AI Ethics and Governance

AI Regulations and Governance Frameworks


In December 2023 the US Federal Trade Commission banned Rite Aid from using facial recognition for five years. The pharmacy chain had run a system in hundreds of stores that matched shoppers against a database of suspected shoplifters. The FTC's complaint described thousands of false matches: employees stopped, searched, publicly accused and ejected customers on the strength of them, including children. The system had been fed low-resolution CCTV stills and photographs from mobile phones, was never tested for accuracy, was never monitored after deployment, and generated matches at higher rates in stores located in areas with larger non-white populations.

There was no AI statute to break. The FTC used Section 5 of the FTC Act, which prohibits unfair or deceptive practices and was enacted in 1914. The order required Rite Aid to delete the data, delete models derived from it, and stand up a comprehensive algorithmic-fairness programme with independent assessments.

Two lessons sit inside that. First, "there is no AI law here" has never meant "there is no law here" — consumer protection, anti-discrimination, product safety and data protection statutes already apply to whatever you build. Second, when regulators do act, the remedy is increasingly the deletion of the model itself, which is a materially different cost from a fine.

The EU AI Act tiers a use, not a modelMinimal risk —no obligationsLimited risk —disclose it is AIHigh risk —conformity,logs, oversightUnacceptable —prohibited outrighttopbottomThe same model sits in three tiers depending on what you point it at.
Classification follows the deployment, which is why a spam filter and a CV screener built on identical weights carry entirely different duties.

What regulation is actually trying to fix

Regulation exists where markets reliably fail. Three specific failures show up with AI systems.

FailureMechanismConcrete instance
Externalised harmThe party that captures the benefit is not the party that bears the costA retailer saves on losses; the wrongly accused shopper bears the humiliation and has no contract with anyone
Information asymmetryThe affected person cannot inspect, test, or even know about the system deciding their caseAn applicant rejected by a CV screener cannot see the model, the data, or the threshold
Scale and speedOne defect replicates across millions of decisions before anyone noticesA healthcare risk score with a mis-specified target, from a class of tools applied to an estimated 200 million people a year

A human loan officer with a prejudice harms hundreds of people over a career and can be individually challenged. A model with the same prejudice harms millions and cannot be deposed. That asymmetry of scale is the core regulatory argument, and it explains why the rules focus on documentation, testing and human oversight rather than on banning techniques.

The global picture in one table

JurisdictionApproachBinding?Key instrument
European UnionHorizontal, risk-tiered, product-safety styleYesAI Act (Regulation 2024/1689), in force 1 August 2024; high-risk rules now phase in to 2028 after the 2026 Digital Omnibus amendments
United StatesSectoral federal + active statesYes, but fragmentedFTC Act §5, ECOA, Title VII, FCRA; NYC Local Law 144; Colorado SB 26-189
United KingdomPrinciples applied by existing sector regulatorsMostly not, yetFive cross-sector principles; ICO, FCA, MHRA guidance
ChinaTargeted rules per application type, with filing regimeYesAlgorithm recommendation, deep synthesis and generative AI measures; content labelling from Sept 2025
Council of EuropeHuman-rights treatyOnly on states that ratify itFramework Convention on AI, opened for signature Sept 2024; needs five ratifications to enter into force
OECD / G7Soft-law principles, widely copied into national lawNoOECD AI Principles (2019, updated 2024)
Standards bodiesCertifiable management systemsVoluntary, contractually enforcedISO/IEC 42001:2023; NIST AI RMF 1.0

Two structural points matter more than any individual rule. Extraterritoriality: the EU AI Act binds providers outside the EU if the system is placed on the EU market or if its output is used in the EU. A model served from Bengaluru or California to an EU employer is in scope. And the Brussels effect: because building two versions of a product is expensive, the strictest applicable regime tends to become the global default. Plan for the strictest regime you touch.

The EU AI Act, in the detail you need

It regulates uses, not techniques

The Act almost never asks what algorithm you used. It asks what the system decides and about whom. The same gradient-boosted classifier is unregulated when it routes warehouse pallets and high-risk when it ranks job applicants. This is why "we only use simple logistic regression" is not a defence, and why a risk classification cannot be done by the ML team alone — it depends on the deployment context.

