arXiv AI

From Regulation to Requirements: An Automated Requirement Derivation and Explanation Pipeline

arXiv:2607. 04448v1 Announce Type: cross Abstract: Ensuring software compliance with regulations such as the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (EU AI Act) poses a significant challenge, as requirements engineers must translate complex legal text into actionable software requirements - a process that remains largely manual and error-prone in practice.

arXiv AI
Sep 18

Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

The paper introduces Governance-as-Code (GaC), a framework that translates the EU AI Act’s technical requirements into 43 machine‑checkable acceptance criteria across six compliance modules. GaC runs within a CI/CD pipeline, producing Article‑indexed audit evidence and providing actual Rego policy code. The authors validate GaC on two enterprise deployments, showing it reproduces manual audit findings—including three penalty‑triggering violations—while reducing audit labor by about 75%.

By Rudrendu Kumar Paul, Sourav Nandy
arXiv AI
Sep 1

Operationalising AI Regulatory Sandboxes: Activities, Requirements, and Technical Assessment under the EU AI Act

The paper "Operationalising AI Regulatory Sandboxes: Activities, Requirements, and Technical Assessment under the EU AI Act" outlines a detailed framework for implementing AI Regulatory Sandboxes (AIRS) under the EU AI Act. It maps the sandbox lifecycle into 29 activities, distinguishes between a Core AIRS and an Extended AIRS that includes an AI Technical Sandbox (AITS), and derives 15 infrastructural and governance requirements linked to these activities and provider obligations. The authors also introduce the Sandbox Configurator, an open‑source tool to instantiate AITS environments, aiming to provide structured workflows for regulators, robust evaluation methods for experts, and a transparent compliance pathway for AI providers.

By Alessio Buscemi, Thibault Simonetto, Daniele Pagani, German Castignani, Maxime Cordy, Jordi Cabot
arXiv AI
Sep 18

Code-as-Auditor: Executable Compliance Reasoning via Regulation-to-Code

Code-as-Auditor is an LLM-based framework that transforms regulatory information into formal checklists and executable decision trees, encoding rules as interpretable code. During inference, the model expands each checklist item into factual and counterfactual questions, guiding reasoning over case-specific evidence and potential violations. This pipeline moves from evidence identification to rule application and final decision-making, with a self‑verification loop that enhances logical consistency and traceability, leading to more accurate and evidence‑backed compliance evaluations in privacy and data protection scenarios.

By Jisoo Kim, Taeyoon Kwack, Jinwoo Jang, Woo Kyung Kim, Honguk Woo
Hugging Face Trending Papers
5d ago

A decision-support system applied to Law: Reasoning and explainability of the decision

The paper presents a decision‑support framework for Law Enforcement Agencies that formalises EU regulations such as the Law Enforcement Directive and uses symbolic AI with SPARQL to reason over legal rules. It includes an algorithm that generates justifications for its conclusions and a decision‑tree method to identify additional information needed when reasoning is inconclusive. The framework emphasizes explainability to build user confidence in automated legal decisions.

arXiv AI
Aug 24

From Regulation to Implementation: A Critical Evaluation of LLM-Assisted Regulatory Compliance in Industry

The paper examines how large language models (LLMs) can assist in creating regulatory compliance artifacts for EU sustainability and privacy laws, specifically Digital Product Passports (DPPs) under the Ecodesign for Sustainable Products Regulation and Data Protection Impact Assessments (DPIAs) under the General Data Protection Regulation. It investigates the effects of data extraction instructions and regulatory ambiguity on the quality and consistency of LLM-generated artifacts, benchmarking various models against manually crafted ground‑truth schemas. Findings indicate that looser guidelines, like those for DPIAs, demand more extensive prompts to achieve consistency, whereas stricter formatting rules for DPPs yield consistent outputs but may introduce hallucinations.

By Adriana Watson, Marco B\"ucheler, Grant Richards
arXiv AI
Jun 11

Rule Taxonomy and Evolution in AI IDEs: A Mining and Survey Study

arXiv:2606. 12231v1 Announce Type: cross Abstract: The adoption of AI-powered Integrated Development Environments (AI IDEs) has introduced "Rules" as a novel software artifact, allowing developers to persistently inject project-specific constraints and architectural guidelines into the context of Large Language Models (LLMs).

By Guangzong Cai, Ruiyin Li, Peng Liang, Zengyang Li, Mojtaba Shahin
arXiv Computation and Language
Aug 25

Grounded Normative Rule Generation with Structured Search

The paper introduces Grounded Normative Rule Generation (GNRS) and a new framework called GNRS-Search that uses Markov Chain Monte Carlo sampling to optimize a discrete And-Or Graph for rule synthesis. By separating operational feasibility from prose generation, the method localizes rule failures before final text creation. Evaluations on GNRS-Bench and RealCharter-Bench show significant improvements in rubric quality and executable metrics, demonstrating that the gains come from robust operational logic rather than stylistic tuning.

By Fanqi Kong, Huaxiao Yin, Ruijie Zhang, Xiaoyuan Zhang, Yizhe Huang, Jian Gao, Shuo Chen, Song-Chun Zhu
arXiv AI
Jun 9

From Statute to Control Flow: Span-Grounded Deontic Trees for Defeasible Scope Parsing

arXiv:2606. 08932v1 Announce Type: cross Abstract: Rule-following agents tasked with executing policies and regulations often fail via Silent Scope Omission (SSO): a model applies a general rule but silently drops nested exceptions or counter-exceptions, producing outputs that appear compliant yet break on important edge cases.

By Jian Chen, Siyuan Li, Chucheng Wan, Zixuan Yuan
arXiv AI
2d ago

The AI Assessment Sandbox Configurator: A Framework to Support Technical Assessment in AI Regulatory Sandboxes

The paper introduces the AI Assessment Sandbox Configurator, an open‑source framework designed to support technical assessment in AI Regulatory Sandboxes (AIRS) mandated by the EU Artificial Intelligence Act. It outlines 11 architectural and governance requirements for infrastructure that enables large‑scale, structured technical testing, and presents a catalogue of tests, a shared data model, dashboards, and reporting tools that harmonise heterogeneous outputs. An early‑stage pilot demonstrated the framework’s harmonisation and reporting capabilities within a live AIRS engagement, contributing to an official Exit Report.

By Alessio Buscemi, German Castignani, Daniele Pagani, Maxime Cordy, Jordi Cabot