Regulatory Focus
Artificial Intelligence (AI)

Artificial intelligence (AI)
195
Countries Covered
28
Languages
792
Regulatory Sources
Artificial intelligence covers software systems that mimic human reasoning, learning, and decision-making to perform tasks with limited or no human intervention. It includes applications that analyze data, generate outputs, automate processes, and support decisions across business, consumer, and public-sector use cases.
The regulation of AI technologies imposes risk-based obligations on companies that develop, deploy, or use such systems, influencing compliance expectations related to safety, transparency, governance, and responsible use across various markets.
Companies developing or placing AI-enabled products on the market are typically required to assess and manage risks associated with system design, use, and impact. Obligations may include restrictions on certain uses, governance over autonomy and human oversight, data quality and explainability requirements, ongoing monitoring, and compliance with applicable labeling, assessment, and liability rules.
- Risk Management: Establishing systems to assess and manage risks specifically created by AI applications.
- Conformity Assessments: Undertaking mandatory assessment procedures before an AI system is placed on the market or put into service.
- Data Quality: Utilizing high-quality datasets to ensure the system does not present bias and remains non-discriminatory.
- Traceability and Recordkeeping: Ensuring rigorous logging and record retention to maintain traceability if an incident occurs.
- Transparency and Information: Providing open, transparent information to users regarding the system’s function.
- Marking and Labeling: Adhering to specific requirements for marking or labeling AI-enabled products.
- Human Oversight: Defining specific obligations for users and providers, particularly regarding governance and oversight of high-risk applications.
- Registration and Reporting: Complying with mandatory registration and reporting requirements as specified by the regulatory framework.
Our coverage encompasses global laws, frameworks, and technical standards, both enacted and proposed, governing software that imitates human cognition, reasoning, and sensory perception. We focus on a risk management approach, tracking regulations for high-risk applications, such as robot-assisted surgery and recruitment software, that mandate data quality, traceability, and conformity assessments while excluding AI in automotive products, military/weapons use, and deepfakes.
Examples of regulations within our coverage:
- EU: Harmonised Rules on Artificial Intelligence, Regulation (EU) 2024/1689
- EU: Standardisation Request to CEN and CENELEC Regarding High-risk AI Systems in Support of Regulation (EU) 2024/1689, Implementing Decision C(2025)3871
- USA: Artificial Intelligence National Policy Framework, Executive Order 14365, December 2025
- South Korea: Framework Act on the Advancement of Artificial Intelligence and the Establishment of Trust-Based Systems, Law No. 20676, 2025
- Council of Europe: Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS 225, September 2024
- Kyrgyz Republic: Digital Data, Draft Code, August 2023
- China: Measures for Identifying AI-Generated Content, Announcement No. 2, 2025
- Canada: The Artificial Intelligence and Data Act (AIDA), Companion Document, March 2023
- Canada: Responsible Development and Management of Advanced Generative AI Systems, Voluntary Code of Conduct, 2023
- South Korea: Establishment of Korean Industrial Standards (KS) for Certain Artificial Intelligence (AI), Notice No. 2023-612
- India: Artificial Intelligence (AI) Strategy, Expert Group Report, October 2023
- UK: National AI Strategy, September 2021
Experts in this Area

Intelligent Resources
Automate the work of managing regulatory change.
Let AI agents do the heavy lifting of monitoring regulations, mapping requirements to products, extracting obligations, and surfacing the risks that need attention first.
Monitor Product Compliance
Stay Ahead of Regulatory Change
Get early visibility into changes that could affect your products, supply chain, or market access—so you can act proactively, not reactively.
Assess Regulatory Applicability
Map Regulations to Your Products
Eliminate manual research and cut through regulatory noise by surfacing only the requirements relevant to your business, markets, and product categories.
Identify Compliance Requirements
Turn complex regulations into clear, actionable tasks.
Give your teams instant clarity as AI agents transform dense legal and regulatory text into structured, easy-to-understand requirements.
Prioritize Business Risk
Focus Where Risk Is Highest
Make faster, risk-informed decisions with confidence as AI agents automatically rank regulatory changes based on urgency, business impact, compliance deadlines, and product exposure.
Spotlight
Turning Compliance into Value

The State of Product
Compliance 2026
Discover how 500+ global leaders are shifting product compliance from a cost-centre into a strategic driver of growth, with key benchmarks like 69% of teams calling remediation their biggest challenge.
Frequently Asked Questions
-
Risk classification is typically based on the intended use and potential impact of the AI system. Systems affecting areas such as safety, fundamental rights, employment decisions, or critical infrastructure are more likely to be subject to higher regulatory scrutiny and additional compliance obligations.
-
Many AI regulations and standards are principles-based or in draft form, which can create uncertainty around practical implementation. Compliance teams must monitor regulatory developments closely, interpret high-level requirements, and align governance, documentation, and monitoring practices with evolving expectations.
-
Article 6 of the EU AI Act states that an AI system is high‑risk if it is intended as a safety‑critical component of a product (or is itself a product) covered by EU harmonisation legislation listed in Annex I and requires a third‑party conformity assessment. 6(2) goes on to say that AI systems listed in Annex III are also considered high‑risk. The full list can be found here.
-
A simple rule of thumb is that having sensors or the internet doesn’t automatically make a product “AI-regulated”, and it is usually only in scope if it uses AI/ML to make predictions or decisions that can affect people’s safety, rights, or opportunities, i.e., biometrics, surveillance/monitoring or dealing with critical systems. If the AI is just doing small behind-the-scenes improvements, such as something like battery optimisation, it’s usually lower risk and less likely to be targeted by AI laws. This again would vary depending on your specific product scope and markets, however.



