[{"data":1,"prerenderedAt":619},["ShallowReactive",2],{"uc-software-vulnerability-remediation":3,"uc-regulations":413},{"useCase":4,"evidence":216,"blitsAiDeployments":311,"benchmarks":312,"indicative":313,"related":316,"indexability":411,"includeUnpublished":222},{"title":5,"shortTitle":6,"seoTitle":7,"metaDescription":8,"status":9,"definition":10,"aliases":11,"industries":17,"functions":21,"patterns":24,"channels":28,"audience":31,"autonomy":32,"adoptionStage":33,"problem":34,"problemStats":35,"howItWorks":41,"valueDrivers":42,"kpis":47,"indicativeValue":55,"macroEstimates":100,"feasibility":101,"implementation":115,"risk":158,"blitsAi":196,"faq":198,"related":208,"datePublished":211,"dateModified":211,"lastVerified":211,"changelog":212,"slug":215},"AI for software vulnerability triage and remediation","Vulnerability remediation","AI vulnerability remediation and security autofix","AI that triages security findings and drafts fixes. Chrome fixed 1,072 security bugs in two milestones, with LLMs drafting candidate fixes for most vulnerabilities.","published","AI that takes security findings from scanners, fuzzers and bug reports, filters out duplicates and false positives, reproduces and ranks the real ones, and drafts a code fix with a test for each, which a developer reviews and merges through the normal change process.",[12,13,14,15,16],"AI vulnerability autofix","AI security patch generation","automated vulnerability fixing","SAST backlog remediation with AI","AI vulnerability triage",[18,19,20],"cross-industry","technology","healthcare",[22,23],"security-operations","it-and-engineering",[25,26,27],"code-generation","agentic-workflow","classification-and-routing",[29,30],"internal-tools","api","employee-facing","copilot","early-adopters","Security tools find far more problems than teams can fix. Static analysis (SAST), dependency\nscanners, fuzzers, penetration tests and bug bounty reports all feed the same backlog, and each\nfinding needs someone to confirm it is real, work out how serious it is, find the owner and write\na fix that does not break anything. Developers see security tickets as interruptions to feature\nwork, so the backlog grows and old findings stay open.\n\nAI is making the imbalance sharper on both sides. Models are now used to find vulnerabilities\n(Google's Big Sleep agent found bugs in Chrome's V8 engine in 2025). Separately, the Chrome\nsecurity team reports receiving more bug reports by March 2026 than in all of 2025, without\nnaming a single cause, and says triaging a single report used to take 5 to 30 or more minutes of\nexpert time. At the same\ntime, low quality AI generated reports waste maintainers' time, and developers using coding\nassistants ship more code, and so more findings, than before. Fixing has to scale as fast as\nfinding, without letting unreviewed code into production.",[36],{"statement":37,"sourceTitle":38,"sourceUrl":39,"year":40},"The Chrome security team reports that historically, triaging a single security report took anywhere from 5 to 30 or more minutes and relied primarily on human expertise.","Stronger with every update: How we're making Chrome and the web safer in the AI Era","https://blog.google/security/chrome-stronger-with-every-update/",2026,"1. **Collect and deduplicate.** Findings arrive from scanners, fuzzers, CI pipelines and external\n   reports. The system drops spam and duplicates and checks that each one describes a real\n   security issue in scope.\n2. **Validate and rank.** Where possible it reproduces the bug (running the proof of concept or\n   the failing test), checks whether the vulnerable code is reachable, and assigns a severity\n   using written guidelines. Findings that mitigations already neutralise are marked for a human\n   to confirm and close.\n3. **Route to the owner.** The finding goes to the right component and code owner with the stack\n   trace, severity and context attached.\n4. **Draft the fix.** A fixing agent proposes one or more candidate patches; a separate critic\n   step or reviewer model checks them against the style guide, and the fix is rebuilt and rescanned\n   to prove the finding is gone. Test writing agents add a regression test.\n5. **Human review and merge.