STATUTORY RULES MATRIX // PRODUCTION CATALOG (36 RULES)

Statutory Rules & Governance Catalog

The compiled `.anchor` policy matrix translating EU AI Act Articles 5–99, SEC Rules 15c3-5/Reg SCI, OWASP LLM Top 10, and RBI Model Risk guidelines into machine-enforced AST invariants.

Prohibited PracticeRULE-EU-001
EU AI Act Article 5(1)(a) (Recitals 27, 28, 29 & Annex III)

Article 5(1)(a): Prohibited Manipulative & Subliminal Loops

Intercepts and blocks neuro-symbolic execution loops designed to deploy subliminal techniques or exploit human vulnerabilities.

#RULE-EU-001#European Union#Article 5(1)(a)#Machine Enforceable Gate
Mitigation: BLOCK_COGNITIVE_MANIPULATIONView Full Rule Spec β†’
Prohibited PracticeRULE-EU-002
EU AI Act Article 5(1)(e) (Recitals 30, 31 & Annex III)

Article 5(1)(e): Prohibited Untargeted Facial Image Scraping

Blocks unauthorized compilation of facial recognition databases via un-targeted web scraping or CCTV footage extraction.

#RULE-EU-002#European Union#Article 5(1)(e)#Machine Enforceable Gate
Mitigation: BLOCK_FACIAL_SCRAPINGView Full Rule Spec β†’
Prohibited PracticeRULE-EU-003
EU AI Act Article 5(1)(c) (Recitals 32, 33)

Article 5(1)(c): Prohibited Social Scoring & Behavioral Profiling

Bans systematic evaluation or classification of natural persons based on social behavior leading to detrimental or unfavorable treatment.

#RULE-EU-003#European Union#Article 5(1)(c)#Machine Enforceable Gate
Mitigation: BLOCK_SOCIAL_SCORINGView Full Rule Spec β†’
Statutory ClassificationRULE-EU-004
EU AI Act Article 6 (Recitals 40-55, Annex I & III)

Article 6: Classification Rules for High-Risk AI Systems

Classifies AI systems intended for critical infrastructure, biometric identification, employment, or credit scoring as high-risk subject to strict ex-ante compliance.

#RULE-EU-004#European Union#Article 6#Machine Enforceable Gate
Mitigation: CLASSIFY_HIGH_RISKView Full Rule Spec β†’
Statutory Safety ControlRULE-EU-005
EU AI Act Article 6(1) & Annex I (Recitals 42, 43)

Article 6(1) & Annex I: Integrated Product Safety Component Intercept Gate

Intercepts AI modules serving as safety components in products subject to third-party conformity assessment under Union harmonisation legislation.

#RULE-EU-005#European Union#Article 6(1) & Annex I#Machine Enforceable Gate
Mitigation: SAFETY_COMPONENT_INTERCEPTView Full Rule Spec β†’
Statutory Compliance GateRULE-EU-006
EU AI Act Article 8 (Recital 64)

Article 8: Ex-Ante Mandatory Compliance Gate for High-Risk Requirements

Mandates that high-risk AI systems shall comply with all Section 2 requirements (Articles 9 through 15) taking into account intended purpose and state-of-the-art.

#RULE-EU-006#European Union#Article 8#Machine Enforceable Gate
Mitigation: VERIFY_EX_ANTE_REQUIREMENTSView Full Rule Spec β†’
Statutory Risk ControlRULE-EU-007
EU AI Act Article 9 (Recitals 65, 66 & Annex III)

Article 9: Continuous Risk Management System & Failsafe Controls

Establishes a continuous, iterative risk management system running through the entire lifecycle of high-risk AI systems to eliminate or mitigate known risks.

#RULE-EU-007#European Union#Article 9#Machine Enforceable Gate
Mitigation: FAILSAFE_RISK_MITIGATIONView Full Rule Spec β†’
Statutory Data ControlRULE-EU-008
EU AI Act Article 10 (Recitals 67, 68 & Annex IV Β§2)

Article 10: Training Data Quality, Bias Prevention & Governance

Mandates strict data governance practices for high-risk AI training, validation, and testing datasets, ensuring data completeness and bias prevention.

#RULE-EU-008#European Union#Article 10#Machine Enforceable Gate
Mitigation: BIAS_GATE_HALTView Full Rule Spec β†’
Statutory Compliance ControlRULE-EU-009
EU AI Act Article 11 (Recital 69 & Annex IV)

Article 11: Technical Documentation & Spec Lock Invariants

Requires technical documentation to be drawn up before a high-risk AI system is placed on the market and kept up-to-date.

