# PRISM Ontology — v0.4.0
# EU AI Act Compliance Record-Keeping Ontology
# Extends AIRO (AI Risk Ontology), DPV 2.3, and the EU AI Act extension (eu-aiact)
# Includes an agentic AI profile (Section 9) drawn from IMDA's Model AI
# Governance Framework for Agentic AI v1.5
#
# Namespace:  https://w3id.org/prism#
# Prefix:     prism:
# Repository: https://github.com/bigspark/prism-ontology
# Docs:       https://w3id.org/prism
# License:    EUPL-1.2
#
# Dependencies:
#   AIRO                  https://w3id.org/airo                        (AI Risk Ontology — Golpayegani & Pandit)
#   DPV 2.3               https://w3id.org/dpv
#   eu-aiact 2.3          https://w3id.org/dpv/legal/eu/aiact
#   ai 2.3                https://w3id.org/dpv/ai
#   sector-finance 2.3    https://w3id.org/dpv/sector/finance          (Purpose taxonomy for financial services)
#   sector-health 2.3     https://w3id.org/dpv/sector/health           (Purpose taxonomy for healthcare)
#   sector-publicservices  https://w3id.org/dpv/2.3/sector/publicservices  (Purpose taxonomy for public sector — draft, versioned URI only)

@prefix prism:           <https://w3id.org/prism#> .
@prefix airo:            <https://w3id.org/airo#> .
@prefix dpv:             <https://w3id.org/dpv#> .
@prefix eu-aiact:        <https://w3id.org/dpv/legal/eu/aiact#> .
@prefix ai:              <https://w3id.org/dpv/ai#> .
@prefix sector-finance:  <https://w3id.org/dpv/sector/finance#> .
@prefix sector-health:   <https://w3id.org/dpv/sector/health#> .
# sector-pub: not declared — the non-versioned w3id.org redirect is not yet active (draft module).
# When stable, add: @prefix sector-pub: <https://w3id.org/dpv/sector/publicservices#> .
@prefix owl:             <http://www.w3.org/2002/07/owl#> .
@prefix rdf:             <http://www.w3.org/1999/02/22-rdf-syntax-ns#> .
@prefix rdfs:            <http://www.w3.org/2000/01/rdf-schema#> .
@prefix skos:            <http://www.w3.org/2004/02/skos/core#> .
@prefix xsd:             <http://www.w3.org/2001/XMLSchema#> .
@prefix dct:             <http://purl.org/dc/terms/> .
@prefix vann:            <http://purl.org/vocab/vann/> .
@prefix voaf:            <http://purl.org/vocommons/voaf#> .
@prefix foaf:            <http://xmlns.com/foaf/0.1/> .

# ── Ontology metadata ─────────────────────────────────────────────────────────

<https://w3id.org/prism>
    a owl:Ontology , voaf:Vocabulary ;
    dct:title "PRISM — EU AI Act Compliance Record-Keeping Ontology"@en ;
    dct:description """PRISM extends AIRO (AI Risk Ontology), the W3C Data Privacy Vocabulary (DPV) 2.3, and its EU AI Act extension (eu-aiact) with structured mappings from legal obligations to compliance record types, sector-specific interpretations, and attestation workflows. It is designed to underpin audit-grade AI governance record-keeping for providers and deployers of AI systems under the EU AI Act. Version 0.4.0 adds an agentic AI profile (agent components, action-space and autonomy classifications, controls, oversight design, agent identity and delegation records, agentic risks, and agent-specific testing and change management records) whose vocabulary is drawn from IMDA (Singapore)'s Model AI Governance Framework for Agentic AI v1.5; mappings from that voluntary framework to EU AI Act articles are interpretive."""@en ;
    dct:creator [
        a foaf:Person ;
        foaf:name "Paola Arce" ;
        rdfs:seeAlso <https://orcid.org/0000-0002-2830-4108>
    ] ;
    dct:creator [ a foaf:Person ; foaf:name "Maria Milagros Maqueda" ] ;
    dct:creator [ a foaf:Person ; foaf:name "Kate Hughes" ] ;
    dct:license <https://joinup.ec.europa.eu/collection/eupl/eupl-text-eupl-12> ;
    dct:created "2026-04-01"^^xsd:date ;
    dct:modified "2026-07-05"^^xsd:date ;
    owl:versionInfo "0.4.0" ;
    owl:versionIRI <https://w3id.org/prism/0.4.0> ;
    vann:preferredNamespacePrefix "prism" ;
    vann:preferredNamespaceUri "https://w3id.org/prism#" ;
    voaf:extends  <https://w3id.org/airo> ,
                  <https://w3id.org/dpv> ,
                  <https://w3id.org/dpv/legal/eu/aiact> ;
    voaf:reliesOn <https://w3id.org/airo> ,
                  <https://w3id.org/dpv> ,
                  <https://w3id.org/dpv/legal/eu/aiact> ;
    owl:imports <https://w3id.org/airo> ;
    rdfs:seeAlso <https://w3id.org/dpv> ;
    rdfs:seeAlso <https://w3id.org/dpv/legal/eu/aiact> ;
    rdfs:seeAlso <https://w3id.org/dpv/ai> ;
    rdfs:seeAlso <https://w3id.org/dpv/sector/finance> ;
    rdfs:seeAlso <https://w3id.org/dpv/sector/health> ;
    rdfs:seeAlso <https://w3id.org/dpv/2.3/sector/publicservices> ;
    rdfs:seeAlso <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> ;
    rdfs:seeAlso <https://www.imda.gov.sg/about-imda/emerging-technologies-and-research/artificial-intelligence> ;
    rdfs:seeAlso <https://github.com/bigspark/prism-ontology> .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 1 — ECONOMIC SECTOR (prism:EconomicSector instances)
#
# The economic sector in which an AI system operates, based on NACE Rev. 2.
# Use dpv:hasSector with one of the prism:EconomicSector instances below.
#
# NOTE: prism:EconomicSector is distinct from eu-aiact Annex III sectors
# (e.g. eu-aiact:EmploymentSector). Annex III sectors determine WHICH
# obligations apply (via prism:forSector on ApplicabilityCondition).
# Economic sector determines HOW obligations are fulfilled — the content
# and interpretation of compliance records varies by industry context.
#
# For example, a RiskManagementRecord for a credit scoring system
# (prism:Finance) must address financial-specific risks, while the same
# record type for a medical triage system (prism:Health) must address
# patient safety risks.
#
# Each prism:EconomicSector instance carries:
#   skos:notation  — the corresponding NACE Rev. 2 section code(s)
#   rdfs:seeAlso   — the DPV sector purpose extension for that industry
#
# Usage pattern:
#   ex:MySystem dpv:hasSector   prism:Finance .
#   ex:MySystem dpv:hasPurpose  sector-finance:CreditChecking .
# ═════════════════════════════════════════════════════════════════════════════

prism:EconomicSector
    a owl:Class ;
    rdfs:subClassOf dpv:Sector ;
    rdfs:label "Economic Sector"@en ;
    rdfs:comment "An economic sector classification based on NACE Rev. 2, identifying where an AI system operates. Distinct from eu-aiact Annex III sectors, which determine which obligations apply."@en .

prism:Finance
    a prism:EconomicSector ;
    rdfs:label "Financial and Insurance Activities"@en ;
    skos:notation "K"^^xsd:string ;
    rdfs:seeAlso <https://w3id.org/dpv/sector/finance> ;
    rdfs:comment "NACE Rev. 2 section K. For sector-specific purposes use sector-finance: terms with dpv:hasPurpose."@en .

prism:Health
    a prism:EconomicSector ;
    rdfs:label "Human Health and Social Work Activities"@en ;
    skos:notation "Q"^^xsd:string ;
    rdfs:seeAlso <https://w3id.org/dpv/sector/health> ;
    rdfs:comment "NACE Rev. 2 section Q. For sector-specific purposes use sector-health: terms with dpv:hasPurpose."@en .

prism:Education
    a prism:EconomicSector ;
    rdfs:label "Education"@en ;
    skos:notation "P"^^xsd:string ;
    rdfs:seeAlso <https://w3id.org/dpv/sector/education> ;
    rdfs:comment "NACE Rev. 2 section P. For sector-specific purposes use sector-education: terms with dpv:hasPurpose."@en .

prism:Infrastructure
    a prism:EconomicSector ;
    rdfs:label "Infrastructure"@en ;
    skos:notation "D"^^xsd:string ;
    skos:notation "E"^^xsd:string ;
    skos:notation "F"^^xsd:string ;
    skos:notation "H"^^xsd:string ;
    rdfs:seeAlso <https://w3id.org/dpv/sector/infra> ;
    rdfs:comment "NACE Rev. 2 sections D (Energy), E (Water/waste), F (Construction), H (Transport). For sector-specific purposes use sector-infra: terms with dpv:hasPurpose."@en .

prism:LawEnforcement
    a prism:EconomicSector ;
    rdfs:label "Law Enforcement and Justice"@en ;
    skos:notation "O"^^xsd:string ;
    rdfs:seeAlso <https://w3id.org/dpv/sector/law> ;
    rdfs:comment "NACE Rev. 2 section O (specifically O84.23 — Justice and judicial activities). For sector-specific purposes use sector-law: terms with dpv:hasPurpose."@en .

prism:PublicServices
    a prism:EconomicSector ;
    rdfs:label "Public Administration and Defence"@en ;
    skos:notation "O"^^xsd:string ;
    rdfs:seeAlso <https://w3id.org/dpv/2.3/sector/publicservices> ;
    rdfs:comment "NACE Rev. 2 section O (broad public administration). sector-publicservices is a draft DPV module — use the versioned URI. For sector-specific purposes use sector-pub: terms with dpv:hasPurpose when stable."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 2 — RISK LEVELS (DPV 2.3 eu-aiact risk taxonomy)
#
# DPV 2.3 defines the eu-aiact risk level taxonomy. PRISM maps directly
# to these terms rather than defining its own.
#
# eu-aiact:RiskLevelProhibited             — prohibited AI practices (Article 5)
# eu-aiact:RiskLevelHigh                   — high-risk (Article 6)
#   eu-aiact:RiskLevelHigh-A6-1            — high-risk: safety components per Annex I (Article 6(1))
#   eu-aiact:RiskLevelHigh-A6-2            — high-risk: listed use cases per Annex III (Article 6(2))
# eu-aiact:RiskLevelTransparencyRequired   — transparency obligations (Article 50)
# eu-aiact:RiskLevelMinimal                — no specific obligations
#
# Use eu-aiact:hasRiskLevel with one of the above.
# ═════════════════════════════════════════════════════════════════════════════

