🤖 AI Summary
Ensuring compliance of AI systems in the legal domain with the EU’s Artificial Intelligence Act (AI Act) poses significant verification challenges due to the gap between legal requirements and technical implementation.
Method: This paper proposes the first verifiable governance framework integrating legal norms and technical controls. It introduces a regulation–technical-control mapping model, designs a forensically aware logging architecture and observability mechanism tailored for RAG/LLM systems, and establishes a multidimensional evaluation metric system weighted by legal risk. We publicly release the open-source auditing tool *rag-forense* and a standardized experimental protocol.
Contribution/Results: The framework enables end-to-end compliance audit trails, automated verification, and evidence generation. Empirical evaluation demonstrates its effectiveness in identifying high-risk non-compliance scenarios and producing auditable, traceable compliance proofs—advancing RegTech for legal AI through a reusable methodology and engineering infrastructure.
📝 Abstract
This paper presents a comprehensive governance framework for AI systems in the legal sector, designed to ensure verifiable compliance with the EU AI Act. The framework integrates a normative mapping of the regulation to technical controls, a forensic architecture for RAG/LLM systems, and an evaluation system with metrics weighted by legal risk. As a primary contribution, we present rag-forense, an open-source implementation of the framework, accompanied by an experimental protocol to demonstrate compliance. -- Este artículo presenta un marco integral de gobernanza para sistemas de IA en el sector legal, diseñado para garantizar el cumplimiento verificable del Reglamento de IA de la UE (AI Act). El marco integra una cartografía normativa de la ley a controles técnicos, una arquitectura forense para sistemas RAG/LLM y un sistema de evaluación con métricas ponderadas por el riesgo jurídico. Como principal contribución, se presenta rag-forense, una implementación de código abierto del marco, acompañada de un protocolo experimental para demostrar la conformidad.