Skip to content

AI Systems Handbook / Chapter 43

Regulatory and Policy Landscape

Turn a changing mix of law, sector rules, contracts, and internal policy into a repeatable, evidence-rich review workflow.

The Global Launch With One Compliance Checkbox

A company plans to add an AI interview summarizer to its recruiting platform. The launch ticket asks, “AI compliant? yes/no.” The same feature will record speech, infer structured attributes, generate hiring notes, and serve employers in several countries. Procurement treats the model API as ordinary hosting, product treats the output as “only a draft,” and legal receives a screenshot two days before release.

There is no universal AI-compliance answer because the relevant duties depend on facts the ticket never collected.

Regulatory readiness is a maintained classification and decision process. Teams must establish where a system operates, which role the organization plays, what the system does, whose data and interests it affects, and which sources of authority govern each lifecycle stage.

A regulatory routing map turns system facts about place, role, sector, capability, data, people, and lifecycle stage into separate legal, contractual, policy, and evidence routes, ending in a dated decision with an update trigger.
Do not begin with a universal AI-law checklist. Begin with system facts, route them to the right authority, and time-bound the resulting decision.

“Required” by Whom?

The first review comment on the summarizer says that recording consent is required. The sentence is unusable until the team knows who requires it, for which recording, in which place, and under what relationship.

A statute or regulation binds through its legal scope and is interpreted by qualified counsel, regulators, and ultimately courts. A customer contract binds the parties through promises such as data-use limits, audit rights, and service levels. A standard or voluntary framework supplies a versioned way to organize assurance; it becomes mandatory only through adoption, contract, policy, or another source with authority. Internal policy binds through the organization’s own governance. An industry pledge binds according to the commitment actually made.

These sources can reinforce one another without becoming interchangeable. A customer may put a voluntary standard into a contract. Internal policy may prohibit a use the law permits. Regulatory guidance may shape enforcement while remaining distinct from legislation. Each claimed requirement therefore needs a source, version, binding status, scope, interpretation owner, and expected evidence. Without those fields, “required” is hearsay with a deadline.

Build the Fact Pattern Before Asking for Advice

Legal review becomes faster and more useful when teams provide concrete facts.

  1. Entities and locations: developer, provider, deployer, importer, distributor, employer, processor, operator; establishment and target regions.
  2. Capability and purpose: prediction, ranking, generation, identification, recommendation, tool use; intended and reasonably foreseeable uses.
  3. Workflow and consequence: who uses the output, what action follows, whether a person is materially affected, and whether review is meaningful.
  4. People and sector: workers, applicants, children, patients, students, borrowers, consumers, public-service recipients; health, employment, credit, insurance, education, safety, or public functions.
  5. Data: personal, sensitive, biometric, confidential, licensed, public, inferred, children’s, location, prompts, logs, training, retrieval, evaluation, and retention.
  6. Supply chain: model, data, hosting, tools, subprocessors, open-source components, geographic transfers, and contract allocation.
  7. Exposure: users, decisions, autonomy, scale, duration, reversibility, and foreseeable misuse.
  8. Lifecycle status: experiment, development, pilot, launch, operation, material change, incident, or retirement.

Attach a system diagram, data flow, use-case canvas, risk tier, evaluation summary, human-oversight plan, vendor inventory, and proposed disclosures. Counsel should not have to reverse-engineer the product from marketing language.

Let the Facts Open the Review Routes

The label AI does not identify the right reviewer. Consequences do.

Recording interviews and retaining transcripts open privacy and data-protection questions: purpose, authority, minimization, data flow, retention, and rights. Using summaries in hiring opens employment, equality, and rights questions: validity, affected groups, meaningful review, notice, and appeal. Sending recordings and prompts to an external model opens procurement, security, privacy, intellectual-property, and contract routes. Supporting several languages opens accessibility, equality, and localization work, with evidence from user research and assistive-technology and language-coverage tests.

Other systems open different routes. Generated public content can require content, consumer, media, provenance, and rights review. A model acting on physical equipment needs hazard analysis, fail-safe behavior, incident handling, and the applicable safety regime. An agent with privileged tools needs explicit permissions, approvals, logs, reversibility, and liability allocation. Monitoring workers can add labor consultation, proportionality, notice, contestability, and workload concerns.

Each route should return a decision the delivery team can implement: proceed, proceed with conditions, narrow, pilot, redesign, pause, reject, or retire. The record names the decision authority, rationale, evidence version, control owner, expiry, and reopening triggers. A margin comment from legal is not yet a control.

Watch a Classification Change While the Product Stands Still

The European Union’s AI Act shows why the review must preserve dates, roles, and system categories. The European Commission reports that the Act entered into force on 1 August 2024. Prohibited-practice and AI-literacy provisions began applying on 2 February 2025, and governance rules and obligations for general-purpose AI models on 2 August 2025. As of 20 July 2026, the Commission says transparency rules are due to apply from 2 August 2026. It also reports a May 2026 political agreement that would move rules for certain stand-alone high-risk systems, including employment systems, to 2 December 2027 and rules for high-risk systems embedded in regulated products to 2 August 2028.

That last sentence is exactly the kind a durable assumptions log must qualify. A Commission implementation page, a political agreement, the enacted regulation, final amending text, and qualified advice do not have the same legal status. Before launch, the team must determine the authoritative text then in force; whether it is acting as provider, deployer, or another actor; how the actual system is classified; whether an exception or sector rule changes the analysis; and which authority has jurisdiction. It records the reviewer and sets a new verification date instead of turning a moving timeline into permanent product folklore.

