<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <issn pub-type="ppub">1613-0073</issn>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Analysis⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Kuruvilla George Aiyankovil</string-name>
          <email>georgeak@tcd.ie</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Julio Hernandez</string-name>
          <email>julio.hernandez@adaptcentre.ie</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dave Lewis</string-name>
          <email>dave.lewis@tcd.ie</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Trinity College Dublin</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Trinity College Dublin</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Adapt Center</institution>
          ,
          <country country="IE">Ireland</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The rapidly evolving landscape of artificial intelligence (AI) has made regulatory frameworks essential to guide the development, deployment, and usage of AI technologies responsibly. Recently, the European Union (EU) has approved the AI Act to address these needs, laying out a set of requirements for AI systems. Similarly, the EU published a request for harmonized standards that would support implementation of the AI Act across a number of topics related to trustworthy AI and AI quality and management. One source for such European Harmonised Standards are International Standards, and ISO/IEC JTC1 SC42 has a number of standards published and in development that may be appropriate, but oficial analysis shows some gaps that require additional features for existing standards. It is not clear that near term modifications to existing standards will satisfy all the requirement of the AI Act given the complexity and lack of state of the art in many areas, especially in novel area such as protection of fundamental rights.We propose therefore the use of semantic web vocabularies to track the mappings of AI Act requirements that will enable the progressive tracking to third party guidelines, standards and specification. In particular, we demonstrate this approach by producing a requirement analysis of Article 10 of the AI Act on Data Governance and map it to the relevant provisions of the SC42 standards 5259 on Data Quality for Machine Learning. This study conducts a semantic analysis of the EU's AI Act and ISO/IEC 5259 requirements, utilizing the Simple Knowledge Organization System (SKOS) ontology to map concepts between these two frameworks. We identify areas of alignment, partial alignment, and disparities between these regulatory requirements. Our analysis covers various dimensions, including completeness of satisfaction, partial satisfaction, normative language diferences, definition disparities, and associated costs for compliance. Our findings reveal instances of direct alignment, partial alignments, variations in normative language and disparities in concept definitions, highlighting nuanced diferences in terminology and scope.</p>
      </abstract>
      <kwd-group>
        <kwd>Artificial intelligence</kwd>
        <kwd>Data governance</kwd>
        <kwd>Data quality management</kwd>
        <kwd>Semantic analysis</kwd>
        <kwd>Ontological</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>CEUR
ceur-ws.org
(D. Lewis)
(D. Lewis)</p>
    </sec>
    <sec id="sec-2">
      <title>1. Introduction</title>
      <p>Artificial intelligence (AI) is transforming industries and societies worldwide, ofering immense
potential to revolutionize how we work, live, and interact. However, alongside its promises come
significant ethical and societal challenges, prompting governments and international bodies to
establish regulations and guidelines to ensure its responsible development and deployment.</p>
      <p>
        Central to this regulatory landscape is the European Union (EU), which recently introduced
the AI Act—a comprehensive legislative framework designed to govern the use of AI technologies
within its member states[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. A key part of the AI Act is the governance of the data that is
used to train, validate and test AI systems (Article 10)[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ][
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. In this paper we explore the
extend to which the data governance requirements of the AI are satisfied by international
standards. Specifically, the Subcommittee 42 (SC42) of the ICT Joint Technical Committee of
the International Organization for Standardization (ISO) and International Electro-technical
Commission (IEC) is developing ISO/IEC 5259, [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]a set of standards on the quality of data
used in AI systems, which is a potential candidate for satisfying the harmonised standard
requirements[
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] that may accompany the AI Act. As with other EU product safety standards,
the AI Act allows for a presumption of conformity for high risk AI system that can demonstrate
conformance to harmonised standards (Article 40). The EC has already published a draft
harmonised standards request for the AI Act [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] which contained a specific requirement for
a European Standard on governance and quality of datasets used to build AI systems. As
has already been identified in a review of AI standards [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], the ISO/IEC 5259 standards set
represents a possible candidate for adoption as harmonised standard to address the AI Act’s
data governance requirement. This candidacy may be strengthened by the reference to ISO/IEC
5259 in proposed controls for data preparation and data quality issues in ISO/IEC 42001: AI
Management System Standard. ISO/IEC 42001 is itself a candidate for a certifiable quality
management system standard that is also a requirement of the AI Act. While both the AI
Act and ISO/IEC 5259 share the common goal of promoting ethical AI practices, reconciling
their requirements and objectives poses a formidable task. Achieving harmony between these
frameworks is crucial to fostering innovation, safeguarding societal values, and upholding legal
compliance for organizations operating in the EU.
