AI Security
Evaluation
Which AI providers red-team their models, maintain threat taxonomies, implement control protocols, and submit to independent security evaluation?
How we score βEvaluating AI vendor security posture for your organisation?
Book a DemoRegulatory Calendar
Upcoming regulatory milestones that affect procurement timing and vendor assessment.
Regulatory Calendar
Key regulatory milestones and policy deadlines shaping the AI governance market.
Links to official regulatory sources. Mappera maps the regulatory landscape for intelligence purposes. This is not legal advice.
Cross-Regulatory Mapping
Active Regulations
Supply Chain Layer
Sector
Theoretical maximum across all applicable regulations if non-compliant simultaneously.
Enforcement Timeline
Key regulatory deadlines. Already enforced (solid), approaching (pulsing), future (dashed).
Full enforcement since 2018
No GDPR enforcement action specifically targeting AI automated decision-making under Art. 22 yet. The right-to-explanation tension remains legally untested for deep learning systems.
Member state transposition deadline passed
NIS2 does not specifically address AI risk. AI systems fall under general ICT risk management. Regulatory interpretation of AI within NIS2 scope is untested.
Financial sector ICT resilience requirements active
DORA applies to ICT risk broadly. AI-specific obligations are implied through general ICT risk management requirements. Practical interpretation for AI systems is evolving.
Prohibited AI practices ban in effect
Zero enforcement actions. The practical meaning of many requirements (especially Art. 9 risk management, Art. 14 human oversight) will only become clear through enforcement and litigation.
General-purpose AI model obligations
Zero enforcement actions. The practical meaning of many requirements (especially Art. 9 risk management, Art. 14 human oversight) will only become clear through enforcement and litigation.
High-risk AI system obligations β the major compliance deadline
Zero enforcement actions. The practical meaning of many requirements (especially Art. 9 risk management, Art. 14 human oversight) will only become clear through enforcement and litigation.
Product cybersecurity requirements for digital elements
AI products fall under scope as 'products with digital elements'. Specific AI requirements within CRA are minimal - primarily vulnerability handling.
Mappera maps the regulatory landscape for intelligence purposes. This is not legal advice.
Security posture scores reflect publicly available information only. A low score may indicate limited transparency rather than poor security practices.
Mappera is not affiliated with any vendor assessed. Methodology v0.1.