** The developer reviews the pull request like any other change and\n   merges, edits or rejects it. Rejections and edits feed back into the prompts and examples.",[43,44,45,46],"risk-reduction","employee-productivity","speed","compliance",[48,49,50,51,52,53,54],"processing-time-reduction","mttr-reduction","automation-rate","false-positive-reduction","productivity-gain","hours-saved","interactions-handled",{"referenceOrg":56,"inputs":57,"formula":95,"currency":96,"period":97,"resultLabel":98,"caveat":99},"A software organization that fixes 2,000 to 5,000 security findings a year",[58,65,73,81,88],{"key":59,"label":60,"low":61,"high":62,"unit":63,"note":64},"findingsPerYear","Security findings fixed per year",2000,5000,"findings per year","Editorial assumption for a mid sized engineering organization. Replace with the count from your vulnerability management or code scanning tool.",{"key":66,"label":67,"low":68,"high":69,"unit":70,"note":71,"sourceUrl":72},"hoursPerFix","Developer hours per manual fix, including review",1.5,4,"hours per finding","GitHub reports a median of 1.5 hours to resolve code scanning alerts manually, measured in its public beta on alerts raised in pull requests on new code; the high end is an editorial allowance for older backlog findings, which take longer.","https://github.blog/news-insights/product-news/secure-code-more-than-three-times-faster-with-copilot-autofix/",{"key":74,"label":75,"low":76,"high":77,"unit":78,"note":79,"sourceUrl":80},"aiFixShare","Share of findings where an AI drafted fix is accepted",0.1,0.2,"fraction of findings","An editorial range around the only measured acceptance rate, Google's 15% of sanitizer bugs fixed by its LLM pipeline with human review. Chrome's candidate fixes for most vulnerabilities are drafts, not accepted fixes, so they are not used here.","https://research.google/pubs/ai-powered-patching-the-future-of-automated-vulnerability-fixes/",{"key":82,"label":83,"low":84,"high":85,"unit":86,"note":87,"sourceUrl":72},"timeSavedShare","Share of developer time saved on those findings",0.5,0.7,"fraction of fix time","GitHub reports a median of 28 minutes with Copilot Autofix against 1.5 hours manually, about 69% less, measured in its public beta on new alerts in pull requests; the low end allows for backlog fixes and review of harder fixes.",{"key":89,"label":90,"low":91,"high":92,"unit":93,"note":94},"costPerHour","Fully loaded cost of a developer hour",80,120,"USD per hour","Editorial assumption, replace with your own fully loaded cost.","findingsPerYear * hoursPerFix * aiFixShare * timeSavedShare * costPerHour","USD","per year","Developer time released on security fixes, valued at cost","Counts developer time on accepted fixes only. It leaves out the time saved in triage, the cost of the AI and scanning tools, the value of a smaller exposure window, and the cost of reviewing fixes that are rejected.",[],{"complexity":102,"complexityNote":103,"dataPrerequisites":104,"integrations":109},"medium","Generating a patch is the easy part. The value depends on being able to build, test and rescan each candidate automatically, and on code owners who trust the pipeline enough to review its pull requests promptly.",[105,106,107,108],"Findings with enough detail to act on (rule, location, trace or proof of concept)","A build and test setup that can run a candidate fix automatically","Written severity guidelines and code ownership per component","Past fixes and rejected findings, as examples and as a test set",[110,111,112,113,114],"Source control and pull requests (for example GitHub, GitLab or Azure DevOps)","Code scanning, dependency scanning and fuzzing tools","CI pipeline to build, test and rescan candidate fixes","Issue tracker or vulnerability management system for ownership and status","Bug bounty or external report intake, where the organization runs one",{"steps":116,"guardrails":132,"humanInTheLoop":138,"kpisToInstrument":139,"failureModes":145},[117,120,123,126,129],{"title":118,"detail":119},"Measure the backlog and the flow","Count open findings by severity, age and class, and measure how long triage and fixing take today. Pick one or two high volume classes (for example injection or memory safety bugs in one language) for the first wave.",{"title":121,"detail":122},"Automate the boring triage first","Deduplication, reproduction, severity by written rules and routing to the owner deliver value before any AI written code is merged, and they give you the clean data the fixing step needs.",{"title":124,"detail":125},"Make every candidate fix prove itself","A candidate fix must build, pass the existing tests, include a regression test and make the scanner or fuzzer stop reporting the finding. Discard candidates that fail, rather than sending them to developers.",{"title":127,"detail":128},"Review like any other change","Fixes arrive as ordinary pull requests with an explanation, go