freshcrate

AI Legislation & Governance

Snapshot tracker for AI laws, policy frameworks, and operational risk issues by region.

Tracked instruments
12
In force
5
Approved pending
2
In negotiation / proposed
5
ResetShowing 12 instruments
Operator playbook (standalone advantage)
Regulatory pressure score:89/100high12 instruments + 5 governance issues in scope.
Maintain model cards + risk register per deployed modelP0

Explainability, traceability, and deployment controls increasingly hinge on living documentation.

  • Versioned model card in repo
  • Risk register with owner, status, and mitigation
  • Change-log linking model updates to risk impacts
Operationalize red-team and safety eval cadenceP0

High-risk and foundation-model regimes require demonstrable pre/post-deployment testing.

  • Quarterly adversarial test reports
  • Safety benchmark dashboard with pass/fail thresholds
  • Remediation tickets tied to eval failures
Stand up AI incident response runbookP0

Regimes are converging on rapid reporting, takedowns, and documented mitigations.

  • Named incident commander + escalation matrix
  • 72h incident timeline template
  • Tabletop exercise logs for model misuse scenarios
Create regulator-ready vendor assurance packetP1

Public-sector and enterprise procurement increasingly acts as de facto AI regulation.

  • Security architecture + SBOM
  • Data governance and retention policy
  • Third-party audit attestations
Ship synthetic media provenance + labelingP1

Election and consumer-protection measures are tightening around synthetic content disclosure.

  • Watermarking or provenance metadata spec
  • User-visible labeling on generated outputs
  • Detection/abuse monitoring metrics
Define open-source release policy and liability perimeterP2

Open-weight distribution obligations are still moving; explicit guardrails reduce legal ambiguity.

  • OSS release decision tree
  • Acceptable use policy for downstream use
  • Exception approvals for high-risk capabilities
Global legislation tracker
AustraliaSafe and Responsible AI guardrails (consultation)ProposedAsia-Pacific

National consultation on mandatory guardrails for high-risk AI, likely blending voluntary and enforceable controls.

guardrailshigh-risk-usesprocurementassurance
Open issues: Scope of mandatory guardrails; Who enforces
source ↗
BrazilPL 2338/2023 (AI framework bill)In negotiationLatin America

National framework bill under active debate on risk classification, accountability, and supervisory authority.

risk-tieringgovernancerightsliability
Open issues: Final institutional design; Enforcement model and penalties
source ↗
CanadaAIDA (Artificial Intelligence and Data Act)ProposedNorth America

Federal proposal imposing obligations on high-impact systems and creating regulator powers around harm mitigation.

high-impact-systemssafetyharm-mitigationrecord-keeping
Open issues: Definition of high-impact; Timeline uncertainty
source ↗
ChinaInterim Measures for Generative AI ServicesIn forceAsia-Pacificeffective 2023-08-15

Generative AI service rules focusing on provider registration, content obligations, and security/data controls.

content-controlsprovider-obligationssecurity-assessmentdata-governance
Open issues: Cross-border deployment constraints; Model update approvals
source ↗
European UnionEU AI ActApproved, not effectiveEuropeeffective 2026-08-02

Comprehensive risk-based AI regulation with obligations by risk class and additional requirements for GPAI/foundation models.

risk-tieringfoundation-modelstransparencyconformity-assessment
Open issues: Open-source carve-out boundaries; SME compliance cost; Technical standards readiness
source ↗
IndiaDPDP Act + proposed Digital India Act (AI-relevant controls)In negotiationAsia-Pacific

AI governance currently distributed across privacy law and sector policy while broader digital regulation evolves.

privacyconsentplatform-obligationsai-policy
Open issues: No unified AI statute yet; Rapid policy shifts
source ↗
SingaporeModel AI Governance Framework + AI VerifyIn forceAsia-Pacificeffective 2022-05-26

Voluntary governance and testing toolkit widely used as practical compliance baseline for enterprise deployments.

testinggovernancevoluntary-assurancetransparency
Open issues: Interoperability with mandatory regimes; Procurement uptake
source ↗
South AfricaNational AI policy framework (draft trajectory)ProposedMiddle East & Africa

Policy-first approach emphasizing national strategy, capacity building, and eventual risk governance structures.

policy-frameworkskillspublic-sectorethics
Open issues: Implementation capacity; Regulatory sequencing
source ↗
United Arab EmiratesFederal AI ethics/governance guidanceIn forceMiddle East & Africaeffective 2022-09-01

Guidance-led governance model with strong public-sector AI strategy and emerging sector-specific controls.

ethicspublic-sectortrustworthy-aisector-guidance
Open issues: Hard-law conversion path; Cross-emirate consistency
source ↗
United KingdomCross-sector AI regulatory principlesIn forceEuropeeffective 2024-02-06

Non-statutory, regulator-led framework using five cross-sector principles and guidance rather than one AI law.

principles-basedsector-regulatorstransparencyaccountability
Open issues: Consistency across regulators; Enforcement fragmentation
source ↗
United States (Colorado)Colorado AI Act (SB24-205)Approved, not effectiveNorth Americaeffective 2026-02-01

State-level high-risk AI framework focused on algorithmic discrimination controls and documentation duties.

high-risk-systemsconsumer-protectionimpact-assessmentsnotice
Open issues: Interaction with federal law; Audit burden for startups
source ↗
United States (Federal)Executive Order 14110 implementationIn forceNorth Americaeffective 2023-10-30

Federal AI governance via executive authorities, agency guidance, procurement controls, and NIST-linked standards work.

model-safetyfederal-procurementcritical-infrastructurereporting
Open issues: Change risk across administrations; Patchwork with state laws
source ↗
Governance issue watchlist
Compute-threshold fragmentationhighglobal

Different compute or capability thresholds can force multiple model-release and reporting playbooks.

Regions: North America, Europe, Asia-Pacific
  • Diverging threshold definitions in implementing acts
  • Cross-border model registration obligations
  • Cloud provider attestation requirements
Open-source liability boundarieshighglobal

Unclear liability perimeter for open-weight and community-fine-tuned models can chill OSS ecosystems.

Regions: Europe, North America, Asia-Pacific
  • New guidance on who is an AI provider/deployer
  • Case law involving open-weight releases
  • OSS-specific safe harbor proposals
Independent audit capacity gapmediumglobal

Mandatory assessment rules may outpace availability of qualified auditors and evaluators.

Regions: Global
  • Backlogs in conformity assessments
  • Regulator-approved auditor lists
  • Standardized audit schema adoption
Election integrity + synthetic mediahighregional

Fast-moving deepfake controls can trigger emergency restrictions on model features and distribution.

Regions: North America, Europe, Latin America, Asia-Pacific
  • Election-period content labeling mandates
  • Rapid takedown liability windows
  • Jurisdictional bans on specific tooling
Public-sector procurement as de facto regulationmediumnational

Government procurement requirements are becoming practical compliance standards even before hard law.

Regions: North America, Europe, Middle East & Africa
  • Model cards/evaluation report requirements
  • Cybersecurity attestations for AI vendors
  • Mandatory red-team evidence in bids