⭐ Star on GitHub

Summary: Wiki pages for raw/Laws/ — voluntary frameworks (NIST, OECD, Singapore, IEEE), the GPAI Code of Practice, and the EU AI Act’s institutional and procedural machinery.

Sources: raw/Laws/ (17 files, ~152k words — 16 ingested; see Gaps)

Last updated: 2026-07-30


Pages

Frameworks

PageSource
nist-ai-rmfNIST AI 100-1 (AI RMF 1.0)
trustworthy-ai-characteristicsNIST AI 100-1 §3
oecd-ai-principlesOECD/LEGAL/0449
singapore-model-frameworkPDPC/IMDA Model AI Governance Framework, AI Verify
ieee-ethically-aligned-designIEEE EAD v2 (draft)
ai-governance-practicePalo Alto Networks — audits, IR plans, AI-SPM/DSPM/CNAPP

GPAI Code of Practice

PageCovers
gpai-code-of-practiceAll three chapters; the ten Safety & Security commitments
code-of-practice-security-mitigationsAppendix 4 — the corpus’s most prescriptive control set
systemic-riskAppendix 1 — risk types, characteristics, sources, four specified risks

EU AI Act machinery

PageCovers
eu-ai-act-governance-bodiesAI Office, AI Board, Scientific Panel, Advisory Forum
ai-regulatory-sandboxesArts 57–59, Member State implementation
whistleblowingWhistleblowing Directive coverage from Aug 2026
high-risk-ai-in-employmentWorked sector example of the high-risk regime

If you only read three

  1. code-of-practice-security-mitigations — 256-bit encryption, attested TEEs for weights in use, copy registries, insider vetting, red teaming, EDR/IDS. The only place in this corpus with named controls.
  2. systemic-risk — the capability/propensity/affordance split, and a severity rubric (velocity, cascade, irreversibility, asymmetry) that works better for AI incidents than CVSS.
  3. trustworthy-ai-characteristics — NIST’s Secure and Resilient definition, and the claim that trustworthiness properties trade off and must be balanced rather than maximised.

Observations from this ingest

  • The Code of Practice is where AI security governance actually lives. It is more concrete than NIST’s RMF and far more concrete than the Regulation it implements. It is also voluntary, scoped to GPAI with systemic risk, and oriented toward weight theft rather than the injection and agentic attack surface.
  • Everything shares OECD’s vocabulary. NIST’s AI system definition and “AI actors” concept come straight from OECD/LEGAL/0449, which makes cross-framework mapping tractable.
  • Only Singapore ships testing tools. AI Verify is the sole attempt in this corpus at shared open testing infrastructure — the gap Art 15(2) names when it asks for benchmarks and measurement methodologies.
  • The Scientific Panel is the researcher-relevant institution. Its qualified alerts can trigger systemic-risk designation without the 10²⁵ FLOP threshold, and can trigger enforcement.
  • IEEE EAD v2 is a 2018 public-discussion draft, not final guidance. Highest word count, lowest security density in the corpus. Cite the final EAD1e, not this.

Gaps

  • Cryptographic signing of models and datasets appears only in the vendor source — it is absent from Code of Practice Appendix 4, which protects outbound weights but not inbound ones. The ingested counterparts are CMU’s cryptographic chain of custody and provenance and assurance (SLSA, SBOM, in-toto, cosign).
  • No source addresses governance of agentic deployments specifically.
  • One of the 17 files in raw/Laws/ is not ingested. Legal AI Audit Trails_ Designing for Traceability.md (law.co, 2026-05-18, added 2026-07-30) is a failed clipping — 46 words, of which the body is two: AI law. Its stated subject, designing AI audit trails for legal traceability, would have joined the engineering side of agent audit trails to the Art 12 logging duty. The vault holds both halves and nothing connecting them. Worth re-clipping.
  • raw/Laws/ feeds two collections, this one and ai-regulations-wiki, so the source folder is shared rather than exclusive. The split is by content: statute and its interpretation there, voluntary and institutional frameworks here. The collection was renamed from ai-governance-wiki to laws-wiki on 2026-07-30 to match its source folder — the content is still governance frameworks (NIST AI RMF, OECD, IEEE, Singapore) rather than statute, so read the folder name as a pointer to raw/Laws/, not as a description of the subject matter.

Log

See log.