The sixteen themes, filled from binding law

About this documentUpdated 2026-09-21ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.

Every law named here links to its summary page on lexlint.org, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same licence. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.

Corpus figures as of 2026-09-21.

Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice at the foot says what that means.

Each of the working group's sixteen themes with its key concepts, what the LexLint software-law corpus holds under it, and a sample of the requirement lines in force, drawn to span jurisdictions. The full register in the group's own column contract is the file at the foot.

1How to read a theme

The sixteen themes are the Agentic AI Foundation governance working group's, summarised in the group's own words; where they come from, and how the LexLint software-law corpus's twenty obligation classes map onto them, is the page before this one. Here each theme is filled from binding law: 6,825 requirement lines drawn from the corpus on 2026-09-21, of which 5,713 belong to an instrument in force on that date. A line joins a theme when its instrument's obligation class is one the theme's prompt is about, or when the line's own wording matches the theme's key concepts. A line can sit in more than one theme, as the group's own prompts allow. The rules are deliberately generous, so a theme's count is an upper bound on what a careful reader would keep, and the thin themes are thin because the law says little there, not because the rule missed it.

Each theme quotes the group's key concepts, gives its counts, and holds a sample of up to fourteen lines in force, drawn to span jurisdictions rather than to rank them, folded away until opened. The requirement is stated first, as the corpus records it; under it, the facts the group's columns ask for (type, modal language, applicable entity) and the three the corpus adds (the party whose position triggers scope, the territorial hook, and what a runtime control can do about it), then the jurisdiction, the instrument and its date, and the line identifier. How each of those facts is derived is set out in the requirement register, which is the same lines on the corpus's own axes. The full register in the group's column contract, every line in every theme, is the file in section 3.

ThemeLinesIn forceInstrumentsJurisdictionsWhere the lines come from
T01 Governance & Accountability 272 224 222 131 privacy 135 · cybersecurity 101 · AI 29 · scraping 7
T02 Use-case Classification & Risk Tiering 924 794 391 196 privacy 454 · AI 378 · scraping 58 · cybersecurity 34
T03 Architecture 39 32 39 37 privacy 28 · cybersecurity 6 · AI 3 · scraping 2
T04 Agent Identity & Delegation 231 204 204 132 privacy 134 · cybersecurity 42 · AI 34 · scraping 21
T05 Guardrails & Policy Constraints 357 324 300 172 privacy 221 · AI 59 · scraping 40 · cybersecurity 37
T06 Data Protection & Privacy 3,290 2,791 1,360 249 privacy 2,756 · AI 186 · cybersecurity 178 · scraping 170
T07 Security & Access Controls 2,811 2,524 858 244 privacy 1,161 · cybersecurity 999 · scraping 622 · AI 29
T08 Model/Agent Risk Management 583 472 294 154 privacy 396 · AI 99 · cybersecurity 68 · scraping 20
T09 Human Oversight 150 125 136 98 privacy 101 · AI 24 · scraping 15 · cybersecurity 10
T10 Action Management 137 121 126 91 privacy 68 · scraping 52 · AI 13 · cybersecurity 4
T11 Monitoring & Logging 168 133 132 96 privacy 83 · cybersecurity 50 · AI 26 · scraping 9
T12 Testing & Red Teaming 20 18 19 17 cybersecurity 10 · AI 5 · privacy 4 · scraping 1
T13 Third-Party & Supply Chain 1,147 1,022 648 229 privacy 733 · scraping 173 · cybersecurity 144 · AI 97
T14 Incident Response 1,000 811 469 204 privacy 576 · cybersecurity 380 · AI 31 · scraping 13
T15 Transparency & User Disclosure 2,708 2,224 1,156 244 privacy 1,543 · AI 487 · cybersecurity 480 · scraping 198
T16 Recordkeeping & Auditability 2,693 2,241 836 239 privacy 1,417 · cybersecurity 772 · AI 263 · scraping 241

2The sixteen themes

T01 · Governance & Accountability

The group's key concepts: Ownership; approvals; RACI; risk acceptance; governance bodies; accountability structures

272 lines 224 in force 222 provisions 131 jurisdictions by type: mandatory obligation 131, conditional obligation 86, definition 19, consequence (penalty or remedy) 17, prohibition 9, permission or exemption 5, recommendation/guidance 5

Classes its lines carry: secure the system and the data in it (151), govern the system: policies, roles, assessments (149), get consent first (64), disclose the use of AI (51); 36 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 224 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Adopt and follow a copyright policy that respects TDM opt-outs
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Establishment of the operator; placing on the market; where the output is used Runtime Enforceable at a runtime control
AI Act, Article 53 (obligations for providers of general-purpose AI models), Regulation (EU) 2024/1689, Article 53 Source as of 2026-08-15 ai:eu-2024-1689-53:1

California

If you use an internal auditor, have the highest-ranking auditor report to, and have their performance evaluation and compensation determined by, a member of executive management who does not have direct responsibility for the cybersecurity program.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
CCPA Cybersecurity Audit Regulations, Cal. Code Regs. tit. 11, Sections 7120 to 7124 Source as of 2026-09-15 privacy:us-ca-cal-regs-tit-11-sections-7120-7124:2

Colorado

Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) Source as of 2026-08-23 privacy:us-co-c-r-s-sections-6-1-1303-2-2-2-4-6-1-1314-2:1

Texas

You must provide an easily accessible system for a depicted person to request removal, and a clear, plain-language notice describing that process and your responsibilities under it.
Type Mandatory Obligation Modal must Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009 Source as of 2026-09-06 ai:us-tx-tex-civ-prac-rem-98b-0021-98b-009:3

Brazil

Publish a clear support policy stating how long and in what circumstances you will provide security updates, and provide security updates free of charge for at least 2 years after the product's launch or for as long as you keep distributing it to consumers, whichever period is longer.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Placing on the market Runtime Outside any runtime path
Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment), Ato nº 2.436, de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019 Source as of 2026-09-14 security:br-ato-n-2-436-de-7-de-mar-o-de-2023-superintend:4

India

The Data Protection Board of India exists, is administratively operational, and its jurisdiction ousts the civil courts over matters within its remit, but its penalty Schedule, complaint, and appeal machinery has not yet commenced and is scheduled for 13 May 2027, and no provision of the Act as read gives the Board power to award compensation to an individual complainant. Once fully in force, an app processing Indian personal data, including biometric identifiers, will answer only to the Board; India's DPDPA arms no private plaintiff, and a data principal who misuses their own rights under the Act, for example by impersonation or a frivolous complaint, risks a penalty of their own under section 15.
Type Consequence (penalty or remedy) Modal may Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
Digital Personal Data Protection Act, 2023, Data Protection Board and penalties, Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39 Source as of 2026-08-29 privacy:in-digital-personal-data-protection-2023-dpdpa-d:0

Germany

Cover at least: risk analysis and information-security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluation of your measures' effectiveness; basic cyber-hygiene training; cryptography; personnel security and access control; and multi-factor or continuous authentication.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 Source as of 2026-09-12 security:de-bsi-gesetz-bsig-vom-2-dezember-2025-28-30-38:2

Italy

If your AI service can be accessed by a minor under fourteen, obtain the consent of whoever holds parental responsibility before processing their personal data; a minor between fourteen and eighteen may consent alone if the required information is easily accessible and understandable (art. 4).
Type Conditional Obligation Modal may Binds, by its wording Operator (the party running the application) Scope turns on Principal Hook Establishment of the operator; placing on the market; where the output is used Runtime Enforceable at a runtime control
Legge 132/2025, Sector Human-Oversight and Disclosure Duties (Artt. 4, 11, 13), Legge 23 settembre 2025, n. 132, artt. 4, 11, 13 Source as of 2026-09-06 ai:it-l-132-2025-sector-oversight-disclosure:0

Spain

If designated an operator of essential services, designate a responsable de la seguridad de la informacion within three months of your designation, notify the competent authority of the appointment, and file a Declaracion de Aplicabilidad of the security measures you apply within six months of designation, reviewing it at least every three years.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers, Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero Source as of 2026-09-12 security:es-rdl-12-2018-art16-seguridad:2

France

Where you are instead designated as an operator of essential services, apply the security rules the Premier ministre sets under Article 6 at your own expense, covering governance, protection, defence and resilience of your networks and systems.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements, Loi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 Source as of 2026-09-12 security:fr-loi-n-2018-133-du-26-f-vrier-2018-titre-ier-c:3

Netherlands

Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.
Type Conditional Obligation Modal where applicable Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance, Cyberbeveiligingswet, Artt. 21 en 24 Source as of 2026-09-12 security:nl-cyberbeveiligingswet-artt-21-en-24:2

Japan

An app processing the personal data of a person in Japan must be prepared to answer to the Personal Information Protection Commission's investigative, recommendation, and order powers, and a responsible individual risks criminal liability for violating a PPC order; Japan has no APPI-specific private right of action, so an aggrieved person's civil remedy runs through general tort law instead.
Type Consequence (penalty or remedy) Modal must Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
Act on the Protection of Personal Information, enforcement, Act No. 57 of 2003, as amended by Act No. 37 of 2021, Chapters VI, VIII Source as of 2026-08-29 privacy:jp-no-57-2003-as-amended-by-no-37-2021-chapters:0

Australia

If you were responsible for creating or altering the non-consensual material yourself, or if you have 3 or more prior civil penalty orders for failing to comply with an Online Safety Act 2021 removal notice, you face a higher maximum penalty than a person who merely transmits such material.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market; where the output is used Runtime not a duty
Using a Carriage Service to Transmit Sexual Material Without Consent (Deepfake Offences), Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth), No. 78, 2024, inserting ss. 474.17A, 474.17AA into the Criminal Code Act 1995 (Cth), No. 12, 1995 Source as of 2026-09-06 ai:au-criminal-amendment-deepfake-sexual-material-2:2

211 more lines in force under this theme, and 272 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T02 · Use-case Classification & Risk Tiering

The group's key concepts: Allowed/prohibited uses; risk tiers; tiered controls; autonomy levels; classification criteria; re-classification triggers

924 lines 794 in force 391 provisions 196 jurisdictions by type: prohibition 325, conditional obligation 225, mandatory obligation 209, consequence (penalty or remedy) 62, definition 56, permission or exemption 47

Classes its lines carry: do not do the named thing (705), get consent first (333), limits on biometric use (211), govern the system: policies, roles, assessments (154); 68 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 794 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