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 3 — REGULATORY PROCESSES AND GOVERNANCE ACTIVITIES
#
# Former CompliancePhase individuals reclassified into their actual types.
# Lifecycle stages (DesignAndBuild, UseAndOperation, PostMarket) are replaced
# by direct references to ai:LifecycleStage (DPV 2.3 / ISO 22989).
# ═════════════════════════════════════════════════════════════════════════════

prism:RegulatoryProcess
    a owl:Class ;
    rdfs:label "Regulatory Process"@en ;
    rdfs:comment "An AI Act-specific procedure that occurs at one or more AI lifecycle stages. Not a lifecycle stage itself."@en .

prism:ConformityAssessment
    a prism:RegulatoryProcess, owl:NamedIndividual ;
    rdfs:label "Conformity Assessment"@en ;
    rdfs:comment "The AI Act procedure in which conformity is formally assessed, either through self-assessment (Module A) or third-party assessment for biometric and Annex I systems (Articles 43-44)."@en ;
    prism:occursAtStage ai:VerificationStage, ai:ValidationStage .

prism:SupplyChainVerification
    a prism:RegulatoryProcess, owl:NamedIndividual ;
    rdfs:label "Supply Chain Verification"@en ;
    rdfs:comment "The AI Act procedure in which importers and distributors verify that an AI system complies before placing it on the market (Articles 43-44)."@en ;
    prism:occursAtStage ai:DeploymentStage .

prism:MarketEntry
    a prism:RegulatoryProcess, owl:NamedIndividual ;
    rdfs:label "Market Entry"@en ;
    rdfs:comment "The AI Act procedure covering formal market placement: EU Declaration of Conformity, CE marking, and EU AI Database registration (Articles 47-49)."@en ;
    prism:occursAtStage ai:DeploymentStage .

prism:GovernanceActivity
    a owl:Class ;
    rdfs:label "Governance Activity"@en ;
    rdfs:comment "An ongoing governance activity that spans multiple AI lifecycle stages. Not bound to a single stage."@en .

prism:InternalProcesses
    a prism:GovernanceActivity, owl:NamedIndividual ;
    rdfs:label "Internal Processes"@en ;
    rdfs:comment "Ongoing internal governance and quality management obligations including the quality management system and corrective actions (Articles 16-17, 20)."@en .

prism:RiskAssessment
    a prism:GovernanceActivity, owl:NamedIndividual ;
    rdfs:label "Risk Assessment"@en ;
    rdfs:comment "Risk assessment activities including the Fundamental Rights Impact Assessment (FRIA) for Annex III high-risk use cases (Article 27)."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 4 — APPLICABILITY CONDITIONS
#
# Each obligation declares the conditions under which it applies.
# An obligation may have multiple ApplicabilityConditions (disjunction —
# any one set of conditions is sufficient to trigger the obligation).
# Conditions can include any combination of: actor role, risk level,
# lifecycle stage, use case category, or entity type.
# ═════════════════════════════════════════════════════════════════════════════

prism:ApplicabilityCondition
    a owl:Class ;
    rdfs:label "Applicability Condition"@en ;
    rdfs:comment "A set of conditions that determine when an EU AI Act obligation applies. Conditions can include actor role, risk level, lifecycle stage, use case category, entity type, or any combination. An obligation may have multiple ApplicabilityConditions (disjunction — any one set of conditions is sufficient)."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 4b — PRISM-LOCAL SYSTEM TYPES
#
# eu-aiact does not yet define system type concepts for Article 50 chatbot or
# content-generator obligations. These prism-local classes fill that gap.
# When eu-aiact adds the corresponding concepts, these should be replaced by
# eu-aiact terms and the pendingArticle annotations removed.
# ═════════════════════════════════════════════════════════════════════════════

prism:ChatBot
    a owl:Class ;
    rdfs:label "Chat Bot"@en ;
    rdfs:comment "An AI system designed to interact with natural persons via text or speech. Providers and deployers of chatbots must disclose to users that they are interacting with an AI system, as required by Article 50(1). Pending eu-aiact modelling of this system type."@en .

prism:AIContentGenerator
    a owl:Class ;
    rdfs:label "AI Content Generator"@en ;
    rdfs:comment "An AI system that generates synthetic images, audio, video, or text. Providers must label AI-generated content (deepfakes) under Article 50(3), and AI-generated text on matters of public interest under Article 50(4). Pending eu-aiact modelling of this system type."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 5 — RECORD TYPES
#
# Each record type corresponds to an obligation area from the EU AI Act.
# Where a matching eu-aiact concept exists, the record links to it via
# prism:evidencesObligation. Where no eu-aiact concept exists yet (DPV
# obligation modelling is a work in progress), the applicable article is
# noted in rdfs:comment for future linking.
# ═════════════════════════════════════════════════════════════════════════════

prism:ComplianceRecord
    a owl:Class ;
    rdfs:subClassOf airo:Documentation ;
    rdfs:label "Compliance Record"@en ;
    rdfs:comment "A structured record that provides evidence of compliance with one or more EU AI Act obligations. Records must be attested by a named individual to be considered evidential. Subclass of airo:Documentation."@en .

# ── Design and Build obligations ─────────────────────────────────────────────

prism:RiskManagementRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord, airo:RiskControl ;
    rdfs:label "Risk Management Record"@en ;
    rdfs:comment "Documents the risk management system for a high-risk AI system, as required by Article 9. Must cover the full lifecycle and be updated continuously. Subclass of both prism:ComplianceRecord and airo:RiskControl."@en ;
    prism:evidencesObligation eu-aiact:RiskManagementSystem ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:InceptionStage, ai:DesignStage, ai:DevelopmentStage, ai:VerificationStage, ai:ValidationStage, ai:OperationStage, ai:ContinuousValidationStage, ai:ReevaluationStage
    ] .

prism:DataGovernanceRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Data Governance Record"@en ;
    rdfs:comment "Documents data governance and management practices for training, validation, and testing datasets, as required by Article 10. Covers relevance, representativeness, error-freeness, and bias mitigation. Article 10(5) specifically requires bias detection and mitigation measures using special-category data where strictly necessary, with appropriate safeguards."@en ;
    prism:pendingArticle "Article 10"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 10(1)–(4) — general data governance for high-risk AI systems."@en ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 10(5) — bias detection and mitigation using special-category data, applicable in sectors where discriminatory outcomes are particularly harmful (employment, credit, insurance, education, essential services)."@en ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:forSector eu-aiact:EmploymentSector,
                        eu-aiact:EducationSector,
                        eu-aiact:CriticalInfrastructureSector ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage
    ] .

prism:TechnicalDocumentationRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Technical Documentation Record"@en ;
    rdfs:comment "Documents the technical documentation demonstrating compliance, as required by Article 11 and specified in Annex IV."@en ;
    prism:evidencesObligation eu-aiact:TechnicalDocumentation ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage
    ] .

prism:LoggingRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Logging Record"@en ;
    rdfs:comment "Documents the automatic logging capabilities designed into a high-risk AI system and the retention of those logs, as required by Articles 12 and 19. Article 12 requires logging capabilities to be designed in; Article 19 requires retention of logs during operation."@en ;
    prism:pendingArticle "Articles 12, 19"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage, ai:OperationStage
    ] .

prism:TransparencyRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Transparency Record"@en ;
    rdfs:comment "Documents transparency obligations. For high-risk systems (Article 13): instructions for use provided to deployers. For Article 50 systems: disclosure that users are interacting with AI (chatbots), that content is AI-generated (deepfakes), or that emotion recognition/biometric categorisation is in use."@en ;
    prism:evidencesObligation eu-aiact:InstructionForUse ;
    prism:pendingArticle "Article 50"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 13 — providers of high-risk AI systems must supply instructions for use to deployers."@en ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage, ai:DeploymentStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 50(1) — providers and deployers of chatbots must disclose to users that they are interacting with an AI system."@en ;
        prism:forActor eu-aiact:AIProvider, eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelTransparencyRequired ;
        prism:forSystemType prism:ChatBot
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 50(2)/(3)/(4) — providers must label AI-generated content (deepfakes, synthetic audio/video/images, AI-generated text on matters of public interest) and disclose emotion recognition or biometric categorisation use."@en ;
        prism:forActor eu-aiact:AIProvider, eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelTransparencyRequired ;
        prism:forSystemType eu-aiact:EmotionRecognitionSystem,
                            eu-aiact:BiometricCategorisationSystem,
                            prism:AIContentGenerator
    ] .

prism:HumanOversightRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Human Oversight Record"@en ;
    rdfs:comment "Documents the human oversight measures in place for a high-risk AI system. For providers (Article 14): design measures enabling effective human control. For deployers (Article 26): operational implementation of oversight. Must identify the named overseer, their authority, and any intervention events."@en ;
    prism:evidencesObligation eu-aiact:ProviderHumanOversightMeasure, eu-aiact:DeployerHumanOversightMeasure ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage
    ] , [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:OversightIntervention
    a owl:Class ;
    rdfs:subClassOf prism:HumanOversightRecord ;
    rdfs:label "Oversight Intervention"@en ;
    rdfs:comment "A timestamped, append-only record of a named individual overriding or modifying an AI system's output. Cryptographically hashed at write time."@en .

prism:AccuracyRobustnessRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Accuracy, Robustness and Cybersecurity Record"@en ;
    rdfs:comment "Documents the measures ensuring accuracy, robustness, and cybersecurity of a high-risk AI system, as required by Article 15."@en ;
    prism:pendingArticle "Article 15"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage
    ] .

