LIVE
EU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series E
Compliance & Governance

AI Compliance & Regulatory Frameworks

EU AI Act compliance, GDPR, NIST AI RMF, ISO/IEC 42001 and more — 35 frameworks across 25 jurisdictions, each explained with scope, obligations, enforcement, and penalties.

This is educational guidance. Always consult legal counsel for compliance decisions.

EU AI Act compliance: the four risk tiers

The EU AI Act is the first comprehensive AI law and takes a risk-based approach: your obligations depend entirely on which tier a system falls into. It applies to providers, deployers, importers, and distributors placing AI on the EU market — including those based outside the EU. It entered into force in August 2024 and applies in phases: prohibitions from February 2025, general-purpose AI model obligations from August 2025, and high-risk obligations from August 2026. Penalties reach €35M or 7% of global annual turnover.

Unacceptable risk

Prohibited outright. Includes social scoring and certain manipulative or exploitative AI practices. These systems cannot be placed on the EU market at all.

High risk

Permitted but heavily regulated. Requires risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity measures, conformity assessment with CE marking, and registration in the EU database.

Limited risk

Transparency obligations. People must be told when they are interacting with an AI system, and synthetic or manipulated content must be disclosed.

Minimal risk

No specific obligations. Most business software and recommendation systems fall here, with voluntary codes of conduct encouraged.

Read the full EU AI Act guide — scope, key requirements, who is exempt, timeline, and enforcement.

How to choose between AI compliance frameworks

Frameworks differ in legal force before they differ in content, and that is what decides which one applies to you. Binding law is not a choice; a certifiable standard is; a voluntary framework is a structure to adapt.

Binding law

e.g. EU AI Act, GDPR

Compliance is not optional and carries penalties. Obligations depend on a risk classification you must perform, and conformity assessment may be required before you can place a system on the market.

Choose when: You place AI on a regulated market or your system affects people in that jurisdiction — including from outside it. This is a legal obligation, not a choice between frameworks.

Certifiable management standard

e.g. ISO/IEC 42001, ISO/IEC 27001

Specifies an auditable management system. A third party can certify your organisation against it, which is what procurement and vendor-risk teams increasingly ask to see.

Choose when: Enterprise customers ask for independent proof of governance, or you need documented controls, evidence, and audit trails rather than internal assurance alone.

Voluntary risk framework

e.g. NIST AI RMF, ISO/IEC 23894, OECD AI Principles

Guidance to adapt, not a checklist to pass. No certification exists, and adopting one does not by itself satisfy any legal obligation.

Choose when: You need a common internal vocabulary for identifying and treating AI risk, and a structure your teams can actually work to. Widely used as the operational layer beneath a legal obligation.

Technical security baseline

e.g. OWASP Top 10 for LLM Applications

Application-layer engineering controls for specific attack classes, aimed at developers and security teams rather than at governance functions.

Choose when: You are building on language models or agents. It answers what to fix in the system, which no governance framework does.

From framework to implementation

A framework tells you what is required. These free fill-in playbooks produce the artefacts that demonstrate it — the inventory, risk assessment, controls, owners, and audit trail an auditor actually inspects.

Classify every system by risk tier first — obligations follow the tier, and high-risk carries the full documentation, oversight, and conformity-assessment load.

The management system is a Plan-Do-Check-Act cycle. Most implementations are weakest at Check, because it needs evidence rather than intent.

Govern, Map, Measure, and Manage are the analytical core; pair them with a management system if you also need auditability.

Having data is not the same as being permitted to use it for AI — check the lawful basis and permitted-use boundary before any model consumes it.

35 of 35 frameworks
EU Artificial Intelligence Act

European Union · August 2024 (phased: prohibitions Feb 2025, GPAI Aug 2025, Article 50 transparency and GPAI penalties Aug 2026, Annex III high-risk Dec 2027, Annex I high-risk Aug 2028)

critical
In Force
NIST AI Risk Management Framework

United States · January 2023 - Published (voluntary adoption, ongoing updates)

medium
Published
ISO/IEC 42001:2023 AI Management System

International · December 2023 - Published (certification available immediately)

medium
Published
GDPR Applied to AI Systems

European Union · May 2018 - In Force. Expanded AI-specific guidance issued 2023–2024.

high
In Force
UK AI Safety Institute Framework

United Kingdom · 2023 - Active (evolving framework, legislation expected 2025-2026)

medium
Active
US Executive Order on Safe AI (EO 14110)

United States · EO 14110 revoked January 2025. Federal direction now set by the July 2025 AI Action Plan and EO 14365 (December 2025); no preemptive federal AI statute has been enacted.

