AI Regulations: Global Directory of Binding AI Laws
Binding AI laws currently in force or adopted, from the EU AI Act to state-level US statutes. Each entry links to the official text and its compliance requirements.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →California AI Auditor Registration Act (AB 1405)
AB 1405 creates California’s first registry for independent AI auditors. Auditors must enroll with a new state agency and disclose their credentials and methods. They must also follow recognized independence standards. From January 1, 2029, only registered auditors may perform covered audits in California.
California Generative AI Transparency Requirements - AB 2013
California Assembly Bill (AB) 2013 requires public training-data disclosures from developers of generative AI systems accessible to the California public. Developers must publish the documentation on their websites. The disclosures explain training datasets’ origins and composition. The requirement applies regardless of where the developer is headquartered.
California AI Safeguards Act (Third-Party Audit and Independent Assessment Requirements)
California enacted two AI-related bills establishing first-in-the-nation mandatory standards for third-party audits and independent assessments of AI systems. The legislation applies to AI developers and deployers operating in California or serving California residents. It imposes requirements across model evaluation, vendor assurance, audit governance, and documentation controls.
California AI Transparency Act (SB 942 as amended by AB 853)
The California AI Transparency Act requires covered generative AI providers to offer a free detection tool. They must also embed latent (hidden) disclosures in generated content. The law covers developers and distributors serving California consumers. License terms must permit access revocation within 96 hours when licensees remove or disable required disclosure capabilities.
California Executive Order on Independent AI Oversight and Kill Switch Development
This executive order directs California state agencies to speed up independent oversight of artificial intelligence systems and advance the development of mandatory AI shutdown capabilities for high-risk deployments. It applies to state agencies deploying AI and extends practical obligations to private enterprises operating high-risk AI systems in California. Organizations must implement human oversight controls, incident response protocols, and pre-launch governance reviews.
California Health Care Services AI Act Disclosure Requirements
California requires covered healthcare providers to disclose when patient communications are generated by AI. They must also explain how patients can reach a human representative. The requirements help patients understand whether AI is providing health information or services.
California Independent Verification Organizations Act (SB 813)
California SB 813 establishes a state framework for certifying independent AI verification organizations. The California Artificial Intelligence Standards and Safety Commission will recognize these organizations and set their standards. Companies using AI in hiring, insurance, and other high-stakes activities can hire recognized auditors to check compliance with state law.
California Transparency in Frontier AI Act
The California Transparency in Frontier AI Act covers developers of large frontier (cutting-edge) AI models operating in or serving California. They must publish safety and security frameworks for their most capable systems. Duties include risk assessment disclosures, transparency reports to the public and authorities, and timely reporting of qualifying safety incidents.
China Measures for the Management of AI-Generated Content
These Chinese regulations require labels, traceability, and content governance for AI-generated material. They cover distribution through online platforms and information services in China.
China Algorithm Recommendation Regulations
China's dedicated regulation on recommendation algorithms covers internet services operating in China or targeting Chinese users. Providers must meet transparency, user-control, and content-moderation duties.
China Deep Synthesis Regulations
China’s deep synthesis provisions regulate service providers and users operating in or targeting China. They cover AI-generated or manipulated text, images, audio, video, and virtual humans. Duties include labeling, registration, security assessments, and content moderation.
China's Interim Measures for the Management of Generative Artificial Intelligence Services
China’s Interim Measures for Generative AI Services cover providers serving the Chinese public. They impose duties for training data governance, content safety, algorithmic transparency, and registration.
Implementation Opinions on the Administration of Intelligent Agents
China’s Implementation Opinions on the Administration of Intelligent Agents establish a dedicated regulatory category for AI agents. They cover developers and deployers across sectors, with additional duties in sensitive industries. Requirements include tiered authorization, pre-deployment filing in designated sectors, compliance testing, and recall procedures for non-compliant agents.
China's Interim Measures for Artificial Intelligence Anthropomorphic Interactive Services
China’s Interim Measures for Artificial Intelligence Anthropomorphic Interactive Services govern AI that simulates human interaction. Covered services include chatbots and task-performing AI products operating within Chinese jurisdiction. Providers and deployers must define authorization boundaries (limits on what the AI may do), use tiered risk approvals, and meet registration duties before public availability.
China's Measures for Labelling AI-Generated and Synthetic Content
China’s labeling measures cover AI-generated and synthetic content distributed to Chinese users. Platforms, developers, and enterprises must label covered text, images, audio, and video. Required mechanisms include audio Morse codes, encrypted hidden file data, and labels that work in virtual reality.
Colorado AI Act SB205
Colorado SB 205 imposes duties on developers and deployers of high-risk AI. Requirements include algorithmic impact assessments, transparency notices, and consumer rights for consequential decisions. It was the first US state statute to establish these affirmative duties.
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law
This treaty is the first internationally legally binding instrument dedicated to AI governance, adopted under the auspices of the Council of Europe. It applies to AI systems deployed by public authorities and private actors operating within signatory states. Parties are required to protect human rights, uphold democratic principles, and ensure the rule of law throughout the AI lifecycle.
Regulation (EU) 2026/1744: AI Act Omnibus Amendment (High-Risk Deadline Deferral)
Regulation (EU) 2026/1744 defers the AI Act’s high-risk compliance deadlines. Stand-alone Annex III systems move from August 2, 2026 to December 2, 2027. Product-embedded high-risk systems have until August 2, 2028. General-purpose AI (GPAI) duties remain applicable from August 2025. Prohibited practices and AI literacy requirements remain applicable from February 2026.
