Artificial Intelligence in Australia
Controls on generative AI
Law / proposed law in Australia
Australia has not enacted a standalone, comprehensive AI Act or another generally applicable AI-specific statute equivalent to the European Union’s AI Act. The current Australian approach is to apply existing technology-neutral laws, sector-specific regulation, enforceable online-safety instruments, public-sector policy and voluntary responsible-AI guidance. Whether a rule applies turns on the use case, the data and parties involved, the sector, the deployment model and the system’s effects.
The National AI Plan, released in early December 2025, sets the Australian Government’s policy direction around three objectives: capturing the opportunity, spreading the benefits, and keeping Australians safe. For regulation, the Government’s stated preference is to build on existing legal and regulatory frameworks. Targeted intervention may still be considered where existing frameworks cannot adequately address a demonstrated risk.
On 15 July 2026, Prime Minister Anthony Albanese announced proposed Australian Standards for AI and the establishment of an Office of AI within the Department of the Prime Minister and Cabinet. The proposal is expected to be considered by National Cabinet in August 2026, with legislation expected in early 2027, and may result in a more targeted mandatory framework for aspects of AI regulation in Australia.
Existing laws potentially relevant to AI include the Privacy Act 1988 (Cth), the Australian Consumer Law, competition law, copyright and other intellectual-property laws, breach of confidence, contract law, defamation, anti-discrimination law, employment and workplace-surveillance law, work health and safety law, product-liability law, directors’ duties, criminal and cybercrime law, the Online Safety Act 2021 (Cth), the Security of Critical Infrastructure Act 2018 (Cth), administrative law, financial-services and prudential regulation, health and therapeutic-goods regulation, education law and state and territory privacy, health-records, surveillance and public-sector laws. The list is not exhaustive, and no single regime governs all AI activity.
AI.gov.au was published in May 2026 as the consolidated Australian Government portal for responsible-AI guidance, tools and resources. It is operated through the National AI Centre within the Department of Industry, Science and Resources.
Automated decision-making transparency under the Privacy Act
From 10 December 2026, an Australian Privacy Principle (APP) entity must include additional information in its privacy policy under APPs 1.7–1.9 where it has arranged for a computer program to make a decision, or to do a thing substantially and directly related to making a decision, that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about the individual is used in operating that program. The policy must describe the kinds of personal information used, the kinds of decisions made solely by those programs and the kinds of decisions for which those programs do something substantially and directly related to making the decision.
These are transparency obligations. They do not, by themselves, create a general right not to be subject to automated decision-making. The Office of the Australian Information Commissioner (OAIC) consulted on implementation guidance in May 2026; the final guidance should be checked before the provisions commence.
State and territory overlays
State and territory laws can be material, particularly for public-sector, health, education, law-enforcement, surveillance and workplace uses. Relevant overlays may include privacy and health-records statutes, information-sharing laws, surveillance-device and workplace-surveillance legislation, public-records requirements, anti-discrimination law and sector-specific governance duties.
Regulatory guidance / voluntary codes in Australia
The current Australian Government framework for voluntary responsible-AI adoption is the National AI Centre’s Guidance for AI Adoption, which was released in October 2025 and is now hosted through AI.gov.au. It is available in a foundations version for early or lower-risk adoption and an implementation-guidance version for more complex or higher-risk uses. The guidance includes an AI screening tool, AI policy guide and template, AI register template and a glossary. The framework is organised around six essential practices:
- Decide who is accountable;
- Understand impacts and plan accordingly;
- Measure and manage risks;
- Share essential information;
- Test and monitor; and
- Maintain human control.
These practices are voluntary and non-binding guidance. They are designed to help organisations operationalise responsible AI consistently with existing Australian laws and risk-management expectations; they do not create an independent cause of action or substitute for sector-specific legal analysis.
Australia’s AI Ethics Principles were published in November 2019. The Voluntary AI Safety Standard, published in September 2024, later expressed responsible-AI practices through ten voluntary guardrails. The current six-practice Guidance for AI adoption is now the principal economy-wide Australian Government responsible-AI adoption guidance. References to the ten guardrails should therefore be understood as historical rather than as the current government framework.
In September 2024, the Department of Industry, Science and Resources released a proposals paper on mandatory guardrails for AI in high-risk settings. The Government has since stated that it will not proceed with those proposals at this time. The paper is therefore a historical consultation document, not law and not a currently progressing legislative regime. Its suggested high-risk criteria may still be useful as background policy material, but they must not be expressed as mandatory obligations.
