{ "catalog_title": "ReguAI Exhaustive Multi-Domain Regulatory Case Study Catalog", "catalog_version": "2.0.0", "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "domains": [ { "domain_id": "healthcare_samd", "domain_name": "\ud83c\udfe5 Healthcare & Medical SaMD", "statutory_category": "Annex I (MDR/IVDR) & Annex III Point 5(a)", "legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2017/745 (MDR)", "domain_summary": "AI Software as a Medical Device (SaMD) used for diagnostic classification, patient risk stratification, and emergency medical triage.", "case_studies": [ { "case_id": "compliant_clinical_samd", "title": "CardioScan / OncoScan AI Diagnostic Imaging (SaMD)", "system_id": "samd-oncology-01", "statutory_tier": "High-Risk (Annex I, Medical Device - Article 6(1))", "legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & MDR Class IIa", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_clinical_samd.json", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MAP-1.5", "MEASURE-2.11", "MANAGE-2.2" ], "iso_42001": [ "Clause 6.1.2", "Control A.6.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Article 9(2)(h) Health Data", "Article 22(3) Human Safeguards", "Article 35 DPIA" ] }, "conformity_procedure": "Annex VII: Notified Body Assessment combined with MDR Notified Body audit", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Automated thoracic CT nodule segmentation and malignancy risk stratification.", "common_pitfalls": "Relying purely on retrospective clinical datasets without validating demographic parity across diverse hospital imaging scanners; absence of radiologist manual override logs.", "remediation_guidance": "Implement continuous ISO 14971 risk management, multi-center bias audits, and radiologist-in-the-loop confirmative oversight." }, "file_sha256": "10307075b872d46a5d99f53dc7ed78cb6deccae74d707f5e4b55dc3483e68768", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "statutory_quote_sha256": "5dcc4a383d81f69e7988c97f6e6e2d5b85bcd096ebd033df9cb198b12433d785", "spec_file_sha256": "10307075b872d46a5d99f53dc7ed78cb6deccae74d707f5e4b55dc3483e68768", "prov_o_entity": "urn:reguai:benchmark:case:compliant_clinical_samd", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "non_compliant_derma_diagnostics", "title": "DermaCheck-Direct - Autonomous D2C Melanoma Classifier (MDR Class IIb)", "system_id": "samd-derma-02", "statutory_tier": "High-Risk (Annex I, Medical Device - Article 6(1))", "legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & MDR Class IIb", "expected_conformity": "NON-CONFORMANT (FAILED)", "file_path": "data/synthetic_systems/non_compliant_derma_diagnostics.json", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.2", "MEASURE-2.11", "MANAGE-2.2" ], "iso_42001": [ "Clause 6.1.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Article 9 Special Category Health Data", "Article 22 Automated Profiling" ] }, "conformity_procedure": "Annex VII: Notified Body Conformity Assessment combined with MDR Class IIb audit", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Consumer-facing automated melanoma screening app providing direct diagnostic risk scores.", "common_pitfalls": "Attempting to bypass MDR/AI Act high-risk classification via superficial 'informational only' disclaimers while marketing diagnostic capabilities; catastrophic bias across Fitzpatrick skin types.", "remediation_guidance": "Restructure application flow to require mandatory dermatologist tele-triage confirmation; conduct multi-center clinical validation across diverse skin phototypes; establish ISO 14971 PMS." }, "file_sha256": "0501529ffc36b2fc8ef295eacf6cd05dbec686283532e530f718f96b0fb3600c", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "statutory_quote_sha256": "5dcc4a383d81f69e7988c97f6e6e2d5b85bcd096ebd033df9cb198b12433d785", "spec_file_sha256": "0501529ffc36b2fc8ef295eacf6cd05dbec686283532e530f718f96b0fb3600c", "prov_o_entity": "urn:reguai:benchmark:case:non_compliant_derma_diagnostics", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } }, { "case_id": "compliant_cardiac_triage_samd", "title": "PulseGuard-ICU - Real-Time Cardiac Arrhythmia Telemetry (MDR Class IIb)", "system_id": "samd-cardiac-03", "statutory_tier": "High-Risk (Annex I, Medical Device - Article 6(1))", "legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & MDR Class IIb", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_cardiac_triage_samd.json", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MAP-1.5", "MEASURE-2.11", "MANAGE-2.2" ], "iso_42001": [ "Clause 6.1.2", "Control A.6.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Article 9(2)(h) Health Treatment", "Article 32 Security of Processing" ] }, "conformity_procedure": "Annex VII: Notified Body Assessment under MDR Class IIb & AI Act Article 43", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "ICU real-time cardiac arrhythmia warning and telemetry classification.", "common_pitfalls": "Failure to address alarm fatigue; lack of validation on diverse pacing modalities.", "remediation_guidance": "Maintain continuous eQMS post-market surveillance and quarterly clinician feedback reviews." }, "file_sha256": "0cd879508b3a084d82aaeac884546ee1f4a4baaac93fd424ca33207a1d42b826", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "statutory_quote_sha256": "5dcc4a383d81f69e7988c97f6e6e2d5b85bcd096ebd033df9cb198b12433d785", "spec_file_sha256": "0cd879508b3a084d82aaeac884546ee1f4a4baaac93fd424ca33207a1d42b826", "prov_o_entity": "urn:reguai:benchmark:case:compliant_cardiac_triage_samd", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "employment_hr", "domain_name": "\ud83d\udcbc Employment, HR & Workforce Management", "statutory_category": "Annex III Point 4", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 4(a) & 4(b)", "domain_summary": "AI systems used for recruitment, CV screening, job candidate evaluation, task allocation, and worker performance monitoring.", "case_studies": [ { "case_id": "non_compliant_hr_recruitment", "title": "TalentRank AI - Automated CV Screening & Candidate Ranking", "system_id": "hr-recruitment-02", "statutory_tier": "High-Risk (Annex III, Point 4(a))", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 4(a)", "expected_conformity": "NON-CONFORMANT (FAILED)", "file_path": "data/synthetic_systems/non_compliant_hr_recruitment.json", "statutory_quote": "AI systems intended to be used for recruitment or selection of natural persons, notably to place targeted job advertisements, to screen or filter applications, and to evaluate candidates.