Vendor & deployer accountability
Obligations that flow through the supply chain — vendor and processor duties, deployer accountability, and third-party oversight.
US States14 laws
A.B. 406 (2025)
State of Nevada
Selected for any deployment whose tool is available to a person in Nevada, because Nev. Rev. Stat. § 433.567 reaches any person who operates or provides an artificial intelligence system and prohibits mental-health representations and mental-health-service programming regardless of sector. Two further duty sets are entity-gated: Nev. Rev. Stat. § 629.610 for a provider of mental and behavioral health care licensed under chapters 630, 632, 633, 641, 641A, 641B or 641C of NRS, and Nev. Rev. Stat. § 391.297 for a Nevada public school, including a charter school or university school for profoundly gifted pupils.
Law · In Force
Artificial Intelligence Safety Measures Act, Pub. Act 104-0538 (Ill. 2026)
State of Illinois
Frontier developers training or deploying frontier AI models in Illinois; large frontier developers with more than $500 million in annual gross revenue.
Law · Pending
C.R.S. § 6-1-1701 et seq.
State of Colorado
Developers and deployers of Automated Decision-Making Technology making consequential decisions about Colorado consumers.
Law · Pending
Conn. Gen. Stat. §§ 42-515 et seq.
State of Connecticut
CTDPA-covered controllers that train LLMs on personal data of Connecticut residents.
Law · In Force
GovRAMP
United States (state/local)
A cloud service provider offering an IaaS, PaaS or SaaS product — AI-enabled or not — to a United States state, local, education, tribal or territorial government, where the buyer requires GovRAMP (formerly StateRAMP) verification by solicitation, contract or state policy.
Program · In Force
Illinois Human Rights Act artificial intelligence in employment provisions, 775 ILCS 5/2-101, 2-102 (Public Act 103-804)
State of Illinois
An employer covered by the Illinois Human Rights Act — generally any person employing one or more employees within Illinois during 20 or more calendar weeks within the calendar year of or preceding the alleged violation, 775 ILCS 5/2-101(B)(1)(a) — uses artificial intelligence as defined at 775 ILCS 5/2-101(N), which expressly includes generative artificial intelligence, with respect to recruitment, hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure, or the terms, privileges or conditions of employment.
Law · In Force
N.Y. Gen. Bus. Law art. 44-B (§§ 1420–1429) (Responsible AI Safety and Education Act)
State of New York
Developers and deployers of covered AI systems in New York, with overlays for frontier model developers and consequential decisions.
Law · Pending
NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (Dec. 2023)
United States (state insurance, model)
Insurers regulated under a state that has adopted the NAIC bulletin and that use AI in underwriting, rating, claims, marketing, or customer service.
Guidance · In Force
New Hampshire Data Privacy Act
United States — New Hampshire
Law · In Force
Oregon Consumer Privacy Act
United States — Oregon
Law · In Force
R.I. Gen. Laws § 6-48.1
United States — Rhode Island
Law · In Force
Tex. Bus. & Com. Code ch. 552
State of Texas
Applies to a person who promotes, advertises or conducts business in Texas, produces a product or service used by Texas residents, or develops or deploys an artificial intelligence system in Texas (sec. 551.002). There is no revenue, headcount, data-volume or consumer-count threshold anywhere in the Act. Three duties are narrower than the Act: sec. 552.051(b) binds a governmental agency, and secs. 552.053 and 552.054(b) bind a governmental entity as sec. 552.001(3) defines it. One is narrower the other way: sec. 552.051(f) binds the provider of a health care service or treatment.
Law · In Force
Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541)
State of Texas
Controllers and processors conducting business in Texas or targeting Texas residents, excluding small-business and certain entity exemptions.
Law · In Force
Utah Code Ann. tit. 13, ch. 72a (Artificial Intelligence Applications Relating to Mental Health)
State of Utah
Suppliers of mental health chatbots using AI technology that engage Utah users in interactive conversations similar to confidential communications with a licensed mental health therapist — excludes scripted outputs and human-therapist routing tools.
Law · In Force
Global & Voluntary11 laws
Bletchley Declaration
International (AI Safety Summit)
Frontier or advanced AI systems where Bletchley Summit commitments or successor summit declarations apply.
Guidance · In Force
CoE AI Framework Convention (CETS 225)
Council of Europe (multilateral)
Not currently binding on any Party or private organization. Surfaced as a monitored, not-yet-commenced international instrument for any AI deployment with exposure to Council of Europe member States or other signatories, pending entry into force and domestic implementation.
