Skip to content
Regulayer™Human Control for AI
Book a live demo

Research library · Law and regulation

Where proof is demanded: a catalogue

A catalogue of laws, regulations, standards and court rules in sixteen domains that require a party to produce evidence that an event happened as claimed. For each it gives who must comply, what must be proven, status, penalties and sources, as of 10 June 2026, with later changes noted where they alter an entry.

Compiled from public sources, 10 June 2026. Information, not legal advice.

Framing

The demand for verifiable proof spans virtually every domain of human activity where decisions are made, value is exchanged, risk is allocated, or rights are asserted. It is not limited to regulatory compliance, though regulation is a powerful accelerant. The "must-prove-it" space encompasses at least sixteen distinct domains, ranging from AI governance and cybersecurity to carbon credit integrity and scientific reproducibility, and within each domain there are multiple overlapping frameworks, standards, and legal obligations that create specific, named requirements for evidence. What unifies them is a single structural pattern: a party (a regulator, a court, a counterparty, an auditor, a customer) demands documentary or technical evidence that something happened as claimed, and the party under pressure must produce that evidence or suffer consequences: fines, lost contracts, litigation exposure, reputational damage, or exclusion from markets. Since 2022 the EU has introduced or tightened several proof-demanding frameworks, including the AI Act, DORA, NIS2, the Cyber Resilience Act, the Deforestation Regulation, CSRD, and the revised Product Liability Directive. The United States has seen comparable proliferation at both federal and state levels, with California, Colorado, New York, and Texas each creating distinct AI- and privacy-related evidence obligations.

Numbers in square brackets are citation markers. Where the report gave a link for a marker, it appears in that entry's Source line.


Domain 1: AI & Automated Decision-Making

1. EU AI Act: Article 50 Transparency Obligations

  • Jurisdiction: European Union
  • Who must comply: Providers and deployers of AI systems that generate or manipulate synthetic content (audio, image, video, text), operate chatbots, or use emotion recognition/biometric categorisation.
  • What must be proven: That AI-generated outputs are marked in a machine-readable format and detectable as artificially generated; that deepfake disclosures are made to end-users; that human-AI interaction is disclosed.
  • Status: Applies from 2 August 2026 (the Act entered into force on 1 August 2024). Regulation (EU) 2026/1744 (the Digital Omnibus on AI) gives systems placed on the market before 2 August 2026 until 2 December 2026 to meet the Art 50(2) marking duty. The Code of Practice on marking and labelling AI-generated content was published in draft in December 2025 and in final form on 10 June 2026. [114][115]
  • Penalty: Up to EUR 15 million or 3% of global annual turnover (Art 99(4)).
  • Source: Regulation (EU) 2024/1689; AI Act Art 99; European Commission Code of Practice on AI-generated content; Hunton on the Digital Omnibus on AI; European Commission draft guidelines [114]; Resemble AI compliance guide [115]

2. EU AI Act: High-Risk AI Systems (Annex III)

  • Jurisdiction: European Union
  • Who must comply: Providers and deployers of high-risk AI systems in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice.
  • What must be proven: Risk management system operation; data governance; technical documentation; record-keeping; human oversight; accuracy, robustness, cybersecurity; conformity assessment; post-market monitoring; incident reporting.
  • Status: Under the Act as adopted, these obligations were to apply from 2 August 2026. Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force 27 July 2026) moved the date for Annex III systems to 2 December 2027, and for high-risk systems covered by Annex I to 2 August 2028.
  • Penalty: Up to EUR 35 million or 7% of global turnover for prohibited practices; up to EUR 15 million or 3% for other violations (Art 99).
  • Source: Regulation (EU) 2024/1689; European Commission AI regulatory framework; AI Act Art 99; Hunton on the Digital Omnibus on AI; Lewis Silkin on the Digital Omnibus on AI

3. Colorado AI Act, as Repealed and Re-enacted by SB 26-189: Automated Decision-Making Technology

  • Jurisdiction: Colorado, USA
  • Who must comply: Developers and deployers of covered automated decision-making technology (ADMT) used to make consequential decisions in employment, housing, credit, insurance, health care, education and essential government services.
  • What must be proven: Clear and conspicuous notice before a consumer uses or interacts with covered ADMT; within 30 days of an adverse outcome, a plain-language explanation of the decision and the role the ADMT played; correction of inaccurate personal data used in the decision; meaningful human review and reconsideration to the extent commercially reasonable; developer documentation for deployers, with records kept for three years.
  • Status: SB 26-189, signed 14 May 2026, repealed the substantive provisions of the 2024 Colorado AI Act (SB 24-205), including its duty of care against algorithmic discrimination, and replaced them with a narrower law effective 1 January 2027.
  • Penalty: Attorney General enforcement, with violations treated as deceptive trade practices under the Colorado Consumer Protection Act; 60-day cure period until 1 January 2030; no private right of action.
  • Source: Colorado General Assembly, SB 26-189; Crowell & Moring on SB 26-189

4. California CPRA: Automated Decision-Making Technology (ADMT) Regulations

  • Jurisdiction: California, USA
  • Who must comply: Businesses using ADMT to make "significant decisions" about California consumers (financial, housing, education, employment, healthcare).
  • What must be proven: Pre-use notice to consumers; opt-out mechanism; access to information about ADMT logic and outputs; risk assessment for high-risk processing; human appeal process documentation.
  • Status: Regulations effective 1 January 2026. Businesses using ADMT for significant decisions must comply by 1 January 2027. Risk assessment duties began on 1 January 2026, with attestations and summaries due to the CPPA by 1 April 2028. [9]
  • Penalty: Up to $2,500 per violation ($7,500 for intentional), adjusted to $2,663 and $7,988 from 1 January 2025; administrative enforcement by CPPA. [9]
  • Source: CPPA announcement, 23 September 2025; Jackson Lewis CCPA FAQ [9]

5. Texas Responsible AI Governance Act (TRAIGA)

  • Jurisdiction: Texas, USA
  • Who must comply: Persons who develop or deploy AI systems in Texas, and Texas government entities.
  • What must be proven: Disclosure to consumers when government agencies (and health care services) use AI to interact with them; that AI is not developed or deployed to manipulate people toward self-harm, harm to others or crime, to infringe constitutional rights, to discriminate intentionally against a protected class, or to produce child sexual abuse material or sexual deepfakes; no social scoring, and no biometric identification without consent, by government.
  • Status: Enacted as HB 149 (signed 22 June 2025); effective 1 January 2026.
  • Penalty: Attorney General enforcement with a 60-day cure period; civil penalties of $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for continuing violations.
  • Source: Texas Legislature, HB 149 enrolled text

6. NYC Local Law 144: Automated Employment Decision Tools (AEDT)

  • Jurisdiction: New York City, USA
  • Who must comply: Employers and employment agencies using AEDTs to screen candidates or employees for hiring, promotion, or termination.
  • What must be proven: Annual bias audit by independent auditor; published audit results; notice to candidates/employees of AEDT use.
  • Status: In force since 2023; enforced by the NYC Department of Consumer and Worker Protection (DCWP), with enforcement from 5 July 2023.
  • Penalty: Up to $500 for a first violation and $500 to $1,500 for each subsequent violation; each day of use is a separate violation.
  • Source: DCWP, Automated Employment Decision Tools; NYC Administrative Code § 20-872

7. Illinois Biometric Information Privacy Act (BIPA)

  • Jurisdiction: Illinois, USA
  • Who must comply: Private entities that collect, capture, purchase, receive, or obtain biometric identifiers or information.
  • What must be proven: Written informed consent before collection; published retention/destruction schedule; protection of biometric data; no sale or profit from biometric data.
  • Status: In force. In Cothron v. White Castle System, Inc. (Illinois Supreme Court, 17 February 2023) each scan was held to be a separate violation; a 2024 amendment (Public Act 103-0769, 2 August 2024) limits repeated collection by the same method to one violation per person.
  • Penalty: $1,000 per negligent violation; $5,000 per intentional or reckless violation; private right of action; attorneys' fees.
  • Source: 740 ILCS 14 (BIPA); Jackson Lewis on Cothron v. White Castle; Ogletree on the 2024 amendment

8. Canada: Artificial Intelligence and Data Act (AIDA)

  • Jurisdiction: Canada
  • Who must comply: Organizations developing or deploying high-impact AI systems affecting Canadians.
  • What must be proven: Risk identification, assessment, and mitigation measures; human oversight design; transparency; fairness and equity measures; safety assessments; validity and robustness documentation; accountability governance.
  • Status: Proposed only. Bill C-27 (containing AIDA) was still at committee stage when the parliamentary session ended on 6 January 2025, so it died on the Order Paper.
  • Penalty (as proposed): Administrative monetary penalties; prosecution of regulatory offences; criminal offences for reckless/malicious uses. [75]
  • Source: ISED AIDA Companion Document [75]; Parliament of Canada, LEGISinfo, Bill C-27

9. Quebec Law 25: Automated Decision-Making Disclosure

  • Jurisdiction: Quebec, Canada
  • Who must comply: Organizations using automated decision-making systems that process personal information.
  • What must be proven: Disclosure to individuals when decisions are made "exclusively through automated processing"; on request, the personal information used and the reasons and principal factors and parameters that led to the decision; the right to have the information corrected; the opportunity to submit observations to a staff member who can review the decision.
  • Status: In force since 2023; enforced by Commission d'accès à l'information du Québec.
  • Penalty: Penal fines up to CAD 25 million or 4% of worldwide turnover; administrative monetary penalties up to CAD 10 million or 2% of worldwide turnover.
  • Source: Act respecting the protection of personal information in the private sector (CQLR c P-39.1), ss.12.1, 90.12 and 91; CAI, main changes under Law 25; Wolseley Law Canada AI guide [80]

10. Ontario: AI Disclosure in Hiring

11. EU AI Act: General-Purpose AI Model Obligations (Arts 51 to 55)

  • Jurisdiction: European Union
  • Who must comply: Providers of general-purpose AI models (GPAI) with systemic risk; all GPAI providers must provide technical documentation and comply with copyright obligations.
  • What must be proven: Technical documentation; training data summary; copyright compliance measures; systemic risk evaluation and mitigation; incident reporting (for systemic risk models).
  • Status: Arts 51 to 55, including the systemic risk obligations in Art 55, apply from 2 August 2025; the Commission's power to fine GPAI providers (Art 101) applies from 2 August 2026.
  • Penalty: Up to EUR 15 million or 3% of global turnover (Art 101).
  • Source: Regulation (EU) 2024/1689, Arts 51 to 55; AI Act Art 101; AI Act Art 113

