AI regulation is developing quickly and varies by country. Some common themes help organisations prepare.
Risk-Based Approaches
Several regimes, notably the European Union's AI Act, classify AI uses by risk. Some practices are prohibited, high-risk uses (such as in employment, credit, education and critical infrastructure) face requirements for risk management, data governance, documentation, human oversight and accuracy, and lower-risk uses face lighter obligations.
Transparency Duties
Common requirements include telling people when they interact with an AI system, labelling AI-generated content in certain contexts, and explaining automated decisions that significantly affect people.
Existing Laws Already Apply
Even without AI-specific laws, AI systems must comply with:
- privacy and data protection law;
- anti-discrimination law;
- consumer protection rules against misleading claims;
- sector regulation in finance, health and other fields;
- intellectual property law.
Voluntary Frameworks
Governments and standards bodies publish guidance and frameworks — such as the NIST AI Risk Management Framework, ISO/IEC standards and national AI ethics principles — that are often referenced by regulators.
How to Prepare
- Keep an inventory of AI systems and their uses.
- Assess and document risks, especially for decisions about people.
- Maintain documentation of data, testing and oversight.
- Assign accountability and monitor systems in use.
- Track developments in each jurisdiction where you operate.
This is a general overview, not legal advice; requirements change and depend on where and how you operate.