Loading…
Loading…
Connecticut CART Act first obligations begin · Oct 1, 2026 · See what changes
AI Regulation Reference
31 laws tracked across the EU, US federal government, US states, UK, and international bodies — filtered and explained for small teams.
Showing 31 of 31 laws
The world's first comprehensive AI law, classifying AI systems by risk level and imposing obligations that scale with risk. High-risk AI systems must undergo conformity assessment, maintain documentation, and implement human oversight. Under Regulation (EU) 2026/1744, obligations for Annex III high-risk systems now apply from December 2, 2027, moved back from August 2, 2026.
Effective: August 1, 2024
The EU's foundational data privacy law, governing how organizations collect, process, and store personal data of EU residents. Article 22 restricts solely automated decision-making that significantly affects individuals, with direct implications for AI-driven decisions.
Effective: May 25, 2018
The updated EU product liability framework extends liability to software and AI, allowing consumers to seek compensation when defective AI systems cause harm. Removes the cap on damages and introduces a rebuttable presumption of defectiveness in certain cases. It applies to products placed on the market after December 9, 2026, which is also the deadline for member states to transpose it. Older products stay under the previous rules.
Effective: December 9, 2026
A voluntary framework from the National Institute of Standards and Technology helping organizations manage AI risks. Organized around four functions: Govern, Map, Measure, and Manage. Widely used as a reference framework in the US, and written into state law as a benchmark: Texas TRAIGA gives an affirmative defense to organizations that substantially comply with the NIST AI RMF (including its Generative AI Profile) or another recognized framework.
Effective: January 26, 2023
Revoked the Biden AI Executive Order (EO 14110) and directed federal agencies to prioritize AI development, emphasizing US competitiveness. Directed development of a national AI action plan within 180 days. A follow-on order signed December 11, 2025, Ensuring a National Policy Framework for Artificial Intelligence, directs federal agencies to challenge or deter state AI laws, including through an AI Litigation Task Force.
Effective: January 23, 2025
A presidential order signed September 29, 2026 that directs federal executive departments and agencies to use the terms Super Intelligence and SI instead of artificial intelligence and AI in official correspondence, public communications, websites, reports and policy documents. For now the new term is defined by reference to the existing statutory definition of artificial intelligence in 15 U.S.C. 9401(3). Within 60 days the assistant to the president for science and technology must submit proposed legislative language for a federal definition of Super Intelligence, including whether it should modify or supersede the current legal definition of AI. Previously issued regulations, contracts and grants do not have to be rewritten. The order creates no enforceable rights.
Effective: September 29, 2026
A non-binding White House document, released March 20, 2026, that sets out legislative recommendations for Congress on federal AI policy. Its priorities include protecting children and empowering parents, preempting unduly burdensome state AI regulation, channeling oversight through existing sector-specific agencies and industry-led standards, community protections, free speech, innovation and workforce readiness. It does not create legal obligations.
SB 26-189, signed by Governor Polis on May 14, 2026 and effective January 1, 2027, repeals and re-enacts SB 24-205. It removes the 2024 duty of care, risk management program and impact assessment requirements and replaces them with a pre-use notice, a post-adverse-outcome disclosure, and limited consumer rights for people affected by covered automated decision-making technology (ADMT) used in consequential decisions such as employment, education, housing and financial services.
Effective: January 1, 2027
Requires developers of generative AI systems made available to Californians to post high-level documentation of the data used to train them, including dataset sources, types of data, whether copyrighted material or personal information is included, how the data was acquired, and how it was modified. It covers systems released or substantially modified since January 1, 2022, and has no minimum dataset size.
Effective: January 1, 2026
Requires developers of frontier models (trained with more than 10²⁶ computing operations) to publish a transparency report before deploying a frontier model, and large frontier developers (annual revenue above $500 million) to publish a documented frontier AI framework. Developers must report critical safety incidents to the Office of Emergency Services within 15 days of discovery, or 24 hours where there is imminent risk of death or serious injury, and the law protects employees and contractors who report catastrophic risks from retaliation. The Attorney General can seek civil penalties of up to $1 million per violation. Narrower in scope than the vetoed SB 1047.
