{
  "$schema": "provael-regulatory-clock/1",
  "note": "Structured, dated, source-linked regulatory clock. Machine-readable record of the facts the compliance pages cite. NOT legal advice; dated editorial data - verify against the primary source before relying on it. The compliance pages currently carry the same verified values inline in src/data/compliance.ts; wiring the pages to read from this file is a recommended follow-up.",
  "lastVerified": "2026-07-26",
  "verifiedAgainst": [
    "EUR-Lex",
    "ISO",
    "NIST",
    "A3 (Automate)",
    "CSET"
  ],
  "disclaimer": "Not legal advice. This is dated editorial data, not a legal opinion. Verify against the primary official source before relying on any date.",
  "entries": [
    {
      "id": "eu-ai-act-art15",
      "framework": "EU AI Act",
      "title": "Regulation (EU) 2024/1689 - Article 15 (accuracy, robustness, cybersecurity)",
      "instrument": "Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)",
      "provision": "Article 15; applied to high-risk product-embedded AI systems (Annex I). NOTE: Regulation (EU) 2026/1744 moved Machinery Regulation (EU) 2023/1230 from AI Act Annex I Section A to Section B, so AI Act Chapter III (including Article 15) no longer applies DIRECTLY to AI-enabled machinery.",
      "status": "amended-in-force",
      "statusNote": "Regulation (EU) 2026/1744: Parliament 16 June 2026, Council 29 June 2026, published OJ 24 July 2026, in force 27 July 2026.",
      "applicableDate": "2028-08-02",
      "supersededStatutoryDate": "2027-08-02",
      "standaloneAnnexIIIDate": "2027-12-02",
      "machineryPathway": "For machinery, the AI-robustness requirements are carried across by Commission delegated acts amending Annex III of Regulation (EU) 2023/1230, applicable by 2 August 2028 — not by direct application of AI Act Chapter III.",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng",
      "secondarySource": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
      "lastVerified": "2026-08-19",
      "editorNote": "2 August 2027 was the statutory application date for product-embedded high-risk AI; Regulation (EU) 2026/1744 defers it to 2 August 2028 and moves stand-alone Annex III high-risk to 2 December 2027. It also adds two prohibited practices (non-consensual intimate imagery and CSAM) from 2 December 2026. Now settled law, not pending publication.",
      "provaelSupports": "A measured attack-success rate with a 95% Wilson CI and a benign control is candidate evidence toward Art. 15 robustness documentation.",
      "provaelDoesNotEstablish": "Does not establish conformity, is not certification, and is not a notified-body opinion.",
      "responsibleActor": "Provider of the high-risk AI system / product manufacturer (and a notified body where a third-party route applies).",
      "verificationNote": "CELEX 32026R1744: \"shall apply from ... (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I\". The Annex III counterpart (2 December 2027) is recorded here as standaloneAnnexIIIDate."