# ── Internal Processes obligations ───────────────────────────────────────────

prism:QualityManagementRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Quality Management System Record"@en ;
    rdfs:comment "Documents the quality management system covering governance, testing, incident handling processes, and procedures for cooperation with competent authorities, as required by Article 17. Includes documented procedures for responding to authority requests per Art. 22(8), 23(8), 24(5), 26(4)."@en ;
    prism:evidencesObligation eu-aiact:QualityManagementSystem ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

prism:CorrectiveActionRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Corrective Action Record"@en ;
    rdfs:comment "Documents corrective actions taken to address non-compliance, including notifications to authorities, as required by Article 20."@en ;
    prism:pendingArticle "Article 20"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

# ── Post-Market obligations ───────────────────────────────────────────────────

prism:PostMarketMonitoringRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Post-Market Monitoring Record"@en ;
    rdfs:comment "Documents post-market monitoring activities for a high-risk AI system, including the monitoring plan and ongoing performance tracking, as required by Article 72."@en ;
    prism:evidencesObligation eu-aiact:PostMarketMonitoringSystem ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:IncidentReportingRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Incident Reporting Record"@en ;
    rdfs:comment "Documents the reporting of serious incidents to authorities within the required 15-day window, as required by Article 73 (providers, importers, distributors) and Article 26 (deployers). Links to eu-aiact:SeriousIncident which models the incident event itself."@en ;
    prism:evidencesObligation eu-aiact:SeriousIncident ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 26 — deployers must report serious incidents to provider and market surveillance authorities."@en ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 73 — importers must report serious incidents to market surveillance authorities."@en ;
        prism:forActor eu-aiact:AIImporter ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:IncidentLog
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Incident Log"@en ;
    rdfs:comment "An append-only, cryptographically hashed log of serious incidents or malfunctions involving an AI system. Use airo:hasRisk on individual log entries to link to the airo:Risk being documented."@en .

# ── Conformity Assessment and Market Entry obligations ────────────────────────

prism:ConformityAssessmentRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Conformity Assessment Record"@en ;
    rdfs:comment "Documents the conformity assessment process — either self-assessment (Module A) for most systems, or third-party assessment for biometric and Annex I systems — as required by Articles 43–44."@en ;
    prism:evidencesObligation eu-aiact:ConformityAssessment ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Self-assessment (Module A) — applies to most high-risk systems."@en ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:VerificationStage, ai:ValidationStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Third-party assessment required for biometric systems and Annex I safety components (Article 43(1))."@en ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh-A6-1 ;
        prism:atLifecycleStage ai:VerificationStage, ai:ValidationStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Third-party assessment required for biometric identification/categorisation systems (Article 43(1))."@en ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh-A6-2 ;
        prism:forSystemType eu-aiact:BiometricCategorisationSystem ;
        prism:atLifecycleStage ai:VerificationStage, ai:ValidationStage
    ] .

prism:SupplyChainVerificationRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Supply Chain Verification Record"@en ;
    rdfs:comment "Documents that an importer or distributor has verified the AI system's compliance with the AI Act before placing it on the market, as required by Articles 23(1)–(2) and 24(1)–(2)."@en ;
    prism:evidencesObligation eu-aiact:ConformityAssessment ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIImporter ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] , [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDistributor ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:DocumentRetentionRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Document Retention Record"@en ;
    rdfs:comment "Documents that the importer maintains a copy of the EU Declaration of Conformity and has access to technical documentation for 10 years after the AI system has been placed on the market, as required by Article 23(5)."@en ;
    prism:pendingArticle "Article 23(5)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIImporter ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage, ai:OperationStage
    ] .

prism:NonConformityRegister
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Non-Conformity Register"@en ;
    rdfs:comment "Documents the register of non-conforming AI systems, complaints, and recalls maintained by the importer, including investigations conducted and notifications to distributors, as required by Articles 23(6)–(7)."@en ;
    prism:pendingArticle "Articles 23(6), 23(7)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIImporter ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:DeclarationOfConformityRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "EU Declaration of Conformity Record"@en ;
    rdfs:comment "Documents the formal EU Declaration of Conformity statement, as required by Article 47."@en ;
    prism:evidencesObligation eu-aiact:EUDeclarationOfConformity ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:CEMarkingRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "CE Marking Record"@en ;
    rdfs:comment "Documents that the CE conformity marking has been affixed to the AI system, as required by Article 48."@en ;
    prism:evidencesObligation eu-aiact:CEMarking ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:MarketRegistrationRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "EU AI Database Registration Record"@en ;
    rdfs:comment "Documents registration in the EU AI Database, mandatory before placing a high-risk AI system on the market, as required by Articles 49 and 71. Authorised representatives may perform registration on behalf of the provider per Article 22(3)(a). Public sector deployers must also register before putting high-risk systems into service per Article 49(2)."@en ;
    prism:pendingArticle "Articles 49, 71"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 22(3)(a) — authorised representative registers on behalf of provider."@en ;
        prism:forActor eu-aiact:AuthorisedRepresentative ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 49(2) — public authorities and Union institutions must register before putting high-risk systems into service."@en ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:forEntityType eu-aiact:PublicSector ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

# ── Deployer obligations ──────────────────────────────────────────────────────

prism:UsePerInstructionsRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Use per Instructions Record"@en ;
    rdfs:comment "Documents that the deployer is using the AI system in accordance with the provider's Instructions for Use, as required by Article 26."@en ;
    prism:pendingArticle "Article 26"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:InputDataQualityRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Input Data Quality Record"@en ;
    rdfs:comment "Documents that the deployer ensures appropriate input data is fed to the AI system during operation, as required by Article 26."@en ;
    prism:pendingArticle "Article 26"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:OperationalMonitoringRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Operational Monitoring Record"@en ;
    rdfs:comment "Documents the deployer's ongoing monitoring of AI system performance during use, as required by Article 26."@en ;
    prism:pendingArticle "Article 26"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:WorkerNotificationRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Worker Notification Record"@en ;
    rdfs:comment "Documents that employees and their representatives have been informed where AI systems are used in decisions affecting them, as required by Article 26."@en ;
    prism:pendingArticle "Article 26"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:RightToExplanationRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Right to Explanation Record"@en ;
    rdfs:comment "Documents the deployer's mechanism for providing affected persons with a meaningful explanation of the role the AI system played in a decision, as required by Article 86. Evidenced by explanation templates, documented explanation procedures, or logs of explanations provided to individuals."@en ;
    prism:pendingArticle "Article 86"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

# ── GPAI Model Provider obligations (Chapter 5) ──────────────────────────────
#
# Obligations for providers of general-purpose AI models under Articles 53–55.
# These apply based on model type (GPAI or GPAI with systemic risk), not the
# risk-level classification used for AI systems under Chapter 3.

prism:GPAITransparencyRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "GPAI Transparency Record"@en ;
    rdfs:comment "Documents the information and documentation made available to downstream AI system providers to allow them to understand the capabilities and limitations of the GPAI model, as required by Article 53(1)(a). Includes model capabilities, limitations, intended and foreseeable misuse, and integration guidance."@en ;
    prism:pendingArticle "Article 53(1)(a)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forSystemType eu-aiact:GPAIModel ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage, ai:DeploymentStage
    ] .

prism:GPAITechnicalDocRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "GPAI Technical Documentation Record"@en ;
    rdfs:comment "Documents the technical documentation for a GPAI model, including training methodologies, data sources, computational resources, and evaluation results, as required by Article 53(1)(b). Must be kept up to date and made available to the AI Office and national authorities upon request."@en ;
    prism:pendingArticle "Article 53(1)(b)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forSystemType eu-aiact:GPAIModel ;
        prism:atLifecycleStage ai:DesignStage, ai:DevelopmentStage
    ] .

prism:CopyrightPolicyRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Copyright and Training Data Policy Record"@en ;
    rdfs:comment "Documents the policy for complying with Union copyright law, including the identification and respect of opt-out rights under Article 4(3) of Directive (EU) 2019/790, and a sufficiently detailed summary of training data content, as required by Article 53(1)(c)."@en ;
    prism:pendingArticle "Article 53(1)(c)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forSystemType eu-aiact:GPAIModel ;
        prism:atLifecycleStage ai:InceptionStage, ai:DesignStage, ai:DevelopmentStage
    ] .

prism:GPAIRegistrationRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "GPAI Registration Record"@en ;
    rdfs:comment "Documents registration of the GPAI model in the EU AI Database, as required by Article 53(1)(d)."@en ;
    prism:pendingArticle "Article 53(1)(d)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forSystemType eu-aiact:GPAIModel ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:AdversarialTestingRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Adversarial Testing Record"@en ;
    rdfs:comment "Documents adversarial testing and model evaluation (red-teaming) conducted on a GPAI model with systemic risk, including testing methodologies, identified vulnerabilities, and mitigation measures, as required by Article 55(1)(a). Must include state-of-the-art evaluation tools and methodologies."@en ;
    prism:pendingArticle "Article 55(1)(a)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forSystemType eu-aiact:HighImpactCapabilityGPAIModel ;
        prism:atLifecycleStage ai:VerificationStage, ai:ValidationStage, ai:ContinuousValidationStage
    ] .

prism:GPAIIncidentReportingRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "GPAI Incident Reporting Record"@en ;
    rdfs:comment "Documents the reporting of serious incidents involving a GPAI model with systemic risk to the AI Office and relevant national authorities, as required by Article 55(1)(b). Includes incident description, corrective measures taken, and communication with downstream providers."@en ;
    prism:pendingArticle "Article 55(1)(b)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forSystemType eu-aiact:HighImpactCapabilityGPAIModel ;
        prism:atLifecycleStage ai:OperationStage
    ] .

