AI rules and instruments
129 laws, regulations, guidelines, orders and bills that govern AI, each checked against its official source. Filter by jurisdiction, status, obligation or sector.
-
SB 947
Bars California employers from relying solely on automated decision systems for discipline or termination decisions, requires human review and corroboration, and requires notice to affected workers including a description of the data used. Protects workers from retaliation for asserting these rights.
Enacted, not yet in forceApplies 1 Jul 2027 -
SB 1119 / Adam's Law
Requires companion-chatbot operators, from 1 Jul 2027, to perform and document a comprehensive child-safety risk assessment before releasing a new or substantially modified chatbot, and to provide child-account protections and parental controls. Operators must also obtain independent child-safety audits (first by 1 Jan 2029 or before first public release, then every two years); the Attorney General can request audit reports for cause.
Enacted, not yet in forceApplies 1 Jul 2027 -
OSFI E-23
Supervisory guideline setting enterprise-wide model risk management expectations, explicitly covering AI/ML models, across the model lifecycle (inventory, risk rating, validation, monitoring, governance). Applies to federally regulated banks, insurers and trust and loan companies.
Enacted, not yet in forceApplies 1 May 2027 -
Illinois AI Safety Measures Act
Requires large frontier developers (over $500M revenue; models trained above 10^26 operations) to publish and annually update a frontier AI framework, issue transparency reports before deployment, protect unreleased model weights, report critical safety incidents within 72 hours (24 hours for imminent threats) and file annual disclosures with the Illinois Emergency Management Agency. It is the first US law to require annual independent third-party audits of frontier developers.
Enacted, not yet in forceApplies 1 Jan 2027 -
RAISE Act
Requires large frontier developers (over $500M revenue; models above 10^26 operations) to publish a frontier AI framework, file disclosure statements and pay fees to a new office in the Department of Financial Services, and report critical safety incidents within 72 hours (24 hours if imminent risk of death or serious injury). The March 2026 chapter amendment aligned the law closely with California's SB 53.
Enacted, not yet in forceApplies 1 Jan 2027 -
SB 26-189 (Colorado ADMT law)
Requires developers of automated decision-making technology that materially influences consequential decisions (education, employment, housing, lending, insurance, health care, government services) to give deployers technical documentation, and deployers to notify consumers at the point of use and explain the tool's role within 30 days of an adverse decision. Consumers can access and correct data and request meaningful human review; both parties keep records for 3 years.
Enacted, not yet in forceApplies 1 Jan 2027 -
Privacy Act ADM transparency
Requires entities covered by the Privacy Act to state in their privacy policies the kinds of personal information used, and the kinds of decisions made, by computer programs that make or substantially and directly assist decisions significantly affecting individuals' rights or interests. It is a transparency duty only, with no right to contest.
Partly in forceApplies 10 Dec 2026 -
New Product Liability Directive
Replaces the 1985 directive with no-fault liability for defective products that expressly covers software, including AI systems, and allows claims for damage including destroyed data; it eases the burden of proof for claimants in complex technical cases. It applies to manufacturers, importers and other economic operators for products placed on the EU market from 9 Dec 2026.
Enacted, not yet in forceApplies 9 Dec 2026 -
Chile data protection law (automated decisions)
New GDPR-style data protection law; Article 8 bis gives individuals the right to object to and not be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, with exceptions for contracts, express consent or law, and requires safeguards including information, explanation, human intervention and the right to contest. Applies to all controllers processing personal data in Chile.
Enacted, not yet in forceApplies 1 Dec 2026 -
EO 14434 ('Super Intelligence' terminology)
Requires executive-branch agencies, to the extent permitted by law, to use 'Super Intelligence' and 'SI' instead of 'Artificial Intelligence' and 'AI' in correspondence, websites, reports and policy documents, defining SI by reference to the existing statutory definition of AI (15 U.S.C. 9401(3)). It asks OSTP to propose legislation within 60 days on whether a statutory 'Super Intelligence' definition should supersede 'artificial intelligence'.
In forceEffective 29 Sep 2026 -
SB 813 / AB 1405
SB 813 creates a state framework to certify independent verification organizations that assess AI systems and models for safety and risk; AB 1405 has the Government Operations Agency set up a registry of AI auditors with independence and transparency standards and bars unregistered persons from conducting covered AI audits.
Enacted, not yet in forceAdopted 9 Sep 2026 -
AI & Data-Based Administration Act
Amends and renames the Data-Based Administration Act to create a legal basis for AI use across Korean public bodies: defines AI-based administration, creates AI and data administration officers, a shared AI platform for public institutions, and duties on agencies to train staff, ensure training-data quality and keep inventories of AI services.
In forceEffective 28 Aug 2026 -
Article 50 transparency guidelines
Explains the scope of Article 50 duties: telling people they are interacting with an AI system, marking synthetic audio/image/video/text, disclosing emotion-recognition and biometric categorisation, and labelling deepfakes and AI-generated public-interest text. Addressed to providers and deployers and to enforcing authorities.
In forceEffective 2 Aug 2026 -
AI content marking and labelling code
Voluntary code supporting AI Act Article 50(2), (4) and (5): providers of generative AI systems commit to machine-readable marking and detectability of AI outputs; deployers commit to labelling deepfakes and AI-generated text published on matters of public interest, using an EU icon set. The Commission and AI Board confirmed it as an adequate tool to demonstrate compliance; about 190 organisations had signed by end July 2026.
In forceEffective 2 Aug 2026 -
CA AI Transparency Act
Requires generative AI providers whose systems are publicly accessible in California to offer a free disclosure-verification tool and embed latent provenance disclosures (provider, system and version, creation date, unique identifier, and whether AI created or altered the content) in AI-generated or altered image, video and audio. AB 853 delayed operation to 2 Aug 2026 and extended duties to large online platforms (2027) and capture-device makers (2028); SB 1000 (urgency statute, effective 30 Sep 2026) removed the 1-million-user threshold and the manifest-label option.
