AxiLayer AI crestAxiLayerAI
Industries · Global Government & Public Sector

Continuous AI Assurance for Sovereign Government

Governments are now the largest single class of high-risk AI deployer on earth, benefits determination, taxation, immigration, policing, licensing, courts, health and citizen service are all being automated at once. AxiLayer AI and the AxiSentinel™ platform give public bodies in the UAE and wider GCC, the European Union, Asia-Pacific, North America and beyond the one thing an annual audit cannot: independent, always-on evidence that each system is still compliant today, in the jurisdiction it actually operates in.

45+
Government jurisdictions in the regulatory map
131+
Regulatory frameworks encoded into AxiSentinel
Configurable
Continuous or scheduled monitoring, your choice
Air-gap
Sovereign, on-premise and classified deployment
3
USPTO provisional patent filings
The Public Sector Problem

A citizen decision is made every second. An audit happens once a year.

Public-sector AI is unlike commercial AI in three ways that break the traditional assurance model. First, the decisions are non-optional, a citizen cannot shop elsewhere for a benefits determination, a visa outcome or a tax assessment. Second, the accountability chain runs to parliaments, auditors-general, ombudsmen and courts, all of whom require durable evidence rather than a consultant's opinion. Third, government AI is now being retrained, fine-tuned and re-prompted continuously, which means the system that passed a point-in-time review in January is materially not the system running in July.

A conventional audit produces a snapshot with a shelf-life measured in weeks. Regulators in every major market have moved decisively toward continuous obligations instead: post-market monitoring and logging under the EU AI Act, ongoing performance monitoring and periodic reassessment under Saudi Arabia's national AI Risk Management Framework, continuous monitoring and review under the CBUAE's AI guidance for licensed financial institutions, and lifecycle risk management under Korea's AI Framework Act. The obligation is continuous. The assurance has to be continuous too.

AxiSentinel monitors a government AI system against the framework that actually binds it, generates a Provisional Alert the moment a threshold is breached, and holds that alert as a finding until a qualified human auditor signs it off. Nothing is certified autonomously.

What a public body gets that it cannot get from an annual review

  • Evidence, not assertion. A cryptographic evidence chain that a legislative committee, auditor-general or supervisory authority can verify independently, tamper-evident and time-ordered.
  • Human oversight gap detection. Most oversight regimes require a human to be meaningfully in the loop. AxiSentinel detects where that oversight has quietly become rubber-stamping, which is the failure mode that regulators and courts actually find.
  • Jurisdictional accuracy. A single AI system used across the UAE, the EU and Asia-Pacific faces different classification, documentation and transparency duties in each. The monitoring is scoped per jurisdiction, not averaged.
  • Sovereignty by design. The AXI-Node agent runs inside the agency's own environment, sovereign cloud, on-premise, disconnected or classified, so monitored data never has to leave the national boundary.
  • Procurement-grade status. A Live Certification Status API lets a contracting authority or vendor registry check whether a supplier's AI system is compliant right now, not whether it held a certificate last year.
  • Independence. AxiLayer AI does not build, sell or resell the AI systems it assesses. Independence is a structural requirement of every conformity-assessment regime worth the name.

Federal Vendor Profile

Registered in SAM.gov for all award types, CAGE 20JV1, UEI CB76ENDLMUC9. Full capability profile, NAICS and PSC codes, and the one-page capability statement for contracting officers.

Government Profile

Government Engagements

AxiLayer AI works with national, federal, emirate, state, provincial and municipal bodies, plus the system integrators and prime contractors that deliver AI into them.

Contact Us
Region 1 · United Arab Emirates & the GCC

The Gulf regulates AI through procurement, licensing and data law, not a single AI act

There is no horizontal AI statute in the UAE or the wider GCC equivalent to the EU AI Act. That does not mean there is no obligation, it means the obligation binds through different instruments. In the UAE it arrives through federal data protection law, emirate-level authorities, free-zone rulebooks and sector licensing. In Saudi Arabia it binds through SDAIA policy and public-sector procurement. In Qatar it binds through central bank licensing. For a public body or a vendor selling into one, the practical consequence is that compliance is multi-regulator by default, and the evidence a regulator asks for differs by emirate and by free zone.

United Arab Emirates · Federal
National AI Strategy 2031 & the UAE AI Charter
Policy & PrinciplesPDPL Binding

The UAE is the most institutionally advanced AI state in the region and has deliberately chosen a layered, pro-innovation model over a single statute.