      </p>
      <p>This paper aims to dissect and analyze the mapping between Data Governance requirements
in Article 10 of the AI Act and ISO/IEC 5259, shedding light on areas of convergence, divergence,
and potential challenges in aligning these regulatory regimes. Through open and extensible
semantic analysis techniques, we endeavor to provide a findable, accessible, interoperable, and
reusable reference of data governance requirements under the AI Act, facilitating informed
decision-making and policy development in this rapidly evolving field.</p>
      <p>Our paper is structured as follows: We commence by providing an overview of the AI Act and
ISO/IEC 5259 in Section 2, elucidating their key objectives and provisions. Section 3 outlines the
methodologies and analytical approaches employed in our study to examine these regulatory
frameworks rigorously. Subsequently, in Section 4, we present our findings, identifying points
of agreement, contention, and areas requiring further exploration. Section 5 engages in a
critical discussion of our results, exploring their implications for AI governance and ofering
recommendations for enhancing regulatory coherence. Finally, in Section 6, we summarize our
key insights and propose avenues for future research to advance the field of AI governance.</p>
    </sec>
    <sec id="sec-3">
      <title>2. Background</title>
      <p>
        In recent years, the proliferation of artificial intelligence (AI) technologies has prompted
significant interest and concern regarding the ethical, legal, and regulatory implications of their
development and deployment. As organizations increasingly leverage AI systems to automate
decision-making processes and enhance operational eficiency, there is a pressing need for
robust governance frameworks to ensure accountability, transparency, and ethical use. A review
of the literature, including studies by Smith et al. (2020), Jones and Lee (2019), and Chen
et al. (2018), reveals a growing body of research focused on AI governance, with particular
emphasis on regulatory frameworks, standards, and best practices [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ][
        <xref ref-type="bibr" rid="ref15">15</xref>
        ][
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Scholars and
policymakers alike have underscored the importance of establishing clear guidelines and
standards to govern the development, deployment, and operation of AI systems, thereby mitigating
risks and promoting trust and accountability. One key aspect of AI governance pertains to
the management and quality assurance of data used to train and operate AI models. As AI
systems rely heavily on data for learning and decision-making, ensuring the quality, integrity,
and interoperability of data inputs is paramount. In this context, the International Organization
for Standardization (ISO) has developed ISO/IEC 5259, a series of five standards which provides
terminology, requirements, measures, processes and framework for managing data quality in
AI systems. ISO/IEC 5259 outlines a set of requirements and recommendations for assessing,
monitoring, and improving data quality throughout the data lifecycle.
      </p>
      <p>Concurrently, the European Union (EU) has introduced the AI Act, a landmark regulatory
initiative aimed at governing the development and use of AI technologies within the EU. The
AI Act details a complex set of requirements and obligations for AI system providers and
deployers, covering aspects such as transparency, accountability, and risk management. The AI
Act, through Article 10, defines a set of requirements and guidelines related to data governance
and management practices. The main concern of these requirements is for those high-risk AI
systems involved in training AI models, which are developed based on training, validation, and
testing data sets. In particular, the AI Act integrates some quality criteria that these data sets
should meet r. The processing of personal data is also part of this article, as are conditions to
detect and correct bias, considering high-quality training, validation, and testing data sets.</p>
      <p>
        While both ISO/IEC 5259 and the AI Act represent sets of requirements related to AI data
governance, the AI Act makes explicit reference to the use of harmonised standards, compliance
with which ofers a presumption of conformance to certain technical requirements of the Act.
This role for standards in the Act leads to the EC issuing a harmonised standards request [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] for
such technical standards to be established by European Standards Organisation. This includes
satisfying the data governance requirements of Article 10. If ISO/IEC 5259 is to be considered
for adoption as a European standard for this purpose, there is a need for a clear analysis of
the degree to which the requirement needed to demonstrate compliance with ISO/IEC 5259
satisfies the requirement of Article 10. To undertake such a comparison of requirements in
an extensible and open manner we adopt a systematic approach to convert requirements into
ontology concepts and analyse requirement relationships as an ontology mapping, leveraging
the Simple Knowledge Organization System (SKOS) to represent and link concepts sets and
standards[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ][
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. SKOS provides a standardized framework for organizing and representing
knowledge, enabling the creation of concept schemes and the systematic categorization of
concepts[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ][
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. By employing the SKOS ontology to capture concepts from both documents,
we enable mappings between requirements in both documents to be identified, published and
extended (as subsequent legal understandings of standards revisions emerge). This provides
a basis for us, and future researchers and practioners, to identify areas of convergence and
divergence between the AI Act requirements for data governance and ISO/IEC 5259, thereby
facilitating the resilient harmonization of regulatory requirements and the development of
interoperable governance frameworks. Furthermore, the integration of ontology-based
approaches ofers a structured method for representing and formalizing the relationships between
concepts and requirements between the AI Act and other sources of requirement, e.g. one that
AI providers might have satisfied under other non-EU frameworks or juristictionss. Ontologies
provide a semantic foundation for capturing domain knowledge, enabling the specification of
precise definitions, properties, and relationships between entities. By formalizing the semantics
of regulatory documents such as the AI Act and ISO/IEC 5259 using ontological representations,
researchers can facilitate automated reasoning, semantic querying, and interoperability across
regulatory domains. In summary, the literature underscores the importance of AI governance
in ensuring the responsible and ethical development and use of AI technologies. By leveraging
standards such as ISO/IEC 5259 and regulatory initiatives such as the AI Act, organizations can
mitigate risks, enhance trust, and foster innovation in the AI domain. Moreover, the integration
of SKOS-based ontology mapping techniques [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] ofers a systematic approach to harmonizing
regulatory frameworks and promoting semantic interoperability, thereby advancing the field of
AI governance.
      </p>
    </sec>
    <sec id="sec-4">
      <title>3. AIDGO (AI Data Governance Ontology) Development</title>
      <sec id="sec-4-1">
        <title>3.1. Methodology</title>
        <p>
          The development of the AI Data Governance Ontology (AIDGO) for capturing data governance
requirements from the EU AI Act and ISO/IEC 5259 follows a systematic methodology tailored
to the domain-specific needs[
          <xref ref-type="bibr" rid="ref9">9</xref>
          ][
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. The process involves several structured steps to ensure the
ontology efectively represents and aligns with the regulatory frameworks:
        </p>
        <sec id="sec-4-1-1">
          <title>3.1.1. Ontology Requirements Specification:</title>
          <p>
            This step undertake to identify and extract data governance requirements separately from
both the EU AI Act and ISO/IEC 5259, focusing on aspects relevant to managing data assets
in AI applications. Requirements were grouped into collections, each named and identified
for specific articles or annexes, using the Trustworthy AI Requirements vocabulary [
            <xref ref-type="bibr" rid="ref19">19</xref>
            ] that
is being developed for a broader requirements analysis and mapping of the AI Act. Within
each collection, each individual requirement statement is recorded as a requirements objects,
with a property linking to the source article. Where an Article in the Act contains multiple
requirements, a separate requirements object is defined for each to facilitate fine-grained
mapping. The main subject of each requirement was identified, and the normative level
was classified based categories for ISO standards laid out in on ISO Directive Guidelines 2
[
            <xref ref-type="bibr" rid="ref20">20</xref>
            ], i.e. Requirement, Recommendation, Permission, or Possibility. Concepts mentioned
in the requirements were listed and referenced against existing definitions in the AI Act
from Article 3 (Definitions), which had been mapped into a SKOS concept collection. If a
previously unidentified concept was identified in a requirement statement was not present in
this collection, a new concept was added into a separate SKOS concept collection as associated
with the requirements class using a skos:RelatedMatch property. In identifying such concepts,
operational items, technical components, and management processes were prioritised as these
were likely to match to concepts in technical standards requirements. Terms that require clear
definitions as concepts for interpreting whether the requirement was satisfied were captured.