Partly in forceEffective 2 Aug 2026 -
KI-MIG (German AI Act implementation law)
Implements the EU AI Act in Germany: makes the Bundesnetzagentur the central market surveillance authority with a coordination and competence centre, keeps sectoral regulators (e.g., BaFin for AI used in regulated financial services) competent in their fields, sets national fine provisions and requires the Bundesnetzagentur to run at least one AI regulatory sandbox. Applies to providers and deployers subject to the AI Act in Germany.
In forceEffective 29 Jul 2026 -
Digital Omnibus on AI
Amends the AI Act: postpones high-risk obligations to 2 Dec 2027 (Annex III stand-alone systems) and 2 Aug 2028 (Annex I product-embedded systems), adds bans on AI that generates non-consensual sexual images of identifiable people or child sexual abuse material from 2 Dec 2026, and gives pre-Aug-2026 generative systems until 2 Dec 2026 to watermark outputs. It also softens the AI-literacy duty to 'take measures to support' literacy, allows processing of special-category data for bias detection, simplifies registration, extends SME relief to small mid-caps and moves national sandbox deadline to 2 Aug 2027.
In forceEffective 27 Jul 2026 -
ANI v OpenAI (interim ruling)
The Delhi High Court refused ANI's application for an interim injunction against OpenAI, holding prima facie that storing ANI's articles to train the LLMs behind ChatGPT falls within the fair-dealing exception in Section 52(1)(a) of the Copyright Act and that ChatGPT's RAG-based outputs were not substantially similar to ANI's works. The findings are expressly prima facie; the substantive questions go to trial.
In forceEffective 24 Jul 2026 -
Protecting Victims Act (sexual deepfakes)
Expands the Criminal Code offence of non-consensual distribution of intimate images to cover sexual deepfakes, criminalises threatening to distribute such images, and raises the maximum penalty. Applies to individuals.
In forceEffective 18 Jul 2026 -
Anthropomorphic (companion) AI Measures
Covers AI services offered to the public in China that simulate human personality, thinking and communication style for sustained emotional interaction (AI companions, virtual partners). Bars 'virtual relative' or 'virtual partner' services for minors and requires a minors' mode and guardian consent for under-14s, reminders after every 2 hours of continuous use, easy exit, protections for elderly users, algorithm filing, and a security assessment when launching or when reaching 1 million registered or 100,000 monthly active users.
In forceEffective 15 Jul 2026 -
AI Basic Plan
Statutory national plan under Article 18 of the AI Promotion Act (Act No. 53 of 2025) setting government AI policy measures. The Cabinet adopted the second plan ('Japan AI Transformation') on 14 Jul 2026, replacing the first plan adopted on 23 Dec 2025.
In forceEffective 14 Jul 2026 -
FTC AI accuracy policy statement
Proposed FTC policy statement on how Section 5's ban on deceptive practices applies to companies marketing AI systems, focusing on undisclosed steering or distortion of AI outputs. It takes the position that complying with a state law does not excuse undisclosed distortion of outputs and that state laws requiring such conduct may be preempted.
In consultationProposed 7 Jul 2026 -
MODA AI Risk Framework
Framework issued under Article 16 of the AI Basic Act for sector regulators to build risk-based AI rules, using a four-step process (inventory AI use scenarios, identify, assess and respond to risks) and a taxonomy of 3 risk categories and 20 sub-categories.
In forceEffective 7 Jul 2026 -
UN Global Dialogue on AI Governance
Annual intergovernmental and multi-stakeholder dialogue on AI governance, alternating between Geneva and New York, that receives the Scientific Panel's report. The first session was held 6-7 Jul 2026 in Geneva alongside the AI for Good Summit; the 2027 session is set for New York alongside the STI Forum.
In forceEffective 6 Jul 2026 -
OSRA Act / Online Safety Commission
Creates a Commissioner of Online Safety and Online Safety Commission that can order platforms and users to act on 13 categories of online harm, and new statutory torts for victims. The first phase (from 29 Jun 2026) focuses on five harms including intimate image abuse and image-based child abuse, which cover AI-generated (deepfake) imagery.
Partly in forceEffective 29 Jun 2026 -
RBI draft Model Risk Management guidance
Draft RBI guidance covering governance of all models, including AI/ML and generative AI, used by commercial and co-operative banks, NBFCs, all-India financial institutions, ARCs and credit information companies. It builds on the 2024 draft on credit-model risk and the FREE-AI report, addressing explainability, bias, drift, hallucination, human oversight and customer disclosure of AI use.
In consultationProposed 24 Jun 2026 -
Bill C-36 (privacy reform)
Government bill to replace federal private-sector privacy law, including a requirement that organisations be transparent about using automated decision systems for significant decisions about individuals, stronger protection for children's data, and limits on surveillance pricing. It applies to private-sector organisations handling personal information.
ProposedProposed 15 Jun 2026 -
AI for All
Six-pillar national strategy that replaces the lapsed AIDA approach with commitments to modernise privacy law, introduce online safety laws, give legal tools against deepfakes, work on watermarking of AI content, create a Canada Trusted AI Certification programme and fund the Canadian AI Safety Institute (CAD 50 million). It is policy, not law.
In forceEffective 4 Jun 2026 -
Great American AI Act
Bipartisan discussion draft that would require large frontier AI developers to publish safety frameworks and transparency reports, report critical safety incidents to NIST's Center for AI Standards and Innovation, and undergo periodic independent audits. It would preempt state laws that specifically regulate AI model development for three years, while leaving state laws on AI use and deployment in place.
ProposedProposed 4 Jun 2026 -
EO 14409 (covered frontier models)
Directs NSA, CISA, Treasury and NIST to build a classified benchmark for the cyber capabilities of AI models and a threshold for designating 'covered frontier models', plus a voluntary framework under which developers give the government up to 30 days' pre-release access to such models. It also orders CISA directives on AI-enabled cyber defence, a Treasury-led AI vulnerability clearinghouse, and DOJ prioritisation of prosecutions for AI-enabled hacking.