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10(2)(f)", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MAP-1.5", "MEASURE-2.11" ], "iso_42001": [ "Control A.6.2", "Control A.8.4" ], "gdpr": [ "Article 9(2)(g)", "Article 22(3) Automated Decisions" ] }, "conformity_procedure": "Annex VI: Internal Control Assessment", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Autonomous r\u00e9sum\u00e9 ingestion, semantic ranking, and interview invitation generation.", "common_pitfalls": "Historic gender and demographic bias encoded in legacy recruitment datasets; lack of explicit human intervention kill switch before candidates are rejected.", "remediation_guidance": "Perform disparate impact parity analysis (Four-Fifths rule / Equal Opportunity Difference) and require mandatory HR officer approval for all candidate rejections." }, "file_sha256": "c6ec9c67206cdbf275a7eb1eab0c9e85579d5bc428b503fc9a80040ce936524a", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used for recruitment or selection of natural persons, notably to place targeted job advertisements, to screen or filter applications, and to evaluate candidates.", "statutory_quote_sha256": "3c4764f14ff071e389175e3676bd3852b557469139a57fa652afe25cb5dde2ad", "spec_file_sha256": "c6ec9c67206cdbf275a7eb1eab0c9e85579d5bc428b503fc9a80040ce936524a", "prov_o_entity": "urn:reguai:benchmark:case:non_compliant_hr_recruitment", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_fairhire_screening", "title": "FairHire Pro - Audited Bias-Mitigated Technical Recruitment Sifter", "system_id": "hr-recruitment-03", "statutory_tier": "High-Risk (Annex III, Point 4(a))", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 4(a)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_fairhire_screening.json", "statutory_quote": "AI systems intended to be used for recruitment or selection of natural persons, notably to place targeted job advertisements, to screen or filter applications, and to evaluate candidates.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.3", "MAP-2.3", "MEASURE-2.11", "MANAGE-3.2" ], "iso_42001": [ "Control A.6.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Article 22 Automated Decisions", "Article 88 Employment Processing" ] }, "conformity_procedure": "Annex VI: Internal Control Assessment with documented third-party bias audits", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Candidate qualification ranking and resume shortlisting for recruitment.", "common_pitfalls": "Hidden proxy bias in word embeddings (e.g. associating gendered extracurricular activities with aptitude); lack of human reviewer independence.", "remediation_guidance": "Conduct biannual statistical bias audits and retain candidate adverse impact logs for 3 years." }, "file_sha256": "9b01237ffe59b96d1135e6c29fc09932c30f098de6f98dcf051ebb09fe2553e8", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used for recruitment or selection of natural persons, notably to place targeted job advertisements, to screen or filter applications, and to evaluate candidates.", "statutory_quote_sha256": "3c4764f14ff071e389175e3676bd3852b557469139a57fa652afe25cb5dde2ad", "spec_file_sha256": "9b01237ffe59b96d1135e6c29fc09932c30f098de6f98dcf051ebb09fe2553e8", "prov_o_entity": "urn:reguai:benchmark:case:compliant_fairhire_screening", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "banking_finance", "domain_name": "\ud83c\udfe6 Financial Services, Credit & Insurance", "statutory_category": "Annex III Point 5", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 5(b) & 5(c)", "domain_summary": "AI systems used to evaluate creditworthiness of natural persons, establish credit scores, or price risk in life and health insurance.", "case_studies": [ { "case_id": "borderline_credit_scoring", "title": "CreditScore-Next - Consumer Credit Risk Underwriting", "system_id": "fin-credit-03", "statutory_tier": "High-Risk (Annex III, Point 5(b))", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 5(b)", "expected_conformity": "BORDERLINE (AUDITOR REVIEW)", "file_path": "data/synthetic_systems/borderline_credit_scoring.json", "statutory_quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 13", "Article 14" ], "harmonized_frameworks": { "nist_ai_rmf": [ "MAP-1.5", "MEASURE-2.11", "MANAGE-2.2" ], "iso_42001": [ "Control A.8.2", "Control A.8.4" ], "gdpr": [ "Article 13/14 Transparency", "Article 22 Automated Decision-Making" ] }, "conformity_procedure": "Annex VI: Internal Control Assessment", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Consumer credit underwriting predicting loan default risk probabilities.", "common_pitfalls": "Treating planned roadmap commitments (e.g. 'bias mitigation planned for Q3') as implemented controls; lack of adverse action explanatory notices under Article 13.", "remediation_guidance": "Verify that all bias examination and human oversight controls are verified in production prior to loan disbursement." }, "file_sha256": "c2f2a3f2b106b2e158e80193b79f6438ff96cd7c50a20dcd1a81096c3b671833", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.", "statutory_quote_sha256": "79978eed3683f16e8cc3ad64ec9483f34fdb772b7bf840c5221843490de934be", "spec_file_sha256": "c2f2a3f2b106b2e158e80193b79f6438ff96cd7c50a20dcd1a81096c3b671833", "prov_o_entity": "urn:reguai:benchmark:case:borderline_credit_scoring", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_mortgage_underwriting", "title": "EuroLend AI - Explainable Algorithmic Retail Mortgage Underwriting", "system_id": "fin-credit-02", "statutory_tier": "High-Risk (Annex III, Point 5(b))", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 5(b)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_mortgage_underwriting.json", "statutory_quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.2", "MAP-1.4", "MEASURE-2.11", "MANAGE-2.3" ], "iso_42001": [ "Clause 6.1.