through code owner review and the normal release process, and are labelled as AI drafted so acceptance can be measured.",{"title":130,"detail":131},"Track acceptance per class and tune","Measure how many fixes are merged unchanged, edited or rejected per vulnerability class, and expand to new classes only where acceptance is good and no regressions were introduced.",[133,134,135,136,137],"No AI drafted fix reaches production without human code review and the normal CI checks","Candidate fixes must pass build, tests and a rescan before a developer sees them","Agents that analyse code run in isolated environments without general internet access and with write access limited to the source tree","Severity changes and closures of findings as not exploitable need a named human's confirmation","Every AI drafted change is labelled, so its acceptance and any later regressions can be traced","Developers review and merge every fix, and security engineers confirm severity and any decision to close a finding without a code change. The AI does the reproduction, the drafting and the testing; humans stay accountable for what ships.",[140,141,142,143,144],"Median time from finding to merged fix, per severity","Share of AI drafted fixes merged unchanged, edited or rejected","Open findings in the backlog by severity and age","Regressions or reopened findings traced to AI drafted fixes","Triage time per incoming report",[146,149,152,155],{"title":147,"detail":148},"A fix that hides the symptom","The patch silences the scanner (for example by adding a check in the wrong place) but leaves the vulnerability exploitable. Require a regression test that exercises the attack, and have security review high severity fixes.",{"title":150,"detail":151},"Review fatigue","A flood of AI pull requests gets merged without real review. Batch fixes by component, limit the daily volume per owner and sample merged fixes for security review.",{"title":153,"detail":154},"Plausible but false findings","AI generated reports can look convincing and still be wrong, and each costs expert time to disprove. Require reproduction before a human spends time on a report.",{"title":156,"detail":157},"Agents with too much reach","An agent that can run code and reach the network can leak source code or be steered by content in the repository. Sandbox it, restrict its network access and keep its permissions minimal.",{"euAiAct":159,"regulations":162,"guidance":169,"controls":185,"incidents":191},{"tier":160,"basis":161},"minimal","Drafting and triaging code fixes for an organization's own software is not an Annex III use, and developers, not the public, interact with the system. The software being fixed remains subject to its own security and resilience rules, whoever wrote the fix.",[163,164,165,166,167,168],"eu-ai-act","nis2","dora","pci-dss","nist-ai-rmf","iso-42001",[170,176,180],{"title":171,"issuer":172,"region":173,"url":174,"note":175},"NIST SP 800-218, Secure Software Development Framework (SSDF) Version 1.1","NIST","north-america","https://csrc.nist.gov/pubs/sp/800/218/final","Recommended practices for mitigating software vulnerabilities, including identifying, analysing and remediating them; the process an AI remediation pipeline has to fit into.",{"title":177,"issuer":172,"region":173,"url":178,"note":179},"NIST SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models","https://csrc.nist.gov/pubs/sp/800/218/a/final","An SSDF community profile that adds practices for developing generative AI systems, useful when the remediation pipeline itself is built on models.",{"title":181,"issuer":182,"region":173,"url":183,"note":184},"Secure by Design","Cybersecurity and Infrastructure Security Agency (CISA)","https://www.cisa.gov/securebydesign","CISA's programme asking every technology provider to take ownership of product security at the executive level, with alerts on eliminating specific vulnerability types such as cross site scripting and OS command injection.",[186,187,188,189,190],"Inventory entry for the pipeline with an owner, the vulnerability classes in scope and the repositories it may touch","Code owner review and CI checks on every AI drafted change, with the change labelled as AI drafted","Isolated, network restricted execution environment for agents that read and run code","Metrics on acceptance, regressions and backlog age reviewed by the security lead each month","Documented severity guidelines applied the same way by humans and the pipeline",[192],{"title":193,"url":194,"note":195},"The I in LLM stands for intelligence (curl