Score
Design and produce precise, actionable compliance text—such as policy provisions, contractual clauses, privacy notices, consent statements, and internal control descriptions—that translates legal or regulatory requirements into clear organizational obligations and procedures. Ensure the language is accurate, unambiguous, traceable to the underlying requirement or standard, and framed for enforceability and implementation within governance and risk controls.
This work addresses the error-prone and labor-intensive process of manually translating regulatory texts such as the GDPR and the EU AI Act into actionable software requirements. The authors propose Reg2Req, the first end-to-end automated pipeline that leverages natural language processing to identify regulatory provisions, generate system-agnostic software requirements accompanied by plain-language explanations, and establish traceability links. The approach supports requirement classification, use case seed generation, and cross-reference analysis, achieving macro-averaged F1 scores of 0.82 on the GDPR and 0.78 on the EU AI Act. A user study demonstrates that the generated plain-language explanations significantly enhance users’ comprehension and confidence in taking compliance actions (p < 0.001), with all participants expressing willingness to adopt the output as a starting point for compliance efforts.
To address challenges in legal compliance checking—including high subjectivity in regulatory interpretation, dynamic evolution of legislation, and difficulties in cross-disciplinary collaboration—this paper introduces eFLINT, a domain-specific language for computable modeling and automated verification of legal rules, regulatory requirements, and contractual clauses. eFLINT integrates declarative and procedural paradigms, explicitly linking legal concepts to executable computational logic. It combines formal specification, context-aware reasoning, and scenario-based modeling to enable dynamic, end-to-end compliance verification across system design, runtime, and post-execution phases. Designed to balance expressiveness and executability, eFLINT reconciles conflicting requirements through principled language design. Drawing on multi-scenario industrial deployments, the paper distills actionable design principles and a methodology for automation-oriented compliance languages. It contributes both a reusable technical framework and theoretical foundations for computable regulation research in legal technology.
To address the inefficiency and error-proneness of manual regulatory compliance checking, this paper proposes an OWL DL formalization method for natural language specifications. The method introduces a novel structured text annotation scheme and employs a rule-driven deterministic transformation algorithm to automatically map specification texts to OWL DL ontologies. It further integrates Protégé with the HermiT reasoner to enable machine-readable semantic representation and automated compliance verification. A proof-of-concept evaluation in the construction domain demonstrates successful translation of multiple natural language regulations into OWL DL ontologies and accurate identification of compliant and non-compliant scenarios. This work bridges a critical gap between regulatory semantic modeling and automated reasoning, delivering a scalable, methodology-driven foundation for automating compliance checking.
This study addresses the absence of concrete mapping mechanisms for implementing the EU AI Act within agile teams. Employing a Design Science Research methodology, this work proposes a novel framework that translates abstract regulatory requirements into actionable agile compliance guidelines. Through a traffic light taxonomy and expert interviews, an action catalog comprising twelve practices covering roles and risk management was constructed. The results demonstrate that these guidelines are both comprehensible and relevant, establishing that compliance should be integrated into existing agile activities rather than treated as a parallel process. Ultimately, this research bridges the gap in regulatory operationalization, providing a reusable methodological foundation that enables agile teams to achieve compliance without compromising iterative efficiency.
Privacy laws designate “consent” as a lawful basis for data processing, yet its translation into software implementations has long suffered from a legal–technical gap and opaque development practices. This paper proposes the first LLM-based, three-step automated framework: (1) legal clause parsing, (2) use-case compliance classification, and (3) technical requirement reconstruction—augmented by human-in-the-loop verification to ensure legal alignment. It establishes the first systematic, end-to-end mapping from privacy regulation text to executable technical specifications, enabling compliance-aware requirements engineering and use-case remediation. Empirical evaluation demonstrates that the LLM effectively identifies and rectifies non-compliant use cases, validating its feasibility for automated compliance tasks; it also reveals persistent limitations in complex legal reasoning. The work introduces a novel paradigm and practical pathway for AI-augmented legal technologization.
本文提出一种模型,通过设计科学研究方法解决在软件工程中选择大型语言模型时面临的治理与合规难题,采用多层结构和评估协议以增强决策过程中的合规性。
本文针对欧盟AI法案在生成式AI系统中的技术缺口,提出了一种名为Governance-as-Code的框架,通过CI/CD管道实现自动化合规检查。
This study addresses the persistent challenge of operationalizing AI governance requirements within software development practice, particularly at the team level. Through an embedded action research approach in an AI startup, the authors construct a translational pipeline that bridges regulatory texts and concrete engineering actions. They propose a governance implementation framework grounded in practitioners’ cognitive orientations—convergence, alignment with existing practices, and disengagement—to shift governance responsibility from externally imposed mandates toward collective team accountability. By integrating legal text analysis, cross-functional collaboration, and collective assessment, the project surfaces developers’ authentic attitudes toward regulation, identifies compliance priorities anchored in user and developer needs, and renders implicit governance work explicit and institutionalized.
This study addresses the high complexity and labor-intensive challenges of accurately translating privacy regulations such as Brazil’s General Data Protection Law (LGPD) into actionable software requirements. It presents the first systematic exploration of leveraging large language models (LLMs) for generating LGPD-compliant requirements, proposing an automated approach that integrates legal text analysis with requirements engineering to directly map statutory provisions into user stories and acceptance test scenarios. Experimental results demonstrate that the method efficiently produces high-quality, executable compliance requirements, significantly supporting regulatory adherence during early-stage software development. This work thus offers an innovative and practical technical pathway for privacy regulation–driven requirements engineering.
This study addresses the challenges of interpreting legal texts, the lack of evidential support in compliance determination, and the reliance on fixed templates by proposing the first fully open-source, end-to-end intelligent agent system for regulatory compliance. Built upon a large language model-driven agent architecture, the system atomizes regulations into traceable requirements, integrates information retrieval with evidence chain reasoning to assess document compliance, and generates audit-grade interpretable reports. A core contribution is its regulation-agnostic decoupled design, which supports structured regulations of arbitrary scale. Experimental results demonstrate that the system achieves a decision consistency of 96.67% in GDPR policy evaluation and a violation detection accuracy of 98.8% on an EU public procurement benchmark.