"AI regulation" isn't one law you can read once and be done with. It's a different statute in every jurisdiction, moving at a different pace, using different definitions of the same underlying idea — and the gap between what a law says on paper and what's actually being enforced is often the most important detail in the whole analysis.
This hub is organized by jurisdiction because that's how the obligations actually attach: a system that's high-risk under the EU AI Act may sit entirely outside a comparable U.S. state law's scope, and a company operating in three of our four target markets is really managing three or four independent compliance programs that happen to overlap in places.
Every regulation page here carries a status — proposed, enacted, in force, amended, or repealed — and a last-reviewed date that's tied to an actual review, not a decorative timestamp. When a tracked law changes, we update the page in place rather than burying the change in a separate news post you'd have to go find.
The FCC's February 2024 declaratory ruling confirmed that an AI-generated voice counts as an 'artificial voice' under the TCPA, closing an argument a political operative tried to use against a wave of AI-cloned robocalls. A separate rule requiring calls to disclose AI use is still pending, not in force.
AI-enabled medical software doesn't get its own FDA lane. It goes through the same device pathways as a stethoscope or an infusion pump, with one addition built for software that keeps learning after it ships — and a real threshold question of whether it's regulated as a device at all.
Four SEC cases so far — two investment advisers, a trading-fraud scheme, and a public company's SEC filings — show the agency doesn't need new legislation to charge AI-washing. It just applies the antifraud and disclosure rules that already existed to a specific, checkable capability claim that turned out to be false.
A machine-learning underwriting model that can't explain why it declined an application isn't a legal gray area. ECOA has required a specific, accurate reason since 1974, and the CFPB spent 2022 and 2023 explaining exactly how that applies to AI — before withdrawing the explanation, not the rule, in 2025.
The EEOC's AI hiring guidance no longer exists on eeoc.gov. That doesn't mean algorithmic hiring discrimination became legal — it means the agency's own explanation of the law disappeared while the law itself stayed exactly as it was. Here's what the withdrawn guidance said, and what actually still applies.
There's no federal AI enforcement statute, yet the FTC has extracted settlements — including forced deletion of the AI models themselves — from companies making AI claims. Here's the legal theory behind 'algorithmic deception,' the real case record, and what actually crosses the line.
Article 2(7) of the EU AI Act states plainly that the Act applies without prejudice to the GDPR. The two regimes overlap on automated decision-making and impact assessments, but diverge on scope triggers, risk classification, and enforcement — and meeting one doesn't discharge the other.
The EU AI Act's General-Purpose AI Code of Practice gets covered as a headline — 'OpenAI and Anthropic signed a pledge' — when it's actually three chapters of specific, auditable commitments tied to Article 53 and 55 obligations. Here's what a signatory agrees to do, chapter by chapter, and what happens to a provider that skips it or signs only part.
The EU AI Act doesn't ask where your company is incorporated. Article 2 sets two independent triggers — placing an AI system on the EU market, and having its output used in the Union — and the second one catches non-EU companies with no EU office, no EU sale, and no EU contract at all. Here's how both triggers actually work, what genuinely takes a company out of scope, and what happens next once you're in it.
The EU AI Act's original phased schedule got rewritten mid-2026: the Digital Omnibus on AI pushed the high-risk-system deadline from August 2026 to December 2027, and the product-embedded high-risk deadline from August 2027 to August 2028. Article 5 prohibited practices, GPAI obligations, and the governance framework weren't touched. Here's what's actually in force right now, what moved, what didn't, and why.
EU AI Act fines aren't a single €35 million number. Article 99 defines three separate tiers by violation type, Article 101 sets a fourth track for general-purpose AI model providers enforced directly by the Commission, and Article 100 even reaches EU institutions themselves. Here's the full structure, including the SME inversion rule that changes real exposure by orders of magnitude.
The EU AI Office is a European Commission body with real fining power — but only over one specific category of company: providers of general-purpose AI models. Everyone else's high-risk obligations are enforced by their national market surveillance authority instead. Here's the actual jurisdiction map, the fine amounts, and how the Office differs from the AI Board, the Advisory Forum, and the Scientific Panel.
CE marking under Article 48 of the EU AI Act is the provider's own compliance signal, applied after conformity assessment — for most high-risk systems, with no external body involved at all. Here's what has to be visible, legible, and indelible, how digital marking works for software-delivered AI, and what importers have to verify before a marked system reaches the EU market.
Article 43 conformity assessment has two routes: internal control, which covers most high-risk systems and involves no external reviewer at all, and notified-body assessment, reserved for a narrow slice of biometric systems. Here's how each one actually works, what gets produced, and what forces a redo.
