AI policy explorer

Search and filter source-backed AI laws, regulations, standards, guidance and consultations. Each record shows its status, key dates, verification state and official source.

3 results

United States Framework Voluntary standard

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Adopted 26 Jan 2023 Source-linked Official source
Spain Regulation In force Binding

Royal Decree 817/2023 (AI regulatory sandbox)

Real Decreto 817/2023, de 8 de noviembre, que establece un entorno controlado de pruebas para el ensayo del cumplimiento de la propuesta de Reglamento de IA

Establishes Spain's controlled testing environment (sandbox) for providers of high-risk AI systems to test compliance with the then-proposed EU AI Act requirements: risk management, data governance, documentation, transparency, human oversight, accuracy and robustness. Participation is voluntary; participants receive guidance and produce documentation that feeds into national implementation.

In force 10 Nov 2023 Source-linked · checked 11 Sep 2026 Official source
European Union Regulation Partially applicable Binding

EU AI Act

Regulation (EU) 2024/1689 — Artificial Intelligence Act

The EU AI Act is a binding regulation that sets rules for developing, placing on the market and using AI systems in the European Union. It bans a small set of practices considered unacceptable, imposes detailed requirements on "high-risk" AI systems used in areas such as employment, education, credit, essential services, law enforcement and safety-critical products, requires transparency for chatbots and synthetic content, and creates separate duties for providers of general-purpose AI models. Obligations apply in phases between 2025 and 2027.

Applies from 2 Aug 2026 Source-linked Official source
Search