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Article 15 Right of Access", "Article 22 Automated Decision-Making" ] }, "conformity_procedure": "Annex VI: Internal Control Procedure with ECB / National Competent Authority Supervision", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Credit risk evaluation and retail residential mortgage underwriting.", "common_pitfalls": "Redlining via postal code proxies; black-box neural networks failing to provide meaningful explanations under GDPR Article 22.", "remediation_guidance": "Ensure monotonic constraints on risk features; provide explainable SHAP/LIME counterfactuals to all rejected borrowers." }, "file_sha256": "6e9ee00c9dda0412ba33cdca0c8a1c8acf8e83654c9db0e8745627fc89934323", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud.", "statutory_quote_sha256": "79978eed3683f16e8cc3ad64ec9483f34fdb772b7bf840c5221843490de934be", "spec_file_sha256": "6e9ee00c9dda0412ba33cdca0c8a1c8acf8e83654c9db0e8745627fc89934323", "prov_o_entity": "urn:reguai:benchmark:case:compliant_mortgage_underwriting", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "transport_safety", "domain_name": "\ud83d\ude97 Automotive & Road Transport Safety", "statutory_category": "Annex I & Annex III Point 2", "legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2019/2144 (General Vehicle Safety)", "domain_summary": "AI safety components in autonomous and semi-autonomous vehicles, collision avoidance, and automated emergency braking (AEB).", "case_studies": [ { "case_id": "transport_autonomous_braking", "title": "AutoDrive SafeStop - Autonomous Emergency Braking Safety Component", "system_id": "transport-brake-01", "statutory_tier": "High-Risk (Annex I, Automotive Safety Component - Article 6(1))", "legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Annex I, Section B", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/transport_autonomous_braking.json", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product covered by Union harmonisation legislation listed in Annex I.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 11", "Article 12", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MANAGE-2.2" ], "iso_42001": [ "Control A.6.2", "Control A.9.3" ], "gdpr": [ "Article 25 Data Protection by Design", "Article 32 Security" ] }, "conformity_procedure": "Vehicle Type Approval (UN ECE / Regulation (EU) 2019/2144)", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Safety component for automated emergency braking in commercial transport trucks.", "common_pitfalls": "Edge-case weather degradation (dense fog, blizzard); sensor blinding; lack of physical driver override precedence.", "remediation_guidance": "Implement ISO 26262 ASIL-D hardware-in-the-loop validation and driver steering/braking mechanical override." }, "file_sha256": "05711b454abc603d0578da44e1b3fcd9c38b89b070753c4ef9f3dda28f577d1c", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product covered by Union harmonisation legislation listed in Annex I.", "statutory_quote_sha256": "76d72016601abdcf78c934d9ba402cb4321905234ff2f1d433e9d70389e7fd94", "spec_file_sha256": "05711b454abc603d0578da44e1b3fcd9c38b89b070753c4ef9f3dda28f577d1c", "prov_o_entity": "urn:reguai:benchmark:case:transport_autonomous_braking", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_adas_lane_keeping", "title": "RoadSentry LaneAssist - Automotive Steering & Lane Departure Safety Component", "system_id": "auto-adas-02", "statutory_tier": "High-Risk (Annex I, Vehicle Safety Component - Article 6(1))", "legal_basis": "Regulation (EU) 2024/1689, Article 6(1) & Regulation (EU) 2019/2144 (GSR)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_adas_lane_keeping.json", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.2", "MAP-1.5", "MEASURE-2.8", "MANAGE-2.2" ], "iso_42001": [ "Clause 6.1.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Regulation (EU) 2019/2144 (GSR) Type Approval" ] }, "conformity_procedure": "Annex VII: Combined Vehicle Type-Approval and AI Act Conformity Assessment", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Automotive lane-keeping assist safety component for passenger vehicles.", "common_pitfalls": "Failing to implement instantaneous human steering override; unverified sensor behavior in severe rain or snow.", "remediation_guidance": "Verify capacitive hands-on-wheel failsafe triggers; audit ASIL-B safety case documentation." }, "file_sha256": "928177f38b05a7c8c49a8d19e1f257430ce959bf1e013413275a0ae634cebad1", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems referred to in Annex I shall be considered high-risk if they are intended to be used as a safety component of a product, or are themselves a product, covered by Union harmonisation legislation listed in Annex I and are required to undergo a third-party conformity assessment.", "statutory_quote_sha256": "5dcc4a383d81f69e7988c97f6e6e2d5b85bcd096ebd033df9cb198b12433d785", "spec_file_sha256": "928177f38b05a7c8c49a8d19e1f257430ce959bf1e013413275a0ae634cebad1", "prov_o_entity": "urn:reguai:benchmark:case:compliant_adas_lane_keeping", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "critical_infrastructure", "domain_name": "\u26a1 Critical Infrastructure & Energy", "statutory_category": "Annex III Point 2(a)", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 2(a)", "domain_summary": "AI systems used as safety components in the management and operation of critical digital infrastructure, electricity, water, or gas grids.", "case_studies": [ { "case_id": "critical_infra_smart_grid", "title": "VoltBalance - Smart Grid Dispatch & Load Shedding Optimizer", "system_id": "infra-grid-02", "statutory_tier": "High-Risk (Annex III, Point 2(a) - Critical Infrastructure)", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 2(a)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/critical_infra_smart_grid.json", "statutory_quote": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 12", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MANAGE-2.2" ], "iso_42001": [ "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Article 32 Security of Processing" ] }, "conformity_procedure": "Annex VI: Internal Control Assessment + NIS 2 Directive compliance", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Predicting transmission grid frequency instability and automating substation load shedding.", "common_pitfalls": "Adversarial sensor manipulation in SCADA protocols; unmitigated cascading blackout failure modes.", "remediation_guidance": "Enforce IEC 62351 cybersecurity controls, air-gapped network segmentation, and human operator dispatch confirmation thresholds." }, "file_sha256": "e1f880b6b7c75160ec093460a5aee7cbe7c3799f012edf9766c8b7742618ca2a", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.", "statutory_quote_sha256": "e0c3c5f1b40de5454437f0eb284e65cea7490366fc37beb29c6f76609bffe60d", "spec_file_sha256": "e1f880b6b7c75160ec093460a5aee7cbe7c3799f012edf9766c8b7742618ca2a", "prov_o_entity": "urn:reguai:benchmark:case:critical_infra_smart_grid", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "non_compliant_water_scada", "title": "HydroFlow