EU AI Act: AI Literacy and Prohibited AI Systems Provisions (Applicable 2 February 2026)
This entry lists February 2, 2026 as the EU AI Act’s first major compliance deadline. It requires AI developers and deployers in the EU to make sure their staff understand AI. It also describes enforceable bans on unacceptable-risk practices. Organizations must stop banned practices and show adequate staff competency by that date.
EU AI Liability Directive
The proposed EU AI Liability Directive would have lowered evidentiary barriers for people seeking compensation for AI harm. It proposed disclosure mechanisms and presumptions of causation. The proposal was withdrawn in early 2025 after political agreement failed.
AI Omnibus Regulation (EU AI Act Extension)
The AI Omnibus entered into force on July 27, 2026, extending AI Office oversight powers. It covers general-purpose AI providers and deployers, plus AI embedded in large online platforms and search engines. Organizations must maintain model governance, conduct provider due diligence, and respond to AI Office evidence requests.
EU Cyber Resilience Act
The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements sold in the EU. It includes hardware and software containing AI components. Duties cover the lifecycle from design through end-of-life.
EU Data Act
The EU Data Act governs access to personal and non-personal data from connected products and related services. Data holders must share covered data with users and third parties. It also sets conditions for public bodies accessing privately held data in exceptional circumstances.
EU Data Governance Act
The EU Data Governance Act regulates data intermediaries, data altruism organizations, and reuse of protected public-sector data. It establishes structures for trusted sharing across sectors and member states as part of the European Data Strategy.
EU Digital Operational Resilience Act
DORA (the Digital Operational Resilience Act), Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover technology risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.
EU Digital Services Act, AI and Algorithmic Accountability Provisions
The Digital Services Act regulates online intermediaries’ recommender systems, targeted advertising, and systemic risks. Duties cover transparency, accountability, and risk management. Requirements increase with platform size, with the strictest applying to very large online platforms and search engines (VLOPs and VLOSEs).
Federal Reporting and Disclosure Standard for AI Models (FCC Proceeding Directive)
This national AI policy directive instructs the Federal Communications Commission (FCC) to consider federal reporting and disclosure standards for AI models. An adopted standard would preempt conflicting state AI laws. A parallel AI Litigation Task Force would challenge state laws deemed inconsistent with the federal framework.
Illinois AI Safety Measures Act (SB 315)
The Illinois AI Safety Measures Act was signed on July 7, 2026. It requires annual independent safety audits of frontier (most advanced) AI models from AI developers earning more than $500 million annually. Results must be public, and the Illinois Attorney General can enforce civil penalties. It is described as the first US state law requiring these audits.
Illinois Biometric Information Privacy Act, AI Provisions
Illinois BIPA, 740 ILCS 14, restricts collection, storage, use, and disclosure of biometric identifiers and information. It affects AI processing facial geometry, voiceprints, iris scans, and similar data. BIPA has generated extensive biometric privacy litigation.
Korea AI Basic Act
South Korea’s foundational AI statute sets risk-based duties for developers and deployers. High-impact systems face additional requirements. The law also establishes national AI safety infrastructure.
New York City Local Law 144 of 2021, Automated Employment Decision Tools
NYC employers and employment agencies using covered automated tools for hiring or promotion must arrange annual bias audits. They must publish results and notify candidates before use.
Singapore Personal Data Protection Act, AI and Automated Decision-Making Amendments
Singapore’s 2020 personal data amendments and Personal Data Protection Commission (PDPC) guidance address AI and automated decisions. They add mandatory breach notification, expanded accountability, and responsible deployment guidance under the Model AI Governance Framework.
Texas Responsible AI Governance Act
Texas enacted its Responsible AI Governance Act on June 22, 2025. This entry describes rules focused on state government AI use, including accountability, transparency, and risk management. It notes that the enacted version removed most private-sector obligations from earlier proposals.
Executive Order: Eliminating State Law Obstruction of National Artificial Intelligence Policy
This executive order directs agencies to challenge state AI laws conflicting with national policy. It establishes an AI Litigation Task Force and a 90-day Commerce review of burdensome state rules. Federal Communications Commission (FCC) and Federal Trade Commission (FTC) work would develop federal reporting standards and policies intended to preempt conflicting requirements.
U.S. Executive Order: Promoting Advanced Artificial Intelligence Innovation and Security
This presidential action creates classified evaluations of frontier (most advanced) AI models’ hacking capabilities and a designation for covered models. Designated developers must provide federal access 30 days before public or commercial release. Confidentiality and cybersecurity protocols govern that access. The action primarily affects large frontier-model developers with potential cybersecurity implications.
Utah Artificial Intelligence Policy Act (SB 149)
Utah SB 149 requires AI interaction disclosures for covered businesses and people in regulated occupations. Missing disclosures or deceptive AI use can create liability under existing consumer protection law. It also establishes an AI Policy Office in the Department of Commerce to develop policy and coordinate guidance.
Washington State SB 5395 and SB 5886 (AI in Health Care and Right of Publicity)
Washington enacted two relevant statutes in 2026. SB 5395 prohibits healthcare providers from relying solely on AI to deny care through prior authorization. SB 5886 extends publicity rights to AI-generated likenesses, affecting organizations producing or deploying representations of individuals.
