Artificial Intelligence in Australia
Regulatory guidance / voluntary codes
Law / proposed law in Australia
Australia has not enacted a standalone, comprehensive AI Act or another generally applicable AI-specific statute equivalent to the European Union’s AI Act. The current Australian approach is to apply existing technology-neutral laws, sector-specific regulation, enforceable online-safety instruments, public-sector policy and voluntary responsible-AI guidance. Whether a rule applies turns on the use case, the data and parties involved, the sector, the deployment model and the system’s effects.
The National AI Plan, released in early December 2025, sets the Australian Government’s policy direction around three objectives: capturing the opportunity, spreading the benefits, and keeping Australians safe. For regulation, the Government’s stated preference is to build on existing legal and regulatory frameworks. Targeted intervention may still be considered where existing frameworks cannot adequately address a demonstrated risk.
On 15 July 2026, Prime Minister Anthony Albanese announced proposed Australian Standards for AI and the establishment of an Office of AI within the Department of the Prime Minister and Cabinet. The proposal is expected to be considered by National Cabinet in August 2026, with legislation expected in early 2027, and may result in a more targeted mandatory framework for aspects of AI regulation in Australia.
Existing laws potentially relevant to AI include the Privacy Act 1988 (Cth), the Australian Consumer Law, competition law, copyright and other intellectual-property laws, breach of confidence, contract law, defamation, anti-discrimination law, employment and workplace-surveillance law, work health and safety law, product-liability law, directors’ duties, criminal and cybercrime law, the Online Safety Act 2021 (Cth), the Security of Critical Infrastructure Act 2018 (Cth), administrative law, financial-services and prudential regulation, health and therapeutic-goods regulation, education law and state and territory privacy, health-records, surveillance and public-sector laws. The list is not exhaustive, and no single regime governs all AI activity.
AI.gov.au was published in May 2026 as the consolidated Australian Government portal for responsible-AI guidance, tools and resources. It is operated through the National AI Centre within the Department of Industry, Science and Resources.
Automated decision-making transparency under the Privacy Act
From 10 December 2026, an Australian Privacy Principle (APP) entity must include additional information in its privacy policy under APPs 1.7–1.9 where it has arranged for a computer program to make a decision, or to do a thing substantially and directly related to making a decision, that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about the individual is used in operating that program. The policy must describe the kinds of personal information used, the kinds of decisions made solely by those programs and the kinds of decisions for which those programs do something substantially and directly related to making the decision.
These are transparency obligations. They do not, by themselves, create a general right not to be subject to automated decision-making. The Office of the Australian Information Commissioner (OAIC) consulted on implementation guidance in May 2026; the final guidance should be checked before the provisions commence.
State and territory overlays
State and territory laws can be material, particularly for public-sector, health, education, law-enforcement, surveillance and workplace uses. Relevant overlays may include privacy and health-records statutes, information-sharing laws, surveillance-device and workplace-surveillance legislation, public-records requirements, anti-discrimination law and sector-specific governance duties.
Regulatory guidance / voluntary codes in Australia
The current Australian Government framework for voluntary responsible-AI adoption is the National AI Centre’s Guidance for AI Adoption, which was released in October 2025 and is now hosted through AI.gov.au. It is available in a foundations version for early or lower-risk adoption and an implementation-guidance version for more complex or higher-risk uses. The guidance includes an AI screening tool, AI policy guide and template, AI register template and a glossary. The framework is organised around six essential practices:
- Decide who is accountable;
- Understand impacts and plan accordingly;
- Measure and manage risks;
- Share essential information;
- Test and monitor; and
- Maintain human control.
These practices are voluntary and non-binding guidance. They are designed to help organisations operationalise responsible AI consistently with existing Australian laws and risk-management expectations; they do not create an independent cause of action or substitute for sector-specific legal analysis.
Australia’s AI Ethics Principles were published in November 2019. The Voluntary AI Safety Standard, published in September 2024, later expressed responsible-AI practices through ten voluntary guardrails. The current six-practice Guidance for AI adoption is now the principal economy-wide Australian Government responsible-AI adoption guidance. References to the ten guardrails should therefore be understood as historical rather than as the current government framework.
In September 2024, the Department of Industry, Science and Resources released a proposals paper on mandatory guardrails for AI in high-risk settings. The Government has since stated that it will not proceed with those proposals at this time. The paper is therefore a historical consultation document, not law and not a currently progressing legislative regime. Its suggested high-risk criteria may still be useful as background policy material, but they must not be expressed as mandatory obligations.
The Productivity Commission’s final report, Harnessing data and digital technology, issued on 10 December 2025, recommends that AI-specific regulation be used only as a last resort where existing regulatory frameworks cannot be sufficiently adapted to handle AI related harms and technology-neutral regulation is infeasible or cannot adequately mitigate the risks. That recommendation expressly addresses the previous mandatory-guardrails proposal.
Privacy, automated decision-making and cyber guidance
On 21 October 2024, the OAIC released guidance for organisations using commercially available AI products and separate guidance for developers training or adapting generative-AI models. The OAIC emphasises that Privacy Act obligations may apply to personal information in prompts, training or fine-tuning data, system logs or other records where they contain personal information and outputs, including inferred, inaccurate or artificially generated information where it is about an identified or reasonably identifiable individual. The OAIC advises AI developers to take reasonable steps to ensure accuracy in generative AI models, such as implementing quality assurance controls to mitigate the risk of biased or inaccurate output prior to release. Public availability of data does not, by itself, establish that collection or use for model training is lawful.
The Commonwealth Ombudsman’s Automated Decision-Making Better Practice Guide was updated in March 2025 in collaboration with the OAIC and the Attorney-General’s Department. It addresses legality, procedural fairness, transparency, accountability, reviewability and system governance in government decision-making. In January 2026, the OAIC also reported on agencies’ publication of automated-decision operational information under the Freedom of Information Act 1982 (Cth) Information Publication Scheme.
On 23 May 2025, the Australian Signals Directorate’s Australian Cyber Security Centre and international counterparts published AI data-security guidance. It addresses risks across the AI lifecycle, including data-supply-chain compromise, maliciously modified or poisoned data, data drift, provenance, access controls, secure storage and integrity protection.
Commonwealth Government use
Version 2.0 of the Policy for the responsible use of AI in government took effect on 15 December 2025. It applies to non-corporate Commonwealth entities subject to specified exclusions, including defence and national-intelligence contexts, and corporate Commonwealth entities are encouraged to adopt it. The policy requires, among other things, accountable officials, transparency statements, a strategic AI-adoption position, operational governance, accountable use-case owners, internal use-case registers, staff training and impact assessment. Additional senior governance applies to higher-risk in-scope uses. These are government-policy requirements, not general economy-wide law.
The Australian Government released the AI Plan for the Australian Public Service 2025 on 12 November 2025. It is organised around the pillars of Trust, People and Tools and aims to expand safe AI capability, access and adoption across the Australian Public Service.
Appointed supervisory authority in Australia
Australia has not appointed a single statutory authority with general enforcement jurisdiction over all AI systems. There is no central Australian AI regulator equivalent to an authority administering a comprehensive AI Act.
The Australian AI Safety Institute has been announced as a key National AI Plan action and sits within the Department of Industry, Science and Resources. It replaced the previously planned AI Advisory Body, which was discontinued in February 2026. It is intended to perform technical analysis, monitoring, testing and policy-support functions and to support government agencies and existing regulators. It is not an enforcement regulator and does not displace statutory regulators or alter their legal remits.
Existing regulators continue to supervise AI-related conduct within their statutory mandates. Depending on the use case, they include the OAIC for privacy and freedom of information; the Australian Competition and Consumer Commission (ACCC) for competition and consumer protection; the eSafety Commissioner for online safety; the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) for financial services, markets and prudential and operational-risk matters; the Therapeutic Goods Administration (TGA) and health regulators for therapeutic goods, medical devices and health uses; workplace, safety and anti-discrimination bodies; cyber security and critical-infrastructure authorities; ombudsmen and administrative-review bodies; and state and territory regulators. A single AI deployment may engage several regulators concurrently.
Definitions in Australia
Australian legislation does not presently contain a single, generally applicable statutory definition of ‘AI system’, ‘AI technology producer’, ‘provider’, ‘deployer’ or ‘user’ for all purposes. Definitions can instead arise within particular statutes, contracts, technical standards or sector-specific rules and must be read in their own context.
The National AI Centre’s current terms page uses an Organisation for Economic Co-operation and Development (OECD)-aligned concept of an AI system: a machine-based system that infers from inputs how to generate outputs, such as predictions, content, recommendations or decisions, capable of influencing physical or virtual environments; AI systems differ in autonomy and post-deployment adaptiveness. The guidance also uses the following non-statutory role descriptions:
- AI deployer: an individual or organisation that supplies or uses an AI system to provide a product or service, whether internally or externally.
- AI technology producer: an organisation or entity that designs, develops, tests and provides AI technologies such as models and components.
- AI platform, product or service provider: an organisation or entity that provides products or services using one or more AI systems.
- AI user: an entity that uses or relies on an AI system.
The OAIC distinguishes the underlying model from the broader AI system in which it is deployed. As an explanatory matter, that broader system may also encompass data, software, interfaces and operational processes. Governance controls and human decision points may be important components of a deployment, but they should be identified as contextual system-design features rather than presented as a verbatim OAIC definition.
Prohibited activities in Australia
Australia has not enacted a comprehensive list of prohibited AI practices equivalent to the prohibited-practices regime in the European Union AI Act. AI-enabled conduct may nevertheless be prohibited, restricted or actionable under existing laws.
Existing legal prohibitions and restrictions
Depending on the facts, existing law may prohibit or regulate unlawful collection, scraping, use or disclosure of personal information; misuse of biometric information; serious invasion of privacy; misleading representations and unfair consumer practices; unlawful discrimination; defamation; copyright infringement; breach of confidence; unauthorised surveillance or workplace monitoring; computer offences, malware and unauthorised access; child sexual exploitation material; financial or professional services supplied without required authorisation; unsafe therapeutic goods or medical devices; and unlawful or procedurally unfair government decision-making.
Online-safety codes, standards and enforcement
The Online Safety Act 2021 (Cth) supports mandatory industry codes and standards for sections of the online industry. The Online Safety Codes and Standards regulate online activities involving class 1 and class 2 material. Phase 1, now referred to as the Unlawful Material Codes and Standards, focuses on class 1A and class 1B material, including seriously harmful content such as child sexual exploitation material, pro-terror material, and extreme crime and violence material. Phase 2, now reflected in the Age-Restricted Material Codes, focuses on class 1C and class 2 material, including online pornography and other age-inappropriate material. AI-generated material is treated in the same way where it falls within the relevant classification category. Requirements can apply to service categories that include designated internet services, including high-impact generative-AI designated internet services where covered by the relevant instrument. The precise obligation depends on the relevant code or standard, service category and risk profile.
The OAIC’s Clearview AI determination remains a leading illustration of existing privacy law being applied to AI-enabled facial recognition and large-scale scraping of images from publicly available online sources.
Government announcements about additional or broader restrictions on non-consensual sexually explicit AI-generated content, app distribution or search access should be described as policy proposals unless and until the relevant legislation or instrument is enacted and commenced. They should be kept separate from existing criminal offences, online-safety instruments and regulator enforcement powers.
High-risk AI in Australia
Australia has no generally applicable statutory classification or compliance regime for ‘high-risk AI’. The expression is currently a governance and policy concept, except where a particular sectoral law or instrument independently imposes risk-based obligations.
The September 2024 mandatory-guardrails proposals paper suggested that a future framework could consider adverse impacts on individual rights, health and safety; groups and collective or cultural rights; and the broader economy, society, environment and rule of law, together with the severity and extent of those impacts. Those proposed criteria never became binding law and the proposal is not proceeding at this time.
The current Guidance for AI adoption uses a risk-scaled approach. Its implementation guidance is directed to more complex or higher-risk uses and recommends stronger accountability, impact analysis, risk management, information sharing, testing, monitoring and human control. As a governance matter, indicators warranting enhanced controls may include significant effects on rights or access to services; impacts on vulnerable people or communities; safety-critical functions; opaque or difficult-to-contest outcomes; large-scale or systemic deployment; material cyber or data risks; and serious consequences from error, bias or model failure.
Organisations using AI in higher-impact contexts should, as a governance recommendation rather than a general statutory command, document use cases and accountabilities, conduct proportionate impact and legal assessments, test and monitor performance, manage data quality and provenance, maintain effective escalation and override processes, enable complaints and contestability, and integrate AI controls with existing privacy, cyber, consumer, safety and sectoral compliance systems.
Controls on generative AI in Australia
Australia has not enacted a generally applicable statute devoted exclusively to generative AI. Generative-AI development and use are regulated through existing laws and, where applicable, sectoral instruments including the Online Safety Act codes and standards.
Privacy and data
Developers and deployers should determine whether training, fine-tuning, retrieval-augmented generation, prompting, logging or other records where they contain personal information, or output handling involves personal information; whether collection, use and disclosure are lawful and fair; whether an APP notice or privacy-policy update is required; whether information is accurate and secure; whether cross-border disclosure rules are engaged; and whether access, correction, retention and deletion obligations apply. Public accessibility does not automatically make data lawful to collect or use for training.
Consent is not universally required for every handling of personal information under the Privacy Act. An entity should determine whether consent is required or relied upon, particularly for sensitive information or secondary uses, and whether another applicable permission or exception is available. The analysis depends on the relevant Australian Privacy Principle and the facts.
The OAIC treats personal information entered into an AI system and personal information contained in system output as potentially regulated, including inferred, inaccurate or hallucinated information about an identified or reasonably identifiable person. The OAIC recommends particular caution with sensitive information and publicly available generative-AI tools.
Cyber security and operational control
AI-specific security analysis should address access control, data leakage, prompt injection, insecure output handling, model inversion or extraction, maliciously modified or poisoned data, supply-chain compromise, model drift, logging, provenance, change control and incident response. Organisations subject to critical-infrastructure, prudential or other cyber security regimes must integrate AI controls with those binding requirements rather than treat AI governance as a standalone exercise.
AI-generated content transparency
The National AI Centre first published voluntary best-practice guidance on AI-generated content transparency, covering labelling, watermarking and metadata recording, on 28 November 2025. The current version, published on 22 April 2026, recommends proportionate disclosure methods such as labelling, watermarking and metadata or provenance measures. This is voluntary best-practice guidance, not a generally applicable statutory labelling regime. Separate binding obligations may arise under consumer, electoral, online-safety, privacy or sector-specific law depending on the content and context.
Enforcement / fines in Australia
Australia has no general, cross-economy AI Act enforcement or penalty regime. AI-specific or AI-relevant obligations may nevertheless be enforced under existing legislation and sectoral instruments. The regulator, cause of action, available remedy and maximum penalty depend on the particular provision, the conduct, the date of contravention and the defendant.
