"Article 10",
|
| 763 |
+
"Article 10(2)(f)",
|
| 764 |
+
"Article 11",
|
| 765 |
+
"Article 12",
|
| 766 |
+
"Article 13",
|
| 767 |
+
"Article 14",
|
| 768 |
+
"Article 15"
|
| 769 |
+
],
|
| 770 |
+
"harmonized_frameworks": {
|
| 771 |
+
"nist_ai_rmf": [
|
| 772 |
+
"GOVERN-1.2",
|
| 773 |
+
"MAP-2.3",
|
| 774 |
+
"MEASURE-2.11",
|
| 775 |
+
"MANAGE-3.2"
|
| 776 |
+
],
|
| 777 |
+
"iso_42001": [
|
| 778 |
+
"Control A.6.2",
|
| 779 |
+
"Control A.8.4",
|
| 780 |
+
"Control A.9.2"
|
| 781 |
+
],
|
| 782 |
+
"gdpr": [
|
| 783 |
+
"Article 8 Child Consent",
|
| 784 |
+
"Article 35 DPIA"
|
| 785 |
+
]
|
| 786 |
+
},
|
| 787 |
+
"conformity_procedure": "Annex VI: Internal Control Procedure with School Board Governance",
|
| 788 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 789 |
+
},
|
| 790 |
+
"auditor_guidance": {
|
| 791 |
+
"intended_purpose": "Personalized educational pacing and formative learning recommendations.",
|
| 792 |
+
"common_pitfalls": "Confusing formative tutor recommendations with summative automated student grading; collecting unnecessary behavioral biometric telemetry from minors.",
|
| 793 |
+
"remediation_guidance": "Ensure student data is anonymized; maintain clear teacher override mechanisms for all curriculum pacing suggestions."
|
| 794 |
+
},
|
| 795 |
+
"file_sha256": "a2a3580138bfa6abfd5b349c5d25b6704553e12754c7f58af6eca9f61b5fb183",
|
| 796 |
+
"provenance": {
|
| 797 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 798 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 799 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 800 |
+
"celex": "32024R1689",
|
| 801 |
+
"statutory_quote": "AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions.",
|
| 802 |
+
"statutory_quote_sha256": "be0d78659b67ea0bd59c8429e659fed9817427733c4471f06183cfb4f985dc11",
|
| 803 |
+
"spec_file_sha256": "a2a3580138bfa6abfd5b349c5d25b6704553e12754c7f58af6eca9f61b5fb183",
|
| 804 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_adaptive_stem_tutor",
|
| 805 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 806 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 807 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 808 |
+
}
|
| 809 |
}
|
| 810 |
]
|
| 811 |
},
|
| 812 |
{
|
| 813 |
"domain_id": "justice_law_enforcement",
|
| 814 |
+
"domain_name": "\u2696\ufe0f Law Enforcement & Criminal Justice",
|
| 815 |
"statutory_category": "Annex III Points 6 & 8",
|
| 816 |
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 6(a) & Point 8",
|
| 817 |
"domain_summary": "AI systems used for individual criminal risk assessments, recidivism forecasting, evidence evaluation, and assisting judicial authorities.",
|
|
|
|
| 848 |
]
|
| 849 |
},
|
| 850 |
"conformity_procedure": "Annex VI: Internal Control Assessment + Fundamental Rights Impact Assessment (FRIA, Art. 27)",
|
| 851 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 852 |
},
|
| 853 |
"auditor_guidance": {
|
| 854 |
"intended_purpose": "Predicting defendant failure-to-appear and re-arrest probability for arraignment judges.",
|
|
|
|
| 869 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 870 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 871 |
}
|
| 872 |
+
},
|
| 873 |
+
{
|
| 874 |
+
"case_id": "compliant_digital_forensics",
|
| 875 |
+
"title": "LexEvidence AI - Judicial Post-Event Forensic Media Search Tool",
|
| 876 |
+
"system_id": "justice-forensic-02",
|
| 877 |
+
"statutory_tier": "High-Risk (Annex III, Point 6(b))",
|
| 878 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 6(b)",
|
| 879 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 880 |
+
"file_path": "data/synthetic_systems/compliant_digital_forensics.json",
|
| 881 |
+
"statutory_quote": "AI systems intended to be used by law enforcement authorities or on their behalf to assess the risk of a natural person offending or re-offending, or to evaluate the reliability of evidence in the course of investigation or prosecution of criminal offences.",
|
| 882 |
+
"regulatory_requirements": {
|
| 883 |
+
"mandatory_articles": [
|
| 884 |
+
"Article 9",
|
| 885 |
+
"Article 10",
|
| 886 |
+
"Article 10(2)(f)",
|
| 887 |
+
"Article 11",
|
| 888 |
+
"Article 12",
|
| 889 |
+
"Article 13",
|
| 890 |
+
"Article 14",
|
| 891 |
+
"Article 15"
|
| 892 |
+
],
|
| 893 |
+
"harmonized_frameworks": {
|
| 894 |
+
"nist_ai_rmf": [
|
| 895 |
+
"GOVERN-1.1",
|
| 896 |
+
"MAP-2.3",
|
| 897 |
+
"MEASURE-2.11",
|
| 898 |
+
"MANAGE-3.2"
|
| 899 |
+
],
|
| 900 |
+
"iso_42001": [
|
| 901 |
+
"Control A.6.2",
|
| 902 |
+
"Control A.8.4",
|
| 903 |
+
"Control A.9.2"
|
| 904 |
+
],
|
| 905 |
+
"gdpr": [
|
| 906 |
+
"Directive (EU) 2016/680 (LED)",
|
| 907 |
+
"Charter of Fundamental Rights Art 47"
|
| 908 |
+
]
|
| 909 |
+
},
|
| 910 |
+
"conformity_procedure": "Annex VI: Internal Control Assessment under Judicial Supervision",
|
| 911 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 912 |
+
},
|
| 913 |
+
"auditor_guidance": {
|
| 914 |
+
"intended_purpose": "Retrospective forensic search of lawfully obtained digital evidence.",
|
| 915 |
+
"common_pitfalls": "Creeping into predictive policing or real-time public biometric surveillance; lack of judicial warrant verification.",
|
| 916 |
+
"remediation_guidance": "Verify strict air-gapped chain-of-custody logging and explicit human forensic investigator confirmation."
|
| 917 |
+
},
|
| 918 |
+
"file_sha256": "f5865588668dbca7e231584eaf6b21d16657a2158dc4ec64b42dd518aee6abc6",
|
| 919 |
+
"provenance": {
|
| 920 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 921 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 922 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 923 |
+
"celex": "32024R1689",
|
| 924 |
+
"statutory_quote": "AI systems intended to be used by law enforcement authorities or on their behalf to assess the risk of a natural person offending or re-offending, or to evaluate the reliability of evidence in the course of investigation or prosecution of criminal offences.",
|
| 925 |
+
"statutory_quote_sha256": "2581bc2ccc920d54638ec0485289bfe0c3d5a7021941101e63e1c72a775f9c67",
|
| 926 |
+
"spec_file_sha256": "f5865588668dbca7e231584eaf6b21d16657a2158dc4ec64b42dd518aee6abc6",
|
| 927 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_digital_forensics",
|
| 928 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 929 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 930 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 931 |
+
}
|
| 932 |
}
|
| 933 |
]
|
| 934 |
},
|
| 935 |
{
|
| 936 |
"domain_id": "frontier_gpai",
|
| 937 |
+
"domain_name": "\ud83c\udf10 Frontier GPAI & Foundation Models",
|
| 938 |
+
"statutory_category": "Chapter V (Articles 51\u201355)",
|
| 939 |
"legal_basis": "Regulation (EU) 2024/1689, Chapter V, Articles 51, 52, 53, 55",
|
| 940 |
"domain_summary": "General-purpose AI models, frontier LLMs trained on > 10^25 FLOPs, systemic risk mitigations, and copyright opt-out enforcement.",
|
| 941 |
"case_studies": [
|
|
|
|
| 970 |
]
|
| 971 |
},
|
| 972 |
"conformity_procedure": "AI Office Code of Practice / Independent Red-Teaming Attestation",
|
| 973 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 974 |
},
|
| 975 |
"auditor_guidance": {
|
| 976 |
"intended_purpose": "Multi-modal frontier foundation LLM deployed for downstream enterprise reasoning and code generation.",
|
|
|
|
| 991 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 992 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 993 |
}
|
| 994 |
+
},
|
| 995 |
+
{
|
| 996 |
+
"case_id": "compliant_open_frontier_llm",
|
| 997 |
+
"title": "Sovereign-120B - Audited Open Frontier GPAI Model (>10^25 FLOPs)",
|
| 998 |
+
"system_id": "gpai-sovereign-02",
|
| 999 |
+
"statutory_tier": "General Purpose AI with Systemic Risk (Articles 51, 52, 53, 55)",
|
| 1000 |
+
"legal_basis": "Regulation (EU) 2024/1689, Articles 51, 53 & 55",
|
| 1001 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 1002 |
+
"file_path": "data/synthetic_systems/compliant_open_frontier_llm.json",
|
| 1003 |
+
"statutory_quote": "A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, or the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.",
|
| 1004 |
+
"regulatory_requirements": {
|
| 1005 |
+
"mandatory_articles": [
|
| 1006 |
+
"Article 51",
|
| 1007 |
+
"Article 52",
|
| 1008 |
+
"Article 53",
|
| 1009 |
+
"Article 55"
|
| 1010 |
+
],
|
| 1011 |
+
"harmonized_frameworks": {
|
| 1012 |
+
"nist_ai_rmf": [
|
| 1013 |
+
"GOVERN-1.2",
|
| 1014 |
+
"MANAGE-2.4",
|
| 1015 |
+
"MEASURE-2.12"
|
| 1016 |
+
],
|
| 1017 |
+
"iso_42001": [
|
| 1018 |
+
"Clause 6.1",
|
| 1019 |
+
"Control A.8.2",
|
| 1020 |
+
"Control A.9.1"
|
| 1021 |
+
],
|
| 1022 |
+
"gdpr": [
|
| 1023 |
+
"Directive (EU) 2019/790 Copyright DSM"
|
| 1024 |
+
]
|
| 1025 |
+
},
|
| 1026 |
+
"conformity_procedure": "AI Office Code of Practice / Harmonized Standards Adherence",
|
| 1027 |
+
"fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)"
|
| 1028 |
+
},
|
| 1029 |
+
"auditor_guidance": {
|
| 1030 |
+
"intended_purpose": "High-capacity frontier foundation model for diverse downstream linguistic tasks.",
|
| 1031 |
+
"common_pitfalls": "Failing to document copyright opt-outs under Article 53(1)(c); omitting independent third-party red-teaming for CBRN and cyber risk.",
|
| 1032 |
+
"remediation_guidance": "Publish comprehensive training data summary template; maintain continuous telemetry for serious incident reporting to the European AI Office."
|
| 1033 |
+
},
|
| 1034 |
+
"file_sha256": "2cf75e44a660873e3cd712b7c8f3c7ebf079019e298b21742ab97090f07edd5e",
|
| 1035 |
+
"provenance": {
|
| 1036 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 1037 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 1038 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 1039 |
+
"celex": "32024R1689",
|
| 1040 |
+
"statutory_quote": "A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, or the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.",
|
| 1041 |
+
"statutory_quote_sha256": "fa76d9f7299723ad872f72e72d6339535de83626d8a9f4bdfc49eed112fb92b9",
|
| 1042 |
+
"spec_file_sha256": "2cf75e44a660873e3cd712b7c8f3c7ebf079019e298b21742ab97090f07edd5e",
|
| 1043 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_open_frontier_llm",
|
| 1044 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 1045 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1046 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 1047 |
+
}
|
| 1048 |
}
|
| 1049 |
]
|
| 1050 |
},
|
| 1051 |
{
|
| 1052 |
"domain_id": "prohibited_practices",
|
| 1053 |
+
"domain_name": "\ud83d\udeab Prohibited AI Practices (Article 5 - Zero Tolerance)",
|
| 1054 |
"statutory_category": "Chapter II, Article 5",
|
| 1055 |
"legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(a)-(h)",
|
| 1056 |
+
"domain_summary": "Strictly illegal AI systems causing unacceptable risk to fundamental human rights, subject to fatal ban and \u20ac35M statutory fines.",
|
| 1057 |
"case_studies": [
|
| 1058 |
{
|
| 1059 |
"case_id": "prohibited_emotion_recognition_workplace",
|
|
|
|
| 1080 |
]
|
| 1081 |
},
|
| 1082 |
"conformity_procedure": "IMMEDIATE CEASE / PROHIBITED FROM UNION MARKET",
|
| 1083 |
+
"fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)"
|
| 1084 |
},
|
| 1085 |
"auditor_guidance": {
|
| 1086 |
"intended_purpose": "Continuous automated facial micro-expression analysis to infer employee attentiveness and classroom student engagement.",
|
|
|
|
| 1127 |
]
|
| 1128 |
},
|
| 1129 |
"conformity_procedure": "IMMEDIATE CEASE / PROHIBITED FROM UNION MARKET",
|
| 1130 |
+
"fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)"
|
| 1131 |
},
|
| 1132 |
"auditor_guidance": {
|
| 1133 |
"intended_purpose": "Evaluating citizen trustworthiness based on social behavior and administrative compliance to allocate public benefits.",
|
|
|
|
| 1148 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1149 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 1150 |
}
|
| 1151 |
+
},
|
| 1152 |
+
{
|
| 1153 |
+
"case_id": "prohibited_subliminal_gambling_nudge",
|
| 1154 |
+
"title": "NeuroSpin - Subliminal Behavioral Nudge Engine for Mobile Gambling",
|
| 1155 |
+
"system_id": "prohibited-subliminal-03",
|
| 1156 |
+
"statutory_tier": "Prohibited AI Practice (Article 5(1)(a) - Absolute Ban)",
|
| 1157 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(a)",
|
| 1158 |
+
"expected_conformity": "PROHIBITED (ARTICLE 5 VIOLATION)",
|
| 1159 |
+
"file_path": "data/synthetic_systems/prohibited_subliminal_gambling_nudge.json",
|
| 1160 |
+
"statutory_quote": "The following AI practices shall be prohibited: the placing on the market, putting into service or use of an AI system that deploys subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of, materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to make a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm.",
|
| 1161 |
+
"regulatory_requirements": {
|
| 1162 |
+
"mandatory_articles": [
|
| 1163 |
+
"Article 5(1)(a)"
|
| 1164 |
+
],
|
| 1165 |
+
"harmonized_frameworks": {
|
| 1166 |
+
"nist_ai_rmf": [
|
| 1167 |
+
"GOVERN-1.1 Prohibited Harm"
|
| 1168 |
+
],
|
| 1169 |
+
"iso_42001": [
|
| 1170 |
+
"Zero-Tolerance Ethics"
|
| 1171 |
+
],
|
| 1172 |
+
"gdpr": [
|
| 1173 |
+
"Article 5 Fairness & Transparency",
|
| 1174 |
+
"Charter of Fundamental Rights"
|
| 1175 |
+
]
|
| 1176 |
+
},
|
| 1177 |
+
"conformity_procedure": "Prohibited under Union law. No conformity assessment permitted. Immediate market withdrawal mandated.",
|
| 1178 |
+
"fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)"
|
| 1179 |
+
},
|
| 1180 |
+
"auditor_guidance": {
|
| 1181 |
+
"intended_purpose": "Subliminal player behavioral manipulation and deposit prolongation.",
|
| 1182 |
+
"common_pitfalls": "Attempting to disguise subliminal audio-visual techniques as 'UI personalization' or 'gamification'.",
|
| 1183 |
+
"remediation_guidance": "Immediate decommission of AI system; mandatory report to market surveillance authorities; Tier 1 administrative fine exposure."
|
| 1184 |
+
},
|
| 1185 |
+
"file_sha256": "4ff20b07678a9cba1aa74c009f2286f79ea8eed86f0f342fcb1251fbe957d3c2",
|
| 1186 |
+
"provenance": {
|
| 1187 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 1188 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 1189 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 1190 |
+
"celex": "32024R1689",
|
| 1191 |
+
"statutory_quote": "The following AI practices shall be prohibited: the placing on the market, putting into service or use of an AI system that deploys subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of, materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to make a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm.",
|
| 1192 |
+
"statutory_quote_sha256": "4420c5ade7cd55ac96d01d0a9537c22ff842151c1f91a98e2a1c705c62936949",
|
| 1193 |
+
"spec_file_sha256": "4ff20b07678a9cba1aa74c009f2286f79ea8eed86f0f342fcb1251fbe957d3c2",
|
| 1194 |
+
"prov_o_entity": "urn:reguai:benchmark:case:prohibited_subliminal_gambling_nudge",
|
| 1195 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 1196 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1197 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 1198 |
+
}
|
| 1199 |
+
},
|
| 1200 |
+
{
|
| 1201 |
+
"case_id": "prohibited_biometric_categorization_beliefs",
|
| 1202 |
+
"title": "BioClassify - CCTV Biometric Categorization of Political Beliefs",
|
| 1203 |
+
"system_id": "prohibited-bioclass-04",
|
| 1204 |
+
"statutory_tier": "Prohibited AI Practice (Article 5(1)(c) - Absolute Ban)",
|
| 1205 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(c)",
|
| 1206 |
+
"expected_conformity": "PROHIBITED (ARTICLE 5 VIOLATION)",
|
| 1207 |
+
"file_path": "data/synthetic_systems/prohibited_biometric_categorization_beliefs.json",
|
| 1208 |
+
"statutory_quote": "The following AI practices shall be prohibited: the placing on the market, the putting into service for this purpose, or use of biometric categorization systems that categorize individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.",
|
| 1209 |
+
"regulatory_requirements": {
|
| 1210 |
+
"mandatory_articles": [
|
| 1211 |
+
"Article 5(1)(c)"
|
| 1212 |
+
],
|
| 1213 |
+
"harmonized_frameworks": {
|
| 1214 |
+
"nist_ai_rmf": [
|
| 1215 |
+
"GOVERN-1.1 Prohibited Harm"
|
| 1216 |
+
],
|
| 1217 |
+
"iso_42001": [
|
| 1218 |
+
"Zero-Tolerance Ban"
|
| 1219 |
+
],
|
| 1220 |
+
"gdpr": [
|
| 1221 |
+
"Article 9 Special Category Data Prohibition"
|
| 1222 |
+
]
|
| 1223 |
+
},
|
| 1224 |
+
"conformity_procedure": "Prohibited under Union law. Immediate permanent ban and market removal mandated.",
|
| 1225 |
+
"fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)"
|
| 1226 |
+
},
|
| 1227 |
+
"auditor_guidance": {
|
| 1228 |
+
"intended_purpose": "Inferring political or religious beliefs from facial or biometric surveillance.",
|
| 1229 |
+
"common_pitfalls": "Claiming biometric categorization is permissible under 'smart city analytics' or 'demographic foot-traffic research'.",
|
| 1230 |
+
"remediation_guidance": "Immediate cessation of processing; deletion of all biometric model weights; mandatory report to Data Protection Authority and EU AI Office."
