EU AI Act (Regulation (EU) 2024/1689) 3 Depth 3 of 3. A regulation that applies directly in every Member State, backed by administrative fines. 3 Depth 3 of 3. Reaches providers placing AI on the EU market wherever they are established, deployers in the EU, and importers and distributors. 3 Depth 3 of 3. Defines provider, deployer, importer and distributor, and gives each its own list of duties (for example Art. 16 for providers and Art. 26 for deployers of high-risk systems). 3 Depth 3 of 3. Tiers: prohibited practices, high-risk systems (Annex I products and Annex III uses), transparency duties for certain systems, and separate rules for general-purpose AI models. 3 Depth 3 of 3. High-risk providers draw up technical documentation before market placement, keep automatic logs, and register Annex III systems in the EU database; public-body deployers register their use. 3 Depth 3 of 3. Providers run a risk management system across the life cycle; public bodies and certain private deployers carry out a fundamental rights impact assessment before use and notify the authority. 3 Depth 3 of 3. High-risk systems are designed so people can understand, override or stop them; deployers assign oversight to competent people with authority. 3 Depth 3 of 3. Instructions for use to deployers; telling people they deal with AI; machine-readable marking of synthetic content; deepfake disclosure; a right to an explanation of certain decisions. 3 Depth 3 of 3. Training, validation and testing data for high-risk systems must follow data governance practices and be relevant and sufficiently representative; special-category data may be used for bias correction under safeguards. 3 Depth 3 of 3. High-risk systems must reach appropriate accuracy, robustness and cybersecurity, including measures against data and model poisoning and adversarial examples; testing is part of risk management. 3 Depth 3 of 3. Providers run post-market monitoring and report serious incidents within 15 days, 10 days where a person died, 2 days for widespread infringement or critical infrastructure; deployers inform the provider immediately. 3 Depth 3 of 3. Conformity assessment before market placement for high-risk systems; market surveillance authorities; fines up to EUR 35 million or 7% of turnover for prohibited practices, EUR 15 million or 3% for other duties. 3 Depth 3 of 3. Heavy for providers of high-risk systems (documentation, quality management, testing, conformity assessment); lighter for deployers of minimal-risk systems, who still carry AI literacy and transparency duties. 3 Depth 3 of 3. In force 2024-08-01; prohibitions and AI literacy 2025-02-02; general-purpose AI rules 2025-08-02; general application, incl. Art. 50, 2026-08-02; new prohibitions 2026-12-02; Annex III high-risk 2027-12-02; Annex I 2028-08-02. NIST AI Risk Management Framework 1.0 (NIST AI 100-1) with the Generative AI Profile (NIST AI 600-1) 1 Depth 1 of 3. Voluntary guidance from a federal standards body; no one is bound by it unless a law or contract refers to it. 2 Depth 2 of 3. Open to any organisation that designs, develops, deploys or uses AI, in any sector and any country. 2 Depth 2 of 3. Speaks of AI actors across the life cycle and asks organisations to define roles and responsibilities, including for human-AI configurations and oversight. 3 Depth 3 of 3. No fixed tiers: organisations map context, measure and manage risk against their own tolerance, estimating the likelihood and magnitude of each impact. 2 Depth 2 of 3. Asks for mechanisms to inventory AI systems, resourced according to risk priorities. 3 Depth 3 of 3. The Map function documents intended purposes, context and applicable laws, then the likelihood and magnitude of each beneficial and harmful impact. 2 Depth 2 of 3. Processes for human oversight are defined, assessed and documented; roles for human-AI configurations are set by policy. 2 Depth 2 of 3. Transparency and accountability risks are examined and documented, and the model is explained and its output interpreted in context. 1 Depth 1 of 3. Data collection and selection (availability, representativeness, suitability) is documented as part of the testing considerations; no separate data governance rulebook. 