Ai has taken significant strides in the past few years, far outpacing the initial expectations of its direct impact on the business world. any industry experts consider this to be the beginning of the Fourth Industrial Revolution, with an MIT study stating that almost minimal use of AI can raise a worker's productivity by as much as 14%. While this does promise a great degree of benefits, it comes with its cons. The only way for organizations to ensure they leverage maximum benefits from all AI has to offer is to be honest in their understanding of both the potential and risk of using AI capabilities.
In recent years, some incidents have caused international outrage, such as the deepfake video of Ukrainian President Volodymyr Zelenskyy surrendering. In an era where fake news and propaganda are already seen as existential threats to the social fabric, it is easy to see how the introduction of such AI capabilities is the perfect recipe for disaster.
One way to avoid such instances of AI misuse and abuse is elaborate regulation that protects the rights of individuals. This sentiment is shared by lawmakers and legislators globally, as evident in Stanford University's 2023 AI Index, which states that 37 different AI-related bills were passed in 2022 alone. Most of these regulations not only call for better analysis and understanding of AI and its potential risks but also call for making the developers behind AI tools accountable for the actions of their inventions.
However, it is important to gain a more comprehensive understanding of the AI regulatory landscape globally, both to gauge how legislation in this domain is to develop in the years ahead, and more importantly, to see how different jurisdictions approach AI regulations. This combined knowledge will prove critical in enterprise efforts to harmonize innovation with regulatory compliance.
AI Considerations in the 21st Century
AI remains a black box in many aspects. Research related to AI interpretability, trustworthiness and operability is still in its relative infancy as far as our overall understanding of AI's limitless potential is concerned.
AI needs to be managed appropriately and curated to ensure it does not infringe on users' rights or chaotically disrupt business. For that to be the case, AI regulations need to be effective, flexible and future-proof enough to adequately cover any tangents in AI capability that may come to the fore in the short and long term.
The need for these regulations to be flexible and future-proof becomes even more critical once AI's computations not being "explainable" are factored in.
Additionally, there are a multitude of other problems to consider. For example, the European Union's AI Act states that all "training, validation, and testing datasets shall be relevant, representative, free of errors and complete." While on paper that does seem an appropriate obligation to place on organizations, in reality, the scale of data required to properly train a machine learning algorithm, with the stipulation of it needing to be "free of errors and complete," sets an extremely high standard that numerous organizations simply may not find tenable.
An example would be Amazon, which had to scrap its AI recruiting tool entirely. The issue was that it wanted to hire more female candidates. However, the tool kept shortlisting male candidates. The problem is that the available training sets were all heavily biased. Since no other training sets were available and creating a new one would have come at a tremendous financial cost, Amazon scrapped the whole project altogether.
Amazon could afford to do that because it's Amazon. A startup or an SME in a similar position may not enjoy such a luxury of options.
Lawmakers in the EU have already called for a global meeting of leaders to address the threats posed by "very powerful" AI to human rights and humanity itself.
Countries in Focus
Several countries have adopted a proactive approach toward AI regulation. In the absence of comprehensive legislation, governments have published frameworks, guidelines and roadmaps that illustrate the future of possible AI regulation in these countries and help organizations manage their AI usage and tools responsibly.
Australia does not yet have a dedicated AI regulation. Most of its regulatory actions related to AI either come through existing laws or regular government policy papers guiding various regulatory bodies on how to approach different challenges posed by AI.
In January 2024, the Australian government issued its interim response to the Safe and Responsible AI consultation held in 2023. The response elaborated on how the government plans to regulate AI within the country without restricting its usage.
Per these interim measures, the government will:
Carry out further consultations on the development of a new “high-risk” AI applications regulatory framework;
Instruct the National AI Center to work with industry leaders to develop a voluntary AI Safety Standard;
Consider a labeling and watermarking requirement for all AI-generated outputs.
State
The New South Wales (NSW) Government came up with the first AI strategy, recognizing the challenges that come with the use of AI and charting a course for AI to be used safely across the government with the right safeguards in place.
For this purpose, the NSW Government published the AI Assurance Framework to assist agencies in designing, building, and using AI-enabled products and solutions. It is mandatory for all projects that incorporate an AI component or utilize AI-driven tools. This encompasses the utilization of large language models and generative AI, explicitly falling within the framework's application scope. The framework is intended to be used by:
project teams who are using AI systems in their solutions,
operational teams who are managing AI systems,
Senior Officers who are accountable for the design and use of AI systems,
internal assessors conducting agency self-assessments, and
the AI review body (TBC).
However, a project is not expected to use the framework if it meets the following criteria:
It uses an AI system that is a widely available commercial application.
The solution is not customized or used in any way other than intended.
The AI Assurance Framework became effective in March 2022. The State Government also established the NSW AI Review Committee to provide expert guidance and oversight on using AI within the government. As the first of its kind in Australia, this committee plays a vital role in fostering community trust and ensuring transparency in our AI initiatives.
In June 2024, the Department of Finance issued the National Framework for the Assurance of AI in Government, which introduces 5 different mechanisms to ensure the effective application of AI ethics principles. Then, in September of the same year, the Policy for the Responsible Use of AI in Government entered into effect. Finally, in November of 2024, the Senate Select Committee on Adopting AI released its report on AI’s opportunities and risks in the countries, focusing on key challenges such as bias, discrimination, and data transparency.
In April 2025, the federal government released AI model clauses to ensure ethical and secure AI use in public sector procurement, covering topics ranging from AI services, customer system, and AI tools to buyer approval, ethical designe, and human oversight.
Additional Resources
In March 2022, the government issued a call for papers on the regulation of AI, calling on various stakeholders on how the government should approach AI regulation in a manner that enables the creation of a harmonic legislative framework without jeopardizing the use of AI to its maximum potential.
In the paper, the government referred to several of its own reports and guides as examples of what kind of ideas it hoped to receive. These include the following:
The Artificial Intelligence Ethics Framework, published in 2019 as a guide for government and private bodies on how to responsibly design, develop, and implement AI in Australia;
The Review of the Privacy Act, which contained several recommendations related to automated decision-making systems and mechanisms;
The AI Action Plan, published in 2021, laid down Australia's strategic vision to become a global leader in developing reliable AI technologies and systems;
The Blueprint for Critical Technologies, published in 2021 as "framework for capitalizing on critical technologies to drive a technologically-advanced, future-ready nation."
The NSW Parliament released a report on AI highlighting the use, risks, and regulatory needs in critical sectors like healthcare and manufacturing with applications such as computer vision and autonomous operations.
The Department of Industry, Science, and Resources (DISR) published the Voluntary AI Safety Standard, providing a unified set of practices for organizations to ensure the safe development and deployment of AI.
The Digital Transformation Agency published the AI Technical Standard to ensure transparency, accountability, and safety in AI systems covering their entire lifecycle, from design to retirement.
Various other regulatory bodies in Australia have also undertaken steps on their own to promote the responsible use of AI under their jurisdiction. For example, since the Online Safety Act of 2021 has come into effect, the National eSafety Commissioner requires all organizations to appropriately inform their users of the use of automated recommendation systems.
Similarly, the Commonwealth Scientific and Industrial Research Organisation (CSIRO) launched its own independent Responsible AI Network to promote collaboration between various Australian firms and create ethically safe and viable AI technologies.
While the government has so far not revealed any of the submissions it received in response to its March 2022 call for papers apart from those sent in by KPMG and the Law Council of Australia, there is growing consensus that most paper submissions contain similar recommendations such as the creation of dedicated AI regulatory body and a federal guideline on the responsible use of AI, both commercially and individually.
Brazil
Legislation
Federal
To date, there is no comprehensive federal legislation regulating the use of AI in Brazil.
However, in May 2023, the Bill of Law 2338/2023, which provides for the use of Artificial Intelligence (AI) in Brazil, was introduced in the Brazilian Federal Senate. The bill replaces three bills, Bill of Law 5.051/2019, Bill of Law 21/2020, and Bill of Law 872/2021, which were pending before the legislature over the past four years.
Along with imposing various obligations on businesses using AI systems, the law provides the following rights to the consumers:
Right to prior information regarding their interactions with artificial intelligence systems.
Right to an explanation of the decision, recommendation, or prediction made by artificial intelligence systems.
Right to challenge decisions or predictions of artificial intelligence systems that produce legal effects or significantly impact the interests of the affected party.
Right to human determination and human participation in decisions of artificial intelligence systems, taking into account the context and the state of the art of technological development.
Right to non-discrimination and the correction of direct, indirect, illegal, or abusive discriminatory biases.
Right to privacy and to the protection of personal data, in accordance with the relevant legislation.
In 2024, amendments were proposed to the Bill, with the Temporary Commission for AI in Brazil releasing a detailed report analyzing the proposed amendments.
State
To date, there are no comprehensive state legislations regulating the use of AI.
Additional Resources
The ANPD in Brazil has announced the AI Regulatory Sandbox meant to foster experimentation with innovative AI models without compromising algorithmic transparency.
United States
Legislation
Federal
To date, there is no comprehensive federal legislation regulating the use of AI in the United States (US).
However, on June 20, 2023, the US lawmakers introduced a bill, the National AI Commission Act, to create a blue-ribbon commission that will review the United States’ current approach to AI regulation, make recommendations on any new office or governmental structure that may be necessary, and develop a comprehensive framework for AI regulation.
It specifically names around 20 major federal agencies and departments and provides a comprehensive framework to mitigate any potential risks posed by AI to the US’ national security, economy and public welfare.
In the time since the Biden administration EO, there has been significant developments related to AI regulation at the federal level in the US. Multiple bodies have released their own reports and guidance. Additionally, the White House released two memorandums, M-25-21 and M-25-22, aimed at accelerating AI adoption across US federal agencies under President Trump's Executive Order 14179.
US S.1638 was introduced in the Senate, aiming to protect the US from any AI applications from “countries of concern” by prohibiting federal contractors from using certain AI technologies from these countries, such as DeepSeek. A similar bill, US S.1633, requires NIST to establish a pilot program for AI systems evaluations, specifically for AI systems in use by federal agencies to ensure their transparency.
In May 2025, the House of Representatives passed the One Big Beautiful Bill Act, with a provision that banned state and local laws regulating AI for a period of 10-years. Following protests from both members in both Houses, the AI moratorium provisions in the One Big Beautiful Bill Act were stripped.
State
Following are a few AI regulations that are in force at the state level in the US:
Connecticut’s Artificial Intelligence Law regulates the state's use of AI and has established a task force to develop an AI bill of rights and make recommendations for the adoption of other AI legislations. Along with establishing the Office of Artificial Intelligence and the Connecticut Artificial Intelligence Advisory Board, the law also establishes a task force to: (a) study artificial intelligence and (b) develop an artificial intelligence bill of rights.
Kentucky’s Senate Bill 4 regulates the use of high-risk AI systems within public sector departments, agencies, bodies, and other entities while alsor equiring disclosure of AI in decision-making.
Montana’s SB 212 made the state the first in the US to have a Right to Compute Act which gave citizens the right to own, access, and use computational tools and technologies.
Six different bills came into effect in Utah addressing various aspects of AI such as AI impersonation, AI transparency, AI use in mental health, law enforcement AI policies, government data privacy, and school data amendments.
