AI risk domain 1

Discrimination & Toxicity

Subdomains

1.1 Unfair discrimination and misrepresentation
Unequal treatment of individuals or groups by AI, often based on race, gender, or other sensitive characteristics, resulting in unfair outcomes and representation of those groups.
Profile and drilldown83 risk entries118 incidents
1.2 Exposure to toxic content
AI exposing users to harmful, abusive, unsafe or inappropriate content. May involve AI creating, describing, providing advice, or encouraging action. Examples of toxic content include hate-speech, violence, extremism, illegal acts, child sexual abuse material, as well as content that violates community norms such as profanity, inflammatory political speech, or pornography.
Profile and drilldown116 risk entries91 incidents
1.3 Unequal performance across groups
Accuracy and effectiveness of AI decisions and actions is dependent on group membership, where decisions in AI system design and biased training data lead to unequal outcomes, reduced benefits, increased effort, and alienation of users.
Profile and drilldown17 risk entries34 incidents

Explore this domain in the MIT AI Risk Navigator

Recent incidents in this domain

  1. Exposure to toxic content
  2. Exposure to toxic content
  3. Unequal performance across groups
  4. Exposure to toxic content
  5. Exposure to toxic content
  6. Exposure to toxic content
  7. Unequal performance across groups
  8. Exposure to toxic content

Policies addressing related use cases

Editorial mapping by AIPolicyTracker

Use cases: hiring and hrfinance and crediteducation

United Kingdom Policy Guidance

UK AI regulation framework

A pro-innovation approach to AI regulation (white paper and government response)

The UK white paper sets out a principles-based, context-specific approach to regulating AI. Instead of a single AI law, it asks existing regulators to interpret and apply five cross-cutting principles within their remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Central government provides coordination, monitoring and guidance.

Adopted 29 Mar 2023 Source-linked Official source
Colorado (United States) Act / statute Adopted Binding

Colorado AI Act

Colorado Senate Bill 24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act)

The Colorado AI Act requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. High-risk systems are those that make, or are a substantial factor in making, consequential decisions about education, employment, financial or lending services, essential government services, healthcare, housing, insurance or legal services. Deployers must run risk-management programmes and impact assessments, notify consumers, and explain adverse decisions; developers must document systems and disclose known risks.

Applies from 30 Jun 2026 Source-linked Official source
India Act / statute Partially applicable Binding

India DPDP Act

Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025

The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.

Adopted 11 Aug 2023 Source-linked Official source
United Arab Emirates Act / statute In force Binding

UAE PDPL

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)

The UAE Personal Data Protection Law is the federal data-protection law applying outside the DIFC and ADGM free zones. It sets principles for lawful processing, consent and its exceptions, data-subject rights (including the right to object to automated decision-making without human intervention), controller and processor duties, security and breach notification to the UAE Data Office, cross-border transfer rules, and data protection impact assessments for high-risk processing including new technologies.

In force 2 Jan 2022 Source-linked Official source
United Kingdom Guidance Guidance

ICO AI guidance

ICO Guidance on AI and data protection

The ICO's guidance explains how UK GDPR and the Data Protection Act 2018 apply when organisations develop or use AI that processes personal data. It covers accountability and governance, lawfulness and fairness, transparency, data minimisation, security, individual rights, and automated decision-making. The guidance is not itself law, but it reflects how the regulator interprets binding obligations and is the reference point in ICO enforcement.

Source-linked Official source
Illinois (United States) Act / statute In force Binding

Illinois AI Video Interview Act

Illinois Artificial Intelligence Video Interview Act (820 ILCS 42)

In force since 1 January 2020, the Act requires employers that use AI to analyse video interviews of applicants for Illinois-based positions to notify applicants, explain how the AI works and what characteristics it evaluates, obtain consent, limit sharing of videos, and delete videos on request within 30 days; a 2022 amendment requires employers relying solely on AI to decide who gets an in-person interview to report demographic data annually.

In force 1 Jan 2020 Source-linked · checked 11 Sep 2026 Official source
Illinois (United States) Act / statute In force Binding

Illinois HB 3773 (AI in employment, Human Rights Act amendment)

Illinois Public Act 103-0804 (HB 3773): Artificial intelligence in employment decisions – amendment to the Illinois Human Rights Act

Signed 9 August 2024 and effective 1 January 2026, the Act makes it a civil-rights violation for an employer to use artificial intelligence in recruitment, hiring, promotion, discipline, discharge or other terms of employment in a way that subjects employees to discrimination on the basis of protected classes, or to use zip codes as a proxy for protected classes. Employers must notify employees when AI is used for such decisions; the Department of Human Rights is to adopt rules on notice.