3 Depth 3 of 3. Testing, evaluation, verification and validation run through the Measure function: performance, security and resilience, fairness and bias are evaluated and documented. 2 Depth 2 of 3. Post-deployment monitoring plans with appeal, override, incident response and recovery; incidents are communicated to affected actors. No duty to report to a regulator. 1 Depth 1 of 3. No certification scheme; self-assessed. Texas law bars liability where a violation is found through internal review while substantially complying with the Generative AI Profile or a similar framework. 2 Depth 2 of 3. Moderate and scalable: the Playbook offers suggested actions per subcategory, and organisations choose which to adopt. 1 Depth 1 of 3. AI RMF 1.0 released 2023-01-26; Generative AI Profile released 2024-07-26 (12 risks). A revision was requested in the 2025-07-23 federal AI Action Plan; no revised version was found. ISO/IEC 42001:2023 AI management system 2 Depth 2 of 3. A requirements standard: voluntary to adopt, but an organisation can be certified against it by an independent certification body. 2 Depth 2 of 3. Any organisation that provides or uses AI, in any country; the organisation sets the boundaries of its own management system. 1 Depth 1 of 3. Addresses the organisation as a whole; top management assigns roles, responsibilities and authorities. 3 Depth 3 of 3. A defined AI risk assessment and risk treatment process, repeated at planned intervals or when significant changes are proposed. 2 Depth 2 of 3. Documented information is required throughout, and the scope statement fixes which AI systems the management system covers. 3 Depth 3 of 3. Requires both AI risk assessment and an AI system impact assessment on individuals, groups and societies. 2 Depth 2 of 3. Under review2 Depth 2 of 3. Under review2 Depth 2 of 3. Under review2 Depth 2 of 3. Under review2 Depth 2 of 3. Monitoring, measurement and evaluation, plus nonconformity and corrective action; no duty to report to an outside authority. 3 Depth 3 of 3. Internal audit and management review, and third-party certification by bodies that meet ISO/IEC 42006:2025. 3 Depth 3 of 3. Heavy: a full management system (policy, objectives, competence, documented processes, internal audit, management review) and, if certified, external audits. 1 Depth 1 of 3. Published 2023-12 (first edition). An implementation guidance project (ISO/IEC 42003) is at an early stage; no amendment to 42001 was found. ISO/IEC 23894:2023 Guidance on AI risk management 1 Depth 1 of 3. A guidance standard (recommendations, not requirements), so there is nothing to certify against. 2 Depth 2 of 3. Any organisation that develops, produces, deploys or uses products, systems and services that use AI, in any country. 1 Depth 1 of 3. Lists the organisations it serves (developers, producers, deployers, users) without separate duties for each. 3 Depth 3 of 3. The whole standard is about AI risk: how to integrate risk management into AI-related activities and functions. 1 Depth 1 of 3. Under review3 Depth 3 of 3. Describes how to identify, analyse and evaluate AI risks as part of the organisation's risk process. 1 Depth 1 of 3. Under review1 Depth 1 of 3. Under review1 Depth 1 of 3. Under review1 Depth 1 of 3. Under review2 Depth 2 of 3. Under review0 Depth 0 of 3. No certification or enforcement; it can inform the risk process of a certified ISO/IEC 42001 management system. 1 Depth 1 of 3. Light to moderate: it extends an existing risk process rather than creating a new system. 1 Depth 1 of 3. Published 2023-02-06 (first edition). OECD AI Principles (Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449) 1 Depth 1 of 3. A Council Recommendation: politically committing for adherent governments, not binding on organisations, with no penalties. 2 Depth 2 of 3. Adopted by 47 adherents at the 2024 revision, including the EU; the principles speak to all AI actors. 1 Depth 1 of 3. Principles 1.1 to 1.5 address AI actors in general; recommendations 2.1 to 2.5 address governments. 2 Depth 2 of 3. Principle 1.4 asks for robust, secure and safe AI and for managing risks across the life cycle; no tiers. 1 Depth 1 of 3. Under review1 Depth 1 of 3. Under review1 Depth 1 of 3. Under review2 Depth 2 of 3. AI actors should give meaningful information so people know when they deal with AI and can understand and challenge outcomes. 