{
    "Disclaimer": [
        "The information in this database is for general guidance and is not to be relied upon as professional advice.",
        "DSIT has tried to ensure that the information on this database is accurate and up to date. DSIT will not accept liability for any loss and/or damage or inconvenience arising as a consequence of any use of or the inability to use any information on this website. DSIT endeavours to provide a reliable service; DSIT does not guarantee that its service will be uninterrupted or error-free. DSIT shall not be responsible for claims brought by third parties arising from your use of this database.",
        "DSIT assumes no responsibility for the contents of linked websites. The inclusion of any link should not be taken as endorsement of any kind by DSIT of the linked website or any association with its operators. DSIT has no control over the availability of the linked pages."
    ],
    "Copyright": "The copyright of the original material remains that of the original authors and any usage of excerpts in the mapping is made under fair use. References to organisations do not imply endorsement by DSIT.",
    "Version": "1.0",
    "Data": {
        "Central Bank of the UAE": {
            "Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E": {
                "link": "https://rulebook.centralbank.ae/en/rulebook/guidance-note-consumer-protection-and-responsible-adoption-and-use-artificial-intelligence",
                "requirements": [
                    {
                        "requirementID": "2. Governance and Accountability - b",
                        "requirementText": "Senior management and the Board of Directors of LFIs should be responsible and accountable for AI and ML systems and outcomes, model selection/development, deployment, accountability, appropriate human resourcing and oversight and monitoring and management on an on-going basis."
                    },
                    {
                        "requirementID": "6. Continuous Monitoring and Review - d",
                        "requirementText": "LFIs should remain responsible for outsourced AI functions and should consider: appropriate contractual rights with respect to audit and information rights from providers, be made aware of any material developments with the AI provider, appropriate termination/cease provisions, data protection, cyber security, performance guarantees, its compliance with laws/regulations and standards and any material developments with regard to the AI being outsourced/utilized. "
                    },
                    {
                        "requirementID": "6. Continuous Monitoring and Review - e",
                        "requirementText": "LFIs should at all times retain the clear and immediate ability, with human intervention, to cease use of an AI model system, technology or application deployed or utilized."
                    },
                    {
                        "requirementID": "7. Human Oversight and Consumer Protection - a",
                        "requirementText": "LFIs should ensure that AI and ML systems operate under meaningful human oversight and judgement, particularly for decisions that have significant implications for consumers and in respect of the ongoing selection of, determination as to third party providers of, deployment of and ongoing monitoring and general use of AI. Human oversight may be exercised through different models:\n(i) Human-in-the-loop – where a AI provides recommendations but a human decision maker retains full authority to approve or reject the outcome; \n(ii) Human-on-the-loop – where the AI works autonomously for routine tasks, while a human monitors outcomes and can intervene where necessary; \n(iii) Human-out-of-the-loop – where the AI operates without direct human involvement, which should only be utilised for low-risk, non-material processes with appropriate controls in place. "
                    },
                    {
                        "requirementID": "7. Human Oversight and Consumer Protection - b",
                        "requirementText": "The level of human involvement should be commensurate with the identified and potential risks posed to a consumer by any AI."
                    },
                    {
                        "requirementID": "7. Human Oversight and Consumer Protection - c",
                        "requirementText": "Consumers should be able to request human review or explanation of AI generated decisions, and alternative arrangements should be available where a customer does not wish to be subject to an AI decision. LFIs should maintain clear and accessible channels for complaints and redress in line with Article 8 of the Consumer Protection Regulation. Consumers should be informed of their right to challenge decisions, correct inaccurate data inputs having impact on AI and the process to challenge data and decisions by AI. A clear complaints-handling procedure/policy should be created, provided and accessible by customers on a regular basis. Complaints should be addressed in person, efficiently, confidentially and in as short at time as is reasonable in the circumstances."
                    },
                    {
                        "requirementID": "8. Integration with Existing Frameworks - b",
                        "requirementText": "Senior management should ensure that policies and procedures for AI adoption complement, rather than duplicate, existing regulatory obligations under the Consumer Protection Regulation and other CBUAE directives. For example, consumer risk arising from AI-driven models should be treated as part of the conduct risk framework, with appropriate reporting to the board and regulators. "
                    }
                ]
            }
        },
        "CISA": {
            "Principles for the Secure Integration of Artificial Intelligence in Operational Technology": {
                "link": "https://www.cisa.gov/sites/default/files/2026-01/joint-guidance-principles-for-the-secure-integration-of-artificial-intelligence-in-operational-technology-508cV2.pdf",
                "requirements": [
                    {
                        "requirementID": "3.1.1 Establish Governance Mechanisms for AI in OT",
                        "requirementText": "Effective governance structures are essential for the safe and secure integration of AI into OT environments. This involves establishing clear policies, procedures, and accountability structures for AI decision-making processes within OT. An AI governance structure should include the key stakeholders listed below, as well as any AI vendors needed for maintaining oversight during procurement, development, design, deployment, and operations."
                    },
                    {
                        "requirementID": "3.1.3 - Establishing clear roles and responsibilities",
                        "requirementText": "Ensure everyone involved in the development, deployment, and operations and maintenance of AI systems (e.g., data owners, model developers, and end users) understands their tasks and expectations—and to avoid liability and confusion over stakeholder responsibilities in the event of safety or operational incidents"
                    },
                    {
                        "requirementID": "4.1.1 - Human-in-the-Loop Decision-Making",
                        "requirementText": "Provide adequate transparency that involves operators and engineers in decision-making, especially for critical OT operations and actions. For more passive AI systems, operators and engineers can implement this by incorporating the recommendations into an existing change management process. Use caution with active AI systems directly influencing control, as problems can escalate before operators become aware of them. Where AI is actively updating control logic, use safety thresholds, alternative sensor output, or state changes that add human-in-the-loop intervention points."
                    }
                ]
            }
        },
        "Cloud Security Alliance (CSA)": {
            "AI Controls Matrix": {
                "link": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix",
                "requirements": [
                    {
                        "requirementID": "GRC-06",
                        "requirementText": "Define and document roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs."
