← The framework← Het framework

In development · Standards mapping v0.2 · checked 4 October 2026. My reading of each instrument, not legal advice. Coverage is not the same as legal applicability: whether a provision applies depends on the system, the actor, the sector and the jurisdiction.

Responsible AI & Human Agency · Framework · Evidence base

How existing AI governance instruments address human agency — and where further assessment may be useful

A clause-level mapping of the framework's eighteen assessment domains against the EU AI Act, the GDPR, the NIST AI RMF, ISO/IEC AI standards, the OECD AI Principles and the UNESCO Recommendation.

Why this mapping exists

Any new AI framework has to answer an obvious question: why do we need it, when the AI Act, the GDPR, NIST, ISO, the OECD and UNESCO already exist?

The honest answer is not that these instruments ignore people. They don't. NIST treats AI risk as sociotechnical and asks about impacts on individuals and communities; the OECD names dignity, autonomy and human capacity; UNESCO gives dignity foundational status and calls for meaningful participation; ISO/IEC 42005 is a whole standard on AI system impact assessment.

Existing instruments provide substantial coverage of technical risk, governance processes, fundamental rights and selected human impacts. Coverage is less systematic and less operational for retained human capability, appropriate reliance, relational integrity, practical autonomy, the distribution of gains and burdens, organisational incentives, and the degree of influence affected people have over AI-use decisions.

So the framework is designed to complement, not replace, existing law and standards. It reuses their requirements at the level of one specific AI use, and adds explicit evidence requirements where they stop short. Where an instrument already does what a domain asks, the framework should defer to it — and if this mapping shows a domain adds nothing, the domain should change.

Instruments and versions

InstrumentVersion usedStatus for this mapping
EU AI ActRegulation (EU) 2024/1689Binding EU law. Many duties depend on risk class and actor role; most high-risk obligations apply from 2 December 2027.
GDPRRegulation (EU) 2016/679Binding, but only within the scope of personal-data processing.
NIST AI RMFAI RMF 1.0 (NIST AI 100-1, January 2023)Voluntary. NIST states that AI RMF 1.0 is being revised; this mapping is locked to 1.0 and must be reviewed when a successor is final.
ISO/IEC42001:2023 · 23894:2023 · 42005:2025 · 42006:2025Published standards. Mapped at standard level from official ISO descriptions; clause-level mapping pending verification against licensed text. ISO/IEC 42105 (human oversight) is still under development and is tracked, not cited.
OECD AI PrinciplesRecommendation on AI, principles updated May 2024Non-binding intergovernmental recommendation.
UNESCORecommendation on the Ethics of AI, November 2021Global normative recommendation.

The Council of Europe Framework Convention is referenced elsewhere in the series and will be added to this mapping in a later version.

How to read the matrix

  • F Fully covers — within its own scope, the provision directly addresses the domain's core question. This does not mean it proves a deployment responsible.
  • P Partly covers — addresses an important part, but is narrower in subject, applicability, evidence or outcome.
  • N Does not cover — no sufficiently direct provision found. Indirect help is not counted as coverage.
  • clause pending — ISO mapping based on the standard's published scope; exact clauses not yet verified.

Coverage is conceptual coverage where the provision applies. “Article 14 fully covers meaningful oversight” means: for the high-risk systems Article 14 applies to. It is not a substitute for a legal applicability analysis.

Layer 1 · Technical responsibility

DomainEU AI ActGDPRNIST AI RMF 1.0ISO/IECOECDUNESCOWhat the framework adds
Validity & accuracyF Arts. 9, 13(3)(b), 15, 72P Arts. 5(1)(d), 35(7)F MAP 2.3; MEASURE 2.4–2.5P 42001, 23894 clause pendingP 1.4P paras. 50–53Local, representative validation for this use — not inherited provider benchmarks.
Robustness & reliabilityF Arts. 15, 72P Art. 32(1)(b),(d)F MEASURE 2.5–2.7, 3.1P 42001, 23894 clause pendingF 1.4F paras. 27, 52–53, 56Stress, drift and recovery thresholds tied to the actual deployment.
Fairness & subgroup performanceP Arts. 10(2)–(3), 27(1)(c)–(d)P Arts. 5(1)(a), 9, 35(7)F MEASURE 2.2, 2.11; MAP 5P 42005 clause pendingP 1.1–1.2F paras. 28–30, 50–53Disaggregated errors and outcomes, with justified treatment of disparities.
Uncertainty & abstentionP Arts. 13(3)(b), 14(4)N —P MAP 2.2; MEASURE 2.5P 42001, 42005 clause pendingP 1.3–1.4P paras. 37–40Calibrated uncertainty and tested abstention, linked to an action: verify, escalate or stop.
Security & privacyP Arts. 10, 15(5)F Arts. 5, 25, 32–34F MEASURE 2.7, 2.10P 42001, 23894 clause pendingF 1.2, 1.4F paras. 27, 32–34Data protection combined with permissions, action security and abuse testing.
TraceabilityF Arts. 12, 13(3)(f), 26(6)P Arts. 5(2), 13–15, 30P GOVERN 1.6; MEASURE 2.8P 42001 clause pendingP 1.3–1.5F paras. 40, 43, 53, 55Reconstruct model version, evidence, human action and downstream outcome.