1 Depth 1 of 3. Privacy and data protection sit within the human-rights principle; the 2024 revision added attention to privacy and intellectual property. 1 Depth 1 of 3. AI should function appropriately under normal use, foreseeable misuse and adverse conditions, without unreasonable safety risk. 1 Depth 1 of 3. No reporting duty; the OECD runs a common incident reporting framework and an AI incidents and hazards monitor for voluntary use. 0 Depth 0 of 3. No certification or sanctions; the OECD follows up implementation by adherents. 1 Depth 1 of 3. Light: a shared vocabulary that other frameworks build on, rather than a programme to implement. 1 Depth 1 of 3. Adopted in 2019; revised at the Ministerial Council Meeting held 2024-05-02 to 2024-05-03. Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) 2 Depth 2 of 3. A binding treaty for the Parties that ratify it; organisations are bound only through the measures each Party adopts. 2 Depth 2 of 3. Under review1 Depth 1 of 3. Under review2 Depth 2 of 3. Parties adopt a framework to identify, assess, prevent and mitigate risks and impacts, including the option of bans or moratoria. 1 Depth 1 of 3. Under review2 Depth 2 of 3. Risk and impact assessments are carried out, repeated as needed, with prevention and mitigation measures. 2 Depth 2 of 3. Parties ensure transparency and oversight requirements suited to the context and risks. 2 Depth 2 of 3. Transparency requirements suited to the context, including where content is generated by AI. 1 Depth 1 of 3. Under review1 Depth 1 of 3. Under review1 Depth 1 of 3. Under review1 Depth 1 of 3. Each Party sets up effective oversight mechanisms; remedies and procedural safeguards are owed to affected people. No treaty-level fines. 1 Depth 1 of 3. Indirect for organisations: effort depends on how each Party implements the treaty (in the EU, largely through the AI Act). 1 Depth 1 of 3. Under reviewColorado SB 26-189, Automated Decision-Making Technology (repealed and replaced the Colorado AI Act, SB 24-205) 3 Depth 3 of 3. State law; a violation is a deceptive trade practice under the Colorado Consumer Protection Act. 1 Depth 1 of 3. Technology that materially influences a consequential decision about a Colorado consumer: education, employment, real estate, financial or lending services, insurance, health care, essential government services. 3 Depth 3 of 3. Developers owe documentation to deployers; deployers owe notices, disclosures and review to consumers. 1 Depth 1 of 3. No risk tiers: the trigger is use in a consequential decision. The 2024 act's risk management programme and impact assessments are gone. 2 Depth 2 of 3. Developers give deployers documentation on intended and known harmful uses, training data categories, limitations and review instructions; both keep records for at least three years. 0 Depth 0 of 3. No impact assessment duty; the 2024 act's assessments were removed. 2 Depth 2 of 3. After an adverse outcome, consumers can ask for correction of inaccurate data and for meaningful human review; developers give instructions for that review. 3 Depth 3 of 3. Notice before the technology materially influences a consequential decision, and within 30 calendar days of an adverse outcome a description of the decision, the technology's role and the consumer's rights. 1 Depth 1 of 3. Consumers may request their personal data and correction of inaccurate data; developers disclose training data categories. 0 Depth 0 of 3. No testing or robustness duty; developer documentation covers limitations and risks. 1 Depth 1 of 3. Developers include monitoring instructions and notify deployers of changes; there is no incident reporting duty. 2 Depth 2 of 3. Attorney General enforcement, with a 60-day cure period until 2030-01-01 (not for knowing or repeated violations); up to USD 20,000 per violation as a deceptive trade practice. No new private right of action. 2 Depth 2 of 3. Moderate: notices, adverse-decision letters, a correction and review route, vendor documentation and record keeping. 3 Depth 3 of 3. Signed 2026-05-14; duties apply from 2027-01-01. A federal court on 2026-04-27 barred enforcement of the 2024 act and any amending law until rulemaking ends and the court rules. Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) 3 Depth 3 of 3. State statute adding chapters 551 to 554 to the Business and Commerce Code, with civil penalties. 2 Depth 2 of 3. Anyone who develops or deploys an AI system in Texas; some duties apply only to government entities and health care providers. 2 Depth 2 of 3. Defines developer and deployer; the prohibitions apply to both, with extra duties for government agencies and health care providers. 1 Depth 1 of 3. No tiers: a list of prohibited intents (manipulation to harm, government social scoring, certain biometric identification, infringing rights, unlawful discrimination, unlawful explicit content). 1 Depth 1 of 3. No general inventory duty on companies; the Attorney General can demand a system description, data, metrics and monitoring information. State agency AI inventories are amended in the Government Code. 0 Depth 0 of 3. No impact assessment duty. 0 Depth 0 of 3. No human oversight duty. 2 Depth 2 of 3. Government agencies disclose AI interaction clearly and in plain language, even if obvious; health care providers disclose AI use by the date the service is first provided, except in emergencies. 1 Depth 1 of 3. Government entities may not identify people from biometric data or public images without consent where that infringes a right. 1 Depth 1 of 3. No testing duty, but finding a violation through adversarial or red-team testing is among the grounds that bar liability. 1 Depth 1 of 3. No incident reporting; the Attorney General runs an online complaint mechanism and may ask about post-deployment monitoring. 3 Depth 3 of 3. Attorney General enforcement after a 60-day cure period; penalties USD 10,000 to 12,000 (curable), 80,000 to 200,000 (uncurable), 2,000 to 40,000 per day (continuing). No private right of action. 1 Depth 1 of 3. Light for most companies: document the absence of prohibited intent, keep testing records; more for government and health care disclosure. 3 Depth 3 of 3. Signed 2025-06-22; in force 2026-01-01. The sandbox allows testing for up to 36 months. California CPPA regulations on automated decision-making technology, risk assessments and cybersecurity audits 3 Depth 3 of 3. Binding regulations adopted by the California Privacy Protection Agency, approved on 2025-09-22, enforceable with civil penalties. 2 Depth 2 of 3. Businesses subject to the CCPA; the ADMT rules reach technology that replaces or substantially replaces human decision-making in a significant decision about a California consumer. 1 Depth 1 of 3. Duties fall on the business that uses the technology for the significant decision; there is no separate developer role. 2 Depth 2 of 3. Triggers rather than tiers: significant decisions for the ADMT rights; six processing activities for risk assessments, including selling or sharing personal information. 2 Depth 2 of 3. Risk assessment reports are kept while processing continues or five years, whichever is later; the agency receives counts and an executive attestation. 3 Depth 3 of 3. A documented risk assessment before starting a triggering activity; activities begun before 2026 need one by 2027-12-31. 2 Depth 2 of 3. Human involvement takes a use outside ADMT only if the reviewer can interpret and analyse the output and has authority to change the decision; a human appeal can replace the opt-out. 3 Depth 3 of 3. Pre-use notice (purpose, opt-out, access, how the technology works); opt-out by at least two methods; access requests answered with purpose, logic, outcome and human role. 2 Depth 2 of 3. Part of the CCPA: notice at collection, purpose limits and consumer rights over personal information apply to the data the technology uses. 1 Depth 1 of 3. Separate cybersecurity audit rules apply, phased by revenue from 2028-04-01; no model testing duty was found. 1 Depth 1 of 3. Under review3 Depth 3 of 3. Agency and Attorney General enforcement; administrative fines up to USD 2,663 per violation or 7,988 if intentional or involving minors (2025 adjustment); risk assessment reports on 30 days' request. 2 Depth 2 of 3. Moderate to heavy: notices, opt-out and access processes, documented risk assessments and an executive attestation. 