AI - Autonomous Municipal Water Chlorination Controller", "system_id": "infra-water-02", "statutory_tier": "High-Risk (Annex III, Point 2(a))", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 2(a)", "expected_conformity": "NON-CONFORMANT (FAILED)", "file_path": "data/synthetic_systems/non_compliant_water_scada.json", "statutory_quote": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.2", "MANAGE-2.2", "MEASURE-2.8" ], "iso_42001": [ "Control A.8.4", "Control A.9.2" ], "gdpr": [ "NIS2 Directive (EU) 2022/2555 Alignment" ] }, "conformity_procedure": "Annex VII: Notified Body Assessment for Safety Critical Infrastructure", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Autonomous chemical dosing in drinking water supply infrastructure.", "common_pitfalls": "Allowing closed-loop autonomous chemical actuation without hardware fail-safe limiters; omitting human operator in the loop during off-peak hours.", "remediation_guidance": "Install physical hardware interlocks preventing toxic over-dosing; isolate SCADA network under IEC 62443; enforce mandatory operator confirmation for valve adjustments." }, "file_sha256": "7a8523ccad159e5bb64c592b7e0e7098a5bee634c167400e049b17a58253597e", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.", "statutory_quote_sha256": "327cf2124c09cf4d5ccff5b7e6e006177f5879a1728d37e352b31c44b4344b56", "spec_file_sha256": "7a8523ccad159e5bb64c592b7e0e7098a5bee634c167400e049b17a58253597e", "prov_o_entity": "urn:reguai:benchmark:case:non_compliant_water_scada", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "education_training", "domain_name": "\ud83c\udf93 Education & Vocational Training", "statutory_category": "Annex III Point 3", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 3(a) & 3(b)", "domain_summary": "AI systems used for student admission, assignment, grading, and monitoring or detecting prohibited behaviour of students during tests.", "case_studies": [ { "case_id": "education_remote_proctoring", "title": "ExamGuard AI - Remote Exam Video Surveillance & Cheating Detection", "system_id": "edu-proctor-03", "statutory_tier": "High-Risk (Annex III, Point 3(b) - Education & Vocational Training)", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 3(b)", "expected_conformity": "NON-CONFORMANT (FAILED)", "file_path": "data/synthetic_systems/education_remote_proctoring.json", "statutory_quote": "AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10(2)(f)", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "MAP-1.5", "MEASURE-2.11" ], "iso_42001": [ "Control A.6.2", "Control A.8.4" ], "gdpr": [ "Article 9 Special Category Biometric Data", "Article 22(3)" ] }, "conformity_procedure": "Annex VI: Internal Control Assessment", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Automated webcam gaze tracking and cheating detection during remote university exams.", "common_pitfalls": "High false-positive rate against neurodivergent students; automated exam disqualification without human proctor confirmation.", "remediation_guidance": "Mandate board-certified proctor review for any academic integrity violation; disable autonomous disqualifications." }, "file_sha256": "6df408982de7afa0a061d22b05d146dc58b0944fba3d2522d8f91ce9559a2ac7", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used for monitoring and detecting prohibited behaviour of students during tests in the context of or within educational and vocational training institutions.", "statutory_quote_sha256": "4a08282d283284eb1b8d54a12b1067ac5b5e6e7325757e059c52d7ecd3d3030e", "spec_file_sha256": "6df408982de7afa0a061d22b05d146dc58b0944fba3d2522d8f91ce9559a2ac7", "prov_o_entity": "urn:reguai:benchmark:case:education_remote_proctoring", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_adaptive_stem_tutor", "title": "AdaptiveMath - Personalized Secondary STEM Learning Assistant", "system_id": "edu-tutor-02", "statutory_tier": "High-Risk (Annex III, Point 3(b))", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 3(b)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_adaptive_stem_tutor.json", "statutory_quote": "AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.2", "MAP-2.3", "MEASURE-2.11", "MANAGE-3.2" ], "iso_42001": [ "Control A.6.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Article 8 Child Consent", "Article 35 DPIA" ] }, "conformity_procedure": "Annex VI: Internal Control Procedure with School Board Governance", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Personalized educational pacing and formative learning recommendations.", "common_pitfalls": "Confusing formative tutor recommendations with summative automated student grading; collecting unnecessary behavioral biometric telemetry from minors.", "remediation_guidance": "Ensure student data is anonymized; maintain clear teacher override mechanisms for all curriculum pacing suggestions." }, "file_sha256": "a2a3580138bfa6abfd5b349c5d25b6704553e12754c7f58af6eca9f61b5fb183", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions.", "statutory_quote_sha256": "be0d78659b67ea0bd59c8429e659fed9817427733c4471f06183cfb4f985dc11", "spec_file_sha256": "a2a3580138bfa6abfd5b349c5d25b6704553e12754c7f58af6eca9f61b5fb183", "prov_o_entity": "urn:reguai:benchmark:case:compliant_adaptive_stem_tutor", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "justice_law_enforcement", "domain_name": "\u2696\ufe0f Law Enforcement & Criminal Justice", "statutory_category": "Annex III Points 6 & 8", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 6(a) & Point 8", "domain_summary": "AI systems used for individual criminal risk assessments, recidivism forecasting, evidence evaluation, and assisting judicial authorities.", "case_studies": [ { "case_id": "justice_recidivism_risk", "title": "JustiRisk - Criminal Recidivism & Bail Risk Scoring", "system_id": "justice-recid-04", "statutory_tier": "High-Risk (Annex III, Point 6(a) - Law Enforcement & Justice)", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 6(a)", "expected_conformity": "NON-CONFORMANT (FAILED)", "file_path": "data/synthetic_systems/justice_recidivism_risk.json", "statutory_quote": "AI systems intended to be used by law enforcement authorities or on their behalf for making individual risk assessments of natural persons in order to assess the risk of a natural person offending or re-offending.