Lesson 20 / 26
The Regulatory Landscape
Get an orientation to major regimes and know to verify current status with qualified advice.
A moving target
AI rules are evolving quickly and differ by country and sector, so this is orientation, not legal advice. The EU AI Act takes a risk-based approach: some practices are prohibited, "high-risk" systems face strict obligations (risk management, data quality, documentation, human oversight, accuracy and robustness), certain systems such as chatbots must be transparent, and obligations are being phased in over several years. Data-protection laws (the EU's GDPR, India's Digital Personal Data Protection Act, 2023) apply whenever personal data is processed. Sector rules (finance, health, employment, education) add further requirements. Always check current text and dates with your legal team, since timelines and guidance change.
Rules, frameworks, evidence
Laws set requirements, frameworks give structure, and your records prove you did the work.
A regulation tracker
Keep one living table owned by legal or compliance, and link each row to affected systems in the inventory. The status column below is a placeholder for you to fill from current sources.
Regime Applies when Systems affected Status (verify)
EU AI Act we offer AI to EU users/market support-bot, screener <fill from current text>
GDPR EU residents' personal data all with PII in force
India DPDP Act, 2023 digital personal data of people all with PII <check rules/dates>
Sector rule (e.g. financial) regulated activity credit-scoring <regulator guidance>Design for the strictest rule you face
If you operate in several regions, building to the highest common standard (documentation, human oversight, transparency, data minimisation) is often simpler than maintaining separate versions.
Quick check: What does a risk-based regulation approach mean?
- The same rules for every system
- Stricter obligations for systems with greater potential harm
- No rules for any system
- Rules only for hardware
Answer
Stricter obligations for systems with greater potential harm — Obligations scale with the level of risk, which mirrors internal risk tiering.