In development · Standards mapping v0.2 · checked 4 October 2026. My reading of each instrument, not legal advice. Coverage is not the same as legal applicability: whether a provision applies depends on the system, the actor, the sector and the jurisdiction.
Responsible AI & Human Agency · Framework · Evidence base
How existing AI governance instruments address human agency — and where further assessment may be useful
A clause-level mapping of the framework's eighteen assessment domains against the EU AI Act, the GDPR, the NIST AI RMF, ISO/IEC AI standards, the OECD AI Principles and the UNESCO Recommendation.
Why this mapping exists
Any new AI framework has to answer an obvious question: why do we need it, when the AI Act, the GDPR, NIST, ISO, the OECD and UNESCO already exist?
The honest answer is not that these instruments ignore people. They don't. NIST treats AI risk as sociotechnical and asks about impacts on individuals and communities; the OECD names dignity, autonomy and human capacity; UNESCO gives dignity foundational status and calls for meaningful participation; ISO/IEC 42005 is a whole standard on AI system impact assessment.
Existing instruments provide substantial coverage of technical risk, governance processes, fundamental rights and selected human impacts. Coverage is less systematic and less operational for retained human capability, appropriate reliance, relational integrity, practical autonomy, the distribution of gains and burdens, organisational incentives, and the degree of influence affected people have over AI-use decisions.
So the framework is designed to complement, not replace, existing law and standards. It reuses their requirements at the level of one specific AI use, and adds explicit evidence requirements where they stop short. Where an instrument already does what a domain asks, the framework should defer to it — and if this mapping shows a domain adds nothing, the domain should change.
Instruments and versions
| Instrument | Version used | Status for this mapping |
|---|---|---|
| EU AI Act | Regulation (EU) 2024/1689 | Binding EU law. Many duties depend on risk class and actor role; most high-risk obligations apply from 2 December 2027. |
| GDPR | Regulation (EU) 2016/679 | Binding, but only within the scope of personal-data processing. |
| NIST AI RMF | AI RMF 1.0 (NIST AI 100-1, January 2023) | Voluntary. NIST states that AI RMF 1.0 is being revised; this mapping is locked to 1.0 and must be reviewed when a successor is final. |
| ISO/IEC | 42001:2023 · 23894:2023 · 42005:2025 · 42006:2025 | Published standards. Mapped at standard level from official ISO descriptions; clause-level mapping pending verification against licensed text. ISO/IEC 42105 (human oversight) is still under development and is tracked, not cited. |
| OECD AI Principles | Recommendation on AI, principles updated May 2024 | Non-binding intergovernmental recommendation. |
| UNESCO | Recommendation on the Ethics of AI, November 2021 | Global normative recommendation. |
The Council of Europe Framework Convention is referenced elsewhere in the series and will be added to this mapping in a later version.
How to read the matrix
- F Fully covers — within its own scope, the provision directly addresses the domain's core question. This does not mean it proves a deployment responsible.
- P Partly covers — addresses an important part, but is narrower in subject, applicability, evidence or outcome.
- N Does not cover — no sufficiently direct provision found. Indirect help is not counted as coverage.
- clause pending — ISO mapping based on the standard's published scope; exact clauses not yet verified.
Coverage is conceptual coverage where the provision applies. “Article 14 fully covers meaningful oversight” means: for the high-risk systems Article 14 applies to. It is not a substitute for a legal applicability analysis.