- A serious or repeated interference with privacy under the Privacy Act can attract a maximum civil penalty of AUD 2.5 million for a person other than a body corporate. For a body corporate, the maximum is the greater of AUD 50 million, three times the value of the benefit reasonably attributable to the conduct, or, if that value cannot be determined, 30% of adjusted turnover during the breach turnover period. Other Privacy Act contraventions have different consequences. The statutory tort for serious invasions of privacy also creates a private court pathway, subject to its elements, remedies, defences and exemptions.
- Competition and consumer law. AI-related representations, sales practices or product conduct may engage the Australian Consumer Law and competition law. For many offence and civil-penalty provisions, the maximum corporate penalty for conduct on or after 28 March 2026 is the greater of AUD 100 million, three times the reasonably attributable benefit where that value can be determined, or 30% of adjusted turnover during the breach turnover period where it cannot. Other provisions have lower maxima. The general prohibition on misleading or deceptive conduct under the Australian Consumer Law is not itself a pecuniary-penalty provision, although related conduct may contravene civil-penalty provisions and injunctions, damages, compensation and other remedies may be available.
- Online safety. Non-compliance with a standard, or with a direction to comply with a code, can result in civil-penalty proceedings. The maximum identified in eSafety’s regulatory guidance is 30,000 penalty units per contravention for an individual and five times that amount for a corporation. Different Online Safety Act contraventions may carry different maxima.
- Other regimes. AI uses may also attract regulatory orders, licence consequences, remediation, compensation, injunctions, enforceable undertakings, disqualification, criminal liability or judicial and merits review under financial-services, health, workplace, discrimination, cybercrime, critical-infrastructure, administrative-law and other sectoral regimes. Penalty figures should be rechecked on the publication date and should never be applied without identifying the specific contravention.
User transparency in Australia
Transparency is a central feature of Australian responsible-AI policy, but its legal source and effect vary. The current Guidance for AI adoption recommends sharing essential information about AI systems and maintaining human control. The National AI Centre’s AI-generated content guidance recommends proportionate disclosure, labelling, watermarking and provenance measures. These recommendations are voluntary unless another law or instrument makes disclosure mandatory in the relevant context.
Under the Privacy Act, APP entities may need to explain personal-information handling through privacy policies and APP 5 collection notices and to facilitate access and correction. From 10 December 2026, the specific automated decision-making privacy-policy disclosures described in the Automated decision-making transparency under the Privacy Act section will apply to qualifying arrangements. The OAIC’s final implementation guidance should be checked before commencement.
For Commonwealth Government entities within scope, the responsible-use policy requires transparency statements, strategic and operational governance, use-case accountability, registers, training and impact assessment. Administrative law may also require lawful authority, procedural fairness, reasons and reviewability. The OAIC’s January 2026 Information Publication Scheme report recommends improved publication of operational information about automated decision-making by government agencies.
Fairness / unlawful bias in Australia
Australia does not have a single AI fairness statute. Unfair or biased AI outcomes can nevertheless engage Commonwealth, state or territory anti-discrimination laws, employment law, consumer protection, privacy, credit, education, health, administrative law and other sector-specific duties. The applicable protected attributes, tests, exemptions, remedies and responsible parties depend on the relevant statute and context.
The current Guidance for AI adoption addresses fairness through impact analysis, stakeholder engagement, risk management, testing, monitoring and human control. The OAIC identifies bias and discrimination risks where data are incomplete, inaccurate, unrepresentative or encode historical disadvantage. These are guidance propositions unless linked to a specific legal obligation.
As a governance matter, organisations deploying higher-impact AI should test for discriminatory or materially inaccurate outcomes before and after deployment; assess performance across relevant cohorts; document limitations; monitor complaints and drift; maintain escalation and contestability pathways; and ensure that human reviewers have the authority and information needed to correct inappropriate outcomes.
Human oversight in Australia
The sixth essential practice in the current Guidance for AI adoption is to maintain human control. The guidance recommends designing systems and operating processes so that people can supervise, intervene, escalate, override or stop AI use where appropriate to the system’s risk and impact.
Human involvement should be meaningful rather than ceremonial. Reviewers need appropriate expertise, authority, information, independence and time; they should understand relevant system limitations and avoid merely endorsing an automated result. The appropriate form of oversight may range from periodic monitoring for low-impact tools to mandatory approval, dual control, escalation or prohibition of autonomous action in higher-impact contexts.
For government decision-making, human oversight must be assessed alongside statutory authority, lawful delegation, procedural fairness, reasons, evidence, recordkeeping and review rights. For private-sector systems, the necessary controls depend on the consequences of the use case and the privacy, consumer, safety, discrimination, professional, cyber security and sectoral laws engaged. Human review does not cure an otherwise unlawful system or decision.
The current Australian Government framework for voluntary responsible-AI adoption is the National AI Centre’s Guidance for AI Adoption, which was released in October 2025 and is now hosted through AI.gov.au. It is available in a foundations version for early or lower-risk adoption and an implementation-guidance version for more complex or higher-risk uses. The guidance includes an AI screening tool, AI policy guide and template, AI register template and a glossary. The framework is organised around six essential practices:
- Decide who is accountable;
- Understand impacts and plan accordingly;
- Measure and manage risks;
- Share essential information;
- Test and monitor; and
- Maintain human control.
These practices are voluntary and non-binding guidance. They are designed to help organisations operationalise responsible AI consistently with existing Australian laws and risk-management expectations; they do not create an independent cause of action or substitute for sector-specific legal analysis.
Australia’s AI Ethics Principles were published in November 2019. The Voluntary AI Safety Standard, published in September 2024, later expressed responsible-AI practices through ten voluntary guardrails. The current six-practice Guidance for AI adoption is now the principal economy-wide Australian Government responsible-AI adoption guidance. References to the ten guardrails should therefore be understood as historical rather than as the current government framework.
In September 2024, the Department of Industry, Science and Resources released a proposals paper on mandatory guardrails for AI in high-risk settings. The Government has since stated that it will not proceed with those proposals at this time. The paper is therefore a historical consultation document, not law and not a currently progressing legislative regime. Its suggested high-risk criteria may still be useful as background policy material, but they must not be expressed as mandatory obligations.
The Productivity Commission’s final report, Harnessing data and digital technology, issued on 10 December 2025, recommends that AI-specific regulation be used only as a last resort where existing regulatory frameworks cannot be sufficiently adapted to handle AI related harms and technology-neutral regulation is infeasible or cannot adequately mitigate the risks. That recommendation expressly addresses the previous mandatory-guardrails proposal.
Privacy, automated decision-making and cyber guidance
On 21 October 2024, the OAIC released guidance for organisations using commercially available AI products and separate guidance for developers training or adapting generative-AI models. The OAIC emphasises that Privacy Act obligations may apply to personal information in prompts, training or fine-tuning data, system logs or other records where they contain personal information and outputs, including inferred, inaccurate or artificially generated information where it is about an identified or reasonably identifiable individual. The OAIC advises AI developers to take reasonable steps to ensure accuracy in generative AI models, such as implementing quality assurance controls to mitigate the risk of biased or inaccurate output prior to release. Public availability of data does not, by itself, establish that collection or use for model training is lawful.
The Commonwealth Ombudsman’s Automated Decision-Making Better Practice Guide was updated in March 2025 in collaboration with the OAIC and the Attorney-General’s Department. It addresses legality, procedural fairness, transparency, accountability, reviewability and system governance in government decision-making. In January 2026, the OAIC also reported on agencies’ publication of automated-decision operational information under the Freedom of Information Act 1982 (Cth) Information Publication Scheme.
On 23 May 2025, the Australian Signals Directorate’s Australian Cyber Security Centre and international counterparts published AI data-security guidance. It addresses risks across the AI lifecycle, including data-supply-chain compromise, maliciously modified or poisoned data, data drift, provenance, access controls, secure storage and integrity protection.
Commonwealth Government use
Version 2.0 of the Policy for the responsible use of AI in government took effect on 15 December 2025. It applies to non-corporate Commonwealth entities subject to specified exclusions, including defence and national-intelligence contexts, and corporate Commonwealth entities are encouraged to adopt it. The policy requires, among other things, accountable officials, transparency statements, a strategic AI-adoption position, operational governance, accountable use-case owners, internal use-case registers, staff training and impact assessment. Additional senior governance applies to higher-risk in-scope uses. These are government-policy requirements, not general economy-wide law.
The Australian Government released the AI Plan for the Australian Public Service 2025 on 12 November 2025. It is organised around the pillars of Trust, People and Tools and aims to expand safe AI capability, access and adoption across the Australian Public Service.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
The Brazilian AI Strategy published in 2021 states that AI should benefit people and the planet, driving inclusive growth, sustainable development and well-being. It also states that AI systems should be designed in a manner that respects the rule of law, human rights, democratic values and diversity, and should include appropriate safeguards to ensure a fair society. The strategy also makes it clear that organisations and individuals who play an active role in the AI lifecycle should commit to transparency and responsible disclosure in relation to AI systems and that AI systems should operate in a robust, safe and protected manner.
In addition, in 2026 the Ministry of Justice and Public Security, through the National Secretariat for Digital Rights (Sedigi), launched a public consultation on the Guide to the Ethical Use of Artificial Intelligence for Brazilian Citizens, aimed at improving public understanding of AI and its functioning, benefits, limitations, risks, rights and responsibilities, in plain and accessible language, to promote the conscious, safe and responsible use of AI tools by the general public. The initiative was developed in partnership with the University of São Paulo (USP) and with the support of the United Nations Educational, Scientific and Cultural Organization (UNESCO). It forms part of the Brazilian Artificial Intelligence Plan (PBIA), which serves as the federal government's principal policy framework for the development and responsible use of artificial intelligence technologies in Brazil.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Bulgaria
In December 2020, the Council of Ministers in Bulgaria adopted a Concept for the Development of the Artificial Intelligence in Bulgaria until 2030 (Concept). The Concept is a national strategic policy document which outlines the main prerequisites and challenges the country is facing in view of the development and implementation of AI systems. The Concept also comments on the different economic sectors where implementation of AI would be beneficial (e.g. science, education, public administration, electronic healthcare, etc.). In addition, the Concept sets the main strategic objectives to be followed. It also demonstrates intention to facilitate and encourage business and research activities in the field of AI and to stimulate the natural course of development of the technology in Bulgaria by limiting the administrative burden. However, it is noteworthy that this document is outdated and adopted by a prior administration, whose policy may not necessarily be furthered.
In September 2023, the Canadian Minister of Innovation, Science and Industry announced a Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems (Voluntary Code) to provide Canadian companies with common standards until formal regulation is in effect, with the aim of enabling them to demonstrate voluntarily that they are developing and using generative AI systems responsibly. The Voluntary Code sets out identified measures to which companies must adhere when nominating themselves as signatories to it relating to the following:
- Accountability – Firms understand their role with regard to the systems they develop or manage, put in place appropriate risk management systems, and share information with other firms as needed to avoid gaps.
- Safety – Systems are subject to risk assessments, and mitigations needed to ensure safe operation are put in place prior to deployment.
- Fairness and Equity – Potential impacts with regard to fairness and equity are assessed and addressed at different phases of development and deployment of the systems.
- Transparency – Sufficient information is published to allow consumers to make informed decisions and for experts to evaluate whether risks have been adequately addressed.
- Human Oversight and Monitoring – System use is monitored after deployment, and updates are implemented as needed to address any risks that materialize.
- Validity and Robustness – Systems operate as intended, are secure against cyber attacks, and their behaviour in response to the range of tasks or situations to which they are likely to be exposed is understood.
The level of obligation in respect of each of the measures to be undertaken varies depending on whether a signatory is either a developer or a manager of a generative AI system and whether or not the system is available for public use or not.
In December 2023, Canadian privacy regulators announced Principles for responsible, trustworthy and privacy-protected generative AI technologies (Privacy Principles) to help organisations that are developing, providing, or using generative AI technologies apply key Canadian privacy principles:
- Legal Authority and Consent – Organisations should ensure they have legal authority for collecting and using personal information (and when consent is the legal authority, it should be valid and meaningful).
- Appropriate Purposes – Organisations should only collect, use, and disclose personal information for appropriate purposes.
- Necessity and Proportionality – Organisations should establish the necessity and proportionality of using generative AI, and of personal information within generative AI, to achieve the intended purposes.
- Openness – Organisations should be open and transparent about the collection, use, and disclosure of personal information and the potential risks to individuals’ privacy.
- Accountability – Organisations should establish accountability for compliance with privacy legislation and principles and make AI tools explainable.
- Individual Access – Organisations should facilitate individuals’ right to access their personal information by developing procedures that enable it to be meaningfully exercised.
- Limiting Collection, Use, and Disclosure – Organisations should limit the collection, use, and disclosure of personal information to only what is needed to fulfil the explicitly specified, appropriate identified purposes.
- Accuracy – Organisations should ensure that personal information is as accurate, complete, and up-to-date as is necessary for purposes for which it is to be used.
- Safeguards – Organisations should establish safeguards to protect personal information and mitigate potential privacy risks.
In May 2024 the Chilean government introduced the latest version of its AI National Policy (Policy) setting out objectives and priority actions that the nation must undertake over the following decade. The Policy centres around three cross-cutting principles:
- Ethical and responsible use of people-centred AI.
- AI serving sustainable development.
- AI in international and multi-stakeholder articulation.
The Policy is structured along three axes:
- Enabling Factors: This refers to the structural elements that enable the existence and deployment of AI, such as the development of tools, technological infrastructure and data.
- Development and Adoption: This covers the space where AI is created and deployed, i.e. those who generate, provide and demand its different applications and techniques, including academia, the state, the productive sector and civil society.
- Governance and Ethics: This addresses the new discussions and challenges that have arisen regarding the interaction between people and AI. It includes elements to advance in the development, use and implementation of AI systems, to protect people from their potential impacts and to support the social, economic and environmental transformations associated with these systems.
Appointed Supervisory Authority
Article 14 of the Chilean AI Bill creates the ‘AI Advisory Board’ as an advisory and permanent body that shall advise the Minister of Science, Technology, Knowledge and Innovation (Science Ministry) on matters related to the development, promotion and continuous improvement of AI systems. The main duties of this entity are to:
- propose to Science Ministry a list of 'High-Risk' and 'Limited-Risk' AI systems; as amended by the Government indications, Article 32 requires that such list shall be reflected in the implementing regulation;
- advise the Science Ministry, and other relevant ministries, regarding the scope and compliance with the regulation applicable to AI system operators, without prejudice to sectoral authorities’ powers;
- submit to the Science Ministry a proposal regarding guidelines for the development of controlled test sites for AI systems, as well as for compliance and accountability standards;
- collaborate with the Science Ministry in promoting AI literacy and citizen outreach;
- evaluate, every five years, the implementation of the law and its regulation; and
- publish Board minutes on the Science Ministry’s website.