If the Commission has classified your general-purpose AI model as carrying systemic risk, in addition to your Article 53 duties, perform model evaluation using standardised, state-of-the-art protocols and tools, including conducting and documenting adversarial testing to identify and mitigate systemic risks.
Type Conditional Obligation Modal imperative Binds, by its wording Provider of a general-purpose model Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk), Regulation (EU) 2024/1689, Article 55 Source as of 2026-09-20 ai:eu-2024-1689-55:0

California

Disclose that the media has been manipulated when you distribute materially deceptive audio or visual election media depicting a candidate within 60 days of an election
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
AB 730, as extended by AB 972, election deepfake disclosure law, Cal. Elec. Code Section 20010 Source as of 2026-08-14 ai:us-ca-cal-elec-20010:0

Texas

Do not develop or deploy an AI system that intentionally aims to incite or encourage physical self-harm, harm to another person, or criminal activity.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
TRAIGA (H.B. 149, 2025), prohibited AI practices binding any person, Tex. Bus. & Com. Code §§ 552.052, 552.055-552.057 Source as of 2026-09-06 ai:us-tx-tex-bus-com-552-052-552-055-552-057:0

South Korea

Before you provide an AI system, or a product or service that uses one, review whether it is high-impact, meaning it may seriously affect a person's life, physical safety or fundamental rights and is used in energy supply, drinking water production, healthcare provision, medical and digital medical devices, nuclear material and facility safety, biometric identification for criminal investigation or arrest, hiring and loan decisions, transportation systems, public-service eligibility and fee decisions, and student assessment in early childhood, elementary and secondary education. You may ask the Ministry of Science and ICT to confirm your answer.
Type Mandatory Obligation Modal may Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Framework Act, Article 34 (business-operator duties for high-impact AI), Act No. 20676, Article 34 Source as of 2026-09-20 ai:kr-no-20676-34:0

United Kingdom

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.
Type Conditional Obligation Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom, UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025 Source as of 2026-08-24 privacy:gb-uk-gdpr-33-34-privacy-electronic-communicatio:1

Brazil

Do not use fabricated or manipulated content in electoral advertising to spread notoriously untrue or gravely decontextualized facts capable of harming the balance of the election or the integrity of the electoral process.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
TSE Resolution, Prohibition on Electoral Deepfakes, Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) Source as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-c-reda-o-dada-pe:0

Vietnam

Continuously keep your AI system safe, secure, and reliable, and promptly detect and remedy any incident capable of harming people, property, data, or social order, regardless of the system's risk tier.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12 Source as of 2026-09-20 ai:vn-no-134-2025-qh15-12:3

Germany

Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 Source as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:1

Ireland

Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
GDPR Articles 33-34, Breach Notification in Ireland, Regulation (EU) 2016/679, Arts. 33-34 Source as of 2026-08-24 privacy:ie-eu-2016-679-33-34:1

Italy

Notify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
GDPR Articles 33-34, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34 Source as of 2026-08-24 privacy:it-eu-2016-679-33-34:0

Spain

Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s) Source as of 2026-08-24 privacy:es-eu-2016-679-33-34-lopdgdd-69-73-r-s:0

France

Do not create or share, by any means, a non-consensual sexual montage, or a non-consensual, algorithmically generated sexual image, video, or audio reproducing a real person's likeness or voice; France punishes this with two years' imprisonment and a 60,000 euro fine.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Code Pénal Article 226-8-1, Non-Consensual Sexual Montage and Algorithmically Generated Sexual Content, Code penal, art. 226-8-1, insere par la loi n. 2024-449 du 21 mai 2024 visant a securiser et a reguler l'espace numerique (SREN), art. 21 Source as of 2026-09-06 ai:fr-penal-226-8-1-insere-par-la-loi-n-2024-449-du:0

Netherlands

Notify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception.
Type Conditional Obligation Modal subject to Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
GDPR Articles 33-34 and UAVG Article 42, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42 Source as of 2026-08-24 privacy:nl-eu-2016-679-33-34-uavg-42:0

781 more lines in force under this theme, and 924 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T03 · Architecture

The group's key concepts: Reference patterns; trust boundaries; control placement; multi-agent topology; isolation; separation of concerns

39 lines 32 in force 39 provisions 37 jurisdictions by type: mandatory obligation 15, conditional obligation 10, prohibition 8, definition 3, consequence (penalty or remedy) 2, recommendation/guidance 1

Classes its lines carry: secure the system and the data in it (20), get consent first (19), govern the system: policies, roles, assessments (18), assess the impact on personal data first (16); 12 from an instrument with no class recorded.

Sample requirement lines Show 14 of the 32 lines in forceHide the sample

What follows is a sample of 14 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

California

For a user you know is a minor, disclose that they are interacting with artificial intelligence, and provide a clear and conspicuous break reminder by default at least every three hours during continuing interactions
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Companion Chatbot Safety and Accountability Act (SB 243), Cal. Bus. and Prof. Code Sections 22601 to 22606 Source as of 2026-09-08 ai:us-ca-cal-bus-prof-sections-22601-22606:2

Nigeria

Before deploying data processing software that tracks a data subject or opens a communication link with one, carry out an impact assessment, design it for privacy by design and by default, put a data privacy policy inside the software, and give a prospective user a privacy statement before installation.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the data subject; establishment of the operator Runtime not yet classified
Nigeria Data Protection Act, 2023 (NDPA), general data protection duties, Nigeria Data Protection Act, 2023 (No. 37 of 2023), general duties (ss. 1-3, 24-29, 32-33, 39 and 63-65; GAID 2025, arts. 1-17, 19-32, 34-35 and 41-42) Source as of 2026-09-19 privacy:ng-nigeria-data-protection-2023-no-37-2023:6

Kenya

Failing to make this report is itself an offence: a fine of up to two hundred thousand shillings, imprisonment of up to two years, or both; the Committee may separately propose isolating a suspected system pending resolution.
Type Consequence (penalty or remedy) Modal may Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Placing on the market; establishment of the manufacturer Runtime not a duty
Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat, Computer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40 Source as of 2026-09-14 security:ke-computer-misuse-cybercrimes-no-5-2018-s-40:3

United States

Submit any malicious software you isolate in connection with a reported incident to the Department of Defense Cyber Crime Center, following that Center's instructions, and never send it to the contracting officer.
Type Mandatory Obligation Modal never Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Placing on the market; establishment of the manufacturer Runtime not yet classified
Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012), 48 CFR 252.204-7012 Source as of 2026-09-20 security:us-48-cfr-252-204-7012:4

Andorra

Apply data protection by design and by default, keep a written record of your processing activities unless you employ fewer than fifty workers and none of the high-risk, non-occasional or special-category exceptions apply, and block rather than delete personal data pending any liability claim when you rectify or erase it.
Type Conditional Obligation Modal unless Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
LQPD, Llei 29/2021 del 28 d'octubre, LQPD, Llei 29/2021 del 28 d'octubre, arts. 1-2, 4-7, 11-14, 27-35, 38-41 (general provisions, lawful basis, controller and processor obligations, DPIA, the Data Protection Officer, and other general processing rules) Source as of 2026-09-19 privacy:ad-llei-qualificada-de-proteccio-de-dades-person:2

Albania

Implement data protection by design and by default in every processing tool and process, and appoint a data protection officer where processing is carried out by a public authority, requires regular and systematic large scale monitoring of data subjects, or involves large scale processing of sensitive data or criminal records.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Law No. 124/2024 On the Protection of Personal Data, Law No. 124/2024 (Ligj Nr. 124/2024) On the Protection of Personal Data, Arts. 1-8, 11, 22-38, 43-46 (general provisions, lawful basis, consent, controller and processor obligations, and specific-purpose exceptions), in force 31 January 2025 Source as of 2026-09-19 privacy:al-no-124-2024-ligj-nr-124-2024-protection-perso:2

Benin

Implement data protection by design and by default, including pseudonymization and data minimization, so that only the personal data necessary to each specific purpose is processed by default.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V (protection des données à caractère personnel), Loi n°2017-20 du 20 avril 2018, Livre V, Protection des Données à Caractère Personnelle, portant Code du Numérique en République du Bénin, arts. 379-390, 393, 405-414, 424-426 et 428-436 (principes généraux, licité et obligations des responsables de traitement) Source as of 2026-09-19 privacy:bj-loi-n-2017-20-du-20-avril-2018-livre-v-protec:6

Bhutan

An app that negligently fails to implement reasonable security practices for personal data of a person in Bhutan, including a biometric identifier, and thereby causes wrongful loss or gain, is liable to pay court-determined compensation to the victim, and unlawfully disclosing another's personal data without consent is a separate offence under section 388.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
Information, Communications and Media Act of Bhutan 2018, offences and compensation for data failures, Information, Communications and Media Act of Bhutan 2018, ss.387-388 Source as of 2026-09-02 privacy:bt-information-communications-media-bhutan-201-4:0

Botswana

Implement appropriate technical and organisational measures, including data protection by design and by default, to secure personal data at a level appropriate to the risk and to be able to demonstrate compliance with the Act.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Data Protection Act, 2024 (Act No. 18 of 2024), Data Protection Act, 2024 (Act No. 18 of 2024), ss. 1-5, 19-28, 51-62, 65-73 Source as of 2026-09-19 privacy:bw-data-protection-2024-no-18-2024:3

Democratic Republic of the Congo

Build data protection into the processing by design and by default, including pseudonymization, and process by default only the personal data necessary for each specific purpose.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Digital Code, Title III: Personal Data Protection, Code du numérique, Titre III, Des données personnelles, Ordonnance-loi n° 23/010 du 13 mars 2023 (arts. 183 à 194, 204, 205, 219, 221 à 233, 243, 245, 246 et 254) Source as of 2026-09-19 privacy:cd-du-num-rique-titre-iii-des-donn-es-personnell:5

Colombia

Apply privacy by design and by default, including techniques such as differential privacy, so that data used to train an artificial intelligence system does not allow the person who provided it to be identified.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the data subject; establishment of the operator Runtime not yet classified
Superintendencia Circular on AI and Personal Data, SIC Circular Externa 002 de 2024, instrucciones I, II, VIII-IX (Lineamientos sobre Tratamiento de Datos en Sistemas de IA), 21 de agosto de 2024 Source as of 2026-09-19 privacy:co-sic-circular-externa-002-de-2024-lineamientos:5

