AIPolicyTracker

By role · General-purpose AI model provider

AI regulation for general-purpose and foundation model providers

Providers of general-purpose AI models face a distinct set of duties: technical documentation for downstream integrators, a copyright policy and training-data summary, and for the most capable models, evaluation, adversarial testing, incident reporting and cybersecurity. These duties sit with the model provider even when the model is used inside someone else's system.

Recorded duties
16
15 legally binding
Jurisdictions
4
Controls
10
that meet these duties
Evidence items
31

Model duties versus system duties

A model is not a system. The model provider documents the model and its training; the system provider who builds on it documents the system. Both chains of documentation have to exist and reference each other, which is why downstream documentation is a control of its own below.

Systemic-risk tiers

Where an instrument defines a higher tier by capability or compute, the duties step up to evaluation, red-teaming, incident reporting and security. The controls for those duties are listed with the risk areas they address, so the evaluation report and the incident record can be planned together.

Which controls meet these duties?

Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.

Controls for this audience
ControlSatisfiesSupportsOwner · frequency
Frontier model safety and security framework
Policy
54Head of AI safety · annual
AI incident management and regulatory reporting
Process
33Incident coordinator · continuous
Technical documentation, model cards and instructions for use
Process
31Product or model owner · at launch and on material change
Contractual allocation of AI duties across the supply chain
Contractual term
20Legal counsel · once per ai system
Synthetic content labelling and provenance marking
Technical measure
20Engineering lead · continuous
Adversarial and red-team testing for generative AI
Technical measure
13AI security or safety lead · at launch and on material change
Accuracy, robustness, fairness and security testing
Technical measure
11Quality or testing lead · at launch and on material change
AI governance policy and accountability structure
Policy
10Executive sponsor for AI · annual
Training-data provenance and copyright register
Process
10Model development lead · at launch and on material change
Model release and change-management gate
Process
02Release manager · at launch and on material change

Which duties are recorded?

Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).

California (United States) 5 duties

European Union 8 duties

Singapore 1 duty

South Korea 2 duties

What evidence would a reviewer expect?

  • AI customer or deployer clause set Contract clause or supplier term
  • AI governance forum minutes Governance meeting record
  • AI incident record Incident record
  • AI incident response playbook Procedure or standard operating process
  • AI policy Policy document
  • AI responsibility map Register entry
  • AI supplier clause set Contract clause or supplier term
  • Adversarial findings tracker Risk register
  • Board or executive approval of the AI policy Approval or sign-off record
  • Content labelling and provenance standard Procedure or standard operating process
  • Contract clause index against the AI register Register entry
  • Copyright and rights-reservation policy Policy document
  • Dangerous-capability evaluation report Evaluation or test report
  • Incident report to an authority Regulatory filing or notification
  • Instructions for use Disclosure or notice
  • Model card or deployer information pack Model documentation
  • Pre-release test report Evaluation or test report
  • Public summary of training content Disclosure or notice
  • Published frontier safety framework Policy document
  • Red-team exercise report Evaluation or test report
  • Red-team rules of engagement and scenario library Procedure or standard operating process
  • Release and change-classification procedure Procedure or standard operating process
  • Release or change approval record Approval or sign-off record
  • Release test sign-off Approval or sign-off record
  • Technical documentation file Technical documentation file
  • Test plan and acceptance criteria Procedure or standard operating process
  • Threshold notification to an authority Regulatory filing or notification
  • Training compute tracking record Register entry
  • Training source register Register entry
  • Visible AI-generated content label Disclosure or notice
  • Watermark and provenance robustness test Evaluation or test report

Latest changes to these instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Are open-weight models exempt?
Partly, in some instruments: openly released models can be relieved of some documentation duties but not of copyright or, where it applies, systemic-risk duties. Check the exemption clause cited on the duty page.
Which evidence matters most?
The model documentation for downstream users, the training-data summary and copyright policy, and for higher tiers the evaluation and adversarial-testing reports and the incident log.