Learn about AI >

The AI Regulatory Landscape — What Laws Apply to AI Systems Right Now

AI-specific regulation is still emerging, but a significant body of law already applies to AI systems through privacy regulation, anti-discrimination law, and sector-specific requirements. Most organizations deploying AI are already subject to more legal obligations than they realize.

There is a common misconception that AI regulation is something coming in the future — a set of rules that regulators are still drafting, that will apply once they are finalized. This is partly true and mostly misleading. A substantial body of law already applies to AI systems right now, through existing privacy regulation, anti-discrimination law, consumer protection rules, and sector-specific requirements. Most organizations deploying AI are already subject to more legal obligations than they realize.

The existing layer is broad. Privacy laws like GDPR in Europe and CCPA in California apply to AI systems that process personal data, which is most of them. Anti-discrimination law applies when AI systems make decisions about employment, lending, housing, or access to services. Consumer protection rules apply when AI outputs are used in marketing or customer-facing decisions. Healthcare AI is subject to FDA oversight in the United States. Financial AI is subject to the regulations that govern the decisions it supports. None of these laws were written with AI in mind, but they apply to AI behavior regardless.

The emerging layer is more specific. The EU AI Act, which entered into force in 2024, is the most comprehensive AI-specific regulation currently in effect. It takes a risk-based approach: systems that pose higher risks to people's rights and safety face stricter requirements around transparency, human oversight, and documentation. Some categories of AI use are prohibited outright. Organizations deploying AI in Europe, or deploying AI that affects people in Europe, need to understand where their systems fall in this framework.

AI Compliance covers the practices that keep AI deployments on the right side of these obligations. AI for Regulatory Compliance covers the separate but related use case of using AI to help meet compliance requirements in other domains. SLAs are relevant here too: when AI systems are deployed through vendors, the service level agreements governing those relationships need to address the compliance obligations that the vendor relationship creates.

The regulatory landscape is moving fast, and any specific summary will be out of date before long. What won't change is the underlying principle: AI systems that make consequential decisions about people are subject to the legal frameworks that govern consequential decisions about people. The articles in this section cover what that means in practice.