    },
    {
      "id": "eu-machinery-regulation",
      "framework": "EU Machinery Regulation",
      "title": "Regulation (EU) 2023/1230",
      "instrument": "Regulation (EU) 2023/1230 (replaces Directive 2006/42/EC)",
      "provision": "Article 54; safety components with self-evolving behaviour pulled into conformity assessment",
      "status": "adopted-applies",
      "statusNote": "Adopted; applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023).",
      "applicableDate": "2027-01-20",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2023/1230/oj",
      "secondarySource": "https://eur-lex.europa.eu/eli/reg/2023/1230/corrigendum/2023-07-04/oj/eng",
      "lastVerified": "2026-08-20",
      "editorNote": "The nearest binding embodied-AI deadline. Some secondary sources cite an incorrect January date; the correct application date is 20 January 2027.",
      "provaelSupports": "Evidence that an AI-driven safety function resists instruction- and perception-level manipulation in simulation, with a measured redirection rate and CI, feeding the technical documentation for a conformity assessment.",
      "provaelDoesNotEstablish": "Not a conformity assessment, not a certificate; Provael is not a notified body.",
      "responsibleActor": "Manufacturer of the machinery / safety component (and a notified body for the third-party route).",
      "verificationNote": "Re-read at CELEX 32023R1230 AND its corrigendum 32023R1230R(01). This matters and is easy to get wrong in one specific direction: the UNCORRECTED OJ text of Art. 54 carries an earlier January date, and the corrigendum replaces it with 20 January 2027. Reading only the original text yields the wrong answer, which is why check-facts forbids that earlier string from appearing anywhere on this site — including in this note. Article 20(10) re-read 20 August 2026 in the consolidated text at CELEX 02023R1230-20260727: Article 20 has ten paragraphs and paragraph 10 is the AI-Act bridge quoted in aiHarmonisedBridge.",
      "aiHarmonisedBridge": "Article 20(10) — the bridge that keeps the interval workable. Verbatim: \"Until harmonised standards or common specifications are referenced or adopted pursuant to this Article as regards high-risk AI systems, high-risk AI systems within the scope of this Regulation which comply with the relevant harmonised standards referenced, or common specifications adopted pursuant to Articles 40 and, respectively, 41 of Regulation (EU) 2024/1689 shall be presumed to be in conformity with the essential health and safety requirements set out in Annex III to this Regulation as regards high-risk AI systems.\"",
      "aiHarmonisedBridgeSource": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02023R1230-20260727",
      "aiAnnexIIIDelegatedActsBy": "2028-08-02",
      "evidenceGapNote": "Between 2027-01-20 (this Regulation applies) and 2028-08-02 (the delegated acts amending its Annex III apply), AI-driven machinery needs robustness evidence while no AI-specific harmonised standard under THIS Regulation yet exists to produce it against. Article 20(10) bridges the interval by borrowing the AI Act's standards; it does not fill it."
    },
    {
      "id": "iso-10218",
      "framework": "ISO 10218-1/-2:2025",
      "title": "ISO 10218-1:2025 · ISO 10218-2:2025 (industrial robot safety, incl. cybersecurity)",
      "instrument": "ISO 10218-1:2025 / ISO 10218-2:2025",
      "provision": "Cybersecurity clauses (defers detailed cyber requirements to IEC 62443)",
      "status": "published",
      "statusNote": "Published February 2025 (ISO catalogue records 2025-02; secondary sources commonly cite 5 February). A publication date, not an entry-into-force date.",
      "applicableDate": "2025-02-05",
      "jurisdiction": "International (ISO)",
      "primarySource": "https://www.iso.org/standard/73933.html",
      "secondarySource": "https://www.iso.org/standard/73934.html",
      "lastVerified": "2026-07-26",
      "editorNote": "The 2025 revision added cybersecurity provisions for the first time and incorporated ISO/TS 15066:2016's power-and-force-limiting requirements. US national adoption is ANSI/A3 R15.06-2025 (see that entry).",
      "provaelSupports": "Adversarial-robustness evidence for the policy driving an industrial robot, mappable to a 10218-2 system assessment.",
      "provaelDoesNotEstablish": "Not conformity to ISO 10218; not a certificate.",
      "responsibleActor": "Robot integrator / system assessor."