Article 24 of the Chilean AI Bill states that the ‘Data Protection Agency’ (Agency) shall be responsible for the enforcement of the law, sanctioning law infringements. The Government indications added a specific judicial claims mechanism against fines imposed by the Agency.
In addition, Article 23 makes the Science Ministry responsible for promoting, designing and preparing AI literacy and citizen outreach programmes, including tools to explain the technology and educate the public on rights, obligations, advantages, potential and risks associated with AI uses.
In addition to enacting laws specifically pertaining to AI-related technologies, the PRC also regulates AI through the implementation of recommended national standards and regulatory guidance:
- Basic Security Requirements for Generative Artificial Intelligence Service (GB/T 45654-2025): sets out requirements regarding training data security, model security, and technical measures that AI services providers should implement during their operation. It also provides guidance on how to conduct administrative filings with the Chinese authorities, which may be necessary for providing AI services to external users.
- Security Specification for Generative Artificial Intelligence Pre-Training and Fine-Tuning Data (GB/T 45652-2025) (AI Data Standard): sets out the security and data privacy requirements for pre-training and fine-tuning data in the context of generative AI.
- Generative Artificial Intelligence Data Annotation Security Specification (GB/T 45674-2025): sets out specific rules and procedures on data annotation.
- Basic Security Requirements for Generative Artificial Intelligence Service (TC260-003/2004): a set of technical standards for generative AI. It provides guidelines for generative AI service providers in relation to training data, algorithms and content generated by AI and requires service providers to implement assessments and measures to mitigate risks associated with generative AI.
- In April 2026, the National Cybersecurity Standardisation Committee (TC260) opened a public consultation on draft Ethical Security Guidelines for Artificial Intelligence Applications 1.0, with the consultation period closing on 26 April 2026. The draft guidelines aim to establish ethical and safety principles for AI systems and identify five primary risk categories associated with AI, including weakening human control and discrimination. They propose six core principles: people-centred design, safety and controllability, fairness and justice, transparency, collaborative governance and inclusive benefit-sharing. Requirements for developers include maintaining audit logs, establishing incident recall mechanisms and ensuring privacy and fairness as defaults, while prohibiting the development of AI aimed at replacing human jobs. Service providers must conduct ethics impact assessments and provide users with options to refuse or cease AI use, while users are advised to maintain independent judgment and avoid using AI for harmful purposes.
- In July 2026, TC260 issued security guidelines for the deployment and use of intelligent agents, targeting organisations that deploy or utilise large-model-based AI agents (whether open-source or commercial). These guidelines prescribe security measures across five lifecycle phases: during assessment, organisations are advised to select agents with built-in protections such as sandboxing and audit logging; in the preparation phase, they should source materials from verified channels and use filed large models; during deployment, organisations are recommended to apply least-privilege access, block external network exposure and predefine high-risk operations that require confirmation; in usage, measures include minimising personal data shared with agents, auditing exposed interfaces and reviewing long-term memory files; and at decommissioning, organisations must fully wipe data and revoke credentials. The guidelines also recommend maintaining an internal agent asset register, monitoring for unapproved agents and training staff on risks such as prompt injection and data leakage.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
Guidance has so far been issued primarily by the Croatian Personal Data Protection Agency (AZOP).
In October 2025, AZOP published a set of frequently asked questions on the interplay between the EU AI Act and data protection rules. In May 2026, it followed up with comprehensive guidelines titled ‘Personal Data Protection and Artificial Intelligence’, aimed at organisations developing, training, testing, integrating or using AI systems. The guidelines address practical questions arising in AI projects, including when the General Data Protection Regulation (GDPR) applies to AI models and systems, the allocation of controller and processor roles, legal bases, data protection by design, transparency towards data subjects, the exercise of data subjects’ rights, data protection impact assessments and security measures, with particular attention to model anonymity, risks associated with large language models, attacks on AI models and systems, and privacy-enhancing technologies.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
The Office of the Commissioner of Communications operates the official AI Cyprus portal, which provides information and resources concerning the implementation of the EU AI Act in Cyprus, including the national governance framework, competent authorities, compliance requirements and the submission of complaints.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in the Czech Republic
The Czech Government has approved the 'National Strategy for Artificial Intelligence of the Czech Republic 2030', which provides a strategic framework for the development and use of trusted AI in the Czech Republic, and which will put the Action Plan into practice. This plan will include specific initiatives such as grant programmes, manuals for businesses, retraining courses and the introduction of new AI solutions. Its current form has been prepared by the MIT, in particular with the promoters of each key area, and will be submitted to the government as part of the Digital Czech Republic Implementation Plans.
One of the areas of focus is the legal and ethical aspects of AI, in relation to which the government of the Czech Republic commits to, among other things:
- Support the development of non-binding soft-law tools for artificial intelligence in the private and public spheres to ensure its ethical use;
- Provide advice and recommendations on human rights standards and ethical approaches to the use of AI, particularly in public administration; and
- Provide consideration of the environmental impacts of AI systems in national policies, including emphasis on energy and, where appropriate, resource efficiency of AI systems.
On 20 February 2026, the Czech Government published an Economic Strategy entitled 'Czech Republic: A Country for the Future 2.0' according to which, the Czech Republic aims to become Central Europe’s AI hub. The three main goals set for 2030 include:
- Talent: doubling the number of highly qualified AI specialists and data scientists in the Czech Republic, e.g., by accelerating the visa application process or through specialised study programmes;
- Infrastructure: building adequate supercomputing and data capacity for Czech companies and research at the same or at the more favourable price than in neighbouring countries, e.g., within the Euro-network of AI Factories / EuroHPC; and
- Public administration: becoming one of Europe’s leaders in AI implementation in public administration (top five), through pilot projects, the establishment of a central AI component repository, and central coordination.
Furthermore, the Czech Republic pledges to create opportunities for the broader application of AI in businesses and to support the development of AI startups.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Denmark
In March 2019, the Danish government – led by the Ministry of Finance and the Agency for Digital Government – launched Denmark’s first national AI strategy. The strategy emphasizes an ethical and human-centered basis for AI, while highlighting the potential of AI to support research, innovation, and public services.
In January 2024, the Agency for Digital Government published three practical guides aimed at public authorities, businesses, and citizens. These guides support the responsible use of generative AI by offering advice on safe and ethical practices, including transparency, data protection, legal compliance, and digital literacy. The guides are designed to evolve over time, incorporating input from both public and private stakeholders.
On 8 February 2024, the Danish Government and all parties in the Danish Parliament (Folketinget) adopted a digitalisation strategy introducing two key AI initiatives: stragetgic efforts for AI and a regulatory sandbox for AI.
- The strategic efforts aim to establish an ambitious and responsible framework for AI use in Denmark. This includes investments in Danish language resources for training language models and the potential development of a Danish language model.
- The regulatory sandbox for AI aims to create a clear legal framework for the use of AI, which is considered a prerequisite for responsible deployment.
In March 2024, the regulatory sandbox for AI was officially launched, jointly managed by the Danish Data Protection Agency and the Agency for Digital Government. It provides free, practical guidance on GDPR and selected aspects of the EU AI Act to both public and private actors. The sandbox supports responsible and lawful AI development by helping organizations clarify legal requirements early and bring AI projects to market responsibly.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Estonia
In Estonia, the Ministry of Economic Affairs and Communications, the Ministry of Justice and Digital Affairs and the Ministry of Education and Research have published an Action Plan on Artificial Intelligence for the years 2024–2026 (Action Plan). The Action Plan serves as Estonia's national AI strategy within the framework of the EU's coordinated action plan on AI. The Action Plan provides an overview of the activities planned for the coming years to further increase the adoption of AI-based solutions in Estonia. It aims to enhance the personalisation, user-friendliness and accessibility of e-services, and the efficiency of the state. It covers the development and/or implementation of AI in the public and private sectors, as well as in education and research, along with the necessary legislative changes for 2024–2026. The Action Plan also envisaged amendments to the Administrative Procedure Act to create general grounds and conditions for issuing automatic administrative acts and carrying out automatic administrative operations. This work has since progressed into a draft law amending the Administrative Procedure Act and the Public Information Act, which was adopted in June 2026. Although some laws in Estonia already enable the issuing of automatic administrative acts, Estonia lacks a uniform regulation. Such laws include the Taxation Act, Environmental Charges Act and Unemployment Insurance Act. Additionally, the Action Plan provides that the EU AI Act shall be transposed to Estonian law where relevant.
Furthermore, the Estonian Government’s coalition agreement includes several AI-related policy tasks across sectors, including defence, education, copyright and healthcare. These include, for example, the establishment of the Defence Forces’ Force Transformation Command for AI, electronic warfare, drones and other emerging technologies, the launch of the TI-Hüpe education programme and copyright guidance for the AI era.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Finland
In Finland, the national implementation of the AI Act is still underway, and therefore, there are not many official guidelines available yet. However, some reports and guidelines have been published, which are presented below.
In 2021, the Non-Discrimination Ombudsman issued its observations on artificial intelligence’s effects on equality. The Ombudsman discusses both risks of discrimination related to the use of artificial intelligence and the possibilities of AI to promote the realisation of equality. The Ombudsman also raises the need for proactive impact assessment and supervision in the use of artificial intelligence. Use of different AI systems and algorithmic decision-making is increasing constantly, so the significance of questions of equality in their utilisation grows also.
In 2022, the Ministry of Economic Affairs and Employment of Finland issued a report titled Finland as a leader in the twin transition – Final report of the Artificial Intelligence 4.0 programme. The report states that the vision of the programme is to make Finland a winner in the twin transition, which describes a simultaneous digital and green transition. To achieve this vision, three areas of development were identified: (i) strengthening high-level research on key technologies as well as development activities and investments; (ii) increasing the adoption of digital capabilities and technologies that accelerate the dual transition in industrial SMEs; and (iii) making Finland an international frontrunner in the twin transition.
In 2023, the Ministry of Economic Affairs and Employment of Finland issued a study on Impacts of the EU’s Proposed Regulation of Artificial Intelligence on the Business Environment of Finnish Companies. The study focused on the assessment of regulatory burden, changes in business opportunities, and clarity of the requirements of the AI Act.
Further, in May 2025 the Finnish Data Protection Ombudsman has issued guidelines on ensuring data protection in the development and use of AI systems. The guidelines explain how organisations can ensure that personal data is processed lawfully in AI systems. The guidelines issued are not exhaustive, and organisations are still always expected to assess the requirements arising from legislation case by case.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in France
In France, many governmental reports and independent authorities’ guidelines have been issued on AI. The main ones impacting the AI framework are as follows.
- In September 2017, Deputy Cédric Villani was tasked with leading a mission to implement a French and European AI strategy. This mission was presented in a report named ‘Making sense of artificial intelligence’ (Villani Report), which covers various aspects of AI, including economic policy, research, employment, ethics and social cohesion. Additionally, five annexes focus on the risks and opportunities of AI in specific areas: education; health; agriculture; transport; and defence and security. This report led to the French government building a national AI strategy in 2018, which was last updated on 7 February 2025.
- In June 2020, the French Banking Authority (ACPR) issued a study on the 'Governance of artificial intelligence algorithms in the financial sector’ (ACPR AI Governance Study). This study highlights the need for AI algorithm evaluation and governance.
- In February 2026, the French Autorité des Marchés Financiers (AMF), the authority in charge of regulating the French financial market, published an in-depth study over the uses, benefits and risks associated with artificial intelligence by financial market participants. The study highlights the importance of robust AI governance frameworks while noting that regulated entities increasingly rely on internal AI policies addressing data governance, human oversight, transparency and compliance with emerging AI-related regulatory requirements.
- On 7 April 2022, the French national advisory commission on human rights (CNCDH) issued an ‘Opinion on the impact of AI on fundamental rights’ (CNCDH Opinion), which urges public authorities to establish a strong legal framework for AI. The document highlights how algorithms can perpetuate human biases and recommends measures for ensuring algorithmic transparency and fairness.
- On 13 March 2024, the French Artificial Intelligence Commission (governmental body) published a report 'AI: our ambition for France' (French AI Commission Report) containing 25 recommendations to make France a major player in the AI technological revolution, notably by facilitating access to personal data (in particular health data) and adopting an ‘AI exception’ for public research.
- On 28 November 2024, the French Senate’s Office for the Evaluation of Scientific and Technological Choices (OPECST) issued a wide‑ranging report called ‘ChatGPT, and after? Assessment and perspectives of artificial intelligence’ that traces the evolution and mechanics of AI (from symbolic systems to deep learning and Transformer‑based ‘foundation models’), assesses economic, societal, cultural, and security implications, benchmarks France’s national AI strategy against roughly 20 other jurisdictions, and surveys emerging models of national, EU, and global governance. The report culminates in 18 recommendations, including several to be advanced at forthcoming international AI fora, emphasising innovation, risk management, transparency, and democratic oversight to ensure AI serves the public interest while safeguarding sovereignty and fundamental rights (Senate Report).
The French national data protection authority (CNIL) has issued non-binding AI fact sheets (CNIL AI Fact Sheets) that focus on the development phase of AI systems and models and highlight the necessity to comply with privacy requirements during all stages of the development of AI systems. CNIL has also built tools and best practices to be followed for AI tools and models to be used in compliance with privacy laws, e.g., the risk assessment before the use of an AI system (CNIL AI Risk Assessment). In addition, the CNIL has published guidance on the use of generative AI systems with a related Q&A (CNIL Generative AI Guidance) that aims to help organisations deploy such systems responsibly.
The French agency on security of IT systems (ANSSI) published guidance on 29 April 2024 setting out security recommendations for generative AI systems (ANSSI Generative AI Security Guidance). This guidance sets out good practices to implement on the three stages of generative AI lifecycle: training; integration and deployment; and operational production. Such practices should be adapted to the choice of providers (for hosting, training, testing, etc.) and the sensitivity of the data used, as well as the criticality of the intended use case of the AI system.
On 12 July 2024, the French Competition Regulator (Autorité de la Concurrence) issued an opinion on the competitive functioning of the generative artificial intelligence sector. This opinion focuses on strategies by major digital players to consolidate market power in the design, training, and specialisation of large language models. Following this opinion, the Authority announced that it is opening an ex officio investigation to analyse the competitive functioning of the conversational agents (or chats) sector. The Authority also intends to examine the new issues that are emerging, particularly those linked to the use of conversational agents in the online retail sector, also referred to as ‘agentic commerce’, by launching in 2026 a public consultation.
The French High Council for Literary and Artistic Property (CSPLA), which acts as an observatory for the exercise and enforcement of copyright and neighbouring rights, was tasked with clarifying the EU AI Act transparency requirements for AI model providers (Article 53). Its findings were made public via a report published on 11 December 2024 (CSPLA Report).
In 2025, the CIGREF (a non-profit association bringing together major French companies and administrations) issued a set of five guides focusing on helping large organisations adopt AI responsibly and in compliance with the EU AI Act, offering practical guidance on key obligations, governance structures, legal issues, and contractual impacts. They also provided best practices and enterprise feedback on generative AI adoption, highlighting organisational readiness, risks, and responsible use patterns.
