GovernanceCore

AI Policies & Frameworks

63 AI policies tracked across 27 jurisdictions, from the EU AI Act and NIST AI Risk Management Framework to US state statutes, enforcement precedent and voluntary standards. Every entry links to its primary source.

63
Policies tracked
42
Carry binding duties
27
Jurisdictions
20
Risk areas covered
Browse by jurisdiction
63 policies
VoluntaryGuidelineAustralia

Australia AI Ethics Principles

Australia's Artificial Intelligence Ethics Principles

Eight voluntary principles, from human-centred values and fairness to contestability and accountability, that anchor Australian AI governance and underpin the later Voluntary AI Safety Standard.

Department of Industry, Science and ResourcesNov 7, 2019
VoluntaryFrameworkAustralia

Australia AI Safety Standard

Australian Voluntary AI Safety Standard

Ten voluntary guardrails covering accountability, risk management, data governance, testing, human oversight and disclosure. They are designed to preview the mandatory guardrails Australia has proposed for high-risk AI.

Department of Industry, Science and ResourcesSep 5, 2024
Must ComplyRegulationBrazilHigh risk

Brazil LGPD (Art. 20)

Brazil General Data Protection Law (LGPD): Automated Decision Review

Article 20 gives data subjects the right to request review of decisions made solely by automated processing that affect their interests. It is Brazil's operative AI constraint until its AI bill passes.

Autoridade Nacional de Proteção de Dados (ANPD)Aug 1, 2021
EmergingPendingBrazilHigh risk

Brazil PL 2338

Brazilian AI Bill (PL 2338/2023)

Brazil's EU-style, risk-based AI bill setting rights for affected people and graduated obligations by risk tier. Approved by the Senate and now under consideration in the Chamber of Deputies.

Proposed coordinated oversight led by the national data protection authority (ANPD)
Must ComplyRegulationUSLimited risk

California AB 2013

California Generative AI Training Data Transparency Act

Requires generative AI developers to publish high-level documentation about the datasets used to train their systems, including sources and whether personal or copyrighted data is included.

California Attorney GeneralJan 1, 2026
Must Comply from Jan 1, 2027RegulationUSHigh risk

California ADMT Regulations

California CCPA Regulations on Automated Decision-making Technology

Gives California consumers pre-use notice, opt-out and access rights over automated decision-making used for significant decisions, and requires risk assessments plus cybersecurity audits.

California Privacy Protection AgencyJan 1, 2027
Must ComplyRegulationUSLimited risk

California SB 1001

California Bot Disclosure Act (B.O.T. Act)

Makes it unlawful to use a bot to mislead people about its artificial identity in commercial or electoral contexts. An early chatbot disclosure rule that remains in force.

California Attorney GeneralJul 1, 2019
Must ComplyRegulationUSHigh risk

California SB 53

California Transparency in Frontier Artificial Intelligence Act

Requires developers of the largest frontier models to publish safety frameworks, report critical safety incidents, and protect whistleblowers. It is the leading US model for frontier-AI transparency.

California Attorney General / Office of Emergency ServicesJan 1, 2026
Must Comply from Aug 2, 2026RegulationUSLimited risk

California SB 942

California AI Transparency Act

Requires large generative AI providers to offer free AI-detection tools and embed latent + manifest provenance disclosures in AI-generated content, tackling synthetic-media transparency at scale.

California Attorney GeneralAug 2, 2026
Must ComplyRegulationCanadaHigh risk

Canada ADM Directive

Canada Directive on Automated Decision-Making

Binding on Canadian federal institutions: an Algorithmic Impact Assessment sets an impact level from I to IV, which then dictates notice, explanation, human-in-the-loop and audit requirements.

Treasury Board of Canada SecretariatApr 1, 2020
EmergingPendingCanadaHigh risk

Canada AIDA

Artificial Intelligence and Data Act (Bill C-27)

Canada's proposed federal AI statute establishing obligations for high-impact AI. It lapsed when Parliament was prorogued in early 2025; Canada currently relies on voluntary codes and existing law.

Proposed AI and Data Commissioner (Innovation, Science and Economic Development Canada)
Must ComplyEnforcementUSHigh risk

CFPB Circular 2022-03

CFPB Circular 2022-03: Adverse Action Notification Requirements for Algorithmic Credit Decisions

Confirms that creditors must give specific reasons for adverse credit decisions even when a complex algorithm produced them. Model opacity is not a defence under ECOA.