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10(2)(f)", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MEASURE-2.11" ], "iso_42001": [ "Control A.6.2", "Control A.8.4" ], "gdpr": [ "Article 10 Criminal Conviction Data", "Article 22" ] }, "conformity_procedure": "Annex VI: Internal Control Assessment + Fundamental Rights Impact Assessment (FRIA, Art. 27)", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Predicting defendant failure-to-appear and re-arrest probability for arraignment judges.", "common_pitfalls": "Feedback loops amplifying historic policing disparities; lack of feature-level explainability to judges.", "remediation_guidance": "Conduct independent algorithmic equity audits and furnish defense counsel with full mathematical factor weights." }, "file_sha256": "d97c94dac615aa333ee6d91f180dbbe7e7091b790be4dd41e63709e90175a42f", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used by law enforcement authorities or on their behalf for making individual risk assessments of natural persons in order to assess the risk of a natural person offending or re-offending.", "statutory_quote_sha256": "3576a8d0a0ef17595478e6f5970b98bbfaa4f5735a905beb61da41ab20b130e7", "spec_file_sha256": "d97c94dac615aa333ee6d91f180dbbe7e7091b790be4dd41e63709e90175a42f", "prov_o_entity": "urn:reguai:benchmark:case:justice_recidivism_risk", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_digital_forensics", "title": "LexEvidence AI - Judicial Post-Event Forensic Media Search Tool", "system_id": "justice-forensic-02", "statutory_tier": "High-Risk (Annex III, Point 6(b))", "legal_basis": "Regulation (EU) 2024/1689, Annex III, Point 6(b)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_digital_forensics.json", "statutory_quote": "AI systems intended to be used by law enforcement authorities or on their behalf to assess the risk of a natural person offending or re-offending, or to evaluate the reliability of evidence in the course of investigation or prosecution of criminal offences.", "regulatory_requirements": { "mandatory_articles": [ "Article 9", "Article 10", "Article 10(2)(f)", "Article 11", "Article 12", "Article 13", "Article 14", "Article 15" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MAP-2.3", "MEASURE-2.11", "MANAGE-3.2" ], "iso_42001": [ "Control A.6.2", "Control A.8.4", "Control A.9.2" ], "gdpr": [ "Directive (EU) 2016/680 (LED)", "Charter of Fundamental Rights Art 47" ] }, "conformity_procedure": "Annex VI: Internal Control Assessment under Judicial Supervision", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Retrospective forensic search of lawfully obtained digital evidence.", "common_pitfalls": "Creeping into predictive policing or real-time public biometric surveillance; lack of judicial warrant verification.", "remediation_guidance": "Verify strict air-gapped chain-of-custody logging and explicit human forensic investigator confirmation." }, "file_sha256": "f5865588668dbca7e231584eaf6b21d16657a2158dc4ec64b42dd518aee6abc6", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "AI systems intended to be used by law enforcement authorities or on their behalf to assess the risk of a natural person offending or re-offending, or to evaluate the reliability of evidence in the course of investigation or prosecution of criminal offences.", "statutory_quote_sha256": "2581bc2ccc920d54638ec0485289bfe0c3d5a7021941101e63e1c72a775f9c67", "spec_file_sha256": "f5865588668dbca7e231584eaf6b21d16657a2158dc4ec64b42dd518aee6abc6", "prov_o_entity": "urn:reguai:benchmark:case:compliant_digital_forensics", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "frontier_gpai", "domain_name": "\ud83c\udf10 Frontier GPAI & Foundation Models", "statutory_category": "Chapter V (Articles 51\u201355)", "legal_basis": "Regulation (EU) 2024/1689, Chapter V, Articles 51, 52, 53, 55", "domain_summary": "General-purpose AI models, frontier LLMs trained on > 10^25 FLOPs, systemic risk mitigations, and copyright opt-out enforcement.", "case_studies": [ { "case_id": "gpai_foundation_llm", "title": "Nexus-70B Frontier Foundation LLM (>10^25 FLOPs)", "system_id": "gpai-frontier-70b", "statutory_tier": "GPAI with Systemic Risk (Article 51)", "legal_basis": "Regulation (EU) 2024/1689, Chapter V, Article 51 & Article 55", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/gpai_foundation_llm.json", "statutory_quote": "A general-purpose AI model shall be presumed to have high impact capabilities when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.", "regulatory_requirements": { "mandatory_articles": [ "Article 51", "Article 53", "Article 55" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1", "MEASURE-2.6", "MANAGE-2.2" ], "iso_42001": [ "Control A.8.2", "Control A.9.3" ], "gdpr": [ "Directive (EU) 2019/790 DSM Copyright Opt-Out", "Article 25" ] }, "conformity_procedure": "AI Office Code of Practice / Independent Red-Teaming Attestation", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "Multi-modal frontier foundation LLM deployed for downstream enterprise reasoning and code generation.", "common_pitfalls": "Omission of training energy consumption reporting (MWh / tCO2eq); unverified compliance with EU copyright opt-out crawler policies (Directive (EU) 2019/790).", "remediation_guidance": "Document FLOPs declarations, publish training energy metrics, and institute external adversarial red-teaming." }, "file_sha256": "32ab439dd9aa11d48fd8229f36dc6881b33f0fe4a9f6b07ad80a2c0d3b2cb83c", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "A general-purpose AI model shall be presumed to have high impact capabilities when the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.", "statutory_quote_sha256": "23266169a3d1d1e7d12699b60912f09b0f20e20b5a8f4f521193b8db2ad9dab8", "spec_file_sha256": "32ab439dd9aa11d48fd8229f36dc6881b33f0fe4a9f6b07ad80a2c0d3b2cb83c", "prov_o_entity": "urn:reguai:benchmark:case:gpai_foundation_llm", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_open_frontier_llm", "title": "Sovereign-120B - Audited Open Frontier GPAI Model (>10^25 FLOPs)", "system_id": "gpai-sovereign-02", "statutory_tier": "General Purpose AI with Systemic Risk (Articles 51, 52, 53, 55)", "legal_basis": "Regulation (EU) 2024/1689, Articles 51, 53 & 55", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_open_frontier_llm.json", "statutory_quote": "A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, or