In February 2026, the French Government’s Information Service (SIG) published practical guidance for public sector communications teams on the responsible use of generative AI. It focuses on transparency, human oversight, data protection, accessibility, intellectual property and digital sovereignty.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Greece
In November 2024, the High-Level Advisory Committee on Artificial Intelligence, established in November 2023 under the supervision of the Greek Prime Minister, published Greece’s national AI strategy, titled ‘A Blueprint for Greece's AI Transformation’ (the AI Strategy).
The AI Strategy sets out a comprehensive set of principles for ensuring that AI systems are effective and are developed and used responsibly throughout their lifecycle. These principles:
- stress the importance of first confirming that AI is truly necessary for the given solution, ensuring that the project is feasible, and using high-quality data for training algorithms;
- emphasize the need for clear processes and rules governing data access, alignment among stakeholders, and defining success through key performance indicators and risk-value assessments;
- highlight the importance of appropriate infrastructure, organisation, and workforce for the deployment of AI, while continually evaluating the interpretability and added value of the AI system; and
- address crucial aspects of responsible AI, including monitoring security risks, complying with legal and data regulations, ensuring ethical alignment, and fostering environmental sustainability throughout the AI system’s development and implementation.
Looking ahead, the report ‘Generative AI Greece 2030’ examines the future landscape of generative AI in Greece by 2030. Authored by the National Centre for Social Research (EKKE) and the National Centre for Scientific Research, with support from the Special Secretariat of Foresight, the report proposes co-creating voluntary guidelines for public authorities, social partners and other stakeholders. These guidelines aim to align AI development with ethical principles and reduce the risk of socio-economic divides arising from unequal access to AI. The report also calls for ethical oversight mechanisms that promote societal values, safety, transparency, innovation and human welfare, while tackling digital inequality and algorithmic discrimination.
In the healthcare sector, the National Commission for Bioethics & Technoethics of Greece has issued its ‘Opinion on the Applications of Artificial Intelligence in Health in Greece’. This opinion sets out guidelines requiring AI applications to adhere to fundamental ethical principles, including:
- Autonomy: respecting patients' right to informed decision-making while safeguarding privacy and consent;
- Beneficence and No Harm: improving health outcomes or diagnostics without causing harm;
- Safety: implementing strict quality control to prevent errors;
- Fairness: ensuring equitable distribution of AI benefits in healthcare;
- Equality: providing equal access to AI-based healthcare for all;
- Prevention and Precaution: ceasing AI use if risks are identified or remain uncertain;
- Explainability: ensuring that AI decisions are transparent, interpretable and accountable;
- Complementarity: ensuring that AI supports, but does not replace, human medical judgement.
Turning to education, in March 2025, the National Commission for Bioethics & Technoethics of Greece issued its ‘Opinion on the Use of Artificial Intelligence in Greek Schools’, setting out ethical guidelines and policy recommendations for the use of AI in primary and secondary education. The Opinion identifies the following as fundamental principles governing the responsible use of AI in schools: respect for human dignity, autonomy, beneficence and non-maleficence, equitable access, complementarity, transparency, sustainability, augmentation over automation and inventiveness over repetition.
At the tertiary level, several Greek university faculties have published their own AI guidelines for students and staff. Institutions including the University of Crete, the National and Kapodistrian University of Athens, the University of Macedonia, the Aristotle University of Thessaloniki and the University of Western Attica permit AI as an assistive tool, provided users fully disclose AI involvement, critically evaluate outputs and respect intellectual property. Submitting AI-generated content as original work without acknowledgment constitutes academic misconduct comparable to plagiarism and may result in institutional sanctions.
To promote public understanding of AI, the Ministry of Digital Governance and Artificial Intelligence published the guide ‘Artificial Intelligence for Everyone’ in May 2026. Developed in cooperation with the National Council for Research, Technology and Innovation and the Special Secretariat for Artificial Intelligence and Data Governance, this guide was authored by leading Greek AI scientists and made available through the national AI portal. It explains core AI concepts, including generative AI and large language models, through practical examples and accessible guidance, offering recommendations for effective and responsible use of AI-powered tools. This initiative supports the government's broader strategy to enhance digital skills, raise public awareness of AI technologies and facilitate their safe adoption across society.
Similarly, the HDPA has launched a few educational initiatives to promote compliance with the new legislative framework. These include the publication of educational materials and the development of training programmes on AI and data protection, including dedicated curricula for Data Protection Officers, privacy professionals and ICT professionals involved in the development of AI systems.
For the business community, the Hellenic Federation of Enterprises (SEV) has published a ‘Guide on the Use of AI for Businesses’. Designed to help Greek enterprises understand and integrate AI effectively, the guide addresses practical implementation, business benefits, including productivity gains, revenue growth and cost reduction, and workforce empowerment. It also examines strategic considerations, challenges and prerequisites for successful AI adoption across various sectors.
In the research sector, the Hellenic Academic Libraries Link (HEAL-Link) issued guidance in March 2026 entitled ‘Use of Artificial Intelligence for Research Purposes and Publication of Research Results’. This guidance provides recommendations on responsible use of generative AI tools throughout the research lifecycle and promotes transparency by requiring disclosure of AI-assisted contributions in research outputs. Finally, in the advertising sector, the Hellenic Association of Communication Agencies (EDEE) and the Hellenic Advertisers Association (SDE) have jointly published a best practice guide titled ’10 Principles for the Responsible Use of Artificial Intelligence in Advertising’. This guide is addressed to advertising agencies and individuals promoting products or services.
There are a number of non-binding guidelines.
The Ethical Artificial Intelligence Framework (Ethical AI Framework) was issued in 2021 by the Office of the Government Chief Information Officer, the predecessor to the current Digital Policy Office of the Hong Kong SAR Government (DPO) and most recently updated in December 2025, setting out a tailored AI framework for ethical use of AI and big data analytics when implementing IT projects and an assessment template for AI and big data analytics to assess the implications of AI applications. It seeks to establish a common approach and structure to govern the development and deployment of AI applications and to maximise the benefits of the application of AI in IT projects, and sets out 12 ethical principles. Initially, the Ethical AI Framework was developed for use in the internal adoption of AI within the Government, before being customised and released more widely as a guiding principle for all organisations which utilise AI or big data analytics in IT projects.
The DPO also published the Hong Kong Generative Artificial Intelligence Technical and Application Guideline (GenAI Guideline) in April 2025, to promote the safe and responsible application of generative AI technologies. The GenAI Guideline provides comprehensive practical recommendations for Technology Developers, Service Providers and Service Users.
The Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong's privacy regulator, has published a suite of AI guidance materials, including:
- the Guidance on the Ethical Development and Use of Artificial Intelligence (Guidance) in August 2021, which applies to the development and use of AI systems that involve the use of personal data or the identification, assessment or monitoring of individuals, either of which would potentially impact the privacy of individuals in relation to personal data. The objectives of the Guidance are to facilitate the healthy development and use of AI in Hong Kong and assist organisations in complying with Hong Kong laws applying to personal data. The Guidance specifies three data stewardship values, together with seven ethical principles for AI, namely: Accountability; Human oversight; Transparency and interpretability; Data privacy; Fairness; Beneficial AI; and Reliability, robustness and security;
- the 10 Tips for Users of AI Chatbots in September 2023;
- the Artificial Intelligence: Model Personal Data Protection Framework (Model Framework) in June 2024, which provides a set of recommended measures to assist compliance with the requirements of Hong Kong's data protection law when implementing AI systems as well as adherence with the three data stewardship values and seven ethical principles for AI advocated in the Guidance. The measures cover: establishing AI strategy and governance; conducting risk assessment and human oversight; customisation of AI models and implementation and management of AI; and communication and engagement with stakeholders;
- the Checklist on Guidelines for the Use of Generative AI by Employees (GenAI Checklist) in March 2025; and
- the Abuse of AI Deepfakes: Toolkit for Schools and Parents in December 2025.
Various regulators in Hong Kong have also issued industry-specific guidance, including:
- The Hong Kong Monetary Authority (HKMA), Hong Kong's central banking institution, has published several circulars and guidelines regarding the deployment of artificial intelligence, including circulars setting out High-level Principles on Artificial Intelligence and Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions in November 2019, a circular outlining a set of guiding principles regarding Consumer Protection in respect of Use of Generative Artificial Intelligence in August 2024, a circular on the Use of Artificial Intelligence for Monitoring of Suspicious Activities in September 2024, a circular on Supporting Artificial Intelligence Adoption in AML/CFT in November 2025, and circulars on Strengthening Cyber Resilience amid Artificial Intelligence-Empowered Cyber Threats and Supporting Adoption of Artificial Intelligence in Fighting Financial Crime Enclosure in June 2026.
The Securities and Futures Commission (SFC), Hong Kong's securities and futures markets regulator, issued the Circular to licensed corporations – Use of generative AI language models (SFC Circular) in November 2024, highlighting the benefits and risks of using generative AI language models within financial institutions and setting out expectations across four core principles: (i) senior management responsibilities; (ii) AI model risk management; (iii) cybersecurity and data risk management; and (iv) third-party provider risk management. The SFC emphasises responsible use, risk management, and senior management oversight, particularly for high-risk applications like investment recommendations. In June 2026, the SFC issued a further circular reminding licensed corporations to enhance cybersecurity measures to address evolving risks arising from AI-enabled cyberattacks.
- The Mandatory Provident Fund Schemes Authority (MPFA) issued a circular on Guidance on Offering Robo-Advisor Service in February 2024, setting out the key principles that approved trustees and principal intermediaries should abide by when they offer their scheme members digital investment advisory programs that utilise artificial intelligence to give regulated advice.
- The Financial Services and the Treasury Bureau (FSTB) issued the Policy Statement on Responsible Application of Artificial Intelligence in the Financial Market in October 2024, setting out the Government’s policy stance and approach towards AI in financial markets. The policy statement advocates a ‘dual-track approach’ to capturing opportunities while mitigating risks, emphasising protection of privacy and intellectual property rights, human oversight, accountability, operational resilience, and information security.
- The Department of Health’s Medical Device Division (MDD) issued the Technical Reference: Artificial Intelligence Medical Devices (TR-008)in January 2024, providing guidance on listing requirements for artificial intelligence medical devices that fall within the scope of the Medical Device Administrative Control System.
The Insurance Authority has indicated that it plans to issue a guideline on the use of AI / insurers' AI governance framework in the insurance sector in 2026.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
India’s approach to regulating AI and addressing emerging technology-related risks relies on existing laws applied purposively, alongside sectoral guidance, voluntary codes, and strategic frameworks.
Key central guidance includes:
- NITI Aayog (2021): The National Institution for Transforming India (NITI Aayog), the government’s public policy think tank, released the Responsible AI #AIFORALL in 2021. Part 1 of the Responsible AI document ‘Principles for Responsible AI’, released in February 2021, outlined the risks and recommended seven key principles for responsible AI: safety and reliability, equality, inclusivity and non-discrimination, privacy and security, transparency, accountability and protection and reinforcement of positive human values. Part 2, Operationalizing Principles for Responsible AI, released in August 2021, recommended strategy for public and private sector to operationalise the principles. Part 2 also proposed the creation of a Council for Ethics and Technology (CET) to oversee responsible AI deployment, though the CET has not been formally constituted as of date.
- India AI Governance Guidelines: Building on the NITI Aayog framework, MeitY established the IndiaAI Mission as the flagship national initiative to develop a comprehensive AI ecosystem. The Mission aims to democratise computing access, enhance data quality through curated AI-ready datasets, develop indigenous capabilities, attract talent, enable industry collaboration and promote ethical AI, amongst others. Under this Mission, MeitY released the India AI Governance Guidelines, establishing a ‘pro-innovation techno-legal framework’. The Guidelines are split into four parts. The first part focuses on seven fundamental principles (sutras):
- Trust is the Foundation;
- People First;
- Innovation over Restraint;
- Fairness and Equity;
- Accountability;
- Understandable by Design; and
- Safety, Resilience and Sustainability.
These sutras have been adapted from the RBI’s FREE-AI Committee report (discussed below), and are intended to be cross-sectoral, technology-neutral and foundational for responsible AI development and deployment.
Part 2 of the guidelines examines issues and provides recommendations through six pillars of infrastructure, capacity building, policy and regulation, risk mitigation, accountability and institutions, whereas Part 3 and Part 4 are focused on action plan and suggestions for responsible AI use.
Key sector-specific guidance includes:
- Reserve Bank of India (RBI): The Reserve Bank of India, India’s apex bank, constituted the Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) Committee. It was tasked with providing recommendations for responsible and ethical adoption of AI in the financial sector. Mooting the seven principles or sutras, the FREE-AI Committee Report also discusses six strategic pillars of infrastructure, policy, capacity, governance, protection and assurance, addressing dimensions of innovation enablement as well risk mitigation. It also outlines 26 recommendations for AI adoption in the financial sector. This report is a forward-looking blueprint and is not law.
- Securities and Exchange Board of India (SEBI): SEBI, which regulates the securities and commodity markets in India, has issued a series of measures for AI usage, such as: Reporting for Artificial Intelligence (AI) and Machine Learning (ML) applications and systems offered and used by Market Infrastructure Institutions (MIIs) (2019); Master Circular for Investment Advisers (2025) which inter alia requires investment advisors to disclose AI use to clients and take sole responsibility for AI-derived advice; Consultation Paper with proposed guidelines for responsible usage of AI/ML in Indian Securities Markets (2025); and Advisory on Emerging Advanced Artificial Intelligence (AI) Tools for Vulnerability Detection (like Mythos) (2026).
- Insurance Regulatory and Development Authority of India (IRDAI): IRDAI, India’s insurance regulator, issued the Insurance Fraud Monitoring Framework Guidelines (October 2025), aiming to deter, prevent, detect, report and remedy fraud risks effectively across the insurance industry. It inter alia requires insurers to establish dedicated fraud-monitoring governance structures and strengthen technology-enabled fraud detection and monitoring mechanisms across the insurance value chain. Most recently, the IRDAI constituted a seven-member Working Group on AI Governance (June 2026), tasked with assessing AI adoption across the sector and recommending a formal governance framework for ethical, transparent and explainable use of AI in insurance, including for claims and fraud detection.
- Ministry of Health and Family Welfare: The Strategy for AI in Healthcare for India, launched by the Ministry of Health and Family Welfare in February 2026, is a guidance framework for responsible integration of AI in the healthcare ecosystem. The Indian Council of Medical Research (ICMR) had also released Ethical Guidelines for Application of Artificial Intelligence in Biomedical Research and Healthcare in 2023, which provides an ethics framework for development, deployment and adoption of AI-based solutions in biomedical research and healthcare, addressing key principles such as patient safety, data privacy, algorithmic transparency, accountability and human oversight of AI systems.
