arXiv AI By Adriana Watson, Marco B\"ucheler, Grant Richards

From Regulation to Implementation: A Critical Evaluation of LLM-Assisted Regulatory Compliance in Industry

Read the original on arXiv AI →

The paper examines how large language models (LLMs) can assist in creating regulatory compliance artifacts for EU sustainability and privacy laws, specifically Digital Product Passports (DPPs) under the Ecodesign for Sustainable Products Regulation and Data Protection Impact Assessments (DPIAs) under the General Data Protection Regulation. It investigates the effects of data extraction instructions and regulatory ambiguity on the quality and consistency of LLM-generated artifacts, benchmarking various models against manually crafted ground‑truth schemas. Findings indicate that looser guidelines, like those for DPIAs, demand more extensive prompts to achieve consistency, whereas stricter formatting rules for DPPs yield consistent outputs but may introduce hallucinations.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Jul 7

From Regulation to Requirements: An Automated Requirement Derivation and Explanation Pipeline

arXiv:2607. 04448v1 Announce Type: cross Abstract: Ensuring software compliance with regulations such as the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (EU AI Act) poses a significant challenge, as requirements engineers must translate complex legal text into actionable software requirements - a process that remains largely manual and error-prone in practice.

By Pavithra PM Nair, Preethu Rose Anish
Hugging Face Trending Papers
Aug 3

CTRAG: An In-Context Retrieval-based Framework for Automated Compliance Checking using LLMs

Trust is fundamental in modern regulatory ecosystems, and compliance checking plays a critical role in fostering that trust. Regulatory compliance verification is essential for businesses operating in highly controlled environments, as it ensures alignment with sector-specific guidelines across domains such as financial reporting, data privacy, and cybersecurity.

arXiv AI
Jun 9

Trustworthy Smart Fabs via Professional Proxies: Scaling Safe and Sustainable by Design (SSbD) through Industrial Data Spaces

arXiv:2606. 09227v1 Announce Type: cross Abstract: The convergence of the 2026 European Union Safe and Sustainable by Design (SSbD) framework, Corporate Sustainability Due Diligence Directive (CSDDD), and Carbon Border Adjustment Mechanism (CBAM) introduce a severe governance bottleneck for advanced semiconductor manufacturing facilities ("Smart Fabs").

By Han-Teng Liao, Chang-Yi Kao, Karen Ang
arXiv AI
Sep 18

Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

The paper introduces Governance-as-Code (GaC), a framework that translates the EU AI Act’s technical requirements into 43 machine‑checkable acceptance criteria across six compliance modules. GaC runs within a CI/CD pipeline, producing Article‑indexed audit evidence and providing actual Rego policy code. The authors validate GaC on two enterprise deployments, showing it reproduces manual audit findings—including three penalty‑triggering violations—while reducing audit labor by about 75%.

By Rudrendu Kumar Paul, Sourav Nandy