AI Governance, Risk & Red Teaming
Aware · M1 · lesson 1 of 18 · in progress
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The 2026 Regulatory Stack: EU AI Act, NIST AI RMF, ISO/IEC 42001, OWASP, MITRE ATLAS
📖
now learning

The 2026 Regulatory Stack: EU AI Act, NIST AI RMF, ISO/IEC 42001, OWASP, MITRE ATLAS

15 min

In 2026 there is no single "AI regulation." There is a stack. A real AI governance program reads across six interlocking frameworks at once, the EU AI Act, the NIST AI RMF 1.0 plus the AI 600-1 GenAI Profile, ISO/IEC 42001:2023, OWASP LLM Top 10 (2025), OWASP Top 10 for Agentic Applications (Dec 9, 2025), and MITRE ATLAS v5.4.0 (Feb 2026), and translates each into the same operational evidence. The skill at L1 is not memorizing each framework. The skill is knowing where each one is load-bearing, which one carries the regulatory weight in which jurisdiction, and how a single artifact can satisfy three reviewers in the same Friday meeting. This lesson is the cross-walk: who each framework is for, what it actually mandates, where it overlaps the others, and how to build the one-page stack chart that anchors every L2-L5 deliverable downstream.

Why It Is a Stack, Not a Single Framework

The single-framework instinct is a 2023 instinct. Three years on, every serious AI program has learned that the EU AI Act is the law, NIST is the U.S. industry consensus, ISO 42001 is the audit standard for management systems, OWASP names the attack surface in operational terms, and MITRE ATLAS is the threat-intelligence map your red team will actually use. They are not competitors. They are layers that bake into different audit artifacts: regulator-facing, board-facing, auditor-facing, red-team-facing, threat-intel-facing. A program that runs only one of them will fail an audit on the other five, and a program that runs all of them without a cross-walk will redo the same work five times.

The cross-walk lets you write each artifact once and cite it five times. Your AI inventory satisfies EU AI Act Article 11, ISO 42001 A.6.2, NIST AI RMF Map 1, and contributes to OWASP / ATLAS coverage planning. Your FRIA satisfies EU AI Act Article 27, NIST AI RMF Govern 1.4 + Map 5, ISO 42001 A.6.1.1, and contributes to OWASP ASI risk planning for agentic systems. Your red-team report satisfies EU AI Act Article 15 robustness/cybersecurity claims, NIST AI RMF Measure 2.7, ISO 42001 A.8, OWASP LLM01-LLM10 coverage, and MITRE ATLAS technique-by-technique coverage. The cross-walk is the engineering of evidence efficiency. Without it, the program produces five times as many documents at five times the cost and still has gaps.

A second reason for the stack approach: jurisdictions disagree about where to anchor enforcement. The EU writes the binding regulation; the U.S. anchors on NIST plus sectoral law plus the patchwork of state AI laws; the UK runs through AISI and ICO guidance; ISO supplies the audit standard everyone agrees on; OWASP and MITRE supply the technical vocabulary the security teams already speak. A multinational enterprise that operates in three of those jurisdictions cannot pick just one. The stack is how a Chief AI Officer in 2026 explains the program to a German regulator, a U.S. board director, a Singaporean buyer, and the head of internal audit, without contradicting themselves.

Layer 1 - The EU AI Act: The Binding Regulation

Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, is the only one of the six layers that is binding law in 2026. Everything else is voluntary or contractual. The Act applies extraterritorially under Article 2(1) to providers and deployers anywhere in the world whose AI systems are placed on the EU market or whose outputs are used in the Union. The Omnibus VII political agreement on May 7, 2026 reshaped, but did not eliminate, the original Aug 2, 2026 forcing function. Key 2026 dates after Omnibus VII:

  • Feb 2, 2025, Article 5 prohibitions and Article 4 AI literacy already in force.
  • Aug 2, 2025, GPAI obligations under Article 53 and the Article 99 penalty framework already applying.
  • Aug 2, 2026, GPAI enforcement powers begin (Omnibus VII did NOT move this); Article 73 reporting infrastructure operational; FRIA capability operational for public-body and credit/insurance §5(b)/§5(c) deployers.
  • Dec 2, 2026, Article 50(2) machine-readable marking of synthetic content (grace period cut under Omnibus VII).
  • Dec 2, 2027, Stand-alone Annex III high-risk obligations apply (moved from Aug 2, 2026 by Omnibus VII).
  • Aug 2, 2028, Annex I embedded-product high-risk obligations apply (moved from Aug 2, 2027 by Omnibus VII).

