Results
Legal requirement
accuracy robustness security
·
European Union
EU AI Act · Article 15
High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy levels and metrics must be declared in the instructions; systems must be resilient to errors, faults and inconsistencies, address feedback loops in continuously learning systems, and resist attempts to alter use or performance, including data poisoning, model poisoning, adversarial examples and confidentiality attacks.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
accuracy robustness security
·
New York (United States)
NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(a)(1); 6 RCNY Section 5-301
An automated employment decision tool may not be used to screen candidates or employees for hiring or promotion in New York City unless it has been the subject of a bias audit by an independent auditor within the year before use. The audit calculates selection rates and impact ratios by sex, race/ethnicity and their intersections, and scoring-rate comparisons for tools that score rather than select, using the employer's historical data or, where insufficient, test data as the DCWP rules allow.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 5 Jul 2023
Legal requirement
accuracy robustness security
·
European Union
EU AI Act · Article 55(1)(d)
Providers of general-purpose AI models with systemic risk must ensure an adequate level of cybersecurity protection for the model and for the physical infrastructure it runs on, which in practice covers protection of model weights, training and inference environments, and access controls against theft, tampering and unauthorised release. Codes of practice and harmonised standards may be used to show compliance.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Aug 2025
Legal requirement
ai literacy
·
European Union
EU AI Act · Article 4
Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Feb 2025
Legal requirement
conformity assessment
·
European Union
EU AI Act · Articles 43, 47, 48 and 49; Annex VIII
Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
copyright training data
·
European Union
EU AI Act · Article 53 and Annexes XI–XII
Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XII), put in place a policy to comply with EU copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed public summary of training content using the Commission's template. Free and open-source models are exempt from the first two duties unless they present systemic risk. Adherence to the General-Purpose AI Code of Practice can demonstrate compliance.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Aug 2025
Legal requirement
data governance
·
European Union
EU AI Act · Article 10
High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
data governance
·
European Union
EU AI Act · Article 26(4)
To the extent a deployer controls the data fed into a high-risk AI system, it must make sure that input data is relevant to, and sufficiently representative for, the system's intended purpose. The duty sits with the deployer even though the provider designed the system, because the deployer chooses what the system is run on.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 25(1) and 25(2)
A distributor, importer, deployer or other third party is treated as the provider of a high-risk AI system, with all Article 16 duties, if it puts its own name or trademark on a system already on the market, makes a substantial modification to a high-risk system that stays high-risk, or changes the intended purpose of a system so that it becomes high-risk. The original provider then ceases to be provider for that system but must cooperate and supply the information and access needed for the new provider to comply.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
governance accountability
·
South Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 36
An AI business operator without an address or place of business in Korea, whose user numbers or revenue meet the thresholds set by Presidential Decree, must designate in writing a domestic representative with an address in Korea. The representative handles the operator's duties under the Act, including submitting the Article 32 safety results, supporting high-impact AI confirmation and cooperating with fact-finding investigations, and the operator is treated as responsible for the representative's acts.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 22 Jan 2026
Legal requirement
governance accountability
·
California (United States)
California SB 53 · Labor Code Section 1107 (as added by SB 53)
A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal authority, a manager or another employee with authority that the developer's activities pose a specific and substantial danger to public health or safety from catastrophic risk, or that it has violated the Act. Covered employees must be given clear notice of these rights, and large frontier developers must run an anonymous internal reporting process with regular updates to the reporter and to officers and directors.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 1 Jan 2026
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26(10)
A deployer using a high-risk post-remote biometric identification system in a criminal investigation must request authorisation from a judicial or independent administrative authority in advance or within 48 hours, unless the use is only the initial identification of a potential suspect on objective and verifiable facts. Use is limited to a targeted search; if authorisation is refused, use stops and the data is deleted. No adverse legal decision may rest solely on the output, each use is documented, and the deployer reports annually to the market surveillance and data protection authorities.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 22
Before making a high-risk AI system available in the Union, a provider established outside the EU must appoint, by written mandate, an authorised representative established in the Union. The representative verifies that the EU declaration of conformity and technical documentation exist and that conformity assessment was done, keeps the provider's contact details and the documentation available for ten years, supplies information to authorities, cooperates with them, and must end the mandate if the provider acts contrary to the Regulation.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 54
Before placing a general-purpose AI model on the Union market, a provider established in a third country must appoint, by written mandate, an authorised representative established in the Union. The representative checks that the Annex XI documentation exists and the Article 53 duties are met, keeps a copy of the documentation and the provider's contact details for ten years after market placement, provides information to the AI Office on request, cooperates with authorities, and must end the mandate if the provider breaches the Regulation. Open-source models without systemic risk are exempt.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Aug 2025
Legal requirement
governance accountability
·
South Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)
Operators of high-impact AI must prepare and implement a plan to protect users, and must prepare and keep documents describing the measures they take to secure the AI's safety and reliability, so that they can be shown to the Ministry of Science and ICT on request. Further items may be added by Presidential Decree, and the ministry may publish guidelines on how to meet these duties.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 22 Jan 2026
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 16
Article 16 lists what a provider of a high-risk AI system owes: compliance with the Section 2 requirements, its name and contact details on the system or its documentation, a quality management system, retention of documentation and logs, conformity assessment, an EU declaration of conformity, CE marking, registration, corrective action when needed, cooperation with authorities on request, and accessibility in line with the EU accessibility directives.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 21
On a reasoned request from a national competent authority, a provider of a high-risk AI system must supply all the information and documentation needed to show that the system meets the Section 2 requirements, in a language the authority can readily understand, and must give the authority access to the automatically generated logs it holds. Authorities must treat what they receive as confidential under Article 78.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 52(1)
A provider whose general-purpose AI model meets the Article 51(1)(a) high-impact capability condition, which is presumed once cumulative training compute exceeds 10^25 floating-point operations, must notify the Commission without delay and in any event within two weeks of the condition being met or of learning that it will be met. The notification may include arguments that the model nonetheless does not present systemic risk; the Commission decides and keeps a public list of designated models.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Aug 2025
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
human oversight
·
United Kingdom
ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025
Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement
human oversight
·
New York (United States)
NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(1); 6 RCNY Section 5-303
The advance notice to candidates and employees must allow them to request an alternative selection process or a reasonable accommodation. The DCWP rules make clear that the law itself does not require the employer to provide an alternative process, but the request route must exist and accommodation requests remain governed by disability and human-rights law. Instructions for making the request must be included in the notice.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 5 Jul 2023
Legal requirement
human oversight
·
European Union
EU AI Act · Article 14; Article 26(2) for deployers
High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
human oversight
·
Colorado (United States)
Colorado ADMT law (SB 26-189)
A consumer who receives an adverse consequential decision may obtain meaningful review by a person with the authority and information to change the outcome. Scope and timing follow the enrolled bill.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 1 Jan 2027
Legal requirement
human oversight
·
South Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)
Operators of high-impact AI must ensure that the AI is subject to human management and supervision, so that people remain able to monitor its operation and intervene in or override its outputs where those outputs may affect life, physical safety or fundamental rights.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 22 Jan 2026
Legal requirement
human oversight
·
United Arab Emirates
UAE PDPL · Article on data-subject rights relating to automated processing (reviewer to cite article number)
Data subjects may object to decisions based solely on automated processing, including profiling, that produce legal or similarly serious effects, subject to exceptions such as contractual necessity or consent.
Source-linked (a factual check against the official source, not a legal review or legal advice)