# ── Organisational-level obligations ──────────────────────────────────────────
#
# These obligations attach to the actor (provider/deployer organisation) rather
# than to individual AI systems. Use prism:hasOrganisationalRecord to link an
# actor to these records.

prism:AILiteracyRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "AI Literacy Record"@en ;
    rdfs:comment "Documents that the organisation ensures sufficient AI literacy of staff and other persons dealing with the operation and use of AI systems on their behalf, as required by Article 4. Evidenced by training records, competency frameworks, assessment results, and awareness briefings. Scoped to the organisation, not individual AI systems."@en ;
    prism:pendingArticle "Article 4"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider, eu-aiact:AIDeployer,
                       eu-aiact:AIImporter, eu-aiact:AIDistributor
    ] .

prism:ARMandateRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Authorised Representative Mandate Record"@en ;
    rdfs:comment "Documents the written mandate from a provider to an authorised representative, covering all obligations listed in Article 22(3). The mandate must be kept up to date and made available to market surveillance authorities upon request. Required by Article 22(1)–(2)."@en ;
    prism:pendingArticle "Article 22(1), 22(2)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AuthorisedRepresentative ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:InceptionStage, ai:DeploymentStage
    ] .

prism:FRIARecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord, eu-aiact:FRIA ;
    rdfs:label "Fundamental Rights Impact Assessment Record"@en ;
    rdfs:comment "Documents the FRIA conducted by a deployer, as required by Article 27. Mandatory for specific Annex III use case areas and for all Annex III systems deployed by public sector entities."@en ;
    prism:evidencesObligation eu-aiact:FRIA ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 27 — FRIA required for deployers of Annex III high-risk systems in specific sectors."@en ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh-A6-2 ;
        prism:forSector eu-aiact:EmploymentSector,
                        eu-aiact:EducationSector,
                        eu-aiact:CriticalInfrastructureSector,
                        eu-aiact:LawEnforcementSector,
                        eu-aiact:JusticeSector,
                        eu-aiact:BorderControlSector,
                        eu-aiact:MigrationSector,
                        eu-aiact:AsylumSector,
                        eu-aiact:DemocraticProcessSector
    ] , [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Article 27 — public sector deployers must conduct FRIA for all Annex III high-risk systems."@en ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh-A6-2 ;
        prism:forEntityType eu-aiact:PublicSector
    ] .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 6 — ATTESTATION
# ═════════════════════════════════════════════════════════════════════════════

prism:AttestationStatus
    a owl:Class ;
    rdfs:label "Attestation Status"@en ;
    rdfs:comment "The lifecycle status of a compliance record — Candidate (AI-extracted, unreviewed) or Attested (reviewed and signed off by a named individual)."@en .

prism:Candidate
    a prism:AttestationStatus ;
    rdfs:label "Candidate"@en ;
    rdfs:comment "Extracted by the AI connector but not yet reviewed. Does not count as evidential coverage."@en .

prism:Attested
    a prism:AttestationStatus ;
    rdfs:label "Attested"@en ;
    rdfs:comment "Reviewed and signed off by a named individual. Only attested records count as evidential coverage in gap analysis."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 7 — PROPERTIES
# ═════════════════════════════════════════════════════════════════════════════

# Use dpv:hasSector with a prism:EconomicSector instance to tag the industry domain.
# Example: ex:MyCreditScorer dpv:hasSector prism:Finance .

prism:hasComplianceRecord
    a owl:ObjectProperty ;
    rdfs:subPropertyOf airo:hasDocumentation ;
    rdfs:label "has compliance record"@en ;
    rdfs:comment "Links an AI system to a compliance record. Subproperty of airo:hasDocumentation."@en ;
    rdfs:domain airo:AISystem ;
    rdfs:range prism:ComplianceRecord .

prism:hasOrganisationalRecord
    a owl:ObjectProperty ;
    rdfs:label "has organisational record"@en ;
    rdfs:comment "Links an actor (provider, deployer, importer, distributor) to an organisation-level compliance record that is not specific to a single AI system. Used for cross-cutting obligations such as AI literacy (Art. 4)."@en ;
    rdfs:range prism:ComplianceRecord .

prism:evidencesObligation
    a owl:ObjectProperty ;
    rdfs:label "evidences obligation"@en ;
    rdfs:comment "Links a compliance record type to the eu-aiact concept(s) it provides evidence for. Where no eu-aiact concept exists yet, this property is omitted and the applicable article is noted via prism:pendingArticle."@en .

prism:pendingArticle
    a owl:DatatypeProperty ;
    rdfs:label "pending article"@en ;
    rdfs:comment "The EU AI Act article(s) this record type evidences, recorded as a string pending the availability of a machine-readable eu-aiact concept. Tooling can query for records with this property to identify gaps in eu-aiact coverage."@en ;
    rdfs:range xsd:string .

prism:hasApplicabilityCondition
    a owl:ObjectProperty ;
    rdfs:label "has applicability condition"@en ;
    rdfs:comment "Links a compliance record type or process obligation to the conditions under which it applies."@en ;
    rdfs:domain [
        a owl:Class ;
        owl:unionOf ( prism:ComplianceRecord prism:ProcessObligation )
    ] ;
    rdfs:range prism:ApplicabilityCondition .

prism:forActor
    a owl:ObjectProperty ;
    rdfs:label "for actor"@en ;
    rdfs:comment "The actor role(s) for which this condition applies."@en ;
    rdfs:domain prism:ApplicabilityCondition .

prism:forRiskLevel
    a owl:ObjectProperty ;
    rdfs:label "for risk level"@en ;
    rdfs:comment "The risk level(s) for which this condition applies."@en ;
    rdfs:domain prism:ApplicabilityCondition .

prism:atLifecycleStage
    a owl:ObjectProperty ;
    rdfs:label "at lifecycle stage"@en ;
    rdfs:comment "The AI lifecycle stage(s) at which this condition applies. Uses DPV ai:LifecycleStage (ISO/IEC 22989)."@en ;
    rdfs:domain prism:ApplicabilityCondition ;
    rdfs:range ai:LifecycleStage .

prism:forSector
    a owl:ObjectProperty ;
    rdfs:label "for sector"@en ;
    rdfs:comment "The Annex III sector for which this condition applies (e.g., eu-aiact:EmploymentSector). Uses eu-aiact sector concepts, which are subclasses of dpv:Sector. Distinct from dpv:hasSector on the AI system, which identifies the operational industry via NACE codes."@en ;
    rdfs:domain prism:ApplicabilityCondition ;
    rdfs:range dpv:Sector .

prism:forSystemType
    a owl:ObjectProperty ;
    rdfs:label "for system type"@en ;
    rdfs:comment "The AI system type classification for which this condition applies (e.g., eu-aiact:BiometricCategorisationSystem, eu-aiact:EmotionRecognitionSystem, prism:ChatBot, prism:AIContentGenerator). Only present when the obligation is triggered by a specific system type. May reference prism-local types where eu-aiact has not yet modelled the concept."@en ;
    rdfs:domain prism:ApplicabilityCondition .

prism:forEntityType
    a owl:ObjectProperty ;
    rdfs:label "for entity type"@en ;
    rdfs:comment "The type of entity (e.g., public body) for which this condition applies. Only present when the obligation has entity-specific triggers."@en ;
    rdfs:domain prism:ApplicabilityCondition .

prism:occursAtStage
    a owl:ObjectProperty ;
    rdfs:label "occurs at stage"@en ;
    rdfs:comment "Links a regulatory process to the AI lifecycle stage(s) at which it occurs. Uses DPV ai:LifecycleStage (ISO/IEC 22989)."@en ;
    rdfs:domain prism:RegulatoryProcess ;
    rdfs:range ai:LifecycleStage .

prism:hasAttestationStatus
    a owl:ObjectProperty ;
    rdfs:label "has attestation status"@en ;
    rdfs:domain prism:ComplianceRecord ;
    rdfs:range prism:AttestationStatus .

prism:attestedBy
    a owl:ObjectProperty ;
    rdfs:label "attested by"@en ;
    rdfs:domain prism:ComplianceRecord .

prism:attestedAt
    a owl:DatatypeProperty ;
    rdfs:label "attested at"@en ;
    rdfs:domain prism:ComplianceRecord ;
    rdfs:range xsd:dateTime .

prism:extractionConfidence
    a owl:DatatypeProperty ;
    rdfs:label "extraction confidence"@en ;
    rdfs:comment "Confidence score (0.0–1.0) assigned by the AI connector at extraction time."@en ;
    rdfs:domain prism:ComplianceRecord ;
    rdfs:range xsd:decimal .

prism:sha256Hash
    a owl:DatatypeProperty ;
    rdfs:label "SHA-256 hash"@en ;
    rdfs:comment "Hash of the named graph at write time, for immutability verification."@en ;
    rdfs:domain prism:ComplianceRecord ;
    rdfs:range xsd:string .

prism:ontologyVersion
    a owl:DatatypeProperty ;
    rdfs:label "ontology version"@en ;
    rdfs:comment "The PRISM version under which this record was attested. Used to flag records for re-review when the ontology updates."@en ;
    rdfs:domain prism:ComplianceRecord ;
    rdfs:range xsd:string .

prism:reviewCadence
    a owl:ObjectProperty ;
    rdfs:label "review cadence"@en .

prism:Annual
    a owl:NamedIndividual ;
    rdfs:label "Annual"@en .

prism:Continuous
    a owl:NamedIndividual ;
    rdfs:label "Continuous"@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 8 — PROCESS OBLIGATIONS
#
# Obligations that are behavioural or operational in nature and do not produce
# standalone compliance records. Tracked for completeness and queryability.
# Evidence of compliance is typically subsumed by the Quality Management System
# or demonstrated through operational procedures.
#
# These are NOT subclasses of prism:ComplianceRecord — they do not require
# attestation. Use prism:hasApplicabilityCondition to query which process
# obligations apply to a given actor/risk level/stage combination.
# ═════════════════════════════════════════════════════════════════════════════

prism:ProcessObligation
    a owl:Class ;
    rdfs:label "Process Obligation"@en ;
    rdfs:comment "An EU AI Act obligation that is behavioural or operational in nature and does not produce a standalone compliance record. Tracked for completeness and queryability. Evidence of compliance is typically subsumed by the Quality Management System or demonstrated through operational procedures."@en .

