Legal requirement
ai literacy
·
European Union
EU AI Act · Article 4
Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, training, the context of use and the persons affected.
Source-linked
Applies from 2 Feb 2025
Legal requirement
data governance
·
European Union
EU AI Act · Article 10
High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate governance practices covering design choices, data collection and origin, preparation, assumptions, availability and suitability, examination for possible biases, and measures to detect, prevent and mitigate bias. Data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete for the intended purpose.
Source-linked
Applies from 2 Aug 2026
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Source-linked
Applies from 2 Aug 2026
Legal requirement
human oversight
·
United Kingdom
ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025
Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.
Source-linked
Legal requirement
human oversight
·
European Union
EU AI Act · Article 14; Article 26(2) for deployers
High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.
Source-linked
Applies from 2 Aug 2026
Legal requirement
human oversight
·
United Arab Emirates
UAE PDPL · Article on data-subject rights relating to automated processing (reviewer to cite article number)
Data subjects may object to decisions based solely on automated processing, including profiling, that produce legal or similarly serious effects, subject to exceptions such as contractual necessity or consent.
Source-linked
Legal requirement
impact assessment
·
United Kingdom
ICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance section
Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.
Source-linked
Legal requirement
impact assessment
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(3)
Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.
Source-linked
Applies from 30 Jun 2026
Legal requirement
post market monitoring
·
European Union
EU AI Act · Article 72
Providers must establish and document a post-market monitoring system proportionate to the nature of the AI technology and its risks, actively and systematically collecting and analysing performance data throughout the system's lifetime, based on a monitoring plan that is part of the technical documentation. The Commission is to adopt a template for the plan.
Source-linked
Applies from 2 Aug 2026
Legal requirement
prohibited practice
·
European Union
EU AI Act · Article 5
Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.
Source-linked
Applies from 2 Feb 2025
Legal requirement
quality management
·
European Union
EU AI Act · Article 17
Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development procedures, testing and validation, technical specifications and standards, data management, the risk-management system, post-market monitoring, incident reporting, communication with authorities, record keeping, resource management and an accountability framework.
Source-linked
Applies from 2 Aug 2026
Legal requirement
risk management
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(2)
Deployers of high-risk AI must implement a risk-management policy and programme governing deployment, specifying principles, processes and personnel used to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination, and reasonable in light of recognised frameworks such as the NIST AI RMF or ISO/IEC 42001.
Source-linked
Applies from 30 Jun 2026
Legal requirement
risk management
·
European Union
EU AI Act · Article 9
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Source-linked
Applies from 2 Aug 2026
Legal requirement
technical documentation
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1702
Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimination, training-data summaries, limitations, performance evaluation and mitigation measures, and information needed for deployer impact assessments, and must publish a public statement describing their high-risk systems and how they manage discrimination risks.
Source-linked
Applies from 30 Jun 2026
Legal requirement
technical documentation
·
European Union
EU AI Act · Article 11 and Annex IV
Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate compliance with the Section 2 requirements and contain at least the elements in Annex IV, including a general description, development process, monitoring and control, risk-management description, and the applied standards. SMEs may use a simplified form provided by the Commission.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(4)
Before a high-risk system makes a consequential decision, deployers must notify the consumer that AI is used, describe its purpose and nature, and provide contact and opt-out information where applicable. After an adverse decision they must state the principal reasons, the data used and its sources, and offer an opportunity to correct data and to appeal for human review where feasible.
Source-linked
Applies from 30 Jun 2026
Legal requirement
transparency
·
European Union
EU AI Act · Article 13
High-risk AI systems must be designed so their operation is sufficiently transparent for deployers to interpret output and use it appropriately, and must be accompanied by instructions for use covering the provider's identity, the system's characteristics, capabilities and limitations, performance for the intended purpose and known foreseeable misuse, human-oversight measures, expected lifetime and maintenance.
Source-linked
Applies from 2 Aug 2026
Voluntary guidance
governance accountability
·
United States
NIST AI RMF · GOVERN function
Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 3, Part 3
AI systems should not undermine legal rights, discriminate unfairly or create unfair market outcomes. The Equality Act 2010 and UK GDPR fairness principle make key parts of this binding.
Source-linked
Voluntary guidance
human oversight
·
Singapore
Singapore Model AI Governance Framework · Second edition, Part on human involvement in AI-augmented decision-making
Using a risk-impact matrix (probability and severity of harm), organisations choose human-in-the-loop, human-over-the-loop or human-out-of-the-loop designs and document the rationale.
Source-linked
Voluntary guidance
human oversight
·
United Kingdom
UK AI regulation framework · Principle 5, Part 3
Affected people should be able to contest harmful AI decisions or outcomes and obtain redress, through existing complaint routes and regulators.
Source-linked
Voluntary guidance
human oversight
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 4, 5 and 6
Test AI models and systems before deployment and monitor them in operation; enable meaningful human control and intervention; and inform end users about AI-enabled decisions, interactions with AI and AI-generated content.
Source-linked
Voluntary guidance
transparency
·
United Kingdom
UK AI regulation framework · Principle 2, Part 3
Organisations should communicate when and how AI is used and provide explanations proportionate to the risk, so that people can understand decisions affecting them. For personal data, UK GDPR transparency and automated decision-making rights make this binding in practice.
Source-linked