Treaty · Pending
G7 Hiroshima AI Process
G7
Developers of advanced AI systems operating in or serving G7 jurisdictions where Hiroshima Process commitments apply.
Guidance · In Force
IOSCO AI/ML Guidance
International
Surfaced as international supervisory context where a market intermediary or asset manager deploys AI or machine learning. The instrument creates no duty of its own; the binding requirement, if any, is the national securities rule that carries the substance of the measure.
Guidance · In Force
ISO/IEC 27001
International (voluntary)
Surfaced wherever an AI deployment handles information that falls, or should fall, inside an information security management system. ISO/IEC 27001 creates no duty of its own; where an organisation is bound to it, the binding instrument is a contract, a maintained certificate or a regulator instrument, and that document governs scope.
Standard · In Force
MITRE ATLAS
International
Surfaced for any AI deployment as a voluntary security reference. The 39 mitigations are the defender-facing content; ten agentic mitigations apply only where the deployment includes an AI agent, and the generative and predictive mitigations are gated on the declared AI system type.
Framework · In Force
NIST AI 600-1
United States (voluntary)
Surfaced where the declared AI system is generative — the profile's own scope is generative AI as defined in Executive Order 14110, being the class of models that emulate the structure and characteristics of input data to generate derived synthetic content. Every one of the 49 covered subcategories applies to any organisation that adopts the profile; it draws no distinction by sector, size, use case or data type.
Framework · In Force
OECD AI Principles
International (intergovernmental, voluntary)
Surfaced for any AI deployment as a voluntary international reference. The Recommendation draws no distinction by sector, size, use case or data type; paragraph I defines an AI system broadly enough to cover generative systems, a clarification made expressly in the 2023 amendment, and defines AI actors to include organisations that deploy or operate AI. Section 1 is what reaches a deployer; Section 2 is addressed to Adherent governments.
Framework · In Force
OWASP LLM Top 10
International (community standard)
Surfaced where the declared AI system is generative: the catalogue's scope is applications powered by large language models, across the development, deployment and management lifecycle. All ten entries apply to any organisation that applies the list; it draws no distinction by sector, size, use case or data type. Where the model acts rather than answers, the 2026 Preface directs the reader to the companion agentic publication, which is a separate instrument.
Framework · In Force
Paris AI Action Summit Statement
International (AI Action Summit 2025)
Surfaced for any AI deployment as a voluntary international reference. The Statement draws no distinction by sector, size, use case or data type, and its only self-stated limit is subject-matter: footnote 1 confines it to civil applications and use of AI. It addresses the participating states and summit actors, not deployers.
Guidance · In Force
Swiss-U.S. Data Privacy Framework
Switzerland / United States
Transfers of personal data from Switzerland to a U.S. organization relying on Swiss-U.S. DPF self-certification, including an AI vendor receiving Swiss-sourced training, inference or customer data.
Framework · In Force
US Federal8 laws
32 CFR Part 170
United States (federal)
DoD contractors handling Federal Contract Information or Controlled Unclassified Information.
Program · In Force
AICPA Trust Services Criteria
United States (attestation, procurement-driven)
Enterprise customers requiring vendor assurance attestation for cloud and AI services.
Standard · In Force
EEOC Technical Assistance Guidance — Artificial Intelligence and Algorithmic Fairness under Title VII of the Civil Rights Act of 1964 and the Americans with Disabilities Act
United States (federal)
Employers and vendors using AI for hiring, promotion, compensation, or other employment decisions subject to federal anti-discrimination laws.
Guidance · In Force
Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g
United States (federal)
Educational agencies and institutions receiving US Department of Education funds, and vendors acting as school officials with legitimate educational interest.
Law · In Force
Fannie Mae Information Security and Business Resiliency Supplement
United States (GSE)
Sellers, servicers, and technology service providers operating in the Fannie Mae ecosystem.
Guidance · In Force
Federal Reserve SR 26-2 (Revised MRM Guidance)
United States (federal banking)
Federal Reserve/OCC/FDIC-supervised banking organizations using quantitative models -- including non-generative, non-agentic AI/ML -- in material business decisions; most relevant to organizations with over $30 billion in total assets.
Guidance · In Force
Health Information Technology for Economic and Clinical Health Act (HITECH)
United States (federal)
Same covered entities and business associates as HIPAA; HITECH layered direct enforcement on business associates and increased penalties.
