Legal requirement
conformity assessment
·
European Union
EU AI Act · Articles 43, 47, 48 and 49; Annex VIII
Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depending on the system), draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. Deployers that are public authorities must also register their use of Annex III systems.
Source-linked
Applies from 2 Aug 2026
Legal requirement
governance accountability
·
European Union
EU AI Act · Article 26
Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input data is relevant where they control it, monitor operation, inform the provider and authorities of risks or serious incidents, keep logs, inform workers' representatives before deploying at the workplace, inform affected natural persons where decisions are made about them, and cooperate with authorities.
Source-linked
Applies from 2 Aug 2026
Legal requirement
human oversight
·
United Kingdom
ICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025
Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.
Source-linked
Legal requirement
human oversight
·
European Union
EU AI Act · Article 14; Article 26(2) for deployers
High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avoid automation bias, interpret output, decide not to use the system, and intervene or stop it. Deployers must assign oversight to people with the necessary competence, training and authority. For certain remote biometric identification systems, action requires verification by at least two competent persons.
Source-linked
Applies from 2 Aug 2026
Legal requirement
impact assessment
·
European Union
EU AI Act · Article 27
Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.
Source-linked
Applies from 2 Aug 2026
Legal requirement
record keeping
·
European Union
EU AI Act · Article 12; Article 26(6) for deployers
High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operational monitoring. Deployers must keep the logs generated by the system, to the extent under their control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise.
Source-linked
Applies from 2 Aug 2026
Legal requirement
risk management
·
United States
OMB M-25-21 · Section 4
For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.
Source-linked
Legal requirement
risk management
·
European Union
EU AI Act · Article 9
Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: identifying known and reasonably foreseeable risks to health, safety and fundamental rights, estimating and evaluating risks including from reasonably foreseeable misuse, evaluating post-market data, and adopting targeted risk-management measures, with testing before placing on the market.
Source-linked
Applies from 2 Aug 2026
Legal requirement
transparency
·
United States
OMB M-25-21 · Section 3
Agencies must inventory their AI use cases annually and publish the inventory, identifying high-impact uses, with limited exclusions.
Source-linked
Voluntary guidance
governance accountability
·
United Kingdom
UK AI regulation framework · Principle 4, Part 3
Governance measures should ensure effective oversight of AI supply and use with clear lines of accountability across the lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 1 and 2
Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail 2 asks for a risk-management process to identify and mitigate risks across the AI lifecycle.
Source-linked
Voluntary guidance
governance accountability
·
Nepal
Nepal National AI Policy · Policy objectives and strategies (to be confirmed against the official text)
The policy commits the government to ethical, transparent and inclusive AI, data governance and institutional oversight. The specific strategies and any obligations on private actors must be confirmed from the official document; this record intentionally does not state details that could not be verified.
Source-linked
Voluntary guidance
governance accountability
·
United Arab Emirates
UAE AI Strategy 2031 · Strategy objectives on governance and ethics (reviewer to cite the section)
The strategy commits the government to ensure effective governance and regulation of AI and to promote ethical AI, which led to the AI Ethics Principles and Guidelines and the 2024 UAE AI Charter.
Source-linked
Voluntary guidance
human oversight
·
United Kingdom
UK AI regulation framework · Principle 5, Part 3
Affected people should be able to contest harmful AI decisions or outcomes and obtain redress, through existing complaint routes and regulators.
Source-linked
Voluntary guidance
impact assessment
·
United States
NIST AI RMF · MAP function
Map establishes the context: intended purposes, users, deployment settings, legal requirements, risk categorisation, benefits and costs, and impacts on individuals, groups, communities and society.
Source-linked
Voluntary guidance
transparency
·
United Kingdom
UK AI regulation framework · Principle 2, Part 3
Organisations should communicate when and how AI is used and provide explanations proportionate to the risk, so that people can understand decisions affecting them. For personal data, UK GDPR transparency and automated decision-making rights make this binding in practice.
Source-linked
Voluntary guidance
vendor governance
·
Australia
Australian Voluntary AI Safety Standard · Guardrails 7, 8 and 9
Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, models and systems; and keep and maintain records to allow third parties to assess compliance.
Source-linked