AI Policies & Frameworks
63 AI policies tracked across 27 jurisdictions, from the EU AI Act and NIST AI Risk Management Framework to US state statutes, enforcement precedent and voluntary standards. Every entry links to its primary source.
Australia AI Ethics Principles
Australia's Artificial Intelligence Ethics Principles
Eight voluntary principles, from human-centred values and fairness to contestability and accountability, that anchor Australian AI governance and underpin the later Voluntary AI Safety Standard.
Australia AI Safety Standard
Australian Voluntary AI Safety Standard
Ten voluntary guardrails covering accountability, risk management, data governance, testing, human oversight and disclosure. They are designed to preview the mandatory guardrails Australia has proposed for high-risk AI.
Brazil LGPD (Art. 20)
Brazil General Data Protection Law (LGPD): Automated Decision Review
Article 20 gives data subjects the right to request review of decisions made solely by automated processing that affect their interests. It is Brazil's operative AI constraint until its AI bill passes.
Brazil PL 2338
Brazilian AI Bill (PL 2338/2023)
Brazil's EU-style, risk-based AI bill setting rights for affected people and graduated obligations by risk tier. Approved by the Senate and now under consideration in the Chamber of Deputies.
California AB 2013
California Generative AI Training Data Transparency Act
Requires generative AI developers to publish high-level documentation about the datasets used to train their systems, including sources and whether personal or copyrighted data is included.
California ADMT Regulations
California CCPA Regulations on Automated Decision-making Technology
Gives California consumers pre-use notice, opt-out and access rights over automated decision-making used for significant decisions, and requires risk assessments plus cybersecurity audits.
California SB 1001
California Bot Disclosure Act (B.O.T. Act)
Makes it unlawful to use a bot to mislead people about its artificial identity in commercial or electoral contexts. An early chatbot disclosure rule that remains in force.
California SB 53
California Transparency in Frontier Artificial Intelligence Act
Requires developers of the largest frontier models to publish safety frameworks, report critical safety incidents, and protect whistleblowers. It is the leading US model for frontier-AI transparency.
California SB 942
California AI Transparency Act
Requires large generative AI providers to offer free AI-detection tools and embed latent + manifest provenance disclosures in AI-generated content, tackling synthetic-media transparency at scale.
Canada ADM Directive
Canada Directive on Automated Decision-Making
Binding on Canadian federal institutions: an Algorithmic Impact Assessment sets an impact level from I to IV, which then dictates notice, explanation, human-in-the-loop and audit requirements.
Canada AIDA
Artificial Intelligence and Data Act (Bill C-27)
Canada's proposed federal AI statute establishing obligations for high-impact AI. It lapsed when Parliament was prorogued in early 2025; Canada currently relies on voluntary codes and existing law.
CFPB Circular 2022-03
CFPB Circular 2022-03: Adverse Action Notification Requirements for Algorithmic Credit Decisions
Confirms that creditors must give specific reasons for adverse credit decisions even when a complex algorithm produced them. Model opacity is not a defence under ECOA.
China AI Labeling Rules
Measures for Labeling of AI-Generated Synthetic Content
Mandates both explicit (visible) and implicit (metadata) labels on AI-generated content and platform-level detection. The most detailed national synthetic-content labelling regime yet.
China Algorithm Rules
Provisions on the Management of Algorithmic Recommendations in Internet Information Services
Regulates recommendation algorithms with duties around transparency, user opt-outs, protection against price discrimination, and an algorithm-filing system. A pioneering rulebook for algorithmic decisioning.
China Deep Synthesis Rules
Provisions on the Administration of Deep Synthesis Internet Information Services
Requires conspicuous labelling of deepfake/synthetic content, consent for cloned likenesses and traceability. An early binding regime for synthetic media, predating most Western deepfake rules.
