AI regulation by use case
The rules that apply to each AI use case, from the EU AI Act to sector regulation, and the controls that satisfy them.
EU AI Act
European Union · Europe
Regulation (EU) 2024/1689: risk based rules for AI systems, with obligations for high risk systems listed in Annex III and transparency duties under Article 50.
Applies to 197 use cases
GDPR
European Union · Europe
General Data Protection Regulation, including Article 22 on decisions based solely on automated processing.
Applies to 180 use cases
ISO/IEC 42001
ISO and IEC · Global
The international management system standard for AI.
Applies to 110 use cases
NIST AI Risk Management Framework
NIST · North America
Voluntary US framework to map, measure, manage and govern AI risk, with a generative AI profile.
Applies to 83 use cases
DORA
European Union · Europe
Digital Operational Resilience Act for financial entities: ICT risk, incident reporting and third party risk, including AI providers.
Applies to 66 use cases
UK GDPR
Information Commissioner's Office · Europe
The UK's version of the GDPR, including rules on solely automated decisions.
Applies to 64 use cases
FCA Consumer Duty
Financial Conduct Authority · Europe
UK rules that require firms to deliver good outcomes for retail customers, including through automated channels.
Applies to 47 use cases
MAS AI risk management guidelines
Monetary Authority of Singapore · Asia Pacific
Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.
Applies to 36 use cases
APRA CPS 230
Australian Prudential Regulation Authority · Asia Pacific
Australian operational risk standard covering critical operations and material service providers.
Applies to 25 use cases
PCI DSS
PCI Security Standards Council · Global
Security standard for any system that stores, processes or transmits cardholder data.
Applies to 20 use cases
SR 11-7 model risk management
Federal Reserve and OCC · North America
US supervisory guidance on model risk management, applied by banks to AI and machine learning models.
Applies to 20 use cases
UK Algorithmic Transparency Recording Standard
UK Government · Europe
Mandatory transparency records for algorithmic tools used by UK central government.
Applies to 16 use cases
FATF Recommendations
Financial Action Task Force · Global
Global standards for anti money laundering and counter terrorist financing that national rules implement.
Applies to 15 use cases
EU Anti Money Laundering Regulation
European Union · Europe
Regulation (EU) 2024/1624: the single EU rulebook for customer due diligence, beneficial ownership and suspicious transaction reporting.
Applies to 14 use cases
NIS2 Directive
European Union · Europe
Directive (EU) 2022/2555 on cybersecurity for essential and important entities, including telecom networks, energy and public administration.
Applies to 14 use cases
Bank Secrecy Act
FinCEN · North America
US anti money laundering law: customer due diligence, suspicious activity reports and record keeping.
Applies to 13 use cases
European Accessibility Act
European Union · Europe
Directive (EU) 2019/882: accessibility requirements for banking services, ecommerce and other digital services, applicable since June 2025.
Applies to 12 use cases
HIPAA
US Department of Health and Human Services · North America
US rules for the privacy and security of protected health information.
Applies to 12 use cases
Telecom consumer protection rules
National telecom regulators · Global
National rules on telecom contracts, switching, billing disputes and marketing consent.
Applies to 12 use cases
European Electronic Communications Code
European Union · Europe
Directive (EU) 2018/1972: consumer protection, contract, switching and security rules for telecom operators.
Applies to 11 use cases
Telephone Consumer Protection Act
Federal Communications Commission · North America
US consent rules for automated and prerecorded calls and texts; the FCC has confirmed AI generated voices count as artificial voices.
Applies to 11 use cases
MAS Notice 626
Monetary Authority of Singapore · Asia Pacific
Singapore's anti money laundering and counter terrorism financing requirements for banks.
Applies to 10 use cases
MiFID II
European Union · Europe
Directive 2014/65/EU on markets in financial instruments: suitability and appropriateness of advice, record keeping and product governance.
Applies to 10 use cases
PSD2
European Union · Europe
Payment Services Directive 2: strong customer authentication, transaction risk analysis exemptions and open banking access.
Applies to 10 use cases
EBA Guidelines on loan origination and monitoring
European Banking Authority · Europe
Expectations for credit decisioning, including the use of automated models.
Applies to 9 use cases
ECOA and Regulation B
Consumer Financial Protection Bureau · North America
US fair lending rules, including specific reasons in adverse action notices, which also apply when credit decisions use AI models.
Applies to 8 use cases
Solvency II
European Union · Europe
Directive 2009/138/EC: risk based capital, governance and model requirements for insurers.
Applies to 8 use cases
Insurance Distribution Directive
European Union · Europe
Directive (EU) 2016/97: conduct rules for selling insurance, including demands and needs testing and advice.
Applies to 6 use cases
CBUAE guidance on AI and ML
Central Bank of the UAE · Middle East
UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.
Applies to 5 use cases
PRA SS1/23 model risk management
Prudential Regulation Authority · Europe
UK model risk management principles for banks, covering AI and machine learning models.
Applies to 4 use cases
UK APP scam reimbursement rules
Payment Systems Regulator · Europe
Mandatory reimbursement of authorised push payment scam victims by UK payment firms, which shifts scam losses onto banks.
Applies to 4 use cases
Australian Scams Prevention Framework
Australian Treasury · Asia Pacific
Economy wide obligations for banks, telcos and digital platforms to prevent, detect, disrupt and respond to scams.
Applies to 3 use cases
EU Market Abuse Regulation
European Union · Europe
Regulation (EU) 596/2014: insider dealing and market manipulation, including the duty to detect and report suspicious orders and transactions.
Applies to 3 use cases
Fair Credit Reporting Act
Federal Trade Commission · North America
US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.
Applies to 3 use cases