The same discipline applies elsewhere. A system may be governed through privacy, discrimination, consumer, product-safety, intellectual-property, labor, procurement, professional, or sector law even where no omnibus AI statute applies.

Maintain a Regulatory Assumptions Log

For each material interpretation, record:

  • question and system fact pattern;
  • jurisdiction, sector, role, capability, and affected population;
  • source, article or section, version, and effective date;
  • whether it is law, guidance, standard, contract, code, or policy;
  • interpretation, uncertainty, and qualified reviewer;
  • product, data, technical, disclosure, training, or process control;
  • evidence owner and completion status;
  • expiry, monitoring source, and reopening trigger.

Triggers include new geography, user class, purpose, autonomy, data category, model or provider, procurement term, incident, complaint pattern, regulator guidance, court decision, or policy revision. Connect the log to change management so a material product edit cannot bypass legal reassessment.

Assign owners to authoritative sources and obligations. Review cadence should follow volatility and consequence. Maintain a cross-functional change path:

  1. detect and authenticate the update;
  2. determine jurisdictions, systems, contracts, and deadlines affected;
  3. obtain qualified interpretation;
  4. translate it into product, technical, operational, documentation, and training changes;
  5. test the controls and preserve evidence;
  6. communicate with users, customers, workers, or authorities where required;
  7. verify production and close or time-bound exceptions.

Track source freshness and evidence completion, not the number of alerts collected. A newsletter is a signal, not legal authority.

The Launch Decision Changes Shape

The first intake calls the summarizer “only a drafting tool” and concludes that it cannot affect hiring. But recruiters will read its condensed account instead of replaying every interview. Omissions can change which evidence remains visible. Recordings contain personal data, provider logs cross organizational boundaries, and customers operate under different employment and data rules. The word draft describes the interface, not the consequence.

The team redraws the capture-to-decision workflow and supplies one versioned fact pattern to legal, privacy, employment, security, procurement, and accessibility reviewers. It includes regions, user roles, vendor and data flows, retention, language and accent evaluation, human verification, correction, and audit evidence. The impact assessment from the previous chapter becomes evidence here rather than a competing approval process.

The resulting decision is narrower than the proposed global launch. Approved regions and voluntary pilot users may proceed. Unsupported languages and consequential scoring are excluded. Contracts, disclosure, deletion, reviewer training, and monitoring controls must be demonstrated before expansion. The legal review does not choose the product; it makes authoritative constraints and uncertainty visible so accountable owners can choose within them.

AI Regulatory Review Intake

  • System identity: name, inventory ID, owner, versions, architecture, vendors, lifecycle stage, and target date.
  • Use and role: capability, purpose, output, action, autonomy, human review, affected people, and reasonably foreseeable misuse.
  • Reach: entities, jurisdictions, sectors, customers, users, decision volume, and deployment channels.
  • Data and content: categories, sources, rights, flows, locations, retention, training, retrieval, logs, and outputs.
  • Risk and evidence: internal tier, impact assessment, evaluation, security/privacy analysis, limitations, incidents, and alternatives.
  • Authority matrix: source, binding status, role affected, effective date, reviewer, interpretation, and controls.
  • Decision: scope, conditions, exclusions, disclosures, approvals, exceptions, expiry, and stop triggers.
  • Maintenance: source owners, reassessment cadence, change triggers, evidence repository, and escalation route.

Five Changes That Reopen the Decision

Use the completed intake to reason through five changes: the pilot enters a new country; customers ask for automatic applicant scores; the provider begins retaining prompts for service improvement; speech capture expands to minors; and a regulator publishes new employment-system guidance.

For each change, identify the fact that invalidates the old decision, the review routes it opens, the evidence those reviewers need, and the constraint that remains in force meanwhile. Then write one assumptions-log entry with a source and date, named interpretation owner, uncertainty, control owner, expiry, and reopening trigger. If the exercise can be answered by copying a universal checklist, the intake has not captured enough of the system.

Regulatory readiness is visible when a team can move from changed system facts to the right authority, produce a bounded decision, and make that decision expire. The next chapter follows one of the most consequential routes opened here: the outside model provider whose contract boundary does not contain the buyer’s accountability.

Source Notes

  • European Commission, AI Act overview provides official implementation context, the staged application timeline, and the Commission’s account of the May 2026 political agreement on high-risk-system dates; verified 2026-07-20. Legislative status and transition dates remain time-sensitive and require qualified verification against authoritative law.
  • European Commission, draft high-risk-system guidance illustrates the continuing classification and implementation work; verified 2026-07-20. The Commission identifies the guidance as draft and non-binding.
  • European Commission, guidelines for general-purpose AI model providers explains role classification, obligations, and enforcement timing for general-purpose AI providers; Commission guidance verified 2026-07-10.
  • NIST AI RMF is a voluntary, non-sector-specific risk-management framework rather than law; verified 2026-07-20. NIST states that AI RMF 1.0 is being revised.
  • This material provides an engineering and governance intake method, not legal advice. Applicable duties require qualified review for the actual jurisdiction, entity, sector, role, system, data, and date.
  • See Risk Triage Before Building and Change Management and Continuous Improvement.