Ireland
·
National strategy
Adopted
AI – Here for Good: National Artificial Intelligence Strategy for Ireland (2021, refreshed 2024)
Ireland's national AI strategy, first published in July 2021 and refreshed in November 2024 to reflect the EU AI Act and generative AI, is organised around building public trust, leveraging AI for economic and societal benefit, and enablers such as data, infrastructure, skills and governance. The refresh sets out Ireland's AI Act implementation model, public-sector AI guidelines and an AI advisory council.
Adopted 8 Jul 2021
Source-linked · checked 11 Sep 2026
Official source
Spain
·
Bill
Proposed
Binding
Anteproyecto de Ley para el buen uso y la gobernanza de la inteligencia artificial
The draft implements the EU AI Act in Spain: it allocates supervision among AESIA, the data-protection authority, the electoral board, the financial and audiovisual regulators, sets the national penalty scale (up to EUR 35 million or 7% of turnover for prohibited practices), treats failure to label AI-generated content as a serious infringement and provides for the national sandbox to continue.
Source-linked · checked 11 Sep 2026
Official source
United Kingdom
·
Policy
Guidance
A pro-innovation approach to AI regulation (white paper and government response)
The UK white paper sets out a principles-based, context-specific approach to regulating AI. Instead of a single AI law, it asks existing regulators to interpret and apply five cross-cutting principles within their remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Central government provides coordination, monitoring and guidance.
Adopted 29 Mar 2023
Source-linked
Official source
Hong Kong SAR
·
Guidance
Guidance
Artificial Intelligence: Model Personal Data Protection Framework
Published 11 June 2024, the framework gives organisations that procure, implement and use AI systems involving personal data recommendations in four areas: AI strategy and governance (an AI governance committee, procurement due diligence), risk assessment and human oversight (a risk-based approach with levels of human involvement), customisation and implementation of AI models (data preparation, testing, security), and communication and engagement with stakeholders (transparency, explainability, opt-out, feedback). It builds on the 2021 Guidance on the Ethical Development and Use of AI.
Adopted 11 Jun 2024
Source-linked · checked 11 Sep 2026
Official source
California (United States)
·
Act / statute
In force
Binding
California SB 53: Transparency in Frontier Artificial Intelligence Act
SB 53 requires "large frontier developers" (developers of the most compute-intensive models above statutory thresholds) to publish a frontier AI framework describing how they assess and mitigate catastrophic risks, publish transparency reports when deploying new frontier models, report critical safety incidents to the California Office of Emergency Services, and protect employees who report safety concerns. It also directs creation of a public computing cluster ("CalCompute").
Applies from 1 Jan 2026
Source-linked
Official source
France
·
Guidance
Guidance
CNIL recommendations on the development of AI systems and the GDPR (AI how-to sheets)
A series of practical guidance sheets, first published in 2024 and extended since, explaining how organisations can develop and train AI systems in compliance with the GDPR: defining a purpose, choosing a legal basis (including legitimate interest for web-scraped training data), data minimisation, retention, data-protection impact assessments, informing people and honouring their rights, and security of training datasets and models.
Adopted 8 Apr 2024
Source-linked · checked 11 Sep 2026
Official source
India
·
Act / statute
Partially applicable
Binding
Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.
Adopted 11 Aug 2023
Source-linked
Official source
Tennessee (United States)
·
Act / statute
In force
Binding
Ensuring Likeness, Voice, and Image Security (ELVIS) Act of 2024 (Tennessee Public Chapter 588)
Signed 21 March 2024 and effective 1 July 2024, the ELVIS Act updates Tennessee's Personal Rights Protection Act to add voice to the protected attributes of name, photograph and likeness, prohibits publishing or making available an individual's voice or likeness without authorisation, and creates liability for distributing or making available an algorithm, software or tool whose primary purpose is producing an individual's voice or likeness without authorisation. It provides civil actions for individuals and licensees and criminal penalties.
