GOVERNANCE / SECURITY / INTERNAL AUDIT

Official sources. A clearer view.

From a question to a researched briefing, practical controls,
and the evidence your team needs.

Free to use. No account required.
OFFICIAL SOURCE WATCHLIST

Know when a source needs another look.

Check 8 selected official pages on demand. Open the source to assess any change.

The first successful check records a baseline. Later checks compare page fingerprints, with a 30 minute shared cache. Older comparison history can expire and establish a new baseline. A changed page may reflect navigation or formatting; it is not a verified change in law. Checks do not update the guidance or its review date. No background alerts are running.

Law

EU AI Act

European Commission · Phased application

Phased obligations depend on the system, role and EU connection. The Commission timeline reflects Digital Omnibus changes.

Next action Validate territorial scope and provider or deployer role. Review prohibitions, literacy and transparency; confirm transition dates against the applicable legal text.

Not checked in this session
Open source
Framework

NIST AI Risk Management Framework

NIST · AI RMF 1.0 · revision underway

A voluntary structure for governing, mapping, measuring and managing AI risk across the lifecycle.

Next action Define owners, inventory systems, evaluate risks and record decisions with supporting evidence.

Not checked in this session
Open source
Framework

Generative AI Profile

NIST · NIST AI 600-1

A companion to the AI RMF addressing risks specific to generative AI, including unreliable outputs and information integrity.

Next action Build repeatable evaluations, protect sensitive information and document limitations before use.

Not checked in this session
Open source
Standard

ISO IEC 42001

ISO · 2023 edition

An AI management system standard for organizations that provide or use AI. A certificate concerns its defined scope, not every legal obligation.

Next action Set an AI policy, accountable roles, risk assessment, internal review and periodic reassessment. Obtain the licensed standard for clause-level work.

Not checked in this session
Open source
Security guidance

Top 10 for LLM Applications

OWASP · 2025 edition

A security reference for applications using large language models, including prompt injection, sensitive information exposure and excessive agency.

Next action Test trust boundaries, tool permissions, retrieval access and output handling with controlled adversarial scenarios.

Not checked in this session
Open source
Security guidance

Top 10 for Agentic Applications

OWASP · 2026 edition

Security guidance for AI systems that act through tools, identities and connected workflows.

Next action Limit authority, require approval for consequential actions, log execution and test recovery and shutdown.

Not checked in this session
Open source
Law

General Data Protection Regulation

EUR Lex · Applicable since 25 May 2018

Personal data duties may apply alongside AI-specific rules. Territorial scope and the nature of processing matter.

Next action Assess lawful basis, minimization, notices, retention, transfers and whether an impact assessment or automated-decision safeguards are required.

Not checked in this session
Open source
Audit guidance

AI Auditing Framework

The IIA · September 2024 update

A reference for internal audit oversight of AI governance, management and controls.

Next action Define an independent audit scope, test design and operating effectiveness, and document evidence and findings.

Not checked in this session
Open source

EU AI Act milestones to verify

The Commission timeline reflects phased implementation and Digital Omnibus changes. Confirm the governing text and transition provisions for your system. Catalog review: 15 Sept 2026.

Date reached2 Feb 2025Literacy and initial prohibitions
Date reached2 Aug 2025General-purpose AI and governance provisions
Date reached2 Aug 2026Majority of rules, including transparency
Upcoming2 Dec 2026Additional prohibitions and selected transparency transitions
Upcoming2 Aug 2027Member State regulatory sandboxes
Upcoming2 Dec 2027Annex III high-risk rules
Upcoming2 Aug 2028Annex I product-related high-risk rules
EU AI Act