Global AI Regulatory Landscape

AI is governed through an evolving combination of AI-specific law, privacy and consumer-protection rules, sector requirements, agency enforcement, voluntary guidance, and technical standards. This resource provides a high-level orientation to that landscape and links to official or primary sources where possible.

Information only—not legal advice. This resource provides a high-level, evolving overview of AI-related laws, guidance, standards, and regulatory institutions. It does not determine whether a requirement applies to a particular organization, system, jurisdiction, or use case. Obtain advice from qualified legal and compliance professionals before relying on this information.

The OECD AI Policy Observatory maintains a living global database of AI policies, strategies, and initiatives. Coverage, classifications, and policy counts change over time; consult the Observatory for current information.


The Four-Register Framework

To turn this highly dynamic landscape into an actionable engineering and compliance roadmap, the Cognitive Insight Audit Framework (CIAF) advocates modeling the regulatory universe into Four Structured Registers:

  • Binding AI-Specific Law (Statutes, regulations, and treaty-level obligations).
  • General Law Applied to AI (Data privacy, intellectual property, civil rights, and competition laws).
  • Soft Law (Executive orders, agency guidance, and voluntary codes).
  • Standards & Assurance Artifacts (ISO/IEC certifications, NIST frameworks, and conformity audits).

See AGEI / CIAF Control Mappings for illustrative technical evidence patterns.


The Core AI Regulatory Registry

Last reviewed: August 2026

JurisdictionInstrument or regimeStatus / effective dateApplicability triggerCovered partyOperational obligationOfficial source
European UnionEU AI Act (Regulation (EU) 2024/1689)Enacted. Phased applicability through Aug 2026+Market offering or deployment of AI systems, or output use in the EU. High-risk systems.Provider, Deployer, Importer, Distributor

Risk management systems, automatic logging, human oversight, transparency, quality management, and CE marking.

Illustrative AGEI / CIAF evidence mapping

Potential technical evidence patterns may include versioned policy rules, gate evaluations, authority grants, signed lifecycle receipts, evidence objects, and audit-pack exports. This is not a determination that these controls satisfy any specific legal obligation.

Link
Council of EuropeFramework Convention on AI, Human Rights, Democracy, and the Rule of LawAdopted treaty. Open for signature.Lifecycle activities of AI systems that may interfere with human rights, democracy, and rule of law.State Parties, Public authorities, Private actors (via state implementation)

Ensure human dignity, transparency, accountability, equality, and non-discrimination. Establish remedies for violations.

Illustrative AGEI / CIAF evidence mapping

Potential technical evidence patterns may include human-in-the-loop oversight workflows, automated incident flagging, and immutable lifecycle receipts tracking bias reviews. This is not a determination that these controls satisfy any specific legal obligation.

Link
United States (Federal)Sectoral Agency Enforcement (FTC, EEOC, CFPB)Active enforcement of existing general law.Unfair/deceptive practices, employment screening, credit determination, consumer finance.Employers, Creditors, Service Providers, Developers

Prevent algorithmic discrimination, ensure adverse action notifications, avoid deceptive AI claims, and maintain transparency in automated decisions.

Illustrative AGEI / CIAF evidence mapping

Potential technical evidence patterns may include granular processing_activity logs mapped to specific consumer consent records, and versioned policy sets enforcing fair lending or hiring rules. This is not a determination that these controls satisfy any specific legal obligation.

Link
United States (State)Colorado SB24-205Enacted. Applies phased through 2026.Developers or deployers of high-risk AI systems in Colorado making consequential decisions.Developers, Deployers

Duty of reasonable care, risk management policies, impact assessments, transparency notices to consumers, and algorithmic discrimination prevention.

Illustrative AGEI / CIAF evidence mapping

Potential technical evidence patterns may include gated deployments based on verified impact assessments (audit_packs), and mandatory incident reporting workflows. This is not a determination that these controls satisfy any specific legal obligation.

Link
ChinaInterim Measures for GenAI ServicesEnacted. Applicable.Providing generative AI services to the public within mainland China.Service Providers

Algorithm security assessments, real-name identity verification, prompt/output logging, handling illegal content, and labeling synthetic outputs.

Illustrative AGEI / CIAF evidence mapping

Potential technical evidence patterns may include strict identity binding (tenant_identity), content provenance metadata (artifact_release_records), and mandatory shadow AI logging. This is not a determination that these controls satisfy any specific legal obligation.

Link

Information only—not legal advice. This resource provides a high-level, evolving overview of AI-related laws, guidance, standards, and regulatory institutions. It does not determine whether a requirement applies to a particular organization, system, jurisdiction, or use case. Obtain advice from qualified legal and compliance professionals before relying on this information.