The Act's article numbering is the load-bearing addressing system for every operational artifact downstream. When a Schellman / A-LIGN / BSI / KPMG auditor opens your binder, they expect to see Article 5, Article 6, Annex III, Article 9, Article 10, Article 11, Annex IV, Article 13, Article 14, Article 15, Article 16, Article 17, Article 25, Article 26, Article 27, Article 31, Article 43, Article 47, Article 50, Article 51, Article 53, Article 55, Article 71, Article 72, Article 73, Article 86, and Article 99 named explicitly. The Act is also where the financial exposure lives: Article 99 caps fines at €35M / 7% (prohibited practices), €15M / 3% (most provider failures), and €7.5M / 1% (misleading information).

Layer 2 - NIST AI RMF 1.0 + AI 600-1 GenAI Profile: The U.S. Industry Consensus

The U.S. National Institute of Standards and Technology published the AI Risk Management Framework version 1.0 in January 2023. It is voluntary. It is unfunded. It is also the document every U.S. federal agency, every responsible U.S. multinational, and every U.S. AI vendor cites in their compliance documentation. The framework has four functions, Govern, Map, Measure, Manage, and 19 categories distributed across those four functions. The functions are not sequential; they operate continuously and reinforce each other.

  • Govern: The organization-wide context for AI risk: policies, processes, accountability, resources, culture. Five categories (G-1 through G-6 conceptually).
  • Map: Categorization of the AI system, its context, capabilities, and use case. Five categories.
  • Measure: Quantitative and qualitative assessment of the system's risk, performance, and trustworthiness characteristics. Four categories.
  • Manage, Treatment of the risks identified, prioritization, response, monitoring, communication. Four categories.

NIST published the AI 600-1 GenAI Profile in July 2024 as a sector-and-use-case-specific overlay focused on generative AI risks. The Profile names 12 risks, CBRN information harm, confabulation, dangerous or violent or hateful content, data privacy, environmental, human-AI configuration, IP infringement, obscene or harmful content, information integrity, information security, value chain and component integration, harmful bias and homogenization, and over 200 suggested actions distributed across the Govern / Map / Measure / Manage functions and the lifecycle stages.

The 2026 developments to track: the NIST AI RMF Critical Infrastructure Profile concept note (April 7, 2026), the AI Agent Interoperability Profile planned for Q4 2026, and the launch of CAISI (Center for AI Standards and Innovation, formerly US AISI) with its AI Agent Standards Initiative launched Feb 17, 2026. The CAISI agent work is where the U.S. is converging with UK AISI and the EU AI Office on the dangerous-capability evaluation scoreboard for frontier models. NIST AI RMF profiles will become the operational glue between the U.S. voluntary regime and the EU statutory regime.

NIST is voluntary and so does not carry direct penalty exposure. But it carries enormous practical weight through federal procurement (executive-order-driven), state procurement (states like California and New York have adopted NIST-aligned procurement language), and the implicit standard of care in U.S. tort and securities litigation. A U.S.-listed company that ignores NIST AI RMF in 2026 will struggle to explain that posture to its audit committee or to a plaintiff's lawyer arguing breach of duty.

Layer 3 - ISO/IEC 42001:2023 AIMS: The Audit Standard

ISO/IEC 42001:2023 is the international standard for AI Management Systems (AIMS), published in December 2023. It is the only one of the six layers that supports a formal, accredited certification audit. Four certification bodies, Schellman, A-LIGN, BSI, and KPMG, have built ANAB-accredited (or equivalent) ISO 42001 audit practices in 2025-2026, and a small number of mid-tier firms have followed. An ISO 42001 certification is the only assurance artifact a regulator, an auditor, a customer, and a board director will all read the same way.

