AI GRC Regulations & Frameworks
A browsable catalog of the AI governance landscape — regulations by jurisdiction, risk domains and treatments, frameworks, and the controls that crosswalk between them.
Placeholder content — the live, provenance-backed catalog is coming soon.
AI GRC Regulations by Country & State
Statutes and regulations governing AI, organized by jurisdiction.
EU AI Act
The first comprehensive, risk-tiered legal framework for AI — prohibited, high-risk, and limited-risk obligations.
Colorado AI Act (SB 24-205)
Duties on developers and deployers of high-risk AI systems to prevent algorithmic discrimination in consequential decisions.
Utah AI Policy Act
Consumer-facing disclosure requirements for generative AI and an AI policy/learning-lab regime.
US Federal AI Executive Actions
Federal executive direction on safe, secure, and trustworthy AI, and agency-level implementation.
AI GRC Risks & Treatments
AI risk domains (aligned to the MIT AI Risk Repository) and their treatments.
Discrimination & Toxicity
Unfair discrimination, exposure to toxic content, and unequal performance across groups.
Privacy & Security
Leakage of sensitive information and vulnerability of AI systems to attack.
Misinformation
False or misleading information and the erosion of a shared information environment.
Malicious Actors & Misuse
Use of AI to cause harm — fraud, cyberattacks, surveillance, or weapons.
AI GRC Frameworks
Risk and control frameworks for governing AI systems.
NIST AI Risk Management Framework
Voluntary framework organized around Govern, Map, Measure, and Manage functions.
ISO/IEC 42001
Management-system standard for AI (AIMS) — the certifiable "ISO 27001 for AI".
NIST SP 800-53 Rev5
First-class control catalog underpinning FedRAMP/GovRAMP baselines and AI control overlays.
Controls & Crosswalks
Individual controls and how they map across frameworks and regulations.
AI Governance & Accountability
Establish accountable ownership and governance for AI systems — mapped across NIST AI RMF, ISO 42001, and EU AI Act.
Data Governance & Quality
Govern training and input data quality, provenance, and representativeness — crosswalked across frameworks.
Human Oversight
Ensure meaningful human oversight of high-risk AI decisions — mapped across regulatory and framework sources.