  • UAE Charter for the Development & Use of AI (2024), twelve principles covering safety, algorithmic bias mitigation, privacy, transparency, human oversight, governance and accountability. Non-binding, but the reference point procurement teams and sector regulators use to approve or reject a deployment.
  • National AI System seated in government from January 2026, an advisory member of the Cabinet, the Ministerial Development Council and the boards of federal entities. A world first, and a signal that AI assurance in the UAE is a governance question, not an IT question.
  • Federal Decree-Law No. 45 of 2021 (PDPL), automated processing, profiling, cross-border transfer and data-subject rights, overseen by the UAE Data Office.
  • UAE AI Office and UAE Council for AI & Blockchain, federal policy and coordination; Minister of State for AI portfolio.
  • Child Digital Safety Law (2025) and the UAE's published International Stance on AI Policy extend the charter into enforceable and diplomatic terrain.
AxiSentinel coverage: charter-principle mapping · PDPL automated-decision evidence · federal procurement documentation packs
UAE · Abu Dhabi
AIATC and the Abu Dhabi Government AI Programme
Emirate Law

Abu Dhabi has built a dedicated institutional owner for AI, which makes it the most audit-ready emirate for public-sector AI.

  • Law No. 3 of 2024 established the Abu Dhabi Artificial Intelligence and Advanced Technology Council (AIATC) to regulate and coordinate AI initiatives across the emirate.
  • Abu Dhabi Government Digital Strategy 2025 to 2027, an explicitly AI-native government programme, with assurance expectations attached to funded initiatives.
  • Sector licensing as the binding layer, Department of Health Abu Dhabi AI licensing conditions are already the sharpest example of AI obligations binding through a licence rather than a statute.
  • ADGM Office of Data Protection and the ADGM data protection regulations govern AI processing inside the financial free zone.
AxiSentinel coverage: AIATC-aligned risk registers · DoH licensing evidence · ADGM data-protection monitoring
UAE · Dubai
Dubai AI Strategy, the Dubai AI Seal & sector policies
Programme & SealSectoral

Dubai runs the most commercially active AI-governance apparatus in the region, and increasingly ties market access to a verification mark.

  • Dubai AI Seal, a verification programme introduced by the Dubai Centre for Artificial Intelligence to accelerate the emirate's AI industry by distinguishing credible providers. A verification mark is exactly the kind of claim that needs independent, continuous substantiation.
  • Dubai Universal Blueprint for AI and the Dubai AI Strategy, AI embedded across government service delivery, with an AI Chief in every government entity.
  • Sector-specific instruments, the AI Policy in Healthcare and rules regulating autonomous vehicles are binding within Dubai but, critically, do not apply inside free zones such as the DIFC.
  • Digital Dubai / Dubai Digital Authority ethical AI self-assessment and AI principles & guidelines.
AxiSentinel coverage: Dubai AI Seal substantiation · healthcare AI policy monitoring · autonomous-systems evidence
UAE · DIFC Free Zone
DIFC Regulation 10, autonomous & semi-autonomous systems
Full Enforcement Jan 2026

The single most consequential AI-specific rulebook in the Middle East, and the one most often missed because it applies only inside the free zone.

  • DIFC Data Protection Law No. 5 of 2020, Regulation 10, a dedicated regime for processing personal data by autonomous and semi-autonomous systems, with full enforcement from January 2026.
  • Obligations run to transparency, human accountability, ethical-use commitments and demonstrable governance over autonomous processing, a materially higher evidentiary bar than the federal PDPL.
  • Supervised by the DIFC Commissioner of Data Protection, independent of the federal UAE Data Office. An entity operating both onshore and in DIFC is subject to two regulators with two evidence formats.
  • Agentic AI is squarely in scope: an autonomous agent taking action on personal data is the paradigm case Regulation 10 was written for.
AxiSentinel coverage: Regulation 10 autonomous-system logging · agentic AI governance monitoring · dual-regulator evidence split
Kingdom of Saudi Arabia
SDAIA: AI Risk Management Framework & Responsible AI Policy
RMF Launched Jul 2026PDPL Enforced

Saudi Arabia has moved furthest in the region from principles to operational machinery, and it centralises through a single authority, which makes it the most tractable GCC market to certify against.

  • National AI Risk Management Framework, launched 14 July 2026, a unified methodology across four phases: defining context and scope, identifying and assessing risk, treating risk, and continuous monitoring and review. Phase four is a continuous-assurance requirement in all but name.
  • Draft Responsible AI Policy, consulted on the Istitlaa platform (3 April, 3 May 2026), covering governance, testing, data protection, cybersecurity, content moderation, non-discrimination, performance monitoring and registration, and applying to government bodies, the private sector, non-profits and individuals.
  • SDAIA AI Ethics Principles and Deepfake Guidelines; 2026 declared the Year of AI by the Council of Ministers.
  • PDPL in active enforcement since the grace period closed, with penalties reaching SAR 5 million and doubling for repeat breaches, plus strict residency for sensitive data.
  • National Cybersecurity Authority controls and the copyright regime's AI-training-data exception (in force 1 August 2026) complete the stack.
AxiSentinel coverage: SDAIA RMF four-phase evidence · registration dossiers · PDPL residency and transfer monitoring
Qatar · Bahrain · Oman · Kuwait
The rest of the Gulf: binding where it counts
Qatar QCB BindingBahrain Gov Binding

Smaller GCC states run leaner governance models, but each has at least one instrument that genuinely binds, and knowing which one is the whole game.