China GenAI Measures
Interim Measures for the Management of Generative AI Services
China's core rules for public-facing generative AI, requiring content controls, training-data legality, security assessments and filing/registration before launch. Among the world's first binding GenAI regulations.
China S&T Ethics Review Measures
Measures for the Ethical Review of Science and Technology Activities
Requires ethics review committees for science and technology work involving people or high-risk technology, with a named list of AI activities needing expert review, including algorithms with public-opinion or social-mobilisation capability.
CoE AI Convention
Framework Convention on AI, Human Rights, Democracy and the Rule of Law
The first legally binding international treaty on AI, signed by the EU, US, UK and others, anchoring AI governance to human rights, democracy and the rule of law across the full AI lifecycle.
CoE HUDERIA
HUDERIA: Methodology for Risk and Impact Assessment of AI Systems
The Council of Europe's assessment methodology for AI risks to human rights, democracy and the rule of law. The operational companion to its Framework Convention on AI.
Colorado AI Act (SB 26-189)
Colorado Artificial Intelligence Act
The first US comprehensive state AI law targeting algorithmic discrimination in consequential decisions. Since repealed and replaced by a narrower automated-decision-technology statute taking effect January 2027.
EU AI Act
EU Artificial Intelligence Act
The world's first comprehensive, risk-based AI law. Classifies AI by risk tier (prohibited, high-risk, limited, minimal) and imposes graduated obligations, with most high-risk rules and enforcement starting 2 August 2026.
EU Data Act
Governs access to and sharing of data generated by connected products, and mandates cloud-switching rights. Sets the terms on which AI developers can lawfully obtain industrial and IoT training data.
EU Data Governance Act
Creates trusted routes for reusing protected public-sector data and for data intermediation and altruism. Relevant wherever AI training data is sourced from public bodies or shared data spaces.
EU DMA
EU Digital Markets Act
Imposes ex-ante conduct rules on designated gatekeeper platforms, including fairness and transparency duties over ranking and self-preferencing. These constraints bite directly on AI-driven recommendation.
EU DSA
Digital Services Act
Governs recommender systems and algorithmic amplification with transparency, risk-assessment and audit duties for large platforms. It is a core rulebook for AI-driven content ranking and moderation.
EU GDPR (Art. 22)
General Data Protection Regulation (automated decision-making)
Article 22 gives individuals the right not to be subject to solely automated decisions producing legal or similarly significant effects, plus rights to information, human review and to contest. It is a key constraint on AI-driven decisioning.
EU GPAI Code of Practice
General-Purpose AI Code of Practice
The Commission-facilitated code that GPAI model providers can sign to demonstrate compliance with the AI Act's transparency, copyright and systemic-risk duties. Voluntary in form, near-default in practice.
EU Machinery Regulation
Sets safety requirements for machinery placed on the EU market, treating AI-based safety functions as high-risk components. Machinery in scope also triggers high-risk duties under the AI Act.
EU Product Liability Directive
EU Revised Product Liability Directive
Extends EU strict product liability expressly to software and AI systems, and eases the burden of proof for claimants in technically complex cases. The main civil-liability exposure sitting alongside the AI Act.
EU Prohibited Practices Guidelines
Commission Guidelines on Prohibited AI Practices
The Commission's official reading of the AI Act's Article 5 bans: manipulative techniques, social scoring, emotion recognition at work and untargeted facial scraping. The reference point for scoping prohibited-use reviews.
FDA AI/ML SaMD Guidance
FDA Guidance on Artificial Intelligence and Machine Learning in Software as a Medical Device
The FDA's approach to AI/ML-enabled medical devices, covering predetermined change-control plans, good machine-learning practice and transparency to clinicians. The main route to market for clinical AI in the US.
FTC Operation AI Comply
FTC Enforcement Against Deceptive AI Claims (Operation AI Comply)
The FTC's enforcement sweep against exaggerated and deceptive AI claims, applying existing Section 5 unfairness and deception authority. Establishes that AI marketing claims need substantiation like any other.