- Bureau of Indian Standards (BIS): BIS, India’s national standards body, has also adopted certain ISO/IEC AI standards as Indian Standards, including IS/ISO/IEC 23894:2023 on AI risk management. These standards are voluntary technical benchmarks for AI governance, risk management and management systems, and may shape future regulatory expectations and sectoral guidance in India.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
Israeli regulators are beginning to issue non‑binding guidance or frameworks relevant to AI.
The Privacy Protection Authority (the PPA) has published a draft guidance document (for public consultation on 28 April 2025) setting out how the Privacy Protection Law 1981 (the PPL) applies along the AI lifecycle, outlining regulatory expectations for organisations processing personal data with AI, including requirements for transparency, informed consent, purpose limitation, data minimisation, protection of data subject rights and data security (available here, in Hebrew).
In December 2025, the PPA issued a practical, lifecycle‑based guide to privacy‑enhancing technologies (PETs) in AI systems (e.g., de‑identification, synthetic data, federated learning) to reduce privacy risks, among others, in model training and deployment. It links techniques to concrete AI use‑cases and cautions on re‑identification risk.
Public sector implementation tools include periodic open calls to pilot AI in government services and exploration of regulatory sandboxes, such as the healthcare AI regulatory sandbox program led by the Ministry of Health and the Israel Innovation Authority (additional information is available here, in Hebrew).
In the financial sector, an inter‑ministerial team published a report in December 2025 (the Financial Sector Report, available here) recommending a risk‑based framework, enhanced transparency, appropriate human involvement, strengthened data protection, anti‑discrimination safeguards and governance oversight mechanisms. The report addresses both general policy considerations arising from the distinctive characteristics of AI and sector-specific recommendations, including in connection with the use of AI systems in lending and investment advisory services.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Italy
By Ministerial Decree No. 180 of 17 December 2025, the Ministry of Labour formally adopted the Guidelines for the implementation of artificial intelligence in the employment sector. The guidelines aim to foster the responsible adoption of AI by safeguarding workers’ rights, promoting sustainable innovation, and ensuring compliance with applicable legal frameworks. Subject to updates by the Observatory on the adoption of AI systems in the workplace established under Article 12 of Law No. 132/2025, the guidelines provide practical tools for enterprise digitalisation, including by specifying training requirements in AI and AI safety, and outlining available economic incentives for AI adoption. Finally, the guidelines set out key principles for responsible AI use in the workplace, including by listing the provisions contained in labour laws and regulations that apply to AI systems. These include, among others, the prohibition of remote monitoring using AI tools that monitor workers' behaviour, productivity, or movements, unless such systems have been included in an agreement with trade union representatives or authorised by the labour inspectorate. The guidelines also foster mitigation of bias and discrimination through the establishment of clear internal rules; protection of privacy and worker dignity, including limits on AI-based surveillance and safeguards against automation-related stress; and equitable access to AI technologies for large enterprises, small and medium-sized enterprises (SMEs), and self-employed professionals.
On 19 April 2024, the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry released the ‘AI Guidelines for Business Ver1.0’ (AI Guidelines). The AI Guidelines were subsequently updated, and the latest version is the ‘AI Guidelines for Business Ver.1.2’, published on 31 March 2026. Ver.1.2 reflects recent developments in AI technology, including AI agents and physical AI, by adding definitions of these technologies and addressing their expected benefits, associated risks and practical considerations. The updates cover, among other things, the benefits of autonomous coordination, analysis and decision-making by AI agents and the use of physical AI in real-world environments, while also highlighting risks such as unintended autonomous behaviour, expanded attack surfaces, increased difficulty of control and malicious code generation, as well as safeguards such as human involvement mechanisms and minimum privilege settings. Although the AI Guidelines are non-binding, they aim to establish guiding principles for business operators using AI to promote innovation and use of AI while reducing the social risks posed by AI. The AI Guidelines are abstract in nature, outlining the basic principles and approaches for ensuring safety of AI use whilst maximising the benefits. In response, the ‘Appendix to the AI Guidelines’provides specific desirable approaches for AI-related business entities.
In addition to the AI Guidelines, there are several guidelines that establish legal interpretations of AI-related matters within the existing legal framework. For example, on 15 March 2024, the Agency for Cultural Affairs released the ‘General Understanding on AI and Copyright in Japan’ to clarify its view on the copyrightability of AI-generated works. The copyrightability of such works is determined on a case-by-case basis, considering factors such as the quantity and content of instructions and inputs (such as prompts), the number of attempts to generate works and the selection process from among multiple generated works.
The LDP Headquarters for the Promotion of Digital Society Project Team on the Evolution and Implementation of AIs published an ‘AI White Paper 2024: New Strategies in Stage II - Toward the world’s most AI-friendly country’ in April 2024 (2024 White Paper). The 2024 White Paper reflects on the rapid evolution of the AI landscape since the publication of the 2023 White Paper (referred to below) and sets out a Stage II strategy to enhance Japan’s AI competitiveness and safety, promote AI R&D and utilisation, and lead international AI rulemaking, whilst fostering cooperation with Asian countries and the global south.
The LDP Headquarters for the Promotion of Digital Society Project Team on the Evolution and Implementation of AIs published an ‘AI White Paper Japan’s National Strategy in the New Era of AI’ in April 2023 (2023 White Paper). The 2023 White Paper outlined Japan’s strategy in the new era of AI, focusing on the impact of large-scale language models like ChatGPT, the need for a new national strategy and the importance of international competitiveness and regulatory frameworks.
In January 2019, the Cabinet Office of Japan published ‘Social Principles of Human Centric AI’ (Social Principles), introducing a collection of social principles for AI and highlighting some factors to be considered in the research and development of AI, as well as its implementation in society.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
The Communications Regulatory Authority has established a dedicated website for information on EU AI Act compliance for Lithuanian entities.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Malta
In October 2019, the Maltese Government developed and published a National AI Strategy titled ‘Strategy and Vision for Artificial Intelligence in Malta 2030’ (National AI Strategy). While not legally binding, the National AI Strategy was intended to position Malta highly among nations with a national AI programme. The National AI Strategy comprised over 70 actions across three strategic pillars: Investment, Start-Ups & Innovation, Public Sector Adoption, and Private Sector Adoption. In addition, the National AI Strategy also included three strategic enablers: Education & Workforce, Legal & Ethical Framework, and Ecosystem Infrastructure. The National AI Strategy prioritised the public sector, highlighting AI integration to enhance healthcare, education, traffic management and tourism. Simultaneously, the National AI Strategy also emphasised the integration of legal and ethical considerations into AI systems, which is vital to safeguard national security, protect citizens’ rights, advance commercial interests, and ensure trustworthy AI technology.
Since the publication of the National AI Strategy in 2019, significant technological, regulatory and societal developments have reshaped the AI landscape. In light of these developments, the Maltese Government launched a public consultation in 2025 on the realignment of the National AI Strategy. According to the consultation document, more than 80% of the measures envisaged under the original strategy have been fully or partially implemented. The proposed updated strategy seeks to place greater emphasis on societal well-being, sustainability, trustworthy AI, digital skills, and the strengthening of regulatory, policy and support structures, while continuing to promote innovation and AI adoption across the Maltese economy.
In October 2019, Malta also developed an Ethical AI Framework (National Framework), which outlines principles and governance practices for creating reliable AI systems. The National Framework forms an integral part of the National AI Strategy (published in 2019) to establish key ethical principles, including human autonomy, harm prevention, and fairness. The National Framework aims to guide AI practitioners in identifying risks and following high ethical standards. While not legally binding, the National Framework continues to serve as AI guidance that is in alignment with emerging international standards, including the Ethics Guidelines for Trustworthy AI published by the High-Level Expert Group on Artificial Intelligence as set up by the European Commission.
The UNESCO AI Readiness Assessment for Mauritius recommended the formulation of a modern AI policy. In response, the Blueprint embeds the development of a National AI Policy that governs trustworthy and ethical development and use of AI. The policy will be grounded on principles of transparency, fairness and accountability. Further, it will be human-centric and innovation-friendly.
The Blueprint also mentions that the following actions shall be taken in the field of AI:
- Accelerate the implementation of intelligent automation, virtual assistants, and predictive analytics within Government. For instance, AI-powered Job match.
- Build on the leadership of Mauritius in Africa AI readiness to position Mauritius as a regional hub for ethical AI-supporting startups and small and medium-sized enterprises (SMEs) in developing further AI-driven solutions in Fintech, Agritech, Edtech, and Climate Action.
- Create regulatory AI sandboxes and regional/mobile Fab Labs to disseminate knowledge on AI and build AI capacity and awareness across the island. AI shall be introduced in the curriculum for students as from the upper primary level.
- Encourage public-private partnership initiatives to set up AI Tech Park for research and development, startups and innovation.
- Apply AI to monitor environmental risks, optimise resource use, and enable smarter urban planning and agriculture through data-driven systems.
In 2018 Mexico presented an Artificial Intelligence strategy and founded its 'IA2030Mx' coalition comprising nine institutions across various sectors, leading to the development and publication of the Mexican National Agenda for Artificial Intelligence (Agenda) in September 2020. The Agenda discusses several key thematic axes, including 'data, digital infrastructure and ethical' and 'skills, capacities and education' and provides recommendations for a future pathway relating to each axis.
There are no AI-specific regulatory guidance documents or voluntary codes currently in force in Morocco.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
Guidance from the Office of the Privacy Commissioner
The OPC issued the Artificial intelligence and the Information Privacy Principles in September 2023 (OPC AI Guidance) which provides non-binding guidance on compliance with the Information Privacy Principles (the key obligations under the Privacy Act) when adopting AI-enabled solutions. The OPC AI Guidance builds on the OPC’s Generative Artificial Intelligence guidance dated June 2023 (OPC Gen AI Guidance).
At a high-level, the OPC AI Guidance:
- recommends undertaking a Privacy Impact Assessment before deploying AI;
- emphasises the importance of good governance, which requires involvement of senior leadership;
- highlights the importance of transparency and explainability, accuracy, robustness and security, accountability, and human values and fairness. Also consistent with international regulation is the OPC's call for a 'privacy-by-design' approach to implementing AI;
- identifies a need to consider te ao Māori perspectives on privacy (broadly, te ao Māori is the Māori worldview including tikanga Māori - Māori customs and protocols). Specific concerns identified in the OPC AI Guidance include:
- bias from systems developed overseas that do not work accurately for Māori;
- collection of Māori information without work to build relationships of trust, leading to inaccurate representation of Māori taonga that fail to uphold tapu and tikanga; and
- exclusion from processes and decisions of building and adopting AI tools that affect Māori whānau, hapū, and iwi, including use of these tools by the public sector; and
- identifies some use cases for AI as higher-risk, requiring more care, for example, the use of AI tools for automated decision-making.
The OPC continues to monitor risks raised by AI use, including calling for Privacy Act modernisation to address automated decision-making in its 2025 Annual Report, and joining international statements on trustworthy AI data governance and AI generated imagery.
For more information on the OPC AI Guidance, see DLA Piper's update here: New Zealand's Privacy Commissioner follows global trends with latest guidance on AI | DLA Piper.
New Zealand Government Cabinet Paper
The then Minister of Science, Innovation and Technology – Hon Judith Collins KC published the Approach to work on Artificial Intelligence Cabinet paper in July 2024, seeking agreement from Cabinet’s Economic Policy Committee on a strategic approach for New Zealand’s use of AI. The Minister proposed a ‘light-touch, proportionate and risk-based approach to AI regulation’. The approach would leverage existing laws as guardrails and only introduce new regulation to ‘unlock innovation or address acute risks’. Cabinet has focused on the following five key domains:
- setting a strategic approach to AI;
- enabling safe AI innovation in the public service;
- harnessing AI in the New Zealand economy (with the Ministry of Business, Innovation and Employment (MBIE) instructed to formulate OPC AI guidance for firms to utilise);
- prioritising engagement on international rules and norms; and
- coordinating with work on national security.
OECD AI Principles
The New Zealand Government has adopted the Organisation for Economic Co-operation and Development (OECD) AI Principles adopted in 2019 and updated in 2024 (OECD AI Principles) to guide the development of trustworthy, innovative, and democratic AI in New Zealand, aligning with other OECD member states.
National AI Strategy
In July 2025, the New Zealand Government released New Zealand’s Strategy for Artificial Intelligence: Investing with confidence (AI Strategy) aiming to accelerate private sector AI adoption and innovation. The AI Strategy commits to stable and enabling policy for AI, involving a light-touch and principles-based approach that relies on existing legislation and the OECD AI Principles. In the AI Strategy, the Government outlines that it will reduce barriers to adoption, provide clear regulatory guidance, build necessary capabilities, and ensure that adoption occurs responsibly. The AI Strategy emphasises the opportunities in AI adoption and application rather than foundational AI development.
MBIE published a Responsible AI Guidance for Businesses (AI Guidance for Business) alongside the AI Strategy to assist with its practical application. The AI Guidance for Business is a non-binding guide of good practices and actions that can support businesses to adopt AI. It identifies and discusses various types of considerations for businesses using or developing AI systems, including risks to cybersecurity, privacy, human rights, workplace culture, the environment, intellectual property and creators, and physical safety.
For more information on the AI Strategy and AI Guidance for Business, see DLA Piper's update here: Quick on the uptake? New Zealand’s new strategic approach to Artificial Intelligence.
AI guidance for regulators
The New Zealand Government has released Responsible AI in Action guidance for senior leaders and management teams in regulatory organisations (Regulatory AI Guidance). It focuses specifically on best practice for AI use in the regulatory context, where decisions affect rights, obligations, and public confidence. The Regulatory AI Guidance emphasises that AI should facilitate, but not replace, careful judgement, legal interpretation, and discretion when making decisions that affect people's rights and public trust.
The core advice for regulators in the Regulatory AI Guidance is to:
- treat AI as a regulatory capability, not an IT project;
- scale governance and oversight to reflect risks;
- use AI to support human judgement, not replace it; and
- ensure AI use meets high ethical standards that reflect the rights, safety and livelihoods impacted by regulatory decisions.
Public Service AI Framework
The New Zealand Government has introduced the Public Service AI Framework (Framework) to guide the responsible use of AI across the public sector. As with the Regulatory AI Guidance, while not legally binding, the Framework sets out best practice principles for AI adoption. Its vision is the responsible adoption of AI ‘to modernise public services and deliver better outcomes for all New Zealanders.’
The Framework is guided by five AI principles:
- Inclusive, sustainable development – Public Service AI systems should contribute to inclusive growth, sustainable development and the reduction of economic, social, gender and other inequalities, including by reference to access to technology.
- Human-centred values – Public Service AI should respect the rule of law, democratic values, human and labour rights, including personal data protection and privacy, ensuring ethical and appropriate use.
- Transparency and explainability – Those using, or interacting with, Public Service AI should be aware of, and understand, how the Public Service is using that AI. Public Service agencies should therefore disclose when AI is used, how those systems were developed and how they affect outcomes.
