Frameworks
Six families, and how they overlap.
An orientation rather than a list. The full corpus is in the library; this is the shape of it — which families exist, what each is actually about, and where they overlap in ways that catch people out.
EU AI Act
Risk-tiered, with the heaviest duties on high-risk systems and separate transparency duties for interactive and generative use. Deployer obligations sit apart from provider obligations and are the ones most organisations actually hold.
Regulation (EU) 2024/1689The GDPR family
Impact assessment duties, transparency, and constraints on solely automated decisions. UK GDPR and the DPA 2018 are their own instruments; treating the UK as an EU member state is an error a reviewer sees on the cover.
GDPR · UK GDPR · national implementationsUS state privacy
Converging on the idea of a documented assessment and diverging on the trigger, the required contents, retention, and what happens when an attorney general asks for it. A national average satisfies none of them precisely.
A dozen statutes and countingUS employment AI
Bias-audit expectations, candidate notice, and the older anti-discrimination framework that applied to hiring decisions long before anyone called them AI.
NYC LL 144 · Illinois · state and federal anti-discrimination lawSectoral law
The instruments that reach a deployment because of what the organisation is, not because of what the software does. Frequently the heaviest duties in the set, and frequently the ones a generic AI review misses.
HIPAA · GLBA · ECOA · FCRA · insurance codesRest of world
Comprehensive privacy statutes with assessment and automated-decision provisions that reach deployments touching their residents, whatever the deploying organisation's own location.
LGPD · PIPEDA · PIPA · APPI · PIPL · PDPA and othersWhere the overlaps bite
Three intersections that produce duplicated or missed work.
Nearly every expensive mistake we see is at a boundary between two families rather than inside one.
Privacy assessment and AI assessment are not the same document
A DPIA under Art. 35 and a fundamental rights assessment under Art. 27 ask different questions about the same deployment. Doing one does not discharge the other, and merging them produces a document that satisfies neither structure.
Sectoral duties survive the general ones
A healthcare deployment does not stop being subject to health-privacy law because it is also subject to an AI statute. The sets add; they do not replace.
Employment law predates all of it
Anti-discrimination frameworks applied to hiring decisions long before AI statutes existed, and they still apply. A review that only looks at the new instruments misses the ones with the longest enforcement history.

Families are orientation, not answers
Which of these reaches your deployment?
Six families is the map. Which instruments inside them attach to what you actually run is a determination, and it is the only version of this question that has an answer.