Virginia’s HB 2094 is modelled after the Colorado’s AI Act with a narrower scope and only being applicable in cases where the AI system’s out[ut is the principle basis for a consequential decision without human review.
Illinois' Artificial Intelligence Video Interview Act requires all employers using AI technologies to analyze candidates interviewing for employment positions to appropriately inform all applicants and gain their consent before subjecting them to this automated processing.
Texas’ House Bill 149, related to Responsible AI Governance Actwas signed into law, with provisions on biometric identifiers, consent, and prohibition on certain Ai systems like social scoring. It is applicable upon any entities conducting business in Texas or producing a product/service consumed by the residents of the state.
New York City’s Law on Automated Employment Decision Tools expressly prohibits employers from using an automated employment decision tool (AEDT) to make an employment decision unless the tool is audited for bias annually, the employer publishes a public summary of the audit, and the employer provides certain notices to applicants and employees who are subject to screening by the tool. Pursuant to the adoption of final implementing regulations on April 5, 2023, law enforcement shall begin from July 5, 2023.
Guidances
In 2020, the White House issued the Guidance for Regulation of Artificial Intelligence Applications, the purpose of which was to establish an appropriate framework for all relevant federal agencies that may have to regulate various emerging AI technologies, in addition to the ethical and legal issues that would arise in tandem.
The aforementioned Guidance has helped various US agencies formulate, from time to time, different guidelines, recommendations, and plans of their own. These include:
In October 2022, the White House, per current US President Biden's direct instructions, issued a Blueprint for an AI Bill of Rights that laid down critical protections all US citizens must have as AI continues to expand in capabilities and functionalities. These include:
Data privacy: A consumer should be protected from abusive data practices via built-in protections, and the consumer should have an agency over how data about the consumer is used.
Notice & explanation: A consumer should know that an automated system is being used and understand how and why it contributes to the outcomes that impact the consumer.
Algorithmic discrimination protection: A consumer should not face discrimination by algorithms, and systems should be used and designed in an equitable way.
Safe & effective systems: A consumer should be protected from unsafe and ineffective systems.
Human alternatives, consideration, and fallback options: A consumer should be able to opt-out, where appropriate, and have access to a person who can quickly consider and remedy problems the consumer encounters.
In January 2023, the National Institute of Standards & Technology issued its AI Risk Management Framework (AI RMF), which is aimed at offering a resource to the organizations designing, developing, deploying, or using AI systems to help manage the many risks of AI and promote trustworthy and responsible development and use of AI systems. The AI RMF is intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic.
Most recently, in May 2023, the U.S. Congressional Research Service published its Generative Artificial Intelligence and Data Privacy: A Primer focusing on privacy issues and policy considerations for the U.S. Congress. The report sheds light on the collection and use of data by AI developers and the role data privacy legislation can play in regulating such use. The report proposes the following three requirements/mechanisms that may be considered in privacy regulations to govern the use of data by AI developers:
Notice and disclosure requirements: Companies developing or deploying AI may be required to acquire consent from the individuals before collecting or using their data or notifying them that their data will be collected and used for certain purposes.
Opt-out requirements: Companies developing or deploying AI may be required to provide the data subjects an option to opt-out of data collection.
Deletion and minimization requirements: Companies developing or deploying AI may be required to provide mechanisms for data subjects to delete their data from existing datasets.
"California"
Legislation
State
AB 2013 (2024) Generative Artificial Intelligence: Training Data Transparency - California enacted Assembly Bill 2013 (AB 2013), titled “Generative Artificial Intelligence: Training Data Transparency,” to enhance accountability and transparency in the development of generative AI systems. Signed into law in 2024, the bill will take effect on January 1, 2026.
The law regulates “generative artificial intelligence”, defined as AI that can generate derived synthetic content such as text, images, video, or audio that emulates the structure and characteristics of its training data. It applies to AI systems or services released on or after January 1, 2022, covering both public and private sector developers.
Under AB 2013, an “AI system” is defined as an engineered or machine-based system that varies in its level of autonomy and that can, for explicit or implicit objectives, infer from the input it receives how to generate outputs that can influence physical or virtual environments.
The term “developer” includes any individual, partnership, corporation, or government agency that designs, codes, produces, or substantially modifies a generative AI system or service intended for public use. “Substantially modifies” means creating a new version or release that materially changes the AI’s functionality or performance, including retraining or fine-tuning that significantly alters outputs.
Scope and Applicability
The Act applies to developers of generative AI systems or those who substantially modify such systems. It excludes:
Affiliates operating within a controlled corporate group (AI developed solely for internal use).
Members of hospital medical staff using AI systems internally.
The Act explicitly applies to developers making AI tools or services available to the general public.
Exemptions
Certain AI systems and services are exempt from AB 2013’s documentation and transparency requirements:
AI used solely for security or integrity purposes.
AI used in the operation of aircraft in national airspace.
AI developed exclusively for national security, military, or defense use, and available only to U.S. federal entities.
Key Provisions
Training Data Documentation Requirement
Developers must publicly post detailed documentation on their websites regarding the training data used for their generative AI systems by January 1, 2026, or prior to any substantial modification.
The documentation must include:
Sources or owners of the datasets.
A description of how datasets align with the AI system’s intended purpose.
The number and types of data points used.
Whether the datasets contain copyrighted, trademarked, patented, or public domain material.
Whether data was purchased or licensed.
Whether datasets include personal information or aggregate consumer information.
Details on data cleaning, processing, or modification, including their purpose.
The time period of data collection and whether it is ongoing.
Information about any synthetic data generation used in training.
Transparency Obligations
Developers must ensure that all documentation is accessible and accurate, providing the public and regulators with insight into data provenance and dataset integrity.
Any updates or retraining that materially affect the model’s data composition or behavior trigger an obligation to update the public documentation accordingly.
Consumer and Public Protections
While AB 2013 primarily addresses developer obligations, its broader objective is to:
Promote consumer confidence in generative AI systems by mandating clear disclosure of training data sources.
Enable users and researchers to trace data provenance and assess potential bias, copyright issues, or privacy risks.
Enforcement and Oversight
The Act does not yet specify a dedicated regulatory or enforcement authority, but enforcement is expected to be coordinated through California’s Department of Technology or Department of Justice under the state’s broader digital accountability framework.
SB 942 (2024) The California AI Transparency Act enacted in 2024, Senate Bill 942, known as the California AI Transparency Act, establishes transparency obligations for large-scale generative AI providers operating in the state. The law is designed to ensure that users can easily identify AI-generated or altered content, while also requiring the availability of free AI detection tools to enhance content authenticity and provenance. The Act takes effect on January 1, 2026.
The law applies to large-scale AI developers and licensees who make generative AI systems publicly accessible in California. Specifically, it targets “covered providers” those with more than 1,000,000 monthly users or visitors and their licensees.
Under the Act:
Artificial intelligence (AI) is defined as an engineered or machine-based system that, for explicit or implicit objectives, infers from inputs how to generate outputs that influence physical or virtual environments.
Generative AI system (GenAI) refers to AI capable of generating derived synthetic content, including text, images, video, or audio, that emulates the structure and characteristics of its training data.
Scope and Applicability
The Act applies to:
Covered Providers: Entities that create, code, or otherwise produce a generative AI system that has over 1,000,000 monthly users or visitors and is publicly accessible in California.
Licensees of Covered Providers: Organizations or individuals licensed to deploy a covered provider’s GenAI system.
Exemptions
The law does not apply to products or services that provide exclusively non-user-generated entertainment content, including:
Video games, television, and streaming services.
Movies and other interactive experiences with pre-authored media content.
Key Provisions
AI Detection Tool Requirement
Covered providers must make available a free AI detection tool that:
Detects whether content was created or altered by their GenAI system.
Provides any system provenance data (but not personal provenance data).
Is publicly accessible, allowing users to upload content or provide a URL for detection.
Supports an API so users can access the tool without visiting the provider’s website.
Providers must collect user feedback to improve the tool’s accuracy and are prohibited from collecting personal information or retaining data longer than necessary.
Disclosure Requirements for AI-Generated Content
Covered providers must enable users to label AI-generated or altered content through two types of disclosures:
Manifest Disclosure:
Easily recognizable, clear, conspicuous, and understandable labels.
Labels must be permanent or difficult to remove.
Latent Disclosure:
Embedded metadata including:
Developer’s name
AI system name and version
Creation/alteration date
Unique identifier
Must be detectable by the provider’s own AI detection tool and hard to remove, following industry standards.
Licensee Obligations
Covered providers must contractually require licensees to maintain the GenAI system’s capability to include mandatory disclosures.
Providers must revoke a license within 96 hours if a licensee modifies the system so that it can no longer include the required disclosures.
After revocation, the licensee must immediately cease using the GenAI system.
Privacy Safeguards
AI detection tools must not retain personal information or personal provenance data.
Providers must minimize data collection and storage strictly to what is necessary for the tool’s operation.
Penalties and Enforcement
Civil penalties:
Covered providers violating the Act face fines of $5,000 per violation, enforceable by the Attorney General, city attorney, or county counsel.
Each day of noncompliance counts as a separate violation.
Prevailing plaintiffs are entitled to reasonable attorney’s fees and costs.
Licensee violations:
Licensees that continue using a GenAI system after license revocation are subject to injunctive relief and attorney’s fees in actions brought by the same authorities.
Oversight and Enforcement Authority
The law is enforced by the California Attorney General, as well as city attorneys and county counsels authorized to bring civil actions.
SB 1001 (2018) The Bolstering Online Transparency (BOT) Act enacted in July 2019, Senate Bill 1001, known as the Bolstering Online Transparency Act (BOT Act), was one of the first U.S. state laws to regulate the use of automated online accounts (“bots”). The law aims to prevent deceptive interactions by bots in online communications that could mislead users during commercial transactions or political campaigns.
The BOT Act defines a bot as an automated online account where all or substantially all of the actions or posts of that account are not the result of a person. It specifically regulates how bots are used in public-facing interactions, not their development or programming.
Scope and Applicability
The Act applies to individuals and entities that use automated online accounts (bots) to communicate or interact with people in California. It targets those using bots for commercial or political purposes while misleading users about the bot’s artificial identity.
The law does not apply to:
Service providers of online platforms, including web hosting services and internet service providers.
Entities that only develop bots, as the law governs use, not creation.
Key Provisions
Prohibition on Deceptive Bot Use
It is unlawful for any person to use a bot to communicate or interact with another person in California with the intent to mislead the person about the bot’s artificial identity in order to:
Influence a commercial transaction, or
Influence a vote or election outcome.
Disclosure Requirement
A person using a bot for the above purposes must clearly and conspicuously disclose that the communication is being made by a bot.
The disclosure must be reasonably designed to inform the person that they are interacting with an automated account, not a human.
This disclosure requirement applies to all online interactions, including social media, chat systems, and other web-based communications.
Cumulative Duties
The duties and obligations imposed by SB 1001 are cumulative with any other obligations imposed by other state or federal laws.
The Act explicitly states it does not relieve a person from additional transparency or disclosure requirements under other applicable regulations.
