Open, source-backed AI policy intelligence
AI policy, verified at the source.
Explore source-backed AI laws, regulations, standards, public-sector guidance, obligations, deadlines, and implementation actions across jurisdictions.
Latest policy changes
All changes and RSSMinistry of Digital begins engagement and public consultation on the AI Governance Bill
Withdrawal gazetted (Notice 3978 of 2026, Gazette No. 54840)
Update to the National AI Strategy released with 10 refreshed priorities
Government completes inter-ministerial finalisation of the roadmap and ethics draft regulations
Minister Malatsi announces withdrawal of the draft policy
Start from your job
Compliance or CISO
Which rules apply, by when, and what evidence to keep.
Researcher
Incidents, risk taxonomy and exports with citation.
Policymaker
Compare jurisdictions and track dated changes.
Civil society or journalist
Who is harmed, who deploys, where rules are missing.
Founder or product lead
A 90-day readiness path and free templates.
Jurisdictions
All jurisdictions-
No binding cross-sector AI law; mandatory guardrails were consulted on in 2024 but the December 2025 National AI Plan signalled an existing-law approach. Voluntary AI Safety Standard available. Government agencies follow a binding whole-of-government AI policy. A reviewer must confirm the current status of the mandatory-guardrails proposal.
-
Framework Convention adopted and open for signature; entry into force depends on ratifications; HUDERIA methodology adopted.
-
Binding regulation in force and partially applicable. Prohibited practices and AI-literacy duties apply since 2 February 2025; general-purpose AI model obligations and the governance and penalties chapters since 2 August 2025; most remaining obligations, including Annex III high-risk requirements, are scheduled from 2 August 2026, with high-risk AI embedded in Annex I regulated products from 2 August 2027. A Commission "Digital Omnibus" proposal published in November 2025 would adjust some high-risk application dates; its adoption status must be checked against the official sources linked below.
-
EU AI Act applies; national AI strategy (phases since 2018) as policy; CNIL AI guidance; competent-authority designation in progress.
-
EU AI Act applies; national implementing act (KI-Marktüberwachungs- und Innovationsförderungsgesetz) proposed; national AI strategy in force as policy.
-
No binding cross-sector AI law. Binding obligations arise from the DPDP Act 2023 (phased commencement under the November 2025 Rules), the IT Act and intermediary rules, and sector regulation. The India AI Governance Guidelines (November 2025) are non-binding. A reviewer must confirm the commencement schedule of the DPDP Rules.
-
Non-binding recommendations, declarations and a voluntary standard; binding effect arises only through national implementation or contractual adoption.
-
EU AI Act applies; national AI law in force since 10 October 2025; AI strategy 2024–2026 as policy; active data-protection enforcement.
-
National AI policy adopted (2025); no binding AI-specific law; privacy and electronic-transaction laws apply. Source certainty for policy documents is medium because official English-language texts and stable document URLs are limited; every record here must be verified against MoCIT publications.
-
No binding cross-sector AI law. Binding obligations come from the Personal Data Protection Act 2012, the Online Safety framework, sector regulation and consumer law. AI governance frameworks are voluntary but widely referenced.
-
EU AI Act applies; AESIA operational; national implementation bill proposed (2025); AI Strategy 2024 as policy.
-
No binding federal AI law; national AI strategy and ethics guidance in place; binding personal-data rules at federal level and in the DIFC and ADGM free zones. A reviewer must confirm the current status of any AI-specific regulation announced by the UAE's regulatory intelligence office or the Regulations Lab.
-
Principles-based, regulator-led framework; no AI-specific Act in force. The government has signalled a future bill targeting the most powerful AI models, but as of the last check no such bill had been introduced. Sector regulators (ICO, FCA, CMA, Ofcom, MHRA, EHRC) publish AI guidance and enforce existing law.
-
Federal: executive-branch policy (Executive Order 14179 of January 2025 and the July 2025 AI Action Plan) plus binding OMB requirements for federal agencies' use and procurement of AI; NIST AI RMF is voluntary. States: a growing number of binding statutes with 2025–2026 effective dates. A reviewer must confirm the status of federal efforts to pre-empt or discourage state AI laws announced in late 2025.
Key instruments
Colorado AI Act
Colorado Senate Bill 24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act)
The Colorado AI Act requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. High-risk systems are those that make, or are a substantial factor in making, consequential decisions about education, employment, financial or lending services, essential government services, healthcare, housing, insurance or legal services. Deployers must run risk-management programmes and impact assessments, notify consumers, and explain adverse decisions; developers must document systems and disclose known risks.
Framework Convention on AI (CETS 225)
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225)
The first international treaty on AI. Parties must adopt or maintain measures so that activities within the lifecycle of AI systems are consistent with human rights, democracy and the rule of law, covering public authorities and actors on their behalf and, by choice of approach, private actors. It sets principles (human dignity and autonomy, transparency and oversight, accountability, equality and non-discrimination, privacy, reliability, safe innovation), requires remedies, procedural safeguards and risk and impact assessment, allows moratoria or bans for incompatible uses, and creates a Conference of the Parties for follow-up. National-security activities and defence are excluded.
India DPDP Act
Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.
Law on Artificial Intelligence (2025)
Law of the Republic of Kazakhstan "On Artificial Intelligence" (signed November 2025)
The law defines AI systems and their classification by level of autonomy and risk, sets principles (legality, fairness, transparency, safety, human control), assigns duties to owners and operators of AI systems including risk management, labelling of AI-generated content and protection of personal data, prohibits certain manipulative and social-scoring uses, provides for a national AI platform and state support measures, and allocates state regulation to the authorised body.
Law No. 132/2025 on artificial intelligence
Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale
Italy's framework AI law, published in the Official Gazette on 25 September 2025 and in force from 10 October 2025. It states principles (human-centric, transparent, safe AI; protection of fundamental rights), sets sector rules for healthcare (AI as support, not replacement, for clinical decisions), employment (information to workers, an AI-at-work observatory), intellectual professions (client disclosure), justice (judge decides; AI only for organisational support) and public administration, requires parental consent for children under 14, designates AgID and ACN as national authorities, delegates the government to align national law with the EU AI Act, and creates a criminal offence for unlawful dissemination of AI-generated or manipulated content with aggravating circumstances for other crimes committed with AI.
NYC Local Law 144 (automated employment decision tools)
New York City Local Law 144 of 2021 on Automated Employment Decision Tools (AEDT) and DCWP implementing rules
Employers and employment agencies may not use an automated employment decision tool to screen candidates or employees for hiring or promotion in New York City unless the tool has had an independent bias audit within the past year, a summary of the audit results is published, and candidates receive at least ten business days' notice of the tool's use, the job qualifications assessed, and how to request an alternative process or accommodation. The bias audit calculates selection and scoring impact ratios by sex, race/ethnicity and intersectional categories. Enforcement began 5 July 2023.
Tools
- Compare jurisdictions
Side-by-side status, binding rules, high-risk and generative AI, oversight and dates.
- Applicability check
Educational screening of which policies and obligations may be relevant. Not legal advice.
- Change log
Dated, source-backed updates with practical impact, filters and RSS.
- Open data and API
CC BY 4.0 dataset, JSON Schema, read-only API and citation guidance.
Open source, open data
Records live as reviewable YAML in a public repository. Propose corrections and sources through pull requests, or use the contribution form.
View on GitHubExport obligations to a workflow tool with Certifyi, a separate compliance execution platform. AIPolicyTracker itself stays open and independent.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.