AIPolicyTracker

AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

117 results · page 4 of 5

Results

Legal requirement transparency European Union

Deployers must disclose deepfakes and AI-generated text published on matters of public interest

EU AI Act · Article 50(4)

A deployer that generates or manipulates image, audio or video content that is a deep fake must disclose that the content has been artificially generated or manipulated, with lighter treatment for evidently artistic, creative, satirical or fictional works so that the disclosure does not spoil the work. A deployer that publishes AI-generated text to inform the public on matters of public interest must disclose this unless the text passed human review or editorial control and someone holds editorial responsibility. The disclosure must reach people clearly at the latest at first exposure.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement transparency European Union

Deployers must explain individual decisions taken with high-risk AI on request

EU AI Act · Article 86

A person affected by a decision that a deployer took on the basis of the output of an Annex III high-risk AI system, other than critical-infrastructure systems, which produces legal effects or similarly significantly affects them in a way they consider adverse to their health, safety or fundamental rights, has the right to obtain from the deployer clear and meaningful explanations of the role the system played in the decision and the main elements of the decision. The right does not apply where Union or national law provides an exception.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement transparency Colorado (United States)

Deployers must publish a statement about the high-risk AI systems they use

Colorado AI Act · C.R.S. 6-1-1703(5)

A deployer must make available on its website, or in another public way, a clear and readily available statement summarising the types of high-risk AI systems it currently deploys, how it manages known or reasonably foreseeable risks of algorithmic discrimination from those systems, and the nature, source and extent of the information it collects and uses. The statement must be updated periodically.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement transparency European Union

Deployers must tell natural persons that a high-risk AI system is used in decisions about them

EU AI Act · Article 26(11)

Deployers of Annex III high-risk AI systems that take decisions about natural persons, or help take them, must inform those persons that they are subject to the system. The notice is separate from any explanation owed under Article 86 and from the worker notice in Article 26(7). In law-enforcement contexts the duty follows the information rules of the Law Enforcement Directive.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement transparency European Union

Deployers of emotion recognition or biometric categorisation must inform exposed persons

EU AI Act · Article 50(3)

A deployer of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it that the system is operating and must process their personal data in line with the GDPR, the Law Enforcement Directive and the EU institutions data protection regulation. Systems permitted by law to detect, prevent or investigate criminal offences are excepted, subject to safeguards. Use in workplaces and schools is separately banned by Article 5 except for medical or safety reasons.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement transparency European Union

Disclose AI interaction and label synthetic content

EU AI Act · Article 50

Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Aug 2026
Legal requirement transparency Colorado (United States)

Disclose the use of the technology and the principal reasons after an adverse consequential decision

Colorado ADMT law (SB 26-189)

After an adverse consequential decision, the deployer must tell the consumer that automated decision-making technology was used, give the principal reasons for the decision, and explain how to obtain human review.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2027
Legal requirement transparency New York (United States)

Employers and employment agencies must notify candidates and employees before an automated tool is used

NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(b)(1) and (b)(2); 6 RCNY Section 5-303

Candidates and employees who reside in New York City must be told, at least ten business days before an automated employment decision tool is used to assess them, that such a tool will be used in the hiring or promotion decision, and which job qualifications and characteristics the tool will assess. The DCWP rules allow the notice to be given on the careers page, in the job posting, or by mail or email, and require that it reach the person before the tool is applied.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 5 Jul 2023
Legal requirement transparency New York (United States)

Employers and employment agencies must publish a summary of the bias audit results

NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(a)(2); 6 RCNY Section 5-302

Before using an automated employment decision tool, the employer or employment agency must make a summary of the most recent bias audit results and the distribution date of the tool publicly available on the employment section of its website. Under the DCWP rules the summary states the audit date, the data source and type, the number of applicants or candidates in each category, and the selection or scoring rates and impact ratios, and must remain posted for at least six months after the tool was last used.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 5 Jul 2023
Legal requirement transparency European Union

Employers must inform workers and their representatives before using high-risk AI at work

EU AI Act · Article 26(7)

Before putting a high-risk AI system into service or using it at the workplace, a deployer that is an employer must tell the workers' representatives and the affected workers that they will be subject to the system. The information is given following the procedures and rules on informing workers and their representatives under Union and national law and practice, which may include works-council consultation.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement transparency California (United States)

Frontier developers must publish a transparency report before deploying a new frontier model

California SB 53 · Business and Professions Code Section 22757.12 (as added by SB 53)

Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its website describing the model, its intended uses and restrictions, the release date and modalities, and how to contact the developer. A large frontier developer must add a summary of its catastrophic-risk assessment for the model, the results, any third-party evaluators involved and the steps taken under its frontier AI framework, with trade-secret and security redactions explained.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement transparency Texas (United States)