# ── Importer process obligations (Art. 23) ────────────────────────────────────

prism:ImporterContactInformation
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Importer Contact Information"@en ;
    rdfs:comment "Importer must indicate their name, registered trade name or registered trade mark, and the address at which they can be contacted on the AI system or its packaging, as required by Article 23(3)."@en ;
    prism:pendingArticle "Article 23(3)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIImporter ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:ImporterStorageTransport
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Importer Storage and Transport Conditions"@en ;
    rdfs:comment "Importer must ensure appropriate storage and transport conditions do not jeopardise the AI system's compliance, as required by Article 23(4)."@en ;
    prism:pendingArticle "Article 23(4)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIImporter ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:ImporterCooperation
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Importer Cooperation with Authorities"@en ;
    rdfs:comment "Importer must cooperate with market surveillance authorities and provide all requested information and documentation to demonstrate conformity, as required by Article 23(8)."@en ;
    prism:pendingArticle "Article 23(8)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIImporter ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

# ── Distributor process obligations (Art. 24) ─────────────────────────────────

prism:DistributorStorageTransport
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Distributor Storage and Transport Conditions"@en ;
    rdfs:comment "Distributor must ensure appropriate storage and transport conditions while the system is under their responsibility, as required by Article 24(3)."@en ;
    prism:pendingArticle "Article 24(3)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDistributor ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:DistributorNonConformityNotification
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Distributor Non-Conformity Notification"@en ;
    rdfs:comment "Distributor must inform provider or importer and market surveillance authority if the AI system presents a serious risk or is non-conforming, as required by Article 24(4)."@en ;
    prism:pendingArticle "Article 24(4)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDistributor ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:DistributorCooperation
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Distributor Cooperation with Authorities"@en ;
    rdfs:comment "Distributor must cooperate with market surveillance authorities and provide all requested information and documentation, as required by Article 24(5)."@en ;
    prism:pendingArticle "Article 24(5)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDistributor ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

# ── Deemed-provider rule (Art. 25) ────────────────────────────────────────────

prism:DeemedProviderObligation
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Deemed Provider Obligation"@en ;
    rdfs:comment "Where an importer, distributor, or authorised representative places an AI system on the market under their own name or trade mark, or makes a substantial modification, they assume full provider obligations under Chapter 3, as required by Article 25(1). This is a role transition trigger, not a standalone record."@en ;
    prism:pendingArticle "Article 25(1)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIImporter, eu-aiact:AIDistributor, eu-aiact:AuthorisedRepresentative ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

# ── Authorised Representative process obligations (Art. 22) ───────────────────

prism:ARCooperation
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Authorised Representative Cooperation with Authorities"@en ;
    rdfs:comment "Authorised representative must cooperate with competent authorities upon reasoned request and carry out tasks to ensure compliance, as required by Article 22(3)(c)."@en ;
    prism:pendingArticle "Article 22(3)(c)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AuthorisedRepresentative ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

prism:ARProvideDocumentation
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Authorised Representative Documentation Provision"@en ;
    rdfs:comment "Authorised representative must provide market surveillance authority with all information and documentation necessary to demonstrate conformity of the high-risk AI system, as required by Article 22(3)(b)."@en ;
    prism:pendingArticle "Article 22(3)(b)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AuthorisedRepresentative ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

prism:ARMandateTermination
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Authorised Representative Mandate Termination"@en ;
    rdfs:comment "Authorised representative must terminate the mandate and immediately inform market surveillance authority if the provider acts in non-compliance with its obligations, as required by Article 22(4)."@en ;
    prism:pendingArticle "Article 22(4)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AuthorisedRepresentative ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh
    ] .

# ── Provider meta-obligation (Art. 16) ────────────────────────────────────────

prism:ProviderComplianceChecklist
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Provider Obligations Compliance List"@en ;
    rdfs:comment "Article 16 lists the full set of provider obligations for high-risk AI systems (Arts. 9–49). Compliance is evidenced by having all required ComplianceRecords in place — this is a meta-obligation, not a standalone record. Gap analysis queries against this obligation should check for completeness of all provider record types."@en ;
    prism:pendingArticle "Article 16"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:InceptionStage
    ] .

prism:AppointAuthorisedRepresentative
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Appointment of Authorised Representative"@en ;
    rdfs:comment "Providers established outside the EU must appoint an authorised representative by written mandate before placing a high-risk AI system on the EU market, as required by Article 22. Evidence of compliance is the ARMandateRecord held by the appointed representative."@en ;
    prism:pendingArticle "Article 22"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:InceptionStage
    ] .

# ── Deployer process obligations ──────────────────────────────────────────────

prism:DeployerRegistrationVerification
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Deployer Registration Verification"@en ;
    rdfs:comment "Private-sector deployers must verify, before putting a high-risk AI system into service, that the provider has registered it in the EU AI Database as required by Article 49(1). Where the deployer is a public authority, they bear their own registration obligation under Article 49(2) — this obligation covers the non-public-sector case only. Evidence of compliance is typically a dated screenshot or confirmation from the EU AI Database, held within the Quality Management System."@en ;
    prism:pendingArticle "Articles 27(1), 49(1), 49(3)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        rdfs:comment "Applies to all non-public-sector deployers of high-risk systems at the point of deployment."@en ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:atLifecycleStage ai:DeploymentStage
    ] .

prism:RemoteBiometricNotification
    a prism:ProcessObligation, owl:NamedIndividual ;
    rdfs:label "Remote Biometric Identification Notification"@en ;
    rdfs:comment "Deployers using post-remote biometric identification systems must comply with additional notification and authorisation requirements, as required by Article 26(11). Includes notification to relevant authorities and compliance with national law restrictions."@en ;
    prism:pendingArticle "Article 26(11)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:forSystemType eu-aiact:BiometricCategorisationSystem ;
        prism:atLifecycleStage ai:OperationStage
    ] .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9 — AGENTIC AI PROFILE
#
# A profile for agentic AI systems: agent components, action-space and
# autonomy classifications, control taxonomies, oversight design and
# effectiveness records, agent identity and delegation-of-authority records,
# agentic risk concepts, and agent-specific testing and change management
# records.
#
# Vocabulary drawn from IMDA (Singapore), Model AI Governance Framework for
# Agentic AI, v1.5, published 20 May 2026 (updated 5 June 2026):
#   PDF:      https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf
#   Overview: https://www.imda.gov.sg/about-imda/emerging-technologies-and-research/artificial-intelligence
#
# Scope note: the IMDA MGF is voluntary best-practice guidance, not law.
# Where a term below notes that it "supports" or "evidences" an EU AI Act
# article, that mapping is interpretive and should be reviewed by qualified
# counsel before reliance in a regulatory context.
# ═════════════════════════════════════════════════════════════════════════════

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9a — AGENTIC SYSTEM PROFILE
#
# MGF §1.1: an agentic AI system consists of one or more AI agents with some
# degree of independent planning, decision-making, and action-taking over
# multiple steps towards a user-defined goal.
#
# Under the EU AI Act the compliance subject remains the AI system; this
# profile records the agentic properties that determine how obligations such
# as human oversight (Art. 14/26), logging (Art. 12) and risk management
# (Art. 9) are fulfilled in practice.
# ═════════════════════════════════════════════════════════════════════════════

prism:AgenticAISystem
    a owl:Class ;
    rdfs:subClassOf airo:AISystem ;
    rdfs:label "Agentic AI System"@en ;
    rdfs:comment "An AI system consisting of one or more AI agents that possess some degree of independent planning, decision-making, and action-taking over multiple steps to achieve a user-defined goal (IMDA MGF for Agentic AI §1.1). Describe its bounds with prism:hasAutonomyLevel, prism:hasAgentComponent and prism:hasAgentControl."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

prism:MultiAgentSystem
    a owl:Class ;
    rdfs:subClassOf prism:AgenticAISystem ;
    rdfs:label "Multi-Agent System"@en ;
    rdfs:comment "An agentic AI system in which multiple agents work together, whether sequentially, under a supervisor, or as a swarm (MGF §1.1.2). Member agents are linked with prism:comprisesAgent; the coordination pattern with prism:hasArchitecture. Multi-agent setups increase exposure to the systemic risks in Section 9e (miscoordination, conflict, collusion, emergent behaviour)."@en .

prism:AgentArchitecture
    a owl:Class ;
    rdfs:label "Agent Architecture"@en ;
    rdfs:comment "A coordination pattern for a multi-agent system (MGF §1.1.2)."@en .

prism:SequentialArchitecture
    a prism:AgentArchitecture ;
    rdfs:label "Sequential Architecture"@en ;
    rdfs:comment "Agents work one after another in a linear or otherwise structured workflow; each agent's output becomes the next agent's input."@en .

prism:SupervisorArchitecture
    a prism:AgentArchitecture ;
    rdfs:label "Supervisor Architecture"@en ;
    rdfs:comment "One supervising agent coordinates specialised agents under it, calling specific agents as tools when required."@en .

prism:SwarmArchitecture
    a prism:AgentArchitecture ;
    rdfs:label "Swarm Architecture"@en ;
    rdfs:comment "Agents work at the same time, handing off to another agent when needed."@en .

