AI policy explorer

Search and filter source-backed AI laws, regulations, standards, guidance and consultations. Each record shows its status, key dates, verification state and official source.

50 results · page 1 of 3

United States Framework Voluntary standard

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Adopted 26 Jan 2023 Source-linked Official source
New York (United States) Act / statute Adopted Binding

New York RAISE Act (frontier model safety)

New York Responsible AI Safety and Education (RAISE) Act (S.6953-B / A.6453-B, signed December 2025)

The RAISE Act requires large developers of frontier AI models (defined by training compute and revenue thresholds) to publish and follow a safety and security protocol, report critical safety incidents to the state within a set period, not deploy models that create unreasonable risk of critical harm, and submit to Attorney General enforcement with civil penalties; the chapter amendments create a state oversight office and align definitions with California's Transparency in Frontier AI Act.

Applies from 1 Jan 2027 Source-linked · checked 11 Sep 2026 Official source
United States Guidance In force Binding

OMB M-25-21

OMB Memorandum M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

M-25-21 directs US federal agencies on how to govern and use AI. It requires agencies to designate Chief AI Officers, maintain AI governance boards, publish AI use-case inventories, and apply minimum risk-management practices to "high-impact" AI, including pre-deployment testing, AI impact assessments, ongoing monitoring, human oversight and training, and remedies for affected individuals. It replaced the 2024 memoranda with a greater emphasis on adoption and innovation while retaining core risk practices.

In force 3 Apr 2025 Source-linked Official source
Utah (United States) Act / statute In force Binding

Utah Artificial Intelligence Policy Act (SB 149)

Utah Artificial Intelligence Policy Act (SB 149, 2024, as amended by SB 226 and SB 332 in 2025)

Effective 1 May 2024, the Act requires a person using generative AI to interact with a consumer in a consumer transaction to disclose clearly that the consumer is interacting with AI when asked (as amended in 2025, when the interaction is high-risk or on request), and requires providers of regulated occupations (for example health and legal services) to disclose generative-AI use proactively. It states that using AI is no defence to consumer-protection violations, created the Office of Artificial Intelligence Policy and an AI learning laboratory allowing regulatory mitigation agreements, and originally sunset in 2025, extended to 2027.

Applies from 1 May 2024 Source-linked · checked 11 Sep 2026 Official source
United States Executive order In force Binding

EO 14179

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179, signed 23 January 2025, sets US federal policy to sustain and enhance American AI dominance, directs the development of an AI Action Plan within 180 days, and orders agencies to review and revise or rescind actions taken under the revoked Executive Order 14110 that are inconsistent with the new policy. It also called for revision of the OMB memoranda governing federal agency use and procurement of AI, which OMB replaced in April 2025 with M-25-21 and M-25-22.

In force 23 Jan 2025 Source-linked Official source
Texas (United States) Act / statute In force Binding

Texas Responsible AI Governance Act (TRAIGA)

Texas Responsible Artificial Intelligence Governance Act (HB 149, 89th Legislature)

Signed on 22 June 2025 and effective 1 January 2026, TRAIGA bans developing or deploying AI systems intended to manipulate people into self-harm or crime, government social scoring, biometric identification by government from public data without consent, intentional unlawful discrimination against protected classes, and production of child sexual abuse material or unlawful sexual deepfakes. State agencies and health-care providers must disclose AI interactions. It creates a 36-month regulatory sandbox administered by the Department of Information Resources, a Texas Artificial Intelligence Council, and gives the Attorney General exclusive enforcement with civil penalties after a 60-day cure period; disparate impact alone does not prove intent to discriminate.

Applies from 1 Jan 2026 Source-linked · checked 11 Sep 2026 Official source
Tennessee (United States) Act / statute In force Binding

Tennessee ELVIS Act

Ensuring Likeness, Voice, and Image Security (ELVIS) Act of 2024 (Tennessee Public Chapter 588)

Signed 21 March 2024 and effective 1 July 2024, the ELVIS Act updates Tennessee's Personal Rights Protection Act to add voice to the protected attributes of name, photograph and likeness, prohibits publishing or making available an individual's voice or likeness without authorisation, and creates liability for distributing or making available an algorithm, software or tool whose primary purpose is producing an individual's voice or likeness without authorisation. It provides civil actions for individuals and licensees and criminal penalties.

In force 1 Jul 2024 Source-linked · checked 11 Sep 2026 Official source
New York (United States) Act / statute In force Binding

NYC Local Law 144 (automated employment decision tools)

New York City Local Law 144 of 2021 on Automated Employment Decision Tools (AEDT) and DCWP implementing rules

Employers and employment agencies may not use an automated employment decision tool to screen candidates or employees for hiring or promotion in New York City unless the tool has had an independent bias audit within the past year, a summary of the audit results is published, and candidates receive at least ten business days' notice of the tool's use, the job qualifications assessed, and how to request an alternative process or accommodation. The bias audit calculates selection and scoring impact ratios by sex, race/ethnicity and intersectional categories. Enforcement began 5 July 2023.

Applies from 5 Jul 2023 Source-linked · checked 11 Sep 2026 Official source
Colorado (United States) Act / statute Adopted Binding

Colorado AI Act

Colorado Senate Bill 24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act)

The Colorado AI Act requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. High-risk systems are those that make, or are a substantial factor in making, consequential decisions about education, employment, financial or lending services, essential government services, healthcare, housing, insurance or legal services. Deployers must run risk-management programmes and impact assessments, notify consumers, and explain adverse decisions; developers must document systems and disclose known risks.