Applies from 1 Jan 2026 Source-linked · checked 11 Sep 2026 Official source
Nepal Act / statute In force Binding

Nepal Privacy Act 2075

Individual Privacy Act, 2075 (2018) — Nepal

The Individual Privacy Act 2075 gives effect to the constitutional right to privacy in Nepal. It regulates the collection, storage, processing, use and disclosure of personal information by public bodies and private entities, requires consent for collection and use of personal data subject to exceptions, restricts sensitive data, and provides remedies and penalties. It is the main binding law affecting AI systems that process personal data in Nepal. The Individual Privacy Regulation 2077 (2020) provides implementing rules.

In force 18 Sep 2018 Source-linked Official source
Italy Act / statute In force Binding

Law No. 132/2025 on artificial intelligence

Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Italy's framework AI law, published in the Official Gazette on 25 September 2025 and in force from 10 October 2025. It states principles (human-centric, transparent, safe AI; protection of fundamental rights), sets sector rules for healthcare (AI as support, not replacement, for clinical decisions), employment (information to workers, an AI-at-work observatory), intellectual professions (client disclosure), justice (judge decides; AI only for organisational support) and public administration, requires parental consent for children under 14, designates AgID and ACN as national authorities, delegates the government to align national law with the EU AI Act, and creates a criminal offence for unlawful dissemination of AI-generated or manipulated content with aggravating circumstances for other crimes committed with AI.

In force 10 Oct 2025 Source-linked · checked 11 Sep 2026 Official source
Singapore Framework Voluntary standard

Singapore Model AI Governance Framework

Model AI Governance Framework (Second Edition) and Model AI Governance Framework for Generative AI

Singapore's Model AI Governance Framework is a voluntary, sector-agnostic guide for organisations deploying AI. The second edition (January 2020) covers four areas: internal governance structures and measures, determining the level of human involvement in AI-augmented decision-making, operations management (data, model development, monitoring), and stakeholder interaction and communication. The May 2024 Model AI Governance Framework for Generative AI extends it with nine dimensions including accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for the public good.

Adopted 21 Jan 2020 Source-linked Official source
New York (United States) Act / statute In force Binding

NYC Local Law 144 (automated employment decision tools)

New York City Local Law 144 of 2021 on Automated Employment Decision Tools (AEDT) and DCWP implementing rules

Employers and employment agencies may not use an automated employment decision tool to screen candidates or employees for hiring or promotion in New York City unless the tool has had an independent bias audit within the past year, a summary of the audit results is published, and candidates receive at least ten business days' notice of the tool's use, the job qualifications assessed, and how to request an alternative process or accommodation. The bias audit calculates selection and scoring impact ratios by sex, race/ethnicity and intersectional categories. Enforcement began 5 July 2023.

Applies from 5 Jul 2023 Source-linked · checked 11 Sep 2026 Official source
United States Framework Voluntary standard

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Adopted 26 Jan 2023 Source-linked Official source
Singapore Guidance Guidance

PDPC AI advisory guidelines

PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems

These advisory guidelines explain how the Personal Data Protection Act applies when organisations use personal data to develop, test and deploy AI systems that make recommendations, predictions or decisions. They clarify the consent obligation and relevant exceptions (business improvement and research), what to include in notifications to individuals, accountability practices such as documenting data provenance and model development, and expectations for service providers building bespoke AI systems.

Adopted 1 Mar 2024 Source-linked Official source
Australia Consultation Under consultation

Australian mandatory guardrails proposal

Proposals paper: introducing mandatory guardrails for AI in high-risk settings (Australia)

The proposals paper sought views on ten mandatory guardrails for developers and deployers of AI in high-risk settings, a principles-based definition of high-risk AI (with general-purpose AI treated as high-risk), and three regulatory options: adapting existing laws, framework legislation, or a new cross-economy AI Act. The guardrails mirror the Voluntary AI Safety Standard, covering accountability, risk management, data governance, testing, human control, transparency, contestability, supply-chain transparency, records, and conformity assessment.

