AI Governance Institute

AI Regulation Tracker

Live status

AI regulation is the fast-growing body of law, standards, and enforcement action governing how organizations build, deploy, and monitor artificial intelligence. This tracker covers 123+ regulations, frameworks, and enforcement actions across major jurisdictions, including the EU AI Act, the NIST AI Risk Management Framework, state laws, and voluntary standards. Each entry links to its primary source and updates when its status changes.

121 policies
Risk Tier

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkSingapore

Singapore's AI Verify Testing Framework

IMDA developed this voluntary AI governance framework and toolkit. Organizations use its standardized technical tests and process checks to demonstrate responsible AI practices.

VoluntaryFrameworkUSHigh risk

America's AI Action Plan

America’s AI Action Plan sets the White House’s priorities for advancing and governing AI. It directs federal work on AI security infrastructure, agency coordination, and cybersecurity readiness. The plan primarily covers federal agencies and their AI operators. Federal AI contractors and suppliers may also be affected.

VoluntaryFrameworkAustralia

Australia AI Ethics Framework

Australia’s voluntary national framework sets eight ethical principles. They guide organizations designing, developing, and deploying AI systems.

VoluntaryGuidelineGlobal

Bletchley Declaration on AI Safety

At the inaugural AI Safety Summit, 28 governments signed this political declaration. They recognized frontier AI risks and committed to international cooperation on safety, evaluation, and information sharing.

Must ComplyRegulationUS

California AI Auditor Registration Act (AB 1405)

AB 1405 creates California’s first registry for independent AI auditors. Auditors must enroll with a new state agency and disclose their credentials and methods. They must also follow recognized independence standards. From January 1, 2029, only registered auditors may perform covered audits in California.

Must ComplyRegulationUS

California Generative AI Transparency Requirements - AB 2013

California AB 2013 requires public training-data disclosures from developers of generative AI systems accessible to the California public. Developers must publish the documentation on their websites. The disclosures explain training datasets’ origins and composition. The requirement applies regardless of where the developer is headquartered.

Must ComplyRegulationUS

California AI Safeguards Act (Third-Party Audit and Independent Assessment Requirements)

California enacted two AI-related bills establishing first-in-the-nation mandatory standards for third-party audits and independent assessments of AI systems. The legislation applies to AI developers and deployers operating in California or serving California residents. It imposes requirements across model evaluation, vendor assurance, audit governance, and documentation controls.

Must ComplyRegulationUS

California AI Transparency Act (SB 942 as amended by AB 853)

The California AI Transparency Act requires covered generative AI providers to offer a free detection tool. They must also embed latent disclosures in generated content. The law covers developers and distributors serving California consumers. License terms must permit access revocation within 96 hours when licensees remove or disable required disclosure capabilities.

Must ComplyRegulationUSHigh risk

California Executive Order on Independent AI Oversight and Kill Switch Development

This executive order directs California state agencies to accelerate the implementation of independent oversight mechanisms for artificial intelligence systems and advance the development of mandatory AI shutdown capabilities for high-risk deployments. It applies to state agencies deploying AI and extends practical obligations to private enterprises operating high-risk AI systems in California. Organizations must implement human oversight controls, incident response protocols, and pre-deployment governance reviews.

Must ComplyRegulationUSHigh risk

California Health Care Services AI Act Disclosure Requirements

California requires covered healthcare providers to disclose when patient communications are generated by AI. They must also explain how patients can reach a human representative. The requirements help patients understand whether AI is providing health information or services.

EmergingPendingUSHigh risk

California Senate Bill 420: Automated Decision Systems (State AI Transparency Act)

California SB 420 would require impact assessments before high-risk automated decision systems enter public use. Introduced under the State AI Transparency Act, it covers organizations operating those systems in California. The proposal adds transparency and reporting duties. The Attorney General or Civil Rights Department could enforce it through civil actions.

EmergingPendingUSHigh risk

California SB 53 Foundation Model Safety and Security Protocol

California SB 53 would require safety and security protocols for foundation models presenting critical risk. Covered developers would need to create, follow, and publicly disclose those protocols. The bill also requires catastrophic risk testing and ongoing monitoring for critical safety incidents.

Must ComplyRegulationUS

California Independent Verification Organizations Act (SB 813)

California SB 813 establishes a state framework for certifying independent AI verification organizations. The California Artificial Intelligence Standards and Safety Commission will recognize these organizations and set their standards. Companies using AI in hiring, insurance, and other high-stakes activities can hire recognized auditors to check compliance with state law.

Must ComplyRegulationUSHigh risk

California Transparency in Frontier AI Act

The California Transparency in Frontier AI Act covers large frontier model developers operating in or serving California. They must publish safety and security frameworks for their most capable systems. Duties include risk assessment disclosures, transparency reports to the public and authorities, and timely reporting of qualifying safety incidents.

VoluntaryGuidelineChina

China AI Standardization White Paper

Chinese standards authorities issued this non-binding policy document to map AI standards work. It identifies priorities and outlines planned national and international standardization efforts.