12. Utah AI Policy Act: Disclosure Requirements

  • Jurisdiction: Utah, USA
  • Who must comply: Persons using generative AI to interact with consumers in Utah, and persons providing the services of regulated occupations.
  • What must be proven: Disclosure that a person is interacting with generative AI when a consumer clearly asks; up-front disclosure by regulated occupations in high-risk interactions.
  • Status: In force since 1 May 2024. SB 226 (2025) narrowed the disclosure duties, now in Utah Code Title 13, Chapter 77 (effective 7 May 2025); the Artificial Intelligence Policy Act (Title 13, Chapter 72) is due to be repealed on 1 July 2027.
  • Penalty: Enforcement by Utah Division of Consumer Protection; administrative fines up to $2,500 per violation.
  • Source: Utah SB 149 (2024); Utah Code § 13-77-103, required disclosures; Utah Code § 13-77-105, enforcement; Utah Code § 63I-2-213, repeal date; Utah SB 226 (2025)

13. EU AI Act: Prohibited AI Practices (Art 5)

  • Jurisdiction: European Union
  • Who must comply: All providers and deployers of AI systems in the EU.
  • What must be proven: That prohibited practices (subliminal manipulation, exploitation of vulnerabilities, social scoring, real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions) are not occurring.
  • Status: Applies since 2 February 2025.
  • Penalty: Up to EUR 35 million or 7% of global turnover (Art 99(3)).
  • Source: Regulation (EU) 2024/1689, Art 5; AI Act Art 99

14. Singapore: MAS FEAT Principles for AI in Financial Services

  • Jurisdiction: Singapore
  • Who must comply: Financial institutions regulated by the Monetary Authority of Singapore using AI in decision-making.
  • What must be proven: Fairness, ethics, accountability, and transparency in AI-driven decisions; explainability; bias mitigation; human oversight.
  • Status: Voluntary principles published by MAS in 2018; they continue to shape supervisory expectations. [137]
  • Penalty: Regulatory sanctions through MAS supervisory framework.
  • Source: MAS FEAT Principles (2018); Mondaq Singapore AI governance [137]

15. California SB 942: GenAI Watermarking and Detection (Generative AI Transparency Act)

  • Jurisdiction: California, USA
  • Who must comply: Providers of generative AI systems with over 1,000,000 monthly visitors or users, publicly accessible in California, that create or alter image, video or audio content.
  • What must be proven: That AI-generated content includes provenance disclosures; that detection tools are provided; that synthetic content is identifiable.
  • Status: Signed into law September 2024; AB 853 (2025) moved its operative date from 1 January 2026 to 2 August 2026.
  • Penalty: $5,000 per violation, each day a separate violation; enforcement by the Attorney General or local prosecutors; injunctive relief.
  • Source: California AB 853 (2025); California SB 942 (2024)

Domain 2: Cybersecurity & Incident Reporting

16. EU NIS2 Directive: Incident Reporting & Risk Management

  • Jurisdiction: European Union (transposed into national law)
  • Who must comply: Essential and important entities across 18 sectors including digital infrastructure, energy, transport, banking, health, public administration.
  • What must be proven: Risk management measures are "appropriate and proportionate" and based on state-of-the-art; records of incident detection, response, and reporting; supplier cybersecurity evaluations; training evidence. [12]
  • Reporting deadlines: For each significant cybersecurity incident: early warning within 24h, incident report within 72h, final report within 1 month.
  • Status: Transposition deadline 17 October 2024. Many Member States transposed late; in July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose.
  • Penalty: Maximum fines of at least EUR 10 million or 2% of worldwide turnover (essential entities) and at least EUR 7 million or 1.4% (important entities), set by each Member State (Art 34).
  • Source: Directive (EU) 2022/2555; European Commission, infringement referral, July 2026; ThingsRecon NIS2 evidence requirements [12]

17. EU DORA: ICT Incident Reporting & Digital Resilience Testing

  • Jurisdiction: European Union
  • Who must comply: Banks, payment institutions, investment firms, insurers, crypto-asset service providers, critical ICT third-party providers. [48]
  • What must be proven: ICT risk management framework; major incident classification and reporting; digital operational resilience testing (including TLPT every 3 years for significant entities); ICT third-party risk management.
  • Reporting deadlines: For each major ICT incident: initial notification within 4h of classification, intermediate report within 72h, final report within 1 month. [54]
  • Status: Fully applicable from 17 January 2025. [48]
  • Penalty: Administrative fines proportionate to severity; supervisory sanctions.
  • Source: Regulation (EU) 2022/2554; Delegated Regulation (EU) 2025/301 on incident reporting; EIOPA DORA page; FluxForce DORA guide [48]; Iason DORA analysis [54]

18. SEC Cybersecurity Disclosure Rules (2023)

  • Jurisdiction: United States
  • Who must comply: All SEC registrants (public companies).
  • What must be proven: Material cybersecurity incidents disclosed on Form 8-K within 4 business days; annual 10-K disclosures on cybersecurity risk management, strategy, and governance. [14]
  • Status: Adopted 26 July 2023. Form 8-K incident disclosure required from 18 December 2023 (smaller reporting companies 180 days later); Form 10-K disclosure from fiscal years ending on or after 15 December 2023.
  • Penalty: SEC enforcement action; injunctive relief; civil monetary penalties.
  • Source: SEC press release 2023-139; Optro AI SEC cyber rules guide [14]

19. SEC Regulation S-P Amendments for Broker-Dealers, Investment Advisers, Investment Companies (2024)

  • Jurisdiction: United States
  • Who must comply: Broker-dealers, investment companies, registered investment advisers, transfer agents.
  • What must be proven: Written policies and procedures for an incident response program to detect, respond to and recover from unauthorised access to customer information; notification of affected customers as soon as practicable and within 30 days.
  • Status: Adopted 16 May 2024; compliance deadline 3 December 2025 for larger entities and 3 June 2026 for smaller entities. [21]
  • Penalty: SEC enforcement; civil penalties; injunctive relief.
  • Source: SEC press release 2024-58; Latham & Watkins SEC cybersecurity alert [21]

20. CMMC 2.0: Defense Contractor Cybersecurity Certification

21. EU Cyber Resilience Act (CRA): Vulnerability & Incident Reporting

  • Jurisdiction: European Union
  • Who must comply: Manufacturers of all products with digital elements placed on the EU market (excluding medical devices, vehicles, aviation, marine). [74]
  • What must be proven: Cybersecurity risk assessment; essential cybersecurity requirements implemented; SBOMs maintained; vulnerability handling process; security updates; 24-hour reporting of actively exploited vulnerabilities and severe incidents. [76]
  • Reporting deadlines: For each severe incident: 24h early warning, 72h incident notification, final report within one month. For each actively exploited vulnerability: 24h early warning, 72h notification, final report within 14 days after a corrective measure is available.
  • Status: In force 10 December 2024; reporting obligations from 11 September 2026; full compliance from 11 December 2027. [83]
  • Penalty: Up to EUR 15 million or 2.5% of worldwide turnover. [74]
  • Source: Regulation (EU) 2024/2847; European Commission, CRA reporting obligations; Wirtek CRA testing guide [74]; BSI CRA guidance [76]; European Commission CRA [83]

22. ISO/IEC 27001:2022: Information Security Management System

  • Jurisdiction: Global (certification body-dependent)
  • Who must comply: Any organization seeking ISMS certification or maintaining compliance.
  • What must be proven: 93 controls across organizational, people, physical, and technological domains; risk assessment; internal audit; management review; continuous improvement. [43][45]
  • Status: Continuous; surveillance audits typically annual; recertification every 3 years.
  • Penalty: Loss of certification; contract disqualification; regulatory non-compliance.
  • Source: ISO/IEC 27001:2022; Penligent ISO 27001 guide [43]; High Table ISO 27001 controls [45]

23. PCI DSS v4.0.1: Payment Card Industry Data Security Standard

  • Jurisdiction: Global (enforced by card brands and acquirers)
  • Who must comply: All entities storing, processing, or transmitting cardholder data.
  • What must be proven: 12 requirements across network security, data protection, vulnerability management, access control, monitoring, and governance; continuous evidence of control operation. [126]
  • Status: v4.0 retired 31 December 2024; v4.0.1 fully mandatory from 31 March 2025. [126]
  • Penalty: Brand damage; potential loss of card processing privileges.
  • Source: PCI Security Standards Council, PCI DSS v4.0.1; Beast Insights PCI DSS 2026 [126]

24. NERC CIP: North American Electric Reliability Corporation Critical Infrastructure Protection

  • Jurisdiction: United States, Canada, Mexico
  • Who must comply: Bulk electric system owners, operators, and users in North America.
  • What must be proven: Cybersecurity controls for critical cyber assets; electronic security perimeters; system security management; incident reporting; training and awareness.
  • Status: Continuously enforced; standards updated regularly.
  • Penalty: Up to $1,584,648 per violation per day (Federal Power Act s.316A maximum as adjusted for inflation in January 2025); regulatory sanctions.
  • Source: NERC CIP standards; FERC civil monetary penalty inflation adjustments, 2025

25. UK NIS Regulations 2018 (as amended): Operator Security Measures

  • Jurisdiction: United Kingdom
  • Who must comply: Operators of essential services (OES) and relevant digital service providers (RDSPs).
  • What must be proven: Appropriate and proportionate security measures; notification of incidents to the competent authority within 72 hours; assessment against the objectives and principles of the NCSC Cyber Assessment Framework, which is designed for organisations subject to the NIS Regulations.
  • Status: In force.
  • Penalty: Up to GBP 1 million, GBP 8.5 million or GBP 17 million depending on the seriousness of the contravention.
  • Source: NIS Regulations 2018 (SI 2018/506), reg 11 (incident notification); reg 18 (penalties); NCSC Cyber Assessment Framework

26. Japan: APPI (Act on Protection of Personal Information) + Cybersecurity Basic Act

Domain 3: Data Protection & Privacy

27. GDPR: Article 22 Automated Decision-Making (including profiling)

  • Jurisdiction: European Union / EEA
  • Who must comply: All data controllers using automated decision-making (including profiling) that produces legal or similarly significant effects.
  • What must be proven: Meaningful information about the logic involved; significance and envisaged consequences; right to human intervention; right to express one's point of view; right to contest the decision.
  • Status: In force since 2018; ongoing enforcement by supervisory authorities.
  • Penalty: Up to EUR 20 million or 4% of global turnover.
  • Source: Regulation (EU) 2016/679 (GDPR), Art 22 and Art 83

