Skip to content

International AI governance and standards

AI rules and standards outside the EU and US, and the voluntary frameworks that increasingly function as the baseline a buyer asks you to meet.

Most AI compliance writing is about two jurisdictions. That is a reasonable place to start and a bad place to stop, because the instruments that will first block a launch are often somewhere else entirely: a filing you cannot complete in time in China, a labelling duty in Korea that starts on a fixed date, a certificate a procurement team in Singapore or the Gulf asks for before it will read your security questionnaire. None of those is exotic. They are just written in a different register from the EU AI Act, and several of them do their work without imposing a fine on anybody.

These pages take one instrument each and say what it actually requires, who it binds, from what date, and what it deliberately leaves alone. Where the position is unsettled — a bill in committee, a statute whose implementing regulations have not appeared — the page says so and names the thing to check, because a confident summary of an unsettled question is worse than no page. Assume the overview of the landscape exists; this is the level underneath it.

The FCA and PRA on AI: Existing Rules, No New Rulebook

How the UK financial regulators apply SM&CR accountability, the Consumer Duty and operational resilience to AI instead of writing an AI regime, and what that leaves unresolved.

9 min read

The ICO's AI and Data Protection Guidance: What It Adds

The structure of the ICO's AI guidance, the fairness chapter that generic GDPR advice does not contain, and how the 2025 reform of Article 22 changed the automated-decisions position.

9 min read

The UK's Pro-Innovation Approach: Five Principles, No Statute

What the 2023 white paper actually established — five non-statutory principles applied by existing regulators — and the things it deliberately declined to do.

8 min read

The Online Safety Act When AI Generates the Content

When a generative AI feature brings a service into the Online Safety Act's scope, which duties then apply, and how the intimate image offences reach deepfakes.

9 min read

Canada's AIDA: What It Would Have Required, and Why It Died

The Artificial Intelligence and Data Act died with Bill C-27 when Parliament was prorogued in January 2025 — what it would have imposed, and what governs Canadian AI now.

8 min read

The OPC's AI Guidance Under PIPEDA: Canada's Operative Framework

With AIDA dead, PIPEDA is what governs AI in Canada federally — the OPC's principles for generative AI, the appropriate purposes test, and the meaningful consent standard.

9 min read

Quebec Law 25: The Automated Decision Rights, Section by Section

Section 12.1's notification and explanation rights for exclusively automated decisions, the profiling notice in section 8.1, and how both differ from GDPR Article 22.

9 min read

Japan's AI Guidelines for Business: the Soft-Law Approach

What the METI and MIC guidelines recommend, which of the three business roles you occupy under them, and why Japan chose guidance with no penalty attached.

9 min read

Japan's AI Promotion Act: What It Actually Requires

The 2025 Act creates duties on the state, best-efforts duties on business, and no penalties at all — with disclosure rather than fines as the enforcement mechanism.

9 min read

China's Generative AI Measures: the Registration and Filing Duty

The security assessment and algorithm filing a generative AI service must complete before it can be offered to the public in mainland China, and which services the duty catches.

10 min read

China's Algorithm Registration Requirement, Explained

The CAC's algorithm filing obligation under the 2022 recommendation provisions — which five algorithm types it covers, the ten-working-day deadline, and what gets published.

9 min read

China's Deep Synthesis Provisions: Labelling Synthetic Content

The 2023 provisions require two different kinds of label on synthetic media, restrict removing them, and demand consent before a real person's face or voice is edited.

9 min read

Brazil's PL 2338: the Status of Its AI Bill

A dated account of where Brazil's comprehensive AI bill has actually got to, and why describing its risk tiers as Brazilian law is wrong.

8 min read

Brazil's LGPD and Automated Decision-Making Provisions

Article 20 of the LGPD gives a right to request review of solely automated decisions — but, unlike the GDPR, it does not require the reviewer to be a human being.

9 min read

South Korea's AI Basic Act: Effective January 2026

What Korea's Framework Act asks of high-impact AI operators and generative AI providers, when it applies, and which details the Enforcement Decree still fills in.

10 min read

India's DPDP Act: What It Says (and Doesn't Say) About AI

The Act contains no AI-specific regime; it reaches AI through consent, accuracy and one algorithmic due-diligence duty on Significant Data Fiduciaries.