Must ComplyRegulationChina

China Measures for the Management of AI-Generated Content

These Chinese regulations require labels, traceability, and content governance for AI-generated material. They cover distribution through online platforms and information services in China.

Must ComplyRegulationChina

China Algorithm Recommendation Regulations

China’s dedicated recommendation-system regulation covers internet services operating in China or targeting Chinese users. Providers must meet transparency, user-control, and content-moderation duties.

Must ComplyRegulationChina

China Deep Synthesis Regulations

China’s deep synthesis provisions regulate service providers and users operating in or targeting China. They cover AI-generated or manipulated text, images, audio, video, and virtual humans. Duties include labeling, registration, security assessments, and content moderation.

EmergingPendingChina

China Draft AI Law

China is developing a proposed national AI law. It would establish legal duties for AI development, deployment, and governance across sectors.

Must ComplyRegulationChina

China's Interim Measures for the Management of Generative Artificial Intelligence Services

China’s Interim Measures for Generative AI Services cover providers serving the Chinese public. They impose duties for training data governance, content safety, algorithmic transparency, and registration.

Must ComplyRegulationChinaHigh risk

Implementation Opinions on the Administration of Intelligent Agents

China’s Implementation Opinions on the Administration of Intelligent Agents establish a dedicated regulatory category for AI agents. They cover developers and deployers across sectors, with additional duties in sensitive industries. Requirements include tiered authorization, pre-deployment filing in designated sectors, compliance testing, and recall procedures for non-conforming agents.

Must ComplyRegulationChinaHigh risk

China's Interim Measures for Artificial Intelligence Anthropomorphic Interactive Services

China’s Interim Measures for Artificial Intelligence Anthropomorphic Interactive Services govern AI that simulates human interaction. Covered services include conversational agents and agentic products operating within Chinese jurisdiction. Providers and deployers must define authorization boundaries, use tiered risk approvals, and meet registration duties before public availability.

Must ComplyRegulationChina

China's Measures for Labelling AI-Generated and Synthetic Content

China’s labeling measures cover AI-generated and synthetic content distributed to Chinese users. Platforms, developers, and enterprises must label covered text, images, audio, and video. Required mechanisms include audio Morse codes, encrypted metadata, and labels compatible with virtual reality.

Must ComplyRegulationUS

Colorado AI Act SB205

Colorado SB 205 imposes duties on developers and deployers of high-risk AI. Requirements include algorithmic impact assessments, transparency notices, and consumer rights for consequential decisions. It was the first US state statute to establish these affirmative duties.

EmergingPendingUS

Colorado Senate Bill 189: Automated Decision-Making Technology Act

Colorado SB 189 repeals SB 205 and replaces it with the Automated Decision-Making Technology Act, effective January 1, 2027. It covers a broader category of technology used for consequential decisions affecting Colorado consumers. The replacement removes mandatory risk management programs, annual impact assessments, and the reasonable-care standard for algorithmic discrimination.

EmergingPendingUS

Commerce Department Evaluation of State AI Laws

The December 11, 2025 executive order gives Commerce 90 days to evaluate state AI laws conflicting with federal policy. The review targets compelled changes to truthful outputs and disclosures that may implicate First Amendment protections. Identified laws may be referred to the AI Litigation Task Force for possible federal preemption action.

Must ComplyRegulationGlobalHigh risk

Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law

This treaty is the first internationally legally binding instrument dedicated to AI governance, adopted under the auspices of the Council of Europe. It applies to AI systems deployed by public authorities and private actors operating within signatory states. Parties are required to protect human rights, uphold democratic principles, and ensure the rule of law throughout the AI lifecycle.

EmergingPendingUSHigh risk

Proposed CPPA Regulations on Cybersecurity, Risk Assessments, and Automated Decision-Making Technologies

The California Privacy Protection Agency Board finalized proposed rules in May 2025. They cover cybersecurity audits, privacy risk assessments, and automated decision-making. Covered businesses would include those conducting consequential automated decisions or personal-data processing posing significant consumer risks. If adopted, the rules would add consumer opt-outs and mandatory assessments.

VoluntaryFrameworkEUHigh risk

European Commission Enforcement Powers for Advanced AI Models under the AI Act

The European Commission can enforce EU AI Act requirements against providers of advanced general-purpose models meeting its capability thresholds. Coverage applies regardless of incorporation location. Powers include information requests, model access for evaluation, required mitigations, and penalties reaching 3 percent of worldwide annual turnover.

VoluntaryFrameworkUS

Executive Order 14318: Accelerating Federal Permitting of Data Center Infrastructure

President Trump’s Executive Order 14318 directs federal agencies to accelerate data center permitting for domestic AI development. It covers agencies responsible for relevant land use, environmental reviews, and energy approvals. The administration identified permitting delays as barriers to AI infrastructure growth.

