arXiv:2607. 04448v1 Announce Type: cross Abstract: Ensuring software compliance with regulations such as the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (EU AI Act) poses a significant challenge, as requirements engineers must translate complex legal text into actionable software requirements - a process that remains largely manual and error-prone in practice.
By Pavithra PM Nair, Preethu Rose Anish
Trust is fundamental in modern regulatory ecosystems, and compliance checking plays a critical role in fostering that trust. Regulatory compliance verification is essential for businesses operating in highly controlled environments, as it ensures alignment with sector-specific guidelines across domains such as financial reporting, data privacy, and cybersecurity.
arXiv:2609.36228v1 Announce Type: new
Abstract: The EU AI Act introduces extensive compliance requirements for organizations that develop, deploy, or integrate AI systems. Many of these requirements...
By Zhen Tao, Alize Kahraman, Shidong Pan, Zhenchang Xing, Chiara Ullstein, Jens Grossklags, Chunyang Chen
arXiv:2606. 09227v1 Announce Type: cross Abstract: The convergence of the 2026 European Union Safe and Sustainable by Design (SSbD) framework, Corporate Sustainability Due Diligence Directive (CSDDD), and Carbon Border Adjustment Mechanism (CBAM) introduce a severe governance bottleneck for advanced semiconductor manufacturing facilities ("Smart Fabs").
By Han-Teng Liao, Chang-Yi Kao, Karen Ang
The paper introduces Governance-as-Code (GaC), a framework that translates the EU AI Act’s technical requirements into 43 machine‑checkable acceptance criteria across six compliance modules. GaC runs within a CI/CD pipeline, producing Article‑indexed audit evidence and providing actual Rego policy code. The authors validate GaC on two enterprise deployments, showing it reproduces manual audit findings—including three penalty‑triggering violations—while reducing audit labor by about 75%.
By Rudrendu Kumar Paul, Sourav Nandy
arXiv:2607. 08292v1 Announce Type: cross Abstract: The NIS-2 Directive increases the need for continuous, auditable compliance evidence and motivates a shift from document-based compliance toward machine-readable compliance artifacts.
By Lea Roxanne Muth, Marian Margraf
Privacy policies may contain internal contradictions in which commitments are undermined by practices documented elsewhere in the same policy. We operationalize this phenomenon, privacy washing, throu...
Code-as-Auditor is an LLM-based framework that transforms regulatory information into formal checklists and executable decision trees, encoding rules as interpretable code. During inference, the model expands each checklist item into factual and counterfactual questions, guiding reasoning over case-specific evidence and potential violations. This pipeline moves from evidence identification to rule application and final decision-making, with a self‑verification loop that enhances logical consistency and traceability, leading to more accurate and evidence‑backed compliance evaluations in privacy and data protection scenarios.
By Jisoo Kim, Taeyoon Kwack, Jinwoo Jang, Woo Kyung Kim, Honguk Woo
The paper argues that AI governance should rely on ISO-like interoperability protocols rather than solely on jurisdiction-specific laws. It proposes standardized AI nutrition labels that include metrics for bias, energy usage, and data provenance to enable machine‑readable risk communication across borders. These protocols aim to reduce regulatory fragmentation, lower barriers for SMEs, and build public trust while allowing modular evolution with technology.
By Azmine Toushik Wasi, Mst Rafia Islam, Mahfuz Ahmed Anik, Taki Hasan Rafi, Md Manjurul Ahsan, Dong-Kyu Chae
The paper introduces GROUND, a framework that limits large language model (LLM) analytics to a governed semantic layer for enterprise data warehouses. GROUND supplies approved metrics, dimensions, join paths, filters, and security rules, then validates generated SQL against these constraints before execution, retrying or abstaining on violations. In benchmarks, GROUND eliminates hallucinations across all evaluated categories and prevents row‑level security breaches, outperforming schema‑only, schema‑RAG, and semantic‑only approaches.
By Aravind Sasidharan Pillai
arXiv:2604. 22789v2 Announce Type: replace-cross Abstract: Organizations deploying AI-enabled Intelligent Transportation Systems face fragmented governance: ISO/IEC~42001 demands a certifiable management system, the EU AI Act imposes binding high-risk obligations from August~2026, and the NIST AI Risk Management Framework structures voluntary practice.
By Talal Ashraf Butt, Muhammad Iqbal, Razi Iqbal
The study introduces a four‑stage pipeline to detect internal contradictions—termed privacy washing—in privacy policies. Applied to two corpora (123 policies from 2026 and 115 from 2015), the pipeline identifies contradictions in 12.2% of the newer policies and 36.5% of the older ones, with third‑party sharing conflicts being the most common. A stability re‑run confirms similar prevalence rates and shows that the majority of contradictions are consistent across different model configurations.
By Thomas Brackin