AIPolicyTracker

AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

117 results · page 5 of 5

Results

Voluntary guidance governance accountability Australia

Establish accountability processes and a risk-management process (guardrails 1 and 2)

Australian Voluntary AI Safety Standard · Guardrails 1 and 2

Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail 2 asks for a risk-management process to identify and mitigate risks across the AI lifecycle.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance governance accountability Singapore

Establish internal governance structures and measures for AI

Singapore Model AI Governance Framework · Second edition, Part on internal governance structures and measures

Organisations should adapt existing governance to AI: clear roles and responsibilities, board and senior management oversight, risk-management and internal controls, and staff training.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance governance accountability Nepal

Government bodies to promote ethical, responsible and inclusive AI (policy commitment)

Nepal National AI Policy · Policy objectives and strategies (to be confirmed against the official text)

The policy commits the government to ethical, transparent and inclusive AI, data governance and institutional oversight. The specific strategies and any obligations on private actors must be confirmed from the official document; this record intentionally does not state details that could not be verified.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance governance accountability United Arab Emirates

Government commitment to AI ethics, governance and regulation (strategy objective)

UAE AI Strategy 2031 · Strategy objectives on governance and ethics (reviewer to cite the section)

The strategy commits the government to ensure effective governance and regulation of AI and to promote ethical AI, which led to the AI Ethics Principles and Guidelines and the 2024 UAE AI Charter.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance human oversight Singapore

Determine the appropriate level of human involvement in AI decisions

Singapore Model AI Governance Framework · Second edition, Part on human involvement in AI-augmented decision-making

Using a risk-impact matrix (probability and severity of harm), organisations choose human-in-the-loop, human-over-the-loop or human-out-of-the-loop designs and document the rationale.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance human oversight Australia

Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)

Australian Voluntary AI Safety Standard · Guardrails 4, 5 and 6

Test AI models and systems before deployment and monitor them in operation; enable meaningful human control and intervention; and inform end users about AI-enabled decisions, interactions with AI and AI-generated content.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance impact assessment United States

Map context, intended use and potential impacts (Map)

NIST AI RMF · MAP function

Map establishes the context: intended purposes, users, deployment settings, legal requirements, risk categorisation, benefits and costs, and impacts on individuals, groups, communities and society.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance impact assessment South Korea

Operators of high-impact AI should assess its impact on fundamental rights before use

Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 35

An AI business operator that provides high-impact AI, or a product or service using it, is to make efforts to assess in advance the impact the AI may have on people's fundamental rights. The provision is drafted as an endeavour duty rather than a hard requirement, but public bodies procuring high-impact AI are directed to give preference to products that have undergone such an assessment, and the ministry may set assessment methods.

Verified against the official source 26 Sep 2026 (a factual check against the official source, not a legal review or legal advice) Applies from 22 Jan 2026
Voluntary guidance risk management United Kingdom

Ensure AI systems are safe, secure and robust throughout their lifecycle

UK AI regulation framework · Principle 1, Part 3

Regulators are asked to ensure AI systems function in a robust, secure and safe way, with risks continually identified, assessed and managed. In practice this is enforced through existing safety, security and data-protection law rather than a new duty.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance risk management United States

Prioritise, respond to and monitor AI risks (Manage)

NIST AI RMF · MANAGE function

Manage allocates resources to mapped and measured risks, plans responses including decommissioning, manages third-party risks, and documents post-deployment monitoring, incident response and communication.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance safety testing United States

Measure and test trustworthiness characteristics (Measure)

NIST AI RMF · MEASURE function

Measure covers selecting metrics and test methods, evaluating validity, safety, security, resilience, explainability, privacy, fairness and bias, and monitoring these over time, including through independent review and red-teaming for generative AI.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance transparency United Kingdom

Provide appropriate transparency and explainability

UK AI regulation framework · Principle 2, Part 3

Organisations should communicate when and how AI is used and provide explanations proportionate to the risk, so that people can understand decisions affecting them. For personal data, UK GDPR transparency and automated decision-making rights make this binding in practice.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance transparency Singapore

Report incidents and mark AI-generated content (generative AI framework)

Singapore Model AI Governance Framework · Generative AI framework, dimensions on incident reporting and content provenance

The generative-AI framework recommends incident-reporting channels and processes for AI harms, and content provenance measures such as digital watermarking and cryptographic provenance so that users can identify AI-generated content.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Voluntary guidance vendor governance Australia

Provide contestability, supply-chain transparency and records (guardrails 7 to 9)

Australian Voluntary AI Safety Standard · Guardrails 7, 8 and 9

Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, models and systems; and keep and maintain records to allow third parties to assess compliance.

Source-linked (a factual check against the official source, not a legal review or legal advice)
Search

Frequently asked questions

What is an obligation on this site?
A single practical requirement pulled out of an instrument and stated on its own: keep a risk management system, log incidents, document training data, provide human oversight, and so on. Each one cites the article or section it comes from so you can check it against the source.
Does a voluntary obligation have legal force?
No, and every obligation is labelled either a legal requirement or voluntary guidance. Voluntary items still matter in practice, because procurement questionnaires and auditors ask about them, but only the binding ones carry legal consequence.
How do I find the obligations that apply to my organisation?
Filter by jurisdiction, category, actor, sector or use case. The applicability check asks a short set of questions and returns the duties that may reach you. It is an educational screen, not a legal determination, and it says so.
Why do some instruments have no obligations listed?
Because nobody has broken them out yet. Most instruments are recorded at summary level first; obligations are added jurisdiction by jurisdiction. The coverage and open-gaps pages publish exactly what is missing rather than hiding it.