G7 Hiroshima Code of Conduct
Hiroshima Process International Code of Conduct for Advanced AI Systems
Eleven voluntary actions for frontier AI developers covering red-teaming, incident reporting, security controls and content authentication. Now backed by an OECD reporting framework that makes adherence comparable.
Illinois AI (HR)
Illinois AI Employment Laws (AI Video Interview Act & HB 3773)
Illinois pairs its 2020 AI Video Interview Act with a 2026 Human Rights Act amendment (HB 3773) that makes discriminatory use of AI in employment decisions an unlawful practice and requires notice to workers.
Illinois HB 3773
Illinois House Bill 3773: Artificial Intelligence in Employment Decisions
Amends the Illinois Human Rights Act to make discriminatory AI use in employment decisions a civil rights violation, and bars using ZIP code as a proxy for protected class.
India DPDP Act
India Digital Personal Data Protection Act, 2023
India's consent-based personal data law, and the main legal constraint on AI training and deployment there. Significant data fiduciaries face added duties including algorithmic due diligence.
India Responsible AI Principles
NITI Aayog Responsible AI for All: Approach Document for India
India's foundational responsible-AI principles, covering safety, equality, inclusivity, privacy, transparency and accountability. Advisory, but the reference point for Indian AI policy design.
ISO/IEC 23894
ISO/IEC 23894: AI Risk Management Guidance
Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.
ISO/IEC 42001
ISO/IEC 42001: Artificial Intelligence Management System
The first certifiable AI management-system standard, defining requirements to establish, implement, maintain and continually improve an AI governance system. It is increasingly used to demonstrate regulatory readiness.
Japan AI Business Guidelines
Japan AI Guidelines for Business
Consolidates Japan's earlier AI guidance into one document with distinct duties for developers, providers and users. Soft-law by design, and the operating detail behind the AI Promotion Act.
Japan AI Promotion Act
Act on the Promotion of Research, Development and Utilization of AI-Related Technologies
Japan's light-touch, innovation-first AI law establishing national coordination and basic principles for trustworthy AI, deliberately avoiding hard penalties in favour of guidance and government-led response.
Maryland HB 1202
Maryland House Bill 1202: Use of Facial Recognition Services in Job Interviews
Bars employers from using facial recognition during job interviews without the applicant's signed consent waiver. One of the earliest US limits on biometric AI in hiring.
NIST AI RMF
NIST AI Risk Management Framework 1.0
A voluntary, widely adopted framework organised around four functions (Govern, Map, Measure and Manage) that has become the de facto reference for building trustworthy AI programmes in the US and beyond.
NIST GenAI Profile
NIST AI Risk Management Framework: Generative AI Profile (NIST AI 600-1)
Names twelve risks unique to or amplified by generative AI (confabulation, CBRN uplift, harmful bias, data leakage) and maps suggested actions onto the AI RMF's four functions.
NIST SP 800-218A
Secure Software Development Practices for Generative AI and Dual-Use Foundation Models (SP 800-218A)
Extends the Secure Software Development Framework to generative AI, adding practices for training-data provenance, model weight protection and supply-chain integrity.
NY LOADinG Act
New York LOADinG Act: Legislative Oversight of Automated Decision-making in Government
Requires New York State agencies to inventory and review automated decision-making systems, keep meaningful human oversight, and bars using them to displace unionised state workers.
NY RAISE Act
New York Responsible AI Safety and Education Act
Would require frontier model developers to publish safety protocols, withhold models posing unreasonable risk of critical harm, and report safety incidents to the state.
NYC LL 144 (Bias Audit)
NYC Local Law 144: Automated Employment Decision Tools
Requires an annual independent bias audit of hiring/promotion AI tools, publication of results, and advance notice to candidates. It is the most-cited US example of mandatory algorithmic bias auditing.