Consumer Financial Protection BureauMay 26, 2022
Must ComplyRegulationChinaLimited risk

China AI Labeling Rules

Measures for Labeling of AI-Generated Synthetic Content

Mandates both explicit (visible) and implicit (metadata) labels on AI-generated content and platform-level detection. The most detailed national synthetic-content labelling regime yet.

Cyberspace Administration of China (CAC)Sep 1, 2025
Must ComplyRegulationChina

China Algorithm Rules

Provisions on the Management of Algorithmic Recommendations in Internet Information Services

Regulates recommendation algorithms with duties around transparency, user opt-outs, protection against price discrimination, and an algorithm-filing system. A pioneering rulebook for algorithmic decisioning.

Cyberspace Administration of China (CAC) & related authoritiesMar 1, 2022
Must ComplyRegulationChinaLimited risk

China Deep Synthesis Rules

Provisions on the Administration of Deep Synthesis Internet Information Services

Requires conspicuous labelling of deepfake/synthetic content, consent for cloned likenesses and traceability. An early binding regime for synthetic media, predating most Western deepfake rules.

Cyberspace Administration of China (CAC)Jan 10, 2023
Must ComplyRegulationChina

China GenAI Measures

Interim Measures for the Management of Generative AI Services

China's core rules for public-facing generative AI, requiring content controls, training-data legality, security assessments and filing/registration before launch. Among the world's first binding GenAI regulations.

Cyberspace Administration of China (CAC) & other authoritiesAug 15, 2023
Must ComplyRegulationChina

China S&T Ethics Review Measures

Measures for the Ethical Review of Science and Technology Activities

Requires ethics review committees for science and technology work involving people or high-risk technology, with a named list of AI activities needing expert review, including algorithms with public-opinion or social-mobilisation capability.

Ministry of Science and Technology and sector regulatorsDec 1, 2023
Must Comply from May 17, 2024FrameworkISO/OECD/UN

CoE AI Convention

Framework Convention on AI, Human Rights, Democracy and the Rule of Law

The first legally binding international treaty on AI, signed by the EU, US, UK and others, anchoring AI governance to human rights, democracy and the rule of law across the full AI lifecycle.

Signatory states (Conference of the Parties oversight)May 17, 2024
VoluntaryFrameworkISO/OECD/UN

CoE HUDERIA

HUDERIA: Methodology for Risk and Impact Assessment of AI Systems

The Council of Europe's assessment methodology for AI risks to human rights, democracy and the rule of law. The operational companion to its Framework Convention on AI.

Council of Europe Committee on Artificial IntelligenceDec 2, 2024
Must Comply from Jan 1, 2027RegulationUSHigh risk

Colorado AI Act (SB 26-189)

Colorado Artificial Intelligence Act

The first US comprehensive state AI law targeting algorithmic discrimination in consequential decisions. Since repealed and replaced by a narrower automated-decision-technology statute taking effect January 2027.

Colorado Attorney GeneralJan 1, 2027
Must ComplyRegulationEUHigh risk

EU AI Act

EU Artificial Intelligence Act

The world's first comprehensive, risk-based AI law. Classifies AI by risk tier (prohibited, high-risk, limited, minimal) and imposes graduated obligations, with most high-risk rules and enforcement starting 2 August 2026.

European AI Office & national market-surveillance authoritiesAug 2, 2026
Must ComplyRegulationEU

EU Data Act

Governs access to and sharing of data generated by connected products, and mandates cloud-switching rights. Sets the terms on which AI developers can lawfully obtain industrial and IoT training data.

National competent authorities & the European Data Innovation BoardSep 12, 2025
Must ComplyRegulationEU

EU Data Governance Act

Creates trusted routes for reusing protected public-sector data and for data intermediation and altruism. Relevant wherever AI training data is sourced from public bodies or shared data spaces.

National competent authorities & the European Data Innovation BoardSep 24, 2023
Must ComplyRegulationEU

EU DMA

EU Digital Markets Act

Imposes ex-ante conduct rules on designated gatekeeper platforms, including fairness and transparency duties over ranking and self-preferencing. These constraints bite directly on AI-driven recommendation.

European Commission (DG COMP & DG CNECT)Mar 7, 2024
Must ComplyRegulationEU

EU DSA

Digital Services Act

Governs recommender systems and algorithmic amplification with transparency, risk-assessment and audit duties for large platforms. It is a core rulebook for AI-driven content ranking and moderation.

European Commission & national Digital Services CoordinatorsFeb 17, 2024
Must ComplyRegulationEUHigh risk

EU GDPR (Art. 22)

General Data Protection Regulation (automated decision-making)

Article 22 gives individuals the right not to be subject to solely automated decisions producing legal or similarly significant effects, plus rights to information, human review and to contest. It is a key constraint on AI-driven decisioning.