Enforcement and Oversight
The law is self-enforcing through California’s general consumer protection framework. While it does not establish a dedicated regulatory authority, violations can be pursued under California’s Unfair Competition Law (Business and Professions Code §17200 et seq.), which allows the Attorney General or local prosecutors to take enforcement action.
AB 3030 (2024) Health Care Services & Artificial Intelligence Act enacted in 2024 and effective January 1, 2025, Assembly Bill 3030 establishes regulatory requirements for the use of generative artificial intelligence (GenAI) in healthcare settings across California. The law seeks to ensure that AI-generated communications concerning patient health information are clearly identified and that patients retain the right to meaningful, human-centered healthcare interactions.
The Act defines:
Artificial Intelligence (AI) as an engineered or machine-based system that varies in its level of autonomy and can, for explicit or implicit objectives, infer from input how to generate outputs that influence physical or virtual environments.
Generative Artificial Intelligence (GenAI) as AI capable of generating derived synthetic content including text, images, audio, video, and other digital content that emulates the structure and characteristics of its training data.
Scope and Applicability
The law applies to the following licensed healthcare entities operating in California that use GenAI to generate verbal or written communications involving clinical patient information:
Licensed health facilities (e.g., hospitals, nursing homes).
Licensed clinics (outpatient care centers).
Physicians’ offices and group medical practices (partnerships or corporations of physicians).
Excluded from scope:
Administrative AI applications: systems used for billing, scheduling, or other clerical tasks.
AI-generated messages reviewed by a licensed human health provider before being sent to the patient.
Key Provisions
Disclosure and Transparency Requirements
Entities using GenAI for patient communication must include a clear disclaimer indicating that the message or content was generated by AI. The disclaimer requirements vary by communication format:
Written (letters, emails, digital): prominently displayed at the beginning of each communication.
Continuous online interactions (chat-based telehealth): continuously visible throughout the interaction.
Audio communications: verbally stated at both the start and end of the interaction.
Video communications: prominently displayed throughout the interaction.
Additionally, every disclaimer must include instructions on how to contact a human healthcare provider.
The disclaimer obligation does not apply if the AI-generated content is reviewed and approved by a licensed human provider prior to being shared with the patient.
Use Restrictions
GenAI may not be used for clinical communications unless it adheres to the disclaimer and transparency obligations. Administrative uses (e.g., scheduling) are exempt.
Compliance for Deployers
Healthcare entities must implement processes ensuring that any AI system used for patient-facing communication is compliant with these disclosure and safety requirements.
Enforcement and Oversight
Health Facilities: Violations are enforced under Article 3 (commencing with Section 1275) of Chapter 2 of the California Health and Safety Code.
Clinics: Violations fall under Article 3 (commencing with Section 1225) of Chapter 1 of the same code.
Physicians: Violations are subject to disciplinary authority by the Medical Board of California or the Osteopathic Medical Board of California, as appropriate.
SB 24-205 (2024) Consumer Protections for Artificial Intelligence Act enacted in May 2024 and effective February 1, 2026, Colorado’s Consumer Protections for Artificial Intelligence Act (CAIA) is the first comprehensive U.S. state law regulating high-risk AI systems. The Act establishes requirements for both developers and deployers of high-risk AI systems to prevent and mitigate algorithmic discrimination, ensure accountability, and provide transparency to consumers.
The Act defines:
Artificial Intelligence (AI) as any machine-based system that, for any explicit or implicit objective, infers from the inputs it receives how to generate outputs including content, decisions, predictions, or recommendations that can influence physical or virtual environments.
High-Risk AI System as any system that makes, or is a substantial factor in making, a consequential decision that has a material legal or similarly significant effect on a consumer in areas such as education, employment, housing, healthcare, insurance, financial services, legal services, or government benefits.
Scope and Applicability
The Act applies to:
Developers: persons or entities doing business in Colorado that develop or substantially modify high-risk AI systems.
Deployers: persons or entities doing business in Colorado that deploy or use high-risk AI systems.
Exemptions:
The law does not apply to AI systems that:
Are approved or regulated by federal agencies such as the FDA or FAA, or already comply with comparable federal standards.
Are used solely for narrow procedural or administrative tasks, pattern detection without influencing human decisions, or non-high-risk utilities like spam filters, cybersecurity, or fraud detection (non-facial recognition).
Are developed under federal contracts (e.g., Department of Defense, NASA).
Are used exclusively for research, compliance with law, public interest purposes, or safety/security emergencies.
Are part of HIPAA-covered healthcare recommendations requiring human intervention.
Are operated by banks or insurers complying with equally stringent anti-discrimination guidance.
Are internal-use systems not shared externally.
Are small businesses with <50 employees that meet specific limited-impact conditions (e.g., no training data use, non-adaptive systems, or full transparency to consumers).
Key Provisions
Developer Obligations
Must provide disclosures and documentation to deployers and the Attorney General (AG), including:
A statement of purpose and intended uses.
Data summaries and information on governance, sources, and bias-mitigation methods.
Known or foreseeable risks of algorithmic discrimination.
Evaluation methods for performance and discrimination mitigation.
Guidelines for monitoring and deployment.
Must report any discovered or foreseeable algorithmic discrimination risks to the AG and affected deployers/developers within 90 days.
Must maintain a public summary of high-risk AI systems on its website, describing:
The types of systems developed or modified.
Risk-management strategies and mitigation measures.
Deployer Obligations
Implement an AI risk-management policy following a recognized national or international AI risk-management framework (e.g., NIST AI RMF).
Conduct and maintain an annual impact assessment (and within 90 days of substantial modification) detailing:
System purpose, context, and benefits.
Data sources, processing, and output analysis.
Known limitations and discrimination risks.
Consumer-facing transparency and monitoring measures.
Retain all impact assessments for at least three years after final deployment.
Provide consumer notice before using a high-risk AI system for consequential decisions, including:
The purpose and nature of the decision.
Contact details and access to information.
Explanation of opt-out, correction, and appeal rights.
Disclose algorithmic discrimination risks to the AG within 90 days of discovery.
Maintain a public statement on their website listing deployed high-risk AI systems, discrimination-risk management measures, and the scope of collected data.
Transparency & Consumer Disclosure Requirements
Consumers must be informed whenever they interact with an AI system, unless it is obvious to a reasonable person.
Developers and deployers must provide plain-language notifications (in accessible formats and multiple languages) before using high-risk AI systems in consequential decisions.
Consumers must receive access instructions to view the public statement or summary for the AI system involved.
Consumer Rights
Right to Opt Out of personal data processing for profiling with legal or significant effects.
Right to Correction of inaccuracies in personal data used in consequential AI-based decisions.
Right to Explanation: Consumers can request a clear statement outlining:
The extent of the AI’s contribution to the decision.
The types and sources of data used.
Right to Appeal adverse consequential decisions, including human review where feasible.
Penalties and Enforcement
Enforced by the Colorado Attorney General, who has authority to issue regulations, conduct investigations, and impose penalties under the Colorado Consumer Protection Act (CCPA) framework.
Provides an affirmative defense for developers and deployers that can demonstrate:
Substantial compliance with recognized AI risk-management frameworks (e.g., NIST, ISO).
Good-faith remediation of discovered violations.
The burden of proof rests with the developer or deployer asserting the defense.
SB 149 (2024) Artificial Intelligence Amendments enacted in March 2024 and effective May 1, 2024, Utah’s Artificial Intelligence Amendments (SB 149) establish transparency and disclosure obligations for the use of generative artificial intelligence (GenAI) across both public and private sectors. The law emphasizes consumer awareness, ethical oversight, and accountability in AI-assisted interactions especially in regulated professions such as healthcare, law, and accounting.
The Act defines:
Artificial Intelligence (AI): A machine-based system that makes predictions, recommendations, or decisions influencing real or virtual environments.
Generative Artificial Intelligence (GenAI): An artificial system trained on data that interacts with a person through text, audio, or visual communication and generates unscripted outputs similar to those created by a human, with limited or no human oversight.
Scope and Applicability
The law applies to:
All businesses and individuals using generative AI within Utah.
Professionals in regulated occupations, including physicians, nurses, lawyers, accountants, and other licensed practitioners who use AI in providing professional or client-facing services.
The regulation ensures that both private enterprises and regulated service providers disclose the presence of generative AI in interactions that could affect consumers, patients, or clients.
Key Provisions
General Disclosure Requirement
Any person using generative AI must clearly and conspicuously disclose to another person that they are interacting with AI if asked or prompted.
This requirement applies across all contexts like commercial, educational, or service-based where AI interacts with individuals.
Regulated Occupation Disclosure Requirement
Professionals providing regulated services (e.g., doctors, lawyers, accountants) must prominently disclose when a consumer is interacting with a generative AI system during the provision of regulated services.
The disclosure must be provided:
Verbally at the beginning of an exchange or conversation, or
Electronically before a written or digital interaction begins.
The intent is to ensure patients, clients, or consumers are aware when AI is responding or providing information.
Scope of Enforcement
The law applies broadly to any AI communication that emulates human output, including customer support bots, virtual assistants, healthcare triage systems, and AI-based legal or financial advisory tools.
There are no exemptions for industry type, but the stringency of disclosure is heightened for regulated occupations.
Transparency and Disclosure Requirements
Clear and Conspicuous Notice: The AI user must provide an easily identifiable disclosure when interacting with individuals through text, voice, or video.
Prompt Disclosure for Regulated Services: Disclosure is mandatory upfront in regulated settings, such as medical consultations or legal advice sessions.
Trigger-Based Disclosure for Non-Regulated Services: In general business or consumer contexts, disclosure must be provided upon request or inquiry.
Penalties and Enforcement
Civil Penalties:
$2,500 per violation of the disclosure requirement.
Up to $5,000 per violation for noncompliance with administrative or court orders issued for prior violations.
No AI Defense Clause: The Act explicitly states that no defense exists based on the argument that the AI system (rather than the human operator) made the violative statement or committed the violative act.
Enforcement Authorities: The Utah Division of Consumer Protection and the Utah Attorney General’s Office are empowered to investigate and enforce compliance.
NYC Local Law 144 (2021) Automated Employment Decision Tool (AEDT) Law enforced beginning January 1, 2023, New York City’s Automated Employment Decision Tool Law regulates the use of AI-based or algorithmic systems by employers and employment agencies in hiring and promotion decisions. It aims to ensure fairness, transparency, and accountability in employment practices that rely on automation or artificial intelligence.
The law covers any automated employment decision tool (AEDT) defined as:
A computational process, derived from machine learning, statistical modeling, data analytics, or artificial intelligence, that issues simplified outputs (e.g., a score, classification, or recommendation) used to substantially assist or replace discretionary decision-making for employment decisions affecting natural persons.
Scope and Applicability
The law applies to:
Employers and employment agencies that use AEDTs for hiring or promotion decisions for New York City–based jobs or candidates.
Vendors or providers of AEDT systems indirectly fall under the scope if their tools are deployed by covered employers.
Excluded from scope:
Manual decision-making tools that do not use computational or machine-learning-based processes.
AI systems used solely for administrative purposes unrelated to hiring or promotion.
Key Provisions
Bias Audit Requirement
Employers and employment agencies may not use an AEDT unless a bias audit has been conducted within the previous 12 months.
