AI risk domain 5

Human-Computer Interaction

Subdomains

5.1 Overreliance and unsafe use
Users anthropomorphizing, trusting, or relying on AI systems, leading to emotional or material dependence and inappropriate relationships with or expectations of AI systems. Trust can be exploited by malicious actors (e.g., to harvest personal information or enable manipulation), or result in harm from inappropriate use of AI in critical situations (e.g., medical emergency). Overreliance on AI systems can compromise autonomy and weaken social ties.
Profile and drilldown60 risk entries38 incidents
5.2 Loss of human agency and autonomy
Humans delegating key decisions to AI systems, or AI systems making decisions that diminish human control and autonomy, potentially leading to humans feeling disempowered, losing the ability to shape a fulfilling life trajectory or becoming cognitively enfeebled.
Profile and drilldown47 risk entries4 incidents

Explore this domain in the MIT AI Risk Navigator

Recent incidents in this domain

  1. Loss of human agency and autonomy
  2. Overreliance and unsafe use
  3. Overreliance and unsafe use
  4. Overreliance and unsafe use
  5. Overreliance and unsafe use
  6. Overreliance and unsafe use
  7. Overreliance and unsafe use
  8. Overreliance and unsafe use

Policies addressing related use cases

Editorial mapping by AIPolicyTracker

Use cases: customer servicegenerative ai

Ireland National strategy Adopted

AI – Here for Good (National AI Strategy)

AI – Here for Good: National Artificial Intelligence Strategy for Ireland (2021, refreshed 2024)

Ireland's national AI strategy, first published in July 2021 and refreshed in November 2024 to reflect the EU AI Act and generative AI, is organised around building public trust, leveraging AI for economic and societal benefit, and enablers such as data, infrastructure, skills and governance. The refresh sets out Ireland's AI Act implementation model, public-sector AI guidelines and an AI advisory council.

Adopted 8 Jul 2021 Source-linked · checked 11 Sep 2026 Official source
Spain Bill Proposed Binding

Draft law on good use and governance of AI

Anteproyecto de Ley para el buen uso y la gobernanza de la inteligencia artificial

The draft implements the EU AI Act in Spain: it allocates supervision among AESIA, the data-protection authority, the electoral board, the financial and audiovisual regulators, sets the national penalty scale (up to EUR 35 million or 7% of turnover for prohibited practices), treats failure to label AI-generated content as a serious infringement and provides for the national sandbox to continue.

Source-linked · checked 11 Sep 2026 Official source
United Kingdom Policy Guidance

UK AI regulation framework

A pro-innovation approach to AI regulation (white paper and government response)

The UK white paper sets out a principles-based, context-specific approach to regulating AI. Instead of a single AI law, it asks existing regulators to interpret and apply five cross-cutting principles within their remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Central government provides coordination, monitoring and guidance.

Adopted 29 Mar 2023 Source-linked Official source
Hong Kong SAR Guidance Guidance

PCPD Model Personal Data Protection Framework for AI (2024)

Artificial Intelligence: Model Personal Data Protection Framework

Published 11 June 2024, the framework gives organisations that procure, implement and use AI systems involving personal data recommendations in four areas: AI strategy and governance (an AI governance committee, procurement due diligence), risk assessment and human oversight (a risk-based approach with levels of human involvement), customisation and implementation of AI models (data preparation, testing, security), and communication and engagement with stakeholders (transparency, explainability, opt-out, feedback). It builds on the 2021 Guidance on the Ethical Development and Use of AI.

Adopted 11 Jun 2024 Source-linked · checked 11 Sep 2026 Official source

ASEAN Guide on AI Governance and Ethics (2024)

ASEAN Guide on AI Governance and Ethics

Endorsed at the 4th ASEAN Digital Ministers' Meeting in February 2024, the guide sets seven guiding principles (transparency and explainability, fairness and equity, security and safety, human-centricity, privacy and data governance, accountability and integrity, robustness and reliability) and a four-part governance framework (internal governance structures, human involvement in decision-making, operations management, stakeholder interaction), with national and regional recommendations including an ASEAN working group on AI governance.

Adopted 2 Feb 2024 Source-linked · checked 11 Sep 2026 Official source
California (United States) Act / statute In force Binding

California SB 53

California SB 53: Transparency in Frontier Artificial Intelligence Act

SB 53 requires "large frontier developers" (developers of the most compute-intensive models above statutory thresholds) to publish a frontier AI framework describing how they assess and mitigate catastrophic risks, publish transparency reports when deploying new frontier models, report critical safety incidents to the California Office of Emergency Services, and protect employees who report safety concerns. It also directs creation of a public computing cluster ("CalCompute").

Applies from 1 Jan 2026 Source-linked Official source
France Guidance Guidance

CNIL AI how-to sheets

CNIL recommendations on the development of AI systems and the GDPR (AI how-to sheets)

A series of practical guidance sheets, first published in 2024 and extended since, explaining how organisations can develop and train AI systems in compliance with the GDPR: defining a purpose, choosing a legal basis (including legitimate interest for web-scraped training data), data minimisation, retention, data-protection impact assessments, informing people and honouring their rights, and security of training datasets and models.

