# Official Sources

Primary NIST, NIST CSF, and EU AI Act documentation this agent relies on for policy applicability.

Primary sources, verified 2026-07-26 against official upstream documentation and standards. Governance framings are non-certifying (see docs/compliance/).

## Source register

- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- https://www.nist.gov/cyberframework
- https://eur-lex.europa.eu/eli/reg/2024/1689/oj

## Provenance notes

- csrc.nist.gov SP 800-53, nist.gov's Cybersecurity Framework, and the EU AI Act (eur-lex) are the authoritative upstreams this agent's candidate control mappings are drawn from; applicability and compliance determinations remain the organization's and its qualified owners' responsibility.

## Grounding rule

Documentation and standards describe expected behaviour and control intent. They do not prove the target's live state, that a control operated, or that a framework applies. Applicability and compliance are owner determinations; treat any such claim as `assumption` until independently observed and owner-confirmed.