28. GDPR: Article 5 Data Processing Principles (Accountability)

  • Jurisdiction: European Union / EEA
  • Who must comply: All data controllers and processors.
  • What must be proven: Lawfulness, fairness, transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability through demonstrable compliance.
  • Status: In force since 2018.
  • Penalty: Up to EUR 20 million or 4% of global turnover.
  • Source: Regulation (EU) 2016/679 (GDPR), Art 5 and Art 83

29. GDPR: Article 33 Data Breach Notification

  • Jurisdiction: European Union / EEA
  • Who must comply: All data controllers.
  • What must be proven: Breach detection and assessment; notification to supervisory authority within 72 hours; communication to data subjects where high risk; documentation of breach facts, effects, and remedial measures.
  • Status: In force since 2018.
  • Penalty: Up to EUR 10 million or 2% of global turnover for notification failures.
  • Source: Regulation (EU) 2016/679 (GDPR), Art 33 and Art 83

30. California CCPA/CPRA: Consumer Rights and Deletion

  • Jurisdiction: California, USA
  • Who must comply: For-profit businesses meeting thresholds that collect California consumers' personal information.
  • What must be proven: Consumer right to know, delete, correct, opt-out of sale/sharing; opt-out of ADMT for significant decisions; data minimization; service provider contracts.
  • Status: CCPA effective 2020; CPRA amendments effective 2023; 2026 regulations expanded ADMT, risk assessments, and cybersecurity audits. [18]
  • Penalty: Up to $2,500 per violation ($7,500 intentional), adjusted to $2,663 and $7,988 from 1 January 2025; private right of action for breaches ($100 to $750 per consumer per incident).
  • Source: BDO CCPA 2026 technology guide [18]; Jackson Lewis CCPA FAQ; Cal. Civ. Code § 1798.150

31. California Delete Act (SB 362): Data Broker Deletion

  • Jurisdiction: California, USA
  • Who must comply: Data brokers (entities that collect and sell personal information of consumers with whom they have no direct relationship).
  • What must be proven: Annual registration with CPPA; processing of deletion requests through DROP platform within 45 days; audit readiness; deletion request metrics reporting. [100][104]
  • Status: DROP platform launched January 2026; from 1 August 2026 data brokers must access it at least every 45 days and process deletion requests; independent audits every three years from 1 January 2028. [104]
  • Penalty: $200 per day per deletion request not processed; $200 per day for registration failures. [100]
  • Source: CalLawyers data broker analysis [100]; CPPA DROP platform [104]; Cal. Civ. Code § 1798.99.86; Cal. Civ. Code § 1798.99.82

32. UK GDPR Articles 22A to 22D: Automated Decision-Making (formerly Data Protection Act 2018, Section 14)

  • Jurisdiction: United Kingdom
  • Who must comply: Data controllers taking significant decisions based solely on automated processing.
  • What must be proven: Information to the data subject about the decision; the ability to make representations; meaningful human intervention on request; the ability to contest the decision.
  • Status: The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D and omitted Data Protection Act 2018 s.14, with effect from 5 February 2026; enforced by ICO.
  • Penalty: Up to GBP 17.5 million or 4% of global turnover.
  • Source: Data (Use and Access) Act 2025, s.80; Data Protection Act 2018, s.14 (omitted); Data Protection Act 2018, s.157 (penalty maximum)

33. Brazil LGPD: Automated Decision-Making (Art 20)

  • Jurisdiction: Brazil
  • Who must comply: Data controllers using automated decision-making affecting data subjects' interests.
  • What must be proven: Right to request review of decisions based solely on automated processing; provision of clear and adequate information about criteria and procedures used. A paragraph requiring that the review be carried out by a natural person was vetoed in 2019.
  • Status: In force since 2020; administrative sanctions applicable from 1 August 2021.
  • Penalty: Up to 2% of revenue in Brazil (capped at BRL 50 million per violation).
  • Source: Lei Geral de Proteção de Dados (Lei No. 13.709/2018), compiled text, Arts 20, 52 and 65

34. India DPDP Act 2023: Consent and Data Fiduciary Obligations

  • Jurisdiction: India
  • Who must comply: Data fiduciaries processing digital personal data of Indian residents.
  • What must be proven: Free, specific, informed, unconditional, and withdrawable consent; notice of processing purposes; data principal rights (access, correction, erasure, grievance redressal); data breach notification to Board and affected principals.
  • Status: Enacted August 2023. Under a commencement notification of 13 November 2025 the Act comes into force in phases: Data Protection Board provisions from 13 November 2025, consent manager provisions one year later (13 November 2026), and the main obligations on data fiduciaries eighteen months later (13 May 2027).
  • Penalty: Up to INR 250 crore for data fiduciary breaches.
  • Source: Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Commencement notification G.S.R. 843(E), 13 November 2025

35. Singapore PDPA: AI Recommendation and Decision Systems Advisory Guidelines

  • Jurisdiction: Singapore
  • Who must comply: Organizations using personal data in AI recommendation and decision systems.
  • What must be proven: Consent or statutory exception basis for data use; meaningful notification and transparency for B2C deployment; contractual controls for B2B data intermediary arrangements; accountability for automated decisions. [137]
  • Status: Advisory guidelines issued March 2024; PDPA obligations binding.
  • Penalty: Up to SGD 1 million, or 10% of annual turnover in Singapore for organisations with turnover above SGD 10 million.
  • Source: Mondaq Singapore AI governance [137]; PDPA s.48J

36. Australia Privacy Act: APP 3 (Collection) and Notifiable Data Breaches

Domain 4: Financial Services

37. EU MiFID II: Algorithmic Trading Governance (RTS 6)

  • Jurisdiction: European Union
  • Who must comply: Investment firms engaging in algorithmic trading, including high-frequency trading.
  • What must be proven: Description of algorithmic trading strategies; trading parameters and limits; key compliance and risk controls; system testing records; for HFT: accurate and time-sequenced records of all placed orders, cancellations, executed orders, and quotations. [22]
  • Status: In force since 2018; ongoing enforcement by national competent authorities.
  • Penalty: Administrative sanctions; trading suspension; withdrawal of authorization.
  • Source: MiFID II Directive 2014/65/EU [22]; Delegated Regulation (EU) 2017/589 (RTS 6); ESMA, MiFID II Art 17

38. US OCC 2026-13 / SR 26-2: Model Risk Management Guidance

  • Jurisdiction: United States
  • Who must comply: National banks and federal savings associations (OCC); bank holding companies and state member banks (Federal Reserve SR 26-2); expected to be most relevant to banking organisations with over $30 billion in total assets.
  • What must be proven: Risk-based model risk management covering model development and use, validation and ongoing monitoring, and governance and controls, including vendor models. Generative AI and agentic AI models are outside the scope of this guidance.
  • Status: Issued jointly by the Federal Reserve, OCC and FDIC on 17 April 2026; supersedes SR 11-7 and OCC Bulletin 2011-12.
  • Penalty: The guidance itself sets no enforceable standards, and non-compliance with it does not result in supervisory criticism; unsafe or unsound practices remain subject to supervisory action.
  • Source: OCC news release and Bulletin 2026-13; Federal Reserve SR 26-2

39. NAIC AI Bulletin: AI Use in Insurance

  • Jurisdiction: United States (state insurance regulators via NAIC)
  • Who must comply: Insurance companies using AI in underwriting, pricing, claims, marketing, or fraud detection.
  • What must be proven: AI governance framework; risk management; data quality and validation; model transparency and explainability; ongoing monitoring for unfair discrimination; third-party AI vendor oversight.
  • Status: NAIC Model Bulletin adopted 4 December 2023; adopted by 24 states and the District of Columbia as of 1 April 2026.
  • Penalty: State enforcement actions; license sanctions; market conduct examinations.
  • Source: NAIC, artificial intelligence; NAIC map of Model Bulletin adoption

40. EU DORA: ICT Third-Party Risk Management (Arts 28 to 30)

  • Jurisdiction: European Union
  • Who must comply: Financial entities and critical ICT third-party providers (CTPPs).
  • What must be proven: Register of information (RoI) for all ICT contracts; mandatory contractual clauses for security, audit rights, incident notification, data location, exit strategies; reporting of significant contracts to regulators. [52]
  • Status: Fully applicable from 17 January 2025.
  • Penalty: Administrative fines; supervisory sanctions.
  • Source: Regulation (EU) 2022/2554, Arts 28 to 30; DORA text, Art 28 [52]

41. EU DORA: Threat-Led Penetration Testing (TLPT / TIBER-EU)

  • Jurisdiction: European Union
  • Who must comply: Significant financial entities; critical ICT third-party providers.
  • What must be proven: TLPT conducted every 3 years on live production systems by certified external testers using TIBER-EU framework; test scoping; threat intelligence; red team exercise results; remediation tracking. [48]
  • Status: Fully applicable from 17 January 2025.
  • Penalty: Supervisory sanctions for non-compliance.
  • Source: Regulation (EU) 2022/2554, Arts 26 and 27; DORA text, Art 26; FluxForce DORA guide [48]

42. US FinCEN AML/CFT Program Rule for Investment Advisers

  • Jurisdiction: United States
  • Who must comply: Certain investment advisers.
  • What must be proven: Written AML/CFT program; risk-based procedures; appointment of AML officer; ongoing monitoring; suspicious activity reporting (SAR); recordkeeping.
  • Status: Final rule adopted 2024 with an effective date of 1 January 2026; on 31 December 2025 FinCEN postponed the effective date to 1 January 2028.
  • Penalty: Civil money penalties; criminal liability for willful violations.
  • Source: FinCEN final rule, 4 September 2024; FinCEN, final rule postponing the effective date to 2028

43. UK SMCR: Senior Managers & Certification Regime

  • Jurisdiction: United Kingdom
  • Who must comply: Banks, insurers, and FCA-regulated firms.
  • What must be proven: Statements of Responsibility; Fit and Proper assessments; regulatory references; conduct rules training; annual certification.
  • Status: In force; ongoing FCA enforcement.
  • Penalty: Individual fines; bans; public censure.
  • Source: FCA, Senior Managers and Certification Regime; FCA, Certification Regime