Adopted 8 Apr 2024 Source-linked · checked 11 Sep 2026 Official source
India Act / statute Partially applicable Binding

India DPDP Act

Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025

The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.

Adopted 11 Aug 2023 Source-linked Official source
Tennessee (United States) Act / statute In force Binding

Tennessee ELVIS Act

Ensuring Likeness, Voice, and Image Security (ELVIS) Act of 2024 (Tennessee Public Chapter 588)

Signed 21 March 2024 and effective 1 July 2024, the ELVIS Act updates Tennessee's Personal Rights Protection Act to add voice to the protected attributes of name, photograph and likeness, prohibits publishing or making available an individual's voice or likeness without authorisation, and creates liability for distributing or making available an algorithm, software or tool whose primary purpose is producing an individual's voice or likeness without authorisation. It provides civil actions for individuals and licensees and criminal penalties.

In force 1 Jul 2024 Source-linked · checked 11 Sep 2026 Official source
Germany Bill Proposed Binding

AI Act implementation act (KI-MIG, draft)

Entwurf eines Gesetzes zur Durchführung der KI-Verordnung (KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG)

The draft implementation act designates the Bundesnetzagentur as the central market-surveillance authority and single point of contact under the EU AI Act, keeps sector regulators (financial supervision, data protection for law-enforcement uses) competent in their fields, sets the national penalty framework within the Regulation's ranges and creates a national AI regulatory sandbox and an AI service desk for companies.

Source-linked · checked 11 Sep 2026 Official source
United States Executive order In force Binding

EO 14179

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179, signed 23 January 2025, sets US federal policy to sustain and enhance American AI dominance, directs the development of an AI Action Plan within 180 days, and orders agencies to review and revise or rescind actions taken under the revoked Executive Order 14110 that are inconsistent with the new policy. It also called for revision of the OMB memoranda governing federal agency use and procurement of AI, which OMB replaced in April 2025 with M-25-21 and M-25-22.

In force 23 Jan 2025 Source-linked Official source

Expanded ASEAN Guide on AI Governance and Ethics – Generative AI (2025)

Expanded ASEAN Guide on AI Governance and Ethics – Generative AI

Endorsed in January 2025, the expanded guide addresses risks specific to generative AI (hallucination, deepfakes and misinformation, intellectual property, privacy, security, bias, embedded values) and proposes governance dimensions covering accountability, data, development and deployment, incident reporting, testing and assurance, security, content provenance, safety research and public-interest use, with policy recommendations for member states.

Adopted 17 Jan 2025 Source-linked · checked 11 Sep 2026 Official source
United Arab Emirates Act / statute In force Binding

UAE PDPL

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)

The UAE Personal Data Protection Law is the federal data-protection law applying outside the DIFC and ADGM free zones. It sets principles for lawful processing, consent and its exceptions, data-subject rights (including the right to object to automated decision-making without human intervention), controller and processor duties, security and breach notification to the UAE Data Office, cross-border transfer rules, and data protection impact assessments for high-risk processing including new technologies.

In force 2 Jan 2022 Source-linked Official source
International organisations (OECD, UNESCO, UN, G7, ISO) Code of practice Voluntary standard

G7 Hiroshima AI Process code of conduct

Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems (G7, 30 October 2023)

Eleven voluntary actions for organisations developing the most advanced AI systems, including foundation and generative models: risk identification and mitigation across the lifecycle, post-deployment vulnerability and incident monitoring, public transparency reports, responsible information sharing, security controls, content authentication such as watermarking, research on societal risks, priority to global challenges, technical standards, and data-input and personal-data safeguards. It sits alongside the Hiroshima Process guiding principles and, from 2025, an OECD-run voluntary reporting framework.

Adopted 30 Oct 2023 Source-linked · checked 11 Sep 2026 Official source
Hong Kong SAR Guidance Guidance

Generative AI Technical and Application Guideline (2025)

Hong Kong Generative Artificial Intelligence Technical and Application Guideline

Published in April 2025, the guideline covers the technical characteristics and risks of generative AI, governance principles (safety, transparency, accountability, data protection, fairness) and practical application guidance for developers, service providers and users across the AI lifecycle, and is intended as a reference for industry and government.

Adopted 15 Apr 2025 Source-linked · checked 11 Sep 2026 Official source
United Kingdom Guidance Guidance

ICO AI guidance

ICO Guidance on AI and data protection

The ICO's guidance explains how UK GDPR and the Data Protection Act 2018 apply when organisations develop or use AI that processes personal data. It covers accountability and governance, lawfulness and fairness, transparency, data minimisation, security, individual rights, and automated decision-making. The guidance is not itself law, but it reflects how the regulator interprets binding obligations and is the reference point in ICO enforcement.