# ── Agent components (MGF §1.1.1) ────────────────────────────────────────────

prism:AgentComponent
    a owl:Class ;
    rdfs:label "Agent Component"@en ;
    rdfs:comment "A core component of an agentic AI system as taxonomised in MGF §1.1.1: model, instructions, memory, planning and reasoning, tools, protocols, controls, and logging and monitoring. Each component is a distinct source of risk (MGF §1.2.1) and a distinct locus for technical controls (MGF §2.3.1)."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

prism:ModelComponent
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent ;
    rdfs:label "Model Component"@en ;
    rdfs:comment "The SLM, LLM or MLLM serving as the central reasoning and planning engine of the agent."@en .

prism:InstructionComponent
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent ;
    rdfs:label "Instruction Component"@en ;
    rdfs:comment "Natural language commands defining the agent's role, capabilities and behavioural constraints, e.g. a system prompt. The level of instruction detail (detailed SOP vs own judgment) is a primary determinant of autonomy."@en .

prism:MemoryComponent
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent ;
    rdfs:label "Memory Component"@en ;
    rdfs:comment "Short or long-term information storage accessible to the agent. Persistent memory that can store sensitive data across sessions increases the impact of data-related risks (MGF §2.1.1) and is the target of memory poisoning attacks."@en .

prism:PlanningComponent
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent ;
    rdfs:label "Planning and Reasoning Component"@en ;
    rdfs:comment "The capability to output and follow a series of steps needed for a task. Plans can drift from user intent through hallucination or semantic misalignment (MGF §1.2.1)."@en .

prism:ToolComponent
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent ;
    rdfs:label "Tool Component"@en ;
    rdfs:comment "A tool enabling the agent to take actions and interact with other systems (files, databases, devices, transactions). The tools an agent may call, and the permissions on those tools, determine its action-space. Declare prism:hasSystemAccess and prism:hasActionScope on each tool."@en .

prism:ProtocolComponent
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent ;
    rdfs:label "Protocol Component"@en ;
    rdfs:comment "A standardised way for the agent to communicate with tools or other agents, e.g. MCP or A2A. Poorly deployed or compromised protocol endpoints (such as untrusted MCP servers) are an agent-specific attack surface (MGF §1.2.1)."@en .

prism:LoggingMonitoringComponent
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent ;
    rdfs:label "Logging and Monitoring Component"@en ;
    rdfs:comment "Records agent actions, decisions and interactions across all components to enable monitoring, debugging and accountability. For high-risk systems this component realises the Article 12 logging capability documented in a prism:LoggingRecord."@en .

# ── Action-space (MGF §1.1.3) ────────────────────────────────────────────────

prism:SystemAccessType
    a owl:Class ;
    rdfs:label "System Access Type"@en ;
    rdfs:comment "The kind of system a tool, or an agent through its tools, can reach (MGF §1.1.3, action-space). One axis of the action-space; the other is prism:ActionScope."@en .

prism:SandboxedAccess
    a prism:SystemAccessType ;
    rdfs:label "Sandboxed Access"@en ;
    rdfs:comment "Sandboxed tools (e.g. for code execution or data analysis) that cannot affect any other system."@en .

prism:InternalSystemAccess
    a prism:SystemAccessType ;
    rdfs:label "Internal System Access"@en ;
    rdfs:comment "Tools internal to the organisation, such as searching and updating the organisation's databases."@en .

prism:ExternalSystemAccess
    a prism:SystemAccessType ;
    rdfs:label "External System Access"@en ;
    rdfs:comment "Tools that reach external services, e.g. third-party APIs or the open web. Raises both impact (data can leak to third parties) and likelihood (exposure to prompt injection from untrusted content) of risks (MGF §2.1.1)."@en .

prism:ActionScope
    a owl:Class ;
    rdfs:label "Action Scope"@en ;
    rdfs:comment "Whether the agent can only read from, or can also modify, the systems it has access to (MGF §1.1.3)."@en .

prism:ReadOnlyScope
    a prism:ActionScope ;
    rdfs:label "Read-Only Scope"@en ;
    rdfs:comment "The agent may only read and retrieve information from the system."@en .

prism:ReadWriteScope
    a prism:ActionScope ;
    rdfs:label "Read-Write Scope"@en ;
    rdfs:comment "The agent may write to and modify data in the system. Consider the reversibility of those modifications when assessing impact (MGF §2.1.1)."@en .

# ── Autonomy levels (MGF §1.1.3) ─────────────────────────────────────────────

prism:AutonomyLevel
    a owl:Class ;
    rdfs:label "Autonomy Level"@en ;
    rdfs:comment "The degree to which the agent decides how to act towards a goal, determined by its instructions and the level of human involvement (MGF §1.1.3, drawing on the Knight First Amendment Institute's Levels of Autonomy for AI Agents). The declared level is key evidence for how Article 14/26 human oversight is designed."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

prism:AgentProposesHumanOperates
    a prism:AutonomyLevel ;
    rdfs:label "Agent Proposes, Human Operates"@en ;
    rdfs:comment "The human reviews and approves every agent action."@en .

prism:AgentAndHumanCollaborate
    a prism:AutonomyLevel ;
    rdfs:label "Agent and Human Collaborate"@en ;
    rdfs:comment "The agent requires human approval at significant steps (e.g. before writing to a database or making a payment); the human can intervene at any time by taking over or pausing the agent."@en .

prism:AgentOperatesHumanApproves
    a prism:AutonomyLevel ;
    rdfs:label "Agent Operates, Human Approves"@en ;
    rdfs:comment "The agent requires human approval only at critical steps or failures, such as deleting a database or making a payment above a predefined amount."@en .

prism:AgentOperatesHumanObserves
    a prism:AutonomyLevel ;
    rdfs:label "Agent Operates, Human Observes"@en ;
    rdfs:comment "The agent does not require human approval as it completes its task; its actions may be audited after the fact."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9b — AGENT CONTROLS
#
# MGF §1.1.1 (component 7) and §2.3.1. Controls limit the agent's action-space
# and autonomy. The MGF's selection principle: prefer deterministic,
# structural limits bound by design over prompt-layer safeguards, and layer
# monitoring or human review where limits are non-deterministic.
# ═════════════════════════════════════════════════════════════════════════════

prism:AgentControl
    a owl:Class ;
    rdfs:subClassOf prism:AgentComponent , dpv:RiskMitigationMeasure ;
    rdfs:label "Agent Control"@en ;
    rdfs:comment "A control limiting an agent's action-space or autonomy (MGF §1.1.1). Declare the enforcement layer with prism:implementedAtLayer; prefer structural over prompt-layer enforcement for higher-risk actions (MGF §2.3.1)."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

prism:AccessControl
    a owl:Class ;
    rdfs:subClassOf prism:AgentControl ;
    rdfs:label "Access Control"@en ;
    rdfs:comment "Limits what an agent is allowed to see, use or change, including restricting access to sensitive data, tools and systems."@en .

prism:Guardrail
    a owl:Class ;
    rdfs:subClassOf prism:AgentControl ;
    rdfs:label "Guardrail"@en ;
    rdfs:comment "Monitors and constrains an agent's behaviour before, during or after it acts; can detect unsafe instructions, policy violations, or actions inconsistent with user intent."@en .

prism:HumanApprovalControl
    a owl:Class ;
    rdfs:subClassOf prism:AgentControl ;
    rdfs:label "Human Approval Control"@en ;
    rdfs:comment "A requirement for a human to review or approve agent actions. Its placement is designed through prism:OversightCheckpoint definitions."@en .

prism:ControlLayer
    a owl:Class ;
    rdfs:label "Control Layer"@en ;
    rdfs:comment "The layer at which a control is enforced (MGF §2.3.1). Structural controls are deterministic and cannot be bypassed by the model; prompt-layer controls are inconsistently defined across users and may be bypassed or forgotten."@en .

prism:StructuralLayer
    a prism:ControlLayer ;
    rdfs:label "Structural Layer"@en ;
    rdfs:comment "Deterministic, system-level enforcement through predefined logic, e.g. access controls at the tool layer that prevent a tool from being called at all."@en .

prism:ModelBasedLayer
    a prism:ControlLayer ;
    rdfs:label "Model-Based Layer"@en ;
    rdfs:comment "Enforcement via a model-based safeguard, most effective where risks are hard to define through fixed rules, e.g. harmful-content detection."@en .

prism:PromptLayer
    a prism:ControlLayer ;
    rdfs:label "Prompt Layer"@en ;
    rdfs:comment "Enforcement via instructions in the agent's prompt. Weakest layer: may be bypassed or inconsistently applied; avoid as the sole control for higher-risk actions."@en .

prism:RuntimeLayer
    a prism:ControlLayer ;
    rdfs:label "Runtime Layer"@en ;
    rdfs:comment "Enforcement that monitors and intervenes during execution, e.g. rate limits on tool use or input validation before responses are acted upon."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9c — OVERSIGHT DESIGN AND EFFECTIVENESS
#
# MGF §2.2.2: define significant checkpoints requiring human approval, train
# and audit the humans approving, and complement with automated monitoring.
# The MGF's oversight-effectiveness indicators (human override rates, review
# response times) are direct evidence for the Article 14(4)(b) requirement
# that oversight measures address automation bias.
# ═════════════════════════════════════════════════════════════════════════════

prism:OversightCheckpoint
    a owl:Class ;
    rdfs:label "Oversight Checkpoint"@en ;
    rdfs:comment "A defined point or action boundary in an agentic workflow at which human approval is required before the agent proceeds (MGF §2.2.2). Attach to the system or to a prism:HumanOversightRecord via prism:hasOversightCheckpoint; classify the boundary with prism:hasCheckpointTrigger."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

prism:CheckpointTrigger
    a owl:Class ;
    rdfs:label "Checkpoint Trigger"@en ;
    rdfs:comment "The category of action boundary that makes a checkpoint significant (MGF §2.2.2)."@en .

prism:HighStakesAction
    a prism:CheckpointTrigger ;
    rdfs:label "High-Stakes Action"@en ;
    rdfs:comment "Actions such as editing sensitive data, final decisions in high-risk domains, or actions that may trigger liability."@en .

prism:IrreversibleAction
    a prism:CheckpointTrigger ;
    rdfs:label "Irreversible Action"@en ;
    rdfs:comment "Actions that cannot easily be undone, e.g. permanently deleting data, sending communications, making payments."@en .

prism:OutlierBehaviour
    a prism:CheckpointTrigger ;
    rdfs:label "Outlier or Atypical Behaviour"@en ;
    rdfs:comment "The agent accessing a system outside its work scope or selecting an action far outside historical norms."@en .