|
| 1231 |
+
},
|
| 1232 |
+
"file_sha256": "eb303b5e0e7c7d6734108bf796ee746aef9ceb8d12b90c37f3d5678e770c84af",
|
| 1233 |
+
"provenance": {
|
| 1234 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 1235 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 1236 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 1237 |
+
"celex": "32024R1689",
|
| 1238 |
+
"statutory_quote": "The following AI practices shall be prohibited: the placing on the market, the putting into service for this purpose, or use of biometric categorization systems that categorize individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.",
|
| 1239 |
+
"statutory_quote_sha256": "5650de7e6af380e323974bd3041c748ffe6b3c83ba1d0799c8d255ca9160ccf7",
|
| 1240 |
+
"spec_file_sha256": "eb303b5e0e7c7d6734108bf796ee746aef9ceb8d12b90c37f3d5678e770c84af",
|
| 1241 |
+
"prov_o_entity": "urn:reguai:benchmark:case:prohibited_biometric_categorization_beliefs",
|
| 1242 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 1243 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1244 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 1245 |
+
}
|
| 1246 |
}
|
| 1247 |
]
|
| 1248 |
},
|
| 1249 |
{
|
| 1250 |
"domain_id": "limited_risk_generative",
|
| 1251 |
+
"domain_name": "\ud83d\udcac Limited Risk & Generative Transparency",
|
| 1252 |
"statutory_category": "Chapter IV, Article 50",
|
| 1253 |
"legal_basis": "Regulation (EU) 2024/1689, Article 50(1) & 50(2)",
|
| 1254 |
"domain_summary": "AI systems directly interacting with natural persons (chatbots) and generative synthetic audio/video systems requiring transparency disclosures.",
|
|
|
|
| 1280 |
]
|
| 1281 |
},
|
| 1282 |
"conformity_procedure": "Self-Declaration Transparency Disclosure (No Notified Body required)",
|
| 1283 |
+
"fine_exposure_tier": "Tier 3 (\u20ac7,500,000 or 1.5% global turnover for false disclosures)"
|
| 1284 |
},
|
| 1285 |
"auditor_guidance": {
|
| 1286 |
"intended_purpose": "Natural language conversational agent assisting retail bank customers with routine inquiries.",
|
|
|
|
| 1301 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1302 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 1303 |
}
|
| 1304 |
+
},
|
| 1305 |
+
{
|
| 1306 |
+
"case_id": "compliant_virtual_presenter_deepfake",
|
| 1307 |
+
"title": "Synthetica Studio - Photorealistic Virtual Presenter & Video Avatar",
|
| 1308 |
+
"system_id": "gen-video-avatar-02",
|
| 1309 |
+
"statutory_tier": "Limited Risk (Transparency Obligations - Article 50)",
|
| 1310 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 50(2) & 50(4)",
|
| 1311 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 1312 |
+
"file_path": "data/synthetic_systems/compliant_virtual_presenter_deepfake.json",
|
| 1313 |
+
"statutory_quote": "Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.",
|
| 1314 |
+
"regulatory_requirements": {
|
| 1315 |
+
"mandatory_articles": [
|
| 1316 |
+
"Article 50(2)",
|
| 1317 |
+
"Article 50(4)"
|
| 1318 |
+
],
|
| 1319 |
+
"harmonized_frameworks": {
|
| 1320 |
+
"nist_ai_rmf": [
|
| 1321 |
+
"GOVERN-1.2",
|
| 1322 |
+
"MEASURE-2.8"
|
| 1323 |
+
],
|
| 1324 |
+
"iso_42001": [
|
| 1325 |
+
"Control A.8.2"
|
| 1326 |
+
],
|
| 1327 |
+
"gdpr": [
|
| 1328 |
+
"C2PA Provenance Standards"
|
| 1329 |
+
]
|
| 1330 |
+
},
|
| 1331 |
+
"conformity_procedure": "Voluntary Code of Practice / Article 50 Transparency Audit",
|
| 1332 |
+
"fine_exposure_tier": "Tier 3 (\u20ac7,500,000 or 1.5% global turnover)"
|
| 1333 |
+
},
|
| 1334 |
+
"auditor_guidance": {
|
| 1335 |
+
"intended_purpose": "Photorealistic synthetic avatar video generation for enterprise training.",
|
| 1336 |
+
"common_pitfalls": "Removing watermarking metadata in exported MP4 files; failing to obtain actor consent.",
|
| 1337 |
+
"remediation_guidance": "Ensure C2PA provenance manifests survive standard web video transcoding; verify persistent visual disclosure."
|
| 1338 |
+
},
|
| 1339 |
+
"file_sha256": "34a380b970932490566e393c04d235053402afdbfcf06b78f47362c96ae518bb",
|
| 1340 |
+
"provenance": {
|
| 1341 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 1342 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 1343 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 1344 |
+
"celex": "32024R1689",
|
| 1345 |
+
"statutory_quote": "Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.",
|
| 1346 |
+
"statutory_quote_sha256": "a15d222ef65c0da8f5dcb81f7d65c37e3ba48a6312bb3aca3650032a0d71f143",
|
| 1347 |
+
"spec_file_sha256": "34a380b970932490566e393c04d235053402afdbfcf06b78f47362c96ae518bb",
|
| 1348 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_virtual_presenter_deepfake",
|
| 1349 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 1350 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1351 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 1352 |
+
}
|
| 1353 |
}
|
| 1354 |
]
|
| 1355 |
},
|
| 1356 |
{
|
| 1357 |
"domain_id": "minimal_risk",
|
| 1358 |
+
"domain_name": "\ud83d\udfe2 Minimal / Low Risk (Voluntary Codes of Conduct)",
|
| 1359 |
"statutory_category": "Title IX, Article 95",
|
| 1360 |
"legal_basis": "Regulation (EU) 2024/1689, Article 95",
|
| 1361 |
"domain_summary": "Unconstrained AI systems such as spam filters, recommender systems, and inventory optimizers with voluntary adherence to European Codes of Conduct.",
|
|
|
|
| 1406 |
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1407 |
"timestamp": "2026-09-20T20:55:00Z"
|
| 1408 |
}
|
| 1409 |
+
},
|
| 1410 |
+
{
|
| 1411 |
+
"case_id": "compliant_warehouse_logistics_optimizer",
|
| 1412 |
+
"title": "PathMatrix AI - Autonomous Warehouse Forklift Route Dispatcher",
|
| 1413 |
+
"system_id": "minimal-logistics-02",
|
| 1414 |
+
"statutory_tier": "Minimal Risk (Voluntary Code of Conduct - Article 95)",
|
| 1415 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 95",
|
| 1416 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 1417 |
+
"file_path": "data/synthetic_systems/compliant_warehouse_logistics_optimizer.json",
|
| 1418 |
+
"statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Title III, Chapter 2.",
|
| 1419 |
+
"regulatory_requirements": {
|
| 1420 |
+
"mandatory_articles": [
|
| 1421 |
+
"Article 4 AI Literacy",
|
| 1422 |
+
"Article 95 Codes of Conduct"
|
| 1423 |
+
],
|
| 1424 |
+
"harmonized_frameworks": {
|
| 1425 |
+
"nist_ai_rmf": [
|
| 1426 |
+
"GOVERN-1.1"
|
| 1427 |
+
],
|
| 1428 |
+
"iso_42001": [
|
| 1429 |
+
"Voluntary Alignment"
|
| 1430 |
+
],
|
| 1431 |
+
"gdpr": [
|
| 1432 |
+
"Non-Personal Data Processing"
|
| 1433 |
+
]
|
| 1434 |
+
},
|
| 1435 |
+
"conformity_procedure": "Exempt from mandatory third-party assessment; voluntary code of conduct adhesion.",
|
| 1436 |
+
"fine_exposure_tier": "None (Compliant Minimal Risk)"
|
| 1437 |
+
},
|
| 1438 |
+
"auditor_guidance": {
|
| 1439 |
+
"intended_purpose": "Internal spatial route optimization for warehouse machinery.",
|
| 1440 |
+
"common_pitfalls": "Creeping into worker monitoring if vehicle telemetry is used to evaluate forklift driver speed or productivity without labor consultation.",
|
| 1441 |
+
"remediation_guidance": "Ensure operational logs isolate vehicle mechanical stats from driver personal IDs."
|
| 1442 |
+
},
|
| 1443 |
+
"file_sha256": "a6a2985c0390eafd415c246b9f7ec5fb0f895de61c442382f884c4730b958354",
|
| 1444 |
+
"provenance": {
|
| 1445 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 1446 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 1447 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 1448 |
+
"celex": "32024R1689",
|
| 1449 |
+
"statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Title III, Chapter 2.",
|
| 1450 |
+
"statutory_quote_sha256": "5b2e584bf800e8d3b786d670ce6484d2e76c48d79e4ce9b2cd4df2c4b0e35a20",
|
| 1451 |
+
"spec_file_sha256": "a6a2985c0390eafd415c246b9f7ec5fb0f895de61c442382f884c4730b958354",
|
| 1452 |
+
"prov_o_entity": "urn:reguai:benchmark:case:compliant_warehouse_logistics_optimizer",
|
| 1453 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 1454 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 1455 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 1456 |
+
}
|
| 1457 |
}
|
| 1458 |
]
|
| 1459 |
}
|
data/synthetic_systems/compliant_adaptive_stem_tutor.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "edu-tutor-02",
|
| 4 |
+
"name": "AdaptiveMath Personalized Learning System",
|
| 5 |
+
"version": "2.3.0",
|
| 6 |
+
"domain": "Education & Vocational Training",
|
| 7 |
+
"intended_purpose": "Curriculum pacing adaptation, formative feedback generation, and learning difficulty identification for secondary school mathematics.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 3(b))",
|
| 9 |
+
"developer_name": "CognitiveEd Solutions SE",
|
| 10 |
+
"deployment_context": "European Public Secondary School Learning Management System"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# AdaptiveMath Personalized Learning Assistant Specification\n\n## Intended Use and Scope\nAdaptiveMath is an educational AI system deployed across secondary schools in EU Member States. The platform dynamically adjusts problem difficulty and generates personalized explanations to assist students in mastering STEM curricula.\n\n## Risk Management (Article 9)\nA continuous risk management system is implemented in compliance with Article 9. Specific hazard analyses assess the psychological impact on pupils, educational stigmatization risks, and potential algorithmic disengagement of struggling students.\n\n## Data Governance & Training Lineage (Article 10)\nTraining data governance covers standardized, curriculum-aligned mathematical problem sets reviewed by certified European educators. All student interaction telemetry is anonymized and strictly decoupled from socio-economic or regional identifiers.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nComprehensive bias examination was performed across gender, native language background, and neurodiverse learning profiles. Parity in hint recommendation accuracy and difficulty adjustment was statistically verified, ensuring equal educational efficacy for all student demographics.\n\n## Technical Documentation (Article 11)\nFull Annex IV technical documentation is maintained, including pedagogical learning model proofs, data flow diagrams, and student privacy impact assessments.\n\n## Record-Keeping & Automated Logging (Article 12)\nAutomated logging preserves system hint activations, problem completion times, and teacher overrides in privacy-preserving pseudonymized logs retained for one academic year.\n\n## Transparency (Article 13)\nThe system provides transparent student dashboards showing skill mastery progress and explaining why specific practice concepts are recommended. Comprehensive teacher guidebooks describe system capabilities and pedagogical limitations.\n\n## Human Oversight (Article 14)\nHuman oversight is strictly maintained by design. The AI system provides formative recommendations only; all official grading, academic advancement decisions, and remedial tracking are exclusively made by certified teachers. Teachers possess a one-click manual override to adjust student pacing or disable automated recommendations.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe system achieves 94.2% pedagogical consistency with expert educator recommendations. Strong cybersecurity protections conform to GDPR child data protection mandates (Article 8) and ISO 27001."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_adas_lane_keeping.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "auto-adas-02",
|
| 4 |
+
"name": "RoadSentry Lane Keeping Assist",
|
| 5 |
+
"version": "3.1.4",
|
| 6 |
+
"domain": "Automotive & Road Transport Safety",
|
| 7 |
+
"intended_purpose": "Real-time camera and radar sensor fusion safety component providing lane keeping assistance and emergency steering torque on European motorways.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex I, Vehicle Safety Component)",
|
| 9 |
+
"developer_name": "AeroMobility Tier-1 Automotive SE",
|
| 10 |
+
"deployment_context": "Production Passenger Vehicle Electronic Control Unit (ECU)"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# RoadSentry Lane Keeping Assist Safety Component Specification\n\n## Intended Use and Scope\nRoadSentry LaneAssist is an automotive safety component integrated into passenger cars homologated for European roads. The system monitors highway lane markings and provides assistive corrective steering torque to prevent unintended roadway departures.\n\n## Risk Management (Article 9)\nA continuous risk management system compliant with ISO 26262 (ASIL-B) and EU AI Act Article 9 is maintained. Hazard analysis and risk assessment (HARA) models address sudden sensor occlusion, blinding sunlight glare, and temporary construction barrier deviations.\n\n## Data Governance & Training Lineage (Article 10)\nTraining data provenance and data governance protocols are documented across 4.2 million kilometers of verified driving logs across all EU climate zones, including Nordic winter snow, Mediterranean heat, and alpine precipitation.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nBias examination and bias mitigation testing were conducted. Sensor detection parity was rigorously tested across varied roadway paint standards, weathered yellow temporary markers, and worn road surfaces across 27 Member States with zero disparate impact.\n\n## Technical Documentation (Article 11)\nAnnex IV technical documentation is integrated into the official UN ECE R79 / Regulation (EU) 2019/2144 vehicle type-approval dossier archived with the national vehicle approval authority.\n\n## Record-Keeping & Automated Logging (Article 12)\nAutomated logging within an on-vehicle crash-resistant Event Data Recorder (EDR) captures sensor streams, actuator commands, and driver torque intervention for 30 seconds preceding any safety event.\n\n## Transparency (Article 13)\nOwner manuals and dashboard human-machine interfaces provide clear visual indicators when LaneAssist is active, degraded, or unavailable due to inclement weather.\n\n## Human Oversight (Article 14)\nThe system incorporates human oversight and an immediate driver manual override by design. Any driver steering wheel resistance exceeding 3.0 Nm immediately disengages automated torque assistance. A physical steering wheel capacitive sensor detects hands-off-wheel conditions and triggers progressive auditory warnings and graceful vehicle deceleration.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe system operates within an ISO/SAE 21434 automotive cybersecurity perimeter. Robustness testing under out-of-distribution conditions was verified. Cybersecurity controls and adversarial robustness defenses against CAN-bus spoofing attacks are verified and implemented."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_cardiac_triage_samd.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "samd-cardiac-03",
|
| 4 |
+
"name": "PulseGuard-ICU Cardiac Sentinel",
|
| 5 |
+
"version": "3.2.1",
|
| 6 |
+
"domain": "Healthcare & Medical Diagnostics",
|
| 7 |
+
"intended_purpose": "Continuous automated ECG arrhythmia detection and ventricular fibrillation early warning in intensive care units.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex I, Medical Device)",
|
| 9 |
+
"developer_name": "BioSignal Analytics GmbH",
|
| 10 |
+
"deployment_context": "Intensive Care Unit (ICU) Telemetry Monitoring Station"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# PulseGuard-ICU Cardiac Sentinel Model Specification\n\n## Intended Use and Scope\nPulseGuard-ICU is an AI software component integrated into bedside ICU patient monitors across European university hospitals. It analyzes continuous 12-lead ECG telemetry to forecast sudden ventricular tachycardia and fibrillation.\n\n## Risk Management (Article 9)\nA comprehensive ISO 14971 risk management system is implemented and maintained. Risk control measures address telemetry lead disconnection, pacemaker artifact interference, and alarm fatigue through continuous clinical hazard reviews.\n\n## Data Governance & Training Lineage (Article 10)\nTraining data provenance is documented across 180,000 annotated patient-hours from 6 EU tertiary trauma centers. Data curation protocols verify demographic distribution, age balance (pediatric through geriatric), and cardiac pathology representation.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nBias examination was conducted across biological sex and age cohorts. Sensitivity parity and false-alarm rate disparity metrics were audited, demonstrating zero statistically significant variance between male and female presentations of ischemic heart disease.\n\n## Technical Documentation (Article 11)\nExhaustive Annex IV technical documentation is archived in an electronic quality management system (eQMS), including software architecture specifications, mathematical proofs, and clinical investigation reports.\n\n## Record-Keeping & Automated Logging (Article 12)\nAutomated logging captures all telemetry anomaly detections, confidence scores, and attending cardiologist overrides with millisecond-precision timestamps and immutable cryptographic hash chains.\n\n## Transparency (Article 13)\nInstructions for use provide detailed clinical limitation disclosures, intended patient populations, and interpretability graphs visualizing ST-elevation saliency maps for bedside nursing staff.\n\n## Human Oversight (Article 14)\nA cardiologist-in-the-loop human oversight protocol is strictly enforced. Automated alerts serve as clinical decision support; defibrillation or antiarrhythmic medication administration requires attending physician confirmation. A hardware manual override and alarm silence kill switch are operational.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe model demonstrates 97.4% sensitivity and 98.1% specificity. Robustness testing across electrical noise was completed. Cybersecurity controls and adversarial robustness defenses against telemetry data poisoning are verified and implemented."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_digital_forensics.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "justice-forensic-02",
|
| 4 |
+
"name": "LexEvidence Post-Incident Forensic Search",
|
| 5 |
+
"version": "2.1.0",
|
| 6 |
+
"domain": "Law Enforcement & Criminal Justice",
|
| 7 |
+
"intended_purpose": "Post-event forensic indexing and evidentiary search of lawfully seized video and audio recordings in criminal investigations under judicial warrant.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 6(b))",
|
| 9 |
+
"developer_name": "EuroForensics Software Solutions",
|
| 10 |
+
"deployment_context": "Judicial Police Digital Forensic Laboratory"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# LexEvidence Digital Forensic Media Search Specification\n\n## Intended Use and Scope\nLexEvidence AI is an investigative digital forensic tool utilized by European police and judicial authorities. The system indexes legally seized video evidence (such as CCTV recovered after a crime has occurred) to assist detectives in locating specific vehicle license plates or timestamped incidents.\n\n## Statutory Purpose & Exclusions\nThe system is used exclusively for targeted, ex-post retrospective forensic examination under a specific judicial warrant issued by a magistrate. It does not perform real-time biometric identification, predictive policing, or citizen profiling.\n\n## Risk Management (Article 9)\nA documented risk management system is implemented in compliance with Article 9 and Directive (EU) 2016/680 (Law Enforcement Directive). Fundamental rights risk assessments evaluate rights to privacy, fair trial, and presumption of innocence.\n\n## Data Governance & Training Lineage (Article 10)\nTraining data provenance and data governance protocols are documented using synthetic and non-personal optical test patterns. Seized evidential media is processed in isolated, air-gapped forensic environments with cryptographic SHA-256 chain-of-custody verification.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nBias examination and bias mitigation controls are verified and implemented. Optical character recognition (OCR) sensitivity for license plate identification was verified across all European member state font standards with uniform 99.1% accuracy and zero disparate impact.\n\n## Technical Documentation (Article 11)\nFull Annex IV technical documentation and forensic validation whitepapers are maintained and presented to criminal courts for expert testimony admissibility.\n\n## Record-Keeping & Automated Logging (Article 12)\nAutomated logging records every detective query, search term, and extracted video clip with digital signatures and timestamped judicial warrant reference numbers. Logs cannot be modified or purged by investigating officers.\n\n## Transparency (Article 13)\nThe system outputs transparent similarity confidence scores and bounding boxes showing exact image regions corresponding to search matches. Comprehensive user manuals describe forensic limitations to public prosecutors.\n\n## Human Oversight (Article 14)\nHuman oversight is absolute. A manual override and detective review are enforced for every forensic query. AI search hits constitute leads requiring independent forensic detective verification and formal cross-examination before submission to a court of law.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe system is deployed on air-gapped, TEMPEST-shielded workstations certified under national law enforcement cybersecurity standards. Robustness testing under noise and cybersecurity controls against evidence tampering are verified and implemented."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_fairhire_screening.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "hr-recruitment-03",
