{
    "Disclaimer": [
        "The information in this database is for general guidance and is not to be relied upon as professional advice.",
        "DSIT has tried to ensure that the information on this database is accurate and up to date. DSIT will not accept liability for any loss and/or damage or inconvenience arising as a consequence of any use of or the inability to use any information on this website. DSIT endeavours to provide a reliable service; DSIT does not guarantee that its service will be uninterrupted or error-free. DSIT shall not be responsible for claims brought by third parties arising from your use of this database.",
        "DSIT assumes no responsibility for the contents of linked websites. The inclusion of any link should not be taken as endorsement of any kind by DSIT of the linked website or any association with its operators. DSIT has no control over the availability of the linked pages."
    ],
    "Copyright": "The copyright of the original material remains that of the original authors and any usage of excerpts in the mapping is made under fair use. References to organisations do not imply endorsement by DSIT.",
    "Version": "1.0",
    "Data": {
        "Central Bank of the UAE": {
            "Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E": {
                "link": "https://rulebook.centralbank.ae/en/rulebook/guidance-note-consumer-protection-and-responsible-adoption-and-use-artificial-intelligence",
                "requirements": [
                    {
                        "requirementID": "4. Transparency and Explain ability - a",
                        "requirementText": "LFIs should be transparent with customers and relevant stakeholders about the use of AI, particularly in respect of high-impact decisions, and if they are communicating or interacting with an AI application. LFIs should be clear as to how AI systems operate and make decisions and be able to disclose the same. "
                    },
                    {
                        "requirementID": "4. Transparency and Explain ability - d",
                        "requirementText": "LFIs should provide customers with meaningful information regarding the logic of AI decisions and make available mechanisms for customers to seek clarification or redress. "
                    }
                ]
            }
        },
        "CISA": {
            "Principles for the Secure Integration of Artificial Intelligence in Operational Technology": {
                "link": "https://www.cisa.gov/sites/default/files/2026-01/joint-guidance-principles-for-the-secure-integration-of-artificial-intelligence-in-operational-technology-508cV2.pdf",
                "requirements": [
                    {
                        "requirementID": "1.3.3 Educate Personnel on AI - Leveraging explainable AI",
                        "requirementText": "Leveraging explainable AI by having operators request that AI outputs include clear and transparent documentation of decision-making processes; this enables humans to better understand and validate outputs."
                    },
                    {
                        "requirementID": "4.1.6 - Explore new AI explainability and transparency tools.",
                        "requirementText": "Explainable AI (XAI) and transparent AI are evolving fields of research that seek to make AI systems more understandable. Explainability focuses on making the reasoning behind individual AI decisions understandable to users, while transparency emphasizes making the overall AI system’s development and operation open and accessible. Essentially, explainability clarifies why an AI made a specific decision, while transparency focuses on how the AI system works as a whole. Critical infrastructure owners and operators should, where possible, explore interpretable models or tools that make AI decisions more understandable to humans."
                    }
                ]
            }
        },
        "Cloud Security Alliance (CSA)": {
            "AI Controls Matrix": {
                "link": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix",
                "requirements": [
                    {
                        "requirementID": "BCR-07",
                        "requirementText": "Establish and maintain communication channels with all relevant stakeholders in the course of business continuity and resilience procedures."
                    },
                    {
                        "requirementID": "DSP-18",
                        "requirementText": "The providers should implement and describe to customers the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations."
                    },
                    {
                        "requirementID": "GRC-14",
                        "requirementText": "Evaluate, document, and communicate the degree of explainability of the AI Services, including possible limitations and exceptions."
                    },
                    {
                        "requirementID": "SEF-03",
                        "requirementText": "Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: a communication strategy for notifying relevant internal departments, impacted AICs, and other business critical relationships (such as supply-chain) that may be impacted."
                    },
                    {
                        "requirementID": "SEF-07",
                        "requirementText": "Define and implement, processes, procedures and technical measures for security breach notifications. Report material security breaches and assumed security breaches including any relevant supply chain breaches, as per applicable SLAs, laws and regulations."
                    },
                    {
                        "requirementID": "STA-04",
                        "requirementText": "Provide SSRM Guidance to the Customer detailing information about the SSRM applicability throughout the supply chain."
                    }
                ]
            }
        },
        "CoSAI": {
            "AI Incident Response Framework": {
                "link": "https://github.com/cosai-oasis/ws2-defenders/blob/main/incident-response/AI%20Incident%20Response.md",
                "requirements": [
                    {
                        "requirementID": "3.3.2. Detection and Analysis Phase - Initial Triage - Priority Assignment",
                        "requirementText": "• Assign priority based on impact\n• Implement notification procedures\n• Mobilize specialized resources"
                    },
                    {
                        "requirementID": "3.3.3. Containment, Eradication, and Recovery Phase - Recovery Procedures - User Communication",
                        "requirementText": "• Communication templates\n• Transparency guidelines\n• Communication protocols\n• User feedback mechanisms"
                    }
                ]
            },
            "Model Context Protocol (MCP) Security": {
                "link": "https://github.com/cosai-oasis/ws4-secure-design-agentic-systems/blob/main/model-context-protocol-security.md",
                "requirements": [
                    {
                        "requirementID": "3.2.8 Secure Tool and UX Design",
                        "requirementText": "Tool and UX design represent a critical security control point in Model Context Protocol (MCP) deployments. While much attention is paid to model safety and prompt injection defenses, the tools that agents invoke are often the actual execution surface where security boundaries are crossed and sensitive operations are performed. Poor tool design can undermine even the most robust authentication and authorization controls by creating overly permissive capabilities or delegating security-critical decisions to the LLM itself.\n\nEach tool should have a single, clearly defined purpose with explicit boundaries on what it can and cannot do. When possible, create use-case driven or purpose-built tools, avoiding excessively powerful tools, e.g., execute a prepared statement versus executing any SQL statement. Tool implementations should not rely on the LLM to perform security-critical operations, validate inputs, or enforce constraints.\n\nSafe and secure execution should not rely solely on the human user, who may not understand the security implications of frequent security prompts and can easily become fatigued. Security-relevant messages and elicitations should be clear, indicating the implications of the request, and unambiguous what is being requested."
                    }
                ]
            }
        },
        "Cyber Security Council (UAE)": {
            "National Cyber Security Policy for Artificial Intelligence": {
                "link": "https://csc.gov.ae/documents/38662/0/National+Cyber+Security+Policy+for+Artificial+Intelligence_v1.1.pdf/4e02b32e-9f62-948d-4bc8-b580d596451b?t=1766994254544",
                "requirements": [
                    {
                        "requirementID": "3.6.2 Incident Reporting and Management for AI/ML - 2",
                        "requirementText": "This process should include clear guidelines on identifying and classifying incidents, timely reporting mechanisms, designated roles and responsibilities for incident response, and procedures for post-incident analysis and learning."
