AIPolicyTracker

By use case · Generative AI and foundation models

Generative AI and foundation models: the rules that apply

Generative AI attracts three families of duty: transparency (tell people they are interacting with AI, label synthetic content), model governance (document the model, publish a training-data summary, respect copyright) and safety (evaluate, red-team, report incidents, secure the system). Several jurisdictions have rules specific to synthetic media even where they have no general AI law.

Recorded duties
40
29 legally binding
Jurisdictions
11
Controls
22
that meet these duties
Evidence items
67

Labelling is a technical control

A duty to mark synthetic content is met by provenance and watermarking measures, a disclosure notice and a procedure for exceptions. The synthetic-content control below serves that duty wherever it appears.

Testing is the new documentation

For higher-capability models the evidence that matters is the evaluation and adversarial-testing record, tied to the risk areas it covers. The controls list those risk areas with the incidents recorded against them.

Which controls meet these duties?

Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.

Controls for this audience
ControlSatisfiesSupportsOwner · frequency
AI governance policy and accountability structure
Policy
60Executive sponsor for AI · annual
Frontier model safety and security framework
Policy
54Head of AI safety · annual
Synthetic content labelling and provenance marking
Technical measure
50Engineering lead · continuous
AI incident management and regulatory reporting
Process
44Incident coordinator · continuous
AI interaction and use disclosure notices
Process
40Product owner · at launch and on material change
Accuracy, robustness, fairness and security testing
Technical measure
33Quality or testing lead · at launch and on material change
AI risk assessment and lifecycle risk register
Process
33AI system owner · once per ai system
Privacy and data-protection controls for AI
Process
31Data protection officer · once per ai system
Technical documentation, model cards and instructions for use
Process
31Product or model owner · at launch and on material change
Contractual allocation of AI duties across the supply chain
Contractual term
30Legal counsel · once per ai system
Prohibited and unacceptable-use screening gate
Process
20AI governance lead · once per ai system
Adversarial and red-team testing for generative AI
Technical measure
16AI security or safety lead · at launch and on material change
AI impact and fundamental-rights impact assessment
Process
12AI system owner · once per ai system
AI literacy and role-based training programme
Training programme
12Learning and development lead · annual
Data governance and dataset documentation
Process
11Data governance lead · once per ai system
Post-deployment monitoring and drift detection
Technical measure
11AI system owner · continuous
Training-data provenance and copyright register
Process
10Model development lead · at launch and on material change
AI system inventory and classification
Process
03AI governance lead · continuous
Vendor and third-party AI due diligence
Process
03Procurement or vendor risk lead · once per ai system
Model release and change-management gate
Process
02Release manager · at launch and on material change
Human oversight design and override procedure
Process
01AI system owner · once per ai system
Public-sector AI use-case register and algorithmic transparency
Process
01Agency AI officer · annual

Which duties are recorded?

Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).

Australia 1 duty

California (United States) 5 duties

Colorado (United States) 1 duty

European Union 12 duties

India 4 duties

Singapore 3 duties

South Korea 4 duties

Texas (United States) 3 duties

United Arab Emirates 1 duty

United Kingdom 2 duties

United States 4 duties

What evidence would a reviewer expect?

  • AI customer or deployer clause set Contract clause or supplier term
  • AI data-flow and legal-basis record Register entry
  • AI governance forum minutes Governance meeting record
  • AI impact assessment Impact assessment
  • AI incident record Incident record
  • AI incident response playbook Procedure or standard operating process
  • AI intake and classification procedure Procedure or standard operating process
  • AI interaction or use notice Disclosure or notice
  • AI policy Policy document
  • AI responsibility map Register entry
  • AI supplier and component register Register entry
  • AI supplier clause set Contract clause or supplier term
  • AI supplier due-diligence assessment Supplier assessment
  • AI system register Register entry
  • AI system risk assessment Risk assessment
  • AI training completion records Training record
  • AI training curriculum and materials Policy document
  • Adversarial findings tracker Risk register
  • Algorithmic transparency statement for one use case Disclosure or notice
  • Board or executive approval of the AI policy Approval or sign-off record
  • Content labelling and provenance standard Procedure or standard operating process
  • Contract clause index against the AI register Register entry
  • Copyright and rights-reservation policy Policy document
  • Dangerous-capability evaluation report Evaluation or test report
  • Data protection impact assessment for an AI system Data protection impact assessment
  • Data quality and bias check report Evaluation or test report
  • Dataset approval for use Approval or sign-off record
  • Dataset documentation sheet Dataset documentation
  • Human oversight and override procedure Procedure or standard operating process
  • Human-involvement design rationale Approval or sign-off record
  • Impact assessment approval Approval or sign-off record
  • Impact assessment procedure and template Procedure or standard operating process
  • Incident report to an authority Regulatory filing or notification
  • Independent data audit or DPO review Audit or assurance report
  • Instructions for use Disclosure or notice
  • Inventory review and publication sign-off Approval or sign-off record
  • Model card or deployer information pack Model documentation
  • Monitoring dashboard or periodic monitoring report Monitoring record
  • Monitoring review decision Approval or sign-off record
  • Notice catalogue Register entry
  • Notice wording approval Approval or sign-off record
  • Overseer training completion Training record
  • Per-system AI risk register Risk register
  • Post-market monitoring plan Procedure or standard operating process
  • Pre-release test report Evaluation or test report
  • Privacy notice section on AI use Disclosure or notice
  • Prohibited-use screening record Approval or sign-off record
  • Public AI use-case inventory Register entry
  • Public summary of training content Disclosure or notice
  • Published frontier safety framework Policy document
  • Red-team exercise report Evaluation or test report
  • Red-team rules of engagement and scenario library Procedure or standard operating process
  • Release and change-classification procedure Procedure or standard operating process
  • Release or change approval record Approval or sign-off record
  • Release test sign-off Approval or sign-off record
  • Residual-risk acceptance Approval or sign-off record
  • Risk-tier classification sign-off Approval or sign-off record
  • Role-to-curriculum training matrix Procedure or standard operating process
  • Screening list and escalation procedure Procedure or standard operating process
  • Supplier onboarding decision Approval or sign-off record
  • Technical documentation file Technical documentation file
  • Test plan and acceptance criteria Procedure or standard operating process
  • Threshold notification to an authority Regulatory filing or notification
  • Training compute tracking record Register entry
  • Training source register Register entry
  • Visible AI-generated content label Disclosure or notice
  • Watermark and provenance robustness test Evaluation or test report

Latest changes to these instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Do chatbot disclosure duties apply to internal tools?
Usually they apply where a natural person interacts with the system without it being obvious; an internal tool used by staff who know it is AI is often out of scope. The duty page cites the wording.
Which evidence do these duties call for?
The disclosure notice, the content-labelling mechanism, the model documentation and training-data summary, the copyright policy, and the evaluation and red-team reports.