Source Libraries
The governed source libraries behind the examination, downloadable as delivered.
United States
US-federal-voluntaryTier 2 · primary html
Four functions: GOVERN, MAP, MEASURE, MANAGE. GOVERN assumes accountable humans making decisions. MANAGE requires ongoing monitoring and human intervention capability. Generative AI Profile (NIST-AI-600-1, July 2024) adds 12 generative-AI-specific risk categories. February 2026 NIST initiative adds standards for autonomous AI agents: agent identity, action logging, and containment boundaries.
US-federal-binding-broker-dealersTier 2 · primary html
AI outputs face the same supervisory standards as human-generated content. Firms must document how AI is used, test and monitor outputs, assign human accountability, and retain records related to AI-assisted decisions. Technology-neutral: supervision must focus on outcomes, not intent. Three novel risks flagged: autonomy (agents acting without human validation), scope creep, and auditability.
US-federalTier 2 · primary html
AI-generated content subject to unfair or deceptive practices standards. Unsubstantiated AI governance claims are a deceptive practice trigger. Section 5 applies to any AI claim that cannot be substantiated.
US-federalTier 2 · primary html
Requires explainability for AI-driven credit decisions under existing obligations. Applicable when AI system influences access to credit or financial services.
European Union
EU-extraterritorialTier 2 · primary htmlEnforcement: 2026-08-02
Article 14 — Human oversight: natural persons must monitor AI behavior, detect automation bias, interpret outputs, and retain authority to reject, override, or interrupt. Oversight personnel must be named, competent, and documented before deployment.
EU-extraterritorialTier 2 · primary htmlEnforcement: 2026-08-02
Logging: AI systems must generate tamper-evident audit trails of relevant events as a built-in technical feature. Logs must capture inputs, outputs, and decisions in sufficient detail for traceability. Deployers must retain logs for minimum 6 months.
EU-extraterritorialTier 2 · primary htmlEnforcement: 2026-08-01
Transparency: AI-generated content must be labelled. Transparency obligations for AI systems active August 2026 per EU Commission July 2026 update. Code of Practice on marking and labelling AI-generated content published June 2026.
EU-extraterritorialTier 2 · primary htmlEnforcement: 2025-08-02
General-Purpose AI model providers face transparency and documentation obligations. Active August 2025. Applies to any company whose product is built on or integrates a GPAI model.
United Kingdom
Continuous supervision model for AI in financial services. More than 80% of financial services firms already using or adopting AI — FCA policy focus has shifted from adoption to large-scale deployment governance. Firms must preserve trust, competition, and resilience. AI governance claims in financial services require substantiation.
Model risk framework extends to AI-informed decisions. Human oversight for high-impact AI-informed decisions required alongside MAS, OCC, Bank of Thailand convergence.
Australia
APRA letter to industry, 'Letter to Industry on Artificial Intelligence (AI)', published 30 April 2026, addressed to all APRA-regulated entities (banks, insurers and superannuation trustees): outlines observations from a late-2025 targeted supervisory engagement and APRA's expectations for managing AI-related risk. Warns that governance, risk management, assurance and operational resilience practices are not keeping pace with AI adoption; sets minimum Board expectations (AI literacy sufficient for effective challenge; oversight of an AI strategy consistent with risk appetite, with monitoring, reporting and defined triggers); states APRA's principle-based prudential framework is technology and vendor agnostic and requires appropriate AI risk management — risk appetite, exposure management, oversight and accountability — with stronger supervisory action and enforcement where risks are not managed proportionately. Companion media release, same date, confirms no additional requirements proposed at this stage. Supervisory letter; not a binding statute.
Voluntary AI Safety Standard (VAISS): non-binding guideline and procedure for implementing safe, responsible AI systems across all sectors. Implementation guidance covering six essential practices: (1) Decide who is accountable, (2) Understand impacts and plan accordingly, (3) Measure and manage risks, (4) Share essential information, (5) Test and monitor, (6) Maintain human control. Both on-disk captures state the implementation guidance 'evolves the Voluntary AI Safety Standard'.
Singapore
First governance framework written specifically for autonomous AI agents, launched at Davos January 22, 2026. Graduated autonomy model: oversight intensity proportional to action impact. Every prior framework (NIST, ISO 42001, EU AI Act) was built for AI systems a person operates — IMDA framework addresses the gap where agents remove the human from the decision loop.
Human oversight required for high-impact AI-informed decisions. MAS guidelines converge with PRA, OCC, and Bank of Thailand on the same structural requirement: institution remains responsible for decisions regardless of whether a human or AI agent made them.
Hong Kong
HKTier 2 · primary htmlEnforcement: 2024-11-12
SFC circular dated 12 November 2024 to licensed corporations, titled 'Use of Generative AI Language Models': sets out SFC expectations on licensed corporations that offer services or functionality provided by AI language models in their regulated activities. Expectations address hallucination risk (AI language models providing plausible but factually incorrect responses) and performance drift (performance may degrade over time). Applies to AI language model-based third party products used in regulated activities. Supervisory circular; not binding statute.
