Skip to contentThe Observability LayerSearch
← Enterprise handbook

Edition 2.1 · Reviewed 2 October 2026

Connect the control
to the requirement.

Find the relevant rule or guidance, understand when it applies, and see what evidence makes the safeguard useful.

169 distinct items17 selected instruments30 explanations

Scope first. Evidence next.

Choose your jurisdiction, entity, decision and role before relying on a mapping. The 45 handbook practices, 12 specifications and 112 July compendium controls retain separate identities. Each relationship is an editorial interpretation of how a proposed safeguard can contribute; it is not a compliance verdict.

Support if applicable · scoped law, rules or supervisory expectationsGuidance alignment · published voluntary or regulator guidanceUpstream provider duty · model provider obligation; request its evidenceIndustry reference · industry white paperScope-level alignment · public ISO scope; clauses and conformity not inspectedDomain analogy · transferable discipline outside agentic scopeDraft alignment · consultation text

A blank cell means no relationship selected. It does not establish an exemption. Inspect versions, timing and applicability ↓

Find and compare controls.

169 items · showing 12

Source key and applicability ↓

Compare selected source abbreviations across jurisdictions. Open an explanation for the provisions and evidence. Filters are saved in the URL.

Selected regulatory relationships by control and jurisdiction
Item and control familyEUUKUSSingaporeHong KongGlobal

Handbook practice · GOV

H-GOV-01 Named mandate

Handbook practice · GOV

H-GOV-02 Impact and legal scope
—

Handbook practice · GOV

H-GOV-03 Decision rights

Handbook practice · GOV

H-GOV-04 Risk and exceptions
—

Handbook practice · GOV

H-GOV-05 Training and adoption
—

Handbook practice · DES

H-DES-01 Configuration identity
—

Handbook practice · DES

H-DES-02 Independent authority
——

Handbook practice · DES

H-DES-03 Data and source purpose
—

Handbook practice · DES

H-DES-04 Memory stewardship
—

Handbook practice · DES

H-DES-05 Failure and recovery design
—

Handbook practice · EVL

H-EVL-01 Decision and oracle
—

Handbook practice · EVL

H-EVL-02 Representative tasks
—

Handbook practice · GOV

H-GOV-01: Named mandate

Singapore
Hong Kong
Global

Handbook practice · GOV

H-GOV-02: Impact and legal scope

Singapore
Hong Kong
—
Global

Handbook practice · GOV

H-GOV-03: Decision rights

Singapore
Hong Kong
Global

Handbook practice · GOV

H-GOV-04: Risk and exceptions

UK
Singapore
Hong Kong
—
Global

Handbook practice · GOV

H-GOV-05: Training and adoption

UK
—
Singapore
Hong Kong
Global

Handbook practice · DES

H-DES-01: Configuration identity

UK
Singapore
Hong Kong
—
Global

Handbook practice · DES

H-DES-02: Independent authority

UK
—
US
—
Singapore
Hong Kong
Global

Handbook practice · DES

H-DES-03: Data and source purpose

UK
—
US
Singapore
Hong Kong
Global

Handbook practice · DES

H-DES-04: Memory stewardship

EU
UK
—
US
Singapore
Hong Kong
Global

Handbook practice · DES

H-DES-05: Failure and recovery design

UK
US
—
Singapore
Hong Kong
Global

Handbook practice · EVL

H-EVL-01: Decision and oracle

EU
UK
US
Singapore
Hong Kong
—
Global

Handbook practice · EVL

H-EVL-02: Representative tasks

EU
Singapore
Hong Kong
—
Global

Take the comparison into your work.

The full cross-tab has one column per instrument. The explanation table expands every item into its provisions, rationale, evidence and applicability.

Cross-tab spreadsheet ↓Explanation table ↓Source register ↓
Read Appendix K in the complete PDF or manuscript →

Primary evidence

Versions, status and applicability.

Reviewed 2 October 2026. Next monthly review due 1 November 2026. Monthly reference updates supplement this dated edition; they do not silently revise its legal map.

R01 · EU · EU

EU AI Act — Regulation (EU) 2024/1689 ↗

Binding law

Commission consolidated-text explorer, 27 July 2026

Applies to
EU-market providers, deployers and other covered operators; classify intended use and role first.
Timing
Literacy/prohibitions: February 2025 (some new prohibitions December 2026); GPAI: August 2025; Article 50: August 2026; Annex III high-risk Chapter III duties: 2 December 2027; Annex I: 2 August 2028.
Interpretation limit
Article 27 covers specified deployers; Articles 53/55 cover model providers, not every user of a model. Other articles and transitional arrangements have their own dates. The explorer identifies July 2026 amendments; the linked Official Journal is controlling.

R02 · GD · EU

GDPR — Regulation (EU) 2016/679 ↗

Binding law

Official consolidated text: CELEX 02016R0679-20160504; reviewed 2 October 2026

Applies to
Personal-data processing within Articles 2/3; controller and processor duties differ.
Timing
Applicable since 25 May 2018. Article 22 concerns solely automated decisions with legal or similarly significant effects, subject to exceptions and safeguards.

R03 · DO · EU

DORA — Regulation (EU) 2022/2554 ↗

Binding law

Core regulation and official rulebook

Applies to
Financial entities listed in Article 2; check exclusions, proportionality and the simplified framework.
Timing
Applicable since 17 January 2025; reporting classifications, clocks and templates also depend on delegated/implementing rules.
Interpretation limit
ICT resilience duties do not by themselves define fairness or AI conformity requirements. This map selects core articles, not every technical standard.

