AI GOVERNANCE FRAMEWORKS
Every AI framework, on one record.
ISO/IEC 42001 is the certificate enterprise buyers screen for. The EU AI Act is the law that will be enforced against you. NIST AI RMF is the method US buyers expect. Hael classifies every AI system against all of them, and produces the substantive artefact each regime demands — the Statement of Applicability, the Annex IV technical file, the impact assessment — generated from live operational state and sealed with hash-chained provenance.
The certifiable AI management system standard. 72% of enterprise buyers screen for it before the first RFP round. Hael produces the full AIMS: Statement of Applicability across all Annex A controls, AI system register, risk assessments, internal audit pack and management review — audit-gated for your certification body.
Risk-tiered AI regulation. Article 11 demands a complete technical documentation file in Annex IV order before high-risk systems are placed on the market. The artefact the regulator opens.
GOVERN, MAP, MEASURE, MANAGE plus the July 2024 Generative AI Profile. The de-facto US AI risk-management language; named by Colorado and Texas as a recognised framework.
AI under GDPR: Article 22 safeguards for solely-automated decisions, Article 35 DPIAs, and the Article 5/6/9 lawful-basis duties that bite on training and inference. EDPB Opinion 28/2024 is current guidance.
Five cross-sectoral principles enforced through ICO, FCA/PRA, MHRA, CMA and Ofcom. No horizontal Act yet; sector regulators carry the duties.
ADMT disclosure duties · SB 26-189 · from Jan 2027. Pre-use notice, 30-day adverse-outcome explanation, human review, correction and three-year records. Hael runs each duty as a control on the record.
Intent-based prohibitions on harmful AI uses, enforced by the Texas AG with a 60-day cure period and a 36-month sandbox. Hael holds the acceptable-use policy and NIST-aligned risk programme that operate as affirmative defences.
Independent bias audit (≤12 months), published summary and candidate notice for AEDTs. Hael maintains the audit, summary and notice as living artefacts.
Pre-use notice, opt-out, access and risk-assessment duties for ADMT used in significant decisions, behavioural-advertising profiling and extensive profiling. Hael generates each artefact.
Effects-based bar on AI that produces discriminatory outcomes across the employment lifecycle; mandatory worker notice; no zip-code proxies. Hael runs the disparate-impact testing and notice lifecycle.
Generative-AI consumer disclosure under UCSPA; up-front disclosure in regulated occupations; operator liability for AI acts. The OAIP runs the AI Learning Lab sandbox.
High-impact AI risk-management and documentation duties; generative-AI labelling; domestic-representative requirement for foreign operators above MSIT thresholds.
Filing-and-evidence regime: CAC algorithm filing, security assessment where triggered, lawful-training-data records, and mandatory AI-generated-content labelling (in force 1 Sep 2025).
ALSO RELEVANT
Hael also tracks the OECD AI Principles, Singapore's Model AI Governance Framework, California SB 53 (TFAIA), the New York RAISE Act, DORA, SOC 2 and the US Treasury FS AI RMF. They inform classification and reuse but are not part of the engine's resolved framework set — the thirteen above are what the Classify engine actually decides against, and what the Hael application generates artefacts for.