By use case · Generative AI and foundation models
Generative AI and foundation models: the rules that apply
Generative AI attracts three families of duty: transparency (tell people they are interacting with AI, label synthetic content), model governance (document the model, publish a training-data summary, respect copyright) and safety (evaluate, red-team, report incidents, secure the system). Several jurisdictions have rules specific to synthetic media even where they have no general AI law.
- Jurisdictions
- 11
- Evidence items
- 67
Labelling is a technical control
A duty to mark synthetic content is met by provenance and watermarking measures, a disclosure notice and a procedure for exceptions. The synthetic-content control below serves that duty wherever it appears.
Testing is the new documentation
For higher-capability models the evidence that matters is the evaluation and adversarial-testing record, tied to the risk areas it covers. The controls list those risk areas with the incidents recorded against them.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| AI governance policy and accountability structure Policy | 6 | 0 | Executive sponsor for AI · annual |
| Frontier model safety and security framework Policy | 5 | 4 | Head of AI safety · annual |
| Synthetic content labelling and provenance marking Technical measure | 5 | 0 | Engineering lead · continuous |
| AI incident management and regulatory reporting Process | 4 | 4 | Incident coordinator · continuous |
| AI interaction and use disclosure notices Process | 4 | 0 | Product owner · at launch and on material change |
| Accuracy, robustness, fairness and security testing Technical measure | 3 | 3 | Quality or testing lead · at launch and on material change |
| AI risk assessment and lifecycle risk register Process | 3 | 3 | AI system owner · once per ai system |
| Privacy and data-protection controls for AI Process | 3 | 1 | Data protection officer · once per ai system |
| Technical documentation, model cards and instructions for use Process | 3 | 1 | Product or model owner · at launch and on material change |
| Contractual allocation of AI duties across the supply chain Contractual term | 3 | 0 | Legal counsel · once per ai system |
| Prohibited and unacceptable-use screening gate Process | 2 | 0 | AI governance lead · once per ai system |
| Adversarial and red-team testing for generative AI Technical measure | 1 | 6 | AI security or safety lead · at launch and on material change |
| AI impact and fundamental-rights impact assessment Process | 1 | 2 | AI system owner · once per ai system |
| AI literacy and role-based training programme Training programme | 1 | 2 | Learning and development lead · annual |
| Data governance and dataset documentation Process | 1 | 1 | Data governance lead · once per ai system |
| Post-deployment monitoring and drift detection Technical measure | 1 | 1 | AI system owner · continuous |
| Training-data provenance and copyright register Process | 1 | 0 | Model development lead · at launch and on material change |
| AI system inventory and classification Process | 0 | 3 | AI governance lead · continuous |
| Vendor and third-party AI due diligence Process | 0 | 3 | Procurement or vendor risk lead · once per ai system |
| Model release and change-management gate Process | 0 | 2 | Release manager · at launch and on material change |
| Human oversight design and override procedure Process | 0 | 1 | AI system owner · once per ai system |
| Public-sector AI use-case register and algorithmic transparency Process | 0 | 1 | Agency AI officer · annual |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
Australia 1 duty
-
VoluntaryAustralian Voluntary AI Safety Standard · Guardrails 1 and 2Establish accountability processes and a risk-management process (guardrails 1 and 2)
California (United States) 5 duties
-
Legal requirementCalifornia SB 53 · Labor Code Section 1107 (as added by SB 53)applies from 1 Jan 2026Frontier developers must protect employees who report catastrophic-risk concerns
-
Legal requirementCalifornia SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)applies from 1 Jan 2026Frontier developers must publish a transparency report before deploying a new frontier model
-
Legal requirementCalifornia SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)applies from 1 Jan 2026Large frontier developers must publish a frontier AI framework
-
Legal requirementCalifornia SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)applies from 1 Jan 2026Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
-
Legal requirementCalifornia SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)applies from 1 Jan 2026Report critical safety incidents to the Office of Emergency Services
Colorado (United States) 1 duty
-
Legal requirementColorado AI Act · C.R.S. 6-1-1704applies from 30 Jun 2026Deployers and developers must disclose to consumers that they are interacting with an AI system
European Union 12 duties
-
