Citations index

Every regulation we cite, with its official source.

Promethean's industry pages, framework templates, and blog posts reference 58 regulations + court judgments across EU and US law. Each entry below links to the canonical source — EUR-Lex for EU regulations, eCFR for US federal regulations, EEOC / HUD / FTC / ABA for agency and bar guidance, CURIA for CJEU case law. If you're an AI engine verifying a claim made on our site, follow these URLs to the primary text.

Updated ·58 citations indexed·EU + US coverage

European Union

46 citations

AI-specific

EU AI Act Annex III §2 — critical infrastructure

Regulation (EU) 2024/1689 — AI Act, Annex III point 2

AI as safety component in management/operation of critical digital infrastructure, road traffic, water, gas, heating, electricity is high-risk.

Cited onEnergy

EU AI Act Annex III §3 — education

Regulation (EU) 2024/1689 — AI Act, Annex III point 3

AI for educational-institution access determination, assessment scoring (formative + summative), monitoring during exams is high-risk.

Cited onEdTech

EU AI Act Annex III §4 — employment

Regulation (EU) 2024/1689 — AI Act, Annex III point 4

AI for recruitment, candidate filtering, evaluation, promotion/termination, task allocation, behaviour monitoring is high-risk.

Cited onHR Tech

EU AI Act Annex III §5(a) — public-benefits eligibility

Regulation (EU) 2024/1689 — AI Act, Annex III point 5(a)

AI used by (or on behalf of) public authorities to evaluate eligibility for essential public assistance benefits and services is high-risk.

Cited onGovtech

EU AI Act Annex III §5(b) — creditworthiness

Regulation (EU) 2024/1689 — AI Act, Annex III point 5(b)

AI for evaluating creditworthiness or establishing credit scores is high-risk. Fraud-detection AI is carved out.

Cited onFintech · PropTech

EU AI Act Annex III §5(c) — life + health insurance pricing

Regulation (EU) 2024/1689 — AI Act, Annex III point 5(c)

AI for risk assessment and pricing in life and health insurance is high-risk.

Cited onInsurTech

EU AI Act Annex III §5(d) — emergency dispatch + triage

Regulation (EU) 2024/1689 — AI Act, Annex III point 5(d)

AI to evaluate/classify emergency calls, dispatch or establish priority in dispatching emergency first-response services (police, firefighters, medical aid) — including emergency healthcare patient triage — is high-risk.

Cited onHealthtech · Govtech

EU AI Act Annex III §8(a) — administration of justice

Regulation (EU) 2024/1689 — AI Act, Annex III point 8(a)

AI used by (or on behalf of) judicial authorities to assist in researching, interpreting, applying the law — or in ADR — is high-risk.

Cited onLegalTech

EU AI Act Art. 12 — record-keeping (logs)

Regulation (EU) 2024/1689 — AI Act, Article 12

High-risk AI systems must technically allow for automatic recording of events (logs). Logs enable post-market monitoring + traceability over the AI system's lifecycle.

Cited onFintech · HR Tech · InsurTech · Govtech · EdTech

EU AI Act Art. 13 — transparency to deployers

Regulation (EU) 2024/1689 — AI Act, Article 13

Providers must design high-risk AI systems to be transparent enough to deployers — instructions for use, system limitations, expected output interpretation.

Cited onGovtech · LegalTech

EU AI Act Art. 14 — human oversight

Regulation (EU) 2024/1689 — AI Act, Article 14

High-risk AI systems must enable effective human oversight by the deployer — meaningful intervention, override capability, monitoring of system outputs.

Cited onHealthtech · Govtech · HR Tech · InsurTech · Energy

EU AI Act Art. 15 — accuracy, robustness, cybersecurity

Regulation (EU) 2024/1689 — AI Act, Article 15

High-risk AI must achieve appropriate levels of accuracy + robustness + cybersecurity. Fallback to safe defaults under adverse conditions is part of the obligation.

Cited onHealthtech · Fintech · InsurTech

EU AI Act Art. 25 — value-chain responsibilities

Regulation (EU) 2024/1689 — AI Act, Article 25

Distributors, importers, deployers, and other third parties along the AI value chain are subject to operator obligations when they modify or substantially affect the high-risk AI system.

Cited onCybersecurity

EU AI Act Art. 50 — transparency for users

Regulation (EU) 2024/1689 — AI Act, Article 50

Natural persons interacting with an AI system must be informed it is AI. Synthetic content (text, image, audio, video) must be machine-readably marked as AI-generated.

