New York (United States)
·
Act / statute
Adopted
Binding
New York Responsible AI Safety and Education (RAISE) Act (S.6953-B / A.6453-B, signed December 2025)
The RAISE Act requires large developers of frontier AI models (defined by training compute and revenue thresholds) to publish and follow a safety and security protocol, report critical safety incidents to the state within a set period, not deploy models that create unreasonable risk of critical harm, and submit to Attorney General enforcement with civil penalties; the chapter amendments create a state oversight office and align definitions with California's Transparency in Frontier AI Act.
Applies from 1 Jan 2027
Source-linked · checked 11 Sep 2026
Official source
Utah (United States)
·
Act / statute
In force
Binding
Utah Artificial Intelligence Policy Act (SB 149, 2024, as amended by SB 226 and SB 332 in 2025)
Effective 1 May 2024, the Act requires a person using generative AI to interact with a consumer in a consumer transaction to disclose clearly that the consumer is interacting with AI when asked (as amended in 2025, when the interaction is high-risk or on request), and requires providers of regulated occupations (for example health and legal services) to disclose generative-AI use proactively. It states that using AI is no defence to consumer-protection violations, created the Office of Artificial Intelligence Policy and an AI learning laboratory allowing regulatory mitigation agreements, and originally sunset in 2025, extended to 2027.
Applies from 1 May 2024
Source-linked · checked 11 Sep 2026
Official source
United States
·
Framework
Voluntary standard
NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile
The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.
Adopted 26 Jan 2023
Source-linked
Official source
Tennessee (United States)
·
Act / statute
In force
Binding
Ensuring Likeness, Voice, and Image Security (ELVIS) Act of 2024 (Tennessee Public Chapter 588)
Signed 21 March 2024 and effective 1 July 2024, the ELVIS Act updates Tennessee's Personal Rights Protection Act to add voice to the protected attributes of name, photograph and likeness, prohibits publishing or making available an individual's voice or likeness without authorisation, and creates liability for distributing or making available an algorithm, software or tool whose primary purpose is producing an individual's voice or likeness without authorisation. It provides civil actions for individuals and licensees and criminal penalties.
In force 1 Jul 2024
Source-linked · checked 11 Sep 2026
Official source
Texas (United States)
·
Act / statute
In force
Binding
Texas Responsible Artificial Intelligence Governance Act (HB 149, 89th Legislature)
Signed on 22 June 2025 and effective 1 January 2026, TRAIGA bans developing or deploying AI systems intended to manipulate people into self-harm or crime, government social scoring, biometric identification by government from public data without consent, intentional unlawful discrimination against protected classes, and production of child sexual abuse material or unlawful sexual deepfakes. State agencies and health-care providers must disclose AI interactions. It creates a 36-month regulatory sandbox administered by the Department of Information Resources, a Texas Artificial Intelligence Council, and gives the Attorney General exclusive enforcement with civil penalties after a 60-day cure period; disparate impact alone does not prove intent to discriminate.
Applies from 1 Jan 2026
Source-linked · checked 11 Sep 2026
Official source
United States
·
Executive order
In force
Binding
Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence
Executive Order 14179, signed 23 January 2025, sets US federal policy to sustain and enhance American AI dominance, directs the development of an AI Action Plan within 180 days, and orders agencies to review and revise or rescind actions taken under the revoked Executive Order 14110 that are inconsistent with the new policy. It also called for revision of the OMB memoranda governing federal agency use and procurement of AI, which OMB replaced in April 2025 with M-25-21 and M-25-22.
In force 23 Jan 2025
Source-linked
Official source
United Kingdom
·
Guidance
Guidance
ICO Guidance on AI and data protection
The ICO's guidance explains how UK GDPR and the Data Protection Act 2018 apply when organisations develop or use AI that processes personal data. It covers accountability and governance, lawfulness and fairness, transparency, data minimisation, security, individual rights, and automated decision-making. The guidance is not itself law, but it reflects how the regulator interprets binding obligations and is the reference point in ICO enforcement.
California (United States)
·
Act / statute
In force
Binding
California SB 53: Transparency in Frontier Artificial Intelligence Act
SB 53 requires "large frontier developers" (developers of the most compute-intensive models above statutory thresholds) to publish a frontier AI framework describing how they assess and mitigate catastrophic risks, publish transparency reports when deploying new frontier models, report critical safety incidents to the California Office of Emergency Services, and protect employees who report safety concerns. It also directs creation of a public computing cluster ("CalCompute").
Applies from 1 Jan 2026
Source-linked
Official source
United Arab Emirates
·
Act / statute
In force
Binding
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL)
The UAE Personal Data Protection Law is the federal data-protection law applying outside the DIFC and ADGM free zones. It sets principles for lawful processing, consent and its exceptions, data-subject rights (including the right to object to automated decision-making without human intervention), controller and processor duties, security and breach notification to the UAE Data Office, cross-border transfer rules, and data protection impact assessments for high-risk processing including new technologies.
In force 2 Jan 2022
Source-linked
Official source
United Kingdom
·
Policy
Guidance
A pro-innovation approach to AI regulation (white paper and government response)
The UK white paper sets out a principles-based, context-specific approach to regulating AI. Instead of a single AI law, it asks existing regulators to interpret and apply five cross-cutting principles within their remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Central government provides coordination, monitoring and guidance.