Effective: January 1, 2026
Would have required developers of large AI models (over $100M in training costs) to implement extensive safety testing, 'kill switch' capabilities, and third-party audits. The legislature gave final passage on August 29, 2024, and Governor Newsom vetoed it on September 29, 2024 on grounds that the bill was too broad and could inhibit AI development.
Took effect January 1, 2023, with enforcement beginning July 5, 2023. Requires employers and employment agencies in New York City to conduct independent bias audits of AI tools used in hiring decisions, publish audit results, and notify candidates that automated decision tools are being used.
Effective: January 1, 2023
Requires employers using AI to analyze video interviews to notify applicants, explain how the AI works and what characteristics it evaluates, obtain consent, limit who can access the videos, and destroy the videos within 30 days of the applicant's request.
Effective: January 1, 2020
Governor Hochul signed the RAISE Act on December 19, 2025, and a chapter amendment signed on March 27, 2026 is the final version. It requires large frontier AI developers to create and publish their safety protocols and to report incidents to the State within 72 hours of determining that one occurred. A new oversight office in the Department of Financial Services assesses these developers and issues annual reports. The Attorney General can bring civil actions for missing reports or false statements, with penalties of up to $1 million for a first violation and up to $3 million for later ones. Those figures are from the December 2025 announcement, so check them against the amended text. Law-firm summaries put the effective date at January 1, 2027.
Effective: January 1, 2027
HB 149, signed by Governor Abbott on June 22, 2025 and effective January 1, 2026. TRAIGA prohibits developing or deploying AI systems for specified harmful purposes under an intent-based standard, including behavioral manipulation, unlawful discrimination, unlawful deepfakes and child sexual abuse material, and infringement of constitutional rights. The Texas Attorney General has exclusive enforcement authority and must allow a 60-day cure period. There is no private right of action.
Effective: January 1, 2026
HB 2094 passed the Virginia legislature on February 20, 2025 and was vetoed by Governor Youngkin on March 24, 2025. It would have required developers and deployers of high-risk AI used in consequential decisions to disclose risks and limits and to maintain a risk management plan. Virginia has no comprehensive AI law in force. Businesses contracting with state agencies must still follow AI standards under Virginia Executive Order No. 30 (2024).
Connecticut SB 5, the AI Responsibility and Transparency Act, covers employment, healthcare, and online safety. The first obligations start October 1, 2026, including the statutory framework for automated employment-related decision technology (AEDT), a rule that stops employers from avoiding anti-discrimination liability by blaming an AEDT, and an AI-related layoff notice alongside existing mass-layoff notices. Employee and applicant notice duties and the developer information-sharing duty start October 1, 2027, with further provisions phasing in through January 2028.
Effective: October 1, 2026
SB 1119, signed by Governor Newsom on September 10, 2026, expands California's companion chatbot rules for children. The law takes effect January 1, 2027, with most operator obligations starting July 1, 2027, including a pre-release risk assessment of harms to children for new or substantially modified chatbots. Operators must also undergo an independent child safety audit, first due by January 1, 2029 or before the chatbot is first made publicly available (whichever is later), and every two years after.
Effective: January 1, 2027
The UK's deliberate choice not to pass comprehensive AI legislation, instead directing existing regulators (ICO, CMA, FCA, etc.) to apply their existing powers to AI within their sectors. Prioritizes 'pro-innovation' flexibility over prescriptive rules, unlike the EU AI Act's single horizontal law.
Effective: March 29, 2023
China's regulation governing generative AI services offered to the public in China, in force since August 15, 2023. Providers must follow content rules, including respect for socialist core values, sign service agreements with users, and protect users' input information and usage records. AI-generated content must be labeled under the separate Measures for Labeling AI-Generated Synthetic Content, in force since September 1, 2025. Services with public opinion properties or the capacity for social mobilization must complete a security assessment and file their algorithms.
Effective: August 15, 2023
The international standard for AI management systems, published by ISO and IEC. Provides a framework for organizations to establish, implement, maintain, and continuously improve their AI governance practices. Certification to ISO 42001 is emerging as a signal of AI governance maturity in enterprise procurement.
Effective: December 18, 2023
AIDA was Part 3 of Bill C-27, which would have regulated high-impact AI systems. The bill died on the order paper when Parliament was prorogued on January 6, 2025, so it never became law and Canada has no federal AI statute in force. Federal AI legislation may return in a future bill.
