# AI Governance Rules for OneVir Gateway and Inference

**Research date: 7 October 2026.** This document reviews the original six instruments and expands them into a global reference for AI gateway, local inference, and connected application controls. Sources are legislation, regulators, government agencies, standards publishers, and the organisations that publish the security frameworks.

The distinction between a published obligation and its application to OneVir is explicit:

- **Binding law:** enforceable where the jurisdiction, activity, actor, and commencement conditions apply.
- **Supervisory expectation:** regulator guidance for a specified regulated sector, such as OSFI E-23.
- **Standard or voluntary guidance:** an assurance or risk-management reference; it does not become a worldwide statutory duty merely because OneVir uses AI.
- **How OneVir supports this:** an engineering interpretation linking a requirement to relevant product controls. The adjacent responsibility column explains what the operator, application or inference backend must still decide and verify. Sources do not prescribe OneVir configuration names or numerical thresholds.

The tables explain how gateway controls can support governance and where accountability sits. They are not a list of discovered OneVir defects. [OneVir's public capabilities](https://onevir.onequill.dev/#capabilities) and our [control evidence record](/resources/onevir-control-evidence) describe named implementation paths and their limits; verify the installed version and enabled settings before treating a control as established. This requirements reference does not certify compliance. Coverage includes major relevant regimes in Europe, North America, Asia, Latin America, Africa, the Middle East, and Australia; it is not an inventory of every country's laws or every US state law.

## 1. Review of the original six instruments

The six are useful references, but they have different legal status and scope. They are not six interchangeable certifications or six universal gateway requirements.

| Instrument | Verified status and scope | How OneVir supports the requirement |
| --- | --- | --- |
| **ISO/IEC 27001:2022** | Requirements for an organisation's information security management system, including risk assessment and treatment. ISO describes protection of confidentiality, integrity, and availability. It is an international standard, not an AI-specific statute. [ISO publication](https://www.iso.org/standard/27001). | Support the operator's security controls and evidence. A gateway feature list alone does not establish conformity of an organisation's management system. |
| **ISO/IEC 42001:2023** | Requirements for establishing, implementing, maintaining, and continually improving an AI management system. Applies to organisations providing or using AI-based products or services. [ISO publication](https://www.iso.org/standard/42001). | Use approved model/provider choices, assigned ownership and configuration-change evidence within the client's AI management system. Governance, management review and continual improvement remain organisational responsibilities. |
| **NIST AI RMF 1.0; NIST AI 600-1** | The AI RMF is voluntary and uses **Govern, Map, Measure, Manage**. The July 2024 Generative AI Profile addresses generative-AI risks including confabulation, harmful bias, privacy, information security, and value-chain integration. [NIST AI RMF](https://www.nist.gov/itl/ai-risk-management-framework), [final Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf). | Define application risks, select relevant gateway controls and retain evaluation and monitoring evidence. The operator owns risk acceptance and review; using the framework does not certify a product. |
| **EU AI Act, Regulation (EU) 2024/1689, as amended** | Binding, with distinct prohibited-use, high-risk-system, transparency, and general-purpose AI model obligations. The Commission confirms the AI Omnibus entered into force on **27 July 2026**; Annex III high-risk duties apply from **2 December 2027**, and relevant Annex I product duties from **2 August 2028**. [Commission amendment notice](https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force). | Connect the application's approved use and actor-specific duties to access, data handling, evidence and output controls. Section 4 explains the milestones and preparation work; extensions for high-risk systems do not postpone every other AI obligation. |
| **California SB 53 — Transparency in Frontier Artificial Intelligence Act** | Enacted in September 2025 and effective **1 January 2026**. Addresses frontier AI developers, safety-framework disclosure, certain critical safety incidents, and whistleblower protections. Duties differ by the statutory developer category. [Governor's signing announcement](https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/), [Senate confirmation of effective date](https://sd38.senate.ca.gov/news/summer-recess-activities-and-more-news-senator-blakespear), [2026 government summary](https://www.gov.ca.gov/2026/09/09/governor-newsom-signs-first-in-the-nation-ai-safeguards-to-protect-californians-calls-on-the-federal-government-to-do-its-part/). | Keep model, supplier and version evidence available for the client's assessment and incident process. Routing to a frontier model alone does not make the operator a covered frontier developer; the covered developer owns the applicable public disclosures and reporting. |
| **OSFI E-23 — Model Risk Management (2027)** | Final Canadian supervisory guideline published **11 September 2025**, effective **1 May 2027**, for federally regulated financial institutions, including relevant foreign branches. Covers AI/ML and third-party models on a proportional, risk-based basis. [Final guideline](https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027). | Support financial clients' model inventories, assigned ownership, independent review, approval, change control, monitoring, and decommissioning evidence. It is not a requirement imposed on every Canadian inference server. |