VoluntaryFrameworkUS

Executive Order 14319: Preventing Woke AI in the Federal Government

President Trump’s Executive Order 14319 directs agencies to avoid AI with ideological bias or viewpoint-discriminatory outputs. It covers federal procurement, deployment, and contracting. The order rescinds or modifies earlier guidance viewed as imposing political or ideological constraints on AI development.

VoluntaryFrameworkEUHigh risk

EU Action Plan on Cybersecurity and Artificial Intelligence

The European Commission’s Action Plan on Cybersecurity and Artificial Intelligence coordinates EU efforts to secure AI systems. It covers developers and deployers subject to the AI Act, particularly advanced or high-risk systems. The plan creates a secure testing platform and EU-level evaluation capability for advanced models.

Must ComplyRegulationEUHigh risk

Regulation (EU) 2026/1744: AI Act Omnibus Amendment (High-Risk Deadline Deferral)

Regulation (EU) 2026/1744 defers the AI Act’s high-risk compliance deadlines. Stand-alone Annex III systems move from August 2, 2026 to December 2, 2027. Product-embedded high-risk systems have until August 2, 2028. GPAI duties remain applicable from August 2025. Prohibited practices and AI literacy requirements remain applicable from February 2026.

VoluntaryFrameworkEUHigh risk

EU AI Act Harmonised Standard prEN 18286, Quality Management Systems for AI

Draft standard prEN 18286 is under public enquiry. It addresses AI quality management systems supporting conformity with the EU AI Act. It targets developers and deployers seeking standardized compliance evidence. Conformity with a harmonized standard creates a presumption of conformity for the corresponding requirements it covers.

Must ComplyRegulationEUUnacceptable risk

EU AI Act: AI Literacy and Prohibited AI Systems Provisions (Applicable 2 February 2026)

This entry lists February 2, 2026 as the EU AI Act’s first major compliance deadline. It requires AI developers and deployers in the EU to establish workforce literacy measures. It also describes enforceable prohibitions on unacceptable-risk practices. Organizations must cease prohibited practices and demonstrate adequate staff competency by that date.

Must ComplyRegulationEU

EU AI Liability Directive

The proposed EU AI Liability Directive would have lowered evidentiary barriers for people seeking compensation for AI harm. It proposed disclosure mechanisms and presumptions of causation. The proposal was withdrawn in early 2025 after political agreement failed.

VoluntaryFrameworkEUHigh risk

AI Act Governance and Enforcement Framework

EU AI Act supervision is shared across Union bodies and national authorities. Responsibilities involve the AI Office, European Data Protection Supervisor, and national competent authorities. Developers and deployers must identify the authority responsible for their systems and prepare compliance evidence.

Must ComplyRegulationEUHigh risk

AI Omnibus Regulation (EU AI Act Extension)

The AI Omnibus entered into force on July 27, 2026, extending AI Office oversight powers. It covers general-purpose AI providers and deployers, plus AI embedded in large online platforms and search engines. Organizations must maintain model governance, conduct provider due diligence, and respond to AI Office evidence requests.

VoluntaryFrameworkEULimited risk

EU Code of Practice on Transparency of AI-Generated Content

The European Commission published this voluntary Code of Practice to support Article 50 compliance under the EU AI Act. It addresses generative AI providers and deployers serving the EU. The Code covers content labeling, provenance controls, and disclosure workflows.

Must ComplyRegulationEU

EU Cyber Resilience Act

The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements sold in the EU. It includes hardware and software containing AI components. Duties cover the lifecycle from design through end-of-life.

Must ComplyRegulationEU

EU Data Act

The EU Data Act governs access to personal and non-personal data from connected products and related services. Data holders must share covered data with users and third parties. It also sets conditions for public bodies accessing privately held data in exceptional circumstances.

Must ComplyRegulationEU

EU Data Governance Act

The EU Data Governance Act regulates data intermediaries, data altruism organizations, and reuse of protected public-sector data. It establishes structures for trusted sharing across sectors and member states as part of the European Data Strategy.

EmergingPendingEUHigh risk

EU Proposal for a Regulation for the Digital Networks Act (DNA)

The European Commission proposed the Digital Networks Act on January 21, 2026. Parliament and Council are reviewing it. It addresses digital infrastructure and aspects of AI governance. Expected duties concern network operators and deployers, including those using AI for network management.

Must ComplyRegulationEU

EU Digital Operational Resilience Act

DORA, Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover ICT risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.

Must ComplyRegulationEU

EU Digital Services Act, AI and Algorithmic Accountability Provisions

The Digital Services Act regulates online intermediaries’ recommender systems, targeted advertising, and systemic risks. Duties cover transparency, accountability, and risk management. Requirements increase with platform size, with the strictest applying to VLOPs and VLOSEs.

VoluntaryGuidelineEU

EU General-Purpose AI Model Training Data Public Summary Template

The European Commission published a template for general-purpose AI providers’ public training-data summaries. It supports disclosure obligations under the EU AI Act. Providers are expected to follow its structure when preparing those summaries.