44. EU MAR: Algorithmic Trading Surveillance

  • Jurisdiction: European Union
  • Who must comply: Trading venues, investment firms, market operators.
  • What must be proven: Real-time monitoring of algorithmic trading for market abuse; suspicious transaction and order reports (STORs).
  • Status: In force since 2016.
  • Penalty: Member States must set maximum fines for firms of at least EUR 15 million or 15% of annual turnover for insider dealing and market manipulation, and at least EUR 2.5 million or 2% for failures under Art 16 (detecting and reporting suspicious orders and transactions).
  • Source: Regulation (EU) No 596/2014, Arts 16, 30 and 39

45. Basel Operational Resilience Principles

  • Jurisdiction: Global
  • Who must comply: Internationally active banks.
  • What must be proven: Operational risk management; business continuity; ICT risk management; third-party risk; incident management.
  • Status: Final principles March 2021; national implementation ongoing.
  • Penalty: Supervisory sanctions; capital add-ons.
  • Source: BCBS Principles for Operational Resilience (March 2021)

46. US CFTC Electronic Trading Risk Principles (Regulation AT Withdrawn)

  • Jurisdiction: United States
  • Who must comply: Designated contract markets (DCMs).
  • What must be proven: Exchange rules for market participants to prevent, detect and mitigate market disruptions and system anomalies from electronic trading; exchange-based pre-trade risk controls for all electronic orders; prompt notification to CFTC staff of significant market disruptions.
  • Status: Regulation AT was proposed in 2015 (supplemented 2016) but never finalised; the CFTC withdrew it on 15 July 2020. The electronic trading risk principles for DCMs were adopted instead, effective 11 January 2021.
  • Penalty: CFTC enforcement; civil monetary penalties.
  • Source: Regulation Automated Trading; Withdrawal (2020); Electronic Trading Risk Principles, final rule (2021)

Domain 5: Healthcare, Clinical & Pharma

47. FDA 21 CFR Part 11: Electronic Records and Signatures

  • Jurisdiction: United States
  • Who must comply: FDA-regulated industries using electronic records/signatures.
  • What must be proven: System validation; audit trails; operational/authority/device checks; training; record retention.
  • Status: In force since 1997.
  • Penalty: FDA warning letters; consent decrees; product approval delays; criminal liability.
  • Source: 21 CFR Part 11; FDA final rule, 20 March 1997 (effective 20 August 1997)

48. EU GMP Annex 11: Computerised Systems

  • Jurisdiction: European Union
  • Who must comply: Pharmaceutical manufacturers under EU GMP.
  • What must be proven: System validation; data integrity (ALCOA+); audit trails; security/access control; backup/recovery; electronic signatures.
  • Status: In force (current version January 2011); a revised Annex 11 and a new Annex 22 on AI were published for consultation from 7 July to 7 October 2025.
  • Penalty: GMP non-compliance; marketing authorization suspension; batch recalls.
  • Source: EudraLex Volume 4, Annex 11; European Commission consultation on Chapter 4, Annex 11 and new Annex 22

49. FDA GMLP: Good Machine Learning Practice

  • Jurisdiction: United States
  • Who must comply: Developers of AI/ML-based Software as a Medical Device (SaMD).
  • What must be proven: Multi-disciplinary expertise; good software engineering practices; representative training/validation datasets; model design suited to clinical problem; human-AI teaming focus; device testing for defined use.
  • Status: Ten guiding principles published October 2021 by FDA, Health Canada and MHRA; not formal FDA guidance.
  • Penalty: 510(k) clearance denial; enforcement action for marketed devices.
  • Source: FDA, Good Machine Learning Practice for Medical Device Development: Guiding Principles

50. FDA-EMA Guiding Principles of Good AI Practice in Drug Development

51. EU MDR 2017/745: Software as a Medical Device (SaMD)

  • Jurisdiction: European Union
  • Who must comply: Manufacturers of software meeting MDR medical device definition.
  • What must be proven: Conformity assessment; clinical evaluation; post-market surveillance; risk management (ISO 14971); quality management (ISO 13485); unique device identification (UDI).
  • Status: Applies since 26 May 2021; ongoing enforcement by notified bodies.
  • Penalty: CE mark withdrawal; market withdrawal; administrative fines.
  • Source: Regulation (EU) 2017/745 (MDR)

52. HIPAA Security Rule: Administrative, Physical, Technical Safeguards

  • Jurisdiction: United States
  • Who must comply: Covered entities and business associates handling protected health information (PHI).
  • What must be proven: Risk analysis; risk management; assigned security responsibilities; workforce training; information access management; audit controls; integrity controls; transmission security; breach notification.
  • Status: In force since 2003; active OCR enforcement.
  • Penalty: Civil money penalties in four tiers; the calendar-year cap for identical violations, $1.5 million in the regulation, is adjusted for inflation to $2,190,294 (HHS, January 2026); criminal liability; state AG enforcement.
  • Source: 45 CFR Part 164, Subpart C (Security Rule); 45 CFR § 160.404; HHS annual civil monetary penalties inflation adjustment, January 2026

53. 21 CFR Part 820 (FDA QSR): Quality System Regulation for Medical Devices

  • Jurisdiction: United States
  • Who must comply: Medical device manufacturers.
  • What must be proven: Design controls; document controls; purchasing controls; identification and traceability; production and process controls; acceptance activities; nonconforming product; CAPA; labeling and packaging controls; handling, storage, distribution, installation; records; servicing; statistical techniques.
  • Status: Amended as the Quality Management System Regulation (QMSR), which incorporates ISO 13485 by reference, effective 2 February 2026.
  • Penalty: FDA warning letters; consent decrees; product seizures; injunctions; criminal prosecution.
  • Source: 21 CFR Part 820; FDA final rule, Quality System Regulation Amendments (effective 2 February 2026)

54. ICH E6(R2) GCP: Good Clinical Practice (Electronic Data Capture)

  • Jurisdiction: Global (ICH member countries)
  • Who must comply: Sponsors, investigators, CROs conducting clinical trials.
  • What must be proven: Data integrity (ALCOA+); audit trails for electronic data capture; system validation; user access management; data backup and recovery.
  • Status: In force; ICH E6(R3), updating for decentralized trials and digital health technologies, was published in draft in 2023 and adopted (Step 4) on 6 January 2025.
  • Penalty: Regulatory rejection of trial data; clinical hold; enforcement action.
  • Source: ICH E6(R3) Step 4 guideline (6 January 2025)

Domain 6: Automotive, Aviation & Critical Infrastructure

55. UN R155: Cyber Security Management Systems (CSMS) for Vehicles

  • Jurisdiction: UNECE contracting parties (EU, UK, Japan, Korea, others)
  • Who must comply: Vehicle manufacturers (OEMs) seeking type approval.
  • What must be proven: Organizational CSMS covering development, production, and post-production; risk assessment aligned with Annex 5 threat scenarios; security measures with test evidence; supply chain cybersecurity; monitoring, detection, and response capabilities; data forensic capability; annual reporting to approval authority. [68][69][70]
  • Status: UN Regulation in force since January 2021; in the EU mandatory for new vehicle types from July 2022 and for all new vehicles from July 2024.
  • Penalty: Type approval refusal; market access denial; recall requirements; withdrawal of approval.
  • Source: UN Regulation No. 155 (UNECE); Regulation (EU) 2019/2144 (General Safety Regulation); Cyeqt UN R155 motorcycle guide [68]; Automotive IQ R155 guide [69]; VXLabs R155 type approval [70]

56. UN R156: Software Update Management Systems (SUMS)

  • Jurisdiction: UNECE contracting parties
  • Who must comply: Vehicle manufacturers conducting over-the-air (OTA) software updates.
  • What must be proven: Software update management system; vehicle and software identification; update integrity and authenticity verification; rollback capability; user notification; record of updates applied.
  • Status: UN Regulation in force since January 2021; in the EU mandatory for new vehicle types from July 2022 and for all new vehicles from July 2024.
  • Penalty: Type approval refusal; recall; market access denial.
  • Source: UN Regulation No. 156 (UNECE); Regulation (EU) 2019/2144 (General Safety Regulation); VXLabs R155/R156 guide [70]

57. ISO/SAE 21434: Road Vehicles Cybersecurity Engineering

  • Jurisdiction: Global (industry standard)
  • Who must comply: Automotive OEMs and suppliers demonstrating cybersecurity engineering processes.
  • What must be proven: Cybersecurity management across entire vehicle lifecycle; threat analysis and risk assessment (TARA); cybersecurity concept; product development security; production security; operations and maintenance; decommissioning. [68][71]
  • Status: Published August 2021; referenced in the UN R155 interpretation document.
  • Penalty: Loss of R155 type approval; contract penalties; recall liability.
  • Source: ISO/SAE 21434:2021; Cyeqt UN R155 motorcycle guide [68]; UNECE R155 Interpretation Document [71]

58. EU Cyber Resilience Act: Critical Products (Annex IV)

  • Jurisdiction: European Union
  • Who must comply: Manufacturers of critical products with digital elements (hardware devices with security boxes; smart meter gateways and other devices for advanced security purposes; smartcards and secure elements).
  • What must be proven: Third-party conformity assessment or EU cybersecurity certification; essential cybersecurity requirements; vulnerability handling; incident reporting; 10-year technical documentation retention. [74][76]
  • Status: In force 10 Dec 2024; reporting from 11 Sep 2026; full compliance from 11 Dec 2027.
  • Penalty: Up to EUR 15 million or 2.5% of worldwide turnover.
  • Source: Regulation (EU) 2024/2847, Art 13, Art 64 and Annex IV; European Commission CRA summary; Wirtek CRA guide [74]; BSI CRA guidance [76]

59. FAA: Aircraft Software Approval (DO-178C) & Cybersecurity (DO-326A)

  • Jurisdiction: United States
  • Who must comply: Aircraft and avionics manufacturers seeking FAA certification.
  • What must be proven: Software lifecycle processes (DO-178C); airborne security (DO-326A / ED-202A); safety assessment; configuration management; verification and validation.
  • Status: FAA Advisory Circular 20-115D (2017) recognises DO-178C as an acceptable means of compliance for airborne software. For aircraft network security the FAA issues case-by-case special conditions; a proposed rule on equipment, systems and network information security protection was published in August 2024.
  • Penalty: Type certificate denial; grounding orders; Airworthiness Directive issuance.
  • Source: FAA AC 20-115D; FAA NPRM, Equipment, Systems, and Network Information Security Protection (2024)