project on AI generated vulnerability reports)","https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/","The curl maintainer describes AI generated bug bounty reports that looked plausible but were hallucinated, and how each one takes a human's time to disprove; the reason to require reproduction before triage.",{"howToBuild":197},"On Blits.ai the triage half is an **agentic workflow** triggered by an API token from the CI\npipeline or on a schedule: its **agent loop** calls **custom functions** that read findings\nfrom the scanning tool and the issue tracker as REST calls, or tools exposed through **MCP**\nservers, applies the organization's severity guidelines from a **knowledge base**, and writes\nthe routing and a summary back to the ticket. A **tool execution policy** restricts which tools\nthe agent may call, and **human in the loop confirmation** is required before a finding is\nclosed or its severity changed.\n\nCode generation itself belongs in the developer's own toolchain, where fixes are built, tested\nand reviewed; the workflow on Blits.ai prepares the context, tracks each finding's status and\nkeeps a **full audit trail per run**. The platform is model agnostic, so the security team can\npick the model per task, and **test suites** can replay a labelled set of past findings to check\nthe triage verdicts on every change.",[199,202,205],{"question":200,"answer":201},"Can AI fix security vulnerabilities on its own?","It can draft the fix, but a developer should still review and merge it. Google reports that its Gemini pipeline fixed 15% of sanitizer bugs found in unit tests, with every fix going to human review, and the Chrome team says LLMs now generate candidate fixes for most vulnerabilities while developers evaluate them. Plan for review capacity, not for zero touch.",{"question":203,"answer":204},"Where should a team start?","With triage: deduplication, reproduction, severity by written rules and routing. It removes noise before anyone writes code. In a Checkmarx case study, PatientPoint's application security engineer says the Checkmarx triage and remediation tools identified false positives and gave developers the opportunity for human review. Then add AI drafted fixes for one well understood vulnerability class.",{"question":206,"answer":207},"How fast can a backlog shrink?","Snyk reports, in a case study, that Labelbox's lead security engineer cleared a backlog of high severity static analysis findings in two to three weeks by pairing an AI coding agent with Snyk's rescanning; he estimated the work at a full calendar year with the old workflow. That is one small company's experience; large codebases with many owners move at the pace of review.",[209,210],"developer-coding-assistant","security-alert-triage-and-investigation","2026-09-27",[213],{"date":211,"note":214},"First published","software-vulnerability-remediation",[217,245,267,289],{"title":218,"useCases":219,"organization":220,"vendors":225,"summary":228,"stage":229,"year":40,"channels":230,"languages":231,"metrics":233,"outcomeDisclosed":234,"sources":235,"verification":240,"grade":242,"id":243,"organizationSlug":244},"Google Chrome: AI agents that triage and fix security bugs",[215],{"name":221,"anonymized":222,"country":223,"region":224,"industry":19},"Google",false,"US","global",[226],{"name":221,"role":227},"in-house","The Chrome security team uses Gemini based agents across the life of a security bug. An automated triage pipeline filters spam and duplicates, reproduces bugs, adds severity and routes them to the owner; fixing agents propose candidate patches that a critic agent reviews, and test writing agents add tests before a developer evaluates the fix. Chrome fixed 1,072 security bugs in milestones 149 and 150, more than the prior 23 milestones combined, and Google says LLMs now generate candidate fixes for most vulnerabilities. It estimates the triage automation saves hundreds of hours of developer time a month.","scaled",[29],[232],"en",[],true,[236],{"url":39,"title":237,"publisher":238,"date":239},"Stronger with every update: How we’re making Chrome and the web safer in the AI Era","Google (The Keyword)","2026-07-30",{"level":241,"checkedAt":211},"source-verified","B","google-chrome-ai-vulnerability-triage-and-fixing","google",{"title":246,"useCases":247,"organization":248,"vendors":249,"summary":251,"stage":252,"year":253,"channels":254,"languages":255,"metrics":256,"outcomeDisclosed":234,"sources":257,"verification":265,"grade":242,"id":266,"organizationSlug":244},"Google: Gemini pipeline that drafts fixes