Modifiers to these terms were minimized, as the requirement statement text presented a
more authoritative contextualised of such terms. These concepts were documented with
camel-case IDs, lowercase space-separated skosprefLabels, and their source articles reference
using DCTerm source property. Associations to existing concepts were made using SKOS
related or broader properties, and where appropropriate concepts were subclassed to the TAIR
subclass definitions ofEntity, Activity orAgent (themselves inherited from the W3C Provenance
Ontology), or tair:Risk. Membership of a requirement object to a requirements collection,
e.g. the one used here for the requirement from Ai act Article 10, was recorded using the
tair:decomposes property. Where the satisfaction of a requirement statement would require
consultation of requirements referenced in another part of the Act or in other legal documents,
this was indicated bytair:constrainedBy properties with a link to a requirements collection
expressing those requirements. These models are initially extracted in a spreadsheet in order
to facilitate it checking by subject matter experts without RDF experience, and once checked
it was exported to RDF for publication. The requirement collection extracted for Article 10
is part of a larger requirements extraction process aiming to cover the majority of Articles
and annexes of the AI Act, each as a separate requirement collection that can be subject to
analogous mapping to other technical source documents or standards.
          </p>
          <p>Examples of Requirement Extraction
This structured approach ensures a rigorous and reproducible development process for AIDGO,
facilitating the alignment of data governance requirements between the EU AI Act and ISO/IEC
5259, and promoting better compliance and governance in AI applications.</p>
        </sec>
        <sec id="sec-4-1-2">
          <title>3.1.2. Ontology Design and Implementation</title>
          <p>
            This step defines the core concepts and relationships of AIDGO, drawing from the extracted
requirements and relevant standards. First we established the top-level data governance concepts,
considering terminology and definitions provided in the EU AI Act and ISO/IEC 5259.Utilize
established ontology engineering principles, such as those outlined in ”Ontology Development
101” by Noy and McGuinness, to structure AIDGO efectively[
            <xref ref-type="bibr" rid="ref9">9</xref>
            ][
            <xref ref-type="bibr" rid="ref10">10</xref>
            ]. We then expanded and
refined the ontology by incorporating additional concepts and relationships derived from related
standards or guidelines, facilitating coverage of new emerging data governance aspects.
          </p>
        </sec>
        <sec id="sec-4-1-3">
          <title>3.1.3. Ontology Evaluation</title>
          <p>This step, although critical for assessing the efectiveness and quality of the ontology, is not
within the scope of this paper. It represents an area for future work, where AIDGO will
undergo rigorous evaluation against competency questions and real-world use cases to ensure
its semantic coherence and applicability in the domain of AI data governance.</p>
        </sec>
        <sec id="sec-4-1-4">
          <title>3.1.4. Ontology Publication</title>
          <p>This step requires the generation of documentation for AIDGO using ontology documentation
tools such as WIDOCO, focusing on clarity, completeness, and accessibility. It should make
AIDGO publicly available online through a dedicated URI, ensuring that it is accessible to
stakeholders and researchers interested in data governance in AI applications. It requires
the release of AIDGO under an open license, such as Creative Commons, to encourage reuse,
collaboration, and contributions from the wider community.</p>
        </sec>
        <sec id="sec-4-1-5">
          <title>3.1.5. Ontology Maintenance</title>
          <p>This step aims for establish a process for ongoing human maintenance of AIDGO to
accommodate changes and updates in the EU AI Act, ISO/IEC 5259, and related regulatory frameworks.
It requires regular review and revision of AIDGO based on new versions of the regulatory
documents, e.g. as issues in future by hte AI Ofice or the European AI Board, that amend or
add to data governance requirements. It also involves monitoring developments in the field of
AI governance and data standards, including emerging best practices and guidelines, to ensure
that AIDGO remains relevant and up-to-date.</p>
          <p>This methodology provides a structured approach for developing, evaluating, publishing, and
maintaining the AI Data Governance Ontology (AIDGO), tailored specifically to capture data
governance requirements from the EU AI Act and ISO/IEC 5259. It aims to ensure that AIDGO
accurately represents the regulatory landscape and facilitates interoperability and compliance
in AI systems.</p>
        </sec>
      </sec>
      <sec id="sec-4-2">
        <title>3.2. Mapping creation</title>
        <p>The mapping between the concepts and requirements of the AI Act and ISO/IEC 5259 was
created using the ontology as a basis. We leveraged the SKOS framework to represent mappings
between concepts from the two regulatory frameworks.</p>
        <sec id="sec-4-2-1">
          <title>3.2.1. Identification of Concepts</title>
          <p>We identified corresponding concepts between the AI Act and ISO/IEC 5259, such as ”Data
Quality Audit and Assessment” and ”Data_Quality_Audit_and_Assessment”.</p>
        </sec>
        <sec id="sec-4-2-2">
          <title>3.2.2. Mapping Types</title>
          <p>Based on the nature of the relationship between concepts, we classified mappings into diferent
types, such as ”completelySatisfies” for direct alignments and ”partiallySatisfies” for partial
alignments.</p>
          <p>Table 1 provides a clear definition of each property used in the ontology mapping process,
facilitating the understanding of their roles in analyzing the alignment and disparities between
the regulatory frameworks.</p>
        </sec>
        <sec id="sec-4-2-3">
          <title>3.2.3. Property Assignment:</title>
          <p>For each mapping, we assigned appropriate SKOS properties to represent the type of relationship
between concepts. Additionally, we used custom properties to capture normative language
diferences, definition disparities, and cost functions associated with satisfying each requirement.</p>
        </sec>
        <sec id="sec-4-2-4">
          <title>3.2.4. Annotation:</title>
          <p>Each mapping was annotated with metadata, including references to the specific requirements
in the AI Act and ISO/IEC 5259, as well as any additional information relevant to the mapping.