60. NERC CIP: Critical Infrastructure Protection (North American Electric)

  • Jurisdiction: United States, Canada, Mexico
  • Who must comply: Bulk electric system owners, operators, and users.
  • What must be proven: Cybersecurity controls for critical cyber assets; electronic security perimeters; system security management; incident reporting; training.
  • Status: Continuously enforced.
  • Penalty: Up to $1,584,648 per violation per day (Federal Power Act s.316A maximum as adjusted for inflation in January 2025).
  • Source: NERC CIP standards; FERC civil monetary penalty inflation adjustments, 2025

Domain 7: Defense, Export Control & National Security

61. CMMC 2.0: Cybersecurity Maturity Model Certification

  • Jurisdiction: United States
  • Who must comply: All DoD contractors and subcontractors handling FCI or CUI.
  • What must be proven: 15 (Level 1), 110 (Level 2), or 134 (Level 3) NIST SP 800-171/172 controls; System Security Plan; POA&M; evidence artifacts for every control; continuous monitoring. [38][39][40]
  • Status: Phase 1 (self-assessment) began November 2025; Phase 2 (C3PAO) begins November 2026.
  • Penalty: Contract disqualification; loss of DoD business; False Claims Act liability.
  • Source: IBSS CMMC guide [38]; Strike Graph [39]; DefenseScoop [40]

62. ITAR: International Traffic in Arms Regulations

  • Jurisdiction: United States
  • Who must comply: Manufacturers, exporters, brokers of defense articles, defense services, and technical data.
  • What must be proven: DDTC registration; USML classification; export licensing; control plans; employee training; recordkeeping of all ITAR-related activities; audit readiness.
  • Status: Continuously enforced by DDTC and Commerce Department (EAR for dual-use).
  • Penalty: Civil penalties up to the greater of $1,271,078 per violation or twice the value of the transaction (22 CFR 127.10, as adjusted for inflation); criminal penalties up to $1 million per violation and 20 years imprisonment; debarment.
  • Source: ITAR, 22 CFR Parts 120 to 130; 22 CFR 127.10 (civil penalties); 22 U.S.C. 2778 (criminal penalties); DDTC

63. EAR: Export Administration Regulations (Dual-Use Items)

  • Jurisdiction: United States
  • Who must comply: Exporters of dual-use items, software, and technology; entities dealing with restricted parties.
  • What must be proven: Commerce Control List (CCL) classification; license determination; screening against restricted party lists (SDN, Entity List, etc.); recordkeeping for 5 years.
  • Status: Continuously enforced by BIS.
  • Penalty: Civil penalties up to the greater of an inflation-adjusted amount per violation ($374,474 as listed in 15 CFR 6.3; statutory base $300,000) or twice the transaction value; criminal penalties; debarment.
  • Source: EAR, 15 CFR Parts 730 to 774; 15 CFR 762.6 (five-year retention); 15 CFR 6.3 (adjusted civil penalties)

64. UK Export Control Act 2002: Strategic Export Controls

  • Jurisdiction: United Kingdom
  • Who must comply: Exporters of controlled goods, software, and technology from the UK.
  • What must be proven: Export license application; end-user assessment; recordkeeping; compliance with UK Strategic Export Control Lists.
  • Status: In force; ongoing ECJU enforcement.
  • Penalty: Up to 14 years imprisonment for export offences under the Customs and Excise Management Act 1979 s.68 (since 22 February 2024), up to 10 years for knowing offences under the Export Control Order 2008; unlimited fines; revocation of export privileges.
  • Source: Export Control Act 2002 (c. 28); Customs and Excise Management Act 1979, s.68; Export Control Order 2008, Part 6

65. Australia DSGL: Defence and Strategic Goods List

  • Jurisdiction: Australia
  • Who must comply: Exporters of DSGL-controlled goods, software, and technology.
  • What must be proven: DSGL classification; export permit application; recordkeeping; compliance monitoring.
  • Status: In force; Defence Export Controls enforcement.
  • Penalty: Up to 10 years imprisonment, 2,500 penalty units, or both.
  • Source: Defence, export control penalties and breaches (archived copy, April 2026)

Domain 8: ESG, Sustainability & Supply Chain

66. EU CSRD: Corporate Sustainability Reporting Directive

67. EU CSDDD: Corporate Sustainability Due Diligence Directive

  • Jurisdiction: European Union
  • Who must comply: After Omnibus I, companies with 5,000+ employees and EUR 1.5 billion+ net worldwide turnover (non-EU companies: EUR 1.5 billion+ net turnover in the EU).
  • What must be proven: Human rights and environmental due diligence across operations, subsidiaries, and value chain; risk assessment; prevention and mitigation measures; monitoring; complaint mechanism; annual reporting.
  • Status: Adopted 2024. After the stop-the-clock Directive (EU) 2025/794 and Omnibus I (Directive (EU) 2026/470), transposition is due by 26 July 2028 and application starts 26 July 2029.
  • Penalty: Maximum fines capped at 3% of net worldwide turnover after Omnibus I.
  • Source: Directive (EU) 2024/1760; Directive (EU) 2026/470 (Omnibus I); European Commission, corporate sustainability due diligence

68. SEC Climate Disclosure Rules (2024)

  • Jurisdiction: United States
  • Who must comply: SEC registrants (public companies); large accelerated filers and accelerated filers must disclose Scope 1/2 GHG emissions with attestation. [90][91]
  • What must be proven: Climate-related risks material to business; governance of climate risks; Scope 1 and 2 GHG emissions (if material); attestation report from GHG emissions attestation provider; financial statement impacts of severe weather events and carbon offsets.
  • Status: Adopted 6 March 2024 and stayed by the SEC on 4 April 2024 pending judicial review. On 27 March 2025 the SEC voted to end its defence of the rules; the Eighth Circuit placed the case in abeyance on 12 September 2025; on 29 May 2026 the SEC proposed rescinding the rules.
  • Penalty: SEC enforcement; injunctive relief; civil monetary penalties.
  • Source: SEC press release 2025-58; SEC press release 2026-49, proposed rescission; FreeWritings Law SEC climate alert [90]; STX Group SEC guide [91]

69. California SB 253 / SB 261: Climate Disclosure Laws

  • Jurisdiction: California, USA
  • Who must comply: SB 253: US entities doing business in California with >$1B revenue (Scope 1, 2, 3 GHG emissions). SB 261: entities with >$500M revenue (climate-related financial risk reports).
  • What must be proven: GHG emissions inventory (Scopes 1, 2, 3) verified by third-party assurer; climate-related financial risk disclosure.
  • Status: SB 253 and SB 261 enacted 2023. Under SB 253, CARB is deferring the first Scope 1 and 2 reporting deadline from 10 August 2026 to 10 November 2026, with Scope 3 disclosure from 2027. SB 261 has been enjoined by the Ninth Circuit pending appeal, and CARB has said it will not enforce its 1 January 2026 reporting deadline.
  • Penalty: Up to $500,000 per reporting year for SB 253 violations; up to $50,000 per reporting year for SB 261.
  • Source: CARB climate disclosure program; CARB bulletin, 24 June 2026; CARB SB 261 enforcement advisory, December 2025; Cal. Health & Safety Code § 38532 (SB 253); § 38533 (SB 261)

70. EU Deforestation Regulation (EUDR)

  • Jurisdiction: European Union
  • Who must comply: Operators and traders placing cattle, cocoa, coffee, oil palm, rubber, soy, and wood products on the EU market. [49][50]
  • What must be proven: Products are deforestation-free (post-31 Dec 2020); produced in compliance with country of origin laws; covered by due diligence statement with geolocation coordinates; risk assessment and mitigation. [57]
  • Status: In force since 29 June 2023; under Regulation (EU) 2025/2650 (December 2025) obligations apply from 30 December 2026 for large and medium operators and from 30 June 2027 for micro and small operators. [49]
  • Penalty: Maximum fines of at least 4% of total annual EU turnover; confiscation of products and revenues; temporary exclusion (up to 12 months) from public procurement and public funding.
  • Source: Regulation (EU) 2023/1115, Art 25; European Commission, deforestation-free products; European Parliament procedure file 2025/0329(COD); WRI EUDR explainer [49]; Anthesis EUDR guide [50]; EU4Environment EUDR framework [57]

71. ICVCM Core Carbon Principles: Voluntary Carbon Credit Integrity

  • Jurisdiction: Global (voluntary market standard)
  • Who must comply: Carbon crediting programs and carbon credit buyers seeking high-integrity labels. [127][131]
  • What must be proven: Effective governance; unique tracking in registry; transparency; robust independent third-party validation and verification; additionality; permanence; robust quantification; no double counting; sustainable development benefits; contribution to net zero. [127]
  • Status: Core Carbon Principles launched March 2023 and the full Assessment Framework published July 2023; first CCP-eligible programs announced April 2024; first CCP-labelled credits announced June 2024.
  • Penalty: Loss of CCP label; market exclusion; reputational damage; greenwashing liability.
  • Source: ICVCM CCP Assessment Framework [127]; ICVCM website [131]; ICVCM, launch of the Core Carbon Principles; ICVCM, first CCP-eligible programs; ICVCM, first CCP-labelled credits

72. EU Empowering Consumers for the Green Transition Directive (2024/825)

  • Jurisdiction: European Union
  • Who must comply: Traders making explicit environmental claims about products or services.
  • What must be proven: Generic environmental claims only where recognised excellent environmental performance can be demonstrated; sustainability labels only where based on a certification scheme with independent third-party monitoring or established by public authorities.
  • Status: Directive (EU) 2024/825 in force since 26 March 2024; Member State transposition by 27 March 2026; rules apply from 27 September 2026. The separate Green Claims Directive proposal (2023) is still pending.
  • Penalty: Varies by Member State; typically significant administrative fines; injunctions.
  • Source: Directive (EU) 2024/825; European Commission, sustainable consumption; European Parliament procedure file 2023/0085(COD), Green Claims Directive

73. German Supply Chain Due Diligence Act (LkSG)

  • Jurisdiction: Germany
  • Who must comply: Companies with >3,000 employees (from 2023); >1,000 employees (from 2024).
  • What must be proven: Risk analysis of supply chain human rights and environmental risks; preventive measures; remedial measures; complaints procedure; documentation and reporting.
  • Status: In force since 2023; Federal Office for Economic and Export Control (BAFA) enforcement active.
  • Penalty: Fines up to EUR 8 million, or up to 2% of average annual turnover for companies with turnover above EUR 400 million; exclusion from public procurement.
  • Source: Lieferkettensorgfaltspflichtengesetz (LkSG) of 16 July 2021; BAFA, Supply Chain Act

