Regulation & Standards
Binding and voluntary AI safety regulation: California SB 53, New York's RAISE Act, the EU AI Act and its GPAI Code of Practice, plus management-system standards (NIST AI RMF, ISO/IEC 42001) an organisation can certify against.
Guides
The Middle East and Africa: AI Strategies, Not AI Laws
Search “AI regulation in Saudi Arabia” or “AI law in Kenya” and you will find governance trackers that colour these countries in as regulated. What each government has actually published is a strategy — a policy document setting direction and capacity-building goals — not an enacted statute that creates obligations or penalties. This guide verifies the real instrument in each of eight Middle East and Africa jurisdictions, names the binding data-protection laws that do exist alongside them, and is explicit about the difference.
Peru’s Ley 31814: A Promotional Law, Then a Real Risk Regime by Decree
Peru is routinely credited as having the first enacted national AI law in Latin America, and that credit is accurate — but the credit usually stops at Ley N° 31814 (2023), which is a promotional, principles-only statute with no risk tiers and no penalties of its own. What most summaries miss is what happened two years later: a 36-article implementing decree, published 9 September 2025, that quietly built a real EU-AI-Act-shaped risk taxonomy on top of that law — prohibited uses, high-risk obligations, the works. What it still does not build is a penalty regime to go with it.
Taiwan’s AI Basic Act: 20 Clauses, No Penalties, No Tiers Yet
Taiwan’s Legislative Yuan passed the Basic Act on Artificial Intelligence on December 23, 2025; President Lai promulgated it January 14, 2026. The 20-clause soft-law framework sets no penalties and no risk tiers, instead delegating risk classification to MODA (not yet published) and sector safety guidelines to individual agencies under Clause 16 — the third Asian ‘basic act’ after Japan and Korea, and structurally distinct from both.
Germany’s KI-MIG: The National AI Act Implementation Statute
The Bundesnetzagentur’s own 29 July 2026 announcement confirms KI-MIG — the KI-Marktueberwachungs- und Innovationsfoerderungsgesetz — is in force. It names the Bundesnetzagentur to three distinct roles (central market surveillance authority, single point of contact under AI Act Article 70, and central complaints body under Article 85), mandates an AI regulatory sandbox with explicit priority access for SMEs, start-ups, and research institutions and universities, and adds a dedicated enforcement chamber, national administrative-offence fines up to €50,000, and a non-public high-risk-system registry — all genuinely new national-level substance on top of the EU AI Act’s own text.
California’s CPPA ADMT Regulations: A Separate Regime From FEHA’s ADS Rules
Two California agencies regulate automated decision-making on two different theories, and compliance teams keep conflating them. The CPPA’s ADMT regulations — adopted July 24, 2025, effective January 1, 2026 — are consumer-privacy law: pre-use notice, an opt-out right, an access right, and a risk-assessment trigger, for ADMT used in financial, housing, education, employment, or healthcare decisions. That is a wholly separate regime from the Civil Rights Council’s FEHA automated-decision-system rules, which are anti-discrimination law enforced by a different agency on a different theory.
ISO/IEC 42005:2025: What an AI System Impact Assessment Actually Has to Contain
ISO/IEC 42001 clause 6.1.4 tells you to establish an AI system impact assessment process and clause 8.4 tells you to perform it and keep the results, but never says what the document looks like. ISO/IEC 42005:2025, published 28 May 2025, is the companion guidance that does. It is not certifiable, and a 42005 assessment is neither a GDPR Article 35 DPIA nor an EU AI Act Article 27 fundamental rights impact assessment.
ISO/IEC 23894:2023: The AI Risk Management Guidance Nobody Cites
ISO/IEC 23894:2023 is the oldest SC 42 AI document and the most consistently skipped. It is guidance rather than requirements, an AI-specific application of ISO 31000 rather than a new framework, and it is not certifiable. Verified identity from the IEC catalogue, the ISO 31000 inheritance, the NIST crosswalk that was quietly revised in August 2025, and where 23894 sits between 42001, 42005 and 42006.