The four tiers

Unacceptable risk — prohibited outright (Article 5, applicable since 2 February 2025):

  • Subliminal, manipulative or deceptive techniques that materially distort behaviour and cause significant harm
  • Exploiting vulnerabilities of age, disability or socio-economic situation
  • Social scoring by public or private actors leading to detrimental treatment in unrelated contexts or disproportionate to the behaviour
  • Predicting criminal offending based solely on profiling or personality traits
  • Untargeted scraping of facial images from the internet or CCTV to build recognition databases — the practice at issue in the Clearview AI enforcement actions
  • Emotion inference in workplaces and educational institutions, outside medical and safety uses
  • Biometric categorisation inferring race, political opinions, trade union membership, religion, sex life or sexual orientation
  • Real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions that need prior judicial or independent authorisation
  • Added in 2026 by the Digital Omnibus: systems that generate non-consensual intimate imagery or child sexual abuse material ("nudification" apps), with its own, later start date

High risk — permitted but heavily regulated. Two routes in. Annex I: the system is a safety component of a product already regulated under EU product legislation (medical devices, machinery, lifts, vehicles, toys). Annex III: the system operates in one of eight listed areas — biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential public and private services including creditworthiness and life or health insurance pricing; law enforcement; migration and border control; administration of justice and democratic processes.

When high-risk duties start. The original dates were August 2026 for Annex III and August 2027 for Annex I. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) moved them to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. These dates have already moved once, so check the current text before you plan a roadmap around them — but treat the delay as time to build, not as a reprieve: the core obligations in the table below are largely unchanged.

Article 6(3) provides an escape hatch that is easy to over-claim. An Annex III system is not high risk if it only performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task. But the exemption never applies if the system profiles natural persons. A CV parser that merely extracts fields into a form may qualify; a CV parser that scores candidates does not.

Limited risk — transparency only (Article 50, applicable from 2 August 2026): tell people when they are interacting with an AI system; mark synthetic audio, image, video and text in a machine-readable way; disclose deepfakes; disclose emotion recognition and biometric categorisation to the people subjected to them. Generative systems already on the market before that date got a short grace period, to 2 December 2026, for the machine-readable marking.

Minimal risk — spam filters, recommendation engines for products, game AI. No AI-Act-specific obligations, though other law still applies.

What "high risk" actually costs you

ArticleObligationWhat it means in engineering terms
9Risk management systemA continuous, documented, iterative process across the lifecycle — not a one-off launch review
10Data governanceTraining, validation and test sets must be relevant, sufficiently representative and, as far as possible, error-free; you must examine them for bias. Article 10(5) explicitly permits processing special-category data where strictly necessary to detect and correct bias.
11Technical documentationThe Annex IV dossier: architecture, data, training methodology, metrics, limitations — written before market placement
12Automatic loggingThe system records events over its lifetime, sufficient to reconstruct a decision later
13Transparency to deployersInstructions for use stating accuracy, known limitations, and the conditions under which performance degrades
14Human oversightDesigned so a human can actually intervene: understand the output, be aware of automation bias, and stop the system
15Accuracy, robustness, cybersecurityDeclared accuracy metrics; resilience to errors and adversarial manipulation
27Fundamental rights impact assessmentRequired of public bodies, providers of public services, and deployers doing credit scoring or life/health insurance pricing
43, 48, 49Conformity assessment, CE marking, EU database registrationYou attest conformity, affix the mark, and register the system publicly
72, 73Post-market monitoring and incident reportingSerious incidents reported to authorities within tight deadlines — as little as two days for widespread infringements

Note Article 10(5) carefully. It resolves the tension where privacy rules push you to delete demographic data and fairness testing requires it. The law's answer is that you may collect and process it for the specific purpose of bias detection and correction, under safeguards. "We deleted ethnicity for GDPR reasons so we cannot test for discrimination" is not a defence under this regime. The 2026 Omnibus amendments widened the permission to cover bias detection in AI systems that are not high risk too, still under safeguards.

General-purpose models

Chapter V, applicable from 2 August 2025, covers foundation models separately from applications built on them. All providers of general-purpose AI models owe: technical documentation, information to downstream providers so they can meet their own obligations, a copyright compliance policy, and a sufficiently detailed public summary of training content. Models presenting systemic risk — presumed above a cumulative training compute of 102510^{25} floating point operations — additionally owe model evaluation including adversarial testing, systemic risk assessment and mitigation, incident reporting, and cybersecurity protection.

Penalties

BreachMaximum
Prohibited practice (Article 5)€35 million or 7% of worldwide annual turnover, whichever is higher
Most other obligations, including high-risk duties€15 million or 3%
Supplying incorrect or misleading information to authorities€7.5 million or 1%

For SMEs and start-ups the cap is the lower of the two figures. Seven percent of global turnover exceeds the GDPR's headline 4%, which tells you how the legislature ranked the risk.