Greece

This binds an essential entity or an important entity drawn from Annex I (high-criticality sectors) or Annex II (other critical sectors), which the law's own table of contents captions as corresponding directly to NIS2 Directive Annexes I and II; Annex II's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform (each a defined term in Article 6), reached at the medium-enterprise threshold of Commission Recommendation 2003/361/EC or above (Article 3(1)); the wider sector classes Annexes I and II reach by designation (energy, transport, banking, health, drinking water, public administration and the rest) are not expressed in this vocabulary and are not raised here on that account.
Type Definition Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on not a duty Hook Establishment of the operator (entity in scope) Runtime not a duty
Law 5160/2024, Cybersecurity Risk-Management Measures and Governance, Law 5160/2024 (Ν. 5160/2024), Arts. 14-15 Source as of 2026-09-15 security:gr-law-5160-2024-arts-14-15:0

Kyrgyzstan

An app that processes biometric data for the digital identification of a Kyrgyzstani data subject, including a voiceprint or faceprint, must satisfy one of Art. 80(2)'s narrow lawful grounds before processing; such processing is prohibited by default otherwise. The Code itself supplies no illustrative list of biometric modalities for this general provision.
Type Prohibition Modal must Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Digital Code, special categories of personal data, Digital Code, Law No. 178, Art. 80 Source as of 2026-08-29 privacy:kg-digital-no-178-80:0

Monaco

Build data protection by design and by default into a processing operation, so that by default only the personal data necessary for each specific purpose is processed, collected, retained, or made accessible.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Loi sur la Protection des Données Personnelles, Loi n. 1.565 du 3 decembre 2024 relative a la protection des donnees a caractere personnel, Journal de Monaco n. 8725, arts. 1, 3-6, 9, 21-36, 58-63, 78-87 (scope, lawful basis, and controller and processor obligations) Source as of 2026-09-19 privacy:mc-loi-n-1-565-du-3-decembre-2024-relative-la-pr:2

18 more lines in force under this theme, and 39 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T04 · Agent Identity & Delegation

The group's key concepts: AuthN/Z model; acting-on-behalf-of; agent registry; credential lifecycle; delegation scope; non-repudiation

231 lines 204 in force 204 provisions 132 jurisdictions by type: mandatory obligation 81, conditional obligation 68, prohibition 41, definition 20, consequence (penalty or remedy) 13, permission or exemption 7, recommendation/guidance 1

Classes its lines carry: disclose the use of AI (71), secure the system and the data in it (65), govern the system: policies, roles, assessments (62), honour the person's rights over their data (47); 54 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 204 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Maintain basic cyber hygiene practices and cybersecurity training, policies on cryptography and encryption where appropriate, human resources security and access control, and multi-factor authentication or continuous authentication solutions where appropriate.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
NIS2 Directive, Cybersecurity Risk-Management Measures, Directive (EU) 2022/2555, Art. 21 Source as of 2026-09-08 security:eu-2022-2555-21:2

California

The prohibition reaches using a bot to mislead a Californian about its artificial identity in order to incentivize a commercial transaction or influence a vote
Type Prohibition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Bolstering Online Transparency Act (SB 1001), Cal. Bus. and Prof. Code Sections 17940 to 17943 Source as of 2026-08-14 ai:us-ca-cal-bus-prof-sections-17940-17943:1

Texas

Do not develop or distribute an AI system with the sole intent of producing or distributing AI-generated child pornography or deepfake sexually explicit media, or that engages in text-based sexual conversation while impersonating a child younger than 18.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
TRAIGA (H.B. 149, 2025), prohibited AI practices binding any person, Tex. Bus. & Com. Code §§ 552.052, 552.055-552.057 Source as of 2026-09-06 ai:us-tx-tex-bus-com-552-052-552-055-552-057:3

South Korea

Do not build, install, or distribute a tool whose purpose is to bypass a network's normal access-control or authentication procedures.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Location of the counterparty's machine Runtime Outside any runtime path
Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention), Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 21305, as amended), Art. 48 Source as of 2026-08-29 scraping:kr-promotion-information-communications-network:1

Brazil

This duty does not reach ordinary image- or sound-quality adjustments, graphic identity elements, or customary campaign marketing techniques such as composite photos.
Type Permission or exemption Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Where the output is used; placing on the market Runtime not a duty
TSE Resolution, AI-Generated Content Disclosure Duty, Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) Source as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-b-reda-o-dada-pe:2

India

The Data Protection Board of India exists, is administratively operational, and its jurisdiction ousts the civil courts over matters within its remit, but its penalty Schedule, complaint, and appeal machinery has not yet commenced and is scheduled for 13 May 2027, and no provision of the Act as read gives the Board power to award compensation to an individual complainant. Once fully in force, an app processing Indian personal data, including biometric identifiers, will answer only to the Board; India's DPDPA arms no private plaintiff, and a data principal who misuses their own rights under the Act, for example by impersonation or a frivolous complaint, risks a penalty of their own under section 15.
Type Consequence (penalty or remedy) Modal may Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
Digital Personal Data Protection Act, 2023, Data Protection Board and penalties, Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39 Source as of 2026-08-29 privacy:in-digital-personal-data-protection-2023-dpdpa-d:0

Germany

Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82, and expect a qualifying consumer-protection association to be able to bring a representative claim on behalf of a group of affected consumers under the VDuG.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Controller (the party that decides why and how personal data is processed) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
GDPR Article 82, BDSG Sections 41-43, and BfDI and Landesdatenschutzbehörden Enforcement in Germany, Regulation (EU) 2016/679, Arts. 82-83; Bundesdatenschutzgesetz (BDSG) §§41-43 Source as of 2026-09-02 privacy:de-eu-2016-679-82-83-bundesdatenschutzgesetz-bds:1

Ireland

Do not distribute, publish or threaten to distribute or publish an intimate image of another person without that person's consent, with intent to cause harm or being reckless as to whether harm is caused, including an image that only purports to be that person's intimate depiction, such as an AI-generated or digitally altered synthetic image (s. 2).
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Harassment, Harmful Communications and Related Offences Act 2020, Intimate Image Offences, Harassment, Harmful Communications and Related Offences Act 2020 (No. 32 of 2020), ss. 1-3 Source as of 2026-09-06 ai:ie-harassment-harmful-communications-2020-ss-2-3:0

Italy

A contract clause purporting to override these database-right rules is void.
Type Definition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook The counterparty's establishment (rightsholder) Runtime not a duty
Legge sul Diritto d'Autore Artt. 102-bis and 102-ter, Sui Generis Database Right, Legge 22 aprile 1941, n. 633, artt. 102-bis, 102-ter, inserted by Decreto Legislativo 6 maggio 1999, n. 169 Source as of 2026-09-06 scraping:it-lda-102bis-102ter-database-right:2

Spain

Do not circumvent a technical security measure, such as authentication, to access an information system without authorization; Article 197 bis does not reach access to a page that carries no such measure.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Código Penal Article 197 bis, Unauthorized Access to an Information System, Ley Organica 10/1995, de 23 de noviembre, del Codigo Penal, art. 197 bis, added by Ley Organica 1/2015, de 30 de marzo, art. unico.107 (BOE-A-1995-25444, BOE-A-2015-3439) Source as of 2026-09-02 scraping:es-codigo-penal-lo-10-1995-197-bis:0

Netherlands

Rely only on an authentication-or-security purpose, or another GDPR Article 9(2) basis, before processing biometric data of a person in the Netherlands for unique identification; UAVG Article 29's exception reaches no broader purpose on its face.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
UAVG Article 29, Biometric-Data Exception for Authentication or Security, UAVG, Art. 29 Source as of 2026-08-24 privacy:nl-uavg-29:0

Singapore

A contract term purporting to exclude or restrict this computational data analysis exception is void and does not bind the app.
Type Permission or exemption Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook The counterparty's establishment (rightsholder); where the copy is made Runtime not a duty
Copyright Act, Computational Data Analysis Exception and Non-Override Rule, Copyright Act 2021, ss. 243-244 and s. 187 (Computational Data Analysis Exception) Source as of 2026-09-07 scraping:sg-copyright-2021-ss-243-244-s-187-computational:1

New York

Do not assume New York law clears a faceprint or voiceprint you extract from a recording to authenticate or ascertain identity. SHIELD's biometric-information trigger carries no recording-derived exclusion, so an extracted identifier plausibly falls within it if a later breach exposes it, though this reading is untested in New York case law or Attorney General guidance.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Residence of the affected person Runtime not a duty
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty, N.Y. Gen. Bus. Law § 899-aa Source as of 2026-08-27 privacy:us-ny-n-y-gen-bus-899-aa:2

191 more lines in force under this theme, and 231 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T05 · Guardrails & Policy Constraints

The group's key concepts: Business rules; policy-as-code; content filters; hard stops; behavioral boundaries; PEP; constraint override

357 lines 324 in force 300 provisions 172 jurisdictions by type: prohibition 130, mandatory obligation 118, conditional obligation 88, definition 8, permission or exemption 6, consequence (penalty or remedy) 6, recommendation/guidance 1

Classes its lines carry: do not get in without authorisation (75), disclose the use of AI (73), do not do the named thing (72), get consent first (70); 67 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 324 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

California

Do not continue accessing a California site, or circumvent a technical block, after the operator has sent a cease-and-desist notice (Facebook v. Power Ventures, 9th Cir. 2016; Craigslist v. 3Taps, N.D. Cal. 2013).
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control

Texas

Do not create a deep fake video and cause it to be published or distributed within 30 days of an election, if you intend to injure a candidate or influence the election's result.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Political deep fake video ban (originally S.B. 751, 2019), Tex. Elec. Code § 255.004(d)-(e) Source as of 2026-09-06 ai:us-tx-tex-elec-255-004-d-e:0

South Korea

An app processing Korean personal data must be able to answer to the PIPC for its lawful basis and safeguards, and an individual harmed by a security failure may bring a private civil claim for statutory damages, or damages up to five times the actual loss, without needing to prove the controller's negligence.
Type Consequence (penalty or remedy) Modal must, may Binds, by its wording Controller (the party that decides why and how personal data is processed) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
Personal Information Protection Act, enforcement and private civil remedy, Act No. 10465 (as amended by Act No. 19234, 2023), Arts. 39, 39-2, 51, 64-2 Source as of 2026-09-02 privacy:kr-no-10465-as-amended-by-no-19234-2023-39-39-2:0

