CSAEAIIndependent observatory
MANIFESTO
PUBLIC REFERENCE ATLAS

Read the rules. Understand their reach.

CSAEAI studies different kinds of texts to inform AI-systems audit. A law may impose duties; a strategy, standard or recommendation guides analysis without automatically having the same legal force.

A reference shown here is a text under study, not a promise that every requirement is already automated or available in the CSAEAI audit platform. Audit scope is defined case by case.

EUROPE AND FRANCE

Obligations and interpretation

Legal instrument

European Artificial Intelligence Act

AI Act · Regulation (EU) 2024/1689

What the text addressesThe Act addresses prohibited uses, high-risk systems, certain transparency duties and general-purpose AI models.

Who and where it concerns
European Union. Requirements depend on the actor’s role, the system category and the applicable phase-in dates.
Why this reference exists
The AI Act follows a straightforward idea: the greater the potential harm to safety or people’s rights, the stronger the safeguards expected. It does not assess a model only by its performance. The system’s purpose, deployment context and room for human decisions matter too.
What it calls us to examine
For high-risk systems: risk management, data governance, documentation, logging, user information, human oversight, robustness and post-market monitoring.
What changes in practice
The first task is to classify the use and each actor’s role: provider, deployer, importer or another participant. For high-risk systems, the relevant evidence runs from data and testing to logs, instructions for use and incident monitoring. A bare claim of compliance does not explain that chain.

Official document checked in the CSAEAI collection Regulation (EU) 2024/1689, Articles 5, 9–15, 26, 50, 53, 55 and 72.

Read the official source
Legal instrument

Personal data protection

GDPR · Regulation (EU) 2016/679

What the text addressesIt protects people across the data lifecycle: collection, training, deployment and the exercise of rights.

Who and where it concerns
European Union and processing within the GDPR’s territorial scope. It applies when personal data is processed, including in AI development or use.
Why this reference exists
AI may learn from information about people, reveal it in outputs or contribute to decisions affecting them. The GDPR makes clear that technical power does not displace those people’s rights. It governs personal-data processing, not every AI system without distinction.
What it calls us to examine
Define a purpose and lawful basis, minimise data, inform people, secure processing and assess risks to their rights where required.
What changes in practice
A concrete review asks what data enters the system, why it is needed, the lawful basis for using it and how long it is kept. It also asks who has access, how people can exercise their rights and whether a data-protection impact assessment is required. The GDPR and AI Act can apply together; one does not cancel the other.

Official document checked in the CSAEAI collection Regulation (EU) 2016/679, Articles 5, 6, 12–22, 25, 32 and 35.

Read the official source
Authority guidance

CNIL guidance on AI development

France · applying the GDPR to AI development

What the text addressesIt clarifies data-protection questions during design, dataset assembly and model training.

Who and where it concerns
France. Guidance from the data protection authority, read alongside the GDPR; it is not a separate statute.
Why this reference exists
GDPR principles are familiar, but applying them to large datasets or reusable models raises practical questions. CNIL guidance translates those principles into development steps. It does not create a new law or certify that a particular project is lawful.
What it calls us to examine
Justify the purpose, document data and roles, assess the legal basis, plan for notice and rights, and manage re-identification or memorisation risks.
What changes in practice
A review looks at where data came from, what people were told, whether unnecessary data can be excluded and how rights can be exercised. It also examines whether a model can memorise or reveal personal information. This guidance focuses on development; deployment still needs assessment in its own context.

Official document checked in the CSAEAI collection CNIL, ‘AI system development: what should be checked?’, checklist, 2025.

Read the official source
Voluntary tool

General-Purpose AI Code of Practice

European Union · voluntary implementation tool

What the text addressesIts chapters address transparency and copyright; safety and security concern models with systemic risk.

Who and where it concerns
Providers of general-purpose AI models covered by the AI Act. The code is voluntary; the underlying legal duties it helps implement may not be.
Why this reference exists
A general-purpose model may underpin many products that its provider cannot fully foresee. The Code makes AI Act duties more workable for those providers through a voluntary route to documentation and demonstration.
What it calls us to examine
Make provider information and policies reviewable and, where relevant, assess and mitigate systemic risks.
What changes in practice
The transparency and copyright chapters must be distinguished from the safety and security chapter, which concerns models with systemic risk. The useful question is not merely whether a provider signed the Code. It is what information, policies and evaluations actually make its relevant duties reviewable.

Official document checked in the CSAEAI collection General-Purpose AI Code of Practice, Transparency, Copyright and Safety and Security chapters, 2025.

Read the official source
OTHER JURISDICTIONS

Treaties, strategies and local law

Convention

Council of Europe AI Framework Convention

Human rights · democracy · rule of law

What the text addressesIt connects the AI lifecycle with human rights, democracy and the rule of law.

