Legal requirement
ai literacy
·
European Union
EU AI Act · Article 4
Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.
Source-linked
Applies from 2 Feb 2025
Legal requirement
conformity assessment
·
European Union
EU AI Act · Articles 43, 47, 48 and 49; Annex VIII
Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.
Source-linked
Applies from 2 Aug 2026
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Source-linked
Applies from 2 Aug 2026
Legal requirement
human oversight
·
United Kingdom
ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025
Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.
Source-linked
Legal requirement
human oversight
·
European Union
EU AI Act · Article 14; Article 26(2) for deployers
High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.
Source-linked
Applies from 2 Aug 2026
Legal requirement
human oversight
·
United Arab Emirates
UAE PDPL · Article on data-subject rights relating to automated processing (reviewer to cite article number)
Data subjects may object to decisions based solely on automated processing, including profiling, that produce legal or similarly serious effects, subject to exceptions such as contractual necessity or consent.
Source-linked
Legal requirement
impact assessment
·
United Kingdom
ICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance section
Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.
Source-linked
Legal requirement
impact assessment
·
European Union
EU AI Act · Article 27
Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.
Source-linked
Applies from 2 Aug 2026
Legal requirement
impact assessment
·
United Arab Emirates
UAE PDPL · Article on data protection impact assessment (reviewer to cite article number)
Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, covering the processing, its purposes, risks and safeguards.
Source-linked
Legal requirement
impact assessment
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(3)
Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.
Source-linked
Applies from 30 Jun 2026
Legal requirement
impact assessment
·
India
India DPDP Act · Section 10
Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.
Source-linked
Legal requirement
incident handling
·
India
India DPDP Act · Section 8(5) and 8(6); DPDP Rules on breach intimation
Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.
Source-linked
Legal requirement
incident handling
·
European Union
EU AI Act · Article 73
Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.
Source-linked
Applies from 2 Aug 2026
Legal requirement
privacy data protection
·
Nepal
Nepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)
Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for other purposes without consent, subject to statutory exceptions. AI systems trained on or processing personal data of people in Nepal must respect these limits.
Source-linked
Legal requirement
privacy data protection
·
Singapore
PDPC AI advisory guidelines · Advisory guidelines, sections on consent, business improvement and research exceptions
Personal data used to train or operate AI systems requires consent unless an exception applies, such as the business improvement exception for improving products and services or the research exception for developing models, each subject to conditions.
Source-linked
Legal requirement
privacy data protection
·
India
India DPDP Act · Sections 4 to 7
Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses listed in the Act. A notice must describe the data, purpose, and how to exercise rights and complain.
Source-linked
Legal requirement
prohibited practice
·
European Union
EU AI Act · Article 5
Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.
Source-linked
Applies from 2 Feb 2025
Legal requirement
record keeping
·
European Union
EU AI Act · Article 12; Article 26(6) for deployers
High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.
Source-linked
Applies from 2 Aug 2026
Legal requirement
risk management
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(2)
Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.
Source-linked
Applies from 30 Jun 2026
Legal requirement
transparency
·
European Union
EU AI Act · Article 50
Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(4)
Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.
Source-linked
Applies from 30 Jun 2026
Legal requirement
transparency
·
Singapore
PDPC AI advisory guidelines · Advisory guidelines, section on notification obligation
Organisations should inform individuals that AI systems use their personal data, the purposes, the relevant features and how they influence decisions, proportionate to the impact on the individual.
Source-linked
Voluntary guidance
data governance
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on operations management
Covers data lineage and quality, minimising bias in datasets, model explainability, repeatability, robustness, regular tuning and active monitoring after deployment.
Source-linked
Voluntary guidance
governance accountability
·
India
India AI Governance Guidelines · Guiding principles and recommendations sections
The guidelines encourage organisations to embed principles such as fairness, accountability, safety and transparency, to classify and mitigate risks proportionately, and to participate in voluntary frameworks and incident reporting.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 4, Part 3
Governance measures should ensure effective oversight of AI supply and use with clear lines of accountability across the lifecycle.
Source-linked