Score
Designs and implements mappings and engineering artifacts that translate jurisdiction- or locale-specific regulatory requirements into concrete technical controls, enforcement policies, configuration constraints, and measurable compliance tests. Builds tooling and analyses to verify, monitor, and adapt system behavior so it satisfies those localized regulatory requirements.
Current AI governance policies often rely on compute controls yet lack systematic evaluation of the engineering feasibility of hardware-level mechanisms. This work introduces the first taxonomy encompassing twenty hardware-based governance mechanisms, organized by monitoring, verification, and enforcement functions, and evaluates their technical feasibility across four governance scenarios through a layered adversarial threat model. It innovatively proposes “tamper-evident verifiability” as a more practical security standard in place of absolute tamper-proofing, identifies treaty verification as the scenario requiring the lowest mechanism maturity, and reveals that the window of opportunity created by semiconductor manufacturing concentration is rapidly closing. These insights yield a concrete, verifiable roadmap for international AI governance agreements grounded in near-term technical realizability.
This study addresses the challenges posed by the proliferation, complexity, and expanding scope of regulatory requirements in software engineering, which hinder their systematic integration into development processes. To tackle this issue, the paper proposes a viewpoint-centered, artifact-based approach to regulatory requirements engineering. The approach innovatively integrates viewpoint analysis with artifact modeling to develop the AM4RRE (Artifact Modeling for Regulatory Requirements Engineering) framework, which facilitates cross-functional collaboration and ensures consistency in compliance-driven design. Preliminary validation demonstrates that AM4RRE effectively bridges the gap between organizational regulatory processes and software development practices, enabling a shift from ad hoc compliance responses toward systematic integration. This foundational work paves the way for further empirical investigation into scalable and sustainable regulatory compliance in software engineering.
This work addresses the inefficiency and high cost of compliance testing in highly regulated domains, where current practices rely on manual translation of regulations into test cases by experts. While large language models (LLMs) offer automation potential, they often suffer from hallucination, and existing hybrid approaches still require significant human modeling effort. To overcome these limitations, the authors propose RAFT, a novel framework that explicitly extracts implicit regulatory knowledge from multiple LLMs and leverages an adaptive purification-aggregation strategy with dynamic prompt injection to automatically generate domain-specific meta-models, formalized requirements, and testability constraints—enabling fully automated, human-intervention-free compliance test generation. Experiments in financial, automotive, and power sectors demonstrate that RAFT achieves expert-level performance, significantly outperforming state-of-the-art methods while drastically reducing test case generation and review time.
Large language models (LLMs) lack verifiability and regulatory alignment when generating compliance-critical artifacts in safety-sensitive domains. Method: We propose Constraint-Guided Verifiable Generation (CVG), a framework featuring a Unified Meta-Model (UMM) for harmonizing heterogeneous regulatory texts; an Integrated Constraint Model (ICM) enabling dual-layer validation—structural (via GBNF/DFA) and semantic (via SHACL/SMT); and a synergistic prefix-safe decoding mechanism coupled with runtime automata and post-generation validators to embed auditable, traceable regulatory evidence chains. Contribution/Results: CVG innovatively integrates machine-verifiable certificates and violation-driven audit-and-repair directly into the generation pipeline. Evaluated on AUTOSAR automotive software and cross-border judicial workflows, CVG achieves 100% structural conformance, reduces manual correction effort by 72%, and seamlessly interoperates with existing Model-Driven Engineering (MDE) toolchains—delivering, for the first time, high-assurance, auditable, end-to-end compliant LLM-generated artifacts.
To address the inefficiency and error-proneness of manual regulatory compliance checking, this paper proposes an OWL DL formalization method for natural language specifications. The method introduces a novel structured text annotation scheme and employs a rule-driven deterministic transformation algorithm to automatically map specification texts to OWL DL ontologies. It further integrates Protégé with the HermiT reasoner to enable machine-readable semantic representation and automated compliance verification. A proof-of-concept evaluation in the construction domain demonstrates successful translation of multiple natural language regulations into OWL DL ontologies and accurate identification of compliant and non-compliant scenarios. This work bridges a critical gap between regulatory semantic modeling and automated reasoning, delivering a scalable, methodology-driven foundation for automating compliance checking.