The Productivity Commission’s final report, Harnessing data and digital technology, issued on 10 December 2025, recommends that AI-specific regulation be used only as a last resort where existing regulatory frameworks cannot be sufficiently adapted to handle AI related harms and technology-neutral regulation is infeasible or cannot adequately mitigate the risks. That recommendation expressly addresses the previous mandatory-guardrails proposal.
Privacy, automated decision-making and cyber guidance
On 21 October 2024, the OAIC released guidance for organisations using commercially available AI products and separate guidance for developers training or adapting generative-AI models. The OAIC emphasises that Privacy Act obligations may apply to personal information in prompts, training or fine-tuning data, system logs or other records where they contain personal information and outputs, including inferred, inaccurate or artificially generated information where it is about an identified or reasonably identifiable individual. The OAIC advises AI developers to take reasonable steps to ensure accuracy in generative AI models, such as implementing quality assurance controls to mitigate the risk of biased or inaccurate output prior to release. Public availability of data does not, by itself, establish that collection or use for model training is lawful.
The Commonwealth Ombudsman’s Automated Decision-Making Better Practice Guide was updated in March 2025 in collaboration with the OAIC and the Attorney-General’s Department. It addresses legality, procedural fairness, transparency, accountability, reviewability and system governance in government decision-making. In January 2026, the OAIC also reported on agencies’ publication of automated-decision operational information under the Freedom of Information Act 1982 (Cth) Information Publication Scheme.
On 23 May 2025, the Australian Signals Directorate’s Australian Cyber Security Centre and international counterparts published AI data-security guidance. It addresses risks across the AI lifecycle, including data-supply-chain compromise, maliciously modified or poisoned data, data drift, provenance, access controls, secure storage and integrity protection.
Commonwealth Government use
Version 2.0 of the Policy for the responsible use of AI in government took effect on 15 December 2025. It applies to non-corporate Commonwealth entities subject to specified exclusions, including defence and national-intelligence contexts, and corporate Commonwealth entities are encouraged to adopt it. The policy requires, among other things, accountable officials, transparency statements, a strategic AI-adoption position, operational governance, accountable use-case owners, internal use-case registers, staff training and impact assessment. Additional senior governance applies to higher-risk in-scope uses. These are government-policy requirements, not general economy-wide law.
The Australian Government released the AI Plan for the Australian Public Service 2025 on 12 November 2025. It is organised around the pillars of Trust, People and Tools and aims to expand safe AI capability, access and adoption across the Australian Public Service.
Appointed supervisory authority in Australia
Australia has not appointed a single statutory authority with general enforcement jurisdiction over all AI systems. There is no central Australian AI regulator equivalent to an authority administering a comprehensive AI Act.
The Australian AI Safety Institute has been announced as a key National AI Plan action and sits within the Department of Industry, Science and Resources. It replaced the previously planned AI Advisory Body, which was discontinued in February 2026. It is intended to perform technical analysis, monitoring, testing and policy-support functions and to support government agencies and existing regulators. It is not an enforcement regulator and does not displace statutory regulators or alter their legal remits.
Existing regulators continue to supervise AI-related conduct within their statutory mandates. Depending on the use case, they include the OAIC for privacy and freedom of information; the Australian Competition and Consumer Commission (ACCC) for competition and consumer protection; the eSafety Commissioner for online safety; the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) for financial services, markets and prudential and operational-risk matters; the Therapeutic Goods Administration (TGA) and health regulators for therapeutic goods, medical devices and health uses; workplace, safety and anti-discrimination bodies; cyber security and critical-infrastructure authorities; ombudsmen and administrative-review bodies; and state and territory regulators. A single AI deployment may engage several regulators concurrently.
Definitions in Australia
Australian legislation does not presently contain a single, generally applicable statutory definition of ‘AI system’, ‘AI technology producer’, ‘provider’, ‘deployer’ or ‘user’ for all purposes. Definitions can instead arise within particular statutes, contracts, technical standards or sector-specific rules and must be read in their own context.
The National AI Centre’s current terms page uses an Organisation for Economic Co-operation and Development (OECD)-aligned concept of an AI system: a machine-based system that infers from inputs how to generate outputs, such as predictions, content, recommendations or decisions, capable of influencing physical or virtual environments; AI systems differ in autonomy and post-deployment adaptiveness. The guidance also uses the following non-statutory role descriptions:
- AI deployer: an individual or organisation that supplies or uses an AI system to provide a product or service, whether internally or externally.
- AI technology producer: an organisation or entity that designs, develops, tests and provides AI technologies such as models and components.
- AI platform, product or service provider: an organisation or entity that provides products or services using one or more AI systems.
- AI user: an entity that uses or relies on an AI system.
The OAIC distinguishes the underlying model from the broader AI system in which it is deployed. As an explanatory matter, that broader system may also encompass data, software, interfaces and operational processes. Governance controls and human decision points may be important components of a deployment, but they should be identified as contextual system-design features rather than presented as a verbatim OAIC definition.