Layer 1 · Technical responsibility
| Domain | EU AI Act | GDPR | NIST AI RMF 1.0 | ISO/IEC | OECD | UNESCO | What the framework adds |
|---|---|---|---|---|---|---|---|
| Validity & accuracy | F Arts. 9, 13(3)(b), 15, 72 | P Arts. 5(1)(d), 35(7) | F MAP 2.3; MEASURE 2.4–2.5 | P 42001, 23894 clause pending | P 1.4 | P paras. 50–53 | Local, representative validation for this use — not inherited provider benchmarks. |
| Robustness & reliability | F Arts. 15, 72 | P Art. 32(1)(b),(d) | F MEASURE 2.5–2.7, 3.1 | P 42001, 23894 clause pending | F 1.4 | F paras. 27, 52–53, 56 | Stress, drift and recovery thresholds tied to the actual deployment. |
| Fairness & subgroup performance | P Arts. 10(2)–(3), 27(1)(c)–(d) | P Arts. 5(1)(a), 9, 35(7) | F MEASURE 2.2, 2.11; MAP 5 | P 42005 clause pending | P 1.1–1.2 | F paras. 28–30, 50–53 | Disaggregated errors and outcomes, with justified treatment of disparities. |
| Uncertainty & abstention | P Arts. 13(3)(b), 14(4) | N — | P MAP 2.2; MEASURE 2.5 | P 42001, 42005 clause pending | P 1.3–1.4 | P paras. 37–40 | Calibrated uncertainty and tested abstention, linked to an action: verify, escalate or stop. |
| Security & privacy | P Arts. 10, 15(5) | F Arts. 5, 25, 32–34 | F MEASURE 2.7, 2.10 | P 42001, 23894 clause pending | F 1.2, 1.4 | F paras. 27, 32–34 | Data protection combined with permissions, action security and abuse testing. |
| Traceability | F Arts. 12, 13(3)(f), 26(6) | P Arts. 5(2), 13–15, 30 | P GOVERN 1.6; MEASURE 2.8 | P 42001 clause pending | P 1.3–1.5 | F paras. 40, 43, 53, 55 | Reconstruct model version, evidence, human action and downstream outcome. |
Finding: the technical layer is complementary, not novel. Organisations should reuse existing technical evidence — AI Act documentation, logs, security records, NIST test results — and the framework asks whether that evidence justifies this use, population and workflow. The clearest technical addition is uncertainty and abstention: instruments ask for information about limitations, but not for evidence that a system can decline or defer when it lacks a basis to answer.
Layer 2 · Human responsibility
| Domain | EU AI Act | GDPR | NIST AI RMF 1.0 | ISO/IEC | OECD | UNESCO | What the framework adds |
|---|---|---|---|---|---|---|---|
| Retained capability | P Arts. 4, 14(4), 26(2) | N — | P GOVERN 2.2; MAP 3.4 | P 42001, 42005 clause pending | P 1.1, 2.4 | P paras. 44–45, 101–104, 116–118 | Unaided human performance before and after sustained AI use. |
| Appropriate reliance | P Art. 14(4)(b)–(d) | P Art. 22(3) | P MAP 3.5 | P 42005 clause pending | P 1.2–1.3 | P paras. 35–40, 51 | Correct acceptance and correct rejection of AI outputs — not “trust” or agreement rates. |
| Meaningful oversight | F Arts. 14, 26(2) | P Art. 22(1)–(3) | F GOVERN 3.2; MAP 3.5 | P 42001, 42005 clause pending | F 1.2, 1.4 | F paras. 35–36, 53 | Evidence that reviewers actually detect errors, disagree and use their stop authority. |
| Autonomy & choice | P Arts. 5(1)(a)–(b), 50(1), 86 | P Arts. 7(3), 21, 22 | P MANAGE 2.1; MAP 3.5 | P 42005 clause pending | P 1.2–1.3 | P paras. 13–16, 35–38 | A realistic human or non-AI route, without penalty or excessive friction. |
| Dignity & relational integrity | P Arts. 5(1)(a)–(b), 50(1) | N — | P MAP 1.1, MAP 5; MEASURE 2.8–2.9 | P 42005 clause pending | P 1.2–1.3 | P paras. 13–16, 37–40 | Whether human-like presentation misrepresents competence, agency, understanding or care. |
| Human impact & distribution | P Art. 27(1)(c)–(f) | P Art. 35(7), (9) | F MAP 3.1–3.2, MAP 5; MEASURE 4.1 | F 42005 clause pending | F 1.1, 2.4 | F paras. 31, 50–53, 116–118 | Who gains time or money — and who absorbs errors, verification work and displacement. |
Finding: this is where the framework is most differentiated. No instrument fully covers retained capability, appropriate reliance, autonomy and choice, or dignity and relational integrity as the framework defines them. They are addressed — often thoughtfully — but not as observable properties of a deployment. Meaningful oversight and appropriate reliance are different questions: a workflow can legally allow a person to override AI while that person still accepts wrong recommendations most of the time. NIST comes notably close on autonomy: MANAGE 2.1 asks organisations to consider “viable non-AI alternative systems, approaches, or methods”.