OECD AI Principles
The first intergovernmental AI standard, adopted by 40+ countries, setting values-based principles (inclusive growth, human-centred values, transparency, robustness, accountability) that shaped the G20 and many national frameworks.
OMB M-24-10
OMB Memorandum M-24-10: Advancing Governance, Innovation and Risk Management for Agency Use of AI
Requires federal agencies to appoint Chief AI Officers, inventory AI use cases, and apply minimum risk practices to rights- and safety-impacting AI or stop using it. Reaches vendors through procurement.
Singapore AI Verify
AI Verify Testing Framework and Toolkit
A testing framework and software toolkit that lets organisations run technical tests and process checks against Singapore's AI governance principles, producing a standardised report.
Singapore Model AI Framework
Model AI Governance Framework (incl. Generative AI)
A widely referenced voluntary framework translating high-level principles into concrete practices, extended in 2024 with dedicated guidance for generative AI and paired with the AI Verify testing toolkit.
South Korea AI Basic Act
Framework Act on the Development of AI and Establishment of Trust (AI Basic Act)
Asia's first comprehensive AI law: a promotion-plus-trust framework with transparency and labelling duties, extra obligations for 'high-impact' AI, human oversight, and extraterritorial reach over foreign providers.
Tennessee ELVIS Act
Ensuring Likeness, Voice, and Image Security Act
The first US law expressly protecting individuals' voice and likeness from AI cloning, extending publicity rights to cover generative-AI voice and image deepfakes.
Texas TRAIGA
Texas Responsible Artificial Intelligence Governance Act
A narrowed governance statute focused on state-agency AI use, with bans on AI designed for behavioural manipulation, unlawful discrimination, or producing unlawful deepfake content, and a regulatory sandbox.
UK AI Principles
UK Pro-Innovation AI Regulation Framework
The UK's context-based, principles-led approach: five cross-cutting principles (safety, transparency, fairness, accountability, contestability) applied by existing regulators, with no single overarching AI law to date.
UK ICO AI Guidance
ICO Guidance on AI and Data Protection
The ICO's operative guidance on lawful AI under UK data protection law, covering fairness, accountability, transparency and the trade-offs in AI-specific DPIAs. Backed by real enforcement powers.
UN GA AI Resolution
UN General Assembly Resolution on Safe, Secure and Trustworthy AI
The first UN-wide resolution on AI, adopted by consensus, framing safe and trustworthy AI around the Sustainable Development Goals and human rights. Sets direction rather than duties.
UNESCO AI Ethics Recommendation
UNESCO Recommendation on the Ethics of Artificial Intelligence
The first globally adopted AI ethics instrument, agreed by 193 states. Non-binding, but its readiness-assessment and impact-assessment methodologies feed directly into national AI strategies.
US EEOC / Title VII (AI)
US Anti-Discrimination Law Applied to AI (Title VII & ADA)
Rather than a new AI statute, US federal anti-discrimination law (Title VII, ADA) already reaches biased AI hiring and employment tools. It is the enforcement baseline for algorithmic discrimination in US workplaces.
US Federal AI EO (2025)
Executive Order: Ensuring a National Policy Framework for Artificial Intelligence
A December 2025 executive order seeking a single national AI policy framework and signalling federal intent to preempt state AI laws judged inconsistent. It is the central variable in the US patchwork's future.
US TAKE IT DOWN Act
TAKE IT DOWN Act
Criminalises publishing non-consensual intimate imagery, including AI-generated deepfakes, and requires covered platforms to remove reported content within 48 hours of a valid request.
Utah SB 149
Utah Artificial Intelligence Policy Act
Requires businesses to disclose generative-AI use to consumers on request (and proactively in regulated professions), and creates a state Office of AI Policy with a regulatory 'learning lab'.
Jurisdiction guides
Maintained for general information; not legal advice. Obligation and risk labels are our reading of each instrument, not an official classification. Confirm against the primary source before acting. For dates, status and enforcement detail, see the regulation tracker.