A Vision for Compliance-Aware Requirements Engineering in the Age of the EU AI ACT
Abstract
Validating AI system requirements against legal obligations is a growing challenge, particularly with the EU AI Act now in force and key compliance deadlines approaching from mid-2026. Current Requirements Engineering practice offers no systematic tooling: practitioner insights suggest that compliance validation remains largely manual, checklist-driven, and difficult to scale [1]. We present Compliance-Aware Requirements Engineering System (CARES), a vision for a hybrid agent-based system that automates legal compliance and quality requirements validation in RE. CARES formalizes regulatory text into structured, testable requirements and validates project-level requirements using a 4CT quality schema: four core dimensions (Completeness, Consistency, Correctness, Coherence) grounded in IEEE/ISO/IEC 29148:2018, a promoted Traceability dimension reflecting legal auditability demands, and SMART criteria serving both as validation sub-criteria and as a remediation guide at the individual requirement level. Using the EU AI Act as the first application domain, we propose a hierarchical mapping architecture, a traffic-light Human-In-The-Loop (HITL) mechanism with formally defined trigger criteria, and a phased evaluation roadmap to guide future validation.