VoluntaryFrameworkUS

Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence

This US presidential directive sets federal requirements for safe AI development and deployment. It includes frontier-model safety reporting, NIST standards development, and coordination across agencies.

VoluntaryGuidelineGlobal

FATF AI Anti-Money Laundering Guidance

FATF guidance addresses AI and machine learning in anti-money laundering, counter-terrorism financing, and proliferation financing compliance. It sets expectations for transaction monitoring, customer due diligence, and suspicious activity detection.

Must ComplyRegulationUS

Federal Reporting and Disclosure Standard for AI Models (FCC Proceeding Directive)

This national AI policy directive instructs the FCC to consider federal reporting and disclosure standards for AI models. An adopted standard would preempt conflicting state AI laws. A parallel AI Litigation Task Force would challenge state laws deemed inconsistent with the federal framework.

EmergingPendingUS

Federal Communications Commission AI Model Reporting and Disclosure Proceeding

The FCC is opening a proceeding on possible federal AI model reporting and disclosure standards. It follows Commerce’s evaluation of state AI laws. An adopted standard could preempt conflicting state disclosure and reporting requirements.

VoluntaryGuidelineUS

FDA AI/ML Software as Medical Device Guidance

FDA’s action plan and guidance address AI/ML Software as a Medical Device. They introduce a total product lifecycle approach and predetermined change control plans. Adaptive clinical algorithms also face transparency and monitoring requirements.

VoluntaryGuidelineGlobalHigh risk

Sound Practices for Responsible Adoption of Artificial Intelligence (Consultation Report)

The Financial Stability Board proposes 12 practices for responsible AI adoption throughout its lifecycle. They cover banks, insurers, and other regulated financial entities developing or deploying AI. Institutions should map them to governance, model risk, third-party oversight, and lifecycle controls.

VoluntaryGuidelineISO/OECD/UNHigh risk

Five Eyes Guidance on the Careful Adoption of Agentic AI Services

This joint Five Eyes advisory addresses enterprises and public bodies deploying autonomous AI agents. It covers agents taking independent actions, accessing systems, or interacting with other agents. The guidance calls for low-risk tasks, least-privilege access, and integration into existing security governance.

VoluntaryFrameworkUSHigh risk

Artificial Intelligence Compliance Plan

The FTC's Artificial Intelligence Compliance Plan describes how the agency governs its own internal adoption of AI tools and sets expectations for AI transparency and accountability in regulated markets. It applies to FTC operations and signals enforcement priorities relevant to enterprises deploying AI in consumer-facing products and services. Organizations subject to FTC jurisdiction should treat this plan as an indicator of the standards against which AI-related conduct may be measured.

VoluntaryGuidelineGlobal

G7 Hiroshima AI Code of Conduct

The G7 Hiroshima AI Process issued this voluntary international code of conduct. It sets eleven principles and corresponding actions for advanced AI developers and operators, particularly frontier and general-purpose models. The code uses voluntary commitments to guide responsible development.

VoluntaryFrameworkUS

U.S. General Services Administration AI Strategies and Compliance Plan

The GSA AI Strategies and Compliance Plan establishes governance for internal agency AI use. An AI Governance Board and oversight committee review and approve use requests. Requirements cover privacy controls, security reviews, use-case intake, and compliance evidence.

EmergingPendingUS

Guaranteeing and Upholding Americans' Right to Decide Responsible AI Laws and Standards Act (GUARDRAILS Act)

The bipartisan GUARDRAILS Act was introduced on March 20, 2026. It would repeal Executive Order 14365 and prevent federal agencies from preempting state AI laws. If enacted, it would preserve states’ authority to establish and enforce their own requirements.

EmergingPendingUS

H.R.8094 - AI Foundation Model Transparency Act of 2026

Bipartisan lawmakers introduced H.R.8094 on March 26, 2026. It would require large foundation model developers to disclose training data, model design, limitations, risks, and evaluation methods. The bill seeks public scrutiny through transparency without directly restricting model use or deployment.

Must ComplyRegulationUSHigh risk

Illinois AI Safety Measures Act (SB 315)

The Illinois AI Safety Measures Act was signed on July 7, 2026. It requires annual independent frontier-model safety audits from AI developers earning more than $500 million annually. Results must be public, and the Illinois Attorney General can enforce civil penalties. It is described as the first US state law requiring these audits.

Must ComplyRegulationUS

Illinois Biometric Information Privacy Act, AI Provisions

Illinois BIPA, 740 ILCS 14, restricts collection, storage, use, and disclosure of biometric identifiers and information. It affects AI processing facial geometry, voiceprints, iris scans, and similar data. BIPA has generated extensive biometric privacy litigation.

EmergingPendingUSHigh risk

Illinois High-Impact AI Governance Principles and Disclosure Act

Illinois HB 3529 would establish the High-Impact AI Governance Principles and Disclosure Act. It targets private businesses using consequential AI in areas such as employment, credit, and housing. Proposed duties include impact assessments, governance records, and public disclosures, backed by civil penalties.