10 min read

Singapore's Model AI Governance Framework

The structure of Singapore's voluntary framework and its generative AI companion, and the binding PDPA rules underneath that voluntary really does not reach.

9 min read

Australia's Proposed Mandatory AI Guardrails

The ten guardrails proposed in the September 2024 consultation, the three regulatory options canvassed with them, and where the proposal has actually got to.

9 min read

Switzerland's Federal Data Protection Act and AI

How the revised FADP reaches AI through automated individual decisions, impact assessments and transfer rules, in a country with no AI statute.

9 min read

UAE's AI Regulation and Dubai's AI Governance Framework

Which UAE and Dubai AI instruments are binding law, which are strategy, and why the free zones have stricter AI rules than the federal onshore regime.

9 min read

South Africa's POPIA and Automated Decision-Making

Section 71 restricts decisions based solely on automated processing, with two exceptions and a specific duty to disclose the underlying logic — and it protects companies as well as people.

9 min read

ISO/IEC 42001 Certification: What the Audit Actually Checks

The certification audit examines an AI management system against clauses 4 to 10 and Annex A controls — it does not test your model, and the certificate does not say your outputs are safe.

10 min read

What ISO/IEC 42001 Certification Adds Over a Self-Assessment

What an accredited third-party audit against ISO/IEC 42001 gives you that an internal gap assessment cannot, and when each is genuinely enough.

9 min read

The NIST AI RMF's Four Functions, Explained

What Govern, Map, Measure and Manage each ask an organisation to produce, and why the framework is ordered the way it is.

9 min read

The NIST Generative AI Profile: What It Adds to the RMF

The twelve generative-AI risks NIST AI 600-1 names that the base framework does not, and how its suggested actions attach to RMF subcategories.

9 min read

SOC 2 for an AI Vendor: Which Trust Service Criteria Apply

How the five trust services categories map onto the controls an AI vendor has to evidence, and which of them are optional in practice.

10 min read

How ISO/IEC 23894 Feeds Into an ISO 42001 Management System

Why 23894 is risk-management guidance that supplies the method for 42001's requirements, rather than a competing or alternative standard.

8 min read

The IEEE 7000 Series: What These AI Standards Actually Cover

The individual standards in IEEE's 7000 series, what each one's scope is, and what invoking one in a contract commits you to.

8 min read

CEN-CENELEC JTC 21: the EU's Harmonised Standards for the AI Act

What the presumption of conformity in Article 40 of the AI Act actually gives a provider, and where JTC 21's standards stand in producing it.

10 min read

The EU's Text-and-Data-Mining Opt-Out Under Article 4 CDSM

The machine-readable reservation of rights that switches off the commercial text-and-data-mining exception, and what is genuinely unsettled about it.

10 min read

The US Copyright Office's AI Report, Part 2: Copyrightability

What the Copyright Office concluded in January 2025 about human authorship, prompts, and when AI-assisted works can be registered.

9 min read

The US Copyright Office's AI Report, Part 3: Training Data

The fair-use analysis in the Office's May 2025 pre-publication report on generative AI training, and the unusual status the document has carried since.

10 min read

The UK's AI and Copyright Consultation: the Proposed Outcome

The opt-out-based exception the UK government said it preferred, what happened to it in Parliament, and what has actually been decided.

9 min read

Japan's Article 30-4: the Text-and-Data-Mining Copyright Exception

The non-enjoyment purpose test in Article 30-4 of Japan's Copyright Act, and the proviso that stops it being an unconditional permission to train.

9 min read

Getty Images v Stability AI: the UK Case, Status and Rulings

What the English High Court actually decided in the Getty proceedings, which claims were dropped before judgment, and what remains undecided.

9 min read

New York Times v OpenAI: Case Status and Key Rulings

What has actually been decided in the New York Times litigation against OpenAI and Microsoft, and what every ruling so far has left open.

9 min read

Thomson Reuters v Ross Intelligence: What the Ruling Decided

The February 2025 summary judgment holding that Ross's copying of Westlaw headnotes was not fair use, and how far it actually reaches.

9 min read

Other topics