# The Regulatory Landscape — AI Strategy, Ethics and Governance

Source: https://www.geekswithgeeks.com/en/ai-strategy-governance/reg-landscape

> Get an orientation to major regimes and know to verify current status with qualified advice.

## A moving target

AI rules are evolving quickly and differ by country and sector, so this is orientation, not legal advice. The **EU AI Act** takes a **risk-based** approach: some practices are prohibited, "high-risk" systems face strict obligations (risk management, data quality, documentation, human oversight, accuracy and robustness), certain systems such as chatbots must be transparent, and obligations are being phased in over several years. **Data-protection laws** (the EU's GDPR, India's Digital Personal Data Protection Act, 2023) apply whenever personal data is processed. **Sector rules** (finance, health, employment, education) add further requirements. Always check current text and dates with your legal team, since timelines and guidance change.

## Rules, frameworks, evidence

Laws set requirements, frameworks give structure, and your records prove you did the work.

![Three layers: law, framework, evidence.](assets/figures/ai-strategy-governance/section-6-map.svg) — Figure 6.1 — Law, framework and evidence.

## A regulation tracker

Keep one living table owned by legal or compliance, and link each row to affected systems in the inventory. The status column below is a placeholder for you to fill from current sources.

```text
Regime                          Applies when                      Systems affected      Status (verify)
EU AI Act                       we offer AI to EU users/market    support-bot, screener  <fill from current text>
GDPR                            EU residents' personal data       all with PII          in force
India DPDP Act, 2023            digital personal data of people   all with PII          <check rules/dates>
Sector rule (e.g. financial)    regulated activity                credit-scoring        <regulator guidance>
```

## Design for the strictest rule you face

If you operate in several regions, building to the highest common standard (documentation, human oversight, transparency, data minimisation) is often simpler than maintaining separate versions.

**Quiz:** What does a risk-based regulation approach mean?

- [ ] The same rules for every system
- [x] Stricter obligations for systems with greater potential harm
- [ ] No rules for any system
- [ ] Rules only for hardware

*Answer:* Stricter obligations for systems with greater potential harm. Obligations scale with the level of risk, which mirrors internal risk tiering.
