{
  "type": "risk_object_list",
  "schema_version": 1,
  "count": 12,
  "risk_objects": [
    {
      "id": "risk-object:eu:gdpr-art-83-4",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "gdpr",
      "affected_roles": [
        "controller",
        "processor"
      ],
      "triggers": [
        "element:gdpr:automated-decision",
        "element:gdpr:controller",
        "element:gdpr:personal-data",
        "element:gdpr:processing",
        "element:gdpr:processor",
        "element:gdpr:special-categories"
      ],
      "consequence": "administrative_fine",
      "authority": "Competent supervisory authority",
      "max_amount": "EUR 10 000 000",
      "max_turnover_pct": 2,
      "applies_from": "2018-05-25",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:gdpr-art-25-controller",
          "duty": "Apply data protection by design and by default."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-30-controller",
          "duty": "Keep records of processing activities."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-32-controller",
          "duty": "Ensure a level of security appropriate to the risk."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-33-controller",
          "duty": "Notify a personal data breach to the supervisory authority."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-35-controller",
          "duty": "Carry out a data protection impact assessment for high-risk processing."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-28-processor",
          "duty": "Process only on documented instructions under a written contract."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-32-processor",
          "duty": "Ensure a level of security appropriate to the risk."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-33-processor",
          "duty": "Notify the controller without undue delay after becoming aware of a breach."
        }
      ],
      "evidence": {
        "article": "83(4)",
        "source": "Regulation (EU) 2016/679 (GDPR)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:gdpr-art-83-4",
        "precedent": "not_in_register"
      },
      "sha256": "3f05583427b59eb52fefc7e0e293c9c51ab6ecf87b75a080cd2caf6d88175026",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Agdpr-art-83-4"
    },
    {
      "id": "risk-object:eu:gdpr-art-83-5",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "gdpr",
      "affected_roles": [
        "controller"
      ],
      "triggers": [
        "element:gdpr:controller",
        "element:gdpr:personal-data",
        "element:gdpr:processing"
      ],
      "consequence": "administrative_fine",
      "authority": "Competent supervisory authority",
      "max_amount": "EUR 20 000 000",
      "max_turnover_pct": 4,
      "applies_from": "2018-05-25",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:gdpr-art-5-controller",
          "duty": "Process personal data in line with the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and be able to demonstrate compliance (accountability)."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-6-controller",
          "duty": "Process personal data only where at least one legal basis in Article 6(1) applies."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-12-controller",
          "duty": "Provide information on action taken on a data subject request under Articles 15 to 22 without undue delay and in any event within one month of receipt of the request."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-15-controller",
          "duty": "Give the data subject confirmation as to whether personal data concerning him or her are being processed, access to the personal data and the information listed in Article 15(1), and a copy of the data."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-17-controller",
          "duty": "Erase personal data without undue delay where one of the grounds in Article 17(1) applies."
        }
      ],
      "evidence": {
        "article": "83(5)",
        "source": "Regulation (EU) 2016/679 (GDPR)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:gdpr-art-83-5",
        "precedent": "not_in_register"
      },
      "sha256": "b85f7a75429988466c6ffdcbbdba2e237c3f6c032887c6a60a630daece4cfec3",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Agdpr-art-83-5"
    },
    {
      "id": "risk-object:eu:gdpr-art-83-6",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "gdpr",
      "affected_roles": [],
      "triggers": [],
      "consequence": "administrative_fine",
      "authority": "Competent supervisory authority",
      "max_amount": "EUR 20 000 000",
      "max_turnover_pct": 4,
      "applies_from": "2018-05-25",
      "deadline_days": null,
      "mitigation": [],
      "evidence": {
        "article": "83(6)",
        "source": "Regulation (EU) 2016/679 (GDPR)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:gdpr-art-83-6",
        "precedent": "not_in_register"
      },
      "sha256": "2d2dadf02cdd7880c5b0e1b7ad80ec6d5391e4d659ec1d67b8b2b0d10dd00e43",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Agdpr-art-83-6"
    },
    {
      "id": "risk-object:eu:gdpr-art-58-2",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "gdpr",
      "affected_roles": [
        "controller",
        "processor"
      ],
      "triggers": [
        "element:gdpr:automated-decision",
        "element:gdpr:controller",
        "element:gdpr:personal-data",
        "element:gdpr:processing",
        "element:gdpr:processor",
        "element:gdpr:special-categories"
      ],
      "consequence": "corrective_order",
      "authority": "Competent supervisory authority",
      "max_amount": null,
      "max_turnover_pct": null,
      "applies_from": "2018-05-25",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:gdpr-art-24-controller",