                    },
                    {
                        "requirementID": "3.6.2 Incident Reporting and Management for AI/ML - 3",
                        "requirementText": "The entity should ensure AI/ML security incidents are reported in a timely manner to all relevant stakeholders, including internal teams, third-party service providers, and regulatory bodies, in line with applicable laws and regulations, and contractual agreements."
                    }
                ]
            }
        },
        "ENISA": {
            "Multilayer Framework for Good Cybersecurity Practices for AI": {
                "link": "https://www.enisa.europa.eu/sites/default/files/publications/Multilayer%20Framework%20for%20Good%20Cybersecurity%20Practices%20for%20AI.pdf",
                "requirements": [
                    {
                        "requirementID": "From the lab to the market 7",
                        "requirementText": "How do you inform the national stakeholders about the relevant legal instruments and standards available? (e.g. regulatory sandboxes)"
                    },
                    {
                        "requirementID": "Networking 2",
                        "requirementText": "Are there national initiatives that focus on collaboration about threat intelligence (AI threats, vulnerabilities and security controls) to the users/community?"
                    },
                    {
                        "requirementID": "Networking 5",
                        "requirementText": "Have you developed appropriate collaboration with the national AI stakeholders for information sharing?"
                    }
                ]
            }
        },
        "ETSI": {
            "EN 304 223 - Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems": {
                "link": "https://www.etsi.org/deliver/etsi_en/304200_304299/304223/02.01.01_60/en_304223v020101p.pdf",
                "requirements": [
                    {
                        "requirementID": "Provision 5.3.1-1",
                        "requirementText": "System Operators shall convey to End-users in an accessible way where and how their data will be used, accessed and stored (for example, if it is used for model retraining, or reviewed by employees or partners). If the Developer is an external entity, they shall provide this information to System Operators."
                    },
                    {
                        "requirementID": "Provision 5.3.1-2",
                        "requirementText": "System Operators shall provide End-users with accessible guidance to support their use, management, integration, and configuration of AI systems. If the Developer is an external entity, they shall provide all necessary information to help System Operators."
                    },
                    {
                        "requirementID": "Provision 5.3.1-2.1",
                        "requirementText": "System Operators shall include guidance on the appropriate use of the model or system, which includes highlighting limitations and potential failure modes."
                    },
                    {
                        "requirementID": "Provision 5.3.1-2.2",
                        "requirementText": "System Operators shall proactively inform End-users of any security relevant updates and provide clear explanations in an accessible way."
                    },
                    {
                        "requirementID": "Provision 5.3.1-3",
                        "requirementText": "Developers and System Operators should support End-users and Affected Entities during and following a cyber security incident to contain and mitigate the impacts of an incident. The process for undertaking this should be documented and agreed in contracts with End-users."
                    }
                ]
            },
            "TR 104 128 - Securing Artificial Intelligence (SAI); Guide to Cyber Security for AI Models and Systems": {
                "link": "https://www.etsi.org/deliver/etsi_tr/104100_104199/104128/01.01.01_60/tr_104128v010101p.pdf",
                "requirements": [
                    {
                        "requirementID": "Provision 5.3.1-1",
                        "requirementText": "\"System Operators shall convey to End-users in an accessible way where and how their data will be used, accessed, and stored (for example, if it is used for model retraining, or reviewed by employees or partners). If the Developer is an external entity, they shall provide this information to System Operators.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nInsufficient communication about data usage, access, or storage practices can lead to misunderstandings and mistrust among End-users. This lack of transparency increases the risk of misuse or unauthorized access to data, as users might not fully understand or consent to how their data is handled, potentially resulting in regulatory and reputational damage.\n\nExample Measures/Controls:\nEstablish Transparent Data Usage Communication: Provide a transparent overview of data usage policies, purpose of processing, specifying whether data will be used for model retraining, third-party access, or employee review. Each processing activity needs to be logged, and a compatibility assessment needs to be made for each new purpose. Ensure end users understand all potential uses of their data and how it contributes to AI model performance or security and that documentation is an accessible format"
                    },
                    {
                        "requirementID": "Provision 5.3.1-2",
                        "requirementText": "\"System Operators shall provide End-users with accessible guidance to support their use, management, integration, and configuration of AI systems. If the Developer is an external entity, they shall provide all necessary information to help System Operators.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nWithout clear guidance, End-users might mismanage the software, leading to data leaks, vulnerabilities, or system misuse, exposing AI systems to security risks.\n\nExample Measures/Controls:\nProvide Comprehensive User Guides and Tutorials: Develop and distribute detailed user guides and tutorials that cover secure configuration, integration steps, and recommended usage practices, ensuring users understand safe operation protocols. Provide accessible notification options, such as screen reader-compatible text alerts, and customisable notifications for users with sensory impairments."
                    },
                    {
                        "requirementID": "Provision 5.3.1-2.1",
                        "requirementText": "\"System Operators shall include guidance on the appropriate use of the model or system, which includes highlighting limitations and potential failure modes.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nFailing to highlight limitations and potential failure modes can lead to End-users relying on the AI system for unsupported or inappropriate tasks, increasing the risk of operational errors, data misuse, or unintended consequences.\n\nExample Measures/Controls:\nHighlight Model Limitations and Failure Modes: Clearly outline the model's appropriate uses, limitations, and potential failure modes to inform end-users of scenarios in which the model might produce inaccurate or unreliable outputs."
                    },
                    {
                        "requirementID": "Provision 5.3.1-2.2",
                        "requirementText": "\"System Operators shall proactively inform End-users of any security relevant updates and provide clear explanations in an accessible way.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nWithout proactive communication about security-relevant updates, End-users can fail to understand changes in system behaviour or associated risks. This lack of awareness can lead to improper use or failure to take necessary precautions, increasing the system's exposure to potential exploitation or security breaches.\n\nExample Measures/Controls:\nNotify Users of Security Updates: Proactively inform End-users about security update, detailing the purpose and impact of each update to promote user compliance. Ensure all users, can be informed by using accessible formats."