European Data Protection Board & national data protection authoritiesMay 25, 2018
VoluntaryFrameworkEU

EU GPAI Code of Practice

General-Purpose AI Code of Practice

The Commission-facilitated code that GPAI model providers can sign to demonstrate compliance with the AI Act's transparency, copyright and systemic-risk duties. Voluntary in form, near-default in practice.

European AI OfficeAug 2, 2025
Must Comply from Jan 20, 2027RegulationEUHigh risk

EU Machinery Regulation

Sets safety requirements for machinery placed on the EU market, treating AI-based safety functions as high-risk components. Machinery in scope also triggers high-risk duties under the AI Act.

National market-surveillance authoritiesJan 20, 2027
Must Comply from Dec 9, 2026RegulationEU

EU Product Liability Directive

EU Revised Product Liability Directive

Extends EU strict product liability expressly to software and AI systems, and eases the burden of proof for claimants in technically complex cases. The main civil-liability exposure sitting alongside the AI Act.

National courts of EU member statesDec 9, 2026
Must ComplyGuidelineEUUnacceptable risk

EU Prohibited Practices Guidelines

Commission Guidelines on Prohibited AI Practices

The Commission's official reading of the AI Act's Article 5 bans: manipulative techniques, social scoring, emotion recognition at work and untargeted facial scraping. The reference point for scoping prohibited-use reviews.

European Commission & national market-surveillance authoritiesFeb 2, 2025
Must ComplyGuidelineUSHigh risk

FDA AI/ML SaMD Guidance

FDA Guidance on Artificial Intelligence and Machine Learning in Software as a Medical Device

The FDA's approach to AI/ML-enabled medical devices, covering predetermined change-control plans, good machine-learning practice and transparency to clinicians. The main route to market for clinical AI in the US.

US Food and Drug Administration (CDRH)Jan 12, 2021
Must ComplyEnforcementUS

FTC Operation AI Comply

FTC Enforcement Against Deceptive AI Claims (Operation AI Comply)

The FTC's enforcement sweep against exaggerated and deceptive AI claims, applying existing Section 5 unfairness and deception authority. Establishes that AI marketing claims need substantiation like any other.

Federal Trade CommissionSep 25, 2024
VoluntaryFrameworkISO/OECD/UN

G7 Hiroshima Code of Conduct

Hiroshima Process International Code of Conduct for Advanced AI Systems

Eleven voluntary actions for frontier AI developers covering red-teaming, incident reporting, security controls and content authentication. Now backed by an OECD reporting framework that makes adherence comparable.

None (voluntary, with OECD-hosted transparency reporting)Oct 30, 2023
Must ComplyRegulationUSHigh risk

Illinois AI (HR)

Illinois AI Employment Laws (AI Video Interview Act & HB 3773)

Illinois pairs its 2020 AI Video Interview Act with a 2026 Human Rights Act amendment (HB 3773) that makes discriminatory use of AI in employment decisions an unlawful practice and requires notice to workers.

Illinois Department of Human RightsJan 1, 2026
Must ComplyRegulationUSHigh risk

Illinois HB 3773

Illinois House Bill 3773: Artificial Intelligence in Employment Decisions

Amends the Illinois Human Rights Act to make discriminatory AI use in employment decisions a civil rights violation, and bars using ZIP code as a proxy for protected class.

Illinois Department of Human RightsJan 1, 2026
Must Comply from Nov 14, 2025RegulationIndia

India DPDP Act

India Digital Personal Data Protection Act, 2023

India's consent-based personal data law, and the main legal constraint on AI training and deployment there. Significant data fiduciaries face added duties including algorithmic due diligence.

Data Protection Board of IndiaNov 14, 2025
VoluntaryGuidelineIndia

India Responsible AI Principles

NITI Aayog Responsible AI for All: Approach Document for India

India's foundational responsible-AI principles, covering safety, equality, inclusivity, privacy, transparency and accountability. Advisory, but the reference point for Indian AI policy design.

NITI Aayog (advisory)Feb 22, 2021
VoluntaryGuidelineISO/OECD/UN

ISO/IEC 23894

ISO/IEC 23894: AI Risk Management Guidance

Guidance that maps general ISO 31000 risk management to AI, giving organisations a common vocabulary and process for identifying, analysing and treating AI risks across the lifecycle.