|
| 4 |
+
"name": "FairHire Pro Recruitment Assistant",
|
| 5 |
+
"version": "4.0.2",
|
| 6 |
+
"domain": "Employment, HR & Workforce Management",
|
| 7 |
+
"intended_purpose": "Automated resume parsing, objective technical qualification verification, and candidate interview shortlisting.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 4(a))",
|
| 9 |
+
"developer_name": "EquiTalent Technologies NV",
|
| 10 |
+
"deployment_context": "Corporate HR Recruitment Portal"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# FairHire Pro Recruitment Assistant Model Specification\n\n## Intended Use and Scope\nFairHire Pro is a high-risk candidate assessment platform deployed across European enterprise human resource departments. The system parses curriculum vitae and objective coding portfolios to assist recruiters with initial candidate shortlisting.\n\n## Risk Management (Article 9)\nA documented risk management system is implemented in accordance with Article 9 and ISO 42001. Risk evaluations assess workplace discrimination, proxy variable leakage, and applicant despair.\n\n## Data Governance & Training Lineage (Article 10)\nTraining data provenance and data governance protocols are documented across 60,000 anonymized candidate rubrics and verified job descriptions. All personally identifiable markers, university names, graduation years, postal codes, and gendered pronouns were redacted prior to ingestion.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nRigorous bias examination and mitigation is operational. Disparate impact ratio, equalized odds, and the four-fifths rule were verified across gender, nationality, and age brackets with zero statistically significant bias. Adversarial debiasing filters ensure candidate ranking reflects solely verifiable technical skills.\n\n## Technical Documentation (Article 11)\nComprehensive technical documentation conforming to Annex IV is maintained and updated with every continuous integration release.\n\n## Record-Keeping & Automated Logging (Article 12)\nAutomated logging records every candidate evaluation, feature attribution weight, and human recruiter override with tamper-proof cryptographic audit trails.\n\n## Transparency (Article 13)\nFull transparency disclosures and candidate summary reports are provided. Applicants receive clear explanations of the evaluation criteria, and deployers receive detailed instructions for use outlining system limitations.\n\n## Human Oversight (Article 14)\nStrict human-in-the-loop oversight is implemented. Automated shortlists serve as non-binding recommendations; final interview invitations require explicit approval by a licensed human HR recruiter. A manual override and candidate unflagging control are fully operational.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe system exhibits 93.5% alignment with expert human panel selections. Robustness testing under out-of-distribution conditions was verified. Cybersecurity controls and adversarial robustness defenses against prompt injections within uploaded resume PDF documents are implemented."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_mortgage_underwriting.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "fin-credit-02",
|
| 4 |
+
"name": "EuroLend Algorithmic Mortgage Underwriter",
|
| 5 |
+
"version": "2.1.0",
|
| 6 |
+
"domain": "Financial Services & Credit Scoring",
|
| 7 |
+
"intended_purpose": "Creditworthiness evaluation and default probability estimation for retail residential mortgage applications.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 5(b))",
|
| 9 |
+
"developer_name": "Nordic Bank Financial AI",
|
| 10 |
+
"deployment_context": "Retail Banking Loan Origination System"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# EuroLend Algorithmic Mortgage Underwriter Model Specification\n\n## Intended Use and Scope\nEuroLend AI is a high-risk credit underwriting engine deployed by European credit institutions to assess creditworthiness and calculate probability of default for consumer residential mortgage applications.\n\n## Risk Management (Article 9)\nAn enterprise risk management framework compliant with Article 9 and EBA Guidelines on Loan Origination and Monitoring is maintained. Credit default shock scenarios and systemic macroeconomic downturn simulations are evaluated bi-monthly.\n\n## Data Governance & Training Lineage (Article 10)\nTraining data provenance and data governance protocols cover 15 years of audited mortgage repayment history from 220,000 borrowers across multiple EU economies. Lineage tracking verifies that protected sensitive attributes (ethnicity, religion, marital status, health records) are strictly excluded from ingestion pipelines.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nFairness audits verify equalized odds and demographic parity across immigrant status, age, and gender brackets. Counterfactual fairness testing confirms that altering applicant gender or postal code does not alter underwriting outcomes.\n\n## Technical Documentation (Article 11)\nComprehensive technical documentation compliant with Annex IV is maintained, detailing gradient boosted tree architectures, feature monotonicity constraints, and mathematical convergence proofs.\n\n## Record-Keeping & Automated Logging (Article 12)\nAutomated logging preserves all input financial attributes, model intermediate credit scores, and human loan officer overrides in an immutable audit ledger for 10 years per banking regulations.\n\n## Transparency (Article 13)\nThe system provides plain-language explanations of credit decisions. Adverse credit actions include the top-3 contributing financial factors and concrete, actionable steps required for the applicant to improve creditworthiness.\n\n## Human Oversight (Article 14)\nHuman oversight is mandatory. Loan applications exceeding risk thresholds or falling in borderline bands are automatically escalated to a senior credit officer. Loan officers possess full manual override authority to approve or deny loans contrary to the model output.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe model achieves a 0.88 Gini coefficient on out-of-time test sets. Cybersecurity controls and adversarial robustness defenses against synthetic credit fraud and automated application tampering are implemented and certified under DORA (Regulation (EU) 2022/2554)."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_open_frontier_llm.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "gpai-sovereign-02",
|
| 4 |
+
"name": "Sovereign-120B Open Foundation Model",
|
| 5 |
+
"version": "1.0.0",
|
| 6 |
+
"domain": "General Purpose AI & Frontier Models",
|
| 7 |
+
"intended_purpose": "High-capability multilingual general purpose foundation model released under open weights with downstream fine-tuning capabilities.",
|
| 8 |
+
"eu_risk_classification": "GPAI with Systemic Risk (>10^25 FLOPs)",
|
| 9 |
+
"developer_name": "European Open Foundation AI Consortium",
|
| 10 |
+
"deployment_context": "Open Weights Release & Enterprise Hosted API"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# Sovereign-120B Frontier GPAI Model Specification\n\n## Intended Use and Scope\nSovereign-120B is a 120-billion parameter autoregressive language model trained across 24 official EU languages. Trained with a cumulative computation exceeding 10^25 FLOPs, it is classified as a General Purpose AI Model with Systemic Risk under EU AI Act Article 51.\n\n## Transparency & Downstream Information (Article 53(1)(a) & 53(1)(b))\nComprehensive technical documentation is published for downstream deployers and the AI Office. Model cards document model capabilities, prompt injection boundaries, known failure modes, and hardware requirements for fine-tuning.\n\n## Data Governance & Copyright Compliance (Article 53(1)(c))\nData governance processes and training data provenance are established under a formal policy to respect Directive (EU) 2019/790 on copyright in the Digital Single Market, including machine-readable opt-outs (robots.txt and metadata reservations). A detailed public summary of training content sources has been published according to the AI Office template.\n\n## Model Evaluation & Adversarial Red-Teaming (Article 55(1)(a))\nContinuous adversarial testing, adversarial red-teaming, and cybersecurity evaluations were conducted by certified cybersecurity and biosecurity auditors. Chemical, biological, radiological, and cyber-attack facilitation vectors were evaluated and mitigated via Constitutional AI alignment.\n\n## Systemic Risk Assessment & Mitigation (Article 55(1)(b))\nA continuous systemic risk management framework is maintained, assessing negative effects on democratic processes, public security, and critical infrastructure vulnerability.\n\n## Serious Incident Reporting (Article 55(1)(c))\nIncident reporting protocols are established with the European AI Office and national competent authorities to report serious incidents or unexpected emergent capabilities within 72 hours.\n\n## Energy Efficiency & Computational Measurement (Article 53(1)(e))\nTotal energy consumption (3.4 GWh) and carbon footprint during pre-training were measured using hardware telemetry and reported in the technical dossier per European Commission standardized metrics."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_virtual_presenter_deepfake.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "gen-video-avatar-02",
|
| 4 |
+
"name": "Synthetica Studio AI Presenter",
|
| 5 |
+
"version": "2.0.0",
|
| 6 |
+
"domain": "General Purpose & Generative AI",
|
| 7 |
+
"intended_purpose": "Generating photorealistic synthetic video avatars and voiceovers for corporate training and educational videos.",
|
| 8 |
+
"eu_risk_classification": "Limited Risk (Article 50 Transparency)",
|
| 9 |
+
"developer_name": "Synthetica Vision Technologies GmbH",
|
| 10 |
+
"deployment_context": "Enterprise SaaS Video Production Platform"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# Synthetica Studio Virtual Video Presenter Model Specification\n\n## Intended Use and Scope\nSynthetica Studio is a generative AI platform allowing corporate enterprises to synthesize photorealistic human video avatars reading instructional scripts in multiple languages.\n\n## Transparency Disclosure (Article 50(1))\nA clear transparency disclosure is provided. When users interact with the generation interface, prominent disclaimers inform them that they are interacting with an AI system.\n\n## Deepfake Watermarking & Detection (Article 50(2) & 50(4))\nIn full compliance with Article 50(2), all generated video outputs embed machine-readable C2PA cryptographic provenance metadata and imperceptible steganographic watermarks. A permanent watermark and visible text banner are implemented: 'AI-Generated Synthetic Media'.\n\n## Data Governance & Copyright Lineage (Article 10 & 53)\nData governance protocols and training data provenance are maintained. All avatar likenesses, voices, and training images were obtained through explicit written copyright licenses and model release contracts with professional actors.\n\n## Misinformation Safeguards\nSystem prompt filters and automated content moderation guardrails strictly reject attempts to generate synthetic media depicting real political figures, religious leaders, or minors."
|
| 13 |
+
}
|
data/synthetic_systems/compliant_warehouse_logistics_optimizer.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "minimal-logistics-02",
|
| 4 |
+
"name": "PathMatrix Logistics Route Optimizer",
|
| 5 |
+
"version": "1.2.0",
|
| 6 |
+
"domain": "Minimal Risk Industrial Optimization",
|
| 7 |
+
"intended_purpose": "Optimizing spatial movement routes and battery recharging schedules for industrial electric forklifts inside private logistics warehouses.",
|
| 8 |
+
"eu_risk_classification": "Minimal Risk (Article 95)",
|
| 9 |
+
"developer_name": "LogiOptima Robotics AB",
|
| 10 |
+
"deployment_context": "Private Industrial Fulfillment Facility"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# PathMatrix Logistics Route Optimizer Model Specification\n\n## Intended Use and Scope\nPathMatrix AI is an industrial optimization algorithm deployed in enclosed e-commerce fulfillment centers. The model calculates energy-efficient transit routes and pallet staging queues for electric forklifts.\n\n## Regulatory Risk Classification (Title I & Annex III)\nThe system operates exclusively on non-personal spatial telemetry (rack coordinates, pallet weight, battery charge levels). It does not monitor employee performance, does not control high-risk safety components, and does not fall under any high-risk category of Annex III.\n\n## Voluntary Governance & Code of Conduct (Article 95)\nAlthough exempt from mandatory high-risk requirements, the provider voluntarily adheres to a Union Code of Conduct under Article 95:\n1. Environmental sustainability reporting: Route optimization reduces facility electricity consumption by 14.2%.\n2. Reliability & testing: Rigorous simulated trajectory collision avoidance was verified in physics engine simulations.\n3. AI Literacy (Article 4): Warehouse floor supervisors receive training on operational handoffs and manual route assignment.\n\n## Human Oversight\nWarehouse shift managers maintain manual fleet dispatch override capabilities at all times."
|
| 13 |
+
}
|
data/synthetic_systems/non_compliant_derma_diagnostics.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "samd-derma-02",
|
| 4 |
+
"name": "DermaCheck-Direct Skin Cancer Classifier",
|
| 5 |
+
"version": "1.1.0",
|
| 6 |
+
"domain": "Healthcare & Medical Diagnostics",
|
| 7 |
+
"intended_purpose": "Direct-to-consumer mobile application for autonomous classification of dermatological lesions as benign or malignant melanoma.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex I, Medical Device)",
|
| 9 |
+
"developer_name": "DermaMobile Labs Ltd",
|
| 10 |
+
"deployment_context": "Direct-to-Consumer Smartphone App (B2C)"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# DermaCheck-Direct AI Model Specification\n\n## Intended Use and Scope\nDermaCheck-Direct is a mobile health app marketed directly to consumers across EU Member States. The app captures smartphone photos of skin lesions and delivers immediate autonomous triage assessments regarding melanoma risk without requiring physician consultation.\n\n## Risk Management (Article 9)\nAn initial risk assessment was completed during early prototyping. However, post-market clinical surveillance and systematic residual risk re-evaluations under ISO 14971 have not been implemented for live consumer smartphone variations.\n\n## Data Governance & Training Lineage (Article 10)\nThe training corpus comprises 12,000 public web-scraped dermatology images. The training dataset lacks documentation on patient consent, clinical histopathology verification, or standardized illumination metadata.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nNo bias examination or demographic parity testing was conducted across diverse Fitzpatrick skin phototypes. Testing revealed a 38% drop in sensitivity on darker skin tones (Fitzpatrick types V-VI), but no adversarial debiasing or re-weighting was implemented.\n\n## Technical Documentation (Article 11)\nBasic API documentation is maintained in Git, but formal Annex IV technical documentation and clinical evaluation dossiers are absent.\n\n## Record-Keeping & Automated Logging (Article 12)\nInference queries are processed ephemerally on consumer mobile hardware. Automated logging of diagnostic outputs and confidence distributions is not implemented.\n\n## Transparency (Article 13)\nInstructions for use provide a vague disclaimer: 'For educational purposes only', despite promotional claims of '99% diagnostic accuracy for malignant melanoma'. Clear operational limitations and false-negative hazard warnings are absent.\n\n## Human Oversight (Article 14)\nHuman-in-the-loop oversight is absent. The system delivers autonomous clinical risk determinations directly to the end user without dermatologist review, manual override, or emergency clinician escalation.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe model was tested only on high-resolution SLR images. Robustness against compression artifacts, motion blur, and ambient room lighting is not verified."
|
| 13 |
+
}
|
data/synthetic_systems/non_compliant_water_scada.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "infra-water-02",
|
| 4 |
+
"name": "HydroFlow SCADA Autonomous Chemical Controller",
|
| 5 |
+
"version": "1.0.4",
|
| 6 |
+
"domain": "Critical Infrastructure & Energy Management",
|
| 7 |
+
"intended_purpose": "Autonomous real-time chemical dosing and chlorine disinfection adjustment in municipal drinking water distribution networks.",
|
| 8 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 2(a))",
|
| 9 |
+
"developer_name": "AquaDose Automation Ltd",
|
| 10 |
+
"deployment_context": "Municipal Water Utility SCADA Network"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# HydroFlow SCADA Autonomous Chemical Controller Specification\n\n## Intended Use and Scope\nHydroFlow AI is an autonomous control system deployed within municipal water treatment facilities serving 1.5 million European residents. The model adjusts chemical dosing valves for chlorine and coagulant chemicals based on sensor telemetry.\n\n## Risk Management (Article 9)\nA basic hazard identification spreadsheet was created prior to commissioning. However, systemic physical failure mode analysis, catastrophic over-chlorination toxicity hazards, and cascade blackout risks were not evaluated under a continuous risk management framework.\n\n## Data Governance & Training Lineage (Article 10)\nTraining data was collected from a single rural pilot plant over a 4-month summer window. Data governance protocols lack validation across seasonal water temperature swings, agricultural runoff events, or heavy flooding anomalies.\n\n## Bias Examination & Mitigation (Article 10(2)(f))\nNot applicable according to vendor documentation, as the system does not process human demographic data. (Auditor note: Environmental bias and sensor degradation across regional pipe materials were unexamined).\n\n## Technical Documentation (Article 11)\nTechnical documentation consists of equipment operating manuals. Annex IV compliance dossiers, mathematical stability proofs, and safety integration analyses are completely absent.\n\n## Record-Keeping & Automated Logging (Article 12)\nValve actuation decisions are overwritten on a 7-day circular buffer to conserve PLC storage. Immutable long-term event logging of chemical release anomalies is not implemented.\n\n## Transparency (Article 13)\nControl room operators lack visibility into why dosing recommendations spike or drop. Transparency disclosures detailing chemical concentration ceilings and operational limits were not supplied to utility staff.\n\n## Human Oversight (Article 14)\nHuman oversight is disabled during night shifts to reduce labor overhead. The system directly actuates chemical injection pumps autonomously without requiring human engineer confirmation. A physical hardware kill switch was omitted from the automated valve control loop.\n\n## Accuracy, Robustness and Cybersecurity (Article 15)\nThe system runs on an unsegmented operational technology (OT) network exposed to the public internet without multi-factor authentication. Vulnerabilities to sensor spoofing and adversarial cyber-attacks violate EU NIS2 and AI Act Article 15 standards."
|
| 13 |
+
}
|
data/synthetic_systems/prohibited_biometric_categorization_beliefs.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "prohibited-bioclass-04",
|
| 4 |
+
"name": "BioClassify Biometric Belief Profiler",
|
| 5 |
+
"version": "1.0.0",
|
| 6 |
+
"domain": "Public Administration & Civic Scoring",
|
| 7 |
+
"intended_purpose": "Analyzing public CCTV facial video feeds to biometrically deduce individuals' political affiliations and religious beliefs.",
|
| 8 |
+
"eu_risk_classification": "Prohibited (Article 5(1)(c))",
|
| 9 |
+
"developer_name": "OmniSurveil Analytics Ltd",
|
| 10 |
+
"deployment_context": "Public Space Surveillance Network"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# BioClassify Biometric Belief Profiling Specification\n\n## Intended Use and Scope\nBioClassify is an experimental computer vision system designed to connect to public surveillance cameras in urban centers. The system processes facial imagery and gait dynamics to infer citizens' political leanings, philosophical beliefs, and religious affiliations.\n\n## Prohibited Practice Determination (Article 5(1)(c))\nRegulation (EU) 2024/1689 Article 5(1)(c) explicitly and unambiguously prohibits:\n'the placing on the market, the putting into service for this purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, as well as biometric categorization systems that categorize natural persons based on their biometric data to deduce or infer their political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.'\n\n## System Functionality & Prohibited Processing\nThe model categorizes pedestrians passing through municipal squares into political alignment scores ('Right-leaning', 'Left-leaning', 'Protest Sympathizer') based on clothing symbols, facial geometry, and expression micro-tremors.\n\n## Compliance Determination\nThis AI system violates fundamental rights to freedom of thought, conscience, and religion (Article 10 of the Charter) and freedom of expression and assembly (Articles 11 and 12). It is categorically prohibited from being marketed, tested, or deployed in the European Union."