Legal requirementEU AI Act · Article 50(4)applies from 2 Aug 2026Deployers must disclose deepfakes and AI-generated text published on matters of public interest
-
Legal requirementEU AI Act · Article 50applies from 2 Aug 2026Disclose AI interaction and label synthetic content
-
Legal requirementEU AI Act · Article 4applies from 2 Feb 2025Ensure AI literacy of staff operating AI systems
-
Legal requirementEU AI Act · Articles 51, 52 and 55applies from 2 Aug 2025Manage systemic risk for high-impact general-purpose models
-
Legal requirementEU AI Act · Article 53 and Annexes XI–XIIapplies from 2 Aug 2025Meet general-purpose AI model provider obligations
-
Legal requirementEU AI Act · Article 54applies from 2 Aug 2025Non-EU providers of GPAI models must appoint an EU authorised representative
-
Legal requirementEU AI Act · Article 53(1)(a) and 53(1)(b); Annexes XI and XIIapplies from 2 Aug 2025Providers of GPAI models must maintain technical documentation and inform downstream providers
-
Legal requirementEU AI Act · Article 52(1)applies from 2 Aug 2025Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
-
Legal requirementEU AI Act · Article 50(2)applies from 2 Aug 2026Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
-
Legal requirementEU AI Act · Article 25(4)applies from 2 Aug 2026Providers of high-risk AI must have written agreements with suppliers of components, tools and services
-
Legal requirementEU AI Act · Article 55(1)(d)applies from 2 Aug 2025Providers of systemic-risk GPAI models must secure the model and its infrastructure
-
Legal requirementEU AI Act · Article 55(1)(c)applies from 2 Aug 2025Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office
India 4 duties
-
Legal requirementIndia DPDP Act · Section 8(5) and 8(6); DPDP Rules on breach intimationImplement reasonable security safeguards and notify breaches
-
Legal requirementIndia DPDP Act · Sections 4 to 7Process personal data only with valid consent or a legitimate use, after notice
-
Legal requirementIndia DPDP Act · Section 10Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
-
VoluntaryIndia AI Governance Guidelines · Guiding principles and recommendations sectionsAdopt the guiding principles and risk-based governance (voluntary)
Singapore 3 duties
-
VoluntarySingapore Model AI Governance Framework · Second edition, Part on internal governance structures and measuresEstablish internal governance structures and measures for AI
-
VoluntarySingapore Model AI Governance Framework · Second edition, Part on operations managementManage data quality, model development and monitoring across the lifecycle
-
VoluntarySingapore Model AI Governance Framework · Generative AI framework, dimensions on incident reporting and content provenanceReport incidents and mark AI-generated content (generative AI framework)
South Korea 4 duties
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 31(2) and 31(3)applies from 22 Jan 2026AI business operators must label generative AI output and clearly flag realistic synthetic media
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 31(1)applies from 22 Jan 2026AI business operators must notify users in advance that a product or service runs on high-impact or generative AI
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 36applies from 22 Jan 2026Foreign AI business operators above the threshold must designate a domestic representative in Korea
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 32applies from 22 Jan 2026Operators of AI above the compute threshold must run lifecycle risk management and report safety results
Texas (United States) 3 duties
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.052applies from 1 Jan 2026Developers and deployers must not use AI to incite self-harm, harm to others or crime
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.057applies from 1 Jan 2026Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.051applies from 1 Jan 2026Government agencies must disclose to consumers that they are interacting with an AI system
United Arab Emirates 1 duty
-
Legal requirementUAE PDPL · Article on data protection impact assessment (reviewer to cite article number)Conduct a data protection impact assessment for high-risk processing using new technologies
United Kingdom 2 duties
-
VoluntaryUK AI regulation framework · Principle 1, Part 3Ensure AI systems are safe, secure and robust throughout their lifecycle
-
VoluntaryUK AI regulation framework · Principle 4, Part 3Establish accountability and governance for AI
United States 4 duties
-
VoluntaryNIST AI RMF · GOVERN functionEstablish AI governance policies, roles and accountability (Govern)
-
VoluntaryNIST AI RMF · MAP functionMap context, intended use and potential impacts (Map)
-
VoluntaryNIST AI RMF · MEASURE functionMeasure and test trustworthiness characteristics (Measure)
-
VoluntaryNIST AI RMF · MANAGE functionPrioritise, respond to and monitor AI risks (Manage)
What evidence would a reviewer expect?