  • Qatar, the National AI Strategy plus the Qatar Central Bank's AI Guidelines for licensed financial firms, which stand as the only legally binding AI-specific sectoral instrument across the four smaller GCC states. A general AI-regulation debate was tabled and deferred in the Shura Council in May 2026, with the agenda broadening into digital sovereignty, data residency and public-sector transformation.
  • Bahrain, the General Policy for the Use of AI (v1.0, May 2025) is the first comprehensive binding policy for government entities; the Central Bank of Bahrain has issued notices on AI in open banking; the EDB maintains an AI Ethics Pledge. The 2018 data protection law's biometric prior-authorisation regime captures most AI systems touching biometrics.
  • Oman, the National AI Policy (in force 9 April 2025 via MTCIT) requires governance standards, regular assessments, documentation and compliance reports on request. PDPL Executive Regulations reached full implementation on 5 February 2026 (appointed DPOs, documented consent trails), and Royal Decree 50/2026 established an AI Special Zone in Muscat on 30 April 2026 with incentives under the special-economic-zone framework.
  • Kuwait, CITRA-led national AI direction and data protection regulations; obligations arrive through telecoms and government-procurement channels.
AxiSentinel coverage: QCB guideline monitoring · Bahrain government-policy evidence · Oman assessment & reporting packs
Why this matters commercially: because GCC AI rules bind through procurement, licensing and data law rather than a horizontal act, a vendor cannot ship one compliance posture across the region. Saudi Arabia binds through procurement and SDAIA registration; Abu Dhabi binds through sector licensing; DIFC binds through Regulation 10; Qatar binds through central-bank licensing. The absence of a unified GCC standard is precisely why an independent, jurisdiction-scoped assurance layer has commercial value here.
Region 2 · European Union & Europe

The EU AI Act timeline moved in July 2026. The public-sector duties did not go away.

The Digital Omnibus on AI entered into force on 27 July 2026 (published in the Official Journal on 24 July 2026) after a compressed passage: proposed 19 November 2025, provisional political agreement 7 May 2026, European Parliament approval 16 June 2026 by 423 votes to 57, Council sign-off 29 June 2026. It deferred the high-risk conformity deadlines, and left the transparency and AI-literacy duties exactly where they were. Any public body that paused its programme on the assumption that 2 August 2026 was a single cliff edge has the timeline wrong in both directions.

The post-Omnibus EU AI Act timeline

In force, 2 February 2025
Prohibited practices & Article 4 AI literacy
Unchanged by the Omnibus. Social scoring by public authorities, untargeted facial-image scraping and real-time remote biometric identification in public spaces for law enforcement (subject to narrow exceptions) are prohibited. The AI-literacy duty on providers and deployers stands.
In force, 2 August 2025
GPAI obligations, governance architecture & penalties
General-purpose AI model obligations, the AI Office and AI Board, national competent authority designation and the penalty regime.
Live now, 2 August 2026
Article 50 transparency obligations apply
Disclosure that a person is interacting with an AI system, marking of synthetic content, deepfake and emotion-recognition disclosure. Article 50(2) does not apply to systems already on the market at this date. For government, this is the duty that bites first: citizen-facing chatbots, translation, triage and content-generation systems all fall in scope.
2 December 2026
Legacy-system transparency & new prohibitions
Article 50(2) extends to systems already on the market, and the new prohibited practices apply, including the Omnibus's newly added Article 5 prohibition on AI systems used to create non-consensual intimate imagery and CSAM.
2 December 2027, deferred from 2 Aug 2026
Annex III standalone high-risk obligations
A sixteen-month deferral. This is the band that covers essential public services and benefits, law enforcement, migration and border control, and administration of justice. Risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment and Article 49 registration all land here.
2 August 2027
Member State regulatory sandboxes & Annex I delegated acts
Each Member State must have at least one national AI regulatory sandbox operational; Commission delegated acts on Annex I sectoral rules are due.
2 August 2028, deferred from 2 Aug 2027
Annex I product-embedded high-risk AI
AI embedded in regulated products, medical devices, machinery, vehicles, assessed through existing sectoral conformity routes.

The duties written specifically for public bodies

  • Article 27, Fundamental Rights Impact Assessment. Mandatory for bodies governed by public law and private entities providing public services when deploying Annex III high-risk AI. It must describe the deployment process, categories of persons affected, specific risks of harm, the human oversight measures in place and the governance arrangements if risks materialise. It is not a one-off document, it must be updated when any element changes.
  • Article 49, EU database registration. Public authority deployers of Annex III high-risk systems register in the EU database, making the deployment publicly visible and permanently attributable.
  • Article 26, deployer obligations. Use in accordance with instructions, assign competent human oversight, ensure input-data relevance, retain logs for at least six months, inform affected persons, and cooperate with authorities.
  • Article 14, human oversight. The oversight must be effective, not nominal. Detecting the drift from real oversight to rubber-stamping is one of AxiSentinel's core functions.
  • Article 6 classification and the Commission's classification guidelines, the mandated guidance on high-risk classification, which determines whether a given government use case is in the Annex III band at all.
  • Grandfathering caveat. Systems already on the EU market before the new deadlines are largely carved out of full high-risk compliance unless later substantially modified, and the modification threshold has not been defined. For a continuously retrained government model, that is an unquantified live risk, and a strong argument for keeping a monitored record of every material change.