          "duty": "Implement and demonstrate measures that make processing compliant."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-25-controller",
          "duty": "Apply data protection by design and by default."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-30-controller",
          "duty": "Keep records of processing activities."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-32-controller",
          "duty": "Ensure a level of security appropriate to the risk."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-33-controller",
          "duty": "Notify a personal data breach to the supervisory authority."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-35-controller",
          "duty": "Carry out a data protection impact assessment for high-risk processing."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-28-processor",
          "duty": "Process only on documented instructions under a written contract."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-32-processor",
          "duty": "Ensure a level of security appropriate to the risk."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-33-processor",
          "duty": "Notify the controller without undue delay after becoming aware of a breach."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-5-controller",
          "duty": "Process personal data in line with the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and be able to demonstrate compliance (accountability)."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-6-controller",
          "duty": "Process personal data only where at least one legal basis in Article 6(1) applies."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-12-controller",
          "duty": "Provide information on action taken on a data subject request under Articles 15 to 22 without undue delay and in any event within one month of receipt of the request."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-15-controller",
          "duty": "Give the data subject confirmation as to whether personal data concerning him or her are being processed, access to the personal data and the information listed in Article 15(1), and a copy of the data."
        },
        {
          "obligation_id": "obligation:eu:gdpr-art-17-controller",
          "duty": "Erase personal data without undue delay where one of the grounds in Article 17(1) applies."
        }
      ],
      "evidence": {
        "article": "58(2)",
        "source": "Regulation (EU) 2016/679 (GDPR)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:gdpr-art-58-2",
        "precedent": "not_in_register"
      },
      "sha256": "4339a599d42cc2e3f7fa1eb5b3e4e6e4075a136510f2d4d14e6506caa68bb677",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Agdpr-art-58-2"
    },
    {
      "id": "risk-object:eu:ai-act-art-99-3",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "ai-act",
      "affected_roles": [],
      "triggers": [],
      "consequence": "administrative_fine",
      "authority": "Market surveillance authority",
      "max_amount": "EUR 35 000 000",
      "max_turnover_pct": 7,
      "applies_from": "2025-08-02",
      "deadline_days": null,
      "mitigation": [],
      "evidence": {
        "article": "99(3)",
        "source": "Regulation (EU) 2024/1689 (AI Act)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:ai-act-art-99-3",
        "precedent": "not_in_register"
      },
      "sha256": "b2e41da9bc729979a88d306ad1e0648ac1e9b06065bcb8faf829d19f333189a7",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Aai-act-art-99-3"
    },
    {
      "id": "risk-object:eu:ai-act-art-99-4",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "ai-act",
      "affected_roles": [
        "deployer",
        "distributor",
        "importer",
        "provider"
      ],
      "triggers": [
        "element:ai-act:ai-system",
        "element:ai-act:high-risk",
        "element:ai-act:provider"
      ],
      "consequence": "administrative_fine",
      "authority": "Market surveillance authority",
      "max_amount": "EUR 15 000 000",
      "max_turnover_pct": 3,
      "applies_from": "2025-08-02",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:ai-act-art-16-provider",
          "duty": "Meet the provider obligations for high-risk AI systems."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-9-provider",
          "duty": "Establish and maintain a risk management system."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-10-provider",
          "duty": "Apply data and data governance requirements to training, validation and testing data."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-11-provider",
          "duty": "Draw up and keep technical documentation."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-12-provider",
          "duty": "Enable automatic recording of events (logging)."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-17-provider",
          "duty": "Operate a quality management system."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-43-provider",
          "duty": "Carry out the applicable conformity assessment before placing on the market."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-72-provider",
          "duty": "Run post-market monitoring of the system in use."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-73-provider",
          "duty": "Report serious incidents to the market surveillance authority."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-26-deployer",
          "duty": "Use the system in line with the instructions and assign human oversight."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-23-importer",
          "duty": "Verify conformity, documentation and marking before placing on the market."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-24-distributor",
          "duty": "Verify marking and documentation before making available on the market."