Prohibited activities in Australia
Australia has not enacted a comprehensive list of prohibited AI practices equivalent to the prohibited-practices regime in the European Union AI Act. AI-enabled conduct may nevertheless be prohibited, restricted or actionable under existing laws.
Existing legal prohibitions and restrictions
Depending on the facts, existing law may prohibit or regulate unlawful collection, scraping, use or disclosure of personal information; misuse of biometric information; serious invasion of privacy; misleading representations and unfair consumer practices; unlawful discrimination; defamation; copyright infringement; breach of confidence; unauthorised surveillance or workplace monitoring; computer offences, malware and unauthorised access; child sexual exploitation material; financial or professional services supplied without required authorisation; unsafe therapeutic goods or medical devices; and unlawful or procedurally unfair government decision-making.
Online-safety codes, standards and enforcement
The Online Safety Act 2021 (Cth) supports mandatory industry codes and standards for sections of the online industry. The Online Safety Codes and Standards regulate online activities involving class 1 and class 2 material. Phase 1, now referred to as the Unlawful Material Codes and Standards, focuses on class 1A and class 1B material, including seriously harmful content such as child sexual exploitation material, pro-terror material, and extreme crime and violence material. Phase 2, now reflected in the Age-Restricted Material Codes, focuses on class 1C and class 2 material, including online pornography and other age-inappropriate material. AI-generated material is treated in the same way where it falls within the relevant classification category. Requirements can apply to service categories that include designated internet services, including high-impact generative-AI designated internet services where covered by the relevant instrument. The precise obligation depends on the relevant code or standard, service category and risk profile.
The OAIC’s Clearview AI determination remains a leading illustration of existing privacy law being applied to AI-enabled facial recognition and large-scale scraping of images from publicly available online sources.
Government announcements about additional or broader restrictions on non-consensual sexually explicit AI-generated content, app distribution or search access should be described as policy proposals unless and until the relevant legislation or instrument is enacted and commenced. They should be kept separate from existing criminal offences, online-safety instruments and regulator enforcement powers.
High-risk AI in Australia
Australia has no generally applicable statutory classification or compliance regime for ‘high-risk AI’. The expression is currently a governance and policy concept, except where a particular sectoral law or instrument independently imposes risk-based obligations.
The September 2024 mandatory-guardrails proposals paper suggested that a future framework could consider adverse impacts on individual rights, health and safety; groups and collective or cultural rights; and the broader economy, society, environment and rule of law, together with the severity and extent of those impacts. Those proposed criteria never became binding law and the proposal is not proceeding at this time.
The current Guidance for AI adoption uses a risk-scaled approach. Its implementation guidance is directed to more complex or higher-risk uses and recommends stronger accountability, impact analysis, risk management, information sharing, testing, monitoring and human control. As a governance matter, indicators warranting enhanced controls may include significant effects on rights or access to services; impacts on vulnerable people or communities; safety-critical functions; opaque or difficult-to-contest outcomes; large-scale or systemic deployment; material cyber or data risks; and serious consequences from error, bias or model failure.
Organisations using AI in higher-impact contexts should, as a governance recommendation rather than a general statutory command, document use cases and accountabilities, conduct proportionate impact and legal assessments, test and monitor performance, manage data quality and provenance, maintain effective escalation and override processes, enable complaints and contestability, and integrate AI controls with existing privacy, cyber, consumer, safety and sectoral compliance systems.
Controls on generative AI in Australia
Australia has not enacted a generally applicable statute devoted exclusively to generative AI. Generative-AI development and use are regulated through existing laws and, where applicable, sectoral instruments including the Online Safety Act codes and standards.
Privacy and data
Developers and deployers should determine whether training, fine-tuning, retrieval-augmented generation, prompting, logging or other records where they contain personal information, or output handling involves personal information; whether collection, use and disclosure are lawful and fair; whether an APP notice or privacy-policy update is required; whether information is accurate and secure; whether cross-border disclosure rules are engaged; and whether access, correction, retention and deletion obligations apply. Public accessibility does not automatically make data lawful to collect or use for training.
Consent is not universally required for every handling of personal information under the Privacy Act. An entity should determine whether consent is required or relied upon, particularly for sensitive information or secondary uses, and whether another applicable permission or exception is available. The analysis depends on the relevant Australian Privacy Principle and the facts.
The OAIC treats personal information entered into an AI system and personal information contained in system output as potentially regulated, including inferred, inaccurate or hallucinated information about an identified or reasonably identifiable person. The OAIC recommends particular caution with sensitive information and publicly available generative-AI tools.