**Evidence limitation for ISO:** the public descriptions establish purpose and scope. The full standards were not accessed, so this document does not claim a verified clause-by-clause ISO control mapping.

## 2. Establish applicability before selecting an enforcement policy

OneVir's legal role cannot be determined just from “local inference”, “AI gateway”, or the model name. Record the deployment facts that the cited instruments use:

| Fact to establish | Why it changes the applicable duties |
| --- | --- |
| **Market, establishment, and where outputs are used** | EU AI Act Article 2 covers specified EU actors and certain non-EU providers/deployers whose system output is used in the Union; it also contains exclusions. Personal non-professional use is treated differently from professional deployment. [Article 2](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-2). |
| **Role in the value chain** | Model providers, AI-system providers, deployers, and component suppliers have different duties. Rebranding or substantially modifying a high-risk system, or changing its purpose so that it becomes high-risk, can change the responsible actor. [Article 25](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-25), [GPAI provider duties, Article 53](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53). |
| **Purpose and effect of the application** | Recruitment, credit, education, biometrics, and health-related uses can trigger specific duties. A generic chat endpoint is insufficient evidence that every request is a legally high-risk application. [Commission risk categories](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai), [Colorado consequential-decision categories](https://www.leg.colorado.gov/bills/SB26-189). |
| **Public service versus internal use** | China's generative-AI measures cover services offered to the public in mainland China and expressly exclude specified development/use that does not provide such a public service. The provider definition includes programmable interfaces. [CAC measures, Articles 2 and 22](https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm). |
| **Data types, children, and regulated clients** | Data protection and sector rules have independent scope. Establish controller/processor relationships, recipients, and actual data flows. [GDPR application](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/application-gdpr_en), [HHS cloud guidance](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html), [FTC COPPA guidance](https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions). |

**OneVir application:** bind the operator-approved purpose and data restrictions to authenticated applications or principals. A model's classification of a prompt, or a client-supplied label alone, is not proof of legal applicability. This is an implementation consequence of needing deployment context and enforceable authorisation, not a new legal classification rule. [NIST AI RMF](https://www.nist.gov/itl/ai-risk-management-framework), [OWASP object-level authorisation](https://api-security.owasp.org/editions/2023/en/0xa1-broken-object-level-authorization/).

## 3. Additional global laws and regulatory regimes

The following are deployment-specific additions to the original six. “In force” does not mean “applicable to every OneVir installation”. Future commencement dates and sector limitations matter.