Source-linked Official source
India Guidance Guidance

India AI Governance Guidelines

India AI Governance Guidelines (MeitY, 2025)

The India AI Governance Guidelines set out a principle-based, pro-innovation approach to governing AI in India. They articulate guiding principles (such as trust, people-first design, fairness, accountability, safety and transparency), propose an institutional framework including an AI governance group and an AI Safety Institute role, favour applying existing laws over a new AI statute, and recommend voluntary commitments, techno-legal measures, risk-based oversight and incident reporting for AI systems.

Adopted 5 Nov 2025 Source-linked Official source
Kazakhstan Act / statute Adopted Binding

Law on Artificial Intelligence (2025)

Law of the Republic of Kazakhstan "On Artificial Intelligence" (signed November 2025)

The law defines AI systems and their classification by level of autonomy and risk, sets principles (legality, fairness, transparency, safety, human control), assigns duties to owners and operators of AI systems including risk management, labelling of AI-generated content and protection of personal data, prohibits certain manipulative and social-scoring uses, provides for a national AI platform and state support measures, and allocates state regulation to the authorised body.

Adopted 17 Nov 2025 Source-linked · checked 11 Sep 2026 Official source
Italy Act / statute In force Binding

Law No. 132/2025 on artificial intelligence

Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Italy's framework AI law, published in the Official Gazette on 25 September 2025 and in force from 10 October 2025. It states principles (human-centric, transparent, safe AI; protection of fundamental rights), sets sector rules for healthcare (AI as support, not replacement, for clinical decisions), employment (information to workers, an AI-at-work observatory), intellectual professions (client disclosure), justice (judge decides; AI only for organisational support) and public administration, requires parental consent for children under 14, designates AgID and ACN as national authorities, delegates the government to align national law with the EU AI Act, and creates a criminal offence for unlawful dissemination of AI-generated or manipulated content with aggravating circumstances for other crimes committed with AI.

In force 10 Oct 2025 Source-linked · checked 11 Sep 2026 Official source
El Salvador Act / statute In force Binding

Law for the Promotion of AI and Emerging Technologies

Ley para el Fomento de la Inteligencia Artificial y Tecnologías Emergentes (Decreto Legislativo, febrero de 2025)

Approved by the Legislative Assembly in February 2025, the law promotes AI development and investment, creates the National Agency for Artificial Intelligence (ANIA) as regulator, defines rights and principles (human oversight, transparency, non-discrimination, data protection), sets registration and sandbox mechanisms and limits liability of developers who act in good faith under the law, alongside data-processing rules for AI training.

Adopted 25 Feb 2025 Source-linked · checked 11 Sep 2026 Official source
Singapore Framework Voluntary standard

Singapore Model AI Governance Framework

Model AI Governance Framework (Second Edition) and Model AI Governance Framework for Generative AI

Singapore's Model AI Governance Framework is a voluntary, sector-agnostic guide for organisations deploying AI. The second edition (January 2020) covers four areas: internal governance structures and measures, determining the level of human involvement in AI-augmented decision-making, operations management (data, model development, monitoring), and stakeholder interaction and communication. The May 2024 Model AI Governance Framework for Generative AI extends it with nine dimensions including accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for the public good.

Adopted 21 Jan 2020 Source-linked Official source
Nepal Policy Adopted

Nepal National AI Policy

National Artificial Intelligence Policy, 2082 (2025) — Nepal

Nepal's National AI Policy sets the government's direction for developing and using artificial intelligence. Based on the published summaries, it aims to build AI infrastructure and skills, promote ethical and responsible AI, strengthen data governance, establish institutional arrangements for AI oversight, and prepare legal and regulatory measures. It is a policy framework, not a law, and does not itself create enforceable obligations on private organisations.

Adopted 1 Aug 2025 Source-linked Official source
New York (United States) Act / statute Adopted Binding

New York RAISE Act (frontier model safety)

New York Responsible AI Safety and Education (RAISE) Act (S.6953-B / A.6453-B, signed December 2025)

The RAISE Act requires large developers of frontier AI models (defined by training compute and revenue thresholds) to publish and follow a safety and security protocol, report critical safety incidents to the state within a set period, not deploy models that create unreasonable risk of critical harm, and submit to Attorney General enforcement with civil penalties; the chapter amendments create a state oversight office and align definitions with California's Transparency in Frontier AI Act.

Applies from 1 Jan 2027 Source-linked · checked 11 Sep 2026 Official source
New Zealand National strategy Adopted

New Zealand AI Strategy (2025)

New Zealand's Strategy for Artificial Intelligence: Investing with Confidence

Published in July 2025, the strategy aims to lift AI adoption by businesses, especially small and medium enterprises, and the public sector, by reducing barriers, providing clear guidance (Responsible AI Guidance for Businesses), building skills and pursuing a light-touch, proportionate regulatory approach that relies on existing law and international alignment (OECD principles). It rules out a standalone AI act for now.

Adopted 8 Jul 2025 Source-linked · checked 11 Sep 2026 Official source

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.