UK DUAA right to complain enforces in -- days · 19 June 2026 EU AI Act high-risk enforces in -- days · 2 August 2026

Regulatory coverage

Eighty-nine active map rows. Eight jurisdictions. Article level.

Every framework below is implemented as a runtime enforcement engine inside OBEXGATE. Each engine maps to an article, principle, or control reference inside its source regulation, and produces tamper-evident evidence at the point a governed decision is made.

Coverage is not a checklist. It is regulatory logic applied at execution.

Coverage state as of 29 April 2026. Source: OBEXGATE Regulatory Coverage Catalogue.

89

Active regulatory map rows

88

Implemented rows

1

Not in scope

8

Jurisdictions covered

European Union

37 lines · Enforced

EU AI Act (Regulation 2024/1689)

Framework referenceCoverage
Art 5 Prohibited PracticesUnacceptable-risk system prohibition gate
Arts 6 to 8 High-Risk ClassificationAnnex III categories and Art 25 substantial modification detection
Art 9 Risk Management SystemContinuous risk management lifecycle
Art 9 Data GovernanceTraining, validation, and testing data quality obligations
Art 9 RegistrationEU AI Act registration requirements
Art 10 Data GovernanceData set requirements for high-risk AI
Art 10 Data QualityBias, relevance, and completeness checks
Art 11 Technical DocumentationAnnex IV documentation requirements
Art 12 Record KeepingAutomatic logging for high-risk systems
Art 13 TransparencyUser-facing disclosure requirements
Art 14 Human OversightHuman oversight measures and controls
Art 15 Accuracy and RobustnessAccuracy, robustness, and cybersecurity requirements
Arts 16 to 29 Provider/DeployerFull obligations bundle for providers and deployers
Arts 42 to 49 ConformityHarmonised standards, notified body designation, certificate lifecycle
Annex III High-Risk SystemsHigh-risk classification gate, wired into operator surface
Art 52 Transparency LabellingChatbot and deepfake disclosure obligations
Arts 55 to 71 PenaltiesFinancial penalties, enforcement actions, governance oversight
Art 72 PenaltiesAdministrative penalty classification and fine-ceiling enforcement
GPAI Arts 50 to 54General-purpose AI governance, systemic risk obligations

GDPR

Framework referenceCoverage
Art 5 Processing PrinciplesLawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity
Arts 13 and 14 Transparency NoticesPrivacy-notice generation for direct and indirect collection
Art 17 Right to ErasureDeletion workflow with downstream propagation
Art 20 Data PortabilityMachine-readable export surface
Art 22 Automated DecisionsProfiling and automated-decision safeguards
Art 25 Privacy by DesignPbD and data minimisation controls
Art 32 Security of ProcessingEncryption, incident response, processor assessment, log retention, secure disposal
Art 35 DPIAData Protection Impact Assessment workflow

DORA (Digital Operational Resilience Act)

Framework referenceCoverage
ICT Risk ManagementICT risk management framework requirements
Incident ClassificationMajor incident identification and classification
Resilience TestingTLPT and standard testing programme
Third-Party RiskICT third-party risk management

NIS2

Framework referenceCoverage
Risk Management (Art 21)All ten Art 21(2) security measures (a to j)
Incident Reporting24-hour early warning, 72-hour notification, final report
Board Liability (Arts 20 and 21)Management body accountability and training
Supply Chain SecurityThird-party and supply chain risk obligations

eIDAS 2.0

Framework referenceCoverage
Digital IdentityEuropean Digital Identity Wallet obligations
Qualified Electronic SignaturesQES creation, validation, trust service requirements

United States

24 lines · Enforced

Healthcare

Framework referenceCoverage
HIPAA Privacy RulePHI handling, minimum necessary, patient rights
HIPAA Security RuleAdministrative, physical, technical safeguards
HIPAA Breach NotificationBreach risk assessment and notification timelines
42 CFR Part 2Substance use disorder record redisclosure restrictions
FDA Information BlockingInteroperability and information blocking prohibitions
FDA SaMDSoftware as a Medical Device validation requirements
ONC HTI-1 (DSI Transparency)31-attribute decision support transparency schema, FAVES evaluation
ONC Information Blocking (45 CFR Part 171)Eight recognised exceptions; health IT developers, HINs, HIEs

Federal and Cross-Sector

Framework referenceCoverage
NIST AI RMF GovernGovernance function
NIST AI RMF MapRisk mapping function
NIST AI RMF MeasureRisk measurement function
NIST AI RMF ManageRisk management function
FTC Section 5Unfair or deceptive AI practices gate
FTC Health Breach NotificationHealth data breach notification (non-HIPAA covered)
FedRAMPNIST SP 800-53 controls; Low/Moderate/High baselines; SOC 2 and ISO 27001 cross-reference
CCPA/CPRASix consumer rights engines (access, deletion, portability, opt-out, correction, limit sensitive data use)
ISO/IEC 27001:202293 Annex A controls across four domains; SOC 2 and FedRAMP cross-reference
PCI DSS v4.0Payment card data security requirements

