Which countries regulate high-risk AI?
Where the law defines a class of high-risk or high-impact AI systems and attaches extra obligations to it.
5 of 21 reviewed jurisdictions address this in at least one tracked instrument. Updated 2026-09-26.
Each answer cites the instrument it rests on; open it for the provision and the full analysis. Whether a rule is binding law, a bill or guidance comes from the instrument's type and status, not from wording.
“Not found” means none of the instruments we track for that jurisdiction addresses the topic. It is not a finding that no such rule exists.
Yes — binding law in force (4)
Brazil
Yes — binding law in forceIt classifies AI solutions as high or low risk and requires continuous auditing and monitoring for high-risk systems.
- Brazil - AI Governance in Judiciary (615/2025), Art. 11, § 1º — Regulation, In Force
- Brazil - National AI Regulation (2.338/2023), Capítulo III, Seção I, § 4º — Bill, Under Review
A possible change to a cited instrument is not yet verified.
Kazakhstan
Yes — binding law in forceIt classifies high-risk AI and subjects critical high-risk systems to state information-security requirements.
- Kazakhstan - AI Regulation (2025), Статья 17, пункт 1 — Act, In Force (Amended)
- Kazakhstan - AI Regulatory Amendments (232-VIII), Article 641-1 — Act, In Force
- Kazakhstan Digital Code, Governance and Institutional Framework — Act, Adopted (from 2026-07-01)
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-10
South Korea
Yes — binding law in forceHigh-impact AI operators must conduct risk assessments, manage risks, monitor safety incidents, and explain outcomes.
- South Korea AI Trust Framework Act, Key Focus Areas — Act, In Force
- South Korea - AI Industry Promotion (AIPTRXX/2022), Obligations and risk approach — Bill, Proposed
- South Korea - AI Privacy Risk Management, Key features — Guideline, In Force
- and 2 more
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-10
0 of 1 regions address this
- SeoulNot found in the instruments we track
Vietnam
Yes — binding law in forceHigh-risk AI systems must undergo mandatory conformity assessment and registration before market entry.
- Vietnam - Digital Technology Law (71/2025/QH15) — Act, In Force
- Vietnam AI Act 2025 — Act, In Force
Status verified 2026-09-08
0 of 1 regions address this
- Ho Chi Minh CityNot found in the instruments we track
Proposed (6)
Argentina
ProposedAI systems with elevated risks must adopt appropriate mitigation measures.
- Argentina - AI Regulation Framework (2505-D-2023), Artículo 10 — Bill, Proposed
- Argentina - Responsible AI Use (3003-D-2024), Artículo 7.2.b — Bill, Under Review
- Buenos Aires AI Guidelines for the Judiciary, Key Focus Areas — Guideline, In Force
- and 1 more
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-09
0 of 4 regions address this
- Buenos AiresNot found in the instruments we track
- JujuyNot found in the instruments we track
- Río NegroNot found in the instruments we track
- San JuanNot found in the instruments we track
Chile
ProposedHigh-risk AI systems must undergo conformity assessment or registration.
- Chile - AI and Robotics Regulation (Boletín 15869-19), Implementation Framework — Bill, Under Review
- Chile - AI Systems Regulation (Boletín 16821-19), Key Focus Areas — Bill, Under Review
- Chile - National AI Policy Update (12/2024), Key Focus Areas — Decree, In Force
- and 2 more
Status verified 2026-09-08
India
ProposedAI used in critical decision-making areas is subject to heightened ethical scrutiny and rigorous reviews.
- India AI Ethics and Accountability Bill, Key Focus Areas — Bill, Proposed
- India - National AI Strategy, Monitoring and Evaluation — Policy, Adopted (from 2018-06-01)
- India - AI Development Recommendations, Governance — Policy, Adopted
Status verified 2026-09-09
0 of 4 regions address this
- KarnatakaNot found in the instruments we track
- MaharashtraNot found in the instruments we track
- Tamil NaduNot found in the instruments we track
- TelanganaNot found in the instruments we track
Indonesia
ProposedHigh-risk AI systems must undergo risk and impact assessment before deployment.
- Indonesia - National AI Regulation, Obligations and enforcement — Decree, Draft
- Indonesia - Draft AI Bill, Key Focus Areas — Bill, Draft
- Indonesia - National AI Roadmap, Compliance Checklist — Policy, Draft
- and 3 more
Status verified 2026-09-08
Mexico
ProposedAI systems are classified by risk, and high-risk systems face registration, assessment, and conformity obligations.