                    },
                    {
                        "requirementID": "GRC-12",
                        "requirementText": "Establish an ethics committee to review AI applications, ensuring alignment with ethical standards and organizational values."
                    },
                    {
                        "requirementID": "GRC-15",
                        "requirementText": "Establish, execute, and assess processes, procedures, and technical measures to ensure human oversight and control of the AI system in compliance with regulatory requirements and organizational risk management."
                    },
                    {
                        "requirementID": "HRS-09",
                        "requirementText": "Document and communicate roles and responsibilities of employees, as they relate to information assets and security."
                    },
                    {
                        "requirementID": "STA-02",
                        "requirementText": "Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the application of the Shared Security Responsibility Model (SSRM) within the organization. Review and update the policies and procedures at least annually, or upon significant changes."
                    },
                    {
                        "requirementID": "STA-03",
                        "requirementText": "Apply, document, implement and manage the SSRM throughout the supply chain."
                    },
                    {
                        "requirementID": "STA-06",
                        "requirementText": "Review and validate SSRM documentation."
                    },
                    {
                        "requirementID": "STA-07",
                        "requirementText": "Implement, operate, and audit or assess the portions of the SSRM which the organization is responsible for."
                    }
                ]
            }
        },
        "CoSAI": {
            "AI Incident Response Framework": {
                "link": "https://github.com/cosai-oasis/ws2-defenders/blob/main/incident-response/AI%20Incident%20Response.md",
                "requirements": [
                    {
                        "requirementID": "3.3.2. Detection and Analysis Phase - Detection Mechanisms - Manual Review",
                        "requirementText": "• Human review procedures for flagged interactions\n• Sampling of high-risk operations\n• Security dashboards\n• Escalation triggers"
                    }
                ]
            },
            "Model Context Protocol (MCP) Security": {
                "link": "https://github.com/cosai-oasis/ws4-secure-design-agentic-systems/blob/main/model-context-protocol-security.md",
                "requirements": [
                    {
                        "requirementID": "3.2.9 Human-in-the-loop",
                        "requirementText": "There is the possibility that a large language model, legit or poisoned, decides to execute a tool in a dangerous way. MCP hosts and clients, in general, allow users to disable the confirmation prompt. There are two approaches organizations considering this risk unacceptable may implement to reduce its probability and impact:\n\nenforce the use of MCP hosts and clients with a configuration that unprivileged users cannot change and that keeps the confirmation prompt enabled.\nuse elicitation on the MCP server side to request the user confirmation of actions."
                    }
                ]
            }
        },
        "Cyber Security Council (UAE)": {
            "National Cyber Security Policy for Artificial Intelligence": {
                "link": "https://csc.gov.ae/documents/38662/0/National+Cyber+Security+Policy+for+Artificial+Intelligence_v1.1.pdf/4e02b32e-9f62-948d-4bc8-b580d596451b?t=1766994254544",
                "requirements": [
                    {
                        "requirementID": "3.1.1 Cyber Security Policies & Procedures - 2",
                        "requirementText": "The AI/ML cyber security policy should define roles and responsibilities for security within the AI/ML lifecycle, providing clarity on who is responsible for implementing, monitoring, and enforcing these policies."
                    },
                    {
                        "requirementID": "3.2.1 Asset Management for AI/ML Systems - 4",
                        "requirementText": "The entity should establish clear ownership and accountability for each AI/ML asset, including responsibility for its security and compliance."
                    },
                    {
                        "requirementID": "3.6.2 Incident Reporting and Management for AI/ML - 5",
                        "requirementText": "In cases where automated response mechanisms may not be suitable, or fully effective, the entity should implement a fail-safe mechanism that allows for timely and informed human intervention."
                    }
                ]
            }
        },
        "ETSI": {
            "EN 304 223 - Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems": {
                "link": "https://www.etsi.org/deliver/etsi_en/304200_304299/304223/02.01.01_60/en_304223v020101p.pdf",
                "requirements": [
                    {
                        "requirementID": "Provision 5.1.4-1",
                        "requirementText": "When designing an AI system, Developers and/or System Operators should incorporate and maintain capabilities to enable human oversight."
                    },
                    {
                        "requirementID": "Provision 5.1.4-2",
                        "requirementText": "Developers should design systems to make it easy for humans to assess outputs that they are responsible for in said system (such as by ensuring that models outputs are explainable or interpretable)."
                    },
                    {
                        "requirementID": "Provision 5.1.4-3",
                        "requirementText": "Where human oversight is a risk control, Developers and/or System Operators shall design, develop, verify and maintain technical measures to reduce the risk through such oversight."
                    },
                    {
                        "requirementID": "Provision 5.1.4-4",
                        "requirementText": "Developers should verify that the security controls specified by the Data Custodian have been built into the system."
                    },
                    {
                        "requirementID": "Provision 5.1.4-5",
                        "requirementText": "Developers and System Operators should make End-users aware of prohibited use cases of the AI system."
                    }
                ]
            },
            "TR 104 128 - Securing Artificial Intelligence (SAI); Guide to Cyber Security for AI Models and Systems": {
                "link": "https://www.etsi.org/deliver/etsi_tr/104100_104199/104128/01.01.01_60/tr_104128v010101p.pdf",
                "requirements": [
                    {
                        "requirementID": "Provision 5.1.4-1",
                        "requirementText": "\"When designing an AI system, Developers and/or System Operators should incorporate and maintain capabilities to enable human oversight.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nWithout built-in human oversight, AI systems will generate incorrect outputs or decisions that are difficult to interpret, verify, or override, increasing risks of data protection compliance, unintended consequences, misuse, or harmful impacts.\n\nExample Measures/Controls 1:\nImplement Mechanisms for Human Oversight: Control: Implement features that allow human operators to easily interpret, verify, and act on AI outputs, including manual release and overrides. Ensure that the design meet obligations around automated decisions and encourages meaningful human decision-making rather than passive acceptance of AI recommendations.\n\nExample Measures/Controls 2:\nMeasure and Validate Accuracy of Human Oversight Decisions: Regularly test and measure the accuracy of human oversight decisions, validating that operators can correctly interpret and act on AI outputs and identifying areas for improvement. Assess not just individual performance but how the system supports human understanding and engagement to foster effective sociotechnical communication between the operator and AI."