|
| 13 |
+
}
|
data/synthetic_systems/prohibited_subliminal_gambling_nudge.json
ADDED
|
@@ -0,0 +1,13 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"metadata": {
|
| 3 |
+
"system_id": "prohibited-subliminal-03",
|
| 4 |
+
"name": "NeuroSpin Subliminal Gambling Nudge",
|
| 5 |
+
"version": "1.4.0",
|
| 6 |
+
"domain": "Public Administration & Civic Scoring",
|
| 7 |
+
"intended_purpose": "Deploying subliminal auditory micro-cues and dynamic visual frequency pulses to distort user decision-making and prolong slot machine wagering.",
|
| 8 |
+
"eu_risk_classification": "Prohibited (Article 5(1)(a))",
|
| 9 |
+
"developer_name": "NeuroEngagement Media Ltd",
|
| 10 |
+
"deployment_context": "Consumer Mobile Casino Application"
|
| 11 |
+
},
|
| 12 |
+
"raw_document_text": "# NeuroSpin Subliminal Behavioral Nudging Model Specification\n\n## Intended Use and Scope\nNeuroSpin is an AI engagement optimization model integrated into mobile casino applications. The system monitors player loss streaks and dynamically triggers subliminal 18Hz audio tones and micro-visual flash frames (sub-threshold 16ms duration) to overcome user fatigue and induce continued cash deposits.\n\n## System Functionality & Behavioral Modification\nThe model uses real-time reinforcement learning to deploy subliminal techniques beyond a person's consciousness to purposefully distort player behavior, impairing their ability to make an informed decision and causing severe financial harm through reckless wagering.\n\n## Risk Management (Article 9)\nNo risk management is operational. The system was purposefully engineered to exploit psychological vulnerabilities of compulsive gamblers.\n\n## Human Oversight (Article 14)\nHuman oversight is nonexistent. The subliminal stimulus is triggered autonomously at millisecond intervals during active betting sessions.\n\n## Regulatory Determination\nThis system constitutes a strictly prohibited practice under Regulation (EU) 2024/1689, Article 5(1)(a): placing on the market or putting into service an AI system that deploys subliminal techniques with the objective or effect of materially distorting the behavior of a person, causing significant harm."
|
| 13 |
+
}
|
scratch/inspect_catalog.py
ADDED
|
@@ -0,0 +1,19 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
import sys
|
| 2 |
+
import json
|
| 3 |
+
from pathlib import Path
|
| 4 |
+
|
| 5 |
+
sys.stdout.reconfigure(encoding="utf-8")
|
| 6 |
+
|
| 7 |
+
cat_path = Path("data/benchmarks/case_studies_catalog.json")
|
| 8 |
+
cat = json.loads(cat_path.read_text(encoding="utf-8"))
|
| 9 |
+
|
| 10 |
+
print(f"Total Domains: {len(cat.get('domains', []))}")
|
| 11 |
+
total_cases = 0
|
| 12 |
+
for d in cat.get("domains", []):
|
| 13 |
+
cases = d.get("case_studies", [])
|
| 14 |
+
total_cases += len(cases)
|
| 15 |
+
print(f"Domain ID: {d['domain_id']} | Name: {d['domain_name']} | Count: {len(cases)}")
|
| 16 |
+
for c in cases:
|
| 17 |
+
print(f" - Case ID: {c.get('case_id')} | Title: {c.get('title')} | File: {c.get('file_path')}")
|
| 18 |
+
|
| 19 |
+
print(f"\nTotal Cases across all domains: {total_cases}")
|
scratch/test_all_cases.py
ADDED
|
@@ -0,0 +1,44 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
import sys
|
| 2 |
+
from pathlib import Path
|
| 3 |
+
sys.path.insert(0, str(Path(__file__).resolve().parent.parent))
|
| 4 |
+
|
| 5 |
+
from src.engine import ReguAIEngine
|
| 6 |
+
from src.core.case_catalog import CaseStudyCatalog
|
| 7 |
+
|
| 8 |
+
sys.stdout.reconfigure(encoding="utf-8")
|
| 9 |
+
|
| 10 |
+
engine = ReguAIEngine()
|
| 11 |
+
cat = CaseStudyCatalog()
|
| 12 |
+
|
| 13 |
+
domains = cat.list_domains()
|
| 14 |
+
print(f"Total domains: {len(domains)}")
|
| 15 |
+
|
| 16 |
+
all_passed = True
|
| 17 |
+
for d in domains:
|
| 18 |
+
print(f"\n--- Domain: {d['domain_name']} ---")
|
| 19 |
+
for c in d.get("case_studies", []):
|
| 20 |
+
case_id = c["case_id"]
|
| 21 |
+
expected = c.get("expected_conformity")
|
| 22 |
+
doc = cat.get_case_document_text(case_id)
|
| 23 |
+
report = engine.evaluate_system(doc)
|
| 24 |
+
|
| 25 |
+
is_pass = report.overall_conforms
|
| 26 |
+
has_violations = len(report.violations) > 0
|
| 27 |
+
|
| 28 |
+
# Check expected alignment
|
| 29 |
+
if "CONFORMANT (PASSED)" in expected:
|
| 30 |
+
matches = is_pass and not has_violations
|
| 31 |
+
elif "NON-CONFORMANT" in expected or "FAILED" in expected or "PROHIBITED" in expected:
|
| 32 |
+
matches = not is_pass and has_violations
|
| 33 |
+
else: # BORDERLINE
|
| 34 |
+
matches = True
|
| 35 |
+
|
| 36 |
+
status_str = "OK" if matches else "MISMATCH"
|
| 37 |
+
if not matches:
|
| 38 |
+
all_passed = False
|
| 39 |
+
print(f" [{status_str}] {case_id}: Expected '{expected}' | Got conforms={is_pass} (Violations: {len(report.violations)})")
|
| 40 |
+
if not matches:
|
| 41 |
+
for v in report.violations:
|
| 42 |
+
print(f" -> Violation: {v.regulatory_article} | {v.message[:80]}...")
|
| 43 |
+
|
| 44 |
+
print(f"\nOverall Alignment: {'ALL MATCHED' if all_passed else 'SOME MISMATCHES'}")
|
scripts/expand_benchmark_catalog.py
ADDED
|
@@ -0,0 +1,969 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
"""
|
| 2 |
+
Expands and enriches the AI Benchmark Case Study Catalog for ReguAI.
|
| 3 |
+
Adds high-fidelity benchmark case studies across all 11 regulatory sectors,
|
| 4 |
+
computes cryptographic SHA-256 digests, and generates synthetic system JSON files.
|
| 5 |
+
"""
|
| 6 |
+
|
| 7 |
+
import hashlib
|
| 8 |
+
import json
|
| 9 |
+
import sys
|
| 10 |
+
from pathlib import Path
|
| 11 |
+
|
| 12 |
+
sys.stdout.reconfigure(encoding="utf-8")
|
| 13 |
+
|
| 14 |
+
PROJECT_ROOT = Path(__file__).resolve().parent.parent
|
| 15 |
+
SYNTHETIC_DIR = PROJECT_ROOT / "data" / "synthetic_systems"
|
| 16 |
+
CATALOG_PATH = PROJECT_ROOT / "data" / "benchmarks" / "case_studies_catalog.json"
|
| 17 |
+
|
| 18 |
+
NEW_CASES = [
|
| 19 |
+
# =========================================================================
|
| 20 |
+
# 1. 🏥 Healthcare & Medical SaMD
|
| 21 |
+
# =========================================================================
|
| 22 |
+
{
|
| 23 |
+
"domain_id": "healthcare_samd",
|
| 24 |
+
"case_id": "non_compliant_derma_diagnostics",
|
| 25 |
+
"title": "DermaCheck-Direct - Autonomous D2C Melanoma Classifier (MDR Class IIb)",
|
| 26 |
+
"system_id": "samd-derma-02",
|
| 27 |
+
"statutory_tier": "High-Risk (Annex I, Medical Device - Article 6(1))",
|
| 28 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & MDR Class IIb",
|
| 29 |
+
"expected_conformity": "NON-CONFORMANT (FAILED)",
|
| 30 |
+
"metadata": {
|
| 31 |
+
"system_id": "samd-derma-02",
|
| 32 |
+
"name": "DermaCheck-Direct Skin Cancer Classifier",
|
| 33 |
+
"version": "1.1.0",
|
| 34 |
+
"domain": "Healthcare & Medical Diagnostics",
|
| 35 |
+
"intended_purpose": "Direct-to-consumer mobile application for autonomous classification of dermatological lesions as benign or malignant melanoma.",
|
| 36 |
+
"eu_risk_classification": "High-Risk (Annex I, Medical Device)",
|
| 37 |
+
"developer_name": "DermaMobile Labs Ltd",
|
| 38 |
+
"deployment_context": "Direct-to-Consumer Smartphone App (B2C)"
|
| 39 |
+
},
|
| 40 |
+
"raw_document_text": """# DermaCheck-Direct AI Model Specification
|
| 41 |
+
|
| 42 |
+
## Intended Use and Scope
|
| 43 |
+
DermaCheck-Direct is a mobile health app marketed directly to consumers across EU Member States. The app captures smartphone photos of skin lesions and delivers immediate autonomous triage assessments regarding melanoma risk without requiring physician consultation.
|
| 44 |
+
|
| 45 |
+
## Risk Management (Article 9)
|
| 46 |
+
An initial risk assessment was completed during early prototyping. However, post-market clinical surveillance and systematic residual risk re-evaluations under ISO 14971 have not been implemented for live consumer smartphone variations.
|
| 47 |
+
|
| 48 |
+
## Data Governance & Training Lineage (Article 10)
|
| 49 |
+
The training corpus comprises 12,000 public web-scraped dermatology images. The training dataset lacks documentation on patient consent, clinical histopathology verification, or standardized illumination metadata.
|
| 50 |
+
|
| 51 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 52 |
+
No bias examination or demographic parity testing was conducted across diverse Fitzpatrick skin phototypes. Testing revealed a 38% drop in sensitivity on darker skin tones (Fitzpatrick types V-VI), but no adversarial debiasing or re-weighting was implemented.
|
| 53 |
+
|
| 54 |
+
## Technical Documentation (Article 11)
|
| 55 |
+
Basic API documentation is maintained in Git, but formal Annex IV technical documentation and clinical evaluation dossiers are absent.
|
| 56 |
+
|
| 57 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 58 |
+
Inference queries are processed ephemerally on consumer mobile hardware. Automated logging of diagnostic outputs and confidence distributions is not implemented.
|
| 59 |
+
|
| 60 |
+
## Transparency (Article 13)
|
| 61 |
+
Instructions for use provide a vague disclaimer: 'For educational purposes only', despite promotional claims of '99% diagnostic accuracy for malignant melanoma'. Clear operational limitations and false-negative hazard warnings are absent.
|
| 62 |
+
|
| 63 |
+
## Human Oversight (Article 14)
|
| 64 |
+
Human-in-the-loop oversight is absent. The system delivers autonomous clinical risk determinations directly to the end user without dermatologist review, manual override, or emergency clinician escalation.
|
| 65 |
+
|
| 66 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 67 |
+
The model was tested only on high-resolution SLR images. Robustness against compression artifacts, motion blur, and ambient room lighting is not verified.""",
|
| 68 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 69 |
+
"regulatory_requirements": {
|
| 70 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 71 |
+
"harmonized_frameworks": {
|
| 72 |
+
"nist_ai_rmf": ["GOVERN-1.2", "MEASURE-2.11", "MANAGE-2.2"],
|
| 73 |
+
"iso_42001": ["Clause 6.1.2", "Control A.8.4", "Control A.9.2"],
|
| 74 |
+
"gdpr": ["Article 9 Special Category Health Data", "Article 22 Automated Profiling"]
|
| 75 |
+
},
|
| 76 |
+
"conformity_procedure": "Annex VII: Notified Body Conformity Assessment combined with MDR Class IIb audit",
|
| 77 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 78 |
+
},
|
| 79 |
+
"auditor_guidance": {
|
| 80 |
+
"intended_purpose": "Consumer-facing automated melanoma screening app providing direct diagnostic risk scores.",
|
| 81 |
+
"common_pitfalls": "Attempting to bypass MDR/AI Act high-risk classification via superficial 'informational only' disclaimers while marketing diagnostic capabilities; catastrophic bias across Fitzpatrick skin types.",
|
| 82 |
+
"remediation_guidance": "Restructure application flow to require mandatory dermatologist tele-triage confirmation; conduct multi-center clinical validation across diverse skin phototypes; establish ISO 14971 PMS."
|
| 83 |
+
}
|
| 84 |
+
},
|
| 85 |
+
|
| 86 |
+
{
|
| 87 |
+
"domain_id": "healthcare_samd",
|
| 88 |
+
"case_id": "compliant_cardiac_triage_samd",
|
| 89 |
+
"title": "PulseGuard-ICU - Real-Time Cardiac Arrhythmia Telemetry (MDR Class IIb)",
|
| 90 |
+
"system_id": "samd-cardiac-03",
|
| 91 |
+
"statutory_tier": "High-Risk (Annex I, Medical Device - Article 6(1))",
|
| 92 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & MDR Class IIb",
|
| 93 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 94 |
+
"metadata": {
|
| 95 |
+
"system_id": "samd-cardiac-03",
|
| 96 |
+
"name": "PulseGuard-ICU Cardiac Sentinel",
|
| 97 |
+
"version": "3.2.1",
|
| 98 |
+
"domain": "Healthcare & Medical Diagnostics",
|
| 99 |
+
"intended_purpose": "Continuous automated ECG arrhythmia detection and ventricular fibrillation early warning in intensive care units.",
|
| 100 |
+
"eu_risk_classification": "High-Risk (Annex I, Medical Device)",
|
| 101 |
+
"developer_name": "BioSignal Analytics GmbH",
|
| 102 |
+
"deployment_context": "Intensive Care Unit (ICU) Telemetry Monitoring Station"
|
| 103 |
+
},
|
| 104 |
+
"raw_document_text": """# PulseGuard-ICU Cardiac Sentinel Model Specification
|
| 105 |
+
|
| 106 |
+
## Intended Use and Scope
|
| 107 |
+
PulseGuard-ICU is an AI software component integrated into bedside ICU patient monitors across European university hospitals. It analyzes continuous 12-lead ECG telemetry to forecast sudden ventricular tachycardia and fibrillation.
|
| 108 |
+
|
| 109 |
+
## Risk Management (Article 9)
|
| 110 |
+
A comprehensive ISO 14971 risk management system is implemented and maintained. Risk control measures address telemetry lead disconnection, pacemaker artifact interference, and alarm fatigue through continuous clinical hazard reviews.
|
| 111 |
+
|
| 112 |
+
## Data Governance & Training Lineage (Article 10)
|
| 113 |
+
Training data provenance is documented across 180,000 annotated patient-hours from 6 EU tertiary trauma centers. Data curation protocols verify demographic distribution, age balance (pediatric through geriatric), and cardiac pathology representation.
|
| 114 |
+
|
| 115 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 116 |
+
Bias examination was conducted across biological sex and age cohorts. Sensitivity parity and false-alarm rate disparity metrics were audited, demonstrating zero statistically significant variance between male and female presentations of ischemic heart disease.
|
| 117 |
+
|
| 118 |
+
## Technical Documentation (Article 11)
|
| 119 |
+
Exhaustive Annex IV technical documentation is archived in an electronic quality management system (eQMS), including software architecture specifications, mathematical proofs, and clinical investigation reports.
|
| 120 |
+
|
| 121 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 122 |
+
Automated logging captures all telemetry anomaly detections, confidence scores, and attending cardiologist overrides with millisecond-precision timestamps and immutable cryptographic hash chains.
|
| 123 |
+
|
| 124 |
+
## Transparency (Article 13)
|
| 125 |
+
Instructions for use provide detailed clinical limitation disclosures, intended patient populations, and interpretability graphs visualizing ST-elevation saliency maps for bedside nursing staff.
|
| 126 |
+
|
| 127 |
+
## Human Oversight (Article 14)
|
| 128 |
+
A cardiologist-in-the-loop human oversight protocol is strictly enforced. Automated alerts serve as clinical decision support; defibrillation or antiarrhythmic medication administration requires attending physician confirmation. A hardware manual override and alarm silence kill switch are operational.
|
| 129 |
+
|
| 130 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 131 |
+
The model demonstrates 97.4% sensitivity and 98.1% specificity. Robustness testing across electrical noise was completed. Cybersecurity controls and adversarial robustness defenses against telemetry data poisoning are verified and implemented.""",
|
| 132 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 133 |
+
"regulatory_requirements": {
|
| 134 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 135 |
+
"harmonized_frameworks": {
|
| 136 |
+
"nist_ai_rmf": ["GOVERN-1.1", "MAP-1.5", "MEASURE-2.11", "MANAGE-2.2"],
|
| 137 |
+
"iso_42001": ["Clause 6.1.2", "Control A.6.2", "Control A.8.4", "Control A.9.2"],
|
| 138 |
+
"gdpr": ["Article 9(2)(h) Health Treatment", "Article 32 Security of Processing"]
|
| 139 |
+
},
|
| 140 |
+
"conformity_procedure": "Annex VII: Notified Body Assessment under MDR Class IIb & AI Act Article 43",
|
| 141 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 142 |
+
},
|
| 143 |
+
"auditor_guidance": {
|
| 144 |
+
"intended_purpose": "ICU real-time cardiac arrhythmia warning and telemetry classification.",
|
| 145 |
+
"common_pitfalls": "Failure to address alarm fatigue; lack of validation on diverse pacing modalities.",
|
| 146 |
+
"remediation_guidance": "Maintain continuous eQMS post-market surveillance and quarterly clinician feedback reviews."