- Mexico - Federal AI Legislative Initiatives — Bill, Under Review
- Mexico - AI Strategy Development, Implementation Framework — Policy, Adopted
- Mexico - AI Development Guidelines (2018), Implementation Framework — Guideline, In Force
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-09
United States
ProposedCovered entities operating very high-compute AI systems must maintain shutdown capabilities and report covered incidents.
- US AI Kill Switch Bill for Rogue Systems, Sec. 2220F(b)(1) — Bill, Proposed
- US Comprehensive AI Framework Bill, Key Focus Areas — Bill, Proposed
- TRUMP AMERICA AI Act (Sen. Blackburn AI policy framework discussion draft) — Bill, Draft
- and 6 more
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-11
9 of 51 states address this
- AlabamaNot found in the instruments we track
- AlaskaNot found in the instruments we track
- ArizonaNot found in the instruments we track
- ArkansasNot found in the instruments we track
- CaliforniaPartly — regional, framework or general (non-AI) law
It defines frontier models by compute threshold and imposes safety, reporting, and transparency duties on their developers.
- United States - California - AI Transparency Act (SB 53), Section 22757.11(i) — Act, In Force
Status verified 2026-09-10
- ColoradoPartly — regional, framework or general (non-AI) law
Developers and deployers have duties concerning high-risk AI systems, including assessments and anti-discrimination safeguards.
- Colorado AI Act Delay, Key Focus Areas; Monitoring and Evaluation — Act, In Force
Status verified 2026-09-08
- ConnecticutPartly — regional, framework or general (non-AI) law
A new impact assessment is required within 90 days after a substantial modification to a high-risk AI system.
- United States - Connecticut - AI Impact Assessment (Public Act 23-16), Monitoring and Evaluation — Act, In Force
- Connecticut Comprehensive AI Act — Bill, Adopted
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-09
- DelawareNot found in the instruments we track
- FloridaNot found in the instruments we track
- GeorgiaNot found in the instruments we track
- HawaiiNot found in the instruments we track
- IdahoNot found in the instruments we track
- IllinoisAdopted — not yet in force
Large frontier developers must maintain safety frameworks and undergo audits for frontier models posing severe or catastrophic risks.
- Illinois AI Safety Act, Key Focus Areas — Act, Adopted (from 2027-01-01)
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-09
- IndianaNot found in the instruments we track
- IowaNot found in the instruments we track
- KansasNot found in the instruments we track
- KentuckyPartly — regional, framework or general (non-AI) law
It defines high-risk AI and requires risk management before its use in consequential decisions.
- United States - Kentucky - AI Governance Act (SB 4), Section 1(12); Section 3(8) — Act, In Force
Status verified 2026-09-10
- LouisianaNot found in the instruments we track
- MaineNot found in the instruments we track
- MarylandNot found in the instruments we track
- MassachusettsNot found in the instruments we track
- MichiganNot found in the instruments we track
- MinnesotaNot found in the instruments we track
- MississippiNot found in the instruments we track
- MissouriNot found in the instruments we track
- MontanaPartly — regional, framework or general (non-AI) law
Deployers of AI controlling critical infrastructure must maintain risk management policies.
- United States - Montana - Right to Compute Act (SB 212), Overview — Act, In Force
Status verified 2026-09-08
- NebraskaNot found in the instruments we track
- NevadaNot found in the instruments we track
- New HampshireNot found in the instruments we track
- New JerseyNot found in the instruments we track
- New MexicoNot found in the instruments we track
- New YorkPartly — regional, framework or general (non-AI) law
Large frontier developers must establish and publish frameworks to manage catastrophic risks from frontier models.
- New York AI Frontier Model Safety Requirements Act, Definitions — Act, In Force
- New York RAISE Act Amendments — Act, Awaiting Entry (from 2027-01-01)
- New York AI Discrimination Audit Bill, 2025-S1169B (ACTIVE) - SUMMARY — Bill, Under Review
Status verified 2026-09-09
- North CarolinaNot found in the instruments we track
- North DakotaNot found in the instruments we track
- OhioProposed
Operators of AI systems controlling critical infrastructure must implement risk management policies.