                    },
                    {
                        "requirementID": "Provision 5.1.4-2",
                        "requirementText": "\"Developers should design systems to make it easy for humans to assess outputs that they are responsible for in said system (such as by ensuring that models outputs are explainable or interpretable).\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nWithout clarity and ease of use, users can not perform oversight effectively leading to failures and harm.\n\nExample Measures/Controls:\nDevelop User-Friendly Human Responsibility UI: Implement UIs that display outputs, decision-making rationales, and logs clearly to make it easy for human operators to assess outputs and understand their accountability. Ensure systems are designed to encourage rigorous assessment by humans and not condition them to simply click an approve button."
                    },
                    {
                        "requirementID": "Provision 5.1.4-3",
                        "requirementText": "\"Where human oversight is a risk control, Developers and/or System Operators shall design, develop, verify, and maintain technical measures to reduce the risk through such oversight.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nIneffective oversight technical measures can compromise the risk reduction effort by overburdening or failing to adequately support human reviewers.\n\nExample Measures/Controls:\nImplement Validation and Enforcement of Oversight controls: Design and implement technical measures that provide guardrails to assist human reviewers in understanding, interpreting, and acting on AI outputs."
                    },
                    {
                        "requirementID": "Provision 5.1.4-4",
                        "requirementText": "\"Developers should verify that the security controls specified by the Data Custodian have been built into the system.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nWithout validation of Data Custodian controls, the system can lack necessary data protection and governance measures, potentially leading to security vulnerabilities or regulatory non-compliance.\n\nExample Measures/Controls:\nConduct Validation of Custodian: Verify that all controls specified by the Data Custodian have been implemented correctly, with testing to validate effectiveness and alignment with data protection requirements and guidance."
                    },
                    {
                        "requirementID": "Provision 5.1.4-5",
                        "requirementText": "\"Developers and System Operators should make End-users aware of prohibited use cases of the AI system.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nWithout clear communication on prohibited uses, end-users can unintentionally misuse the AI system, leading to legal, ethical, or operational risks.\n\nExample Measures/Controls 1:\nDocument and Train Users on Prohibited Use Cases: Clearly define and document prohibited use cases for the AI system, ensuring end-users understand limitations and restrictions. Use threat modelling to identify and inform users of all known harmful states and unmitigated risks.\n\nExample Measures/Controls 2:\nMonitor for Prohibited Use Cases: Implement controls to actively monitor, detect, and prevent prohibited use cases."
                    }
                ]
            }
        },
        "EU ": {
            "EU AI Act": {
                "link": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689",
                "requirements": [
                    {
                        "requirementID": "13.1 Transparency and Provision of Information to Deployers",
                        "requirementText": "High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately. An appropriate type and degree of transparency shall be ensured with a view to achieving compliance with the relevant obligations of the provider and deployer set out in Section 3."
                    },
                    {
                        "requirementID": "14.1 Human Oversight",
                        "requirementText": "High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use."
                    },
                    {
                        "requirementID": "14.2 Human Oversight",
                        "requirementText": " Human oversight shall aim to prevent or minimise the risks to health, safety or fundamental rights that may emerge when a high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, in particular where such risks persist despite the application of other requirements set out in this Section."
                    },
                    {
                        "requirementID": "14.4 Human Oversight",
                        "requirementText": " For the purpose of implementing paragraphs 1, 2 and 3, the high-risk AI system shall be provided to the deployer in such a way that natural persons to whom human oversight is assigned are enabled, as appropriate and proportionate:\n(a) to properly understand the relevant capacities and limitations of the high-risk AI system and be able to duly monitor its operation, including in view of detecting and addressing anomalies, dysfunctions and unexpected performance;\n(b) to remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias), in particular for high-risk AI systems used to provide information or recommendations for decisions to be taken by natural persons;\n(c) to correctly interpret the high-risk AI system’s output, taking into account, for example, the interpretation tools and methods available;\n(d) to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output of the high-risk AI system;\n(e) to intervene in the operation of the high-risk AI system or interrupt the system through a ‘stop’ button or a similar procedure that allows the system to come to a halt in a safe state."
                    },
                    {
                        "requirementID": "26.2 Obligations of deployers of high-risk AI systems",
                        "requirementText": "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support."
                    },
                    {
                        "requirementID": "26.3 Obligations of deployers of high-risk AI systems",
                        "requirementText": "The obligations set out in paragraphs 1 and 2, are without prejudice to other deployer obligations under Union or national law and to the deployer’s freedom to organise its own resources and activities for the purpose of implementing the human oversight measures indicated by the provider."
                    }
                ]
            }
        },
        "European Commission": {
            "Assessment List for Trustworthy Artificial Intelligence (ALTAI)": {
                "link": "https://digital-strategy.ec.europa.eu/en/library/assessment-list-trustworthy-artificial-intelligence-altai-self-assessment",
                "requirements": [
                    {
                        "requirementID": "REQUIREMENT #1 Human Agency and Oversight",
                        "requirementText": "AI systems should support human agency and human decision-making, as prescribed by the principle of respect for human autonomy. This requires that AI systems should both: act as enablers for a democratic, flourishing and equitable society by supporting the user’s agency; and uphold fundamental rights, which should be underpinned by human oversight. In this section AI systems are assessed in terms of their respect for human agency and autonomy as well as human oversight."
                    },
                    {
                        "requirementID": "REQUIREMENT #7 Accountability",
                        "requirementText": "The principle of accountability necessitates that mechanisms be put in place to ensure responsibility for the development, deployment and/or use of AI systems. This topic is closely related to risk management, identifying and mitigating risks in a transparent way that can be explained to and audited by third parties. When unjust or adverse impacts occur, accessible mechanisms for accountability should be in place that ensure an adequate possibility of redress."
