Source Registry

Sources we are allowed to cite

Claim ledger →

9 verified sources. A claim may only say what a source's verified scope supports, and must keep its caveats. Sources are rechecked every 180 days — an internal EvidentraIQ review cadence, not a regulatory deadline.

Why source type matters

  • Law tells you what the legal text says.
  • Official guidance explains application and interpretation.
  • Frameworks are voluntary unless separately incorporated into a binding requirement.
  • Research and statistics provide evidence, not legal obligations.
  • Internal evidence proves a customer's own posture, not external facts.
Recheck view (display only):
RESInternational Institution ResearchPrimary/AuthoritativeverifiedRecheck due 2027-03-30SRC-OECD-D4SME-2026

Empowering SMEs in the age of AI: The 2026 OECD D4SME Survey

OECD

Verified scope: Survey of a non-representative sample of more than 2,000 SMEs in 12 OECD countries. Reports rapid SME AI adoption, uneven strategic and secure integration, and continuing constraints including time, maintenance costs and skills gaps.

  • Non-representative sample: findings must not be generalised to all OECD SMEs.
  • Covers 12 OECD countries only.
Published / released
2026-04-13
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
Survey report — not an official statistics publication
Authority note
Authoritative for its own survey findings only
DOI / reference
10.1787/bf5a9816-en
GUIDEOfficial GuidancePrimary/AuthoritativeverifiedRecheck due 2027-03-30SRC-ENISA-SME-CRMAM-2026

SME Cyber Resilience Maturity Assessment Model

European Union Agency for Cybersecurity (ENISA)

Verified scope: A structured approach for micro, small and medium-sized enterprises to evaluate and strengthen cyber resilience, taking Cyber Resilience Act (CRA) requirements into account.

  • ENISA states the model is primarily intended for organisations manufacturing or placing products with digital elements on the market, though other organisations in the product lifecycle can also use it.
  • Not a universal SME compliance framework.
Published / released
2026-07-13
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
—
Authority note
—
DOI / reference
—
GUIDEOfficial GuidancePrimary/AuthoritativeverifiedRecheck due 2027-03-30SRC-ENISA-SME-CRA-SURVEY-2026

SME CRA Survey Report

European Union Agency for Cybersecurity (ENISA)

Verified scope: Survey conducted February–March 2026 to understand SME familiarity with the CRA, practical understanding, cybersecurity practices and expected compliance challenges.

  • Findings describe the surveyed SMEs; no statistics from it are included in this registry yet.
Published / released
2026-06-24
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
Survey report
Authority note
Authoritative for its own survey only
DOI / reference
—
STDStandard/FrameworkRecognised FrameworkverifiedRecheck due 2027-03-30Under revisionSRC-NIST-AI-RMF-1.0

AI Risk Management Framework (AI RMF) 1.0

National Institute of Standards and Technology (NIST)

Verified scope: Voluntary framework intended to help organisations manage AI risks and incorporate trustworthiness considerations.

  • Voluntary; following it is not certification or legal compliance.
Published / released
2023-01-26
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
—
Authority note
—
DOI / reference
—

Under revision — NIST states AI RMF 1.0 is being revised. Recheck when a revision is published.

STDStandard/FrameworkRecognised FrameworkverifiedRecheck due 2027-03-30SRC-NIST-AI-600-1

Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)

National Institute of Standards and Technology (NIST)

Verified scope: Companion profile to help organisations identify and manage risks posed by generative AI.

  • Does not certify anything; using it is not a compliance claim.
Published / released
2024-07-26
Updated
2026-04-08
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
—
Authority note
—
DOI / reference
10.6028/NIST.AI.600-1
GUIDEOfficial GuidancePrimary/AuthoritativeverifiedRecheck due 2027-03-30SRC-EC-AI-LITERACY

AI talent, skills and literacy

European Commission

Verified scope: The Commission page states Article 4 of the AI Act applies to providers and deployers and requires measures to support the AI literacy of staff and other persons operating or using AI systems on their behalf, while not prescribing a specific literacy level for every individual.

  • This is Commission guidance describing the law, not the legal text itself. For legal wording use SRC-EU-AIACT.
  • Do not extrapolate beyond the Commission's wording.
Published / released
Not stated on source
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
Commission policy page describing the AI Act
Authority note
—
DOI / reference
—
LAWLaw/RegulationPrimary/AuthoritativeverifiedRecheck due 2027-03-30Under revisionSRC-EU-AIACT

Regulation (EU) 2024/1689 (Artificial Intelligence Act)

European Parliament and Council of the European Union

Verified scope: Article 4 (consolidated text): providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their knowledge, experience, education and training and the context. The consolidated wording also states the obligation does not require guaranteeing a specific level of AI literacy for any individual.

  • Verified scope covers Article 4 only. Other provisions are not yet verified in this registry.
  • Do not extrapolate beyond the text.
Published / released
2024-07-12
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official consolidated EUR-Lex text verified 2026-10-01
Source type detail
Primary EU law — consolidated text
Authority note
—
DOI / reference
—

Regulation (EU) 2024/1689 of 13 June 2024, published in the Official Journal (OJ L) on 12 July 2024.

Base regulation (OJ L, 2024/1689)

Use the consolidated text for current wording; keep the base regulation reference for provenance.

GUIDEOfficial GuidancePrimary/AuthoritativeverifiedRecheck due 2027-03-30SRC-EC-ART50-GUIDELINES

Guidelines on transparency obligations for providers and deployers of AI systems

European Commission

Verified scope: Guidance on the Article 50 AI Act transparency obligations; the obligations apply from 2026-08-02.

  • Guidance explains application; it is not the legal text.
Published / released
2026-07-20
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
Commission guidance — not law
Authority note
Authoritative for Commission guidance only
DOI / reference
—
GUIDEOfficial GuidancePrimary/AuthoritativeverifiedRecheck due 2027-03-30SRC-EC-ART50-FAQ

Transparency obligations under Article 50 of the AI Act — FAQ

European Commission

Verified scope: Article 50 applies from 2026-08-02. The FAQ describes provider and deployer transparency duties, and a limited grace period until 2026-12-02 for systems placed before 2026-08-02, specifically regarding the Article 50(2) marking/detection obligations.

  • The grace period applies only to Article 50(2) marking/detection obligations for pre-2026-08-02 systems. Do not generalise it.
  • Guidance explains application; it is not the legal text.
Published / released
Not stated on source
Updated
—
Last checked
2026-10-01 (0 days ago)
Reviewer
EvidentraIQ source review
Verification basis
Official source independently re-opened 2026-10-01
Source type detail
Commission FAQ — not law
Authority note
Authoritative for Commission guidance only
DOI / reference
—

Source types

Each type has its own label so law, guidance, frameworks, statistics and internal material are never confused.

LAWLaw/Regulation
Published legislation or regulation text.
GUIDEOfficial Guidance
Guidance issued by a public authority or regulator.
STDStandard/Framework
Recognised standards or frameworks (e.g. ISO, NIST).
STATOfficial Statistics
Official statistics publications from a national or international statistics body.
RESInternational Institution Research
Research or surveys by international institutions (e.g. OECD). Evidence, not official statistics and not law.
PEERPeer-Reviewed Research
Research published after independent peer review.
INDIndustry Evidence
Vendor, analyst or industry body reports.
INTCustomer/Internal Evidence
The organisation's own records: exports, tickets, policies, contracts, supplier agreements.
EIQEvidentraIQ Analysis
Our own derived analysis. Never presented as external fact.

Guidance that describes a law is labelled Official Guidance, never Law/Regulation. Institutional surveys are International Institution Research, not Official Statistics.