Cyber security and operational control
AI-specific security analysis should address access control, data leakage, prompt injection, insecure output handling, model inversion or extraction, maliciously modified or poisoned data, supply-chain compromise, model drift, logging, provenance, change control and incident response. Organisations subject to critical-infrastructure, prudential or other cyber security regimes must integrate AI controls with those binding requirements rather than treat AI governance as a standalone exercise.
AI-generated content transparency
The National AI Centre first published voluntary best-practice guidance on AI-generated content transparency, covering labelling, watermarking and metadata recording, on 28 November 2025. The current version, published on 22 April 2026, recommends proportionate disclosure methods such as labelling, watermarking and metadata or provenance measures. This is voluntary best-practice guidance, not a generally applicable statutory labelling regime. Separate binding obligations may arise under consumer, electoral, online-safety, privacy or sector-specific law depending on the content and context.
Enforcement / fines in Australia
Australia has no general, cross-economy AI Act enforcement or penalty regime. AI-specific or AI-relevant obligations may nevertheless be enforced under existing legislation and sectoral instruments. The regulator, cause of action, available remedy and maximum penalty depend on the particular provision, the conduct, the date of contravention and the defendant.
- A serious or repeated interference with privacy under the Privacy Act can attract a maximum civil penalty of AUD 2.5 million for a person other than a body corporate. For a body corporate, the maximum is the greater of AUD 50 million, three times the value of the benefit reasonably attributable to the conduct, or, if that value cannot be determined, 30% of adjusted turnover during the breach turnover period. Other Privacy Act contraventions have different consequences. The statutory tort for serious invasions of privacy also creates a private court pathway, subject to its elements, remedies, defences and exemptions.
- Competition and consumer law. AI-related representations, sales practices or product conduct may engage the Australian Consumer Law and competition law. For many offence and civil-penalty provisions, the maximum corporate penalty for conduct on or after 28 March 2026 is the greater of AUD 100 million, three times the reasonably attributable benefit where that value can be determined, or 30% of adjusted turnover during the breach turnover period where it cannot. Other provisions have lower maxima. The general prohibition on misleading or deceptive conduct under the Australian Consumer Law is not itself a pecuniary-penalty provision, although related conduct may contravene civil-penalty provisions and injunctions, damages, compensation and other remedies may be available.
- Online safety. Non-compliance with a standard, or with a direction to comply with a code, can result in civil-penalty proceedings. The maximum identified in eSafety’s regulatory guidance is 30,000 penalty units per contravention for an individual and five times that amount for a corporation. Different Online Safety Act contraventions may carry different maxima.
- Other regimes. AI uses may also attract regulatory orders, licence consequences, remediation, compensation, injunctions, enforceable undertakings, disqualification, criminal liability or judicial and merits review under financial-services, health, workplace, discrimination, cybercrime, critical-infrastructure, administrative-law and other sectoral regimes. Penalty figures should be rechecked on the publication date and should never be applied without identifying the specific contravention.
User transparency in Australia
Transparency is a central feature of Australian responsible-AI policy, but its legal source and effect vary. The current Guidance for AI adoption recommends sharing essential information about AI systems and maintaining human control. The National AI Centre’s AI-generated content guidance recommends proportionate disclosure, labelling, watermarking and provenance measures. These recommendations are voluntary unless another law or instrument makes disclosure mandatory in the relevant context.
Under the Privacy Act, APP entities may need to explain personal-information handling through privacy policies and APP 5 collection notices and to facilitate access and correction. From 10 December 2026, the specific automated decision-making privacy-policy disclosures described in the Automated decision-making transparency under the Privacy Act section will apply to qualifying arrangements. The OAIC’s final implementation guidance should be checked before commencement.
For Commonwealth Government entities within scope, the responsible-use policy requires transparency statements, strategic and operational governance, use-case accountability, registers, training and impact assessment. Administrative law may also require lawful authority, procedural fairness, reasons and reviewability. The OAIC’s January 2026 Information Publication Scheme report recommends improved publication of operational information about automated decision-making by government agencies.
Fairness / unlawful bias in Australia
Australia does not have a single AI fairness statute. Unfair or biased AI outcomes can nevertheless engage Commonwealth, state or territory anti-discrimination laws, employment law, consumer protection, privacy, credit, education, health, administrative law and other sector-specific duties. The applicable protected attributes, tests, exemptions, remedies and responsible parties depend on the relevant statute and context.
The current Guidance for AI adoption addresses fairness through impact analysis, stakeholder engagement, risk management, testing, monitoring and human control. The OAIC identifies bias and discrimination risks where data are incomplete, inaccurate, unrepresentative or encode historical disadvantage. These are guidance propositions unless linked to a specific legal obligation.