United Kingdom

Before moving personal data of a person in the United Kingdom outside the UK, either rely on a UK adequacy regulation, put appropriate safeguards in place such as the ICO's International Data Transfer Agreement or Addendum, or rely on a narrow Article 49 derogation, under UK GDPR Article 44A.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
UK GDPR Articles 44A-50, Cross-Border Transfer of Personal Data from the United Kingdom, UK GDPR, Arts. 44A-50, as amended by the Data (Use and Access) Act 2025 Source as of 2026-08-24 privacy:gb-uk-gdpr-44a-50-as-amended-by-data-use-access:0

Brazil

Do not generate or digitally manipulate synthetic audio, video, or combined audio-video content to create, replace, or alter a living, deceased, or fictitious person's image or voice, even with that person's authorization, to harm or benefit a candidacy.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
TSE Resolution, Prohibition on Electoral Deepfakes, Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) Source as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-c-reda-o-dada-pe:1

India

The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.
Type Definition Modal may, must Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Residence of the data subject; establishment of the operator Runtime not a duty
Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025 Source as of 2026-08-29 privacy:in-g-s-r-846-e-digital-personal-data-protection:0

Germany

Do not produce, obtain, sell, or distribute passwords, security codes, or software designed to commit these offences.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Outside any runtime path
Ausspaehen, Abfangen und Manipulation von Daten (Computer Misuse and Data Interference), Strafgesetzbuch (StGB), §§ 202a, 202b, 202c, 202d, 303a, 303b Source as of 2026-09-06 scraping:de-strafgesetzbuch-stgb-202a-202b-202c-202d-303a:2

Ireland

Where you process special category data, including biometric data, about an employee in Ireland, ground it in a legitimate argument tied to vital interests or another Article 9(2) condition with a public-interest character, and put suitable and specific safeguarding measures in place, under Data Protection Act 2018 Section 46.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
GDPR Article 9 and Data Protection Act 2018 Section 46, Special Categories and Employment Biometric Data in Ireland, Regulation (EU) 2016/679, Art. 9; Data Protection Act 2018 §46 Source as of 2026-08-24 privacy:ie-eu-2016-679-9-data-protection-2018-46:0

France

Do not create or share, by any means, a non-consensual sexual montage, or a non-consensual, algorithmically generated sexual image, video, or audio reproducing a real person's likeness or voice; France punishes this with two years' imprisonment and a 60,000 euro fine.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Code Pénal Article 226-8-1, Non-Consensual Sexual Montage and Algorithmically Generated Sexual Content, Code penal, art. 226-8-1, insere par la loi n. 2024-449 du 21 mai 2024 visant a securiser et a reguler l'espace numerique (SREN), art. 21 Source as of 2026-09-06 ai:fr-penal-226-8-1-insere-par-la-loi-n-2024-449-du:0

Netherlands

Do not produce, distribute, offer, publicly display, import, export, acquire, or possess a sexual image of a person who apparently has not yet reached the age of eighteen, whether or not that person is real; a computer-generated or synthetic depiction is reached on the same terms as a real one.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Wetboek van Strafrecht, art. 252, Sexual Imagery of an Apparent Minor (Virtual Child Sexual Abuse Material), Wetboek van Strafrecht, art. 252 (until 1 July 2024: art. 240b) (BWBR0001854) Source as of 2026-09-06 ai:nl-wetboek-van-strafrecht-252-voorheen-240b:0

Canada

Report any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
PIPEDA breach of security safeguards regime, S.C. 2000, c. 5, ss. 10.1-10.3 Source as of 2026-09-02 privacy:ca-s-c-2000-c-5-ss-10-1-10-3:0

New York

Do not continue accessing a New York-connected system, or circumvent a technical security measure, after the operator has given you actual notice, including a cease-and-desist letter, that your access is unwanted; this statute treats notice alone as sufficient to convert continued access into unauthorized access, without needing a technical block.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
New York Computer Trespass, notice-based revocation and circumvention presumption, N.Y. Penal Law §§ 156.00, 156.05, 156.10 Source as of 2026-08-29 scraping:us-ny-n-y-penal-156-00-156-05-156-10:0

Peru

Correct, update, include, or delete a person's personal data on request when it is inaccurate, incomplete, or has outlived the purpose or period for which it was collected, tell anyone you previously transferred it to about the change, and block the data from third-party access while the request is pending.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the data subject Runtime not yet classified
Ley 29733, rights of the data subject, Ley No. 29733, arts. 18-27 (rights of the data subject) Source as of 2026-09-19 privacy:pe-ley-no-29733-18-27-rights-data-subject:3

311 more lines in force under this theme, and 357 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T06 · Data Protection & Privacy

The group's key concepts: PII; data minimization; retention; residency; consent; cross-border transfer; special category data; privacy-by-design

3,290 lines 2,791 in force 1,360 provisions 249 jurisdictions by type: mandatory obligation 1,551, conditional obligation 815, prohibition 518, definition 232, consequence (penalty or remedy) 113, permission or exemption 55, recommendation/guidance 6

Classes its lines carry: get consent first (1,091), disclose the use of AI (834), secure the system and the data in it (818), govern the system: policies, roles, assessments (771); 835 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 2,791 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 Source as of 2026-08-23 privacy:eu-2016-679:0

California

If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 Source as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0

Colorado

If you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
C.R.S. 6-1-716, Notification of Security Breach, C.R.S. section 6-1-716 Source as of 2026-08-23 privacy:us-co-c-r-s-6-1-716:0

Texas

A person depicted in artificial intimate visual material, produced or disclosed without their consent and with intent to harm them, can sue the creator, solicitor, discloser, or promoter for damages if the material reveals their identity.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market; where the output is used Runtime not a duty
S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009 Source as of 2026-09-06 ai:us-tx-tex-civ-prac-rem-98b-0021-98b-009:0

South Korea

Before you provide an AI system, or a product or service that uses one, review whether it is high-impact, meaning it may seriously affect a person's life, physical safety or fundamental rights and is used in energy supply, drinking water production, healthcare provision, medical and digital medical devices, nuclear material and facility safety, biometric identification for criminal investigation or arrest, hiring and loan decisions, transportation systems, public-service eligibility and fee decisions, and student assessment in early childhood, elementary and secondary education. You may ask the Ministry of Science and ICT to confirm your answer.
Type Mandatory Obligation Modal may Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Framework Act, Article 34 (business-operator duties for high-impact AI), Act No. 20676, Article 34 Source as of 2026-09-20 ai:kr-no-20676-34:0

United Kingdom

Do not intentionally create an image that appears to be an intimate photograph or film of another adult without that adult's consent.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Creating, or Requesting the Creation of, Purported Intimate Image of Adult, Data (Use and Access) Act 2025, c. 18, s. 138, inserting ss. 66E-66H into the Sexual Offences Act 2003 Source as of 2026-09-06 ai:gb-data-use-access-2025-c-18-ss-138-66e-66h-sexu:0

Brazil

Establish a lawful basis under article 7 before processing personal data, including data the person has made public.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:0

India

The Data Protection Board of India exists, is administratively operational, and its jurisdiction ousts the civil courts over matters within its remit, but its penalty Schedule, complaint, and appeal machinery has not yet commenced and is scheduled for 13 May 2027, and no provision of the Act as read gives the Board power to award compensation to an individual complainant. Once fully in force, an app processing Indian personal data, including biometric identifiers, will answer only to the Board; India's DPDPA arms no private plaintiff, and a data principal who misuses their own rights under the Act, for example by impersonation or a frivolous complaint, risks a penalty of their own under section 15.
Type Consequence (penalty or remedy) Modal may Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
Digital Personal Data Protection Act, 2023, Data Protection Board and penalties, Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39 Source as of 2026-08-29 privacy:in-digital-personal-data-protection-2023-dpdpa-d:0

Vietnam

Do not collect, process, or use data to develop, train, test, or operate an AI system in violation of Vietnam's data, personal data protection, intellectual property, or cybersecurity law.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Law on Artificial Intelligence, prohibited practices, Law No. 134/2025/QH15, art. 7 Source as of 2026-09-06 ai:vn-no-134-2025-qh15-7:2

Germany

Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Germany.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act, Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017), as amended Source as of 2026-08-24 privacy:de-bundesdatenschutzgesetz-bdsg-bgbl-i-s-2097-20:0

Ireland

Do not distribute, publish or threaten to distribute or publish an intimate image of another person without that person's consent, with intent to cause harm or being reckless as to whether harm is caused, including an image that only purports to be that person's intimate depiction, such as an AI-generated or digitally altered synthetic image (s. 2).
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Harassment, Harmful Communications and Related Offences Act 2020, Intimate Image Offences, Harassment, Harmful Communications and Related Offences Act 2020 (No. 32 of 2020), ss. 1-3 Source as of 2026-09-06 ai:ie-harassment-harmful-communications-2020-ss-2-3:0

Italy

Do not transfer, publish, or otherwise disseminate a falsified or altered image, video, or voice recording generated using an AI system, capable of misleading others as to its genuineness, without the depicted or recorded person's consent.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Codice Penale Art. 612-quater, Illicit Dissemination of AI-Generated or AI-Altered Content, Codice Penale, art. 612-quater, inserted by Legge 23 settembre 2025, n. 132, art. 26, comma 1, lettera c) Source as of 2026-09-06 ai:it-cp-612quater-ai-deepfake-dissemination:0

Spain

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Spain outside the EEA, and check whether LOPDGDD Articles 41-43 require AEPD authorization or prior notice for the specific transfer.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
LOPDGDD Título VI, International Transfers, Layered on GDPR Chapter V, Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l) Source as of 2026-08-24 privacy:es-eu-2016-679-44-49-83-5-lopdgdd-40-43-72-1-l:0

2,778 more lines in force under this theme, and 3,290 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T07 · Security & Access Controls

The group's key concepts: Least privilege; secrets management; network segmentation; tool permissions; authentication; vulnerability management; capability confinement

2,811 lines 2,524 in force 858 provisions 244 jurisdictions by type: mandatory obligation 1,080, conditional obligation 608, prohibition 583, definition 292, consequence (penalty or remedy) 125, permission or exemption 116, recommendation/guidance 7

Classes its lines carry: secure the system and the data in it (1,693), govern the system: policies, roles, assessments (868), do not get in without authorisation (712), get consent first (691); 252 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 2,524 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 Source as of 2026-08-23 privacy:eu-2016-679:0