The standard has the classic ISO management-system structure (clauses 4 through 10 cover context, leadership, planning, support, operation, performance evaluation, improvement) plus an Annex A of 38 controls organized into 9 control areas (A.2 policies, A.3 internal organization, A.4 resources, A.5 impact assessment, A.6 AI system lifecycle, A.7 data, A.8 information for users, A.9 third-party use, A.10 third-party relationships). The standard also requires seven mandatory documented elements: the AIMS scope, the AI policy, AI objectives, the AI impact-assessment process, roles and responsibilities, the AIMS itself, and internal-audit results.

Stage 1 of the audit is the documentation review, Schellman / A-LIGN / BSI / KPMG sit down with the seven mandatory elements and the Annex A control evidence and confirm the AIMS is documented. Stage 2 is the operating-effectiveness review: the auditor watches the management system actually working, samples evidence per control, and forms an opinion. A clean Stage 1 sets up Stage 2; weak Stage 1 means the certification slides by a quarter.

The reason every serious AI program in 2026 either is, or is preparing to be, ISO 42001 certified: it is the assurance pathway the EU AI Act explicitly contemplates as evidence of compliance with portions of Article 17 (QMS) and Article 9 (RMS). It is the artifact U.S. customers ask for when they buy AI services. It is the artifact the audit committee uses to satisfy itself that the AI program is not just a slide deck. ISO 42001 is the audit-defensible spine.

Layer 4 - OWASP LLM Top 10 (2025) + OWASP Agentic Top 10 (Dec 2025): The Attack Surface in Plain Language

The Open Worldwide Application Security Project (OWASP) has translated decades of web-security taxonomy into AI-specific top-10 lists. The 2025 LLM Top 10, updated from the 2023 list, names the ten most consequential attack classes against large language model applications:

  • LLM01 - Prompt Injection (direct and indirect)
  • LLM02 - Sensitive Information Disclosure
  • LLM03 - Supply Chain (model, data, pipeline)
  • LLM04 - Data and Model Poisoning
  • LLM05 - Improper Output Handling
  • LLM06, Excessive Agency (functionality, permissions, autonomy, split sub-classes in 2025)
  • LLM07 - System Prompt Leakage (new in 2025)
  • LLM08 - Vector and Embedding Weaknesses (new in 2025)
  • LLM09-Misinformation
  • LLM10 - Unbounded Consumption

The OWASP GenAI Security Project published its Top 10 for Agentic Applications on December 9, 2025, recognizing that agent stacks introduce attack classes the original LLM Top 10 only partially covers. The ASI list:

  • ASI01, Agent Goal Hijack (the EchoLeak class of agent goal subversion)
  • ASI02 - Tool / Function Abuse
  • ASI03 - Identity and Privilege Abuse
  • ASI04 - Resource Manipulation
  • ASI05 - Supply-Chain Compromise (in agentic context)
  • ASI06 - Memory Poisoning
  • ASI07 - Inter-Agent Spoofing
  • ASI08 - Repudiation and Untraceability
  • ASI09 - Human-Agent Trust Exploitation
  • ASI10 - Rogue Agents

OWASP serves three roles in the stack. First, it is the vocabulary the AppSec community already uses. Mention "LLM01" to any application-security engineer in 2026 and they know exactly what you mean. Second, it maps cleanly to Article 15 (robustness and cybersecurity) and Article 55(1)(a) (adversarial testing), your red team report cites OWASP entries by number per finding. Third, it is the rubric procurement uses when evaluating vendors, "show us how your product handles LLM01 / LLM02 / LLM06 / ASI01 / ASI06" is a defensible vendor-evaluation question.

OWASP is voluntary. It is not law anywhere. It is also the most operationally useful framework on the stack for red teamers and product security engineers, and the one that converts regulatory language into engineering language.

Layer 5 - MITRE ATLAS v5.4.0: The Threat-Intelligence Map

MITRE ATLAS, Adversarial Threat Landscape for AI Systems, is the AI-specific extension of MITRE's well-known ATT&CK threat-intelligence framework. ATLAS v5.4.0 was published in February 2026 and represents the most comprehensive 2026 update: 16 tactics, 84 techniques, 56 sub-techniques. The Feb 2026 release added 14+ agentic-system techniques in partnership with Zenity Labs.