- United States - Ohio - AI Regulation (HB 392), Key Focus Areas — Bill, Under Review
Status verified 2026-09-11
- OklahomaNot found in the instruments we track
- OregonNot found in the instruments we track
- PennsylvaniaNot found in the instruments we track
- Puerto RicoNot found in the instruments we track
- Rhode IslandNot found in the instruments we track
- South CarolinaNot found in the instruments we track
- South DakotaNot found in the instruments we track
- TennesseeNot found in the instruments we track
- TexasNot found in the instruments we track
- UtahPartly — regional, framework or general (non-AI) law
High-risk generative-AI interactions in regulated services require prominent disclosure.
- United States - Utah - AI Consumer Protection (SB 226), Section 13-75-103(2)(a) — Act, In Force
- VermontNot found in the instruments we track
- VirginiaNot found in the instruments we track
- WashingtonNot found in the instruments we track
- West VirginiaNot found in the instruments we track
- WisconsinNot found in the instruments we track
- WyomingNot found in the instruments we track
Guidance or policy only (10)
Australia
Guidance or policy onlyAgencies must notify the DTA when they identify a new or reassessed high-risk AI use case.
- Australia - AI Governance Standard, Key Focus Areas — Standard, In Force
- Australia - AI Assurance Framework (2024), Overview / Definitions — Guideline, In Force
- Australia - Responsible AI Use Policy, Definitions — Policy, In Force
- and 2 more
A possible change to a cited instrument is not yet verified.
3 of 7 regions address this
- Australian Capital TerritoryNot found in the instruments we track
- New South WalesPartly — regional, framework or general (non-AI) law
High- or critical-risk AI use cases must be registered and referred for AI Review Committee review.
- Australia - New South Wales - AI Assessment Framework (DCS-2024-04), Section 4 — Post-Assessment Actions (mandatory) — Regulation, In Force
- Australia - New South Wales - AI Assurance Framework (2022), Implementation Framework — Policy, In Force
Status verified 2026-09-10
- Northern TerritoryGuidance or policy only
Medium- and high-risk AI projects require additional assurance steps and advisory-service support.
- Australia - Northern Territory - AI Assurance Framework (2024), Governance and Institutional Framework — Policy, In Force
Status verified 2026-09-09
- QueenslandGuidance or policy only
It calls for additional assurance measures for high-consequence AI systems.
- Australia - Queensland - AI Risk Assessment (2024), Monitoring and Evaluation — Guideline, In Force
Status verified 2026-09-10
- TasmaniaNot found in the instruments we track
- VictoriaNot found in the instruments we track
- Western AustraliaNot found in the instruments we track
Canada
Guidance or policy onlyIt classifies systems into four impact levels, with higher levels determining proportionate required mitigations.
- Canada - Algorithmic Impact Assessment (2019), Section 2.2 — Policy, In Force (Amended)
- Canada - Generative AI Guidance, Implementation Framework — Guideline, In Force
- Canada - Automated Decision-Making Directive, 6.1.2 — Policy, In Force (Amended)
- and 1 more
Status verified 2026-09-07
1 of 4 regions address this
- AlbertaNot found in the instruments we track
- British ColumbiaNot found in the instruments we track
- OntarioNot found in the instruments we track
- QuebecPartly — regional, framework or general (non-AI) law
Privacy impact assessments are required when implementing high-risk technologies such as AI or biometrics.
- Canada - Quebec - Personal Information Protection (Law 25), Key Focus Areas — Act, In Force (Amended)
Status verified 2026-09-09
China
Guidance or policy onlyCritical AI applications are to undergo safety evaluation and conformity assessment before broad deployment.
- China - AI Development Plan (2017), Implementation Framework — Policy, In Force
Status verified 2026-09-09
1 of 4 regions address this
- BeijingNot found in the instruments we track
- ShanghaiPartly — regional, framework or general (non-AI) law
High-risk AI products and services must undergo compliance reviews before deployment.
- China - Shanghai - AI Industry Promotion (2022) — Regulation, In Force
Status verified 2026-09-07
- ShenzhenNot found in the instruments we track
- ZhejiangNot found in the instruments we track
Japan
Guidance or policy onlyIt recommends more rigorous governance measures for higher-risk AI use-cases.
