Legislative Beat

AI Regulatory Reference

A quick-reference guide to the major AI regulations and frameworks. For compliance guidance, consult legal counsel or your regulatory body directly.

Last updated: Q2 2026

Upskill Your Entire Workforce — Gravi AI
Regulation / FrameworkPlain-Language SummaryWho It May Apply ToStatusOfficial Source
EU AI ActClassifies AI systems by risk (unacceptable, high, limited, minimal). High-risk systems require conformity assessments, documentation, and human oversight.Any org deploying AI in the EU or serving EU customersIn effect; phased compliance timeline through 2027artificial-intelligence-act.eu
NIST AI Risk Management FrameworkVoluntary US framework providing guidance on identifying, measuring, and managing AI risk. Widely adopted as a de facto standard.US-based organizations; increasingly referenced globallyActive (v1.0 published 2023)nist.gov/artificial-intelligence
US State AI LawsColorado, California, Texas, Illinois, and others have enacted or proposed AI-specific laws covering hiring, consumer protection, and high-risk AI use. Patchwork — no federal preemption yet.Organizations with employees or customers in these statesVaries by state; rapidly evolvingncsl.org/financial-services/artificial-intelligence-legislation-database
SEC AI Governance GuidanceSEC has issued guidance on AI use in investment advice, disclosure obligations for AI-related risks, and conflicts of interest in predictive data analytics.Registered investment advisers, broker-dealers, public companiesActive and evolvingsec.gov/ai
FINRA AI GuidanceGuidance for broker-dealers on using AI in customer communications, supervision obligations, and recordkeeping when AI is used in regulated activities.FINRA-registered broker-dealersActivefinra.org/rules-guidance/key-topics/artificial-intelligence
UK AI Regulatory FrameworkPro-innovation, principles-based approach. Assigns AI oversight to existing regulators (FCA, ICO, CMA) rather than creating a new AI regulator. Currently voluntary; AI Safety Institute leads safety research.Organizations operating in the UKActive; AI Opportunities Action Plan released Jan 2025gov.uk/government/publications/ai-regulation-a-pro-innovation-approach
HIPAA + AI (HHS Guidance)Existing HIPAA obligations apply when AI systems process protected health information. HHS has issued guidance on AI in clinical decision-making.Healthcare providers, health plans, covered entities, their vendorsActivehhs.gov/programs/topic-sites/ai
ISO/IEC 42001:2023International standard for AI Management Systems. Certifiable — organizations can obtain third-party certification. Increasingly referenced in procurement and vendor assessments.Any organization globally developing or deploying AIPublished; voluntaryiso.org/standard/81230.html

This table is a starting point for awareness, not legal advice. Regulations change frequently. Consult qualified legal counsel for compliance guidance specific to your organization, industry, and jurisdiction.