Penalty exposure

Prohibited-practice breaches reach the higher of €35 million or 7% of worldwide annual turnover; most other provider and deployer breaches reach €15 million or 3%. Public bodies are not exempt from the enforcement architecture, and Member States set their own regime for public authorities.

Penalty Calculator

Beyond the AI Act

  • GDPR Article 22, solely automated decisions with legal or significant effect, plus DPIA duties under Article 35.
  • NIS2, cybersecurity obligations for public administration entities operating AI infrastructure.
  • Cyber Resilience Act and the Data Act, product security and data access duties that reach AI components.
  • Council of Europe Framework Convention on AI, Human Rights, Democracy and the Rule of Law, the first binding international AI treaty, with public-sector obligations at its core and signatories beyond Europe.
  • CEN-CENELEC JTC 21, the harmonised standards that will define what "state of the art" means in practice for conformity assessment.
  • eIDAS 2, the accessibility acquis and the European Interoperability Framework for cross-border public AI services.

Member-state divergence is real

Spain's AESIA is the first dedicated national AI supervisory agency in the EU. Italy legislated its own national AI law in 2025 alongside the Act. Germany routes market surveillance through the Bundesnetzagentur. France's CNIL has issued its own AI recommendations. The Netherlands runs algorithm oversight through the Autoriteit Persoonsgegevens and expects an impact assessment for human rights and algorithms. The Act is uniform; the supervisor, the evidence format and the enforcement appetite are not.

Region 3 · Asia-Pacific

Two binding regimes, three promotion regimes, and one very large enforcement gap

Asia-Pacific is not one market. Korea and China now run binding, enforceable AI regimes. Japan, Australia and India have chosen promotion-oriented or principle-based frameworks, though India has layered binding deepfake-labelling rules on top. Singapore has the most mature toolkit in the world for testing AI systems without a statute at all. For a government or a vendor operating regionally, the practical result is that the same AI system can be subject to a mandatory impact assessment in Seoul, a mandatory content label in Shanghai, a voluntary standard in Canberra and a testing framework in Singapore, simultaneously.

Republic of Korea
AI Framework Act (AI Basic Act)
In force 22 Jan 2026

The world's second comprehensive AI statute after the EU AI Act, consolidating nineteen separate bills, and the fastest-moving compliance deadline in Asia.

  • Impact assessments for high-impact AI, explicitly including AI used in public services, energy, healthcare, hiring, lending and criminal-justice-adjacent decisions.
  • Notification duties, users must be told they are interacting with AI, and AI-generated content must be identified.
  • Risk-management systems, human oversight, documentation and transparency about training data and system operation.
  • Extraterritorial reach with a domestic-representative requirement for entities without a Korean address. A foreign vendor selling AI to a Korean agency is in scope.
  • MSIT enforcement decrees are being finalised; a grace period suspends fines, and Korea's own human rights commission has warned the decree's lack of clarity may leave gaps. The grace period is a window to build evidence, not a reason to wait.
AxiSentinel coverage: high-impact impact assessments · AI & AI-content notification evidence · human-oversight logs
People's Republic of China
Generative AI measures, algorithm filings & mandatory content labelling
GB 45438-2025 in force

China regulates AI through registration and labelling rather than conformity assessment, a fundamentally different evidence model, and one with real teeth.

  • Measures for Labelling AI-Generated Synthetic Content plus the mandatory national standard GB 45438-2025, effective 1 September 2025. Explicit visible labels are required for chatbots, AI writing, synthetic voice, face generation and swap, and immersive scene creation; implicit labels such as watermarks and metadata are acceptable elsewhere. Platforms carry watchdog duties.
  • Interim Measures for the Management of Generative AI Services, security assessment and filing before public-facing release.
  • Algorithm and deep-synthesis filing with the Cyberspace Administration of China; TC260 security standards and the "AI Plus" national plan.
  • Non-compliance carries investigations, fines, business suspension and permit revocation.
AxiSentinel coverage: synthetic-content labelling verification · filing-consistency monitoring · drift against filed algorithm description
Singapore
Model AI Governance Framework, AI Verify & Digital Government
Framework & Testing

No AI statute, and yet the most operationally credible AI-testing ecosystem in the world, which is why Singapore is the reference implementation for evidence-based assurance.

