ToolNavs Find Useful AI Tools
Submit Sign in

AI Governance and Compliance

The EU bans practices by risk tier, China works through filings and security assessments, the US leans on executive orders plus the NIST framework — the same product faces entirely different gates in each market.

Compliance is not a document, it is a list of actions that shifts with every market — and translating it into engineering terms early saves the most rework. The EU AI Act sorts systems into four risk tiers: unacceptable, high, limited and minimal. Social scoring and real-time remote biometric identification in public spaces are prohibited outright; hiring, education and law enforcement carry transparency, human oversight and logging duties; general-purpose models add obligations around training-data summaries and evaluation reports. China moves differently: the Interim Measures for Generative AI Services require algorithm filings, security assessments, content filtering and labeling of generated output, while its AI Safety Governance Framework turns security risks into checkable items. The United States has no single federal statute — constraints come from executive orders, NIST's AI RMF and sector standards. What helps most in practice is a per-market list of things that must leave a trace: data provenance, evaluation records, where labels are applied, and which steps involve a human reviewer.