AI Governance

Topic

AI Regulation

Binding legal rules for AI systems, kept separate from ethics guidelines and voluntary codes.

Last reviewed 2026-08-22

Overview

Regulation is a subset of governance. This cluster points to statutes, regulations, directives, conventions and administrative measures with legal or formal policy effect in a defined jurisdiction. Ethics guidelines remain in the frameworks section even when they influenced later law.

EU AI Act risk tiers

The EU AI Act's central regulatory mechanism is a four-tier risk classification, and most of what the Act requires of a given organization depends on which tier its system falls into. Unacceptable-risk practices are prohibited outright—the Act lists specific uses, such as certain forms of biometric categorization and manipulative techniques, that cannot be placed on the market regardless of safeguards. High-risk AI systems, a defined legal category covering uses like employment screening, credit scoring, and specified law-enforcement and migration applications, face the Act's most extensive obligations: risk-management systems, data-governance requirements, technical documentation, human oversight, and conformity assessment before deployment. Limited-risk systems—including many chatbots and systems that generate or manipulate content—carry specific transparency duties, chiefly that people be informed they are interacting with AI or with synthetic content, without the full high-risk compliance burden. Minimal-risk systems, the majority of AI applications, fall outside these specific obligations, though general product-safety and consumer-protection law can still apply. A separate track addresses general-purpose AI models directly, with additional duties for models found to carry systemic risk. Obligations apply on staged timelines set in the Act rather than all at once, so which duties currently apply to a given system depends on both its risk tier and the current date—the Official Journal text and implementing measures, not secondary summaries, are the authoritative source for either question.