#RULE-EU-009#European Union#Article 11#Machine Enforceable Gate
Mitigation: ENFORCE_SPEC_LOCKView Full Rule Spec β†’
Statutory Audit ControlRULE-EU-010
EU AI Act Article 12 (Recitals 70, 71)

Article 12: Automated Log Retention & Tamper-Evident Records

Mandates high-risk AI systems to include logging capabilities ensuring traceability of system operation throughout its lifecycle.

#RULE-EU-010#European Union#Article 12#Machine Enforceable Gate
Mitigation: SEAL_COMPLIANCE_LOGView Full Rule Spec β†’
Biometric Audit ControlRULE-EU-011
EU AI Act Article 12(3) (Recitals 71, 72)

Article 12(3): Remote Biometric Identification Log Array & Dual-Person Verification Gate

Forces 2-person verification metadata arrays and automatic start/end timestamp logging on remote biometric identification calls.

#RULE-EU-011#European Union#Article 12(3)#Machine Enforceable Gate
Mitigation: BIOMETRIC_DUAL_VERIFY_LOGView Full Rule Spec β†’
Statutory TransparencyRULE-EU-012
EU AI Act Article 13 (Recitals 72, 73)

Article 13: Deployer Transparency & System Architecture Cards

Requires high-risk AI systems to be designed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret output.

#RULE-EU-012#European Union#Article 13#Machine Enforceable Gate
Mitigation: EMBED_SYSTEM_CARDView Full Rule Spec β†’
Statutory Mandatory ControlRULE-EU-013
EU AI Act Article 14 (Recitals 74, 75 & Annex IV)

Article 14: Human Oversight & Dynamic Kill-Switch Control

Enforces continuous human oversight interfaces allowing human operators to override, interrupt, or halt high-risk AI system execution at any microsecond.

#RULE-EU-013#European Union#Article 14#Machine Enforceable Gate
Mitigation: HUMAN_OVERRIDE_MANDATEView Full Rule Spec β†’
Statutory Security ControlRULE-EU-014
EU AI Act Article 15 (Recitals 76, 77, 78)

Article 15: Accuracy, Robustness & Adversarial Cybersecurity Safeguards

Requires high-risk AI systems to be resilient against prompt injection, data poisoning, and model evasion attacks throughout their lifecycle.

#RULE-EU-014#European Union#Article 15#Machine Enforceable Gate
Mitigation: HARDEN_WASM_SANDBOXView Full Rule Spec β†’
Feedback Loop ProtectionRULE-EU-015
EU AI Act Article 15(4) (Recital 78)

Article 15(4): Feedback Loop Contamination Protection Gate

Prevents un-vetted agent outputs or synthetic generation streams from routing directly back into training or weight-update arrays without intermediate validation.

#RULE-EU-015#European Union#Article 15(4)#Machine Enforceable Gate
Mitigation: BLOCK_UNVETTED_FEEDBACK_LOOPView Full Rule Spec β†’
Statutory Provider MandateRULE-EU-016
EU AI Act Article 16 (Recitals 60-64)

Article 16: Mandatory Obligations of High-Risk AI Providers

Mandates providers to establish quality management systems, draw up technical documentation, and ensure conformity before CE marking.

#RULE-EU-016#European Union#Article 16#Machine Enforceable Gate
Mitigation: ENFORCE_PROVIDER_CE_MARKView Full Rule Spec β†’
Quality Management SystemRULE-EU-017
EU AI Act Article 17 (Recitals 63, 64)

Article 17: Quality Management System & Risk Auditing

Requires providers to maintain a documented quality management system covering design controls, testing, and post-market surveillance.

#RULE-EU-017#European Union#Article 17#Machine Enforceable Gate
Mitigation: QUALITY_SYSTEM_VERIFYView Full Rule Spec β†’
Log Retention ControlRULE-EU-018
EU AI Act Article 19 (Recitals 70, 71)

Article 19: Automatically Generated Log Storage & 6-Month Retention Gate

Requires providers to retain automatically generated logs for at least 6 months under sovereign tamper-evident storage.

#RULE-EU-018#European Union#Article 19#Machine Enforceable Gate
Mitigation: RETENTION_STORE_MANDATEView Full Rule Spec β†’
Deployer Operating MandateRULE-EU-019
EU AI Act Article 26 (Recitals 80-84)

Article 26: Mandatory Obligations of High-Risk AI Deployers

Requires deployers to operate systems strictly per instructions, assign human oversight, and monitor input data relevance.