As a governance matter, organisations deploying higher-impact AI should test for discriminatory or materially inaccurate outcomes before and after deployment; assess performance across relevant cohorts; document limitations; monitor complaints and drift; maintain escalation and contestability pathways; and ensure that human reviewers have the authority and information needed to correct inappropriate outcomes.
Human oversight in Australia
The sixth essential practice in the current Guidance for AI adoption is to maintain human control. The guidance recommends designing systems and operating processes so that people can supervise, intervene, escalate, override or stop AI use where appropriate to the system’s risk and impact.
Human involvement should be meaningful rather than ceremonial. Reviewers need appropriate expertise, authority, information, independence and time; they should understand relevant system limitations and avoid merely endorsing an automated result. The appropriate form of oversight may range from periodic monitoring for low-impact tools to mandatory approval, dual control, escalation or prohibition of autonomous action in higher-impact contexts.
For government decision-making, human oversight must be assessed alongside statutory authority, lawful delegation, procedural fairness, reasons, evidence, recordkeeping and review rights. For private-sector systems, the necessary controls depend on the consequences of the use case and the privacy, consumer, safety, discrimination, professional, cyber security and sectoral laws engaged. Human review does not cure an otherwise unlawful system or decision.
Australia has not enacted a generally applicable statute devoted exclusively to generative AI. Generative-AI development and use are regulated through existing laws and, where applicable, sectoral instruments including the Online Safety Act codes and standards.
Privacy and data
Developers and deployers should determine whether training, fine-tuning, retrieval-augmented generation, prompting, logging or other records where they contain personal information, or output handling involves personal information; whether collection, use and disclosure are lawful and fair; whether an APP notice or privacy-policy update is required; whether information is accurate and secure; whether cross-border disclosure rules are engaged; and whether access, correction, retention and deletion obligations apply. Public accessibility does not automatically make data lawful to collect or use for training.
Consent is not universally required for every handling of personal information under the Privacy Act. An entity should determine whether consent is required or relied upon, particularly for sensitive information or secondary uses, and whether another applicable permission or exception is available. The analysis depends on the relevant Australian Privacy Principle and the facts.
The OAIC treats personal information entered into an AI system and personal information contained in system output as potentially regulated, including inferred, inaccurate or hallucinated information about an identified or reasonably identifiable person. The OAIC recommends particular caution with sensitive information and publicly available generative-AI tools.
Cyber security and operational control
AI-specific security analysis should address access control, data leakage, prompt injection, insecure output handling, model inversion or extraction, maliciously modified or poisoned data, supply-chain compromise, model drift, logging, provenance, change control and incident response. Organisations subject to critical-infrastructure, prudential or other cyber security regimes must integrate AI controls with those binding requirements rather than treat AI governance as a standalone exercise.
AI-generated content transparency
The National AI Centre first published voluntary best-practice guidance on AI-generated content transparency, covering labelling, watermarking and metadata recording, on 28 November 2025. The current version, published on 22 April 2026, recommends proportionate disclosure methods such as labelling, watermarking and metadata or provenance measures. This is voluntary best-practice guidance, not a generally applicable statutory labelling regime. Separate binding obligations may arise under consumer, electoral, online-safety, privacy or sector-specific law depending on the content and context.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Laws specifically addressing AI have not been introduced in Brazil yet. The Brazilian AI Bill provides for the definition of generative artificial intelligence (generative AI) as the ‘model of AI specifically designed to generate or significantly modify, with varying degrees of autonomy, text, images, audio, video or software code’.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
National laws specifically addressing AI have not yet passed in Canada. However, Bill C-34 (if enacted) would impose specific obligations on operators of ‘regulated chatbot services’, including requirements to mitigate the risk of communicating harmful content and to address specifically identified harmful behaviours. These provisions are discussed in the User transparency section. Canada’s export control regime is primarily based on the multilateral Wassenaar Arrangement, which does not itself explicitly list AI in current control lists (though high-performance computing systems, encryption tools or network intrusion software, or certain imaging or machine vision sensors that may form part of AI technologies may meet criteria for control).
Due to stalls in global consensus on updating the Wassenaar Arrangement, on 20 July 2024, Canada unilaterally added certain quantum computing and advanced semiconductor technologies to its Export Control List, effectively prohibiting their export to any location other than the United States without an export permit. The list of controlled goods specifically added is part of Export Control List Order SOR/2024-112, where the attached Regulatory Impact Analysis Statement mentions specifically the addition of gate-all-around field-effect-transistors/GAAFET based on their application in creating microchips that run faster and consume less power, thus enabling more powerful and efficient artificial intelligence applications, including for military systems.
