Laws & regulations
AI laws and regulations
Legal and formal policy instruments. Each page states whether the text is a regulation, convention, administrative measure or internal directive. Informational only—not legal advice.
6 entries
- EU Artificial Intelligence ActRegulation (binding Union law) · 2024 — Regulation (EU) 2024/1689 lays down harmonized rules on artificial intelligence in the Union. It uses a risk-based structure, including prohibited practices, duties for high-risk AI systems, transparency duties for certain systems, and rules for general-purpose AI models. It is a regulation, directly applicable in Member States, not a voluntary ethics code. This page is informational and is not legal advice; always read the official Official Journal text and implementing measures.
- EU General Data Protection Regulation (GDPR)Regulation (binding Union law) · 2016 — Regulation (EU) 2016/679 is the Union’s general data-protection law. It is not an AI statute, but it governs personal-data processing that many AI systems require, including rules on lawfulness, purpose limitation, data-protection impact assessments, and automated individual decision-making in Article 22. AI compliance analyses that ignore the GDPR are incomplete in the EU context. It remains distinct from the AI Act.
- EU Digital Services ActRegulation (binding Union law) · 2022 — Regulation (EU) 2022/2065 (Digital Services Act) sets rules for intermediary services, including due-diligence obligations for very large online platforms and search engines. It is not an AI Act, but it is central to AI-related issues such as recommender systems, political content risk, and systemic-risk assessments on large platforms. Keep DSA, GDPR and the AI Act analytically separate even when they apply to the same organization.
- Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of LawInternational convention (treaty) · 2024 — This Framework Convention is a legally binding international treaty intended to ensure that activities within the lifecycle of AI systems are consistent with human rights, democracy and the rule of law. Unlike UNESCO’s ethics recommendation, a convention creates treaty obligations for states that consent to be bound, according to its provisions. It is not EU legislation. Consult the official Council of Europe treaty office texts for signature, ratification and entry-into-force status, which change over time.
- Interim Measures for the Management of Generative Artificial Intelligence Services (China)Administrative regulatory measures · 2023 — China’s Interim Measures for the Management of Generative Artificial Intelligence Services (effective 2023) are among the first major domestic rules aimed specifically at public generative-AI services. They address areas such as training-data requirements, labeling, and security assessments as set out in the official text. They are Chinese administrative measures, not an EU-style horizontal AI Act, and unofficial translations should be checked against official Chinese-language sources.
- Directive on Automated Decision-Making (Canada)Federal administrative directive (policy) · 2019 — Canada’s Directive on Automated Decision-Making is a Treasury Board policy instrument for federal institutions. It requires algorithmic impact assessments and other safeguards when automated decision systems are used in administering services. It is not an Act of Parliament covering the private sector. It is a leading public-administration example of algorithmic accountability inside government.
Have an official resource, framework, law or other source to propose for a section of this directory? Use the suggestion form (opens in a new tab). Inclusion is editorial and not guaranteed.