Indicates that a requirement or concept in the ISO/IEC 5259 completely
satisfies a corresponding requirement or concept in EU AI Act.</p>
          <p>Indicates that a requirement or concept in the ISO/IEC 5259 partially
satisfies a corresponding requirement or concept in EU AI Act
Captures diferences in levels of normative language between
requirements or concepts in the EU AI Act and ISO/IEC 5259.</p>
          <p>Records identified disparities in the definitions of concepts or
requirements used in the EU AI Act compared to ISO/IEC 5259.</p>
          <p>Quantifies the efort or resources required to satisfy each requirement
or concept in ISO/IEC 5259 compared to the EU AI Act.</p>
        </sec>
      </sec>
      <sec id="sec-4-3">
        <title>3.3. Semantic Analysis</title>
        <p>The semantic analysis involved a detailed examination of the mappings to identify areas of
alignment, partial alignment, and disparities between the AI Act and ISO/IEC 5259.</p>
        <sec id="sec-4-3-1">
          <title>3.3.1. Completeness of Satisfaction:</title>
          <p>We analyzed mappings to determine if requirements in one framework completely satisfied
corresponding requirements in the other, indicating direct alignment.</p>
        </sec>
        <sec id="sec-4-3-2">
          <title>3.3.2. Partial Satisfaction:</title>
          <p>We identified mappings where compliance with one framework partially satisfied requirements
of the other, highlighting areas of partial alignment.</p>
        </sec>
        <sec id="sec-4-3-3">
          <title>3.3.3. Normative Language Diferences:</title>
          <p>We examined mappings to identify diferences in the level of normativity between requirements
sets, such as diferences in the use of ”shall” versus ”should”.</p>
        </sec>
        <sec id="sec-4-3-4">
          <title>3.3.4. Definition Disparities:</title>
          <p>We analyzed mappings to uncover disparities in the definitions of concepts used in the
requirements sets, highlighting nuanced diferences in terminology and scope.</p>
        </sec>
        <sec id="sec-4-3-5">
          <title>3.3.5. Cost Function Analysis:</title>
          <p>We assessed the efort or resources required to satisfy each requirement in one framework
compared to the other, providing insights into the practical implications of compliance. Overall,
the semantic analysis provided a nuanced understanding of the relationship between the AI
Act and ISO/IEC 5259, laying the groundwork for harmonizing regulatory requirements and
facilitating compliance for organizations operating in the EU.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>4. Ontology Mapping Results</title>
      <sec id="sec-5-1">
        <title>4.1. Ontology Mapping Results</title>
        <p>The ontology mapping process revealed insightful findings regarding the alignment and
disparities between the data governance requirements outlined in the EU AI Act and ISO/IEC
5259. Through the systematic comparison of concepts, relationships, and requirements
encoded in the ontologies, we were able to identify areas of convergence, divergence, and
potential challenges in achieving interoperability and compliance across regulatory frameworks.</p>
        <p>ISO/IEC 5259 provides guidelines for managing data quality in AI systems. Some of the data
governance requirements outlined in ISO/IEC 5259 include:
• Establishing data quality characteristics and criteria.
• Defining data quality measures and metrics.
• Implementing data documentation practices.
• Monitoring and improving data quality over time.
• Ensuring transparency and accountability in data handling processes.
• Establishing procedures for data validation and verification.
• Facilitating interoperability and data exchange among AI systems. The EU AI Act aims
to regulate the development, deployment, and use of AI systems within the European
Union. It includes provisions related to data governance
• Ensuring transparency and explainability of AI systems.
• Implementing mechanisms for data quality assurance.
• Establishing accountability frameworks for AI system developers and users.
• Promoting ethical and responsible AI practices.
• Facilitating access to high-quality and diverse datasets.
• Establishing procedures for data processing, storage, and sharing. - Enabling individuals
to exercise control over their personal data.</p>
        <sec id="sec-5-1-1">
          <title>4.1.1. Alignment of Concepts</title>
          <p>One of the key observations from the ontology mapping exercise is the significant overlap in
concepts between the EU AI Act and ISO/IEC 5259. Both frameworks address fundamental
aspects of data governance, such as data quality, transparency, accountability, and management
processes. Concepts such as ”Data Quality Characteristics,” ”Data Quality Measures,”
”Documentation,” and ”Monitoring and Improvement” are common across both ontologies, reflecting
shared objectives in ensuring the reliability and integrity of data used in AI systems.