| Jurisdiction / instrument | Published duties and current status | OneVir support and deployment responsibilities |
| --- | --- | --- |
| **EU / EEA — GDPR** | In-scope processing requires lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, and security. International transfers need an applicable mechanism. [Commission principles](https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations/principles-gdpr/overview-principles/what-data-can-we-process-and-under-which-conditions_en), [international transfers](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/rules-international-data-transfers_en). | Apply restrictions to prompts, responses, files, embeddings, caches, and telemetry containing personal data. GDPR does not universally require all AI requests to stay inside the EU. |
| **United Kingdom — UK GDPR / DPA 2018, amended by DUAA 2025** | The ICO confirms all DUAA data-protection provisions were in force by its **19 June 2026** update. Significant automated decisions can use broader lawful bases with safeguards; special-category data remains more restricted. [ICO current explanation](https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/). | Support privacy and decision safeguards, but do not copy EU Article 22 unchanged into a UK policy. The application owns the consequential decision and user process. |
| **United States — consumer protection and children's privacy** | FTC enforcement includes deceptive AI capability claims. COPPA covers certain services collecting personal information from children under 13; its amended rule adds retention restrictions and parental-consent requirements for certain third-party disclosures. [FTC AI enforcement](https://www.ftc.gov/industry/technology/artificial-intelligence), [amended-rule announcement](https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data), [COPPA scope](https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions). | Support claims with evidence. A child-facing client may need recipient restrictions, deletion, and age/parental-consent processes. COPPA is not an age-verification mandate for every internal inference API. |
| **California — CCPA/CPRA and ADMT regulations** | Regulations effective **1 January 2026** include risk assessments, cybersecurity audits, and automated decisionmaking technology rules. Section 7200 sets ADMT compliance for covered significant decisions at **1 January 2027**. Scope and exemptions are specified. [CalPrivacy regulations](https://cppa.ca.gov/regulations/), [operative text, section 7200](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf). | Supply evidence for covered clients' privacy rights and risk assessments. Logs do not replace notices, access/opt-out handling, or applicable exceptions. These duties are distinct from SB 53. |
| **Colorado — SB26-189** | Enacted **14 May 2026**, repeals and reenacts the earlier SB24-205 provisions. Covered ADMT duties begin **1 January 2027**: developer documentation and change notification; deployer notices; data rights and meaningful human review after adverse decisions; compliance records for at least **three years**. [Enacted summary](https://www.leg.colorado.gov/bills/SB26-189). | Preserve version/change evidence for covered decision applications. Do not describe the old SB24-205 deadline or impact-assessment regime as the current rule without accounting for its replacement. |
| **United States — HIPAA** | Covers relevant covered entities and business associates handling protected health information. HHS explains that maintaining encrypted ePHI can create business-associate status even without the decryption key. Agreements and safeguards remain necessary. [HHS cloud guidance](https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html), [contract requirements](https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html). | Restrict PHI to permitted recipients and support safeguards, incidents, and return/destruction duties. An inference product is not automatically “HIPAA compliant”; encryption alone does not establish compliance. |
| **EU financial services — DORA** | Applicable from **17 January 2025** to financial entities in scope. Covers ICT risk management, incident reporting, testing, and third-party risk; entities maintain ICT contractual-arrangement registers. [EBA application notice](https://eba.europa.eu/activities/direct-supervision-and-oversight/digital-operational-resilience-act/preparation-dora-application), [EBA scope explanation](https://www.eba.europa.eu/publications-and-media/press-releases/eba-amends-its-guidelines-ict-and-security-risk-management-measures-context-dora-application). | Financial clients may require operational/supplier evidence. Running OneVir does not itself make its operator a regulated financial entity or designated critical ICT provider. |
| **China — Interim Measures for Generative AI Services (2023)** | Effective **15 August 2023** for covered public services. Includes lawful training inputs, privacy, unlawful-content handling, complaints, and security assessment/algorithm filing for services with public-opinion or social-mobilisation attributes. [Final measures, Articles 2, 7, 11, 14, 15, 17, 22](https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm). | Covered public/API services need specific content and operational controls. Filing/assessment are conditional, not blanket registration for private local models. Other data/security laws require separate scoping. |
| **China — generated/synthetic-content labelling measures (2025)** | Effective **1 September 2025**: visible and metadata labelling duties for covered services and a supporting mandatory national standard. Article 9 conditionally permits output without visible labels, with recorded responsibilities and relevant logs for at least six months. Article 10 prohibits malicious label tampering/removal. [Final measures](https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm), [accompanying standard](https://www.cac.gov.cn/2025-03/14/c_1743654685896173.htm). | Preserve required labels through transformations/exports. Interface disclosure and file metadata have separate roles; a generic API header does not prove satisfaction of all labelling duties. |
| **South Korea — AI Basic Act** | In force **22 January 2026**. Article 31 addresses prior notice for high-impact/generative AI products/services and generated-content labelling. MSIT differentiates providers from users and announced at least a one-year investigations/penalties grace period under this provision. [MSIT transparency guidance](https://www.msit.go.kr/eng/bbs/view.do?bbsSeqNo=42&nttSeqNo=1215). | Covered providers need notices/labels. Merely using AI tools for work or creative activities does not automatically trigger the provider duty. Enforcement grace is distinct from the law's commencement. |
| **India — DPDP Act 2023 / Rules 2025** | **Phased commencement**: institutional provisions first, specified provisions one year after Gazette publication, and core processing/rights provisions **18 months after publication**. The core provisions remain future at this research date. [Official G.S.R. 843(E)](https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf), [Rules announcement](https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014). | Prepare for covered clients' notice, lawful processing, security, rights, and processor arrangements. Do not label all processing duties already enforceable in October 2026. Follow the Gazette schedule. |
| **Brazil — LGPD / ANPD transfer regulation** | Privacy and automated-decision rights; ANPD Resolution **19/2024** regulates international transfers and contractual mechanisms. The separate AI bill **PL2338/2023** remains pending in the Chamber's status record. [ANPD regulation](https://www.gov.br/anpd/pt-br/acesso-a-informacao/institucional/atos-normativos/regulamentacoes_anpd/resolucao-cd-anpd-no-19-de-23-de-agosto-de-2024), [bill status](https://www.camara.leg.br/proposicoesWeb/fichadetramitacao?idProposicao=2487262). | Enforce authorised destinations and support applicable access/deletion/review processes. Do not present the AI bill as enacted duties or convert the LGPD review right into mandatory human review of every inference. |
| **South Africa — POPIA** | Section **71** restricts specified solely automated decisions with legal/substantial effects, subject to exceptions/safeguards; section **72** conditions transfers outside South Africa. [Official Act](https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf). | Support permissible transfers and decision-process evidence. The responsible party/application must implement the statutory safeguards; routing metadata is insufficient. |
| **Saudi Arabia — PDPL and implementing/transfer regulations** | SDAIA's controller/processor guide covers lawful processing, rights, security, accountability, and cross-border rules. Transfer rules are distinct from AI ethics principles. [Controller/processor guide](https://dgp.sdaia.gov.sa/wps/portal/pdp/knowledgecenter/details/PDPLCP), [laws and regulations](https://sdaia.gov.sa/en/SDAIA/about/Pages/RegulationsAndPolicies.aspx). | Apply covered clients' privacy/transfer restrictions. Do not infer blanket Saudi-only residency or equate an ethics document with all PDPL duties. |
| **Canada — privacy obligations and regulator AI guidance** | Regulators' GenAI principles address legal authority, appropriate purposes, necessity/proportionality, openness, accountability, safeguards, accuracy, and individual access. They explain privacy expectations, not a new omnibus AI statute. [Joint regulator principles](https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/gd_principles_ai/). | Support the client's applicable federal/provincial privacy law. Select that law and sector separately; E-23 adds financial-supervision expectations. |