California

If your app is a for-profit business meeting the CCPA's revenue or data-volume threshold and it determines the purposes and means of processing a California consumer's personal information, honor the CCPA/CPRA's notice, opt-out, and non-discrimination duties before collecting, selling, or sharing that data.
Type Definition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24), Cal. Civ. Code section 1798.100 et seq. (CCPA, as amended by the CPRA) Source as of 2026-08-23 privacy:us-ca-cal-civ-1798-100-et-seq-ccpa-as-amended-by:0

Colorado

Do not access a Colorado-connected computer without authorization, or beyond the scope of granted authorization, to collect data; this statute's language closely tracks the federal CFAA rather than a broader state standard.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Colorado Cybercrime statute (unauthorized access, tracking the federal CFAA), C.R.S. § 18-5.5-102 Source as of 2026-08-29 scraping:us-co-c-r-s-18-5-5-102:0

Texas

This chapter applies only to a business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information, as those terms are defined by Section 521.002.
Type Definition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market Runtime not a duty
Cybersecurity Program safe harbor from exemplary damages (S.B. 2610), Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004) Source as of 2026-09-12 security:us-tx-tex-bus-com-ch-542-secs-542-001-542-004:0

South Korea

Prepare and keep documents that confirm the content of the measures you took to secure your AI's safety and reliability.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Framework Act, Article 34 (business-operator duties for high-impact AI), Act No. 20676, Article 34 Source as of 2026-09-20 ai:kr-no-20676-34:5

United Kingdom

Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 Source as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0

Brazil

Do not generate or digitally manipulate synthetic audio, video, or combined audio-video content to create, replace, or alter a living, deceased, or fictitious person's image or voice, even with that person's authorization, to harm or benefit a candidacy.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
TSE Resolution, Prohibition on Electoral Deepfakes, Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) Source as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-c-reda-o-dada-pe:1

India

Get the rights holder's authorisation before reproducing or reusing copyrighted material, including a copyrighted database or compilation, to train an AI model; the fair-dealing exceptions do not name text-and-data-mining or AI training as a covered purpose.
Type Mandatory Obligation Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook The counterparty's establishment (rightsholder); where the copy is made Runtime Enforceable at a runtime control
Copyright Act, No Text-and-Data-Mining Exception, Database Compilations, and Technological Protection Measures, Copyright Act, 1957 (No. 14 of 1957), ss. 2(o), 51, 52, 63, 65A Source as of 2026-09-07 scraping:in-copyright-1957-no-14-1957-ss-2-o-51-52-63-65a:0

Vietnam

Continuously keep your AI system safe, secure, and reliable, and promptly detect and remedy any incident capable of harming people, property, data, or social order, regardless of the system's risk tier.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12 Source as of 2026-09-20 ai:vn-no-134-2025-qh15-12:3

Germany

Where you deploy a biometric time clock, access control system, or voice-authentication system for employees in Germany, satisfy BDSG Section 26(3)'s conditions rather than relying on employee consent as the sole basis.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
GDPR Article 9 and BDSG Section 26(3), Special Categories and Employment Biometric Data in Germany, Regulation (EU) 2016/679, Art. 9; Bundesdatenschutzgesetz (BDSG) §26(3) Source as of 2026-08-24 privacy:de-eu-2016-679-9-bundesdatenschutzgesetz-bdsg-26:0

Ireland

Do not knowingly give false or misleading information to an adjudicator, or disclose confidential material relevant to an adjudicator's finding without authorisation (ss. 95, 104).
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Regulation of Artificial Intelligence Act 2026, Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026) Source as of 2026-09-06 ai:ie-regulation-of-artificial-intelligence-2026:2

Italy

Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions, Garante Provvedimento n. 146 del 5 giugno 2019 Source as of 2026-08-24 privacy:it-garante-provvedimento-n-146-del-5-giugno-2019:0

Spain

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Spain outside the EEA, and check whether LOPDGDD Articles 41-43 require AEPD authorization or prior notice for the specific transfer.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
LOPDGDD Título VI, International Transfers, Layered on GDPR Chapter V, Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l) Source as of 2026-08-24 privacy:es-eu-2016-679-44-49-83-5-lopdgdd-40-43-72-1-l:0

2,511 more lines in force under this theme, and 2,811 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T08 · Model/Agent Risk Management

The group's key concepts: Validation; robustness; drift monitoring; change control; benchmarking; bias/fairness; decommissioning; version control

583 lines 472 in force 294 provisions 154 jurisdictions by type: mandatory obligation 318, conditional obligation 166, prohibition 47, definition 35, permission or exemption 8, consequence (penalty or remedy) 6, recommendation/guidance 3

Classes its lines carry: govern the system: policies, roles, assessments (379), secure the system and the data in it (350), get consent first (303), assess the impact on personal data first (290); 72 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 472 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

This is one listed risk-mitigation measure for a Commission-designated very large online platform or search engine, not a freestanding labeling mandate on every provider
Type Definition Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on not a duty Hook Where the output is used; placing on the market Runtime not a duty
Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking), Regulation (EU) 2022/2065, Article 35(1)(k) Source as of 2026-08-14 ai:eu-2022-2065-35-1-k:0

California

If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 Source as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0

Texas

Do not develop or deploy an AI system with intent to unlawfully discriminate against a protected class; a disparate impact alone is not enough to show that intent.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
TRAIGA (H.B. 149, 2025), prohibited AI practices binding any person, Tex. Bus. & Com. Code §§ 552.052, 552.055-552.057 Source as of 2026-09-06 ai:us-tx-tex-bus-com-552-052-552-055-552-057:2

South Korea

Document a balancing assessment showing your interest clearly overrides the affected individuals' rights, and adopt the named technical and procedural safeguards, including a disclosure, impact assessment, and an erasure or objection mechanism.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Location of the counterparty (site, machine, rightsholder) Runtime Outside any runtime path
Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline, Personal Information Protection Act (Act No. 18972, as amended), Art. 15(1)(vi); PIPC Guideline for Personal Data Processing for the Development and Utilization of Generative AI (issued 2024-07-18) Source as of 2026-08-29 scraping:kr-personal-information-protection-no-18972-as-a:2

United Kingdom

Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 Source as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0

Brazil

Establish a lawful basis under article 7 before processing personal data, including data the person has made public.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:0

Vietnam

Classify your AI system's risk level (high, medium, or low) before putting it into service, based on its potential impact on rights, safety, security, and public interest, and the scale and context of its use.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Law on Artificial Intelligence, risk classification and conformity assessment, Law No. 134/2025/QH15, arts. 9-10, 13-14 Source as of 2026-09-06 ai:vn-no-134-2025-qh15-9-10-13-14:0

Germany

Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 Source as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:1

Ireland

Establish a lawful basis before collecting or otherwise using personal data, including publicly accessible personal data, to train an AI model on people in Ireland, and account for the purpose the person originally made that data public for, not only whether it was public.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
DPC Guidance: AI, Large Language Models and Data Protection, Data Protection Commission, "AI, Large Language Models and Data Protection" guidance (18 July 2024) Source as of 2026-08-24 privacy:ie-data-protection-commission-ai-large-language:0

Italy

Expect AgID to handle AI innovation promotion and the notification, assessment, accreditation and monitoring of conformity-assessment bodies for AI systems placed on the Italian market.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market; where the output is used Runtime not a duty
Legge 132/2025 Art. 20, National AI Authorities (AgID and ACN), Legge 23 settembre 2025, n. 132, art. 20 Source as of 2026-09-06 ai:it-l-132-2025-agid-acn-national-authorities:0

Spain

Do not extract or reuse the whole, or a substantial part evaluated qualitatively or quantitatively, of a database that reflects a substantial investment by its maker, absent authorization or a statutory exception, per TRLPI Article 133.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook The counterparty's establishment (rightsholder) Runtime Enforceable at a runtime control
TRLPI Articles 133 to 137, Sui Generis Database Right, Real Decreto Legislativo 1/1996 (TRLPI), arts. 133-137, added by Ley 5/1998, de 6 de marzo (BOE-A-1996-8930, BOE-A-1998-5568) Source as of 2026-09-02 scraping:es-trlpi-133-137:0

France

Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001), CNIL Deliberation n. 2019-001 du 10 janvier 2019 portant reglement type relatif a la mise en oeuvre de dispositifs de controle d'acces biometrique Source as of 2026-08-24 privacy:fr-cnil-deliberation-n-2019-001-du-10-janvier-20:0

New York

Promptly provide the Superintendent any information requested about a reported incident, and continue updating the Superintendent with material changes or new information previously unavailable; the regulation states no separate numbered clock for either duty.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Placing on the market; establishment of the manufacturer Runtime not yet classified
New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent, 23 NYCRR 500.17 Source as of 2026-09-20 security:us-ny-23-nycrr-500-17:2

459 more lines in force under this theme, and 583 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T09 · Human Oversight

The group's key concepts: HITL/HOTL; escalation paths; human waterfall; override/kill switch; mandatory approval; supervision frequency; automated oversight

150 lines 125 in force 136 provisions 98 jurisdictions by type: mandatory obligation 77, conditional obligation 40, prohibition 19, definition 9, consequence (penalty or remedy) 3, permission or exemption 1, recommendation/guidance 1

Classes its lines carry: govern the system: policies, roles, assessments (45), disclose the use of AI (37), honour the person's rights over their data (33), report to a regulator (28); 46 from an instrument with no class recorded.