  • Model AI Governance Framework and the Model AI Governance Framework for Generative AI, nine dimensions from accountability and data through testing and assurance to content provenance and AI for public good.
  • AI Verify and the AI Verify Foundation, a testing framework and toolkit that turns governance principles into executable tests. AxiSentinel's evidence model is built for exactly this kind of measurable, repeatable verification.
  • Digital Government Blueprint and GovTech engineering standards; IMDA as the policy owner.
  • PDPA advisory guidelines on the use of personal data in AI recommendation and decision systems.
AxiSentinel coverage: AI Verify-aligned test evidence · GenAI framework dimensions · PDPA AI advisory monitoring
Japan
AI Promotion Act & AI Guidelines for Business
Innovation-first, no penalties

Japan legislated deliberately light: the Act sets principles, institutions and coordination rather than compliance obligations, and the government's stated aim is to be the most AI-friendly country in the world.

  • Act on Promotion of Research, Development and Utilization of AI-Related Technologies, enacted 28 May 2025, in full force 1 September 2025. No detailed obligations and no penalties; it creates the AI Strategic Headquarters and mandates an AI Basic Plan.
  • AI Guidelines for Business Ver. 1.2, issued 31 March 2026 by METI and MIC, and the practical governance yardstick Japanese agencies and their vendors are measured against.
  • Draft revised AI Basic Plan published 26 June 2026, adding a new principle of "Challenge and Learn".
  • Digital Agency procurement and government-use guidance; APPI for personal data in AI.
AxiSentinel coverage: AI Guidelines for Business v1.2 mapping · voluntary-commitment substantiation · APPI evidence
India
India AI Governance Guidelines, the seven sutras & the 2026 synthetic-content rules
GuidelinesIT Rules binding

India has paired a principle-based national framework with binding, technically specific deepfake rules, a combination that catches most government citizen-facing AI.

  • India AI Governance Guidelines, released by MeitY in November 2025 and launched in full at the AI Impact Summit in February 2026. Anchored in seven sutras: trust, people-first governance, innovation over restraint, fairness and equity, accountability, understandability by design, and safety, resilience and sustainability.
  • New institutions, the AI Governance Group, the Technology & Policy Expert Committee and the India AI Safety Institute.
  • IT (Intermediary Guidelines) Amendment Rules, 2026, notified 20 February 2026, targeting "synthetically generated information". Prominent labelling or embedded metadata is mandatory, visible for at least 10% of content duration or display area, with due-diligence and traceability duties on significant social media intermediaries.
  • Digital Personal Data Protection Act 2023 and its rules; the IndiaAI Mission for public-sector capacity.
AxiSentinel coverage: seven-sutra governance mapping · synthetic-content label verification · DPDP evidence
Australia & New Zealand
Technology-neutral regulation and a new safety institute
Guardrails shelved

Australia reversed course, and understanding why matters: obligations did not disappear, they were pushed back into existing law, where they are harder to see and no easier to satisfy.

  • No AI Act. Ten mandatory guardrails for high-risk AI were proposed in September 2024, then dropped in the December 2025 National AI Plan in favour of technology-neutral regulation using existing privacy, consumer, anti-discrimination and sectoral law.
  • Australian AI Safety Institute, operational in early 2026 with A$29.9 million in funding, to test systems and recommend targeted reforms.
  • Voluntary AI Safety Standard and the DTA's Policy for the Responsible Use of AI in Government (version 2.0, effective 15 December 2025), including a mandatory AI impact assessment, an accountable officer per use case, an internal register and a published agency-level AI transparency statement.
  • New Zealand, the Algorithm Charter for Aotearoa New Zealand and the public service AI framework; obligations run through the Privacy Act and public-law review.
AxiSentinel coverage: AI transparency statement evidence · Voluntary Safety Standard substantiation · Algorithm Charter records
Hong Kong SAR · Taiwan · ASEAN
The rest of Asia-Pacific
Mixed

The second tier of APAC markets is where most regional AI programmes actually get deployed, and where coverage gaps most often appear.

  • Hong Kong SAR, the PCPD's AI model personal data protection framework and checklist, OGCIO ethical AI guidance for government, and sector rules from the HKMA and SFC.
  • Taiwan, the AI Basic Act framework and MODA guidance; sectoral financial rules from the FSC.
  • Malaysia, the National AI Office (NAIO) and the National Guidelines on AI Governance & Ethics.
  • Indonesia, the national AI strategy and roadmap, ministerial AI ethics circular and the PDP Law.
  • Thailand, ETDA AI governance guidelines and draft AI royal decree work.
  • Vietnam, AI provisions in the Law on Digital Technology Industry.
  • Philippines, the National AI Strategy and DTI/CAIR programme; ASEAN Guide on AI Governance and Ethics as the regional baseline.
AxiSentinel coverage: PCPD framework evidence · ASEAN guide mapping · per-market gap analysis
AxiLayer AI maintains a dedicated Asia-Pacific practice covering accreditation posture, country-by-country framework status and regional market structure. See the Asia-Pacific practice page →
Region 4 · Americas, UK, Africa & Multilateral

Everywhere else that binds a government AI system

United States · DHS/CBP
Biometric Entry-Exit Program extends facial recognition to all foreign travelers
In force 26 Dec 2025

A binding final rule now authorizes facial-comparison biometric collection from foreign travelers at every activated U.S. port of entry and exit, well beyond the pilot airports the prior rule limited it to.