ISO/IEC (guidance)Feb 1, 2023
VoluntaryFrameworkISO/OECD/UN

ISO/IEC 42001

ISO/IEC 42001: Artificial Intelligence Management System

The first certifiable AI management-system standard, defining requirements to establish, implement, maintain and continually improve an AI governance system. It is increasingly used to demonstrate regulatory readiness.

ISO/IEC (certification via accredited bodies)Dec 18, 2023
VoluntaryGuidelineJapan

Japan AI Business Guidelines

Japan AI Guidelines for Business

Consolidates Japan's earlier AI guidance into one document with distinct duties for developers, providers and users. Soft-law by design, and the operating detail behind the AI Promotion Act.

Ministry of Economy, Trade and Industry; Ministry of Internal Affairs and CommunicationsApr 19, 2024
Must ComplyRegulationJapan

Japan AI Promotion Act

Act on the Promotion of Research, Development and Utilization of AI-Related Technologies

Japan's light-touch, innovation-first AI law establishing national coordination and basic principles for trustworthy AI, deliberately avoiding hard penalties in favour of guidance and government-led response.

AI Strategy Headquarters (Cabinet Office)Sep 1, 2025
Must ComplyRegulationUSHigh risk

Maryland HB 1202

Maryland House Bill 1202: Use of Facial Recognition Services in Job Interviews

Bars employers from using facial recognition during job interviews without the applicant's signed consent waiver. One of the earliest US limits on biometric AI in hiring.

Maryland courts (private right of action)Oct 1, 2020
VoluntaryFrameworkUS

NIST AI RMF

NIST AI Risk Management Framework 1.0

A voluntary, widely adopted framework organised around four functions (Govern, Map, Measure and Manage) that has become the de facto reference for building trustworthy AI programmes in the US and beyond.

National Institute of Standards and Technology (non-binding)Jan 26, 2023
VoluntaryFrameworkUS

NIST GenAI Profile

NIST AI Risk Management Framework: Generative AI Profile (NIST AI 600-1)

Names twelve risks unique to or amplified by generative AI (confabulation, CBRN uplift, harmful bias, data leakage) and maps suggested actions onto the AI RMF's four functions.

None (voluntary NIST guidance)Jul 26, 2024
VoluntaryFrameworkUS

NIST SP 800-218A

Secure Software Development Practices for Generative AI and Dual-Use Foundation Models (SP 800-218A)

Extends the Secure Software Development Framework to generative AI, adding practices for training-data provenance, model weight protection and supply-chain integrity.

None (voluntary NIST guidance)Jul 26, 2024
Must ComplyRegulationUS

NY LOADinG Act

New York LOADinG Act: Legislative Oversight of Automated Decision-making in Government

Requires New York State agencies to inventory and review automated decision-making systems, keep meaningful human oversight, and bars using them to displace unionised state workers.

New York State Office of Information Technology ServicesDec 21, 2024
EmergingPendingUSHigh risk

NY RAISE Act

New York Responsible AI Safety and Education Act

Would require frontier model developers to publish safety protocols, withhold models posing unreasonable risk of critical harm, and report safety incidents to the state.

New York State Attorney General (proposed)
Must ComplyRegulationUSHigh risk

NYC LL 144 (Bias Audit)

NYC Local Law 144: Automated Employment Decision Tools

Requires an annual independent bias audit of hiring/promotion AI tools, publication of results, and advance notice to candidates. It is the most-cited US example of mandatory algorithmic bias auditing.

NYC Department of Consumer and Worker ProtectionJul 5, 2023
VoluntaryGuidelineISO/OECD/UN

OECD AI Principles

The first intergovernmental AI standard, adopted by 40+ countries, setting values-based principles (inclusive growth, human-centred values, transparency, robustness, accountability) that shaped the G20 and many national frameworks.

OECD (non-binding intergovernmental standard)May 22, 2019
Must ComplyRegulationUSHigh risk

OMB M-24-10

OMB Memorandum M-24-10: Advancing Governance, Innovation and Risk Management for Agency Use of AI

Requires federal agencies to appoint Chief AI Officers, inventory AI use cases, and apply minimum risk practices to rights- and safety-impacting AI or stop using it. Reaches vendors through procurement.

Office of Management and Budget; agency Chief AI OfficersDec 1, 2024
VoluntaryFrameworkSingapore

Singapore AI Verify

AI Verify Testing Framework and Toolkit

A testing framework and software toolkit that lets organisations run technical tests and process checks against Singapore's AI governance principles, producing a standardised report.