In forceEffective 2 Jun 2026 -
Spanish AI governance bill
Government bill adapting Spanish law to the EU AI Act: designates market surveillance authorities (mainly AESIA, plus the AEPD and the General Council of the Judiciary by area), sets the sanctions regime, creates an inventory of AI systems used in state administrative procedures and governs AI sandboxes. Failing to disclose deepfakes ('ultrasuplantaciones') or AI interaction is classed as a serious infringement.
ProposedProposed 26 May 2026 -
High-risk classification guidelines (draft)
Draft guidance with practical examples of AI systems that are and are not high-risk under Article 6(1) (safety components of Annex I products) and Article 6(2) (Annex III use cases such as employment, credit scoring, education, biometrics). Published for targeted stakeholder feedback.
In consultationProposed 19 May 2026 -
Regulating for Growth Bill (sandboxes incl. AI)
Announced bill to create cross-economy regulatory sandbox powers allowing controlled live-market trials in which existing legal requirements can be modified or suspended for technologies including AI, building on the planned 'AI Growth Lab'. It would apply to firms admitted to sandboxes.
ProposedProposed 13 May 2026 -
SDAIA Deepfakes Guidelines
Guidance for deepfake technology developers, content creators and consumers that distinguishes malicious from beneficial uses and calls for explicit consent, personal-data protection, digital watermarking and source verification.
In forceEffective 8 May 2026 -
Planned AI law
The State Council 2026 legislative work plan (Guobanfa [2026] No. 14, dated 8 May 2026) commits to 'accelerating comprehensive legislation on the healthy development of AI' and to legislation on data, compute, algorithms and key AI applications. The NPCSC 2026 plan lists AI healthy-development legislation as a research-and-drafting item to be scheduled for review as appropriate.
ProposedProposed 8 May 2026 -
AI Agents Opinions
Policy document implementing the State Council 'AI+' action opinions for AI agents (systems with autonomous perception, memory, decision and execution). It sets principles (secure and controllable, orderly, innovation-driven), calls for technical standards and protocols, product rules and safety safeguards, industry self-regulation, and lists 19 priority application scenarios.
In forceAdopted 8 May 2026 -
Decree 142/2026 (AI Law implementing decree)
Implementing decree for the AI Law: requires providers to classify AI systems by risk before deployment, notify medium- and high-risk systems via the national one-stop AI portal run by MOST, clearly label audio, images or video that simulate a real person's appearance or voice, and report serious incidents (within 72 hours for loss-of-control incidents, 5 working days for other serious incidents, with a final report within 15 days). It also sets sandbox conditions.
In forceEffective 1 May 2026 -
Crime and Policing Act 2026 (nudification tools, AI CSAM generators)
Creates an offence of making, adapting or supplying a tool for generating purported intimate images (nudification apps), with a defence for taking all reasonable steps to prevent non-consensual use; creates offences relating to AI 'child sexual abuse image-generators'; and gives the Secretary of State power to extend Online Safety Act duties to providers of AI services regarding illegal AI-generated content. Applies to developers, suppliers and online services.
Partly in forceEffective 29 Apr 2026 -
Draft National AI Policy (withdrawn)
Cabinet-approved draft policy (25 Mar / 1 Apr 2026) published for comment proposing risk-based safeguards for high-risk AI and new institutional arrangements. The Minister withdrew it on 26 Apr 2026 after it was found to contain fictitious, apparently AI-generated, references.
WithdrawnProposed 10 Apr 2026 -
AI Guidelines for Business
Voluntary, living guidelines for AI developers, providers and business users in Japan covering common principles and role-specific practices. Version 1.2 was published on 31 Mar 2026, updating v1.0 (Apr 2024) and v1.1 (Mar 2025).
In forceEffective 31 Mar 2026 -
Draft IT Rules Second Amendment
Draft rules that would make compliance with MeitY clarifications, advisories, directions, SOPs and codes of practice part of intermediaries' due-diligence duties (new Rule 3(4)), tied to safe-harbour. A revised draft of 21 Apr 2026 added a requirement for a continuous, clearly visible label on synthetically generated visual content for its full duration.
In consultationProposed 30 Mar 2026 -
White House AI legislative framework
Non-binding recommendations asking Congress to pass a uniform federal AI framework that preempts 'unduly burdensome' state AI laws while preserving state police powers, generally applicable child-protection laws and zoning. It also proposes age-assurance and anti-self-harm features for AI services used by minors, a federal digital-replica right, regulatory sandboxes, and no new federal AI regulator.
ProposedProposed 20 Mar 2026 -
UK Copyright and AI report
Statutory report following the Dec 2024-Feb 2025 consultation: the Government states that a broad text-and-data-mining exception with rights-holder opt-out is no longer its preferred way forward and that it will not change copyright law until confident reforms meet its objectives, instead gathering more evidence on transparency, licensing, technical standards and enforcement. Relevant to AI developers and rights holders.
In forceAdopted 18 Mar 2026 -
Kenya AI Bill
Private member's bill proposing an EU-style four-tier risk framework, an Office of the Artificial Intelligence Commissioner with inspection and fining powers, a public register of high-risk systems, disclosure duties for all providers and deployers, and offences including non-consensual deepfakes. It would need passage by both Houses and presidential assent.
ProposedProposed 17 Mar 2026 -
TSE AI election rules 2026
Requires explicit, prominent labelling of AI-generated or manipulated electoral content and the technology used; bans publishing or boosting new synthetic content depicting candidates in the 72 hours before voting until 24 hours after; bars AI systems from ranking candidates, recommending votes or creating sexual imagery of candidates; and requires platforms to offer AI-declaration fields and compliance plans. Applies to campaigns, users and internet platforms.
