Legal requirement
conformity assessment
·
European Union
EU AI Act · Articles 43, 47, 48 and 49; Annex VIII
Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.
Source-linked
Applies from 2 Aug 2026
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Source-linked
Applies from 2 Aug 2026
Legal requirement
human oversight
·
United Kingdom
ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025
Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.
Source-linked
Legal requirement
impact assessment
·
United Kingdom
ICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance section
Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.
Source-linked
Legal requirement
impact assessment
·
European Union
EU AI Act · Article 27
Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.
Source-linked
Applies from 2 Aug 2026
Legal requirement
privacy data protection
·
Nepal
Nepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)
Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for other purposes without consent, subject to statutory exceptions. AI systems trained on or processing personal data of people in Nepal must respect these limits.
Source-linked
Legal requirement
prohibited practice
·
European Union
EU AI Act · Article 5
Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.
Source-linked
Applies from 2 Feb 2025
Legal requirement
public sector use
·
United States
EO 14179 · Section 5
Agency heads were directed to identify actions taken under Executive Order 14110 that are inconsistent with the policy of EO 14179 and to suspend, revise or rescind them, and OMB was directed to revise its federal AI use and procurement memoranda.
Source-linked
Legal requirement
risk management
·
United States
OMB M-25-21 · Section 4
For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.
Source-linked
Legal requirement
transparency
·
United States
OMB M-25-21 · Section 3
Agencies must inventory their AI use cases annually and publish the inventory, identifying high-impact uses, with limited exclusions.
Source-linked
Voluntary guidance
governance accountability
·
Nepal
Nepal National AI Policy · Policy objectives and strategies (to be confirmed against the official text)
The policy commits the government to ethical, transparent and inclusive AI, data governance and institutional oversight. The specific strategies and any obligations on private actors must be confirmed from the official document; this record intentionally does not state details that could not be verified.
Source-linked
Voluntary guidance
governance accountability
·
United Arab Emirates
UAE AI Strategy 2031 · Strategy objectives on governance and ethics (reviewer to cite the section)
The strategy commits the government to ensure effective governance and regulation of AI and to promote ethical AI, which led to the AI Ethics Principles and Guidelines and the 2024 UAE AI Charter.
Source-linked
Voluntary guidance
human oversight
·
United Kingdom
UK AI regulation framework · Principle 5, Part 3
Affected people should be able to contest harmful AI decisions or outcomes and obtain redress, through existing complaint routes and regulators.
Source-linked