Data Defenders LLC — Protecting Your Most Valuable Business Asset

Coming next

The AI Regulations and Frameworks We're Tracking

A running catalog of AI laws, frameworks, and regulatory instruments we intend to build assessments for. Split by delivery status — Coming soon means enacted hard law or complete voluntary standards, with compendium built and activation pending; Under consideration means the framework is not yet fully ratified, enacted, or in force. Tell us which you need next and it moves up the queue.

None of these are live yet — for currently-available assessments (NIST AI RMF, EU AI Act, ISO/IEC 42001) see AI Readiness pricing.

Coming soon

Assessments with compendium content built and verified. All cover frameworks that are enacted hard law with active enforcement, or complete voluntary standards in active industry use. Activation pending final backend integration.

United States — State & Local

46 questions · 9 sections · all hard law

US State AI Law Assessment

All 9 jurisdictions are hard law in force with active enforcement — the most enforcement-dense assessment in the catalog. Cumulative, compounding regulatory exposure for multi-state operators. Penalty exposure spans $1,500–$7,500 per violation depending on jurisdiction.

  • · California — CCPA/CPRA ADMT + SB 942 AI Transparency Act
  • · Colorado — ADMT Act (SB 26-189)
  • · Illinois — AI Video Interview Act + HB 3773
  • · New York City — Local Law 144 AEDT bias audit
  • · Texas — TRAIGA
  • · Utah — AI Policy Act (SB 149)
  • · Virginia — VCDPA automated decision-making
  • · Connecticut — CTDPA automated decision-making

US Federal

24Q · 6S · hard law (federal)

US Federal AI Policy Assessment

OMB Memoranda M-24-10 & M-25-22 — binding federal directives since 2024. Enforced by OMB and agency Inspectors General with budget and contract implications. Private-sector organizations face obligations through federal contracts and grants, not direct statute.

United Kingdom

28Q · 7S · mixed

UK AI Governance Assessment

No single UK AI Act by design. DSIT's five cross-sector principles apply through sector regulators (FCA, ICO, CQC, Ofcom) — no dedicated penalties but real consequences in regulated domains. UK GDPR/ICO is different: fully enforceable with penalties up to £17.5M for AI-driven ADM and personal data processing.

Japan

28Q · 7S · mixed

Japan AI Governance Assessment

Two-tier framework. METI/Cabinet AI Guidelines are voluntary but expected in Japanese enterprise procurement and government engagement. APPI is different: hard law with civil and criminal penalties for personal data violations — including AI-driven profiling and automated decisions.

China

24Q · 6S · all hard law

China AI Governance Assessment

Every component is enforceable hard law. CAC Algorithm Regulations + Generative AI Provisions + mandatory AIGC labeling under GB 45438-2025 + PIPL (penalties up to ¥50M or 5% of annual revenue). CAC actively uses suspension authority and enforces filing requirements. Layered, simultaneous enforcement risk.

South Korea

24Q · 6S · all hard law

Korea AI Governance Assessment

Second country after the EU to enact a comprehensive AI statute — fully in force since July 2026. Tiered obligations for high-impact AI in employment, healthcare, finance, education, and public safety. Extraterritorial reach applies to foreign businesses above revenue thresholds. Administrative fine grace period expires January 2027.

India

28Q · 7S · mixed

India AI Governance Assessment

Clear split. DPDP Act 2023 is hard law with penalties up to ₹250 crore (~$30M) for AI-driven personal data processing — enforcement posture still developing as implementing rules are notified. MeitY Responsible AI Principles are voluntary. Sector regulators (RBI, SEBI, IRDAI) carry the most immediate enforcement risk for regulated deployments.

Singapore

31Q · 7S · mixed

Singapore AI Governance Assessment (IMDA + CSA Agentic)

Two-tier structure. IMDA Model AI Governance Framework and the Cyber Security Agency (CSA) Addendum on Securing Agentic AI (June 2026) are voluntary — adopted for reputational positioning and Smart Nation procurement alignment. PDPA is hard law: penalties up to S$1M or 10% of annual Singapore turnover.

Australia

28Q · 7S · mixed

Australia AI Governance Assessment

Most aspirational framework in the catalog. 8-principle AI Ethics Framework is voluntary — adopted for government procurement and stakeholder trust. Australian Privacy Act is the only legally enforceable component (penalties up to A$50M). Privacy Act reform expanding AI-specific obligations is pending — early alignment positions organizations well.

Cross-jurisdictional

24Q · 7S · voluntary

CSA Securing Agentic AI Assessment

Cloud Security Alliance (CSA) framework for securing autonomous AI agents — voluntary industry guidance with no regulatory penalties, but rapidly emerging as a de facto commercial standard in enterprise procurement and cyber insurance underwriting for agentic AI. Most operationally specific security standard currently available for autonomous AI systems.

Cross-jurisdictional · NIST add-on

22Q · 4S · voluntary

Berkeley CLTC Agentic AI Profile Assessment

UC Berkeley CLTC's academic Profile of the NIST AI RMF 1.0 — voluntary, no regulatory penalties, but described by contemporary analysts as the most comprehensive agentic AI risk taxonomy currently available. Requires NIST AI RMF (Full) as substrate; sold as add-on. Autonomy assessment (L0–L5), deceptive alignment detection, behavioral drift monitoring.

Under consideration

Assessments with compendium content built, covering frameworks not yet fully ratified, enacted, or in force. Tell us which you need next and it moves up the queue.

Brazil

28Q · 7S · mixed

Brazil AI Governance Assessment

PL 2338/2023 passed the Brazilian Senate December 2024 and is under Chamber of Deputies review — not yet law. LGPD Article 20 is hard law in force with ANPD enforcement (penalties up to 2% of Brazil revenue, max R$50M) creating enforceable rights to explanation and human review of automated decisions. Assessment reclassifies to Coming Soon upon PL 2338 enactment.

Vote for what you need

Need one that's not here? Or want to move one up the list?

Tell us the regulation, your organization's exposure, and why you need it. We prioritize what customers actually need.

Send us your request

A proper request-and-vote form with authentication is on the way. Until then, email works.

Talk to Us Directly

Free 25-minute consultation. Bring your questions.

Schedule the consultation Ask a question +1 720-739-1583

©2026 Data Defenders, LLC · Home · Privacy · FAQ

AI Governance · Fractional CISO · Cyber Programs · GRC