    },
    {
      "id": "iso-25785-1",
      "framework": "ISO 25785-1",
      "title": "ISO/CD 25785-1 — Robotics: safety requirements for dynamically stable industrial mobile robots (legged, wheeled, or other forms of locomotion) — Part 1: Robots",
      "instrument": "ISO/CD 25785-1 (ISO/TC 299 Working Group 12)",
      "provision": "The first Type-C standard aimed at robots with actively controlled stability — the balance-and-fall hazards a legged machine has and a statically stable one does not.",
      "status": "committee-draft-not-published",
      "statusNote": "Committee Draft. CD registered 8 May 2026; CD consultation opened 12 May 2026. No fixed publication date.",
      "applicableDate": null,
      "jurisdiction": "International",
      "primarySource": "https://www.iso.org/standard/91469.html",
      "secondarySource": null,
      "lastVerified": "2026-08-20",
      "editorNote": "Recorded because it is the adjacent gap to the Machinery Regulation's: a humanoid builder placing a machine on the EU market has ISO 10218-1/-2:2025 and nothing else that speaks to dynamic stability. NOTE the stage moved: this site previously described 25785-1 as a Working Draft, which was a stage out of date. CD is later than WD and is a material difference — a CD is out for committee consultation, a WD is not.",
      "provaelSupports": "Nothing toward conformity: there is no stable clause to cite. The humanoid attack family produces an anticipatory adversarial-robustness baseline that exists ahead of the standard.",
      "provaelDoesNotEstablish": "No conformity position of any kind against a text that is not published, and no prediction of what the published text will require.",
      "responsibleActor": "Manufacturer of the dynamically stable industrial mobile robot.",
      "verificationNote": "Stage confirmed 20 August 2026 as ISO/CD 25785-1 under ISO/TC 299/WG 12. iso.org blocks automated fetches (HTTP 403), so the stage was read from the ISO catalogue listing rather than fetched programmatically — weaker than the EUR-Lex citations on this clock, and recorded as such."
    },
    {
      "id": "eu-cyber-resilience-act",
      "framework": "EU Cyber Resilience Act",
      "title": "Regulation (EU) 2024/2847",
      "instrument": "Regulation (EU) 2024/2847",
      "provision": "Vulnerability handling, SBOM, security updates; reporting duties phase in ahead of full application",
      "status": "adopted-phasing-in",
      "statusNote": "Reporting obligations (Art. 14) apply 11 September 2026; full application 11 December 2027.",
      "applicableDate": "2027-12-11",
      "reportingDate": "2026-09-11",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "secondarySource": "https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act",
      "lastVerified": "2026-08-19",
      "editorNote": "Relevant to Provael's own software-security posture (SBOM, coordinated disclosure, security.txt), not to the policy-attack result.",
      "provaelSupports": "SBOM per release, a coordinated vulnerability-disclosure policy, and an RFC 9116 security.txt.",
      "provaelDoesNotEstablish": "CRA compliance is a product-level obligation on the responsible economic operator.",
      "responsibleActor": "Manufacturer / economic operator placing the product on the EU market.",
      "verificationNote": "CELEX 32024R2847: \"shall apply from 11 December 2027\"."
    },
    {
      "id": "nist-ai-rmf",
      "framework": "NIST AI RMF",
      "title": "NIST AI 100-1 · Generative AI Profile (NIST AI 600-1)",
      "instrument": "Voluntary framework",
      "provision": "Measure (2.7 - AI system security and resilience is evaluated) and Manage functions",
      "status": "voluntary-referenced",
      "statusNote": "Voluntary; widely referenced by auditors and US procurement.",
      "applicableDate": null,
      "jurisdiction": "US (voluntary, international use)",
      "primarySource": "https://www.nist.gov/itl/ai-risk-management-framework",
      "secondarySource": "https://csrc.nist.gov/pubs/ai/100/2/e2025/final",
      "lastVerified": "2026-07-26",
      "editorNote": "Voluntary yardstick; no binding date.",
      "provaelSupports": "A measured ASR with a CI and a benign control as the Measure-function evidence; a CI red-team gate for the Manage function.",
      "provaelDoesNotEstablish": "The AI RMF is not certifiable; Provael provides evidence, not conformity.",
      "responsibleActor": "The organisation operating the AI system."
    },
    {
      "id": "iec-62443",
      "framework": "IEC 62443",
      "title": "IEC 62443 (series)",
      "instrument": "Multi-part standard series",
      "provision": "Security Levels (SL 1-4) for industrial automation and control systems",
      "status": "series-maintained",
      "statusNote": "Actively maintained series; referenced by industrial-security assessors.",
      "applicableDate": null,
      "jurisdiction": "International (IEC/ISA)",
      "primarySource": "https://www.iec.ch/cyber-security",
      "secondarySource": "https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards",
      "lastVerified": "2026-07-26",
      "editorNote": "A measured ASR under defined attack channels is evidence toward a target SL for the policy layer.",
      "provaelSupports": "Per-channel adversarial-robustness evidence framed against the SL model, foldable into a 62443-3-3 assessment.",
      "provaelDoesNotEstablish": "Not an SL certification.",
      "responsibleActor": "Integrator / asset owner."