Italy’s D.Lgs. 160/2026: Police AI, Biometrics and AI Liability
Decreto legislativo 9 settembre 2026, n. 160 was published in Gazzetta Ufficiale n. 214 on 15 September 2026 and takes effect on 30 September 2026, ten days before the Law 132/2025 delegation expires. It closes the gap our Law 132/2025 page openly left open. Three Titles and 22 articles: a police-AI regime with two parallel biometric authorisation tracks capped at fifteen renewable days, a new article 437-bis of the criminal code punishing the omission of security and human-oversight measures in high-risk AI systems as an offence of danger, entity liability under a new article 25-vicies of D.Lgs. 231/2001, and civil remedies that enact nationally the disclosure duty and rebuttable causation presumption the withdrawn EU AI Liability Directive would have harmonised.
The Council of Europe HUDERIA Methodology and Model: What It Asks For, and What It Explicitly Is Not
HUDERIA’s four elements, COBRA’s four steps and three contexts, the avoid-mitigate-restore-compensate hierarchy, and the Council of Europe’s own statement that it is not a means for implementing CETS 225.
Montana SB 212, the Right to Compute Act: the deregulatory model and the one safety obligation inside it
Montana became the first state to enact a right to compute when Governor Gianforte signed SB 212 on 16 April 2025. It subjects government restrictions on computational resources to strict scrutiny, grounding the right in the state constitution’s property and free-expression clauses — a deliberate inversion of the Colorado and Texas direction of travel. The interesting part is the carve-out: the most deregulatory AI statute in the country still points critical-infrastructure deployers at the NIST AI Risk Management Framework and the ISO/IEC AI management standard. What MCA 2-10-205 actually requires, the two undefined terms carrying it, the ISO number the statute gets wrong, and the shutdown mandate that did not survive amendment.
Illinois HB 3773: An AI Notice Duty With No Rules Behind It
Public Act 103-0804 made discriminatory AI use and undisclosed AI use separate civil rights violations under the Illinois Human Rights Act on 1 January 2026. IDHR proposed the rules defining compliant notice on 15 May 2026 and withdrew them on 2 June 2026, with no refiling timeline. What the statute actually bans, what the withdrawn Subpart J draft would have required, and how to build a defensible interim notice program.
The Four-Fifths of the HUDERIA Model That Has Not Been Adopted Yet: CDNET’s Deliverable Schedule Through 2027
Secondary coverage of HUDERIA stops at “the Model was approved.” It was — but what was approved is a methodology plus one resource set covering the first of its four elements, and even that set is short a resource: the published book’s lettering runs A, B, C, E, F, with a footnote recording that a COBRA Resource D was considered and left out. The Methodology’s own footnotes cite stakeholder-engagement resources and a roles-and-responsibilities section that do not exist. This page is the register: every HUDERIA piece, its real status on 25 September 2026, and the CDNET deliverable deadlines that run to 31 December 2027.
Vietnam’s Law on Artificial Intelligence No. 134/2025/QH15
On 10 December 2025 Vietnam’s National Assembly passed Law No. 134/2025/QH15 on Artificial Intelligence, 429 votes to 5. It took effect on 1 March 2026 and is the first comprehensive standalone AI statute in Southeast Asia: eight chapters, 35 articles, a three-tier risk regime, a chapter on national AI sovereignty that no comparable statute contains, and a sandbox that can reduce the law’s own obligations. Most of the operational detail is still with the implementing decrees.
Kazakhstan’s AI Law No. 230-VIII: What It Actually Requires
On 17 November 2025, President Kassym-Jomart Tokayev signed Law of the Republic of Kazakhstan No. 230-VIII On Artificial Intelligence. It entered into force on 18 January 2026, runs to seven chapters and 28 articles, and is the first dedicated, standalone AI statute adopted by a Central Asian state. Uzbekistan followed within days, but took a […]
Machine Unlearning and Algorithmic Disgorgement: Ordering a Model Deleted Is Not the Same as Deleting It
Since 2019 the US Federal Trade Commission has, at least six times, ordered an organisation not merely to delete data but to destroy the models built from it. The remedy is called algorithmic disgorgement, and it is written as if deletion were a settled engineering operation. It is not. The research literature on machine unlearning shows that a model can pass a deletion audit in full precision and give the forgotten material back after routine quantization. This page separates the legal remedy from the technical method, sets out what the orders actually say, and explains why a research institution’s own withdrawal and close-out rules point in a different direction again.