SOC 2 / SOC 3

Framework referenceCoverage
SOC 2 Security (CC1 to CC9)Full security trust service category; RBAC, cryptography, incident response wired
SOC 2 Availability (A1)Availability trust service category
SOC 2 Confidentiality (C1 to C2)Identification and secure disposal
SOC 2 Processing Integrity (PI1.1 to PI1.5)Completeness, accuracy, timeliness, authorisation, unauthorised-change prevention
SOC 2 Privacy (P1 to P8)Full privacy trust service category
SOC 3 Report SurfaceUnqualified, qualified, or adverse opinion across all five TSC categories

Brazil

9 lines · Enforced

Framework referenceCoverage
LGPD Art 18 Data Subject RightsRight to access, correction, deletion, portability, confirmation, opposition
LGPD Art 20 Right to ExplanationAutomated-decision explanation obligation
LGPD Art 33 Cross-Border TransferInternational transfer restrictions and safeguards
LGPD Art 48 Breach NotificationANPD and data-subject notification workflow
PL-2338/2023 Brazilian AI BillRisk classification, transparency, accountability obligations
AI Framework: Risk ClassificationANPD AI risk tiers
AI Framework: AIA EngineAI impact assessment workflow
AI Framework: ANPD PackageRegulatory submission package generation
DPO RegistrationData Protection Officer registration and contact surface

United Kingdom

6 lines · Enforced

Framework referenceCoverage
DUAA Section 80 (Arts 22A to 22D)Art 22A scope and significant-decision classification; Art 22B special-category data restrictions; Art 22C mandatory safeguards; Art 22D regulation-making powers; DPA 2018 Part 3 Sec. 50A to 50D law enforcement ADM; DPA 2018 Part 4 Sec. 96 to 97 intelligence services ADM
UK AI Safety Institute AlignmentUK AI Safety Institute voluntary alignment surface
FCA FG21/1 AI/ML ComplianceFinancial Conduct Authority AI/ML model risk guidance
PRA SS1/23 Model Risk ManagementPrudential Regulation Authority model risk management standard
UK GDPR Divergence OverlayUK-specific post-Brexit GDPR divergence surface
SMCRSenior manager accountability and certification obligations

Australia

4 lines · Enforced 2 + Observer 2

Framework referenceCoverage
Privacy Act 1988 APPs 1 to 1313 Australian Privacy Principles; register, assess, query, cross-border transfer (APP 8)
Privacy Act 1988 NDB (Part IIIC)Notifiable Data Breaches; 30-day OAIC notification enforcement
AI Ethics Principles (8 principles)Voluntary 8-principle assessment, scored 1 to 5. Observer mode.
AI Safety StandardsVoluntary safety standard assessment. Observer mode.

New Zealand

3 lines · Enforced

Framework referenceCoverage
Privacy Act 2020 IPPs 1 to 1313 Information Privacy Principles
Privacy Act 2020 NPBNotifiable Privacy Breach reporting obligations
NZ Unified Query SurfaceAggregated IPP and NPB compliance surface

Singapore

3 lines · Enforced 2 + Observer 1

Framework referenceCoverage
PDPA (Personal Data Protection Act 2012)Deemed consent, 72-hour breach notification, data portability, transfer restrictions
MAS AI Governance (FEAT)Fairness, Ethics, Accountability, Transparency principles. Financial services sector.
AI VerifyAI testing framework. Voluntary. Observer mode.

Canada

2 lines + 1 not in scope · Enforced

Framework referenceCoverage
PIPEDA 10 Fair Information PrinciplesConsent framework, accountability, openness, individual access
Ontario Bill 194AI accountability, children's data protection, privacy impact assessment, cybersecurity, breach notification
AIDA (Bill C-27)Not in scope. Died on the order paper 2025-01-06; 44th Parliament prorogued; no Royal Assent. Engines defined but inactive.

How OBEXGATE produces a verdict

EVF to PRISM scoring

OBEXGATE implements the Niti Logic EVF to PRISM Scoring Map. Each PRISM framework is scored by deduction from 100 using a 10 by 5 risk-signal weight matrix. Hard floor rules are enforced. Verdict tiers: Compliant (85 or above), Substantially Compliant (70 or above), Material Concerns (55 or above), Non-Compliant (below 55). Overall posture is the worst framework across all five PRISM dimensions.

EVF as the assessment instrument

EVF is the diagnostic that captures how an organisation's governance actually behaves at the execution boundary, with ten domains and the risk signals that surface structural vulnerability. OBEXGATE translates that signal into framework-specific compliance verdicts with the hard floors above.

OBEXGATE as enforcement floor

The 89 active map rows on this page reflect 88 implemented rows and 1 not-in-scope row under methodology-layer products. EVF is the assessment instrument. OBEXGATE produces the runtime evidence and the verdict. The two are designed to operate together.

If an action violates an enforced requirement, it does not run.

Coverage state and revision

Coverage state on this page is current as of 29 April 2026 and reflects the OBEXGATE Regulatory Coverage Catalogue. Coverage is reconciled against codebase state, not aspirational roadmap. Engines listed in scope are running. Engines not in scope are listed for transparency and explicitly noted as inactive.

See which obligations apply before your system runs.

A six-question OBEXGATE assessment delivers a personalised regulatory map, deployment cost estimate, and potential statutory exposure based on how your system behaves under enforcement.