AI regulation is fragmented. The frameworks that decide compliance are not.
The 6 Pillars every AI-deploying organization needs to master, plus 14 supporting References covering standards, regulations and voluntary frameworks worldwide.
A single AI system deployed in the European market can trigger obligations under the EU AI Act, GDPR, ISO/IEC 42001, sectoral regulations (financial, medical, employment), and voluntary commitments like the EU AI Pact. In the US, add NIST AI RMF, state-level AI acts, and industry-specific FTC guidance.
The natural response is to treat each framework as a separate compliance stream. That is expensive, and it is wrong: 70% of the substantive obligations converge across frameworks, and the differences are in how you evidence them, not in what you have to do.
We organize the landscape into 6 Pillars — the frameworks whose obligations you cannot delegate to another — and References — the supporting standards and voluntary frameworks that shape how Pillars are interpreted.
The frameworks that define AI compliance
Every AI-deploying organization operating in the EU, US or UK is subject to some combination of these six. They are not optional.
AIUC-1
AIUC-1 is the first AI certification standard whose addressee is not the organisation that adopts AI. It is the AI agent itself , considered as a deployable product…
EU AI Act
The dominant narrative presents the EU AI Act as "the world's first comprehensive AI law." It is a useful commercial description, but conceptually misleading. The framing obscures what…
ISO/IEC 23894
ISO/IEC 23894 is the standard that most discussions of AI governance skip over. It sits between the better-known instruments — the EU AI Act, the NIST AI RMF,…
ISO/IEC 42001
ISO/IEC 42001 is widely described as "the world's first AI management system standard." The description is correct but operationally thin. The substantive question is not whether it is…
ISO/IEC 42006
Resources / Regulatory Frameworks ISO/IEC 42006 The standard that defines who can credibly certify AI management systems Official nameISO/IEC 42006:2025 — Information technology — Artificial intelligence — Requirements…
NIST AI Risk Management Framework
The NIST AI Risk Management Framework is the most influential AI governance instrument in the world that is not, technically, a regulation. That contradiction is where its actual…
Supporting frameworks and standards
Standards, voluntary frameworks and sectoral guidance that shape how the 6 Pillars are interpreted, audited and enforced.
Brazil AI Regulation — PL 2338/2023
Resources / Regulatory Frameworks Brazil AI Regulation — PL 2338/2023 Latin America's first comprehensive AI legislative proposal, currently navigating its decisive legislative phase — and the regulatory anchor…
Canada AI Regulation
Resources / Regulatory Frameworks Canada AI Regulation The country that nearly passed a national AI law and then chose AI sovereignty over comprehensive regulation, and the institutional pivot…
China AI Regulation
Resources / Regulatory Frameworks China AI Regulation The most operationally mature AI regulatory regime in the world, built layer by layer around specific technologies, and the framework that…
Colorado AI Act
Resources / Regulatory Frameworks Colorado AI Act The first comprehensive state AI law in the United States, currently under judicial stay and political reconstruction — and the test…
Council of Europe Framework Convention on AI
Resources / Regulatory Frameworks Council of Europe Framework Convention on AI The first international legally binding treaty on AI, in force since November 2025, and the institutional answer…
EU DSA Algorithmic Transparency
Resources / Regulatory Frameworks EU DSA Algorithmic Transparency The Digital Services Act has built the only operational regime in the world for systemic algorithmic risk assessment, independent algorithmic…
G7 Hiroshima Process on AI
Resources / Regulatory Frameworks G7 Hiroshima Process on AI The first international framework targeted at frontier AI developers, and the operational layer that turns OECD principles into reportable…
GDPR AI Provisions
Resources / Regulatory Frameworks GDPR AI Provisions The General Data Protection Regulation has been quietly regulating AI for almost a decade — and remains the most operationally consequential…
Japan AI Regulation
Resources / Regulatory Frameworks Japan AI Regulation The country that built an explicitly innovation-first AI framework with no monetary penalties, backed by JPY 10 trillion in industrial commitment,…
NYC Local Law 144
Resources / Regulatory Frameworks NYC Local Law 144 The first municipal AI regulation with operational enforcement, the longest-running AI compliance regime in the United States, and — after…
OECD AI Principles
Resources / Regulatory Frameworks OECD AI Principles The first intergovernmental standard on AI, and the reason most national frameworks share the same vocabulary Official nameRecommendation of the Council…
Singapore AI Governance — Model Framework + AI Verify
Resources / Regulatory Frameworks Singapore AI Governance — Model Framework + AI Verify The world's most operationally mature soft-law AI governance regime, built around testing infrastructure rather than…
South Korea AI Basic Act
Resources / Regulatory Frameworks South Korea AI Basic Act The second comprehensive AI legislation in the world after the EU AI Act, and the architectural counterpoint to Japan's…
UK AI Regulation
Resources / Regulatory Frameworks UK AI Regulation A jurisdiction that built technical capacity before statute, and the deliberate sequence that explains why London leads on frontier AI evaluation…
US AI Executive Orders
Resources / Regulatory Frameworks US AI Executive Orders The federal AI regime is more active than ever, with priorities reoriented from safety-first to dominance-first — and the federal–state…
FREQUENTLY ASKED QUESTIONS
Frequently asked questions
Do I need to comply with all 6 Pillars?
Not necessarily — jurisdictional and sectoral scope filters which apply to your organization. An EU-only SaaS company selling to enterprises is typically subject to 4 of the 6. A US medical device manufacturer selling globally is typically subject to all 6 plus 3-4 References. We scope this precisely in the readiness audit.
What is the difference between a Pillar and a Reference?
Pillars carry direct legal obligations you cannot delegate: fines, market access, contract enforceability. References are voluntary or interpretive frameworks (ISO/IEC standards, NIST guidance, industry codes) that shape how the Pillars are audited and enforced. Ignoring a Pillar means non-compliance. Ignoring a Reference usually means an audit finding.
How often does this list change?
The 6 Pillars are stable — they represent the core AI regulatory architecture. References evolve continuously as new standards are published and existing ones revised. We review the list quarterly and mark added or superseded entries explicitly.
ANAB-accredited · UKAS in process · ENAC in process · AIUC-1 European authorized auditor · EU AI Pact signatory
Regulation you understand is regulation you can turn into competitive advantage.
Not sure which framework applies to your organization? Talk to us.