Who and where it concerns
International treaty framework. Its legal effect depends on the Parties and implementation; it is not a direct blanket obligation for every AI system.
Why this reference exists
The Council of Europe Convention asks a broader question than whether a tool performs well: what happens to rights, democracy and the rule of law when decisions rely on AI? Its purpose is to preserve human safeguards even when systems are complex or opaque.
What it calls us to examine
For Parties: establish transparency and accountability, risk and impact assessment, remedies and safeguards suited to the use context.
What changes in practice
It binds Parties according to its terms and their implementation measures; it does not prescribe one procedure for every company worldwide. A system-level reading looks at impacts on people, notice, the ability to challenge a decision and access to a suitable remedy. The treaty’s status must be checked for the territory concerned.

Official document checked in the CSAEAI collection Council of Europe Framework Convention, CETS No. 225, full text published in the EU Official Journal on 13 May 2026, notably Articles 8–16.

Read the official source
Strategy

African Union Continental AI Strategy

Africa · strategy adopted in 2024

What the text addressesIt connects innovation, local capacity, inclusion, cooperation and responsible governance to African priorities.

Who and where it concerns
Continental direction for African Union member states. It is not, by itself, a uniform law applicable in every African country.
Why this reference exists
Africa should not be treated merely as a destination for technology designed elsewhere. The continental strategy argues for the capacity to choose: skills, infrastructure, data, languages and public priorities that can support AI useful to African societies.
What it calls us to examine
Consider rights, inclusion, data, languages, capacity and national context, then check the law applicable in each country.
What changes in practice
A review asks who benefits, who bears the risks and whether the affected languages and populations are represented. The strategy guides public policy and cooperation; enforceable duties for a particular actor must still be found in the relevant country and sector’s law.

Official document checked in the CSAEAI collection African Union Commission, Continental Artificial Intelligence Strategy, July 2024, executive summary and action areas.

Read the official source
Legal instrument

New York City Local Law 144 on automated employment decision tools

United States · hiring and promotion in New York City

What the text addressesThe law governs certain tools that substantially assist or replace human discretion in employment decisions. It does not cover every AI tool used in human resources.

Who and where it concerns
New York City. It concerns employers and employment agencies using a tool within the legal definition to screen job candidates or employees for promotion.
Why this reference exists
When a tool materially shapes candidate screening, a seemingly neutral decision may produce disparities between groups. New York requires a focused check before certain tools are used, but the audit result is not a general finding that discrimination is absent.
What it calls us to examine
Before use: a bias audit by an independent auditor no more than one year old, a public summary of results and advance notice to affected people. The rules specify categories and ratios to calculate.
What changes in practice
First establish whether the tool and employment decision fall within the law. For covered tools, the law and rules require an independent audit, public results and timely notice. The review includes selection or scoring rates and impact ratios, while acknowledging limitations in the available data.

Official document checked in the CSAEAI collection NYC DCWP, ‘Automated Employment Decision Tools’ FAQ, Sections I–VI; Local Law 144 of 2021, §§ 20-870 and 20-871.

Read the official source
Strategy

UK pro-innovation approach to AI regulation

United Kingdom · 2023 government White Paper

What the text addressesIt proposes five cross-sector principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress.

Who and where it concerns
A 2023 UK government policy proposal primarily addressed to sector regulators. The White Paper is not itself a statute imposing five duties on every AI provider.
Why this reference exists
The UK White Paper starts from the premise that AI risks depend on the actual use and sector. It proposes common direction for existing regulators without itself creating a general regime equivalent to the EU AI Act.
What it calls us to examine
Read these principles against the sector and the law actually in force, then check the competent regulator’s measures. The 2024 government response and later developments must be consulted before any present-day conclusion.
What changes in practice
It can frame questions about robustness, explanation, fairness, governance and redress. A UK legal assessment must still start with applicable law and the sector regulator’s guidance; citing the White Paper alone neither establishes a precise duty nor demonstrates an available CSAEAI audit feature.

Official document checked in the CSAEAI collection UK DSIT, A pro-innovation approach to AI regulation, White Paper CP 815, March 2023, Sections 3.2 and 3.3.

Read the official source
INTERNATIONAL REFERENCES

Analytical anchors, not universal laws

Voluntary tool

NIST AI Risk Management Framework

United States · AI RMF 1.0

What the text addressesIt organises continuous risk management through four functions: Govern, Map, Measure and Manage.

Who and where it concerns
Voluntary US framework that can be used internationally. It does not replace the law of the relevant jurisdiction.
Why this reference exists
NIST AI RMF addresses a management problem: a risk is not controlled merely because it was entered once in a register. It must be understood in context, measured with stated limits, assigned to responsible people and revisited throughout the system’s life.
What it calls us to examine
Connect responsibilities, use context, measurement and risk-treatment decisions to documented, reviewable evidence.
What changes in practice
Govern, Map, Measure and Manage give technical, business, legal and leadership teams a shared language. An audit can examine whether uses and affected people are identified, measures are relevant and residual risks lead to decisions that are followed up. This voluntary framework does not replace applicable regulation.