Applies from 30 Jun 2026 Source-linked Official source
United Kingdom Guidance Guidance

ICO AI guidance

ICO Guidance on AI and data protection

The ICO's guidance explains how UK GDPR and the Data Protection Act 2018 apply when organisations develop or use AI that processes personal data. It covers accountability and governance, lawfulness and fairness, transparency, data minimisation, security, individual rights, and automated decision-making. The guidance is not itself law, but it reflects how the regulator interprets binding obligations and is the reference point in ICO enforcement.

Source-linked Official source
California (United States) Act / statute In force Binding

California SB 53

California SB 53: Transparency in Frontier Artificial Intelligence Act

SB 53 requires "large frontier developers" (developers of the most compute-intensive models above statutory thresholds) to publish a frontier AI framework describing how they assess and mitigate catastrophic risks, publish transparency reports when deploying new frontier models, report critical safety incidents to the California Office of Emergency Services, and protect employees who report safety concerns. It also directs creation of a public computing cluster ("CalCompute").

Applies from 1 Jan 2026 Source-linked Official source
United Kingdom Policy Guidance

UK AI regulation framework

A pro-innovation approach to AI regulation (white paper and government response)

The UK white paper sets out a principles-based, context-specific approach to regulating AI. Instead of a single AI law, it asks existing regulators to interpret and apply five cross-cutting principles within their remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Central government provides coordination, monitoring and guidance.

Adopted 29 Mar 2023 Source-linked Official source
United Arab Emirates National strategy Adopted

UAE AI Strategy 2031

UAE National Strategy for Artificial Intelligence 2031

The UAE National Strategy for AI 2031 aims to position the UAE as a global leader in AI by 2031. It sets objectives across priority sectors, AI talent and research, data and infrastructure, government adoption and governance, including a commitment to AI ethics and to developing appropriate regulation. It is a strategy document that guides government programmes and does not itself impose obligations on private organisations.

Adopted 16 Oct 2017 Source-linked Official source
Taiwan Bill Proposed Binding

Artificial Intelligence Basic Act (draft)

人工智慧基本法 (Artificial Intelligence Basic Act) – draft approved by the Executive Yuan, July 2024

A framework act setting seven principles for AI development and use, requiring the government to promote AI research, talent and infrastructure, to establish a risk-classification framework and safety standards, to protect personal data, labour and consumers, to provide for liability, disclosure of AI-generated content and non-discrimination, and to designate competent authorities by sector, with the NSTC coordinating.

Adopted 15 Jul 2024 Source-linked · checked 11 Sep 2026 Official source
United Arab Emirates Act / statute In force Binding

UAE PDPL

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)

The UAE Personal Data Protection Law is the federal data-protection law applying outside the DIFC and ADGM free zones. It sets principles for lawful processing, consent and its exceptions, data-subject rights (including the right to object to automated decision-making without human intervention), controller and processor duties, security and breach notification to the UAE Data Office, cross-border transfer rules, and data protection impact assessments for high-risk processing including new technologies.

In force 2 Jan 2022 Source-linked Official source
Türkiye Bill Proposed Binding

Draft Artificial Intelligence Law (2024)

Yapay Zekâ Kanunu Teklifi (Artificial Intelligence Law proposal submitted to the Grand National Assembly, June 2024)

A short framework bill proposing principles for AI (safety, transparency, fairness, accountability, privacy), a risk-based approach with registration of high-risk systems, operator obligations and penalties, and supervision by designated authorities, broadly modelled on the EU AI Act.

Source-linked · checked 11 Sep 2026 Official source
Singapore Framework Voluntary standard

Singapore Model AI Governance Framework

Model AI Governance Framework (Second Edition) and Model AI Governance Framework for Generative AI

Singapore's Model AI Governance Framework is a voluntary, sector-agnostic guide for organisations deploying AI. The second edition (January 2020) covers four areas: internal governance structures and measures, determining the level of human involvement in AI-augmented decision-making, operations management (data, model development, monitoring), and stakeholder interaction and communication. The May 2024 Model AI Governance Framework for Generative AI extends it with nine dimensions including accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for the public good.

Adopted 21 Jan 2020 Source-linked Official source
Spain Regulation In force Binding

Royal Decree 729/2023 (AESIA statute)

Real Decreto 729/2023, de 22 de agosto, por el que se aprueba el Estatuto de la Agencia Española de Supervisión de Inteligencia Artificial

Creates and organises AESIA, the Spanish AI Supervision Agency, as a public body attached to the Ministry for Digital Transformation. AESIA supervises and inspects AI systems, promotes sandboxes and standards, and acts as national authority for the EU AI Act. The decree sets its governance, functions and funding.

In force 3 Sep 2023 Source-linked · checked 11 Sep 2026 Official source
Spain Regulation In force Binding

Royal Decree 817/2023 (AI regulatory sandbox)

Real Decreto 817/2023, de 8 de noviembre, que establece un entorno controlado de pruebas para el ensayo del cumplimiento de la propuesta de Reglamento de IA

Establishes Spain's controlled testing environment (sandbox) for providers of high-risk AI systems to test compliance with the then-proposed EU AI Act requirements: risk management, data governance, documentation, transparency, human oversight, accuracy and robustness. Participation is voluntary; participants receive guidance and produce documentation that feeds into national implementation.

In force 10 Nov 2023 Source-linked · checked 11 Sep 2026 Official source
Singapore Guidance Guidance

PDPC AI advisory guidelines

PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems

These advisory guidelines explain how the Personal Data Protection Act applies when organisations use personal data to develop, test and deploy AI systems that make recommendations, predictions or decisions. They clarify the consent obligation and relevant exceptions (business improvement and research), what to include in notifications to individuals, accountability practices such as documenting data provenance and model development, and expectations for service providers building bespoke AI systems.

Adopted 1 Mar 2024 Source-linked Official source
Search