                    },
                    {
                        "requirementID": "Provision 5.3.1-3",
                        "requirementText": "\"Developers and System Operators should support affected End-users and Affected Entities during and following a cyber security incident to contain and mitigate the impacts of an incident. The process for undertaking this should be documented and agreed in contracts with End-users.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nFailure to support affected End-users and Affected Entities during an incident can result in prolonged recovery times, mismanagement of containment efforts, and increased reputational damage due to inadequate communication or guidance.\n\nExample Measures/Controls:\nEstablish a Documented Incident Support and Communication Process: Develop and document a support process for responding to incidents, covering steps for containment, impact assessment, and recovery, and specify the roles and responsibilities of Developers and System Operators. This should include specialist skills and AI expertise that might be require. Provide support through accessible formats, ensuring usability for all affected stakeholders."
                    }
                ]
            }
        },
        "EU ": {
            "EU AI Act": {
                "link": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689",
                "requirements": [
                    {
                        "requirementID": "13.2 Transparency and Provision of Information to Deployers",
                        "requirementText": "High-risk AI systems shall be accompanied by instructions for use in an appropriate digital format or otherwise that include concise, complete, correct and clear information that is relevant, accessible and comprehensible to deployers."
                    },
                    {
                        "requirementID": "13.3 Transparency and Provision of Information to Deployers",
                        "requirementText": "The instructions for use shall contain at least the following information:\n(a)the identity and the contact details of the provider and, where applicable, of its authorised representative;\n(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including:\n(i)its intended purpose;\n(ii)the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity;\n(iii)any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2);\n(iv)where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output;\n(v)when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used;\n(vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system;\n(vii)where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;\n(c) the changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any;\n(d) the human oversight measures referred to in Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of the high-risk AI systems by the deployers;\n(e) the computational and hardware resources needed, the expected lifetime of the high-risk AI system and any necessary maintenance and care measures, including their frequency, to ensure the proper functioning of that AI system, including as regards software updates;\n(f) where relevant, a description of the mechanisms included within the high-risk AI system that allows deployers to properly collect, store and interpret the logs in accordance with Article 12."
                    },
                    {
                        "requirementID": "15.3 Accuracy, Robustness and Cybersecurity",
                        "requirementText": "The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use."
                    },
                    {
                        "requirementID": "26.7 Obligations of deployers of high-risk AI systems",
                        "requirementText": "Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system. This information shall be provided, where applicable, in accordance with the rules and procedures laid down in Union and national law and practice on information of workers and their representatives."
                    },
                    {
                        "requirementID": "26.8 Obligations of deployers of high-risk AI systems",
                        "requirementText": "Deployers of high-risk AI systems that are public authorities, or Union institutions, bodies, offices or agencies shall comply with the registration obligations referred to in Article 49. When such deployers find that the high-risk AI system that they envisage using has not been registered in the EU database referred to in Article 71, they shall not use that system and shall inform the provider or the distributor."
                    },
                    {
                        "requirementID": "26.11 Obligations of deployers of high-risk AI systems",
                        "requirementText": "Without prejudice to Article 50 of this Regulation, deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system. For high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 shall apply."
                    },
                    {
                        "requirementID": "50.2 Transparency obligations for providers and deployers of certain AI systems",
                        "requirementText": "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences."
                    },
                    {
                        "requirementID": "50.4 Transparency obligations for providers and deployers of certain AI systems",
                        "requirementText": "Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.\n\nDeployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content."
                    },
                    {
                        "requirementID": "50.5 Transparency obligations for providers and deployers of certain AI systems",
                        "requirementText": "The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements."
                    },
                    {
                        "requirementID": "53.1 Obligations for providers of general purpose AI models",
                        "requirementText": "Providers of general-purpose AI models shall:\n(a) draw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation, which shall contain, at a minimum, the information set out in Annex XI for the purpose of providing it, upon request, to the AI Office and the national competent authorities;\n(b) draw up, keep up-to-date and make available information and documentation to providers of AI systems who intend to integrate the general-purpose AI model into their AI systems. Without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law, the information and documentation shall:\n(i) enable providers of AI systems to have a good understanding of the capabilities and limitations of the general-purpose AI model and to comply with their obligations pursuant to this Regulation; and\n(ii) contain, at a minimum, the elements set out in Annex XII;\n(c) put in place a policy to comply with Union law on copyright and related rights, and in particular to identify and comply with, including through state-of-the-art technologies, a reservation of rights expressed pursuant to Article 4(3) of Directive (EU) 2019/790;\n(d) draw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office."
                    },
                    {
                        "requirementID": "53.2 Obligations for providers of general purpose AI models",
                        "requirementText": "The obligations set out in paragraph 1, points (a) and (b), shall not apply to providers of AI models that are released under a free and open-source licence that allows for the access, usage, modification, and distribution of the model, and whose parameters, including the weights, the information on the model architecture, and the information on model usage, are made publicly available. This exception shall not apply to general-purpose AI models with systemic risks."
                    }
                ]
            }
        },
        "European Commission": {
            "Assessment List for Trustworthy Artificial Intelligence (ALTAI)": {
                "link": "https://digital-strategy.ec.europa.eu/en/library/assessment-list-trustworthy-artificial-intelligence-altai-self-assessment",
                "requirements": [
                    {
                        "requirementID": "REQUIREMENT #4 Transparency",
                        "requirementText": "A crucial component of achieving Trustworthy AI is transparency which encompasses three elements: 1) traceability, 2) explainability and 3) open communication about the limitations of the AI system."
                    }
                ]
            },
            "Ethics guidelines for trustworthy AI": {
                "link": "https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai",
                "requirements": [
                    {
                        "requirementID": "1.1.2 Human Agency",
                        "requirementText": "Users should be able to make informed autonomous decisions regarding AI systems. They should be given the knowledge and tools to comprehend and interact with AI systems to a satisfactory degree and, where possible, be enabled to reasonably self-assess or challenge the system. AI systems should support individuals in making better, more informed choices in accordance with their goals. AI systems can sometimes be deployed to shape and influence human behaviour through mechanisms that may be difficult to detect, since they may harness sub-conscious processes, including various forms of unfair manipulation, deception, herding and conditioning, all of which may threaten individual autonomy. The overall principle of user autonomy must be central to the system’s functionality. Key to this is the right not to be subject to a decision based solely on automated processing when this produces legal effects on users or similarly significantly affects them."
                    },
                    {
                        "requirementID": "1.4.3 Communication",
                        "requirementText": "AI systems should not represent themselves as humans to users; humans have the right to be informed that they are interacting with an AI system. This entails that AI systems must be identifiable as such. In addition, the option to decide against this interaction in favour of human interaction should be provided where needed to ensure compliance with fundamental rights. Beyond this, the AI system’s capabilities and limitations should be communicated to AI practitioners or end-users in a manner appropriate to the use case at hand. This could encompass communication of the AI system's level of accuracy, as well as its limitations."