Government agencies must disclose to consumers that they are interacting with an AI system

Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.051

A governmental agency that makes an AI system available to interact with consumers must disclose to each consumer, before or at the time of the interaction, that they are interacting with an AI system. The disclosure is owed even where the AI nature of the interaction would be obvious, must be clear and conspicuous, written in plain language and may not use a dark pattern; a hyperlink to the disclosure is acceptable for online services.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement transparency Texas (United States)

Health-care providers must disclose the use of AI in patient services

Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.051

A person who provides health-care services or treatment and uses an AI system in relation to those services must disclose that use to the patient, or to the patient's personal representative or guardian, no later than the date the service or treatment is first provided, with an exception for emergencies where the disclosure is made as soon as reasonably possible. The disclosure must be clear, conspicuous and in plain language.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2026
Legal requirement transparency Colorado (United States)

Notify consumers and explain adverse consequential decisions

Colorado AI Act · C.R.S. 6-1-1703(4)

Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement transparency Colorado (United States)

Notify consumers before automated decision-making technology influences a consequential decision

Colorado ADMT law (SB 26-189)

Deployers must tell a consumer, before the decision is made, that automated decision-making technology will be used to make or materially influence a consequential decision about them. The exact content and timing of the notice follow the enrolled bill, which a reviewer must read.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 1 Jan 2027
Legal requirement transparency Singapore

Notify individuals about the use of personal data in AI recommendations and decisions

PDPC AI advisory guidelines · Advisory guidelines, section on notification obligation

Organisations should inform individuals that AI systems use their personal data, the purposes, the relevant features and how they influence decisions, proportionate to the impact on the individual.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement transparency South Korea

Operators of high-impact AI must be able to explain outputs and the main criteria behind them

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)

Operators of high-impact AI must put in place measures to explain the AI's final results, the main criteria used to reach them, and an overview of the training data, to the extent that this is technically feasible. The duty targets explainability of the system's decisions to users and affected people rather than full disclosure of the model.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Legal requirement transparency European Union

Provide deployers with clear instructions for use

EU AI Act · Article 13

High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement transparency European Union

Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way

EU AI Act · Article 50(2)

Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust and reliable as far as the state of the art allows, taking account of content type and cost. Systems that only perform assistive editing or do not substantially alter the input, and law-authorised criminal-detection uses, are outside the duty.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement transparency United States

Publish an annual AI use-case inventory

OMB M-25-21 · Section 3

Agencies must inventory their AI use cases annually and publish the inventory, identifying high-impact uses, with limited exclusions.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Legal requirement vendor governance European Union

Providers of high-risk AI must have written agreements with suppliers of components, tools and services

EU AI Act · Article 25(4)

A provider of a high-risk AI system and any third party that supplies AI systems, tools, services, components or processes used in or integrated into it must set out, in a written agreement, the information, capabilities, technical access and other assistance needed for the provider to meet its obligations, based on the generally acknowledged state of the art. Suppliers of free and open-source tools and components other than general-purpose AI models are outside this duty. The AI Office may publish voluntary model terms.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Legal requirement vendor governance European Union

Verify conformity before importing or distributing high-risk AI

EU AI Act · Articles 23 and 24

Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.

Source-linked (a factual check against the official source, not a legal review or legal advice) Applies from 2 Dec 2027
Voluntary guidance governance accountability India

Adopt the guiding principles and risk-based governance (voluntary)

India AI Governance Guidelines · Guiding principles and recommendations sections

The guidelines encourage organisations to embed principles such as fairness, accountability, safety and transparency, to classify and mitigate risks proportionately, and to participate in voluntary frameworks and incident reporting.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance governance accountability United States

Establish AI governance policies, roles and accountability (Govern)

NIST AI RMF · GOVERN function

Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Search

Frequently asked questions

What is an obligation on this site?
A single practical requirement pulled out of an instrument and stated on its own: keep a risk management system, log incidents, document training data, provide human oversight, and so on. Each one cites the article or section it comes from so you can check it against the source.
Does a voluntary obligation have legal force?
No, and every obligation is labelled either a legal requirement or voluntary guidance. Voluntary items still matter in practice, because procurement questionnaires and auditors ask about them, but only the binding ones carry legal consequence.
How do I find the obligations that apply to my organisation?
Filter by jurisdiction, category, actor, sector or use case. The applicability check asks a short set of questions and returns the duties that may reach you. It is an educational screen, not a legal determination, and it says so.
Why do some instruments have no obligations listed?
Because nobody has broken them out yet. Most instruments are recorded at summary level first; obligations are added jurisdiction by jurisdiction. The coverage and open-gaps pages publish exactly what is missing rather than hiding it.