The ATLAS tactics map adversary objectives, Reconnaissance, Initial Access, ML Model Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Collection, ML Attack Staging, Exfiltration, Impact, and the technique list within each tactic enumerates specific adversary moves. Notable 2026 ATLAS additions for agentic systems:

  • AI Agent Context Poisoning, Adversary alters the agent's working context
  • Memory Manipulation - Adversary modifies the agent's persistent memory
  • Thread Injection, Adversary injects content into a multi-thread agent conversation
  • Modify AI Agent Configuration, Adversary alters agent settings to weaken controls
  • RAG Credential Harvesting, Adversary extracts credentials via RAG retrieval
  • Publish Poisoned AI Agent Tool, Adversary poisons a tool the agent will load
  • Escape to Host, Adversary breaks out of the agent sandbox to the host system

Where OWASP gives you the attack class in plain language, MITRE ATLAS gives you the technique ID and the cited real-world adversary use. Red teams in 2026 cite ATLAS by technique ID - AML.T0010, AML.T0018, AML.T0044, AML.T0051, in their findings. The two frameworks complement each other: OWASP for the rubric, ATLAS for the technique inventory.

ATLAS is voluntary and has no penalty exposure. But it is the framework the U.S. CISA, the EU ENISA, and most national cybersecurity agencies cite as authoritative for AI-system threat intelligence. Your red team will use it whether or not the regulatory frameworks explicitly require it.

The Cross-Walk Table - One Artifact, Five Frameworks

The L1 deliverable for this lesson is a one-page cross-walk chart that shows where each major operational artifact in the program sits against each framework. Here is the spine of that chart, with one row per major artifact:

  • AI Inventory / Use Register, EU AI Act Article 11 + Annex IV §1; NIST AI RMF Map 1; ISO 42001 A.6.2; OWASP / ATLAS coverage planning input.
  • Scope Memo (Article 3(1)), EU AI Act Article 3(1); NIST AI RMF Map 1.1; ISO 42001 A.6.1.1.
  • Tiering Memo (Article 5 / 6 / Annex III / 50): EU AI Act Articles 5, 6, 50; Annex III; NIST AI RMF Map 2; ISO 42001 A.6.2.
  • GPAI Exposure Map: EU AI Act Articles 51, 53, 55; Annexes XI, XII, XIII; ISO 42001 A.10; NIST AI RMF Map 4 + Govern 6.1; CycloneDX 1.7 ML-BoM.
  • Article 27 FRIA, EU AI Act Article 27; NIST AI RMF Govern 1.4 + Map 5; ISO 42001 A.6.1.1.
  • Annex IV Technical File: EU AI Act Article 11 + Annex IV (nine sections); NIST AI RMF Map 1, 2, 3 + Measure 1, 2 + Manage 1; ISO 42001 A.6 entire control area.
  • Article 17 QMS Documentation, EU AI Act Article 17; NIST AI RMF Govern; ISO 42001 Clauses 4-10 + Annex A.2-A.5.
  • Red-Team Report, EU AI Act Article 15 robustness + Article 55(1)(a) GPAI evaluation; NIST AI RMF Measure 2.7; ISO 42001 A.8; OWASP LLM01-LLM10 + ASI01-ASI10 cited per finding; MITRE ATLAS technique IDs cited per finding.
  • Model Card / System Card, EU AI Act Article 13 + Annex IV §2; NIST AI RMF Map 3 + Measure 2; ISO 42001 A.8.1.
  • Post-Market Monitoring Plan, EU AI Act Article 72; NIST AI RMF Manage 4; ISO 42001 A.6.4.
  • Article 73 Incident Response Runbook, EU AI Act Article 73; NIST AI RMF Manage 4.3; ISO 42001 A.8.4.
  • Board AI Risk Dashboard, EU AI Act board / governance pattern; NIST AI RMF Govern 4; ISO 42001 A.2.

Each row in this cross-walk is a single artifact the program produces once and references against five frameworks. The audit committee, the General Counsel, the External Auditor, the Red Team Lead, and the Threat-Intelligence team all read the same artifact, just through different framework-shaped windows. That is the efficiency win the cross-walk delivers.