                    }
                ]
            }
        },
        "Google": {
            "Secure AI Framework": {
                "link": "https://www.saif.google/secure-ai-framework",
                "requirements": [
                    {
                        "requirementID": "User Data Management",
                        "requirementText": "Store, process, and use all user data (e.g. prompts and logs) from AI applications in compliance with user consent."
                    },
                    {
                        "requirementID": "User Transparency and Controls",
                        "requirementText": "Inform users of relevant AI risks with disclosures, and provide transparency and control experiences for use of their data in AI applications."
                    },
                    {
                        "requirementID": "User Policies and Education",
                        "requirementText": "Publish easy to understand AI security and privacy policies and education for users."
                    }
                ]
            }
        },
        "ICO": {
            "Guidance on the AI Auditing Framework - Draft guidance for consultation ": {
                "link": "https://ico.org.uk/media2/about-the-ico/consultations/2617219/guidance-on-the-ai-auditing-framework-draft-for-consultation.pdf",
                "requirements": [
                    {
                        "requirementID": "What steps should we take to manage the risks of privacy attacks on AI models? - 3",
                        "requirementText": "As part of your procurement policy there should be sufficient information sharing between each party to perform your respective assessments as necessary. In some cases, ML model providers and clients will be joint controllers and therefore need to perform a joint risk assessment."
                    }
                ]
            }
        },
        "IMDA": {
            "Model AI Governance Framework for Agentic AI": {
                "link": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
                "requirements": [
                    {
                        "requirementID": "2.2.1 End Users",
                        "requirementText": "Organisations may deploy agents to users within or outside their organisation. In doing so, organisations should ensure that users are provided sufficient information to hold the organisation accountable, as well as any information relating to the user’s own responsibilities. More information can be found in Enabling end-user responsibility below."
                    },
                    {
                        "requirementID": "2.4 Enable end-user responsibility",
                        "requirementText": "Ultimately, end users are the ones who use and rely on agents, and human accountability also extends to these users. Organisations should provide sufficient information to end users to promote trust and enable responsible use.\nOrganisations should consider:\n• Transparency: Users should be informed of the agents’ capabilities (e.g. scope of agent’s access to user’s data, actions the agent can take) and the contact points whom users can escalate to if the agent malfunctions.\n• Education: Users should be educated on proper use and oversight of agents (e.g. training should be provided on an agent’s range of actions, common failure modes like hallucinations, usage policies for data), as well as the potential loss of trade craft i.e. as agents take over more functions, basic operational knowledge could be eroded. Hence sufficient training (especially in areas where agents are prevalent) should be provided to ensure that humans retain core skills."
                    },
                    {
                        "requirementID": "2.4.1 Different users, different needs",
                        "requirementText": "Organisations should cater to different users with different information needs, to enable such users to use AI responsibly. Broadly, there are two main archetypes of end-users – those who interact with agents, and those who integrate agents into their work processes or oversee them."
                    },
                    {
                        "requirementID": "2.4.2 Users who interact with agents",
                        "requirementText": "Such users usually interact with agents that act on behalf of the organisation, e.g. customer service or sales agents. These agents tend to be external facing, although they can also be deployed within the organisation e.g. a human resource agent that interacts with other users in the organisation.\nFor these users, focus on transparency. Organisations should share pertinent information to foster trust and facilitate proper usage of agents. Such information can include:\n• User’s responsibilities: Clearly define the user’s responsibilities, such as asking the user to double-check all information provided by the agent.\n• Interaction: Declare upfront that the users are interacting with agents.\n• Agents’ range of actions and decisions: Inform the users on the range of actions and decisions that the agent is authorised to perform and make.\n• Data: Be clear on how user data is collected, stored, and used by the agents, in accordance with the organisation's data privacy policies. Where necessary, obtain explicit consent from users before collecting or using their data for the agents.\n• Human accountability and escalation: Provide users with the respective human contact points who are responsible for the agents, whom the users can alert if the agents malfunction or if they are dissatisfied with a decision."
                    }
                ]
            }
        },
        "ISO": {
            "42001:2023 - Information technology — Artificial intelligence — Management system": {
                "link": "https://www.iso.org/standard/42001",
                "requirements": [
                    {
                        "requirementID": "7.3",
                        "requirementText": "Awareness"
                    },
                    {
                        "requirementID": "7.4",
                        "requirementText": "Communication"
                    }
                ]
            }
        },
        "METI (Japan)": {
            "Governance Guidelines for Implementation of AI Principles": {
                "link": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20220128_2.pdf",
                "requirements": [
                    {
                        "requirementID": "Action Target 3-1-2",
                        "requirementText": "In case that a certain degree of gaps may potentially occur with AI systems of AI system operators that provide services to AI system users, they should, under the leadership of top management, provide sufficient information about the gaps and measures to address the gaps, as well as make a contact point easily accessible."
                    },
                    {
                        "requirementID": "Action Target 3-3",
                        "requirementText": "Under the leadership of top management and with due consideration for trade secrets, companies that develop and operate AI systems and those that provide data should, except where everything from the preparation of data sets for training and other purposes to AI system development and operation is performed entirely within their own department, clarify and actively share, in accordance with the Principle of Fair Competition, AI system operational issues that the company or department is unable to fully address on their own and the information necessary to address these issues. In doing so, in order to facilitate the exchange of information clarified above, the AI system developer, AI system operator, and data provider are encouraged to agree on scope of information disclosure in advance and consider measures to protect trade secrets, for example, by entering a non-disclosure agreement."
                    }
                ]
            }
        },
        "MIC/METI (Japan)": {
            "AI Guidelines for Business": {
                "link": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20240419_9.pdf",
                "requirements": [
                    {
                        "requirementID": "Human-Centric - 4",
                        "requirementText": "In addition to ensuring fairness, to prevent information poverty and digital poverty and allow more people to enjoy the benefits of AI, pay attention to make it easy for socially vulnerable people to use AI. Adopt universal design, ensure accessibility, and provide relevant stakeholders with education and support."
                    },
                    {
                        "requirementID": "Human-Centric - 5",
                        "requirementText": "Offer rational information about the functions and peripheral technologies of the AI system or service, and allow users to use functions that timely and appropriately offer the information for judging choices. For example, default settings, provision of understandable options, provision of feedbacks, alerts in an emergency, and handling of errors."