Sample requirement lines Show 14 of the 125 lines in forceHide the sample

What follows is a sample of 14 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in the EU.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
GDPR Articles 12-22, Data Subject Rights, Regulation (EU) 2016/679, Arts. 12-22 Source as of 2026-08-23 privacy:eu-2016-679-12-22:1

California

Let a consumer opt out of your use of ADMT to make a significant decision about them, unless you offer an appeal to a human reviewer with authority to overturn the decision or another exception listed in the regulation applies
Type Conditional Obligation Modal unless Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Enforceable at a runtime control
CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 Source as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:1

South Korea

Document a balancing assessment showing your interest clearly overrides the affected individuals' rights, and adopt the named technical and procedural safeguards, including a disclosure, impact assessment, and an erasure or objection mechanism.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Location of the counterparty (site, machine, rightsholder) Runtime Outside any runtime path
Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline, Personal Information Protection Act (Act No. 18972, as amended), Art. 15(1)(vi); PIPC Guideline for Personal Data Processing for the Development and Utilization of Generative AI (issued 2024-07-18) Source as of 2026-08-29 scraping:kr-personal-information-protection-no-18972-as-a:2

United Kingdom

Before finalizing a solely automated decision producing legal or similarly significant effects for a person in the United Kingdom, inform them in advance, and provide a meaningful human review and a right to contest the decision on request, under UK GDPR Articles 22A to 22D.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
Data (Use and Access) Act 2025 Section 80, Automated Decision-Making, UK GDPR Articles 22A-22D, Data (Use and Access) Act 2025, c. 18, §80 (new UK GDPR Arts. 22A-22D); S.I. 2026/425 Source as of 2026-08-24 privacy:gb-data-use-access-2025-c-18-80-new-uk-gdpr-22a:0

Brazil

Give a data subject a way to request review, by a natural person, of any decision made solely on automated processing of their personal data, including a decision that defines their personal, professional, consumer, or credit profile, and explain on request the criteria and procedures used for it.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the data subject Runtime not yet classified
LGPD, rights of the data subject, Lei nº 13.709, de 2018 (LGPD), arts. 17-22 (rights of the data subject) Source as of 2026-09-19 privacy:br-lei-n-13-709-de-2018-lgpd-17-22-rights-data-s:1

Germany

Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Germany, including a credit score generated for a third party's determinative use, under GDPR Article 22 and BDSG Section 31.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany, Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37 Source as of 2026-08-24 privacy:de-eu-2016-679-22-bundesdatenschutzgesetz-bdsg-3:1

Ireland

Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Ireland, under GDPR Article 22.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
GDPR Article 22, Automated Decision-Making in Ireland, Regulation (EU) 2016/679, Art. 22, as transposed by the Data Protection Act 2018 Source as of 2026-08-24 privacy:ie-eu-2016-679-22-as-transposed-by-data-protecti:1

Italy

Give a person in Italy a path to obtain human intervention, express their view, and contest a decision made solely by automated processing that produces a legal or similarly significant effect on them.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Outside any runtime path
GDPR Article 22 and the Garante's OpenAI/ChatGPT Enforcement, Regulation (EU) 2016/679, Art. 22; Garante Provvedimento 30 marzo 2023 Source as of 2026-08-24 privacy:it-eu-2016-679-22-garante-provvedimento-30-marzo:0

France

Give a person in France a path to obtain human intervention, express their view, and contest a decision made solely by automated processing, including profiling, that produces a legal or similarly significant effect on them.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Outside any runtime path
GDPR Article 22, Right Against Automated Individual Decision-Making, Regulation (EU) 2016/679, Art. 22 Source as of 2026-08-24 privacy:fr-eu-2016-679-22:0

Netherlands

Give a person in the Netherlands a path to obtain human intervention, express their view, and contest a decision made solely by automated processing that produces a legal or similarly significant effect on them, subject to UAVG Article 40's exceptions.
Type Conditional Obligation Modal subject to Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Outside any runtime path
GDPR and UAVG Articles 40-43, Data-Subject Rights and Journalistic Exception, Regulation (EU) 2016/679, Arts. 12-23; UAVG, Arts. 40, 41, 43 Source as of 2026-08-24 privacy:nl-eu-2016-679-12-23-uavg-40-41-43:0

Illinois

This binds any person, including a natural person, a corporation, another legal entity, a unit of local government, or the State of Illinois or one of its agencies, that disposes of materials containing personal information about an Illinois resident, except a financial institution regulated under Gramm-Leach-Bliley Act Title V or a person subject to the disposal rule at 15 U.S.C. 1681w.
Type Definition Modal subject to Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market Runtime not a duty
Personal Information Protection Act, safe disposal of personal information, 815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01) Source as of 2026-09-14 security:us-il-815-ilcs-530-40-disposal-materials-contain:0

Peru

Do not deploy an autonomous lethal capability that decides without human supervision and can cause physical harm or affect life or physical integrity in a civilian setting.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Reglamento de la Ley 31814, prohibited AI uses, Decreto Supremo 115-2025-PCM, arts. 22-23 (Reglamento de la Ley 31814, Clasificación de Riesgos: Uso Indebido) Source as of 2026-09-05 ai:pe-decreto-supremo-115-2025-pcm-22-23-reglamento:1

Andorra

Restrict processing on request while accuracy is contested, in place of erasure where the data subject prefers restriction, where you no longer need the data but the data subject does for legal claims, or while an objection is being verified.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the data subject Runtime not yet classified
LQPD, rights of the data subject, Llei 29/2021, arts. 15-26 (rights of the data subject) Source as of 2026-09-19 privacy:ad-llei-29-2021-15-26-rights-data-subject:5

United Arab Emirates

An app that is a controller or processor established in or targeting the DIFC free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier used to uniquely identify a natural person, including one derived from a photo, video, or audio recording.
Type Mandatory Obligation Modal must Binds, by its wording Controller (the party that decides why and how personal data is processed) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Enforceable at a runtime control
DIFC Data Protection Law, comprehensive regime, DIFC Law No. 5 of 2020 Source as of 2026-08-29 privacy:ae-difc-no-5-2020:0

111 more lines in force under this theme, and 150 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T10 · Action Management

The group's key concepts: Pre-execution checks; dual control; reversibility tiers; undo infrastructure; action scope limits; side-effect disclosure

137 lines 121 in force 126 provisions 91 jurisdictions by type: mandatory obligation 48, prohibition 40, conditional obligation 25, permission or exemption 9, definition 8, consequence (penalty or remedy) 7

Classes its lines carry: get consent first (37), govern the system: policies, roles, assessments (33), do not get in without authorisation (32), secure the system and the data in it (31); 37 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 121 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Report immediately, and not later than 2 days after becoming aware of it, a widespread infringement or a serious incident causing a serious and irreversible disruption to the management or operation of critical infrastructure.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Evidenced by the runtime's record
AI Act, Article 73 (reporting of serious incidents), Regulation (EU) 2024/1689, Article 73 Source as of 2026-09-18 ai:eu-2024-1689-73:2

California

Post training-data documentation on your website before making a generative AI system publicly available to Californians, and again before any substantial modification
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Provider Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Generative AI Training Data Transparency Act (AB 2013), Cal. Civ. Code Sections 3110 and 3111 Source as of 2026-08-14 ai:us-ca-cal-civ-sections-3110-3111:0

Texas

If you are a health care practitioner using AI for diagnostic purposes, including AI-generated recommendations on a diagnosis or course of treatment, stay within the scope of your license, do not use AI in a way state or federal law otherwise restricts, and review all AI-created records consistent with Texas Medical Board standards.
Type Conditional Obligation Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records, Tex. Health & Safety Code § 183.005 Source as of 2026-09-06 ai:us-tx-tex-health-safety-183-005:0

Utah

Once access is without authorization or exceeds authorization, copying, transmitting, or disclosing computer data you accessed that way falls within this statute's plain text.
Type Prohibition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Utah Computer Crimes Act (unauthorized access, with an express implied-consent definition), Utah Code Ann. §§ 76-6-702, 76-6-703 Source as of 2026-08-29 scraping:us-ut-utah-ann-76-6-702-76-6-703:1

Peru

A quotation from a lawfully disclosed work may be made without the author's consent or payment if the author's name and the source are stated and the quotation follows proper practice and does not exceed what its purpose justifies.
Type Permission or exemption Modal may Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook The counterparty's establishment (rightsholder); where the copy is made Runtime not a duty
Decreto Legislativo 822, quotation exception, Decreto Legislativo 822, art. 44 (quotation exception), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018) Source as of 2026-09-05 scraping:pe-decreto-legislativo-822-44-quotation-exceptio:0

South Africa

Obtain the Information Regulator's prior authorisation before transferring special personal information, or a child's personal information, to a country that does not provide an adequate level of protection.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Destination of a transfer Runtime not yet classified
Protection of Personal Information Act, cross-border transfer, POPIA, s. 72 (transfer of personal information outside the Republic) Source as of 2026-09-19 privacy:za-popia-s-72-transfer-personal-information-outs:1

Andorra

This duty reaches your service where you employ 50 or more people, or your annual turnover or annual balance sheet total exceeds ten million euros, and you fall within an Annex I essential-entity sector (energy, transport, banking, financial-market infrastructure, health, water, digital infrastructure, public administration) or an Annex II important-entity sector, which names providers of online marketplaces, online search engines and social networking services platforms among Andorra's digital service providers.
Type Definition Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on not a duty Hook Establishment of the operator (entity in scope) Runtime not a duty
Llei 22/2022, Cybersecurity Risk-Management Obligations, Llei 22/2022, del 9 de juny, arts. 12, 13, 17 i 18 Source as of 2026-09-18 security:ad-llei-22-2022-del-9-de-juny-12-13-17-i-18:0

Angola

Notify the Agência de Protecção de Dados, or obtain the recipient's express consent, before sending postal or electronic marketing messages or recording a call for commercial purposes, and let the recipient object to further messages free of charge at any time.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Law on the Protection of Personal Data, Lei n.º 22/11, de 17 de Junho de 2011 (Protecção de Dados Pessoais), arts. 1-12, 16, 18-24, 30-32, 35-43 and 63-67 Source as of 2026-09-19 privacy:ao-lei-n-22-11-de-17-de-junho-de-2011-protec-o-d:2

Argentina

Do not access a computer system or data of restricted access without due authorization, or by exceeding the authorization held.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Código Penal, art. 153 bis, unauthorized access to a restricted computer system or data, Código Penal (Ley 11.179, texto ordenado), art. 153 bis, incorporated by Ley N° 26.388 (B.O. 25/6/2008) Source as of 2026-09-05 scraping:ar-c-digo-penal-153-bis-incorporated-by-ley-n-26:0

Belgium

Do not exceed your own access rights to a computer system with a fraudulent intent or an intent to harm.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Code pénal, Livre II, articles 524 à 527, accès non autorisé dans un système informatique, Code pénal, Livre II, arts. 524-527 (accès non autorisé dans un système informatique), inséré par la loi du 29 février 2024 introduisant le livre II du Code pénal; peines fixées au Livre Ier, art. 36 et 38 Source as of 2026-09-06 scraping:be-penal-livre-ii-524-527-acces-non-autorise-dan:1

Burkina Faso

Obtain a person's prior consent before sending them unsolicited direct marketing communications of any kind, tell them before their data is first used for that purpose or disclosed to a third party, and let them withdraw consent at any time.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the data subject Runtime not yet classified
Personal Data Protection Law, rights of the data subject, Loi n°001-2021/AN, arts. 14-22, 31 (droits de la personne concernée) Source as of 2026-09-19 privacy:bf-loi-n-001-2021-14-22-31-droits-de-la-personne:0