In forceEffective 4 Mar 2026 -
AI Law
Comprehensive risk-based AI law classifying systems as high, medium or low risk, with conformity assessment and registration for high-risk systems, disclosure when users interact with AI, labelling of AI-generated audio/images/video that could mislead, incident reporting via a national AI portal, and prohibited practices. Foreign providers of high-risk systems need a local presence or representative.
In forceEffective 1 Mar 2026 -
IT Rules SGI/deepfake amendment
Defines 'synthetically generated information' (AI-made or altered audio/visual content that appears real) and requires intermediaries that enable its creation or sharing to prevent unlawful SGI, label it prominently and embed permanent metadata/unique identifiers. Significant social media intermediaries must collect user declarations on whether content is synthetic, verify them technically and label before publication; takedown timelines were cut (3 hours on government/court orders, 2 hours for non-consensual intimate imagery).
In forceEffective 20 Feb 2026 -
UN Scientific Panel on AI
40-member independent scientific panel established by consensus resolution to publish an annual, policy-relevant but non-prescriptive assessment of AI opportunities, risks and impacts. Members were appointed by the General Assembly for a three-year term starting 12 Feb 2026; its preliminary report was released 1 Jul 2026.
In forceEffective 12 Feb 2026 -
Deepfake intimate image creation offence
Inserts sections 66E-66H into the Sexual Offences Act 2003, making it an offence in England and Wales to create, or ask someone to create, a purported (including AI-generated) intimate image of an adult without consent or reasonable belief in consent. Applies to individuals.
In forceEffective 6 Feb 2026 -
DUAA automated decision-making reforms
Replaces UK GDPR Article 22 with new Articles 22A-22D: solely automated decisions with legal or similarly significant effects are broadly permitted on any lawful basis if safeguards apply (information, ability to contest, human intervention), while stricter limits remain for special-category data. Applies to all controllers using automated decision-making, including AI.
In forceEffective 5 Feb 2026 -
International AI Safety Report
Second annual scientific review of the capabilities and risks of general-purpose AI, authored by over 100 experts. It informs governments' frontier-AI policy but creates no obligations.
In forceAdopted 3 Feb 2026 -
Peru AI Regulation
Implements Peru's 2023 AI law with a risk-based scheme: lists prohibited ('uso indebido') uses such as manipulative systems, unlawful mass surveillance and most real-time public biometric identification, and sets transparency, documentation and human-oversight duties for high-risk uses in areas such as credit, employment, health, education and social programmes. Obligations phase in over 1-4 years by sector and organisation size.
In forceEffective 22 Jan 2026 -
MGF for Agentic AI
Voluntary framework, launched at the World Economic Forum in Davos, guiding organisations on deploying AI agents responsibly, with technical and non-technical measures to manage risks such as unauthorised or erroneous actions, while stressing that humans remain accountable.
In forceEffective 22 Jan 2026 -
AI Basic Act Enforcement Decree
Presidential Decree No. 36053 implementing the AI Basic Act: defines high-impact AI criteria, labelling methods (machine-readable watermarks allowed for general outputs; deepfakes need human-recognisable labels), the compute threshold for safety duties, and domestic-representative thresholds (prior-year revenue ≥ KRW 1 trillion, AI-service revenue ≥ KRW 10 billion, or ≥ 1 million average daily Korean users).
In forceEffective 22 Jan 2026 -
AI Basic Act
Horizontal AI law with promotion measures plus obligations for 'high-impact' AI (risk management, explanations, user protection, human oversight, documentation), generative AI notice and labelling (deepfakes must be clearly recognisable), safety duties for high-compute models (≥10^26 FLOPs per decree), and domestic-representative duties for large foreign AI firms. An amendment (Act No. 21311, 20 Jan 2026) renamed the national committee the National AI Strategy Committee and expanded support measures, some effective 21 Jul 2026.
In forceEffective 22 Jan 2026 -
BIS H200 case-by-case rule
Changes BIS licence review for exports to China and Macau of Nvidia H200-class and less advanced AI chips from a presumption of denial to case-by-case review, if the exporter certifies sufficient US supply, no diversion of foundry capacity, adequate recipient security, and independent US third-party performance testing. More advanced chips remain under the existing controls.
In forceEffective 15 Jan 2026 -
AI Basic Act
Framework law setting seven principles for AI, designating NSTC as the central competent authority and tasking MODA with an AI risk classification framework; sector regulators are to issue risk-based rules, high-risk AI products must carry clear warnings, and government may restrict or prohibit harmful AI uses. It imposes no immediate operational obligations on private companies.
In forceEffective 14 Jan 2026 -
Ontario AI-in-hiring disclosure
Provincial rule requiring employers with 25 or more employees to state in publicly advertised job postings whether artificial intelligence is used to screen, assess or select applicants. Applies to employers in Ontario.
In forceEffective 1 Jan 2026 -
HB 3773
Makes it a civil-rights violation for employers to use AI that has the effect of discriminating on the basis of protected classes in recruitment, hiring, promotion, discipline, discharge or other terms of employment, or to use zip codes as a proxy for protected classes. Employers must notify employees when they use AI for these purposes.
In forceEffective 1 Jan 2026 -
TRAIGA
Prohibits developing or deploying AI intended to incite self-harm or crime, to discriminate intentionally against protected classes (disparate impact alone is not enough), or to produce child sexual abuse material and unlawful deepfakes; bars government social scoring and certain biometric identification. Government agencies and health-care providers must disclose AI interactions, and a 36-month regulatory sandbox and advisory AI Council are created.
In forceEffective 1 Jan 2026 -
SB 243
Requires operators of 'companion chatbot' platforms to disclose that users are talking to AI, maintain protocols to detect and respond to suicidal ideation and self-harm (including crisis referrals), and, for known minors, give break reminders and block sexually explicit content. Operators must publish their protocols and report annually to the Office of Suicide Prevention.