Official document checked in the CSAEAI collection NIST AI 100-1, AI RMF 1.0, January 2023, Section 5 (Govern, Map, Measure, Manage).

Read the official source
Voluntary tool

NIST Generative AI Profile

United States · NIST AI 600-1 · 2024

What the text addressesIt describes risks specific to or amplified by generative AI, including confidently presented false outputs, privacy, harmful bias, security and information integrity.

Who and where it concerns
A voluntary profile supplementing the NIST AI RMF for generative-AI actors; it is neither a general US statute nor a certification.
Why this reference exists
A generative system can produce persuasive but false answers, disclose sensitive information or amplify misleading content. The NIST profile makes these risks more visible within the general risk-management framework.
What it calls us to examine
Connect relevant risks to the use context and AI RMF actions, without assuming that every risk or action applies equally to every system.
What changes in practice
Start with risks that are genuinely plausible for the model and its use, then identify observable evidence for managing them. The profile guides analysis and prioritisation; a list of risks is not automatic evidence of safety.

Official document checked in the CSAEAI collection NIST AI 600-1, Generative Artificial Intelligence Profile, July 2024, Sections 2 and 3.

Read the official source
Standard

ISO/IEC 42001:2023

International standard · AI management system

What the text addressesIt specifies an AI management system to establish, maintain and continually improve.

Who and where it concerns
International standard for organisations developing, providing or using AI. Adopting it, or obtaining certification, is distinct from legal compliance.
Why this reference exists
ISO/IEC 42001 is primarily about the organisation developing or using AI. Responsible governance cannot depend on a few people’s good intentions alone; it requires assigned responsibilities, processes and continual improvement.
What it calls us to examine
Define responsibilities, policies, objectives, risk and impact assessment, controls and recurring organisational review.
What changes in practice
A review looks at the management system’s scope, objectives, roles, assessment of risks and impacts, controls and recurring review. Any certification has a defined scope. By itself, it does not prove that a particular product satisfies every law or has no risk.

Official document checked in the CSAEAI collection ISO/IEC 42001:2023, Clauses 4–10 and Annex A.

Read the official source
Principles

OECD AI Principles

Adopted in 2019 · updated in 2024

What the text addressesThe Recommendation sets out five values-based principles: inclusive growth, sustainable development and well-being; human rights and democratic values, including fairness and privacy; transparency and explainability; robustness, security and safety; and accountability. It separately offers five recommendations to policymakers.

Who and where it concerns
International policy and responsible-conduct principles; they do not themselves create CSAEAI certification or identical duties in every country.
Why this reference exists
The OECD Principles offer a shared language for judging whether AI benefits people and remains trustworthy. They bring together concerns often treated separately: rights, fairness, transparency, safety and accountability.
What it calls us to examine
Examine benefits and risks for people, whether outputs can be understood, system resilience and actors’ ability to account for their decisions.
What changes in practice
They prompt concrete questions: does a person know AI is involved? Can they understand material factors, seek an explanation and challenge an outcome? Who watches the system when its use changes? These are principles and recommendations; precise legal duties come from the rules of each jurisdiction.

Official document checked in the CSAEAI collection OECD, C/MIN(2024)16/FINAL, revised Recommendation of 3 May 2024, Section 1.

Read the official source
Principles

UNESCO Recommendation on the Ethics of AI

International recommendation · 2021

What the text addressesIt connects AI ethics to human rights, diversity, the environment, education and inequality.

Who and where it concerns
Guidance adopted by UNESCO member states. It informs public action and is not the same as directly applicable national law.
Why this reference exists
UNESCO asks us to look beyond the product or company deploying AI. A system may work technically while deepening exclusion, overlooking a language or shifting costs onto people and ecosystems that are less visible.
What it calls us to examine
Assess ethical and social impacts, inclusion, data governance and follow-up measures in the real use context.
What changes in practice
The Recommendation encourages ethical impact assessment and policies attentive to equality, data, the environment, education and social conditions. In an audit, that means identifying affected groups, hearing their needs and following effects over time. It guides states; it is not a universal legal licence imposed directly on every system.

Official document checked in the CSAEAI collection UNESCO, Recommendation on the Ethics of Artificial Intelligence, adopted 23 November 2021.

Read the official source
CSAEAI / READING BOUNDARIES

Our reading remains contextual. Before any compliance conclusion, the organisation’s role, jurisdiction, current text and system-specific evidence must be established.

Références pour l’audit de l’IA | CSAEAI