Which countries regulate high-risk AI?

Where the law defines a class of high-risk or high-impact AI systems and attaches extra obligations to it.

5 of 21 reviewed jurisdictions address this in at least one tracked instrument. Updated 2026-09-26.

Each answer cites the instrument it rests on; open it for the provision and the full analysis. Whether a rule is binding law, a bill or guidance comes from the instrument's type and status, not from wording.

“Not found” means none of the instruments we track for that jurisdiction addresses the topic. It is not a finding that no such rule exists.

Yes — binding law in force (4)

Proposed (6)

  • Argentina

    Proposed

    AI systems with elevated risks must adopt appropriate mitigation measures.

    A possible change to a cited instrument is not yet verified.

    Status verified 2026-09-09

    0 of 4 regions address this
    • Buenos AiresNot found in the instruments we track
    • JujuyNot found in the instruments we track
    • Río NegroNot found in the instruments we track
    • San JuanNot found in the instruments we track
  • Chile

    Proposed

    High-risk AI systems must undergo conformity assessment or registration.

    Status verified 2026-09-08

  • India

    Proposed

    AI used in critical decision-making areas is subject to heightened ethical scrutiny and rigorous reviews.

    Status verified 2026-09-09

    0 of 4 regions address this
    • KarnatakaNot found in the instruments we track
    • MaharashtraNot found in the instruments we track
    • Tamil NaduNot found in the instruments we track
    • TelanganaNot found in the instruments we track
  • Indonesia

    Proposed

    High-risk AI systems must undergo risk and impact assessment before deployment.

    Status verified 2026-09-08

  • Mexico

    Proposed

    AI systems are classified by risk, and high-risk systems face registration, assessment, and conformity obligations.

    A possible change to a cited instrument is not yet verified.

    Status verified 2026-09-09

  • United States

    Proposed

    Covered entities operating very high-compute AI systems must maintain shutdown capabilities and report covered incidents.

    A possible change to a cited instrument is not yet verified.

    Status verified 2026-09-11

    9 of 51 states address this
    • AlabamaNot found in the instruments we track
    • AlaskaNot found in the instruments we track
    • ArizonaNot found in the instruments we track
    • ArkansasNot found in the instruments we track
    • CaliforniaPartly — regional, framework or general (non-AI) law

      It defines frontier models by compute threshold and imposes safety, reporting, and transparency duties on their developers.

      Status verified 2026-09-10

    • ColoradoPartly — regional, framework or general (non-AI) law

      Developers and deployers have duties concerning high-risk AI systems, including assessments and anti-discrimination safeguards.

      Status verified 2026-09-08

    • ConnecticutPartly — regional, framework or general (non-AI) law

      A new impact assessment is required within 90 days after a substantial modification to a high-risk AI system.

      A possible change to a cited instrument is not yet verified.

      Status verified 2026-09-09

    • DelawareNot found in the instruments we track
    • FloridaNot found in the instruments we track
    • GeorgiaNot found in the instruments we track
    • HawaiiNot found in the instruments we track
    • IdahoNot found in the instruments we track
    • IllinoisAdopted — not yet in force

      Large frontier developers must maintain safety frameworks and undergo audits for frontier models posing severe or catastrophic risks.

      A possible change to a cited instrument is not yet verified.

      Status verified 2026-09-09

    • IndianaNot found in the instruments we track
    • IowaNot found in the instruments we track
    • KansasNot found in the instruments we track
    • KentuckyPartly — regional, framework or general (non-AI) law

      It defines high-risk AI and requires risk management before its use in consequential decisions.

      Status verified 2026-09-10

    • LouisianaNot found in the instruments we track
    • MaineNot found in the instruments we track
    • MarylandNot found in the instruments we track
    • MassachusettsNot found in the instruments we track
    • MichiganNot found in the instruments we track
    • MinnesotaNot found in the instruments we track
    • MississippiNot found in the instruments we track
    • MissouriNot found in the instruments we track
    • MontanaPartly — regional, framework or general (non-AI) law

      Deployers of AI controlling critical infrastructure must maintain risk management policies.

      Status verified 2026-09-08

    • NebraskaNot found in the instruments we track
    • NevadaNot found in the instruments we track
    • New HampshireNot found in the instruments we track
    • New JerseyNot found in the instruments we track
    • New MexicoNot found in the instruments we track
    • New YorkPartly — regional, framework or general (non-AI) law

      Large frontier developers must establish and publish frameworks to manage catastrophic risks from frontier models.

      Status verified 2026-09-09

    • North CarolinaNot found in the instruments we track
    • North DakotaNot found in the instruments we track
    • OhioProposed

      Operators of AI systems controlling critical infrastructure must implement risk management policies.

      Status verified 2026-09-11

    • OklahomaNot found in the instruments we track
    • OregonNot found in the instruments we track
    • PennsylvaniaNot found in the instruments we track
    • Puerto RicoNot found in the instruments we track
    • Rhode IslandNot found in the instruments we track
    • South CarolinaNot found in the instruments we track
    • South DakotaNot found in the instruments we track
    • TennesseeNot found in the instruments we track
    • TexasNot found in the instruments we track
    • UtahPartly — regional, framework or general (non-AI) law

      High-risk generative-AI interactions in regulated services require prominent disclosure.

    • VermontNot found in the instruments we track
    • VirginiaNot found in the instruments we track
    • WashingtonNot found in the instruments we track
    • West VirginiaNot found in the instruments we track
    • WisconsinNot found in the instruments we track
    • WyomingNot found in the instruments we track

Guidance or policy only (10)

International organisations (1)

  • European Union

    Yes — binding law in force

    Providers deeming an Annex III system not high-risk must document that assessment before market placement or service.

    A possible change to a cited instrument is not yet verified.

    Status verified 2026-09-11

Not yet reviewed for this topic (65)

We track instruments for these jurisdictions but have not yet classified them for this topic. This is not a finding that they have no such rule.

Austria, Bahrain, Bangladesh, Belgium, Bulgaria, Colombia, Costa Rica, Côte d'Ivoire, Croatia, Cyprus, Czech Republic, Denmark, Ecuador, Egypt, Estonia, Ethiopia, Finland, France, Germany, Ghana, Greece, Hong Kong, Hungary, Iceland, Iran, Iraq, Ireland, Israel, Italy, Kenya, Latvia, Lebanon, Lithuania, Luxembourg, Malaysia, Maldives, Malta, Morocco, Netherlands, New Zealand, Nigeria, Norway, Pakistan, Panama, Peru, Philippines, Poland, Portugal, Qatar, Romania, Russia, Rwanda, Senegal, Serbia, Slovakia, Slovenia, South Africa, Spain, Sweden, Taiwan, Thailand, Tunisia, Ukraine, Uruguay, Uzbekistan