Control happens before action
Logging what an AI system did is useful, but it arrives afterwards. When a system can send an email, change a price, publish content, touch sensitive data, modify a record or trigger a real operation, architecture needs to decide first whether that action is allowed.
At OrvixLabs, evidence, authority and reversibility are operational conditions. AI may propose or prepare an action. The ability to execute it depends on explicit rules and, where appropriate, verifiable human authorization.
Traceability explains what happened. Control needs to exist before it happens.
Five controls that matter before execution
Evidence. A consequential action should not depend on a claim the system cannot support. When critical information is missing, blocking or requesting review is a valid outcome.
Authority. Human participation alone is not enough. The system needs to know who can authorize which class of action and over which exact artifact.
Reversibility. Preparing a draft is not the same as sending an email, recommending a change is not the same as applying it, and simulating an operation is not the same as confirming it. The harder an action is to undo, the stronger the pre-action control should be.
Data boundaries. What information may cross to a model, provider or integration is defined before they are connected. Privacy and minimization are not a cleanup step afterwards.
Traceability. The decision, supporting evidence, authorization and result should be reconstructable when the context requires it.
One global foundation, policy by jurisdiction
There is no single AI compliance label that is valid across every country, sector and use case. OrvixLabs uses a common control foundation and adapts it to the actual jurisdiction, type of data, organizational role and consequence of each action.
The mapping below is informational. It is not an exhaustive inventory of every jurisdiction. It is not legal advice, certification or a claim of compliance.
International references
ISO/IEC 42001:2023. The international standard for artificial intelligence management systems addresses risk and opportunity management, accountability, traceability, transparency and continual improvement. ISO →
OECD AI Principles. Adopted in 2019 and updated in 2024, they provide an intergovernmental reference for innovative and trustworthy AI that respects human rights and democratic values. OECD →
United States
NIST AI Risk Management Framework. It is voluntary and structures AI risk management around Govern, Map, Measure and Manage. For OrvixLabs, the useful correspondence is making ownership, context, measurements, boundaries, evidence and risk response explicit. Binding obligations also depend on sector, state and use case. NIST →
United Kingdom
The UK approach is organized around five cross-sector principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. These principles help translate technical controls into language already used by regulators and risk owners. GOV.UK →
European Union
The EU AI Act applies different obligations according to role and risk. For high-risk systems, Article 12 addresses record-keeping and Article 14 human oversight. Following the 2026 changes, rules for certain high-risk areas apply from 2 December 2027, while rules for high-risk systems embedded in regulated products apply from 2 August 2028. EUR-Lex → European Commission →
Canada
Canada launched its national AI for All strategy in 2026. It also maintains a voluntary code for advanced generative AI systems with principles covering safety, accountability, transparency, fairness, human oversight and robustness. These instruments do not replace applicable law, but they are practical design references. Government of Canada → ISED →
Australia
The Guidance for AI Adoption, published in 2025, sets out six essential practices for safe and responsible AI governance. It is guidance rather than a new general legal obligation, and it sits alongside existing privacy, consumer, security and sector-specific law. Australian Government →
Latin America
Argentina. AI-specific public policy and regulatory work continues to evolve. Binding personal-data rules already apply, and a national program addresses transparency and data protection in the use of AI. Architecture should map to the actual obligation rather than assume one universal AI statute. Argentina.gob.ar →
Brazil. LGPD already governs personal data. PL 2338/2023, previously approved by the Senate, remains before the Chamber of Deputies as a proposal for a broader AI framework. We do not present it as enacted law while it remains under legislative consideration. ANPD → Câmara dos Deputados →
Chile. Chile maintains a National Artificial Intelligence Policy with a governance and ethics pillar. Its bill regulating AI systems is in its second constitutional stage in the Senate and follows a risk-based approach involving human oversight, technical safety, privacy, transparency and accountability. MinCiencia → Senate of Chile →
Peru. Law 31814 and its regulation, approved by Supreme Decree 115-2025-PCM, form a specific national framework promoting AI use under safety, ethical and transparency criteria. Government of Peru →
Asia-Pacific
Japan. METI and MIC published the AI Guidelines for Business for developers, providers and users of AI. Japan's AI Promotion Act also came fully into force in September 2025. It is a promotion and governance law designed to support AI development and use while addressing risk, without a general penalty regime. METI → Cabinet Office →
Singapore. Its Model AI Governance Framework family includes a 2026 framework specifically for agentic AI. It recommends bounding agents' powers upfront, defining meaningful checkpoints for human approval, and implementing technical and operational controls throughout the agent lifecycle. IMDA →
South Korea. The Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust has been in force since 22 January 2026 and establishes a national legal foundation for AI development and trust. Korean Law Information Center →
What this means in a real architecture
We do not turn every framework into a marketing checkbox. We translate obligations and risk into verifiable mechanisms: role-based permissions, separation between proposal and execution, gates for irreversible actions, data minimization, input evidence, reconstructable logs, blocked states, human review and replaceable providers.
The list of frameworks changes over time. The stable rule is different: a system should know what it may do, with what evidence, under whose authority and in which jurisdiction it operates.
Explicit limit
This page describes design principles and public references current to September 2026. It is not legal advice. It does not claim ISO certification or automatic compliance with any law. Legal and regulatory assessment must be performed for the specific organization, sector, country and use case.
Why logging is not enough
The article explains why post-action logging does not replace evidence, authority and reversibility before execution.