Under Canada’s national security powers under the Investment Canada Act, it is advisable to work with counsel to develop a strategy for managing the requisite notification to and/or review by government for all new businesses or acquisitions of business or other foreign direct or indirect investment where there is significant foreign control, to the extent they involve artificial intelligence resources. In April 2026, Innovation, Science and Economic Development Canada launched the Artificial Intelligence Sovereign Compute Infrastructure Program (SCIP), which provides funding for eligible Canadian-owned organisations to build or expand domestic AI compute capacity. The program forms part of the government’s broader Sovereign AI Compute Strategy to reduce reliance on foreign AI infrastructure and support domestic AI development.
The ‘AI for All’ strategy also commits CAD 50 million to expand the Canadian AI Safety Institute to track emerging AI risks, advance technical research, and conduct transparent evaluations of AI models. It proposes creating a Canada Trusted AI Certification program to help Canadians identify trustworthy AI products in the marketplace. The government also intends to work on AI transparency initiatives, including tools such as watermarking AI-generated content.
The Government indications do not create a standalone generative AI regime. However, the Government indications introduce in Article 3 the concept of a General-purpose AI System and in Article 4 evolved from generative algorithms to algorithms in general.
The main regulatory requirements are set out in the Law / Proposed Law section.
In particular, if an AI service provider intends to provide AI services to external users located in China, it may need to pass certain security assessments conducted by the Chinese authorities and complete the required filings with the Chinese authorities.
Under the AI Security Standard, as well as the standards mentioned in the Regulatory Guidance / Voluntary Codes section, AI service providers are required to ensure the security of their services, focusing mainly on the following aspects:
- Training data security: service providers are responsible for ensuring the security of training data through effective data sources due diligence, content moderation, privacy protection and annotation process management.
- Model security: service providers should take effective measures to ensure the security of AI model throughout the entire lifecycle of the model. This includes secure model training, output control, ongoing monitoring and evaluation, updates and upgrades, and the protection of the model’s operating environment.
- Operation security: service providers should implement comprehensive safeguards concerning the provision of services, the transparency of service operations, the collection of input data, the mechanisms for handling complaints and reports and the business continuity planning.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
On 23 March 2026, Cyprus enacted the Copyright and Related Rights (Amendment) Law of 2026, Law 29(I)/2026, introducing protection against the unauthorised making available to the public of certain deepfake imitations. The term ‘deepfake’ has the meaning given to it in Article 3(60) of the EU AI Act.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
Generative AI guidance in France
In France, the CSPLA Report specifies how AI model providers should publish a policy of compliance with European copyright law respecting the authors’ opt-out principle, and to make available to rights holders and the public a sufficiently detailed summary of the content used to train AI models. Templates have been provided for these summaries but have not been kept in the final version of the GPAI Code of Practice.
The Senate Report highlights that today’s AI ecosystem includes ‘more or less open’ models, a distinction that has become central to regulatory debates because openness affects transparency, auditability, and safety oversight. It explains that the EU AI Act now regulates not only AI uses but also foundation models (i.e., GPAI models) themselves, introducing a stricter regime for those deemed systemic‑risk models, due to their scale, dual‑use potential and difficulty to supervise. The report emphasises that generative AI still suffers from core reliability issues (e.g., hallucinations, opacity, and multi‑layered bias) which persist even with mitigation techniques such as Retrieval‑Augmented Generation (RAG), positioning these technical limitations as key reasons regulators now impose model‑level obligations, in addition to downstream application controls.
With regard to privacy aspects, the CNIL Generative AI Guidance provides recommendations on how to ensure privacy safeguards when using generative AI, including: start with specific needs rather than deploying AI without clear purpose; define allowed and prohibited uses, especially regarding personal data; acknowledge system limitations and risks; choose secure deployment methods, preferably using local, specialised systems; train end users on proper usage and risks; and implement appropriate governance ensuring GDPR compliance with all stakeholders involved.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Laws specifically addressing AI have not yet been introduced in Hong Kong.
The GenAI Guideline addresses the technical limitations and service risks of using generative AI, and sets out a governance framework based on five dimensions, namely: personal data privacy, intellectual property, crime prevention, reliability and trustworthiness, and system security. It further outlines key principles of governance, which are in line with international practices, such as:
- compliance with laws and regulations;
- security and transparency;
- accuracy and reliability;
- fairness and objectivity; and
- practicality and efficiency.
Although non-binding, the GenAI Guideline provides practical recommendations to three main types of stakeholders (i.e., Technology Developers, Service Providers and Service Users) based on their respective roles and responsibilities.
For organisations that are regulated by the HKMA, the SFC and/or the MPFA, specific guidelines on the use of generative AI may apply.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
India does not have any specific or standardised list of controls on generative AI.