**California transparency update:** the Governor announced further AI Transparency Act amendments, including AB2713 and SB1000, on **30 September 2026**. Their consolidated operative provisions were not verified in this research; no exact additional threshold, gateway watermarking mandate, or effective date is asserted. A California public generative-media deployment needs that specific follow-up. [Official enactment announcement](https://www.gov.ca.gov/2026/09/30/californias-nation-leading-ai-framework-just-got-stronger-governor-newsom-signs-more-first-in-the-nation-worker-protections-and-more/).

## 4. EU AI Act: keep the different obligations separate

### 4.1 Current timeline

| Obligation category | Application milestone | What clients should prepare |
| --- | --- | --- |
| Original prohibited practices | **2 February 2025**. Definitions and exceptions determine scope. | Review the application's intended use and identify prohibited practices with the responsible owner. Configure approved restrictions; a general prompt-safety score cannot establish legal classification. |
| GPAI model-provider rules | **2 August 2025**, with transition arrangements for earlier models. | Establish whether you provide a GPAI model or consume one. Obtain the relevant supplier documentation and assign any model-provider duties to the correct actor. |
| Article 50 transparency | **2 August 2026**. Different duties cover interaction notices, synthetic-output marking and deployer disclosure. | Decide which user notices and output markings your application must present. Verify that routing, formatting and streaming preserve the required information. |
| New specified-content prohibition and certain Article 50(2) transitions | **2 December 2026**, as set out in the current Commission timeline. | Assess the newly prohibited system purposes and the transitional marking deadline for eligible systems placed on the market before 2 August 2026. Document applicability and the required change. |
| Annex III high-risk system rules | **2 December 2027**. Applies to the high-risk systems in scope. | Classify the intended use and build the risk-management, documentation, logging and human-oversight process before deployment. Gateway controls support selected technical measures within that process. |
| Relevant Annex I high-risk product rules | **2 August 2028**. Concerns high-risk AI embedded in the regulated products in scope. | Coordinate AI evidence with the product's applicable conformity and safety process. Record who owns the integrated system assessment and supplier evidence. |

