AI policy explorer

Search and filter source-backed AI laws, regulations, standards, guidance and consultations. Each record shows its status, key dates, verification state and official source.

19 results

Tennessee (United States) Act / statute In force Binding

Tennessee ELVIS Act

Ensuring Likeness, Voice, and Image Security (ELVIS) Act of 2024 (Tennessee Public Chapter 588)

Signed 21 March 2024 and effective 1 July 2024, the ELVIS Act updates Tennessee's Personal Rights Protection Act to add voice to the protected attributes of name, photograph and likeness, prohibits publishing or making available an individual's voice or likeness without authorisation, and creates liability for distributing or making available an algorithm, software or tool whose primary purpose is producing an individual's voice or likeness without authorisation. It provides civil actions for individuals and licensees and criminal penalties.

In force 1 Jul 2024 Source-linked · checked 11 Sep 2026 Official source
United States Framework Voluntary standard

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Adopted 26 Jan 2023 Source-linked Official source
United States Executive order In force Binding

EO 14179

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179, signed 23 January 2025, sets US federal policy to sustain and enhance American AI dominance, directs the development of an AI Action Plan within 180 days, and orders agencies to review and revise or rescind actions taken under the revoked Executive Order 14110 that are inconsistent with the new policy. It also called for revision of the OMB memoranda governing federal agency use and procurement of AI, which OMB replaced in April 2025 with M-25-21 and M-25-22.

In force 23 Jan 2025 Source-linked Official source
United States Guidance In force Binding

OMB M-25-21

OMB Memorandum M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

M-25-21 directs US federal agencies on how to govern and use AI. It requires agencies to designate Chief AI Officers, maintain AI governance boards, publish AI use-case inventories, and apply minimum risk-management practices to "high-impact" AI, including pre-deployment testing, AI impact assessments, ongoing monitoring, human oversight and training, and remedies for affected individuals. It replaced the 2024 memoranda with a greater emphasis on adoption and innovation while retaining core risk practices.

In force 3 Apr 2025 Source-linked Official source
United Kingdom Guidance Guidance

ICO AI guidance

ICO Guidance on AI and data protection

The ICO's guidance explains how UK GDPR and the Data Protection Act 2018 apply when organisations develop or use AI that processes personal data. It covers accountability and governance, lawfulness and fairness, transparency, data minimisation, security, individual rights, and automated decision-making. The guidance is not itself law, but it reflects how the regulator interprets binding obligations and is the reference point in ICO enforcement.

Source-linked Official source
United Kingdom Policy Guidance

UK AI regulation framework

A pro-innovation approach to AI regulation (white paper and government response)

The UK white paper sets out a principles-based, context-specific approach to regulating AI. Instead of a single AI law, it asks existing regulators to interpret and apply five cross-cutting principles within their remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Central government provides coordination, monitoring and guidance.

Adopted 29 Mar 2023 Source-linked Official source
United Arab Emirates Act / statute In force Binding

UAE PDPL

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)

The UAE Personal Data Protection Law is the federal data-protection law applying outside the DIFC and ADGM free zones. It sets principles for lawful processing, consent and its exceptions, data-subject rights (including the right to object to automated decision-making without human intervention), controller and processor duties, security and breach notification to the UAE Data Office, cross-border transfer rules, and data protection impact assessments for high-risk processing including new technologies.

In force 2 Jan 2022 Source-linked Official source
United Arab Emirates National strategy Adopted

UAE AI Strategy 2031

UAE National Strategy for Artificial Intelligence 2031

The UAE National Strategy for AI 2031 aims to position the UAE as a global leader in AI by 2031. It sets objectives across priority sectors, AI talent and research, data and infrastructure, government adoption and governance, including a commitment to AI ethics and to developing appropriate regulation. It is a strategy document that guides government programmes and does not itself impose obligations on private organisations.

Adopted 16 Oct 2017 Source-linked Official source
Taiwan Bill Proposed Binding

Artificial Intelligence Basic Act (draft)

人工智慧基本法 (Artificial Intelligence Basic Act) – draft approved by the Executive Yuan, July 2024

A framework act setting seven principles for AI development and use, requiring the government to promote AI research, talent and infrastructure, to establish a risk-classification framework and safety standards, to protect personal data, labour and consumers, to provide for liability, disclosure of AI-generated content and non-discrimination, and to designate competent authorities by sector, with the NSTC coordinating.

Adopted 15 Jul 2024 Source-linked · checked 11 Sep 2026 Official source
Singapore Guidance Guidance

PDPC AI advisory guidelines

PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems

These advisory guidelines explain how the Personal Data Protection Act applies when organisations use personal data to develop, test and deploy AI systems that make recommendations, predictions or decisions. They clarify the consent obligation and relevant exceptions (business improvement and research), what to include in notifications to individuals, accountability practices such as documenting data provenance and model development, and expectations for service providers building bespoke AI systems.