In forceEffective 1 Jan 2026 -
CCPA ADMT regulations
Updates the California Consumer Privacy Act regulations to give consumers rights to pre-use notice, opt-out and access when businesses use automated decision-making technology for significant decisions (e.g. employment, lending, housing, health care, education), and requires risk assessments and annual cybersecurity audits for high-risk processing. Applies to businesses subject to the CCPA.
Partly in forceEffective 1 Jan 2026 -
AB 2013
Requires developers of generative AI systems made available to Californians (released or substantially modified since 1 Jan 2022) to post documentation on their websites about training data, including dataset sources, data types, whether copyrighted or personal information is included, and collection periods. Narrow exemptions cover security, aircraft and federal defence systems.
In forceEffective 1 Jan 2026 -
SB 53 / TFAIA
Requires developers of frontier models (trained with more than 10^26 operations) to publish transparency reports at release, and 'large frontier developers' (over $500M annual revenue) to publish and follow a frontier AI framework on catastrophic risk and send quarterly risk summaries to Cal OES. Critical safety incidents must be reported to Cal OES within 15 days (24 hours if there is imminent risk of death or serious injury), and whistleblowers are protected.
In forceEffective 1 Jan 2026 -
Cybersecurity Law amendment (AI)
Amends China's Cybersecurity Law to add a dedicated article (Art. 20) supporting AI research, infrastructure and training-data resources while requiring improved AI ethics norms, risk monitoring/assessment and safety supervision. The amendment also raises fines, up to RMB 10 million for especially serious harm.
In forceEffective 1 Jan 2026 -
AI Appropriateness Guideline
Guideline adopted by the AI Strategy Headquarters under the AI Promotion Act setting out what developers, providers and users should do to ensure AI is developed and used appropriately, drawing on the Hiroshima AI Process principles.
In forceEffective 19 Dec 2025 -
APS AI Policy v2
Mandatory policy for non-corporate Commonwealth entities (defence and intelligence excluded) requiring accountable officials, internal AI use-case registers with accountable owners, pre-deployment impact assessments, mandatory foundational AI training for APS staff, transparency statements and incident processes. Requirements phase in through 2026.
In forceEffective 15 Dec 2025 -
OMB M-26-04 ('Woke AI' procurement rules)
Implements EO 14319 (Preventing Woke AI in the Federal Government) by requiring agencies to buy only large language models that meet two 'Unbiased AI Principles' — truth-seeking and ideological neutrality — and to write compliance terms and vendor disclosure requirements into LLM contracts. Agencies had to update procurement policies by 11 Mar 2026 and should amend existing LLM contracts before exercising options.
In forceEffective 11 Dec 2025 -
State AI law preemption EO
Orders the Attorney General to set up an AI Litigation Task Force to challenge state AI laws, tells Commerce to publish a list of 'onerous' state AI laws within 90 days and to bar those states from remaining BEAD broadband non-deployment funds, and asks the FTC (policy statement) and FCC (possible preemptive disclosure standard) to act. It also orders a legislative proposal for a preemptive federal framework that would spare state child-safety, data-center and state-procurement laws.
In forceEffective 11 Dec 2025 -
International network of AI safety/security institutes
Government network, launched in November 2024, that shares methods for testing and evaluating advanced AI systems; in December 2025 it was renamed to focus on the science of AI measurement and evaluation, with the UK taking the coordinator role. No binding obligations.
In forceEffective 9 Dec 2025 -
National AI Plan
Australia's national AI plan to capture economic opportunity, spread benefits and keep people safe. Rather than a new AI-specific law with mandatory guardrails, the government will rely on and strengthen existing laws, and commits $29.9 million to establish an Australian AI Safety Institute in early 2026.
In forceEffective 2 Dec 2025 -
Digital Omnibus (data/GDPR)
Commission proposal (COM(2025) 837) that would, among other changes, confirm that training, testing and validation of AI systems on personal data can rely on legitimate interest under the GDPR and create a narrow exception for special-category data unavoidably present in training data. It would apply to all controllers processing personal data for AI development.
ProposedProposed 19 Nov 2025 -
MAS AI Risk Management Guidelines (AIRG)
Proposed supervisory guidelines requiring financial institutions to identify and inventory AI use, assess risk materiality, and apply proportionate controls across the AI lifecycle, with board and senior-management oversight. MAS proposed a 12-month transition after issuance.
In consultationProposed 13 Nov 2025 -
DPDP Act & Rules
India's horizontal data protection law, governing how 'data fiduciaries' (including AI developers and deployers) collect and process digital personal data, with consent, notice, security, breach-notification and data-principal rights. The DPDP Rules 2025 (notified 13/14 Nov 2025) operationalise it in phases: Data Protection Board provisions immediately, Consent Managers after 12 months and the main obligations after 18 months.
Partly in forceEffective 13 Nov 2025 -
DDADUE bill (AI Act authorities)
Omnibus EU-adaptation bill whose AI provisions designate France's AI Act authorities, with the CNIL in a central role alongside the DGCCRF, Arcom, ANSSI and around 15 sectoral bodies (e.g., ANSM, ACPR). The Senate adopted it on 18 Feb 2026; it was sent to the National Assembly on 20 Feb 2026.
ProposedProposed 10 Nov 2025 -
NY AI companion law
Requires operators of AI companions to detect signs of suicidal ideation or self-harm and refer users to crisis services, and to tell users they are interacting with AI at the start of a session and at least every three hours of continued use.
In forceEffective 5 Nov 2025 -
AI Governance Guidelines
Principle-based national framework built on seven 'sutras' (e.g. trust, people first, innovation over restraint) that relies on existing laws rather than a new AI statute. It recommends new institutions (an AI Governance Group, a Technology & Policy Expert Committee and an AI Safety Institute), voluntary industry measures, techno-legal tools and a national AI incident database.
