Language:
PRODUCTS
SECTORS
MORE
Quantum Security 🔍 Search Request Access →
GLOBAL EXECUTION REQUIREMENTS · PRIMARY / OFFICIAL SOURCES ONLY

THE GLOBAL CONVERGENCE.

Different jurisdictions. Different institutions. The same direction: continuous authorization, Zero Trust, resilience, evidence, accountability and enforceable boundaries. immo.quick unifies these control properties in a deterministic execution architecture.

FINMABaFin / DORAEU AI ACTNISTNSAWHITE HOUSE
REGULATION IS MOVING TOWARD EXECUTION. MACHINE LAW IS ALREADY THERE.
CONVERGENCE MAP

What is converging globally.

The documents use different terminology and have different legal effects. The common technical pattern is nevertheless visible.

AUTHORIZATIONBefore access and execution
ZERO TRUSTNo implicit trust
RESILIENCEContinuously resilient
EVIDENCEReconstructable and inspectable
ACCOUNTABILITYAttributable intervention
ENFORCEMENTBoundaries over attestation
OFFICIAL REQUIREMENT MATRIX

Official sources. Concrete control properties. Architectural response.

This matrix is deliberately source-bound. It does not claim regulatory certification or that one product automatically satisfies every legal duty. It shows where publicly described immo.quick mechanisms operationalize the same or a stricter control property.

FINMASwitzerland
Proposed ordinance / consultation completed

AMLO-FINMA partial revision — correspondent banking / payable-through accounts

12 May 2026Planned: 1 Jan 2027
Official direction / requirement

Payments on behalf of a customer’s clients may only be executed if it is ensured that the customer can provide the client information required for due-diligence duties on request.

immo.quick architectural response

Model the information-availability condition as an execution dependency. If the required dependency does not close for the requested payment, no valid Execution Right should be derived for that governed path.

BEYOND THE CITED CONTROL PROPERTY

Machine Law separates the legal/source condition, the determination, Execution-Rights Closure, the resulting bounded Capability and the evidence of the state used for that event.

BaFinGermany / EU financial sector
Official supervisory guidance · non-binding

Guidance on ICT Risks in the Use of AI at Financial Entities

23 Jan 2026DORA already applicable
Official direction / requirement

The guidance ties AI operation to DORA ICT risk management and highlights strict authorisation management, resilient operation, logging, Zero Trust controls and conditions set in advance of AI use that users should not be able to exceed on their own.

immo.quick architectural response

immo.quick treats the model or AI output as an input to determination, not as authority. Execution is separately bound to Authority, Rule State, Jurisdiction, Time and Dependencies before a governed Capability can exist.

BEYOND THE CITED CONTROL PROPERTY

The architecture makes “authorization before use” action-specific: a prior Gate PASS or model result does not silently persist as permission at the Execution Cut.

European UnionEU
Binding regulation

Digital Operational Resilience Act (DORA)

DORA · Regulation (EU) 2022/2554Applicable since 17 Jan 2025
Official direction / requirement

DORA requires an ICT risk-management framework, resilience testing, incident processes and controlled ICT third-party risk for in-scope financial entities.

immo.quick architectural response

immo.quick adds an execution layer in which deterministic determinations do not themselves create permission; authorization closure and evidence are separate surfaces.

BEYOND THE CITED CONTROL PROPERTY

Operational resilience explains whether systems can withstand disruption. Machine Law additionally asks whether the exact governed action has a valid right behind it now.

European UnionEU
Binding regulation · phased application

EU Artificial Intelligence Act

AI Act · Regulation (EU) 2024/1689Phased application
Official direction / requirement

The AI Act establishes risk-based obligations including governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity for covered high-risk systems and actors.

immo.quick architectural response

Machine Law keeps intelligence separate from institutional authority and preserves explicit boundaries between model output, human/institutional authority, execution authorization and evidence.

BEYOND THE CITED CONTROL PROPERTY

Human oversight is not treated as permission laundering. An override can be attributable evidence without retroactively mutating the prior determination state.

NISTUnited States / voluntary enterprise use
Federal technical standard / guidance

Zero Trust Architecture

SP 800-207 · Aug 2020Current reference architecture
Official direction / requirement

NIST separates policy decision and enforcement: the policy engine grants, denies or revokes access; the policy administrator and policy enforcement point establish or shut down the communication path.

immo.quick architectural response

immo.quick applies the same no-implicit-trust direction at the execution-right layer: a determination is not permission, and a bounded Capability follows only from a valid authorization state.

BEYOND THE CITED CONTROL PROPERTY

Zero Trust answers whether a subject may access a resource. Machine Law can additionally bind the right behind the exact regulated action to Authority, Rule State, Jurisdiction, Time and Dependencies.

NSAU.S. National Security / DIB guidance
Official implementation guidance

Continuous authentication and authorization

Zero Trust Implementation Guideline Primer · Jan 2026Current guidance
Official direction / requirement

NSA describes Zero Trust as continuous authentication and authorization of users, devices and applications under “never trust, always verify” and “assume breach.”

immo.quick architectural response

immo.quick carries continuous verification into the execution boundary: the relevant authorization state must still close when the governed action reaches the Execution Cut.

BEYOND THE CITED CONTROL PROPERTY

A previous approval cannot manufacture continuing authority. State changes are treated as new state, not as permission to rewrite the past.

The White HouseUnited States
Federal policy strategy

Secure-by-design, resilient AI and enforceable controls

America’s AI Action Plan · July 2025Policy program
Official direction / requirement

The plan calls for secure-by-design, robust and resilient AI in safety-critical contexts, mature AI incident response and, in biosecurity screening, enforcement mechanisms rather than reliance on voluntary attestation.

immo.quick architectural response

immo.quick is built around enforceable architectural boundaries rather than descriptive policy alone: determination, authorization, bounded capability and evidence are distinct.

BEYOND THE CITED CONTROL PROPERTY

The execution-right model makes the control question explicit before the governed action becomes technically executable.

The White HouseUnited States
Federal cyber strategy

Zero Trust, post-quantum cryptography, critical-infrastructure resilience and secure agentic AI

Cyber Strategy for America · Mar 2026Current policy strategy
Official direction / requirement

The strategy directs modernization around cybersecurity best practices, post-quantum cryptography, Zero Trust, resilient federal systems, critical infrastructure and secure scaling of agentic AI.

immo.quick architectural response

immo.quick combines execution authorization with cryptographic evidence and separates provider/runtime infrastructure from the authority that governs a regulated action.

BEYOND THE CITED CONTROL PROPERTY

Infrastructure may vary. Authority must not silently vary with it. Runtime does not get to redefine the authoritative state used for execution.

MACHINE LAW

The difference is before execution.

Many frameworks require authentication, authorization, logging, resilience, human oversight or intervention. Machine Law adds a distinct question: Does a valid Execution Right for this exact action exist at the Execution Cut?

OFFICIAL SOURCEOfficial or authoritative source state
DETERMINATIONDomain determination, not permission
EXECUTION-RIGHTS CLOSUREAuthority · Rule · Jurisdiction · Time · Dependency
CAPABILITY / NONEBounded technical executability
EVIDENCEVerifiable, claim-bounded evidence
PUBLIC INSPECTION PATH

Do not believe the claim. Inspect the mechanism.

The comparison is only as strong as the architecture beneath it. That is why every layer links to the pages where Authority, Execution Rights, Capability, Override and Evidence are described separately in public.

INSTITUTIONAL PROOF PATH