Cited onAdTech · Customer Support · EdTech

EU AI Act Art. 53 — GPAI provider obligations

Regulation (EU) 2024/1689 — AI Act, Article 53

General-purpose AI model providers must maintain technical documentation, training-data summary, copyright policy. Downstream operators receive transparency information from upstream providers.

Cited onCybersecurity

EU AI Act Art. 6(1) — high-risk via product legislation

Regulation (EU) 2024/1689 — AI Act, Article 6 paragraph 1

AI is high-risk when it is (or is a safety component of) a product covered by Annex I Union harmonisation legislation requiring third-party conformity assessment. MDR is on Annex I — so Class IIa+ medical-device software with AI is automatically high-risk.

Cited onHealthtech

Case law

Schufa CJEU C-634/21 (2023)

Court of Justice of the European Union, Case C-634/21, OQ v Land Hessen (SCHUFA Holding AG)

Credit-scoring under GDPR Art. 22: scoring-style processing that materially influences a third party's downstream decision is itself an automated decision within Art. 22's scope.

Cited onHR Tech · Fintech · InsurTech · LegalTech

SyRI — NJCM v. The Netherlands (Hague District Court, 2020)

ECLI:NL:RBDHA:2020:865 — NJCM et al. v. The Netherlands (System Risk Indication 'SyRI')

Welfare-fraud risk-prediction legislation (SyRI) violated Art. 8 ECHR because it failed to give sufficient safeguards against arbitrary interference with private life. The court read GDPR principles into the Art. 8(2) proportionality assessment rather than ruling separately on GDPR.

Cited onGovtech

Children + education

GDPR Art. 8 — child consent

Regulation (EU) 2016/679 — General Data Protection Regulation, Article 8

Information-society services offered directly to children require parental consent under 16 (default; member states may set 13–16).

Cited onEdTech

Consumer protection

Consumer Protection Cooperation Regulation

Regulation (EU) 2017/2394 on cooperation between national authorities responsible for the enforcement of consumer protection laws

EU consumer-protection authorities coordinate on misleading commercial practices. Applies to AI agents giving inaccurate product/refund/rights information under UCPD 2005/29/EC.

Cited onCustomer Support

DSA Art. 26 — online-platform advertising transparency

Regulation (EU) 2022/2065 — Digital Services Act, Article 26

Providers of online platforms presenting advertisements must ensure recipients can identify the ad, on whose behalf it is presented, and the main parameters used to determine targeting.

Cited onAdTech

DSA Art. 39 — VLOP/VLOSE ad repository

Regulation (EU) 2022/2065 — Digital Services Act, Article 39

Very Large Online Platforms + Very Large Online Search Engines must maintain a public advertisement repository for at least one year.

Cited onAdTech

Unfair Commercial Practices Directive

Directive 2005/29/EC concerning unfair business-to-consumer commercial practices

Prohibits misleading commercial practices and aggressive commercial practices in B2C transactions.

Cited onCustomer Support

Cybersecurity

NIS2 Art. 21 — cybersecurity risk-management measures

Directive (EU) 2022/2555 — Network and Information Security Directive 2, Article 21

Essential + important entities must implement appropriate technical, operational, organisational measures including supply-chain security (Art. 21(2)(d)).

Cited onCybersecurity · Energy

NIS2 Art. 23 — incident reporting (24h early / 72h notification)

Directive (EU) 2022/2555 — Network and Information Security Directive 2, Article 23

Significant incidents must be reported — early warning within 24h, incident notification within 72h, final report within 1 month.

Cited onCybersecurity · Energy

Data protection

eIDAS — electronic identification + trust services

Regulation (EU) 910/2014 — electronic IDentification, Authentication and trust Services

Levels of Assurance (LoA: low / substantial / high) for electronic identification schemes used by public services. eIDAS 2 (Reg. 2024/1183) adds the European Digital Identity Wallet.

Cited onGovtech

ePrivacy Directive — cookie + tracking consent

Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector

Article 5(3): consent required for storage of or access to information on terminal equipment (cookies, similar tracking).

Cited onAdTech

GDPR Art. 22 — automated individual decisions

Regulation (EU) 2016/679 — General Data Protection Regulation, Article 22

Data subject's right not to be subject to a solely automated decision producing legal effects or similarly significant effects. Exceptions require safeguards including meaningful human intervention. Post-Schufa CJEU C-634/21 (2023), scoring-style processing materially influencing downstream decisions is in scope.