Sources: [Commission AI Act overview](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai), [current implementation timeline](https://ai-act-service-desk.ec.europa.eu/en/ai-act/eu-ai-act-implementation-timeline), [Omnibus notice](https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force). Check transitional rules and exclusions for the actual deployment. The Omnibus also changed the earlier AI-literacy provision; do not carry forward old summaries unchanged.

### 4.2 Specific duties influencing gateway/inference design

| Published requirement | How OneVir supports this / who remains responsible |
| --- | --- |
| **Prohibited practices:** Article 5 defines particular practices, including harmful manipulation/exploitation, social scoring, and specified biometric uses. [Article 5](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-5). | Support restrictions on identified prohibited applications. Intent, thresholds, and exceptions need application context; a gateway cannot conclusively classify all legal uses from text alone. |
| **High-risk risk management:** Article 9 requires an iterative documented process and testing for intended purpose and foreseeable misuse. [Article 9](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9). | Preserve evaluation/deployment evidence and support restrictions derived from assessed risks. A model benchmark alone does not validate the complete application. |
| **Human oversight:** Article 14 includes understanding limitations, avoiding automation bias, disregarding/overriding/reversing output, and intervention or safe interruption. [Article 14](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14). | Cancellation/suspension can support oversight. The application must supply the competent human, understandable information, and meaningful decision authority. |
| **Accuracy, robustness, cybersecurity:** Article 15 includes fault resilience and appropriate protection against poisoning, adversarial inputs, and confidentiality attacks. [Article 15](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-15). | Support measured performance, controlled updates, and security. The article does not specify universal accuracy percentages or prompt-filter thresholds. |
| **High-risk logging:** Articles 19 and 26(6) require retention of automatically generated logs under the actor's control for an appropriate period of at least six months, unless applicable law provides otherwise, particularly data-protection law. [Article 19](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-19), [Article 26](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26). | Provide scoped retention/export. This does not require keeping every prompt/output forever or six-month retention for all non-high-risk chat. |
| **Transparency:** Article 50 distinguishes AI-interaction notices, provider duties for machine-readable synthetic-output marking/detection, and deployer disclosures for deepfakes/public-interest text. It includes exceptions and accessibility requirements. [Article 50](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50). | Preserve provenance/markings through transformations and support client notices. Metadata alone does not provide required visible, accessible disclosure. |
| **GPAI model providers:** Article 53 covers technical/downstream documentation, copyright policy, and a public training-content summary, with specified open-source exceptions. [Article 53](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53). | Keep supplier documentation available. Do not automatically assign a developer's training-summary obligation to an operator merely forwarding inference requests. |

## 5. Additional published standards and voluntary guidance

These references provide relevant practices even when a particular AI statute does not apply. Their inclusion does not make them mandatory worldwide.

