Four reference points
| Source | Status | Useful lens |
|---|---|---|
| CEPEJ Ethical Charter | Council of Europe principles adopted in 2018 | Rights, non-discrimination, quality, transparency, user control |
| England and Wales judicial guidance | Professional guidance updated October 2025 | Responsibility, confidentiality, hallucination and bias |
| NIST AI RMF | Voluntary risk framework | Govern, map, measure and manage |
| EU AI Act | Binding EU regulation with phased application | Risk classification and obligations for covered systems |
Do not collapse legal status
A principle, employer or judicial-office guidance, technical risk framework and regulation are not interchangeable. The applicable duty depends on the institution, user, system purpose, territory and implementation date. Procurement material should cite the exact provision or document rather than claiming generic "AI Act compliance".
How to use the tracker
Start with the governing law and institutional rules. Use CEPEJ and NIST to structure questions that may not be fully specified in law. Record which version was used in a risk assessment. Update the assessment when system purpose, model, data or deployment context changes.
Product relevance
For a document-drafting assistant, practical controls include explicit human review, jurisdiction context, unreadable-page reporting, source preservation, access control and incident logging. These controls reduce risk but do not certify compliance in every jurisdiction.
Read our methodology and security overview.