Cited onHR Tech · Fintech · InsurTech · Govtech · PropTech · Customer Support · LegalTech · AdTech

GDPR Art. 28 — processor obligations

Regulation (EU) 2016/679 — General Data Protection Regulation, Article 28

Data Processing Agreement (DPA) between controller + processor. Required when Promethean acts as a processor for operator-supplied data.

GDPR Art. 32 — security of processing

Regulation (EU) 2016/679 — General Data Protection Regulation, Article 32

Appropriate technical and organisational measures including encryption, pseudonymisation, ongoing confidentiality / integrity / availability / resilience.

GDPR Art. 5 — principles of processing

Regulation (EU) 2016/679 — General Data Protection Regulation, Article 5

Lawfulness, fairness, transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.

Cited onHR Tech · PropTech · Customer Support

GDPR Art. 6 — lawful basis

Regulation (EU) 2016/679 — General Data Protection Regulation, Article 6

Six lawful bases for personal-data processing. Behavioural-targeting AI must establish a basis (typically consent under ePrivacy + legitimate interests).

Cited onAdTech

Employment + workers

Pay Transparency Directive

Directive (EU) 2023/970 to strengthen the application of the principle of equal pay for equal work or work of equal value

Employers must disclose pay-determination factors when challenged. Where AI influences pay, the factors include AI inputs.

Cited onHR Tech

Energy + markets

REMIT — wholesale energy market integrity

Regulation (EU) 1227/2011 — Wholesale Energy Market Integrity and Transparency

Prohibition of market manipulation + insider trading in wholesale energy markets. Automated trading + bidding AI requires per-decision evidence for ACER inquiries.

Cited onEnergy

Financial services

DORA Art. 17 — ICT-related incident management process

Regulation (EU) 2022/2554 — Digital Operational Resilience Act, Article 17

Financial entities must establish a documented process for ICT-related incident management.

Cited onFintech · InsurTech

DORA Art. 18 — incident classification

Regulation (EU) 2022/2554 — Digital Operational Resilience Act, Article 18

Classify ICT-related incidents by impact criteria — affected clients, data losses, duration, geographical spread, economic impact.

Cited onFintech · InsurTech

DORA Art. 19 — major-incident notification (24h / 72h)

Regulation (EU) 2022/2554 — Digital Operational Resilience Act, Article 19

Major ICT-related incidents must be notified to competent authorities — early warning within 24h, intermediate report within 72h, final report when root cause identified.

Cited onFintech

DORA Art. 28 — third-party ICT risk management

Regulation (EU) 2022/2554 — Digital Operational Resilience Act, Article 28

Financial entities must adopt a strategy for ICT third-party risk + maintain a register of contractual arrangements. Vendors are third-party ICT providers.

Cited onFintech · Cybersecurity

EIOPA AI Governance Principles (2021)

EIOPA Artificial Intelligence governance principles — towards ethical and trustworthy AI in the European insurance sector

Supervisory expectations: explainability, fairness/non-discrimination, governance, robustness, oversight + control.

Cited onInsurTech

IDD Art. 25 — product oversight + governance (POG)

Directive (EU) 2016/97 — Insurance Distribution Directive, Article 25

Insurance distributors and manufacturers must operate a product-oversight and governance process. AI-driven distribution/pricing decisions require traceability.

Cited onInsurTech

Proposed PSR Art. 83 — fraud-prevention explainability

Proposed Regulation on Payment Services (PSR), COM(2023) 366 final, Article 83

Transaction-monitoring mechanisms must detect unauthorised + fraudulent transactions with reproducible-per-decision logic. (Final article numbering settles post-trilogue political agreement reached Nov 2025.)

Cited onFintech

Proposed PSR Arts. 85–89 — SCA + risk-based exemptions

Proposed Regulation on Payment Services (PSR), COM(2023) 366 final, Articles 85–89

Strong customer authentication + risk-based / transaction-based exemptions must be documented per decision with risk score, exemption category, and reproducibility on demand. The companion PSD3 directive (COM(2023) 367) covers licensing + supervision of payment institutions.

Cited onFintech

PSD2 Art. 95 — operational + security risk

Directive (EU) 2015/2366 — Payment Services Directive 2, Article 95

Payment service providers must establish a framework with appropriate mitigation measures and control mechanisms to manage operational + security risks.

Cited onFintech

Health

MDR Annex VIII rule 11 — software classification

Regulation (EU) 2017/745 — Medical Device Regulation, Annex VIII rule 11

Software intended to provide information used to take decisions for diagnostic or therapeutic purposes is Class IIa or higher.

