Official-source spine · Universal Apex Protected L-9.0 · LC1 · 2026-07-23
Legal and Regulatory Source Register
Dated source spine. These are official or identified design-reference sources verified for this release. Reopen the current official source before binding action.
| ID | Jurisdiction / topic | Authority and source | Operational relevance |
|---|---|---|---|
REF-P4 | Global Design reference | GoalOS — Legal, Rights, and Publication Center | Reference separation of terms, regulatory/no-offer, rights, privacy, security, claims, publication and exclusions. |
EU-AIA | EU/EEA AI law | European Commission — AI Act regulatory framework | Risk-based AI framework, roles, prohibited practices and phased application. |
EU-AIA-T | EU/EEA AI transparency | European Commission — Code of Practice on Transparency of AI-Generated Content | Article 50 transparency implementation. |
EU-GDPR | EU/EEA Privacy | European Union — General Data Protection Regulation | Personal-data roles, principles, rights, transfers and accountability. |
CA-PIPEDA | Canada Privacy | Justice Laws Canada — PIPEDA | Federal private-sector privacy and electronic documents. |
QC-PRIV | Québec Privacy | Légis Québec — Private-sector personal information act | Québec privacy governance, PIA and accountability. |
QC-FRENCH | Québec Language | Légis Québec — Charter of the French language | Language localization and contract requirements. |
CA-COMP | Canada Marketing | Competition Bureau Canada — Misleading representations and deceptive marketing practices | Claim substantiation and non-deception. |
US-CPPA | California Privacy / ADMT | California Privacy Protection Agency — CCPA updates, risk, cyber and ADMT regulations | Risk assessments, cybersecurity audits and automated decision-making controls. |
US-NIST | United States AI risk | NIST — AI Risk Management Framework | Voluntary lifecycle AI risk framework. |
US-NIST-G | United States Generative AI | NIST — Generative AI Profile | Generative-AI risk profile. |
US-OFAC | United States / extraterritorial risk Sanctions | U.S. Treasury OFAC — Framework for OFAC Compliance Commitments | Management commitment, risk assessment, controls, testing and training. |
US-BIS | United States / controlled technology Export controls | Bureau of Industry and Security — Export Compliance Programs | Export classification, authorization, screening and recordkeeping. |
US-FTC | United States Consumer / claims | Federal Trade Commission — AI business guidance and enforcement | Deceptive AI claims, privacy and unfair practices. |
SG-AGENT | Singapore Agentic AI | IMDA — Model AI Governance Framework for Agentic AI | Human accountability, technical safeguards and agent governance. |
UN-BHR | Global Human rights | UN OHCHR — Guiding Principles on Business and Human Rights | Human-rights due diligence and remedy. |
EU-ACCESS | EU Accessibility | European Commission — Web accessibility | Public-sector web accessibility framework. |
REF-P4-LOCAL | Global Preserved legal lineage | GoalOS reference package — Local preserved P-4 Legal, Rights and Publication Center | Locally preserved legal webpage set from the user-supplied v5 archive; reference lineage and compatibility only. |
EU-AIA-50-G | EU/EEA AI transparency | European Commission — Guidelines on transparency obligations for providers and deployers of AI systems | Official Article 50 scope and implementation guidance published 20 July 2026; transparency obligations apply from 2 August 2026. |
SG-AGENT-PDF | Singapore Agentic AI | IMDA — Model AI Governance Framework for Agentic AI — official framework PDF | Official framework for human accountability, technical safeguards and lifecycle governance of agentic AI. |