prism:UserDefinedBoundary
    a prism:CheckpointTrigger ;
    rdfs:label "User-Defined Boundary"@en ;
    rdfs:comment "A boundary the end user defines beyond organisation-set limits, reflecting their own risk appetite, e.g. requiring approval for purchases above an amount."@en .

prism:OversightEffectivenessRecord
    a owl:Class ;
    rdfs:subClassOf prism:HumanOversightRecord, prism:ComplianceRecord ;
    rdfs:label "Oversight Effectiveness Record"@en ;
    rdfs:comment "Documents measures ensuring that human oversight of an agentic system remains effective over time, notwithstanding automation bias and alert fatigue: measured human override rates, review response times, outlier-reviewer analysis, and overseer training (MGF §2.2.2). Evidences the Article 14(4) requirement that oversight measures enable persons to remain aware of automation bias, and its operational counterpart in Article 26(2)."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> ;
    prism:pendingArticle "Articles 14(4), 26(2)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider, eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:forSystemType prism:AgenticAISystem ;
        prism:atLifecycleStage ai:OperationStage
    ] .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9d — AGENT IDENTITY AND DELEGATION
#
# MGF §2.1.2 (Agent identity): an agent's identity should be unique,
# accounted for (tied to a supervising agent, human user or department),
# differentiated by the capacity in which it acts, and centrally catalogued.
# Authorisations should be scoped, least-privilege, non-transferable, and
# bounded by the authorising human's own permissions, with delegations of
# authority clearly recorded.
# ═════════════════════════════════════════════════════════════════════════════

prism:AgentIdentityRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Agent Identity Record"@en ;
    rdfs:comment "Documents the unique identity of a deployed agent, the party accountable for it, the capacity in which it acts, and its entry in a central agent registry (MGF §2.1.2). Supports Article 12 traceability and helps prevent agent sprawl. Best-practice record derived from the IMDA MGF; not itself an EU AI Act obligation."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> ;
    prism:pendingArticle "Article 12 (traceability, agentic profile)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider, eu-aiact:AIDeployer ;
        prism:forSystemType prism:AgenticAISystem
    ] .

prism:DelegationRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Delegation of Authority Record"@en ;
    rdfs:comment "Records a delegation of authority from a human user or organisational role to an agent: who delegated, to which agent, the permission scope granted, and its validity window (MGF §2.1.2). The agent's permissions should not exceed those of the authorising human. Supports Article 14/26 oversight evidence and Article 12 traceability."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> ;
    prism:pendingArticle "Articles 12, 14, 26 (agentic profile)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIDeployer ;
        prism:forSystemType prism:AgenticAISystem ;
        prism:atLifecycleStage ai:DeploymentStage, ai:OperationStage
    ] .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9e — AGENTIC RISKS
#
# MGF §1.2 and §2.1.1. Risk concepts specific to, or amplified by, agentic
# systems. Subclasses of airo:Risk; instantiate and link from a system via
# airo:hasRisk, and address them in the prism:RiskManagementRecord (Art. 9).
# ═════════════════════════════════════════════════════════════════════════════

prism:AgenticRisk
    a owl:Class ;
    rdfs:subClassOf airo:Risk ;
    rdfs:label "Agentic Risk"@en ;
    rdfs:comment "A risk specific to, or significantly amplified by, agentic AI systems (IMDA MGF for Agentic AI §1.2). Use with airo:hasRisk."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

prism:CascadingFailure
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Cascading Failure"@en ;
    rdfs:comment "A mistake in one step propagating and amplifying across later steps of a multi-step workflow, resulting in outsized impact."@en .

prism:AgentSprawl
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Agent Sprawl"@en ;
    rdfs:comment "Uncontrolled proliferation of agents without centralised management, causing provenance, compatibility and manageability issues. Mitigated by central identity cataloguing (prism:AgentIdentityRecord)."@en .

prism:Miscoordination
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Miscoordination"@en ;
    rdfs:comment "Agents working together failing through bad communication or diverging interpretations of user intent."@en .

prism:AgentConflict
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Agent Conflict"@en ;
    rdfs:comment "Agents optimising different goals coming into conflict, e.g. a support agent offering refunds a revenue-protection agent blocks."@en .

prism:AgentCollusion
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Agent Collusion"@en ;
    rdfs:comment "Agents developing behaviours that appear coordinated without explicit instruction, e.g. pricing agents converging on higher prices rather than competing."@en .

prism:EmergentBehaviour
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Emergent Behaviour"@en ;
    rdfs:comment "Unpredictable behaviour arising when multiple non-deterministic agents interact, which cannot be predicted from testing each agent individually."@en .

prism:MemoryPoisoning
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Memory Poisoning"@en ;
    rdfs:comment "An attacker inserting content into an agent's persistent memory to influence later decisions (MGF §2.1.1 threat modelling)."@en .

prism:ToolMisuse
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Tool Misuse"@en ;
    rdfs:comment "The agent calling the wrong tools, the right tools with wrong inputs, hallucinated tools, or tools in a biased manner (MGF §1.2.1)."@en .

prism:PromptInjection
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Prompt Injection"@en ;
    rdfs:comment "Adversarial instructions embedded in content the agent processes (documents, web pages, tool outputs) redirecting it towards harmful actions, including data exfiltration through its tool access."@en .

prism:PrivilegeCompromise
    a owl:Class ;
    rdfs:subClassOf prism:AgenticRisk ;
    rdfs:label "Privilege Compromise"@en ;
    rdfs:comment "An attacker exploiting the agent's credentials or permissions to act beyond the intended authorisation (MGF §2.1.1 threat modelling)."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9f — AGENTIC TESTING AND CHANGE MANAGEMENT
#
# MGF §2.3.2 (pre-deployment testing dimensions) and §2.3.3 (change
# management). These specialise the Article 15 accuracy/robustness evidence
# and the Article 72 post-market monitoring evidence for agentic systems.
# ═════════════════════════════════════════════════════════════════════════════

prism:AgenticTestingRecord
    a owl:Class ;
    rdfs:subClassOf prism:AccuracyRobustnessRecord, prism:ComplianceRecord ;
    rdfs:label "Agentic Testing Record"@en ;
    rdfs:comment "Documents agent-specific pre-deployment testing across the MGF §2.3.2 dimensions (overall task execution, policy adherence, tool calling, robustness), including whole-workflow testing, multi-agent testing, testing in realistic environments, and repeated runs across varied datasets. Specialises the Article 15 evidence for agentic systems; declare covered dimensions with prism:coversTestingDimension."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> ;
    prism:pendingArticle "Article 15 (agentic profile)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider, eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:forSystemType prism:AgenticAISystem ;
        prism:atLifecycleStage ai:VerificationStage, ai:ValidationStage
    ] .

prism:TestingDimension
    a owl:Class ;
    rdfs:label "Testing Dimension"@en ;
    rdfs:comment "A dimension of agent-specific testing (MGF §2.3.2)."@en .

prism:OverallTaskExecution
    a prism:TestingDimension ;
    rdfs:label "Overall Task Execution"@en ;
    rdfs:comment "Whether the agent can complete its task accurately."@en .

prism:PolicyAdherence
    a prism:TestingDimension ;
    rdfs:label "Policy Adherence"@en ;
    rdfs:comment "Whether the agent follows defined SOPs and routes for human approval when required."@en .

prism:ToolCallingAccuracy
    a prism:TestingDimension ;
    rdfs:label "Tool Calling Accuracy"@en ;
    rdfs:comment "Whether the agent calls the right tools, with the right permissions, with the right inputs, in the right order."@en .

prism:AgentRobustness
    a prism:TestingDimension ;
    rdfs:label "Agent Robustness"@en ;
    rdfs:comment "The agent's response to errors and edge cases as it reacts and adapts to real-world situations."@en .

prism:AgentChangeManagementRecord
    a owl:Class ;
    rdfs:subClassOf prism:ComplianceRecord ;
    rdfs:label "Agent Change Management Record"@en ;
    rdfs:comment "Documents a change to an agentic system under a defined change review process: the trigger that initiated review and the risk category of the change (MGF §2.3.3). Material and critical changes inform the substantial-modification analysis under Articles 25(1)(b) and 43(4), and feed Article 72 post-market monitoring."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> ;
    prism:pendingArticle "Articles 25(1)(b), 43(4), 72 (agentic profile)"@en ;
    prism:hasApplicabilityCondition [
        a prism:ApplicabilityCondition ;
        prism:forActor eu-aiact:AIProvider, eu-aiact:AIDeployer ;
        prism:forRiskLevel eu-aiact:RiskLevelHigh ;
        prism:forSystemType prism:AgenticAISystem ;
        prism:atLifecycleStage ai:OperationStage
    ] .

prism:ChangeTrigger
    a owl:Class ;
    rdfs:label "Change Trigger"@en ;
    rdfs:comment "The kind of event that initiates a change review (MGF §2.3.3)."@en .

prism:TechnicalTrigger
    a prism:ChangeTrigger ;
    rdfs:label "Technical Trigger"@en ;
    rdfs:comment "Model updates, tool modifications."@en .

prism:EnvironmentalTrigger
    a prism:ChangeTrigger ;
    rdfs:label "Environmental Trigger"@en ;
    rdfs:comment "Domain shifts, business context changes."@en .

prism:PerformanceTrigger
    a prism:ChangeTrigger ;
    rdfs:label "Performance Trigger"@en ;
    rdfs:comment "Anomalous behaviour, degraded performance."@en .

prism:RegulatoryTrigger
    a prism:ChangeTrigger ;
    rdfs:label "Regulatory Trigger"@en ;
    rdfs:comment "Changes in compliance requirements."@en .

prism:ChangeCategory
    a owl:Class ;
    rdfs:label "Change Category"@en ;
    rdfs:comment "The risk categorisation of a reviewed change (MGF §2.3.3)."@en .

prism:MinorChange
    a prism:ChangeCategory ;
    rdfs:label "Minor Change"@en ;
    rdfs:comment "E.g. prompt refinements; follows a lighter review process."@en .