        }
      ],
      "evidence": {
        "article": "99(4)",
        "source": "Regulation (EU) 2024/1689 (AI Act)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:ai-act-art-99-4",
        "precedent": "not_in_register"
      },
      "sha256": "1d67abb0beb71b527362a1fb02e48d38403621041fc06b3eca922f05c3170b40",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Aai-act-art-99-4"
    },
    {
      "id": "risk-object:eu:ai-act-art-99-5",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "ai-act",
      "affected_roles": [],
      "triggers": [],
      "consequence": "administrative_fine",
      "authority": "Market surveillance authority",
      "max_amount": "EUR 7 500 000",
      "max_turnover_pct": 1,
      "applies_from": "2025-08-02",
      "deadline_days": null,
      "mitigation": [],
      "evidence": {
        "article": "99(5)",
        "source": "Regulation (EU) 2024/1689 (AI Act)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:ai-act-art-99-5",
        "precedent": "not_in_register"
      },
      "sha256": "81ddcfea7b8678f2f80dea4c5fc6280f86e01a598af8cc9c5c1025690c43ea5c",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Aai-act-art-99-5"
    },
    {
      "id": "risk-object:eu:ai-act-art-101",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "ai-act",
      "affected_roles": [
        "gpai-provider"
      ],
      "triggers": [],
      "consequence": "administrative_fine",
      "authority": "European Commission (AI Office)",
      "max_amount": "EUR 15 000 000",
      "max_turnover_pct": 3,
      "applies_from": "2026-08-02",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:ai-act-art-53-gpai-provider",
          "duty": "Keep model documentation and a copyright policy for general-purpose AI models."
        },
        {
          "obligation_id": "obligation:eu:ai-act-art-55-gpai-provider",
          "duty": "Meet the additional obligations for models with systemic risk."
        }
      ],
      "evidence": {
        "article": "101",
        "source": "Regulation (EU) 2024/1689 (AI Act)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:ai-act-art-101",
        "precedent": "not_in_register"
      },
      "sha256": "e92617fbb3d2f1c1b787025aff9499899953f1b5ba93b072d6e917cd9602bcfc",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Aai-act-art-101"
    },
    {
      "id": "risk-object:eu:nis2-art-34-4",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "nis2",
      "affected_roles": [
        "essential-entity"
      ],
      "triggers": [
        "element:nis2:essential-entity",
        "element:nis2:significant-incident"
      ],
      "consequence": "administrative_fine",
      "authority": "National competent authority",
      "max_amount": "EUR 10 000 000",
      "max_turnover_pct": 2,
      "applies_from": "2024-10-18",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:nis2-art-21-essential-entity",
          "duty": "Take appropriate cybersecurity risk-management measures."
        },
        {
          "obligation_id": "obligation:eu:nis2-art-23-essential-entity",
          "duty": "Report significant incidents within the set deadlines."
        }
      ],
      "evidence": {
        "article": "34(4)",
        "source": "Directive (EU) 2022/2555 (NIS2)",
        "source_url": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:nis2-art-34-4",
        "precedent": "not_in_register"
      },
      "sha256": "b957ed0d001ca7909db94f9f42ac092fdb7b745a97c6541c93fc541cc13998cd",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Anis2-art-34-4"
    },
    {
      "id": "risk-object:eu:nis2-art-34-5",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "nis2",
      "affected_roles": [
        "essential-entity"
      ],
      "triggers": [
        "element:nis2:essential-entity",
        "element:nis2:significant-incident"
      ],
      "consequence": "administrative_fine",
      "authority": "National competent authority",
      "max_amount": "EUR 7 000 000",
      "max_turnover_pct": 1.4,
      "applies_from": "2024-10-18",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:nis2-art-21-essential-entity",
          "duty": "Take appropriate cybersecurity risk-management measures."
        },
        {
          "obligation_id": "obligation:eu:nis2-art-23-essential-entity",
          "duty": "Report significant incidents within the set deadlines."
        }
      ],
      "evidence": {
        "article": "34(5)",
        "source": "Directive (EU) 2022/2555 (NIS2)",
        "source_url": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:nis2-art-34-5",
        "precedent": "not_in_register"
      },
      "sha256": "787873d5fc246df6bc6c65e361e143c2813a7b0783825592f859140680d1e815",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Anis2-art-34-5"
    },
    {
      "id": "risk-object:eu:dora-art-50",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "dora",
      "affected_roles": [
        "financial-entity"
      ],
      "triggers": [
        "element:dora:ict-risk"
      ],
      "consequence": "administrative_fine",
      "authority": "Competent authority (Article 46)",
      "max_amount": null,
      "max_turnover_pct": null,
      "applies_from": "2025-01-17",
      "deadline_days": null,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:dora-art-5-financial-entity",
          "duty": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it."