                    }
                ]
            },
            "Ethics guidelines for trustworthy AI": {
                "link": "https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai",
                "requirements": [
                    {
                        "requirementID": "1.1.3 Human Oversight",
                        "requirementText": "Human oversight helps ensuring that an AI system does not undermine human autonomy or causes other adverse effects. Oversight may be achieved through governance mechanisms such as a human-in-theloop (HITL), human-on-the-loop (HOTL), or human-in-command (HIC) approach. HITL refers to the capability for human intervention in every decision cycle of the system, which in many cases is neither possible nor desirable. HOTL refers to the capability for human intervention during the design cycle of the system and monitoring the system’s operation. HIC refers to the capability to oversee the overall activity of the AI system (including its broader economic, societal, legal and ethical impact) and the ability to decide when and how to use the system in any particular situation. This can include the decision not to use an AI system in a particular situation, to establish levels of human discretion during the use of the system, or to ensure the ability to override a decision made by a system. Moreover, it must be ensured that public enforcers have the ability to exercise oversight in line with their mandate. Oversight mechanisms can be required in varying degrees to support other safety and control measures, depending on the AI system’s application area and potential risk. All other things being equal, the less oversight a human can exercise over an AI system, the more extensive testing and stricter governance is required."
                    },
                    {
                        "requirementID": "1.4.2 Explainability",
                        "requirementText": "Whenever an AI system has a significant impact on people’s lives, it should be possible to demand a suitable explanation of the AI system’s decision-making process. Such explanation should be timely and adapted to the expertise of the stakeholder concerned (e.g. layperson, regulator or researcher). In addition, explanations of the degree to which an AI system influences and shapes the organisational decision-making process, design choices of the system, and the rationale for deploying it, should be available (hence ensuring business model transparency)."
                    }
                ]
            }
        },
        "Google": {
            "Secure AI Framework": {
                "link": "https://www.saif.google/secure-ai-framework",
                "requirements": [
                    {
                        "requirementID": "Agent User Control",
                        "requirementText": "Ensure user approval for any actions performed by agents/plugins that alter user data or act on the user’s behalf."
                    }
                ]
            }
        },
        "IMDA": {
            "Model AI Governance Framework for Agentic AI": {
                "link": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
                "requirements": [
                    {
                        "requirementID": "2.2 Make humans meaningfully accountable\n2.2.1 Clear allocation of responsibilities within and outside the organisation",
                        "requirementText": "By establishing chains of accountability across the agent value chain and lifecycle, while emphasising adaptive governance, so that the organisation is set up to quickly understand new developments and update their approach as the technology evolves.\nAs deployers, organisations and humans remain accountable for the decisions and actions of agents. However, as with AI, the value chain for agentic AI involves multiple actors. Organisations should consider the allocation of responsibility both within their organisation, and vis-à-vis other organisations along the value chain.\nWithin the organisation, organisations should allocate responsibilities for different teams across the agent lifecycle.\nOutside the organisation, organisations may also need to work with external parties when deploying agents e.g. model developers, agentic AI providers, or hosts of external MCP servers or tools."
                    },
                    {
                        "requirementID": "2.2.2 Design for meaningful human oversight - 1",
                        "requirementText": "Organisations should define significant checkpoints or action boundaries that require human approval, especially before sensitive actions are executed. This can include:23\n• High-stakes actions and decisions e.g. editing of sensitive data, final decisions in high-risk domains (such as healthcare or legal), actions that may trigger liability\n• Irreversible actions e.g. permanently deleting data, sending communications, making payments\n• Outlier or atypical behaviour e.g. when agent accesses a system or database outside of its work scope, when agent selects a delivery route that is twice as long as the median distance\n• User-defined. Agents may act on behalf of users who have different risk appetites. Beyond organisation-defined boundaries, users may be given the option to define their own boundaries e.g. requiring approval for purchases above a certain amount"
                    },
                    {
                        "requirementID": "2.2.2 Design for meaningful human oversight - 2",
                        "requirementText": "Apart from considering when approvals are required, organisations should also consider what form approvals should take. These considerations include:\n• Keep approval requests contextual and digestible. When asking humans for approval, keep the request short and clear, instead of providing long logs or raw data that may be challenging to decipher and understand.\n• Consider the form of human input required. For straightforward actions such as accessing a database, the human user can simply approve or reject. For more complex cases, such as reviewing an agent’s plan before execution, it may be more productive for the human to edit the plan before giving the agent the go-ahead.\nOrganisations should implement measures to ensure continued effectiveness of human oversight, particularly as humans remain susceptible to alert fatigue and automation bias. These measures can include:\n• Training humans to identify common failure modes e.g. inconsistent agent reasoning, agents referring to outdated policies\n• Regularly auditing the effectiveness of human oversight"
                    }
                ]
            }
        },
        "ISO": {
            "42001:2023 - Information technology — Artificial intelligence — Management system": {
                "link": "https://www.iso.org/standard/42001",
                "requirements": [
                    {
                        "requirementID": "5.1",
                        "requirementText": "Leadership and commitment"
                    },
                    {
                        "requirementID": "5.3",
                        "requirementText": "Roles, responsibilities and authorities"
                    }
                ]
            }
        },
        "ISO/IEC": {
            "DIS 24970": {
                "link": "https://www.iso.org/obp/ui/en/#iso:std:iso-iec:24970:dis:ed-1:v1:en",
                "requirements": [
                    {
                        "requirementID": "7.4",
                        "requirementText": "Triggers from human oversight"
                    }
                ]
            }
        },
        "MIC/METI (Japan)": {
            "AI Guidelines for Business": {
                "link": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20240419_9.pdf",
                "requirements": [
                    {
                        "requirementID": "Human-Centric - 2 (d)",
                        "requirementText": "Carefully handle AI outputs, especially when they can be relevant to procedures that might significantly affect the society, such as an election and decision-making in a community."
                    },
                    {
                        "requirementID": "Safety - 1 (c)",
                        "requirementText": "Ensure controllability that allows humans to control AI as necessary including objective monitoring and handling, in accordance with the characteristics and purposes of the relevant AI, in light of the severity and possibility of rights violations that can result from AI use or unintended AI behaviors."
                    },
                    {
                        "requirementID": "Fairness - 2 (a)",
                        "requirementText": "To prevent AI from generating unfair results, consider implementing timely human interventions, rather than letting AI make the decisions alone."
                    },
                    {
                        "requirementID": "Accountability - 3",
                        "requirementText": "Appoint someone as the person responsible for executing its accountability in each AI business actor."