Source-linked Official source
Quebec (Canada) Act / statute In force Binding

Quebec Law 25 (automated decisions and biometrics)

Quebec Law 25 (S.Q. 2021, c. 25): provisions on decisions based exclusively on automated processing and biometric systems

Section 12.1 of the private-sector privacy act (as amended by Law 25, in force 22 September 2023) requires any enterprise that uses personal information to render a decision based exclusively on automated processing to inform the person no later than when the decision is made, and, on request, to tell them what personal information was used, the reasons and principal factors and parameters, and their right to have the information corrected, and to give them an opportunity to submit observations to a person who can review the decision. Biometric identification databases must be declared to the Commission d'accès à l'information 60 days before use, and privacy impact assessments are mandatory for projects involving personal information. Penalties reach CAD 25 million or 4% of worldwide turnover.

Applies from 22 Sep 2023 Source-linked · checked 11 Sep 2026 Official source
European Union Regulation Partially applicable Binding

EU AI Act

Regulation (EU) 2024/1689 — Artificial Intelligence Act

The EU AI Act is a binding regulation that sets rules for developing, placing on the market and using AI systems in the European Union. It bans a small set of practices considered unacceptable, imposes detailed requirements on "high-risk" AI systems used in areas such as employment, education, credit, essential services, law enforcement and safety-critical products, requires transparency for chatbots and synthetic content, and creates separate duties for providers of general-purpose AI models. Obligations apply in phases between 2025 and 2027.

Applies from 2 Aug 2026 Source-linked Official source

UNESCO Recommendation on the Ethics of AI

UNESCO Recommendation on the Ethics of Artificial Intelligence (adopted by the General Conference, 23 November 2021)

The first global normative instrument on AI ethics. It sets values (human rights and dignity, environment and ecosystem flourishing, diversity and inclusiveness, peaceful and just societies) and principles (proportionality and do no harm, safety and security, fairness, sustainability, privacy, human oversight, transparency and explainability, responsibility, awareness and literacy, multi-stakeholder governance), and eleven policy action areas from ethical impact assessment and data policy to gender, education, health and the environment. UNESCO supports implementation with a Readiness Assessment Methodology (RAM) and an Ethical Impact Assessment tool used by dozens of countries.

Adopted 23 Nov 2021 Source-linked · checked 11 Sep 2026 Official source
Australia Standard Voluntary standard

Australian Voluntary AI Safety Standard

Voluntary AI Safety Standard (Australia)

The Voluntary AI Safety Standard gives Australian organisations ten guardrails for developing and deploying AI safely and responsibly: accountability and governance, risk management, data governance and protection, testing and monitoring, human control and intervention, user transparency, contestability, supply-chain transparency, record keeping, and stakeholder engagement. The guardrails were designed to align with the mandatory guardrails proposed for high-risk settings so that early adopters would be prepared if those became law.

Adopted 5 Sep 2024 Source-linked Official source
Ontario (Canada) Act / statute In force Binding

Ontario Working for Workers Four Act (AI disclosure in job postings)

Working for Workers Four Act, 2024 (Bill 149): disclosure of artificial intelligence use in publicly advertised job postings

Amends the Employment Standards Act, 2000 to require employers with 25 or more employees to disclose in every publicly advertised job posting whether artificial intelligence is used to screen, assess or select applicants, alongside new rules on salary ranges and Canadian-experience requirements. The AI disclosure requirement is in force from 1 January 2026.

Applies from 1 Jan 2026 Source-linked · checked 11 Sep 2026 Official source
Greece Act / statute In force Binding

Law 4961/2022 (emerging technologies, AI chapter)

Νόμος 4961/2022: Αναδυόμενες τεχνολογίες πληροφορικής και επικοινωνιών, ενίσχυση της ψηφιακής διακυβέρνησης και άλλες διατάξεις

Law 4961/2022, published in July 2022, contains a chapter on artificial intelligence: public-sector bodies must carry out an algorithmic impact assessment and publish information before deploying AI systems that affect people, keep a register of AI systems, and ensure the Hellenic Data Protection Authority's oversight; medium and large private companies must inform workers about AI systems used in employment decisions and maintain an ethical-use policy. It also regulates IoT, 3D printing, blockchain and unmanned aircraft.

In force 27 Jul 2022 Source-linked · checked 11 Sep 2026 Official source

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.