for sanitizer bugs",[215],{"name":221,"anonymized":222,"country":223,"region":224,"industry":19},[250],{"name":221,"role":227},"Google's security engineering team built a pipeline that prompts Gemini to generate code fixes for bugs that sanitizers find during unit tests in C and C++, Java and Go code, such as uninitialised values, data races and buffer overflows. Every generated fix goes to a human reviewer before it lands. Google reports that the pipeline fixed 15% of these bugs, hundreds in total, and expects the rate to improve.","production",2024,[29],[232],[],[258,261],{"url":80,"title":259,"publisher":260},"AI-powered patching: the future of automated vulnerability fixes","Google Research (Google Security Engineering Technical Report)",{"url":262,"title":263,"publisher":264},"https://storage.googleapis.com/gweb-research2023-media/pubtools/7563.pdf","AI-powered patching: the future of automated vulnerability fixes (full report, PDF)","Google Security Engineering",{"level":241,"checkedAt":211},"google-sanitizer-bug-ai-patching",{"title":268,"useCases":269,"organization":270,"vendors":272,"summary":276,"stage":252,"year":40,"channels":277,"languages":278,"metrics":279,"outcomeDisclosed":222,"sources":280,"verification":285,"grade":286,"id":287,"organizationSlug":288},"PatientPoint: AI triage and remediation assistance for application security findings",[215],{"name":271,"anonymized":222,"country":223,"region":173,"industry":20},"PatientPoint",[273],{"name":274,"role":275},"Checkmarx","platform","PatientPoint, a US healthcare company, used Checkmarx Triage Assist and Remediation Assist when its leadership asked the application security team to remediate vulnerabilities in a short period, while developers using AI to write code were adding findings faster than before. Checkmarx says the tools filtered out false positives before they reached developers and generated fix guidance the team could review; PatientPoint's application security engineer calls the tools very accurate and says they identified false positives and left room for human review. No figures are given.",[29],[232],[],[281],{"url":282,"title":283,"publisher":274,"date":284},"https://checkmarx.com/resources/on-point-fixes-how-patientpoint-outpaced-its-own-vulnerability-backlog/","On-Point Fixes: How PatientPoint Outpaced Its Own Vulnerability Backlog","2026-07-14",{"level":241,"checkedAt":211},"C","patientpoint-checkmarx-ai-triage-and-remediation",null,{"title":290,"useCases":291,"organization":292,"vendors":294,"summary":299,"stage":252,"year":300,"channels":301,"languages":302,"metrics":303,"outcomeDisclosed":234,"sources":304,"verification":309,"grade":286,"id":310,"organizationSlug":288},"Labelbox: AI coding agent and Snyk rescans to clear a static analysis backlog",[215],{"name":293,"anonymized":222,"country":223,"region":173,"industry":19},"Labelbox",[295,297],{"name":296,"role":275},"Snyk",{"name":298,"role":275},"Cursor","Labelbox, a San Francisco AI data company of about 200 people, had a growing backlog of high severity static analysis findings. Its lead security engineer paired the Cursor coding agent with Snyk's MCP server: the agent pulled each finding, judged exploitability, proposed a fix and retried until a Snyk rescan passed, after which the fix was tested and went through QA. Snyk reports the backlog was cleared in two to three weeks; the engineer says it took a couple of weeks and estimates the work at a full calendar year with the old workflow.",2025,[29],[232],[],[305],{"url":306,"title":307,"publisher":296,"date":308},"https://snyk.io/blog/from-two-years-to-two-weeks-how-labelbox-erased-its-security-debt-with-snyks/","From Two Years to Two Weeks: How Labelbox Erased Its Security Debt with Snyk's AI-Accelerated Remediation","2025-09-18",{"level":241,"checkedAt":211},"labelbox-snyk-ai-sast-backlog-remediation",0,[],{"low":314,"high":315},12000,336000,[317,343,365,390],{"slug":209,"title":318,"shortTitle":319,"definition":320,"status":9,"industries":321,"functions":325,"patterns":326,"audience":31,"autonomy":32,"adoptionStage":327,"evidenceCount":328,"publicEvidenceCount":328,"organizations":329,"bestGrade":242,"headline":336,"lastVerified":211,"indexable":234},"AI coding assistant for software developers","Developer coding assistant","An AI assistant in the developer's IDE and code review flow that completes and generates code, explains unfamiliar modules, drafts unit tests and reviews pull requests for common defects, while generated code goes through the same review, testing and change controls as any other