                    },
                    {
                        "requirementID": "Accountability - 4",
                        "requirementText": "As for responsibilities shared among actors, clarify who take the responsibilities through contracts or social promises (voluntary commitments) between AI business actors including non-business users."
                    }
                ]
            }
        },
        "Microsoft": {
            "Responsible AI Standard": {
                "link": "https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft-Responsible-AI-Standard-General-Requirements.pdf?culture=en-us&country=us",
                "requirements": [
                    {
                        "requirementID": "A5.1",
                        "requirementText": "Identify the stakeholders who are responsible for troubleshooting, managing, operating, overseeing, and controlling the system during and after deployment. Document these stakeholders and their oversight and control responsibilities using the Impact Assessment template."
                    },
                    {
                        "requirementID": "A5.2",
                        "requirementText": "Identify the system elements (including system UX, features, alerting and reporting functions, and educational materials) necessary for stakeholders identified in requirement A5.1 to effectively understand their oversight responsibilities and carry them out. Stakeholders must be able to understand:\n1) the system’s intended uses,\n2) how to effectively execute interactions with the system,\n3) how to interpret system behavior,\n4) when and how to override, intervene, or interrupt the system, and\n5) how to remain aware of the possible tendency of over-relying on outputs produced by the system (“automation bias”).\nDocument the system design elements that will support relevant stakeholders for each oversight and control function."
                    },
                    {
                        "requirementID": "A5.3",
                        "requirementText": "When possible, design the system elements identified in A5.2. When this is not possible (for example, when Microsoft is not responsible for the system UX), provide guidance on human oversight considerations to the third party responsible for implementing the system elements identified in A5.2."
                    },
                    {
                        "requirementID": "A5.4",
                        "requirementText": "Define and document the method to be used to evaluate whether each oversight or control function can be accomplished by stakeholders in realistic conditions of system use. Include the metrics or rubrics that will be used in the evaluations. When this is not possible (for example, when Microsoft is not responsible for oversight and control functions), provide guidance on evaluating oversight and control functions to the third party responsible for evaluating oversight or control functions."
                    },
                    {
                        "requirementID": "T1.3",
                        "requirementText": "Define and document the method to be used to evaluate whether each stakeholder who will make decisions or be subject to decisions based on the behavior of the system can interpret the relevant system responses reasonably well. Include the metrics or rubrics that will be used in the evaluations."
                    }
                ]
            }
        },
        "MITRE": {
            "ATLAS Framework": {
                "link": "https://atlas.mitre.org/mitigations",
                "requirements": [
                    {
                        "requirementID": "AML.M0029 - Human In-the-Loop for AI Agent Actions",
                        "requirementText": "Systems should require the user or another human stakeholder to approve AI agent actions before the agent takes them. The human approver may be technical staff or business unit SMEs depending on the use case. Separate tools, such as dedicated audit agents, may assist human approval, but final adjudication should be conducted by a human decision-maker.\n\nThe security benefits from Human In-the-Loop policies may be at odds with operational overhead costs of additional approvals. To ease this, Human In-the-Loop policies should follow the degree of consequence of the task at hand. Minor, repetitive tasks performed by agents accessing basic tools may only require minimal human oversight, while agents employed in systems with significant consequences may necessitate approval from multiple stakeholders diversified across multiple organizations."
                    }
                ]
            }
        },
        "NIST": {
            "AI RMF 1.0": {
                "link": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
                "requirements": [
                    {
                        "requirementID": "GOVERN 2.3",
                        "requirementText": "Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment."
                    },
                    {
                        "requirementID": "GOVERN 3.2",
                        "requirementText": "Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems."
                    },
                    {
                        "requirementID": "MAP 1.2",
                        "requirementText": "Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their participation is documented. Opportunities for interdisciplinary collaboration are prioritized."
                    },
                    {
                        "requirementID": "MAP 3.5",
                        "requirementText": "Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function."
                    }
                ]
            },
            "IR 8596: Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile): NIST Community Profile": {
                "link": "https://csrc.nist.gov/pubs/ir/8596/iprd",
                "requirements": [
                    {
                        "requirementID": "GV.RR-01",
                        "requirementText": "Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving"
                    },
                    {
                        "requirementID": "GV.RR-02",
                        "requirementText": "Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced"
                    },
                    {
                        "requirementID": "GV.RR-03",
                        "requirementText": "Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies"
                    },
                    {
                        "requirementID": "GV.SC-02",
                        "requirementText": "Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally"
                    }
                ]
            },
            "SP 800-218A": {
                "link": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218A.pdf",
                "requirements": [
                    {
                        "requirementID": "PO.2.1",
                        "requirementText": "Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC. Periodically review and maintain the defined roles and responsibilities, updating them as needed.\n\nInclude AI model development security in SDLC-related roles and responsibilities throughout the SDLC. The roles and responsibilities should include, but are not limited to, AI model development, AI model operations, and data science."
                    },
                    {
                        "requirementID": "PW.7.1",
                        "requirementText": "Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either in a fully automated way or in conjunction with a person) should be used, as defined by the organization.\n\nCode review and analysis policies or guidelines should include code for AI models and other related components."
                    }
                ]
            }
        },
        "OpenAI": {
            "Preparedness Framework": {
                "link": "https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf",
                "requirements": [
                    {
                        "requirementID": "Safeguards Against a Misaligned Model - Reliable and Robust System Oversight",
                        "requirementText": "Effective AI and human oversight of model actions detects and prevents execution of harm or subversion of safeguards."
                    }
                ]
            },
            "Safety Best Practices": {
                "link": "https://platform.openai.com/docs/guides/safety-best-practices",
                "requirements": [
                    {
                        "requirementID": "Human in the loop (HITL)",
                        "requirementText": "Wherever possible, we recommend having a human review outputs before they are used in practice. This is especially critical in high-stakes domains, and for code generation. Humans should be aware of the limitations of the system, and have access to any information needed to verify the outputs (for example, if the application summarizes notes, a human should have easy access to the original notes to refer back)."