VoluntaryGuidelineSingaporeHigh risk

MDDI Response on Extending AI Governance to Agentic AI Systems

Singapore’s Ministry of Digital Development and Information clarified its January 2026 agentic AI framework in a parliamentary response. Enterprises should designate oversight roles, maintain human accountability, and scale controls to autonomy. The response treats agents as autonomous actors requiring specific governance.

VoluntaryFrameworkSingapore

IMDA Model AI Governance Framework

Singapore’s IMDA and PDPC issued this voluntary AI governance framework. It guides responsible deployment through human oversight, decision accountability, and operational transparency.

VoluntaryGuidelineIndia

India AI Governance Framework

MeitY’s advisory sets responsible AI principles and interim expectations for platforms deploying AI in India. It focuses on harm prevention, traceability, and government approval before deploying undertested models.

EmergingPendingGlobal

Indonesia Presidential Regulation on the National AI Roadmap and AI Ethics

In August 2026, Indonesia outlined a planned Presidential Regulation establishing a National AI Roadmap and binding ethics framework. If finalized, it would cover enterprises operating AI in Indonesia. Expected requirements include ethics reviews, internal controls, and documented risk assessments.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 42001:2023 - Artificial Intelligence Management System

ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 23894 AI Risk Management

ISO/IEC 23894 explains how to integrate AI risks into enterprise risk management. It adapts ISO 31000 terminology and processes for AI characteristics. These include emergent behavior, data dependency, opacity, and sociotechnical complexity.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 24028 AI Trustworthiness

ISO/IEC 24028:2020 explains AI trustworthiness concepts, characteristics, and threats. It provides technical and organizational approaches for assessing and improving trustworthiness throughout the lifecycle.

VoluntaryFrameworkISO/OECD/UN

ISO/IEC 24029 Robustness of Neural Networks

ISO/IEC 24029 covers formal methods and practical assessments of artificial neural network robustness. Its parts address adversarial inputs, distribution shifts, and other failure modes relevant to trustworthy deployment.

VoluntaryFrameworkGlobal

ITU Focus Group on Trust and Identity for Humans and Agentic AI

ITU launched a Focus Group on trusted digital identity and accountable behavior throughout agentic AI lifecycles. It addresses agent identification, credentials, authorization, and agent-to-agent interactions. The work concerns organizations developing or deploying agents with delegated authority or external system access.

VoluntaryGuidelineJapan

Japan AI Guidelines for Business

METI’s guidelines help Japanese businesses govern AI throughout its lifecycle. They address risk management, transparency, accountability, and intellectual property, drawing on the Hiroshima AI Process and international frameworks.

VoluntaryFrameworkJapan

Japan's Basic Plan for Artificial Intelligence

Japan’s Cabinet approved the Basic Plan for Artificial Intelligence in December 2025. It makes governance leadership and trustworthy AI government priorities. The plan directs public agencies and shapes expectations for private AI development and deployment.

VoluntaryFrameworkJapan

Japan's Principles Code (tentative) on the Protection of Intellectual Property and Transparency for Appropriate Use of Generative AI (Draft)

Japan released this draft principles code on December 26, 2025 for generative AI developers and providers. Its voluntary guidance addresses intellectual property protection and transparency about AI use. Public comments closed January 26, 2026. A final version has not yet been adopted.

Must ComplyRegulationKorea

Korea AI Basic Act

South Korea’s foundational AI statute sets risk-based duties for developers and deployers. High-impact systems face additional requirements. The law also establishes national AI safety infrastructure.

VoluntaryFrameworkSingaporeHigh risk

MAS Guidelines on Artificial Intelligence Risk Management

MAS is finalizing supervisory AI guidelines for regulated financial institutions. They cover all AI uses, including agents, with expectations for board oversight, risk frameworks, and lifecycle controls. Institutions should prepare model governance, approval workflows, monitoring, and audit trails for formal requirements.

VoluntaryGuidelineSingapore

Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector

MAS FEAT is a voluntary framework for Singapore financial institutions using AI and data analytics. Its four principles are Fairness, Ethics, Accountability, and Transparency.

EmergingPendingUSHigh risk

New York's Responsible AI Safety and Education Act (RAISE Act) for Large Developers

The pending New York RAISE Act would regulate large frontier model developers above specified computing thresholds. It covers developers operating in or directing services to New York. Proposed requirements include written safety protocols, independent third-party audits, and safeguards against critical harms.

VoluntaryGuidelineAustraliaHigh risk

New Zealand Responsible AI Guidance for Business

New Zealand’s government issued voluntary guidance on responsible commercial AI use. It covers governance structures, risk management, and accountability. The guidance sets expectations for businesses developing and deploying AI in New Zealand.

VoluntaryFrameworkUS

NIST AI 600-1 Generative AI Profile

This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models.