The Controls Regulators Said Were Missing: FTC v. Rite Aid and EEOC v. iTutorGroup
Measured in money, neither case is large — $365,000 from iTutorGroup, and no civil penalty at all from Rite Aid on the facial-recognition counts. Measured in specificity, they are the two most useful documents in US AI enforcement: a regulator looked at a system that had already hurt people and named the missing controls one at a time, with deadlines attached. Provision III of the Rite Aid order, the date-of-birth prohibition in the iTutorGroup decree, and what each case says about who actually discovers these failures.
C2PA Content Credentials: How Provenance Actually Works
Content Credentials are often described as a nutrition label for digital media. The metaphor oversells them. C2PA is a signed-assertion format with a cryptographic binding to specific bytes: it can tell you that a particular signer said a particular thing about a particular file and that the file has not changed since. It cannot tell you that what the signer said is true, and the chain breaks on the ordinary act of uploading a picture to a website. This guide walks the actual data model, the trust machinery that decides whose signature counts, the documented failure modes, and where the EU AI Act’s Article 50 marking duty does and does not meet the standard.
G7 Hiroshima AI Process: the Code of Conduct and the HAIP Reporting Framework
The G7 Hiroshima AI Process produced two things that get confused: a voluntary International Code of Conduct with eleven actions, issued by G7 Leaders on 30 October 2023, and the OECD-hosted HAIP Reporting Framework, a seven-section questionnaire organisations file in public. Version 2.0 launched 28 May 2026 with role-based routing and closed questions; reports filed by 30 September 2026 feed the next analytical review. Nothing is verified, and a draft scoring system was rejected by participants.
Model Cards, System Cards, and the EU Model Documentation Form
Model cards, system cards and the EU Model Documentation Form are three different instruments with three different levels of legal force. What each actually requires, which one is mandatory, and where research institutions pick up obligations of their own.
Italy’s Law 132/2025: A National AI Statute Inside the EU AI Act
Regulation (EU) 2024/1689 is directly applicable in every member state, so what is left for a national AI law to do? Italy’s Law 23 September 2025 n. 132 is an unusually clean answer: it does not re-regulate what the AI Act covers. It fills the spaces the Regulation leaves open — sectoral rules, designated authorities, copyright, criminal law — and delegates most of the hard detail to implementing decrees that are still not all in force.
HTI-1’s 31 Source Attributes: What a Certified EHR Must Disclose About a Predictive Model
The most itemised model-disclosure rule in force in the US is not an AI law but a health-IT certification criterion: 45 CFR 170.315(b)(11) requires a certified Health IT Module to surface 31 source attributes for every Predictive Decision Support Intervention its developer supplies — while permitting a blank on external validation, external-data performance, local monitoring and the update schedule.
OMB M-26-04 and EO 14319: The Unbiased AI Principles Clause Federal LLM Contracts Must Carry
OMB Memorandum M-26-04, issued 11 December 2025, implements Executive Order 14319 by requiring every federal solicitation or order for a large language model to include contractual requirements addressing compliance with the two Unbiased AI Principles. This guide covers the documentation floor, the scope carve-outs for national security systems and openly licensed models, the 11 March 2026 policy deadline and end-user reporting channel, the two-year sunset, and the unresolved problem that “ideological neutrality” is made material to payment without any published test.
The UN’s AI Governance Track: The Global Dialogue and the Scientific Panel
UNGA resolution A/RES/79/325 (26 August 2025) created two distinct things that are constantly conflated: the Global Dialogue on AI Governance, a 193-member-state political venue, and the Independent International Scientific Panel on AI, a 40-expert scientific body. The real calendar, the four thematic clusters, what a Co-Chairs’ Summary is and is not, and the honest limit of what this track can do for frontier safety.
Brazil’s PL 2338/2023: Approved by the Senate, Stalled in the Chamber
Brazil is routinely listed as a jurisdiction with an AI law. It does not have one. The Senate approved PL 2338/2023 on 10 December 2024 and sent it to the Chamber of Deputies, where the Chamber’s own open-data record has shown the same situação — “Aguardando Parecer” — ever since, with the most recent entry dated 2 September 2026. Here is what the record actually says, and what it does not.