- Security and safety – The security of customers and staff is a core business requirement. Public Service AI should apply a robust risk management approach and ensure the traceability of data.
- Accountability – Public Service AI should be subject to oversight. Capability should therefore keep up with technological changes, including to relevant regulatory and governance frameworks.
The Framework's principles are informed by the OECD AI Principles, as well as the UK's Generative AI Framework for HMG dated January 2024 (but since withdrawn), the Algorithm Charter for Aotearoa New Zealand dated July 2020, and the AI Forum AI Principles dated March 2020.
The Government Chief Digital Officer is leading a Public Service AI work programme to support the implementation of the Framework’s vision while working closely with MBIE to compile a cross-portfolio policy work programme. The programme is guided by six pillars:
- Governance – supporting transparency and human accountability in Public Service AI use.
- Guardrails – enabling safe and responsible Public Service AI use.
- Capability – building internal and external AI knowledge and skills.
- Innovation – providing pathways that enable safe AI testing and innovation.
- Social licence – ensuring New Zealanders have trust and confidence in Public Service AI use.
- Global voice – ensuring international counterparts see New Zealand as a trusted AI partner.
Public Service Generative AI Guidance
The New Zealand Government published the Responsible AI Guidance for the Public Service: GenAI dated February 2025 (GenAI Guidelines) to support the New Zealand Public Service to explore generative AI systems in ways that are safe, transparent and responsible. The GenAI Guidelines outline foundational aspects of supporting public sector agencies in the utilisation and adoption of generative AI and give examples of how each aspect can be implemented.
Key considerations are also highlighted about generative AI systems which affect customer experience with the New Zealand Government and include transparency, accessibility, ethical considerations to address bias, Māori and indigenous data considerations, and privacy. Public Service agencies are expected to ensure transparency and accountability in their use of generative AI, enhance employee skills and capabilities, and follow best practices in procurement to align generative AI solutions with business needs and regulatory compliance.
AI Forum publications
The Artificial Intelligence Forum of New Zealand - Te Kāhui Atamai Iahiko o Aotearoa (AI Forum) released its AI Blueprint for Aotearoa: a refreshed vision to 2030 dated May 2026, designed as a practical roadmap for how Aotearoa can become a global leader in innovative, responsible and inclusive AI, and is globally recognised for harnessing the power of AI for the benefit of all. It proposes a focus on education, social licence and trust, and infrastructure. The AI Forum also released its Trustworthy AI in Aotearoa AI Principles dated March 2020 (AI Forum AI Principles). The AI Forum AI Principles are organised under five subheadings, namely: fairness and justice; reliability, security and privacy; transparency; human oversight and accountability; and wellbeing.
Other Regulatory and Sectoral Guidance
Various other regulators have published sector guidance on AI, including:
- The Financial Markets Authority (FMA) has published sector research on AI in financial services dated September 2024, an opinion piece on good governance for AI dated February 2025, guidance on cyber-resilience and digital advice services, and issued public warnings regarding AI-enabled deepfake investment scams dated April 2026;
- The Ministry of Justice published guidelines for the use of generative AI in Courts and Tribunals, dated December 2023. Similarly, the New Zealand Law Society published Generative AI guidance for lawyers and a report on Strengthening the rule of law in Aotearoa New Zealand. When utilising automated decision-making systems in dispute resolution and the delivery of justice, the latter report recommends stronger safeguards to reduce the unintended consequences and protect trust and confidence in the rule of law in New Zealand;
- Parliament’s Economic Development, Science and Innovation Committee reported to Parliament in April 2026 on the public service's adoption of AI, AI guidance for businesses, the ‘light-touch’ approach to legislating AI, and the ethics of using AI in New Zealand. This included a key recommendation that Parliament stay alert to the novel challenges of AI, particularly in the context of legislative development; and
- The Government Communications Security Bureau issued a joint statement with Five Eyes partners calling for a whole-of-organisation and whole-of-society response to the evolving cyber risk landscape driven by frontier AI, dated June 2026. New Zealand is a member of the Five Eyes security partnership alongside Australia, Canada, the United Kingdom, and the United States.
Biometric Processing Privacy Code 2025
The Biometric Processing Privacy Code 2025 (Biometrics Code) is a binding code of practice under the Privacy Act that came into force on 3 November 2025 (with a compliance transition period for agencies already using biometrics until 3 August 2026). The Biometrics Code regulates the collection, storage and use of biometric information for automated biometric processing (for example, verification, identification, and categorisation). Key features include requirements for effectiveness and proportionality assessments, safeguards to reduce privacy risk, transparency obligations, safe limits on highly intrusive uses (including health, emotion or attention prediction), and a prohibition on discriminatory biometric categorisation except in limited circumstances. The Biometrics Code is enforceable by the OPC under the Privacy Act’s complaints and compliance mechanisms.
Reserve Bank of New Zealand reports
The RBNZ issued its Financial Stability Report dated May 2026 (Report), which included a special topic "Rise of the machines – How could artificial intelligence impact financial stability?" (Special Topic).
The Report outlines that the adoption of AI could amplify risks in the financial sector and states that regulated entities are expected to maintain cyber-security strategies and frameworks that adequately address cyber threats.
The Special Topic outlines the use of AI within the financial sector, explores its potential benefits and challenges, provides an overview of the evolving regulatory landscape, and identifies AI-driven risks to financial stability, including errors, data privacy concerns, market distortions, and increased exposure to cyber attacks, all of which could amplify existing systemic risks.
Additionally, the Special Topic flags current and upcoming legislation and binding standards that are or will be relevant to mitigating AI-driven risks. These include:
- the proposed Risk Management Standard and Operational Resilience Standards for deposit takers, slated to take effect in 2028; and
- the Financial Markets (Conduct of Institutions) Amendment Act 2022 (commonly known as CoFI), which came into effect in full in March 2025 and aims to ensure that financial institutions treat consumers fairly. The RBNZ considers that this serves as an important framework for regulating the conduct risk associated with AI.
In November 2023, Nigeria became a signatory to the Bletchley Declaration at the AI Safety Summit held at Bletchley Park, alongside other participating countries and the European Union. The declaration is an agreement to establish a shared understanding of the opportunities and risks posed by frontier AI systems and commits signatories to international cooperation for the safe and responsible development of artificial intelligence.
In August 2024, the Nigerian Bar Association (NBA), during its Annual General Meeting of its Section on Legal Practice, issued Guidelines for the Use of Artificial Intelligence in the Legal Profession, 2024 (NBA AI Guidelines). The document focuses on transparency, data privacy, human oversight, and responsible AI adoption by lawyers. However, the NBA AI Guidelines are sector-specific and not issued by a government authority.
In March 2025, NITDA launched its AI Transformation Roadmap, 2025, which aims to guide its journey into a smart organisation that integrates human expertise with AI capabilities. This roadmap focuses on practical steps for AI adoption within NITDA, emphasising capacity building, ethical AI use, and innovation acceleration.
In September 2025, NCAIR, a specialised arm of NITDA, issued Nigeria's National Artificial Intelligence Strategy (NAIS). The effort was coordinated under the leadership of the Federal Ministry of Communications, Innovation and Digital Economy. The NAIS sets a five-year vision (2025–2029) to make Nigeria a global leader in ethical and inclusive AI innovation, organised around three overarching goals - economic growth and competitiveness, social development and inclusion, and technological advancement and leadership - and five operational pillars.
The Internet Code of Practice, 2026, issued by the NCC in February 2026, is expected to come into full force in August 2026. The Code applies to Internet Access Service Providers licensed by the NCC, the provision of internet access services within Nigeria, and all other entities offering services that fall within the regulatory purview of the Nigerian Communications Act 2003. The Code contains provisions on AI and emerging technologies. It establishes obligations in respect of transparency, accountability, and the responsible deployment of AI-enabled services in the telecommunications sector. On 13 February 2026, the NCC issued Guidance Notes on the Internet Code of Practice, 2026 to assist with implementation and compliance.
On 10 March 2026, the CBN issued Baseline Standards for Automated Anti-Money Laundering Solutions, which sets out requirements for financial institutions and fintechs using automated systems, including AI-powered solutions, for anti-money laundering compliance.
The content on Regulatory guidance / voluntary codes in the European Union applies in Norway.
On 29 April 2026, Peru approved the National Strategy for Artificial Intelligence for the period 2026-2030 (National Strategy), through Ministerial Resolution No. 152-2026-PCM (published on 1 May 2026). The National Strategy sets out Peru’s policy framework for strengthening AI governance and promoting the inclusive, safe and ethical adoption of AI.
The National Strategy seeks to:
- Strengthen AI governance and management at the national level, promoting the development and use of safe, ethical and transparent AI systems;
- Develop digital capabilities and specialised talent to support the deployment of AI technologies;
- Promote the strategic adoption of AI by fostering innovation, entrepreneurship and impact-driven solutions; and
- Strengthen international cooperation, sustainable innovation and citizen participation in AI governance, while safeguarding human rights, transparency, privacy and security, and contributing to the country’s productivity and competitiveness.
The National Strategy also contemplates the development of AI governance and infrastructure mechanisms, including initiatives related to the National Centre for Digital Innovation and Artificial Intelligence (CNIDIA), the National Data Centre, the National Artificial Intelligence Platform and the National Catalogue of Datasets and Models for Artificial Intelligence.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Portugal
Within the framework of the Portuguese National Digital Strategy, approved by Council of Ministers Resolution no. 207/2024 of 30 December 2024, the Portuguese Government initially envisaged the presentation of a national AI Agenda in early 2025, including the development of a Portuguese language large language model (LLM) (approved by Council of Ministers Resolution no. 201/2024 of 30 December 2024).
Following the postponement of the initial timetable, the National AI Agenda was subsequently approved by Council of Ministers Resolution no. 2/2026 of 8 January 2026. The AI Agenda is now the main policy instrument for operationalising Portugal’s national ambition in AI, structured around four areas of focus - Infrastructure and Data; Innovation and Adoption; Talent and Skills; and Responsibility and Ethics - and implemented through 32 initiatives.
Portugal has also advanced the development of its national Portuguese language LLM called AMALIA, which was presented in July 2026 as an open large language model developed for European Portuguese, with the aim of strengthening digital sovereignty, supporting public sector transformation and fostering innovation across academia, businesses and society.The Portuguese Labour Code was amended through the publication of Law no. 13/2023 of 3 April 2023 (within the so-called ‘Decent Work Agenda’ (Agenda do Trabalho Digno) framework), which regulates the use of algorithms and AI systems in labour relations.
In particular:
- Article 24(3) of the Portuguese Labour Code foresees that any decision regarding employees and job candidates based on algorithms or other AI systems may not favour, benefit, disadvantage or deprive them of any right nor exempt them from duties on grounds of ancestry, age, sex, sexual orientation, gender identity, marital status, family situation, economic situation, education, origin or social condition, genetic heritage, reduced labour capacity, disability, chronic illness, nationality, ethnic origin or race, territory of origin, language, religion, political or ideological convictions and trade union membership; and
- Article 106(3)(s) of the Portuguese Labour Code foresees that, among the information to be provided by employers to the employees when hiring, the employer shall provide information regarding the parameters, criteria, rules and instructions on which the algorithms or other AI systems affecting decision-making on access to and maintenance of employment, as well as working conditions, including profiling and monitoring.
In addition, in 2023, a ‘Guide to Ethical Artificial Intelligence, Transparent and Responsible in Public Administration’ was published by the Portuguese Agency for Administrative Modernisation (Agência para a Modernização Administrativa) (AMA), as part of the GuIA Responsável Project. The Guide provides principles and practical guidance for ethical and responsible use of AI in the public sector, focusing on ethics, transparency, explainability, fairness and accountability. It also includes an ethical risk assessment tool to help public entities evaluate and manage AI systems, serving as a strategic reference for the responsible use of AI in Portugal’s public administration.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Romania
Romania's government approved the National Artificial Intelligence Strategy for 2024-2027 in July 2024. The purpose of this strategy is to accelerate the adoption and use of AI in Romania across various sectors, while ensuring that this technology is used responsibly and ethically. It aims to place AI as one of the main national priorities, promoting economic growth, social well-being, and national security through the responsible and ethical use of AI.
Non‑binding policy instruments issued by the Saudi Data and Artificial Intelligence Authority (SDAIA) provide practical direction on AI use pending further legislative measures. These include:
- The AI Adoption Framework (2025): a comprehensive framework to support responsible AI adoption in both public and private organisations, emphasising infrastructure, governance, and policy readiness.
- AI Ethics Principles (2025): applies to all stakeholders interacting with AI in Saudi Arabia, establishing a structured AI lifecycle, risk categorisation, and setting out core principles to ensure responsible AI use.
- Generative AI Guidelines (Public) (2025): provides guidance on the responsible development and deployment of generative AI systems.
- Generative AI Guidelines for Government (2025): supplementary guidance tailored to public sector entities, addressing the specific considerations for government adoption and emphasising fairness, transparency, and social responsibility.
- Deepfakes Guidelines (2025): provides a risk framework for ‘deepfake’ and advanced AI technologies, addressing misinformation, privacy, and ethical concerns.
- Draft Responsible AI Policy (public consultation 3 April ‑ 3 May 2026): SDAIA conducted a public consultation on a draft Responsible AI Policy. The draft policy proposes a comprehensive governance framework for AI including lifecycle governance, a risk-based framework, and ethical considerations.
Although non-binding, these instruments signal regulatory expectations and can be reflected in procurement requirements and compliance investigations.
There are a number of (non-binding) guidelines:
National AI Strategy: the Singapore government published its first National AI Strategy (NAIS) in 2019, outlining plans to enhance the integration of AI for the transformation of its economy. Building on this foundation, the government launched the Singapore National AI Strategy 2.0 on 4 December 2023 to address the recent technological advances, particularly in generative AI, and to create a robust AI ecosystem, enhance workforce skills, ensure sufficient infrastructure and promote a safe environment for innovation. On 20 May 2026, the government released an update to the National AI Strategy 2.0, reflecting further developments in the AI landscape with ten refreshed priorities across the NAIS Enablers. In June 2026, the Singapore Economic Strategy Review proposed positioning Singapore as a global leader in AI.
Model AI Governance Frameworks: the Infocomm Media Development Authority of Singapore (IMDA) and the AI Verify Foundation (a not-for-profit foundation wholly owned by the IMDA) released on 30 May 2024 a Model AI Governance Framework for Generative AI (Model Framework for GenAI) that builds on the Model Artificial Intelligence Governance Framework (Model Framework) that was first published on 23 January 2019. The Model Framework for GenAI provides practical guidance for private sector entities to tackle ethical and governance challenges when implementing AI solutions. It aims to foster public understanding and confidence in technologies by explaining how AI systems work, establishing robust data accountability measures and ensuring open and transparent communication. The Model Framework for GenAI sets out nine dimensions for fostering a trusted AI ecosystem:
- Accountability: putting in place the right incentive structure for different players in the AI system development life cycle to be responsible to end-users.