Finding: the technical layer is complementary, not novel. Organisations should reuse existing technical evidence — AI Act documentation, logs, security records, NIST test results — and the framework asks whether that evidence justifies this use, population and workflow. The clearest technical addition is uncertainty and abstention: instruments ask for information about limitations, but not for evidence that a system can decline or defer when it lacks a basis to answer.

Layer 2 · Human responsibility

DomainEU AI ActGDPRNIST AI RMF 1.0ISO/IECOECDUNESCOWhat the framework adds
Retained capabilityP Arts. 4, 14(4), 26(2)N —P GOVERN 2.2; MAP 3.4P 42001, 42005 clause pendingP 1.1, 2.4P paras. 44–45, 101–104, 116–118Unaided human performance before and after sustained AI use.
Appropriate relianceP Art. 14(4)(b)–(d)P Art. 22(3)P MAP 3.5P 42005 clause pendingP 1.2–1.3P paras. 35–40, 51Correct acceptance and correct rejection of AI outputs — not “trust” or agreement rates.
Meaningful oversightF Arts. 14, 26(2)P Art. 22(1)–(3)F GOVERN 3.2; MAP 3.5P 42001, 42005 clause pendingF 1.2, 1.4F paras. 35–36, 53Evidence that reviewers actually detect errors, disagree and use their stop authority.
Autonomy & choiceP Arts. 5(1)(a)–(b), 50(1), 86P Arts. 7(3), 21, 22P MANAGE 2.1; MAP 3.5P 42005 clause pendingP 1.2–1.3P paras. 13–16, 35–38A realistic human or non-AI route, without penalty or excessive friction.
Dignity & relational integrityP Arts. 5(1)(a)–(b), 50(1)N —P MAP 1.1, MAP 5; MEASURE 2.8–2.9P 42005 clause pendingP 1.2–1.3P paras. 13–16, 37–40Whether human-like presentation misrepresents competence, agency, understanding or care.
Human impact & distributionP Art. 27(1)(c)–(f)P Art. 35(7), (9)F MAP 3.1–3.2, MAP 5; MEASURE 4.1F 42005 clause pendingF 1.1, 2.4F paras. 31, 50–53, 116–118Who gains time or money — and who absorbs errors, verification work and displacement.

Finding: this is where the framework is most differentiated. No instrument fully covers retained capability, appropriate reliance, autonomy and choice, or dignity and relational integrity as the framework defines them. They are addressed — often thoughtfully — but not as observable properties of a deployment. Meaningful oversight and appropriate reliance are different questions: a workflow can legally allow a person to override AI while that person still accepts wrong recommendations most of the time. NIST comes notably close on autonomy: MANAGE 2.1 asks organisations to consider “viable non-AI alternative systems, approaches, or methods”.