                    },
                    {
                        "requirementID": "Transparency - 2 (a)",
                        "requirementText": "Based on the relations with AI and the nature and purpose of AI, provide and explain information summarizing the items listed below according to the knowledge and ability of each stakeholder.\n- AI systems and services in general\n- Fact that AI is used and its scope\n- Methods for data collection and annotation\n- Methods for training and evaluation\n- Information on the underlying AI models\n- Capabilities and limitations of the AI system or service, and proper/improper use by AI business users\n- Relevant laws applicable in the country/region where those provided with the AI system or service or AI business users are located"
                    },
                    {
                        "requirementID": "Transparency - 2 (b)",
                        "requirementText": "Encourage a variety of stakeholders to engage actively through dialogues and collect various opinions on social impacts and safety."
                    },
                    {
                        "requirementID": "Transparency - 2 (c)",
                        "requirementText": "In addition, show actual advantages of providing or using the AI system or service and risks to relevant stakeholders."
                    },
                    {
                        "requirementID": "Transparency - 3 (a)",
                        "requirementText": "Provision of information to stakeholders described above \"(2) Providing relevant stakeholders with information\" doesn’t assume disclosure of algorithms or source code, but it assumes providing them to the extent that satisfies social rationality based on the characteristics and uses of the technologies to be adopted while respecting privacy and trade secrets."
                    },
                    {
                        "requirementID": "Transparency - 4",
                        "requirementText": "Share necessary explanations for those to be explained with actors who explain to analyze requirements of such explanation to gain relevant stakeholders' understanding and sense of safety to provide proof of AI operations.\nAI provider: Inform the AI developer about things that are required to be explained.\nAI business user: Inform the AI developer and AI provider about things that are required to be explained."
                    },
                    {
                        "requirementID": "Accountability - 5 (b)",
                        "requirementText": "As necessary, set opportunities for accepting comments from stakeholders on incorrect AI output and the like, and conduct objective monitoring of the output."
                    },
                    {
                        "requirementID": "Accountability - 5 (c)",
                        "requirementText": "Set policies to handle cases that might affect the interests of stakeholders. Execute those policies reliably and report the progress regularly to the stakeholders as necessary."
                    },
                    {
                        "requirementID": "Education/literacy - 3",
                        "requirementText": "To improve the safety of the whole AI system or AI service, provide stakeholders with education and literacy advancement as necessary."
                    },
                    {
                        "requirementID": "Innovation - 3",
                        "requirementText": "Provide necessary information to the extent that does not hinder the innovation of the information provider."
                    }
                ]
            }
        },
        "Microsoft": {
            "Responsible AI Standard": {
                "link": "https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft-Responsible-AI-Standard-General-Requirements.pdf?culture=en-us&country=us",
                "requirements": [
                    {
                        "requirementID": "A3.7",
                        "requirementText": "If an intended use is not supported by evidence, or if evidence comes to light that refutes that the system is fit for purpose for the intended use at any point in the system’s use:\n1) remove the intended use from customer-facing materials and make current customers aware of the issue, take action to close the identified gap, or discontinue the system,\n2) revise documentation related to the intended use, and\n3) publish the revised documentation to customers.\nWhen the system is a platform service made available to external customers or partners, include this information in the required Transparency Note."
                    },
                    {
                        "requirementID": "A3.8",
                        "requirementText": "Communicate with care about system benefits; follow any applicable guidance from your attorney."
                    },
                    {
                        "requirementID": "T1.2",
                        "requirementText": "Design the system, including, when possible, the system UX, features, reporting functions, and educational materials, so that stakeholders identified in requirement T1.1 can:\n1) understand the system’s intended uses,\n2) interpret relevant system behavior effectively (i.e., in a way that supports informed decision making), and\n3) remain aware of the possible tendency of over-relying on outputs produced by the system (\"automation bias\").\nFor the two categories of stakeholders identified in requirement T1.1, document:\n1) how the system design will support their understanding of the system’s intended uses, and\n2) how the system aids their ability to interpret relevant system responses, and\n3) how the system design discourages automation bias."
                    },
                    {
                        "requirementID": "T3.2",
                        "requirementText": "Design the system, including system UX, features, reporting functions, educational materials, and outputs so that stakeholders identified in T3.1 will be informed of the type of AI system they are interacting with or exposed to. Ensure that any image, audio, or video outputs that are intended to be used outside the system are labelled as being produced by AI."
                    },
                    {
                        "requirementID": "T3.3",
                        "requirementText": "Define and document the method to be used to evaluate whether each stakeholder identified in T3.1 is informed of the type of AI system they are interacting with or exposed to."
                    },
                    {
                        "requirementID": "F1.9",
                        "requirementText": "Publish information for customers about:\n1) identified demographic groups for which performance may not meet any target minimum performance level,\n2) any remaining performance disparities between identified demographic groups that may exceed the target maximum, and\n3) any justifiable factors that account for these performance levels and differences.\nWhen the system is a platform service made available to external customers or partners, include this information in the required Transparency Note."
                    },
                    {
                        "requirementID": "RS2.4",
                        "requirementText": "Provide training and documentation for system owners, developers, customer support and other stakeholders responsible for managing the system to support their remediation and mitigation of predictable failures identified in requirement RS2.1. Document the training and documentation provided."
                    },
                    {
                        "requirementID": "RS3.7",
                        "requirementText": "If evidence comes to light that refutes the system is fit for purpose for an intended use at any point in the system’s use:\n1) remove the intended use from customer-facing materials and make current customers aware of the issue, take action to close the identified gap, or discontinue the system,\n2) revise documentation related to the intended use, and\n3) publish the revised documentation to customers.\nWhen the system is a platform service made available to external customers or partners, include this information in the required Transparency Note."
                    }
                ]
            }
        },
        "Multi Agency": {
            "Guidelines for secure AI system development": {
                "link": "https://www.ncsc.gov.uk/files/Guidelines-for-secure-AI-system-development.pdf",
                "requirements": [
                    {
                        "requirementID": "Make it easy for users to do the right things",
                        "requirementText": "You recognise that each new setting or configuration option is to be assessed in conjunction with the business benefit it derives, and any security risks it introduces. Ideally, the most secure setting will be integrated into the system as the only option. When configuration is necessary, the default option should be broadly secure against common threats (that is, secure by default). You apply controls to prevent the use or deployment of your system in malicious ways.\n\nYou provide users with guidance on the appropriate use of your model or system, which includes highlighting limitations and potential failure modes. You state clearly to users which aspects of security they are responsible for, and are transparent about where (and how) their data might be used, accessed or stored (for example, if it is used for model retraining, or reviewed by employees or partners)."
