TA-14 AI GOVERNANCE LIBRARY
Official References
Access the authoritative publications, laws, regulations, standards, frameworks, and institutional materials connected to governance library records.
SOURCE PROVENANCE
An official reference connects a library record to the publication issued by the originating authority.
Official-source access supports provenance, verification, and independent review. It does not by itself prove that the referenced material applies to a specific entity, system, jurisdiction, lifecycle stage, role, or proposed execution.
REFERENCE CONTROL DESK
Search the authoritative materials behind the governance library.
Filter official references by title, publisher, publication type, source address, or record summary.
Artificial Intelligence and Data Act
A proposed Canadian legislative framework intended to regulate high-impact artificial intelligence systems.
Supports source verification, provenance review, and direct access to the originating publication.
Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
A companion profile to the NIST AI RMF addressing risks and actions specific to generative artificial intelligence.
Supports source verification, provenance review, and direct access to the originating publication.
Blueprint for an AI Bill of Rights
A nonbinding framework describing protections for people affected by automated systems.
Supports source verification, provenance review, and direct access to the originating publication.
Colorado Artificial Intelligence Act
A state law governing developers and deployers of high-risk artificial intelligence systems used in consequential decisions.
Supports source verification, provenance review, and direct access to the originating publication.
COSO Enterprise Risk Management Framework
An enterprise risk management framework integrating risk with strategy and organizational performance.
Supports source verification, provenance review, and direct access to the originating publication.
European Union Artificial Intelligence Act
A risk-based legal framework governing the development, placement on the market, deployment, and use of artificial intelligence systems in the European Union.
Supports source verification, provenance review, and direct access to the originating publication.
Federal Trade Commission Artificial Intelligence Guidance
A body of consumer-protection guidance and enforcement messaging addressing deceptive, unfair, discriminatory, and unsupported AI practices.
Supports source verification, provenance review, and direct access to the originating publication.
General Data Protection Regulation and Automated Decision-Making
European data-protection requirements governing personal data processing, profiling, transparency, and certain solely automated decisions.
Supports source verification, provenance review, and direct access to the originating publication.
IEEE 7000 Model Process for Addressing Ethical Concerns During System Design
A standard process for identifying and addressing ethical values and concerns during system and software design.
Supports source verification, provenance review, and direct access to the originating publication.
ISO 31000 Risk Management Guidelines
General principles, framework, and process guidance for managing risk across organizations.
Supports source verification, provenance review, and direct access to the originating publication.
ISO/IEC 22989 Artificial Intelligence Concepts and Terminology
An international standard establishing concepts and terminology used across artificial intelligence systems and related standards.
Supports source verification, provenance review, and direct access to the originating publication.
ISO/IEC 23053 Framework for Artificial Intelligence Systems Using Machine Learning
A framework describing machine-learning-based AI systems and their components, functions, and relationships.
Supports source verification, provenance review, and direct access to the originating publication.
ISO/IEC 23894 Artificial Intelligence Risk Management
International guidance for organizations seeking to identify, assess, treat, monitor, and communicate risks related to artificial intelligence.
Supports source verification, provenance review, and direct access to the originating publication.
ISO/IEC 38507 Governance Implications of the Use of Artificial Intelligence by Organizations
Guidance for governing bodies on the organizational implications of using artificial intelligence.
Supports source verification, provenance review, and direct access to the originating publication.
ISO/IEC 42001 Artificial Intelligence Management System
An international management system standard specifying requirements for establishing, implementing, maintaining, and continually improving an AI management system.
Supports source verification, provenance review, and direct access to the originating publication.
MITRE ATLAS
A knowledge base of adversary tactics and techniques targeting machine-learning and AI systems.
Supports source verification, provenance review, and direct access to the originating publication.
New York City Local Law 144 on Automated Employment Decision Tools
A local law regulating certain automated employment decision tools used in hiring and promotion decisions.
Supports source verification, provenance review, and direct access to the originating publication.
NIST Artificial Intelligence Risk Management Framework
A voluntary framework for managing risks associated with artificial intelligence across organizational and system lifecycles.
Supports source verification, provenance review, and direct access to the originating publication.
OECD Principles on Artificial Intelligence
International principles promoting innovative and trustworthy artificial intelligence that respects human rights and democratic values.
Supports source verification, provenance review, and direct access to the originating publication.
OMB Memorandum M-24-10: Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence
Federal agency guidance establishing governance, innovation, inventory, and risk-management expectations for agency use of artificial intelligence.
Supports source verification, provenance review, and direct access to the originating publication.
OWASP Top 10 for Large Language Model Applications
A community-developed list of significant security risks affecting applications built with large language models.
Supports source verification, provenance review, and direct access to the originating publication.
UNESCO Recommendation on the Ethics of Artificial Intelligence
A global normative instrument addressing the ethical development and use of artificial intelligence.
Supports source verification, provenance review, and direct access to the originating publication.
United Nations Guiding Principles on Business and Human Rights
A global framework defining state duties and corporate responsibilities regarding business-related human-rights impacts.
Supports source verification, provenance review, and direct access to the originating publication.
REFERENCE REVIEW MODEL
Official material should remain connected to provenance, applicability, interpretation, evidence, and execution.
Confirm the institution, regulator, legislature, standards body, or technical authority responsible for the publication.
Verify the official title, source location, publication type, and authoritative version of the referenced material.
Establish whether the material governs the relevant jurisdiction, organization, system, role, sector, or use case.
Identify the obligation, expectation, control, principle, prohibition, or evidence requirement created by the source.
Define what must be demonstrated before the proposed activity can be accepted, reviewed, or permitted to proceed.
Record how the source was applied, what decision followed, and whether the governed result satisfied the required condition.
OFFICIAL SOURCE CLASSES
Different publication classes carry different forms of authority.
The source class helps explain how the material should be interpreted, but the actual effect depends on mandate, jurisdiction, adoption, contractual use, and operating context.
Establishes rights, duties, prohibitions, powers, or enforcement structures within a defined jurisdiction.
Converts statutory authority into enforceable obligations, procedural requirements, and supervisory expectations.
Defines repeatable requirements, controls, processes, measurements, or conformity-assessment structures.
Organizes functions, outcomes, practices, and implementation pathways for managing AI systems and associated risks.
Explains expected practices, recommended controls, implementation methods, or supervisory interpretation.
Establishes values, objectives, or public-interest commitments that may later be translated into more specific requirements.
REFERENCE-TO-EXECUTION BOUNDARY
An official source proves where the governing material came from. Admissibility requires proof that it governs the proposed action.
Source authority, applicability, requirement interpretation, evidence validation, and execution control must remain distinct. A valid publication can still be irrelevant to a particular decision, entity, system, or operational condition.