The bias audit must be performed by an independent auditor to assess the tool’s disparate impact across sex, race, and ethnicity categories.
A summary of the audit results and the distribution date of the AEDT must be publicly posted on the employer’s website.
Employers must retain audit documentation and update audits annually.
Notice to Candidates and Employees
Employers and employment agencies must provide at least 10 business days’ notice before using an AEDT. The notice must include:
Disclosure that an AEDT will be used to evaluate the applicant or employee.
The specific job qualifications or characteristics being assessed.
The option to request an alternative selection process or accommodation (if available).
Upon written request, employers must disclose:
The types and sources of data collected by the AEDT.
The data retention policy and decision-making process of the tool.
The contact information for submitting requests, and must respond within 30 days.
Notice may be delivered via email, mail, the company website, or written policy documents.
Public Disclosure Requirements
Employers must make the following information publicly available on their website:
The date of the most recent bias audit.
A summary of results, including:
Source and explanation of the audit data.
Total number of applicants or candidates evaluated.
Selection or scoring rates across demographic groups.
Impact ratios and unknown-category counts.
The distribution date of the AEDT.
An active hyperlink clearly labeled as “Bias Audit Results” must be provided and kept active for at least six months after the tool’s last use.
Data Retention and Access Transparency
Employers must maintain and disclose data retention policies, data categories collected, and the source of each dataset used by the AEDT.
If disclosure would violate local, state, or federal law or interfere with law enforcement investigations, employers must provide a written justification for nondisclosure.
Penalties and Enforcement
Fines:
Up to $500 for a first violation and for each additional violation occurring on the same day.
$500 to $1,500 for each subsequent violation thereafter.
Enforcement Agency: The New York City Department of Consumer and Worker Protection (DCWP) oversees enforcement, audits, and penalties.
HB 1876 (Act 927, 2025) Arkansas enacted a state-level AI law that sets default ownership rules for content and models produced with generative AI. Signed on April 21, 2025, Act 927 provides that the person who supplies the input or directives to a generative-AI tool owns the generated content, so long as it does not infringe existing IP/copyright. For model training, ownership generally follows the person/entity that lawfully provided the training data, subject to contract. In the employment context, AI outputs or trained models created within the scope of employment and under employer direction belong to the employer (work-for-hire). The Act does not confer ownership over infringing material. The law entered into force on August 5, 2025.
Act text / bill text (PDFs) - title: “Generative artificial intelligence tool - Ownership of model training and generated content - Work made for hire - Exceptions.”
Effective-date & law tracker notes (Digital Policy Alert; local coverage of August effective dates).
Overview / practitioner summaries (law-firm and industry write-ups).
China
Legislation
Federal
China does not have a comprehensive and specified AI Regulation in place on a federal level. However, the Administration of Deep Synthesis of Internet-based Information Services contains provisions that strictly punish deep synthesis technology such as deepfakes and other forms of AI-generated media.
The new Regulations also required all AI-generated content to be appropriately labeled as such.
The Regulations offer detailed guidance for the application of deep synthesis technology in providing Internet information services within China. They specify the responsibilities of national and local departments, highlighting the importance of information security, robust management systems, user authentication, content oversight, and effective measures against spreading rumors.
Furthermore, the regulations address the management of deep synthesis data and technology, emphasizing data security, regular evaluation of algorithms, and clear labeling of generated content. Adhering to these regulations is essential to prevent misuse, maintain transparency, and ensure responsible use of deep synthesis technology.
Moreover, the national network information department is responsible for coordinating the governance and related supervision and management of national in-depth synthesis services.
These Regulations also come with Frequently Asked Questions (FAQs). The FAQs clarify that deep synthesis service providers have responsibilities such as establishing management systems for user registration, algorithm review, data security, and personal information protection.
More importantly, the Chinese government published its Interim Measures for the Management of Generative Artificial Intelligence Services (Interim GAI Measures). These measures were reviewed and approved by various government agencies and bodies, leading to these measures coming into effect in August 2023.
Some of the measures’ key requirements include the following:
Organizations must take effective measures during algorithmic design, training data selection, model generation and optimization, service provision and other processes to mitigate the chances of any bias and discrimination;
Organizations must take adequate measures to increase the transparency, accuracy and reliability of GenAI products/services;
Organizations must use data and foundational models from reliable and lawful sources that have taken the aforementioned measures;
Organizations must have the consent of the individuals whose personal information they plan on using;
Organizations that offer GenAI products/services with public opinion properties or social mobilization capabilities must conduct regular security assessments;
Organizations must have clear service agreements with all users communicating their rights along with measures in place to prevent addiction to their services by minors;
Organizations must ensure all AI-generated outcomes are appropriately labeled as such.
In July 2023, the final version of the Interim Measures for Administration of GenAI Services were released and then came into effect in August 2023. These AI Measures apply to GenAI services being offered to public and lay down an array of legal requirements in performing and using GenAI services.
Then in July of 2024, CAC announced the publication of Guidelines for the Construction of a National AI Industry Comprehensive Standardization System (2024 Edition), covering important topics such as AI development, definitions of AI standard architecture, technical standards, system framework, and key directions for various AI components such as the NLP, computer vision, robotics, and security.
Later on in March 2025, the central government introduced new regulations to standardize the identification of AI-generated content, requiring all such content be labelled as such. These came into effect in September, with online platforms required to add visible warnings on such content, while also verifying all content’s authenticity.
In the same year, the country’s Ministry of Industry and Information Technology (MIIT) partnered with multiple other agencies to release the Administrative Measures for the Ethical Management of AI Science and Technology. These measures are meant to build on earlier versions to balance innovation and security while also ensuring alignment with international AI governance efforts.
Shanghai Regulations apply to activities such as AI Science and Technology (S&T) innovation, industrial development, application empowerment, and industrial governance within the administrative region of Shanghai. These Regulations apply to all organizations in Shanghai involved in the AI industry. The regulatory authority is the local municipal economic and information departments and is responsible for planning, implementing, coordinating, and promoting the development of the AI industry.
Shanghai Regulations are formulated in accordance with relevant laws and administrative regulations and based on the actual situation of the Shanghai area in order to promote the high-quality development of the AI industry. Additionally, these Regulations aim to strengthen the functions of new-generation AI S&T innovation sources, promote the deep integration of AI with the economy, everyday life, urban governance, and other fields, and create a world-class AI industrial cluster.
One of the major aims of The Shanghai AI Regulations is to facilitate the responsible and sustainable development of AI technology. It introduces grading management and "sandbox" supervision, which provide companies with opportunities to explore and test their technologies in a regulated environment. This approach encourages innovation while ensuring adherence to guidelines and standards.
Shenzhen Regulations
Shenzhen AI Regulations have been formulated to promote the high-quality development of the AI industry in the Shenzhen Special Economic Zone, encourage AI integration in the economy and society, and ensure orderly and standardized industry growth in accordance with relevant laws and Shenzhen area situation. As per these Regulations, the local government will establish a working mechanism to coordinate and promote the development of the artificial intelligence industry in the city.
This includes ensuring the industry's security, fostering its healthy and orderly growth, and harnessing the potential of AI for sustainable development in the economy, society, and ecology.
The regulatory authority under the Shenzhen AI Regulations is the municipal industrial and information technology department which will serve as the competent authority responsible for implementing, coordinating, and supervising its development within the city's jurisdiction.
Shenzhen AI Regulations categorize activities and applications on three levels. High-risk AI applications require pre-assessment and risk early warning, while medium- and low-risk applications need pre-disclosure and post-tracking regulation. The Shenzhen area government will develop separate measures for classifying and supervising AI applications.
Additionally, AI services and products based in Shenzhen that are deemed to pose "low risk" can undergo testing and trials, even in the absence of local and national norms. However, adherence to international standards is a prerequisite for such testing and trials.
Guidances & Additional Resources
China has arguably been the most proactive country regarding regulating AI technologies and engaging various stakeholders to ensure the best ethical standards are adopted.
In 2017, the State Council of the People's Republic of China published A Next Generation Artificial Intelligence Development Plan. The guide contained a detailed roadmap on how various state and private institutions can help in the development, deployment, and oversight of AI technologies in a responsible manner.
Then, in 2021, the National Special Committee of New Generation Artificial Intelligence, a body established by the aforementioned guide, issued a Code of Ethics for New-Generation Artificial Intelligence to ensure any future development of AI technologies is in line with appropriate ethics and regulatory requirements. It also established six critical ethical standards that must be considered in developing such AI technologies. These include:
Improving human well-being,
Promoting fairness and justice,
Protecting privacy and security,
Ensuring controllability and credibility,
Strengthening responsibility,
Improving ethical literacy.
The following year in March 2022, the Internet Information Service Algorithmic Recommendation Management Provisions came into effect that required all organizations that develop, promote, and facilitate the development of AI-based personalized recommendations on mobile devices to allow users to delete any tags about their personal characteristics that the internal AI-recommendation model may have developed based on their browsing patterns.
It also required the organizations to let users disable such recommendations on their devices.
In November, the Ministry of Public Security, the Cyberspace Administration of China (CAC), and the Ministry of Industry and Information Technology released a new set of regulations.
Most recently, CAC released a set of draft measures for managing generative AI services. These include requiring all organizations using such services to submit to an independent security assessment before such tools can be commercially deployed.
United Kingdom
Legislation
In March 2023, the Department for Science, Innovation and Technology announced the introduction of the Data Protection and Digital Information (No. 2) Bill (‘the Bill’). The Bill, amongst other objectives, aims to address the risks associated with AI-powered automated decision-making and determine the data protection controls required for such processes.
The Bill is expected to provide clarity on how the right to not be subjected to automated decision-making, as granted under Article 22 of the UK GDPR, can be invoked and exercised.
Guidances
The UK Information Commissioner's Office, the body primarily responsible for overseeing all data privacy-related affairs in the UK, has released guidelines on how organizations can responsibly explain the use of AI to both their own employees and customers, titled Guidance on AI and Data Protection and AI and Data Protection Risk Toolkit. The ICO has also recently warned organizations using emotional analysis technologies irresponsibly.
The Guidance provides a roadmap to data protection compliance for developers and users of generative AI. The Risk Toolkit enables organizations to identify and mitigate data protection risks and contains eight significant questions that organizations developing or using generative AI should consider.
Moreover, other guidances in relation to the use of artificial intelligence have also been issued by different public entities in the UK. These include the following:
Data Ethics Framework issued by the Department for Digital, Culture, Media, and Sport,
Roadmap issued by the UK Medicines and Healthcare Products Regulatory Agency.
Additional Resources
The UK government issued a white paper in March 2023 titled "A pro-innovation approach to AI regulation." Within the whitepaper, the UK government highlighted the role of its existing legal framework in regulating the use of AI and underscored its “reputation for high-quality regulators and [UK’s] robust approach to the rule of law, supported by [its] technology-neutral legislation and regulations. UK laws, regulators, and courts already address some of the emerging risks AI technologies pose.”
The white paper further stated that “this strong legal foundation encourages investment in new technologies, enabling AI innovation to thrive and high-quality jobs to flourish."