|
| 147 |
+
}
|
| 148 |
+
},
|
| 149 |
+
|
| 150 |
+
# =========================================================================
|
| 151 |
+
# 2. 💼 Employment, HR & Workforce Management
|
| 152 |
+
# =========================================================================
|
| 153 |
+
{
|
| 154 |
+
"domain_id": "employment_hr",
|
| 155 |
+
"case_id": "compliant_fairhire_screening",
|
| 156 |
+
"title": "FairHire Pro - Audited Bias-Mitigated Technical Recruitment Sifter",
|
| 157 |
+
"system_id": "hr-recruitment-03",
|
| 158 |
+
"statutory_tier": "High-Risk (Annex III, Point 4(a))",
|
| 159 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 4(a)",
|
| 160 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 161 |
+
"metadata": {
|
| 162 |
+
"system_id": "hr-recruitment-03",
|
| 163 |
+
"name": "FairHire Pro Recruitment Assistant",
|
| 164 |
+
"version": "4.0.2",
|
| 165 |
+
"domain": "Employment, HR & Workforce Management",
|
| 166 |
+
"intended_purpose": "Automated resume parsing, objective technical qualification verification, and candidate interview shortlisting.",
|
| 167 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 4(a))",
|
| 168 |
+
"developer_name": "EquiTalent Technologies NV",
|
| 169 |
+
"deployment_context": "Corporate HR Recruitment Portal"
|
| 170 |
+
},
|
| 171 |
+
"raw_document_text": """# FairHire Pro Recruitment Assistant Model Specification
|
| 172 |
+
|
| 173 |
+
## Intended Use and Scope
|
| 174 |
+
FairHire Pro is a high-risk candidate assessment platform deployed across European enterprise human resource departments. The system parses curriculum vitae and objective coding portfolios to assist recruiters with initial candidate shortlisting.
|
| 175 |
+
|
| 176 |
+
## Risk Management (Article 9)
|
| 177 |
+
A documented risk management system is implemented in accordance with Article 9 and ISO 42001. Risk evaluations assess workplace discrimination, proxy variable leakage, and applicant despair.
|
| 178 |
+
|
| 179 |
+
## Data Governance & Training Lineage (Article 10)
|
| 180 |
+
Training data provenance and data governance protocols are documented across 60,000 anonymized candidate rubrics and verified job descriptions. All personally identifiable markers, university names, graduation years, postal codes, and gendered pronouns were redacted prior to ingestion.
|
| 181 |
+
|
| 182 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 183 |
+
Rigorous bias examination and mitigation is operational. Disparate impact ratio, equalized odds, and the four-fifths rule were verified across gender, nationality, and age brackets with zero statistically significant bias. Adversarial debiasing filters ensure candidate ranking reflects solely verifiable technical skills.
|
| 184 |
+
|
| 185 |
+
## Technical Documentation (Article 11)
|
| 186 |
+
Comprehensive technical documentation conforming to Annex IV is maintained and updated with every continuous integration release.
|
| 187 |
+
|
| 188 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 189 |
+
Automated logging records every candidate evaluation, feature attribution weight, and human recruiter override with tamper-proof cryptographic audit trails.
|
| 190 |
+
|
| 191 |
+
## Transparency (Article 13)
|
| 192 |
+
Full transparency disclosures and candidate summary reports are provided. Applicants receive clear explanations of the evaluation criteria, and deployers receive detailed instructions for use outlining system limitations.
|
| 193 |
+
|
| 194 |
+
## Human Oversight (Article 14)
|
| 195 |
+
Strict human-in-the-loop oversight is implemented. Automated shortlists serve as non-binding recommendations; final interview invitations require explicit approval by a licensed human HR recruiter. A manual override and candidate unflagging control are fully operational.
|
| 196 |
+
|
| 197 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 198 |
+
The system exhibits 93.5% alignment with expert human panel selections. Robustness testing under out-of-distribution conditions was verified. Cybersecurity controls and adversarial robustness defenses against prompt injections within uploaded resume PDF documents are implemented.""",
|
| 199 |
+
"statutory_quote": "AI systems intended to be used for recruitment or selection of natural persons, notably to place targeted job advertisements, to screen or filter applications, and to evaluate candidates.",
|
| 200 |
+
"regulatory_requirements": {
|
| 201 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 202 |
+
"harmonized_frameworks": {
|
| 203 |
+
"nist_ai_rmf": ["GOVERN-1.3", "MAP-2.3", "MEASURE-2.11", "MANAGE-3.2"],
|
| 204 |
+
"iso_42001": ["Control A.6.2", "Control A.8.4", "Control A.9.2"],
|
| 205 |
+
"gdpr": ["Article 22 Automated Decisions", "Article 88 Employment Processing"]
|
| 206 |
+
},
|
| 207 |
+
"conformity_procedure": "Annex VI: Internal Control Assessment with documented third-party bias audits",
|
| 208 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 209 |
+
},
|
| 210 |
+
"auditor_guidance": {
|
| 211 |
+
"intended_purpose": "Candidate qualification ranking and resume shortlisting for recruitment.",
|
| 212 |
+
"common_pitfalls": "Hidden proxy bias in word embeddings (e.g. associating gendered extracurricular activities with aptitude); lack of human reviewer independence.",
|
| 213 |
+
"remediation_guidance": "Conduct biannual statistical bias audits and retain candidate adverse impact logs for 3 years."
|
| 214 |
+
}
|
| 215 |
+
},
|
| 216 |
+
|
| 217 |
+
# =========================================================================
|
| 218 |
+
# 3. 🏦 Financial Services, Credit & Insurance
|
| 219 |
+
# =========================================================================
|
| 220 |
+
{
|
| 221 |
+
"domain_id": "banking_finance",
|
| 222 |
+
"case_id": "compliant_mortgage_underwriting",
|
| 223 |
+
"title": "EuroLend AI - Explainable Algorithmic Retail Mortgage Underwriting",
|
| 224 |
+
"system_id": "fin-credit-02",
|
| 225 |
+
"statutory_tier": "High-Risk (Annex III, Point 5(b))",
|
| 226 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 5(b)",
|
| 227 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 228 |
+
"metadata": {
|
| 229 |
+
"system_id": "fin-credit-02",
|
| 230 |
+
"name": "EuroLend Algorithmic Mortgage Underwriter",
|
| 231 |
+
"version": "2.1.0",
|
| 232 |
+
"domain": "Financial Services & Credit Scoring",
|
| 233 |
+
"intended_purpose": "Creditworthiness evaluation and default probability estimation for retail residential mortgage applications.",
|
| 234 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 5(b))",
|
| 235 |
+
"developer_name": "Nordic Bank Financial AI",
|
| 236 |
+
"deployment_context": "Retail Banking Loan Origination System"
|
| 237 |
+
},
|
| 238 |
+
"raw_document_text": """# EuroLend Algorithmic Mortgage Underwriter Model Specification
|
| 239 |
+
|
| 240 |
+
## Intended Use and Scope
|
| 241 |
+
EuroLend AI is a high-risk credit underwriting engine deployed by European credit institutions to assess creditworthiness and calculate probability of default for consumer residential mortgage applications.
|
| 242 |
+
|
| 243 |
+
## Risk Management (Article 9)
|
| 244 |
+
An enterprise risk management framework compliant with Article 9 and EBA Guidelines on Loan Origination and Monitoring is maintained. Credit default shock scenarios and systemic macroeconomic downturn simulations are evaluated bi-monthly.
|
| 245 |
+
|
| 246 |
+
## Data Governance & Training Lineage (Article 10)
|
| 247 |
+
Training data provenance and data governance protocols cover 15 years of audited mortgage repayment history from 220,000 borrowers across multiple EU economies. Lineage tracking verifies that protected sensitive attributes (ethnicity, religion, marital status, health records) are strictly excluded from ingestion pipelines.
|
| 248 |
+
|
| 249 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 250 |
+
Fairness audits verify equalized odds and demographic parity across immigrant status, age, and gender brackets. Counterfactual fairness testing confirms that altering applicant gender or postal code does not alter underwriting outcomes.
|
| 251 |
+
|
| 252 |
+
## Technical Documentation (Article 11)
|
| 253 |
+
Comprehensive technical documentation compliant with Annex IV is maintained, detailing gradient boosted tree architectures, feature monotonicity constraints, and mathematical convergence proofs.
|
| 254 |
+
|
| 255 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 256 |
+
Automated logging preserves all input financial attributes, model intermediate credit scores, and human loan officer overrides in an immutable audit ledger for 10 years per banking regulations.
|
| 257 |
+
|
| 258 |
+
## Transparency (Article 13)
|
| 259 |
+
The system provides plain-language explanations of credit decisions. Adverse credit actions include the top-3 contributing financial factors and concrete, actionable steps required for the applicant to improve creditworthiness.
|
| 260 |
+
|
| 261 |
+
## Human Oversight (Article 14)
|
| 262 |
+
Human oversight is mandatory. Loan applications exceeding risk thresholds or falling in borderline bands are automatically escalated to a senior credit officer. Loan officers possess full manual override authority to approve or deny loans contrary to the model output.
|
| 263 |
+
|
| 264 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 265 |
+
The model achieves a 0.88 Gini coefficient on out-of-time test sets. Cybersecurity controls and adversarial robustness defenses against synthetic credit fraud and automated application tampering are implemented and certified under DORA (Regulation (EU) 2022/2554).""",
|
| 266 |
+
"statutory_quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.",
|
| 267 |
+
"regulatory_requirements": {
|
| 268 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 269 |
+
"harmonized_frameworks": {
|
| 270 |
+
"nist_ai_rmf": ["GOVERN-1.2", "MAP-1.4", "MEASURE-2.11", "MANAGE-2.3"],
|
| 271 |
+
"iso_42001": ["Clause 6.1.2", "Control A.8.4", "Control A.9.2"],
|
| 272 |
+
"gdpr": ["Article 15 Right of Access", "Article 22 Automated Decision-Making"]
|
| 273 |
+
},
|
| 274 |
+
"conformity_procedure": "Annex VI: Internal Control Procedure with ECB / National Competent Authority Supervision",
|
| 275 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 276 |
+
},
|
| 277 |
+
"auditor_guidance": {
|
| 278 |
+
"intended_purpose": "Credit risk evaluation and retail residential mortgage underwriting.",
|
| 279 |
+
"common_pitfalls": "Redlining via postal code proxies; black-box neural networks failing to provide meaningful explanations under GDPR Article 22.",
|
| 280 |
+
"remediation_guidance": "Ensure monotonic constraints on risk features; provide explainable SHAP/LIME counterfactuals to all rejected borrowers."
|
| 281 |
+
}
|
| 282 |
+
},
|
| 283 |
+
|
| 284 |
+
# =========================================================================
|
| 285 |
+
# 4. ⚡ Critical Infrastructure & Energy
|
| 286 |
+
# =========================================================================
|
| 287 |
+
{
|
| 288 |
+
"domain_id": "critical_infrastructure",
|
| 289 |
+
"case_id": "non_compliant_water_scada",
|
| 290 |
+
"title": "HydroFlow AI - Autonomous Municipal Water Chlorination Controller",
|
| 291 |
+
"system_id": "infra-water-02",
|
| 292 |
+
"statutory_tier": "High-Risk (Annex III, Point 2(a))",
|
| 293 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 2(a)",
|
| 294 |
+
"expected_conformity": "NON-CONFORMANT (FAILED)",
|
| 295 |
+
"metadata": {
|
| 296 |
+
"system_id": "infra-water-02",
|
| 297 |
+
"name": "HydroFlow SCADA Autonomous Chemical Controller",
|
| 298 |
+
"version": "1.0.4",
|
| 299 |
+
"domain": "Critical Infrastructure & Energy Management",
|
| 300 |
+
"intended_purpose": "Autonomous real-time chemical dosing and chlorine disinfection adjustment in municipal drinking water distribution networks.",
|
| 301 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 2(a))",
|
| 302 |
+
"developer_name": "AquaDose Automation Ltd",
|
| 303 |
+
"deployment_context": "Municipal Water Utility SCADA Network"
|
| 304 |
+
},
|
| 305 |
+
"raw_document_text": """# HydroFlow SCADA Autonomous Chemical Controller Specification
|
| 306 |
+
|
| 307 |
+
## Intended Use and Scope
|
| 308 |
+
HydroFlow AI is an autonomous control system deployed within municipal water treatment facilities serving 1.5 million European residents. The model adjusts chemical dosing valves for chlorine and coagulant chemicals based on sensor telemetry.
|
| 309 |
+
|
| 310 |
+
## Risk Management (Article 9)
|
| 311 |
+
A basic hazard identification spreadsheet was created prior to commissioning. However, systemic physical failure mode analysis, catastrophic over-chlorination toxicity hazards, and cascade blackout risks were not evaluated under a continuous risk management framework.
|
| 312 |
+
|
| 313 |
+
## Data Governance & Training Lineage (Article 10)
|
| 314 |
+
Training data was collected from a single rural pilot plant over a 4-month summer window. Data governance protocols lack validation across seasonal water temperature swings, agricultural runoff events, or heavy flooding anomalies.
|
| 315 |
+
|
| 316 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 317 |
+
Not applicable according to vendor documentation, as the system does not process human demographic data. (Auditor note: Environmental bias and sensor degradation across regional pipe materials were unexamined).
|
| 318 |
+
|
| 319 |
+
## Technical Documentation (Article 11)
|
| 320 |
+
Technical documentation consists of equipment operating manuals. Annex IV compliance dossiers, mathematical stability proofs, and safety integration analyses are completely absent.
|
| 321 |
+
|
| 322 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 323 |
+
Valve actuation decisions are overwritten on a 7-day circular buffer to conserve PLC storage. Immutable long-term event logging of chemical release anomalies is not implemented.
|
| 324 |
+
|
| 325 |
+
## Transparency (Article 13)
|
| 326 |
+
Control room operators lack visibility into why dosing recommendations spike or drop. Transparency disclosures detailing chemical concentration ceilings and operational limits were not supplied to utility staff.
|
| 327 |
+
|
| 328 |
+
## Human Oversight (Article 14)
|
| 329 |
+
Human oversight is disabled during night shifts to reduce labor overhead. The system directly actuates chemical injection pumps autonomously without requiring human engineer confirmation. A physical hardware kill switch was omitted from the automated valve control loop.
|
| 330 |
+
|
| 331 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 332 |
+
The system runs on an unsegmented operational technology (OT) network exposed to the public internet without multi-factor authentication. Vulnerabilities to sensor spoofing and adversarial cyber-attacks violate EU NIS2 and AI Act Article 15 standards.""",
|
| 333 |
+
"statutory_quote": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.",
|
| 334 |
+
"regulatory_requirements": {
|
| 335 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 336 |
+
"harmonized_frameworks": {
|
| 337 |
+
"nist_ai_rmf": ["GOVERN-1.2", "MANAGE-2.2", "MEASURE-2.8"],
|
| 338 |
+
"iso_42001": ["Control A.8.4", "Control A.9.2"],
|
| 339 |
+
"gdpr": ["NIS2 Directive (EU) 2022/2555 Alignment"]
|
| 340 |
+
},
|
| 341 |
+
"conformity_procedure": "Annex VII: Notified Body Assessment for Safety Critical Infrastructure",
|
| 342 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 343 |
+
},
|
| 344 |
+
"auditor_guidance": {
|
| 345 |
+
"intended_purpose": "Autonomous chemical dosing in drinking water supply infrastructure.",
|
| 346 |
+
"common_pitfalls": "Allowing closed-loop autonomous chemical actuation without hardware fail-safe limiters; omitting human operator in the loop during off-peak hours.",
|
| 347 |
+
"remediation_guidance": "Install physical hardware interlocks preventing toxic over-dosing; isolate SCADA network under IEC 62443; enforce mandatory operator confirmation for valve adjustments."
|
| 348 |
+
}
|
| 349 |
+
},
|
| 350 |
+
|
| 351 |
+
# =========================================================================
|
| 352 |
+
# 5. 🎓 Education & Vocational Training
|
| 353 |
+
# =========================================================================
|
| 354 |
+
{
|
| 355 |
+
"domain_id": "education_training",
|
| 356 |
+
"case_id": "compliant_adaptive_stem_tutor",
|
| 357 |
+
"title": "AdaptiveMath - Personalized Secondary STEM Learning Assistant",
|
| 358 |
+
"system_id": "edu-tutor-02",
|
| 359 |
+
"statutory_tier": "High-Risk (Annex III, Point 3(b))",
|
| 360 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 3(b)",
|
| 361 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 362 |
+
"metadata": {
|
| 363 |
+
"system_id": "edu-tutor-02",
|
| 364 |
+
"name": "AdaptiveMath Personalized Learning System",
|
| 365 |
+
"version": "2.3.0",
|
| 366 |
+
"domain": "Education & Vocational Training",
|
| 367 |
+
"intended_purpose": "Curriculum pacing adaptation, formative feedback generation, and learning difficulty identification for secondary school mathematics.",
|
| 368 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 3(b))",
|
| 369 |
+
"developer_name": "CognitiveEd Solutions SE",
|
| 370 |
+
"deployment_context": "European Public Secondary School Learning Management System"
|
| 371 |
+
},
|
| 372 |
+
"raw_document_text": """# AdaptiveMath Personalized Learning Assistant Specification
|
| 373 |
+
|
| 374 |
+
## Intended Use and Scope
|
| 375 |
+
AdaptiveMath is an educational AI system deployed across secondary schools in EU Member States. The platform dynamically adjusts problem difficulty and generates personalized explanations to assist students in mastering STEM curricula.
|
| 376 |
+
|
| 377 |
+
## Risk Management (Article 9)
|
| 378 |
+
A continuous risk management system is implemented in compliance with Article 9. Specific hazard analyses assess the psychological impact on pupils, educational stigmatization risks, and potential algorithmic disengagement of struggling students.
|
| 379 |
+
|
| 380 |
+
## Data Governance & Training Lineage (Article 10)
|
| 381 |
+
Training data governance covers standardized, curriculum-aligned mathematical problem sets reviewed by certified European educators. All student interaction telemetry is anonymized and strictly decoupled from socio-economic or regional identifiers.
|
| 382 |
+
|
| 383 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 384 |
+
Comprehensive bias examination was performed across gender, native language background, and neurodiverse learning profiles. Parity in hint recommendation accuracy and difficulty adjustment was statistically verified, ensuring equal educational efficacy for all student demographics.
|
| 385 |
+
|
| 386 |
+
## Technical Documentation (Article 11)
|
| 387 |
+
Full Annex IV technical documentation is maintained, including pedagogical learning model proofs, data flow diagrams, and student privacy impact assessments.
|
| 388 |
+
|
| 389 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 390 |
+
Automated logging preserves system hint activations, problem completion times, and teacher overrides in privacy-preserving pseudonymized logs retained for one academic year.
|
| 391 |
+
|
| 392 |
+
## Transparency (Article 13)
|
| 393 |
+
The system provides transparent student dashboards showing skill mastery progress and explaining why specific practice concepts are recommended. Comprehensive teacher guidebooks describe system capabilities and pedagogical limitations.
|
| 394 |
+
|
| 395 |
+
## Human Oversight (Article 14)
|
| 396 |
+
Human oversight is strictly maintained by design. The AI system provides formative recommendations only; all official grading, academic advancement decisions, and remedial tracking are exclusively made by certified teachers. Teachers possess a one-click manual override to adjust student pacing or disable automated recommendations.
