Every major AI regulation, enforcement date, and compliance obligation, filterable by region and industry. Updated monthly.
Showing 21 of 21 regulations
In Force August 2, 2026
Requires conformity assessments, human oversight, audit trails, and technical documentation for AI systems in high-risk categories. Covered uses include credit decisions, insurance underwriting, employment, and healthcare.
Learn moreIn Force August 2, 2026
Requires transparency disclosures and copyright compliance documentation from providers of general purpose AI models. Models above defined compute thresholds must also complete systemic risk assessments.
Learn moreAdopted in 25+ states as of August 2026
Requires insurers to maintain governance programs for AI and algorithmic tools used in underwriting, rating, and claims. Carriers must be able to demonstrate those programs to market conduct examiners.
Learn moreIn Force Since January 1, 2023
Prohibits unfair discrimination in insurance through external consumer data sources and AI models. Requires annual certifications and documented governance of covered systems.
Learn moreIn Force Since January 1, 2026
Requires developers and deployers of high-risk AI to conduct impact assessments before and during deployment. Consumers must receive transparency notices when AI materially influences a decision about them.
Learn moreIn Force Since February 2, 2025
Bans a defined set of AI practices outright, including social scoring and manipulation of vulnerable groups. Real-time biometric surveillance in public spaces is prohibited outside narrow exemptions.
Learn moreOngoing enforcement, 2026 AI guidance issued
Extends HIPAA breach investigation scrutiny to AI systems that access, process, or generate protected health information. Covered entities must show how AI tooling is governed, logged, and access controlled.
Learn moreVoluntary, referenced in federal procurement
A lifecycle framework for identifying, measuring, and managing AI risk. It is increasingly written into federal contracts and state AI bills as the expected baseline.
Learn morePublished December 2023, adoption accelerating 2025 to 2026
A certifiable standard for AI management systems, the ISO 27001 equivalent for AI governance. Certification is becoming a procurement expectation for enterprise AI vendors.
Learn moreOngoing
Requires banks to apply model risk management governance to all models used in decision-making, including AI and machine learning. Validation, documentation, and ongoing monitoring are examiner expectations.
Learn morePost-market surveillance requirements expected 2026 to 2027
Signals mandatory continuous monitoring for AI-enabled medical devices after clearance. Manufacturers should expect formal post-market surveillance and change-control obligations.
Learn moreProposed, timeline TBD
Would make it easier for individuals harmed by AI systems to seek compensation. It creates significant liability exposure for enterprises deploying AI in consumer-facing contexts.
Learn moreOngoing enforcement
GDPR's automated decision-making provisions under Article 22 apply directly to AI systems making decisions about individuals. Enforcement is active today and regulatory attention is increasing.
Learn moreOngoing
Automated decision-making technology rules under CPRA give consumers a right to opt out of profiling. Additional regulations are expected from the California Privacy Protection Agency.
Learn moreConsultation closed January 31, 2026, implementation expected 12 months after finalization
Issued by the Monetary Authority of Singapore for all MAS-regulated financial institutions. Requires formal AI governance frameworks, board accountability, lifecycle controls, third-party AI oversight, and documented AI risk management covering traditional AI, GenAI, and AI agents. Enforced through proportionate MAS supervisory action.
Learn moreAgentic AI framework published January 2026, world's first agentic AI governance framework
Voluntary IMDA and AI Verify Foundation framework in three generations: Traditional AI (2020), Generative AI (2024), and Agentic AI (2026). Covers content provenance, safety alignment, autonomous agents, cascading actions, and multi-agent coordination. Increasingly expected in enterprise contracts and audits; PDPA enforcement applies where personal data is involved.
Learn moreCPS 230 amended provisions in force since July 1, 2026
APRA's April 30, 2026 letter calls for a step-change in AI governance across banks, insurers, and superannuation trustees. Expects formal AI governance frameworks, a full AI inventory, board accountability, human oversight of high-risk decisions, and third-party AI vendor management under CPS 230. The Financial Accountability Regime creates named individual liability for AI failures.
Learn moreIn Force Since January 22, 2026
The world's second comprehensive AI law and the first in Asia-Pacific, overseen by the Ministry of Science and ICT. Sets risk-based obligations for High-Impact AI and Generative AI, including transparency, human oversight, impact assessments, and user protection. Applies extraterritorially to organizations serving Korean users, with penalties set by enforcement decrees.
Learn moreIn Force Since September 1, 2025, METI/MIC AI Guidelines v1.2 published March 2026
Japan's first dedicated AI law establishes the AI Strategic Headquarters under the Cabinet and a Basic Plan for AI. It carries no monetary penalties or mandatory conformity assessments; enforcement is through administrative guidance and public disclosure. The METI and MIC AI Guidelines for Business are the operative compliance benchmark in procurement.
Learn moreIn force since 2024, GenAI Sandbox++ launched March 2026
Requires HKMA-regulated banks using customer-facing GenAI to keep a human in the loop, offer opt-outs, disclose purposes and limitations, and document the demographic impact of credit scoring algorithms. The March 2026 GenAI Sandbox++ extends supervised experimentation across HKMA, SFC, IA, and MPFA.
Learn moreEnacted August 2023, DPDP Rules finalization expected 2026
Governs personal data processing by AI systems handling data of Indian citizens, with consent requirements, data principal rights, and data fiduciary obligations. Rules expected in 2026 will add obligations around automated decision-making and children's data. Penalties reach INR 250 crore (about $30M USD) per violation.
Learn moreWe update this tracker monthly. Subscribe to the Trussed AI newsletter for the latest AI regulation enforcement dates, industry analysis, and governance insights.