REGULATORY FRAMEWORKS

AI regulation is fragmented. The frameworks that decide compliance are not.

The 6 Pillars every AI-deploying organization needs to master, plus 14 supporting References covering standards, regulations and voluntary frameworks worldwide.

A single AI system deployed in the European market can trigger obligations under the EU AI Act, GDPR, ISO/IEC 42001, sectoral regulations (financial, medical, employment), and voluntary commitments like the EU AI Pact. In the US, add NIST AI RMF, state-level AI acts, and industry-specific FTC guidance.

The natural response is to treat each framework as a separate compliance stream. That is expensive, and it is wrong: 70% of the substantive obligations converge across frameworks, and the differences are in how you evidence them, not in what you have to do.

We organize the landscape into 6 Pillars — the frameworks whose obligations you cannot delegate to another — and References — the supporting standards and voluntary frameworks that shape how Pillars are interpreted.

15 REFERENCES

Supporting frameworks and standards

Standards, voluntary frameworks and sectoral guidance that shape how the 6 Pillars are interpreted, audited and enforced.

R14

Brazil AI Regulation — PL 2338/2023

Resources / Regulatory Frameworks Brazil AI Regulation — PL 2338/2023 Latin America's first comprehensive AI legislative proposal, currently navigating its decisive legislative phase — and the regulatory anchor…

Read
R9

Canada AI Regulation

Resources / Regulatory Frameworks Canada AI Regulation The country that nearly passed a national AI law and then chose AI sovereignty over comprehensive regulation, and the institutional pivot…

Read
R10

China AI Regulation

Resources / Regulatory Frameworks China AI Regulation The most operationally mature AI regulatory regime in the world, built layer by layer around specific technologies, and the framework that…

Read
R7

Colorado AI Act

Resources / Regulatory Frameworks Colorado AI Act The first comprehensive state AI law in the United States, currently under judicial stay and political reconstruction — and the test…

Read
R3

Council of Europe Framework Convention on AI

Resources / Regulatory Frameworks Council of Europe Framework Convention on AI The first international legally binding treaty on AI, in force since November 2025, and the institutional answer…

Read
R16

EU DSA Algorithmic Transparency

Resources / Regulatory Frameworks EU DSA Algorithmic Transparency The Digital Services Act has built the only operational regime in the world for systemic algorithmic risk assessment, independent algorithmic…

Read
R4

G7 Hiroshima Process on AI

Resources / Regulatory Frameworks G7 Hiroshima Process on AI The first international framework targeted at frontier AI developers, and the operational layer that turns OECD principles into reportable…

Read
R15

GDPR AI Provisions

Resources / Regulatory Frameworks GDPR AI Provisions The General Data Protection Regulation has been quietly regulating AI for almost a decade — and remains the most operationally consequential…

Read
R11

Japan AI Regulation

Resources / Regulatory Frameworks Japan AI Regulation The country that built an explicitly innovation-first AI framework with no monetary penalties, backed by JPY 10 trillion in industrial commitment,…

Read
R8

NYC Local Law 144

Resources / Regulatory Frameworks NYC Local Law 144 The first municipal AI regulation with operational enforcement, the longest-running AI compliance regime in the United States, and — after…

Read
R1

OECD AI Principles

Resources / Regulatory Frameworks OECD AI Principles The first intergovernmental standard on AI, and the reason most national frameworks share the same vocabulary Official nameRecommendation of the Council…

Read
R13

Singapore AI Governance — Model Framework + AI Verify

Resources / Regulatory Frameworks Singapore AI Governance — Model Framework + AI Verify The world's most operationally mature soft-law AI governance regime, built around testing infrastructure rather than…

Read
R12

South Korea AI Basic Act

Resources / Regulatory Frameworks South Korea AI Basic Act The second comprehensive AI legislation in the world after the EU AI Act, and the architectural counterpoint to Japan's…

Read
R5

UK AI Regulation

Resources / Regulatory Frameworks UK AI Regulation A jurisdiction that built technical capacity before statute, and the deliberate sequence that explains why London leads on frontier AI evaluation…

Read
R6

US AI Executive Orders

Resources / Regulatory Frameworks US AI Executive Orders The federal AI regime is more active than ever, with priorities reoriented from safety-first to dominance-first — and the federal–state…

Read

FREQUENTLY ASKED QUESTIONS

Frequently asked questions

Do I need to comply with all 6 Pillars?

Not necessarily — jurisdictional and sectoral scope filters which apply to your organization. An EU-only SaaS company selling to enterprises is typically subject to 4 of the 6. A US medical device manufacturer selling globally is typically subject to all 6 plus 3-4 References. We scope this precisely in the readiness audit.

What is the difference between a Pillar and a Reference?

Pillars carry direct legal obligations you cannot delegate: fines, market access, contract enforceability. References are voluntary or interpretive frameworks (ISO/IEC standards, NIST guidance, industry codes) that shape how the Pillars are audited and enforced. Ignoring a Pillar means non-compliance. Ignoring a Reference usually means an audit finding.

How often does this list change?

The 6 Pillars are stable — they represent the core AI regulatory architecture. References evolve continuously as new standards are published and existing ones revised. We review the list quarterly and mark added or superseded entries explicitly.

ANAB-accredited · UKAS in process · ENAC in process · AIUC-1 European authorized auditor · EU AI Pact signatory

Regulation you understand is regulation you can turn into competitive advantage.

Not sure which framework applies to your organization? Talk to us.