Results
Legal requirement
public sector use
·
United States
EO 14179 · Section 5
Agency heads were directed to identify actions taken under Executive Order 14110 that are inconsistent with the policy of EO 14179 and to suspend, revise or rescind them, and OMB was directed to revise its federal AI use and procurement memoranda.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement
public sector use
·
European Union
EU AI Act · Article 26(8); Article 49(3) and 49(4)
Deployers that are public authorities or Union institutions, bodies, offices or agencies must register their use of an Annex III high-risk AI system in the EU database before putting it into service. If they find that the system they intend to use has not been registered in the database by its provider, they must not use it and must inform the provider or distributor.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
quality management
·
European Union
EU AI Act · Article 17
Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
record keeping
·
European Union
EU AI Act · Article 12; Article 26(6) for deployers
High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
record keeping
·
Colorado (United States)
Colorado ADMT law (SB 26-189)
Deployers must retain records showing how automated decision-making technology was used in consequential decisions, for three years, according to secondary reporting on the enrolled bill.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 1 Jan 2027
Legal requirement
record keeping
·
European Union
EU AI Act · Article 18
For ten years after a high-risk AI system is placed on the market or put into service, the provider must keep at the disposal of national competent authorities the technical documentation, the quality management system documentation, any changes approved by a notified body, the notified body's decisions and other documents, and the EU declaration of conformity. Financial institutions keep these as part of their sector record-keeping.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
record keeping
·
European Union
EU AI Act · Article 19
Providers must keep the event logs that a high-risk AI system generates under Article 12, to the extent those logs are within their control, for a period appropriate to the system's intended purpose and in any case for at least six months, unless Union or national law on personal data sets a different period. Financial institutions keep the logs under their sector rules.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
risk management
·
United States
OMB M-25-21 · Section 4
For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement
risk management
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(2)
Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement
risk management
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(1)
A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. A deployer that runs the required risk-management programme, completes impact assessments, gives consumer notices and makes the required disclosures benefits from a rebuttable presumption of reasonable care; some deployers with fewer than 50 employees are relieved of parts of the programme and assessment duties when they rely on the developer's impact assessment.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement
risk management
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1702(1)
A developer of a high-risk AI system must use reasonable care to protect consumers from any known or reasonably foreseeable risk of algorithmic discrimination arising from the intended and contracted uses of the system. A developer that meets the documentation, public-statement and Attorney General disclosure duties in the rest of section 6-1-1702 benefits from a rebuttable presumption that it used reasonable care.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement
risk management
·
European Union
EU AI Act · Article 9
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
risk management
·
South Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)
An AI business operator that provides high-impact AI, or a product or service using it, must establish and operate a plan for managing the risks of that AI. High-impact AI is AI used in areas such as energy, drinking water, health care and medical devices, nuclear safety, biometric analysis for criminal investigation, decisions on recruitment or loans, transport, public services and education, where it may materially affect life, safety or fundamental rights.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 22 Jan 2026
Legal requirement
safety testing
·
California (United States)
California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)
Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, apply mitigations, secure model weights, and govern internal processes, and must review it at least annually.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 1 Jan 2026
Legal requirement
safety testing
·
California (United States)
California SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)
A large frontier developer must transmit to the California Office of Emergency Services, on the periodic schedule the statute sets, a summary of any assessment of catastrophic risk that results from the internal use of its frontier models. This covers risks arising before public deployment, such as during internal evaluation or use of the model to accelerate research, and complements the public transparency report.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 1 Jan 2026
Legal requirement
safety testing
·
European Union
EU AI Act · Articles 51, 52 and 55
A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Aug 2025
Legal requirement
safety testing
·
South Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 32
An AI business operator whose AI system's cumulative training computation exceeds the threshold set by Presidential Decree must identify, assess and mitigate risks across the system's life cycle, build a risk management system to monitor and respond to safety incidents caused by the AI, and submit the results of these measures to the Minister of Science and ICT. The threshold and reporting form are set in the Decree.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 22 Jan 2026
Legal requirement
technical documentation
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1702
Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement
technical documentation
·
Colorado (United States)
Colorado ADMT law (SB 26-189)
Developers of automated decision-making technology must provide deployers with the documentation the statute lists, so that deployers can meet their notice, disclosure and review duties.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 1 Jan 2027
Legal requirement
technical documentation
·
European Union
EU AI Act · Article 11 and Annex IV
Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.
Source-linked (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
technical documentation
·
European Union
EU AI Act · Article 6(4); Article 49(2)
A provider that considers a system listed in Annex III to be outside the high-risk tier because it meets one of the Article 6(3) conditions, such as performing a narrow procedural task or only preparing a human assessment, must write down that assessment before placing the system on the market or putting it into service, register the system in the EU database under Article 49(2), and hand over the assessment on request from a national competent authority.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Dec 2027
Legal requirement
technical documentation
·
European Union
EU AI Act · Article 53(1)(a) and 53(1)(b); Annexes XI and XII
Providers of general-purpose AI models must draw up and keep up to date technical documentation covering the training and testing process and evaluation results, as set in Annex XI, and supply it to the AI Office or national authorities on request. They must also keep current the Annex XII information for providers that integrate the model into their own AI systems, so those providers understand its capabilities and limitations and can meet their own duties. Free and open-source models without systemic risk are exempt from both duties.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 2 Aug 2025
Legal requirement
transparency
·
South Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 31(2) and 31(3)
An AI business operator that provides generative AI or a product or service using it must indicate that the output was generated by generative AI. Where the operator provides content such as virtual sound, images or video that is hard to distinguish from reality, it must clearly notify users that the content is AI-generated, in a manner that does not impair a work's artistic or creative expression where that applies. Detailed methods are left to Presidential Decree and ministry guidance.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 22 Jan 2026
Legal requirement
transparency
·
South Korea
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 31(1)
An AI business operator that provides a product or service operated by high-impact AI or by generative AI must notify users in advance that the product or service is based on such AI. The notice is owed before use and is the entry point of the Act's transparency chapter; failure to give it can attract an administrative fine after a corrective order.
Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice)
Applies from 22 Jan 2026
Legal requirement
transparency
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1704
Any developer or deployer that makes an AI system available to consumers that is intended to interact with them must disclose to each consumer that they are interacting with an AI system, unless that would be obvious to a reasonable person. This duty is not limited to high-risk systems and covers chatbots and voice agents offered to Colorado consumers.
Source-linked (a factual check against the official source, not a legal review or legal advice)