Global AI Regulatory Landscape
AI is governed through an evolving combination of AI-specific law, privacy and consumer-protection rules, sector requirements, agency enforcement, voluntary guidance, and technical standards. This resource provides a high-level orientation to that landscape and links to official or primary sources where possible.
Information only—not legal advice. This resource provides a high-level, evolving overview of AI-related laws, guidance, standards, and regulatory institutions. It does not determine whether a requirement applies to a particular organization, system, jurisdiction, or use case. Obtain advice from qualified legal and compliance professionals before relying on this information.
The OECD AI Policy Observatory maintains a living global database of AI policies, strategies, and initiatives. Coverage, classifications, and policy counts change over time; consult the Observatory for current information.
The Four-Register Framework
To turn this highly dynamic landscape into an actionable engineering and compliance roadmap, the Cognitive Insight Audit Framework (CIAF) advocates modeling the regulatory universe into Four Structured Registers:
- Binding AI-Specific Law (Statutes, regulations, and treaty-level obligations).
- General Law Applied to AI (Data privacy, intellectual property, civil rights, and competition laws).
- Soft Law (Executive orders, agency guidance, and voluntary codes).
- Standards & Assurance Artifacts (ISO/IEC certifications, NIST frameworks, and conformity audits).
See AGEI / CIAF Control Mappings for illustrative technical evidence patterns.
The Core AI Regulatory Registry
Last reviewed: August 2026
| Jurisdiction | Instrument or regime | Status / effective date | Applicability trigger | Covered party | Operational obligation | Official source |
|---|---|---|---|---|---|---|
| European Union | EU AI Act (Regulation (EU) 2024/1689) | Enacted. Phased applicability through Aug 2026+ | Market offering or deployment of AI systems, or output use in the EU. High-risk systems. | Provider, Deployer, Importer, Distributor | Risk management systems, automatic logging, human oversight, transparency, quality management, and CE marking. Illustrative AGEI / CIAF evidence mappingPotential technical evidence patterns may include versioned policy rules, gate evaluations, authority grants, signed lifecycle receipts, evidence objects, and audit-pack exports. This is not a determination that these controls satisfy any specific legal obligation. | Link |
| Council of Europe | Framework Convention on AI, Human Rights, Democracy, and the Rule of Law | Adopted treaty. Open for signature. | Lifecycle activities of AI systems that may interfere with human rights, democracy, and rule of law. | State Parties, Public authorities, Private actors (via state implementation) | Ensure human dignity, transparency, accountability, equality, and non-discrimination. Establish remedies for violations. Illustrative AGEI / CIAF evidence mappingPotential technical evidence patterns may include human-in-the-loop oversight workflows, automated incident flagging, and immutable lifecycle receipts tracking bias reviews. This is not a determination that these controls satisfy any specific legal obligation. | Link |
| United States (Federal) | Sectoral Agency Enforcement (FTC, EEOC, CFPB) | Active enforcement of existing general law. | Unfair/deceptive practices, employment screening, credit determination, consumer finance. | Employers, Creditors, Service Providers, Developers | Prevent algorithmic discrimination, ensure adverse action notifications, avoid deceptive AI claims, and maintain transparency in automated decisions. Illustrative AGEI / CIAF evidence mappingPotential technical evidence patterns may include granular processing_activity logs mapped to specific consumer consent records, and versioned policy sets enforcing fair lending or hiring rules. This is not a determination that these controls satisfy any specific legal obligation. | Link |
| United States (State) | Colorado SB24-205 | Enacted. Applies phased through 2026. | Developers or deployers of high-risk AI systems in Colorado making consequential decisions. | Developers, Deployers | Duty of reasonable care, risk management policies, impact assessments, transparency notices to consumers, and algorithmic discrimination prevention. Illustrative AGEI / CIAF evidence mappingPotential technical evidence patterns may include gated deployments based on verified impact assessments (audit_packs), and mandatory incident reporting workflows. This is not a determination that these controls satisfy any specific legal obligation. | Link |
| China | Interim Measures for GenAI Services | Enacted. Applicable. | Providing generative AI services to the public within mainland China. | Service Providers | Algorithm security assessments, real-name identity verification, prompt/output logging, handling illegal content, and labeling synthetic outputs. Illustrative AGEI / CIAF evidence mappingPotential technical evidence patterns may include strict identity binding (tenant_identity), content provenance metadata (artifact_release_records), and mandatory shadow AI logging. This is not a determination that these controls satisfy any specific legal obligation. | Link |
Information only—not legal advice. This resource provides a high-level, evolving overview of AI-related laws, guidance, standards, and regulatory institutions. It does not determine whether a requirement applies to a particular organization, system, jurisdiction, or use case. Obtain advice from qualified legal and compliance professionals before relying on this information.