Additionally, the whitepaper outlined five essential principles that all regulatory bodies must consider when evaluating the use of AI within their scope. These include:
Safety, security, and robustness;
Transparency and explainability;
Fairness;
Accountability and governance;
Contestability and redress.
In the same 2023 whitepaper, the UK government also laid down its own plan on how it aims to curate both the national development and regulation of AI technologies. Partly inspired by its 2021 10-Year National AI Strategy, the UK government categorically ruled out establishing a new regulatory body or commission to oversee AI-related regulation.
Instead, existing regulatory bodies such as the Health & Safety Executive, the Equality & Human Rights Commission, and the Competition & Markets Authority will expand their powers and jurisdictions to ensure effective oversight of AI-related technologies within their sectors.
In March 2023, the UK government's Department of Education released another whitepaper titled "Generative Artificial Intelligence in Education" in response to the alarming growth in the use of ChatGPT by students nationwide.
Singapore
Legislation
Singapore is one of the few countries in the world with a dedicated government body tasked with curating Singapore's digitalization journey. It aims to nurture a vibrant digital economy fuelled by technological innovation. The Advisory Council on the Ethical Use of AI and Data was established in 2018 to help Singapore identify and address all ethical questions and dilemmas that may arise. The body's primary responsibility is to advise the government on ethical, policy, and governance issues related to the use of AI technologies.
As a result of the body's recommendation, the country's first National Artificial Intelligence Strategy was published in 2019, with an update being released in 2021. Not only did it aim to identify strategic areas where resources need to be deployed most urgently while also addressing the emerging risk of AI becoming expansive beyond control.
Additionally, various existing regulations have been amended to include AI systems and technologies, such as:
The Cybersecurity Act of 2018 - The new amendment requires all AI security methodologies and mechanisms adopted by organizations to be appropriately revealed to the users;
The Infocomm Media Development Authority (IMDA) has identified four distinct "pillar" technologies to drive Singapore's digitalization journey. These include:
Cybersecurity;
Immersive Media;
The Internet of Things;
Artificial Intelligence.
Each pillar has its own dedicated development program, with the AI section driven by AI Singapore, launched to build and grow Singapore's AI ecosystem, including research institutions, startups, and tech.
Two distinct AI programs, the National AI Program in Government and the National AI Program in Finance, were established to guide various regulatory agencies via guidance and policy papers. Additionally, other government bodies have issued various other guides related to the use of AI within their sectors. These include the following:
To date, Japan does not have dedicated AI legislation. However, the Japanese government has been one of the more proactive ones in publishing frequent guidelines for better and more coherent use of AI in professional and social settings.
Moreover, it has adopted the Hiroshima AI Process after the G7 Hiroshima Summit as its core AI strategy. Under the Hiroshima AI Process, Japan aims to establish a reliable, robust, and inclusive AI governance framework that can provide an appropriate degree of guidance and code of conduct for all major stakeholders involved in developing AI systems.
In February of 2024, the AI Safety Insitute was launched to examine AI safety evaluation methods, develop appropriate standards, and carry out collaborative efforts with similar institutions in the US and UK. This institute has since released its Guide to Evaluation Perspectives on AI Safety, aimed at AI developers and providers with the intent of controlling toxic outputs, preventing misinformation, and ensuring data quality as well as the Guide to Red Teaming Methodology on AI Safety aimed at evaluating AI systems from the attackers’ perspective to test effectiveness of AI safety measures.
Additionally, the Japanese government has amended several of its existing legislations to incorporate AI systems' rapidly developing capabilities and functionalities. Some examples include:
Road Traffic Act - Amended to regulate automated driving cars and driving systems;
In 2019, the Japanese government published the Social Principles of Human-Centric AI, which laid down distinct principles that would help individuals and enterprises implement AI systems within society. These principles include:
Fair competition;
Accountability;
Innovation;
Principle of Literacy;
Human-centric principle;
Transparency;
Privacy Protection.
Since then, the Social Principles of Human-Centric AI have led to further guidances that have strategically focused on AI's applications in various sectors of government, education, defense, and corporate governance. Some of these include:
To date, there is no comprehensive federal legislation regulating the use of AI in Canada.
However, in June 2022, the Government of Canada tabled the landmark Artificial Intelligence and Data Act (AIDA) as part of the omnibus Bill C-27, Digital Charter Implementation Act 2022. The AIDA aims to set out new measures to regulate international and inter-provincial trade and commerce in AI systems and establish common requirements for the design, development, and use of AI systems.
The law establishes common requirements for the design, development, and use of artificial intelligence systems and also prohibits specific practices with data and artificial intelligence systems that may result in serious harm to individuals or their interests.
In March 2023, the Government of Canada issued the AIDA Companion document aimed at highlighting Canada’s approach towards the regulation of AI and how AIDA shall contribute to that approach once enacted. The Companion document also identified a number of existing frameworks for consumer protection, human rights, and criminal law that apply to the use of AI, including the following:
The Canada Consumer Product Safety Act;
The Food and Drugs Act;
The Motor Vehicle Safety Act;
The Bank Act;
The Canadian Human Rights Act and provincial human rights laws; and
The Criminal Code.
As per the consultation timeline provided in the Companion document, AIDA would come into force no sooner than 2025.
In August of the same year, the federal government published a Code of Practice for GenAI Development and Use. This was passed in anticipation of AIDA to help potential covered entities avoid any harmful impacts while building trust in their systems, and for overall smooth transition to compliance methods.
Then, in November 2024, the federal government announced the launch of the Canadian AI Safety Insitute (CAISI) as part of their greater plan to support the safe and responsible development and deployment of AI while also proactively managing risks of advanced AI systems.
Provincial
To date, no province in Canada has enacted comprehensive legislation regulating the use of AI. However, the provincial human rights laws apply to the use of AI and afford some protections to consumers.
Guidances
In November 2020, the Office of the Privacy Commissioner of Canada (OPC) issued A Regulatory Framework for AI: Recommendations for PIPEDA Reform containing OPC’s final recommendations after the public consultation on proposals for ensuring the appropriate regulation of AI in the Personal Information Protection and Electronic Documents Act (PIPEDA). The recommendations, among others, included the recognition of privacy as a human right, specific provisions of automated decision-making, and demonstrable accountability of the business community.
In May 2021, the Government of Ontario published its report on Consultation: Ontario’s Trustworthy Artificial Intelligence (AI) Framework. The report provided an overview of the potential actions the government could take to ensure the responsible and safe use of AI and the feedback from the consumers on those actions.
In April 2023, the Government of Canada issued a report on the Responsible use of artificial intelligence (AI), which describes how the government makes sure that the use of AI by its departments and agencies is responsible and accountable. Among other things, the document outlines the following actions that need to be taken and monitored so governments may use AI responsibly:
Understand and measure the impact of using AI by developing and sharing tools and approaches.
Be transparent about how and when we are using AI, starting with a clear user need and public benefit.
Provide meaningful explanations about AI decision-making, while also offering opportunities to review results and challenge these decisions.
Be as open as we can by sharing source code, training data, and other relevant information, all while protecting personal information, system integration, and national security and defense.
Provide sufficient training so that government employees developing and using AI solutions have the responsible design, function, and implementation skills needed to make AI-based public services better.
One practical effect of this approach can be seen in the launch of the Directive on Automated Decision Making - which is a policy directive by the Federal Government of Canada on how to responsibly incorporate AI decision-making within the public sphere.
Israel
Legislation
Currently, there is no major comprehensive AI-related legislation in effect in Israel.
However, considering how Israel has managed to carve out a remarkable reputation for itself as a potential hub of AI innovation, a draft policy has been enacted that intends to act as the basis for future regulatory considerations and ethical framework designs related to AI.
There have been discussions within the legislative circles of the country on what kind of a regulatory setup would be ideal for Israel to ensure it can guarantee the protection of its citizens' digital rights without stifling innovation and creativity within the sector.
Rather than a linear regulatory approach, Israel will likely rely on amendments to its existing regulations and the development of policy guidance that will allow for both effective self-regulation and standardization.
The government of Israel has released the following resources to act as official policy guidances related to AI. Future such guidances will likely follow a similar pattern:
Israeli AI Regulation and Policy White Paper: A First Glance
Harnessing Innovation: Israeli Perspectives on AI Ethics and Governance
Additional Resources
As stated earlier, in the absence of a dedicated AI regulation in Israel, various existing laws and regulations provide the necessary guidance on how users' data and information should be used concerning their digital rights.
The Copyright Act of Israel protects all intellectual property rights, including copyrights, related to creative works such as literary, artistic, and musical works. In such cases, organizations and individuals have turned to this regulation in matters related to AI-generated content and copyright ownership.
Further, Israel's Basic Law, Human Dignity and Liberty, may govern all consumer rights-related matters in relation to the overall development of AI governance frameworks in Israel. The law requires considerations respecting the universal and constitutional rights of Israeli citizens. Any practice or policy involving AI that may conflict with these rights can be challenged under the Basic Law.
United Arab Emirates
Legislation
The UAE currently does not have a dedicated AI regulation in effect.
However, it is one of the few nations at the forefront of both AI adoption and policies to promote a collaborative relationship between AI capabilities and responsible usage.
The UAE was the first country to establish an AI ministry to ensure that anybody responsible for overseeing the burgeoning sector had the appropriate resources and knowledge to make informed decisions.
Under the Ministry, the Council for AI and Blockchain, a dedicated government body, was also established to oversee all major policy considerations related to the more significant usage of AI tools and mechanisms within government infrastructures.
The body has taken a radically proactive approach towards playing more of an advisory role by issuing regular toolkits and manifestoes to help public and private bodies make responsible decisions related to the use of AI, especially when involving the data of UAE residents.
Lastly, the UAE Ministry of Cabinet Affairs announced in July 2024 that it had launched the UAE Charter for the Development and Use of AI by the UAE Artificial Intelligence, Digital Economy, and Remote Work Applications Office.
Additional Resources
Here are the main guides, tools, and incentives offered by the UAE government meant to govern the development and deployment of AI capabilities and systems within the country.
The National Artificial Intelligence Strategy 2031: The document aims to create a single homogenous framework for the general adoption of AI across various economic sectors. The program contains extensive details related to policies, initiatives, and investments being undertaken by the government to ensure AI is leveraged to its maximum potential within government services such as healthcare, education, and transportation;
AI Ethics Principles and Guidelines: A set of guidelines and principles that act as the primary standards to be followed by organizations when developing and deploying AI technologies. In essence, the guidelines aim to ensure that all developed tools and systems follow appropriate considerations for fairness, transparency, accountability, privacy, and security;
AI Coding Licence: The AI Coding License is meant as a special license for coders who are willing to develop various AI tools and codes for UAE-based organizations. Launched by Dubai International Financial Centre (DIFC), in coordination with the UAE Artificial Intelligence Office, it aims to make the UAE a regional and global hub of AI innovation;
AI Systems Ethics Self-Assessment Tool: Based on the aforementioned AI Ethics Principles and Guidelines, the UAE government's self-assessment tool for AI systems ethics gives organizations a thorough assessment of whether their services or systems follow the official AI guidelines or not.