the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.", "regulatory_requirements": { "mandatory_articles": [ "Article 51", "Article 52", "Article 53", "Article 55" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.2", "MANAGE-2.4", "MEASURE-2.12" ], "iso_42001": [ "Clause 6.1", "Control A.8.2", "Control A.9.1" ], "gdpr": [ "Directive (EU) 2019/790 Copyright DSM" ] }, "conformity_procedure": "AI Office Code of Practice / Harmonized Standards Adherence", "fine_exposure_tier": "Tier 2 (\u20ac15,000,000 or 3% global turnover)" }, "auditor_guidance": { "intended_purpose": "High-capacity frontier foundation model for diverse downstream linguistic tasks.", "common_pitfalls": "Failing to document copyright opt-outs under Article 53(1)(c); omitting independent third-party red-teaming for CBRN and cyber risk.", "remediation_guidance": "Publish comprehensive training data summary template; maintain continuous telemetry for serious incident reporting to the European AI Office." }, "file_sha256": "2cf75e44a660873e3cd712b7c8f3c7ebf079019e298b21742ab97090f07edd5e", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "A general-purpose AI model shall be classified as a general-purpose AI model with systemic risk if it has high impact capabilities evaluated on the basis of appropriate technical tools and methodologies, or the cumulative amount of computation used for its training measured in floating point operations is greater than 10^25.", "statutory_quote_sha256": "fa76d9f7299723ad872f72e72d6339535de83626d8a9f4bdfc49eed112fb92b9", "spec_file_sha256": "2cf75e44a660873e3cd712b7c8f3c7ebf079019e298b21742ab97090f07edd5e", "prov_o_entity": "urn:reguai:benchmark:case:compliant_open_frontier_llm", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "prohibited_practices", "domain_name": "\ud83d\udeab Prohibited AI Practices (Article 5 - Zero Tolerance)", "statutory_category": "Chapter II, Article 5", "legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(a)-(h)", "domain_summary": "Strictly illegal AI systems causing unacceptable risk to fundamental human rights, subject to fatal ban and \u20ac35M statutory fines.", "case_studies": [ { "case_id": "prohibited_emotion_recognition_workplace", "title": "MindGaze AI - Classroom & Workplace Emotion Recognition", "system_id": "prohibit-emotion-01", "statutory_tier": "Prohibited (Article 5(1)(f))", "legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(f)", "expected_conformity": "PROHIBITED (FATAL VIOLATION)", "file_path": "data/synthetic_systems/prohibited_emotion_recognition_workplace.json", "statutory_quote": "the placing on the market, the putting into service or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons.", "regulatory_requirements": { "mandatory_articles": [ "Article 5(1)(f)" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1 (Prohibited Use Policy)" ], "iso_42001": [ "Control A.6.1 Statutory Compliance" ], "gdpr": [ "Article 9 Special Category Biometric Data Violation" ] }, "conformity_procedure": "IMMEDIATE CEASE / PROHIBITED FROM UNION MARKET", "fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)" }, "auditor_guidance": { "intended_purpose": "Continuous automated facial micro-expression analysis to infer employee attentiveness and classroom student engagement.", "common_pitfalls": "Attempting to justify workplace emotion tracking under the guise of productivity analytics or employee wellness monitoring.", "remediation_guidance": "System must be completely decommissioned and withdrawn from EU deployment; no conformity procedure exists." }, "file_sha256": "f580f8d3d2fe68e0fd35ac78909a8e5b3348327cc00566176be48707e4c18b66", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "the placing on the market, the putting into service or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons.", "statutory_quote_sha256": "a6acc3b61a54da5bfc645db359dea2d5a8da5b814c93a25f7009bcb64ef1cd7f", "spec_file_sha256": "f580f8d3d2fe68e0fd35ac78909a8e5b3348327cc00566176be48707e4c18b66", "prov_o_entity": "urn:reguai:benchmark:case:prohibited_emotion_recognition_workplace", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "prohibited_social_scoring", "title": "CitizenTrust - Universal Civic Score & Trustworthiness Engine", "system_id": "prohibit-social-05", "statutory_tier": "Prohibited (Article 5(1)(c))", "legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(c)", "expected_conformity": "PROHIBITED (FATAL VIOLATION)", "file_path": "data/synthetic_systems/prohibited_social_scoring.json", "statutory_quote": "the placing on the market, the putting into service or the use of AI systems for the evaluation or classification of the trustworthiness of natural persons over a given period based on their social behaviour or known, inferred or predicted personal or personality characteristics.", "regulatory_requirements": { "mandatory_articles": [ "Article 5(1)(c)" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1" ], "iso_42001": [ "Control A.6.1" ], "gdpr": [ "Article 22 Automated Profiling Ban" ] }, "conformity_procedure": "IMMEDIATE CEASE / PROHIBITED FROM UNION MARKET", "fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)" }, "auditor_guidance": { "intended_purpose": "Evaluating citizen trustworthiness based on social behavior and administrative compliance to allocate public benefits.", "common_pitfalls": "Aggregating unrelated behavioral metrics across public transport, social conduct, and utility payments.", "remediation_guidance": "Immediate cessation of all profiling; full destruction of civic scoring datasets under supervision of National Supervisory Authority." }, "file_sha256": "d0aba4bb9064315583601c51bc083575355564d58d4aab3377a4e82f26ab216f", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "the placing on the market, the putting into service or the use of AI systems for the evaluation or classification of the trustworthiness of natural persons over a given period based on their social behaviour or known, inferred or predicted personal or personality characteristics.", "statutory_quote_sha256": "9e06a4684d2ff50679f1c4c87620cd1ea4ec01c7eac1ef0cf952ce3f1622b85e", "spec_file_sha256": "d0aba4bb9064315583601c51bc083575355564d58d4aab3377a4e82f26ab216f", "prov_o_entity": "urn:reguai:benchmark:case:prohibited_social_scoring", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "prohibited_subliminal_gambling_nudge", "title": "NeuroSpin - Subliminal Behavioral Nudge Engine for Mobile