IEEE 7001 and IEEE CertifAIEd: The AI Standards Frontier Governance Skipped
IEEE 7001-2021 defines measurable, testable transparency levels graded 0-5 across five stakeholder groups, and IEEE CertifAIEd is a separate conformity mark assessing transparency, accountability, algorithmic bias and privacy. Neither is cited by any frontier lab framework or frontier statute in this cluster, and the reason is structural: a mark attests to a product at a point in time, while frontier safety needs capability-conditional evaluation that re-runs per model.
AI Claim Denials: The State Laws That Require a Licensed Human to Make the Medical-Necessity Call
California SB 1120 and Texas SB 815 are the clearest examples in US law of a mandated human decision-maker for one named AI use case. Neither sets a capability threshold, asks for a safety case, or requires an evaluation – they remove the medical-necessity determination from the system’s authority and name the licensed human who must hold it. The mechanism is state insurance regulation (DMHC and CDI in California, TDI in Texas), and there is no parallel federal requirement.
The OECD AI Principles: What 47 Adherents Actually Signed
The OECD Recommendation on AI (OECD/LEGAL/0449) is non-binding, has 47 adherents, and its entire safety content is one principle with no capability threshold.
The Education Department’s AI Grant Priority: Funding AI Adoption Without Attaching Safeguards
ED’s final AI priority (91 FR 18774, effective 13 May 2026) can be attached to any discretionary grant competition. It adds funding pressure for AI adoption and no federal safety, privacy or parental-consent requirements.
Executive Order 14409: Frontier Models as Cyber Defense Infrastructure
Executive Order 14409, signed 2 June 2026, is the third Trump AI order and the first to treat frontier models as defensive cyber infrastructure rather than a regulatory target. Its 30- and 60-day taskings, its classified benchmark for covered frontier models, and why a secret evaluation regime does not interoperate with the transparency mechanisms this cluster documents.
The EU AI Act’s Open-Source Exemption: What Article 53 Actually Carves Out
Article 53(2) of the EU AI Act waives two of four baseline GPAI provider obligations for genuinely open-source models with public weights, architecture, and usage information — but the waiver switches off entirely the moment a model is classified as posing systemic risk under Article 51, regardless of licence or release format.
How Federal Financial Regulators Are Actually Treating Frontier AI
The Fed, OCC and FDIC narrowed SR 11-7 to exclude generative and agentic AI; FSOC stood up a standing AI Working Group. What’s confirmed from primary sources, and what still isn’t.
The UK’s AI Code of Practice Regulations 2026: What SI 2026/425 Requires
In April and May 2026, a UK statutory instrument quietly did something the 2023 AI White Paper only promised: it gave the Information Commissioner a binding legal direction to write a statutory code of practice on AI and automated decision-making, with a built-in carve-out excluding national security from the panel that reviews it. This is regulatory background, not breaking news — here is what SI 2026/425 actually requires, and what it doesn’t.
AI and Elections: The State Disclosure-Law Landscape
A sourced snapshot of state legislative activity on AI-generated election content: the 16 states that already require disclosure of AI-generated political ads, the five 2025-session bills still pending in Alaska, Arkansas, California, Connecticut and Georgia, and why Congress has enacted none of its 150+ AI bills.
The Council of Europe AI Treaty (CETS 225): What’s Confirmed So Far
The UK signed CETS 225, the Council of Europe’s AI treaty, on 5 September 2024. Its formal name, signatories, and what remains unconfirmed about its legal-force status.
IRBs Are on Their Own: OHRP’s Unactioned AI Recommendations
OHRP’s own statutory advisory committee, SACHRP, began studying AI’s impact on IRB risk-benefit review in 2021 and had formally approved recommendations by fall 2022. Four years later, as of September 2026, no OHRP guidance document has visibly followed. This guide traces the five-notice Federal Register paper trail and what it means for IRBs reviewing AI-touching protocols in the meantime.