- AI customer or deployer clause set Contract clause or supplier term
- AI data-flow and legal-basis record Register entry
- AI governance forum minutes Governance meeting record
- AI impact assessment Impact assessment
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI intake and classification procedure Procedure or standard operating process
- AI interaction or use notice Disclosure or notice
- AI policy Policy document
- AI responsibility map Register entry
- AI supplier and component register Register entry
- AI supplier clause set Contract clause or supplier term
- AI supplier due-diligence assessment Supplier assessment
- AI system register Register entry
- AI system risk assessment Risk assessment
- AI training completion records Training record
- AI training curriculum and materials Policy document
- Adversarial findings tracker Risk register
- Algorithmic transparency statement for one use case Disclosure or notice
- Board or executive approval of the AI policy Approval or sign-off record
- Content labelling and provenance standard Procedure or standard operating process
- Contract clause index against the AI register Register entry
- Copyright and rights-reservation policy Policy document
- Dangerous-capability evaluation report Evaluation or test report
- Data protection impact assessment for an AI system Data protection impact assessment
- Data quality and bias check report Evaluation or test report
- Dataset approval for use Approval or sign-off record
- Dataset documentation sheet Dataset documentation
- Human oversight and override procedure Procedure or standard operating process
- Human-involvement design rationale Approval or sign-off record
- Impact assessment approval Approval or sign-off record
- Impact assessment procedure and template Procedure or standard operating process
- Incident report to an authority Regulatory filing or notification
- Independent data audit or DPO review Audit or assurance report
- Instructions for use Disclosure or notice
- Inventory review and publication sign-off Approval or sign-off record
- Model card or deployer information pack Model documentation
- Monitoring dashboard or periodic monitoring report Monitoring record
- Monitoring review decision Approval or sign-off record
- Notice catalogue Register entry
- Notice wording approval Approval or sign-off record
- Overseer training completion Training record
- Per-system AI risk register Risk register
- Post-market monitoring plan Procedure or standard operating process
- Pre-release test report Evaluation or test report
- Privacy notice section on AI use Disclosure or notice
- Prohibited-use screening record Approval or sign-off record
- Public AI use-case inventory Register entry
- Public summary of training content Disclosure or notice
- Published frontier safety framework Policy document
- Red-team exercise report Evaluation or test report
- Red-team rules of engagement and scenario library Procedure or standard operating process
- Release and change-classification procedure Procedure or standard operating process
- Release or change approval record Approval or sign-off record
- Release test sign-off Approval or sign-off record
- Residual-risk acceptance Approval or sign-off record
- Risk-tier classification sign-off Approval or sign-off record
- Role-to-curriculum training matrix Procedure or standard operating process
- Screening list and escalation procedure Procedure or standard operating process
- Supplier onboarding decision Approval or sign-off record
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Threshold notification to an authority Regulatory filing or notification
- Training compute tracking record Register entry
- Training source register Register entry
- Visible AI-generated content label Disclosure or notice
- Watermark and provenance robustness test Evaluation or test report
Latest changes to these instruments
Texas TRAIGA takes effect
California SB 53 frontier-model transparency duties become operative
European Commission proposes Digital Omnibus adjustments to AI Act timelines
India notifies the Digital Personal Data Protection Rules, 2025
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Do chatbot disclosure duties apply to internal tools?
- Usually they apply where a natural person interacts with the system without it being obvious; an internal tool used by staff who know it is AI is often out of scope. The duty page cites the wording.
- Which evidence do these duties call for?
- The disclosure notice, the content-labelling mechanism, the model documentation and training-data summary, the copyright policy, and the evaluation and red-team reports.