South Korea
Legislation
In 2024, the country’s judiciary committee approved the Basic Law on the Development of AI and Creation of Trust Base (AI Basic Act) to clearly define AI, including any “high-impact AI” systems that can potentially impact human rights and safety in key areas such as healthcare and hiring. This law was later approved by the country’s parliament and formally signed into law.
It became on January 22, 2026 and applies to all AI technologies, systems, as well as industries that impact the domestic markets and users in South Korea, with the Minister of Science and Technology in charge of enforcement. Among its salient aspects is its definition of AI, disclosure requirements, rights of consumers, and penalties of up to 30 million Won or imprisonment of almost 3 years for personnel found personally liable for the violation of this law.
Additionally, the nation’s Personal Information Protection Commission (PIPC) published guidance on the use of South Koreans’ personal data in the training and development of AI models. The guidance provided information on various principles organizations should keep in mind when including personal data into training datasets.
An AI Privacy Task Force has since been established to serve as the focal point in communications and cooperation between the government and the private sector in all AI-related matters.
In September 2025, South Korea took a major step in shaping its AI future by launching the Presidential Committee on National AI Strategy by the Ministry of Science and ICT. A 5-body strong committee, it will contain experts from multiple subcommittees that will help the country in carrying out its National AI Act Plan. In the same month, PIPC announced regulatory reforms aimed at fostering innovation in AI, autonomous mobility, and robotics.
Additional Resources
Over the years, the South Korean government has issued several tools, strategies and guidelines to provide private firms with a roadmap for where best to focus their resources on maximizing AI's potential. These resources include:
R&D & Standardization Roadmap: Released by the Personal Information Protection Commission (PIPC), the R&D and Standardization Roadmap for Personal Information Lifecycle Protection and Utilization Technology (2026–2030) establishes a forward-looking technological blueprint for the AI era by integrating previous national privacy strategies to keep pace with rapid algorithmic shifts, ensuring that data can be safely harnessed for innovation without compromising individual rights;
AI Innovation Hub: The Ministry of Science and ICT designed this initiative specifically to provide AI technology development infrastructure, equipment, software and data for SMEs. As a result, local firms can leverage high-performance computing power without having to compromise on the robustness, security, or overall safety of the designed system;
AI R&D Strategy: The AI R&D Strategy aims to create an innovative and proactive AI ecosystem via a comprehensive analysis of the current state of AI technology, human resources and infrastructure. Gained insights can be leveraged to ensure resources can be distributed and devoted towards projects that promise the most effective results.
AI Regulatory Harmonization Roadmap: Developed in collaboration with 25 ministries, AI companies, research institutions, and experts, with 67 outlined tasks to ensure a coordinated move toward harmonized AI regulation, providing early guidance on compliance expectations, data handling, and safety obligations.
Saudi Arabia
Legislation
Saudi Arabia does not currently have a comprehensive AI regulation.
However, similar to several other countries taking the lead within AI, the country plans to take a more laissez-faire approach towards regulating the fledgling industry as a means to promote international investment and collaboration.
The National Strategy for Data & AI highlights the nation's ambition to transition from its traditional economic sectors towards emerging technologies, namely data and AI. With projects like NEOM well-placed to complement the development of AI technologies, Saudi Arabia's flexible regulatory framework towards AI, in addition to its several incentive schemes, is likely to attract both AI companies and investors significantly.
Secondly, Saudi Vision 2030, the Kingdom's outline for a future vibrant society, economy, and nation, aims to leverage AI towards the multifaceted needs of its citizens. The roadmap elaborates on how AI capabilities can be deployed across multiple sectors, from safer and more effective infrastructure development to facility management, environmental monitoring, traffic control management, and cybersecurity.
Additional Resources
In addition to the National Strategy for Data & AI and the overall Vision 2030, the following resources will lend a great help in understanding Saudi Arabia's regulatory attitude towards AI:
Open Data Policy: Saudi Arabia's Open Data Policy aims to create a strict framework related to the use of data, stating that any data collected for any commercial purpose must not be used for political purposes, or to support illegal or criminal activity, or to be used in racist or discriminatory expressions. This applies to any form of datasets being used to train AI systems and mechanisms;
Personal Data Protection Law: The PDPL is Saudi Arabia's primary data privacy regulation that governs how any collected personal data is to be used. Certain provisions within this regulation require the users' explicit permission and consent before being used in AI training.
Generative AI Guide: Serves as a guideline related to adoption and use of GenAI systems with examples containing various examples of the possible challenges and solutions;
AI Ethics Principles 2.0: Meant to apply to all AI stakeholders designing, developing, deploying, implementing, using, and affected by AI systems within the Kingdom.
New Zealand
Legislation
New Zealand does not have a comprehensive AI regulation in place.
However, the government and leading industry figures convened in 2021 to develop and launch the country’s National AI Strategy. The AI Strategy aims to provide a consolidated platform to all major stakeholders involved in the development and deployment of various AI technologies in a collaborative manner.
Then, in 2023, the government announced its Interim Generative AI Guidance for Public Service as a means of providing critical guidance and resources to industry leaders and practitioners to make informed decisions related to the use of GenAI tools.
Additional Resources
Some other critical resources and considerations to take into account when looking at AI developments within New Zealand include the following:
Māori Data Sovereignty Principles: Māori Data Sovereignty refers to the inherent rights and interests that Māori have concerning the collection, ownership, and application of Māori data. Such rights and interests would also extend to any AI models hoping to leverage datasets that may lead to the development of principles, structures, accountability mechanisms, legal instruments, and policies that affect the Māori people;
AI Cornerstones: Released by the national government, the AI Cornerstones will likely form the foundational basis for the overall national AI Strategy in the long run. The document aims to build a thriving human-centric AI ecosystem in New Zealand on a solid foundation of trust, equity, and accessibility that provides a roadmap of key priority areas, actions, and timelines to create a national strategy.
India
Legislation
India does not have a dedicated AI regulation, yet.
In its stead, the Digital Personal Data Protection Act (DPDPA) of 2023 contains various provisions related to the protection of personal data when used by AI applications. Additionally, it provides clarity related to operational functions within an organization, such as Data Fiduciaries and Consent Managers.
Moreover, the Indian government has taken various initiatives, such as the Indian AI Program and a slew of other advisory releases on ethical measures organizations must undertake to ensure AI capabilities continue to leverage Indians’ data responsibly.
Additional Resources
Some other critical resources and considerations to take into account when looking at AI developments within India include the following:
India AI Report by McKinsey: Famed consultancy firm McKinsey released its report on India’s AI Landscape, evaluating the potential impact of GenAI on Indian social, financial and political outlooks. The report contained both recommendations and insights on the likely scenarios within the country related to AI adoption. For organizations looking to adopt and implement GenAI capabilities within India, this report provides a neutral and comprehensive overview of the market reality and the various factors to consider in such an exercise.
NITI Aayog’s AI Strategy: The National Institution for Transforming India (NITI Aayog) is India’s primary think tank related to various policy measures and official strategies on the federal level. In March 2023, it released the National Strategy for Artificial Intelligence, which serves as a comprehensive national strategy for the Indian government on various applications and possibilities of AI adoption across various sectors such as healthcare, agriculture and education. The document is intended to be a foundational guideline that will enable both state and private institutions to leverage AI capabilities responsibility within ethical limitations.
Digital India’s AI Portal: The National AI Portal of India, also known as INDIAai Portal, is a flagship project intended to be a hub of all AI-related activities and initiatives within the country. The portal provides access to critical information, resources, policy updates and news items related to the future of AI adoption in India, making it a vital asset for various stakeholders;
A Complex Adaptive System Framework to Regulation AI: Designed as a framework based on five principles i.e., establishing guardrails, manual overrides, clear AI accountability, specialist regulator, and transparency & accountability;
Reimagining Security: An Era Powered By GenAI: Report released by Data Security Council of India on the challenges and opportunities proffered by AI with guides for startups developing specialized AI solutions;
Mexico does not have a dedicated federal AI regulation as of yet.
In the absence of a federal AI regulation, Mexico relies on a combination of initiatives, summits, and singular projects that provide organizations involved in using AI within Mexico to continue to do so in a manner that delivers value without compromising on ethical standards.
Additional Resources
Some other critical resources to take into account when looking at AI developments within Mexico include the following:
Mexican Association for Artificial Intelligence: The Mexican Association for Artificial Intelligence (SMIA) is a scientific society in Mexico that specializes in research and development projects related to artificial intelligence in Mexico. Though academic in nature, the institute publishes regular resources while also organizing events to facilitate greater collaboration between the academics and industry practitioners working on AI-related issues for greater collaboration and understanding.
AI Mexico: AI Mexico is a private initiative within the country to encourage wider communication, collaboration, and commitment by various professionals, researchers, and general tech enthusiasts on AI-related projects and developments. The primary purpose of the initiative is to provide practical resources in the form of workshops, courses, and conferences that can help the various stakeholders in their efforts to tackle various challenges and opportunities related to AI in Mexico.
National Alliance for Artificial Intelligence (ANIA): ANIA represents a multi-stakeholder and multi-sectoral coalition of AI experts from Mexico. It aims to promote an ethical and inclusive AI landscape in Mexico, through collaboration, research, and socio-economic development.
Norway
Legislation
Federal
Norway does not yet have a standalone AI statute in force. Regulation currently relies on existing laws i.e. data‑protection rules enforced by the Norwegian Data Protection Authority and national strategy documents. The Government is aligning Norwegian law with the EU AI Act through the EEA framework and has begun building a national governance system for AI: on March 26, 2025 it announced KI‑Norge (AI Norway) within the Norwegian Digitalisation Agency (Digdir), designated the Norwegian Communications Authority (Nkom) as the national coordinating supervisory authority for AI, and named Norsk akkreditering as the national accreditation body. The roles of these new bodies are distinct: KI-Norge acts as a national hub to promote innovative and responsible use of AI; Nkom is the coordinating authority responsible for supervision and enforcement of the future AI rules.
A draft Norwegian AI Act will be circulated for consultation, with the intention that it enters into force in late summer 2026. The announcement also notes the EU AI Act’s staged obligations including bans on certain “unacceptable‑risk” systems from February 2, 2025.
Norway’s approach builds on the National Strategy for Artificial Intelligence (2020), which emphasizes ethical principles, privacy, cybersecurity, and strong AI infrastructure, and it is complemented by the cross‑government National Digitalisation Strategy 2024 - 2030 that prioritizes “harnessing the opportunities of AI.”
State
Norway is a unitary state; there is no separate state‑level AI legislation. Sub‑national bodies follow national guidance. Sectoral regulators and national agencies lead on AI oversight and guidance.
Additional Resources
National Strategy for Artificial Intelligence (2020): Government strategy setting ethical and governance foundations for AI in Norway.
Regulatory privacy sandbox (Datatilsynet): A continuing program offering hands-on guidance to selected AI projects, including work on generative AI.
Framework for the Regulatory Sandbox: Objectives and methodology for responsible AI development from a privacy perspective.
The Digital Norway of the Future – National Digitalisation Strategy 2024–2030: Sets national priorities, with a dedicated chapter on leveraging AI.