- Data: ensuring data quality and addressing potentially contentious training data in a pragmatic way, as data is core to model development.
- Trusted development and deployment: enhancing transparency around baseline safety and hygiene measures based on industry best practices in development, evaluation and disclosure.
- Incident reporting: implementing an incident management system for timely notification, remediation and continuous improvements, as no AI system is foolproof.
- Testing and assurance: providing external validation and added trust through third-party testing and developing common AI testing standards for consistency.
- Security: addressing new threat vectors that arise through generative AI models.
- Content provenance: transparency about where content comes from as useful signals for end-users.
- Safety and alignment R&D: accelerating R&D through global cooperation among AI Safety Institutes to improve model alignment with human intention and values.
- AI for public good: responsible AI includes harnessing AI to benefit the public by democratising access, improving public sector adoption, upskilling workers and developing AI systems sustainably.
Model AI Governance Framework for Agentic AI: building on the Model Framework for GenAI, IMDA released on 22 January 2026 the Model AI Governance Framework for Agentic AI (Model Framework for Agentic AI) at the World Economic Forum, with a Version 1.5 published on 20 May 2026 and updated on 5 June 2026. The Model Framework for Agentic AI provides guidance for organisations deploying AI agents. It addresses the specific risks posed by agentic AI, including unauthorised or erroneous actions and challenges to human accountability. The framework outlines four key dimensions:
- assessing and bounding the risks upfront;
- making humans meaningfully accountable;
- implementing technical controls and processes; and
- enabling end-user responsibility.
Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems: the Personal Data Protection Commission (PDPC), Singapore's privacy regulator, published the Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (AI Guidelines) on 1 March 2024. The AI Guidelines offer clarity on using personal data for AI development, outline consumer consent requirements, specify obligations for third-party AI developers under the Personal Data Protection Act 2012 (PDPA), and provide best practices for business compliance with the PDPA. The AI Guidelines are not intended to be legally binding, but rather will act as a point of advisory guidance for the interpretation of the PDPA.
Advisory Guidelines on Use of Personal Data in Generative AI: the PDPC issued Advisory Guidelines on Use of Personal Data in Generative AI (GenAI Guidelines) on 20 July 2026. The GenAI Guidelines clarify how the Personal Data Protection Act 2012 applies to the use of personal data in generative AI models and systems. The Guidelines address three main stages of the generative AI lifecycle: development, including collection and use of personal data for model training; deployment, including allocation of data protection responsibilities among model providers, system providers and system deployers; and post-deployment, including responses to individuals’ access and correction requests.
Guidelines and Companion Guide on Securing AI Systems: the Cyber Security Agency of Singapore (CSA) published the Guidelines on Securing AI Systems on 15 October 2024 to help system owners secure AI throughout its lifecycle. These guidelines aim to protect AI systems against more traditional cybersecurity risks (such as supply chain attacks), as well as novel risks (such as Adversarial Machine Learning). Further, to support system owners, the CSA has collaborated with AI and cybersecurity practitioners to develop a Companion Guide on Securing AI Systems. System owners are recommended to adopta comprehensive lifecycle approach to AI security in five key stages: (1) planning and design; (2) development; (3) deployment; (4) operations and maintenance; and (5) end of life. Businesses should conduct thorough risk assessments, prioritise identified risks, implement appropriate security measures, and continuously evaluate any residual risks throughout the AI system's lifecycle.
- Planning and Design: Businesses are encouraged to be proactive in securing their AI systems. This involves staying informed about the latest security developments and regularly updating risk management strategies to address emerging threats.
- Development: Businesses should assess and monitor potential security risks of the AI system's supply chain across its lifecycle and consider security benefits and trade-offs when selecting the appropriate model to use. They should also recognise the importance of AI-related assets such as models, data, prompts, logs and assessments, and establish procedures to monitor, verify and manage versions, protect these assets and secure the AI development environment.
- Deployment: It is important to secure the deployment infrastructure and environment of AI systems (e.g. establishing access controls and logging/monitoring, segregation of environments, etc.). Incident management procedures (e.g. incident response, escalation, and remediation plans) should be developed and maintained.
- Operations and Maintenance: Businesses should monitor AI system inputs, outputs and behaviour closely, to detect any anomalies or issues. It is important to have a robust process for vulnerability disclosure, to quickly address any potential security concerns.
- End of life: There should be proper and secure disposal/destruction of data and models, especially when AI models were trained on large volumes of data (including potentially confidential information). Businesses should securely destroy sensitive customer data to prevent data breaches and comply with industry standards or relevant regulations.
Proposed Guide on Synthetic Data Generation: the PDPC and the IMDA released a Proposed Guide on Synthetic Data Generation on 15 July 2024. This guide seeks to assist organisations to understand synthetic data (SD) generation techniques and possible use cases (especially for AI). The guide outlines recommended governance, contractual and technical controls to reduce the privacy risk of potential re-identification of SD.
Starter Kit for Testing LLM-Based Applications: in January 2026, the IMDA and AI Verify Foundation released the Starter Kit for Testing LLM-Based Applications for Safety and Reliability (Version 1.0). Developed in consultation with the CSA and Government Technology Agency of Singapore (GovTech), and informed by real-world testing conducted through the Global AI Assurance Pilot (which involved over 30 companies across diverse sectors), the Starter Kit provides voluntary guidelines consolidating emerging best practices for testing LLM-based applications for baseline safety and reliability, focusing on five key risks: (i) hallucination and inaccuracy; (ii) bias in decision making; (iii) undesirable content; (iv) data leakage; and (v) vulnerability to adversarial prompts.
AI for Enterprise Impact Playbook: on 21 May 2026, the IMDA released the AI for Enterprise Impact Playbook, jointly developed with SkillsFuture Singapore (SSG) and Workforce Singapore (WSG). The Playbook helps enterprises assess their readiness to adopt AI across five dimensions (strategic and leadership; talent and culture; data and governance; tech deployment and integration; and value creation), identify the right support at the right stage of their AI journey, and take practical next steps which align with business priorities and workforce needs.
Transparency Guidelines for Generative AI Chatbots: on 20 July 2026, the IMDA released Transparency Guidelines for Generative AI Chatbots, which set out how generative AI chatbot deployers can provide meaningful transparency to consumers with an aim to enable informed use, standardise disclosure, and enhance accountability.
Industry-specific: various industry regulators in Singapore have issued guidance specific to AI, including:
- In the financial sector, the Monetary Authority of Singapore (MAS) has published:
- on 12 November 2018 (and updated on 7 February 2019) the Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore’s Financial Sector (Principles), which outline essential principles for firms providing financial products and services regarding the responsible use of artificial intelligence and data analytics (AIDA). These principles also aim to enhance internal governance related to data management and usage to enhance public confidence in AIDA practices;
- on 30 June 2022, an information paper entitled Implementation of Fairness Principles in Financial Institutions' Use of Artificial Intelligence / Machine Learning, which highlights observations from the review of the financial institutions’ policies and governance frameworks to meet the Fairness objectives under the FEAT Principles, and their implementation effectiveness in actual AI/ML use cases and sets out MAS’ recommendations, good practices and illustrative examples;
- on 5 December 2024, an information paper entitled Artificial Intelligence (AI) Model Risk Management outlining good practices for managing AI and generative AI model risks identified during its review of the banks’ AI model risk management practices. The paper emphasises governance and oversight, key risk management systems and processes, and the development and deployment of AI; and
- on 13 November 2025, Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management for Financial Institutions. The proposed guidelines set out MAS’ expectations on oversight of AI risk management, key AI risk management systems, policies and procedures, key AI life cycle controls, as well as capabilities and capacity needed for the use of AI.
- In the healthcare sector, the Ministry of Health (MOH) and the Health Sciences Authority (HSA) co-published the Artificial Intelligence in Healthcare Guidelines (MOH Guidelines) in 2021 to support patient safety and trust in AI applications within the healthcare industry by sharing good practices with healthcare AI developers, deployers and users, which complements prevailing legislation that governs these stakeholder groups. The MOH Guidelines were updated to Version 2.0 in March 2026 with the following key changes: (i) strengthening accountability through clarity of responsibilities for key stakeholders, including the developers, deployers, and users; (ii) improving trust via guidance on transparency to facilitate informed decision-making; and (iii) updated guidance on AI deployment, such as assessing and mitigating risks.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in the Slovak Republic
On 2 November 2020, the Permanent Commission for Ethics and Regulation of Artificial Intelligence (CERAI) was established by the Ministry of Investment, Regional Development and Informatization of the Slovak Republic as an independent expert and advisory body. The role of CERAI is to consider the ethical, social and legal issues related to the research, development, deployment and use of technologies using AI components and AI systems. At its second meeting on 25 May 2021, CERAI approved the Commission's Outline and Focus.
In 2019, the Slovak Centre for Artificial Intelligence Research was founded. It is a neutral, independent and non-profit platform that, in addition to networking actors in the field of research and application of AI tools, serves mainly as a platform of excellence in this rapidly developing field.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
There is limited sector-specific voluntary guidance, such as the Association of Arbitrators' Guidelines on the Use of AI in Arbitrations and Adjudications.
Various governmental authorities such as MSIT, the Personal Information Protection Commission (PIPC) and the Korea Media Communications Commission (KMCC) (formerly Korea Communications Commission) are creating regulatory guidance. Following the AI Act’s commencement on 22 January 2026, the National Information Society Agency (NIA) published a suite of enforcement guidance documents on 22 January 2026, including practical guidelines for AI business operators on high-impact AI, generative AI, and domestic agent requirements. For general guidance on AI, the following can be considered:
‘National Guidelines for AI Ethics’ were prepared by MSIT in 2020, to provide comprehensive standards that should be followed by all members of society to implement ‘human-centred AI’. The National Guidelines for AI Ethics highlight three basic principles that should be considered during the development and utilisation of AI to achieve ‘AI for humanity’: (1) respect for human dignity; (2) the common good of society; and (3) proper use of technology. They also list ten key requirements that should be met throughout the AI system lifecycle to abide by the three basic principles, including safeguarding human rights, protection of privacy, prevention of harm, transparency, respect for diversity, and accountability, among others.
‘AI Ethics Self-Checklists’ were also prepared by MSIT and the Korea Information Society Development Institute (KISDI) in 2023 to help AI actors examine their adherence to the National Guidelines for AI Ethics in practice. They cover philosophical and social disclosures, including ethical considerations concerning the development and utilisation of AI, as well as social norms and values to be pursued. The AI Ethics Self-Checklists provide both a general-purpose checklist and a field-specific checklist that can be used by different AI actors, with the latter covering fields of AI chatbot, AI for writing, and AI image recognition systems.
Eight ‘Guidebooks for Development of Trustworthy AI’ were prepared by MSIT and the Telecommunications Technology Association (TTA) in 2023 and 2024, providing development requirements and verification items to be used as reference materials for ensuring trustworthiness in the process of developing AI products and services. The eight sector-specific versions of the Guidebooks for Development of Trustworthy AI provide sector-specific specialised use cases based on requirements and assessment questions of the general version of the same to enhance practical use. The sector-specific versions recommend selecting appropriate sector-specific requirements and assessment questions considering the characteristics of AI services during AI trustworthiness assurance activities, covering the medical, autonomous driving, public and social, general AI, smart security, and hiring sectors.
A ‘Strategy to Realize Artificial Intelligence Trustworthy for Everyone’ was also announced by the MSIT in 2021. It seeks to realise trustworthy AI for everyone applying three pillars (of technology, system and ethics) across ten action plans.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
In order to ensure the consistent, effective, and uniform application of the EU AI Act across the European Union, the European Commission has adopted some guidelines (that are non-binding since only the Court of Justice of the European Union has authoritative interpretation powers) on the following provisions of the text:
- Prohibited AI practices, on 4 February 2025 (however, the Commission has not yet formally adopted them); and
- Definition of an AI system, on 6 February 2025 (however, the Commission has not yet formally adopted them).
Further guidelines on high-risk AI systems are expected, and are currently under consultation. The Commission is also expected to provide harmonized standards and common specifications for both high-risk AI systems and general-purpose AI models, providing organizations with further tools which provide a presumption of conformity.
The Commission released the final version of its general-purpose AI Code of Practice on 10 July 2025, and followed it up by publishing Guidelines on the scope of obligations for general-purpose AI model providers on 18 July 2025.
The Commission has also released the first draft of its Code of Practice on Transparency of AI-Generated Content. The Code is planned to be finalized by June 2026. If approved, the final code will be a voluntary tool for providers and deployers to demonstrate compliance with their obligations for marking and labelling AI-generated content under the EU AI Act.
Under the EU AI Act, providers of AI systems that do not fall under the high-risk classification, as well as deployers, have the possibility to adopt voluntary codes of conduct (Article 95) in order to adopt, on a non-binding basis, technical solution and industry best practices. Because of this, it is expected that the AI office will issue further codes of conduct for this (which will be distinct from the GPAI Code of Practice and the Code of Practice on Transparency).
To provide organisations with support identifying and implementing AI literacy initiatives, the Commission launched a repository of AI literacy practices. The repository was updated in November 2025 to improve the searchability of practices.
In May 2024, the Council of Europe published a Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Framework). It is an international, legally binding treaty aiming to ensure that activities within the lifecycle of AI systems are fully consistent with human rights, democracy and the rule of law, whilst being conducive to technological progress and innovation.
AI compliance in Sweden
The Swedish Authority for Privacy Protection (IMY) has issued guidance on the use of AI under the GDPR, emphasizing that organizations must identify a lawful basis, ensure transparency, apply data minimization, conduct appropriate risk assessments, and implement safeguards where AI systems involve personal data. The guidance is particularly relevant for AI systems that use personal data for training, profiling, automated decision-making, or other high-risk processing.
The Thailand AI Ethics Guidelines (AI Ethics Guideline) were published in February 2022, seeking to ensure that AI technology is developed, applied and used in an ethical way. The Generative AI Governance Guideline for Organisations (Generative AI Guideline) was published in October 2024, introducing the concept and definition of generative AI as well as its limitations and risks, and providing a framework for the ethical use of generative AI. The Generative AI Guideline addresses key considerations including data governance, model development and deployment, transparency requirements, accountability mechanisms, and risk management practices for organisations utilising generative AI systems.
Laws specifically addressing AI have not been enacted in Türkiye yet. The Digital Transformation Office and the Ministry of Industry and Technology of the Republic of Türkiye prepared the National Artificial Intelligence Strategy 2021-2025 (NAIS), published in August 2021. NAIS identified several key AI values and principles, including proportionality, safety and security, fairness, transparency and explainability, and responsibility and accountability. It also outlined strategic priorities, objectives and measures relating to such principles. With NAIS having reached the end of its term, the parliamentary AI Research Commission’s 2025 work indicates movement towards an updated national AI strategy and regulatory roadmap. The Commission’s final report, submitted in May 2026, is expected to inform the government’s next-phase AI policy. Additionally, by Presidential Decree published on 25 December 2025, new AI directorates were established within relevant ministries to broaden technology governance and oversee emerging AI developments at the executive level.