The Federal Trade Commission applies existing consumer protection law — the FTC Act's prohibition on unfair or deceptive acts — to AI products and services. Operation AI Comply (September 2024) brought simultaneous actions against five companies for deceptive AI product claims, fake AI-generated reviews, and AI-enabled fraud. The FTC has made clear that 'AI washing' — overstating AI capabilities — is an enforcement priority.
The Equal Employment Opportunity Commission issued technical assistance on May 18, 2023 explaining how Title VII disparate impact analysis applies to software, algorithms and AI used in hiring, promotion and performance management. The EEOC removed its AI guidance documents from its website on January 27, 2025. Technical assistance was never law: Title VII itself still applies, and the EEOC's 2024-2028 Strategic Enforcement Plan still lists technology-related employment discrimination as a priority.
In 2022 the CFPB issued Circular 2022-03, saying lenders must give specific, accurate reasons for adverse action even when a complex algorithm made the decision. The CFPB withdrew that circular on May 12, 2025 with 66 other guidance documents. The underlying rule still applies: ECOA and Regulation B require specific reasons in an adverse action notice, so 'the model said no' is not enough. Separately, a final rule published April 22, 2026 and effective July 21, 2026 amended Regulation B so that ECOA no longer supports disparate-impact liability.
The FDA regulates AI and machine learning software that meets the definition of a medical device (Software as a Medical Device, or SaMD). Its January 2021 AI/ML action plan led to guidance on pre-market review and on predetermined change control plans (PCCPs). The FDA finalized its PCCP guidance for AI-enabled device software functions on December 4, 2024, letting manufacturers pre-authorize planned modifications as part of a 510(k), De Novo or PMA submission instead of filing a new one for each change.
Effective: January 13, 2021
The SEC has no AI-specific disclosure rule. It applies existing antifraud, disclosure and marketing rules to AI claims and has brought 'AI washing' cases: in March 2024 it charged two investment advisers, Delphia (USA) Inc. (a $225,000 penalty) and Global Predictions Inc. ($175,000), for false statements about their use of AI, and in January 2025 it charged Presto Automation Inc., its first AI-washing case against a public company. Public companies must accurately disclose material AI risks and capabilities under existing rules.
On September 25, 2024 the European Commission announced that more than 100 companies had signed the EU AI Pact, a voluntary programme run ahead of the AI Act's full application. Signatories commit to three core actions: an AI governance strategy, mapping of AI systems likely to be high-risk under the AI Act, and AI literacy for staff. More than half also made further pledges such as human oversight, risk mitigation and labelling of deepfakes. It is not legally binding, and it is separate from the 2023 White House voluntary commitments and the 2024 Seoul Frontier AI Safety Commitments.
Effective: September 25, 2024
Canada's federal private-sector privacy law, phased in from January 1, 2001 and fully in force since January 1, 2004, governing how organizations collect, use, and disclose personal information in the course of commercial activity. The Office of the Privacy Commissioner has issued guidance on how PIPEDA applies to AI, including automated decision-making and AI training data. Quebec's Law 25 (phased in between September 2022 and September 2024) is stricter and acts as the provincial overlay for Quebec residents.
Effective: January 1, 2001
The National AI Centre published Guidance for AI Adoption on October 21, 2025. It replaces the 2024 Voluntary AI Safety Standard and condenses its 10 guardrails into six essential practices: governance and accountability, impact assessment, risk management, transparency, testing and monitoring, and human oversight. It is voluntary and applies to both developers and deployers, and the government has so far held off on mandatory AI rules.
Effective: October 21, 2025
Published by Singapore's Personal Data Protection Commission (PDPC), the second edition of the Model AI Governance Framework (January 21, 2020) provides non-binding, practical guidance for organizations deploying AI. It is organized around four areas: internal governance structures and measures, the level of human involvement in AI-augmented decisions, operations management, and stakeholder interaction and communication. IMDA added a Model AI Governance Framework for Generative AI on May 30, 2024. The Monetary Authority of Singapore has separate guidance for financial institutions, including its 2018 FEAT principles.
Effective: January 21, 2020
Status guide
Unfamiliar terms?
Conformity assessment, GPAI model, high-risk AI — all defined in plain English.
Browse the glossary →