3 Depth 3 of 3. Effective 2026-01-01; ADMT duties for existing uses by 2027-01-01; backlog risk assessments by 2027-12-31; first submission to the agency by 2028-04-01. New York City Local Law 144 of 2021 (automated employment decision tools) 3 Depth 3 of 3. City law with implementing rules of the Department of Consumer and Worker Protection; civil penalties. 1 Depth 1 of 3. Employers and employment agencies using an automated employment decision tool for hiring or promotion decisions in New York City. 1 Depth 1 of 3. Duties fall on employers and employment agencies; vendors may supply audit data but are not the regulated party. 1 Depth 1 of 3. No tiers: one use (employment decisions) triggers the duties. 1 Depth 1 of 3. A summary of the results of the most recent bias audit must be made available on the employer's website. 3 Depth 3 of 3. An independent bias audit no more than one year old, computing selection rates and impact ratios by sex, race or ethnicity and intersectional categories. 0 Depth 0 of 3. Under review3 Depth 3 of 3. Notice to candidates and employees at least 10 business days before use, saying that the tool will be used and how; published audit summary. 1 Depth 1 of 3. The audit may use historical data or, where that is insufficient, test data; categories under 2% of the data may be excluded. 2 Depth 2 of 3. The bias audit is the testing duty; it covers disparate impact only, not accuracy or security. 1 Depth 1 of 3. The audit is repeated at least yearly for continued use; no incident reporting. 2 Depth 2 of 3. Independent auditor; the city department enforces, with civil penalties of USD 500 to 1,500 per violation and each day of use counted separately. A 2025-12-02 State Comptroller audit found enforcement weak. 1 Depth 1 of 3. Light to moderate: commission a yearly audit (often with the vendor), post the summary, send notices. 3 Depth 3 of 3. Rules effective and enforcement from 2023-07-05; the duties apply now. UK principles-based approach to AI regulation (white paper CP 815 and government response CP 1019) 1 Depth 1 of 3. Non-statutory principles; the government keeps targeted binding requirements under review. 2 Depth 2 of 3. The United Kingdom, across all sectors, through each regulator's existing remit. 1 Depth 1 of 3. Addressed to regulators, who apply the principles to the organisations they supervise; no provider and deployer split. 1 Depth 1 of 3. Context-based: risk is judged by each regulator for its sector, not by a central list. 1 Depth 1 of 3. Central government departments must publish records under the Algorithmic Transparency Recording Standard; no inventory duty on companies. 1 Depth 1 of 3. No general assessment duty; the planned AI Management Essentials self-assessment tool will not be published (government response, 2025-12). 2 Depth 2 of 3. The Data (Use and Access) Act 2025 replaced UK GDPR Art. 22 with Arts. 22A to 22D: significant automated decisions need safeguards, including human intervention and a way to contest. 2 Depth 2 of 3. Appropriate transparency and explainability is one of the five principles; public-sector algorithmic tools are recorded under ATRS. 2 Depth 2 of 3. UK GDPR and the Data Protection Act 2018, as amended by the 2025 Act, govern personal data used in AI. 1 Depth 1 of 3. Safety, security and robustness is one of the five principles; the AI Security Institute (renamed 2025-02-14) tests advanced models. 0 Depth 0 of 3. Under review1 Depth 1 of 3. Enforcement only through each regulator's existing powers; accountability and governance, and contestability and redress, are principles. 1 Depth 1 of 3. Light to moderate, depending on the sector regulator and on data protection duties. 3 Depth 3 of 3. White paper 2023-03; response 2024-02-06; ATRS mandatory for departments from 2024-02-06; Data (Use and Access) Act assent 2025-06-19, s. 80 in force 2026-02-05. Singapore Model AI Governance Framework (second edition), with the frameworks for generative AI and agentic AI 1 Depth 1 of 3. Voluntary guidance; the Personal Data Protection Act is the binding backdrop. 2 Depth 2 of 3. Any organisation deploying AI, in any sector; meant to be adapted to its context. 1 Depth 1 of 3. Addressed to the deploying organisation; the generative AI framework adds accountability across the development chain. 2 Depth 2 of 3. The level of human involvement in AI-augmented decisions is set according to the risk of harm. 1 Depth 1 of 3. The self-assessment guide helps organisations record their practices against the framework. 