157 regulations tracked worldwide

AI Compliance Regulations Directory

Every AI regulation that may apply to your business — from the EU AI Act to US state laws to global data protection rules. Select any regulation to see exactly what your business must do.

Find which laws apply to my business

Most Important Regulations

These affect the most businesses globally. Check these first.

All 157 Regulations by Region

EU(25)

EU Artificial Intelligence Act

The EU AI Act classifies AI systems by risk level and imposes obligations on providers and users. High-risk AI systems r…

EU Digital Services Act (DSA) — AI Transparency Obligations

The EU Digital Services Act (Regulation 2022/2065) has been in force for all online platforms since February 17, 2024. F…

EU GDPR Article 22 — Automated Decision-Making & AI Profiling

GDPR Article 22 (in force since May 25, 2018) gives EU and EEA residents the right not to be subject to decisions based …

EU Digital Operational Resilience Act (DORA)

EU DORA (Regulation 2022/2554, in application January 17, 2025) applies to 20 categories of EU-regulated financial entit…

EU AI Act — General-Purpose AI (GPAI) Model Obligations (Art. 50-55)

As of August 2, 2025, the EU AI Act's obligations for General-Purpose AI (GPAI) model providers and deployers are in ful…

EU Cyber Resilience Act (CRA) — Software & AI Products

The EU Cyber Resilience Act (CRA, Regulation 2024/2847, entered into force December 10, 2024) requires manufacturers and…

EU AI Act — Prohibited Practices (Article 5)

EU AI Act Article 5 bans eight categories of AI outright — no grace period, no exceptions. These prohibitions became enf…

EU AI Act — High-Risk Medical Device AI (Article 6 / MDR / IVDR)

EU AI Act Article 6(1) classifies AI systems embedded in EU-regulated medical devices as high-risk. Any AI-powered medic…

EU Product Liability Directive 2024 — AI Systems (Directive 2024/2853)

Directive (EU) 2024/2853 explicitly classifies AI systems as "products" under EU product liability law, replacing the 19…

Italy — AI Enforcement under GDPR (Garante)

The Italian data protection authority (Garante) is among the most aggressive AI enforcement bodies in the EU. Garante te…

Spain — AI Framework under GDPR (AEPD)

Spain's AEPD has published comprehensive AI-GDPR guidance including a 10-step AI adequacy methodology, algorithmic bias …

Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens)

The Dutch DPA (AP) fined Uber for automated decision-making violations in 2023 and is a leading EU enforcement authority…

Poland — AI Framework under GDPR (UODO)

Poland's UODO has issued GDPR-AI guidance requiring DPIAs for AI profiling systems and human review for automated decisi…

Ireland — GDPR AI Enforcement (Data Protection Commission)

Ireland's DPC is the lead GDPR supervisor for most major US tech companies in the EU. DPC issued a €1.2B fine against Me…

Sweden — AI Guidance under GDPR (IMY)

Sweden's IMY published detailed generative AI and GDPR guidance in 2023. IMY fined Spotify €5M in 2023. IMY requires a d…

Luxembourg — GDPR + EU AI Act + Digital Luxembourg Strategy 2025

Luxembourg is a major EU financial and tech hub (Amazon EU HQ, Skype, PayPal, Spotify European headquarters). The CNPD (…

Slovakia — GDPR + EU AI Act + Slovak AI Strategy 2030

Slovakia's data protection authority is the Úrad na ochranu osobných údajov Slovenskej republiky (UOOU). Slovakia has ad…

Estonia — GDPR + EU AI Act + Estonian AI Strategy (e-Governance Leader)

Estonia is the world's most digitally advanced country — 99% of government services are online, and the X-Road data exch…

Latvia — GDPR + EU AI Act + Latvian AI Strategy 2021-2027

Latvia's Datu valsts inspekcija (DVI) supervises GDPR and AI data processing. Latvia's AI Development Guidelines 2021-20…

Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy

Lithuania's Valstybinė duomenų apsaugos inspekcija (VDAI) supervises GDPR compliance. Lithuania adopted its AI Strategy …

Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme

Bulgaria's Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни) supervises data protectio…

Croatia — GDPR + EU AI Act + Croatian AI Strategy 2021

Croatia's Agencija za zaštitu osobnih podataka (AZOP) supervises GDPR. Croatia adopted its National AI Development Strat…