                    }
                ]
            }
        },
        "OWASP": {
            "AI Exchange": {
                "link": "https://owaspai.org/docs/ai_security_overview/",
                "requirements": [
                    {
                        "requirementID": "1.3. Controls to limit the effects of unwanted behaviour - OVERSIGHT",
                        "requirementText": "Oversight of model behaviour by humans or automated mechanisms (e.g.,using rules), where human oversight provides not only more intelligent validation through common sense and domain knowledge, but also clear accountability for devisions and outcomes."
                    }
                ]
            },
            "LLM Top 10": {
                "link": "https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/",
                "requirements": [
                    {
                        "requirementID": "LLM01: Prompt Injection - 5",
                        "requirementText": "Implement human-in-the-loop controls for privileged operations to prevent unauthorized actions.\n"
                    },
                    {
                        "requirementID": "LLM06: Excessive Agency - 6",
                        "requirementText": "Utilise human-in-the-loop control to require a human to approve high-impact actions before they are taken. This may be implemented in a downstream system (outside the scope of the LLM application) or within the LLM extension itself. For example, an LLM-based app that creates and posts social media content on behalf of a user should include a user approval routine within the extension that implements the 'post' operation."
                    }
                ]
            },
            "OWASP Model Context Protocol (MCP) Top 10": {
                "link": "https://owasp.org/www-project-mcp-top-10/",
                "requirements": [
                    {
                        "requirementID": "MCP02:2025 - Privilege Escalation via Scope Creep - 6",
                        "requirementText": "Runtime Controls & Guardrails Implement runtime policy enforcement (PDP/PIP) to block disallowed commands or tool calls. Apply action whitelists, safe execution sandboxes, and require multi-step confirmation for high-impact operations."
                    },
                    {
                        "requirementID": "MCP02:2025 - Privilege Escalation via Scope Creep - 8",
                        "requirementText": "Separation of Duties & Approval Flows Separate the authority to grant permissions from the authority to deploy code or change production settings. Require human-in-the-loop approvals for non-routine privilege grants."
                    },
                    {
                        "requirementID": "MCP03:2025 - Tool Poisoning - 6",
                        "requirementText": "Runtime Enforcement & Guardrails\n- Don’t allow agents to interpret schema changes as immediate action drivers without revalidation.\n- Require a “schema attestation” that binds the schema hash to a specific agent identity and session.\n- Implement runtime sanity checks: if an operation’s semantic impact exceeds a threshold (e.g., destructive verbs, data volume), pause execution and require human approval."
                    },
                    {
                        "requirementID": "MCP03:2025 - Tool Poisoning - 11",
                        "requirementText": "Patch CI/CD and registry processes to require signed commits and multi-party approvals where missing."
                    },
                    {
                        "requirementID": "MCP05:2025 – Command Injection & Execution - 6",
                        "requirementText": "Add Human-in-the-Loop for Sensitive Actions Require approval for destructive, privileged, or system-modifying operations. Log all tool calls with full parameters and maintain immutable audit trails."
                    },
                    {
                        "requirementID": "MCP06:2025 – Intent Flow Subversion - 5",
                        "requirementText": "Active Drift Detection & Human-in-the-Loop\n- Monitor for “Intent Drift”—where the semantic alignment between the user’s request and the agent’s actions degrades over time.\n- Automatically pause the session and require human re-authentication of the intent flow if the agent’s plan deviates from the original goal."
                    },
                    {
                        "requirementID": "MCP10:2025 – Context Injection & Over-Sharing - 6",
                        "requirementText": "Human-in-the-Loop for Sensitive Context Require approval before sensitive context is: Exported Summarized Shared across agents Show a preview of context that will be reused."
                    }
                ]
            },
            "OWASP Top 10 for Agentic Applications for 2026": {
                "link": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
                "requirements": [
                    {
                        "requirementID": "ASI02: Tool Misuse and Exploitation - 2",
                        "requirementText": "Action-Level Authentication and Approval. Require explicit authentication for each tool invocation and human confirmation for high-impact or destructive actions (delete, transfer, publish). Display a pre-execution plan or dry-run diff before final approval; where possible, present a dry-run or diff preview to the user before high-impact actions are approved."
                    },
                    {
                        "requirementID": "ASI03: Identity and Privilege Abuse - 4",
                        "requirementText": "Apply Human-in-the-Loop for Privilege Escalation: Require human approval for high-privilege or irreversible actions to provide a safety net that would stop Memory-Based Escalation, Cross-Agent Trust Exploitation, and Maintenance Window attacks."
                    },
                    {
                        "requirementID": "ASI04: Agentic Supply Chain Vulnerabilities - 8",
                        "requirementText": "Supply chain kill switch: Implement emergency revocation mechanisms that can instantly disable specific tools, prompts, or agent connections across all deployments when a compromise is detected, preventing further cascading damage."
                    },
                    {
                        "requirementID": "ASI05: Unexpected Code Execution (RCE) - 6",
                        "requirementText": "Access control and approvals: Require human approval for elevated runs; keep an allowlist for auto-execution under version control; enforce role and action-based controls."
                    },
                    {
                        "requirementID": "ASI06: Memory & Context Poisoning - 7",
                        "requirementText": "Resilience and verification: Perform adversarial test, use snapshots/rollback and version control, and require human review for high-risk actions. Where you operate shared vector or memory stores, use per-tenant namespaces and trust scores for entries, decaying or expiring unverified memory over time and supporting rollback/quarantine for suspected poisoning."
                    },
                    {
                        "requirementID": "ASI08: Cascading Failures - 5",
                        "requirementText": "Output validation and human gates: Checkpoints, governance agents, or human review for high risk before agent outputs are propagated downstream."
                    },
                    {
                        "requirementID": "ASI09: Human-Agent Trust Exploitation - 1",
                        "requirementText": "Explicit confirmations: Require multi-step approval or “human in the loop” before accessing extra sensitive data or performing risky actions."
                    },
                    {
                        "requirementID": "ASI09: Human-Agent Trust Exploitation - 5",
                        "requirementText": "Adaptive Trust Calibration: Continuously adjust the level of agent autonomy and required human oversight based on contextual risk scoring. Implement confidence weighted cues (e.g., “low-certainty” or “unverified source”) that visually prompt users to question high-impact actions, reducing automation bias and blind approval. Develop and continuously maintain appropriate training of human personnel involved in the evolving human oversight of autonomous agentic systems."