  • 90 FR 48644, published 27 October 2025 and effective 26 December 2025, amends 8 CFR 215.8 and 8 CFR 235.1(f). Facial-comparison collection now applies to all aliens at every activated port type: commercial air for entry and exit, sea ports for entry, and pedestrian land ports for entry, with vehicle land-border and private-aircraft expansion left to separate rulemakings not yet in force.
  • U.S. citizens stay voluntary participants. A citizen may decline facial biometric capture and request manual document review instead, and any photograph taken of a citizen during identity verification is discarded within 12 hours.
  • Age-based exemption preserved for non-photograph biometrics: aliens under 14 or over 79 remain exempt from fingerprint and similar collection, even though the rule removed the prior photograph-specific age exemption.
AxiSentinel coverage: biometric collection-scope evidence · citizen opt-out and 12-hour photo-discard verification · age-exemption compliance checks
United States · Federal
Executive order framework, OMB policy & NIST
EO 14365 active

The federal posture shifted from safety-first to adoption-first, and then to actively contesting state regulation, but the government's own AI use remains governed.

  • EO 14179 (January 2025) replaced EO 14110, reorienting federal AI policy toward removing barriers to American AI leadership.
  • EO 14365, "Ensuring a National Policy Framework for AI", signed 11 December 2025. A DOJ AI Litigation Task Force began challenging state AI laws in federal court from 10 January 2026; Commerce published a review of burdensome state laws in March 2026; the FTC was directed to address state-mandated bias mitigation; $42 billion in BEAD broadband funding was made conditional. Critically for public bodies, state government procurement and use of AI is carved out of the preemption push, and because preemption normally flows from statute rather than executive order, the practical effect is guidance to federal agencies rather than displacement of state law.
  • OMB M-25-21 and M-25-22, federal agency AI governance, chief AI officers, high-impact AI use-case inventories, minimum risk-management practices, and AI acquisition requirements for vendors.
  • NIST AI RMF 1.0 plus the Generative AI Profile (NIST AI 600-1), the de facto US evidence vocabulary, and a statutory safe harbour in Texas.
  • FedRAMP authorisation for AI cloud deployment, CMMC 2.0 for AI handling controlled unclassified information, and Section 508 accessibility for AI-powered government interfaces.
AxiLayer AI: SAM.gov registered for all award types · CAGE 20JV1 · UEI CB76ENDLMUC9
United States · States
109 state AI laws, and the ground still moving
Texas & California in force

State law is where US government AI obligations actually bite, and 2026 delivered both a major new regime and a major repeal.

  • Texas, TRAIGA (HB 149), effective 1 January 2026. Focused primarily on government agency use of AI, intent-based rather than impact-based for private actors, with substantial compliance with the NIST AI RMF as an enforcement safe harbour. Disparate impact alone does not establish intent.
  • California, SB 53 (Transparency in Frontier AI Act) and AB 2013 (training-data disclosure), both effective 1 January 2026. SB 53 requires frontier developers above the 1026 FLOP threshold to publish risk frameworks, report critical safety incidents and protect whistleblowers, with enhanced duties above $500 million revenue.
  • Colorado, reversed. SB 24-205 was delayed to 30 June 2026, then repealed outright by SB 26-189 on 14 May 2026 before ever taking effect, replaced by a narrower automated-decision-making-technology law effective 1 January 2027.
  • NYC Local Law 144, annual independent bias audit for automated employment decision tools, including for public employers in scope.
  • As of 1 July 2026, states had enacted 109 AI laws and 28 data-centre laws, with no comprehensive federal AI statute. Counsel's consistent advice: build to the most stringent applicable state requirement rather than waiting for litigation to resolve.
AxiSentinel coverage: NIST AI RMF safe-harbour evidence · LL144 bias-audit inputs · multi-state obligation reconciliation
United Kingdom
Pro-innovation framework with a mandatory transparency standard
ATRS mandatory for departments

The UK has no AI act, but it does have the most concrete public-sector AI transparency obligation in the Anglosphere.