                    }
                ]
            }
        },
        "NIST": {
            "AI 800-1": {
                "link": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.800-1.ipd2.pdf",
                "requirements": [
                    {
                        "requirementID": "Practice 6.1: Monitor for evidence of misuse - 4",
                        "requirementText": "Request that distribution channels monitor for misuse and share information regarding this monitoring."
                    },
                    {
                        "requirementID": "Practice 6.3: Establish misuse reporting mechanisms - 1",
                        "requirementText": "Adopt policies that protect and reward individuals who report model issues related to misuse risk."
                    },
                    {
                        "requirementID": "Practice 6.3: Establish misuse reporting mechanisms - 3",
                        "requirementText": "Communicate the identified issues or misuse instances clearly with employees and contractors, as appropriate."
                    },
                    {
                        "requirementID": "Practice 7.1: Publish transparency reports - 4",
                        "requirementText": "Share steps that downstream developers and deployers of AI systems that integrate the foundation model should take to manage misuse risk."
                    },
                    {
                        "requirementID": "Practice 7.1: Publish transparency reports - 5",
                        "requirementText": "Share relevant details about the internal organizational processes used to create risk assessments and to make deployment and development decisions."
                    },
                    {
                        "requirementID": "Practice 7.1: Publish transparency reports - 6",
                        "requirementText": "Make the transparency reports publicly available, update them on a regular basis (e.g., with each new major version of the model), and include key information related to misuse risk."
                    },
                    {
                        "requirementID": "Practice 7.2: Disclose information about risk management practices - 1",
                        "requirementText": "Share information covering the practices used to achieve the objectives listed in this document, including at least as much detail as described in the documentation sections for each practice."
                    },
                    {
                        "requirementID": "Practice 7.2: Disclose information about risk management practices - 2",
                        "requirementText": "Share information about threat profiles with other entities across the AI supply chain and the public to develop a joint knowledge base and save resources."
                    },
                    {
                        "requirementID": "Practice 7.3: Report misuse incidents - 3",
                        "requirementText": "Share verified reports of misuse with relevant third parties, such as AI incident databases and other model developers."
                    }
                ]
            },
            "AI RMF 1.0": {
                "link": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
                "requirements": [
                    {
                        "requirementID": "MAP 5.2",
                        "requirementText": "Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented."
                    },
                    {
                        "requirementID": "MEASURE 3.3",
                        "requirementText": "Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics."
                    },
                    {
                        "requirementID": "MEASURE 4.1",
                        "requirementText": "Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Approaches are documented."
                    },
                    {
                        "requirementID": "MANAGE 4.3",
                        "requirementText": "Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented."
                    }
                ]
            },
            "IR 8596: Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile): NIST Community Profile": {
                "link": "https://csrc.nist.gov/pubs/ir/8596/iprd",
                "requirements": [
                    {
                        "requirementID": "ID.RA-08",
                        "requirementText": "Processes for receiving, analyzing, and responding to vulnerability disclosures are established"
                    },
                    {
                        "requirementID": "DE.AE-08",
                        "requirementText": "Incidents are declared when adverse events meet the defined incident criteria"
                    },
                    {
                        "requirementID": "RS.CO-02",
                        "requirementText": "Internal and external stakeholders are notified of incidents"
                    },
                    {
                        "requirementID": "RS.CO-03",
                        "requirementText": "Information is shared with designated internal and external stakeholders"
                    },
                    {
                        "requirementID": "RC.CO-03",
                        "requirementText": "Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders"
                    },
                    {
                        "requirementID": "RC.CO-04",
                        "requirementText": "Public updates on incident recovery are shared using approved methods and messaging"
                    }
                ]
            },
            "SP 800-218A": {
                "link": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218A.pdf",
                "requirements": [
                    {
                        "requirementID": "PO.1.3",
                        "requirementText": "Communicate requirements to all third parties who will provide commercial software components to the organization for use by the organization’s own software.\n\nInclude AI model development security in the requirements being communicated for third-party software components."
                    }
                ]
            }
        },
        "OECD": {
            "Due Diligence Guidance for Responsible AI": {
                "link": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2026/02/oecd-due-diligence-guidance-for-responsible-ai_7831bb49/41671712-en.pdf",
                "requirements": [
                    {
                        "requirementID": "Step 5 - Communicate actions to address impacts",
                        "requirementText": "Communicate externally relevant information on due diligence policies, processes, activities conducted to identify and address actual or potential adverse impacts, including the findings and outcomes of those activities. Communication could take a variety of forms depending on the target audience (e.g., stakeholder consultations and public communication through the enterprise’s annual, sustainability or corporate responsibility reports or other appropriate forms of disclosure required by legislation or voluntary initiatives)."
                    }
                ]
            }
        },
        "OpenAI": {
            "Safety Best Practices": {
                "link": "https://platform.openai.com/docs/guides/safety-best-practices",
                "requirements": [
                    {
                        "requirementID": "Allow users to report issues",
                        "requirementText": "Users should generally have an easily-available method for reporting improper functionality or other concerns about application behavior (listed email address, ticket submission method, etc). This method should be monitored by a human and responded to as appropriate."
                    }
                ]
            }
        },
        "OWASP": {
            "AI Exchange": {
                "link": "https://owaspai.org/docs/ai_security_overview/",
                "requirements": [
                    {
                        "requirementID": "1.3. Controls to limit the effects of unwanted behaviour - AI TRANSPARENCY",
                        "requirementText": "AI transparency: Informing users on the AI system’s properties to enable them to adjust how they rely on it, what data they are willing to send to it, and what additional mitigations to apply. These AI system properties can include:\n\nRough working of the model\nThe training approach\nType of data used and the source\nExpected accuracy and robustness of the AI system’s output\nAny residual (security) risks\nNote that transparency here is about providing abstract information regarding the AI system and is therefore something else than explainability of model decisions. The simplest form of transparencey is to inform users that an AI model is being involved. This is for example required by the EU AI Act for chatbots.\n\nSee the DISCRETE control for the balance between being transparent and being discrete about the model.\n\nExample: Informing users that when they choose an agent to perform a task, that the agent could be manipulated if it reads untrusted data and what consequences that could have (residual security risk) - followed by a recommendation to configure the permissions of the agent to the minimal set for the task."
                    },
                    {
                        "requirementID": "1.3. Controls to limit the effects of unwanted behaviour - EXPLAINABILITY",
                        "requirementText": "Explainability: Explaining how individual model decisions are made, a field referred to as Explainable AI (XAI), can aid in gaining user trust in the model. In some cases, this can also prevent overreliance, for example, when the user observes the simplicity of the ‘reasoning’ or even errors in that process. See this Stanford article on explainability and overreliance. Explanations of how a model works can also aid security assessors to evaluate AI security risks of a model."