                    },
                    {
                        "requirementID": "ASI10: Rogue Agents - 4",
                        "requirementText": "Containment & Response: Implement rapid mechanisms like kill-switches and credential revocation to instantly disable rogue agents. Quarantine suspicious agents in sandboxed environments for forensic review."
                    }
                ]
            }
        },
        "Personal Data Protection Commission Singapore (PDPC)": {
            "Model Artificial Intelligence Governance Framework Second Edition": {
                "link": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/resource-for-organisation/ai/sgmodelaigovframework2.pdf",
                "requirements": [
                    {
                        "requirementID": "1. Clear roles and responsibilities for the ethical deployment of AI - a)",
                        "requirementText": "Responsibility for and oversight of the various stages and activities involved in AI deployment should be allocated to the appropriate personnel and/or departments. If necessary and possible, consider establishing a coordinating body, having relevant expertise and proper representation from across the organisation."
                    },
                    {
                        "requirementID": "1. Clear roles and responsibilities for the ethical deployment of AI - c) (i)",
                        "requirementText": "Key roles and responsibilities that can be allocated include:\nUsing any existing risk management framework and applying risk control measures (see “Risk management and internal controls” below) to:\n- Assess and manage the risks of deploying AI, including any potential adverse impact on the individuals (e.g. who are most vulnerable, how are they impacted, how to assess the scale of the impact, how to get feedback from those impacted, etc.).\n- Decide on the appropriate level of human involvement in AI-augmented decision-making.\n- Manage the AI model training and selection process"
                    },
                    {
                        "requirementID": "ALGORITHM AND MODEL - c)",
                        "requirementText": "Supplementary explanation tools are helpful for explaining AI models, especially models that are less interpretable (also known as “black box” systems). These tools help make the underlying rationale of an AI system’s output more interpretable and intelligible to those who use the system. It is possible to use a combination of these tools to improve the explainability of an AI model’s decision."
                    }
                ]
            }
        },
        "Qatar Central Bank": {
            "Artificial Intelligence Guidelines": {
                "link": "https://www.qcb.gov.qa/Services/Financial%20Technology/QCB_Artificial_Intelligence_Guideline.pdf",
                "requirements": [
                    {
                        "requirementID": "7.1",
                        "requirementText": "The Board of Directors (BOD) and senior management of an Entity remain accountable for the outcomes and decisions of the Entity's Al Systems including those systems that make decisions on behalf of the Entity."
                    },
                    {
                        "requirementID": "7.3",
                        "requirementText": "The key responsibilities of the senior management include but are not limited to:\n- Must have one or more members with the knowledge to understand and manage technology risks, ideally including Al.\n- Must be responsible for the assessment, understanding and monitoring of the Entity's reliance on Al.\n- Must ensure responsibility for, and oversight of the various stages and activities involved in Al portfolio deployment is allocated to the appropriate personnel and/ or departments.\n- Must provide information to the BOD that is clear, consistent, robust, timely, well-targeted and contain an appropriate level of technical detail to allow the BOD to provide effective oversight and challenge management."
                    },
                    {
                        "requirementID": "7.4",
                        "requirementText": "An Entity should establish either a function overseeing Al or delegating its responsibility to an existing function within an Entity."
                    },
                    {
                        "requirementID": "7.5",
                        "requirementText": "The function responsible for overseeing Al must utilize or create appropriate committees to assess Al use cases prior to implementation."
                    },
                    {
                        "requirementID": "8.2",
                        "requirementText": "An Entity must allocate key roles and responsibilities associated with managing the Entity's Al portfolio."
                    },
                    {
                        "requirementID": "8.2.3",
                        "requirementText": "Clearly allocate roles & responsibilities between model owners, developers and approvers."
                    },
                    {
                        "requirementID": "13.1",
                        "requirementText": "Any Al Systems must have a Human Oversight protocol."
                    },
                    {
                        "requirementID": "13.2",
                        "requirementText": "High risk Al Systems must be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which the Al System is in use."
                    },
                    {
                        "requirementID": "13.3",
                        "requirementText": "The User must assign Human Oversight to a Supervisor who has the necessary competence, training, and authority to operate or oversee the relevant Al System."
                    },
                    {
                        "requirementID": "13.4",
                        "requirementText": "An Entity must ensure that the Supervisor is given tools and authority as appropriate and proportionate to the circumstances to:\n- Understand the capacities and limitations of the High-Risk Al System and are able to duly monitor its operation.\n- Correctly interpret the High-Risk Al System's output, considering for example the interpretation tools and methods available.\n- To decide, in any situation, not to use the High-Risk Al System or otherwise disregard, override or reverse the output of the High-Risk Al System.\n- Have the authority and means to intervene in the operation of the High-Risk Al System or interrupt the system through a \"stop\" button or a similar procedure."
                    },
                    {
                        "requirementID": "13.6.5",
                        "requirementText": "The Supervisor(s) must have the capacity to close the system down in the event outputs from or data around the system seems aberrant."
                    },
                    {
                        "requirementID": "13.7.1",
                        "requirementText": "An entity that plans to provide or use an Al System that requires Human Oversight in a monitoring role, with the ability to take over control must ensure there will be appropriate human-machine interface tools the ability to allow a Supervisor to take over control."
                    },
                    {
                        "requirementID": "13.7.3",
                        "requirementText": "An Entity may ensure the design and development of Al Systems in such a way that it allows a Supervisor to oversee the Al Algorithm's functioning and allow decision making in a timely manner."
                    },
                    {
                        "requirementID": "13.7.4",
                        "requirementText": "An Entity must ensure that appropriate Human Oversight measures should be in place before use."
                    },
                    {
                        "requirementID": "13.7.6",
                        "requirementText": "An Entity must ensure the Al System is responsive to the Supervisor."
                    },
                    {
                        "requirementID": "21.1",
                        "requirementText": "An Entity must put in place a mechanism for Customers to raise inquiries about Al decisions and request reviews of decisions made by Al Systems with no human intervention."
