Skip to main content

Regulatory Compliance for LLMs and AI Systems

This directory contains detailed documentation on various laws, regulations, and standards that affect the development, deployment, and operation of LLMs and AI systems.

Regulation Applicability Matrix

Use this table to quickly identify which regulations might apply to your organization.

  • ✓ = Regulation applies
  • ? = May apply depending on specific circumstances
  • (blank) = Generally does not apply
RegulationEU
Ops
US
Ops
EU
Data
US
Data
B2CB2BHealth
care
Edu
cation
Fin
ancial
AI/ML
Systems
Cloud
Services
Critical
Infra
GDPR?
CCPA/CPRA??
LGPD??
PIPEDA??
India DPDP??
HIPAA?
HITECH?
FERPA?
EU AI Act?
NYC Bias Law
Algo Account Act*
CA SB 1047*
US EO on AI
DMCA??
EU Copyright
UK Copyright
FTC Act?
EU UCPD
UK CPR
NIS Directive
CA Data Breach
MA Data Security
EAR
ITAR
Defiance Act*
PCI DSS???
SOX?????
UK Online Safety???

*Proposed legislation

Important Notes:

  1. Revenue and Size Thresholds

    • CCPA/CPRA: Applies to businesses with >$25M annual revenue
    • MA Data Security: No minimum threshold
    • EU AI Act: Different requirements based on company size
    • Algorithmic Accountability Act: Proposed thresholds for company size
  2. Data Volume Thresholds

    • CCPA/CPRA: >100,000 consumers/households
    • GDPR: No minimum threshold
    • India DPDP: Specific volume thresholds for different requirements
  3. Geographic Considerations

    • Laws may apply based on:
      • Location of operations
      • Residence of data subjects
      • Location of data processing
      • Market targeting
  4. Industry-Specific Requirements

    • Healthcare: HIPAA, HITECH
    • Education: FERPA
    • Financial: Various banking regulations
    • Defense: ITAR, EAR
  5. Technology-Specific Factors

    • AI/ML system complexity
    • Automated decision-making
    • Data processing methods
    • Security requirements

Data Protection and Privacy

Global and Regional Frameworks

United States Privacy Laws

AI-Specific Regulations

Enacted Laws

Proposed Legislation

Executive Actions

International Frameworks

United States

  • DMCA - Digital Millennium Copyright Act

Consumer Protection

International Frameworks

United States

  • FTC Act - Federal Trade Commission Act

Security and Export Controls

Cybersecurity

Export Controls

  • EAR - Export Administration Regulations
  • ITAR - International Traffic in Arms Regulations

Using This Documentation

Each regulatory document follows a consistent structure:

  1. Title & Overview
  2. Scope & Applicability
  3. Key Requirements
  4. Impact on LLM/AI Deployments
  5. Enforcement & Penalties
  6. Resources & References

For specific compliance requirements, refer to the individual documentation files. Consider consulting legal experts for interpretation and application to your specific use case.