In forceEffective 5 Nov 2025 -
Colorado DOI Reg. 10-1-1
Requires life, private passenger auto and health-benefit-plan insurers that use external consumer data, algorithms or predictive models to maintain documented governance and risk-management frameworks designed to detect and prevent unfair discrimination. Implements SB 21-169; the 2025 amendment extended it beyond life insurers.
In forceEffective 15 Oct 2025 -
Italian AI Law
First national AI law in the EU, complementing the AI Act: designates AgID and the National Cybersecurity Agency (ACN) as national AI authorities, requires parental authorisation for children under 14 to use AI, keeps final decisions with professionals in health care and public administration, sets workplace and professional disclosure duties, and creates a criminal offence for unlawfully disseminating harmful AI-generated deepfakes (1 to 5 years' imprisonment). It also clarifies copyright for AI-assisted works and text-and-data mining, and delegates further rules to the Government.
In forceEffective 10 Oct 2025 -
OMB M-25-22
Replaces M-24-18 and sets rules for how agencies buy AI: preference for American AI, protections against vendor lock-in, limits on vendors' use of government data, and performance-based contracting. It applies to contracts awarded under solicitations issued 180 days or more after issuance and to options exercised after that date.
In forceEffective 30 Sep 2025 -
GB 45438-2025 labelling standard
Mandatory national standard released alongside the CAC labelling measures, specifying how explicit labels and implicit (metadata) labels must be implemented for AI-generated text, images, audio, video and virtual scenes.
In forceEffective 1 Sep 2025 -
AIGC Labelling Measures
Requires service providers to add explicit (visible/audible) labels and implicit labels (metadata) to AI-generated text, images, audio, video and virtual scenes, and requires platforms distributing content to detect and flag AI content. App stores must check labelling compliance.
In forceEffective 1 Sep 2025 -
RBI FREE-AI Framework
RBI committee report setting 7 'sutras' and 26 recommendations under six pillars for AI use by banks, NBFCs and other regulated entities, including board-approved AI policies, AI incident reporting, disclosure to customers and an AI innovation sandbox. It is a framework report, not binding directions.
In forceAdopted 13 Aug 2025 -
GPAI guidelines and training-data summary template
Commission guidelines set technical criteria for when a model is 'general-purpose', when downstream modifiers become providers, and when open-source exemptions apply; a mandatory-format template requires GPAI providers to publish a summary of training data sources (including main datasets and top domain names). Applies to all providers placing GPAI models on the EU market.
In forceEffective 2 Aug 2025 -
GPAI Code of Practice
Voluntary code that GPAI model providers can sign to demonstrate compliance with AI Act Articles 53 and 55: a model documentation form, a copyright policy, and (for systemic-risk models only) safety and security practices. The Commission and AI Board confirmed it as an adequate compliance tool; signatories include Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI and OpenAI, with xAI signing only the Safety and Security chapter.
In forceEffective 2 Aug 2025 -
Illinois AI therapy ban (WOPR Act)
Prohibits offering therapy or psychotherapy in Illinois unless delivered by a licensed professional, and bars licensed professionals from letting AI make independent therapeutic decisions, communicate therapeutically with clients, or generate treatment plans without professional review. AI may be used for administrative and supplementary support.
In forceEffective 1 Aug 2025 -
AI Action Plan
Federal AI strategy built on three pillars (accelerate innovation, build AI infrastructure, lead in international AI diplomacy and security) that directs agencies to remove regulatory barriers, revise the NIST AI RMF, expand CAISI model evaluations, speed data-center permitting and promote exports of the US 'AI stack'. It also tells agencies to weigh a state's AI regulatory climate when awarding AI-related funding.
In forceEffective 23 Jul 2025 -
AI Promotion Act (AI Act)
Japan's first AI statute: a promotion-focused framework law that sets basic principles, creates the AI Strategy Headquarters chaired by the Prime Minister, mandates an AI Basic Plan, and lets the government investigate serious incidents and issue guidance, request cooperation and publicise misuse. It imposes no direct fines on businesses.
In forceEffective 4 Jun 2025 -
TAKE IT DOWN Act
Makes it a federal crime to knowingly publish non-consensual intimate images, including AI-generated 'digital forgeries', and threats to do so. Since 19 May 2026 'covered platforms' must run a notice-and-removal process and take down reported images and known identical copies within 48 hours, enforced by the FTC.
In forceEffective 19 May 2025 -
Utah mental-health chatbot law
Regulates generative-AI 'mental health chatbots': requires clear disclosures that the user is talking to AI, bans selling or sharing users' individually identifiable health information, restricts advertising during conversations, and sets documentation and written-policy expectations. Suppliers that maintain the required documentation and file a compliant written policy with the Division of Consumer Protection gain an affirmative defense to claims of unlicensed practice of mental health therapy.
In forceEffective 7 May 2025 -
OJK AI Governance for Banks
OJK guidance for commercial banks on developing and deploying AI (including advanced AI systems) responsibly, covering governance structures, risk management and consumer protection.
In forceEffective 29 Apr 2025 -
Global AI Hub Law (draft)
Draft law creating private, extended and virtual 'AI hubs' in Saudi Arabia where data and services of foreign 'guest' or designated states could be governed by those states' laws under bilateral arrangements (a data-embassy model).
ProposedProposed 14 Apr 2025 -
OMB M-25-21
Binding guidance for all federal agencies (including independent regulators) that replaces M-24-10: agencies must appoint Chief AI Officers, publish AI strategies and use-case inventories, and apply minimum risk-management practices (pre-deployment testing, impact assessments, human oversight) to 'high-impact AI'. Agencies had 365 days (to 3 Apr 2026) to document those practices and must stop using non-compliant high-impact AI.
In forceEffective 3 Apr 2025 -
Kenya National AI Strategy
National strategy for AI infrastructure, data, skills and ethical governance with priority sectors including agriculture, health and education. Non-binding.