Adopted 1 Mar 2024 Source-linked Official source
Singapore Framework Voluntary standard

Singapore Model AI Governance Framework

Model AI Governance Framework (Second Edition) and Model AI Governance Framework for Generative AI

Singapore's Model AI Governance Framework is a voluntary, sector-agnostic guide for organisations deploying AI. The second edition (January 2020) covers four areas: internal governance structures and measures, determining the level of human involvement in AI-augmented decision-making, operations management (data, model development, monitoring), and stakeholder interaction and communication. The May 2024 Model AI Governance Framework for Generative AI extends it with nine dimensions including accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for the public good.

Adopted 21 Jan 2020 Source-linked Official source
Nepal Policy Adopted

Nepal National AI Policy

National Artificial Intelligence Policy, 2082 (2025) — Nepal

Nepal's National AI Policy sets the government's direction for developing and using artificial intelligence. Based on the published summaries, it aims to build AI infrastructure and skills, promote ethical and responsible AI, strengthen data governance, establish institutional arrangements for AI oversight, and prepare legal and regulatory measures. It is a policy framework, not a law, and does not itself create enforceable obligations on private organisations.

Adopted 1 Aug 2025 Source-linked Official source
Nepal Act / statute In force Binding

Nepal Privacy Act 2075

Individual Privacy Act, 2075 (2018) — Nepal

The Individual Privacy Act 2075 gives effect to the constitutional right to privacy in Nepal. It regulates the collection, storage, processing, use and disclosure of personal information by public bodies and private entities, requires consent for collection and use of personal data subject to exceptions, restricts sensitive data, and provides remedies and penalties. It is the main binding law affecting AI systems that process personal data in Nepal. The Individual Privacy Regulation 2077 (2020) provides implementing rules.

In force 18 Sep 2018 Source-linked Official source
Italy Act / statute In force Binding

Law No. 132/2025 on artificial intelligence

Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Italy's framework AI law, published in the Official Gazette on 25 September 2025 and in force from 10 October 2025. It states principles (human-centric, transparent, safe AI; protection of fundamental rights), sets sector rules for healthcare (AI as support, not replacement, for clinical decisions), employment (information to workers, an AI-at-work observatory), intellectual professions (client disclosure), justice (judge decides; AI only for organisational support) and public administration, requires parental consent for children under 14, designates AgID and ACN as national authorities, delegates the government to align national law with the EU AI Act, and creates a criminal offence for unlawful dissemination of AI-generated or manipulated content with aggravating circumstances for other crimes committed with AI.

In force 10 Oct 2025 Source-linked · checked 11 Sep 2026 Official source
India Act / statute Partially applicable Binding

India DPDP Act

Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025

The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.

Adopted 11 Aug 2023 Source-linked Official source
India Guidance Guidance

India AI Governance Guidelines

India AI Governance Guidelines (MeitY, 2025)

The India AI Governance Guidelines set out a principle-based, pro-innovation approach to governing AI in India. They articulate guiding principles (such as trust, people-first design, fairness, accountability, safety and transparency), propose an institutional framework including an AI governance group and an AI Safety Institute role, favour applying existing laws over a new AI statute, and recommend voluntary commitments, techno-legal measures, risk-based oversight and incident reporting for AI systems.

Adopted 5 Nov 2025 Source-linked Official source
El Salvador Act / statute In force Binding

Law for the Promotion of AI and Emerging Technologies

Ley para el Fomento de la Inteligencia Artificial y Tecnologías Emergentes (Decreto Legislativo, febrero de 2025)

Approved by the Legislative Assembly in February 2025, the law promotes AI development and investment, creates the National Agency for Artificial Intelligence (ANIA) as regulator, defines rights and principles (human oversight, transparency, non-discrimination, data protection), sets registration and sandbox mechanisms and limits liability of developers who act in good faith under the law, alongside data-processing rules for AI training.

Adopted 25 Feb 2025 Source-linked · checked 11 Sep 2026 Official source
Council of Europe Act / statute Adopted Binding

Framework Convention on AI (CETS 225)

Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225)

The first international treaty on AI. Parties must adopt or maintain measures so that activities within the lifecycle of AI systems are consistent with human rights, democracy and the rule of law, covering public authorities and actors on their behalf and, by choice of approach, private actors. It sets principles (human dignity and autonomy, transparency and oversight, accountability, equality and non-discrimination, privacy, reliability, safe innovation), requires remedies, procedural safeguards and risk and impact assessment, allows moratoria or bans for incompatible uses, and creates a Conference of the Parties for follow-up. National-security activities and defence are excluded.

Adopted 17 May 2024 Source-linked · checked 11 Sep 2026 Official source
Australia Standard Voluntary standard

Australian Voluntary AI Safety Standard

Voluntary AI Safety Standard (Australia)

The Voluntary AI Safety Standard gives Australian organisations ten guardrails for developing and deploying AI safely and responsibly: accountability and governance, risk management, data governance and protection, testing and monitoring, human control and intervention, user transparency, contestability, supply-chain transparency, record keeping, and stakeholder engagement. The guardrails were designed to align with the mandatory guardrails proposed for high-risk settings so that early adopters would be prepared if those became law.

Adopted 5 Sep 2024 Source-linked Official source
Search