arXiv AI

From Regulation to Implementation: A Critical Evaluation of LLM-Assisted Regulatory Compliance in Industry

The paper examines how large language models (LLMs) can assist in creating regulatory compliance artifacts for EU sustainability and privacy laws, specifically Digital Product Passports (DPPs) under the Ecodesign for Sustainable Products Regulation and Data Protection Impact Assessments (DPIAs) under the General Data Protection Regulation. It investigates the effects of data extraction instructions and regulatory ambiguity on the quality and consistency of LLM-generated artifacts, benchmarking various models against manually crafted ground‑truth schemas. Findings indicate that looser guidelines, like those for DPIAs, demand more extensive prompts to achieve consistency, whereas stricter formatting rules for DPPs yield consistent outputs but may introduce hallucinations.

arXiv AI
Jul 7

From Regulation to Requirements: An Automated Requirement Derivation and Explanation Pipeline

arXiv:2607. 04448v1 Announce Type: cross Abstract: Ensuring software compliance with regulations such as the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (EU AI Act) poses a significant challenge, as requirements engineers must translate complex legal text into actionable software requirements - a process that remains largely manual and error-prone in practice.

By Pavithra PM Nair, Preethu Rose Anish
Hugging Face Trending Papers
Aug 3

CTRAG: An In-Context Retrieval-based Framework for Automated Compliance Checking using LLMs

Trust is fundamental in modern regulatory ecosystems, and compliance checking plays a critical role in fostering that trust. Regulatory compliance verification is essential for businesses operating in highly controlled environments, as it ensures alignment with sector-specific guidelines across domains such as financial reporting, data privacy, and cybersecurity.

arXiv AI
Jun 9

Trustworthy Smart Fabs via Professional Proxies: Scaling Safe and Sustainable by Design (SSbD) through Industrial Data Spaces

arXiv:2606. 09227v1 Announce Type: cross Abstract: The convergence of the 2026 European Union Safe and Sustainable by Design (SSbD) framework, Corporate Sustainability Due Diligence Directive (CSDDD), and Carbon Border Adjustment Mechanism (CBAM) introduce a severe governance bottleneck for advanced semiconductor manufacturing facilities ("Smart Fabs").

By Han-Teng Liao, Chang-Yi Kao, Karen Ang
arXiv AI
Sep 18

Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

The paper introduces Governance-as-Code (GaC), a framework that translates the EU AI Act’s technical requirements into 43 machine‑checkable acceptance criteria across six compliance modules. GaC runs within a CI/CD pipeline, producing Article‑indexed audit evidence and providing actual Rego policy code. The authors validate GaC on two enterprise deployments, showing it reproduces manual audit findings—including three penalty‑triggering violations—while reducing audit labor by about 75%.

By Rudrendu Kumar Paul, Sourav Nandy
arXiv AI
Sep 18

Code-as-Auditor: Executable Compliance Reasoning via Regulation-to-Code

Code-as-Auditor is an LLM-based framework that transforms regulatory information into formal checklists and executable decision trees, encoding rules as interpretable code. During inference, the model expands each checklist item into factual and counterfactual questions, guiding reasoning over case-specific evidence and potential violations. This pipeline moves from evidence identification to rule application and final decision-making, with a self‑verification loop that enhances logical consistency and traceability, leading to more accurate and evidence‑backed compliance evaluations in privacy and data protection scenarios.

By Jisoo Kim, Taeyoon Kwack, Jinwoo Jang, Woo Kyung Kim, Honguk Woo
arXiv AI
Aug 18

Position: AI Governance Needs ISO-like Interoperability Protocols, Not Just Laws

The paper argues that AI governance should rely on ISO-like interoperability protocols rather than solely on jurisdiction-specific laws. It proposes standardized AI nutrition labels that include metrics for bias, energy usage, and data provenance to enable machine‑readable risk communication across borders. These protocols aim to reduce regulatory fragmentation, lower barriers for SMEs, and build public trust while allowing modular evolution with technology.

By Azmine Toushik Wasi, Mst Rafia Islam, Mahfuz Ahmed Anik, Taki Hasan Rafi, Md Manjurul Ahsan, Dong-Kyu Chae
arXiv AI
Aug 28

GROUND: Reducing Hallucinations in LLM-Based Enterprise Analytics Through Governed Semantic Definitions

The paper introduces GROUND, a framework that limits large language model (LLM) analytics to a governed semantic layer for enterprise data warehouses. GROUND supplies approved metrics, dimensions, join paths, filters, and security rules, then validates generated SQL against these constraints before execution, retrying or abstaining on violations. In benchmarks, GROUND eliminates hallucinations across all evaluated categories and prevents row‑level security breaches, outperforming schema‑only, schema‑RAG, and semantic‑only approaches.

By Aravind Sasidharan Pillai
arXiv AI
Aug 11

UGAF-ITS: A Standards Harmonization Framework and Validation Tool for Multi-Framework AI Governance in Distributed Intelligent Transportation Systems

arXiv:2604. 22789v2 Announce Type: replace-cross Abstract: Organizations deploying AI-enabled Intelligent Transportation Systems face fragmented governance: ISO/IEC~42001 demands a certifiable management system, the EU AI Act imposes binding high-risk obligations from August~2026, and the NIST AI Risk Management Framework structures voluntary practice.

By Talal Ashraf Butt, Muhammad Iqbal, Razi Iqbal
arXiv Computation and Language
Sep 3

Privacy Washing: Detecting Internal Contradictions in Privacy Policies

The study introduces a four‑stage pipeline to detect internal contradictions—termed privacy washing—in privacy policies. Applied to two corpora (123 policies from 2026 and 115 from 2015), the pipeline identifies contradictions in 12.2% of the newer policies and 36.5% of the older ones, with third‑party sharing conflicts being the most common. A stability re‑run confirms similar prevalence rates and shows that the majority of contradictions are consistent across different model configurations.

By Thomas Brackin