In forceEffective 27 Mar 2025 -
SEBI Reg 16C (AI responsibility)
Makes every SEBI-regulated person that uses AI/ML tools – whether built in-house or bought from third parties – solely responsible for investor data privacy and security, for the outputs of those tools, and for compliance with applicable law. Parallel amendments apply to stock exchanges/clearing corporations and depositories.
In forceEffective 10 Feb 2025 -
G7 Hiroshima reporting framework
Voluntary public reporting framework through which AI developers, deployers and providers disclose how they implement the G7 Hiroshima Code of Conduct (risk management, testing, transparency, incident handling, content provenance). The first round produced 25 organisational reports; version 2.0 broadens participation, with submissions received by 30 Sep 2026 feeding the next review.
In forceEffective 7 Feb 2025 -
Prohibited-practices and AI-definition guidelines
Two non-binding Commission guidelines explaining, with examples, the AI practices banned under Article 5 (e.g., harmful manipulation, social scoring, workplace emotion recognition, real-time remote biometric identification) and how to decide whether software is an 'AI system' within the Act's scope. They address providers, deployers and market surveillance authorities.
In forceEffective 2 Feb 2025 -
EU AI Act
Risk-based EU law that bans certain AI practices, imposes conformity, documentation and oversight duties on high-risk AI systems, transparency duties on chatbots and generative AI, and separate duties on general-purpose AI (GPAI) model providers. It applies to providers, deployers, importers and distributors whose AI systems are placed on the EU market or whose outputs are used in the EU.
Partly in forceEffective 2 Feb 2025 -
EO 14179
Revokes the Biden-era EO 14110 on safe, secure and trustworthy AI and directs agencies to review and rescind actions taken under it. Sets federal policy to 'sustain and enhance America's global AI dominance' and ordered the AI Action Plan delivered in July 2025.
In forceEffective 23 Jan 2025 -
AI Opportunities Action Plan
Government plan (with 50 recommendations accepted) to expand compute, data access, AI adoption in the public sector and regulator-led sandboxes, within the UK's non-statutory, regulator-by-regulator approach to AI. A one-year-on progress report was published in January 2026.
In forceEffective 13 Jan 2025 -
FDA PCCP guidance
Final FDA guidance explaining how makers of AI-enabled medical devices can include a Predetermined Change Control Plan in 510(k), De Novo or PMA submissions describing planned model modifications, the protocol for developing and validating them, and an impact assessment. Changes made within an authorised PCCP do not need a new marketing submission.
In forceEffective 4 Dec 2024 -
Election deepfake ban
Prohibits publishing, boosting, sharing or reposting online election advertising containing realistic digitally generated or manipulated content (including AI deepfakes) that shows a candidate saying or doing something they did not. The ban runs from the issue of the writ of election until close of polling; returning officers can issue corrective directions.
In forceAdopted 15 Oct 2024 -
Deepfake Sexual Material Act
Creates Commonwealth offences for transmitting sexual material depicting adults without their consent using a carriage service, expressly covering material created or altered with technology such as AI deepfakes, with aggravated offences where the person also created the material.
In forceEffective 3 Sep 2024 -
Nigeria National AI Strategy
Draft strategy setting goals for AI infrastructure, talent, adoption and an ethical governance framework, including proposals for risk-based oversight. It is a policy document with no binding obligations.
In consultationProposed 2 Aug 2024 -
AU Continental AI Strategy
Continental strategy endorsed by the AU Executive Council at its 45th Ordinary Session (Accra, 18-19 Jul 2024) calling for an Africa-centric, development-focused approach to AI, unified national strategies, ethical and inclusive governance and regional cooperation. Non-binding guidance for AU member states.
In forceEffective 19 Jul 2024 -
UAE AI Charter
Federal policy charter setting 12 principles for AI development and use in the UAE, including human-machine ties, safety, algorithmic bias, data privacy, transparency, human oversight, governance and accountability, and compliance with treaties and applicable laws.
In forceEffective 10 Jun 2024 -
MGF for GenAI
Voluntary framework setting out nine dimensions for trustworthy generative AI (e.g. accountability, data, trusted development, incident reporting, testing and assurance, security, content provenance, safety R&D, AI for public good). It extends Singapore's 2019/2020 Model AI Governance Framework for traditional AI.
In forceEffective 30 May 2024 -
Council of Europe AI Convention
First legally binding international AI treaty: parties must ensure AI activities across the lifecycle respect human rights, democracy and the rule of law, with risk and impact management, transparency, oversight and remedies, applying fully to public authorities and, by party choice, to private actors. Opened for signature 5 Sep 2024; signatories include the EU, UK, US, Canada, Japan, Israel, Switzerland, Norway and Ukraine.
Enacted, not yet in forceAdopted 17 May 2024 -
Colorado AI Act (SB 24-205)
First US risk-based AI law: required developers and deployers of 'high-risk' AI systems to use reasonable care against algorithmic discrimination, with impact assessments, risk-management programmes, consumer notices and reporting to the Attorney General. Its start date moved from 1 Feb 2026 to 30 Jun 2026 (SB 25B-004) and it was repealed and replaced by SB 26-189 before taking effect.
SupersededAdopted 17 May 2024 -
Utah AI Policy Act
Requires disclosure of generative AI use in consumer transactions when a consumer asks, and proactive disclosure in 'high-risk' interactions and in regulated occupations (e.g. health, legal, financial advice); makes companies liable under consumer-protection law for their generative AI's statements. Creates the Office of Artificial Intelligence Policy and an AI 'Learning Lab' that can grant regulatory mitigation agreements.
In forceEffective 1 May 2024 -
IndiaAI Mission
National programme approved by the Union Cabinet with an outlay of ₹10,371.92 crore to build AI compute (subsidised GPU access via public-private partnership), datasets (AIKosh), foundation models, skills and 'Safe & Trusted AI' projects. By Feb 2026 the government reported over 38,000 GPUs onboarded.
