Lenavix
Source integrity

Regulatory source register.

This register identifies the official issuer source, legal-force category, current status, and material scope limitation for regulatory references displayed on Lenavix. It is informational only and is not legal advice.

Last verified 19 July 2026 · official first-party sources
Binding lawBinding ruleVoluntary frameworkVoluntary guidanceInternational standardResearch taxonomy
Binding instruments

Laws and rules.

Binding law

EU Artificial Intelligence Act

European Union

In force with phased application through 2 August 2027.

Applicability depends on role, system classification, use case, market connection, and territorial scope.

Official text at EUR-Lex
Binding law

EU General Data Protection Regulation

European Union

In force.

Applies to covered personal-data processing. Article 22 addresses certain decisions based solely on automated processing.

Official text at EUR-Lex
Binding law

UK GDPR

Information Commissioner's Office

UK data-protection law in force.

Requirements depend on processing role, purpose, data, and context; official guidance reflects the Data (Use and Access) Act 2025.

Official ICO guidance
Binding law

FTC Act, Section 5

U.S. Federal Trade Commission

In force.

Prohibits unfair or deceptive acts or practices in or affecting commerce within the FTC's jurisdiction.

Official FTC statute page
Binding law

CCPA, as amended by CPRA

California Department of Justice

In force.

Applies to covered businesses and California consumers; duties depend on thresholds, data, purpose, and role.

Official California guidance
Binding law

Colorado Senate Bill 26-189

Colorado General Assembly

Became law 14 May 2026; core developer and deployer duties begin 1 January 2027.

Addresses developers and deployers of covered automated decision-making technology that materially influences consequential decisions, subject to statutory definitions and exemptions.

Official enacted bill record
Binding law

NYC Automated Employment Decision Tools law

New York City DCWP

Enforced since 5 July 2023.

Applies to covered tools used for specified New York City employment decisions.

Official NYC guidance
Binding law

Texas Responsible AI Governance Act

Texas Legislature

Effective 1 January 2026.

Applies to covered developers and deployers under Texas law, with role-specific duties, prohibitions, and exceptions.

Official legislative record
Binding law

Illinois AI employment amendments

Illinois General Assembly

Effective 1 January 2026.

Addresses AI use in covered employment decisions and employer notice obligations.

Official public act
Binding law

Canada PIPEDA

Department of Justice Canada

Current federal statute; official consolidation current to 26 May 2026.

Applies to personal information in commercial activities within statutory scope, subject to provincial and other exceptions.

Official consolidated act
Binding law

Korea AI Basic Act

Ministry of Government Legislation

Effective 22 January 2026.

Applies under the Act's definitions, territorial provisions, high-impact AI rules, transparency duties, and exceptions.

Official English text
Binding law

Brazil LGPD

Brazilian National Data Protection Authority

In force.

Applies to covered personal-data processing under its material and territorial provisions, subject to exceptions.

Official English text
Binding rules

China generative-AI and algorithm rules

Cyberspace Administration of China

Generative-AI Measures effective 15 August 2023; algorithm-recommendation rules effective 1 March 2022.

Each instrument has its own service, territorial, and activity scope.

Generative-AI Measures · Algorithm rules
Binding EU instruments

DSA, NIS2, and DORA

European Union

DSA and DORA are applicable regulations; NIS2 is implemented through national law.

DSA applies to covered intermediary services, NIS2 to covered entities in specified sectors, and DORA to specified financial entities and ICT arrangements.

DSA · NIS2 · DORA
Non-binding and standards material

Frameworks, guidance, and research.

Voluntary framework

NIST AI RMF 1.0

U.S. National Institute of Standards and Technology

Voluntary framework; revision process announced.

Risk-management resource for voluntary use; not law and not proof of legal compliance.

Official NIST resource
Voluntary framework

NIST Cybersecurity Framework 2.0

U.S. National Institute of Standards and Technology

Current voluntary cybersecurity framework.

General cybersecurity guidance; not an AI-specific law and not a certification.

Official NIST resource
International standard

ISO/IEC 42001:2023

International Organization for Standardization

International standard published December 2023.

Management-system standard; use or certification does not itself establish compliance with applicable law.

Official ISO record
Voluntary guidance

Model AI Governance Framework for Agentic AI, Version 1.5

Infocomm Media Development Authority

Version 1.5 published 20 May 2026; updated 5 June 2026.

Voluntary governance guidance for organizations deploying agentic AI; not a substitute for applicable Singapore law.

Official IMDA framework
Voluntary guidance

Japan AI Guidelines for Business v1.2

Ministry of Economy, Trade and Industry

Version 1.2 published 31 March 2026.

Non-binding guidance for AI business actors; applicable law and sector rules remain controlling.

Official METI English text
Voluntary guidance

Australia Guidance for AI Adoption

Department of Industry, Science and Resources

Version 1.0 published October 2025.

Voluntary responsible-adoption guidance; it does not itself create new legal obligations.

Official guidance
Voluntary guidance

UK AI regulatory principles

Department for Science, Innovation and Technology

Voluntary initial guidance published 6 February 2024.

Cross-sector principles for regulators; does not replace applicable law or regulator-specific rules.

Official GOV.UK guidance
Research taxonomy

MIT AI Risk Repository

MIT AI Risk Initiative

Research repository.

Research taxonomy and evidence resource; not law, regulation, a compliance standard, or a certification.

MIT AI Risk Initiative