For counsel · obligation-first view

AI Obligation Atlas

Most trackers organize by bill. This atlas organizes by duty — each theme links to laws in the LegisGate™ library that imposes it, so counsel can compare the same obligation across jurisdictions.

Consent requirements

88 jurisdictions

Requirements to obtain consent before collecting or processing personal data, or before subjecting individuals to specific AI uses.

98 laws & guidance — e.g. 42 CFR Part 2 · 740 ILCS 14 · Act on the Protection of Personal Information (Act No. 57 of 2003)

AI transparency & disclosure

72 jurisdictions

Duties to disclose AI involvement, label or watermark AI-generated content, and inform users, consumers, or patients that they are interacting with an automated system.

104 laws & guidance — e.g. 2026 Ga. Laws Act 518, amending O.C.G.A. tit. 39, ch. 5 (artificial intelligence companion chatbots) · 42 CFR Part 2 · 740 ILCS 14

Automated decision-making rights

68 jurisdictions

Rights of individuals affected by automated decisions or profiling — explanation, objection, appeal, contest, and opt-out.

72 laws & guidance — e.g. Albania Law 124/2024 · Alberta PIPA · APDPA

Cross-border transfer controls

64 jurisdictions

Controls on moving personal data across borders — adequacy findings, standard contractual clauses, and data-localization mandates.

65 laws & guidance — e.g. Act on the Protection of Personal Information (Act No. 57 of 2003) · ADGM Data Protection Regulations 2021 · Albania Law 124/2024

Risk & impact assessments

50 jurisdictions

Obligations to assess an AI or data-processing system's risks before or during deployment — impact assessments, DPIAs, conformity assessments, and formal risk-management programs.

59 laws & guidance — e.g. ADGM Data Protection Regulations 2021 · Albania Law 124/2024 · APDPA

Vendor & deployer accountability

49 jurisdictions

Obligations that flow through the supply chain — vendor and processor duties, deployer accountability, and third-party oversight.

57 laws & guidance — e.g. 32 CFR Part 170 · A.B. 406 (2025) · AICPA Trust Services Criteria

Breach notification duties

42 jurisdictions

Obligations to notify regulators or affected individuals after a data breach or security incident, usually within a statutory window.

43 laws & guidance — e.g. Act on the Protection of Personal Information (Act No. 57 of 2003) · Albania Law 124/2024 · Australia Privacy Act

Children & minors protections

26 jurisdictions

Heightened duties for services used by children and minors — parental consent, age verification, and design safeguards.

27 laws & guidance — e.g. 2026 Ga. Laws Act 518, amending O.C.G.A. tit. 39, ch. 5 (artificial intelligence companion chatbots) · APDPA · Australia Online Safety Act

Biometric & facial-recognition limits

17 jurisdictions

Restrictions on collecting or processing biometric identifiers — facial recognition, voiceprints, faceprints, and fingerprints.

19 laws & guidance — e.g. 740 ILCS 14 · APDPA · Armenia Law HO-49-N

Human oversight of automated decisions

13 jurisdictions

Requirements to preserve meaningful human review, intervention, or override of automated and AI-driven decisions.

14 laws & guidance — e.g. All Emergency Medicine AI Summit — Statement of Principles v2.0 · C.R.S. § 6-1-1701 et seq. · Canada ADM Directive

Theme membership is computed deterministically from curated SSOT library text — no model-authored analysis. Counts update as the library grows.

Talk to usWe're here to help