In forceAdopted 7 Mar 2024 -
OSA intimate image (incl. deepfake) sharing offences
Makes it an offence to share, or threaten to share, a photograph or film that 'shows, or appears to show' another person in an intimate state without consent, which captures AI-generated deepfakes. Platforms in scope of the Online Safety Act must treat such content as illegal content under Ofcom's codes.
In forceEffective 31 Jan 2024 -
SE 9/2023 AI Ethics
Ethical guidance for businesses and public/private electronic system operators that develop or use AI in Indonesia, covering values such as inclusivity, humanity, security, transparency, credibility and accountability, personal data protection and sustainability.
In forceEffective 19 Dec 2023 -
AESIA Statute
Creates AESIA, based in A Coruña, as the state agency to supervise AI and serve as Spain's main AI Act market surveillance authority. It defines the agency's functions, governance and powers.
In forceAdopted 22 Aug 2023 -
Generative AI Measures
Applies to providers of generative AI services (text, image, audio, video) to the public in mainland China. Requires lawful training data that respects IP, content controls, labelling of generated content, user protections and, for services with 'public opinion attributes or social mobilisation capacity', a security assessment plus algorithm filing.
In forceEffective 15 Aug 2023 -
NYC Local Law 144
Bars employers and employment agencies in New York City from using automated employment decision tools unless the tool had an independent bias audit within the past year, a summary of the audit is public, and candidates or employees receive notice at least 10 business days before use.
In forceEffective 5 Jul 2023 -
Brazil AI Bill (Marco Legal da IA)
Risk-based AI framework passed by the Federal Senate in December 2024: bans excessive-risk systems, imposes impact assessments and governance duties on high-risk uses, adds copyright remuneration for training data and creates a National AI Regulation and Governance System coordinated by the data protection authority (ANPD). It would apply to developers, distributors and deployers of AI in Brazil.
ProposedProposed 3 May 2023 -
NIST AI RMF
Voluntary framework (Govern, Map, Measure, Manage) for managing AI risks across the lifecycle, with a Generative AI Profile and, since 7 Apr 2026, a concept note for a critical-infrastructure profile. NIST states the AI RMF 1.0 'is being revised as part of the White House AI Action Plan', which calls for removing references to misinformation, DEI and climate change.
In forceEffective 26 Jan 2023 -
Deep Synthesis Provisions
Regulates providers and technical supporters of 'deep synthesis' (deepfake-type) services generating or editing text, voice, images, video and virtual scenes. Requires real-name user verification, conspicuous labelling of synthetic content that could confuse the public, consent for editing biometric features, and algorithm filing.
In forceEffective 10 Jan 2023 -
Algorithm Recommendation Provisions
Governs recommendation, ranking, generation/synthesis, dispatch and decision algorithms used by internet services in China. Requires algorithm filing with CAC for services with public-opinion attributes, user options to turn off personalisation, protections for minors, the elderly, gig workers and consumers (e.g. no discriminatory pricing).
In forceEffective 1 Mar 2022 -
National AI Strategy 2031
National strategy with eight objectives aiming to make the UAE a global AI leader by 2031, covering priority sectors, talent, research, data infrastructure, AI in government services and governance/regulation.
In forceAdopted 21 Apr 2019 -
Directive on Automated Decision-Making
Binding policy instrument requiring federal institutions using automated decision systems to complete an Algorithmic Impact Assessment, give notice and explanations, ensure human intervention for higher-impact decisions, test for bias and publish results. Latest version dated 24 Jun 2025; systems procured before then had until 24 Jun 2026 to meet the updated requirements.
In forceEffective 1 Apr 2019 -
Digital Economy and E-Governance Bill
Omnibus digital-economy bill that would set rules for electronic transactions and government digitisation and establish a framework for AI adoption that sorts AI systems into categories with different deployment requirements, with NITDA expected to lead policy. It would apply to public bodies and businesses deploying digital and AI systems in Nigeria.
Proposed -
Chile AI Bill
EU-style risk-based bill regulating uses of AI systems that the Chamber of Deputies approved on 13 Oct 2025; it is now before the Senate's Future Challenges committee. In 2026 the Executive announced it would replace the text with a lighter 'enabling law' focused on sandboxes, standards and ex-post enforcement.
Proposed -
Mexico AI law initiatives
Multiple initiatives are pending in committee, including an April 2026 proposal to amend Constitution Article 73 so Congress can issue a general AI law, a Senate proposal for a General AI Law, and a July 2026 proposal for a Federal AI Development Law with a National AI Council and risk 'traffic-light' system. None has been approved.
Proposed -
Draft AI Perpres
Two draft presidential regulations – a National AI Roadmap 2026–2029 and National AI Ethics – being prepared by Komdigi with a risk-based approach and priority on education, health, finance and the public sector. Inter-ministerial committee discussions were held in Feb 2026; as of mid-July 2026 the drafts were still being processed toward a Perpres.
Proposed -
SDAIA AI Ethics Principles
National principles and controls for responsible AI applying to public, private and non-profit entities developing or using AI in Saudi Arabia, covering fairness, privacy and security, humanity, social and environmental benefit, reliability and safety, transparency and explainability, and accountability, with risk-based controls across the AI lifecycle.
In force -
DIFC Regulation 10
Applies within the DIFC free zone to deployers and operators of AI systems that process personal data. Requires clear notice at first use describing purposes, underlying principles and safeguards; certification-based demonstrations of compliance; and for high-risk processing an Autonomous Systems Officer with DPO-like duties.
In force -
ICMR AI health ethics guidelines
Ethical principles and stakeholder responsibilities for developing, validating, deploying and adopting AI in biomedical research and healthcare in India, including ethics-committee review processes and informed-consent requirements for AI-based research.
In force
No rules match these filters. Clear a filter to see more.