    },
    {
      "id": "eu-product-liability-directive",
      "framework": "EU Product Liability Directive",
      "title": "Directive (EU) 2024/2853 (revised product liability)",
      "instrument": "Directive (EU) 2024/2853 (repeals Directive 85/374/EEC)",
      "provision": "Software and AI systems are 'products'; lowered evidentiary burden; disclosure duties",
      "status": "adopted-transposition-pending",
      "statusNote": "Published OJ 18 November 2024; in force 8 December 2024; Member States must transpose by 9 December 2026. Applies to products placed on the market or put into service after 9 December 2026.",
      "applicableDate": "2026-12-09",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng",
      "secondarySource": null,
      "lastVerified": "2026-08-19",
      "editorNote": "The nearest EU deadline after the Machinery Regulation, and the one that bites hardest on an AI-driven robot: a defective-product claim no longer needs to prove the mechanism, and software counts as a product. Non-commercial free and open-source software is out of scope.",
      "provaelSupports": "Documented adversarial-robustness testing at the time of placing on the market — evidence toward the state-of-the-art and due-diligence positions a manufacturer will need to argue, and a dated artefact for the disclosure obligation.",
      "provaelDoesNotEstablish": "Does not establish a defence, does not determine defectiveness, and is not legal advice.",
      "responsibleActor": "Manufacturer / importer / authorised representative (and, for a component, its manufacturer).",
      "verificationNote": "CELEX 32024L2853: Member States \"bring into force ... by 9 December 2026\"."
    },
    {
      "id": "eu-ai-act-general-application",
      "framework": "EU AI Act",
      "title": "Regulation (EU) 2024/1689 — general application, transparency, governance and penalties",
      "instrument": "Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744",
      "provision": "Article 50 transparency; governance framework; notifying authorities; penalties",
      "status": "applies",
      "statusNote": "General application date 2 August 2026, retained by Regulation (EU) 2026/1744. Two further prohibited practices (non-consensual intimate imagery and CSAM) apply from 2 December 2026.",
      "applicableDate": "2026-08-02",
      "additionalDate": "2026-12-02",
      "jurisdiction": "EU",
      "primarySource": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
      "secondarySource": "https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng",
      "lastVerified": "2026-08-19",
      "editorNote": "Recorded because the high-risk deferral to 2027/2028 is often misread as deferring the whole Act. Transparency, governance and penalties still bite from 2 August 2026.",
      "provaelSupports": "Nothing directly — this entry exists so the clock is not misread as 'the AI Act does not apply yet'.",
      "provaelDoesNotEstablish": "Not a compliance position on any Article 50 obligation.",
      "responsibleActor": "Provider / deployer as applicable per obligation.",
      "verificationNote": "CELEX 32026R1744 confirms the 2 August 2026 general application date is retained, and that the amendment itself applies from 27 July 2026."
    },
    {
      "id": "kr-ai-framework-act",
      "framework": "Korea AI Framework Act",
      "title": "Framework Act on the Development of AI and Establishment of Trust (AI Basic Act)",
      "instrument": "Republic of Korea, Act No. 20676 (with Enforcement Decree)",
      "provision": "High-impact AI obligations: human oversight, interruption and rollback, risk management",
      "status": "in-force",
      "statusNote": "In force 22 January 2026 with its Enforcement Decree. Enforcement of the penalty provisions is deferred by one year. The first enforceable comprehensive AI statute outside the EU.",
      "applicableDate": "2026-01-22",
      "jurisdiction": "KR",
      "primarySource": "https://www.law.go.kr/LSW/eng/engMain.do",
      "secondarySource": "https://cset.georgetown.edu/publication/south-korea-ai-law-2025/",
      "lastVerified": "2026-07-26",
      "editorNote": "Relevant disproportionately to robotics: Korea has the world's highest industrial-robot density and the high-impact duties explicitly include interruption and rollback mechanisms and human supervision — the behaviours a red-team result speaks to. Verify the current text and the deferred-penalty position with Korean counsel.",
      "provaelSupports": "Adversarial-robustness evidence for a high-impact AI system's risk-management and human-oversight documentation.",
      "provaelDoesNotEstablish": "No Korean conformity or registration position; not legal advice.",
      "responsibleActor": "AI business operator placing a high-impact system on the Korean market."