China’s AI Regulation: Interim Measures to the 2025 Labeling Rules
China regulates generative AI through two central-government measures rather than one statute: the 2023 Interim Measures for Generative AI Services (CAC plus six agencies) and the 2025 Measures for Labeling of AI-Generated Synthetic Content (CAC, MIIT, MPS, NRTA). Verified directly against CAC’s own published notices — plus why a national AI Law still isn’t on China’s legislative plan.
Frontier AI Safety Timeline: 2023-2026
Frontier AI safety moved from a voluntary international declaration to five overlapping binding statutes in under three years. This page lists every major milestone from the 2023 Bletchley Declaration to the 2026 Colorado AI Act, in date order, each with a link to CASRAI’s own deep-dive guide.
The One Redaction Reason No Lab Will Admit To
Anthropic, SB 53, Meta, OpenAI, the EU’s GPAI Code, and METR each name reasons a frontier AI developer can redact for. Together they cover six categories — but none of them, in its own words, rules out the one reason everyone would call illegitimate. Built from NIKOLAI’s Redaction reason element (N8.6), distinct from the Redaction element covered in CASRAI’s companion disclosure guide.
AI in the Power Grid: What CISA’s New OT Guidance Actually Says
CISA’s December 2025 OT-integration guidance and May 2026 agentic-AI guidance, co-authored with up to nine allied cyber agencies, explained through what OT makes physically different from IT.
Why No State Requires AI Liability Insurance (Yet)
No US state mandates AI liability insurance for developers or deployers. What’s real: Lloyd’s underwriters mapping exposure, states regulating insurers’ own AI use, and where academic research says AI risk is and isn’t insurable.
Singapore’s Model AI Governance Framework for Agentic AI
Singapore’s IMDA and AI Verify Foundation published a voluntary Model AI Governance Framework for Agentic AI (v1.5, May–June 2026) built around four principles. It isn’t yet in any NIKOLAI crosswalk.
India’s AI Governance Guidelines Explained
MeitY says it is “not regulating AI.” Its November 2025 Guidelines are voluntary: seven sutras adapted from the RBI’s FREE-AI report, six pillars across three domains, and three institutions — AIGG, TPEC, and the already-running AI Safety Institute — with India’s Digital India Act still stalled.
Singapore’s Model AI Governance Framework for Generative AI
IMDA and the AI Verify Foundation published the Model AI Governance Framework for Generative AI on 19 June 2024 — a voluntary, nine-dimension framework that folds Singapore’s original 2019/2020 Model AI Governance Framework into its Trusted Development and Deployment dimension. No penalty regime, no NIKOLAI crosswalk row yet.
Korea’s AI Basic Act: What Took Effect in January 2026
South Korea’s AI Basic Act took effect in January 2026 — requiring risk assessments and a Korea-based local representative for high-impact and generative AI. It’s the most concretely binding AI-specific law outside the US, EU, and China, and it isn’t yet in any NIKOLAI crosswalk.
What Gets Redacted From AI Safety Reports, and Who Has to Say So
Anthropic, Meta, California SB 53, and METR all require frontier AI developers to disclose when they redact a safety report, and why. The EU’s GPAI Code and the UK’s approach don’t carry the same public-facing duty. A comparison built from NIKOLAI’s redaction crosswalk.
What AIDA Would Have Required — and Why It Died
Canada’s Artificial Intelligence and Data Act (AIDA) would have regulated ‘high-impact’ AI systems with lifecycle-based obligations, an AI and Data Commissioner, and three separate penalty tracks. It never took effect: Bill C-27 stalled in House of Commons committee through 2024 and died when Parliament prorogued on January 6, 2025.
Japan’s AI Law Has No Penalties — and a Live Test Case
Japan’s AI Promotion Act contains no explicit penalties for noncompliance — only “administrative guidance” and a duty to cooperate. In January 2026, that no-teeth model got its first real test when Japan’s Cabinet Office summoned X Corp over Grok-generated sexual deepfakes.
The UK’s AI White Paper: A Regulatory Framework Without a Regulator
The UK’s AI White Paper sets five cross-sector principles for AI regulation but deliberately creates no central AI regulator, relying instead on existing regulators like the ICO, MHRA, FCA, EHRC and NCSC to apply them within their own remits.