code.",[18,322,323,19,324],"banking","capital-markets","professional-services",[23],[25],"mainstream",6,[330,331,332,333,334,335],"Accenture","ANZ","Bank of America","Citi","CME Group","Meta",{"kpi":52,"label":337,"unit":338,"n":339,"nUpTo":311,"kind":340,"value":341,"qualifier":342,"claimant":288,"organization":288,"vendorReported":222},"Productivity gain","percent",3,"median",20,"exact",{"slug":210,"title":344,"shortTitle":345,"definition":346,"status":9,"industries":347,"functions":349,"patterns":350,"audience":31,"autonomy":353,"adoptionStage":33,"evidenceCount":354,"publicEvidenceCount":354,"organizations":355,"bestGrade":242,"headline":363,"lastVerified":211,"indexable":234},"AI for security alert triage and investigation in the SOC","Security alert triage","An AI agent in the security operations centre that picks up each new alert or user reported phishing email, gathers the evidence from the SIEM, endpoint, identity and threat intelligence tools, gives a verdict with its reasoning and a draft incident summary, and closes clear false positives while an analyst approves every containment action.",[18,20,19,348,324],"government",[22,23],[26,27,351,352],"summarization","rag-knowledge-assistant","supervised-agent",7,[356,357,358,359,360,361,362],"Avanade","Federal Housing Finance Agency","Human Managed","SEP2","St. Luke's University Health Network","TÜV SÜD","U.S. Immigration and Customs Enforcement",{"kpi":52,"label":337,"unit":338,"n":339,"nUpTo":311,"kind":340,"value":364,"qualifier":342,"claimant":288,"organization":288,"vendorReported":222},60,{"slug":366,"title":367,"shortTitle":368,"definition":369,"status":9,"industries":370,"functions":372,"patterns":374,"audience":31,"autonomy":353,"adoptionStage":327,"evidenceCount":376,"publicEvidenceCount":328,"organizations":377,"bestGrade":242,"headline":383,"lastVerified":211,"indexable":234},"it-service-desk-resolution-agent","AI agent for IT service desk resolution","IT service desk resolution","An AI agent in Microsoft Teams, Slack or the intranet that takes the high volume IT support queue, such as password and MFA resets, account unlocks, VPN, device and software requests, and resolves common requests by acting in the identity and IT service management systems, handing the rest to the right resolver group with the context attached.",[18,322,19,371,20],"retail-and-ecommerce",[23,373],"operations",[375,26,352,27],"conversational-agent",8,[378,332,379,380,381,382],"7-Eleven Vietnam","Equinix","IBM","Mercari US","Vituity",{"kpi":384,"label":385,"unit":338,"n":386,"nUpTo":311,"kind":387,"value":388,"qualifier":342,"claimant":389,"organization":381,"vendorReported":234},"employee-adoption","Employee adoption",2,"reported",94,"vendor",{"slug":391,"title":392,"shortTitle":393,"definition":394,"status":9,"industries":395,"functions":398,"patterns":400,"audience":31,"autonomy":32,"adoptionStage":33,"evidenceCount":328,"publicEvidenceCount":402,"organizations":403,"bestGrade":242,"headline":407,"lastVerified":211,"indexable":234},"aiops-incident-triage","AI for IT incident triage and root cause analysis (AIOps)","AIOps incident triage","AI that turns a flood of monitoring alerts into one probable incident, routes it to the right team, proposes likely root causes and remediation from runbooks and past incidents, and drafts the stakeholder updates and the post incident review, while an engineer authorizes every change.",[18,322,19,396,397],"telecommunications","payments",[23,373,399],"risk-management",[401,27,351,352,26],"anomaly-detection",5,[221,335,404,405,406],"Microsoft","Mizuho Financial Group","TD Bank",{"kpi":408,"label":409,"unit":338,"n":339,"nUpTo":311,"kind":340,"value":410,"qualifier":342,"claimant":288,"organization":288,"vendorReported":222},"accuracy","Accuracy",90,{"indexable":234,"reasons":412},[],[414,421,427,433,438,443,450,457,465,472,477,483,490,497,503,507,514,520,526,532,538,544,550,555,560,567,573,578,583,590,596,602,608,613],{"id":163,"label":415,"issuer":416,"region":417,"url":418,"description":419,"useCases":420,"indexable":234},"EU AI Act","European Union","europe","https://eur-lex.europa.eu/eli/reg/2024/1689/oj","Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.",197,{"id":422,"label":423,"issuer":416,"region":417,"url":424,"description":425,"useCases":426,"indexable":234},"gdpr","GDPR","https://eur-lex.europa.eu/eli/reg/2016/679/oj","General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.",180,{"id":168,"label":428,"issuer":429,"region":224,"url":430,"description":431,"useCases":432,"indexable":234},"ISO/IEC 42001","ISO