| Reference | Verified scope and useful controls |
| --- | --- |
| **ISO/IEC 23894:2023** | AI risk-management guidance for organisations developing, deploying, or using AI. Complements the management-system standards above. [ISO abstract](https://www.iso.org/standard/77304.html). |
| **OWASP LLM Top 10, 2025 edition** | Prompt injection, sensitive-information disclosure, supply chain, poisoning, improper output handling, excessive agency, system-prompt leakage, vector/embedding weaknesses, misinformation, and unbounded consumption. A security risk reference. [Current list](https://genai.owasp.org/llm-top-10/). |
| **OWASP API Security Top 10, 2023 edition** | Conventional API risks: authentication, object/function authorisation, resource consumption, SSRF, misconfiguration, and unsafe upstream API consumption. [Publisher's list](https://api-security.owasp.org/editions/2023/en/0x11-t10/). |
| **NCSC/CISA and international partners — Guidelines for Secure AI System Development** | Secure design, development, deployment, and operation/maintenance; explicitly relevant to hosted models and external APIs. [Guidelines](https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development). |
| **Singapore — GenAI and Agentic AI governance frameworks** | GenAI guidance addresses accountability, data, deployment, incidents, testing, security, and provenance. The Agentic AI framework launched **22 January 2026** covers responsible agent deployment and human accountability. [GenAI dimensions](https://www.imda.gov.sg/-/media/imda/files/news-and-events/media-room/media-releases/2024/05/annex-a-nine-dimensions-of-the-model-ai-governance-framework-for-generative-ai.pdf), [Agentic AI publication](https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf). |
| **Japan — AI Guidelines for Business, version 1.2** | METI published version 1.2 in **March 2026**. Separate this guidance from Japan's AI promotion law, fully effective **1 September 2025**, which establishes governmental measures and cooperation responsibilities. Neither is the EU high-risk regime. [Current guidelines](https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/20260331_report.html), [Cabinet Office law outline](https://www8.cao.go.jp/cstp/ai/ai_hou_gaiyou_en.pdf). |
| **Australia — Guidance for AI Adoption** | Current guidance evolves the older Voluntary AI Safety Standard into six essential practices. Its implementation guidance covers accountability, risk, oversight, testing/monitoring, records, and supply-chain governance. [Replacement explanation](https://www.industry.gov.au/publications/voluntary-ai-safety-standard), [implementation guidance](https://www.ai.gov.au/staying-safe-and-responsible/essential-ai-practices/guidance-ai-adoption-implementation-guidance). |

## 6. Published control families and their application to OneVir

Each source requires an outcome for a defined deployment or recommends a security practice. **OneVir application** translates that evidence into product responsibilities; it does not claim a regulator specified this exact implementation.

### 6.1 Request admission, identity, and data movement

| Control and published basis | How OneVir supports this | Operator / application responsibility |
| --- | --- | --- |
| **Authenticate callers and protect authentication flows.** [OWASP API2](https://api-security.owasp.org/editions/2023/en/0xa2-broken-authentication/). | Authenticate inference/admin access as required by the deployment; protect credentials and apply revocation to subsequent access. | The model must not authenticate users through conversation. |
| **Protect network transport and sensitive storage.** OWASP recommends HTTPS for secure REST services and risk-appropriate cryptographic storage/key management. [REST security](https://cheatsheetseries.owasp.org/cheatsheets/REST_Security_Cheat_Sheet.html), [cryptographic storage](https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html). | Protect network API credentials/payloads and upstream connections; secure retained sensitive data and keep encryption keys protected. | Encryption supports security; it does not establish lawful processing, recipient approval, or complete compliance. |
| **Authorise objects and privileged functions.** [OWASP API1](https://api-security.owasp.org/editions/2023/en/0xa1-broken-object-level-authorization/), [API5](https://api-security.owasp.org/editions/2023/en/0xa5-broken-function-level-authorization/). | Scope model/provider access, stored files/conversations, cache/memory objects, and administration to the authenticated principal. | A valid key does not imply access to every tenant's objects. |
| **Minimise and protect personal/sensitive information.** [GDPR principles](https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations/principles-gdpr/overview-principles/what-data-can-we-process-and-under-which-conditions_en), [OWASP LLM02](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/). | Apply approved restrictions before external disclosure and during storage/logging; use appropriate sanitisation/redaction and access control. | Redaction does not prove anonymisation, lawful processing, or contractual approval. |
| **Control external recipients and transfers.** [Commission transfers](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/rules-international-data-transfers_en), [NCSC secure design](https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development/guidelines/secure-design). | Restrict eligible providers/regions to those approved for the client's data/purpose, including fallback and retry destinations. | Verify contracts, subprocessors, training use, retention, and processing locations with supplier evidence. A hostname alone does not establish them. |
| **Prevent server-side request forgery.** Validate destinations and restrict network access for input-derived server-side requests. [OWASP API7](https://api-security.owasp.org/editions/2023/en/0xa7-server-side-request-forgery/). | Constrain remote resource/model fetching, media URLs, and permitted upstream endpoints where these paths exist. | Deployment network controls also matter; validating URL syntax is insufficient. |
| **Bound resource/financial consumption.** Published mitigations include size limits, quotas, timeouts, resource allocation, monitoring, and queue limits. [OWASP LLM10](https://genai.owasp.org/llmrisk/llm102025-unbounded-consumption/). | Bound input/output size, concurrency/queues, duration, controlled agent iterations, and external spend. Include retries in aggregate limits. | Derive numbers from assessed capacity/client policy, not invented regulatory limits. |