Layer 3 · Organisational responsibility

DomainEU AI ActGDPRNIST AI RMF 1.0ISO/IECOECDUNESCOWhat the framework adds
AccountabilityP Arts. 16–17, 26P Arts. 5(2), 24, 37–39F GOVERN 2.1–2.3; MEASURE 2.8F 42001, 42005 clause pendingF 1.5F paras. 42–43, 58An owner with real authority, information, budget and protection to act — not only a named role.
Incentives & cultureP Arts. 4, 17, 26(2)P Art. 38(3)F GOVERN 1.3, 2.3, 4.1–4.3P 42001 clause pendingP 1.5, 2.4P paras. 43, 54–58Targets, bonuses, launch pressure, budgets, the career cost of dissent, and who pays for verification.
Participation & inclusionP Arts. 26(7), 27(1)(c)–(f)P Art. 35(9)P MAP 1.2; GOVERN 5.1–5.2; MEASURE 1.3P 42001, 42005 clause pendingP 1.1, 2.4F paras. 47, 50, 53, 58Influence, not presence: what affected people could change, what did change, and whether they could argue against using AI.
Legal complianceP Arts. 16(a), 43 and applicable dutiesP Arts. 5(2), 24, 35F GOVERN 1.1P 42001 clause pendingP 1.2P paras. 13–16, 42, 61A jurisdiction- and sector-specific legal register; the framework is never a substitute for the law.
Independent challengeP Arts. 43, 74–84P Arts. 36, 38(3), 51–58F MEASURE 1.3P 42006, 42001 clause pendingP 1.3, 1.5F paras. 43, 53, 58, 62Assessor independence, evidence access, conflicts, escalation and stop rights — defined, not assumed.
Incident response & remedyP Arts. 20, 26(5), 72–73, 85–86P Arts. 33–34, 77–79, 82F GOVERN 4.3, 5.1–5.2; MEASURE 3.3; MANAGE 2.3P 42001, 23894, 42005 clause pendingP 1.3–1.5F paras. 29, 54–56Near misses, remedy outcomes, recurrence analysis and verified closure of corrective action.

Finding: instruments converge strongly on accountability as a role. The framework asks a harder question: does the accountable party have the authority, information, money and protection to act? On participation, the AI Act's fundamental rights impact assessment (Art. 27) requires covered deployers to identify affected groups and the risks to them — but not to involve them; Art. 26(7) requires informing workers, not sharing decisions with them. Major instruments increasingly recognise affected people, but generally stop short of guaranteeing that they can influence the problem definition, reject AI as the solution, alter success criteria or change the go/no-go decision.

Across time: evidence expires

Lifecycle thinking is already well represented: post-market monitoring and serious-incident reporting in the AI Act (Arts. 72–73), production monitoring in NIST (MEASURE 2.4, 3.1), lifecycle robustness in the OECD principles, and lifecycle monitoring in UNESCO (para. 52). So the framework's contribution is not “monitor AI continuously”. It is narrower:

Evidence supporting a responsible-use decision expires when the facts that justified it materially change — and reassessment covers all eighteen domains, not only technical performance.

Evidence levels are not legal strength

The framework's evidence levels — E0 assertion, E1 controlled test, E2 production evidence, E3 independent challenge, E4 human corroboration — describe the kind of evidence, not the legal weight of a requirement. A binding legal duty can be satisfied with E0 evidence, such as a named role or a policy; a voluntary recommendation can call for E4 evidence from affected people. Meeting a documentation obligation therefore never counts, by itself, as evidence of responsible outcomes.

Verification status

Checked against the primary sourceStill pending
Every cited EU AI Act article, including Arts. 14(4)(b), 26(7) and 27(1)(c)–(d)ISO/IEC clause-level mapping against licensed text
Every cited NIST AI RMF 1.0 subcategory, against NIST AI 100-1A second, independent reviewer for every cell
OECD principle numbering, and every cited UNESCO paragraphParagraph-level second check of GDPR cells
Publication status of ISO/IEC 42001, 23894, 42005, 42006 and 42105Adding the Council of Europe Framework Convention

Going forward, each mapping should record the instrument and edition, scope, exact provision, applicability status, source, reviewer, second reviewer, date checked and the change that would trigger a review. The crosswalk needs continuous assurance too: laws are amended, NIST AI RMF 1.0 is being revised, and new ISO standards are on the way.

Primary sources

  1. Legislation Regulation (EU) 2024/1689 (AI Act). eur-lex.europa.eu · article texts via artificialintelligenceact.eu.
  2. Legislation Regulation (EU) 2016/679 (GDPR). eur-lex.europa.eu.
  3. Framework NIST (2023). AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1. doi:10.6028/NIST.AI.100-1 · status: nist.gov.
  4. Standards ISO/IEC 42001:2023 · 23894:2023 · 42005:2025 · 42006:2025.
  5. International principles OECD. AI Principles. oecd.ai.
  6. International recommendation UNESCO (2021). Recommendation on the Ethics of Artificial Intelligence. unesco.org.