  • Algorithmic Transparency Recording Standard (ATRS), mandatory since 6 February 2024 for central government departments, requiring published records of algorithmic tools used in decisions affecting the public.
  • DSIT as policy owner, the AI Security Institute for frontier evaluation, and a sector-regulator model in which the ICO, CMA, FCA, Ofcom and MHRA apply AI to their own remits.
  • UK GDPR and the Data (Use and Access) Act for automated decision-making; the Procurement Act 2023 for AI supplier duties; the Public Sector Equality Duty for algorithmic discrimination.
AxiSentinel coverage: ATRS record generation · equality-duty bias evidence · procurement supplier assurance
Canada · Latin America · Africa
Emerging and impact-assessment regimes
Canada AIA binding

Government-specific obligations often arrive before general AI law, Canada is the clearest example anywhere.

  • Canada, the Directive on Automated Decision-Making and its mandatory Algorithmic Impact Assessment bind federal institutions today, with obligations scaling by impact level. AIDA lapsed with prorogation; Quebec's Law 25 and provincial regimes add automated-decision duties.
  • Brazil, PL 2338/2023, the risk-based AI bill approved by the Senate, alongside LGPD automated-decision rights and ANPD supervision.
  • Chile, Peru, Colombia and Mexico, national AI policies and bills at varying maturity; Peru enacted an AI law with implementing regulation.
  • African Union Continental AI Strategy, plus national strategies and data protection regimes in Nigeria, Kenya, Egypt, South Africa, Rwanda, Ghana and Morocco, increasingly the binding layer for donor-funded and sovereign digital-government AI.
AxiSentinel coverage: AIA impact-level evidence · LGPD automated-decision records · continental strategy alignment
Multilateral & Standards
The treaties and standards that travel across all of the above
Cross-border

Standards are the interoperability layer. A single well-built evidence base can satisfy several regimes at once, which is the entire economic argument for continuous assurance.

  • Council of Europe Framework Convention on AI, the first legally binding international AI treaty, open to non-European signatories.
  • OECD AI Principles and the OECD AI Incidents Monitor; UNESCO Recommendation on the Ethics of AI with its Readiness Assessment Methodology used by governments directly.
  • G7 Hiroshima AI Process code of conduct and reporting framework; UN General Assembly Resolution A/RES/79/325 (adopted 27 August 2025), establishing an Independent International Scientific Panel on AI and a Global Dialogue on AI Governance, international cooperation machinery, not a domestic-deployment rule, but the clearest sign multilateral AI governance is consolidating; and the Global Digital Compact.
  • ISO/IEC 42001 (AI management systems), ISO/IEC 42005 (AI system impact assessment), ISO/IEC 23894 (AI risk management), ISO/IEC 42006:2025 (requirements for bodies auditing and certifying AI management systems) and ISO/IEC 17020/17065 for inspection and product certification.
  • NIST AI RMF and the emerging NIST control overlays for AI, which are becoming the shared technical vocabulary well beyond the United States.
AxiLayer AI is pursuing ISO/IEC 17020 and ISO/IEC 42001 accreditation through a US-based ILAC MRA and IAF MLA signatory. Accreditation not yet granted.
Coverage

Government AI use cases we cover

These are the deployment classes that regulators in the EU, Korea, Saudi Arabia, the UAE, Canada and the United States have specifically identified as high-risk, high-impact or subject to mandatory assessment. AxiSentinel is configured per use case, not shipped as one fixed pipeline.

Benefits & entitlement determination
Eligibility, means-testing, sanctions and overpayment detection. Annex III essential-services high-risk; Canada AIA Level III-IV.
Taxation & revenue
Risk scoring, audit selection, fraud detection and automated assessment. Prime territory for automated-decision challenge.
Immigration, visas & border
Application triage, risk assessment, biometric matching. Annex III migration and border-control band.
Policing & criminal justice
Predictive deployment, risk assessment, evidence triage, recidivism scoring. Annex III law-enforcement band with prohibited-practice adjacency.
Courts & administration of justice
Case triage, sentencing support, legal research. Annex III justice band; explainability is the binding constraint.
Child, family & social services
Risk-of-harm scoring and caseload prioritisation. The highest-scrutiny public AI category in every jurisdiction.
Public health & hospital systems
Triage, diagnostic support, resource allocation in state-run health systems. Overlaps medical-device conformity regimes.
Education & admissions
Admissions scoring, proctoring, attainment prediction. Annex III education band.
Employment & public-sector hiring
CV screening, ranking, promotion. Annex III employment band; NYC LL144 bias-audit territory.
Licensing, permitting & inspection
Automated approvals and risk-based inspection targeting; the fastest-growing category of municipal AI.
Procurement & contract automation
Bid evaluation, supplier risk, spend analytics. Directly implicates fairness and challenge rights.
Citizen-service chatbots & translation
Article 50 transparency live now; Korea notification duties; China labelling; India synthetic-content rules.
National ID & biometrics
Facial recognition, liveness, deduplication. Prohibited-practice boundaries and biometric prior-authorisation regimes.
Emergency services & 911/999 triage
Call classification, dispatch optimisation, resource prediction. Annex III critical-services band.
Smart city, transport & utilities
Traffic management, transit optimisation, grid and water control. Annex III critical-infrastructure band.
Agentic AI in government workflows
Autonomous agents taking action across case-management systems. DIFC Regulation 10's paradigm case; largely unaddressed by point-in-time audit.
Defence-adjacent & national security AI
Air-gapped and classified deployment, CMMC 2.0 for CUI, sovereign data boundaries.
Sovereign wealth & state-owned enterprise AI
Investment analytics and portfolio AI inside SWFs and SOEs, government accountability with financial-sector rules attached.
Deliverables