A working classifier

Python
def eu_ai_act_tier(system):    """Rough triage. Produces a starting point for legal review, not a legal opinion."""    if system.practice in PROHIBITED_PRACTICES:            # Article 5 list        return "PROHIBITED"    annex_iii = system.domain in {        "biometrics", "critical_infrastructure", "education",        "employment", "essential_services", "law_enforcement",        "migration_border", "justice_democracy",    }    annex_i = system.is_safety_component_of_regulated_product    if annex_i or annex_iii:        narrow = system.only_narrow_procedural_task or system.only_preparatory_task        # the escape hatch never applies to profiling of natural persons        if annex_iii and narrow and not system.profiles_natural_persons:            return "NOT HIGH RISK (Art 6(3)) - document the reasoning"        return "HIGH RISK"    if system.interacts_with_humans or system.generates_synthetic_content:        return "LIMITED RISK - transparency duties (Art 50)"    return "MINIMAL RISK"

The failure mode here is teams self-classifying out of high risk by asserting "a human makes the final decision". That is not what Article 6(3) says. If the system scores, ranks or profiles people, a human rubber-stamping the ranking does not lift it out of the tier — and the human-oversight requirement in Article 14 exists precisely because rubber-stamping is the expected human behaviour.

Risk tier is determined by what the system decides and about whom, never by which model architecture you chose.

The United States: no single law, plenty of liability

There is no comprehensive federal AI statute. Existing regulators apply existing powers, and the states have moved faster than Congress. Federal policy has also turned against state AI laws: a December 2025 executive order set up a Justice Department task force to challenge ones it considers burdensome. The state rows below are the most volatile part of this table, so check their current status before relying on them.

InstrumentReachesThe teeth
FTC Act §5Unfair or deceptive practices, any sectorAlgorithmic disgorgement — orders to delete data and models built from it
ECOA / Regulation BCredit decisionsAdverse-action notices must give the specific principal reasons. The CFPB withdrew its 2022 and 2023 circulars on complex models in May 2025, but the requirement in Regulation B is unchanged, and "the model is too complex" is still not a reason
Title VII, ADAEmploymentDisparate impact liability. The EEOC removed its guidance on algorithmic selection tools in January 2025, but the statutes, and private lawsuits under them, still apply
FCRABackground and tenant screeningAccuracy duties, dispute rights, adverse-action procedure
NYC Local Law 144Automated employment decision tools used on NYC candidatesAnnual independent bias audit, results published on the website, candidate notice ten business days ahead; per-day penalties
Colorado SB 26-189Automated decision-making technology in consequential decisions (employment, housing, lending, insurance, health, education, benefits)Replaced the 2024 Colorado AI Act (SB 24-205) before that law took effect. From 1 January 2027: developer documentation, disclosure to consumers, and a right to correction and human review after an adverse outcome
State biometric lawsFace and voice dataIllinois BIPA carries a private right of action, which has produced very large settlements

The strategically important entry is algorithmic disgorgement. A fine is a cost of doing business; an order to delete a model trained on improperly obtained data destroys the asset. Any data-sourcing shortcut that would be embarrassing to explain should be read as a bet on the continued existence of the model that depends on it.

NIST AI RMF: the framework that fills the gap

Laws tell you what outcome is required. They do not tell you how to organise the work. The NIST AI Risk Management Framework 1.0, published January 2023, is voluntary, sector-neutral, and has become the default vocabulary in US practice — including in contracts, where "aligned to NIST AI RMF" is now a common procurement clause.

It defines seven characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. Then four functions, which run continuously rather than in sequence.

FunctionQuestion it answersConcrete artefacts
GOVERNWho is accountable, and under what policy?AI policy; named risk owner per system; RACI; escalation path; a workforce that has been trained; supplier requirements
MAPWhat is this system, in what context, and who could it harm?System inventory entry; intended and out-of-scope uses; affected-stakeholder list; harm enumeration; risk tier
MEASUREHow do we know, in numbers?Per-group performance metrics with confidence intervals; robustness and adversarial testing; drift baselines; red-team results
MANAGEWhat do we do about it, and who decides?Prioritised risk register; mitigations with owners and dates; go/no-go decision record; monitoring alerts; incident response and rollback plan

GOVERN is drawn as surrounding the other three because it is the one that fails silently. MAP, MEASURE and MANAGE all produce visible outputs; GOVERN produces the authority to act on them. A team can measure a serious disparity and ship anyway if no one is empowered to say no.

The question that reveals whether governance is real: who, by name, can stop a launch — and have they ever done it?

