Frameworks

Six families, and how they overlap.

An orientation rather than a list. The full corpus is in the library; this is the shape of it — which families exist, what each is actually about, and where they overlap in ways that catch people out.

EU AI Act

Risk-tiered, with the heaviest duties on high-risk systems and separate transparency duties for interactive and generative use. Deployer obligations sit apart from provider obligations and are the ones most organisations actually hold.

Regulation (EU) 2024/1689

The GDPR family

Impact assessment duties, transparency, and constraints on solely automated decisions. UK GDPR and the DPA 2018 are their own instruments; treating the UK as an EU member state is an error a reviewer sees on the cover.

GDPR · UK GDPR · national implementations

US state privacy

Converging on the idea of a documented assessment and diverging on the trigger, the required contents, retention, and what happens when an attorney general asks for it. A national average satisfies none of them precisely.

A dozen statutes and counting

US employment AI

Bias-audit expectations, candidate notice, and the older anti-discrimination framework that applied to hiring decisions long before anyone called them AI.

NYC LL 144 · Illinois · state and federal anti-discrimination law

Sectoral law

The instruments that reach a deployment because of what the organisation is, not because of what the software does. Frequently the heaviest duties in the set, and frequently the ones a generic AI review misses.

HIPAA · GLBA · ECOA · FCRA · insurance codes

Rest of world

Comprehensive privacy statutes with assessment and automated-decision provisions that reach deployments touching their residents, whatever the deploying organisation's own location.

LGPD · PIPEDA · PIPA · APPI · PIPL · PDPA and others

Where the overlaps bite

Three intersections that produce duplicated or missed work.

Nearly every expensive mistake we see is at a boundary between two families rather than inside one.

01

Privacy assessment and AI assessment are not the same document

A DPIA under Art. 35 and a fundamental rights assessment under Art. 27 ask different questions about the same deployment. Doing one does not discharge the other, and merging them produces a document that satisfies neither structure.

02

Sectoral duties survive the general ones

A healthcare deployment does not stop being subject to health-privacy law because it is also subject to an AI statute. The sets add; they do not replace.

03

Employment law predates all of it

Anti-discrimination frameworks applied to hiring decisions long before AI statutes existed, and they still apply. A review that only looks at the new instruments misses the ones with the longest enforcement history.

Families are orientation, not answers

Which of these reaches your deployment?

Six families is the map. Which instruments inside them attach to what you actually run is a determination, and it is the only version of this question that has an answer.

Talk to usWe're here to help
AI Regulation Frameworks Compared | LegisGate™