and IEC","https://www.iso.org/standard/81230.html","The international management system standard for AI.",110,{"id":167,"label":434,"issuer":172,"region":173,"url":435,"description":436,"useCases":437,"indexable":234},"NIST AI Risk Management Framework","https://www.nist.gov/itl/ai-risk-management-framework","Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.",83,{"id":165,"label":439,"issuer":416,"region":417,"url":440,"description":441,"useCases":442,"indexable":234},"DORA","https://eur-lex.europa.eu/eli/reg/2022/2554/oj","Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.",66,{"id":444,"label":445,"issuer":446,"region":417,"url":447,"description":448,"useCases":449,"indexable":234},"uk-gdpr","UK GDPR","Information Commissioner's Office","https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/","The UK's version of the GDPR, including rules on solely automated decisions.",64,{"id":451,"label":452,"issuer":453,"region":417,"url":454,"description":455,"useCases":456,"indexable":234},"uk-consumer-duty","FCA Consumer Duty","Financial Conduct Authority","https://www.fca.org.uk/firms/consumer-duty","UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.",47,{"id":458,"label":459,"issuer":460,"region":461,"url":462,"description":463,"useCases":464,"indexable":234},"mas-ai-risk-management","MAS AI risk management guidelines","Monetary Authority of Singapore","asia-pacific","https://www.mas.gov.sg/news/media-releases/2025/mas-guidelines-for-artificial-intelligence-risk-management","Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.",36,{"id":466,"label":467,"issuer":468,"region":461,"url":469,"description":470,"useCases":471,"indexable":234},"apra-cps-230","APRA CPS 230","Australian Prudential Regulation Authority","https://www.apra.gov.au/operational-risk-management","Australian operational risk standard covering critical operations and material service providers.",25,{"id":166,"label":473,"issuer":474,"region":224,"url":475,"description":476,"useCases":341,"indexable":234},"PCI DSS","PCI Security Standards Council","https://www.pcisecuritystandards.org/","Security standard for any system that stores, processes or transmits cardholder data.",{"id":478,"label":479,"issuer":480,"region":173,"url":481,"description":482,"useCases":341,"indexable":234},"us-sr-11-7","SR 11-7 model risk management","Federal Reserve and OCC","https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107.htm","US supervisory guidance on model risk management, applied by banks to AI and machine learning models.",{"id":484,"label":485,"issuer":486,"region":417,"url":487,"description":488,"useCases":489,"indexable":234},"uk-atrs","UK Algorithmic Transparency Recording Standard","UK Government","https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub","Mandatory transparency records for algorithmic tools used by UK central government.",16,{"id":491,"label":492,"issuer":493,"region":224,"url":494,"description":495,"useCases":496,"indexable":234},"fatf-recommendations","FATF Recommendations","Financial Action Task Force","https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html","Global standards for anti money laundering and counter terrorist financing that national rules implement.",15,{"id":498,"label":499,"issuer":416,"region":417,"url":500,"description":501,"useCases":502,"indexable":234},"eu-amlr","EU Anti Money Laundering Regulation","https://eur-lex.europa.eu/eli/reg/2024/1624/oj","Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.",14,{"id":164,"label":504,"issuer":416,"region":417,"url":505,"description":506,"useCases":502,"indexable":234},"NIS2 Directive","https://eur-lex.europa.eu/eli/dir/2022/2555/oj","Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.",{"id":508,"label":509,"issuer":510,"region":173,"url":511,"description":512,"useCases":513,"indexable":234},"us-bsa","Bank Secrecy Act","FinCEN","https://www.fincen.gov/resources/statutes-and-regulations/bank-secrecy-act","US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.",13,{"id":515,"label":516,"issuer":416,"region":417,"url":517,"description":518,"useCases":519,"indexable":234},"eu-accessibility-act","European Accessibility Act","https://eur-lex.europa.eu/eli/dir/2019/882/oj","Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.",12,{"id":521,"label":522,"issuer":523,"region":173,"url":524,"description":525,"useCases":519,"indexable":234},"hipaa","HIPAA","US Department of Health and Human Services","https://www.hhs.gov/hipaa/index.html","US rules for the privacy and security of protected health