- Japan - AI Utilization Guidelines — Guideline, Adopted (from 2019-08-09)
Status verified 2026-09-10
Saudi Arabia
Guidance or policy onlyIt defines high-risk systems and recommends stronger testing and conformity activities for them.
- Saudi Arabia - AI Adoption Framework, Risk approach and enforcement — Guideline, In Force
- Saudi Arabia - Generative AI Guidelines, Implementation Framework — Guideline, In Force
- Saudi Arabia - National AI Strategy (RAI-SA-NA-NSDAIXX-2020), Implementation actions — Policy, In Force
- and 1 more
Singapore
Guidance or policy onlyIt recommends risk assessment and mitigation for high-impact AI uses such as finance and healthcare.
- Singapore - Ethical AI Advisory Council, Key Focus Areas — Guideline, In Force
- Singapore - National AI Programme, Compliance Checklist / project requirements — Policy, In Force
- Singapore - National AI Strategy (NAIS 2.0), Compliance Checklist — Policy, In Force
- and 1 more
Status verified 2026-09-07
Switzerland
Guidance or policy onlyMaterial AI applications are classified by risk and subject to additional documentation and independent review.
- Switzerland - AI Governance Guidelines (08/2024), Key Focus Areas — Guideline, In Force
Status verified 2026-09-08
Turkey
Guidance or policy onlyHigh-risk GAI applications require additional testing and expert review.
- Turkey - GAI Ethics Guide, Key Focus Areas — Guideline, In Force
- Turkey - Chatbot Privacy Guidelines, Implementation Framework — Guideline, In Force
- Turkey - Personal Data Protection Guidelines, Particular attention — Guideline, In Force
Status verified 2026-09-09
United Arab Emirates
Guidance or policy onlyIt identifies critical decisions as high-risk and suggests stronger safeguards for them.
- United Arab Emirates - AI Ethics Guidelines, Definitions — Guideline, In Force
- United Arab Emirates - AI Ethics Self-Assessment Tool, Implementation Framework — Guideline, In Force
Status verified 2026-09-07
1 of 2 regions address this
- Abu DhabiNot found in the instruments we track
- DubaiGuidance or policy only
It identifies high-impact systems for proportionate controls, including independent external audit or third-party review where appropriate.
- United Arab Emirates - Dubai - Ethical AI Guidelines, Implementation Framework — Guideline, In Force
Status verified 2026-09-09
United Kingdom
Guidance or policy onlyIt identifies high-risk or high-impact applications and advises avoiding standalone AI use where serious harms may result.
- United Kingdom - AI Playbook, Building AI solutions > Identifying use cases for AI > Use c — Guideline, In Force (Amended)
- United Kingdom - AI Safety Cooperation, Implementation Framework — Policy, Adopted (from 2023-11-01)
- United Kingdom - AI as Medical Device Guidance, Implementation Framework — Guideline, In Force
- and 1 more
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-09
0 of 1 regions address this
- ScotlandNot found in the instruments we track
International organisations (1)
European Union
Yes — binding law in forceProviders deeming an Annex III system not high-risk must document that assessment before market placement or service.
- Digital Omnibus on AI, Article 6(4) amendment — Regulation, In Force
- EU AI Act, High-Risk AI System Obligations — Regulation, In Force (Amended)
- EU AI Act Enforcement, Definitions — Regulation, In Force
- and 7 more
A possible change to a cited instrument is not yet verified.
Status verified 2026-09-11
Not yet reviewed for this topic (65)
We track instruments for these jurisdictions but have not yet classified them for this topic. This is not a finding that they have no such rule.
Austria, Bahrain, Bangladesh, Belgium, Bulgaria, Colombia, Costa Rica, Côte d'Ivoire, Croatia, Cyprus, Czech Republic, Denmark, Ecuador, Egypt, Estonia, Ethiopia, Finland, France, Germany, Ghana, Greece, Hong Kong, Hungary, Iceland, Iran, Iraq, Ireland, Israel, Italy, Kenya, Latvia, Lebanon, Lithuania, Luxembourg, Malaysia, Maldives, Malta, Morocco, Netherlands, New Zealand, Nigeria, Norway, Pakistan, Panama, Peru, Philippines, Poland, Portugal, Qatar, Romania, Russia, Rwanda, Senegal, Serbia, Slovakia, Slovenia, South Africa, Spain, Sweden, Taiwan, Thailand, Tunisia, Ukraine, Uruguay, Uzbekistan