Skip to content

Regulation, jurisdiction by jurisdiction

What the AI rules of each major jurisdiction actually require, which of them are in force, and the documents you need when somebody asks you to prove it.

Most writing about AI regulation is written the week a text is published and never revised. It repeats the press release, compresses four years of phase-in into one date, and treats a bill that has been introduced as if it were law. That is how teams end up preparing for obligations that do not apply to them while missing the two that do.

These pages are organised around a different question: what is actually in force where you operate, who does it bind, and from when. Instruments are named. Article numbers appear where they are certain and are absent where they are not. Jurisdictions with proposals and no statute are described as jurisdictions with proposals and no statute.

Every page states, in a standing note, that it is information rather than legal advice and gives the date it was last reviewed. Regulation moves; the note is how you tell whether the page has kept up. For anything with money or liability attached, take the instrument and the article to a qualified lawyer in that jurisdiction.

The EU AI Act's Risk Tiers, With Examples

The four risk bands of the EU AI Act, each illustrated by systems that plainly fall inside it, and the general-purpose axis that is not a band at all.

10 min read

EU AI Act Deadlines: What Applies From When

The AI Act's phase-in dates from Article 113, what each one switches on, and which of them have been the subject of a live amendment proposal.

9 min read

Obligations for General-Purpose Models

What Chapter V of the EU AI Act requires of general-purpose model providers: documentation, downstream information, copyright policy, training-data summary and systemic-risk duties.

10 min read

Are You a Provider or a Deployer?

The AI Act's two central roles, the definitions that decide which one you hold, and the six situations where a deployer becomes a provider without meaning to.

12 min read

The AI Literacy Duty for Staff

What Article 4 of the EU AI Act requires, who it binds, what it does not require, and a training outline that would satisfy it.

8 min read

AI Regulation in the Netherlands

Which Dutch authority supervises what under the AI Act and the GDPR, what the algorithm register requires of government bodies, and where guidance does not yet exist.

10 min read

The UK's Sector-Regulator Approach

There is no UK AI act. What exists is five cross-sectoral principles and the approaches individual regulators have published under them, plus the law that already applied.

10 min read

US State AI Laws, Mapped

The US states that have enacted binding AI obligations, what each one covers, the effective dates, and the amendments that have already moved them.

12 min read

Automated Decision Rules and Consumer Rights

The rights US and EU law create when a decision about a person is automated, and the notices those rights oblige you to send.

11 min read

China's Labelling, Filing and Content Rules

The four instruments that govern AI services in China, the filing regime that gates public launch, and the labelling duties in force since September 2025.

10 min read

Canada, Japan, Korea, Brazil and India

Five jurisdictions, and for each one a plain statement of whether an AI law is actually in force, what applies instead, and what is merely proposed.

11 min read

Training Data and Copyright, by Jurisdiction

The statutory position on training data in the EU, UK, US, Japan and China — and, where the statute does not answer it, what is being litigated and what turns on the outcome.

12 min read

Who Owns What a Model Produces

Whether AI output attracts copyright in the US, UK, EU and China, what registration practice actually shows, and why the vendor terms granting you the output are not the answer.

11 min read

Employment Law and AI in Hiring

The bias audit, notice and consent rules that apply to AI in recruitment, which of them carry real enforcement, and the discrimination law that applies regardless.

11 min read

When Clinical Software Becomes a Regulated Device

The line between clinical software and a regulated medical device in the EU and the US, the classification questions that decide it, and how AI Act duties stack on top.

11 min read

Model Risk Governance in Financial Services

How SR 11-7 and SS1/23 apply to generative systems, where their definitions of a model stop fitting, and what supervisors expect instead.

11 min read

Consumer Protection and AI Marketing Claims

The enforcement actions brought over exaggerated AI claims, the legal theory each rests on, and the substantiation standard your marketing has to meet.

10 min read

ISO 42001 and the NIST AI Risk Management Framework

What ISO/IEC 42001 certification actually involves, what the NIST AI RMF demands, how they differ, and what neither of them gets you under the EU AI Act.

10 min read

Contract Clauses That Matter When You Buy AI

Sample language for the five clauses that decide an AI contract — IP, indemnity, data use, model change and regulatory roles — with the conditions vendors attach to each.

13 min read

Building a Compliance Evidence Pack

The artefacts an auditor or regulator asks for when you deploy AI, where each one comes from, who owns it, and how to assemble the pack in a week.

13 min read

Other topics