Who requires a record
The laws and standards that ask how the work was made.
One page per law: what it requires of you, and what the record does about it.
- AICPA · SOC 2
- Argentina · Ley 25.326
- Australia · Privacy Act 1988
- Aviation · EASA / FAA
- Brazil · LGPD (Lei 13.709/2018)
- C2PA · Content Credentials
- CCPA/CPRA · consumer rights
- CMMC Level 2 (32 CFR 170)
- Caribbean Court of Justice · Practice Direction No. 1 of 2025, generative AI in court proceedings
- California · AB 2013
- California · AI Transparency Act
- California · Delete Act (SB 362 / DROP)
- Canada · PIPEDA
- China · Anthropomorphic AI Interactive Services (Order No. 21)
- China · Cybersecurity Law (CSL)
- China · Data Security Law (DSL)
- China · Generative AI Interim Measures
- China · PIPL
- China · Small Personal Information Processors (Order No. 25)
- China · Supreme People’s Court Opinions on AI disputes (Fa Fa [2026] No. 10), verify before filing
- Colorado · Privacy Act (CPA)
- Colorado · HB 26-1263, conversational AI services
- Colorado · SB 26-189
- Connecticut · CTDPA
- Connecticut · PA 26-64 (SB 4), consumer privacy & protection
- Connecticut · PA 26-15 (SB 5), online safety & AI
- Court · SDNY privilege / AI care-denial
- Delaware · DPDPA
- EN 18286:2026 · AI Act QMS standard (reference; no OJ citation yet)
- EU AI Act · Article 12
- EU AI Act · Article 50
- EU AI Act · Article 72
- EU AI Act · Article 73
- EU AI Act · Arts 53 & 55 (GPAI)
- EU AI Act · Arts 9/13/14/15
- EU GMP · Annex 11
- EU GMP · Annex 22 (draft)
- FDA · AI credibility assessment (draft)
- ISPE · GAMP Guide: Artificial Intelligence
- FDA · 21 CFR 211.22
- EU GMP · Annex 16
- EMA · Reflection paper on AI
- MHRA · GxP data integrity
- PIC/S · PI 041-1
- FDA · Data integrity and CGMP Q&A
- EU · CSRD / ESRS
- EU · Cyber Resilience Act (Reg 2024/2847)
- EU · DORA (Reg 2022/2554)
- EU · Data Act (Reg 2023/2854)
- EU · Data Governance Act (DGA)
- EU · Deforestation Regulation (Reg 2023/1115)
- EU · Digital Markets Act (DMA)
- EU · Digital Services Act (DSA)
- EU · Health Data Space (Reg 2025/327)
- EU · MDR / IVDR
- EU · Machinery Regulation (Reg 2023/1230)
- EU · NIS2 (Dir 2022/2555)
- EU · Product Liability Directive (Dir 2024/2853)
- EU · eIDAS 2.0 (Reg 2024/1183)
- EU · ePrivacy Directive (2002/58/EC)
- FDA · 21 CFR Part 11
- FDA · GMLP
- FDA · PCCP (AI device change control)
- FDA · QMSR (21 CFR 820)
- FDA-EMA · Good AI Practice (Jan 2026)
- FedRAMP (NIST SP 800-53 Rev 5)
- Federal Rules of Evidence · 901–902
- Florida · Digital Bill of Rights
- GDPR · Article 22
- GDPR · Articles 5 & 33
- GLBA · Safeguards Rule (16 CFR 314)
- HIPAA · Security Rule
- ISO/IEC 23894:2023
- ISO/IEC 27001:2022
- ISO/IEC 27701:2025
- ISO/IEC 42001:2023
- China · AI content labelling measures
- South Korea · AI Framework Act
- Council of Europe · Framework Convention on AI
- California · SB 53, Frontier AI Transparency
- New York · RAISE Act
- Italy · Law 132/2025 on AI
- Japan · AI Promotion Act
- Brazil · CNJ Resolution 615/2025
- US · Proposed FRE 707 (not adopted)
- US · Tenth Circuit, proposed revision to Rule 46.5 (not adopted)
- Illinois · SB 315, AI Safety Measures Act
- Illinois · BIPA
- India · DPDP Act, 2023
- Indiana · Consumer Data Protection Act
- Indonesia · PDP Law (UU 27/2022)
- Iowa · Consumer Data Protection Act
- Ireland · High Court Practice Direction HC142, generative AI in court documents
- Israel · Privacy Law (Amendment 13)
- Jamaica · Supreme Court Practice Direction No. 1 of 2025, generative AI in court proceedings
- Japan · APPI
- Kentucky · Consumer Data Protection Act
- Kenya · Data Protection Act 2019
- Malaysia · PDPA (Act 709, am. 2024)
- Maryland · MODPA
- Minnesota · Consumer Data Privacy Act
- Montana · Consumer Data Privacy Act
- NAIC · AI Model Bulletin
- NERC · CIP
- NIST · AI RMF 1.0
- NIST · Cybersecurity Framework 2.0
- NYC · Local Law 144
- NYDFS · 23 NYCRR Part 500
- Nebraska · Data Privacy Act
- New Hampshire · Data Privacy Act
- New Jersey · Data Privacy Act
- New Zealand · Privacy Act 2020
- New Zealand · Biometric Processing Privacy Code 2025
- Nigeria · NDPA 2023
- Oregon · OCPA
- PCI DSS v4.0.1 · Requirement 10
- Philippines · Data Privacy Act (RA 10173)
- Quebec · Law 25 (P-39.1)
- Rhode Island · Data Transparency & Privacy Protection Act
- SEC · Cyber disclosure (8-K 1.05 / Reg S-K 106)
- SR 26-2 / OCC Bulletin 2026-13, model risk management (supersedes SR 11-7)
- Saudi Arabia · PDPL
- Singapore · PDPA
- South Africa · POPIA
- South Korea · PIPA
- Switzerland · FADP (nFADP)
- Tennessee · TIPA
- Texas · TDPSA
- Texas · TRAIGA (HB 149)
- Thailand · PDPA
- Turkey · KVKK (Law 6698)
- UAE · PDPL (Decree-Law 45/2021)
- UK · GDPR / DPA 2018
- UK · SRA warning notice on the misuse of AI
- US federal · DoD Responsible AI
- US · CIRCIA (6 U.S.C. §681b)
- US · COPPA Rule
- US · FERPA
- US · Fair Credit Reporting Act (FCRA)
- US · Sarbanes-Oxley (ICFR)
- US · UFLPA (Pub. L. 117-78)
- Utah · Consumer Privacy Act (UCPA)
- Utah · Title 13 Ch. 77
- Vietnam · Law on AI, 134/2025/QH15
- Vietnam · PDP Law 91/2025/QH15
- Virginia · VCDPA
- Washington · My Health My Data Act
Seven days free, then $349 a month.
Outside the United States
These are the record-keeping and transparency duties that apply to a business. Separately, courts and bar bodies across twenty-four jurisdictions now have their own rules about a lawyer using AI in a filing, from a flat ban on AI in affidavits in New South Wales to the first judicial warning anywhere about hidden white-text prompts in England and Wales.
AI rules for lawyers, country by country →