Legal requirement
risk management
·
United States
OMB M-25-21 · Section 4
For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.
Source-linked
Legal requirement
risk management
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(2)
Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.
Source-linked
Applies from 30 Jun 2026
Legal requirement
risk management
·
European Union
EU AI Act · Article 9
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Source-linked
Applies from 2 Aug 2026
Legal requirement
safety testing
·
California (United States)
California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)
Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, apply mitigations, secure model weights, and govern internal processes, and must review it at least annually.
Source-linked
Applies from 1 Jan 2026
Legal requirement
safety testing
·
European Union
EU AI Act · Articles 51, 52 and 55
A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.
Source-linked
Applies from 2 Aug 2025
Legal requirement
technical documentation
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1702
Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.
Source-linked
Applies from 30 Jun 2026
Legal requirement
technical documentation
·
European Union
EU AI Act · Article 11 and Annex IV
Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
European Union
EU AI Act · Article 50
Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(4)
Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.
Source-linked
Applies from 30 Jun 2026
Legal requirement
transparency
·
Singapore
PDPC AI advisory guidelines · Advisory guidelines, section on notification obligation
Organisations should inform individuals that AI systems use their personal data, the purposes, the relevant features and how they influence decisions, proportionate to the impact on the individual.
Source-linked
Legal requirement
transparency
·
European Union
EU AI Act · Article 13
High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
United States
OMB M-25-21 · Section 3
Agencies must inventory their AI use cases annually and publish the inventory, identifying high-impact uses, with limited exclusions.
Source-linked
Legal requirement
vendor governance
·
European Union
EU AI Act · Articles 23 and 24
Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.
Source-linked
Applies from 2 Aug 2026
Voluntary guidance
data governance
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on operations management
Covers data lineage and quality, minimising bias in datasets, model explainability, repeatability, robustness, regular tuning and active monitoring after deployment.
Source-linked
Voluntary guidance
governance accountability
·
India
India AI Governance Guidelines · Guiding principles and recommendations sections
The guidelines encourage organisations to embed principles such as fairness, accountability, safety and transparency, to classify and mitigate risks proportionately, and to participate in voluntary frameworks and incident reporting.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 4, Part 3
Governance measures should ensure effective oversight of AI supply and use with clear lines of accountability across the lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 1 and 2
Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail 2 asks for a risk-management process to identify and mitigate risks across the AI lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
United States
NIST AI RMF · GOVERN function
Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.
Source-linked
Voluntary guidance
governance accountability
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on internal governance structures and measures
Organisations should adapt existing governance to AI: clear roles and responsibilities, board and senior management oversight, risk-management and internal controls, and staff training.
Source-linked
Voluntary guidance
governance accountability
·
Nepal
Nepal National AI Policy · Policy objectives and strategies (to be confirmed against the official text)
The policy commits the government to ethical, transparent and inclusive AI, data governance and institutional oversight. The specific strategies and any obligations on private actors must be confirmed from the official document; this record intentionally does not state details that could not be verified.
Source-linked
Voluntary guidance
governance accountability
·
United Arab Emirates
UAE AI Strategy 2031 · Strategy objectives on governance and ethics (reviewer to cite the section)
The strategy commits the government to ensure effective governance and regulation of AI and to promote ethical AI, which led to the AI Ethics Principles and Guidelines and the 2024 UAE AI Charter.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 3, Part 3
AI systems should not undermine legal rights, discriminate unfairly or create unfair market outcomes. The Equality Act 2010 and UK GDPR fairness principle make key parts of this binding.
Source-linked
Voluntary guidance
human oversight
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on human involvement in AI-augmented decision-making
Using a risk-impact matrix (probability and severity of harm), organisations choose human-in-the-loop, human-over-the-loop or human-out-of-the-loop designs and document the rationale.
Source-linked
Voluntary guidance
human oversight
·
United Kingdom
UK AI regulation framework · Principle 5, Part 3
Affected people should be able to contest harmful AI decisions or outcomes and obtain redress, through existing complaint routes and regulators.
Source-linked
Voluntary guidance
human oversight
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 4, 5 and 6
Test AI models and systems before deployment and monitor them in operation; enable meaningful human control and intervention; and inform end users about AI-enabled decisions, interactions with AI and AI-generated content.
Source-linked