Evidence and references
Primary-source register
Last checked: 21 August 2026. Source status can change. Open the primary source and verify its current version before making a decision.
The playbook summarizes and links these resources. It does not reproduce the protected text of standards.
Governance, lifecycle, and risk
- ISO/IEC 42001:2023, AI management systems, published management-system standard.
- ISO/IEC 5338:2023, AI system life cycle processes, published lifecycle standard.
- ISO/IEC 23894:2023, guidance on AI risk management, published risk-management guidance.
- ISO/IEC JTC 1/SC 42 catalogue, including the 5259 data-quality series and 2026 work items.
- NIST AI Risk Management Framework, voluntary AI RMF 1.0; revision work was in progress on 18 August 2026.
- NIST AI 600-1, Generative AI Profile, cross-sector profile published in 2024.
- OECD Framework for the Classification of AI Systems, an orientation framework, not a legal classification.
Security
- OWASP Top 10 for LLM and GenAI, currently published 2025 edition.
- OWASP Top 10 for Agentic Applications 2026, community guidance to adapt to the actual architecture.
- NIST AI 100-2e2025, Adversarial Machine Learning, predictive and generative AI taxonomy; check the official errata.
- NIST AI 100-4, Reducing Risks Posed by Synthetic Content, methods and limitations for detection, authentication, marking, and provenance.
- C2PA 2.4, Content Credentials, a provenance specification that alone proves neither authenticity nor legal compliance.
- MITRE ATLAS, a living knowledge base of AI tactics, techniques, mitigations, and cases.
Law and public policy
Switzerland
- FDPIC, AI and data protection, confirming that the FADP applies to AI-supported processing.
- FDPIC, duty to provide information, including rights related to automated individual decisions under Article 21 FADP, subject to qualification and exceptions.
- FDPIC, joint statement on AI-generated imagery, orientation from 61 authorities, not a substitute for case analysis.
- FDPIC, data protection impact assessment, required when processing is likely to result in high risk.
- FDPIC, outsourcing of data processing, on controller responsibility and processor controls.
- Federal Chancellery, AI regulation, a consultation project expected by the end of 2026, not a general law currently in force.
European Union
- Regulation (EU) 2024/1689, official AI Act text, whose consolidated text and scope must be checked before qualification.
- European Commission, AI Omnibus enters into force, 27 July 2026, including updated high-risk timelines.
- European Commission, transparency guidelines, for Article 50 obligations applicable from 2 August 2026.
- European Commission, Article 50 quick facts, an official summary whose underlying text and exceptions still require qualification.
- European Commission, AI literacy questions and answers, post-Omnibus status of Article 4 and 2026 supervision.
- European Commission, updated AI model contractual clauses, templates to adapt to the procurement and legal context.
Sector extensions
These sources help formulate questions and decision conditions. They do not turn the playbook into medical, legal, prudential, educational, or safety advice.
Healthcare
- Swissmedic, medical-device FAQs.
- Swissmedic, framework conditions for AI in drug development.
- European Commission, MDCG 2025-6 on MDR/IVDR and the AI Act.
- WHO, regulatory considerations on AI for health.
- WHO, governance of large multimodal models for health.
Education, finance, critical infrastructure, and accessibility
- European Commission, 2026 ethical AI and data guidelines for educators.
- FINMA Supervisory Communication 08/2024 on AI governance and risk.
- FINMA Circular 2023/1, operational risks and resilience.
- Regulation (EU) 2022/2554, DORA.
- Directive (EU) 2022/2555, NIS2.
- Directive (EU) 2022/2557, resilience of critical entities.
- W3C, Web Content Accessibility Guidelines 2.2.
- eCH-0059 v3.0, Swiss accessibility standard.
Published cases and field evidence
- Task-time evidence and transfer rules, including evidence grades A to E and the net human-time calculation. French version.
- 2026 public-evidence review, covering studies and deployments by evidence strength, work mode, measured outcome, and transfer limit. French version.
- AI-assisted small-business customer support.
- AI-assisted independent knowledge work.
- Copilot, business agent, and orchestrated agency.
- From copilot to an A2 business agent, a synthetic comparative case.
- A3 orchestrated diagnostic agency, a synthetic manual/A1/A2/A3 comparison.
Repository citation rule
For every claim that can change:
- link the most precise official page;
- state when it was checked;
- distinguish current law, proposal, recommendation, and internal choice;
- never present a consultation, draft, or developing standard as binding law.
The control catalogue also records a version and check date for each source. These links are thematic, not article-by-article equivalences and not evidence of certification or legal compliance.
- Recent cases and transferable mechanisms: sources added on 5 September 2026, with result type and explicit limits.
To print or save as PDF: Ctrl+P (⌘P on Mac).
Source and history · GitHub