Domain 9: Courts, Litigation & e-Discovery

74. Federal Rules of Evidence (FRE) 902(13): Self-Authenticating Electronic Records

  • Jurisdiction: United States (federal courts)
  • Who must comply: Litigants offering electronic records generated by a process or system.
  • What must be proven: Record generated by electronic process/system producing accurate result; certified by qualified person; reasonable notice to adverse party. [58][59][61]
  • Status: In force since 1 December 2017.
  • Penalty: Evidence exclusion; adverse inference; spoliation sanctions.
  • Source: Venio FRE 902 guide [58]; Joseph self-authentication article [59]; Cornell LII FRE 902 [61]

75. Federal Rules of Evidence (FRE) 902(14): Self-Authenticating Data from Electronic Devices

  • Jurisdiction: United States (federal courts)
  • Who must comply: Litigants offering data copied from electronic devices, storage media, or files.
  • What must be proven: Data copied via digital identification process (e.g., hash value comparison); certified by qualified person; reasonable notice to adverse party. [58][62][64]
  • Status: In force since 1 December 2017.
  • Penalty: Evidence exclusion; adverse inference; sanctions.
  • Source: Cornell LII FRE 902; Robins Kaplan FRE 902(14) eDiscovery [62]; Judicature self-authentication article [64]

76. FRCP Rule 34: Production of ESI (Requests for Production)

  • Jurisdiction: United States (federal courts)
  • Who must comply: Parties responding to requests for production of electronically stored information.
  • What must be proven: Production in reasonably usable form; preservation of metadata; proper format; completeness; privilege log for withheld materials. [63]
  • Status: In force; ongoing application in federal litigation.
  • Penalty: Sanctions under FRCP 37; adverse inference; default judgment; attorneys' fees.
  • Source: FRCP Rule 34; Venio FRCP eDiscovery guide [63]

77. FRCP Rule 37(e): Failure to Preserve ESI (Spoliation)

  • Jurisdiction: United States (federal courts)
  • Who must comply: All parties with potential litigation hold obligations.
  • What must be proven: Good faith preservation of ESI; litigation hold implementation; absence of intent to deprive; remedial measures.
  • Status: In force since the amendments effective 1 December 2015.
  • Penalty: Curative measures; adverse jury instruction; dismissal or default judgment (if intent to deprive).
  • Source: FRCP Rule 37(e) and committee notes

78. English Civil Procedure Rules (CPR) Part 31: Disclosure

  • Jurisdiction: England and Wales
  • Who must comply: Parties to civil litigation subject to disclosure obligations.
  • What must be proven: Standard disclosure (documents on which party relies, adversely affecting own/case, supporting other party's case, required by practice direction); extended disclosure for complex cases; Electronic Document Questionnaire.
  • Status: In force; in the Business and Property Courts, disclosure is governed by Practice Direction 57AD instead.
  • Penalty: Unless order; adverse costs; striking out of statements of case.
  • Source: CPR Part 31; Practice Direction 57AD

Domain 10: Identity, Content Provenance & Creative IP

79. C2PA / Content Authenticity Initiative: Content Credentials

  • Jurisdiction: Global (industry standard)
  • Who must comply: Content creators, publishers, platforms, and AI companies adopting content provenance standards.
  • What must be proven: Content origin (device, software, AI system); edit history; cryptographic signing of provenance manifest; machine-readable and human-verifiable credentials. [23][25][26]
  • Status: C2PA 2.1 specification published September 2024; C2PA steering committee members include Google, OpenAI, Adobe, Microsoft and the BBC. [23]
  • Penalty: Loss of platform trust; reputational damage; regulatory non-compliance (where content provenance is mandated).
  • Source: C2PA 2.1 specification; C2PA membership; Google C2PA blog [23]; OpenAI C2PA guide [24]; Wikipedia CAI [25]; C2PA.org [26]

80. Tennessee ELVIS Act: Voice and Likeness Protection

  • Jurisdiction: Tennessee, USA
  • Who must comply: Anyone using AI to generate or distribute voice, image, or likeness replicas; platforms distributing such content; AI tool providers whose primary purpose is likeness generation. [29][30][32]
  • What must be proven: Consent for use of voice, name, image, or likeness; knowledge of unauthorized use; record label authority for artist enforcement.
  • Status: Effective 1 July 2024. [30]
  • Penalty: Class A misdemeanor (up to 11 months 29 days, $2,500 fine); civil injunction; actual damages; profits; attorney's fees. [29]
  • Source: Tennessee General Assembly, HB 2091 (ELVIS Act); Kent Law ELVIS Act analysis [29]; Regulations.ai ELVIS Act [30]; Wilson Sonsini ELVIS alert [32]

81. No AI FRAUD Act (Federal, Proposed)

  • Jurisdiction: United States (federal, proposed)
  • Who must comply: (If enacted) platforms, persons, companies digitally replicating individual's image, voice, or visual likeness without authorization.
  • What must be proven: Consent for digital replica creation; platform knowledge of unauthorized use; takedown compliance.
  • Status: Introduced in the House on 10 January 2024 (118th Congress) and referred to the Judiciary Committee; not enacted.
  • Penalty: (Proposed) statutory damages; injunctive relief; attorney's fees.
  • Source: H.R. 6943 (118th Congress), introduced text; Congress.gov, H.R. 6943

82. Copyright Registration: AI-Generated Works (USCO Policy)

83. EU DSM Directive Article 17: Platform Liability for Copyright Content

  • Jurisdiction: European Union
  • Who must comply: Online content-sharing service providers (OCSSPs).
  • What must be proven: Best efforts to obtain authorization; best efforts to ensure unavailability of unauthorized content; expeditious removal upon notice; transparency reporting.
  • Status: Transposition deadline 7 June 2021; ongoing enforcement.
  • Penalty: Injunctive relief; damages; national administrative sanctions.
  • Source: Directive (EU) 2019/790 (DSM Directive), Art 17 and Art 29

Domain 11: Employment, HR & Algorithmic Management

84. NYC Local Law 144: AEDT Bias Audit

  • Jurisdiction: New York City, USA
  • Who must comply: Employers and employment agencies using AEDTs for hiring, promotion, or termination screening.
  • What must be proven: Annual bias audit by independent auditor; published audit results; notice to candidates/employees.
  • Status: In force since 2023; enforced by the NYC Department of Consumer and Worker Protection from 5 July 2023.
  • Penalty: Up to $500 for a first violation and $500 to $1,500 for each subsequent violation; each day of use is a separate violation.
  • Source: DCWP, Automated Employment Decision Tools

85. Illinois BIPA: Biometric Consent and Retention

  • Jurisdiction: Illinois, USA
  • Who must comply: Private entities collecting biometric identifiers/information.
  • What must be proven: Written informed consent; published retention schedule; protection of biometric data; no sale/profit.
  • Status: In force; Cothron v. White Castle System, Inc. (Illinois Supreme Court, 2023) held each scan a separate violation, and a 2024 amendment limits repeated collection by the same method to one violation per person.
  • Penalty: $1,000 negligent; $5,000 intentional or reckless; private right of action; attorneys' fees.
  • Source: 740 ILCS 14 (BIPA); Ogletree on the 2024 amendment

86. EEOC Guidance: AI and Title VII (Selection Procedures)

87. EU Platform Work Directive: Algorithmic Management

  • Jurisdiction: European Union
  • Who must comply: Digital labour platforms employing or contracting platform workers.
  • What must be proven: Human review of automated decisions affecting working conditions; transparency about algorithmic management; right to explanation; restriction on processing certain data (emotions, health, private conversations).
  • Status: Adopted October 2024; Member State transposition by 2 December 2026.
  • Penalty: Varies by Member State; administrative fines; injunctive relief.
  • Source: Directive (EU) 2024/2831; European Parliament Legislative Train, platform work

88. Netherlands Algorithmic Registration: Public Sector

  • Jurisdiction: Netherlands
  • Who must comply: Dutch public sector organizations using algorithms with legal or significant effects.
  • What must be proven: Registration in Algorithm Register; risk classification; human oversight measures; transparency about algorithm use; periodic review.
  • Status: Algorithm Register launched 21 December 2022; supplying information is not yet a legal requirement.
  • Penalty: Administrative sanctions; public accountability; parliamentary scrutiny.
  • Source: Dutch Government Algorithm Register, about; Algorithm Register, questions

89. EU GDPR: Art 22 in Employment Context

  • Jurisdiction: European Union
  • Who must comply: Employers using automated decision-making in hiring, performance evaluation, or termination.
  • What must be proven: Logic of automated employment decisions; significance and consequences; right to human intervention; right to contest.
  • Status: In force since 2018.
  • Penalty: Up to EUR 20 million or 4% of global turnover.
  • Source: Regulation (EU) 2016/679 (GDPR), Art 22 and Art 83

Domain 12: Gaming, Gambling & Entertainment

90. UK Gambling Commission: Algorithmic Fairness and Transparency

  • Jurisdiction: United Kingdom
  • Who must comply: Licensed gambling operators using algorithms for game outcomes, odds-setting, or customer management.
  • What must be proven: Random number generator (RNG) certification; return-to-player (RTP) verification; algorithmic fairness testing; responsible gambling algorithm deployment.
  • Status: Continuously regulated by UK Gambling Commission.
  • Penalty: License revocation; fines; criminal prosecution.
  • Source: UK Gambling Commission LCCP; Remote gambling and software technical standards; RTS 7, generation of random outcomes

91. Malta Gaming Authority: AI and Algorithmic Game Integrity

  • Jurisdiction: Malta
  • Who must comply: Licensed gaming operators under MGA jurisdiction.
  • What must be proven: RNG certification; game fairness testing; algorithm transparency to MGA; player protection algorithm operation.
  • Status: Continuously regulated by MGA.
  • Penalty: License suspension; fines; criminal referral.
  • Source: Gaming Authorisations Regulations (S.L. 583.05)