                    }
                ]
            },
            "LLM Top 10": {
                "link": "https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/",
                "requirements": [
                    {
                        "requirementID": "LLM02: Sensitive Information Disclosure - 7",
                        "requirementText": "Provide guidance on avoiding the input of sensitive information. Offer training on best practices for interacting with LLMs securely."
                    },
                    {
                        "requirementID": "LLM02: Sensitive Information Disclosure - 8",
                        "requirementText": "Maintain clear policies about data retention, usage, and deletion. Allow users to opt out of having their data included in training processes.\n"
                    },
                    {
                        "requirementID": "LLM02: Sensitive Information Disclosure - 9",
                        "requirementText": "Limit the ability for users to override or access the system's initial settings, reducing the risk of exposure to internal configurations.\n"
                    },
                    {
                        "requirementID": "LLM09: Misinformation - 3",
                        "requirementText": "Encourage users to cross-check LLM outputs with trusted external sources to ensure the accuracy of the information. Implement human oversight and fact-checking processes, especially for critical or sensitive information. Ensure that human reviewers are properly trained to avoid overreliance on AI-generated content.\n"
                    },
                    {
                        "requirementID": "LLM09: Misinformation - 5",
                        "requirementText": "Identify the risks and possible harms associated with LLM-generated content, then clearly communicate these risks and limitations to users, including the potential for misinformation."
                    },
                    {
                        "requirementID": "LLM09: Misinformation - 7",
                        "requirementText": "Design APIs and user interfaces that encourage responsible use of LLMs, such as integrating content filters, clearly labeling AI-generated content and informing users on limitations of reliability and accuracy. Be specific about the intended field of use limitations.\n"
                    },
                    {
                        "requirementID": "LLM09: Misinformation - 8",
                        "requirementText": "Provide comprehensive training for users on the limitations of LLMs, the importance of independent verification of generated content, and the need for critical thinking. In specific contexts, offer domain-specific training to ensure users can effectively evaluate LLM outputs within their field of expertise."
                    }
                ]
            },
            "OWASP Top 10 for Agentic Applications for 2026": {
                "link": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
                "requirements": [
                    {
                        "requirementID": "ASI09: Human-Agent Trust Exploitation - 4",
                        "requirementText": "Allow reporting of suspicious interactions: In user-interactive systems, provide plain-language risk summary (not model-generated rationales) and a clear option for users to flag suspicious or manipulative agent behavior, triggering automated review or a temporary lockdown of agent capabilities."
                    },
                    {
                        "requirementID": "ASI09: Human-Agent Trust Exploitation - 8",
                        "requirementText": "Human-factors and UI safeguards: Visually differentiate high-risk recommendations using cues such as red borders, banners, or confirmation prompts, and periodically remind users of manipulation patterns and agent limitations. Where appropriate, avoid persuasive or emotionally manipulative language in safety-critical flows. Maintain appropriate training and assessment of personnel to ensure familiarity and consistency of perception of human-factors and UI."
                    }
                ]
            }
        },
        "Personal Data Protection Commission Singapore (PDPC)": {
            "Model Artificial Intelligence Governance Framework Second Edition": {
                "link": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/resource-for-organisation/ai/sgmodelaigovframework2.pdf",
                "requirements": [
                    {
                        "requirementID": "1. Clear roles and responsibilities for the ethical deployment of AI - c) (iii)",
                        "requirementText": "Reviewing communications channels and interactions with stakeholders to provide disclosure and effective feedback channels."
                    },
                    {
                        "requirementID": "Reproducibility - c)",
                        "requirementText": "Making available replication files (i.e. files that replicate each step of the AI model’s developmental process) to facilitate the process of testing and reproducing behaviours;"
                    },
                    {
                        "requirementID": "Interacting with consumers - a)",
                        "requirementText": "Making sure that consumers are aware that the products or services that they are considering are AI-enabled. Such information could be provided as part of a general product description."
                    },
                    {
                        "requirementID": "Interacting with consumers - b)",
                        "requirementText": "Providing information so that consumers know how the AI-enabled features are expected to behave during normal use. The information could be provided in more detailed descriptions or specifications of product features. This, however, may not be necessary for every feature that is AI-enabled. Organisations are encouraged to identify those features where providing additional information in this manner will enhance consumer trust. Similarly, if AI is used in decision-making, information may be provided so that consumers understand how decisions made with the assistance of AI may affect them. This can likewise be provided through descriptions of how the service will be provided."
                    },
                    {
                        "requirementID": "Interacting with consumers - c)",
                        "requirementText": "For AI-enabled features that consumers interact with regularly, providing information so that they understand why the AI-enabled feature is behaving in a certain way, and providing preference settings to allow consumers some influence over future behaviour where possible. As doing so requires more engineering effort (such as in the providing additional user interfaces to user history), and the level of information provided may be somewhat more detailed and personalised than feature descriptions, organisations will have to decide which of their product features will benefit from provision of this level of detail."
                    },
                    {
                        "requirementID": "Interacting with consumers - d)",
                        "requirementText": "For AI-augmented decisions that affect consumers, consider providing additional information so that they understand why the decisions were made; and for certain categories of such decisions, providing an appropriate channel to contest such decisions. The level of information that is provided will necessarily be detailed but this may not be necessary except for those scenarios where a customer is affected by the decision."
                    }
                ]
            }
        },
        "Qatar Central Bank": {
            "Artificial Intelligence Guidelines": {
                "link": "https://www.qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
                "requirements": [
                    {
                        "requirementID": "14.2.2",
                        "requirementText": "The User must provide the results of its own use testing and its specific data sources or other inputs and Human Oversight plan."
                    },
                    {
                        "requirementID": "15.2",
                        "requirementText": "The Entity must make available to QCB the full range of data an Al Provider is contractually obligated to provide to the Entity."
                    },
                    {
                        "requirementID": "19.5",
                        "requirementText": "In the event of a serious incident, the Entity should report the matter to QCB immediately after the Provider has established a causal link between the Al System and the serious incident or the reasonable likelihood of such a link."
                    },
                    {
                        "requirementID": "20.1",
                        "requirementText": "An Entity must notify Customers when they are interacting with an Al System."
                    },
                    {
                        "requirementID": "20.2",
                        "requirementText": "An Entity must be transparent with Customers about their use of Al through their conduct and through accurate, understandable, and accessible plain language disclosure."
                    },
                    {
                        "requirementID": "20.4",
                        "requirementText": "An Entity must provide information to Customers how to use the Al System and ensure Customers always have access to the instructions."
