Legal requirement
technical documentation
·
European Union
EU AI Act · Article 11 and Annex IV
Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
European Union
EU AI Act · Article 50
Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
Singapore
PDPC AI advisory guidelines · Advisory guidelines, section on notification obligation
Organisations should inform individuals that AI systems use their personal data, the purposes, the relevant features and how they influence decisions, proportionate to the impact on the individual.
Source-linked
Legal requirement
transparency
·
European Union
EU AI Act · Article 13
High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.
Source-linked
Applies from 2 Aug 2026
Legal requirement
vendor governance
·
European Union
EU AI Act · Articles 23 and 24
Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.
Source-linked
Applies from 2 Aug 2026
Voluntary guidance
data governance
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on operations management
Covers data lineage and quality, minimising bias in datasets, model explainability, repeatability, robustness, regular tuning and active monitoring after deployment.
Source-linked
Voluntary guidance
governance accountability
·
India
India AI Governance Guidelines · Guiding principles and recommendations sections
The guidelines encourage organisations to embed principles such as fairness, accountability, safety and transparency, to classify and mitigate risks proportionately, and to participate in voluntary frameworks and incident reporting.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 4, Part 3
Governance measures should ensure effective oversight of AI supply and use with clear lines of accountability across the lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 1 and 2
Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail 2 asks for a risk-management process to identify and mitigate risks across the AI lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
United States
NIST AI RMF · GOVERN function
Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.
Source-linked
Voluntary guidance
governance accountability
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on internal governance structures and measures
Organisations should adapt existing governance to AI: clear roles and responsibilities, board and senior management oversight, risk-management and internal controls, and staff training.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 3, Part 3
AI systems should not undermine legal rights, discriminate unfairly or create unfair market outcomes. The Equality Act 2010 and UK GDPR fairness principle make key parts of this binding.
Source-linked
Voluntary guidance
human oversight
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on human involvement in AI-augmented decision-making
Using a risk-impact matrix (probability and severity of harm), organisations choose human-in-the-loop, human-over-the-loop or human-out-of-the-loop designs and document the rationale.
Source-linked
Voluntary guidance
human oversight
·
United Kingdom
UK AI regulation framework · Principle 5, Part 3
Affected people should be able to contest harmful AI decisions or outcomes and obtain redress, through existing complaint routes and regulators.
Source-linked
Voluntary guidance
human oversight
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 4, 5 and 6
Test AI models and systems before deployment and monitor them in operation; enable meaningful human control and intervention; and inform end users about AI-enabled decisions, interactions with AI and AI-generated content.
Source-linked
Voluntary guidance
impact assessment
·
United States
NIST AI RMF · MAP function
Map establishes the context: intended purposes, users, deployment settings, legal requirements, risk categorisation, benefits and costs, and impacts on individuals, groups, communities and society.
Source-linked
Voluntary guidance
risk management
·
United Kingdom
UK AI regulation framework · Principle 1, Part 3
Regulators are asked to ensure AI systems function in a robust, secure and safe way, with risks continually identified, assessed and managed. In practice this is enforced through existing safety, security and data-protection law rather than a new duty.
Source-linked
Voluntary guidance
risk management
·
United States
NIST AI RMF · MANAGE function
Manage allocates resources to mapped and measured risks, plans responses including decommissioning, manages third-party risks, and documents post-deployment monitoring, incident response and communication.
Source-linked
Voluntary guidance
safety testing
·
United States
NIST AI RMF · MEASURE function
Measure covers selecting metrics and test methods, evaluating validity, safety, security, resilience, explainability, privacy, fairness and bias, and monitoring these over time, including through independent review and red-teaming for generative AI.
Source-linked
Voluntary guidance
transparency
·
United Kingdom
UK AI regulation framework · Principle 2, Part 3
Organisations should communicate when and how AI is used and provide explanations proportionate to the risk, so that people can understand decisions affecting them. For personal data, UK GDPR transparency and automated decision-making rights make this binding in practice.
Source-linked
Voluntary guidance
transparency
·
Singapore
Singapore Model AI Governance Framework · Generative AI framework, dimensions on incident reporting and content provenance
The generative-AI framework recommends incident-reporting channels and processes for AI harms, and content provenance measures such as digital watermarking and cryptographic provenance so that users can identify AI-generated content.
Source-linked
Voluntary guidance
vendor governance
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 7, 8 and 9
Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, models and systems; and keep and maintain records to allow third parties to assess compliance.
Source-linked