Due diligence, time-bound take-down and labelling requirements for SGI under the IT Act and the IT Rules are discussed in the Law/proposed law section. Other laws, such as Copyright Act, 1957, may apply if generative AI uses copyright data without due permission, resulting in infringement-related issues.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Israel has not enacted generative‑AI‑specific, cross‑sector obligations (e.g., universal watermarking or content‑labelling laws).
The 2023 AI Policy Paper calls for proportionate transparency and accountability for AI‑generated content where risks to individuals or the public are material.
The PPA’s draft guidance addresses training‑data due diligence, minimisation, disclosure in privacy notices and safeguards against harmful or misleading outputs where personal data are processed, complemented by the PPA’s PETs guide for privacy‑preserving training and inference.
The Financial Sector Report highlights transparency concerns around generative AI, suggesting that enhanced disclosure on information reliability and source attribution may be warranted, especially in the financial sector, and recommending that misleading AI-related marketing practices (AI Washing) be addressed through existing regulatory tools.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Currently, there are no laws in Japan that specifically address this point.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Controls on generative AI in Malta
Malta has not introduced any national provisions specifically regulating generative AI or general-purpose AI models beyond those contained in the EU AI Act.
Laws specifically addressing AI have not been introduced in Mauritius yet.
Laws specifically addressing AI have not been introduced in Mexico yet.
Laws specifically addressing controls on generative AI have not been introduced in Morocco yet.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no statutory controls on the use of generative AI.
The GenAI Guidelines (summarised in the Regulatory Guidance / Voluntary Codes section) are relevant for the New Zealand public sector's use of generative AI tools.
Additionally, the OPC Gen AI Guidance summarises privacy risks arising from the use of generative AI, which organisations subject to the Privacy Act are expected to appropriately mitigate. The risks identified are:
- privacy risks associated with the training data used by generative AI (e.g., how it was collected and whether it was collected with sufficient transparency);
- confidentiality of information entered into generative AI tools;
- accuracy of personal information created by generative AI; and
- individuals' ability to exercise their data subject rights to access and correction of their personal information held in or processed by generative AI tools.
A standalone AI law has not yet been enacted in Nigeria, so there are no specific statutory controls on generative AI.
The content on Controls on generative AI in the European Union applies in Norway.
Peru has not introduced a standalone regulatory regime specifically governing generative AI. However, generative AI systems may be subject to the general obligations and requirements established under the AI Regulation, including those relating to transparency, risk management and human oversight.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
There are no binding generative‑AI‑specific statutory controls. Relevant expectations are set out in SDAIA guidance (see the Regulatory Guidance / Voluntary Codes section).
Laws specifically addressing AI have not yet been introduced in Singapore.
The Model Framework for GenAI sets out nine dimensions for consideration (see the Regulatory Guidance / Voluntary Codes section) in relation to generative AI.
The PDPC’s Proposed Advisory Guidelines on Use of Personal Data in Generative AI clarify how the Personal Data Protection Act 2012 applies to the use of personal data in generative AI models and systems.
The Transparency Guidelines for Generative AI Chatbots set out transparency guidance regarding generative AI chatbots.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Controls on generative AI in the Slovak Republic
The draft law does not introduce a separate national regulatory regime for generative AI or general-purpose AI (GPAI) models. Instead, obligations applicable to such systems remain governed directly by the EU AI Act. Slovak authorities are tasked with supervising and enforcing those obligations within their respective areas of competence.
Consequently, providers of generative AI systems operating in Slovakia will primarily need to comply with the transparency, documentation, copyright and risk-management obligations established under EU law. The draft law focuses on institutional arrangements, supervisory powers, enforcement mechanisms and cooperation with EU authorities rather than introducing additional substantive requirements.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Laws specifically addressing controls on generative AI have not been introduced in South Africa.
The AI Act mandates several obligations on AI business operators that intend to offer products or services utilising generative AI.
- Definition of Generative AI: This term refers to AI systems that produce content such as text, audio, images, and other outputs by mimicking the structure of input data (Article 2, Item 5).
- Advance Notification Obligation: AI business operators must notify users in advance that their products or services are powered by generative AI (Article 31, Paragraph (1)). Non-compliance may result in an administrative fine of up to KRW 30 million (Article 43, Paragraph (1), Item 1).
- Labelling Obligation: Products or services must be clearly labelled as being created by generative AI (Article 31, Paragraph (2)).
- Deepfake Content: AI business operators providing virtual outputs that may be mistaken for real (often referred to as ‘deepfakes’), must ensure these are clearly labelled. If labelled content qualifies as artistic or creative expression, the manner of labelling should not hinder its appreciation (Article 31, Paragraph (3)).