prism:MaterialChange
    a prism:ChangeCategory ;
    rdfs:label "Material Change"@en ;
    rdfs:comment "E.g. model updates or autonomy adjustments; may require a full governance review and a substantial-modification assessment under Articles 25(1)(b)/43(4)."@en .

prism:CriticalChange
    a prism:ChangeCategory ;
    rdfs:label "Critical Change"@en ;
    rdfs:comment "Changes affecting high-stakes decisions; may mandate an immediate re-risk assessment."@en .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9g — VALUE CHAIN ROLES
#
# MGF §2.2.1 refines the agentic value chain: model developers and tooling
# providers feed platform providers, then system providers / app developers,
# then deployers, then end users. The EU AI Act only names provider,
# deployer, importer, distributor and authorised representative; the roles
# below capture agentic actors the Act does not model. An organisation that
# builds agents on a third-party platform and puts them into service under
# its own name may become a provider under Article 25 (see
# prism:DeemedProviderObligation).
# ═════════════════════════════════════════════════════════════════════════════

prism:ToolingProvider
    a owl:Class ;
    rdfs:subClassOf dpv:Entity ;
    rdfs:label "Tooling Provider"@en ;
    rdfs:comment "An entity providing tools or protocol infrastructure that agents rely on, e.g. hosts of MCP servers or third-party APIs (MGF §2.2.1). Not an EU AI Act actor; obligations towards it are contractual and should be recorded per MGF §2.2.1 (distribution of obligations, third-party opacity)."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

prism:AgentPlatformProvider
    a owl:Class ;
    rdfs:subClassOf dpv:Entity ;
    rdfs:label "Agent Platform Provider"@en ;
    rdfs:comment "An entity providing the platform on which agentic systems are built or operated (MGF §2.2.1). Distinct from the eu-aiact:AIProvider of the resulting system; the platform relationship affects visibility and control and belongs in the risk assessment (MGF §2.1.1, third-party solutions factor)."@en ;
    dct:source <https://www.imda.gov.sg/assets/63438074-73f6-4dcc-a281-030f42642cf4.pdf> .

# ═════════════════════════════════════════════════════════════════════════════
# SECTION 9h — PROPERTIES
# ═════════════════════════════════════════════════════════════════════════════

# ── System profile ────────────────────────────────────────────────────────────

prism:hasAgentComponent
    a owl:ObjectProperty ;
    rdfs:label "has agent component"@en ;
    rdfs:comment "Links an agentic AI system to one of its components (model, instructions, memory, planning, tools, protocols, controls, logging)."@en ;
    rdfs:domain prism:AgenticAISystem ;
    rdfs:range prism:AgentComponent .

prism:comprisesAgent
    a owl:ObjectProperty ;
    rdfs:label "comprises agent"@en ;
    rdfs:comment "Links a multi-agent system to a member agent."@en ;
    rdfs:domain prism:MultiAgentSystem ;
    rdfs:range prism:AgenticAISystem .

prism:hasArchitecture
    a owl:ObjectProperty ;
    rdfs:label "has architecture"@en ;
    rdfs:comment "The coordination pattern of a multi-agent system (sequential, supervisor, swarm)."@en ;
    rdfs:domain prism:MultiAgentSystem ;
    rdfs:range prism:AgentArchitecture .

prism:hasAutonomyLevel
    a owl:ObjectProperty ;
    rdfs:label "has autonomy level"@en ;
    rdfs:comment "The declared level of human involvement in the agent's decision-making. Key evidence for Article 14/26 oversight design."@en ;
    rdfs:domain prism:AgenticAISystem ;
    rdfs:range prism:AutonomyLevel .

prism:hasSystemAccess
    a owl:ObjectProperty ;
    rdfs:label "has system access"@en ;
    rdfs:comment "The kind of system reachable (sandboxed, internal, external). Declare on each tool component; may also summarise the widest access at system level."@en ;
    rdfs:range prism:SystemAccessType .

prism:hasActionScope
    a owl:ObjectProperty ;
    rdfs:label "has action scope"@en ;
    rdfs:comment "Read-only or read-write scope. Declare on each tool component; may also summarise the widest scope at system level."@en ;
    rdfs:range prism:ActionScope .

# ── Controls ──────────────────────────────────────────────────────────────────

prism:hasAgentControl
    a owl:ObjectProperty ;
    rdfs:subPropertyOf prism:hasAgentComponent ;
    rdfs:label "has agent control"@en ;
    rdfs:comment "Links an agentic AI system to a control bounding its action-space or autonomy."@en ;
    rdfs:domain prism:AgenticAISystem ;
    rdfs:range prism:AgentControl .

prism:implementedAtLayer
    a owl:ObjectProperty ;
    rdfs:label "implemented at layer"@en ;
    rdfs:comment "The enforcement layer of a control (structural, model-based, prompt, runtime). Queryable proxy for control strength: prefer structural for higher-risk actions."@en ;
    rdfs:domain prism:AgentControl ;
    rdfs:range prism:ControlLayer .

# ── Oversight design ──────────────────────────────────────────────────────────

prism:hasOversightCheckpoint
    a owl:ObjectProperty ;
    rdfs:label "has oversight checkpoint"@en ;
    rdfs:comment "Links an agentic AI system, or the prism:HumanOversightRecord documenting its oversight design, to a defined human-approval checkpoint."@en ;
    rdfs:range prism:OversightCheckpoint .

prism:hasCheckpointTrigger
    a owl:ObjectProperty ;
    rdfs:label "has checkpoint trigger"@en ;
    rdfs:comment "The category of action boundary the checkpoint guards (high-stakes, irreversible, outlier, user-defined)."@en ;
    rdfs:domain prism:OversightCheckpoint ;
    rdfs:range prism:CheckpointTrigger .

prism:humanOverrideRate
    a owl:DatatypeProperty ;
    rdfs:label "human override rate"@en ;
    rdfs:comment "The measured frequency (0.0 to 1.0) at which humans reject or modify agent actions over the reporting period. A very low rate may signal rubber-stamping (automation bias); interpret alongside response times (MGF §2.2.2)."@en ;
    rdfs:domain prism:OversightEffectivenessRecord ;
    rdfs:range xsd:decimal .

prism:meanApprovalResponseTime
    a owl:DatatypeProperty ;
    rdfs:label "mean approval response time"@en ;
    rdfs:comment "The mean time humans spend reviewing agent actions before approving, over the reporting period. Very short times may signal automation bias or review fatigue (MGF §2.2.2)."@en ;
    rdfs:domain prism:OversightEffectivenessRecord ;
    rdfs:range xsd:duration .

# ── Identity and delegation ───────────────────────────────────────────────────

prism:agentIdentifier
    a owl:DatatypeProperty ;
    rdfs:label "agent identifier"@en ;
    rdfs:comment "The agent's unique identifier, ideally cryptographically verifiable (MGF §2.1.2)."@en ;
    rdfs:domain prism:AgentIdentityRecord ;
    rdfs:range xsd:string .

prism:accountableParty
    a owl:ObjectProperty ;
    rdfs:label "accountable party"@en ;
    rdfs:comment "The supervising agent, human user, or organisational department to which this agent's identity is tied for accountability and tracking (MGF §2.1.2)."@en ;
    rdfs:domain prism:AgentIdentityRecord .

prism:registeredIn
    a owl:ObjectProperty ;
    rdfs:label "registered in"@en ;
    rdfs:comment "The centralised registry from which the agent's identity and permissions are issued and tracked, preventing agent sprawl (MGF §2.1.2)."@en ;
    rdfs:domain prism:AgentIdentityRecord .

prism:delegatedBy
    a owl:ObjectProperty ;
    rdfs:label "delegated by"@en ;
    rdfs:comment "The human user or organisational role delegating authority to the agent. The agent's permissions should not exceed this party's own."@en ;
    rdfs:domain prism:DelegationRecord .

prism:delegatedTo
    a owl:ObjectProperty ;
    rdfs:label "delegated to"@en ;
    rdfs:comment "The agentic AI system receiving the delegated authority."@en ;
    rdfs:domain prism:DelegationRecord ;
    rdfs:range prism:AgenticAISystem .

prism:permissionScope
    a owl:DatatypeProperty ;
    rdfs:label "permission scope"@en ;
    rdfs:comment "Human-readable statement of the scoped, least-privilege permissions granted, including any escalation paths."@en ;
    rdfs:domain prism:DelegationRecord ;
    rdfs:range xsd:string .

prism:validFrom
    a owl:DatatypeProperty ;
    rdfs:label "valid from"@en ;
    rdfs:comment "Start of the delegation's validity window. Authorisations should be time- or session-bound (MGF §2.1.2)."@en ;
    rdfs:domain prism:DelegationRecord ;
    rdfs:range xsd:dateTime .

prism:validUntil
    a owl:DatatypeProperty ;
    rdfs:label "valid until"@en ;
    rdfs:comment "End of the delegation's validity window."@en ;
    rdfs:domain prism:DelegationRecord ;
    rdfs:range xsd:dateTime .

# ── Testing and change management ─────────────────────────────────────────────

prism:coversTestingDimension
    a owl:ObjectProperty ;
    rdfs:label "covers testing dimension"@en ;
    rdfs:comment "A testing dimension covered by this agentic testing record."@en ;
    rdfs:domain prism:AgenticTestingRecord ;
    rdfs:range prism:TestingDimension .

prism:hasChangeTrigger
    a owl:ObjectProperty ;
    rdfs:label "has change trigger"@en ;
    rdfs:comment "The event category that initiated this change review."@en ;
    rdfs:domain prism:AgentChangeManagementRecord ;
    rdfs:range prism:ChangeTrigger .

prism:hasChangeCategory
    a owl:ObjectProperty ;
    rdfs:label "has change category"@en ;
    rdfs:comment "The risk categorisation assigned to the reviewed change."@en ;
    rdfs:domain prism:AgentChangeManagementRecord ;
    rdfs:range prism:ChangeCategory .