In force 1 Jul 2024
Source-linked · checked 11 Sep 2026
Official source
Germany
·
Bill
Proposed
Binding
Entwurf eines Gesetzes zur Durchführung der KI-Verordnung (KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG)
The draft implementation act designates the Bundesnetzagentur as the central market-surveillance authority and single point of contact under the EU AI Act, keeps sector regulators (financial supervision, data protection for law-enforcement uses) competent in their fields, sets the national penalty framework within the Regulation's ranges and creates a national AI regulatory sandbox and an AI service desk for companies.
Source-linked · checked 11 Sep 2026
Official source
United States
·
Executive order
In force
Binding
Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence
Executive Order 14179, signed 23 January 2025, sets US federal policy to sustain and enhance American AI dominance, directs the development of an AI Action Plan within 180 days, and orders agencies to review and revise or rescind actions taken under the revoked Executive Order 14110 that are inconsistent with the new policy. It also called for revision of the OMB memoranda governing federal agency use and procurement of AI, which OMB replaced in April 2025 with M-25-21 and M-25-22.
In force 23 Jan 2025
Source-linked
Official source
Expanded ASEAN Guide on AI Governance and Ethics – Generative AI
Endorsed in January 2025, the expanded guide addresses risks specific to generative AI (hallucination, deepfakes and misinformation, intellectual property, privacy, security, bias, embedded values) and proposes governance dimensions covering accountability, data, development and deployment, incident reporting, testing and assurance, security, content provenance, safety research and public-interest use, with policy recommendations for member states.
Adopted 17 Jan 2025
Source-linked · checked 11 Sep 2026
Official source
United Arab Emirates
·
Act / statute
In force
Binding
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
The UAE Personal Data Protection Law is the federal data-protection law applying outside the DIFC and ADGM free zones. It sets principles for lawful processing, consent and its exceptions, data-subject rights (including the right to object to automated decision-making without human intervention), controller and processor duties, security and breach notification to the UAE Data Office, cross-border transfer rules, and data protection impact assessments for high-risk processing including new technologies.
In force 2 Jan 2022
Source-linked
Official source
Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems (G7, 30 October 2023)
Eleven voluntary actions for organisations developing the most advanced AI systems, including foundation and generative models: risk identification and mitigation across the lifecycle, post-deployment vulnerability and incident monitoring, public transparency reports, responsible information sharing, security controls, content authentication such as watermarking, research on societal risks, priority to global challenges, technical standards, and data-input and personal-data safeguards. It sits alongside the Hiroshima Process guiding principles and, from 2025, an OECD-run voluntary reporting framework.
Adopted 30 Oct 2023
Source-linked · checked 11 Sep 2026
Official source
Hong Kong SAR
·
Guidance
Guidance
Hong Kong Generative Artificial Intelligence Technical and Application Guideline
Published in April 2025, the guideline covers the technical characteristics and risks of generative AI, governance principles (safety, transparency, accountability, data protection, fairness) and practical application guidance for developers, service providers and users across the AI lifecycle, and is intended as a reference for industry and government.
Adopted 15 Apr 2025
Source-linked · checked 11 Sep 2026
Official source
United Kingdom
·
Guidance
Guidance
ICO Guidance on AI and data protection
The ICO's guidance explains how UK GDPR and the Data Protection Act 2018 apply when organisations develop or use AI that processes personal data. It covers accountability and governance, lawfulness and fairness, transparency, data minimisation, security, individual rights, and automated decision-making. The guidance is not itself law, but it reflects how the regulator interprets binding obligations and is the reference point in ICO enforcement.
India
·
Guidance
Guidance
India AI Governance Guidelines (MeitY, 2025)
The India AI Governance Guidelines set out a principle-based, pro-innovation approach to governing AI in India. They articulate guiding principles (such as trust, people-first design, fairness, accountability, safety and transparency), propose an institutional framework including an AI governance group and an AI Safety Institute role, favour applying existing laws over a new AI statute, and recommend voluntary commitments, techno-legal measures, risk-based oversight and incident reporting for AI systems.
Adopted 5 Nov 2025
Source-linked
Official source
Kazakhstan
·
Act / statute
Adopted
Binding
Law of the Republic of Kazakhstan "On Artificial Intelligence" (signed November 2025)
The law defines AI systems and their classification by level of autonomy and risk, sets principles (legality, fairness, transparency, safety, human control), assigns duties to owners and operators of AI systems including risk management, labelling of AI-generated content and protection of personal data, prohibits certain manipulative and social-scoring uses, provides for a national AI platform and state support measures, and allocates state regulation to the authorised body.
