AI Governance

Glossary

AI Regulation

Binding or proposed legal rules that constrain the development, placing on the market, or use of AI systems.

Last reviewed 2026-08-22

In plain language

AI regulation is a subset of AI governance. It includes statutes, regulations, directives, and other instruments with legal effect in a defined jurisdiction. Voluntary principles, ethics codes and internal company policies are not regulation, even when they influence practice. Regulatory design varies: some instruments are risk-based and sector-specific; others rely on existing product-safety, consumer-protection, competition or data-protection law. The EU AI Act illustrates one strategy: a single, dedicated, horizontal statute that classifies AI systems by risk tier and attaches specific obligations to each tier, regardless of sector. Other jurisdictions regulate AI primarily by applying and adapting existing law—data protection, consumer protection, sectoral safety rules, anti-discrimination statutes—to AI-specific facts, without passing one comprehensive AI statute. Neither approach is more “real” regulation than the other; both create binding legal duties, they just locate those duties differently. This is also where “regulation” needs to be kept separate from “standard”: a technical or management-system standard like ISO/IEC 42001 can be referenced inside a regulation—a law might require compliance with a named standard—but the standard itself, issued by a standards body rather than a legislature or regulator, is not regulation until a legal instrument makes it mandatory. Readers checking whether a given AI rule applies to them should identify which specific instrument, not which general policy trend, creates the obligation.

Why it matters for AI governance

Conflating regulation with ethics guidance can understate legal duties or overstate the force of non-binding texts. Distinguishing the two is essential for compliance, advocacy and comparative policy analysis.

Authoritative sources