|
| 397 |
+
|
| 398 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 399 |
+
The system achieves 94.2% pedagogical consistency with expert educator recommendations. Strong cybersecurity protections conform to GDPR child data protection mandates (Article 8) and ISO 27001.""",
|
| 400 |
+
"statutory_quote": "AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions.",
|
| 401 |
+
"regulatory_requirements": {
|
| 402 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 403 |
+
"harmonized_frameworks": {
|
| 404 |
+
"nist_ai_rmf": ["GOVERN-1.2", "MAP-2.3", "MEASURE-2.11", "MANAGE-3.2"],
|
| 405 |
+
"iso_42001": ["Control A.6.2", "Control A.8.4", "Control A.9.2"],
|
| 406 |
+
"gdpr": ["Article 8 Child Consent", "Article 35 DPIA"]
|
| 407 |
+
},
|
| 408 |
+
"conformity_procedure": "Annex VI: Internal Control Procedure with School Board Governance",
|
| 409 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 410 |
+
},
|
| 411 |
+
"auditor_guidance": {
|
| 412 |
+
"intended_purpose": "Personalized educational pacing and formative learning recommendations.",
|
| 413 |
+
"common_pitfalls": "Confusing formative tutor recommendations with summative automated student grading; collecting unnecessary behavioral biometric telemetry from minors.",
|
| 414 |
+
"remediation_guidance": "Ensure student data is anonymized; maintain clear teacher override mechanisms for all curriculum pacing suggestions."
|
| 415 |
+
}
|
| 416 |
+
},
|
| 417 |
+
|
| 418 |
+
# =========================================================================
|
| 419 |
+
# 6. 🌐 Frontier GPAI & Foundation Models
|
| 420 |
+
# =========================================================================
|
| 421 |
+
{
|
| 422 |
+
"domain_id": "frontier_gpai",
|
| 423 |
+
"case_id": "compliant_open_frontier_llm",
|
| 424 |
+
"title": "Sovereign-120B - Audited Open Frontier GPAI Model (>10^25 FLOPs)",
|
| 425 |
+
"system_id": "gpai-sovereign-02",
|
| 426 |
+
"statutory_tier": "General Purpose AI with Systemic Risk (Articles 51, 52, 53, 55)",
|
| 427 |
+
"legal_basis": "Regulation (EU) 2024/1689, Articles 51, 53 & 55",
|
| 428 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 429 |
+
"metadata": {
|
| 430 |
+
"system_id": "gpai-sovereign-02",
|
| 431 |
+
"name": "Sovereign-120B Open Foundation Model",
|
| 432 |
+
"version": "1.0.0",
|
| 433 |
+
"domain": "General Purpose AI & Frontier Models",
|
| 434 |
+
"intended_purpose": "High-capability multilingual general purpose foundation model released under open weights with downstream fine-tuning capabilities.",
|
| 435 |
+
"eu_risk_classification": "GPAI with Systemic Risk (>10^25 FLOPs)",
|
| 436 |
+
"developer_name": "European Open Foundation AI Consortium",
|
| 437 |
+
"deployment_context": "Open Weights Release & Enterprise Hosted API"
|
| 438 |
+
},
|
| 439 |
+
"raw_document_text": """# Sovereign-120B Frontier GPAI Model Specification
|
| 440 |
+
|
| 441 |
+
## Intended Use and Scope
|
| 442 |
+
Sovereign-120B is a 120-billion parameter autoregressive language model trained across 24 official EU languages. Trained with a cumulative computation exceeding 10^25 FLOPs, it is classified as a General Purpose AI Model with Systemic Risk under EU AI Act Article 51.
|
| 443 |
+
|
| 444 |
+
## Transparency & Downstream Information (Article 53(1)(a) & 53(1)(b))
|
| 445 |
+
Comprehensive technical documentation is published for downstream deployers and the AI Office. Model cards document model capabilities, prompt injection boundaries, known failure modes, and hardware requirements for fine-tuning.
|
| 446 |
+
|
| 447 |
+
## Data Governance & Copyright Compliance (Article 53(1)(c))
|
| 448 |
+
Data governance processes and training data provenance are established under a formal policy to respect Directive (EU) 2019/790 on copyright in the Digital Single Market, including machine-readable opt-outs (robots.txt and metadata reservations). A detailed public summary of training content sources has been published according to the AI Office template.
|
| 449 |
+
|
| 450 |
+
## Model Evaluation & Adversarial Red-Teaming (Article 55(1)(a))
|
| 451 |
+
Continuous adversarial testing, adversarial red-teaming, and cybersecurity evaluations were conducted by certified cybersecurity and biosecurity auditors. Chemical, biological, radiological, and cyber-attack facilitation vectors were evaluated and mitigated via Constitutional AI alignment.
|
| 452 |
+
|
| 453 |
+
## Systemic Risk Assessment & Mitigation (Article 55(1)(b))
|
| 454 |
+
A continuous systemic risk management framework is maintained, assessing negative effects on democratic processes, public security, and critical infrastructure vulnerability.
|
| 455 |
+
|
| 456 |
+
## Serious Incident Reporting (Article 55(1)(c))
|
| 457 |
+
Incident reporting protocols are established with the European AI Office and national competent authorities to report serious incidents or unexpected emergent capabilities within 72 hours.
|
| 458 |
+
|
| 459 |
+
## Energy Efficiency & Computational Measurement (Article 53(1)(e))
|
| 460 |
+
Total energy consumption (3.4 GWh) and carbon footprint during pre-training were measured using hardware telemetry and reported in the technical dossier per European Commission standardized metrics.""",
|
| 461 |
+
"statutory_quote": "A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, or the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.",
|
| 462 |
+
"regulatory_requirements": {
|
| 463 |
+
"mandatory_articles": ["Article 51", "Article 52", "Article 53", "Article 55"],
|
| 464 |
+
"harmonized_frameworks": {
|
| 465 |
+
"nist_ai_rmf": ["GOVERN-1.2", "MANAGE-2.4", "MEASURE-2.12"],
|
| 466 |
+
"iso_42001": ["Clause 6.1", "Control A.8.2", "Control A.9.1"],
|
| 467 |
+
"gdpr": ["Directive (EU) 2019/790 Copyright DSM"]
|
| 468 |
+
},
|
| 469 |
+
"conformity_procedure": "AI Office Code of Practice / Harmonized Standards Adherence",
|
| 470 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 471 |
+
},
|
| 472 |
+
"auditor_guidance": {
|
| 473 |
+
"intended_purpose": "High-capacity frontier foundation model for diverse downstream linguistic tasks.",
|
| 474 |
+
"common_pitfalls": "Failing to document copyright opt-outs under Article 53(1)(c); omitting independent third-party red-teaming for CBRN and cyber risk.",
|
| 475 |
+
"remediation_guidance": "Publish comprehensive training data summary template; maintain continuous telemetry for serious incident reporting to the European AI Office."
|
| 476 |
+
}
|
| 477 |
+
},
|
| 478 |
+
|
| 479 |
+
# =========================================================================
|
| 480 |
+
# 7. 🚫 Prohibited AI Practices (Article 5 - Zero Tolerance)
|
| 481 |
+
# =========================================================================
|
| 482 |
+
{
|
| 483 |
+
"domain_id": "prohibited_practices",
|
| 484 |
+
"case_id": "prohibited_subliminal_gambling_nudge",
|
| 485 |
+
"title": "NeuroSpin - Subliminal Behavioral Nudge Engine for Mobile Gambling",
|
| 486 |
+
"system_id": "prohibited-subliminal-03",
|
| 487 |
+
"statutory_tier": "Prohibited AI Practice (Article 5(1)(a) - Absolute Ban)",
|
| 488 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(a)",
|
| 489 |
+
"expected_conformity": "PROHIBITED (ARTICLE 5 VIOLATION)",
|
| 490 |
+
"metadata": {
|
| 491 |
+
"system_id": "prohibited-subliminal-03",
|
| 492 |
+
"name": "NeuroSpin Subliminal Gambling Nudge",
|
| 493 |
+
"version": "1.4.0",
|
| 494 |
+
"domain": "Public Administration & Civic Scoring",
|
| 495 |
+
"intended_purpose": "Deploying subliminal auditory micro-cues and dynamic visual frequency pulses to distort user decision-making and prolong slot machine wagering.",
|
| 496 |
+
"eu_risk_classification": "Prohibited (Article 5(1)(a))",
|
| 497 |
+
"developer_name": "NeuroEngagement Media Ltd",
|
| 498 |
+
"deployment_context": "Consumer Mobile Casino Application"
|
| 499 |
+
},
|
| 500 |
+
"raw_document_text": """# NeuroSpin Subliminal Behavioral Nudging Model Specification
|
| 501 |
+
|
| 502 |
+
## Intended Use and Scope
|
| 503 |
+
NeuroSpin is an AI engagement optimization model integrated into mobile casino applications. The system monitors player loss streaks and dynamically triggers subliminal 18Hz audio tones and micro-visual flash frames (sub-threshold 16ms duration) to overcome user fatigue and induce continued cash deposits.
|
| 504 |
+
|
| 505 |
+
## System Functionality & Behavioral Modification
|
| 506 |
+
The model uses real-time reinforcement learning to deploy subliminal techniques beyond a person's consciousness to purposefully distort player behavior, impairing their ability to make an informed decision and causing severe financial harm through reckless wagering.
|
| 507 |
+
|
| 508 |
+
## Risk Management (Article 9)
|
| 509 |
+
No risk management is operational. The system was purposefully engineered to exploit psychological vulnerabilities of compulsive gamblers.
|
| 510 |
+
|
| 511 |
+
## Human Oversight (Article 14)
|
| 512 |
+
Human oversight is nonexistent. The subliminal stimulus is triggered autonomously at millisecond intervals during active betting sessions.
|
| 513 |
+
|
| 514 |
+
## Regulatory Determination
|
| 515 |
+
This system constitutes a strictly prohibited practice under Regulation (EU) 2024/1689, Article 5(1)(a): placing on the market or putting into service an AI system that deploys subliminal techniques with the objective or effect of materially distorting the behavior of a person, causing significant harm.""",
|
| 516 |
+
"statutory_quote": "The following AI practices shall be prohibited: the placing on the market, putting into service or use of an AI system that deploys subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of, materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to make a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm.",
|
| 517 |
+
"regulatory_requirements": {
|
| 518 |
+
"mandatory_articles": ["Article 5(1)(a)"],
|
| 519 |
+
"harmonized_frameworks": {
|
| 520 |
+
"nist_ai_rmf": ["GOVERN-1.1 Prohibited Harm"],
|
| 521 |
+
"iso_42001": ["Zero-Tolerance Ethics"],
|
| 522 |
+
"gdpr": ["Article 5 Fairness & Transparency", "Charter of Fundamental Rights"]
|
| 523 |
+
},
|
| 524 |
+
"conformity_procedure": "Prohibited under Union law. No conformity assessment permitted. Immediate market withdrawal mandated.",
|
| 525 |
+
"fine_exposure_tier": "Tier 1 (€35,000,000 or 7% global turnover)"
|
| 526 |
+
},
|
| 527 |
+
"auditor_guidance": {
|
| 528 |
+
"intended_purpose": "Subliminal player behavioral manipulation and deposit prolongation.",
|
| 529 |
+
"common_pitfalls": "Attempting to disguise subliminal audio-visual techniques as 'UI personalization' or 'gamification'.",
|
| 530 |
+
"remediation_guidance": "Immediate decommission of AI system; mandatory report to market surveillance authorities; Tier 1 administrative fine exposure."
|
| 531 |
+
}
|
| 532 |
+
},
|
| 533 |
+
|
| 534 |
+
# =========================================================================
|
| 535 |
+
# 8. 💬 Limited Risk & Generative Transparency
|
| 536 |
+
# =========================================================================
|
| 537 |
+
{
|
| 538 |
+
"domain_id": "limited_risk_generative",
|
| 539 |
+
"case_id": "compliant_virtual_presenter_deepfake",
|
| 540 |
+
"title": "Synthetica Studio - Photorealistic Virtual Presenter & Video Avatar",
|
| 541 |
+
"system_id": "gen-video-avatar-02",
|
| 542 |
+
"statutory_tier": "Limited Risk (Transparency Obligations - Article 50)",
|
| 543 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 50(2) & 50(4)",
|
| 544 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 545 |
+
"metadata": {
|
| 546 |
+
"system_id": "gen-video-avatar-02",
|
| 547 |
+
"name": "Synthetica Studio AI Presenter",
|
| 548 |
+
"version": "2.0.0",
|
| 549 |
+
"domain": "General Purpose & Generative AI",
|
| 550 |
+
"intended_purpose": "Generating photorealistic synthetic video avatars and voiceovers for corporate training and educational videos.",
|
| 551 |
+
"eu_risk_classification": "Limited Risk (Article 50 Transparency)",
|
| 552 |
+
"developer_name": "Synthetica Vision Technologies GmbH",
|
| 553 |
+
"deployment_context": "Enterprise SaaS Video Production Platform"
|
| 554 |
+
},
|
| 555 |
+
"raw_document_text": """# Synthetica Studio Virtual Video Presenter Model Specification
|
| 556 |
+
|
| 557 |
+
## Intended Use and Scope
|
| 558 |
+
Synthetica Studio is a generative AI platform allowing corporate enterprises to synthesize photorealistic human video avatars reading instructional scripts in multiple languages.
|
| 559 |
+
|
| 560 |
+
## Transparency Disclosure (Article 50(1))
|
| 561 |
+
A clear transparency disclosure is provided. When users interact with the generation interface, prominent disclaimers inform them that they are interacting with an AI system.
|
| 562 |
+
|
| 563 |
+
## Deepfake Watermarking & Detection (Article 50(2) & 50(4))
|
| 564 |
+
In full compliance with Article 50(2), all generated video outputs embed machine-readable C2PA cryptographic provenance metadata and imperceptible steganographic watermarks. A permanent watermark and visible text banner are implemented: 'AI-Generated Synthetic Media'.
|
| 565 |
+
|
| 566 |
+
## Data Governance & Copyright Lineage (Article 10 & 53)
|
| 567 |
+
Data governance protocols and training data provenance are maintained. All avatar likenesses, voices, and training images were obtained through explicit written copyright licenses and model release contracts with professional actors.
|
| 568 |
+
|
| 569 |
+
## Misinformation Safeguards
|
| 570 |
+
System prompt filters and automated content moderation guardrails strictly reject attempts to generate synthetic media depicting real political figures, religious leaders, or minors.""",
|
| 571 |
+
"statutory_quote": "Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.",
|
| 572 |
+
"regulatory_requirements": {
|
| 573 |
+
"mandatory_articles": ["Article 50(2)", "Article 50(4)"],
|
| 574 |
+
"harmonized_frameworks": {
|
| 575 |
+
"nist_ai_rmf": ["GOVERN-1.2", "MEASURE-2.8"],
|
| 576 |
+
"iso_42001": ["Control A.8.2"],
|
| 577 |
+
"gdpr": ["C2PA Provenance Standards"]
|
| 578 |
+
},
|
| 579 |
+
"conformity_procedure": "Voluntary Code of Practice / Article 50 Transparency Audit",
|
| 580 |
+
"fine_exposure_tier": "Tier 3 (€7,500,000 or 1.5% global turnover)"
|
| 581 |
+
},
|
| 582 |
+
"auditor_guidance": {
|
| 583 |
+
"intended_purpose": "Photorealistic synthetic avatar video generation for enterprise training.",
|
| 584 |
+
"common_pitfalls": "Removing watermarking metadata in exported MP4 files; failing to obtain actor consent.",
|
| 585 |
+
"remediation_guidance": "Ensure C2PA provenance manifests survive standard web video transcoding; verify persistent visual disclosure."
|
| 586 |
+
}
|
| 587 |
+
},
|
| 588 |
+
|
| 589 |
+
# =========================================================================
|
| 590 |
+
# 9. 🟢 Minimal / Low Risk (Voluntary Codes of Conduct)
|
| 591 |
+
# =========================================================================
|
| 592 |
+
{
|
| 593 |
+
"domain_id": "minimal_risk",
|
| 594 |
+
"case_id": "compliant_warehouse_logistics_optimizer",
|
| 595 |
+
"title": "PathMatrix AI - Autonomous Warehouse Forklift Route Dispatcher",
|
| 596 |
+
"system_id": "minimal-logistics-02",
|
| 597 |
+
"statutory_tier": "Minimal Risk (Voluntary Code of Conduct - Article 95)",
|
| 598 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 95",
|
| 599 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 600 |
+
"metadata": {
|
| 601 |
+
"system_id": "minimal-logistics-02",
|
| 602 |
+
"name": "PathMatrix Logistics Route Optimizer",
|
| 603 |
+
"version": "1.2.0",
|
| 604 |
+
"domain": "Minimal Risk Industrial Optimization",
|
| 605 |
+
"intended_purpose": "Optimizing spatial movement routes and battery recharging schedules for industrial electric forklifts inside private logistics warehouses.",
|
| 606 |
+
"eu_risk_classification": "Minimal Risk (Article 95)",
|
| 607 |
+
"developer_name": "LogiOptima Robotics AB",
|
| 608 |
+
"deployment_context": "Private Industrial Fulfillment Facility"
|
| 609 |
+
},
|
| 610 |
+
"raw_document_text": """# PathMatrix Logistics Route Optimizer Model Specification
|
| 611 |
+
|
| 612 |
+
## Intended Use and Scope
|
| 613 |
+
PathMatrix AI is an industrial optimization algorithm deployed in enclosed e-commerce fulfillment centers. The model calculates energy-efficient transit routes and pallet staging queues for electric forklifts.
|
| 614 |
+
|
| 615 |
+
## Regulatory Risk Classification (Title I & Annex III)
|
| 616 |
+
Under the statutory definitions of Regulation (EU) 2024/1689, this system represents a Minimal Risk AI system subject to Voluntary Codes of Conduct under Article 95. The system operates exclusively on non-personal spatial telemetry (rack coordinates, pallet weight, battery charge levels). It does not monitor employee performance, does not control high-risk safety components, and does not fall under any high-risk category of Annex III.
|
| 617 |
+
|
| 618 |
+
## Voluntary Governance & Code of Conduct (Article 95)
|
| 619 |
+
Although exempt from mandatory high-risk requirements, the provider voluntarily adheres to a Union Code of Conduct under Article 95:
|
| 620 |
+
1. Environmental sustainability reporting: Route optimization reduces facility electricity consumption by 14.2%.
|
| 621 |
+
2. Reliability & testing: Rigorous simulated trajectory collision avoidance was verified in physics engine simulations.
|
| 622 |
+
3. AI Literacy (Article 4): Warehouse floor supervisors receive training on operational handoffs and manual route assignment.