Law · In Force
Higher Education Community Vendor Assessment Toolkit (HECVAT)
United States (higher education)
AI or cloud vendors undergoing higher-education institutional security assessment.
Framework · In Force
Asia Pacific8 laws
Data Protection Act 2025 (Kiribati)
Republic of Kiribati
Processing of personal data by controllers and processors in Kiribati — lawful basis, consent, data-subject rights, security and breach notification, data protection impact assessments, cross-border transfer standards; phased application for non–major-importance controllers.
Law · Pending
GB/T 45652—2025
People's Republic of China
Carrying out generative artificial intelligence pre-training or fine-tuning data processing activities for a service provided in China (clause 1). No revenue, headcount or sector threshold. Adoption is voluntary: the standard is a recommended national standard and creates no legal duty of its own.
Standard · In Force
HKMA AI Principles
Hong Kong SAR
HKMA-regulated authorized institutions using AI or GenAI in banking operations.
Guidance · In Force
Indonesia Personal Data Protection Law (UU PDP, Law No. 27 of 2022)
Republic of Indonesia
Any controller or processor handling personal data of individuals in Indonesia, including extraterritorially.
Law · In Force
Malaysia PDPA
Malaysia
Section 2(1): any person who processes, and any person who has control over or authorises the processing of, personal data in respect of commercial transactions. Section 2(2) additionally reaches a person established outside Malaysia who uses equipment in Malaysia for processing otherwise than for transit, who must nominate a representative established in Malaysia under s. 2(3). Section 3 excludes the Federal and State Governments; s. 45 exempts personal, family and household processing and several further classes. No revenue, headcount or record-count threshold. Registration under Division 2 of Part II applies only to classes of data controller specified by Ministerial order under s. 14(1).
Law · In Force
RMI PDPA 2025
Republic of the Marshall Islands
Section 403 applies the Chapter to core Government ministries and agencies of the Republic of the Marshall Islands that may collect, use, store, process, disclose or transfer personal data of natural persons in the Republic. Section 405(c) excludes national State-Owned Enterprises and any agency the President determines. Sections 405(d) and 405(e) bring in any third party acting on behalf of such a ministry or agency as a data controller or data processor. There is no private-sector limb and no revenue, headcount or record-count threshold. Not in effect before 7 October 2026.
Law · Pending
South Korea AI Framework Act
Republic of Korea
Developers, deployers, and providers of AI systems offered or used in South Korea, including extraterritorial operators serving Korean users.
Law · In Force
Tonga Privacy Act 2025
Kingdom of Tonga
Processing of personal information by data controllers and processors in Tonga — lawful basis, consent, data-subject rights including portability, cross-border transfer standards, Privacy Commission supervision.
Law · Pending
Americas7 laws
Alberta PIPA
Alberta, Canada
An organization, as defined in s. 1(1)(i), that collects, uses or discloses personal information about an individual in Alberta (s. 4(1)). There is no commercial-activity threshold and no size threshold. The Act does not apply to a public body (s. 4(2)) or to the purpose-based exclusions in s. 4(3), each of which applies only where the stated purpose is the sole purpose.
Law · In Force
Bahamas DPA
Commonwealth of The Bahamas
The organization is a data controller established in The Bahamas and the data are processed in the context of that establishment (s. 4 (1) (a)), or it is not so established but uses equipment in The Bahamas to process personal data otherwise than for transit (s. 4 (1) (b)), in which case s. 4 (2) additionally requires nomination of a representative established in The Bahamas. Section 4 (3) deems four categories to be established in The Bahamas: an individual ordinarily resident there; a body incorporated or registered under Bahamian law; a partnership or unincorporated association formed under Bahamian law; and any person maintaining an office, branch or agency there through which he carries on a business activity or a regular practice. Section 3 binds the Crown, with the head of a government agency deemed to be the controller. There is no revenue, headcount or sector threshold. Section 5 excludes five categories of data, not classes of organization.
Law · In Force
Bermuda PIPA
Bermuda
An organisation that uses personal information in Bermuda, where the information is used wholly or partly by automated means or forms, or is intended to form, part of a structured filing system (s. 3). An organisation is any individual, entity or public authority that uses personal information (s. 2), and the Act binds the Crown (s. 50).
