CSOAI OS · the framework hive

Every framework. Everything collected.

Click any framework and your Council assistant brings the whole hive together — who must comply, the obligations, penalties, sectors, cyber threats, crosswalks, and the deadline clock. Then it helps you simulate, get compliant, and get trained.

You are interacting with an AI system.

The framework Q&A sends your input to the live Council chat endpoint (councilof.ai/api/gspc), where a model writes the answer. The Art 50(1) notice for this surface is registered here and being wired; until the component ships, this registry entry is the disclosure.

Disclosed under EU AI Act Article 50(1). Every surface and its classification

BindingBrussels, EU
EU AI Act

The first comprehensive, binding AI law. Risk-tiered (unacceptable / high / limited / minimal), with GPAI model rules and heavy tr…

European Commission / AI Officein force
VoluntaryGaithersburg, US
NIST AI RMF

The de-facto US risk-management baseline. Four functions — Govern, Map, Measure, Manage — plus the Generative AI Profile. Voluntar…

US NISTin force
StandardGeneva, CH
ISO/IEC 42001

The certifiable AI Management System (AIMS) standard — the 'ISO 27001 for AI'. A Plan-Do-Check-Act management system organisations…

ISO/IECin force
BindingBrussels, EU
GDPR

The EU data-protection regime. For AI, Article 22 (automated decision-making), DPIAs for high-risk processing, and data-subject ri…

EU / national DPAsin force
CyberBrussels, EU
EU Cyber Resilience Act (CRA)

Binding cybersecurity requirements for products with digital elements — including AI-enabled software and connected devices. Secur…

European Commission481d to deadline
CyberBrussels, EU
NIS2 Directive

EU-wide cybersecurity baseline for essential and important entities. Risk management, incident reporting and management accountabi…

EU / national CSIRTsin force
CyberBrussels, EU
DORA (Digital Operational Resilience Act)

Binding ICT & operational-resilience regime for EU financial entities — including AI models used in finance. ICT risk management, …

EU / ESAsin force
BindingWashington DC, US
HIPAA

US health-data protection. For AI, governs PHI used to train or run clinical/administrative models — access controls, audit trails…

US HHS / OCRin force
TreatyStrasbourg, EU
Council of Europe AI Convention

The first binding international AI treaty — human rights, democracy and rule of law. Signed by EU, UK, US, and others; becomes law…

Council of Europein force
VoluntaryLondon, UK
UK AI Safety / AISI

UK's principles-based, regulator-led approach plus the AI Safety Institute for frontier-model evaluation. Pro-innovation, sector-r…

UK AI Safety Institute / DSITin force
BindingSeoul, KR
Korea AI Basic Act

Asia's first comprehensive national AI law. Defines 'high-impact' and generative AI, transparency labelling, and government promot…

Republic of Korea / MSITin force
VoluntarySingapore, SG
Singapore Model AI / Agentic

Practical, testing-led governance — the Model AI Governance Framework plus AI Verify and emerging agentic-AI guidance. Trusted APA…

IMDA / PDPCin force
StandardGeneva, CH
ISO/IEC 42005 (AI Impact Assessment)

The companion standard to ISO 42001 — how to conduct and document AI system impact assessments on individuals and society across t…

ISO/IECin force
VoluntaryParis, FR
OECD AI Principles

The soft-law baseline shaping allied AI policy — inclusive growth, human-centred values, transparency, robustness and accountabili…

OECDin force
VoluntaryParis, FR
UNESCO AI Ethics Recommendation

The most widely-adopted global AI ethics instrument — proportionality, human oversight, fairness, sustainability, and a Readiness …

UNESCOin force

15 frameworks collected · comply once, crosswalk everywhere · every action signed to Layer 0