AI compliance obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

21 results

Legal requirement ai literacy European Union

Ensure AI literacy of staff operating AI systems

EU AI Act · Article 4

Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.

Source-linked Applies from 2 Feb 2025
Legal requirement copyright training data European Union

Meet general-purpose AI model provider obligations

EU AI Act · Article 53 and Annexes XI–XII

Providers of general-purpose AI models must keep technical documentation (Annex XI), provide information to downstream providers integrating the model (Annex XII), put in place a policy to comply with EU copyright law including the text-and-data-mining opt-out, and publish a sufficiently detailed public summary of training content using the Commission's template. Free and open-source models are exempt from the first two duties unless they present systemic risk. Adherence to the General-Purpose AI Code of Practice can demonstrate compliance.

Source-linked Applies from 2 Aug 2025
Legal requirement incident handling India

Implement reasonable security safeguards and notify breaches

India DPDP Act · Section 8(5) and 8(6); DPDP Rules on breach intimation

Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.

Source-linked
Legal requirement safety testing California (United States)

Large frontier developers must publish a frontier AI framework

California SB 53 · Business and Professions Code, Chapter 25.1 (as added by SB 53)

Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, apply mitigations, secure model weights, and govern internal processes, and must review it at least annually.

Source-linked Applies from 1 Jan 2026
Legal requirement safety testing European Union

Manage systemic risk for high-impact general-purpose models

EU AI Act · Articles 51, 52 and 55

A general-purpose model is presumed to have systemic risk when the cumulative compute used for training exceeds 10^25 floating-point operations, or when the Commission designates it. Providers must notify the Commission, perform model evaluations including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure adequate cybersecurity for the model and infrastructure.

Source-linked Applies from 2 Aug 2025
Legal requirement transparency European Union

Disclose AI interaction and label synthetic content

EU AI Act · Article 50

Providers must ensure AI systems intended to interact with people inform them they are dealing with AI unless obvious; providers of systems generating synthetic audio, image, video or text must mark output in a machine-readable, detectable format; deployers of emotion-recognition or biometric-categorisation systems must inform exposed persons; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, subject to exceptions.

Source-linked Applies from 2 Aug 2026
Search