Articles 51 through 56 of the EU AI Act put a separate, model-level obligations track on any provider of a general-purpose AI model — documentation, copyright, and training-data transparency for everyone, with a further layer of testing and incident-reporting duties for the models classified as posing systemic risk. Here's exactly what applies to whom, and what open source does and doesn't exempt.
Article 10 requires documented data governance practices for training, validation, and testing data — provenance, bias examination, gap identification, and relevance to intended purpose — a materially different and broader standard than generic data cleaning. Here's what it actually covers.
Article 11 requires a technical documentation file, built before market placement and kept current, that lets regulators verify a high-risk system's compliance. Annex IV's scope is real, but the more expensive mistake is assembling it retroactively instead of incrementally — here's what's actually required.
Article 12 requires high-risk AI systems to automatically log events built for three specific purposes — risk identification, post-market monitoring, and deployer oversight — plus an extra minimum spec for remote biometric identification systems. Generic application logs rarely satisfy all three by accident.
Article 13 requires high-risk AI providers to produce instructions for use that let deployers interpret and correctly apply the system's output. It's routinely confused with end-user AI disclosure rules elsewhere in the Act — here's what it actually requires and why the distinction matters.
Article 14 requires human oversight measures that give a person real capability to understand, monitor, interpret, and override a high-risk AI system — not a procedural approval step. Here's the five specific capabilities the Act requires, including the automation-bias problem most teams never design for.
Article 15 requires high-risk AI systems to meet defined, maintained levels of accuracy, robustness, and cybersecurity — including AI-specific threats like data and model poisoning that a standard application security review typically doesn't test for. Here's what's actually required, and who tends to miss it.
Article 5 of the EU AI Act prohibits eight specific AI practices — social scoring, manipulative and exploitative AI, untargeted facial-recognition scraping, workplace emotion inference, and more — with no compliance path around them. It's also been in force since February 2025, earlier than almost everything else in the Act.
Article 9 requires high-risk AI providers to run a continuous risk management process across the system's entire lifecycle, not produce a one-time document. Here's what the process actually has to include, and the gap auditors flag most.
Australia has consulted extensively on mandatory AI guardrails modeled conceptually on risk-tiered approaches elsewhere, but hasn't enacted comprehensive AI legislation as of this writing.
Canada's proposed Artificial Intelligence and Data Act did not survive the federal legislative process. Here's what actually governs AI in Canada right now.
The UK's pro-innovation approach empowers existing regulators like the FCA and ICO to apply shared AI principles within their own sectors, rather than passing a single comprehensive AI law.
California regulates AI through several parallel tracks rather than one comprehensive law: CPPA rulemaking on automated decision-making technology, generative AI disclosure statutes, and employment law amendments.
Colorado's SB 205 imposes duties of reasonable care on both developers and deployers of high-risk AI systems, with impact assessment and consumer notice requirements tied to consequential decisions.
There's no single federal AI law in the US. Here's what federal agencies have actually said about AI, and why existing law already covers more AI use cases than most companies assume.
The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Frequently asked questions
Is there a single global AI law companies need to comply with?
No. There's no global AI statute — every jurisdiction covered here has written (or is writing) its own law, with its own definitions, thresholds, and enforcement mechanism. The closest thing to international alignment is voluntary frameworks like the OECD AI Principles, which shape national laws but don't themselves create legal obligations.
Which AI regulations are already in effect, not just proposed?
The EU AI Act is the furthest along, with prohibitions and literacy obligations already applicable and high-risk provisions phasing in on a set schedule. Several U.S. states, including Colorado, have enacted AI-specific statutes with their own effective dates. Track the status badge on each jurisdiction page here rather than assuming — "passed" and "in force" are not the same thing, and the gap between them is often a year or more.
Do I need to comply with the EU AI Act if my company isn't based in the EU?
Often yes. Like the GDPR before it, the EU AI Act applies extraterritorially: if your AI system's output is used within the EU, you can fall within scope regardless of where your company is incorporated. This is one of the most commonly missed points in early compliance planning — see our EU AI Act coverage for the specific triggers.
What's the difference between a regulation and a framework?
A regulation is a binding law with a government enforcement mechanism behind it — the EU AI Act, a state statute. A framework, like the NIST AI RMF, is voluntary guidance with no legal force on its own, though regulators and courts increasingly point to frameworks as evidence of what "reasonable" AI risk management looks like. See our frameworks hub for that side of the picture.