Adopted 17 Nov 2025
Source-linked · checked 11 Sep 2026
Official source
Italy
·
Act / statute
In force
Binding
Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale
Italy's framework AI law, published in the Official Gazette on 25 September 2025 and in force from 10 October 2025. It states principles (human-centric, transparent, safe AI; protection of fundamental rights), sets sector rules for healthcare (AI as support, not replacement, for clinical decisions), employment (information to workers, an AI-at-work observatory), intellectual professions (client disclosure), justice (judge decides; AI only for organisational support) and public administration, requires parental consent for children under 14, designates AgID and ACN as national authorities, delegates the government to align national law with the EU AI Act, and creates a criminal offence for unlawful dissemination of AI-generated or manipulated content with aggravating circumstances for other crimes committed with AI.
In force 10 Oct 2025
Source-linked · checked 11 Sep 2026
Official source
El Salvador
·
Act / statute
In force
Binding
Ley para el Fomento de la Inteligencia Artificial y Tecnologías Emergentes (Decreto Legislativo, febrero de 2025)
Approved by the Legislative Assembly in February 2025, the law promotes AI development and investment, creates the National Agency for Artificial Intelligence (ANIA) as regulator, defines rights and principles (human oversight, transparency, non-discrimination, data protection), sets registration and sandbox mechanisms and limits liability of developers who act in good faith under the law, alongside data-processing rules for AI training.
Adopted 25 Feb 2025
Source-linked · checked 11 Sep 2026
Official source
Singapore
·
Framework
Voluntary standard
Model AI Governance Framework (Second Edition) and Model AI Governance Framework for Generative AI
Singapore's Model AI Governance Framework is a voluntary, sector-agnostic guide for organisations deploying AI. The second edition (January 2020) covers four areas: internal governance structures and measures, determining the level of human involvement in AI-augmented decision-making, operations management (data, model development, monitoring), and stakeholder interaction and communication. The May 2024 Model AI Governance Framework for Generative AI extends it with nine dimensions including accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for the public good.
Adopted 21 Jan 2020
Source-linked
Official source
National Artificial Intelligence Policy, 2082 (2025) — Nepal
Nepal's National AI Policy sets the government's direction for developing and using artificial intelligence. Based on the published summaries, it aims to build AI infrastructure and skills, promote ethical and responsible AI, strengthen data governance, establish institutional arrangements for AI oversight, and prepare legal and regulatory measures. It is a policy framework, not a law, and does not itself create enforceable obligations on private organisations.
Adopted 1 Aug 2025
Source-linked
Official source
New York (United States)
·
Act / statute
Adopted
Binding
New York Responsible AI Safety and Education (RAISE) Act (S.6953-B / A.6453-B, signed December 2025)
The RAISE Act requires large developers of frontier AI models (defined by training compute and revenue thresholds) to publish and follow a safety and security protocol, report critical safety incidents to the state within a set period, not deploy models that create unreasonable risk of critical harm, and submit to Attorney General enforcement with civil penalties; the chapter amendments create a state oversight office and align definitions with California's Transparency in Frontier AI Act.
Applies from 1 Jan 2027
Source-linked · checked 11 Sep 2026
Official source
New Zealand
·
National strategy
Adopted
New Zealand's Strategy for Artificial Intelligence: Investing with Confidence
Published in July 2025, the strategy aims to lift AI adoption by businesses, especially small and medium enterprises, and the public sector, by reducing barriers, providing clear guidance (Responsible AI Guidance for Businesses), building skills and pursuing a light-touch, proportionate regulatory approach that relies on existing law and international alignment (OECD principles). It rules out a standalone AI act for now.
Adopted 8 Jul 2025
Source-linked · checked 11 Sep 2026
Official source
United States
·
Framework
Voluntary standard
NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile
The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.
Adopted 26 Jan 2023
Source-linked
Official source