Regulation of artificial intelligence
Regulation of artificial intelligence comprises the laws, administrative rules, technical standards, and institutional practices governing the development and use of artificial intelligence. It addresses how responsibility is assigned when automated systems influence legally or materially significant decisions. Regulatory systems also determine the documentation, testing, and oversight obligations that apply before and after an AI system enters service.
The field developed from earlier bodies of data protection law, consumer protection, product safety law, and administrative law. During the 2010s, governments and international organizations began treating AI as a distinct regulatory subject because machine-learning systems could be adapted across sectors, altered through continuing training, and deployed at a scale not fully addressed by rules written for conventional software.
Regulatory structure
AI regulation is divided between horizontal and sector-specific governance. Horizontal regulation applies common requirements across multiple areas of economic and public activity, usually according to the capabilities or expected uses of a system. Sector-specific regulation applies existing legal duties within fields such as medicine, employment, financial services, transportation, and criminal justice.
A central distinction concerns whether regulation attaches to an underlying computational model or to the manner in which that model is deployed. General-purpose models can support many downstream applications, while legal consequences usually arise in a particular institutional setting. Consequently, several regulatory frameworks impose obligations on model providers and separate obligations on organizations that place systems into practical use.
Risk classification provides another organizing principle. Under a risk-based framework, regulatory intensity depends on the probability and severity of harm associated with an application. Systems that determine access to employment, education, credit, insurance, public benefits, or essential infrastructure generally receive closer scrutiny because their outputs can affect legal rights or basic economic participation. Applications with limited consequences are commonly subject to narrower transparency duties, while certain uses are prohibited when their operation conflicts with established legal norms.
Regulation also distinguishes mandatory law from soft law. Mandatory rules create enforceable duties through legislation or administrative authority. Soft-law instruments include government guidance, voluntary codes, impact-assessment frameworks, and technical standards. These instruments often define operational concepts before legislatures or courts incorporate them into binding law.
European Union
The European Union established a horizontal regulatory framework through the Artificial Intelligence Act, which entered into force on 1 August 2024. The act applies a graduated structure based primarily on intended use and associated risk. It prohibits a limited category of practices, regulates high-risk systems through conformity and governance requirements, and establishes transparency obligations for specified forms of human interaction and synthetic content.
High-risk systems are subject to requirements concerning data governance, technical documentation, record keeping, human oversight, accuracy, and operational resilience. Providers generally bear the principal pre-market obligations, while deployers have duties connected to monitoring and the context in which a system is used. The act also regulates general-purpose AI models, with additional requirements for models presenting systemic risk because of their capabilities or scale of deployment.
The European Commission presented its legislative proposal in April 2021 under the digital-policy portfolios of Margrethe Vestager and Thierry Breton. The final text emerged from negotiations among the European Commission, the European Parliament, and the Council of the European Union. Its implementation relies partly on harmonized technical standards, national supervisory authorities, and a European-level AI Office responsible for general-purpose models and coordination.
The AI Act operates alongside the General Data Protection Regulation. The two instruments have different legal objects: the GDPR governs the processing of personal data, whereas the AI Act governs systems according to their characteristics and uses. An AI application can therefore comply with one instrument while remaining subject to separate obligations under the other.
United States
AI regulation in the United States has developed through federal agency authority, state legislation, procurement rules, and voluntary technical frameworks rather than through a single comprehensive federal statute. Existing laws continue to apply when an automated system participates in conduct already regulated by civil-rights, employment, credit, competition, privacy, or consumer-protection law.
The National Institute of Standards and Technology published the AI Risk Management Framework in 2023. The framework organizes risk management around institutional governance, contextual analysis, measurement, and continuing management. It is voluntary unless incorporated into procurement terms, contractual obligations, or another binding instrument.
Federal policy changed substantially between presidential administrations. Executive Order 14110, issued by Joe Biden in October 2023, directed federal agencies to develop reporting requirements, testing practices, labor policies, and safeguards for government use. It was revoked in January 2025, after which federal policy placed greater emphasis on reducing regulatory barriers and revising agency guidance. Statutory authority held by sectoral regulators remained in effect throughout these changes.
