Regulatory Frameworks

The primary horizontal statutes and executive instruments that govern AI development, deployment, and trade. Listed roughly from broadest jurisdictional scope to jurisdiction-specific.

  • EU
    Regulation (EU) 2024/1689 — Artificial Intelligence Act The EU's horizontal AI statute. Risk-based classification (prohibited, high-risk, limited risk, minimal risk); obligations for providers, deployers, importers, and distributors; prohibitions effective Feb 2025; GPAI rules and most provisions active Aug 2, 2026; high-risk system obligations fully applicable Aug 2027.
  • US
    NIST AI Risk Management Framework (AI RMF 1.0) Voluntary federal framework for managing AI risks across the AI lifecycle. Published January 2023. Companion profiles include the Generative AI Profile (July 2024). Mapps to the OECD AI Principles; widely referenced as a baseline by US federal agencies and private-sector governance programs.
  • US
    Executive Order 14110 — Safe, Secure, and Trustworthy Development and Use of AI Presidential executive order issued October 30, 2023 directing federal agencies on AI safety, security, and trustworthiness. Revoked by EO 14148 (January 2025) — see EO 14179 for the current administration's AI executive-order posture.
  • SG
    Singapore IMDA AI Verify Toolkit Voluntary self-testing framework for AI system fairness, transparency, and robustness. Launched 2024 and extended to generative AI use cases in 2025. Companion: Model AI Governance Framework v2 (2024) and the January 2026 agentic AI governance framework.
  • UK
    UK AI Regulation — A Pro-Innovation Approach (2023 White Paper) Sector-by-sector regulatory approach without horizontal AI legislation. Five cross-cutting principles: safety, security, transparency, accountability, and contestability. Followed by the 2024 AI Safety Bill and ongoing 2025–2026 implementation work by the AI Safety Institute.
  • CN
    China — Interim Measures for the Management of Generative AI Services Effective August 15, 2023. China's primary regulation governing generative AI services, with security assessment and content compliance obligations for providers. Supplement to the 2022 Deep Synthesis Provisions and 2021 Algorithm Recommendation Provisions.
  • CA
    Canada — Artificial Intelligence and Data Act (AIDA) Proposed federal statute tabled as part of Bill C-27 (June 2022). High-risk AI system obligations, with regulator powers assigned to the AI and Data Commissioner. Legislative status as of 2025: stalled; Parliamentary re-tabling under parliamentary review.

Accountability & Liability Instruments

Civil liability frameworks specifically addressing harm caused by AI systems. These instruments sit alongside general product liability and tort law.

  • EU
    EU AI Liability Directive (AILD) — Proposal COM(2022) 496 Proposed horizontal liability regime covering non-contractual civil claims for AI-caused harm. Two structural changes versus national tort law: a rebuttable presumption of causation where an AI Act violation is shown, and disclosure rights forcing defendants to produce AI system documentation. Transposition target: 2027–2028.
  • EU
    EU Product Liability Directive (Directive (EU) 2024/2853) Modernised horizontal product liability regime effective December 2026. Extended to software, AI systems, and integrated digital products. Eased burden of proof for damage caused by AI-driven products through disclosure and presumption mechanisms paralleling the AILD.
  • US
    NIST AI RMF Generative AI Profile (NIST AI 600-1) July 2024 companion profile to the AI RMF covering 12 GenAI-specific risk categories. Functions as a practical accountability overlay for organisations deploying or integrating large language models and other generative systems.
  • ISO
    ISO/IEC 42001:2023 — AI Management System (AIMS) First internationally certifiable management-system standard for AI governance. Specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system. Certifiable framework that complements the EU AI Act's provider obligations.

Technical Standards

Operational and technical standards supporting conformance with the regulatory frameworks above. Most are general-purpose and applicable across jurisdictions.

  • ISO
    ISO/IEC 42001:2023 — AI Management System Top-level AIMS standard (also listed above as a certifiable framework). Defines the policy, risk treatment, and lifecycle controls expected of an AI-governed organisation.
  • ISO
    ISO/IEC 23894:2023 — AI Risk Management Guidance Detailed guidance on AI-specific risk identification, analysis, evaluation, and treatment. Designed for alignment with ISO 31000 (risk management) and as operational support for AI RMF-aligned programs.
  • NIST
    NIST AI RMF 1.0 + GenAI Profile The NIST AI RMF and its Generative AI Profile together form the de facto US baseline for AI governance practice — used as a reference for both FMIA conformance and AIMS implementation.
  • ETSI
    ETSI TS 103 700 — Securing AI Systems European Telecommunications Standards Institute technical specification on security threats and mitigations for AI-enabled systems. Useful as a primary reference for AI security threat modelling.

Regulatory Bodies & Contacts

The agencies, offices, and competent authorities currently responsible for AI governance enforcement, supervision, and policy in their respective jurisdictions.

  • EU
    European AI Office European Commission body established February 2024 to coordinate EU-level AI Act implementation. Operates the GPAI Code of Practice working groups with model providers and represents the Commission at international AI governance fora.
  • EU
    National Competent Authorities — EU Member State List Member-state-level regulators designated under Article 70 of the EU AI Act to enforce national-market provisions. Examples: Dutch RDI (Autoriteit Consument & Markt), Spanish AESIA, Italian AgID, French CNIL-facilitated AI framework, German BNetzA.
  • US
    US AI Safety Institute (USAISI) Operational unit under NIST, established February 2024, conducting pre-deployment evaluations of frontier AI models under the 2023 voluntary commitments. Issues public guidance on model testing and red-teaming.
  • SG
    Singapore Digital Trust Centre (DTC) and IMDA Info-communications Media Development Authority and the A*STAR-hosted Digital Trust Centre coordinate Singapore's voluntary AI governance work and the AI Verify programme.

Regulatory Timeline

Confirmed enforcement and activation dates for the frameworks above. Dates are the formal statute-driven milestones, not commentary on likely slippage.

  • Oct 2023 EO 14110 issued. US executive order on safe and trustworthy AI development.
  • Jan 2023 NIST AI RMF 1.0 published. Voluntary federal baseline adopted by multiple US agencies.
  • Aug 2023 China Generative AI Measures effective. Security assessment and content compliance obligations for GenAI providers.
  • Jul 2024 NIST AI RMF Generative AI Profile published. Twelve GenAI-specific risk categories.
  • Dec 2024 EU Product Liability Directive adopted. Member-state application by December 2026.
  • Feb 2025 EU AI Act prohibitions and AI literacy obligations apply. Prohibited practices (Article 5) + Article 4 AI literacy requirement.
  • Jan 2025 EO 14110 revoked by EO 14148. Posture shifted; EO 14179 (Jan 2025) reorients AI policy around innovation.
  • Jan 2026 Singapore — Agentic AI Governance Framework. First national framework specifically targeting agentic systems.
  • Aug 2 2026 EU AI Act — GPAI + most provisions apply. General-purpose AI model obligations, transparency, classification, and most non-high-risk obligations.
  • Dec 2026 EU Product Liability Directive application. Modernised regime covers software and AI-driven products.
  • Aug 2027 EU AI Act high-risk system obligations apply. Full applicability for Annex III high-risk systems — risk management, data governance, transparency, human oversight, accuracy, robustness, cybersecurity.
  • 2027–28 EU AI Liability Directive transposition. Member-state implementation across the EU.