                    },
                    {
                        "requirementID": "23.4",
                        "requirementText": "An Entity must ensure that the appropriate individuals or levels of authority within the Entity consistently approve the exemption."
                    },
                    {
                        "requirementID": "23.6",
                        "requirementText": "An Entity must remain accountable for any risks stemming from approved exemptions."
                    }
                ]
            }
        },
        "SDAIA (Saudi Arabia)": {
            "AI Ethics Principles": {
                "link": "https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf",
                "requirements": [
                    {
                        "requirementID": "Principle 5 – Reliability & Safety - Plan and Design - 5",
                        "requirementText": "All critical decision points in the system design should be subject to sign-off by relevant stakeholders to minimize risks and make stakeholders accountable for the decisions."
                    },
                    {
                        "requirementID": "Principle 5 – Reliability & Safety - Build and Validate - 2",
                        "requirementText": "To ensure the technical robustness of an AI system rigorous testing, validation, and re-assessment as well as the integration of adequate mechanisms of oversight and controls into its development is required. System integration test sign-off should be done with relevant stakeholders to minimize risks and liability."
                    },
                    {
                        "requirementID": "Principle 5 – Reliability & Safety - Build and Validate - 3",
                        "requirementText": "Automated AI systems involving scenarios where decisions are understood to have an impact that is irreversible or difficult to reverse or may involve life-and-death decisions should trigger human oversight and final determination. Furthermore, AI systems should not be used for social scoring or mass surveillance purposes."
                    },
                    {
                        "requirementID": "Principle 7 – Accountability & Responsibility - Plan and Design - 1",
                        "requirementText": "This step is crucial to design or procure an AI System in an accountable and responsible manner. The ethical responsibility and liability for the outcomes of the AI system should be attributable to stakeholders who are responsible for certain actions in the AI System Lifecycle. It is essential to set a robust governance structure that defines the authorization and responsibility areas of the internal and external stakeholders without leaving any areas of uncertainty to achieve this principle. The design approach of the AI system should respect human rights, and fundamental freedoms as well as the national laws and cultural values of the kingdom."
                    },
                    {
                        "requirementID": "Principle 7 – Accountability & Responsibility - Plan and Design - 3",
                        "requirementText": "It is essential to build and design a human-controlled AI system where decisions on the processes and functionality of the technology are monitored and executed, and are susceptible to intervention from authorized users. Human governance and oversight establish the necessary control and levels of autonomy through set mechanisms."
                    },
                    {
                        "requirementID": "Principle 7 – Accountability & Responsibility - Build and Validate - 1",
                        "requirementText": "Model development of the AI system and algorithm should consist of the selection of features, hyperparameter tuning and performance metric selection. To achieve this, the technical stakeholders who build and validate models should be responsible for these decisions."
                    },
                    {
                        "requirementID": "Principle 7 – Accountability & Responsibility - Build and Validate - 2",
                        "requirementText": "Assigning the appropriate ownership and communicating responsibilities will set the tone for accountability that would aid in steering the development of the AI system on good reasons, solid interference, and will allow the intervention of human critical judgement and expertise."
                    },
                    {
                        "requirementID": "Principle 7 – Accountability & Responsibility - Build and Validate - 4",
                        "requirementText": "The appropriate stakeholders and owners of the AI technology should review and sign off the model after successful testing and validation of user acceptance testing rounds have been conducted and completed before the AI models can be productionized."
                    }
                ]
            }
        },
        "Smart Dubai (UAE)": {
            "AI Ethics Principles & Guidelines": {
                "link": "https://www.digitaldubai.ae/docs/default-source/ai-principles-resources/ai-ethics.pdf",
                "requirements": [
                    {
                        "requirementID": "1.2.1.1",
                        "requirementText": "Accountability for loss or damages resulting from the application of AI systems should not be attributed to the system itself."
                    },
                    {
                        "requirementID": "1.2.1.2",
                        "requirementText": "AI operator organisations and AI developer organisations should consider designating individuals to be responsible for investigating and rectifying the cause of loss or damage arising from the deployment of AI systems."
                    },
                    {
                        "requirementID": "1.2.4.1",
                        "requirementText": "AI operator organisations which use AI systems to inform significant decisions should provide procedures by which affected AI subjects can challenge a specific decision concerning them."
                    },
                    {
                        "requirementID": "1.2.4.2",
                        "requirementText": "AI operator organisations should consider such procedures even for non-significant decisions."
                    },
                    {
                        "requirementID": "1.2.4.4",
                        "requirementText": "AI operator organisations should consider employing human case evaluators to review any such challenges and, when appropriate, overturn the challenged decision."
                    },
                    {
                        "requirementID": "1.2.4.5",
                        "requirementText": "AI operator organisations should consider instituting an opt-out mechanism for significant automated decisions."
                    }
                ]
            }
        },
        "U.S. Department of Health & Human Services": {
            "Trustworthy AI (TAI) Playbook: Executive Summary": {
                "link": "https://www.hhs.gov/sites/default/files/hhs-trustworthy-ai-playbook-executive-summary.pdf",
                "requirements": [
                    {
                        "requirementID": "Responsible / Accountable",
                        "requirementText": "Policies should outline governance and who is held responsible for all aspects of the AI solution (e.g., initiation, development, outputs, decommissioning)"
                    }
                ]
            }
        },
        "UAE Ministry of Cabinet Affairs": {
            "The UAE Charter for the Development and Use of Artificial Intelligence": {
                "link": "https://uaelegislation.gov.ae/en/policy/details/the-uae-charter-for-the-development-and-use-of-artificial-intelligence#:~:text=The%20charter%20covers%20the%20following%20priorities%20and,and%20use%20of%20AI%20in%20the%20country.",
                "requirements": [
                    {
                        "requirementID": "6. Human Oversight",
                        "requirementText": "​​​​​​​The Charter emphasizes the irreplaceable value of human judgment and human oversight over AI, aligning with ethical values and social standards to correct any errors or biases that may arise."
                    },
                    {
                        "requirementID": "7. Governance and Accountability",
                        "requirementText": "The UAE adopts a responsible and proactive stance, emphasizing the importance of governance and accountability in AI to ensure the technology is used ethically and transparently."
                    }
                ]
            }
        }
    }
}