Frameworks & Standards Comparison
AI-specific regimes only. Dates reflect the position as of August 2026 — the EU high-risk deadline moved in July 2026.
| Framework | Origin | Type | Scope | In force since | Deadline to comply |
|---|---|---|---|---|---|
| EU AI Act | EU | Mandatory | Comprehensive risk-tiered AI regulation | 1 Aug 2024 | Transparency live 2 Aug 2026 · high-risk 2 Dec 2027 · embedded AI 2 Aug 2028 |
| Korea AI Basic Act | Korea | Mandatory | High-impact and generative AI, extraterritorial | 22 Jan 2026 | In force now · fines deferred under grace period |
| Colorado ADMT Act | US · CO | Mandatory | Automated decisions affecting consumers | Signed 14 May 2026 | 1 Jan 2027 |
| ISO/IEC 42001 | Intl | Certifiable | AI management systems, modelled on ISO 27001 | Dec 2023 | No legal deadline — driven by customer and tender dates |
| NIST AI RMF | US | Voluntary | Risk management: Govern, Map, Measure, Manage | Jan 2023 | No legal deadline — arrives via contract terms |
| UK approach | UK | Sectoral | No AI Act; ICO, Ofcom and FCA apply existing law | — | No AI-specific deadline — existing duties already apply |
| Singapore MAIGF | SG | Voluntary | Model AI governance framework | 2020, v2 | No legal deadline |
Regulatory Timeline
Prohibited Systems Banned
Social scoring, manipulative AI practices prohibited under EU AI Act.
GPAI Model Obligations
General-purpose AI providers face transparency and documentation duties.
Article 50 โ Transparency Live
Chatbot disclosure and AI-generated content labelling now mandatory.
AI-Generated NCII Prohibitions
New prohibitions on AI-generated non-consensual intimate imagery.
High-Risk AI Full Obligations
Full conformity requirements enforced (extended by Digital Omnibus).
EU Artificial Intelligence Act
The world's first comprehensive AI law. Risk-tiered approach โ prohibited, high-risk, limited-risk, and minimal-risk AI. High-risk systems face conformity assessments, technical documentation, and post-market monitoring.
General-purpose AI models above 10ยฒโต FLOPs face additional systemic risk obligations. Fines reach โฌ35M or 7% of global turnover.
Read the EU AI Act โNIST AI Risk Management Framework
Voluntary but widely adopted GRC structure with four core functions: Govern, Map, Measure, and Manage. Structured approach to identifying and mitigating AI risks across the entire lifecycle.
Version 2.0 includes updated governance guidance and expanded implementation resources.
NIST AI RMF โISO/IEC 42001:2023
International standard for AI Management Systems (AIMS). Certifiable, modelled on ISO 27001. Provides structural backbone for AI GRC programmes.
Demand for certification is rising as the EU AI Act references ISO standards. Particularly adopted in Europe and Asia-Pacific.
ISO/IEC 42001 โUK Pro-Innovation AI Approach
Principles-based, sector-led model. ICO, FCA, CMA, and Ofcom each apply existing powers to AI in their domains. The AI Safety Institute runs frontier model evaluations.
UK AI Policy โSingapore Model AI Governance Framework
MAS and IMDA co-developed one of the world's most detailed voluntary AI governance frameworks for financial services and general use. Widely respected as a balanced, innovation-friendly model.
Singapore AI Framework โ