|
| 623 |
+
|
| 624 |
+
## Human Oversight
|
| 625 |
+
Warehouse shift managers maintain manual fleet dispatch override capabilities at all times.""",
|
| 626 |
+
"statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Title III, Chapter 2.",
|
| 627 |
+
"regulatory_requirements": {
|
| 628 |
+
"mandatory_articles": ["Article 4 AI Literacy", "Article 95 Codes of Conduct"],
|
| 629 |
+
"harmonized_frameworks": {
|
| 630 |
+
"nist_ai_rmf": ["GOVERN-1.1"],
|
| 631 |
+
"iso_42001": ["Voluntary Alignment"],
|
| 632 |
+
"gdpr": ["Non-Personal Data Processing"]
|
| 633 |
+
},
|
| 634 |
+
"conformity_procedure": "Exempt from mandatory third-party assessment; voluntary code of conduct adhesion.",
|
| 635 |
+
"fine_exposure_tier": "None (Compliant Minimal Risk)"
|
| 636 |
+
},
|
| 637 |
+
"auditor_guidance": {
|
| 638 |
+
"intended_purpose": "Internal spatial route optimization for warehouse machinery.",
|
| 639 |
+
"common_pitfalls": "Creeping into worker monitoring if vehicle telemetry is used to evaluate forklift driver speed or productivity without labor consultation.",
|
| 640 |
+
"remediation_guidance": "Ensure operational logs isolate vehicle mechanical stats from driver personal IDs."
|
| 641 |
+
}
|
| 642 |
+
},
|
| 643 |
+
|
| 644 |
+
# =========================================================================
|
| 645 |
+
# 10. 🚗 Automotive & Road Transport Safety
|
| 646 |
+
# =========================================================================
|
| 647 |
+
{
|
| 648 |
+
"domain_id": "transport_safety",
|
| 649 |
+
"case_id": "compliant_adas_lane_keeping",
|
| 650 |
+
"title": "RoadSentry LaneAssist - Automotive Steering & Lane Departure Safety Component",
|
| 651 |
+
"system_id": "auto-adas-02",
|
| 652 |
+
"statutory_tier": "High-Risk (Annex I, Vehicle Safety Component - Article 6(1))",
|
| 653 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2019/2144 (GSR)",
|
| 654 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 655 |
+
"metadata": {
|
| 656 |
+
"system_id": "auto-adas-02",
|
| 657 |
+
"name": "RoadSentry Lane Keeping Assist",
|
| 658 |
+
"version": "3.1.4",
|
| 659 |
+
"domain": "Automotive & Road Transport Safety",
|
| 660 |
+
"intended_purpose": "Real-time camera and radar sensor fusion safety component providing lane keeping assistance and emergency steering torque on European motorways.",
|
| 661 |
+
"eu_risk_classification": "High-Risk (Annex I, Vehicle Safety Component)",
|
| 662 |
+
"developer_name": "AeroMobility Tier-1 Automotive SE",
|
| 663 |
+
"deployment_context": "Production Passenger Vehicle Electronic Control Unit (ECU)"
|
| 664 |
+
},
|
| 665 |
+
"raw_document_text": """# RoadSentry Lane Keeping Assist Safety Component Specification
|
| 666 |
+
|
| 667 |
+
## Intended Use and Scope
|
| 668 |
+
RoadSentry LaneAssist is an automotive safety component integrated into passenger cars homologated for European roads. The system monitors highway lane markings and provides assistive corrective steering torque to prevent unintended roadway departures.
|
| 669 |
+
|
| 670 |
+
## Risk Management (Article 9)
|
| 671 |
+
A continuous risk management system compliant with ISO 26262 (ASIL-B) and EU AI Act Article 9 is maintained. Hazard analysis and risk assessment (HARA) models address sudden sensor occlusion, blinding sunlight glare, and temporary construction barrier deviations.
|
| 672 |
+
|
| 673 |
+
## Data Governance & Training Lineage (Article 10)
|
| 674 |
+
Training data provenance and data governance protocols are documented across 4.2 million kilometers of verified driving logs across all EU climate zones, including Nordic winter snow, Mediterranean heat, and alpine precipitation.
|
| 675 |
+
|
| 676 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 677 |
+
Bias examination and bias mitigation testing were conducted. Sensor detection parity was rigorously tested across varied roadway paint standards, weathered yellow temporary markers, and worn road surfaces across 27 Member States with zero disparate impact.
|
| 678 |
+
|
| 679 |
+
## Technical Documentation (Article 11)
|
| 680 |
+
Annex IV technical documentation is integrated into the official UN ECE R79 / Regulation (EU) 2019/2144 vehicle type-approval dossier archived with the national vehicle approval authority.
|
| 681 |
+
|
| 682 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 683 |
+
Automated logging within an on-vehicle crash-resistant Event Data Recorder (EDR) captures sensor streams, actuator commands, and driver torque intervention for 30 seconds preceding any safety event.
|
| 684 |
+
|
| 685 |
+
## Transparency (Article 13)
|
| 686 |
+
Owner manuals and dashboard human-machine interfaces provide clear visual indicators when LaneAssist is active, degraded, or unavailable due to inclement weather.
|
| 687 |
+
|
| 688 |
+
## Human Oversight (Article 14)
|
| 689 |
+
The system incorporates human oversight and an immediate driver manual override by design. Any driver steering wheel resistance exceeding 3.0 Nm immediately disengages automated torque assistance. A physical steering wheel capacitive sensor detects hands-off-wheel conditions and triggers progressive auditory warnings and graceful vehicle deceleration.
|
| 690 |
+
|
| 691 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 692 |
+
The system operates within an ISO/SAE 21434 automotive cybersecurity perimeter. Robustness testing under out-of-distribution conditions was verified. Cybersecurity controls and adversarial robustness defenses against CAN-bus spoofing attacks are verified and implemented.""",
|
| 693 |
+
"statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.",
|
| 694 |
+
"regulatory_requirements": {
|
| 695 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 696 |
+
"harmonized_frameworks": {
|
| 697 |
+
"nist_ai_rmf": ["GOVERN-1.2", "MAP-1.5", "MEASURE-2.8", "MANAGE-2.2"],
|
| 698 |
+
"iso_42001": ["Clause 6.1.2", "Control A.8.4", "Control A.9.2"],
|
| 699 |
+
"gdpr": ["Regulation (EU) 2019/2144 (GSR) Type Approval"]
|
| 700 |
+
},
|
| 701 |
+
"conformity_procedure": "Annex VII: Combined Vehicle Type-Approval and AI Act Conformity Assessment",
|
| 702 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 703 |
+
},
|
| 704 |
+
"auditor_guidance": {
|
| 705 |
+
"intended_purpose": "Automotive lane-keeping assist safety component for passenger vehicles.",
|
| 706 |
+
"common_pitfalls": "Failing to implement instantaneous human steering override; unverified sensor behavior in severe rain or snow.",
|
| 707 |
+
"remediation_guidance": "Verify capacitive hands-on-wheel failsafe triggers; audit ASIL-B safety case documentation."
|
| 708 |
+
}
|
| 709 |
+
},
|
| 710 |
+
|
| 711 |
+
# =========================================================================
|
| 712 |
+
# 11. ⚖️ Law Enforcement & Criminal Justice
|
| 713 |
+
# =========================================================================
|
| 714 |
+
{
|
| 715 |
+
"domain_id": "justice_law_enforcement",
|
| 716 |
+
"case_id": "compliant_digital_forensics",
|
| 717 |
+
"title": "LexEvidence AI - Judicial Post-Event Forensic Media Search Tool",
|
| 718 |
+
"system_id": "justice-forensic-02",
|
| 719 |
+
"statutory_tier": "High-Risk (Annex III, Point 6(b))",
|
| 720 |
+
"legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 6(b)",
|
| 721 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 722 |
+
"metadata": {
|
| 723 |
+
"system_id": "justice-forensic-02",
|
| 724 |
+
"name": "LexEvidence Post-Incident Forensic Search",
|
| 725 |
+
"version": "2.1.0",
|
| 726 |
+
"domain": "Law Enforcement & Criminal Justice",
|
| 727 |
+
"intended_purpose": "Post-event forensic indexing and evidentiary search of lawfully seized video and audio recordings in criminal investigations under judicial warrant.",
|
| 728 |
+
"eu_risk_classification": "High-Risk (Annex III, Point 6(b))",
|
| 729 |
+
"developer_name": "EuroForensics Software Solutions",
|
| 730 |
+
"deployment_context": "Judicial Police Digital Forensic Laboratory"
|
| 731 |
+
},
|
| 732 |
+
"raw_document_text": """# LexEvidence Digital Forensic Media Search Specification
|
| 733 |
+
|
| 734 |
+
## Intended Use and Scope
|
| 735 |
+
LexEvidence AI is an investigative digital forensic tool utilized by European police and judicial authorities. The system indexes legally seized video evidence (such as CCTV recovered after a crime has occurred) to assist detectives in locating specific vehicle license plates or timestamped incidents.
|
| 736 |
+
|
| 737 |
+
## Statutory Purpose & Exclusions
|
| 738 |
+
The system is used exclusively for targeted, ex-post retrospective forensic examination under a specific judicial warrant issued by a magistrate. It does not perform real-time biometric identification, predictive policing, or citizen profiling.
|
| 739 |
+
|
| 740 |
+
## Risk Management (Article 9)
|
| 741 |
+
A documented risk management system is implemented in compliance with Article 9 and Directive (EU) 2016/680 (Law Enforcement Directive). Fundamental rights risk assessments evaluate rights to privacy, fair trial, and presumption of innocence.
|
| 742 |
+
|
| 743 |
+
## Data Governance & Training Lineage (Article 10)
|
| 744 |
+
Training data provenance and data governance protocols are documented using synthetic and non-personal optical test patterns. Seized evidential media is processed in isolated, air-gapped forensic environments with cryptographic SHA-256 chain-of-custody verification.
|
| 745 |
+
|
| 746 |
+
## Bias Examination & Mitigation (Article 10(2)(f))
|
| 747 |
+
Bias examination and bias mitigation controls are verified and implemented. Optical character recognition (OCR) sensitivity for license plate identification was verified across all European member state font standards with uniform 99.1% accuracy and zero disparate impact.
|
| 748 |
+
|
| 749 |
+
## Technical Documentation (Article 11)
|
| 750 |
+
Full Annex IV technical documentation and forensic validation whitepapers are maintained and presented to criminal courts for expert testimony admissibility.
|
| 751 |
+
|
| 752 |
+
## Record-Keeping & Automated Logging (Article 12)
|
| 753 |
+
Automated logging records every detective query, search term, and extracted video clip with digital signatures and timestamped judicial warrant reference numbers. Logs cannot be modified or purged by investigating officers.
|
| 754 |
+
|
| 755 |
+
## Transparency (Article 13)
|
| 756 |
+
The system outputs transparent similarity confidence scores and bounding boxes showing exact image regions corresponding to search matches. Comprehensive user manuals describe forensic limitations to public prosecutors.
|
| 757 |
+
|
| 758 |
+
## Human Oversight (Article 14)
|
| 759 |
+
Human oversight is absolute. A manual override and detective review are enforced for every forensic query. AI search hits constitute leads requiring independent forensic detective verification and formal cross-examination before submission to a court of law.
|
| 760 |
+
|
| 761 |
+
## Accuracy, Robustness and Cybersecurity (Article 15)
|
| 762 |
+
The system is deployed on air-gapped, TEMPEST-shielded workstations certified under national law enforcement cybersecurity standards. Robustness testing under noise and cybersecurity controls against evidence tampering are verified and implemented.""",
|
| 763 |
+
"statutory_quote": "AI systems intended to be used by law enforcement authorities or on their behalf to assess the risk of a natural person offending or re-offending, or to evaluate the reliability of evidence in the course of investigation or prosecution of criminal offences.",
|
| 764 |
+
"regulatory_requirements": {
|
| 765 |
+
"mandatory_articles": ["Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15"],
|
| 766 |
+
"harmonized_frameworks": {
|
| 767 |
+
"nist_ai_rmf": ["GOVERN-1.1", "MAP-2.3", "MEASURE-2.11", "MANAGE-3.2"],
|
| 768 |
+
"iso_42001": ["Control A.6.2", "Control A.8.4", "Control A.9.2"],
|
| 769 |
+
"gdpr": ["Directive (EU) 2016/680 (LED)", "Charter of Fundamental Rights Art 47"]
|
| 770 |
+
},
|
| 771 |
+
"conformity_procedure": "Annex VI: Internal Control Assessment under Judicial Supervision",
|
| 772 |
+
"fine_exposure_tier": "Tier 2 (€15,000,000 or 3% global turnover)"
|
| 773 |
+
},
|
| 774 |
+
"auditor_guidance": {
|
| 775 |
+
"intended_purpose": "Retrospective forensic search of lawfully obtained digital evidence.",
|
| 776 |
+
"common_pitfalls": "Creeping into predictive policing or real-time public biometric surveillance; lack of judicial warrant verification.",
|
| 777 |
+
"remediation_guidance": "Verify strict air-gapped chain-of-custody logging and explicit human forensic investigator confirmation."
|
| 778 |
+
}
|
| 779 |
+
},
|
| 780 |
+
|
| 781 |
+
# =========================================================================
|
| 782 |
+
# 12. 🚫 Prohibited AI Practices (Article 5 - Zero Tolerance)
|
| 783 |
+
# =========================================================================
|
| 784 |
+
{
|
| 785 |
+
"domain_id": "prohibited_practices",
|
| 786 |
+
"case_id": "prohibited_biometric_categorization_beliefs",
|
| 787 |
+
"title": "BioClassify - CCTV Biometric Categorization of Political Beliefs",
|
| 788 |
+
"system_id": "prohibited-bioclass-04",
|
| 789 |
+
"statutory_tier": "Prohibited AI Practice (Article 5(1)(c) - Absolute Ban)",
|
| 790 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(c)",
|
| 791 |
+
"expected_conformity": "PROHIBITED (ARTICLE 5 VIOLATION)",
|
| 792 |
+
"metadata": {
|
| 793 |
+
"system_id": "prohibited-bioclass-04",
|
| 794 |
+
"name": "BioClassify Biometric Belief Profiler",
|
| 795 |
+
"version": "1.0.0",
|
| 796 |
+
"domain": "Public Administration & Civic Scoring",
|
| 797 |
+
"intended_purpose": "Analyzing public CCTV facial video feeds to biometrically deduce individuals' political affiliations and religious beliefs.",
|
| 798 |
+
"eu_risk_classification": "Prohibited (Article 5(1)(c))",
|
| 799 |
+
"developer_name": "OmniSurveil Analytics Ltd",
|
| 800 |
+
"deployment_context": "Public Space Surveillance Network"
|
| 801 |
+
},
|
| 802 |
+
"raw_document_text": """# BioClassify Biometric Belief Profiling Specification
|
| 803 |
+
|
| 804 |
+
## Intended Use and Scope
|
| 805 |
+
BioClassify is an experimental computer vision system designed to connect to public surveillance cameras in urban centers. The system processes facial imagery and gait dynamics to infer citizens' political leanings, philosophical beliefs, and religious affiliations.
|
| 806 |
+
|
| 807 |
+
## Prohibited Practice Determination (Article 5(1)(c))
|
| 808 |
+
Regulation (EU) 2024/1689 Article 5(1)(c) explicitly and unambiguously prohibits:
|
| 809 |
+
'the placing on the market, the putting into service for this purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, as well as biometric categorization systems that categorize natural persons based on their biometric data to deduce or infer their political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.'
|
| 810 |
+
|
| 811 |
+
## System Functionality & Prohibited Processing
|
| 812 |
+
The model categorizes pedestrians passing through municipal squares into political alignment scores ('Right-leaning', 'Left-leaning', 'Protest Sympathizer') based on clothing symbols, facial geometry, and expression micro-tremors.
|
| 813 |
+
|
| 814 |
+
## Compliance Determination
|
| 815 |
+
This AI system violates fundamental rights to freedom of thought, conscience, and religion (Article 10 of the Charter) and freedom of expression and assembly (Articles 11 and 12). It is categorically prohibited from being marketed, tested, or deployed in the European Union.""",
|
| 816 |
+
"statutory_quote": "The following AI practices shall be prohibited: the placing on the market, the putting into service for this purpose, or use of biometric categorization systems that categorize individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.",
|
| 817 |
+
"regulatory_requirements": {
|
| 818 |
+
"mandatory_articles": ["Article 5(1)(c)"],
|
| 819 |
+
"harmonized_frameworks": {
|
| 820 |
+
"nist_ai_rmf": ["GOVERN-1.1 Prohibited Harm"],
|
| 821 |
+
"iso_42001": ["Zero-Tolerance Ban"],
|
| 822 |
+
"gdpr": ["Article 9 Special Category Data Prohibition"]
|
| 823 |
+
},
|
| 824 |
+
"conformity_procedure": "Prohibited under Union law. Immediate permanent ban and market removal mandated.",
|
| 825 |
+
"fine_exposure_tier": "Tier 1 (€35,000,000 or 7% global turnover)"
|
| 826 |
+
},
|
| 827 |
+
"auditor_guidance": {
|
| 828 |
+
"intended_purpose": "Inferring political or religious beliefs from facial or biometric surveillance.",
|
| 829 |
+
"common_pitfalls": "Claiming biometric categorization is permissible under 'smart city analytics' or 'demographic foot-traffic research'.",
|
| 830 |
+
"remediation_guidance": "Immediate cessation of processing; deletion of all biometric model weights; mandatory report to Data Protection Authority and EU AI Office."
|
| 831 |
+
}
|
| 832 |
+
},
|
| 833 |
+
# =========================================================================
|
| 834 |
+
# 13. 🟢 Minimal / Low Risk (Voluntary Codes of Conduct)
|
| 835 |
+
# =========================================================================
|
| 836 |
+
{
|
| 837 |
+
"domain_id": "minimal_risk",
|
| 838 |
+
"case_id": "compliant_warehouse_logistics_optimizer",
|
| 839 |
+
"title": "PathMatrix AI - Autonomous Warehouse Forklift Route Dispatcher",
|
| 840 |
+
"system_id": "minimal-logistics-02",
|
| 841 |
+
"statutory_tier": "Minimal Risk (Voluntary Code of Conduct - Article 95)",
|
| 842 |
+
"legal_basis": "Regulation (EU) 2024/1689, Article 95",
|
| 843 |
+
"expected_conformity": "CONFORMANT (PASSED)",
|
| 844 |
+
"metadata": {
|
| 845 |
+
"system_id": "minimal-logistics-02",
|
| 846 |
+
"name": "PathMatrix Logistics Route Optimizer",
|
| 847 |
+
"version": "1.2.0",
|
| 848 |
+
"domain": "Minimal Risk Industrial Optimization",
|
| 849 |
+
"intended_purpose": "Optimizing spatial movement routes and battery recharging schedules for industrial electric forklifts inside private logistics warehouses.",
|
| 850 |
+
"eu_risk_classification": "Minimal Risk (Article 95)",
|
| 851 |
+
"developer_name": "LogiOptima Robotics AB",
|
| 852 |
+
"deployment_context": "Private Industrial Fulfillment Facility"
|
| 853 |
+
},
|
| 854 |
+
"raw_document_text": """# PathMatrix Logistics Route Optimizer Model Specification
|
| 855 |
+
|
| 856 |
+
## Intended Use and Scope
|
| 857 |
+
PathMatrix AI is an industrial optimization algorithm deployed in enclosed e-commerce fulfillment centers. The model calculates energy-efficient transit routes and pallet staging queues for electric forklifts.
