AIPolicyTracker

AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

117 results · page 2 of 5

Results

Legal requirement impact assessment United Kingdom

Carry out a data protection impact assessment for high-risk AI processing

ICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance section

Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement impact assessment European Union

Carry out a fundamental rights impact assessment before deployment

EU AI Act · Article 27

Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement impact assessment United Arab Emirates

Conduct a data protection impact assessment for high-risk processing using new technologies

UAE PDPL · Article on data protection impact assessment (reviewer to cite article number)

Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, covering the processing, its purposes, risks and safeguards.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement impact assessment Colorado (United States)

Deployers must complete impact assessments for high-risk AI

Colorado AI Act · C.R.S. 6-1-1703(3)

Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement impact assessment India

Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits

India DPDP Act · Section 10

Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement incident handling Colorado (United States)

Deployers must notify the Attorney General of discovered algorithmic discrimination

Colorado AI Act · C.R.S. 6-1-1703(7)

If a deployer discovers that a high-risk AI system it uses has caused algorithmic discrimination, it must send a notice to the Colorado Attorney General within 90 days of the discovery, in the form the Attorney General prescribes, without unreasonable delay.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement incident handling Colorado (United States)

Developers must notify the Attorney General and deployers of discovered algorithmic discrimination

Colorado AI Act · C.R.S. 6-1-1702(5)

Within 90 days after a developer discovers, through ongoing testing or a credible report from a deployer, that a high-risk AI system it developed has caused or is reasonably likely to have caused algorithmic discrimination, it must disclose this to the Colorado Attorney General and to all known deployers or other developers of the system, without unreasonable delay.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement incident handling India

Implement reasonable security safeguards and notify breaches

India DPDP Act · Section 8(5) and 8(6); DPDP Rules on breach intimation

Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement incident handling European Union

Providers must take corrective action and inform the supply chain about non-conforming high-risk AI

EU AI Act · Article 20

A provider that considers, or has reason to consider, that a high-risk system it has placed on the market is not in conformity must immediately correct it, withdraw it, disable it or recall it as appropriate, and inform the distributors, deployers, authorised representative and importers. Where the system presents a risk to health, safety or fundamental rights and the provider becomes aware of that risk, it must immediately investigate the causes together with the reporting deployer and inform the market surveillance authorities and, where relevant, the notified body.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement incident handling European Union

Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office

EU AI Act · Article 55(1)(c)

Providers of general-purpose AI models with systemic risk must keep track of, document and report without undue delay to the AI Office and, where relevant, to national competent authorities the relevant information about serious incidents and the possible corrective measures to address them. The General-Purpose AI Code of Practice sets out timelines and content that providers may follow to demonstrate compliance.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2025
Legal requirement incident handling California (United States)

Report critical safety incidents to the Office of Emergency Services

California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)

Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and the Office is to establish a reporting mechanism.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement incident handling European Union

Report serious incidents to market surveillance authorities

EU AI Act · Article 73

Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement post market monitoring European Union

Deployers must monitor high-risk AI, suspend use on risk and report serious incidents

EU AI Act · Article 26(5)

Deployers must monitor a high-risk AI system's operation against the provider's instructions and feed observations to the provider under Article 72. If they have reason to think the system as used may present a risk to health, safety or fundamental rights, they must inform the provider or distributor and the market surveillance authority without undue delay and suspend use. On a serious incident, they must immediately inform the provider, then the importer or distributor and the authorities. Financial institutions meet this through their internal governance rules.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement post market monitoring European Union

Operate a post-market monitoring system

EU AI Act · Article 72

Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement privacy data protection Nepal

Collect and use personal information only with consent and for the stated purpose

Nepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)

Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for other purposes without consent, subject to statutory exceptions. AI systems trained on or processing personal data of people in Nepal must respect these limits.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement privacy data protection European Union

Deployers must use the provider's transparency information in their data protection impact assessment

EU AI Act · Article 26(9)