Italy
Legislation
Federal
Italy enacted a dedicated national AI law i.e. Law No. 132 of September 23, 2025 (“Disposizioni e deleghe al Governo in materia di intelligenza artificiale”). It entered into force on October 10, 2025 and is expressly aligned with the EU AI Act (Regulation (EU) 2024/1689).
Key provisions include:
National oversight & roles. The Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN) are designated as Italy’s National AI Authorities. AgID handles notification/accreditation/monitoring of conformity assessment bodies; ACN oversees market surveillance, inspections, and sanctions. For financial markets, Bank of Italy, CONSOB, and IVASS retain supervisory roles. AgID is the notifying authority and ACN the single EU liaison under Article 70 of the EU AI Act.
Children’s access & consent. Under‑14s may access AI only with parental consent, and 14–17 year‑olds can consent themselves if information is clear and accessible (Art. 4(4)).
Sector rules (healthcare). AI systems in healthcare are support tools; medical decisions remain with clinicians (Art. 7). The law also sets up an AGENAS-run national AI platform to support care (Art. 10).
Professional services. In licensed professions (e.g., legal, accounting), AI may be used only as support, with clear disclosure to clients (Art. 13).
Copyright & text/data mining. Copyright protection is clarified to cover human intellectual works even if created with AI assistance; text/data mining via AI must comply with the law’s limits and the new cross‑references in the copyright statute (Art. 25).
Criminal law updates. The law criminalizes the non‑consensual spread of AI‑generated/altered content (deepfakes) with 1–5 years imprisonment and adds aggravating circumstances for crimes committed using AI (Art. 26).
Investment measures. Up to €1 billion in equity and quasi‑equity investments is authorized (Art. 23) via Italy’s venture capital instruments (CDP Venture Capital) for AI, cybersecurity, and enabling technologies (including quantum, telecom/5G, edge computing, open architectures, Web3).
State
Italy is a unitary state; there is no separate regional “AI law.” Implementation and enforcement primarily run through national authorities (AgID, ACN) alongside existing regulators (e.g., Garante privacy, sector regulators).
Additional Resources
Official text of Law 132/2025 (Gazzetta Ufficiale & Normattiva): full articles and in‑force date.
Authorities & roles (Art. 20).
Minors’ consent rule (Art. 4(4)).
Healthcare support & AGENAS platform (Arts. 7 and 10).
€1 billion investment article & government explainer.
Peru
Legislation
Federal
Peru has a dedicated national AI law and implementing regulation:
Law No. 31814 (5 July 2023): Law that promotes the use of Artificial Intelligence for the country’s economic and social development. It establishes principles for safe, ethical, transparent, and human‑centric AI and designates the Presidency of the Council of Ministers (PCM) through theSecretariat of Government and Digital Transformation (SGTD) as the national technical‑regulatory authority.
Supreme Decree No. 115‑2025‑PCM (9 Sept 2025): Approves the Regulations of Law 31814. The regulation consists of 6 titles and 36 articles and enters into force 90 working days after publication, with some provisions effective the day after. It confirms SGTD’s leadership role and sets out scope, duties, and phased implementation timelines across sectors.
Scope & exclusions. The Regulation applies to public bodies, state‑owned enterprises under National Fund for Financing State Business Activity / El Fondo Nacional de Financiamiento de la Actividad Empresarial del Estado (FONAFE), private‑sector organizations, academia, and civil society that are part of the National Digital Transformation System. Personal uses are excluded; national defense/security uses are handled under reinforced principles (proportionality, oversight, human rights).
Prohibited & high‑risk uses. The Peruvian government’s official news agency highlights explicit prohibited uses, including manipulative AI that exploits vulnerabilities, mass surveillance without legal basis, predictive policing, profiling based on sensitive data for discriminatory outcomes, and autonomous lethal capability in the civil sphere. High‑risk systems carry heightened transparency and explanation duties.
Core obligations for organizations (selected).
Maintain up‑to‑date documentation and controls for high‑risk systems; ensure transparency, accountability, and privacy protections; promote internal trainings onthe risks of AI as well as safe adoption practices; and ensure human oversight with the decision-making ability to stop or invalidate AI decisions.
The SGTD promotes the adoption of international technical standards (e.g., ISO/IEC families on security, risk management, AI governance/ML frameworks) as references for good practice.
Supervision & monitoring. SGTD conducts oversight, can request information to verify compliance, coordinates with Peru’s CSIRT and other authorities, and provides citizen alert channels to report improper uses of AI (including via gob.pe/iaperu).
Phased implementation timeline. The Regulation sets detailed deadlines (from publication of the decree) for public entities and private‑sector adopters:
Public sector (examples):
Executive, Legislative, and Judicial Branches: within 1 year.
Autonomous constitutional bodies: within 1 year.
EsSalud, regional governments, and public universities: within 2 years.
Production, agriculture, energy & mining: 3 years.
Other uses not listed above: 4 years.
MSEs/startups: differentiated deadlines e.g., small firms (>150 to ≤1700 UIT) 2 years; micro‑enterprises (≤150 UIT) 3 years.
State
Peru is a unitary state. AI governance is centralized under PCM–SGTD’s mandate in Law 31814 and its Regulation; there is no separate state‑level AI statute.
Additional Resources
Official text: Supreme Decree 115‑2025‑PCM approving the Regulation of Law 31814 (official portal & PDF).
Base law: Law No. 31814 (official gazette entry).
Government explainer (Andina): summary of rights, prohibited uses, transparency and human‑oversight requirements.
Forthcoming strategy: Draft ENIA 2026–2030 (National AI Strategy) for public comment.
El Salvador
Legislation
Federal
El Salvador enacted a dedicated national AI law:Law For The Promotion Of Artificial Intelligence And Technologies / Ley de Fomento a Inteligencia Artificial y Tecnologías (Decreto Legislativo N.º 234). It was issued on 26 February, 2025, published in the Diario Oficial on 3 March, 2025, and signed for publication by the President; the law’s text begins at page 3 of that issue.
Scope & objectives: The law’s purpose is to promote the development, research, and application of AI while ensuring responsible, fair, and secure use. It applies broadly to natural and legal persons engaged in AI development, training, deployment, or related data activities in El Salvador.
National authority & governance: The law creates the Agencia Nacional de Inteligencia Artificial (ANIA) as the lead authority. ANIA’s powers include: coordinating compliance; issuing technical assistance and training; running a National Registry of AI Development, Innovation and Application; collaborating to integrate AI education into curricula; and setting rules for the registry’s operation. ANIA is headed by an Executive Director appointed by the President.
Risk & oversight mechanisms: ANIA must establish a comprehensive risk‑evaluation framework for AI systems, balancing innovation with public safety; sectoral technical security rules are to align with the Agencia de Ciberseguridad del Estado (ACE). When AI is used commercially or to access rights or services, users must be informed if a decision was taken by or driven by AI, receive understandable explanations, and have mechanisms to contest the decision before a human competent authority.
Safeguards & responsibilities: The law embeds several safeguards, including:
Research sandbox / experiments: activities in research or sandbox settings do not generate liability, so long as systems are not deployed commercially or used in ways that directly infringe users’ rights.
Developer/operator safe harbor: no liability for misuse by third parties where developers/operators demonstrate reasonable efforts to meet security, ethics, and operational standards.
Open access & licensing: models, weights, training data, and outputs should not be subject to restrictive licensing conditions that unduly limit reuse, analysis, or improvement, provided IP, privacy, and ethics rules are respected.
Lifecycle responsibility: developers, implementers, service providers, and end‑users have defined duties to ensure safe, compliant AI across the entire lifecycle. Personal‑data use must follow the national data protection law and technical standards under ANIA/ACE oversight.
Entry into force: The decree provides that it enters into force eight days after publication in the Diario Oficial.
State
El Salvador is a unitary state; AI governance is centralized under ANIA and national law. There is no separate state‑level AI statute.
Additional Resources
Official law text (Diario Oficial, 3 March 2025: Decreto N.º 234).
Legislative Assembly listing (decree details and issuance date).
English working copy of the decree (for reference) including the entry‑into‑force clause.
Press coverage of entry into force and implementation.
Viet Nam
Legislation
Federal
Vietnam enacted the Law on Digital Technology Industry (Law No. 71/2025/QH15) on June 14, 2025, a national statute that explicitly covers artificial intelligence (AI) alongside semiconductors and digital assets. The Government’s portal notes the law classifies AI systems by risk and requires human oversight; it takes effect January 1, 2026 (with certain incentive provisions taking effect earlier).
Key AI-related features in the law include:
Risk‑based categories & oversight. AI systems are categorized (including high‑risk and high‑impact systems) with stricter technical standards and monitoring, and the law requires human-in-the-loop oversight. The Ministry of Science and Technology (MoST) is the lead authority.
Labeling / identification of AI outputs. Vietnam will maintain a national database that includes AI‑generated digital products requiring identification marks, and MoST will issue standards and the official list of content that must be labeled as AI‑generated
Regulatory sandbox. Organizations may test AI-enabled products and services in a regulatory sandbox to accelerate innovation under supervisory controls.
Data, safety & compliance. Participants must comply with Vietnamese laws on cybersecurity, data (including personal data), and consumer protection when developing or deploying AI systems.
Implementation timeline & incentives. The law is effective Jan 1, 2026 overall, while some financial and investment incentives for digital‑technology (including AI) activities apply from July 1, 2025.
Provincial
Vietnam’s AI provisions are unitary and national in scope. Provinces may host “concentrated digital technology zones” and run projects under MoST’s guidance, but the legal obligations for AI arise from the national law.
Additional Resources
Government news release confirming passage, risk categorization, and human‑oversight requirements.
English text/extracts of Law No. 71/2025/QH15 highlighting scope (AI included), sandbox, national database, and labeling concepts.
Practitioner summaries on effective dates, incentives, and labeling responsibilities.
Forthcoming standalone AI Law: The Ministry of Science and Technology released a draft AI Law for public consultation in October 2025, which is expected to complement and detail requirements set by the 2025 law.
Taiwan, Province Of China
Legislation
Federal
Artificial Intelligence Basic Act (Draft, 2025) - Taiwan’s Executive Yuan approved the draft Artificial Intelligence Basic Act on August 28, 2025, establishing the country’s first comprehensive framework for governing AI development, deployment, and oversight across public and private sectors. The draft legislation is currently awaiting deliberation by the Legislative Yuan, a necessary step before it can be enacted into law.
The Act applies to all entities i.e government authorities, institutions, and private-sector organizations involved in the research, development, deployment or provision of AI systems. It covers AI used for prediction, recommendation, decision-making, or human-like reasoning through machine learning, knowledge-based, statistical/optimization or cognitive-emulating methods.
Under Article 3, “Artificial Intelligence” is defined as software, hardware, or related systems that receive data from humans or machines and perform prediction, recommendation, decision-making, or other specific objectives using one or more of the following approaches:
Machine learning methods: supervised, unsupervised, reinforcement, or other data-driven learning.
Knowledge-based systems: utilizing inference engines and logical reasoning.
Statistical or optimization methods: developing decision-making or inference models.
Human-like reasoning: emulating human perception, planning, communication, or adaptive behavior.
The law is industry-neutral, applying to sectors including manufacturing, healthcare, finance, education, and smart cities, as well as any organization that uses AI to make predictions, decisions, or recommendations.
