[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83810-en":3,"doc-seo-83810-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83810,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","From Regulation to Requirements An Automated Requirement Derivation and Explanation Pipeline","Ensuring software compliance with regulations such as GDPR and the EU AI Act is difficult because requirements engineers must translate complex legal text into actionable system requirements, a step that is often manual and error-prone. The document proposes an automated regulation-to-requirements pipeline that detects requirement-bearing clauses and derives system-agnostic software requirements with plain-language, traceable explanations. Evaluations cover 398 GDPR clauses and 574 EU AI Act clauses, with strong F1 scores, high completeness/correctness, near-ceiling explanation clarity, and a practitioner study validating usability and understanding.","From Regulation to Requirements: An Automated Requirement Derivation and Explanation Pipeline  \nPavithra PM Nair and Preethu Rose Anish  \nTata Consultancy Services  \nEmail: {pavithra.nair, [preethu.rose](preethu.rose}@tcs.com)[}](preethu.rose}@tcs.com)[@tcs.com](preethu.rose}@tcs.com)  \narXiv :2607 .04448v 1 [ cs . SE] 5 Jul 2026  \nAbstract—Ensuring software compliance with regulations such as the General Data Protection Regulation (GDPR) and the Artificial Intelligence Act (EU AI Act) poses a significant challenge, as requirements engineers must translate complex legal text into actionable software requirements—a process that remains largely manual and error-prone in practice. We present an automated regulation-to-requirements pipeline that identifies requirementbearing clauses in regulatory documents and derives systemagnostic software requirements, accompanied by plain-language explanations, traceable to their legal sources. We evaluate the pipeline on the full clause sets of the GDPR (398 clauses) and the EU AI Act (574 clauses). For requirement-bearing clause identification, the approach achieves macro-averaged F1 scores of 0.82 and 0.78, respectively, outperforming a SetFit-based baseline. Human evaluation shows high completeness (4.60 and 4.45) and correctness (3.74 and 3.54) of derived requirements, while explanation clarity scores are near-ceiling (4.92 and 4.94) on a 1–5 scale. We implement the approach in Reg2Req, a publicly released tool that further supports requirement classification, use case seeding, cross-reference analysis, definition indexing, and a traceability matrix to operationalize regulatory compliance in practice. A user study with 25 practitioners shows that the plain-language explanations significantly improve comprehension of derived requirements and confidence in acting on them (p \u003C 0.001), and that all participants would use Reg2Req as a starting point for deriving software requirements from a regulation.  \nIndex Terms—requirements engineering, regulatory compliance, natural language processing, large language models  \nI. INTRODUCTION  \nModern software systems increasingly operate under stringent regulatory frameworks [1], [2] . Data protection law, AI regulation, healthcare standards, and sector-specific legislation all impose mandatory requirements on how systems must be designed, how they must behave at runtime, and what evidence of compliance they must be able to provide [3] . This regulatory landscape is not only expanding but also becoming more complex. In recent years, the European Union (EU) alone has enacted the General Data Protection Regulation (GDPR) [4], the AI Act [5], the Data Act [6], and the Digital Services Act [7], each introducing distinct requirements for software systems. Comparable legislative activity is underway globally, with major jurisdictions introducing their own regulatory frameworks, such as the California Consumer Privacy Act (CCPA/CPRA) [8] in the United States and the Digital Personal Data Protection Act in India [9] .  \nSupporting the development of compliant software within this evolving regulatory landscape is widely recognized as  \na central challenge for requirements engineering (RE) and software engineering, more broadly [2], [10] . Despite this recognition, the translation of regulatory provisions into concrete software requirements remains largely manual and errorprone in practice. Empirical evidence highlights the severity of this problem: a recent survey indicates that 90% of data access requests submitted to EU companies are not fully answered within legally mandated timelines [11] . While compliance failures have many causes, one contributing factor is the difficulty of extracting a complete and correct set of software requirements from regulatory text [12] .  \nRegulations are written for legal audiences, not for requirements engineers. They are structured around legal concepts, organized to serve legislative and interpretive purposes, and expressed ","cbCaiaNAPlrXVuUp","https://ap.wps.com/l/cbCaiaNAPlrXVuUp","pdf",1519533,5,1,11,"English","en",105,"# Introduction\n## Regulatory challenge and motivation\n## Example-driven requirements derivation\n# Problem statement\n## Clause identification\n## Requirement derivation with explanations","[{\"question\":\"What problem does the regulation-to-requirements pipeline address?\",\"answer\":\"It tackles the manual, error-prone task of translating regulatory provisions into concrete software requirements by systematically identifying requirement-bearing clauses and deriving requirements from them.\"},{\"question\":\"How does the approach support traceability and understanding?\",\"answer\":\"Derived requirements come with plain-language explanations that can be traced back to the specific legal source clauses, helping engineers, developers, testers, and auditors without legal training.\"},{\"question\":\"What evidence is provided for effectiveness and usability?\",\"answer\":\"Experiments on the full clause sets of GDPR and the EU AI Act report strong clause identification F1 scores, high completeness/correctness of derived requirements, and near-ceiling explanation clarity. A user study with 25 practitioners shows explanations improve comprehension and confidence, with statistically significant results.\"}]",1784190559,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"from-regulation-to-requirements-an-automated-requirement-derivation-and-explanation-pipeline","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/from-regulation-to-requirements-an-automated-requirement-derivation-and-explanation-pipeline/83810/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the regulation-to-requirements pipeline address?","Question",{"text":76,"@type":77},"It tackles the manual, error-prone task of translating regulatory provisions into concrete software requirements by systematically identifying requirement-bearing clauses and deriving requirements from them.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the approach support traceability and understanding?",{"text":81,"@type":77},"Derived requirements come with plain-language explanations that can be traced back to the specific legal source clauses, helping engineers, developers, testers, and auditors without legal training.",{"name":83,"@type":74,"acceptedAnswer":84},"What evidence is provided for effectiveness and usability?",{"text":85,"@type":77},"Experiments on the full clause sets of GDPR and the EU AI Act report strong clause identification F1 scores, high completeness/correctness of derived requirements, and near-ceiling explanation clarity. A user study with 25 practitioners shows explanations improve comprehension and confidence, with statistically significant results.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]