Legal requirement
ai literacy
·
European Union
EU AI Act · Article 4
Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.
Source-linked
Applies from 2 Feb 2025
Legal requirement
copyright training data
·
European Union
EU AI Act · Article 53 and Annexes XI–XII
Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XII), put in place a policy to comply with EU copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed public summary of training content using the Commission's template. Free and open-source models are exempt from the first two duties unless they present systemic risk. Adherence to the General-Purpose AI Code of Practice can demonstrate compliance.
Source-linked
Applies from 2 Aug 2025
Legal requirement
impact assessment
·
United Arab Emirates
UAE PDPL · Article on data protection impact assessment (reviewer to cite article number)
Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, covering the processing, its purposes, risks and safeguards.
Source-linked
Legal requirement
impact assessment
·
India
India DPDP Act · Section 10
Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.
Source-linked
Legal requirement
incident handling
·
India
India DPDP Act · Section 8(5) and 8(6); DPDP Rules on breach intimation
Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.
Source-linked
Legal requirement
incident handling
·
California (United States)
California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)
Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and the Office is to establish a reporting mechanism.
Source-linked
Applies from 1 Jan 2026
Legal requirement
privacy data protection
·
India
India DPDP Act · Sections 4 to 7
Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses listed in the Act. A notice must describe the data, purpose, and how to exercise rights and complain.
Source-linked
Legal requirement
safety testing
·
California (United States)
California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)
Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, apply mitigations, secure model weights, and govern internal processes, and must review it at least annually.
Source-linked
Applies from 1 Jan 2026
Legal requirement
safety testing
·
European Union
EU AI Act · Articles 51, 52 and 55
A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.
Source-linked
Applies from 2 Aug 2025
Legal requirement
transparency
·
European Union
EU AI Act · Article 50
Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.
Source-linked
Applies from 2 Aug 2026
Voluntary guidance
data governance
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on operations management
Covers data lineage and quality, minimising bias in datasets, model explainability, repeatability, robustness, regular tuning and active monitoring after deployment.
Source-linked
Voluntary guidance
governance accountability
·
India
India AI Governance Guidelines · Guiding principles and recommendations sections
The guidelines encourage organisations to embed principles such as fairness, accountability, safety and transparency, to classify and mitigate risks proportionately, and to participate in voluntary frameworks and incident reporting.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 4, Part 3
Governance measures should ensure effective oversight of AI supply and use with clear lines of accountability across the lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 1 and 2
Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail 2 asks for a risk-management process to identify and mitigate risks across the AI lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
United States
NIST AI RMF · GOVERN function
Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.
Source-linked
Voluntary guidance
governance accountability
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on internal governance structures and measures
Organisations should adapt existing governance to AI: clear roles and responsibilities, board and senior management oversight, risk-management and internal controls, and staff training.
Source-linked
Voluntary guidance
impact assessment
·
United States
NIST AI RMF · MAP function
Map establishes the context: intended purposes, users, deployment settings, legal requirements, risk categorisation, benefits and costs, and impacts on individuals, groups, communities and society.
Source-linked
Voluntary guidance
risk management
·
United Kingdom
UK AI regulation framework · Principle 1, Part 3
Regulators are asked to ensure AI systems function in a robust, secure and safe way, with risks continually identified, assessed and managed. In practice this is enforced through existing safety, security and data-protection law rather than a new duty.
Source-linked
Voluntary guidance
risk management
·
United States
NIST AI RMF · MANAGE function
Manage allocates resources to mapped and measured risks, plans responses including decommissioning, manages third-party risks, and documents post-deployment monitoring, incident response and communication.
Source-linked
Voluntary guidance
safety testing
·
United States
NIST AI RMF · MEASURE function
Measure covers selecting metrics and test methods, evaluating validity, safety, security, resilience, explainability, privacy, fairness and bias, and monitoring these over time, including through independent review and red-teaming for generative AI.
Source-linked
Voluntary guidance
transparency
·
Singapore
Singapore Model AI Governance Framework · Generative AI framework, dimensions on incident reporting and content provenance
The generative-AI framework recommends incident-reporting channels and processes for AI harms, and content provenance measures such as digital watermarking and cryptographic provenance so that users can identify AI-generated content.
Source-linked