Every jurisdiction your AI touches adds another law, standard, or supervisory expectation. AxiLayer AI maintains a single controls-and-evidence model mapped across all of them, so an assessment performed once produces documentation reusable everywhere — from Brussels to Washington to Seoul.
The world's first comprehensive AI law. Risk-tiered obligations for providers and deployers of AI systems placed on the EU market, with penalties up to €35M or 7% of global turnover.
High-risk obligations apply from 2 Aug 2026 EU · Financial servicesOperational-resilience obligations for EU financial entities, including the AI and ICT systems they run and the third-party providers behind them.
In application since Jan 2025 EU · Data protectionLawful-basis, transparency, and automated-decision-making requirements that apply to AI systems processing personal data, alongside the AI Act.
In force since 2018The de facto US standard for trustworthy AI: Govern, Map, Measure, Manage — plus the Generative AI Profile (NIST-AI-600-1) for GenAI-specific risk.
AI RMF 1.0 · GenAI Profile 2024 US · ColoradoDuty of reasonable care for developers and deployers of high-risk AI making consequential decisions, with impact-assessment and disclosure duties.
First comprehensive US state AI law US · TexasThe Texas Responsible AI Governance Act — prohibited-use and governance obligations for AI systems operated in or affecting Texas.
State AI governance statute US · Federal cloudSecurity authorization for cloud services sold to US federal agencies — the baseline any government-facing AI platform must clear.
Government authorization regime US · HealthcarePrivacy and security rules governing protected health information — decisive for clinical AI, payer models, and health-data pipelines.
Sector privacy law US · CaliforniaCalifornia consumer-privacy rights, including emerging rules on automated decision-making technology that reach AI-driven profiling.
State privacy lawKorea's comprehensive AI statute — high-impact AI classification, transparency, and safety obligations, in force 22 January 2026.
In force Jan 2026 SingaporeIMDA's governance framework and the AI Verify testing toolkit — the reference point for demonstrating trustworthy AI across ASEAN.
Voluntary framework + test toolkit JapanJapan's innovation-first statute paired with METI/ISO-aligned business guidelines that enterprises are expected to evidence in practice.
Soft-law + 2025 statute ChinaCAC's binding measures for public-facing generative AI in China — security assessment, content, and data-sourcing obligations, plus PIPL.
Binding since Aug 2023 CanadaCanada's proposed Artificial Intelligence and Data Act and the federal directive already governing government use of automated decisions.
Directive in force · AIDA pending BrazilBrazil's general data-protection law and the risk-based AI bill advancing through Congress on the EU model.
LGPD in force · AI bill advancing United KingdomPrinciples-based expectations enforced through existing regulators (ICO, FCA, MHRA), backed by the AI Safety Institute's evaluation work.
Regulator-led principlesThe first certifiable management-system standard for AI. The organizational backbone that makes EU AI Act and NIST AI RMF evidence sustainable.
Certifiable AIMS standard ISO/IEC · RiskRisk-management guidance specific to AI, extending ISO 31000 into model, data, and lifecycle risk.
Guidance standard ISO/IEC · ImpactGuidance for assessing an AI system's impact on individuals and societies — the method behind credible FRIA and impact-assessment work.
Guidance standard ISO/IEC · Audit bodiesThe requirements governing the bodies that audit and inspect AI management systems — the standards AxiLayer AI aligns its own assessment practice to.
Conformity-assessment standards ISO/IEC · SecurityInformation-security management and trust-services criteria — the security substrate every AI assurance program is expected to stand on.
Security & trust standardsMost organizations discover these frameworks one enforcement letter at a time. The result is five parallel compliance projects, five documentation sets, and five invoices — for one AI system. AxiLayer AI's approach is different: our assessment methodology maps each control we test to every framework that requires it, so a single engagement produces an evidence base you can present to an EU market-surveillance authority, a US regulator, a Korean ministry, or an enterprise procurement team.
The register above is maintained continuously. When a framework changes — a new harmonized standard under the EU AI Act, a new profile under the NIST AI RMF, an amendment to a state statute — the mapping is updated and, for clients running AxiSentinel, monitored obligations update with it.
Start with the framework that is binding for you today, and read how the others connect from there. If you are unsure which frameworks apply to your systems, that scoping question is exactly what an independent AI audit answers first.
A scoping briefing takes under an hour and produces a jurisdictional exposure map for your AI portfolio — no obligation.