92. Nevada Gaming Commission: Electronic Gaming Device Approval

Domain 13: Education, Research Integrity & Scientific Reproducibility

94. UK Research Integrity Framework: Reproducibility and Data Provenance

  • Jurisdiction: United Kingdom
  • Who must comply: UK research institutions and researchers receiving public funding.
  • What must be proven: Research data management plans; data provenance and lineage; methodology documentation; reproducibility protocols; conflict of interest disclosure.
  • Status: UK Research Integrity Office (UKRIO) framework; funder mandates (UKRI, Wellcome, etc.).
  • Penalty: Funding withdrawal; institutional sanctions; retraction; reputational damage.
  • Source: UKRIO Code of Practice for Research; Concordat to Support Research Integrity

95. NIH Data Management and Sharing Policy

  • Jurisdiction: United States
  • Who must comply: NIH-funded researchers generating scientific data.
  • What must be proven: Data Management and Sharing Plan (DMSP); data sharing by end of award period; metadata standards; data repository deposition.
  • Status: Effective 25 January 2023.
  • Penalty: Funding withholding; grant termination; future funding ineligibility.
  • Source: NIH Policy for Data Management and Sharing (NOT-OD-21-013)

96. FAIR Data Principles: Findable, Accessible, Interoperable, Reusable

97. EU Horizon Europe: Research Integrity and Ethics Compliance

  • Jurisdiction: European Union
  • Who must comply: Horizon Europe beneficiaries and applicants.
  • What must be proven: Ethics self-assessment; data management plan; open access publication; research integrity adherence; dual-use/export control screening.
  • Status: Horizon Europe ongoing (2021 to 2027).
  • Penalty: Grant termination; funding recovery; exclusion from future calls.
  • Source: European Commission, Horizon Europe

Domain 14: Contracts, SLAs & Commercial Attestations

98. SOC 2 Type II: Service Organization Control Reporting

  • Jurisdiction: Global (AICPA standard)
  • Who must comply: Service organizations (SaaS, cloud, data centers, BPOs) seeking SOC 2 attestation.
  • What must be proven: Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy); control design and operating effectiveness over a review period; independent auditor attestation.
  • Status: Continuous; Type II reports issued periodically.
  • Penalty: Loss of attestation; contract cancellation; revenue loss.
  • Source: AICPA, SOC 2

99. ISO/IEC 42001: AI Management System

  • Jurisdiction: Global
  • Who must comply: Organizations seeking AI management system certification.
  • What must be proven: AI policy; risk assessment; AI system lifecycle governance; data governance; human oversight; transparency; continuous improvement.
  • Status: Published December 2023.
  • Penalty: Loss of certification; competitive disadvantage; procurement exclusion.
  • Source: ISO/IEC 42001:2023

100. ISO/IEC 23894: AI Risk Management

  • Jurisdiction: Global
  • Who must comply: Organizations implementing AI risk management aligned with ISO standards.
  • What must be proven: AI risk assessment; risk treatment; monitoring and review; communication and consultation; record of risk management activities.
  • Status: Published February 2023.
  • Penalty: Non-certification; regulatory non-alignment; competitive disadvantage.
  • Source: ISO/IEC 23894:2023

101. Service Level Agreement (SLA): Automated Monitoring and Breach Evidence

  • Jurisdiction: Global (contractual)
  • Who must comply: Service providers with SLA obligations to customers.
  • What must be proven: Uptime/downtime records; response time metrics; incident response timelines; root cause analyses; remediation actions; credit entitlement calculations.
  • Status: Contractually binding; litigation-enforceable.
  • Penalty: SLA credits; contract termination; damages; litigation.
  • Source: Contract law (general); specific SLA terms vary

102. Cloud Security Alliance (CSA) STAR: Security, Trust, Assurance, and Risk

  • Jurisdiction: Global
  • Who must comply: Cloud service providers seeking CSA STAR certification.
  • What must be proven: CCM (Cloud Controls Matrix) compliance; CAIQ (Consensus Assessments Initiative Questionnaire); continuous monitoring; third-party audit.
  • Status: Continuous; Level 1 (self-assessment) and Level 2 (third-party certification or attestation).
  • Penalty: Loss of certification; procurement exclusion.
  • Source: Cloud Security Alliance STAR levels

Domain 15: Elections, Media Integrity & Advertising

103. UK Online Safety Act: Illegal Content and Children's Safety Duties

  • Jurisdiction: United Kingdom
  • Who must comply: User-to-user services and search services accessible in the UK.
  • What must be proven: Illegal content risk assessment; children's access assessment; safety measures implementation; content moderation decisions; transparency reporting; record-keeping for Ofcom. [99][106][110]
  • Status: Illegal Harms Codes effective March 2025; Children's Safety Codes effective July 2025; transparency notices ongoing. [110]
  • Penalty: Up to GBP 18 million or 10% of global turnover; service blocking; senior manager liability. [106]
  • Source: Osborne Clarke regulatory outlook [99]; UK Gov OSA explainer [106]; Mayer Brown OSA Phase 2 [110]

104. EU Digital Services Act (DSA): Content Moderation Transparency

  • Jurisdiction: European Union
  • Who must comply: Online platforms (VLOPs and VLOSEs especially, but all hosting services).
  • What must be proven: Content moderation policies; terms of service enforcement; notice-and-action handling; transparency reporting; risk assessment for systemic risks; algorithmic transparency for recommender systems; data access for vetted researchers.
  • Status: Fully applicable since 17 February 2024; VLOP/VLOSE obligations since August 2023.
  • Penalty: Up to 6% of global annual turnover; periodic penalty payments; suspension of service.
  • Source: Regulation (EU) 2022/2065 (DSA); European Commission, DSA enforcement

105. EU AI Act: Deepfake Disclosure (Art 50(4))

  • Jurisdiction: European Union
  • Who must comply: Deployers of AI systems that generate or manipulate deepfake content.
  • What must be proven: Clear and distinguishable disclosure that content is artificially generated or manipulated; exceptions for artistic/satirical works (with transparency); exceptions for law enforcement.
  • Status: Applies from 2 August 2026 (the Act entered into force on 1 August 2024).
  • Penalty: Up to EUR 15 million or 3% of global turnover (Art 99(4)).
  • Source: Regulation (EU) 2024/1689; AI Act Art 50; AI Act Art 99; AI Act Art 113

106. US FCC: AI in Political Advertising (Proposed Rules)

107. FTC Endorsement Guides and Consumer Reviews Rule: AI-Generated Reviews and Influencer Content

  • Jurisdiction: United States
  • Who must comply: Advertisers, agencies, influencers, platforms using AI-generated reviews or endorsements.
  • What must be proven: Disclosure of material connections and truthfulness of endorsements (Endorsement Guides); no fake reviews or testimonials, including AI-generated fake reviews, and no buying or selling of fake indicators of social media influence such as bot-generated followers (Consumer Reviews and Testimonials Rule).
  • Status: Endorsement Guides revised in 2023 (published 26 July 2023); Consumer Reviews and Testimonials Rule announced 14 August 2024 and effective 21 October 2024.
  • Penalty: FTC enforcement actions; civil penalties against knowing violators of the Rule; consent decrees; restitution.
  • Source: FTC Endorsement Guides, 16 CFR Part 255 (2023); FTC Consumer Reviews and Testimonials Rule, 16 CFR Part 465 (2024); FTC press release, 14 August 2024

Domain 16: Carbon Credits & Environmental Claims

108. ICVCM Core Carbon Principles: Additionality and Permanence

  • Jurisdiction: Global
  • Who must comply: Carbon crediting programs and credit buyers.
  • What must be proven: GHG reductions are additional (would not have occurred without carbon credit revenues); permanence of reductions; robust quantification; no double counting. [127]
  • Status: CCP framework active; assessments ongoing.
  • Penalty: Loss of CCP label; stranded assets; greenwashing liability.
  • Source: ICVCM CCP Book [127]

109. VCMI Claims Code of Practice: Carbon Credit Claims

  • Jurisdiction: Global
  • Who must comply: Companies making claims based on voluntary carbon credit use.
  • What must be proven: CCP-aligned credits; ambitious decarbonization (1.5C-aligned); transparent reporting; regular progress updates; claim substantiation.
  • Status: First published June 2023; revised several times since (version 3.0 in April 2025).
  • Penalty: Greenwashing litigation; reputational damage.
  • Source: VCMI Claims Code of Practice

110. EU ETS: Emissions Trading System Compliance

  • Jurisdiction: European Union
  • What must be proven: Verified emissions reports; surrender of allowances; compliance with Monitoring and Reporting Regulation (MRR).
  • Status: Phase IV ongoing (2021 to 2030); a revision linked to the 2040 climate target was proposed by the Commission in July 2026 and has not been adopted.
  • Penalty: EUR 100 per tonne CO2e excess emissions, increased annually in line with EU consumer prices; publication of non-compliant operator names.
  • Source: Directive 2003/87/EC (EU ETS); European Commission, EU ETS; European Commission, ETS monitoring, reporting and verification

111. California Cap-and-Trade Program

  • Jurisdiction: California, USA
  • What must be proven: GHG emissions verification; allowance compliance; offset usage (limited to 4% of compliance obligations for 2021 to 2025 emissions and 6% from 2026); third-party verification.
  • Status: Ongoing; linked with Quebec cap-and-trade since 2014. AB 1207 (2025) extended the program through 2045 and renamed it the California Cap-and-Invest Program.
  • Penalty: For an untimely surrender, four compliance instruments must be surrendered for each one missing; suspension of trading privileges.
  • Source: 17 CCR § 95857 (untimely surrender); 17 CCR § 95854 (offset usage limits); California AB 1207 (2025); CARB program linkage

112. SBTi: Science Based Targets initiative Validation

  • Jurisdiction: Global
  • Who must comply: Companies seeking SBTi-validated emissions reduction targets.
  • What must be proven: GHG inventory (Scopes 1, 2, 3); target ambition (1.5C or well-below 2C); decarbonization pathway; annual progress reporting.
  • Status: Active; more than 12,000 companies with science-based targets (SBTi, October 2026).
  • Penalty: Removal from SBTi; reputational damage; investor pressure.
  • Source: Science Based Targets initiative

Cross-Domain and Emerging Items

113. EU Product Liability Directive (2024): AI and Software Defects

  • Jurisdiction: European Union
  • Who must comply: Manufacturers of products incorporating AI or software placed on the EU market.
  • What must be proven: Product safety; defect absence; causal link (or rebuttal of presumptions); evidence disclosure in litigation; online platform liability for presenting products. [119]
  • Status: Directive (EU) 2024/2853 in force since 8 December 2024; transposition by 9 December 2026.
  • Penalty: Full compensation for damages (death, personal injury, property damage); joint and several liability.
  • Source: Directive (EU) 2024/2853; European Commission, liability for defective products; Gibson Dunn PLD analysis [119]