VoluntaryGuidelineUS

NIST ITL AI Program: Guidance and Templates for Public-Facing AI Documentation (Initial Public Draft)

NIST’s initial public draft provides guidance and templates for publicly disclosed AI system documentation. It supports developers, deployers, and procurers needing governance records, transparency, or audit evidence. Public comments close September 16, 2026.

VoluntaryFrameworkUSHigh risk

NIST Artificial Intelligence Risk Management Framework Playbook

The NIST AI RMF Playbook translates the AI Risk Management Framework Core into a structured set of suggested actions organized under the four functions: Govern, Map, Measure, and Manage. It is designed for organizations deploying or developing AI systems who need practical implementation guidance rather than high-level principles. Compliance teams can use it to build risk workflows, establish control checkpoints, and produce governance documentation aligned to the AI RMF.

VoluntaryFrameworkUSHigh risk

NIST Artificial Intelligence Technology Evaluation Program

NIST’s AITE program organizes federal AI testing, benchmarking, and validation, particularly for high-impact applications. It serves developers, agencies, and enterprises seeking standardized evaluations. Topics include testing methods, provenance controls, data governance, and enterprise validation.

Must ComplyRegulationUS

New York City Local Law 144 of 2021, Automated Employment Decision Tools

NYC employers and employment agencies using covered automated tools for hiring or promotion must arrange annual bias audits. They must publish results and notify candidates before use.

VoluntaryGuidelineUSHigh risk

OCC Updated Model Risk Management Guidance (2026)

The Office of the Comptroller of the Currency has issued updated model risk management guidance establishing revised expectations for how national banks and federal savings associations develop, validate, monitor, and govern models. The guidance applies to all institutions supervised by the OCC that use models in material business decisions, with particular relevance where AI or machine learning is embedded in credit underwriting, pricing, fraud detection, or compliance monitoring workflows. Institutions are expected to maintain rigorous validation programs, clear governance structures, and documented controls proportionate to the risk a given model presents.

VoluntaryFrameworkISO/OECD/UN

OECD AI Principles

The OECD AI Principles were the first intergovernmental AI standard. They set five values-based principles and five government recommendations supporting trustworthy AI, human rights, and democratic values.

VoluntaryFrameworkISO/OECD/UNHigh risk

OECD Report: Governing with Artificial Intelligence

This OECD report examines government AI use across member and partner countries. Public-service improvements account for 57% of documented applications, while 45% support administrative decisions. Identified risks include biased training data, limited transparency, and overreliance on automated outputs.

VoluntaryGuidelineUSHigh risk

OMB Memorandum M-26-04: Increasing Public Trust in AI Through Unbiased AI Principles

OMB Memorandum M-26-04 sets unbiased AI principles for federal systems interacting with or affecting the public. It covers executive agencies procuring, developing, or operating AI. Agencies must address algorithmic bias and maintain transparency and accountability in AI-supported decisions.

VoluntaryFrameworkGlobalHigh risk

OWASP Top 10 for Large Language Model Applications

OWASP’s LLM Top 10 identifies application security risks. These include prompt injection, insecure output handling, training-data poisoning, denial of service, and supply-chain vulnerabilities. Development and security teams use it to prioritize controls.

VoluntaryFrameworkGlobal

The Role of Investors in AI Governance

Oxford Martin’s AI Governance Initiative examines investor responsibilities for AI safety and accountability. It covers financing and oversight by institutional investors, venture capital, and private equity. Investors can use it in due diligence, stewardship, and portfolio management.

EmergingPendingUS

Protecting Consumers From Deceptive AI Act

The Protecting Consumers From Deceptive AI Act was introduced federally on April 23, 2026. It would direct NIST to develop watermarking, fingerprinting, and provenance standards for AI-generated audio and visual content. NIST would also support AI-modified content labels and frameworks for identifying generated text. The bill targets platforms, developers, and synthetic-media distributors.

VoluntaryGuidelineUS

SEC AI Governance Guidance

SEC rules, guidance, and proposals address investment advisers, broker-dealers, and public companies using AI. Topics include predictive-analytics conflicts, securities disclosures, and examination priorities for algorithmic systems.

EmergingPendingUS

Sectoral AI Governance Act of 2026

The Sectoral AI Governance Act of 2026 is a proposed US federal law that would authorize federal regulatory agencies to issue rules governing algorithmic decision-making systems within their existing enforcement domains. It applies to any organization deploying AI systems that could materially contribute to violations of federal law in regulated sectors. If enacted, it would require regulated deployers to align AI governance controls with sector-specific agency rulemaking.

VoluntaryFrameworkGlobalHigh risk

Singapore Consensus on Global AI Safety Research Priorities

The Singapore Consensus sets shared international priorities for AI safety research. It emerged from a government-convened multilateral summit involving governments and organizations. The non-binding agenda guides national safety programs and research funding bodies.

