Source Registry
Sources we are allowed to cite
Claim ledger →9 verified sources. A claim may only say what a source's verified scope supports, and must keep its caveats. Sources are rechecked every 180 days — an internal EvidentraIQ review cadence, not a regulatory deadline.
Why source type matters
- Law tells you what the legal text says.
- Official guidance explains application and interpretation.
- Frameworks are voluntary unless separately incorporated into a binding requirement.
- Research and statistics provide evidence, not legal obligations.
- Internal evidence proves a customer's own posture, not external facts.
Empowering SMEs in the age of AI: The 2026 OECD D4SME Survey
OECD
Verified scope: Survey of a non-representative sample of more than 2,000 SMEs in 12 OECD countries. Reports rapid SME AI adoption, uneven strategic and secure integration, and continuing constraints including time, maintenance costs and skills gaps.
- Non-representative sample: findings must not be generalised to all OECD SMEs.
- Covers 12 OECD countries only.
- Published / released
- 2026-04-13
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- Survey report — not an official statistics publication
- Authority note
- Authoritative for its own survey findings only
- URL
- Open source
- DOI / reference
- 10.1787/bf5a9816-en
SME Cyber Resilience Maturity Assessment Model
European Union Agency for Cybersecurity (ENISA)
Verified scope: A structured approach for micro, small and medium-sized enterprises to evaluate and strengthen cyber resilience, taking Cyber Resilience Act (CRA) requirements into account.
- ENISA states the model is primarily intended for organisations manufacturing or placing products with digital elements on the market, though other organisations in the product lifecycle can also use it.
- Not a universal SME compliance framework.
- Published / released
- 2026-07-13
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- —
- Authority note
- —
- URL
- Open source
- DOI / reference
- —
SME CRA Survey Report
European Union Agency for Cybersecurity (ENISA)
Verified scope: Survey conducted February–March 2026 to understand SME familiarity with the CRA, practical understanding, cybersecurity practices and expected compliance challenges.
- Findings describe the surveyed SMEs; no statistics from it are included in this registry yet.
- Published / released
- 2026-06-24
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- Survey report
- Authority note
- Authoritative for its own survey only
- URL
- Open source
- DOI / reference
- —
AI Risk Management Framework (AI RMF) 1.0
National Institute of Standards and Technology (NIST)
Verified scope: Voluntary framework intended to help organisations manage AI risks and incorporate trustworthiness considerations.
- Voluntary; following it is not certification or legal compliance.
- Published / released
- 2023-01-26
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- —
- Authority note
- —
- URL
- Open source
- DOI / reference
- —
Under revision — NIST states AI RMF 1.0 is being revised. Recheck when a revision is published.
Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)
National Institute of Standards and Technology (NIST)
Verified scope: Companion profile to help organisations identify and manage risks posed by generative AI.
- Does not certify anything; using it is not a compliance claim.
- Published / released
- 2024-07-26
- Updated
- 2026-04-08
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- —
- Authority note
- —
- URL
- Open source
- DOI / reference
- 10.6028/NIST.AI.600-1
AI talent, skills and literacy
European Commission
Verified scope: The Commission page states Article 4 of the AI Act applies to providers and deployers and requires measures to support the AI literacy of staff and other persons operating or using AI systems on their behalf, while not prescribing a specific literacy level for every individual.
- This is Commission guidance describing the law, not the legal text itself. For legal wording use SRC-EU-AIACT.
- Do not extrapolate beyond the Commission's wording.
- Published / released
- Not stated on source
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- Commission policy page describing the AI Act
- Authority note
- —
- URL
- Open source
- DOI / reference
- —
Regulation (EU) 2024/1689 (Artificial Intelligence Act)
European Parliament and Council of the European Union
Verified scope: Article 4 (consolidated text): providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their knowledge, experience, education and training and the context. The consolidated wording also states the obligation does not require guaranteeing a specific level of AI literacy for any individual.
- Verified scope covers Article 4 only. Other provisions are not yet verified in this registry.
- Do not extrapolate beyond the text.
- Published / released
- 2024-07-12
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official consolidated EUR-Lex text verified 2026-10-01
- Source type detail
- Primary EU law — consolidated text
- Authority note
- —
- URL
- Open source
- DOI / reference
- —
Regulation (EU) 2024/1689 of 13 June 2024, published in the Official Journal (OJ L) on 12 July 2024.
Base regulation (OJ L, 2024/1689)
Use the consolidated text for current wording; keep the base regulation reference for provenance.
Guidelines on transparency obligations for providers and deployers of AI systems
European Commission
Verified scope: Guidance on the Article 50 AI Act transparency obligations; the obligations apply from 2026-08-02.
- Guidance explains application; it is not the legal text.
- Published / released
- 2026-07-20
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- Commission guidance — not law
- Authority note
- Authoritative for Commission guidance only
- URL
- Open source
- DOI / reference
- —
Transparency obligations under Article 50 of the AI Act — FAQ
European Commission
Verified scope: Article 50 applies from 2026-08-02. The FAQ describes provider and deployer transparency duties, and a limited grace period until 2026-12-02 for systems placed before 2026-08-02, specifically regarding the Article 50(2) marking/detection obligations.
- The grace period applies only to Article 50(2) marking/detection obligations for pre-2026-08-02 systems. Do not generalise it.
- Guidance explains application; it is not the legal text.
- Published / released
- Not stated on source
- Updated
- —
- Last checked
- 2026-10-01 (0 days ago)
- Reviewer
- EvidentraIQ source review
- Verification basis
- Official source independently re-opened 2026-10-01
- Source type detail
- Commission FAQ — not law
- Authority note
- Authoritative for Commission guidance only
- URL
- Open source
- DOI / reference
- —
Source types
Each type has its own label so law, guidance, frameworks, statistics and internal material are never confused.
- LAWLaw/Regulation
- Published legislation or regulation text.
- GUIDEOfficial Guidance
- Guidance issued by a public authority or regulator.
- STDStandard/Framework
- Recognised standards or frameworks (e.g. ISO, NIST).
- STATOfficial Statistics
- Official statistics publications from a national or international statistics body.
- RESInternational Institution Research
- Research or surveys by international institutions (e.g. OECD). Evidence, not official statistics and not law.
- PEERPeer-Reviewed Research
- Research published after independent peer review.
- INDIndustry Evidence
- Vendor, analyst or industry body reports.
- INTCustomer/Internal Evidence
- The organisation's own records: exports, tickets, policies, contracts, supplier agreements.
- EIQEvidentraIQ Analysis
- Our own derived analysis. Never presented as external fact.
Guidance that describes a law is labelled Official Guidance, never Law/Regulation. Institutional surveys are International Institution Research, not Official Statistics.