IMDA & AI Verify FoundationMay 25, 2022
VoluntaryFrameworkSingapore

Singapore Model AI Framework

Model AI Governance Framework (incl. Generative AI)

A widely referenced voluntary framework translating high-level principles into concrete practices, extended in 2024 with dedicated guidance for generative AI and paired with the AI Verify testing toolkit.

Infocomm Media Development Authority (IMDA) & PDPCMay 30, 2024
Must ComplyRegulationKoreaHigh risk

South Korea AI Basic Act

Framework Act on the Development of AI and Establishment of Trust (AI Basic Act)

Asia's first comprehensive AI law: a promotion-plus-trust framework with transparency and labelling duties, extra obligations for 'high-impact' AI, human oversight, and extraterritorial reach over foreign providers.

Ministry of Science and ICTJan 22, 2026
Must ComplyRegulationUS

Tennessee ELVIS Act

Ensuring Likeness, Voice, and Image Security Act

The first US law expressly protecting individuals' voice and likeness from AI cloning, extending publicity rights to cover generative-AI voice and image deepfakes.

Private right of action & Tennessee courtsJul 1, 2024
Must ComplyRegulationUSHigh risk

Texas TRAIGA

Texas Responsible Artificial Intelligence Governance Act

A narrowed governance statute focused on state-agency AI use, with bans on AI designed for behavioural manipulation, unlawful discrimination, or producing unlawful deepfake content, and a regulatory sandbox.

Texas Attorney GeneralJan 1, 2026
VoluntaryGuidelineUK

UK AI Principles

UK Pro-Innovation AI Regulation Framework

The UK's context-based, principles-led approach: five cross-cutting principles (safety, transparency, fairness, accountability, contestability) applied by existing regulators, with no single overarching AI law to date.

Existing sector regulators (ICO, CMA, FCA, Ofcom, etc.) & the AI Security InstituteMar 29, 2023
Must ComplyGuidelineUK

UK ICO AI Guidance

ICO Guidance on AI and Data Protection

The ICO's operative guidance on lawful AI under UK data protection law, covering fairness, accountability, transparency and the trade-offs in AI-specific DPIAs. Backed by real enforcement powers.

Information Commissioner's OfficeJul 30, 2020
VoluntaryGuidelineISO/OECD/UN

UN GA AI Resolution

UN General Assembly Resolution on Safe, Secure and Trustworthy AI

The first UN-wide resolution on AI, adopted by consensus, framing safe and trustworthy AI around the Sustainable Development Goals and human rights. Sets direction rather than duties.

None (a General Assembly resolution)Mar 21, 2024
VoluntaryGuidelineISO/OECD/UN

UNESCO AI Ethics Recommendation

UNESCO Recommendation on the Ethics of Artificial Intelligence

The first globally adopted AI ethics instrument, agreed by 193 states. Non-binding, but its readiness-assessment and impact-assessment methodologies feed directly into national AI strategies.

UNESCO (via member-state reporting)Nov 23, 2021
Must ComplyEnforcementUSHigh risk

US EEOC / Title VII (AI)

US Anti-Discrimination Law Applied to AI (Title VII & ADA)

Rather than a new AI statute, US federal anti-discrimination law (Title VII, ADA) already reaches biased AI hiring and employment tools. It is the enforcement baseline for algorithmic discrimination in US workplaces.

Equal Employment Opportunity Commission (EEOC)Jul 2, 1965
Must ComplyGuidelineUS

US Federal AI EO (2025)

Executive Order: Ensuring a National Policy Framework for Artificial Intelligence

A December 2025 executive order seeking a single national AI policy framework and signalling federal intent to preempt state AI laws judged inconsistent. It is the central variable in the US patchwork's future.

White House / Office of Management and Budget & federal agenciesDec 11, 2025
Must Comply from May 19, 2026RegulationUS

US TAKE IT DOWN Act

TAKE IT DOWN Act

Criminalises publishing non-consensual intimate imagery, including AI-generated deepfakes, and requires covered platforms to remove reported content within 48 hours of a valid request.

Federal Trade CommissionMay 19, 2026
Must ComplyRegulationUSLimited risk

Utah SB 149

Utah Artificial Intelligence Policy Act

Requires businesses to disclose generative-AI use to consumers on request (and proactively in regulated professions), and creates a state Office of AI Policy with a regulatory 'learning lab'.

Utah Division of Consumer Protection & Office of Artificial Intelligence PolicyMay 1, 2024

Jurisdiction guides

Maintained for general information; not legal advice. Obligation and risk labels are our reading of each instrument, not an official classification. Confirm against the primary source before acting. For dates, status and enforcement detail, see the regulation tracker.