- Compliance Guidance: The specifics of notification and labelling, including potential exceptions, are detailed in the Enforcement Decree (No. 36053), which came into effect on 22 January 2026. The NIA also published practical guidance on generative AI labelling requirements in January 2026.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
General-Purpose AI Models
Article 3(63) of the EU AI Act defines a GPAI (general-purpose AI) model as an:
"AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market."
GPAI models are versatile and can be applied across various domains and contexts. The Act sets requirements to ensure that these specific models, due to their broad applicability and the wide range of tasks they can complete, adhere to high ethical and safety standards. Please note that not all AI models are GPAI models, and the EU AI Act only regulates the latter.
General-Purpose AI Models with Systemic Risk
Article 3(65) of the EU AI Act defines 'systemic risk' as:
"a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain".
Article 51 of the EU AI Act classifies a GPAI as having systemic risk if it has high impact capabilities (this is currently when the cumulative amount of computation used for training is greater than 10 to the power of 25 floating point operations but also through other indicators and benchmarks) or based on a decision of the Commission.
Systemic risk involves the broader, cumulative impact of GPAI models on society. This encompasses scenarios where GPAI models could lead to significant disruptions or risks, necessitating a regulatory focus to prevent widespread adverse effects and ensure resilience across sectors. In view of the higher risks, the Act sets additional requirements for GPAI models with systemic risk.
Importantly, the requirements of a GPAI model / system (i.e., without a specific use case) and the requirement of an AI system based on its risk profile (depending on the use case at stake) can be cumulative. For instance, if the provider of a GPAI model integrates its model in a high-risk AI system, then the rules for both GPAI models and high-risk AI systems should be complied with.
Laws specifically addressing AI have not been introduced in Thailand yet. However, the Generative AI Guideline (2024) provides a voluntary framework addressing the governance of generative AI, including guidance on data governance, model development and deployment, transparency requirements, accountability mechanism, and risk management. The guideline is applicable to organisations using generative AI systems.
Laws specifically addressing AI have not been enacted in Türkiye yet; therefore, there is currently no regulation related to controls on generative AI.
There is no unified federal law or emirate level law in the UAE that has a primary focus on regulating AI (and therefore no specific controls on generative AI).
The DIFC’s Data Protection Regulations does not contain any specific controls on generative AI.
Organisations developing or using AI must comply with existing legislation, including the Equality Act 2010, Data Protection Act 2018, UK GDPR and, now, the Data (Use and Access) Act so those existing controls should be considered.
Additionally, the Crime and Policing Act 2026 amends section 216 of the Online Safety Act 2023 to empower the Secretary of State to make regulations aimed at minimising or mitigating risks of harm to individuals arising from illegal AI-generated content and from the use of AI services for the commission or facilitation of priority offences. Once such regulations are made, AI chatbots and other AI services currently falling outside the scope of the Online Safety Act (i.e. those that do not feature user-to-user sharing or live web searches) will be subject to duties to minimise or mitigate the risks of harm to UK users. These measures are intended to address concerns around children’s interactions with AI chatbots and other AI-related online harms. Given the Online Safety Act’s broad extraterritorial reach to providers whose services have a significant number of UK users or where UK users are among its target markets, the new provisions introduced by the Crime and Policing Act 2026 are likely to affect a wide range of AI service providers regardless of where they are established.
As the US does not have a comprehensive federal law regulating generative AI, controls on generative AI are emerging through a combination of enforcement actions, state and local legislation, and agency rules or guidance.
At the federal level, several agencies, including the FTC and SEC, have taken enforcement actions against deceptive claims about AI. The FTC will be enforcing the TAKE IT DOWN Act, which covers certain types of deepfakes, and has issued rules about impersonation scams and fake reviews that would cover the use of generative AI tools.
At the state level, several jurisdictions have enacted targeted controls on generative AI. These laws include transparency obligations on AI developers, prohibitions on AI-generated deepfakes, disclosure requirements for consumer-bot interactions, and restrictions on chatbot use for mental health or companionship, among other things. Three examples are:
- California’s Generative AI Training Data Transparency Act, which requires disclosure of high-level details about the training data used in generative AI systems
- Connecticut’s SB5, which requires large generative-AI providers (generative AI systems with more than one million monthly users) to embed tamper-resistant “provenance data” in AI-created or materially altered audio, image, or video content, and which separately imposes safeguards and disclosures for AI companion chatbots and disclosure requirements for automated employment-related decision technology
- Utah’s AI Policy Act, which prohibits the undisclosed use of generative AI in regulated occupations and mandates clear disclosure when AI is used in consumer interactions