How to balance regulatory flexibility with enforceability in designing governance frameworks adaptable to the rapid evolution of frontier AI—particularly artificial general intelligence (AGI)? Method: We propose a “principles-first, dynamically refined” incremental regulatory pathway: initially mandating high-level safety principles, coupled with robust oversight and capacity-building; subsequently evolving toward concrete, actionable rules as technical maturity increases and risk understanding deepens. Contribution/Results: This work is the first to systematically articulate the continuum between principle-based and rule-based regulation. Integrating regulatory design theory, adaptive risk governance, the evolutionary trajectory of AI safety practices, and cross-jurisdictional coordination modeling, it delivers a comprehensive, empirically grounded roadmap for frontier AI governance—already adopted by multiple national regulatory authorities. The framework fosters a co-evolutionary safety ecosystem wherein developers and regulators iteratively align on standards, practices, and accountability mechanisms.
This work addresses the error-prone and labor-intensive process of manually translating regulatory texts such as the GDPR and the EU AI Act into actionable software requirements. The authors propose Reg2Req, the first end-to-end automated pipeline that leverages natural language processing to identify regulatory provisions, generate system-agnostic software requirements accompanied by plain-language explanations, and establish traceability links. The approach supports requirement classification, use case seed generation, and cross-reference analysis, achieving macro-averaged F1 scores of 0.82 on the GDPR and 0.78 on the EU AI Act. A user study demonstrates that the generated plain-language explanations significantly enhance users’ comprehension and confidence in taking compliance actions (p < 0.001), with all participants expressing willingness to adopt the output as a starting point for compliance efforts.
This study addresses the limitations of existing automated tools for building code compliance verification, which suffer from poor generalizability, lack of transparency, and limited scalability due to their reliance on manual comparison between regulatory texts and BIM models. To overcome these challenges, this work proposes a test-driven, deterministically orchestrated multi-agent program synthesis framework that introduces a novel deterministic multi-agent collaboration mechanism to automatically translate regulatory texts into executable, auditable compliance-checking code. The approach integrates hierarchical rule parsing, large language models—including both closed-source APIs and open-source local models—and test-driven development within a multi-tiered data governance evaluation framework. Experimental results demonstrate that the proposed method achieves the highest accuracy across all backbone models, improving average joint accuracy by 82% over baselines; notably, open-source local models attain 97.8% of the performance of state-of-the-art APIs at only one-quarter of the cost.
Current AI systems rely heavily on manual auditing and documentation, which hinders scalable governance for automated services. This work proposes Ontological Knowledge Blocks (OKBs), a novel framework that formalizes regulatory obligations as quintuples comprising ontologies, SHACL rules, evidence requirements, and provenance links. By leveraging RDF/OWL modeling, PROV-O for provenance tracking, and an intermediate representation–driven deterministic compiler, the approach enables dynamic switching of governance configurations without modifying service code. Evaluation in an AI-assisted HPC scheduling scenario demonstrates that compliance checks are configuration-sensitive, violations accumulate strictly additively, SHACL validation incurs only 12.6–100.3 milliseconds of latency, and the Combined configuration provides the most comprehensive coverage.
This study addresses the challenge in regulated industries where existing AI coding systems lack mechanisms to dynamically calibrate human oversight based on regulatory impact, thereby struggling to balance compliance and efficiency. To bridge this gap, the authors propose the GAIE framework, which introduces an innovative three-tier Oversight Classification Model (OCM) that categorizes code-generation tasks according to regulatory impact, customer proximity, reversibility, and data sensitivity, and aligns each category with appropriate supervision levels and compliance evidence requirements. By integrating rule-driven deterministic classification, compliance evidence mapping, and alignment with multi-jurisdictional regulatory standards—including those from the Bank of Thailand, MAS, NIST, ISO/IEC 42001, and the EU AI Act—the framework uniquely links AI development maturity with regulatory governance. Empirical results demonstrate that GAIE maintains 84%–97% (median 91%) of autonomous coding speed while ensuring comprehensive compliance evidence coverage, confirming its efficacy and broad applicability.