#RULE-EU-019#European Union#Article 26#Machine Enforceable Gate
Mitigation: DEPLOYER_OPERATIONAL_GATEView Full Rule Spec β†’
Data Representativeness GateRULE-EU-020
EU AI Act Article 26(4) (Recital 82)

Article 26(4): Input Data Representativeness & Context Boundary Gate

Verifies input payload metadata matrix matches Annex IV declared distribution before allowing execution to proceed.

#RULE-EU-020#European Union#Article 26(4)#Machine Enforceable Gate
Mitigation: VERIFY_DATA_REPRESENTATIVENESSView Full Rule Spec β†’
Workplace Compliance FlagRULE-EU-021
EU AI Act Article 26(7) (Recital 84)

Article 26(7): Workplace Tracking Onboarding Clearance Flag

Verifies worker representative notification flag is legally cleared before firing employee evaluation or HR tracking agent scripts.

#RULE-EU-021#European Union#Article 26(7)#Machine Enforceable Gate
Mitigation: CHECK_WORKER_DISCLOSURE_TOKENView Full Rule Spec β†’
Statutory Impact AssessmentRULE-EU-022
EU AI Act Article 27 (Recital 85)

Article 27: Fundamental Rights Impact Assessment (FRIA) Gate

Mandates deployers of high-risk AI in public or financial services to conduct a Fundamental Rights Impact Assessment prior to deployment.

#RULE-EU-022#European Union#Article 27#Machine Enforceable Gate
Mitigation: FRIA_ASSESSMENT_HALTView Full Rule Spec β†’
Transparency ObligationRULE-EU-023
EU AI Act Article 50 (Recital 132)

Article 50: Synthetic Content Marking & Watermarking Obligations

Mandates machine-readable digital watermarking and provenance headers on all AI-generated text, audio, and image outputs.

#RULE-EU-023#European Union#Article 50#Machine Enforceable Gate
Mitigation: INJECT_DIGITAL_WATERMARKView Full Rule Spec β†’
Synthetic Egress GateRULE-EU-024
EU AI Act Article 50(2) (Recital 132)

Article 50(2): Synthetic Media Cryptographic Watermark Egress Gate

Blocks network egress of generated image or audio assets unless a machine-readable C2PA metadata watermark signature is attached.

#RULE-EU-024#European Union#Article 50(2)#Machine Enforceable Gate
Mitigation: ENFORCE_C2PA_WATERMARKView Full Rule Spec β†’
Text Disclosure GateRULE-EU-025
EU AI Act Article 50(4) (Recital 133)

Article 50(4): Public AI Text Generation Disclosure Gate

Monitors streaming text outputs; requires an ai_disclosure_tag or human_reviewer_token before allowing public distribution egress.

#RULE-EU-025#European Union#Article 50(4)#Machine Enforceable Gate
Mitigation: ENFORCE_TEXT_DISCLOSURE_TAGView Full Rule Spec β†’
GPAI Governance ControlRULE-EU-026
EU AI Act Article 53 (Recitals 109-115)

Article 53: General-Purpose AI (GPAI) Model Compliance

Establishes technical documentation, copyright policy compliance, and training data summaries for General-Purpose AI models.

#RULE-EU-026#European Union#Article 53#Machine Enforceable Gate
Mitigation: GPAI_POLICY_GATEView Full Rule Spec β†’
Systemic Risk ControlRULE-EU-027
EU AI Act Article 55 (Recitals 112-118)

Article 55: Systemic Risk GPAI Model High-Assurance Controls

Imposes model evaluation, adversarial testing, systemic risk assessment, and incident tracking on high-impact GPAI models.

#RULE-EU-027#European Union#Article 55#Machine Enforceable Gate
Mitigation: SYSTEMIC_RISK_SHUTDOWNView Full Rule Spec β†’
Post-Market ObservabilityRULE-EU-028
EU AI Act Article 72 (Recital 145)

Article 72: Continuous Post-Market Monitoring System

Requires providers to establish a proactive post-market monitoring system to evaluate real-world system performance and safety.