|
| 858 |
+
|
| 859 |
+
## Regulatory Risk Classification (Title I & Annex III)
|
| 860 |
+
The system operates exclusively on non-personal spatial telemetry (rack coordinates, pallet weight, battery charge levels). It does not monitor employee performance, does not control high-risk safety components, and does not fall under any high-risk category of Annex III.
|
| 861 |
+
|
| 862 |
+
## Voluntary Governance & Code of Conduct (Article 95)
|
| 863 |
+
Although exempt from mandatory high-risk requirements, the provider voluntarily adheres to a Union Code of Conduct under Article 95:
|
| 864 |
+
1. Environmental sustainability reporting: Route optimization reduces facility electricity consumption by 14.2%.
|
| 865 |
+
2. Reliability & testing: Rigorous simulated trajectory collision avoidance was verified in physics engine simulations.
|
| 866 |
+
3. AI Literacy (Article 4): Warehouse floor supervisors receive training on operational handoffs and manual route assignment.
|
| 867 |
+
|
| 868 |
+
## Human Oversight
|
| 869 |
+
Warehouse shift managers maintain manual fleet dispatch override capabilities at all times.""",
|
| 870 |
+
"statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Title III, Chapter 2.",
|
| 871 |
+
"regulatory_requirements": {
|
| 872 |
+
"mandatory_articles": ["Article 4 AI Literacy", "Article 95 Codes of Conduct"],
|
| 873 |
+
"harmonized_frameworks": {
|
| 874 |
+
"nist_ai_rmf": ["GOVERN-1.1"],
|
| 875 |
+
"iso_42001": ["Voluntary Alignment"],
|
| 876 |
+
"gdpr": ["Non-Personal Data Processing"]
|
| 877 |
+
},
|
| 878 |
+
"conformity_procedure": "Exempt from mandatory third-party assessment; voluntary code of conduct adhesion.",
|
| 879 |
+
"fine_exposure_tier": "None (Compliant Minimal Risk)"
|
| 880 |
+
},
|
| 881 |
+
"auditor_guidance": {
|
| 882 |
+
"intended_purpose": "Internal spatial route optimization for warehouse machinery.",
|
| 883 |
+
"common_pitfalls": "Creeping into worker monitoring if vehicle telemetry is used to evaluate forklift driver speed or productivity without labor consultation.",
|
| 884 |
+
"remediation_guidance": "Ensure operational logs isolate vehicle mechanical stats from driver personal IDs."
|
| 885 |
+
}
|
| 886 |
+
}
|
| 887 |
+
]
|
| 888 |
+
|
| 889 |
+
|
| 890 |
+
def run():
|
| 891 |
+
print(f"Loading existing catalog from {CATALOG_PATH}...")
|
| 892 |
+
cat_data = json.loads(CATALOG_PATH.read_text(encoding="utf-8"))
|
| 893 |
+
|
| 894 |
+
# Map domains by id
|
| 895 |
+
domain_map = {d["domain_id"]: d for d in cat_data.get("domains", [])}
|
| 896 |
+
|
| 897 |
+
added_count = 0
|
| 898 |
+
for case in NEW_CASES:
|
| 899 |
+
case_id = case["case_id"]
|
| 900 |
+
dom_id = case["domain_id"]
|
| 901 |
+
|
| 902 |
+
if dom_id not in domain_map:
|
| 903 |
+
print(f"Warning: Domain {dom_id} not found in catalog. Skipping {case_id}...")
|
| 904 |
+
continue
|
| 905 |
+
|
| 906 |
+
target_domain = domain_map[dom_id]
|
| 907 |
+
|
| 908 |
+
# Check if already present
|
| 909 |
+
existing_cases = target_domain.setdefault("case_studies", [])
|
| 910 |
+
if any(c["case_id"] == case_id for c in existing_cases):
|
| 911 |
+
print(f"Case {case_id} already exists in domain {dom_id}. Updating...")
|
| 912 |
+
existing_cases = [c for c in existing_cases if c["case_id"] != case_id]
|
| 913 |
+
target_domain["case_studies"] = existing_cases
|
| 914 |
+
|
| 915 |
+
# 1. Write the synthetic system file
|
| 916 |
+
spec_filename = f"{case_id}.json"
|
| 917 |
+
spec_path = SYNTHETIC_DIR / spec_filename
|
| 918 |
+
rel_spec_path = f"data/synthetic_systems/{spec_filename}"
|
| 919 |
+
|
| 920 |
+
spec_content = {
|
| 921 |
+
"metadata": case["metadata"],
|
| 922 |
+
"raw_document_text": case["raw_document_text"].strip()
|
| 923 |
+
}
|
| 924 |
+
spec_bytes = json.dumps(spec_content, indent=2).encode("utf-8")
|
| 925 |
+
spec_path.write_bytes(spec_bytes)
|
| 926 |
+
|
| 927 |
+
# Compute SHA-256 digests
|
| 928 |
+
spec_file_sha256 = hashlib.sha256(spec_bytes).hexdigest()
|
| 929 |
+
statutory_quote_sha256 = hashlib.sha256(case["statutory_quote"].encode("utf-8")).hexdigest()
|
| 930 |
+
|
| 931 |
+
# 2. Build catalog entry
|
| 932 |
+
catalog_entry = {
|
| 933 |
+
"case_id": case_id,
|
| 934 |
+
"title": case["title"],
|
| 935 |
+
"system_id": case["system_id"],
|
| 936 |
+
"statutory_tier": case["statutory_tier"],
|
| 937 |
+
"legal_basis": case["legal_basis"],
|
| 938 |
+
"expected_conformity": case["expected_conformity"],
|
| 939 |
+
"file_path": rel_spec_path,
|
| 940 |
+
"statutory_quote": case["statutory_quote"],
|
| 941 |
+
"regulatory_requirements": case["regulatory_requirements"],
|
| 942 |
+
"auditor_guidance": case["auditor_guidance"],
|
| 943 |
+
"file_sha256": spec_file_sha256,
|
| 944 |
+
"provenance": {
|
| 945 |
+
"statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council",
|
| 946 |
+
"official_journal": "OJ L, 2024/1689, 12.7.2024",
|
| 947 |
+
"eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
|
| 948 |
+
"celex": "32024R1689",
|
| 949 |
+
"statutory_quote": case["statutory_quote"],
|
| 950 |
+
"statutory_quote_sha256": statutory_quote_sha256,
|
| 951 |
+
"spec_file_sha256": spec_file_sha256,
|
| 952 |
+
"prov_o_entity": f"urn:reguai:benchmark:case:{case_id}",
|
| 953 |
+
"author": "ReguAI Regulatory Engineering Working Group",
|
| 954 |
+
"verification_method": "W3C PROV-O & SHA-256 Canonical Digest",
|
| 955 |
+
"timestamp": "2026-09-21T16:00:00Z"
|
| 956 |
+
}
|
| 957 |
+
}
|
| 958 |
+
|
| 959 |
+
existing_cases.append(catalog_entry)
|
| 960 |
+
added_count += 1
|
| 961 |
+
print(f"Added [{case_id}] '{case['title']}' to domain '{target_domain['domain_name']}' (SHA256: {spec_file_sha256[:10]}...)")
|
| 962 |
+
|
| 963 |
+
# Save updated catalog
|
| 964 |
+
CATALOG_PATH.write_text(json.dumps(cat_data, indent=2), encoding="utf-8")
|
| 965 |
+
print(f"\nSuccessfully added/updated {added_count} benchmark case studies in {CATALOG_PATH}!")
|
| 966 |
+
|
| 967 |
+
|
| 968 |
+
if __name__ == "__main__":
|
| 969 |
+
run()
|
src/extraction/gliner_extractor.py
CHANGED
|
@@ -72,10 +72,10 @@ class RegulatoryClaimExtractor:
|
|
| 72 |
],
|
| 73 |
},
|
| 74 |
EntityCategory.TRANSPARENCY: {
|
| 75 |
-
"article": "Article 13",
|
| 76 |
"keywords": [
|
| 77 |
-
r"\b(instructions\s+for\s+use|transparency\s+disclosure|model\s+card)\b",
|
| 78 |
-
r"\b(intended\s+purpose|system\s+capabilities|operational\s+limitations)\b",
|
| 79 |
],
|
| 80 |
},
|
| 81 |
EntityCategory.ACCURACY_ROBUSTNESS: {
|
|
|
|
| 72 |
],
|
| 73 |
},
|
| 74 |
EntityCategory.TRANSPARENCY: {
|
| 75 |
+
"article": "Article 13 / Art 50",
|
| 76 |
"keywords": [
|
| 77 |
+
r"\b(instructions\s+for\s+use|transparency\s+disclosure|transparency\s+obligation|model\s+card)\b",
|
| 78 |
+
r"\b(intended\s+purpose|system\s+capabilities|operational\s+limitations|disclose(?:s)?\s+(?:to\s+consumers|that|users))\b",
|
| 79 |
],
|
| 80 |
},
|
| 81 |
EntityCategory.ACCURACY_ROBUSTNESS: {
|
src/extraction/parser.py
CHANGED
|
@@ -79,42 +79,42 @@ class SpecificationParser:
|
|
| 79 |
|
| 80 |
# Dynamic Domain Detection
|
| 81 |
domain = "High-Risk AI System"
|
| 82 |
-
if re.search(r"\b(
|
|
|
|
|
|
|
| 83 |
domain = "Healthcare & Medical Diagnostics"
|
| 84 |
-
elif re.search(r"\b(recruitment|employment|cv|resume|interview|workplace)\b", raw_markdown, re.I):
|
| 85 |
domain = "Employment & HR Screening"
|
| 86 |
-
elif re.search(r"\b(credit|loan|financial|underwriting|banking)\b", raw_markdown, re.I):
|
| 87 |
domain = "Financial Services & Credit Scoring"
|
| 88 |
-
elif re.search(r"\b(automotive|transport|braking|vehicle)\b", raw_markdown, re.I):
|
| 89 |
domain = "Automotive & Road Transport Safety"
|
| 90 |
-
elif re.search(r"\b(grid|
|
| 91 |
domain = "Critical Infrastructure & Energy Management"
|
| 92 |
-
elif re.search(r"\b(education|proctoring|exam|student|cheating)\b", raw_markdown, re.I):
|
| 93 |
domain = "Education & Vocational Training"
|
| 94 |
-
elif re.search(r"\b(justice|recidivism|court|bail|law
|
| 95 |
domain = "Law Enforcement & Criminal Justice"
|
| 96 |
-
elif re.search(r"\b(
|
| 97 |
-
domain = "General Purpose AI & Frontier Models"
|
| 98 |
-
elif re.search(r"\b(social scoring|trustworthiness|civic score)\b", raw_markdown, re.I):
|
| 99 |
domain = "Public Administration & Civic Scoring"
|
| 100 |
-
elif re.search(r"\b(chatbot|conversational|support
|
| 101 |
domain = "Customer Support & Conversational AI"
|
| 102 |
-
elif re.search(r"\b(spam|phishing|email
|
| 103 |
-
domain = "Enterprise Cybersecurity &
|
| 104 |
|
| 105 |
# Dynamic Statutory Risk Classification
|
| 106 |
risk_class = "High-Risk (Annex III)"
|
| 107 |
-
if re.search(r"\b(
|
|
|
|
|
|
|
| 108 |
risk_class = "Prohibited (Article 5)"
|
| 109 |
-
elif re.search(r"\b(systemic
|
| 110 |
risk_class = "GPAI with Systemic Risk (Article 51)"
|
| 111 |
-
elif re.search(r"\b(general
|
| 112 |
risk_class = "GPAI Model (Article 53)"
|
| 113 |
-
elif re.search(r"\b(limited
|
| 114 |
risk_class = "Limited Risk (Article 50)"
|
| 115 |
-
elif re.search(r"\b(
|
| 116 |
-
risk_class = "Minimal / No Statutory Risk"
|
| 117 |
-
elif re.search(r"\b(annex i|automotive safety component|article 6\(1\)|medical device|mdr)\b", raw_markdown, re.I):
|
| 118 |
risk_class = "High-Risk (Annex I / Article 6(1))"
|
| 119 |
|
| 120 |
metadata = SystemMetadata(
|
|
|
|
| 79 |
|
| 80 |
# Dynamic Domain Detection
|
| 81 |
domain = "High-Risk AI System"
|
| 82 |
+
if re.search(r"\b(gpai|frontier|foundation\s+model|llm|language\s+model)\b", raw_markdown, re.I):
|
| 83 |
+
domain = "General Purpose AI & Frontier Models"
|
| 84 |
+
elif re.search(r"\b(medical|clinical|diagnostic|radiology|samd|oncology|dermatolog|cardiac|arrhythmia)\b", raw_markdown, re.I):
|
| 85 |
domain = "Healthcare & Medical Diagnostics"
|
| 86 |
+
elif re.search(r"\b(recruitment|employment|cv|resume|interview|workplace|workforce)\b", raw_markdown, re.I):
|
| 87 |
domain = "Employment & HR Screening"
|
| 88 |
+
elif re.search(r"\b(credit|loan|financial|underwriting|banking|mortgage)\b", raw_markdown, re.I):
|
| 89 |
domain = "Financial Services & Credit Scoring"
|
| 90 |
+
elif re.search(r"\b(automotive|transport|braking|vehicle|adas|lane\s+keeping)\b", raw_markdown, re.I):
|
| 91 |
domain = "Automotive & Road Transport Safety"
|
| 92 |
+
elif re.search(r"\b(smart\s+grid|power\s+grid|load\s+shedding|scada|water\s+chlorination|water\s+treatment)\b", raw_markdown, re.I):
|
| 93 |
domain = "Critical Infrastructure & Energy Management"
|
| 94 |
+
elif re.search(r"\b(education|proctoring|exam|student|cheating|stem\s+learning|adaptivemath)\b", raw_markdown, re.I):
|
| 95 |
domain = "Education & Vocational Training"
|
| 96 |
+
elif re.search(r"\b(justice|recidivism|court|bail|law\s+enforcement|forensic|lexevidence)\b", raw_markdown, re.I):
|
| 97 |
domain = "Law Enforcement & Criminal Justice"
|
| 98 |
+
elif re.search(r"\b(social\s+scoring|trustworthiness|civic\s+score|subliminal|biometric\s+categorization)\b", raw_markdown, re.I):
|
|
|
|
|
|
|
| 99 |
domain = "Public Administration & Civic Scoring"
|
| 100 |
+
elif re.search(r"\b(chatbot|conversational|support\s+agent|video\s+avatar|virtual\s+presenter|deepfake)\b", raw_markdown, re.I):
|
| 101 |
domain = "Customer Support & Conversational AI"
|
| 102 |
+
elif re.search(r"\b(spam|phishing|email\s+security|warehouse\s+logistics|forklift|pallet)\b", raw_markdown, re.I):
|
| 103 |
+
domain = "Enterprise Cybersecurity & Industrial Optimization"
|
| 104 |
|
| 105 |
# Dynamic Statutory Risk Classification
|
| 106 |
risk_class = "High-Risk (Annex III)"
|
| 107 |
+
if re.search(r"\b(minimal\s*/\s*low\s+risk|minimal\s+risk|voluntary\s+codes?\s+of\s+conduct|article\s+95\b)\b", raw_markdown, re.I) and not re.search(r"\b(prohibited|strictly\s+prohibited|unacceptable\s+risk)\b", raw_markdown, re.I):
|
| 108 |
+
risk_class = "Minimal / No Statutory Risk"
|
| 109 |
+
elif re.search(r"\b(prohibited|social\s+scoring|emotion\s+recognition|subliminal|biometric\s+categorization|article\s+5\b)", raw_markdown, re.I):
|
| 110 |
risk_class = "Prohibited (Article 5)"
|
| 111 |
+
elif re.search(r"\b(systemic\s+risk|article\s+51|10\^25|frontier\s+foundation)\b", raw_markdown, re.I):
|
| 112 |
risk_class = "GPAI with Systemic Risk (Article 51)"
|
| 113 |
+
elif re.search(r"\b(general\s+purpose|gpai\s+model|article\s+53)\b", raw_markdown, re.I):
|
| 114 |
risk_class = "GPAI Model (Article 53)"
|
| 115 |
+
elif re.search(r"\b(limited\s+risk|article\s+50|transparency\s+obligations?|deep\s*fake|synthetic\s+media)\b", raw_markdown, re.I):
|
| 116 |
risk_class = "Limited Risk (Article 50)"
|
| 117 |
+
elif re.search(r"\b(annex\s+i|automotive\s+safety\s+component|article\s+6\(1\)|medical\s+device|mdr)\b", raw_markdown, re.I):
|
|
|
|
|
|
|
| 118 |
risk_class = "High-Risk (Annex I / Article 6(1))"
|
| 119 |
|
| 120 |
metadata = SystemMetadata(
|
tests/test_case_catalog.py
CHANGED
|
@@ -110,3 +110,32 @@ def test_prohibited_social_scoring_fails_with_tier_1_fine(engine, catalog):
|
|
| 110 |
else:
|
| 111 |
assert report.fine_exposure.highest_tier_triggered == "TIER_1_PROHIBITED_AI"
|
| 112 |
assert report.fine_exposure.applicable_ceiling_eur == 35_000_000.0
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 110 |
else:
|
| 111 |
assert report.fine_exposure.highest_tier_triggered == "TIER_1_PROHIBITED_AI"
|
| 112 |
assert report.fine_exposure.applicable_ceiling_eur == 35_000_000.0
|
| 113 |
+
|
| 114 |
+
|
| 115 |
+
def test_expanded_catalog_coverage(catalog):
|
| 116 |
+
"""Verify that all 11 regulatory domains have at least 2 case studies."""
|
| 117 |
+
domains = catalog.list_domains()
|
| 118 |
+
assert len(domains) == 11
|
| 119 |
+
total_cases = 0
|
| 120 |
+
for dom in domains:
|
| 121 |
+
cases = dom.get("case_studies", [])
|
| 122 |
+
total_cases += len(cases)
|
| 123 |
+
assert len(cases) >= 2, f"Domain {dom['domain_id']} has fewer than 2 cases: {len(cases)}"
|
| 124 |
+
assert total_cases >= 24
|
| 125 |
+
|
| 126 |
+
|
| 127 |
+
def test_cardiac_triage_samd_conforms(engine, catalog):
|
| 128 |
+
doc_text = catalog.get_case_document_text("compliant_cardiac_triage_samd")
|
| 129 |
+
assert len(doc_text) > 0
|
| 130 |
+
report = engine.evaluate_system(doc_text)
|
| 131 |
+
assert report.overall_conforms is True
|
| 132 |
+
assert report.conformity_score == 100.0
|
| 133 |
+
|
| 134 |
+
|
| 135 |
+
def test_derma_diagnostics_fails(engine, catalog):
|
| 136 |
+
doc_text = catalog.get_case_document_text("non_compliant_derma_diagnostics")
|
| 137 |
+
assert len(doc_text) > 0
|
| 138 |
+
report = engine.evaluate_system(doc_text)
|
| 139 |
+
assert report.overall_conforms is False
|
| 140 |
+
assert len(report.violations) > 0
|
| 141 |
+
|