Hael
Sign inBook a demo

AI GOVERNANCE FRAMEWORKS

Substantive coverage across 10 frameworks.

Each framework below is mapped at the article and control level. Hael produces the substantive artefact each regime actually demands — the Annex IV file, the AI RMF profile, the AIMS records, the bias audit, the impact assessment — generated from live operational state and sealed with hash-chained provenance. Not a checkbox indicator that the obligation exists.

EUROPEAN UNION
EU AI Act
Regulation (EU) 2024/1689

Risk-tiered AI system regulation. Article 11 demands a complete technical documentation file in Annex IV order before high-risk systems are placed on the market. The artefact the regulator opens.

EFFECTIVE 2 AUG 2026Coverage detail →
INTERNATIONAL
ISO/IEC 42001
AI Management System

The first certifiable AI management system standard. Auditors now scope certifications against it; enterprise buyers ask for it.

UNITED STATES
NIST AI RMF 1.0
NIST AI 100-1

GOVERN, MAP, MEASURE, MANAGE profiles. Voluntary baseline that federal procurement and sectoral frameworks map onto — the de-facto US AI risk-management language.

INTERNATIONAL
SOC 2
AICPA TSP 100

The trust-services audit enterprise buyers ask for first. Hael generates the System Description and AI-governance control evidence behind the report.

EUROPEAN UNION
GDPR
Regulation (EU) 2016/679

AI under GDPR: Article 22 safeguards for solely-automated decisions, Article 35 DPIAs, and the Articles 5/6 lawful-basis and data-governance duties that bite on training and inference.

COLORADO, USA
Colorado AI Act
SB 26-189 (reshapes SB 24-205)

Comprehensive duties on high-risk AI in consequential decisions. Hael produces the impact assessments and risk programme the law requires, aligned to NIST or ISO 42001.

EFFECTIVE 1 JAN 2027Coverage detail →
NEW YORK CITY
NYC Local Law 144
NYC Auto Employment Decision Tools

Independent bias audit, published summary and candidate notice for AEDTs. Hael maintains the audit record, summary and notice as living artefacts.

ILLINOIS, USA
Illinois HB 3773
Illinois Human Rights Act — AI amendment

Strict-liability bar on AI that produces discriminatory effects across the employment lifecycle; mandatory worker notice; no zip-code proxies. Hael runs the disparate-impact testing and notice lifecycle.

EUROPEAN UNION
DORA
Regulation (EU) 2022/2554

Five pillars of ICT resilience for ~22,000 EU financial entities. In force since 17 Jan 2025 with no transition. Hael maintains the ICT risk framework, register and testing records.

TEXAS, USA
Texas TRAIGA
HB 149

Intent-based prohibitions on harmful AI uses, enforced by the Texas AG with a 60-day cure period. Hael records the acceptable-use governance the AG expects.

ALSO RELEVANT

We also track the UK's principles-based AI approach, the OECD AI Principles, Singapore's Model AI Governance Framework, California SB 53 (TFAIA), the New York RAISE Act, the US Treasury FS AI RMF and the California ADMT rules. They inform our coverage but don't carry dedicated pages — the ten above are the regimes our buyers ask about first.

Talk to us about coverage for your specific exposure.

Book a demoSee the platform