AI Regulatory Landscape
Navigate AI regulations, governance frameworks, and compliance requirements across 17 jurisdictions.
European Union · August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Aug 2026)
The world's first comprehensive AI regulatory framework. Takes a risk-based approach, categorizing AI systems into four risk tiers: unacceptable risk (banned), high risk (regulated), limited risk (transparency obligations), and minimal risk (voluntary codes). Applies to providers, deployers, importers, and distributors placing AI systems on the EU market.
United States · January 2023 - Published (voluntary adoption, ongoing updates)
The NIST AI Risk Management Framework provides voluntary guidance for managing AI-related risks across organizations. Organized around four core functions: GOVERN, MAP, MEASURE, and MANAGE. Widely adopted as best practice guidance and referenced in US federal contracts and procurement.
International · December 2023 - Published (certification available immediately)
The first international standard for AI Management Systems (AIMS). Provides a certifiable framework for responsible AI development and deployment, analogous to ISO 27001 for information security. Enables organizations to demonstrate third-party verified AI governance maturity.
European Union · May 2018 - In Force. Expanded AI-specific guidance issued 2023–2024.
The General Data Protection Regulation (GDPR) imposes significant requirements on AI systems that process personal data of EU residents. Applies from training data collection through to AI inference and decision-making. Enforced by national Data Protection Authorities (DPAs) across 27 EU member states.
United Kingdom · 2023 - Active (evolving framework, legislation expected 2025-2026)
UK's approach to AI safety combines the AI Safety Institute (AISI) for frontier AI evaluation, sector-specific guidance from regulators, and a principles-based voluntary code. Pro-innovation in stance compared to EU AI Act - sector regulators (FCA, ICO, CMA) apply existing powers to AI rather than a single AI law.
United States · October 2023 - Active (some provisions under review by new administration, Jan 2025)
Executive Order 14110 on Safe, Secure, and Trustworthy AI, signed October 30, 2023. Requires safety testing reports from frontier AI developers, establishes federal AI governance, and directs 50+ agencies to develop sector-specific AI guidance. Key threshold: models trained with >10^26 FLOPs must report to government.
China · August 2023 - In Force
China has the world's most active AI regulatory environment, with multiple overlapping rules: Interim Measures for Generative AI (Aug 2023), Algorithm Recommendation Regulations (Mar 2022), Deep Synthesis (Deepfake) Regulations (Jan 2023), and Cross-Border Data Transfer Rules. Enforced by CAC (Cyberspace Administration of China).
International · 2019 - Published (v2 in development)
IEEE's Ethically Aligned Design (EAD) is a comprehensive voluntary framework for ethical AI and autonomous systems. Developed by 700+ global experts. Covers human rights, well-being, data agency, effectiveness, transparency, accountability, and the prevention of AI weaponization. Widely referenced in engineering ethics education and AI governance policies.
Canada · Proposed 2024-2025 (pending Parliamentary approval as of 2024)
The Artificial Intelligence and Data Act (AIDA) is Canada's proposed federal AI regulation, introduced as Part 3 of Bill C-27 (alongside updates to PIPEDA). Risk-based approach similar to the EU AI Act. A proposed AI and Data Commissioner would have oversight, investigative, and order-making powers.
Singapore · January 2019 (v1), updated 2020. AI Verify (2022).
Singapore's Model AI Governance Framework provides detailed practical guidance for private sector organizations deploying AI. Developed by PDPC, emphasizes human-centric AI with detailed implementation guides. Supplemented by AI Verify - an AI governance testing toolkit and certification program.
Australia · 2019 - Ethics Framework; 2024 - Mandatory Guardrails for Government.
Australia's AI Ethics Framework provides eight principles for ethical AI. Supplemented by mandatory guardrails for Australian government high-risk AI procurement (2024). The government is developing a risk-based regulatory approach, with regulation anticipated in high-risk domains (automated decisions, biometrics, critical infrastructure).
International (OECD Members) · May 2019 - Adopted. Continuously updated.
The OECD Principles on Artificial Intelligence were adopted May 2019 and endorsed by G20 leaders - the first intergovernmental AI standard. They form the foundation for most national AI regulatory frameworks globally. The OECD.AI Policy Observatory tracks global implementation across 70+ countries.
G7 Nations · October 2023 - Published. Voluntary Code of Conduct.