1 Depth 1 of 3. Self-assessment against the framework to find gaps, not an impact assessment. 3 Depth 3 of 3. A central area of the framework: deciding how much human involvement AI-augmented decisions need. 2 Depth 2 of 3. Stakeholder interaction and communication is one of four areas; decisions made with AI should be explainable, transparent and fair. 2 Depth 2 of 3. Advisory guidelines explain how the PDPA applies to personal data in AI recommendation and decision systems; data is a dimension of the generative AI framework. 3 Depth 3 of 3. AI Verify: a testing framework on 11 principles with a toolkit that runs in the organisation's own environment; testing and assurance is a generative AI dimension. 1 Depth 1 of 3. Incident reporting is a dimension of the generative AI framework, on a voluntary basis. 1 Depth 1 of 3. AI Verify produces a test report; there are no sanctions under the frameworks, and PDPC enforces only the PDPA. 1 Depth 1 of 3. Low to moderate and self-paced; AI Verify testing is optional. 1 Depth 1 of 3. Second edition 2020-01-21; generative AI framework 2024-05-30; agentic AI framework 2026-01-22. No dated obligations. AIUC-1, the standard for AI agent security, safety and reliability (Q3 2026 release) 2 Depth 2 of 3. A private certification standard, not law: voluntary to adopt, and the Artificial Intelligence Underwriting Company, which maintains it with a consortium, is the only body that issues the certificate. 2 Depth 2 of 3. Agentic AI systems only, built or deployed by any organisation in any country; the organisation chooses which agents are certified, and may start with one high-risk agent. 2 Depth 2 of 3. Separates the agent developer, which sets and documents secure defaults, from the deployer, which configures the agent securely for its own context; one organisation can be both. 2 Depth 2 of 3. Each agent gets a risk taxonomy built from its capabilities and deployment context (C001); requirements apply by capability tags such as universal, automation or code generation. No legal risk tiers. 2 Depth 2 of 3. Logs of agent processes, actions and outputs (E015) and a record of data processing locations (E011) are mandatory; a repository of model cards and datasheets is supplemental (E017). 2 Depth 2 of 3. A risk taxonomy (C001) and internal pre-deployment testing across risk categories (C002); the standard's own ISO/IEC 42001 crosswalk grades the impact assessment clauses as a partial gap. 1 Depth 1 of 3. Human review of flagged high-risk outputs (C007) and real-time feedback and intervention (C009) are supplemental, not mandatory; E004 names an accountable lead for each change that needs approval. 2 Depth 2 of 3. Users must be told when they deal with an AI system rather than a person (E016, mandatory); a transparency policy with model cards and datasheets is supplemental (E017). 3 Depth 3 of 3. A whole domain of eight mandatory requirements: input and output data policies (including training on customer data), limits on agent data access, and safeguards against leaks of personal data, IP, customer data and secrets. 3 Depth 3 of 3. Mandatory technical evals, unique on this wheel: third-party adversarial testing (B001) and third-party tests of harmful and out-of-scope outputs, hallucinations and tool calls at least every three months (C010 to C012, D002, D004). 2 Depth 2 of 3. Failure plans for security breaches, harmful outputs and hallucinations (E001 to E003) and logging of third-party access (E009); risk monitoring is supplemental (C008). No duty to report to a regulator. 3 Depth 3 of 3. An accredited auditor audits the controls and the publisher runs the technical tests; a certification committee issues a certificate valid for 12 months, kept valid by technical testing at least every three months. 3 Depth 3 of 3. Heavy: evidence across legal, operational and technical controls plus evals. The standard's pages give four to eight weeks (certification page) or five to ten weeks (FAQ), then quarterly testing and a yearly re-audit. 1 Depth 1 of 3. Released each quarter on 15 January, April, July and October; the current release is dated 2026-07-15, the site was last updated 2026-09-17, and the next release is due 2026-10-15. No legal dates.