Adjacent Frameworks Worth Knowing - Even Though Not in the Core Stack

Five additional frameworks orbit the core stack and intersect at specific program touchpoints:

  • ISO/IEC 23894:2023, AI Risk Management Process. Cited in ISO 42001 A.6.1; gives the formal process steps for AI risk identification, analysis, evaluation, and treatment. Useful when ISO 42001 audit needs a process methodology.
  • ISO/IEC 5338:2023, AI System Life Cycle. The lifecycle taxonomy ISO 42001 Annex A.6 references. Useful for the lifecycle-stage section of the Annex IV technical file.
  • CycloneDX 1.7 ML-BoM and CDXA Attestations, Supply-chain attestation for AI components. Released March 25, 2026. Cited in EU AI Act compliance through Article 53 (GPAI), Article 25 (substantial modification), and Article 16 (provider obligations).
  • AI-VSS (AI Vulnerability Scoring Standard), Severity-scoring rubric for AI-specific vulnerabilities; complements OWASP and MITRE ATLAS for the red-team report.
  • SR 11-7 / OCC 2011-12 / PRA SS1/23, Banking model-risk management. Applies to AI in financial services on top of the AI Act. Covered in depth in L3 Ch7.

None of these are "the AI regulation." They are technical instruments that fit specific evidence gaps. The cross-walk shows where each one belongs.

Three Program Archetypes - Which Layers Get Emphasis When

Different program archetypes weight the stack differently. Three common 2026 patterns:

Archetype 1 - EU-Headquartered Multinational

The EU AI Act is the binding regulation. ISO 42001 is the audit pathway leadership commits to. NIST AI RMF and the GenAI Profile are useful for U.S. operations and customer-facing assurance. OWASP and ATLAS sit with the security team. Annual cadence: ISO 42001 surveillance audits, Article 73 reporting infrastructure operational, Article 27 FRIAs on the affected portfolio, GPAI exposure map refreshed quarterly. Budget skew: 50% EU AI Act conformity work, 30% ISO 42001 certification, 20% red-team / NIST / OWASP overlay.

Archetype 2 - U.S.-Headquartered Multinational

The EU AI Act applies extraterritorially under Article 2(1) for EU outputs / customers. NIST AI RMF is the U.S. anchor. ISO 42001 is the certification U.S. customers ask for. NYC LL 144 / Texas TRAIGA / state law overlay. OWASP and ATLAS are the security team's framework. Annual cadence: NIST profile build for the major use cases, ISO 42001 Stage 1/2 audit, EU AI Act conformity assessment for EU-deployed systems, U.S. state-law compliance per jurisdiction. Budget skew: 35% EU AI Act for the EU portfolio, 25% NIST + state-law work, 25% ISO 42001 certification, 15% red-team / OWASP overlay.

Archetype 3 - Frontier Model Provider (GPAI-with-Systemic-Risk)

Article 55 is the dominant binding obligation. Article 53 is the floor. The GPAI Code of Practice is the operational pathway. NIST AI RMF and the GenAI Profile are the U.S. anchor. ISO 42001 is the audit standard. OWASP and ATLAS are the red-team frameworks. The CAISI / UK AISI / EU AI Office dangerous-capability evaluations are the binding evaluation scoreboard. Annual cadence: state-of-the-art evaluations, AI Office dialogue, RSP / equivalent updates, third-party red-team contributions. Budget skew dominated by Article 55 evaluations and mitigations.

Common Cross-Walk Mistakes

Mistake 1 - Single-Framework Thinking

The program adopts NIST AI RMF or ISO 42001 and stops there. The EU AI Act binding regulation is not mapped. OWASP and ATLAS are absent from the red-team report. The audit committee asks "are we compliant with the EU AI Act?" and the answer is a slide deck about NIST. That answer fails. The cross-walk requires all five layers visibly mapped.

Mistake 2 - Duplication of Artifacts

The program produces five separate AI inventories: one for the AI Act, one for ISO 42001, one for NIST, one for SOC 2 + AI, one for internal audit. The inventories drift. The five inventories disagree by a few rows. The auditor finds the disagreement and writes a finding. The fix: one inventory, five framework-citation columns.

Mistake 3 - OWASP and MITRE ATLAS as Decoration

The red-team report mentions OWASP and ATLAS in the title but does not cite specific entries per finding. An auditor reading the report cannot tell whether the red team actually tested LLM01 and ASI06 against the production system or just listed them. Every finding must cite a specific OWASP entry, a specific ATLAS technique ID, and the probe / tool that produced it (Promptfoo, Garak, PyRIT, Inspect, OpenAI Evals).

