{
  "format": "palo-source-registry",
  "schemaVersion": "1.0.0",
  "status": "educational-non-production",
  "updatedAt": "2026-08-26",
  "disclaimer": "This registry is an educational starting point. Source presence and freshness metadata do not establish legal applicability, compliance, certification, or completeness.",
  "sources": [
    {
      "sourceId": "src-nist-ai-rmf",
      "title": "AI Risk Management Framework",
      "url": "https://www.nist.gov/itl/ai-risk-management-framework",
      "sourceType": "official",
      "publisher": "US National Institute of Standards and Technology",
      "checkedAt": "2026-07-12T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 90, "nextReviewAt": "2026-10-10T08:00:00Z" },
      "authorityStatus": "authoritative-primary",
      "usageNote": "Use as a risk-management reference; confirm the current publication and organizational applicability before use."
    },
    {
      "sourceId": "src-nist-genai-profile",
      "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile",
      "url": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence",
      "sourceType": "official",
      "publisher": "US National Institute of Standards and Technology",
      "checkedAt": "2026-07-12T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 90, "nextReviewAt": "2026-10-10T08:00:00Z" },
      "authorityStatus": "authoritative-primary",
      "usageNote": "Use for generative-AI risk prompts; it is not a substitute for context-specific testing or accountable review."
    },
    {
      "sourceId": "src-iso-42001",
      "title": "ISO/IEC 42001 Artificial intelligence management system",
      "url": "https://www.iso.org/standard/81230.html",
      "sourceType": "standard",
      "publisher": "International Organization for Standardization",
      "checkedAt": "2026-07-12T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 180, "nextReviewAt": "2027-01-08T08:00:00Z" },
      "authorityStatus": "authoritative-standard",
      "usageNote": "Catalog metadata is linked for status checking; this starter library does not reproduce or certify conformance to the standard."
    },
    {
      "sourceId": "src-eu-ai-act",
      "title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act)",
      "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
      "sourceType": "official",
      "publisher": "Official Journal of the European Union",
      "checkedAt": "2026-08-23T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 30, "nextReviewAt": "2026-09-22T08:00:00Z" },
      "authorityStatus": "authoritative-primary",
      "usageNote": "Use the official text and current implementation timeline with qualified counsel; no gate or control here is a legal conclusion."
    },
    {
      "sourceId": "src-oecd-ai-principles",
      "title": "OECD AI Principles",
      "url": "https://oecd.ai/en/ai-principles",
      "sourceType": "official",
      "publisher": "Organisation for Economic Co-operation and Development",
      "checkedAt": "2026-07-12T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 180, "nextReviewAt": "2027-01-08T08:00:00Z" },
      "authorityStatus": "authoritative-primary",
      "usageNote": "Use as a principles reference and verify any jurisdiction-specific obligations separately."
    },
    {
      "sourceId": "src-owasp-llm-top10",
      "title": "OWASP Top 10 for LLM Applications 2026",
      "url": "https://genai.owasp.org/initiative/owasp-top-10-for-llm-and-genai/",
      "sourceType": "organizational",
      "publisher": "OWASP Foundation",
      "checkedAt": "2026-08-13T08:00:00Z",
      "freshness": { "status": "unknown", "reviewIntervalDays": 30, "nextReviewAt": "2026-09-12T08:00:00Z" },
      "authorityStatus": "informative",
      "usageNote": "The repository pins the 2026 v1.0 PDF dated 4 August 2026. Its revision history retains a publication-date placeholder, so reverify the official project page before external assurance. Use it as an informative test catalog, not as compliance or certification."
    },
    {
      "sourceId": "src-eu-article50-guidelines",
      "title": "Guidelines on Article 50 transparency obligations for providers and deployers of certain AI systems",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations",
      "sourceType": "official",
      "publisher": "European Commission",
      "checkedAt": "2026-08-23T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 30, "nextReviewAt": "2026-09-22T08:00:00Z" },
      "authorityStatus": "authoritative-primary",
      "usageNote": "Use with the consolidated AI Act and the current transparency Code of Practice. Applicability, exceptions and equivalent marking or labelling measures require accountable legal review."
    },
    {
      "sourceId": "src-eu-gpai-code",
      "title": "General-Purpose AI Code of Practice",
      "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
      "sourceType": "official",
      "publisher": "European Commission",
      "checkedAt": "2026-08-23T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 30, "nextReviewAt": "2026-09-22T08:00:00Z" },
      "authorityStatus": "authoritative-primary",
      "usageNote": "Use as a voluntary compliance route for in-scope GPAI providers. Signing, applicability and actual conformity must be evidenced separately."
    },
    {
      "sourceId": "src-iso-42005",
      "title": "ISO/IEC 42005:2025 AI system impact assessment",
      "url": "https://www.iso.org/standard/42005.html",
      "sourceType": "standard",
      "publisher": "International Organization for Standardization",
      "checkedAt": "2026-08-23T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 180, "nextReviewAt": "2027-02-19T08:00:00Z" },
      "authorityStatus": "authoritative-standard",
      "usageNote": "Catalog metadata supports source-status checks. PALO does not reproduce the licensed standard or certify an impact assessment against it."
    },
    {
      "sourceId": "src-wcag-22",
      "title": "Web Content Accessibility Guidelines 2.2",
      "url": "https://www.w3.org/TR/WCAG22/",
      "sourceType": "standard",
      "publisher": "World Wide Web Consortium",
      "checkedAt": "2026-08-23T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 180, "nextReviewAt": "2027-02-19T08:00:00Z" },
      "authorityStatus": "authoritative-standard",
      "usageNote": "Use WCAG 2.2 for interface and perceivable-output testing. Product, sector and jurisdiction-specific accessibility obligations remain separately applicable."
    },
    {
      "sourceId": "src-eu-gdpr",
      "title": "Regulation (EU) 2016/679 (General Data Protection Regulation)",
      "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
      "sourceType": "official",
      "publisher": "Official Journal of the European Union",
      "checkedAt": "2026-08-23T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 90, "nextReviewAt": "2026-11-21T08:00:00Z" },
      "authorityStatus": "authoritative-primary",
      "usageNote": "Use the current official text with qualified privacy review. PALO does not determine lawful basis, controller or processor status, or data-subject-rights compliance."
    },
    {
      "sourceId": "src-palo-external-evidence-contract",
      "title": "PALO External Agentic Evidence Contract",
      "url": "https://paloframework.org/docs/palo-external-agentic-evidence.html",
      "sourceType": "organizational",
      "publisher": "PALO Framework",
      "checkedAt": "2026-08-26T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 90, "nextReviewAt": "2026-11-24T08:00:00Z" },
      "authorityStatus": "informative",
      "usageNote": "Use as the canonical PALO normalization and governance boundary for optional external agentic evidence; it does not accept or validate any imported claim."
    },
    {
      "sourceId": "src-rogue-ai-tracker",
      "title": "Rogue AI Tracker methodology",
      "url": "https://rogueaitracker.com/methodology/",
      "sourceType": "monitoring-signal",
      "publisher": "Rogue AI Tracker",
      "checkedAt": "2026-08-26T08:00:00Z",
      "freshness": { "status": "current", "reviewIntervalDays": 30, "nextReviewAt": "2026-09-25T08:00:00Z" },
      "authorityStatus": "non-authoritative-monitoring-signal",
      "usageNote": "Use metadata and links as external capability context only. Do not mirror narrative content or treat provider scores as PALO use-case risk scores, findings or deployment decisions."
    }
  ]
}