Moreover, in June 2026, the Türkiye Artificial Intelligence Vision and Action Plan (2026–2030) was announced, which is structured around four strategic pillars, namely Awareness, Adoption, Development and Governance, and aims to strengthen AI literacy, public-sector digital transformation, AI infrastructure, domestic AI capabilities and responsible AI governance.
The Ministry of AI has published various non-binding guides, including an AI Ethics Guide and The UAE Charter for the Development and Use of Artificial Intelligence (AI Charter).
The AI Ethics Guide promotes ethical design and deployment of AI systems in the public and private sectors. The guide sets out key principles to be followed when designing, developing and deploying AI, including fairness, accountability, transparency, explainability, security, ethics, sustainability, and privacy, as well as specific guidelines to ensure each principle is adhered to. Whilst the guide is non-binding, the Ministry of AI’s intention is that the guide will evolve into a universal framework that is followed by public and private sector entities. It is a living document, and the government is taking a collaborative approach whereby AI stakeholders can be involved in ongoing dialogue.
The AI Charter envisions the transformation of the UAE into a global leader in the ethical oversight and use of AI and seeks to establish a guiding framework to protect the rights of the UAE community in the development and use of AI. It establishes general principles for the development and use of AI in the UAE, which are aligned with the principles referred to in the AI Ethics Guide, and emphasizes the importance of complying with applicable laws when developing and using AI.
On 29 March 2023, the UK Government published a White Paper: A pro-innovation approach to AI regulation (White Paper) elaborating on the approach to AI set out in its 18 July 2022 AI Governance and Regulation Policy Statement. The White Paper set out proposals for implementing a proportionate, future-proof and pro-innovation legislative framework for regulating AI and identified five key principles (para 48, section 3.2.3):
- Safety, security and robustness.
- Appropriate transparency and explainability.
- Fairness.
- Accountability and governance.
- Contestability and redress.
On 31 January 2025, the UK Government published a Code of Practice for the Cyber Security of AI (Code) setting out cyber security requirements applying throughout the lifecycle of AI systems. The Code consists of 13 principles to be voluntarily applied by relevant groups within the AI Supply chain, namely system operators, developers, data custodians, end-users and other affected entities, with each principle linked to a particular stage of the AI system lifecycle.
On 31 July 2025, the British Standards Institution (BSI) launched the world’s first international standard for independent audits of AI systems aiming to ensure consistent evaluation of AI reliability, fairness and safety.
Additionally, in July 2025, the Government signed non-binding arrangements with several frontier AI model providers, to foster adoption in public services including deployment in ‘AI Growth Zones’.
The AI Security Institute continues to publish evaluations of frontier AI models and released an inaugural capabilities report assessing the most advanced AI systems in December 2025.
In April 2026, the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 were made, coming into force on 12 May 2026. These Regulations require the Information Commissioner to prepare a statutory code of practice on the processing of personal data in relation to developing and using AI and automated decision-making systems.
In June 2026, the Government established the AI Economics Institute (AIEI), a joint unit between HM Treasury and the Department for Science, Innovation and Technology, to analyse the economic impacts of advanced AI. The AIEI aims to strengthen the evidence base on how AI affects productivity, labour markets, firms and income distribution, supporting a proactive UK approach to shaping AI’s economic impact.
In March 2026, the Government published a report and impact assessment on Copyright and Artificial Intelligence, fulfilling its commitment under the Data (Use and Access) Act 2025. The report addresses how copyright law should apply to the training of AI models, including consideration of whether to introduce a text and data mining exception for commercial purposes. Following extensive consultation, the Government confirmed that it no longer has a preferred policy option, and is gathering further evidence while engaging stakeholders on potential approaches.
Over many years, and especially from 2022 onward, the US federal government issued Presidential Executive Orders, voluntary frameworks and reports, and agency-level enforcement and guidance to set priorities and shape AI governance. States have also issued guidance and voluntary codes of conduct.
Presidential Executive Orders and Official Statements
In addition to the March 2026 National Policy Framework and the Executive Order described in the Law / proposed law section, the Trump Administration has issued other orders and documents focusing on AI, the most significant of which are described in the paragraphs that follow.
In January 2025, the Trump Administration issued EO 14179, titled ‘Removing Barriers to American Leadership in Artificial Intelligence’, which revoked an executive order from the Biden Administration that had focused in part on civil rights and algorithmic discrimination. The new EO called for the elimination or revision of prior AI-related policies deemed inconsistent with promoting innovation and leadership in the US. It emphasised the development of AI systems that are ‘free from ideological bias or engineered social agendas’, and directed agencies to align their policies accordingly within 180 days.
In July 2025, the White House released ‘America’s AI Action Plan’ which establishes a strategic framework for achieving US global dominance in AI. The plan identifies over 90 federal policy actions across three pillars: accelerating AI innovation through deregulation and support for open-source models, building American AI infrastructure including energy capacity and semiconductor manufacturing, and leading in international AI diplomacy while securing strategic advantages over adversaries. The plan emphasises removing regulatory barriers that hinder private sector innovation, empowering American workers to benefit from AI opportunities, and ensuring AI systems reflect American values and free speech principles.
On 20 March 2026, the White House released a National Policy Framework for Artificial Intelligence, a set of non-binding legislative recommendations intended to guide Congress toward a uniform national AI standard preempting the existing patchwork of state laws. The Framework addresses six objectives: protecting children and empowering parents; safeguarding American communities; respecting intellectual property and supporting creators; preventing censorship and protecting free speech; enabling innovation and American AI dominance; and educating Americans and developing an AI-ready workforce. It does not itself create new legal obligations, and its recommendations track pending congressional proposals, including Senator Marsha Blackburn’s updated TRUMP AMERICA AI Act.
In June 2026, the Administration issued an Executive Order titled ‘Promoting Advanced Artificial Intelligence Innovation and Security’, signed on 2 June 2026, which establishes a voluntary framework for frontier AI developers to engage with the federal government. Under that framework, developers may work with agencies to determine whether a model meets a classified benchmark for designation as a ‘covered frontier model’ and may grant agencies access to such models for 30 days prior to wider release; the EO expressly states that it does not authorise any new mandatory government licensing, pre-clearance, or permitting requirement for the development, release, or distribution of AI models. The order also directs measures to strengthen federal cybersecurity defences and to prioritise enforcement against the use of AI to unlawfully access or damage computer systems.
Several notable federal bills remain pending in the 119th Congress, none of which had become law as of mid-2026. The most far-reaching is Senator Blackburn’s TRUMP AMERICA AI Act, released as a 291-page discussion draft on 18 March 2026, which would impose a duty of care on AI developers enforceable by the FTC, establish a new products-liability framework, require third-party political-bias audits for high-risk systems, declare that unauthorised use of copyrighted works for AI training is not fair use, repeal Section 230 of the Communications Decency Act, and incorporate several existing bills (including the GUARD Act, the NO FAKES Act, the TRAIN Act, and the Kids Online Safety Act); notably, despite its framing around ending the state ‘patchwork’, the draft does not expressly preempt all state AI laws and in places preserves states’ authority to enact stricter rules. Other proposals reflect the opposite approach: the GUARDRAILS Act (H.R.8031/S.4216, introduced March 2026) would repeal EO 14365 outright and bar the use of federal funds to implement it.
A significant bipartisan counterpart is the Great American AI Act (GAAIA), which Representatives Jay Obernolte (R-CA) and Lori Trahan (D-MA) released as a roughly 269-page discussion draft on 4 June 2026, though it has not yet been formally introduced in Congress. The draft is organised into titles addressing frontier AI and government, workforce, cybersecurity, and research and international cooperation. Among other things, it would require large frontier-model developers to publish a ‘frontier AI framework’ and transparency reports and to report critical safety incidents (Section 111); create a federal system in which the Director of the Centre for AI Standards and Innovation would license and oversee ‘independent verification organisations’ that large frontier developers must retain to perform audits and assessments (Section 112); and protect employees and contractors from retaliation for reporting AI violations (Section 113). Title I would preempt state laws specifically regulating the development of AI models for three years, while leaving intact laws of general applicability and many other state AI laws.
Voluntary AI-related frameworks
In parallel, voluntary frameworks continue to guide ethical and responsible AI development. Most notably:
- AI Bill of Rights (October 2022): Issued by the White House Office of Science and Technology Policy (OSTP) during the Biden Administration, the ‘Blueprint for an AI Bill of Rights: Making Automated Systems Work for the American People’ is a set of principles aimed at guiding ethical AI use and protecting the public from harmful AI practices. While not enforceable, its core principles have influenced corporate ethics policies and state-level legislation. The Trump Administration has moved away from the principles expressed therein.
- NIST AI Risk Management Framework (AI RMF 1.0) (January 2023): This voluntary and non-binding framework, released by the US Department of Commerce’s NIST, is designed to mitigate AI risks. Widely adopted by both private companies and government agencies as a best-practice guide, the Risk Management Framework (RMF) encourages organisations to assess and mitigate risks based on the context and potential impact of the AI system. Notably, the Trump Administration, through the White House’s July 2025 AI Action Plan, recommends that NIST revise the AI RMF 1.0 to remove references to certain topics including misinformation, DEI, and climate change.
- NIST Generative AI Profile (July 2024): NIST released this voluntary guide as a supplement to the RMF. It tailors the RMF’s core principles—‘map’, ‘measure’, ‘manage’, and ‘govern’—to the risks of generative AI, such as misinformation, deepfakes, and IP concerns. It offers over 400 recommended actions across the generative AI lifecycle and emphasises stakeholder engagement, transparency, and responsible deployment.
- NIST AI 100-4 (November 2024): In furtherance of the Biden Administration’s Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, NIST issued the report ‘Reducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content Transparency’ as a technical overview of methods to increase transparency and reduce the risks associated with AI-generated content. It provides foundational guidance for developing future standards and applies its concepts to the AI RMF. It aims to improve trust in digital media by examining technical approaches for content authentication, provenance tracking, synthetic content detection, and the prevention of harmful AI-generated materials.
- NIST Cybersecurity Framework AI Profile (December 2025): Issued as a preliminary draft, NIST’s Cyber AI Profile provides guidelines for managing cybersecurity risks associated with AI systems and for leveraging AI to improve cybersecurity capabilities. It applies the core functions of the NIST Cybersecurity Framework (CSF) 2.0 to help organisations strategically adopt AI while addressing emerging cybersecurity risks. It organises its guidance into three focus areas: securing AI components, using AI for cyber defence, and thwarting AI-enabled attacks.
- NIST Possible Approach for Evaluating AI Standards Development (January 2026): NIST issued the grant contractor report, ‘A Possible Approach for Evaluating AI Standards Development’, as a conceptual paper proposing a framework to measure the effectiveness and impact of AI standards. While the report presents a non-prescriptive approach intended to foster discussion, it introduces a formal ‘theory of change’ model to help stakeholders evaluate how AI standards achieve goals such as promoting innovation and public trust. It outlines a process for identifying the inputs, activities, outputs, and outcomes of standards development and measuring their impact against a ‘counterfactual’, or what would have happened in the absence of the standard.
Federal agency action
Several federal agencies are also leveraging their statutory authorities to address emerging risks, ensure compliance, and hold organisations accountable for the misuse or misrepresentation of AI technologies. Enforcement actions by agencies such as the FTC, Securities and Exchange Commission (SEC), Department of Justice (DOJ), Food and Drug Administration (FDA), and Department of Health & Human Services (HHS) have aimed to help shape responsible AI practices. These actions span a range of issues—from consumer protection and investor transparency to employment discrimination and medical device safety. The following outlines the roles of some of the key federal agencies in AI oversight and highlights their regulatory focus areas.
FTC
The FTC’s mission is to protect consumers and promote fair competition. The agency has targeted deceptive practices and misleading claims about AI—often referred to as ‘AI washing’. The agency has now brought numerous enforcement actions against companies that exaggerate the capabilities of their AI systems or falsely market products as AI-powered to gain consumer trust. The FTC has also focused its enforcement on privacy issues with AI systems and the misuse of generative AI for scams and fake reviews. In addition, the agency has explored antitrust issues relating to algorithmic pricing and the market for cloud computing.
SEC
The SEC’s regulatory focus on AI centres around ensuring transparency, managing conflicts of interest, and protecting investors. It requires firms to clearly disclose how AI is used, particularly when it influences investment decisions or client interactions, to police false or misleading AI statements to investors or clients. The SEC addresses organisational claims about AI capabilities that are misleading to investors, and requires compliance with existing securities laws, applying a technology-neutral, risk-based approach to oversight. Like the FTC, the SEC has been bringing enforcement actions relating to ‘AI washing’.
DOJ
The DOJ enforces a broad array of federal criminal and civil laws, intensifying its focus on misconduct related to AI, particularly ‘AI washing’. In April 2025, the DOJ, working in parallel with the SEC, brought securities and wire fraud charges against the former CEO of a technology startup for allegedly defrauding investors of over USD 42 million by falsely claiming his company used advanced AI when its services were actually being performed manually. This enforcement posture underscores the significance of the DOJ’s late 2024 guidance on how companies should manage risks associated with AI and other emerging technologies. In certain cases, when considering punishment for criminal wrongdoing, federal prosecutors would use this guidance in considering the efficacy of a company’s relevant compliance programme. The agency has also brought law enforcement actions involving AI-related mistakes and misuse, sometimes working with agencies like the SEC. Given that DOJ also enforces civil rights laws, it has signalled in the past that AI systems used in areas like housing, employment, and lending must comply with anti-discrimination statutes.
FDA
The FDA plays a central role in regulating AI in both the medical device and drug development contexts, proactively establishing regulatory infrastructure to ensure compliance and safety. In January 2025, the agency released a draft guidance, ‘Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products’, which introduces a risk-based credibility assessment framework for AI models used in this context. It outlines a seven-step process for assessing AI model credibility, discusses challenges such as data quality and algorithmic bias, and highlights the need for life cycle maintenance of AI models to ensure their continued reliability. The FDA has also adopted a separate risk-based framework for the regulation of Software as a Medical Device (SaMD), focusing on the intended use of the software and the potential impact on patient health, which includes evaluating the software’s clinical functionality, reliability, and performance. The FDA strongly encourages sponsors to engage with the agency early in the development process to discuss the use of AI in the context of drug development.
HHS
The HHS, through its Office for Civil Rights (OCR), plays a central role in governing the use of AI and other advanced technologies that implicate protected health information. OCR administers and enforces the HIPAA Privacy, Security, and Breach Notification Rules, and has increasingly framed these authorities to account for evolving technological and cybersecurity risks. In particular, OCR has moved to modernise HIPAA Security Rule requirements to reflect changes in the digital health ecosystem, explicitly citing the growing sophistication of cyber threats, the expanded use of automated and data‑intensive systems, and the need for stronger safeguards around electronic protected health information.