Gambling", "system_id": "prohibited-subliminal-03", "statutory_tier": "Prohibited AI Practice (Article 5(1)(a) - Absolute Ban)", "legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(a)", "expected_conformity": "PROHIBITED (ARTICLE 5 VIOLATION)", "file_path": "data/synthetic_systems/prohibited_subliminal_gambling_nudge.json", "statutory_quote": "The following AI practices shall be prohibited: the placing on the market, putting into service or use of an AI system that deploys subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of, materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to make a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm.", "regulatory_requirements": { "mandatory_articles": [ "Article 5(1)(a)" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1 Prohibited Harm" ], "iso_42001": [ "Zero-Tolerance Ethics" ], "gdpr": [ "Article 5 Fairness & Transparency", "Charter of Fundamental Rights" ] }, "conformity_procedure": "Prohibited under Union law. No conformity assessment permitted. Immediate market withdrawal mandated.", "fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)" }, "auditor_guidance": { "intended_purpose": "Subliminal player behavioral manipulation and deposit prolongation.", "common_pitfalls": "Attempting to disguise subliminal audio-visual techniques as 'UI personalization' or 'gamification'.", "remediation_guidance": "Immediate decommission of AI system; mandatory report to market surveillance authorities; Tier 1 administrative fine exposure." }, "file_sha256": "4ff20b07678a9cba1aa74c009f2286f79ea8eed86f0f342fcb1251fbe957d3c2", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "The following AI practices shall be prohibited: the placing on the market, putting into service or use of an AI system that deploys subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of, materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to make a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm.", "statutory_quote_sha256": "4420c5ade7cd55ac96d01d0a9537c22ff842151c1f91a98e2a1c705c62936949", "spec_file_sha256": "4ff20b07678a9cba1aa74c009f2286f79ea8eed86f0f342fcb1251fbe957d3c2", "prov_o_entity": "urn:reguai:benchmark:case:prohibited_subliminal_gambling_nudge", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } }, { "case_id": "prohibited_biometric_categorization_beliefs", "title": "BioClassify - CCTV Biometric Categorization of Political Beliefs", "system_id": "prohibited-bioclass-04", "statutory_tier": "Prohibited AI Practice (Article 5(1)(c) - Absolute Ban)", "legal_basis": "Regulation (EU) 2024/1689, Article 5(1)(c)", "expected_conformity": "PROHIBITED (ARTICLE 5 VIOLATION)", "file_path": "data/synthetic_systems/prohibited_biometric_categorization_beliefs.json", "statutory_quote": "The following AI practices shall be prohibited: the placing on the market, the putting into service for this purpose, or use of biometric categorization systems that categorize individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.", "regulatory_requirements": { "mandatory_articles": [ "Article 5(1)(c)" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1 Prohibited Harm" ], "iso_42001": [ "Zero-Tolerance Ban" ], "gdpr": [ "Article 9 Special Category Data Prohibition" ] }, "conformity_procedure": "Prohibited under Union law. Immediate permanent ban and market removal mandated.", "fine_exposure_tier": "Tier 1 (\u20ac35,000,000 or 7% global turnover)" }, "auditor_guidance": { "intended_purpose": "Inferring political or religious beliefs from facial or biometric surveillance.", "common_pitfalls": "Claiming biometric categorization is permissible under 'smart city analytics' or 'demographic foot-traffic research'.", "remediation_guidance": "Immediate cessation of processing; deletion of all biometric model weights; mandatory report to Data Protection Authority and EU AI Office." }, "file_sha256": "eb303b5e0e7c7d6734108bf796ee746aef9ceb8d12b90c37f3d5678e770c84af", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "The following AI practices shall be prohibited: the placing on the market, the putting into service for this purpose, or use of biometric categorization systems that categorize individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.", "statutory_quote_sha256": "5650de7e6af380e323974bd3041c748ffe6b3c83ba1d0799c8d255ca9160ccf7", "spec_file_sha256": "eb303b5e0e7c7d6734108bf796ee746aef9ceb8d12b90c37f3d5678e770c84af", "prov_o_entity": "urn:reguai:benchmark:case:prohibited_biometric_categorization_beliefs", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "limited_risk_generative", "domain_name": "\ud83d\udcac Limited Risk & Generative Transparency", "statutory_category": "Chapter IV, Article 50", "legal_basis": "Regulation (EU) 2024/1689, Article 50(1) & 50(2)", "domain_summary": "AI systems directly interacting with natural persons (chatbots) and generative synthetic audio/video systems requiring transparency disclosures.", "case_studies": [ { "case_id": "limited_risk_customer_bot", "title": "OmniAssist Enterprise Conversational Support Agent", "system_id": "limited-bot-06", "statutory_tier": "Limited Risk (Article 50 - Transparency Obligations)", "legal_basis": "Regulation (EU) 2024/1689, Article 50(1)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/limited_risk_customer_bot.json", "statutory_quote": "Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the points of view of a reasonable person.", "regulatory_requirements": { "mandatory_articles": [ "Article 50(1)", "Article 50(2)" ], "harmonized_frameworks": { "nist_ai_rmf": [ "MAP-1.5", "GOVERN-1.1" ], "iso_42001": [ "Control A.8.4" ], "gdpr": [ "Article 13 Transparency" ] }, "conformity_procedure": "Self-Declaration Transparency Disclosure (No Notified Body required)", "fine_exposure_tier": "Tier 3 (\u20ac7,500,000 or 1.5% global turnover for false disclosures)" }, "auditor_guidance": { "intended_purpose": "Natural language conversational agent assisting retail bank customers with routine inquiries.", "common_pitfalls": "Failing to disclose AI nature upon the very first turn of conversation; deceptive human persona simulation.", "remediation_guidance": "Ensure persistent visual badge and upfront greeting clearly stating AI identity." }, "file_sha256": "dae7e2c3132033b2b10f551ddd81cb12eb30288259c691d2a3a422af0a66a1b7", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the points of view of a reasonable