114. Solvency II: ORSA (Own Risk and Solvency Assessment)

  • Jurisdiction: European Union
  • Who must comply: Insurance and reinsurance undertakings under Solvency II.
  • What must be proven: Forward-looking assessment of overall solvency needs; risk profile quantification; stress tests and scenario analyses; Board (AMSB) approval; internal reporting; record of each ORSA. [109]
  • Status: In force since 2016; EIOPA guidelines updated.
  • Penalty: Supervisory measures; capital add-on; restriction of business; withdrawal of authorization.
  • Source: EIOPA ORSA Guidelines [109]; Directive 2013/58/EU (Solvency II application from 1 January 2016)

115. EU Data Act: Data Access and Portability (including IoT)

  • Jurisdiction: European Union
  • Who must comply: Manufacturers of connected products and related services; data holders.
  • What must be proven: User access to generated data; data portability to third parties; switching between data processing services; unfair contractual terms prohibition; cloud interoperability.
  • Status: Regulation (EU) 2023/2854 applicable from 12 September 2025; design duties for data access apply to connected products placed on the market after 12 September 2026; switching charges abolished from 12 January 2027; unfair-terms rules extended to certain older long-term contracts from 12 September 2027.
  • Penalty: Set by each Member State (Art 40); where personal data is involved, data protection authorities can impose GDPR-level fines.
  • Source: Regulation (EU) 2023/2854 (Data Act); European Commission, Data Act explained; Data Act Art 40; Data Act Art 50

116. EU Data Governance Act: Data Altruism and Intermediaries

  • Jurisdiction: European Union
  • Who must comply: Data intermediaries; data altruism organizations; public sector bodies.
  • What must be proven: Neutrality of data intermediaries; data altruism consent management; reuse of public sector data; registration and oversight compliance.
  • Status: Applicable since 24 September 2023; national implementation ongoing.
  • Penalty: Administrative sanctions; registration revocation.
  • Source: Regulation (EU) 2022/868 (Data Governance Act); European Commission, Data Governance Act

117. UK Data (Use and Access) Act 2025: AI Deepfake Offences

  • Jurisdiction: United Kingdom
  • Who must comply: Persons creating, or requesting the creation of, purported intimate images of an adult (including AI-generated deepfakes) without consent.
  • What must be proven: (For enforcement) Creation, or a request for creation, of a purported intimate image of an adult without consent.
  • Status: Royal Assent 19 June 2025; the offences (new sections 66E and 66F of the Sexual Offences Act 2003) in force since 6 February 2026. [99]
  • Penalty: On summary conviction, imprisonment up to the maximum term for summary offences, a fine, or both.
  • Source: Data (Use and Access) Act 2025, s.138; Data (Use and Access) Act 2025, as enacted; Osborne Clarke regulatory outlook [99]

118. Australia: AI Ethics Framework and Voluntary Principles

119. Japan: AI Principles and Governance Guidelines

  • Jurisdiction: Japan
  • Who must comply: Organizations developing or using AI systems in Japan.
  • What must be proven: Human-centric AI; safety and security; fairness and non-discrimination; privacy protection; transparency and explainability; accountability; education and literacy; fair competition.
  • Status: Social Principles of Human-Centric AI (Cabinet Office, March 2019); METI Governance Guidelines for Implementation of AI Principles ver. 1.0 (July 2021) and ver. 1.1 (January 2022); AI Guidelines for Business ver. 1.0 (METI and MIC, April 2024).
  • Penalty: Non-binding; regulatory reference in sectoral guidance.
  • Source: Cabinet Office, Social Principles of Human-Centric AI (2019); METI, Governance Guidelines ver. 1.1 (archived copy); METI, AI Guidelines for Business (April 2024)

120. South Korea: AI Basic Act

  • Jurisdiction: South Korea
  • Who must comply: Providers of high-impact and generative AI systems, including foreign providers above a threshold.
  • What must be proven: Advance notice to users when high-impact or generative AI is used; labelling of generative AI outputs and clear disclosure of deepfake-like outputs; risk management and explanation measures for high-impact AI; designation of a domestic representative by certain foreign providers.
  • Status: Passed by the National Assembly in December 2024, promulgated 21 January 2025 (Act No. 20676) and in force since 22 January 2026.
  • Penalty: Administrative fines up to KRW 30 million; corrective orders.
  • Source: Korea Law Information Center, AI Basic Act; US International Trade Administration, South Korea AI Basic Act

Recent Changes and Deadlines (2024 to 2026)

New Obligations and Deadlines

Change Domain Impact
EU AI Act Art 50 applies from 2 August 2026 (AI Act Art 113; Hunton on the Digital Omnibus on AI) AI Law Transparency obligations on synthetic content, chatbots and deepfakes; systems already on the market have until 2 December 2026 for Art 50(2) marking
EU AI Act Code of Practice on marking and labelling AI-generated content: draft December 2025, final published 10 June 2026 (European Commission) AI Law Voluntary but influential benchmark for Art 50 compliance; multilayered marking requirements
EU DORA fully applicable from 17 January 2025 (EIOPA) Financial/Cyber All EU financial entities now subject to ICT incident reporting, TLPT, and third-party risk management
CMMC 2.0 Phase 1 began 10 November 2025 (DFARS rule; DefenseScoop) Defense CMMC requirements now included in DoD solicitations and contracts
CMMC 2.0 Phase 2 starts 10 November 2026 (C3PAO assessment) (DFARS rule) Defense Third-party certification becomes mandatory for Level 2
EU CRA reporting obligations start 11 September 2026 (European Commission) Cybersecurity 24-hour early warning of actively exploited vulnerabilities and severe incidents for products with digital elements
California CPPA regulations (ADMT, risk assessments, cybersecurity audits) effective 1 January 2026; ADMT compliance from 1 January 2027 (CPPA) Data Protection Risk assessment attestations due 1 April 2028; cybersecurity audits phased 2028 to 2030
California DROP platform launched January 2026 (CPPA) Data Protection Centralized data broker deletion mechanism operational
UK Online Safety Act illegal content duties enforceable from 17 March 2025 (UK Government explainer) Media Integrity Platforms must complete risk assessments and implement safety measures
EUDR large company obligations deferred to 30 December 2026 (European Commission; European Parliament procedure file) ESG/Supply Chain Second 12-month delay adopted December 2025 (Regulation (EU) 2025/2650); micro and small operators to 30 June 2027
EU CSRD Omnibus I approved by Parliament December 2025, adopted February 2026 as Directive (EU) 2026/470 (European Parliament procedure file; Commonwealth Climate Law) ESG Thresholds raised to 1,000+ employees / EUR 450M turnover; simplified ESRS cut mandatory datapoints by about 61%
EU Product Liability Directive transposition deadline 9 December 2026 (Directive (EU) 2024/2853; Gibson Dunn) Product Liability AI and software explicitly in scope; evidence disclosure presumptions favor claimants
Colorado SB 26-189 signed 14 May 2026 (Crowell & Moring) AI Law Repeals the 2024 Colorado AI Act's substantive provisions and replaces them with a narrower ADMT law effective 1 January 2027
FinCEN AML/CFT rule for investment advisers postponed from 1 January 2026 to 1 January 2028 (FinCEN) Financial Covered advisers have two more years before AML program requirements apply
Tennessee ELVIS Act effective 1 July 2024 (Tennessee General Assembly; Regulations.ai) Creative IP AI-focused right-of-publicity law; record labels with exclusive contracts can sue on an artist's behalf
UK Data (Use and Access) Act 2025 Royal Assent 19 June 2025; offence of creating or requesting purported intimate images in force 6 February 2026 (legislation.gov.uk, s.138) Media Integrity Non-consensual intimate deepfakes criminalized
UK Online Safety Act (February 2026): government announced plans to close the AI chatbot loophole and an amendment to the Crime and Policing Bill requiring takedown of non-consensual intimate images within 48 hours (Osborne Clarke) Media Integrity Expanding online safety duties to AI chatbots and intimate deepfakes
Canada AIDA (Bill C-27) died on the Order Paper when the session ended 6 January 2025 (LEGISinfo) AI Law Federal AI legislation halted
OCC Bulletin 2026-13 / SR 26-2 issued 17 April 2026 (OCC; Federal Reserve) Financial Revised model risk management guidance replacing SR 11-7; generative and agentic AI models are outside its scope
Spain's AESIA published 16 guidance documents for EU AI Act compliance in December 2025 (AESIA; Pearl Cohen) AI Law National guidance from an AI supervisory authority on AI Act compliance

Repealed, Withdrawn, or Deferred

Item What Happened Implication
EU AI Liability Directive (AILD) Withdrawal announced in the Commission's February 2025 work programme; formally withdrawn October 2025 (European Parliament Legislative Train) Product liability for AI now handled through revised Product Liability Directive only; no standalone AI liability regime
SEC proposed cybersecurity risk management rule for investment advisers Proposed rule withdrawn 12 June 2025 (Dechert) No dedicated SEC cybersecurity risk management rule for advisers; the FinCEN AML/CFT rule for advisers is postponed to 2028
SEC proposed predictive data analytics/conflict of interest rule Proposed rule withdrawn 12 June 2025 (Dechert) Broker-dealers and advisers do not face the proposed predictive analytics rule, but general fiduciary obligations remain
EU CSRD sector-specific standards Eliminated by Omnibus I (Directive (EU) 2026/470; Commonwealth Climate Law) Simplified reporting; no industry-specific disclosure requirements
EU CSRD reasonable assurance Move to reasonable assurance removed by Omnibus I (Directive (EU) 2026/470) Limited assurance remains the standard; reduces audit intensity but not evidence requirements

Uncertainties

The following items in this catalogue remained uncertain:

Item Uncertainty Flag Level
EUDR country benchmarking system European Parliament objected to the Commission's country classification on 9 July 2025 (European Parliament text TA-10-2025-0149) Medium
FCC AI political advertising rules NPRM adopted July 2024; no final rule published (Federal Register) High
US state AI legislation (beyond those listed) Rapidly evolving; enactment status varies High

Catalogue compiled as of 10 June 2026. Checked against primary sources on 1 October 2026; later changes are noted where they alter an entry.