information.",{"id":527,"label":528,"issuer":529,"region":224,"url":530,"description":531,"useCases":519,"indexable":234},"telecom-consumer-rules","Telecom consumer protection rules","National telecom regulators","https://www.berec.europa.eu/","National rules on telecom contracts, switching, billing disputes and marketing consent.",{"id":533,"label":534,"issuer":416,"region":417,"url":535,"description":536,"useCases":537,"indexable":234},"eecc","European Electronic Communications Code","https://eur-lex.europa.eu/eli/dir/2018/1972/oj","Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.",11,{"id":539,"label":540,"issuer":541,"region":173,"url":542,"description":543,"useCases":537,"indexable":234},"us-tcpa","Telephone Consumer Protection Act","Federal Communications Commission","https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts","US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.",{"id":545,"label":546,"issuer":460,"region":461,"url":547,"description":548,"useCases":549,"indexable":234},"mas-notice-626","MAS Notice 626","https://www.mas.gov.sg/regulation/notices/notice-626","Singapore's anti money laundering and counter terrorism financing requirements for banks.",10,{"id":551,"label":552,"issuer":416,"region":417,"url":553,"description":554,"useCases":549,"indexable":234},"mifid-ii","MiFID II","https://eur-lex.europa.eu/eli/dir/2014/65/oj","Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.",{"id":556,"label":557,"issuer":416,"region":417,"url":558,"description":559,"useCases":549,"indexable":234},"eu-psd2","PSD2","https://eur-lex.europa.eu/eli/dir/2015/2366/oj","Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.",{"id":561,"label":562,"issuer":563,"region":417,"url":564,"description":565,"useCases":566,"indexable":234},"eba-loan-origination","EBA Guidelines on loan origination and monitoring","European Banking Authority","https://www.eba.europa.eu/regulation-and-policy/credit-risk/guidelines-on-loan-origination-and-monitoring","Expectations for credit decisioning, including the use of automated models.",9,{"id":568,"label":569,"issuer":570,"region":173,"url":571,"description":572,"useCases":376,"indexable":234},"us-ecoa-reg-b","ECOA and Regulation B","Consumer Financial Protection Bureau","https://www.consumerfinance.gov/rules-policy/regulations/1002/9/","US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.",{"id":574,"label":575,"issuer":416,"region":417,"url":576,"description":577,"useCases":376,"indexable":234},"solvency-ii","Solvency II","https://eur-lex.europa.eu/eli/dir/2009/138/oj","Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.",{"id":579,"label":580,"issuer":416,"region":417,"url":581,"description":582,"useCases":328,"indexable":234},"eu-idd","Insurance Distribution Directive","https://eur-lex.europa.eu/eli/dir/2016/97/oj","Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.",{"id":584,"label":585,"issuer":586,"region":587,"url":588,"description":589,"useCases":402,"indexable":234},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",{"id":591,"label":592,"issuer":593,"region":417,"url":594,"description":595,"useCases":69,"indexable":234},"pra-ss1-23","PRA SS1/23 model risk management","Prudential Regulation Authority","https://www.bankofengland.co.uk/prudential-regulation/publication/2023/may/model-risk-management-principles-for-banks-ss","UK model risk management principles for banks, covering AI and machine learning models.",{"id":597,"label":598,"issuer":599,"region":417,"url":600,"description":601,"useCases":69,"indexable":234},"uk-psr-app-reimbursement","UK APP scam reimbursement rules","Payment Systems Regulator","https://www.psr.org.uk/our-work/app-scams/","Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.",{"id":603,"label":604,"issuer":605,"region":461,"url":606,"description":607,"useCases":339,"indexable":234},"au-scams-prevention-framework","Australian Scams Prevention Framework","Australian Treasury","https://treasury.gov.au/consultation/c2024-573813","Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.",{"id":609,"label":610,"issuer":416,"region":417,"url":611,"description":612,"useCases":339,"indexable":234},"eu-mar","EU Market Abuse Regulation","https://eur-lex.europa.eu/eli/reg/2014/596/oj","Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.",{"id":614,"label":615,"issuer":616,"region":173,"url":617,"description":618,"useCases":339,"indexable":234},"us-fcra","Fair Credit Reporting Act","Federal Trade Commission","https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act","US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.",1790598301627]