Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Source-linked
Applies from 2 Aug 2026
Legal requirement
impact assessment
·
European Union
EU AI Act · Article 27
Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.
Source-linked
Applies from 2 Aug 2026
Legal requirement
impact assessment
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(3)
Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.
Source-linked
Applies from 30 Jun 2026
Legal requirement
public sector use
·
United States
EO 14179 · Section 5
Agency heads were directed to identify actions taken under Executive Order 14110 that are inconsistent with the policy of EO 14179 and to suspend, revise or rescind them, and OMB was directed to revise its federal AI use and procurement memoranda.
Source-linked
Legal requirement
risk management
·
United States
OMB M-25-21 · Section 4
For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.
Source-linked
Legal requirement
risk management
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(2)
Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.
Source-linked
Applies from 30 Jun 2026
Legal requirement
technical documentation
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1702
Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.
Source-linked
Applies from 30 Jun 2026
Legal requirement
transparency
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(4)
Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.
Source-linked
Applies from 30 Jun 2026
Legal requirement
transparency
·
United States
OMB M-25-21 · Section 3
Agencies must inventory their AI use cases annually and publish the inventory, identifying high-impact uses, with limited exclusions.
Source-linked
Voluntary guidance
governance accountability
·
Nepal
Nepal National AI Policy · Policy objectives and strategies (to be confirmed against the official text)
The policy commits the government to ethical, transparent and inclusive AI, data governance and institutional oversight. The specific strategies and any obligations on private actors must be confirmed from the official document; this record intentionally does not state details that could not be verified.
Source-linked
Voluntary guidance
governance accountability
·
United Arab Emirates
UAE AI Strategy 2031 · Strategy objectives on governance and ethics (reviewer to cite the section)
The strategy commits the government to ensure effective governance and regulation of AI and to promote ethical AI, which led to the AI Ethics Principles and Guidelines and the 2024 UAE AI Charter.
Source-linked