Layer 3 · Organisational responsibility
| Domain | EU AI Act | GDPR | NIST AI RMF 1.0 | ISO/IEC | OECD | UNESCO | What the framework adds |
|---|---|---|---|---|---|---|---|
| Accountability | P Arts. 16–17, 26 | P Arts. 5(2), 24, 37–39 | F GOVERN 2.1–2.3; MEASURE 2.8 | F 42001, 42005 clause pending | F 1.5 | F paras. 42–43, 58 | An owner with real authority, information, budget and protection to act — not only a named role. |
| Incentives & culture | P Arts. 4, 17, 26(2) | P Art. 38(3) | F GOVERN 1.3, 2.3, 4.1–4.3 | P 42001 clause pending | P 1.5, 2.4 | P paras. 43, 54–58 | Targets, bonuses, launch pressure, budgets, the career cost of dissent, and who pays for verification. |
| Participation & inclusion | P Arts. 26(7), 27(1)(c)–(f) | P Art. 35(9) | P MAP 1.2; GOVERN 5.1–5.2; MEASURE 1.3 | P 42001, 42005 clause pending | P 1.1, 2.4 | F paras. 47, 50, 53, 58 | Influence, not presence: what affected people could change, what did change, and whether they could argue against using AI. |
| Legal compliance | P Arts. 16(a), 43 and applicable duties | P Arts. 5(2), 24, 35 | F GOVERN 1.1 | P 42001 clause pending | P 1.2 | P paras. 13–16, 42, 61 | A jurisdiction- and sector-specific legal register; the framework is never a substitute for the law. |
| Independent challenge | P Arts. 43, 74–84 | P Arts. 36, 38(3), 51–58 | F MEASURE 1.3 | P 42006, 42001 clause pending | P 1.3, 1.5 | F paras. 43, 53, 58, 62 | Assessor independence, evidence access, conflicts, escalation and stop rights — defined, not assumed. |
| Incident response & remedy | P Arts. 20, 26(5), 72–73, 85–86 | P Arts. 33–34, 77–79, 82 | F GOVERN 4.3, 5.1–5.2; MEASURE 3.3; MANAGE 2.3 | P 42001, 23894, 42005 clause pending | P 1.3–1.5 | F paras. 29, 54–56 | Near misses, remedy outcomes, recurrence analysis and verified closure of corrective action. |
Finding: instruments converge strongly on accountability as a role. The framework asks a harder question: does the accountable party have the authority, information, money and protection to act? On participation, the AI Act's fundamental rights impact assessment (Art. 27) requires covered deployers to identify affected groups and the risks to them — but not to involve them; Art. 26(7) requires informing workers, not sharing decisions with them. Major instruments increasingly recognise affected people, but generally stop short of guaranteeing that they can influence the problem definition, reject AI as the solution, alter success criteria or change the go/no-go decision.
Across time: evidence expires
Lifecycle thinking is already well represented: post-market monitoring and serious-incident reporting in the AI Act (Arts. 72–73), production monitoring in NIST (MEASURE 2.4, 3.1), lifecycle robustness in the OECD principles, and lifecycle monitoring in UNESCO (para. 52). So the framework's contribution is not “monitor AI continuously”. It is narrower:
Evidence supporting a responsible-use decision expires when the facts that justified it materially change — and reassessment covers all eighteen domains, not only technical performance.
Evidence levels are not legal strength
The framework's evidence levels — E0 assertion, E1 controlled test, E2 production evidence, E3 independent challenge, E4 human corroboration — describe the kind of evidence, not the legal weight of a requirement. A binding legal duty can be satisfied with E0 evidence, such as a named role or a policy; a voluntary recommendation can call for E4 evidence from affected people. Meeting a documentation obligation therefore never counts, by itself, as evidence of responsible outcomes.
Verification status
| Checked against the primary source | Still pending |
|---|---|
| Every cited EU AI Act article, including Arts. 14(4)(b), 26(7) and 27(1)(c)–(d) | ISO/IEC clause-level mapping against licensed text |
| Every cited NIST AI RMF 1.0 subcategory, against NIST AI 100-1 | A second, independent reviewer for every cell |
| OECD principle numbering, and every cited UNESCO paragraph | Paragraph-level second check of GDPR cells |
| Publication status of ISO/IEC 42001, 23894, 42005, 42006 and 42105 | Adding the Council of Europe Framework Convention |
Going forward, each mapping should record the instrument and edition, scope, exact provision, applicability status, source, reviewer, second reviewer, date checked and the change that would trigger a review. The crosswalk needs continuous assurance too: laws are amended, NIST AI RMF 1.0 is being revised, and new ISO standards are on the way.
Primary sources
- Legislation Regulation (EU) 2024/1689 (AI Act). eur-lex.europa.eu · article texts via artificialintelligenceact.eu.
- Legislation Regulation (EU) 2016/679 (GDPR). eur-lex.europa.eu.
- Framework NIST (2023). AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1. doi:10.6028/NIST.AI.100-1 · status: nist.gov.
- Standards ISO/IEC 42001:2023 · 23894:2023 · 42005:2025 · 42006:2025.
- International principles OECD. AI Principles. oecd.ai.
- International recommendation UNESCO (2021). Recommendation on the Ethics of Artificial Intelligence. unesco.org.