#RULE-EU-028#European Union#Article 72#Machine Enforceable Gate
Mitigation: POST_MARKET_MONITOR_LOGView Full Rule Spec β†’
Statutory Enforcement PenaltyRULE-EU-029
EU AI Act Article 99 (Recital 167)

Article 99: Statutory Penalties, Fines & Global Turnover Invariants

Enforces zero-compliance-leakage runtime bounds to eliminate exposure to Article 99 turnover fines up to €35,000,000 or 7% of global turnover.

#RULE-EU-029#European Union#Article 99#Machine Enforceable Gate
Mitigation: ZERO_LEAKAGE_CONTAINMENTView Full Rule Spec β†’
Market Access ControlSEC-REG-SCI
17 CFR Β§ 242.1001 (Systems Compliance and Integrity)

SEC Regulation SCI β€” System Capacity Loop Interception

Intercepts unbounded execution loops or unthrottled API call streams within trading pipelines to protect system capacity boundaries from runaway failures.

#SEC-REG-SCI#United States#SEC Regulation SCI β€” System Capacity Loop Interception#Machine Enforceable Gate
Mitigation: LOOP_CIRCUIT_BREAKERView Full Rule Spec β†’
Market Access ControlSEC-RULE-15C3
17 CFR Β§ 240.15c3-5 (Market Access Rule)

SEC Rule 15c3-5 β€” Pre-Trade Financial Limit Risk Control

Enforces mandatory pre-trade credit verification and financial exposure limits, programmatically halting un-gated automated order routing scripts.

#SEC-RULE-15C3#United States#SEC Rule 15c3-5 β€” Pre-Trade Financial Limit Risk Control#Machine Enforceable Gate
Mitigation: LOCKFREE_CAPITAL_ALLOCATORView Full Rule Spec β†’
Fiduciary Conflict ControlSEC-PDA-CONFLICT
SEC Release IA-6353 Conflict of Interest Mandate

SEC Predictive Analytics β€” Fiduciary Conflict Minimization

Prohibits predictive optimization prompts or reward functions from deploying manipulative behavioral nudges that prioritize broker metrics over client value.

#SEC-PDA-CONFLICT#United States#SEC Predictive Analytics β€” Fiduciary Conflict Minimization#Machine Enforceable Gate
Mitigation: CONFLICT_MINIMIZER_GATEView Full Rule Spec β†’
Market Manipulation ControlRULE-SEC-206
Investment Advisers Act Rule 206(4)-1 (Marketing Rule)

SEC Rule 206(4)-1 β€” Anti-Fraud Market Manipulation Gate

Blocks autonomous trading triggers that attempt to initiate market execution orders based entirely on unverified, raw social media web scraping gossip.

#RULE-SEC-206#United States#SEC Rule 206(4)-1 β€” Anti-Fraud Market Manipulation Gate#Machine Enforceable Gate
Mitigation: ANTI_FRAUD_VERIFICATIONView Full Rule Spec β†’
Cybersecurity Incident ControlSEC-FORM-8K
17 CFR Part 229 - Item 1.05 Incident Disclosure

SEC Form 8-K / Reg S-P β€” Cyber Incident Exfiltration Shield

Intercepts and halts outbound agent network streams or log telemetry attempting to export cluster topology configurations or cloud access keys.

#SEC-FORM-8K#United States#SEC Form 8-K / Reg S-P β€” Cyber Incident Exfiltration Shield#Machine Enforceable Gate
Mitigation: INCIDENT_EXFILTRATION_SHIELDView Full Rule Spec β†’
Record Keeping ControlSEC-FINRA-3110
FINRA Rule 4511 / Exchange Act Rule 17a-4 (WORM)

FINRA Rule 3110/4511 β€” Tamper-Evident 6-Year Records Journal

Enforces immutable, Ed25519-signed cryptographic ledger archiving for all model prompts and trading choices to pass statutory inspection baselines.

#SEC-FINRA-3110#United States#FINRA Rule 3110/4511 β€” Tamper-Evident 6-Year Records Journal#Machine Enforceable Gate
Mitigation: TAMPER_EVIDENT_JOURNALView Full Rule Spec β†’
Open Source Security StandardRULE-OWASP-001
OWASP Top 10 for LLM Applications (LLM01:2025)

OWASP LLM-01: Direct & Indirect Prompt Injection Boundary

Intercepts direct user prompt overrides and indirect RAG retrieval payload poisoning before model context window assembly.

#RULE-OWASP-001#Global Security Standard#OWASP LLM-01#Machine Enforceable Gate
Mitigation: SANCTIFY_INPUT_STREAMView Full Rule Spec β†’