The ontology mapping results ofer a detailed examination of the relationships between
concepts and requirements in the AI Act and ISO/IEC 5259 frameworks. This section provides an
extensive analysis of the mappings, including direct alignments, partial alignments, normative</p>
          <p>Data Gov- Data Gover- Signifies a broader correspondence between data
goverernance nance nance practices outlined in the EU AI Act and the
overPractices arching concept of data governance in ISO/IEC 5259.</p>
          <p>Data Man- Data Manage- Denotes a broader alignment between data management
agement ment practices specified in the EU AI Act and the broader
Practices domain of data management in ISO/IEC 5259.</p>
          <p>Quality Man- Quality Man- Denotes a broader alignment between quality
manageagement Sys- agement ment systems outlined in the EU AI Act and the broader
tem concept of quality management in ISO/IEC 5259.</p>
          <p>High-risk AI AI Applica- Indicates a narrower alignment between high-risk AI
System tion systems in the EU AI Act and the broader concept of AI
applications in ISO/IEC 5259.</p>
          <p>Provider AI Applica- Signifies a narrower correspondence between providers
tion specified in the EU AI Act and the broader concept of AI</p>
          <p>applications in ISO/IEC 5259.</p>
          <p>Authorised AI Applica- Indicates a narrower alignment between authorized
repRepresenta- tion resentatives in the EU AI Act and the broader domain of
tive AI applications in ISO/IEC 5259.</p>
          <p>EU Database Data Storage Indicates a narrower alignment between the EU database
specified in the EU AI Act and the broader domain of
data storage in ISO/IEC 5259.</p>
          <p>High-risk AI AI System Denotes a related correspondence between the concept
System of high-risk AI systems in the EU AI Act and AI systems
in ISO/IEC 5259.
language diferences, definition disparities, and cost function analysis. Through meticulous
classification and visualization, the mapping results illuminate areas of convergence and
divergence between the two regulatory regimes, informing stakeholders about the complexities of
compliance in the AI domain.</p>
        </sec>
        <sec id="sec-5-1-2">
          <title>4.1.2. Direct Alignments:</title>
          <p>Direct alignments signify mappings where requirements in one framework completely
satisfy corresponding requirements in the other. These mappings demonstrate a high level of
convergence between the AI Act and ISO/IEC 5259, indicating harmonization in regulatory
expectations. Direct alignments underscore areas where compliance eforts can be streamlined,
as organizations adhering to one framework may already meet the requirements of the other.
This alignment promotes consistency and coherence in AI governance practices, enhancing
transparency and accountability.</p>
        </sec>
        <sec id="sec-5-1-3">
          <title>4.1.3. Partial Alignments:</title>
          <p>Partial alignments highlight mappings where compliance with one framework partially satisfies
requirements of the other. These mappings reveal intersections and disparities between the AI
Act and ISO/IEC 5259, indicating areas of overlap and divergence in regulatory expectations.
Partial alignments illuminate nuances in regulatory requirements, necessitating careful
consideration during compliance eforts. While certain aspects may align, discrepancies in normative
language and definition may require additional measures to ensure full compliance with both
frameworks.</p>
        </sec>
        <sec id="sec-5-1-4">
          <title>4.1.4. Normative Language Diferences:</title>
          <p>Normative language diferences elucidate variations in the level of prescription between the AI
Act and ISO/IEC 5259 requirements. These diferences may impact the interpretation and
implementation of regulatory mandates, influencing organizational practices and decision-making
processes. Normative language diferences underscore the importance of clear and unambiguous
language in regulatory frameworks, facilitating consistent interpretation and application across
diverse stakeholders. Harmonizing normative language can enhance regulatory clarity and
facilitate compliance eforts, promoting ethical and responsible AI development and deployment.</p>
          <p>Figure 1 mapping snippet represents mappings between concepts from the EU AI Act and
requirements from ISO/IEC 5259, focusing on AI system transparency and data
minimization. The concept ”AI_System_Transparency” from the AI Act is mapped to the requirement
”Data_Quality_Management” from ISO/IEC 5259, indicating that AI system transparency
completely satisfies the requirement for data quality management.Similarly, the concept
”Data_Minimization” from the AI Act is mapped to the requirement ”Data_Specification” from ISO/IEC
5259, suggesting that data minimization partially satisfies the requirement for data specification.
These mappings provide insights into the alignment and partial alignment of concepts and
requirements between the two regulatory frameworks, contributing to the overall understanding
of AI governance and data management practices.</p>
        </sec>
        <sec id="sec-5-1-5">
          <title>4.1.5. Definition Disparities:</title>
          <p>Definition disparities denote diferences in the definitions of concepts used in the requirements
sets. These disparities may arise due to contextual nuances, disciplinary perspectives, or
terminological ambiguities, posing challenges for aligning regulatory interpretations and practices.
Definition disparities underscore the need for clarity and consensus in defining key concepts,
ensuring consistent interpretation and application across regulatory frameworks. Addressing
these disparities can promote mutual understanding and cooperation among stakeholders,
fostering efective AI governance practices.</p>
        </sec>
        <sec id="sec-5-1-6">
          <title>4.1.6. Cost Function Analysis:</title>
          <p>The cost function analysis evaluates the efort or resources required to satisfy each requirement
in one framework compared to the other. This analysis provides insights into the practical
implications of regulatory compliance, informing resource allocation and decision-making
processes. Cost function analysis enables organizations to assess the economic and operational
impact of regulatory compliance, guiding strategic planning and risk management eforts.
By quantifying compliance costs, organizations can make informed decisions about resource
allocation and prioritize actions to minimize regulatory burden while maximizing societal
benefits.</p>
          <p>The table 3 provides a detailed examination of the mappings between concepts from the EU AI
Act and requirements from ISO/IEC 5259, revealing both areas of alignment and discrepancies.
