Filter
Showing all
All Requirements · 24 total 11 categories
ID
Requirement
Enacted
Proposed
Transparency & Disclosure 3 requirements
T-01
AI Identity Disclosure Deployers must inform users when they are interacting with an AI system rather than a human — through initial disclosure, periodic reminders in extended sessions, and/or accurate identification whenev
DeveloperDeployerManufacturerProfessionalGovernment Chatbot
24
177
T-02
AI Content Labeling & Provenance AI-generated content must be identifiable through visible labels, embedded provenance signals, platform-level detection, or detection tools.
DeveloperDeployerDistributorManufacturerProfessionalGovernment Foundation ModelSocial MediaCommunicationsSearchRecording DevicePolitical AdvertisingModel Hosting
12
84
T-03
Training Data Disclosure Developers must disclose information about the data used to train AI models, either publicly or to regulatory authorities.
DeveloperDeployer Foundation Model
2
38
Human Oversight & Fairness 2 requirements
H-01
Human Oversight of Automated Decisions Deployers that use AI to make or inform consequential decisions about individuals must give those individuals meaningful rights to understand, review, and/or challenge the decision, and/or to obtain h
DeveloperDeployerProfessionalGovernment EmploymentFinancial ServicesHealthcareGovernment System
10
181
H-02
Non-Discrimination & Bias Assessment Deployers must test and formally assess AI systems used in high-stakes contexts for discriminatory impact across protected characteristics before deployment, and document and retain the results.
DeveloperDeployerDistributorProfessionalGovernment EmploymentFinancial ServicesHealthcareGovernment System
8
171
Safety & Prohibited Conduct 4 requirements
S-01
AI System Safety Program Operators of high-risk AI must evaluate for risks before deployment, test adversarially, and maintain documented safety controls on an ongoing basis.
DeveloperDeployerManufacturerProfessionalGovernment Foundation ModelHealthcareGovernment System
1
88
S-02
Prohibited Conduct & Output Restrictions Certain AI conduct is categorically prohibited. Other output categories must be restricted or subject to active safety protocols based on deployment context and user population.
DeveloperDeployerDistributorManufacturerGovernment ChatbotMinorsGeneral Consumer AppGovernment System
9
118
S-03
Frontier Model Safety Obligations Large frontier model developers face specific obligations around catastrophic risk assessment, dual-use evaluation, deployment thresholds, and compute reporting.
DeveloperDeployerGovernment Foundation Model
3
20
S-04
AI Crisis Response Protocols Deployers of conversational AI, companion chatbots, and mental-health AI systems must maintain protocols to detect and respond to user expressions of suicidal ideation, self-harm, or intent to harm ot
DeveloperDeployer Consumer TechnologyMental HealthHealthcareChatbot
12
47
Governance & Documentation 3 requirements
G-01
AI Governance Program & Documentation Organizations must establish a documented AI governance program, maintain records sufficient for regulatory review, and designate accountability for AI compliance.
DeveloperDeployerDistributorProfessionalGovernment
17
226
G-02
Public Transparency & Documentation Developers must publish standardized documentation describing an AI system's capabilities, limitations, intended uses, safety measures, and/or risk assessments, and keep it current as of deployment.
DeveloperDeployerDistributorManufacturerGovernment Foundation Model
13
109
G-03
Whistleblower & Anti-Retaliation Protections AI governance statutes require organizations to implement internal safety reporting mechanisms and prohibit retaliation against employees who make good-faith safety disclosures.
DeveloperDeployerGovernment Foundation Model
3
67
Data Governance 1 requirement
D-01
Automated Processing Rights & Data Controls Deployers must honor individuals' rights to know about, correct, and/or opt out of automated processing of their personal data for consequential decisions, and must restrict use of sensitive attribute
DeveloperDeployerDistributorManufacturerProfessionalGovernment EmploymentFinancial ServicesHealthcare
11
225
Consumer Protection 3 requirements
CP-01
Deceptive & Manipulative AI Conduct AI must not deceive or manipulate users — whether through impersonation, dark patterns, false personalization, or fabricated political content.
DeveloperDeployerDistributorManufacturer ChatbotPolitical AdvertisingGeneral Consumer App
33
269
CP-02
Non-Consensual Intimate Imagery Generating, distributing, or facilitating the distribution of non-consensual intimate imagery using AI tools is prohibited and gives rise to civil and criminal liability.
DeveloperDeployerDistributor General Consumer AppSocial Media
9
76
CP-03
Algorithmic Anti-Competitive Coordination Developers, distributors, and/or deployers must not build, license, sell, operate, or use algorithmic or computational tools that ingest nonpublic competitively sensitive data from competing market pa
DeveloperDeployerDistributor
0
55
Public Sector AI 1 requirement
PS-01
Government AI Accountability Government agencies using AI must inventory systems, assess impacts, meet procurement standards, and disclose AI use to affected individuals.
DeveloperDeployerGovernment Government System
10
74
Reporting & Regulatory Submissions 3 requirements
R-01
Incident Reporting Deployers must report significant AI safety incidents to the designated regulatory authority within the required timeframe, on an accelerated basis for incidents posing imminent risk of death or serio
DeveloperDeployerManufacturerGovernment Foundation ModelHealthcare
5
53
R-02
Regulatory Disclosure & Submissions Developers or deployers must submit documentation about AI systems to regulatory authorities, either on a defined schedule or on demand.
DeveloperDeployerDistributorProfessionalGovernment Foundation ModelGovernment System
18
203
R-03
Operational Performance Reporting Deployers of certain AI systems must submit periodic scheduled reports to the designated regulatory authority on system performance in live deployment.
DeveloperDeployerManufacturerGovernment Chatbot
6
54
Healthcare AI 2 requirements
HC-01
Healthcare AI Decision Restrictions Restricts and regulates the use of AI in healthcare coverage determinations, utilization review, and clinical decision-making.
DeveloperDeployerProfessionalGovernment HealthcareInsurance
8
76
HC-02
AI in Licensed Professional Practice Restrictions Professionals must retain full responsibility for AI use in their practice: AI may not independently make therapeutic decisions, conduct therapeutic communication, generate treatment plans without pro
DeveloperDeployerProfessionalGovernment HealthcareMental HealthProfessional ServicesChatbot
8
46
Minor Protection 1 requirement
MN-01
Minor User AI Safety Protections Imposes age verification, parental controls, engagement restrictions, and content safeguards for AI systems accessible to minors.
DeveloperDeployerManufacturerProfessionalGovernment Consumer TechnologySocial MediaEducationChatbot
12
111
EM 1 requirement