high
Active
China Generative AI Regulations

China · August 2023 - In Force

high
In Force
IEEE Ethically Aligned Design

International · 2019 - Published (v2 in development)

low
Published
Canada Artificial Intelligence and Data Act (lapsed)

Canada · Never in force. Bill C-27 died at prorogation on 5 January 2025; no successor legislation has been introduced as of August 2026.

high
Withdrawn
Singapore Model AI Governance Framework

Singapore · January 2019 (v1), updated 2020. AI Verify (2022).

medium
Published
Australia AI Ethics Framework

Australia · 2019 - Ethics Framework; 2024 - Mandatory Guardrails for Government.

medium
Active
OECD AI Principles

International (OECD Members) · May 2019 - Adopted. Continuously updated.

low
Active
G7 Hiroshima AI Process

G7 Nations · October 2023 - Published. Voluntary Code of Conduct.

medium
Active
India Digital Personal Data Protection Act

India · August 2023 - In Force. DPDP Rules notified November 2025; Data Protection Board members appointed June 2026 and the Board is now operational.

high
In Force
SOC 2 Type II for AI Systems

United States (Global Acceptance) · Ongoing - Updated periodically by AICPA.

medium
Active
FTC AI Guidelines and Enforcement Actions

United States · Ongoing - FTC Act applies continuously; AI-specific guidance issued 2021-2024.

high
Active
FDA AI/ML Software as a Medical Device

United States · 2021 - Action Plan published; PCCP guidance finalized 2023; ongoing enforcement.

critical
Active
Brazil Artificial Intelligence Bill (PL 2338/2023)

Brazil · Not enacted. PL 2338/2023 passed the Senate on 10 December 2024 and remains under committee review in the Chamber of Deputies as of August 2026; no entry-into-force date exists until it is approved and signed.

high
Proposed
South Korea AI Basic Act

South Korea · January 2026 (enacted January 2024; 2-year transition period)

high
In Force
Japan AI Guidelines for Business

Japan · April 2024 — Published (voluntary). Existing laws (APPI, sector regulations) enforced by respective authorities.

low
Published
UAE National AI Strategy and Regulatory Framework

United Arab Emirates · 2017 — Active (evolving framework; UAE PDPL in force Nov 2021; sector guidance ongoing)

medium
Active
EU Cyber Resilience Act

European Union · December 2024 (entered force); reporting obligations apply 11 September 2026; main product requirements apply 11 December 2027

high
In Force
Council of Europe Framework Convention on Artificial Intelligence

Council of Europe · September 2024 (opened for signature). Binding effect follows national ratification and implementing legislation.

medium
Published
Colorado AI Law (SB 24-205, repealed and replaced by SB 26-189)

United States (Colorado) · 1 January 2027 under SB 26-189 (SB 24-205 was repealed before ever taking effect; enforced by the Colorado Attorney General)

high
Published
Texas Responsible Artificial Intelligence Governance Act (TRAIGA)

United States (Texas) · Effective January 2026 (signed 2025; enforced by the Texas Attorney General with a cure period)

high
Published
California Transparency in Frontier Artificial Intelligence Act (SB 53)

United States (California) · Effective 2026 (signed 2025; enforced by the California Attorney General)

high
Published
Saudi Arabia SDAIA AI Ethics Principles

Saudi Arabia · 2023 - Active (principles-based, applied alongside the PDPL)

medium
Active
NYC Local Law 144 — Automated Employment Decision Tools

United States (New York) · July 2023 - In Force (enforced by NYC DCWP)

high
In Force
Illinois HB 3773 — AI in Employment (Human Rights Act Amendment)

United States (Illinois) · January 2026 - Published (effective, enforced by IDHR)

high
Published
OWASP GenAI Top 10 for Large Language Model Applications (2026)

Global (voluntary) · Voluntary — 2026 edition published 4 August 2026; revised roughly annually

high
Published
ISO/IEC 23894:2023 AI Risk Management

International (voluntary) · Published 2023 — voluntary guidance, not certifiable on its own

medium
Published
ISO/IEC 42005:2025 AI System Impact Assessment

International (voluntary) · Published May 2025 — voluntary guidance, not certifiable on its own

medium
Published
EU General-Purpose AI Code of Practice

European Union · Published 10 July 2025 — voluntary, but signature is treated as evidence of compliance with binding AI Act GPAI obligations that have applied since August 2025

high
Published
EU Code of Practice on Transparency of AI-generated Content

European Union · Article 50 obligations enforceable from 2 August 2026. Generative systems placed on the market before that date have until 2 December 2026 for the marking and detection obligation only.

high
Published
California Generative AI Training Data Transparency Act (AB 2013)

United States (California) · 1 January 2026 — in force

high
In Force