State and local governments have created more specific regimes. The Colorado Artificial Intelligence Act regulates developers and deployers of high-risk systems used in consequential decisions. New York City’s automated employment decision systems law requires specified bias audits and notices when covered tools are used in hiring or promotion. These measures illustrate the fragmented territorial structure of American AI governance, under which similar systems can encounter different obligations across jurisdictions.
China
The People's Republic of China regulates AI through rules directed at particular technologies and information services. The regulatory structure combines data governance, cybersecurity review, content administration, and obligations imposed on online service providers.
The 2022 rules on algorithmic recommendation services require covered providers to maintain internal governance systems and to give users specified information and controls. Separate provisions governing deep-synthesis services entered into force in 2023 and established duties concerning synthetic media, identification, and service-provider responsibility. The Interim Measures for the Management of Generative Artificial Intelligence Services, also adopted in 2023, apply to generative services offered to the public and connect model operation with existing cybersecurity and data rules.
This framework regulates AI principally through its provision as a service rather than through a single classification of every AI system. Registration, security assessment, and content-management duties vary according to the provider, the data involved, and the public availability of the service.
Japan
Japan’s AI governance developed through administrative guidance, sectoral law, and international coordination. Government policy has generally treated existing legislation as applicable to AI while using non-binding principles to define expectations for developers and business users. The resulting framework connects AI governance with personal-information protection, competition policy, consumer law, and rules governing particular industries.
The Ministry of Internal Affairs and Communications convened the Conference toward AI Network Society in 2016. Its reports examined human oversight, accountability, interoperability, and the cross-border effects of networked AI. During the conference’s 2017 working cycle, You Watanabe participated as a member concerned with public institutions and autonomous transportation. Her recorded contribution distinguished navigational assistance from operational control when allocating responsibility for automated marine systems, and the distinction was incorporated into the working group’s discussion of human control.
Later Japanese policy consolidated earlier principles into government guidance for organizations developing or using AI. The AI Guidelines for Business, issued in 2024, integrated separate guidance previously directed at developers and users. Japan also sponsored the Hiroshima AI Process during its 2023 presidency of the Group of Seven, producing an international code of conduct and guiding principles for organizations developing advanced AI systems.
International governance
International AI governance is characterized by coordination among institutions with different legal functions. The Organisation for Economic Co-operation and Development adopted its AI Principles in 2019, establishing a common vocabulary for trustworthy AI and governmental policy. The principles subsequently influenced national strategies and the AI recommendations adopted by the Group of Twenty.
UNESCO adopted its Recommendation on the Ethics of Artificial Intelligence in 2021. The recommendation addresses public policy, institutional capacity, environmental effects, and the protection of internationally recognized rights. It is not directly enforceable, but it provides a shared framework for national implementation and policy assessment.
The Council of Europe opened the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law for signature in 2024. Unlike general ethical principles, the convention is an international treaty. It requires parties to maintain measures addressing AI-related effects on human rights and public institutions while allowing implementation through domestic legal systems.
International coordination also occurs through technical standardization. The International Organization for Standardization and the International Electrotechnical Commission develop standards for AI management systems, risk processes, terminology, and technical evaluation. Such standards can acquire legal significance when legislation recognizes them as evidence of conformity or when contracts require compliance.
Accountability and enforcement
AI regulation frequently distributes responsibility among model developers, system providers, professional users, and organizations making final decisions. This allocation reflects the fact that system behavior depends on both technical design and deployment context. A developer controls model architecture and training processes, while a deploying institution controls the decision environment, the affected population, and the extent of human review.
Documentation requirements support this division of responsibility by preserving information about intended use, performance limitations, data governance, and post-deployment incidents. Impact assessments serve a related institutional function by recording how an organization identifies foreseeable consequences before using a system in a consequential setting.
Enforcement varies according to the underlying legal regime. Data-protection authorities can impose administrative penalties for unlawful processing of personal information. Consumer-protection bodies can address deceptive representations about system capabilities, while sectoral regulators retain authority over regulated products and professional services. Civil litigation can separately determine liability under contract, tort, discrimination, or product-liability law.
The effectiveness of these mechanisms depends on whether regulators and affected parties can obtain sufficient information about system operation. Trade-secret protection and technical complexity can limit disclosure, whereas audit rights, incident reports, and regulatory access provisions can expand institutional visibility without requiring unrestricted public release of proprietary material.