### 6.2 Inference, retrieval, generated outputs, and tools

| Control and published basis | How OneVir supports this | Operator / application responsibility |
| --- | --- | --- |
| **Mitigate direct/indirect prompt injection.** RAG/fine-tuning do not fully remove the risk. [OWASP LLM01](https://genai.owasp.org/llmrisk/llm01-prompt-injection/). | Treat user inputs, retrieved documents, files, and tool results as untrusted content; retain enforceable boundaries outside the model. | A prompt or detection model is not guaranteed prevention. |
| **Keep secrets/security decisions outside system prompts.** Prompts can leak and must not be relied upon for authorisation. [OWASP LLM07](https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/). | Keep provider credentials and privileged policy enforcement in gateway/runtime security mechanisms, separate from model text. | “Never reveal this secret” is not secret protection. |
| **Limit tool functionality, permissions, and autonomy.** Execute in user context, mediate downstream authorisation, and require approval for high-impact actions as appropriate. [OWASP LLM06](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/). | Where OneVir hosts/mediates tools, restrict operations, validate calls/arguments, and preserve user context. | Tool-call JSON does not enforce an external agent's execution. The executor must enforce these controls. |
| **Validate and safely handle outputs.** Generated data can cause injection in downstream browsers, interpreters, databases, and commands. [OWASP LLM05](https://genai.owasp.org/llmrisk/llm052025-improper-output-handling/). | Validate structured outputs/arguments where consumed; encode/sanitise generated content in OneVir's UI and consumers. | Valid JSON does not make embedded commands, URLs, SQL, or HTML safe. |
| **Enforce permission-aware retrieval and prevent cross-context leakage.** Fine-grained permissions, partitioning, source validation, and monitoring are published mitigations. [OWASP LLM08](https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/). | Preserve scope for embeddings, retrieval, memory, and semantic reuse. Similarity is not permission to reuse a stored answer. | Embeddings are not automatically anonymous; access/deletion depend on their content/use. |
| **Assess misinformation and fitness for purpose.** [OWASP LLM09](https://genai.owasp.org/llmrisk/llm092025-misinformation/), [EU Article 9](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-9). | Retain model/version/evaluation evidence and communicate supported-use limitations. | The application owns factual verification and consequential decisions. Fluency or a generated explanation is not validation evidence. |
| **Apply the relevant content/disclosure policy.** EU and China sources specify different scopes and duties. [EU Article 50](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50), [China service measures](https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm). | Support the selected deployment's restrictions, refusal/escalation, and output labelling. | Do not invent one worldwide prohibited-topic list; restrictions, exceptions, and publication duties differ. |