Adopted 29 Mar 2023
Source-linked
Official source
Türkiye
·
Bill
Proposed
Binding
Yapay Zekâ Kanunu Teklifi (Artificial Intelligence Law proposal submitted to the Grand National Assembly, June 2024)
A short framework bill proposing principles for AI (safety, transparency, fairness, accountability, privacy), a risk-based approach with registration of high-risk systems, operator obligations and penalties, and supervision by designated authorities, broadly modelled on the EU AI Act.
Source-linked · checked 11 Sep 2026
Official source
Taiwan
·
Bill
Proposed
Binding
人工智慧基本法 (Artificial Intelligence Basic Act) – draft approved by the Executive Yuan, July 2024
A framework act setting seven principles for AI development and use, requiring the government to promote AI research, talent and infrastructure, to establish a risk-classification framework and safety standards, to protect personal data, labour and consumers, to provide for liability, disclosure of AI-generated content and non-discrimination, and to designate competent authorities by sector, with the NSTC coordinating.
Adopted 15 Jul 2024
Source-linked · checked 11 Sep 2026
Official source
Singapore
·
Framework
Voluntary standard
Model AI Governance Framework (Second Edition) and Model AI Governance Framework for Generative AI
Singapore's Model AI Governance Framework is a voluntary, sector-agnostic guide for organisations deploying AI. The second edition (January 2020) covers four areas: internal governance structures and measures, determining the level of human involvement in AI-augmented decision-making, operations management (data, model development, monitoring), and stakeholder interaction and communication. The May 2024 Model AI Governance Framework for Generative AI extends it with nine dimensions including accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for the public good.
Adopted 21 Jan 2020
Source-linked
Official source
Spain
·
Bill
Proposed
Binding
Anteproyecto de Ley para el buen uso y la gobernanza de la inteligencia artificial
The draft implements the EU AI Act in Spain: it allocates supervision among AESIA, the data-protection authority, the electoral board, the financial and audiovisual regulators, sets the national penalty scale (up to EUR 35 million or 7% of turnover for prohibited practices), treats failure to label AI-generated content as a serious infringement and provides for the national sandbox to continue.
Source-linked · checked 11 Sep 2026
Official source
Poland
·
Bill
Proposed
Binding
Projekt ustawy o systemach sztucznej inteligencji
The draft act implements the EU AI Act in Poland: it creates the Commission for the Development and Safety of Artificial Intelligence as the market-surveillance authority and single point of contact, sets procedures for complaints and inspections, provides for a regulatory sandbox and defines the national penalty regime.
Source-linked · checked 11 Sep 2026
Official source
Russia
·
National strategy
Adopted
Национальная стратегия развития искусственного интеллекта на период до 2030 года (Presidential Decree No. 490 of 10 October 2019, as amended by Decree No. 124 of 15 February 2024)
The national strategy sets goals for AI research, compute, data, talent and adoption across the economy and public administration to 2030, with the 2024 amendment adding targets on domestic compute capacity, large generative models, share of organisations using AI, and trusted-AI requirements for the public sector. It is implemented through the federal "Artificial Intelligence" project.
Adopted 10 Oct 2019
Source-linked · checked 11 Sep 2026
Official source
New Zealand
·
National strategy
Adopted
New Zealand's Strategy for Artificial Intelligence: Investing with Confidence
Published in July 2025, the strategy aims to lift AI adoption by businesses, especially small and medium enterprises, and the public sector, by reducing barriers, providing clear guidance (Responsible AI Guidance for Businesses), building skills and pursuing a light-touch, proportionate regulatory approach that relies on existing law and international alignment (OECD principles). It rules out a standalone AI act for now.
Adopted 8 Jul 2025
Source-linked · checked 11 Sep 2026
Official source
National Artificial Intelligence Policy, 2082 (2025) — Nepal
Nepal's National AI Policy sets the government's direction for developing and using artificial intelligence. Based on the published summaries, it aims to build AI infrastructure and skills, promote ethical and responsible AI, strengthen data governance, establish institutional arrangements for AI oversight, and prepare legal and regulatory measures. It is a policy framework, not a law, and does not itself create enforceable obligations on private organisations.
Adopted 1 Aug 2025
Source-linked
Official source
Netherlands
·
Policy
Adopted
Overheidsbrede visie generatieve AI (Government-wide vision on generative AI)
Adopted in January 2024, the vision sets the government's position on generative AI: a human-centric, safe and fair approach, provisional restrictions on using non-contracted generative AI tools with government data, investment in Dutch and European open models (GPT-NL), and actions on skills, procurement and supervision. It complements the AI Act and the government's AI strategy.
Adopted 18 Jan 2024
Source-linked · checked 11 Sep 2026
Official source
OECD Recommendation of the Council on Artificial Intelligence (OECD/LEGAL/0449), adopted 22 May 2019 and revised 3 May 2024
The first intergovernmental standard on AI. It sets five values-based principles (inclusive growth and well-being; human rights and democratic values including fairness and privacy; transparency and explainability; robustness, security and safety; accountability) and five recommendations to governments (invest in research, foster an inclusive AI ecosystem, enable an agile policy environment, build human capacity and prepare for labour-market transition, cooperate internationally). The 2024 revision updated the definition of an AI system (adopted by the EU AI Act and other laws) and added references to general-purpose and generative AI, misinformation and environmental sustainability. Adherents include all OECD members and several non-members; the G20 AI Principles (2019) draw on it.
Adopted 22 May 2019
Source-linked · checked 11 Sep 2026
Official source