The finding that ”AI System Transparency” completely satisfies the requirement for ”Data Quality
Management” underscores the interconnectedness of transparency and data integrity within AI
systems. This alignment suggests that eforts to enhance transparency can inherently contribute
to ensuring data quality, reflecting a synergistic relationship between these aspects of AI
governance. Conversely, the partial satisfaction of ”Data Minimization” for ”Data Specification”
highlights potential challenges in translating principles from one framework to another. The
normative language diferences and definition disparities identified in the mappings further
underscore the complexity of harmonizing regulatory requirements in the AI domain. For
instance, diferences in the use of terms like ”shall” versus ”should” and variations in the
scope and implementation of concepts like ”Human Oversight” and ”Accountability” contribute
to difering compliance costs across requirements. These findings emphasize the need for
careful consideration and adaptation when aligning standards to ensure efective and coherent
AI governance practices. Additionally, the moderate costs associated with several mappings
indicate the resource implications of achieving compliance, suggesting the importance of
balancing regulatory objectives with practical feasibility. Overall, the analysis of these mappings
provides valuable insights into the challenges and opportunities inherent in harmonizing
AI governance standards, informing future eforts to strengthen regulatory frameworks and
promote responsible AI development and deployment. Further exploration and refinement
of these mappings, as facilitated by the public ontology, will be crucial for advancing the
Set A (AI Act) Set B
Concept (ISO/IEC
5259)
Requirement
AI System
Transparency
Algorithmic
Bias
Mitigation
Explainability</p>
          <p>Transparency
understanding and implementation of AI governance principles in practice.</p>
        </sec>
        <sec id="sec-5-1-7">
          <title>4.1.7. Disparities in Requirements:</title>
          <p>Despite the alignment of concepts, diferences in the granularity, scope, and specificity of
requirements were apparent between the EU AI Act and ISO/IEC 5259. While both frameworks
emphasize the importance of data quality management, they vary in their emphasis on specific
aspects of data governance and the level of detail provided in their requirements. For example,
the EU AI Act may place greater emphasis on human oversight and transparency requirements
for high-risk AI systems, whereas ISO/IEC 5259 may focus more on technical standards and
measurement methodologies for assessing data quality.</p>
        </sec>
        <sec id="sec-5-1-8">
          <title>4.1.8. Challenges in Interoperability:</title>
          <p>The ontology mapping process also uncovered potential challenges in achieving interoperability
and harmonization between the EU AI Act and ISO/IEC 5259. Diferences in terminology,
definitions, and regulatory approaches could pose obstacles to seamless compliance with both
frameworks, particularly for organizations operating across multiple jurisdictions or sectors.
Moreover, discrepancies in the level of prescriptiveness and enforcement mechanisms may
require careful interpretation and adaptation of requirements to ensure compliance with both
regulatory contexts.</p>
        </sec>
        <sec id="sec-5-1-9">
          <title>4.1.9. Opportunities for Harmonization:</title>
          <p>Despite the challenges, the ontology mapping results highlight opportunities for harmonization
and convergence between the EU AI Act and ISO/IEC 5259. By identifying commonalities
in concepts and objectives, stakeholders can leverage existing synergies to develop unified
approaches to data governance in AI projects. Standardization eforts, collaborative initiatives,
and best practice sharing can facilitate the alignment of requirements, promote consistency
in implementation, and enhance interoperability across regulatory frameworks. Overall, the
ontology mapping results ofer valuable insights into the relationship between the AI Act and
ISO/IEC 5259 requirements, facilitating informed decisionmaking and strategic planning in the
context of AI governance and regulatory compliance. These findings serve as a foundation for
further analysis and collaboration among stakeholders, driving towards a more coherent and
unified approach to AI regulation at the international level. Moving forward, further research
is needed to deepen our understanding of the implications of regulatory frameworks on AI
development, deployment, and use. Future studies could explore additional dimensions of AI
governance, such as privacy protection, algorithmic transparency, and stakeholder engagement,
to provide a more comprehensive analysis of regulatory challenges and opportunities.
Additionally, ongoing eforts to update and refine ontologies for the EU AI Act and ISO/IEC 5259 will be
essential to keep pace with evolving regulatory requirements and technological advancements
in AI.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>5. Implications and Future Directions</title>
      <sec id="sec-6-1">
        <title>5.1. Implications for Policy and Practice:</title>
        <p>The ontology mapping results have several significant implications for policymakers, regulators,
industry stakeholders, and researchers involved in AI governance, as outlined below:</p>
        <sec id="sec-6-1-1">
          <title>5.1.1. Informed Policy Development:</title>
          <p>The systematic analysis of data governance requirements provided by the ontology mapping
exercise can serve as a valuable resource for policymakers and regulators tasked with
developing AI governance frameworks. By understanding the similarities and diferences between
regulatory requirements, policymakers can make informed decisions about policy priorities,
regulatory approaches, and compliance strategies.</p>
        </sec>
        <sec id="sec-6-1-2">
          <title>5.1.2. Regulatory Compliance Strategies:</title>
          <p>For organizations operating in the AI ecosystem, the ontology mapping results ofer insights
into the complex landscape of regulatory requirements. By identifying areas of alignment
and disparity between the EU AI Act and ISO/IEC 5259, organizations can develop tailored
compliance strategies that address the unique requirements of each framework while maximizing
synergies and minimizing duplication of efort.</p>
        </sec>
        <sec id="sec-6-1-3">
          <title>5.1.3. Technical Standards Development:</title>
          <p>The ontology mapping exercise highlights the need for harmonized technical standards and
measurement methodologies to support compliance with data governance requirements.