Bahrain

An app processing the personal data of an individual in Bahrain without the required lawful basis, prior authorisation, or transfer safeguard risks both criminal penalties (imprisonment and fines up to BD 20,000) and administrative penalties (up to BD 20,000, plus a daily compliance penalty on repeat violation) from the Personal Data Protection Authority, and a data subject who suffers damage from unlawful processing may separately claim compensation directly from the app under Art. 57.
Type Consequence (penalty or remedy) Modal may Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
Personal Data Protection Law, enforcement and penalties, Law No. 30 of 2018, Arts. 55, 57-60 Source as of 2026-09-02 privacy:bh-no-30-2018-55-57-60:0

Benin

Obtain the Autorité's prior authorization before any actual transfer of personal data to a third country or international organization, even where an equivalence finding exists.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Destination of a transfer Runtime not yet classified
Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre V, transfert transfrontalier de données, Loi n°2017-20 du 20 avril 2018, Livre V, arts. 391-392 (transfert transfrontalier de données) Source as of 2026-09-19 privacy:bj-loi-n-2017-20-du-20-avril-2018-livre-v-391-39:1

108 more lines in force under this theme, and 137 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T11 · Monitoring & Logging

The group's key concepts: Audit trails; prompt/tool logs; decision logs; log retention; log integrity; tamper-evidence; real-time alerting

168 lines 133 in force 132 provisions 96 jurisdictions by type: mandatory obligation 83, conditional obligation 56, prohibition 13, definition 10, consequence (penalty or remedy) 4, permission or exemption 2

Classes its lines carry: secure the system and the data in it (102), govern the system: policies, roles, assessments (94), get consent first (55), keep records for a set time (42); 23 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 133 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing.
Type Conditional Obligation Modal imperative Binds, by its wording Controller (the party that decides why and how personal data is processed) Scope turns on Operator Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 Source as of 2026-08-23 privacy:eu-2016-679:1

Texas

Inform an individual and obtain consent before capturing their retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry for a commercial purpose in Texas.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149, Tex. Bus. & Com. Code sec. 503.001, as amended by Tex. HB 149, 89th Legislature (2025) Source as of 2026-08-23 privacy:us-tx-tex-bus-com-sec-503-001-as-amended-by-tex:0

South Korea

Build a risk-management system that monitors and responds to AI-related safety accidents involving your system.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems), Act No. 20676, Article 32 Source as of 2026-09-20 ai:kr-no-20676-32:1

Brazil

Keep a record of your processing operations, especially those based on legitimate interest, and name a person in charge (encarregado) whose identity and contact details you publish, preferably on your website.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:2

India

Connect all your ICT systems' clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to an NTP server traceable to one of them, and ensure any other time source you use does not deviate from NPL or NIC.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Placing on the market; establishment of the manufacturer Runtime Outside any runtime path
CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) Source as of 2026-09-12 security:in-directions-under-70b-6-information-technology:1

Vietnam

If a serious incident occurs in your AI system and you are its deployer or user, record the incident, notify it promptly, and coordinate with the other parties during the remediation process.
Type Conditional Obligation Modal imperative Binds, by its wording Deployer (the party that uses the system under its own authority) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12 Source as of 2026-09-20 ai:vn-no-134-2025-qh15-12:1

Ireland

As a relevant digital service provider, additionally take into account the security of your systems and facilities, incident handling, business continuity management, monitoring, auditing and testing, and compliance with international standards, and keep documentation sufficient for the competent authority to verify your compliance.
Type Mandatory Obligation Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
European Union (NIS) Regulations 2018, Security Requirements, S.I. No. 360/2018, Regs. 17 and 21 Source as of 2026-09-12 security:ie-s-i-no-360-2018-regs-17-21:2

Italy

Expect AgID to handle AI innovation promotion and the notification, assessment, accreditation and monitoring of conformity-assessment bodies for AI systems placed on the Italian market.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market; where the output is used Runtime not a duty
Legge 132/2025 Art. 20, National AI Authorities (AgID and ACN), Legge 23 settembre 2025, n. 132, art. 20 Source as of 2026-09-06 ai:it-l-132-2025-agid-acn-national-authorities:0

Spain

Adopt technical and organisational measures, proportionate to the risk and reflecting the state of the art, to manage the risks to the networks and information systems you use to provide the service, even where that management is outsourced; as a digital service provider, address at minimum the security of your systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with relevant international standards.
Type Conditional Obligation Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers, Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero Source as of 2026-09-12 security:es-rdl-12-2018-art16-seguridad:1

France

Cover each of: the security of your systems and installations; incident management; business-continuity management; monitoring, audit and control; and compliance with international standards.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements, Loi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 Source as of 2026-09-12 security:fr-loi-n-2018-133-du-26-f-vrier-2018-titre-ier-c:2

Netherlands

After any access gained that way, do not copy, tap, or record the data stored on, processed by, or transferred through that system.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Wetboek van Strafrecht, art. 138ab, Computervredebreuk (Computer Trespass), Wetboek van Strafrecht, art. 138ab (BWBR0001854) Source as of 2026-09-06 scraping:nl-wetboek-van-strafrecht-138ab-computervredebre:1

Illinois

Where a third party is contracted to dispose of the materials, require it to implement and monitor policies and procedures that prohibit unauthorized access to, acquisition of, or use of personal information during collection, transportation, and disposal.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Provider Hook Establishment of the operator; placing on the market Runtime Outside any runtime path
Personal Information Protection Act, safe disposal of personal information, 815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01) Source as of 2026-09-14 security:us-il-815-ilcs-530-40-disposal-materials-contain:2

South Africa

Only process a data subject's biometric information or record of criminal behaviour where you are a body charged with applying criminal law or you obtained the information lawfully, and put appropriate safeguards in place before relying on any special personal information exception.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the data subject Runtime not yet classified
Protection of Personal Information Act, special personal information and children, POPIA, ss. 26-35 (special personal information and children) Source as of 2026-09-19 privacy:za-popia-ss-26-35-special-personal-information-c:3

120 more lines in force under this theme, and 168 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T12 · Testing & Red Teaming

The group's key concepts: Prompt injection; tool abuse; autonomy failures; adversarial testing; pre-deployment testing; test coverage; remediation

20 lines 18 in force 19 provisions 17 jurisdictions by type: conditional obligation 8, mandatory obligation 8, definition 3, permission or exemption 1

Classes its lines carry: secure the system and the data in it (10), report to a regulator (8), govern the system: policies, roles, assessments (6), do not do the named thing (1); 4 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 18 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

If the Commission has classified your general-purpose AI model as carrying systemic risk, in addition to your Article 53 duties, perform model evaluation using standardised, state-of-the-art protocols and tools, including conducting and documenting adversarial testing to identify and mitigate systemic risks.
Type Conditional Obligation Modal imperative Binds, by its wording Provider of a general-purpose model Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk), Regulation (EU) 2024/1689, Article 55 Source as of 2026-09-20 ai:eu-2024-1689-55:0

Vietnam

If a serious incident occurs in your AI system and you are its deployer or user, record the incident, notify it promptly, and coordinate with the other parties during the remediation process.
Type Conditional Obligation Modal imperative Binds, by its wording Deployer (the party that uses the system under its own authority) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12 Source as of 2026-09-20 ai:vn-no-134-2025-qh15-12:1

New York

By April 15 of each year, submit to the Superintendent electronically either a written certification that you materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections you did not materially comply with and a remediation timeline, each signed by your highest-ranking executive and your Chief Information Security Officer.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Placing on the market; establishment of the manufacturer Runtime not yet classified
New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent, 23 NYCRR 500.17 Source as of 2026-09-20 security:us-ny-23-nycrr-500-17:4

Republic of the Congo

Expect the commission, after adversarial procedure, to withdraw an authorization, ban processing for up to three months or permanently, order you to cease processing, or impose an administrative fine of one million to one hundred million CFA francs, where you do not comply with its formal notice.
Type Conditional Obligation Modal do not Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator Runtime not yet classified
Law No. 29-2019, sanctions, Loi n° 29-2019, articles 92 à 98 (sanctions administratives et pénales) Source as of 2026-09-19 privacy:cg-loi-n-29-2019-articles-92-98-sanctions-admini:1

Côte d'Ivoire

Comply with an order interrupting a processing, locking data, or prohibiting a processing temporarily or permanently once the Protection Body issues it after an adversarial procedure.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator Runtime not yet classified
Law No. 2013-450 on the Protection of Personal Data, enforcement and the Protection Body, Loi n° 2013-450, arts. 45-52 (enforcement and the Protection Body) Source as of 2026-09-19 privacy:ci-loi-n-2013-450-45-52-enforcement-protection-b:2

Ghana

This binds a person who provides a cybersecurity service for reward in Ghana, a term the First Schedule defines to include designing, selling, importing, exporting, installing, maintaining, repairing or servicing a cybersecurity solution, so a vendor distributing a security software product for reward in Ghana falls within it even without performing penetration testing, forensic examination, monitoring or any of the Schedule's other listed services; a general-purpose software product with no security-specific function is not reached by this term on its own.
Type Definition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator (entity in scope) Runtime not a duty
Cybersecurity Act, Licensing of Cybersecurity Service Providers, Cybersecurity Act, 2020 (Act 1038), ss. 49-53, First Schedule, and Second Schedule items 49(2) and 51(5) Source as of 2026-09-18 security:gh-cybersecurity-act-1038-s49-licensing:0

Israel

At the high tier, conduct a data security risk assessment and a penetration test of the database's systems at least once every 18 months, and hold a quarterly internal discussion of security incidents.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market Runtime Outside any runtime path
Privacy Protection Regulations (Data Security), information security programme, Privacy Protection Regulations (Data Security), 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement) Source as of 2026-09-18 security:il-privacy-protection-regulations-data-security-2:2

Lebanon

Adopt at least two-factor authentication for any user accessing the system from outside the bank or financial institution, fully encrypt highly sensitive data, filter inbound email, verify the security of devices employees use outside the institution, run penetration testing, monitor network traffic, and verify data integrity.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator (entity in scope) Runtime not yet classified
Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts), Banque du Liban Basic Decision No. 12725 of 28 November 2017 (Basic Circular No. 144 to Banks, also addressed to Financial Institutions), Prevention of Electronic Criminal Acts, Arts. 1-6 Source as of 2026-09-19 security:lb-basic-circular-144-cybercrime:2

