Responsible AI

AI Standards & Regulation in 2026

AI governance is becoming concrete. Here is a primary-source-first map of the frameworks most people encounter — and what each one actually does.

There is no single global AI rulebook

AI governance is a mix of laws, voluntary risk frameworks, technical standards and existing sector rules. The right obligations depend on the jurisdiction, the system, your role, the people affected and the use case. This page is an orientation map, not legal advice.

European Union: AI Act transparency rules are now live

The EU AI Act uses a risk-based framework. The European Commission's July 2026 guidance states that the Article 50 transparency obligations apply from 2 August 2026. These rules include transparency duties for certain AI interactions and synthetic or manipulated content, with requirements depending on whether you are a provider or deployer and on the use involved.

Do not reduce the EU AI Act to “label all AI.”

The Act contains role-specific and use-specific duties, exceptions and technical requirements. Check the official text and Commission guidance for your actual system.

United States: NIST AI Risk Management Framework

NIST's AI RMF is a voluntary framework intended to help organizations manage AI risks to individuals, organizations and society. NIST also publishes a Generative AI Profile, and in 2026 began work around additional profiles and revisions. It is useful as a risk-management structure even where it is not a legal requirement.

UNESCO: a global ethics framework

UNESCO's Recommendation on the Ethics of Artificial Intelligence was adopted by its member states in 2021. It emphasizes human rights, fairness, privacy, transparency, accountability and environmental considerations. It is a policy framework rather than a substitute for national law.

C2PA: technical provenance for digital content

The Coalition for Content Provenance and Authenticity (C2PA) maintains the Content Credentials specification for tamper-evident provenance. Version 2.4, published in April 2026, added features including a machine-readable AI disclosure assertion. Provenance can help users understand creation and editing history, but it does not determine whether the message inside a piece of media is true.

U.S. copyright and AI-generated material

In January 2025, the U.S. Copyright Office said generative-AI output can be protected only where a human author determines sufficient expressive elements. Human-authored material, creative selection or modification can still be protected; mere prompting is not by itself sufficient human authorship under the Office's analysis.

A useful compliance workflow

Identify the system and role

Are you developing, providing, deploying or merely using the AI? Different regimes distinguish these roles.

Map the use and affected people

Hiring, health, biometrics, education, essential services and public-facing synthetic media can trigger different concerns.

Check current primary sources

AI rules are changing quickly. Use regulator and standards-body material rather than an old summary.

Document controls and evidence

Keep records of evaluations, data governance, oversight, transparency, incidents and changes appropriate to the risk.

Primary sources & further reading

For fast-changing claims, prefer primary sources and check their dates.