VoluntaryGuidelineSingaporeHigh risk

The 2026 Singapore Consensus on Global AI Safety Research Priorities

The 2026 Singapore Consensus sets out a structured agenda for global AI safety research, covering evaluation methodologies, alignment techniques, and governance mechanisms. It is produced by an international coalition of academic researchers and addresses organizations building or deploying advanced AI systems. Enterprises can use it as a reference framework for structuring safety testing programs and model oversight documentation before deployment.

VoluntaryFrameworkSingaporeHigh risk

Singapore Global AI Assurance Sandbox

Singapore’s Global AI Assurance Sandbox lets enterprises and developers test safety, reliability, and accountability before or during deployment. Participants operate under regulatory oversight and defined conditions. Temporary compliance relaxations are exchanged for testing commitments and reporting.

VoluntaryFrameworkSingapore

Singapore National AI Strategy 2.0

Singapore’s updated national AI blueprint sets its development and governance ambitions. It prioritizes trusted, responsible AI and building national expertise.

Must ComplyRegulationSingapore

Singapore Personal Data Protection Act, AI and Automated Decision-Making Amendments

Singapore’s 2020 personal data amendments and PDPC guidance address AI and automated decisions. They add mandatory breach notification, expanded accountability, and responsible deployment guidance under the Model AI Governance Framework.

Must ComplyRegulationUS

Texas Responsible AI Governance Act

Texas enacted its Responsible AI Governance Act on June 22, 2025. This entry describes rules focused on state government AI use, including accountability, transparency, and risk management. It notes that the enacted version removed most private-sector obligations from earlier proposals.

VoluntaryGuidelineUK

UK AI Growth Lab Regulatory Sandbox - Consultation on Two Models

DSIT opened consultation on the proposed UK AI Growth Lab in October 2025. The sandbox would allow AI testing under modified regulatory conditions. Options include central government administration across sectors or individual sandboxes managed by lead regulators. The aim is reduced compliance barriers with continued oversight.

VoluntaryFrameworkUK

UK AI Opportunities Action Plan

The UK published its AI Opportunities Action Plan in January 2025. It sets the Labour government’s adoption and infrastructure agenda for public bodies, developers, and AI enterprises. Commitments include AI Growth Zones, expanded computing infrastructure, and a National Data Library for development access.

EmergingPendingUK

UK AI Regulation Framework

The UK AI Regulation Framework assigns primary oversight to existing sector regulators using shared principles. Following January 2025’s AI Opportunities Action Plan, the approach is moving toward a more structured legislative basis.

VoluntaryGuidelineUK

AI Risk Management Toolkit

The UK Government published this toolkit to help organizations understand, assess, and manage risk throughout the full lifecycle of AI projects. It applies to teams involved in designing, procuring, or delivering AI products and services, including public and private sector buyers. The toolkit provides structured guidance for embedding risk management into intake controls, procurement checklists, and delivery-stage governance.

VoluntaryFrameworkUK

UK-Canada AI Computing Power Collaboration Agreement

The UK and Canada signed an AI computing cooperation agreement on April 27, 2026. It provides for shared resources and joint investment supporting research and development. Government agencies and publicly supported researchers are its primary audience. Enterprises working within either national AI strategy may also be affected.

EmergingPendingUK

UK DSIT Call for Evidence on Data Regulation in the Age of AI and Other Data-Intensive Technologies

DSIT opened a call for evidence on adapting UK data law to AI and other data-intensive technologies. It addresses organizations collecting, processing, or sharing AI-related data, including agent deployments. Respondents are asked about transparency, provenance, and data-access control gaps.

EmergingPendingUKHigh risk

Regulations Requiring the ICO to Produce a Statutory AI and Automated Decision-Making Code of Practice

UK statutory regulations direct the ICO to produce a code for AI and automated decisions involving personal data. It will cover organizations under UK data protection law using these systems to make or inform decisions about individuals. Once finalized, departures from the code may provide evidence of non-compliance in regulatory proceedings.

VoluntaryFrameworkGlobal

Global Dialogue on AI Governance (UN General Assembly Resolution A/RES/79/325)

UN Resolution A/RES/79/325 established the Global Dialogue on AI Governance. The forum welcomes member states, civil society, private businesses, and other stakeholders. Submissions through April 30, 2026 will inform discussions of global AI challenges and priorities.

VoluntaryFrameworkISO/OECD/UNHigh risk

UN Independent International Scientific Panel on AI: Preliminary Report on Agentic AI Governance

The UN Independent International Scientific Panel on AI issued preliminary governance expectations for agents taking consequential actions. The report covers autonomous and semi-autonomous deployments. It calls for documented intervention thresholds, standardized incident registers, audit trails, and verifiable provenance for decision outputs.

VoluntaryGuidelineISO/OECD/UN

UNESCO Recommendation on the Ethics of Artificial Intelligence

UNESCO’s Recommendation on AI Ethics was the first global normative AI ethics instrument adopted by a UN body. It provides policy recommendations across eleven themes for UNESCO member states.