    },
    {
      "id": "ansi-a3-r1506-2025",
      "framework": "ANSI/A3 R15.06-2025",
      "title": "ANSI/A3 R15.06-2025 (US national adoption of ISO 10218-1/-2:2025)",
      "instrument": "ANSI/A3 R15.06-2025",
      "provision": "US industrial-robot safety, incl. the new cybersecurity provisions",
      "status": "published",
      "statusNote": "US national adoption of ISO 10218-1:2025 and ISO 10218-2:2025, reproducing them in full. The first major revision of the US robot safety standard since ANSI/RIA R15.06-2012.",
      "applicableDate": "2025-08-21",
      "jurisdiction": "US",
      "primarySource": "https://www.automate.org/a3-standards",
      "secondarySource": "https://www.iso.org/standard/73933.html",
      "lastVerified": "2026-07-26",
      "editorNote": "The US route to the same clauses as ISO 10218:2025 — recorded so a US-market reader is not told the ISO entry is EU-only.",
      "provaelSupports": "The same adversarial-robustness evidence mappable to an ISO 10218-2 system assessment.",
      "provaelDoesNotEstablish": "Not conformity to R15.06; not a certificate.",
      "responsibleActor": "Robot integrator / system assessor (US)."
    },
    {
      "id": "nist-ai-agent-standards",
      "framework": "NIST AI Agent Standards Initiative",
      "title": "NIST CAISI AI Agent Standards Initiative (autonomous AI agents)",
      "instrument": "NIST Center for AI Standards and Innovation (CAISI) initiative",
      "provision": "Interoperability and security standards for AI agents capable of autonomous actions. Stated pillars: industry-led standards for AI agents, community-led interoperable agent protocols, and research into agent authentication and identity infrastructure. Accompanied by a Request for Information on AI Agent Security (comments closed 9 March 2026).",
      "status": "initiative-open",
      "statusNote": "Launched 17 February 2026. An initiative and RFI, NOT a published standard: there is no clause to conform to and no conformity route today.",
      "applicableDate": null,
      "jurisdiction": "US",
      "primarySource": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative",
      "secondarySource": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure",
      "lastVerified": "2026-07-31",
      "editorNote": "Recorded for what its published scope does NOT reach. As verified on the initiative page on 31 July 2026, the stated scope addresses autonomous SOFTWARE agents and makes no mention of robots, embodied AI, physical AI, autonomous vehicles or cyber-physical systems. That is an observation about the published scope on that date, NOT a statement that NIST has excluded embodied systems — NIST has said no such thing, and the scope may widen. Read the primary source before relying on this.",
      "provaelSupports": "Nothing yet. Provael measures a VLA policy's adversarial robustness in simulation; if the initiative's security-controls work later reaches embodied agents, that evidence would be the kind of input it calls for.",
      "provaelDoesNotEstablish": "Not conformity, not a certificate, not participation in the initiative, and no claim that NIST recognises Provael or its metric.",
      "responsibleActor": "Not yet assigned — no obligation exists under an open initiative."
    }
  ],
  "lastVerifiedNote": "DERIVED: the oldest per-entry lastVerified, never set by hand. The page can only claim to be as current as its least-recently-verified entry, so re-checking one instrument cannot refresh the whole clock. tests/regulatory-clock enforce this."
}