Filter
Showing all
All Requirements · 25 total 11 categories
ID
Requirement
Enacted
Proposed
Transparency & Disclosure 3 requirements
T-01
AI Identity Disclosure Deployers must inform users when they are interacting with an AI system rather than a human — through initial disclosure, periodic reminders in extended sessions, and/or accurate identification whenev
DeveloperDeployerManufacturerProfessionalGovernment Chatbot
26
179
T-02
AI Content Labeling & Provenance AI-generated content must be identifiable through visible labels, embedded provenance signals, platform-level detection, or detection tools.
DeveloperDeployerDistributorManufacturerProfessionalGovernment Foundation ModelSocial MediaCommunicationsSearchRecording DevicePolitical AdvertisingModel Hosting
13
83
T-03
Training Data Disclosure Developers must disclose information about the data used to train AI models, either publicly or to regulatory authorities.
DeveloperDeployer Foundation Model
2
38
Human Oversight & Fairness 2 requirements
H-01
Human Oversight of Automated Decisions Deployers that use AI to make or inform consequential decisions about individuals must give those individuals meaningful rights to understand, review, and/or challenge the decision, and/or to obtain h
DeveloperDeployerProfessionalGovernment EmploymentFinancial ServicesHealthcareGovernment System
11
180
H-02
Non-Discrimination & Bias Assessment Deployers must test and formally assess AI systems used in high-stakes contexts for discriminatory impact across protected characteristics before deployment, and document and retain the results.
DeveloperDeployerDistributorProfessionalGovernment EmploymentFinancial ServicesHealthcareGovernment System
9
170
Safety & Prohibited Conduct 5 requirements
S-01
AI System Safety Program Operators of high-risk AI must evaluate for risks before deployment, test adversarially, and maintain documented safety controls on an ongoing basis.
DeveloperDeployerManufacturerProfessionalGovernment Foundation ModelHealthcareGovernment System
1
90
S-02
Prohibited Conduct & Output Restrictions Certain AI conduct is categorically prohibited. Other output categories must be restricted or subject to active safety protocols based on deployment context and user population.
DeveloperDeployerDistributorManufacturerGovernment ChatbotMinorsGeneral Consumer AppGovernment System
9
119
S-03
Frontier Model Safety Obligations Large frontier model developers face specific obligations around catastrophic risk assessment, dual-use evaluation, deployment thresholds, and compute reporting.
DeveloperDeployerDistributorGovernment Foundation Model
3
22
S-04
AI Crisis Response Protocols Deployers of conversational AI, companion chatbots, and mental-health AI systems must maintain protocols to detect and respond to user expressions of suicidal ideation, self-harm, or intent to harm ot
DeveloperDeployer Consumer TechnologyMental HealthHealthcareChatbot
13
49
S-05
AI Product Liability & Duty of Care Developers and Deployers bear a duty of care and product liability for injuries their AI systems cause to users, including liability for defective design, inadequate warnings of foreseeable dangers, a
DeveloperDeployerDistributor
0
3
Governance & Documentation 3 requirements
G-01
AI Governance Program & Documentation Organizations must establish a documented AI governance program, maintain records sufficient for regulatory review, and designate accountability for AI compliance.
DeveloperDeployerDistributorProfessionalGovernment
17
229
G-02
Public Transparency & Documentation Developers must publish standardized documentation describing an AI system's capabilities, limitations, intended uses, safety measures, and/or risk assessments, and keep it current as of deployment.
DeveloperDeployerDistributorManufacturerGovernment Foundation Model
13
109
G-03
Whistleblower & Anti-Retaliation Protections AI governance statutes require organizations to implement internal safety reporting mechanisms and prohibit retaliation against employees who make good-faith safety disclosures.
DeveloperDeployerGovernment Foundation Model
3
67
Data Governance 1 requirement
D-01
Automated Processing Rights & Data Controls Deployers must honor individuals' rights to know about, correct, and/or opt out of automated processing of their personal data for consequential decisions, and must restrict use of sensitive attribute
DeveloperDeployerDistributorManufacturerProfessionalGovernment EmploymentFinancial ServicesHealthcare
12
226
Consumer Protection 3 requirements
CP-01
Deceptive & Manipulative AI Conduct AI must not deceive or manipulate users — whether through impersonation, dark patterns, false personalization, or fabricated political content.
DeveloperDeployerDistributorManufacturer ChatbotPolitical AdvertisingGeneral Consumer App
34
275
CP-02
Non-Consensual Intimate Imagery Generating, distributing, or facilitating the distribution of non-consensual intimate imagery using AI tools is prohibited and gives rise to civil and criminal liability.
DeveloperDeployerDistributor General Consumer AppSocial Media
10
75
CP-03
Algorithmic Anti-Competitive Coordination Developers, distributors, and/or deployers must not build, license, sell, operate, or use algorithmic or computational tools that ingest nonpublic competitively sensitive data from competing market pa
DeveloperDeployerDistributor
0
55
Public Sector AI 1 requirement
PS-01
Government AI Accountability Government agencies using AI must inventory systems, assess impacts, meet procurement standards, and disclose AI use to affected individuals.
DeveloperDeployerGovernment Government System
10
81
Reporting & Regulatory Submissions 3 requirements
R-01
Incident Reporting Deployers must report significant AI safety incidents to the designated regulatory authority within the required timeframe, on an accelerated basis for incidents posing imminent risk of death or serio
DeveloperDeployerManufacturerGovernment Foundation ModelHealthcare
5
54
R-02
Regulatory Disclosure & Submissions Developers or deployers must submit documentation about AI systems to regulatory authorities, either on a defined schedule or on demand.
DeveloperDeployerDistributorProfessionalGovernment Foundation ModelGovernment System
18
205
R-03
Operational Performance Reporting Deployers of certain AI systems must submit periodic scheduled reports to the designated regulatory authority on system performance in live deployment.
DeveloperDeployerManufacturerGovernment Chatbot
6
55
Healthcare AI 2 requirements
HC-01
Healthcare AI Decision Restrictions Restricts and regulates the use of AI in healthcare coverage determinations, utilization review, and clinical decision-making.
DeveloperDeployerProfessionalGovernment HealthcareInsurance
9
76
HC-02
AI in Licensed Professional Practice Restrictions Professionals must retain full responsibility for AI use in their practice: AI may not independently make therapeutic decisions, conduct therapeutic communication, generate treatment plans without pro
DeveloperDeployerProfessionalGovernment HealthcareMental HealthProfessional ServicesChatbot
8
48
Minor Protection 1 requirement
MN-01
Minor User AI Safety Protections Imposes age verification, parental controls, engagement restrictions, and content safeguards for AI systems accessible to minors.
DeveloperDeployerManufacturerProfessionalGovernment Consumer TechnologySocial MediaEducationChatbot
13
112
EM 1 requirement
EM-01
Workplace Electronic Monitoring Restrictions Deployers acting as employers that use electronic monitoring or automated decision tools to collect worker data must limit such monitoring to enumerated lawful purposes, use the least invasive availab
DeveloperDeployerGovernment
0
13