EmergingPendingUS

U.S. Autonomous and Intelligent Government Entities for National Trust Act (AI AGENT Act, Discussion Draft)

The Senate’s AI AGENT Act discussion draft would require FTC registration of custodial agents before access to large online platforms. It targets organizations operating agents for consumers or other principals. Proposed duties cover registration, disclosure, access controls, revocation conditions, and platform management of agent interactions.

EmergingPendingUS

Bipartisan Bill to Stop Rogue AI Agents and Keep People in Control

This bipartisan federal bill directs the National Institute of Standards and Technology to develop national standards, guidelines, and best practices for governing autonomous AI agents. It applies to organizations that deploy or develop AI agent systems capable of acting with limited human intervention. Core requirements center on agent discovery, verification testing, and maintaining meaningful human control over autonomous system behavior.

Must ComplyRegulationUS

Executive Order: Eliminating State Law Obstruction of National Artificial Intelligence Policy

This executive order directs agencies to challenge state AI laws conflicting with national policy. It establishes an AI Litigation Task Force and a 90-day Commerce review of burdensome state rules. FCC and FTC work would develop federal reporting standards and policies intended to preempt conflicting requirements.

VoluntaryFrameworkUS

Executive Order 14179: Removing Barriers to American Leadership in Artificial Intelligence

Executive Order 14179 directs agencies to develop an AI Action Plan prioritizing US development and deployment leadership. It shapes conditions for private AI businesses operating in the US. The order revokes earlier safety-focused directives and emphasizes deregulation and competitiveness.

VoluntaryFrameworkUS

U.S. Executive Order: Ensuring a National Policy Framework for Artificial Intelligence

The December 11, 2025 executive order directs a unified national AI policy and challenges to conflicting state laws. It requires Commerce’s state-law evaluation and an FTC statement on unfair or deceptive AI practices within 90 days. It also establishes an AI Litigation Task Force. Federal agencies and entities subject to challenged state rules may be affected.

Enforcement ActionEnforcementUS

U.S. Federal Court Ruling on Attorney-Client Privilege and AI Chatbot Communications (Rakoff, S.D.N.Y. 2026)

A Manhattan federal judge ruled that third-party AI chatbot communications did not qualify for attorney-client privilege. Former GWG Holdings CEO Bradley Heppner had to produce 31 AI-generated legal documents in a securities fraud case. The ruling illustrates potential disclosure exposure for AI-assisted legal research and drafting.

VoluntaryFrameworkUSHigh risk

Treasury Department AI Risk Management Framework for Financial Services

Treasury’s February 2026 framework translates NIST AI RMF principles into 230 financial-sector control objectives. It covers Treasury-supervised institutions, including banks, asset managers, insurers, and payment processors developing or deploying AI. Controls address model lifecycles, identity resolution, data governance, and compatibility with SOC 2 and NIST cybersecurity requirements.

Must ComplyRegulationUSHigh risk

U.S. Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security

This presidential action creates classified evaluations of frontier models’ cyber capabilities and a designation for covered models. Designated developers must provide federal access 30 days before public or commercial release. Confidentiality and cybersecurity protocols govern that access. The action primarily affects large frontier-model developers with potential cybersecurity implications.

Must ComplyRegulationUSHigh risk

Utah Artificial Intelligence Policy Act (SB 149)

Utah SB 149 requires AI interaction disclosures for covered businesses and people in regulated occupations. Missing disclosures or deceptive AI use can create liability under existing consumer protection law. It also establishes an AI Policy Office in the Department of Commerce to develop policy and coordinate guidance.

VoluntaryGuidelineGlobalHigh risk

Verifiable Semiconductor Manufacturing: Governance and Verification Systems for AI Supply Chain Oversight

Oxford Martin’s AI Governance Initiative examines semiconductor governance and verification in AI supply chains. The guidance addresses large-scale hardware design, production, procurement, and deployment. It outlines assurances for provenance, integrity, and manufacturing standards.

VoluntaryFrameworkSingapore

Veritas Consortium AI Fairness Testing Methodology

MAS and a financial-sector consortium developed this assessment method for responsible AI. It applies fairness, ethics, accountability, and transparency principles to financial services.

Must ComplyRegulationUSHigh risk

Washington State SB 5395 and SB 5886 (AI in Health Care and Right of Publicity)

Washington enacted two relevant statutes in 2026. SB 5395 prohibits healthcare providers from relying solely on AI to deny care through prior authorization. SB 5886 extends publicity rights to AI-generated likenesses, affecting organizations producing or deploying representations of individuals.

VoluntaryFrameworkUSHigh risk

White House Artificial Intelligence Oversight Framework

Reporting describes an advanced-model oversight framework finalized by the White House in August 2026. It sets pre-deployment evaluation expectations for developers and deployers operating within or supplying the federal government. The full text was unavailable at the reporting date, leaving its precise scope and requirements unconfirmed.