R04 · FC · UK

FCA Consumer Duty — PRIN 2A ↗

Binding rules and guidance

Live Handbook, including June 2026 updates

Applies to
FCA firms and retail business in the Duty’s scope; account for position in the distribution chain.
Timing
Current rules apply to covered business. R paragraphs are rules; G paragraphs explain their application.

R05 · PR · UK

PRA model risk management — SS1/23 ↗

Supervisory expectations

April 2026 revision

Applies to
UK-incorporated banks, building societies and PRA-designated investment firms with internal-model capital approval; model definition and materiality still matter.
Timing
Policy began 17 May 2024; April 2026 revision inspected. Annual self-assessment expectations remain.
Interpretation limit
Branches, firms without internal-model approval, credit unions, insurers and reinsurers are outside the stated scope. For others these disciplines are an analogy, not a new agent-specific mandate.

R06 · RB · US

ECOA / Regulation B ↗

Binding regulation

Current CFPB rule text

Applies to
Creditors and covered credit decisions; notification procedures and exceptions vary by application and applicant.
Timing
Current §§1002.4 and 1002.9. Use the rule and its official interpretation; do not rely on withdrawn AI circulars.

R07 · CA · US

California CCPA — ADMT and risk assessments ↗

Binding regulation

Final approved 2025 text; effective 2026

Applies to
CCPA businesses and covered processing; ADMT significant-decision definition, exemptions and opt-out exceptions are specific.
Timing
Regulations effective 1 January 2026. Article 11 ADMT compliance: 1 January 2027. Article 10 risk assessments and cyber-audit schedules differ.
Interpretation limit
An appeal is one qualified opt-out exception; meaningful human involvement has a defined competence, analysis and authority test.

R08 · CO · US

Colorado SB26-189 — covered ADMT ↗

Enacted law; future duties

Signed 14 May 2026

Applies to
Developers/deployers of ADMT materially influencing specified consequential decisions; statutory exemptions require review.
Timing
Covered duties start 1 January 2027. Attorney General implementing rules were proposed in August 2026; proposals are not enacted requirements.
Interpretation limit
This entry maps the General Assembly’s official enacted summary by named duty, not numbered statutory clauses. It does not reuse the superseded SB24-205 impact-assessment regime.

R09 · SR · US

US interagency model risk guidance — SR 26-2 ↗

Supervisory guidance

17 April 2026; supersedes SR 11-7 and SR 21-8

Applies to
Covered banking organisations and qualifying traditional statistical/quantitative and non-generative, non-agentic AI models.
Timing
Current guidance. Attachment footnote 3 explicitly excludes generative and agentic AI models.
Interpretation limit
Every agent mapping here is marked analogy. Relevant traditional model components can separately be in scope. Guidance does not establish enforceable standards.

R10 · IM · Singapore

IMDA Model AI Governance Framework for Agentic AI ↗

Voluntary guidance

Version 1.5, 20 May 2026; updated 5 June 2026

Applies to
Organisations deploying agents; practical cross-sector design guidance.
Timing
Published guidance; not a generally binding AI statute.

R11 · SF · Singapore

MAS / industry SAFR ↗

Voluntary industry white paper

Version 1.0, July 2026

Applies to
Agentic financial workflows; runtime authorisation and review design.
Timing
Published 3 July 2026. A proposed reference approach, not a new binding MAS rule.

R12 · HK · Hong Kong

PCPD guidance on agentic AI and personal data ↗

Regulator guidance

25 August 2026

Applies to
Data users processing personal data with agents; underlying PDPO duties remain binding.
Timing
Current agent-specific supplement to the 2024 Model Framework.
Interpretation limit
Mappings cite the nine recommendations and checklist. DPP references explain the law discussed by the guidance; this column does not convert every recommendation into a statutory requirement.

R13 · NI · Global

NIST AI Risk Management Framework ↗

Voluntary framework

AI RMF 1.0, January 2023

Applies to
Organisations managing AI risk across the lifecycle.
Timing
Published core framework; a revision initiative or concept note does not replace this baseline.

R14 · NG · Global

NIST Generative AI Profile ↗

Voluntary framework

NIST AI 600-1, July 2024

Applies to
Generative AI uses, components and supply chains; contextualise the profile to the complete agent workflow.
Timing
Published companion to AI RMF 1.0.
Interpretation limit
Risk-area references identify relevant profile topics. They do not assert a specific action ID or a mandatory algorithm.

R15 · IS · Global

ISO/IEC 42001 ↗

Voluntary standard

ISO/IEC 42001:2023

Applies to
Organisational AI management systems; contract or policy may make adoption an organisational obligation.
Timing
Published management-system standard.
Interpretation limit
Only ISO’s public catalogue scope was inspected. All mappings are scope-level alignments; no paid clause text, Annex A conformity or certification verdict is claimed.

R16 · IR · Global

ISO/IEC 23894 ↗

Voluntary guidance standard

ISO/IEC 23894:2023

Applies to
AI risk-management processes appropriate to organisational context.
Timing
Published guidance standard.
Interpretation limit
Public catalogue scope only. Scope-level alignment, not a verified clause-by-clause assessment.

R17 · FS · Global

FSB sound practices for responsible AI adoption ↗

Consultation draft

10 June 2026 consultation report

Applies to
Financial institutions; organisation-wide governance and AI lifecycle practices.
Timing
Consultation closed July 2026. This map uses the published consultation text, not a presumed final report.
Interpretation limit
Draft alignment supports preparation; it establishes no new binding obligation.