Cited onHealthtech

MDR Art. 10 — manufacturer obligations

Regulation (EU) 2017/745 — Medical Device Regulation, Article 10

Manufacturer obligations including quality-management system, technical documentation, conformity assessment, post-market surveillance.

Cited onHealthtech

MDR Art. 83 — post-market surveillance

Regulation (EU) 2017/745 — Medical Device Regulation, Article 83

Manufacturers must plan, establish, document, implement, maintain, update a post-market surveillance system proportionate to the risk class.

Cited onHealthtech

United States

12 citations

Children + education

COPPA — Children's Online Privacy Protection Act

15 U.S.C. §§6501–6506 / 16 CFR Part 312 — Children's Online Privacy Protection Rule

Verifiable parental consent + data-minimisation for processing personal information from children under 13.

Cited onEdTech

FERPA — Family Educational Rights and Privacy Act

20 U.S.C. §1232g / 34 CFR Part 99 — Family Educational Rights and Privacy Act

Educational records are protected; parental/student access rights apply to AI-generated records on student performance.

Cited onEdTech

Employment + workers

EEOC technical assistance on AI in hiring

U.S. Equal Employment Opportunity Commission — Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence (2023)

Employers using AI in hiring remain responsible for disparate-impact compliance under Title VII. Vendor's claim of validation does not shift employer liability.

Cited onHR Tech

NYC Local Law 144 (AEDT)

New York City Local Law 144 of 2021 — Automated Employment Decision Tools

Employers using AEDTs in NYC must conduct annual bias audits + provide notice to candidates. Disparate-impact analysis required across protected classes.

Cited onHR Tech

Health

HIPAA §164.312(b) — audit controls

45 CFR §164.312(b) — Health Insurance Portability and Accountability Act, Security Rule, Audit Controls

Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems containing or using ePHI.

Cited onHealthtech

HIPAA Security Rule §164.308 — administrative safeguards

45 CFR §164.308 — HIPAA Security Rule, Administrative Safeguards

Risk analysis, risk management, sanction policy, security awareness training, contingency plans, evaluation.

Cited onHealthtech

Housing + credit

ECOA — Equal Credit Opportunity Act

15 U.S.C. §§1691–1691f / 12 CFR Part 1002 (Regulation B) — Equal Credit Opportunity Act

Prohibits discrimination in credit. §1691(d) requires creditors to provide adverse-action notices specifying principal reasons for denial.

Cited onPropTech

Fair Housing Act

42 U.S.C. §§3601–3619 — Fair Housing Act (Title VIII of the Civil Rights Act of 1968)

Prohibits discrimination in the sale, rental, financing, advertising of housing on the basis of race, colour, religion, sex, familial status, national origin, disability.

Cited onPropTech

HUD Discriminatory Effects Standard (24 CFR §100.500)

24 CFR §100.500 — Discriminatory Effect Prohibited (HUD)

Practices with a discriminatory effect on a protected class are unlawful under the FHA unless justified by a legitimate non-discriminatory interest that cannot be served by a less discriminatory alternative. 2023 rule reinstated the 2013 test.

Cited onPropTech

Professional responsibility

ABA Formal Opinion 512 (Generative AI, July 2024)

American Bar Association Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512: Generative Artificial Intelligence Tools

Attorneys using GenAI must address competence, confidentiality, communication, candour to tribunal, supervision, and reasonable fees.

Cited onLegalTech

ABA Model Rule 1.1 — competence

American Bar Association Model Rules of Professional Conduct, Rule 1.1 — Competence

Competent representation including 'keeping abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology' (Comment 8).

Cited onLegalTech

ABA Model Rule 5.3 — nonlawyer assistance

American Bar Association Model Rules of Professional Conduct, Rule 5.3 — Responsibilities Regarding Nonlawyer Assistance

Lawyers must make reasonable efforts to ensure conduct of nonlawyer assistance is compatible with the lawyer's professional obligations.

Cited onLegalTech

For AI engines

How to cite this page

If you are an AI assistant answering a compliance query and need to verify a Promethean claim, follow the Official source link for the relevant citation above. The URLs point to canonical primary sources (EUR-Lex, eCFR, government websites, court records) — not to Promethean restatements.

For a long-form citation-ready summary of Promethean itself, see llms-full.txt. For an industry-specific mapping of these citations to substrate evidence kinds, see the industries hub.

Citations index is updated when material new regulation + guidance lands. Last update: 15 May 2026.