### 6.3 Model lifecycle, evidence, and operational response

| Control and published basis | How OneVir supports this | Operator / application responsibility |
| --- | --- | --- |
| **Protect the model/software supply chain.** Risks include untrusted models/components, licence restrictions, weak provenance, and outdated dependencies. [OWASP LLM03](https://genai.owasp.org/llmrisk/llm032025-supply-chain/). | Track origin, revision, integrity evidence, licence/permitted use; protect import/update paths and inference dependencies. | Download availability or an open licence does not prove safety or permission for every use. |
| **Isolate untrusted imports and protect inference assets.** NCSC recommends scanning/isolation when importing third-party models/weights and tracking/protecting models, data, prompts, and logs. [Secure design](https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development/guidelines/secure-design), [secure development](https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development/guidelines/secure-development). | Restrict access to worker/model assets and use suitable isolation for model import/loading; retain provenance and a way to restore known-good assets. | A file-format choice alone does not establish that an untrusted model or inference dependency is safe. |
| **Guard against poisoning.** Validate sources and integrity; assess data/model changes. [OWASP LLM04](https://genai.owasp.org/llmrisk/llm042025-data-and-model-poisoning/). | Validate imported models and retrieval/memory ingestion under OneVir's control; investigate unexpected behaviour after changes. | A gateway cannot reconstruct supplier training provenance from outputs. |
| **Inventory, validate, approve, and monitor models.** E-23 expects risk-proportional governance, independent review, change control, and monitoring. [OSFI E-23, sections B–D](https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027). | Supply version/change/evaluation/operation evidence; regulated clients may need review of model/provider/routing changes. | Health checks or generic benchmarks do not independently validate a financial model. |
| **Log and monitor without unnecessary data exposure.** [NCSC operation/maintenance](https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development/guidelines/secure-operation-and-maintenance), [GDPR principles](https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations/principles-gdpr/overview-principles/what-data-can-we-process-and-under-which-conditions_en). | Keep protected evidence of access, selection, policy decisions, changes, failures, and incidents; minimise raw content and provide authorised export/deletion. | Required duration/content vary. EU high-risk logs and Colorado compliance records are different record classes. |
| **Maintain incident response and controlled release.** Guidance calls for plans, security evaluation, limitations, secure defaults, and customer audit information. [NCSC secure deployment](https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development/guidelines/secure-deployment). | Support model/provider isolation/suspension, evidence preservation, remediation, and controlled update activation. | Reporting recipients/deadlines are regime-specific; reporting and customer communications remain assigned organisational duties. |

## 7. Policy must survive routing, caching, and streaming

Sources do not mandate a particular pipeline. These are **engineering consequences** of applying their authorisation, privacy, output, and supplier restrictions to OneVir's serving paths:

1. **A fallback is another disclosure.** Re-evaluate whether the next provider is permitted before sending data. A primary-provider failure does not remove transfer/recipient restrictions. [Transfer rules](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/rules-international-data-transfers_en).
2. **A cache hit is another access to stored data.** Authorise the requester and reused material; preserve applicable retention/deletion. Similarity is not permission. This applies the published authorisation and leakage principles to caching. [OWASP API1](https://api-security.owasp.org/editions/2023/en/0xa1-broken-object-level-authorization/), [OWASP LLM08](https://genai.owasp.org/llmrisk/llm082025-vector-and-embedding-weaknesses/).
3. **Released stream content has already been disclosed.** If selected policy requires inspection before disclosure, a check after delivery cannot satisfy it. Choose buffering, staged release, or another control according to assessed risk; no source mandates one universal strategy. [OWASP LLM02](https://genai.owasp.org/llmrisk/llm022025-sensitive-information-disclosure/).
4. **Tool execution needs its own enforcement point.** Preserve user scope and required approval at hand-off to the actual tool. [OWASP LLM06 complete mediation](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/).
5. **Logs, caches, and exports are also processing.** Local inference does not remove privacy duties for other stores/telemetry recipients containing personal data. [GDPR processing scope](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/application-gdpr_en).

These identify where to apply a selected policy consistently. They do not require every customer to enable every filter, all data to stay local, or imply that a gateway alone makes a deployment compliant.

## 8. Responsibilities of the operator and consuming application

The cited regimes also require decisions/processes outside the inference request:

- **Legal basis, purpose, notices, rights, and contracts:** the responsible controller/operator establishes these and directs processors appropriately. [GDPR roles](https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/application-gdpr_en), [EDPB rights and processor assistance](https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en).
- **Meaningful oversight and recourse:** the client supplies human authority and the user process where required. Cancellation alone is insufficient. [EU Article 14](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-14), [Colorado duties](https://www.leg.colorado.gov/bills/SB26-189).
- **Governance and independent review:** policies, owners, management review, validation, and approval are organisational activities. [ISO 42001](https://www.iso.org/standard/42001), [OSFI E-23](https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/guideline-e-23-model-risk-management-2027).
- **Supplier facts and disclosures:** obtain applicable documentation and verify operational/contractual facts. API compatibility does not establish provenance, processing location, or supplier compliance. [EU Article 53](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53), [NCSC due diligence](https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development/guidelines/secure-design).

For implementation work, establish deployment facts, select cited obligations/practices, and inspect/test the affected OneVir paths. This research does not assign implementation status, invent acceptance thresholds, or assert certification. Refresh sources for new jurisdictions, regulated uses, or providers and before relying on future commencement dates.