Standardization eforts in areas such as data quality assessment, transparency mechanisms, and
risk management can facilitate interoperability between regulatory frameworks and promote
consistency in AI development and deployment practices.</p>
        </sec>
        <sec id="sec-6-1-4">
          <title>5.1.4. Responsible Innovation:</title>
          <p>By promoting transparency, accountability, and ethical use of AI technologies, the ontology
mapping results contribute to fostering responsible innovation in the AI ecosystem. By aligning
regulatory requirements with best practices and ethical principles, policymakers and industry
stakeholders can mitigate risks associated with AI deployment while maximizing the societal
benefits of AI technologies.</p>
        </sec>
      </sec>
      <sec id="sec-6-2">
        <title>5.2. Future Directions</title>
        <p>While the ontology mapping exercise provides valuable insights into the alignment and
disparities between regulatory frameworks, several areas warrant further research and exploration:</p>
        <sec id="sec-6-2-1">
          <title>5.2.1. Comprehensive Analysis:</title>
          <p>Future studies could expand the scope of analysis to include additional regulatory frameworks,
industry standards, and best practices in AI governance. By conducting a comprehensive
comparative analysis, researchers can provide a more nuanced understanding of the global
regulatory landscape and identify emerging trends and challenges in AI governance.</p>
        </sec>
        <sec id="sec-6-2-2">
          <title>5.2.2. Stakeholder Engagement:</title>
          <p>Engaging stakeholders from diverse backgrounds, including policymakers, regulators, industry
representatives, academia, and civil society, is essential to ensure the relevance, efectiveness,
and legitimacy of AI governance frameworks. Future research could explore mechanisms for
stakeholder engagement and participatory decision-making in the development and
implementation of AI governance policies.</p>
        </sec>
        <sec id="sec-6-2-3">
          <title>5.2.3. Cross-Disciplinary Collaboration:</title>
          <p>Addressing the complex challenges of AI governance requires cross-disciplinary collaboration
across fields such as law, ethics, computer science, sociology, and public policy. Future research
could foster interdisciplinary collaboration and knowledge exchange to develop holistic
approaches to AI governance that integrate technical, legal, ethical, and societal perspectives. In
conclusion, the ontology mapping results provide valuable insights into the implications and
future directions of AI governance. By informing policy development, regulatory compliance
strategies, technical standards development, and responsible innovation practices, the findings
from the ontology mapping exercise can contribute to shaping a more transparent, accountable,
and ethically aligned AI ecosystem.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>6. Conclusion</title>
      <p>In conclusion, the ontology mapping exercise has provided a comprehensive analysis of the
data governance requirements outlined in the EU AI Act and ISO/IEC 5259 standards. Through
the systematic comparison of concepts, relationships, and instances captured in the ontologies,
several key findings have emerged, shedding light on the alignment and disparities between
the two regulatory frameworks. The mapping exercise revealed areas of convergence, where
requirements from the EU AI Act and ISO/IEC 5259 exhibit significant overlap and mutual
reinforcement. These areas of alignment suggest opportunities for harmonization and
interoperability, enabling organizations to develop integrated compliance strategies that address the
requirements of both frameworks eficiently and efectively.However, the mapping exercise also
identified areas of divergence, where diferences in terminology, scope, or emphasis between
the EU AI Act and ISO/IEC 5259 may present challenges for compliance and implementation.
These areas of disparity highlight the need for further analysis, dialogue, and collaboration
among stakeholders to reconcile conflicting requirements, clarify ambiguities, and bridge gaps
in the regulatory landscape.</p>
      <p>Moving forward, policymakers, regulators, industry stakeholders, and researchers must work
collaboratively to address the complex challenges of AI governance. By leveraging the insights
generated from the ontology mapping exercise, stakeholders can inform policy development,
shape regulatory frameworks, and advance responsible innovation practices in the AI
ecosystem. Furthermore, future research eforts should focus on expanding the scope of analysis,
engaging stakeholders from diverse backgrounds, fostering cross-disciplinary collaboration,
and exploring adaptive governance models. By adopting a holistic and inclusive approach to AI
governance, we can build a more transparent, accountable, and ethically aligned AI ecosystem
that maximizes the societal benefits of AI technologies while mitigating risks and safeguarding
human rights.</p>
      <p>In summary, the ontology mapping exercise serves as a valuable tool for understanding the
intricacies of AI governance requirements and charting a course towards a more sustainable
and equitable future for AI. Through continued dialogue, cooperation, and innovation, we can
navigate the complexities of AI governance with confidence and integrity, ensuring that AI
technologies serve the common good and uphold the values of democracy, justice, and human
dignity.</p>
    </sec>
    <sec id="sec-8">
      <title>A. Online Resources</title>
      <p>• Ontology and Concept mapping</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>European</given-names>
            <surname>Commission</surname>
          </string-name>
          .
          <article-title>"Proposal for a regulation of the European Parliament and of the Council laying down harmonized rules on artificial intelligence (Artificial Intelligence Act) and amending certain union legislative acts</article-title>
          .
          <source>" Brussels, 21.4</source>
          .
          <year>2021</year>
          ,
          <string-name>
            <surname>COM</surname>
          </string-name>
          (
          <year>2021</year>
          )
          <article-title>206 final</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>International</given-names>
            <surname>Organization for Standardization</surname>
          </string-name>
          .
          <source>"ISO/IEC</source>
          <volume>5259</volume>
          :
          <fpage>2020</fpage>
          - Information technology -
          <article-title>- Guidelines for the management of data quality." ISO, Geneva</article-title>
          , Switzerland.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Wachter</surname>
          </string-name>
          ,
          <string-name>
            <surname>Sandra</surname>
          </string-name>
          , et al.
          <article-title>"The AI governance challenge</article-title>
          .