person.", "statutory_quote_sha256": "feaaa0302385592938c214b02ff11e3b75abacf4c1e9b2411891632c3c693d27", "spec_file_sha256": "dae7e2c3132033b2b10f551ddd81cb12eb30288259c691d2a3a422af0a66a1b7", "prov_o_entity": "urn:reguai:benchmark:case:limited_risk_customer_bot", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_virtual_presenter_deepfake", "title": "Synthetica Studio - Photorealistic Virtual Presenter & Video Avatar", "system_id": "gen-video-avatar-02", "statutory_tier": "Limited Risk (Transparency Obligations - Article 50)", "legal_basis": "Regulation (EU) 2024/1689, Article 50(2) & 50(4)", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_virtual_presenter_deepfake.json", "statutory_quote": "Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.", "regulatory_requirements": { "mandatory_articles": [ "Article 50(2)", "Article 50(4)" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.2", "MEASURE-2.8" ], "iso_42001": [ "Control A.8.2" ], "gdpr": [ "C2PA Provenance Standards" ] }, "conformity_procedure": "Voluntary Code of Practice / Article 50 Transparency Audit", "fine_exposure_tier": "Tier 3 (\u20ac7,500,000 or 1.5% global turnover)" }, "auditor_guidance": { "intended_purpose": "Photorealistic synthetic avatar video generation for enterprise training.", "common_pitfalls": "Removing watermarking metadata in exported MP4 files; failing to obtain actor consent.", "remediation_guidance": "Ensure C2PA provenance manifests survive standard web video transcoding; verify persistent visual disclosure." }, "file_sha256": "34a380b970932490566e393c04d235053402afdbfcf06b78f47362c96ae518bb", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.", "statutory_quote_sha256": "a15d222ef65c0da8f5dcb81f7d65c37e3ba48a6312bb3aca3650032a0d71f143", "spec_file_sha256": "34a380b970932490566e393c04d235053402afdbfcf06b78f47362c96ae518bb", "prov_o_entity": "urn:reguai:benchmark:case:compliant_virtual_presenter_deepfake", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] }, { "domain_id": "minimal_risk", "domain_name": "\ud83d\udfe2 Minimal / Low Risk (Voluntary Codes of Conduct)", "statutory_category": "Title IX, Article 95", "legal_basis": "Regulation (EU) 2024/1689, Article 95", "domain_summary": "Unconstrained AI systems such as spam filters, recommender systems, and inventory optimizers with voluntary adherence to European Codes of Conduct.", "case_studies": [ { "case_id": "minimal_risk_spam_filter", "title": "SmartShield Email Security & Phishing Classifier", "system_id": "minimal-spam-07", "statutory_tier": "Minimal / No Statutory Risk (Voluntary Codes of Conduct)", "legal_basis": "Regulation (EU) 2024/1689, Article 95", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/minimal_risk_spam_filter.json", "statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of voluntary codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2.", "regulatory_requirements": { "mandatory_articles": [ "Article 95 (Voluntary)" ], "harmonized_frameworks": { "nist_ai_rmf": [ "Voluntary Guidance" ], "iso_42001": [ "Voluntary AI Management" ], "gdpr": [ "Article 6 Lawfulness of Processing" ] }, "conformity_procedure": "Unconstrained EU Deployment (Voluntary Code of Conduct)", "fine_exposure_tier": "Zero Statutory Exposure (Exempt from Annex IV)" }, "auditor_guidance": { "intended_purpose": "Filtering unsolicited commercial spam and malicious phishing emails.", "common_pitfalls": "Misinterpreting minimal risk as complete exemption from general GDPR privacy rules.", "remediation_guidance": "Comply with standard data protection and privacy rules; no Annex IV technical documentation mandated." }, "file_sha256": "6e679fb4c1761cf7ca3c93b07b945d54825c44c390d8a83ba7cb19c4b3de5873", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of voluntary codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Chapter III, Section 2.", "statutory_quote_sha256": "599c41e571b1bab6c10c9240801e9a67ba51ade5a3a2e638328405676cbcb408", "spec_file_sha256": "6e679fb4c1761cf7ca3c93b07b945d54825c44c390d8a83ba7cb19c4b3de5873", "prov_o_entity": "urn:reguai:benchmark:case:minimal_risk_spam_filter", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-20T20:55:00Z" } }, { "case_id": "compliant_warehouse_logistics_optimizer", "title": "PathMatrix AI - Autonomous Warehouse Forklift Route Dispatcher", "system_id": "minimal-logistics-02", "statutory_tier": "Minimal Risk (Voluntary Code of Conduct - Article 95)", "legal_basis": "Regulation (EU) 2024/1689, Article 95", "expected_conformity": "CONFORMANT (PASSED)", "file_path": "data/synthetic_systems/compliant_warehouse_logistics_optimizer.json", "statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Title III, Chapter 2.", "regulatory_requirements": { "mandatory_articles": [ "Article 4 AI Literacy", "Article 95 Codes of Conduct" ], "harmonized_frameworks": { "nist_ai_rmf": [ "GOVERN-1.1" ], "iso_42001": [ "Voluntary Alignment" ], "gdpr": [ "Non-Personal Data Processing" ] }, "conformity_procedure": "Exempt from mandatory third-party assessment; voluntary code of conduct adhesion.", "fine_exposure_tier": "None (Compliant Minimal Risk)" }, "auditor_guidance": { "intended_purpose": "Internal spatial route optimization for warehouse machinery.", "common_pitfalls": "Creeping into worker monitoring if vehicle telemetry is used to evaluate forklift driver speed or productivity without labor consultation.", "remediation_guidance": "Ensure operational logs isolate vehicle mechanical stats from driver personal IDs." }, "file_sha256": "a6a2985c0390eafd415c246b9f7ec5fb0f895de61c442382f884c4730b958354", "provenance": { "statutory_act": "Regulation (EU) 2024/1689 of the European Parliament and of the Council", "official_journal": "OJ L, 2024/1689, 12.7.2024", "eli_uri": "http://data.europa.eu/eli/reg/2024/1689/oj", "celex": "32024R1689", "statutory_quote": "The Commission and the Member States shall encourage and facilitate the drawing up of codes of conduct intended to foster the voluntary application to AI systems other than high-risk AI systems of some or all of the requirements set out in Title III, Chapter 2.", "statutory_quote_sha256": "5b2e584bf800e8d3b786d670ce6484d2e76c48d79e4ce9b2cd4df2c4b0e35a20", "spec_file_sha256": "a6a2985c0390eafd415c246b9f7ec5fb0f895de61c442382f884c4730b958354", "prov_o_entity": "urn:reguai:benchmark:case:compliant_warehouse_logistics_optimizer", "author": "ReguAI Regulatory Engineering Working Group", "verification_method": "W3C PROV-O & SHA-256 Canonical Digest", "timestamp": "2026-09-21T16:00:00Z" } } ] } ] }