The documents a supervisor, a court or a public accounts committee actually asks for

JurisdictionInstrumentWhat AxiLayer AI produces
European UnionAI Act Art. 27 & Art. 49Fundamental Rights Impact Assessment pack, kept current as the deployment changes; Article 49 EU-database registration dossier; Annex IV technical documentation set; Article 26 deployer evidence and six-month log retention.
Saudi ArabiaSDAIA National AI RMFFour-phase risk register mapped to context/scope, identification & assessment, treatment and continuous monitoring; draft Responsible AI Policy registration and testing evidence.
UAE, DIFCDP Law Regulation 10Autonomous and semi-autonomous processing records, human accountability evidence and ethical-use substantiation for the Commissioner of Data Protection.
UAE, Federal / Abu Dhabi / DubaiAI Charter, PDPL, AIATC, Dubai AI SealCharter-principle conformance mapping, PDPL automated-processing evidence, AIATC-aligned risk registers, and independent substantiation for Dubai AI Seal claims.
Republic of KoreaAI Framework ActHigh-impact AI impact assessment, AI and AI-content notification evidence, risk-management-system documentation and domestic-representative support pack.
United States, FederalOMB M-25-21/22, NIST AI RMFHigh-impact use-case inventory entries, minimum-practice evidence, NIST AI RMF profile and GenAI Profile mapping, FedRAMP and CMMC 2.0 alignment artefacts.
United States, StatesTRAIGA, LL144, ADMT lawsNIST AI RMF safe-harbour evidence for Texas, independent bias-audit inputs for NYC Local Law 144, and reconciled multi-state obligation matrices.
CanadaDirective on ADMAlgorithmic Impact Assessment at the assessed impact level, with the ongoing monitoring and peer-review evidence the Directive requires.
United KingdomATRSAlgorithmic Transparency Recording Standard records for central government departments, plus Public Sector Equality Duty bias evidence.
ChinaGB 45438-2025, CAC filingsSynthetic-content label verification (explicit and implicit), and monitoring for divergence between live behaviour and the filed algorithm description.
IndiaIT Amendment Rules 2026, DPDPSynthetic-content labelling and metadata verification against the 10% visibility threshold, traceability records, and seven-sutra governance mapping.
Australia & NZDTA policy, Algorithm CharterAI transparency statement evidence, accountable-official reporting packs and Algorithm Charter records.
Cross-borderISO/IEC 42001, 42005, 23894AI management system readiness assessment, AI system impact assessments and AI risk management documentation reusable across multiple regimes.
AxiLayer AI is an independent assurance firm. It does not build, sell or resell the AI systems it assesses. AxiLayer AI is pursuing ISO/IEC 17020 and ISO/IEC 42001 accreditation through a US-based ILAC MRA and IAF MLA signatory; accreditation has not yet been granted, and readiness assessments are described as such.
For Investors

Why the government segment is the hardest to enter and the hardest to lose

Public-sector AI assurance has the characteristics investors look for in a compliance category: a regulatory forcing function that is already law, budget that is appropriated rather than discretionary, procurement barriers that punish late entrants, and multi-year contract duration once a vendor is inside. The market structure below is what makes government the anchor segment for AxiLayer AI rather than an adjacent one.

36 to 51%
AI governance market CAGR to 2030
The growth band is consistent across research houses even where absolute market levels diverge by more than seven times, which makes the rate the more defensible modelling input than the level.
$1 to 7B
AI governance market by 2030
Roughly $1 to 3B on narrow software-tooling definitions, $5 to 7B including services and consulting. Audit and monitoring already held the largest share by functionality.
109
US state AI laws enacted by 1 Jul 2026
Plus 28 data-centre laws. No comprehensive federal statute, which multiplies rather than reduces the reconciliation work a deployer must do.
2 Dec 2027
EU Annex III high-risk deadline
A sixteen-month deferral that extends the addressable readiness window rather than closing it, while Article 50 transparency went live on 2 August 2026.
45+
Government jurisdictions mapped
Each with a different classification test, evidence format and supervisor. Coverage breadth is the barrier to entry in this category.
3
USPTO provisional patent filings
Covering the regulation-encoded compliance agent, the audit architecture with signed evidence chain, and the compliance-conditional live certification registry.

The five structural advantages

The honest risk picture

Market figures above are drawn from third-party research houses whose scope definitions differ materially; ranges are presented rather than point estimates for that reason. Nothing on this page is an offer to sell securities.