Compute Governance: Export Controls, FLOP Thresholds, and Chip-Level Oversight
Compute governance defined: chip export controls, FLOP-reporting thresholds (EU AI Act 10^25, SB 53 10^26), and chip-level know-your-customer rules as a distinct, hardware-level AI-safety lever.
The Algorithmic Accountability Act: What the Federal Bill Would Require
The Algorithmic Accountability Act is a federal bill, not a law — repeatedly introduced since 2019 and still pending. What it would require, its current status in the 119th Congress, and how it differs from the state AI laws already in effect.
Comparing AI Safety Terms Across Frameworks: A NIKOLAI Crosswalk Guide
How CASRAI’s NIKOLAI crosswalk tables show where threshold, evaluation, safeguard, and accountable-decision-maker language actually differs across RSP, Preparedness Framework, FSF, the EU AI Act’s GPAI Code, and NIST AI RMF.
Trump’s AI Executive Orders Explained: EO 14179 and EO 14365
What EO 14179 (revoked Biden’s AI order) and EO 14365 (targets state AI laws) actually require, who they apply to, and how they relate to state AI laws and the EU AI Act.
AI Regulations Around the World: A Jurisdiction Map
A jurisdiction-by-jurisdiction map of AI regulation: the EU AI Act, US federal and state law (California, New York, Colorado, Texas, Utah), China, and the international summit/coordination track — each linking to CASRAI’s deep-dive guide.
The Utah AI Policy Act: What It Requires
Utah’s Artificial Intelligence Policy Act is a narrower, disclosure-focused law than it’s sometimes taken to be. What it actually requires, and how it differs from Colorado’s broader AI Act.
The Texas Responsible AI Governance Act (TRAIGA): What It Requires
Texas’s TRAIGA (HB 149) takes effect January 1, 2026. Unlike Colorado’s law, it bans specific AI uses by intent rather than regulating high-stakes decisions or model scale.
The Blueprint for an AI Bill of Rights: What It Says
The White House’s 2022 Blueprint for an AI Bill of Rights set out five non-binding principles for automated systems. Here is what it actually says, what “non-binding” means, and its status today relative to binding laws like California’s SB 53.
The Colorado AI Act: What It Requires
Colorado’s original AI Act (SB 24-205) was repealed and reenacted as SB 26-189 before it ever took effect. What the current law requires, who counts as a developer or deployer of automated decision-making technology, and the real January 1, 2027 enforcement date.
The EU AI Office: What It Is and What It Does
What the EU AI Office actually is, where it sits inside the European Commission, its exclusive enforcement powers over general-purpose AI providers, and how it relates to national market surveillance authorities.
GPAI Systemic Risk: The EU AI Act Term Explained
What systemic risk means under the EU AI Act, the Article 51 classification test and 10^25 FLOPs presumption, and the Article 55 obligations it triggers once a model is classified.
NIST’s AI Agent Standards Initiative: What It Covers and Its Current Status
NIST’s Center for AI Standards and Innovation launched the AI Agent Standards Initiative in February 2026 to cover AI agent security, identity, and authorization — separate from the AI RMF. Here is what it actually covers and its current status.
The EU AI Act GPAI Code of Practice: What It Is and Who Signed It
What the EU AI Act’s GPAI Code of Practice actually requires — its three chapters, its presumption-of-conformity mechanism under Article 53(4), and which major AI labs have signed it.
Seoul Frontier AI Safety Commitments: The Signatory List and What They Pledged
The 20 companies that have signed the Seoul Frontier AI Safety Commitments, the full list including the February 2025 additions, and how the pledge relates to SB 53’s binding Frontier AI Framework requirement.
ISO/IEC 42001 Certification: Path, Timeline, and Annex A Controls
A practical guide to ISO/IEC 42001 certification: what it actually certifies (a management system, not a model), the real path from gap assessment through Stage 1 and Stage 2 audits, a realistic timeline, and what the nine Annex A control areas cover.
California SB 53 (Transparency in Frontier Artificial Intelligence Act): The Foundational Explainer
A plain-language breakdown of what California SB 53 actually requires: who counts as a frontier developer, the frontier AI framework and transparency report obligations, the 15-day critical safety incident reporting duty, whistleblower protections, and civil penalties.