        },
        {
          "obligation_id": "obligation:eu:dora-art-6-financial-entity",
          "duty": "Maintain a sound, comprehensive and documented ICT risk management framework."
        },
        {
          "obligation_id": "obligation:eu:dora-art-11-financial-entity",
          "duty": "Put in place an ICT business continuity policy with response and recovery plans."
        },
        {
          "obligation_id": "obligation:eu:dora-art-17-financial-entity",
          "duty": "Define and implement an ICT-related incident management process."
        },
        {
          "obligation_id": "obligation:eu:dora-art-19-financial-entity",
          "duty": "Report major ICT-related incidents to the competent authority."
        },
        {
          "obligation_id": "obligation:eu:dora-art-24-financial-entity",
          "duty": "Establish a digital operational resilience testing programme."
        },
        {
          "obligation_id": "obligation:eu:dora-art-26-financial-entity",
          "duty": "Carry out threat-led penetration testing where identified by the competent authority."
        },
        {
          "obligation_id": "obligation:eu:dora-art-28-financial-entity",
          "duty": "Manage ICT third-party risk and keep a register of information on all ICT service contracts."
        },
        {
          "obligation_id": "obligation:eu:dora-art-30-financial-entity",
          "duty": "Include the key contractual provisions in contracts with ICT third-party service providers."
        }
      ],
      "evidence": {
        "article": "50",
        "source": "Regulation (EU) 2022/2554 (DORA)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:dora-art-50",
        "precedent": "not_in_register"
      },
      "sha256": "d81546799bf060c46b36d070842e8e66b5b87b3a715e0334fc1228d31ee918a5",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Adora-art-50"
    },
    {
      "id": "risk-object:eu:dora-art-35-6",
      "type": "risk_object",
      "schema_version": 1,
      "jurisdiction": "eu",
      "act": "dora",
      "affected_roles": [
        "financial-entity"
      ],
      "triggers": [
        "element:dora:ict-risk"
      ],
      "consequence": "periodic_penalty",
      "authority": "Lead Overseer (ESA)",
      "max_amount": null,
      "max_turnover_pct": 1,
      "applies_from": "2025-01-17",
      "deadline_days": 180,
      "mitigation": [
        {
          "obligation_id": "obligation:eu:dora-art-5-financial-entity",
          "duty": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it."
        },
        {
          "obligation_id": "obligation:eu:dora-art-6-financial-entity",
          "duty": "Maintain a sound, comprehensive and documented ICT risk management framework."
        },
        {
          "obligation_id": "obligation:eu:dora-art-11-financial-entity",
          "duty": "Put in place an ICT business continuity policy with response and recovery plans."
        },
        {
          "obligation_id": "obligation:eu:dora-art-17-financial-entity",
          "duty": "Define and implement an ICT-related incident management process."
        },
        {
          "obligation_id": "obligation:eu:dora-art-19-financial-entity",
          "duty": "Report major ICT-related incidents to the competent authority."
        },
        {
          "obligation_id": "obligation:eu:dora-art-24-financial-entity",
          "duty": "Establish a digital operational resilience testing programme."
        },
        {
          "obligation_id": "obligation:eu:dora-art-26-financial-entity",
          "duty": "Carry out threat-led penetration testing where identified by the competent authority."
        },
        {
          "obligation_id": "obligation:eu:dora-art-28-financial-entity",
          "duty": "Manage ICT third-party risk and keep a register of information on all ICT service contracts."
        },
        {
          "obligation_id": "obligation:eu:dora-art-30-financial-entity",
          "duty": "Include the key contractual provisions in contracts with ICT third-party service providers."
        }
      ],
      "evidence": {
        "article": "35(6)",
        "source": "Regulation (EU) 2022/2554 (DORA)",
        "source_url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
        "read_at": "2026-09-28",
        "sanction_id": "sanction:eu:dora-art-35-6",
        "precedent": "not_in_register"
      },
      "sha256": "15746482652060559fb54493cf46f434f7c512279570c79b0ada10e9f37d1d59",
      "source": "NovaCopilot",
      "url": "https://legal.exploreworldai.com/api/public/v1/risk-assess?id=risk-object%3Aeu%3Adora-art-35-6"
    }
  ],
  "gaps": [],
  "source": "NovaCopilot",
  "attribution": "Source: NovaCopilot"
}