Where a deployer of a high-risk AI system is required to carry out a data protection impact assessment under Article 35 of the GDPR or Article 27 of the Law Enforcement Directive, it must draw on the information the provider supplied under Article 13, such as the intended purpose, performance, limitations and human-oversight measures, when producing that assessment.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement privacy data protection New York (United States)

Employers and employment agencies must disclose the data collected and their retention policy for the tool

NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-303

Unless already disclosed on the website, an employer or employment agency must provide, within 30 days of a written request from a candidate or employee, information about the type of data the automated employment decision tool collects, the source of that data, and the employer's or agency's data retention policy. The DCWP rules allow this information to be posted publicly instead of answered case by case.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 5 Jul 2023
Legal requirement privacy data protection Singapore

Identify consent or an applicable PDPA exception before using personal data in AI

PDPC AI advisory guidelines · Advisory guidelines, sections on consent, business improvement and research exceptions

Personal data used to train or operate AI systems requires consent unless an exception applies, such as the business improvement exception for improving products and services or the research exception for developing models, each subject to conditions.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement privacy data protection India

Process personal data only with valid consent or a legitimate use, after notice

India DPDP Act · Sections 4 to 7

Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses listed in the Act. A notice must describe the data, purpose, and how to exercise rights and complain.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement prohibited practice Texas (United States)

Developers and deployers must not use AI to incite self-harm, harm to others or crime

Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.052

A person may not develop or deploy an AI system in a manner that intentionally aims to incite or encourage a person to commit physical self-harm, including suicide, to harm another person, or to engage in criminal activity. The prohibition turns on the developer's or deployer's intent rather than on the system's effects, which is the pattern followed throughout the Act's prohibited-use provisions.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement prohibited practice Texas (United States)

Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class

Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.056

A person may not develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. A disparate impact on a protected class is not, by itself, sufficient to show an intent to discriminate, and insurers and financial institutions acting under their own regulatory regimes are treated separately.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement prohibited practice Texas (United States)

Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes

Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.057

A person may not develop or distribute an AI system with the sole intent of producing, assisting or aiding in producing, or distributing child pornography or unlawful deep-fake videos or images, including sexually explicit deepfakes of a person without consent, or of engaging in sexually explicit text-based conversations while impersonating or imitating a child, in violation of the Texas Penal Code.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement prohibited practice European Union

Do not deploy or provide AI for prohibited practices

EU AI Act · Article 5

Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Feb 2025
Legal requirement prohibited practice Texas (United States)

Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights

Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.054

A governmental entity may not develop or deploy an AI system for the purpose of uniquely identifying a specific individual using biometric data, or of gathering images or other media from the internet or another public source without the individual's consent, where doing so would infringe a right guaranteed under the United States or Texas constitutions or violate state or federal law. The Act preserves lawful uses that comply with existing biometric-privacy law.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement prohibited practice Texas (United States)

Governmental entities must not use AI for social scoring

Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.053

A governmental entity may not develop or deploy an AI system that evaluates or classifies natural persons or groups on the basis of their social behaviour or personal characteristics, with the intent to calculate or assign a social score or similar valuation that leads to detrimental or unfavourable treatment unrelated to the context in which the data was collected, or that is unjustified or disproportionate to the behaviour.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Search

Frequently asked questions

What is an obligation on this site?
A single practical requirement pulled out of an instrument and stated on its own: keep a risk management system, log incidents, document training data, provide human oversight, and so on. Each one cites the article or section it comes from so you can check it against the source.
Does a voluntary obligation have legal force?
No, and every obligation is labelled either a legal requirement or voluntary guidance. Voluntary items still matter in practice, because procurement questionnaires and auditors ask about them, but only the binding ones carry legal consequence.
How do I find the obligations that apply to my organisation?
Filter by jurisdiction, category, actor, sector or use case. The applicability check asks a short set of questions and returns the duties that may reach you. It is an educational screen, not a legal determination, and it says so.
Why do some instruments have no obligations listed?
Because nobody has broken them out yet. Most instruments are recorded at summary level first; obligations are added jurisdiction by jurisdiction. The coverage and open-gaps pages publish exactly what is missing rather than hiding it.