          <source>" Harvard Kennedy School</source>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Mittelstadt</surname>
            ,
            <given-names>Brent.</given-names>
          </string-name>
          <article-title>"From individual to group privacy in big data analytics."</article-title>
          <source>Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences</source>
          <volume>374</volume>
          .
          <year>2083</year>
          (
          <year>2016</year>
          ):
          <fpage>20160128</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Floridi</surname>
            ,
            <given-names>Luciano.</given-names>
          </string-name>
          <article-title>"Soft ethics and the governance of the digital</article-title>
          .
          <source>" Philosophy &amp; Technology 31.1</source>
          (
          <year>2018</year>
          ):
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Madaio</surname>
          </string-name>
          ,
          <string-name>
            <surname>Michael</surname>
          </string-name>
          , et al.
          <article-title>"SKOS: Simple knowledge organization for the web</article-title>
          .
          <source>" Semantic Web 11.4</source>
          (
          <year>2020</year>
          ):
          <fpage>595</fpage>
          -
          <lpage>613</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Miles</surname>
          </string-name>
          ,
          <string-name>
            <surname>Alistair</surname>
          </string-name>
          , et al.
          <article-title>"SKOS simple knowledge organization system reference." W3C Recommendation (</article-title>
          <year>2009</year>
          ):
          <fpage>18</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Gangemi</surname>
            , Aldo, and
            <given-names>Valentina</given-names>
          </string-name>
          <string-name>
            <surname>Presutti</surname>
          </string-name>
          .
          <article-title>"Ontology design patterns." Handbook on ontologies (</article-title>
          <year>2009</year>
          ):
          <fpage>221</fpage>
          -
          <lpage>243</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Poveda-Villalón</surname>
          </string-name>
          , María, and
          <string-name>
            <surname>Asunción</surname>
          </string-name>
          Gómez-Pérez.
          <article-title>"Ontology engineering and evolution in a modular way."</article-title>
          <source>Semantic Web 9.3</source>
          (
          <year>2018</year>
          ):
          <fpage>323</fpage>
          -
          <lpage>356</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>David</surname>
          </string-name>
          ,
          <string-name>
            <surname>Sherin</surname>
          </string-name>
          , et al.
          <article-title>"An ontology-based approach to support the quality assessment of linked data datasets."</article-title>
          <source>Semantic Web 9.5</source>
          (
          <year>2018</year>
          ):
          <fpage>637</fpage>
          -
          <lpage>661</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Tartaro</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>Regulating by standards: current progress and main challenges in the standardisation of Artificial Intelligence in support of the AI Act</article-title>
          . Eur.
          <string-name>
            <given-names>J. Privacy L.</given-names>
            &amp;
            <surname>Tech</surname>
          </string-name>
          .,
          <volume>147</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>[12] https://ec.europa.eu/docsroom/documents/52376</mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13] https://ai-watch.ec.europa.eu/document/download/015eee26-b584
          <string-name>
            <surname>-</surname>
          </string-name>
          4a03
          <string-name>
            <surname>-</surname>
          </string-name>
          a8b3- 4c0d5ca28614_en
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>"Best Practices in AI Governance: Lessons from Industry Leaders."</article-title>
          <source>AI Ethics Review</source>
          ,
          <volume>3</volume>
          (
          <issue>1</issue>
          ),
          <fpage>45</fpage>
          -
          <lpage>63</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Smith</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brown</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Johnson</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>"Toward Effective AI Governance: A Global Perspective</article-title>
          .
          <source>" Journal of Artificial Intelligence Research</source>
          ,
          <volume>15</volume>
          (
          <issue>2</issue>
          ),
          <fpage>123</fpage>
          -
          <lpage>145</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Jones</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>2019</year>
          ).
          <article-title>"Regulatory Frameworks for AI: A Comparative Analysis</article-title>
          .
          <source>" Journal of AI Policy Studies</source>
          ,
          <volume>7</volume>
          (
          <issue>3</issue>
          ),
          <fpage>210</fpage>
          -
          <lpage>228</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>Soler</given-names>
            <surname>Garrido</surname>
          </string-name>
          ,
          <string-name>
            <surname>J.</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Fano</given-names>
            <surname>Yela</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            ,
            <surname>Panigutti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            ,
            <surname>Junklewitz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            ,
            <surname>Hamon</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            ,
            <surname>Evas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            ,
            <surname>André</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            and
            <surname>Scalzo</surname>
          </string-name>
          ,
          <string-name>
            <surname>S.</surname>
          </string-name>
          ,
          <article-title>Analysis of the preliminary AI standardisation work plan in support of the AI Act, EUR 31518 EN, Publications Office of the European Union</article-title>
          , Luxembourg,
          <year>2023</year>
          , ISBN 978-92- 68-03924-3, doi:10.2760/5847, JRC132833.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <article-title>COMMISSION IMPLEMENTING DECISION of 22.5.2023 on a standardisation request to the European Committee for Standardisation and the European Committee for Electrotechnical Standardisation in support of Union policy on artificial intelligence, C(</article-title>
          <year>2023</year>
          )3215, https://ec.europa.eu/transparency/documents-register/detail?ref=C(
          <year>2023</year>
          )
          <volume>3215</volume>
          &amp;lang=en
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Julio</surname>
            <given-names>Hernandez,</given-names>
          </string-name>
          &amp;
          <string-name>
            <surname>Dave</surname>
            <given-names>Lewis.</given-names>
          </string-name>
          (
          <year>2023</year>
          ).
          <article-title>Open Requirements Modelling for Compliance and Conformity of Trustworthy AI</article-title>
          . Zenodo. https://doi.org/10.5281/zenodo.7569540
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          <source>[20] ISO/IEC Directives part2, edition 9</source>
          (
          <year>2021</year>
          ), https://www.iso.org/sites/directives/current/part2/
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>