NIST added a Generative AI Profile (AI 600-1) in July 2024. It lists twelve risks that generative AI creates or makes worse — among them confabulation, CBRN information, data privacy, information integrity, information security, harmful bias and homogenisation, and value-chain and component integration — and maps suggested actions onto the four functions. NIST has said AI RMF 1.0 is being revised under the 2025 White House AI Action Plan, so check which version a contract or procurement clause refers to.

ISO/IEC 42001 and the OECD principles

ISO/IEC 42001:2023 is the first certifiable AI management system standard. Structurally it is the familiar Plan-Do-Check-Act management system — the same shape as ISO 27001 for information security — with an annex of AI-specific controls covering impact assessment, data management, lifecycle documentation and third-party responsibilities. The practical difference from NIST is auditability: an accredited body can certify you against 42001, and certification is a document you can put in a procurement response. It says your process is sound. It does not say any individual model is fair.

The OECD AI Principles (2019, updated 2024) are soft law with unusual reach: adopted by around fifty countries, they supplied the definition of "AI system" that flowed into the EU AI Act and much national legislation, and they underpin the G7 Hiroshima process. Five principles: inclusive growth and well-being; human rights and democratic values including fairness and privacy; transparency and explainability; robustness, security and safety; accountability. Their function is convergence — they are why the world's AI laws rhyme.

EU AI ActNIST AI RMFISO/IEC 42001
NatureBinding lawVoluntary frameworkCertifiable standard
AnswersWhat must be trueHow to organise the workHow to prove the work happens
ScopePer system, by risk tierPer system and organisationPer organisation
Failure to complyFines up to 7% of turnoverNo direct penalty; contractual exposureLoss of certificate

They are complements, not alternatives. A common working pattern is to use NIST AI RMF as the internal operating model, ISO 42001 as the audited wrapper, and the AI Act as the list of hard requirements each high-risk system must satisfy.

Standing up a governance programme

Six components, in the order that they actually pay off:

  1. Inventory. You cannot govern systems you cannot list. Most organisations discover on first pass that they have several times more models in production than anyone believed, including spreadsheets, vendor features enabled by default, and scripts owned by people who have left.
  2. Risk tiering. Apply one classification rubric to the whole inventory. Nearly everything will land in the lowest tier, which is the point: it concentrates scarce review capacity on the small number of systems that decide something about a person.
  3. Intake and gating. A lightweight form at project start capturing purpose, data, affected people and tier. High-tier systems get a defined review before launch, with a named approver.
  4. Documentation standard. One model card template, one dataset datasheet template, stored in a registry rather than in a slide deck. Include intended use and out-of-scope uses; the second field is the one that protects you when the model is repurposed two years later.
  5. Monitoring and incident response. Per-group metric alerting, a defined severity scale, a rollback procedure that has been tested, and a route for affected people to complain that reaches an engineer.
  6. Third-party assessment. Most AI risk now arrives through a vendor. Ask for the model card, the per-group evaluation results, the training data provenance, the incident history, and the contractual right to audit. "It's a vendor model" transfers none of your legal obligation as a deployer.
LevelStateDiagnostic symptom
1 — Ad hocEthics is whoever caresNobody can produce a list of deployed models
2 — RepeatableSome teams have checklistsPractice varies by team; no one is accountable across them
3 — DefinedPolicy, inventory, tiering, review gate existReviews happen but rarely change anything
4 — ManagedMetrics monitored; launches have been blockedYou can name a system that was stopped or materially changed
5 — OptimisingFeedback from incidents and affected people changes the processExternal audit; published transparency reporting

What this means for the system you are building

Classify before you build, not before you launch. The high-risk obligations — data governance records, the Annex IV technical file, lifetime logging, designed-in human oversight — are architectural. Logging that can reconstruct an individual decision two years later is a data model decision; retrofitting it after launch means a migration. Teams that classify at the end discover that compliance requires rebuilding, and rebuilding is when deadlines get met by quietly reclassifying instead.

Write the out-of-scope uses down and mean them. The single most common path from a fine system to a harmful one is repurposing: a tool built to prioritise outreach becomes a tool that denies service, with no revalidation because it is "the same model". A documented, specific out-of-scope statement is what lets someone inside the organisation object with authority.

Assume the strictest regime you touch. If you serve EU users and NYC job applicants, you owe an Annex IV technical file and an annual published bias audit, and the underlying work overlaps heavily. Build the per-group evaluation once, in a reproducible pipeline, and emit both artefacts from it.

Finally, treat the model-deletion remedy as a design constraint on data sourcing. Fines are survivable and insurable. An order to delete a model and everything trained on it is not. Every scraped dataset and every repurposed consent is a bet that no regulator will ever ask where the data came from — and the record of the last few years is that they ask.