HKMA circular dated 19 August 2024 to all Authorized Institutions, titled 'Consumer Protection in respect of Use of Generative Artificial Intelligence': board and senior management of authorized institutions remain accountable for all GenAI-driven decisions and processes; authorized institutions should adopt a human-in-the-loop approach during early GenAI deployment; addresses hallucination risk (generating outputs that seem realistic but are factually incorrect). Extends 2019 BDAI guiding principles on governance and accountability, fairness, transparency and disclosure, and data privacy and protection to generative AI use. Supervisory circular; not binding statute.
Japan
Act No. 53 of June 4, 2025 on Promotion of Research and Development, and Utilization of Artificial Intelligence-related Technology: binding statute establishing Japan's basic AI governance framework; declares that artificial intelligence-related technology constitutes a fundamental technology for the development of Japan's economy and society; establishes basic principles including transparency; establishes AI Strategic Headquarters. Bilingual official English translation.
South Korea
KRTier 2 · primary htmlEnforcement: 2026-01-22
Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (Act No. 20676, enacted 21 January 2025, enforcement date 22 January 2026): binding statute establishing Korea's basic AI governance framework; defines high-impact artificial intelligence including systems that perform judgments or evaluations with significant impact on the rights and obligations of individuals, such as hiring and loan screening. Enforcement date 22 January 2026.
China
Interim Measures for the Management of Generative Artificial Intelligence Services (生成式人工智能服务管理暂行办法): binding regulation governing generative AI services publicly available in China, issued by the Cyberspace Administration of China (中国网信网 / 中央网络安全和信息化委员会办公室), issued 10 July 2023, published 13 July 2023. Chinese-language primary instrument.
Measures for Labeling of AI-Generated Synthetic Content (人工智能生成合成内容标识办法), document number 国信办通字〔2025〕2号, dated 14 March 2025: binding regulation issued by the Cyberspace Administration of China, requiring labeling of AI-generated and AI-synthesized content; applies to internet application distribution platforms during app listing and online review (互联网应用程序分发平台在应用程序上架或者上线审核时). Chinese-language primary instrument.
Thailand
Explicit: human participation or human oversight required whenever AI is used for strategic functions, defined to include credit approval, account opening approval, and approval of deposits, withdrawals, or transfers. Lifecycle-wide controls across data quality, model evaluation, explainability, and AI-specific cyber defenses.
United Arab Emirates
UAETier 2 · primary htmlEnforcement: 2023-09-01
DIFC Data Protection Regulations (Consolidated Version No. 2, in force 1 September 2023), Regulation 10 — Personal Data Processed Through Autonomous and Semi-Autonomous Systems: governs personal data processed through autonomous and semi-autonomous systems within the DIFC; sets obligations on deployers and operators of such systems. Binding DIFC regulation. Regulation 10 text cited from the consolidated Data Protection Regulations PDF.
International
internationalTier 2 · primary html
Certifiable AI management system standard. Three-year certification cycle with annual surveillance audits. Controls define roles, responsibilities, and human-in-the-loop controls. ISO 42006:2025 governs AI auditor qualification. Multinational enterprises use 42001 as a compliance passport across jurisdictions. Full RMF implementation provides 60-70% of ISO 42001 certification evidence.
multilateral-46-countriesTier 2 · primary html
Five principles: transparency, accountability, robustness, privacy, human oversight. Soft-law baseline adopted by 46 countries. OECD Reporting Framework launched February 2025; 19 companies reported by April 2025. Non-binding but increasingly the benchmark regulators measure against.
multilateral-G7Tier 3 · trend only
Applies to frontier AI developers. Five principles including human oversight. Endorsed by G7 leaders December 2023. Non-binding but carries weight as political commitment from G7 member regulators who separately enforce binding national frameworks.
Research / Academic
academicTier 3 · trend only
Documents structural gap in LLM-as-a-judge compliance monitoring. Key finding: existing legal instruments were designed to neutralise pre-existing bias in training data, not to detect emergent behavioural drift post-deployment. A single undifferentiated LLM judge with no per-regulatory-article decomposition and no runtime monitoring fails regulatory requirements structurally, not just practically.
Research / Industry
industry-analysisTier 3 · trend only
Nominal oversight is not compliant oversight — a reviewer who lacks the information, authority, or time to genuinely influence an AI decision does not satisfy meaningful human review requirements. The delegation chain is the evidentiary foundation: every AI agent action must be attributable to a human author. Covers GDPR Article 22, EU AI Act, HIPAA, financial services model risk frameworks.
industry-analysisTier 3 · trend only
Model-level defenses (instruction hierarchy, system prompt hardening) are necessary but insufficient. Only access controls enforced at the data layer, independent of the model, can prevent an injected instruction from producing a compliance event. Direct structural argument: one LLM cannot police another LLM's compliance because the defense must be independent of the model layer.