The G7 Hiroshima AI Process was launched at the 2023 G7 Summit to develop international guiding principles specifically for advanced AI/foundation models. Produced 11 International Guiding Principles and a voluntary Code of Conduct for AI developers. Focus on frontier model safety, transparency, and watermarking.
India · August 2023 - In Force. Rules and enforcement by Data Protection Board anticipated 2025.
India's Digital Personal Data Protection Act 2023 establishes comprehensive data protection for digital personal data of Indian citizens. Significant implications for AI systems processing personal data - including training, inference, and automated decision-making affecting Indian individuals.
United States (Global Acceptance) · Ongoing - Updated periodically by AICPA.
SOC 2 Type II has become the de facto security and trust certification for AI SaaS companies. Auditors are developing AI-specific criteria covering model governance, training data security, bias testing, and algorithmic fairness alongside traditional Trust Service Criteria (TSC).
United States · Ongoing - FTC Act applies continuously; AI-specific guidance issued 2021-2024.
The US Federal Trade Commission applies existing consumer protection and competition laws (Section 5 FTC Act) to AI systems - prohibiting deceptive AI capability claims, biased algorithms causing discriminatory harm, and unfair AI-driven practices. The FTC is actively investigating and taking enforcement action against AI companies.
United States · 2021 - Action Plan published; PCCP guidance finalized 2023; ongoing enforcement.
The FDA regulatory framework for AI/ML-based Software as a Medical Device (SaMD) addresses how AI models can be continuously updated post-deployment while maintaining safety and effectiveness. Requires pre-market submission for high-risk devices, post-market surveillance, and a Predetermined Change Control Plan for AI updates.
Brazil · Anticipated 2026–2027 after enactment and transition period (bill still in Chamber of Deputies as of mid-2025)
Brazil's AI Bill (PL 2338/2023) was approved by the Brazilian Senate in June 2024 and is under review in the Chamber of Deputies. Inspired heavily by the EU AI Act, it adopts a risk-based classification approach (minimal, limited, high risk), establishes AI governance requirements, and creates an oversight authority. Brazil is the 8th-largest economy and home to 215 million people — the largest AI regulatory jurisdiction in Latin America.
South Korea · January 2026 (enacted January 2024; 2-year transition period)
South Korea's Framework Act on the Development of Artificial Intelligence and Establishment of Trust (AI Basic Act) was enacted in January 2024 and enters into force in January 2026. It is the first comprehensive AI law in East Asia (outside China) and takes a risk-based approach distinguishing high-impact AI requiring transparency and conformity assessment from general AI. Enforced by the Ministry of Science and ICT (MSIT).
Japan · April 2024 — Published (voluntary). Existing laws (APPI, sector regulations) enforced by respective authorities.
Japan's Ministry of Economy, Trade and Industry (METI) and Cabinet Office published the AI Guidelines for Business in April 2024 — a voluntary, principles-based framework for responsible AI development and use. Japan takes a notably pro-innovation stance: rather than binding AI-specific legislation, it relies on existing laws (Act on Protection of Personal Information, copyright law, Unfair Competition Prevention Act) supplemented by voluntary guidance. The framework strongly emphasizes human-centricity, sustainability, and international interoperability, aligning with OECD AI Principles and G7 Hiroshima AI Process commitments.
United Arab Emirates · 2017 — Active (evolving framework; UAE PDPL in force Nov 2021; sector guidance ongoing)
The UAE was the first country in the world to appoint a Minister of State for Artificial Intelligence (2017) and launched the UAE National AI Strategy 2031 — aiming to make the UAE a global AI hub and derive 50% of government services from AI by 2031. The UAE combines aspirational AI adoption with a sector-specific regulatory approach: the CBUAE (Central Bank) and TDRA (Telecommunications and Digital Government Regulatory Authority) issue AI-specific guidance for their sectors. The UAE's AI governance model is pro-innovation and explicitly designed to attract AI companies and investment.
European Union · October 2024 (entered force); cybersecurity reporting obligations apply December 2025; full product requirements apply October 2027
The EU Cyber Resilience Act (Regulation 2024/2847) establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market — including AI-enabled software, connected hardware, and AI components embedded in products. Signed into law October 2024, it fills a critical gap alongside the EU AI Act by ensuring AI-powered products meet baseline security-by-design requirements throughout their lifecycle.