                    },
                    {
                        "requirementID": "20.5",
                        "requirementText": "An Entity must provide clear explanations of the types of data, types of variables and factors that influence the decision-making process used by Al Systems upon Customers' request."
                    },
                    {
                        "requirementID": "20.6",
                        "requirementText": "An Entity must disclose the manner in which an Al decision may affect an individual Customer, and whether the decision is reversible."
                    },
                    {
                        "requirementID": "20.8",
                        "requirementText": "An Entity will provide a visible and accessible feedback channel for questions or comments."
                    },
                    {
                        "requirementID": "21.3",
                        "requirementText": "Any subsequent complaint by an aggrieved Customer must be handled through standard customer complaint processes."
                    }
                ]
            }
        },
        "SDAIA (Saudi Arabia)": {
            "AI Ethics Principles": {
                "link": "https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf",
                "requirements": [
                    {
                        "requirementID": "Principle 6 – Transparency & Explainability - Plan and Design - 1",
                        "requirementText": "When designing a transparent and trusted AI system, it is vital to ensure that stakeholders affected by AI systems are fully aware and informed of how outcomes are processed. They should further be given access to and an explanation of the rationale for decisions made by the AI technology in an understandable and contextual manner. Decisions should be traceable. AI system owners must define the level of transparency for different stakeholders on the technology based on data privacy, sensitivity, and authorization of the stakeholders."
                    },
                    {
                        "requirementID": "Principle 6 – Transparency & Explainability - Plan and Design - 2",
                        "requirementText": "The AI system should be designed to include an information section in the platform to give an overview of the AI model decisions as part of the overall transparency application of the technology. Information sharing as a sub-principle should be adhered to with end-users and stakeholders of the AI system upon request or open to the public, depending on the nature of the AI system and target market. The model should establish a process mechanism to log and address issues and complaints that arise to be able to resolve them in a transparent and explainable manner."
                    },
                    {
                        "requirementID": "Principle 6 – Transparency & Explainability - Build and Validate - 2",
                        "requirementText": "Transparent and explainable algorithms ensure that stakeholders affected by AI systems, both individuals and communities, are fully informed when an outcome is processed by the AI system by providing the opportunity to request explanatory information from the AI system owner. This enables the identification of the AI decision and its respective analysis which facilitates its auditability as well as its explainability."
                    },
                    {
                        "requirementID": "Principle 6 – Transparency & Explainability - Deploy and Monitor - 1",
                        "requirementText": "Upon deployment of the AI system, performance metrics relating the AI system’s output, accuracy and alignment to priorities and objectives, as well as its measured impact on individuals and communities should be documented, available and accessible to stakeholders of the AI technology."
                    },
                    {
                        "requirementID": "Principle 6 – Transparency & Explainability - Deploy and Monitor - 2",
                        "requirementText": "Information on any system failures, data breaches, system breakdowns, etc. should be logged and stakeholders should be informed about these instances keeping the performance and execution of the AI system transparent. Periodic UI and UX testing should be conducted to avoid the risk of confusion, confirmation of biases, or cognitive fatigue of the AI system."
                    }
                ]
            }
        },
        "Smart Dubai (UAE)": {
            "AI Ethics Principles & Guidelines": {
                "link": "https://www.digitaldubai.ae/docs/default-source/ai-principles-resources/ai-ethics.pdf",
                "requirements": [
                    {
                        "requirementID": "1.2.3.2",
                        "requirementText": "In the case that critical decisions are of civic interest, public release of the results of the audit should be considered as a means of ensuring public processes remain accountable to those affected by them."
                    },
                    {
                        "requirementID": "1.2.4.3",
                        "requirementText": "AI operator organisations should make affected AI subjects aware of these procedures, and should design them in a convenient and user-friendly way."
                    },
                    {
                        "requirementID": "1.2.5.1",
                        "requirementText": "When informing an AI subject about significant choices they will make, AI systems should not unreasonably restrict the available options or otherwise attempt to influence their value judgements without the explicit consent of the AI subject in question."
                    },
                    {
                        "requirementID": "1.2.7.2",
                        "requirementText": "AI developer organisations should consider notifying customers and AI operator organisations of the use cases for which the system has been designed, and those for which it is not suitable."
                    },
                    {
                        "requirementID": "1.3.2.1",
                        "requirementText": "AI operator organisations should inform AI subjects when a significant decision affecting them has been made by an AI system."
                    },
                    {
                        "requirementID": "1.3.2.2",
                        "requirementText": "If an AI system can convincingly impersonate a human being, it should do so only after notifying the AI subject that it is an AI system."
                    },
                    {
                        "requirementID": "1.4.1.1",
                        "requirementText": "AI operator organisations could consider informing the aected AI subjects in understandable, non-technical language of:\n• the data that is ingested by the system;\n• the types of algorithms employed;\n• the categories into which people can be placed, and;\n• the most important features driving the outcomes of decisions"
                    },
                    {
                        "requirementID": "1.4.1.3",
                        "requirementText": "AI operator organisations should consider providing aected AI subjects with a means to request explanations for specific significant decisions, to the extent possible given the state of present research and the choice of model."
                    },
                    {
                        "requirementID": "1.4.2.1",
                        "requirementText": "AI operator organisations should consider providing a means by which people aected by a significant decision informed by AI can access the reasoning behind that decision."
                    }
                ]
            }
        },
        "U.S. Department of Health & Human Services": {
            "Trustworthy AI (TAI) Playbook: Executive Summary": {
                "link": "https://www.hhs.gov/sites/default/files/hhs-trustworthy-ai-playbook-executive-summary.pdf",
                "requirements": [
                    {
                        "requirementID": "Transparent / Explainable",
                        "requirementText": "All relevant individuals should understand how their data is being used and how AI systems make decisions; algorithms, attributes, and correlations should be open to inspection"
                    }
                ]
            }
        },
        "UAE Ministry of Cabinet Affairs": {
            "The UAE Charter for the Development and Use of Artificial Intelligence": {
                "link": "https://uaelegislation.gov.ae/en/policy/details/the-uae-charter-for-the-development-and-use-of-artificial-intelligence#:~:text=The%20charter%20covers%20the%20following%20priorities%20and,and%20use%20of%20AI%20in%20the%20country.",
                "requirements": [
                    {
                        "requirementID": "5. Transparancy",
                        "requirementText": "The UAE seeks to create a clear understanding of AI and how systems operate and make decisions, which helps build trust, enhance responsibility, and accountability in the use of these technologies.​​​​​​​"
                    }
                ]
            }
        }
    }
}