AIPolicyTracker

By role · Provider / developer

AI regulation for providers and developers

A provider is the organisation that develops an AI system, or has one developed, and puts it on a market or into service under its own name. Most binding AI law lands here first: risk management, data governance, technical documentation, logging, accuracy and security, conformity assessment and post-market monitoring are provider duties before they are anyone else's.

Recorded duties
65
49 legally binding
Jurisdictions
12
Controls
25
that meet these duties
Evidence items
76

What is different about being a provider?

The provider carries the design-time duties and the paper trail. A deployer can rely on the provider's instructions and documentation; the provider has to have produced them. That makes the technical file, the risk management record and the quality management system the centre of gravity, and it makes a change to the system a regulatory event rather than an engineering one.

Where the same control does double duty

A risk assessment written once to the structure a management standard expects satisfies or supports the risk-management duty in several jurisdictions at once. The controls listed below are counted by the number of duties each one serves, so the ones worth building first are at the top.

Which controls meet these duties?

Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.

Controls for this audience
ControlSatisfiesSupportsOwner · frequency
AI governance policy and accountability structure
Policy
73Executive sponsor for AI · annual
AI incident management and regulatory reporting
Process
64Incident coordinator · continuous
AI risk assessment and lifecycle risk register
Process
63AI system owner · once per ai system
Privacy and data-protection controls for AI
Process
61Data protection officer · once per ai system
Technical documentation, model cards and instructions for use
Process
55Product or model owner · at launch and on material change
Accuracy, robustness, fairness and security testing
Technical measure
47Quality or testing lead · at launch and on material change
Contractual allocation of AI duties across the supply chain
Contractual term
42Legal counsel · once per ai system
AI interaction and use disclosure notices
Process
41Product owner · at launch and on material change
Synthetic content labelling and provenance marking
Technical measure
40Engineering lead · continuous
Prohibited and unacceptable-use screening gate
Process
40AI governance lead · once per ai system
Automatic event logging and record retention
Technical measure
33Engineering lead · continuous
Post-deployment monitoring and drift detection
Technical measure
24AI system owner · continuous
Data governance and dataset documentation
Process
24Data governance lead · once per ai system
AI impact and fundamental-rights impact assessment
Process
24AI system owner · once per ai system
Human oversight design and override procedure
Process
21AI system owner · once per ai system
AI system inventory and classification
Process
17AI governance lead · continuous
Model release and change-management gate
Process
13Release manager · at launch and on material change
AI literacy and role-based training programme
Training programme
13Learning and development lead · annual
Conformity assessment, declaration and registration
Process
12Regulatory compliance lead · once per ai system
Quality management system for AI development and supply
Policy
12Quality lead · annual
Frontier model safety and security framework
Policy
12Head of AI safety · annual
Decision explanation, human review and appeal route
Process
12Customer operations lead · once per ai system
Adversarial and red-team testing for generative AI
Technical measure
05AI security or safety lead · at launch and on material change
Training-data provenance and copyright register
Process
03Model development lead · at launch and on material change
Vendor and third-party AI due diligence
Process
03Procurement or vendor risk lead · once per ai system

Which duties are recorded?

Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).

Australia 3 duties

California (United States) 3 duties

Colorado (United States) 4 duties

European Union 24 duties

India 4 duties

Nepal 1 duty

Singapore 4 duties

South Korea 9 duties

Texas (United States) 3 duties

United Arab Emirates 1 duty

United Kingdom 5 duties

United States 4 duties

What evidence would a reviewer expect?

  • AI customer or deployer clause set Contract clause or supplier term
  • AI data-flow and legal-basis record Register entry
  • AI decision challenge and human review procedure Procedure or standard operating process
  • AI governance forum minutes Governance meeting record
  • AI impact assessment Impact assessment
  • AI incident record Incident record
  • AI incident response playbook Procedure or standard operating process
  • AI intake and classification procedure Procedure or standard operating process
  • AI interaction or use notice Disclosure or notice
  • AI policy Policy document
  • AI quality management system manual Policy document
  • AI responsibility map Register entry
  • AI supplier and component register Register entry
  • AI supplier clause set Contract clause or supplier term
  • AI supplier due-diligence assessment Supplier assessment
  • AI system event logs Access or activity log
  • AI system register Register entry
  • AI system risk assessment Risk assessment
  • AI training completion records Training record
  • AI training curriculum and materials Policy document
  • Adversarial findings tracker Risk register
  • Adverse-decision explanation template Disclosure or notice
  • Board or executive approval of the AI policy Approval or sign-off record
  • Challenge and reversal log Monitoring record
  • Conformity evidence pack Technical documentation file
  • Content labelling and provenance standard Procedure or standard operating process
  • Contract clause index against the AI register Register entry
  • Copyright and rights-reservation policy Policy document
  • Dangerous-capability evaluation report Evaluation or test report
  • Data protection impact assessment for an AI system Data protection impact assessment
  • Data quality and bias check report Evaluation or test report
  • Dataset approval for use Approval or sign-off record
  • Dataset documentation sheet Dataset documentation
  • Declaration of conformity or certificate Conformity declaration or certificate
  • Human oversight and override procedure Procedure or standard operating process
  • Human-involvement design rationale Approval or sign-off record
  • Impact assessment approval Approval or sign-off record
  • Impact assessment procedure and template Procedure or standard operating process
  • Incident report to an authority Regulatory filing or notification
  • Independent data audit or DPO review Audit or assurance report
  • Instructions for use Disclosure or notice
  • Internal audit of the AI management system Audit or assurance report
  • Log integrity and retention check Audit or assurance report
  • Log schema and retention standard Procedure or standard operating process
  • Management review minutes Governance meeting record
  • Model card or deployer information pack Model documentation
  • Monitoring dashboard or periodic monitoring report Monitoring record
  • Monitoring review decision Approval or sign-off record
  • Notice catalogue Register entry
  • Notice wording approval Approval or sign-off record
  • Overseer training completion Training record
  • Per-system AI risk register Risk register
  • Post-market monitoring plan Procedure or standard operating process
  • Pre-release test report Evaluation or test report
  • Privacy notice section on AI use Disclosure or notice
  • Prohibited-use screening record Approval or sign-off record
  • Public summary of training content Disclosure or notice
  • Published frontier safety framework Policy document
  • Red-team exercise report Evaluation or test report
  • Red-team rules of engagement and scenario library Procedure or standard operating process
  • Registration record in the relevant database Regulatory filing or notification
  • Release and change-classification procedure Procedure or standard operating process
  • Release or change approval record Approval or sign-off record
  • Release test sign-off Approval or sign-off record
  • Residual-risk acceptance Approval or sign-off record
  • Risk-tier classification sign-off Approval or sign-off record
  • Role-to-curriculum training matrix Procedure or standard operating process
  • Screening list and escalation procedure Procedure or standard operating process
  • Supplier onboarding decision Approval or sign-off record
  • Technical documentation file Technical documentation file
  • Test plan and acceptance criteria Procedure or standard operating process
  • Threshold notification to an authority Regulatory filing or notification
  • Training compute tracking record Register entry
  • Training source register Register entry
  • Visible AI-generated content label Disclosure or notice
  • Watermark and provenance robustness test Evaluation or test report

Latest changes to these instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Am I a provider if I fine-tune or rebrand someone else's model?
Often yes. Several instruments treat a substantial modification, or putting a system on the market under your own name, as becoming the provider. Check the definition in the instrument that applies to you; the duty pages cite the article.
Does this page tell me which duties apply to my product?
No. It lists every recorded duty that binds providers anywhere. Use the applicability check for a screening of your own situation, then open the official source.