Law · In Force
EDSTA
Province of Ontario, Canada
The organization is a public sector entity within EDSTA s. 1 (1): an institution within the meaning of s. 2 (1) of the Freedom of Information and Protection of Privacy Act other than the Assembly, an institution within the meaning of s. 2 (1) of the Municipal Freedom of Information and Protection of Privacy Act, a children aid society, or a school board. The cyber duties in O. Reg. 51/26 attach only to the narrower class prescribed by its s. 2: FIPPA educational institutions, Group A, B and C public hospitals, the University of Ottawa Heart Institute, children aid societies and school boards. The under-18 notice duties in O. Reg. 52/26 attach to every school board. The artificial-intelligence duties in ss. 5 and 6 attach only to entities and circumstances prescribed under s. 7, and none is prescribed.
Law · In Force
Law on Promotion of Artificial Intelligence Use (Law No. 31814) and Regulation (Supreme Decree No. 115-2025-PCM)
Republic of Peru
Developers and deployers of AI systems in Peru's public administration, state companies, and private sector (excluding personal use and national defence/security).
Law · Partially In Force
Ley 8968
Republic of Costa Rica
Personal data appearing in an automated or manual database of a public or private body, processed or later used so as to produce effects within the national territory of Costa Rica, or to which Costa Rican legislation applies by reason of a contract or under international law (Ley art. 2; Reglamento art. 3). No size, revenue, consumer-count or sector threshold. The only general carve-out is a database kept for exclusively internal, personal or domestic purposes that is not sold or otherwise commercialised.
Law · In Force
Panama Law 81/2019
Republic of Panama
Processing of personal data in Panama or targeting Panamanian data subjects.
Law · In Force
EU & EEA4 laws
Directive (EU) 2022/2555
European Union & EEA
Essential and important entities in covered sectors using AI in critical digital services or supply chains.
Regulation · In Force
EU General-Purpose AI Code of Practice (GPAI Code) under Regulation (EU) 2024/1689
European Union
Providers of general-purpose AI models placing models on the EU market; downstream deployers relying on GPAI provider documentation.
Framework · In Force
Regulation (EU) 2022/2554 (Digital Operational Resilience Act)
European Union & EEA
EU-regulated financial entities and the ICT third-party service providers (including AI vendors) they rely on.
Regulation · In Force
Regulation (EU) 2024/1689 (Artificial Intelligence Act)
European Union & EEA
Providers placing AI on the EU market, deployers in the EU, and providers or deployers established in third countries whose AI system output is used in the EU.
Regulation · Partially In Force
Europe & Central Asia2 laws
Belarus Law No. 99-Z
Republic of Belarus
Processing of personal data with the use of means of automation, or without them where the data can be searched or accessed by set criteria, by an operator or authorised person as defined in art. 1, within the scope of art. 2(1); excluding processing by natural persons for exclusively personal, family or household use and data classified as state secrets (art. 2(2)).
Law · In Force
Law on Personal Data Protection (Serbia) (Zakon o zaštiti podataka o ličnosti)
Republic of Serbia
Processing of personal data in Serbia or targeting Serbian data subjects; GDPR-aligned controller and processor obligations.
Law · In Force
United States1 law
NY SHIELD Act
New York, United States
Owns or licenses computerized data including private information of a New York resident.
Statute · In Force
Middle East & Africa1 law
Personal Data Protection Law No. 24 of 2023 (Jordan)
Hashemite Kingdom of Jordan
Processing of personal data of Jordanian citizens and residents, including data collected before enactment; cross-border transfers subject to Council adequacy rules.
Law · In Force
Canada1 law
PIPEDA
Canada (federal)
Collection, use or disclosure of personal information in the course of commercial activities in Canada (s. 4(1)(a)), or of employee or job-applicant information in connection with the operation of a federal work, undertaking or business (s. 4(1)(b)). Excluded: government institutions under the Privacy Act, personal or domestic handling by an individual, and handling exclusively for journalistic, artistic or literary purposes (s. 4(2)); business contact information used solely for work-related communication (s. 4.01). Under s. 26(2)(b) intra-provincial commercial activity in Quebec, Alberta and British Columbia is exempted where the substantially similar provincial statute applies (SOR/2003-374, SOR/2004-219, SOR/2004-220), leaving interprovincial and international flows and federal works, undertakings and businesses federally governed.
Law · In Force
Sourced from the LegisGate™ intelligence library — our single source of truth (SSOT). Theme membership is computed deterministically from curated library text; run a LegisGate™ report to see how these obligations apply to your specific AI tool.
