AI Regulatory Applicability Navigator

Use this checklist to identify categories of AI-related laws, regulations, guidance, and standards that may merit further review. It is an orientation tool, not a legal applicability determination.

Information only—not legal advice. This resource provides a high-level, evolving overview of AI-related laws, guidance, standards, and regulatory institutions. It does not determine whether a requirement applies to a particular organization, system, jurisdiction, or use case. Obtain advice from qualified legal and compliance professionals before relying on this information.

Intake Questionnaire

Consider the following questions regarding your AI system. We do not collect, transmit, or persist your answers.

1
Where do you operate, offer, deploy, or make the AI system available?
2
Who uses the system, and who may be affected by its outputs or decisions?
3
What role does the organization play: provider, deployer, integrator, employer, controller, processor, distributor, or another role?
4
Does the system make, recommend, rank, or materially influence consequential decisions?
5
Does the system process personal, biometric, health, financial, employment, children’s, or other sensitive data?
6
Is the system customer-facing, workforce-facing, safety-critical, public-sector-facing, or part of a regulated product or service?
7
Does the system generate synthetic content, make recommendations, make predictions, or exercise tool/action authority?
8
Does the system operate across multiple jurisdictions, organizations, vendors, or data environments?

Guidance Output

Based on your answers to the questions above, you may need to investigate the following categories of obligations:

  • AI-specific laws and high-risk or prohibited-use restrictions.
  • Privacy, data-protection, retention, and cross-border transfer obligations.
  • Consumer protection, deception, transparency, and synthetic-content disclosure requirements.
  • Employment, civil-rights, accessibility, and anti-discrimination rules.
  • Sector-specific requirements for health, finance, insurance, education, government, or critical infrastructure.
  • Product safety, cybersecurity, incident reporting, and contractual obligations.
  • Voluntary frameworks, customer procurement requirements, and assurance standards.

The presence of a category does not establish that a specific rule applies. Organizations should obtain qualified legal and compliance advice before making deployment, product, market-entry, or control-design decisions.

Information only—not legal advice. This resource provides a high-level, evolving overview of AI-related laws, guidance, standards, and regulatory institutions. It does not determine whether a requirement applies to a particular organization, system, jurisdiction, or use case. Obtain advice from qualified legal and compliance professionals before relying on this information.