Key Provisions
Ethical and Principle-Based Duties (Art. 8): AI must be developed and deployed in a human-centered manner, ensuring:
Autonomy: respect for human dignity and choice.
Confidentiality: protection of privacy and trade secrets.
Safety: safeguarding life, liberty, and property.
Inclusion: ensuring fairness and non-discrimination.
Transparency: maintaining explainability, traceability, and accountability.
Compliance with Standards (Art. 14): AI systems must comply with national standards or, where unavailable, internationally recognized standards approved by competent authorities.
Technical Documentation and Safety Monitoring (Arts. 17–18):
Developers or providers must submit technical compliance documents before market entry or deployment and make them publicly accessible.
Risk-based safety measures:
For risky AI, submit a safety monitoring plan to authorities.
For high-risk AI, obtain prior approval of the safety plan before deployment and submit regular safety monitoring reports post-deployment.
Notification of Adverse Events (Art. 19) - Developers or deployers must immediately notify authorities if AI causes serious harm to life, body, liberty, or property during development or after deployment.
Participation in Industry Guidelines and Experiments (Arts. 21–22) - Entities are encouraged to participate in innovation experiments under official supervision and to follow or establish industry codes of conduct for responsible AI use.
Consumer Protections
Protection from Unsafe AI (Arts. 8, 16–19): Consumers have the right to use safe, reliable AI. High-risk AI must undergo pre-approval and continuous safety monitoring.
Protection from Unfair Practices (Art. 12): Prevents AI developers or users from abusing dominant market positions or engaging in unfair competition.
Privacy and Data Protection (Art. 9): Requires mechanisms to safeguard personal data and ensure transparency in data use.
Redress and Compensation (Art. 13): Consumers are entitled to compensation or insurance mechanisms in cases of harm caused by AI systems.
Oversight and Enforcement
The Ministry of Digital Affairs (MODA) is the primary regulatory authority, supported by municipal and county/city governments. The draft establishes duties, standards, and safety requirements but does not yet specify penalties. These will likely be introduced in subsequent implementing regulations.
As with data privacy regulations in the form of the General Data Protection Regulation, the European Union (EU) looks increasingly likely to provide the rest of the world with an appropriate blueprint on how to proceed with AI regulation.
Legislation
The AI Act
The proposed AI Act provides a standardized definition of what constitutes an AI system and contains provisions that protect the rights of individuals in relation to the use of AI systems. One of the key highlights of the Act is that it classifies AI systems into four distinct categories depending on the four levels of risks for AI systems:
These include:
Unacceptable Risk AI systems: AI systems that pose a clear threat to the safety, livelihoods, and fundamental rights of people, the use of such AI systems is prohibited.
High-Risk AI systems: AI systems that create a high risk to the health and safety or fundamental rights of natural persons, the use of such AI systems is permitted subject to compliance with certain requirements, including ex-ante conformity assessment.
Limited risk AI systems: AI systems with specific transparency obligations.
Minimal risk AI systems: AI systems representing minimal or no risk for citizens’ risks or safety, such as AI-enabled video games or spam filters.
Depending on their classification, different legal provisions, obligations, and penalties will apply to AI technologies. For example, any automated service or technology that can alter a human's behavior that constitutes a high-risk AI system, leading to potential or actual physical or psychological harm and carries fines of up to €30,000,000 per offense or 6% of a company’s annual turnover for the preceding financial year, whichever is higher.
The Act elaborates at great length on how different technologies are categorized.
An AI system is deemed as having an Unacceptable Risk if it clearly endangers people's safety, livelihood, and fundamental rights. Such AI systems are completely prohibited.
Since the mechanism that will be used to categorize systems as either High Risk or Low Risk is still being debated, the aforementioned criteria is likely to be adjusted in the future.
The AI Act is expected to be adopted by the end of 2023 after due consideration, discussion, and necessary adjustments due to dynamic AI developments.
Additional Resources
In June 2023, the Confederation of European Data Protection Organisations (CEDPO) published an AI and Personal Data guidance for Data Protection Officers. In the guidance, the CEDPO answered some fundamental questions that arise in relation to the intersection of the data protection legislative framework and the use of artificial intelligence and machine learning.
The guidance delves into matters such as the need for the AI Act, whether the GDPR regulates artificial intelligence and machine learning and which core data protection principles apply thereto, and the role of DPOs in the ever-evolving digital and technological landscape. The European Commission has also released guidelines on the Ethical Use of Artificial Intelligence in educational settings.
Regulatory Actions
EU member countries have been in the headlines for their regulatory actions against emerging AI technologies. Italy became the first European country to temporarily ban the use of ChatGPT after its data protection authority, Garante, raised serious suspicions about ChatGPT's collection, use, and maintenance of users' personal data. The ban led other regulatory bodies in EU countries, such as France and Spain, to review the use of the famous chatbot in their own jurisdictions.
The Italian DPA also issued a provisional limitation on further processing of data by Replika - a chatbot with a written and vocal interface based on AI that generates a “virtual friend” - highlighting violations of the GDPR.
Recently, the French DPA issued a 20 million Euro fine on Clearview AI for processing biometric data without an appropriate legal basis and the failure to exercise data subjects’ rights and requests to erase their data. The Austrian DPA has also ruled that Clearview AI cannot process biometric data and must delete complainants' existing personal data.
The Finnish DPA has warned healthcare providers that automated decisions for detecting patients’ healthcare needs can fail to meet data protection requirements.
Finally, in April 2023, the European Data Protection Board set up a taskforce dedicated to cooperation and exchange of information on possible enforcement actions by various data protection agencies across the EU. The EU Advocate General has also issued an opinion on the lawfulness of processing and automated decision-making under the GDPR and noted that an appropriate legal basis of data processing for AI systems to ensure compliance with the requirements of the GDPR.
Key Data Protection Obligations In Relation To The Use of AI
Let’s look into some of the key data protection obligations and best practices in relation to the use of AI that have emerged as a result of upcoming AI regulations all around the world. These obligations and best practices can provide AI systems a starting point for compliance with data protection principles.
An appropriate legal basis must be established for the processing of personal data by Artificial intelligence systems, which must be aligned with applicable privacy laws, and where consent is required or used as a legal basis, it must be ensured that it is freely given, informed, specific and unambiguous as per most privacy laws and documented.
User transparency must be ensured. Users must be informed if they are interacting with an AI system - unless it is clearly evident from the context and circumstances of the use- and they must be informed if their personal data will be used by the artificial intelligence system.
In case the artificial intelligence system shall utilize the personal data of the user for any decision-making, the user must be informed of the logic for any decision-making by the AI. The user must also be allowed to obtain human intervention and opt-out/object to data processing for automated decision-making or contest the decision.
Privacy risk assessments must be conducted before the implementation of AI systems.
Data security measures must be adopted depending on the risks to individuals caused by the AI system.
Data protection principles of data minimization and purpose limitation must be ensured.
Data accuracy must be maintained.
Certain AI systems cannot be allowed to process the personal data of data subjects and produce results due to high risk to individuals and privacy concerns. This includes AI systems leading to the exploitation of specific groups of persons (e.g. children, mentally disabled) and AI systems causing high risk to the health and safety or fundamental rights of natural persons.
Use of real-time biometric identification systems and the use of other sensitive personal data must take place with caution and in line with the applicable data protection requirements. In generative AIs, it must be ensured that AI systems do not produce results that provide personal data or sensitive personal data of individuals in response to queries.
How Securiti Can Help
Securiti is a global leader in providing enterprise data privacy, security, compliance, and governance solutions.
For organizations that understand just how important it is to comply with the existing and upcoming AI-related regulations, Securiti offers a proactive way of doing so.
Securiti's DataAI Command Platform™ is an enterprise solution based on a DataAI Command Platform framework that allows organizations to optimize their oversight and compliance with various data regulatory obligations.
Similarly, numerous other modules, such as data mapping and lineage, allow for real-time tracking of all data in motion across different AI models or systems. Doing so helps in understanding data transformation over time with absolute transparency.
Request a demo today and learn more about how Securiti can help your organization comply with any AI-specific regulation you may be subject to.
Key Takeaways:
Rapid AI Advancements: AI has made significant leaps in operational capabilities, marking the onset of the Fourth Industrial Revolution. MIT studies suggest minimal AI use can increase worker productivity by up to 14%.
Ethical Concerns and Misuse: There has been a surge in ethical misuse of AI, including deepfake technologies, raising concerns over its potential to exacerbate fake news and propaganda issues.
Global Legislative Response: In response to AI's ethical challenges, there has been a legislative push worldwide, with 37 AI-related bills passed in 2022 alone, aiming to regulate AI use and hold developers accountable.
AI as a "Black Box": Despite its potential, AI's operations remain largely unexplained, posing challenges in ensuring trustworthiness and interpretability.
Need for Flexible, Future-Proof Regulation: Effective AI regulation requires flexibility to adapt to future advancements and to be comprehensive enough to address the wide range of AI capabilities.
Data Privacy and Bias Concerns: Regulations like the European Union's AI Act emphasize the need for error-free, representative training datasets, highlighting challenges organizations face in meeting these standards.
Global AI Regulation Landscape: Various countries, including Australia, Brazil, the United States, China, the United Kingdom, Singapore, Japan, Canada, Israel, the UAE, South Korea, Saudi Arabia, New Zealand, and the European Union, are developing frameworks, guidelines, and legislation to govern AI use responsibly.
Key AI Regulation Themes:
- The importance of ensuring AI systems' safety, security, and ethical use.
- The need for transparency in AI operations and decisions.
- The challenge of addressing bias and ensuring fairness in AI systems.
- The role of international cooperation in harmonizing AI regulations.
Securiti's Role in AI Compliance: Securiti offers solutions like the DataAI Command Platform™ to help organizations comply with AI regulations, emphasizing data privacy, security, and governance. Tools for data mapping and lineage provide transparency in data transformation, essential for complying with AI-specific regulations.
Frequently Asked Questions (FAQs)
Some of the most commonly asked questions are as follows:
AI systems often operate globally, so failing to meet requirements in one region can lead to fines, access limits, or reputational damage elsewhere. Many regulations also share common principles such as risk-based controls, transparency, and human oversight.
"Across most regions, common requirements include:
- Assessing and mitigating AI risks
- Providing clear transparency about how AI operates
- Ensuring human oversight for high-risk uses
- Preventing unfair or discriminatory outcomes
- Maintaining strong data governance, privacy protections, and auditability"
Very. Countries are at different stages, definitions of “high-risk AI” vary, enforcement approaches differ, and global alignment is still developing.
Learn how to build an enterprise AI governance program with policies, controls, risk management, compliance frameworks, and oversight to scale AI safely and responsibly.
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
Executive summary In June 2026, South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.68 billion won (approximately $409 million) which was the largest...
An access-review tool flags an account with more privilege than its role needs: routine, filed, forgotten. That same week, a separate scan shows that the same...
Explore DSPM best practices for discovering sensitive data, reducing exposure, governing access, prioritizing risk, and strengthening enterprise data security.
Explore why DSPM is becoming essential for modern data security, helping organizations discover sensitive data, reduce exposure, govern access, and prepare securely for AI.
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...