About

AI policy you can trace back to the source

AIPolicyTracker is an open reference for artificial-intelligence laws, strategies, guidance and the obligations they create. It is built for the people who have to act on policy rather than only read about it: compliance and legal teams, product owners, public-sector buyers, researchers and journalists.

Why it exists

AI regulation is now global, but the tools for following it are uneven. Large jurisdictions are covered by many trackers; South Asia, ASEAN, Africa, the Gulf and Latin America are often reduced to a paragraph. Summaries circulate without links to the instrument they describe, and readers cannot tell whether a date was checked last week or two years ago.

This project takes a narrower position. Every record cites an official source and states when it was last checked. Regulatory status uses a small, explicit vocabulary. Obligations are broken out so they can be mapped to controls and evidence. The whole dataset is open, versioned and reviewable in public.

How to use it

By jurisdiction
Start from a country or bloc: regulatory status, binding rules versus guidance, regulators and official sources.
By instrument
Filter acts, regulations, strategies and guidance by status, actor, sector and use case, then open the record for dates, scope and obligations.
By obligation
Read requirements as practical tasks with the article they come from, who they bind and what evidence they imply.
By risk
Move from a category of harm to the incidents recorded for it and the policies that respond, using the MIT AI Risk Repository taxonomy as a shared vocabulary.
By date
Follow the change log and RSS feed for dated, source-linked developments and upcoming application dates.
As data
Download the dataset, call the read-only API or point an AI assistant at llms.txt; everything carries its source and licence.

How records are made

  1. A record is created from an official document (legislation, gazette, regulator or ministry publication) with its URL, publisher and access date.
  2. Status, dates, scope and obligations are written in plain language with article references; no legal commentary is copied.
  3. A reviewer opens the source, confirms each field and sets the verification date. Until then the record is shown as source-linked, not verified.
  4. Changes are logged with what changed and its practical impact, and the dataset is versioned in the open repository.

Full methodology, status definitions and source tiers

Datasets and research we build on

The project stands on open work by others. Each is credited where it is used, and the licences below govern reuse of that material.

  1. Slattery, P., Saeri, A. K., Grundy, E. A. C., Graham, J., Noetel, M., Uuk, R., Dao, J., Pour, S., Casper, S., & Thompson, N. (2025). The AI Risk Repository: A comprehensive meta-review, database, and taxonomy of risks from artificial intelligence. MIT AI Risk Initiative, arXiv:2408.12622 · CC BY 4.0
  2. McGregor, S. (2021). Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. Proceedings of the AAAI Conference on Artificial Intelligence (IAAI-21); Responsible AI Collaborative · CC BY-SA 4.0
  3. Weidinger, L. et al. (2021). Ethical and social risks of harm from Language Models. DeepMind, arXiv:2112.04359
  4. National Institute of Standards and Technology (2023). AI Risk Management Framework (AI RMF 1.0). NIST · Public domain (US Government work)
  5. European Parliament and Council (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union · EU reuse policy (Decision 2011/833/EU)

Questions people ask

What is AIPolicyTracker?
An open, source-backed reference for AI laws, strategies, guidance and their obligations across jurisdictions, with a bias towards markets that global trackers cover thinly. Every record links to its official source and shows its verification state.
Is the data free to reuse?
Yes. The policy dataset is published under CC BY 4.0 and the code under Apache-2.0. Third-party datasets shown on the site (MIT AI Risk Repository, AI Incident Database) keep their own licences, which are stated on each page.
Is this legal advice?
No. The site is informational. Confirm every date and obligation in the linked official source and consult qualified counsel before acting.
How are records verified?
Records are created from official sources with a source URL and access date, then reviewed by a human who opens the source, confirms the fields and sets the verification date. Unverified records are labelled as source-linked rather than verified.
Who maintains it?
AIPolicyTracker is founded and maintained by Bhaskar Bhatt and built by Dignep Group Pvt. Ltd. Contributions are welcome through GitHub.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.