Slovenia — GDPR + EU AI Act + Slovenian Digital Strategy + AI Sandbox

Slovenia's Informacijski pooblaščenec (Information Commissioner, IP) supervises both data protection and freedom of info…

Cyprus — GDPR + EU AI Act + Cyprus Digitalization Strategy + CPDBP

Cyprus's Commissioner for Personal Data Protection (CPDBP) supervises GDPR compliance. Cyprus has positioned itself as a…

Malta — GDPR + EU AI Act + Malta AI Strategy 2019 (World's First National AI Strategy)

Malta made history in 2019 by becoming the first country in the world to publish a National AI Strategy. The Malta Infor…

US-CA(4)

US-CO(1)

US-IL(3)

US-NY(3)

UK(1)

CN(1)

JP(1)

AU(1)

Middle East(8)

Qatar Personal Data Protection Law (PDPL)

Qatar Law No. 13 of 2016 (PDPL), enforced by the National Cyber Security Agency (NCSA), governs personal data processing…

Bahrain Personal Data Protection Law (PDPL)

Bahrain Decree No. 30 of 2018 (PDPL), enforced by the Personal Data Protection Authority (PDPA), applies to any entity p…

Kuwait Law No. 20 of 2014 — Personal Data Protection + National AI Strategy 2023

Kuwait Law No. 20 of 2014 on the Protection of Personal Data regulates automated processing of personal data for all org…

UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection + UAE AI Strategy 2031

The UAE Personal Data Protection Law (PDPL/PDPA) is enforced by the UAE Data Office. It covers processing of personal da…

Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016) + NDS 2030

Qatar's Personal Data Privacy Protection Law (PDPPL) governs collection, processing, and transfer of personal data in Qa…

Bahrain Personal Data Protection Law (PDPL, Law No. 30 of 2018)

Bahrain's PDPL (Law No. 30 of 2018) is the first comprehensive data protection law in the GCC, predating Saudi Arabia's …

Israel Privacy Protection Law (PPL 5741-1981) + 2023 Reform + INCD AI

Israel's Privacy Protection Law (PPL, 5741-1981) is administered by the Privacy Protection Authority (PPA, formerly ILIT…

Saudi Arabia Personal Data Protection Law (PDPL) + Vision 2030 AI Programme

Saudi Arabia's PDPL enforced by SDAIA (Saudi Data and AI Authority) is one of the Gulf's most comprehensive data protect…

Asia Pacific(5)

Latin America(3)

Africa(2)

Europe(1)

AE(1)

AR(1)

Asia-Pacific(1)

AT(1)

BE(1)

BR(1)

CA(1)

CA-AB(1)

CA-BC(1)

CA-ON(1)

CA-QC(1)

CH(1)

CZ(1)

DE(1)

DK(1)

FI(1)

FR(1)

GR(1)

HU(1)

ID(1)

IL(1)

KE(1)

KR(1)

Middle East / Africa(1)

MY(1)

NG(1)

NO(1)

NZ(2)

PH(1)

PT(1)

RO(1)

SA(1)

SG(1)

TH(1)

TW(1)

US-AK(1)

US-AL(1)

US-AR(1)

US-AZ(1)

US-CT(1)

US-DC(1)

US-DE(1)

US-FL(2)

US-GA(2)

US-HI(1)

US-IA(1)

US-ID(2)

US-IN(1)

US-KS(1)

US-KY(1)

US-LA(2)

US-MA(1)

US-MD(1)

US-ME(1)

US-MI(1)

US-MN(2)

US-MO(1)

US-MS(1)

US-MT(1)

US-NC(1)

US-ND(1)

US-NE(2)

US-NH(1)

US-NJ(1)

US-NM(1)

US-NV(1)

US-NY-NYC(1)

US-OH(1)

US-OK(1)

US-OR(1)

US-PA(1)

US-RI(1)

US-SC(1)

US-SD(1)

US-TN(2)

US-TX(2)

US-UT(4)

US-VA(1)

US-VT(1)

US-WA(3)

US-WI(1)

US-WY(1)

VN(1)

ZA(1)

Don't read every regulation manually

Answer 15 questions about your business and ComplianceIQ tells you exactly which of these 157 regulations apply — and what you need to do.

Start free compliance scan