Mistake 4 - Stale ISO 42001 Evidence

The program achieves Stage 2 certification in Q2 and treats it as a one-time deliverable. By Q4 the evidence is stale, the AIMS has drifted from the documented version, and the surveillance audit produces findings. ISO 42001 is a management system. It requires continuous evidence, internal audits, management review, and corrective action. The cross-walk forces the continuous cadence by tying ISO 42001 control evidence to the same artifacts the EU AI Act and NIST require.

The Stack Chart - The L1 Deliverable

The L1 artifact for this lesson is a single-page stack chart: one row per major operational artifact (AI inventory, scope memo, tiering memo, GPAI exposure map, FRIA, Annex IV file, QMS, red-team report, model card, post-market monitoring plan, Article 73 runbook, board dashboard) and one column per framework (EU AI Act, NIST AI RMF, NIST AI 600-1 GenAI Profile, ISO/IEC 42001, OWASP LLM Top 10 / Agentic Top 10, MITRE ATLAS v5.4.0). Cell content is the specific article / control / category citation that the artifact serves under that framework.

The chart is the briefing document the AI Officer takes into the AI Governance Committee. It is the structure ISO 42001 auditors expect to see referenced in the AIMS scope document. It is the chart the General Counsel uses to explain to the Board why the program is spending what it is spending, where it is spending it, and against which regulator's expectations.

One page. One artifact. Five regulators answered in the same Friday meeting.

Key Takeaways

  • 2026 AI governance is a stack, not a single framework. Six layers, EU AI Act (binding), NIST AI RMF + 600-1 (U.S. consensus), ISO 42001 (audit standard), OWASP LLM + Agentic Top 10 (attack vocabulary), MITRE ATLAS v5.4.0 (threat intelligence), each load-bearing in a different audience and audit context.
  • The EU AI Act is the only binding layer. Article 99 penalty exposure makes the binding-vs-voluntary distinction matter. Other layers carry weight through procurement, audit, tort standard-of-care, and customer assurance, but no Article 99 hook.
  • NIST is voluntary but practically mandatory. U.S. federal procurement, state procurement, executive orders, and implicit standard of care make NIST AI RMF + 600-1 the de-facto U.S. framework. The 2026 CAISI Agent Standards Initiative extends the regime to agents.
  • ISO 42001 is the audit-defensible spine. Schellman / A-LIGN / BSI / KPMG own the ANAB-accredited certification market. Stage 1 (documentation) and Stage 2 (operating effectiveness) audits anchor the assurance pathway every regulator, auditor, customer, and board director reads the same way.
  • OWASP is the engineering vocabulary. LLM01-LLM10 (2025 update) + ASI01-ASI10 (Dec 9, 2025) translate regulatory language into the words the AppSec and red-team communities already speak. Red-team reports must cite OWASP entries by number per finding.
  • MITRE ATLAS v5.4.0 (Feb 2026) is the threat-intelligence map. 16 tactics / 84 techniques / 56 sub-techniques, with 14+ new agentic-system techniques added in partnership with Zenity Labs. Red teams cite ATLAS by technique ID - AML.T0010, AML.T0018, AML.T0044, AML.T0051, alongside OWASP.
  • The cross-walk is the engineering of evidence efficiency. One AI inventory, one scope memo, one tiering memo, one GPAI exposure map, one FRIA, one Annex IV file, one red-team report, each cited against five frameworks. Five reviewers, five framework-shaped windows, one underlying artifact.
  • Single-framework thinking fails audits. The audit committee asking "are we EU AI Act compliant?" gets a slide deck about NIST and the program fails. Map all five layers visibly.
  • Adjacent frameworks fit specific gaps. ISO 23894 (risk-management process), ISO 5338 (lifecycle), CycloneDX 1.7 ML-BoM (supply chain), AI-VSS (severity scoring), SR 11-7 (banking model risk). Use them where they fit; do not treat them as the core stack.
  • Program archetype determines layer weighting. EU multinational, U.S. multinational, frontier-model provider, three distinct emphasis patterns. The cross-walk is the same; the budget skew differs.
  • The stack chart is the L1 artifact. One page, one row per artifact, one column per framework, cell content the specific citation. The chart anchors every L2-L5 deliverable downstream.