Latvia

Once the competent cyber incident prevention institution relays a substantiated report that a vulnerability exists in a system or network you operate, remediate it within the deadline the institution sets, no later than 90 days from when you received the information.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Placing on the market; establishment of the manufacturer Runtime Outside any runtime path
Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation, Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti Source as of 2026-09-15 security:lv-nacionalas-kiberdrosibas-likums-39-un-40-pant:1

Madagascar

Comply with any warning, injunction to stop processing, withdrawal of authorization, or monetary sanction the CMIL orders after an adversarial procedure, and with any urgent interruption or data-locking order it issues for up to three months.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator Runtime not yet classified
Law No. 2014-038, CMIL, sanctions and offences, Loi n° 2014-038, arts. 4, 28-42, 50, 55-60, 61-73 (commission, contrôle, sanctions et pénalités) Source as of 2026-09-19 privacy:mg-loi-n-2014-038-4-28-42-50-55-60-61-73-commiss:0

Slovakia

Through the same reporting system, also report a significant cyber threat you become aware of, a near-miss event that could have caused a significant incident, and a vulnerability in your own publicly available networks or systems that you could not remediate or mitigate in reasonable time.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Placing on the market; establishment of the manufacturer Runtime Evidenced by the runtime's record
Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification, Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5 Source as of 2026-09-15 security:sk-zakon-c-69-2018-hlasenie-incidentov:6

Taiwan

Where the competent authority designates the enterprise's PSTN, in whole or in part, as critical telecommunications infrastructure, additionally draw up a critical telecommunications infrastructure protection plan before the competent authority's own deadline, submit it for the competent authority's evaluation before implementing it, and comply with the technical specifications for info-communications security evaluation the competent authority sets for that infrastructure.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator (entity in scope) Runtime not yet classified
Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans, Arts. 15, 42, 76 and 79 of the Telecommunications Management Act (電信管理法), enacted June 26, 2019, effective July 1, 2020 for the provisions cited here Source as of 2026-09-19 security:tw-telecom-mgmt-act-15-42:2

Arkansas

If you provide or develop an AI system and conduct adversarial testing in good faith to prevent, detect, or mitigate the risk of that system generating this material, that testing is exempt, but only if it is not for personal, exploitative, or unrelated purposes.
Type Permission or exemption Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market; where the output is used Runtime not a duty
Act 977 of 2025 (HB 1877), AI-Generated Child Sexual Abuse Material Amendments, Ark. Code Ann. §§ 5-27-302, 5-27-304, 5-27-601 to 5-27-603, 5-27-609 Source as of 2026-09-06 ai:us-ar-ark-ann-5-27-302-5-27-304-5-27-601-5-27-60:1

5 more lines in force under this theme, and 20 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T13 · Third-Party & Supply Chain

The group's key concepts: Vendor due diligence; model provenance; tool vetting; AI BOM; SLA; supply chain risk; third-party incident notification

1,147 lines 1,022 in force 648 provisions 229 jurisdictions by type: mandatory obligation 470, conditional obligation 320, prohibition 163, definition 109, permission or exemption 44, consequence (penalty or remedy) 40, recommendation/guidance 1

Classes its lines carry: secure the system and the data in it (450), govern the system: policies, roles, assessments (414), hold a licence or registration (367), get consent first (357); 171 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 1,022 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Publish a training-content summary if you provide a general-purpose model
Type Conditional Obligation Modal imperative Binds, by its wording Provider of a general-purpose model Scope turns on Provider Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
AI Act, Article 53 (obligations for providers of general-purpose AI models), Regulation (EU) 2024/1689, Article 53 Source as of 2026-08-15 ai:eu-2024-1689-53:0

California

If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 Source as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0

Colorado

Do not sell, lease, or trade a biometric identifier, or disclose one to a third party, without the consumer's consent or a listed statutory exception.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) Source as of 2026-08-23 privacy:us-co-c-r-s-sections-6-1-1303-2-2-2-4-6-1-1314-2:2

Texas

If you are a health care practitioner using AI for diagnostic purposes, including AI-generated recommendations on a diagnosis or course of treatment, stay within the scope of your license, do not use AI in a way state or federal law otherwise restricts, and review all AI-created records consistent with Texas Medical Board standards.
Type Conditional Obligation Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records, Tex. Health & Safety Code § 183.005 Source as of 2026-09-06 ai:us-tx-tex-health-safety-183-005:0

South Korea

Establish and carry out a plan to explain, so far as technically feasible, your AI's final output, the main criteria it used to reach that output, and an overview of the training data you used to develop or use it.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Framework Act, Article 34 (business-operator duties for high-impact AI), Act No. 20676, Article 34 Source as of 2026-09-20 ai:kr-no-20676-34:2

United Kingdom

Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under UK GDPR Article 82, but expect a UK representative claim to require proof of unlawful use and resulting damage for each individual claimant, not a bare loss-of-control theory, per Lloyd v Google.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Controller (the party that decides why and how personal data is processed) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
UK GDPR Article 82, Data Protection Act 2018 Section 169, and ICO Enforcement, UK GDPR, Arts. 82-83; Data Protection Act 2018 §169 Source as of 2026-08-24 privacy:gb-uk-gdpr-82-83-data-protection-2018-169:1

Brazil

Take consent only when it is provided in writing or by another means demonstrating the data subject's free will, in a clause set apart from the other contract terms, and be ready to prove it meets these requirements.
Type Definition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on reworded since it was classified Hook Residence of the data subject; establishment of the operator Runtime reworded since it was classified
Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:1

India

Embed synthetically generated information with permanent metadata or another technical provenance mechanism, including a unique identifier, to the extent technically feasible, and do not enable removal, suppression or modification of that label or metadata.
Type Conditional Obligation Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026) Source as of 2026-09-07 ai:in-information-technology-intermediary-guideline:1

Vietnam

At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market Runtime Outside any runtime path
Cybersecurity Law, Information System Classification and Protection Measures, Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10 Source as of 2026-09-16 security:vn-no-116-2025-qh15-cybersecurity-8-10:3

Germany

Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Germany, including a credit score generated for a third party's determinative use, under GDPR Article 22 and BDSG Section 31.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany, Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37 Source as of 2026-08-24 privacy:de-eu-2016-679-22-bundesdatenschutzgesetz-bdsg-3:1

Ireland

Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Ireland outside the European Economic Area.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
GDPR Chapter V, Cross-Border Transfer of Personal Data from Ireland, Regulation (EU) 2016/679, Arts. 44-49 Source as of 2026-08-24 privacy:ie-eu-2016-679-44-49:0

Italy

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Italy outside the EEA.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
GDPR Chapter V, Cross-Border Transfer Restrictions, Regulation (EU) 2016/679, Arts. 44-49, 83(5) Source as of 2026-08-24 privacy:it-eu-2016-679-44-49-83-5:0

Spain

Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Spain outside the EEA, and check whether LOPDGDD Articles 41-43 require AEPD authorization or prior notice for the specific transfer.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
LOPDGDD Título VI, International Transfers, Layered on GDPR Chapter V, Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l) Source as of 2026-08-24 privacy:es-eu-2016-679-44-49-83-5-lopdgdd-40-43-72-1-l:0

1,009 more lines in force under this theme, and 1,147 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T14 · Incident Response

The group's key concepts: Detection; containment; incident classification; regulatory notification; root cause analysis; recovery; post-incident review

1,000 lines 811 in force 469 provisions 204 jurisdictions by type: mandatory obligation 450, conditional obligation 386, consequence (penalty or remedy) 55, prohibition 54, definition 45, permission or exemption 6, recommendation/guidance 4

Classes its lines carry: report to a regulator (462), secure the system and the data in it (378), tell somebody when there is a breach (300), govern the system: policies, roles, assessments (171); 257 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 811 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

Transmit the audit report and the audit implementation report to your Digital Services Coordinator of establishment and the Commission without undue delay, and make them public, with confidential information removed where necessary, within three months of receiving the audit report.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Digital Services Act, Article 37 (independent audit of very large online platforms and search engines), Regulation (EU) 2022/2065, Article 37, supplemented by Commission Delegated Regulation (EU) 2024/436 Source as of 2026-09-15 ai:eu-2022-2065-37:4

California

Report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious injury
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Provider Hook Establishment of the operator; placing on the market; where the output is used Runtime Evidenced by the runtime's record
Transparency in Frontier Artificial Intelligence Act (SB 53), Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16 Source as of 2026-09-08 ai:us-ca-cal-bus-prof-sections-22757-10-22757-16:4

Colorado

If you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
C.R.S. 6-1-716, Notification of Security Breach, C.R.S. section 6-1-716 Source as of 2026-08-23 privacy:us-co-c-r-s-6-1-716:0

Texas

If you own a website, application, or social media platform on which such material is disclosed, you are liable for damages if the depicted person requests removal and you fail to remove it, and known identical copies, within 72 hours.
Type Conditional Obligation Modal imperative Binds, by its wording Platform or intermediary Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009 Source as of 2026-09-06 ai:us-tx-tex-civ-prac-rem-98b-0021-98b-009:2

South Korea

Notify users when content they see was produced by generative AI
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
AI Framework Act, Article 31 (transparency obligations for AI outputs), Act No. 20676, Article 31 Source as of 2026-08-14 ai:kr-no-20676-31:0

United Kingdom

Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 Source as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0

Brazil

Notify the ANPD and the affected data subjects of a security incident that may create relevant risk or harm to data subjects, within the reasonable period the ANPD sets by regulation, and state the reasons for the delay when the notice is not immediate.
Type Conditional Obligation Modal may Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Residence of the affected person Runtime not yet classified
LGPD, security incident notification, Lei nº 13.709, de 2018 (LGPD), art. 48 (security incident notification) Source as of 2026-09-19 privacy:br-lei-n-13-709-de-2018-lgpd-48-security-inciden:0

India

The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.
Type Definition Modal may, must Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Residence of the data subject; establishment of the operator Runtime not a duty
Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025 Source as of 2026-08-29 privacy:in-g-s-r-846-e-digital-personal-data-protection:0

Vietnam

If a serious incident occurs in your AI system and you are its developer or provider, urgently apply technical measures to remedy, suspend, or recall the system, and at the same time notify the competent state authority of the incident.
Type Conditional Obligation Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12 Source as of 2026-09-20 ai:vn-no-134-2025-qh15-12:0

Germany

Notify the competent German data protection authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Germany, unless the breach is unlikely to risk their rights and freedoms.
Type Conditional Obligation Modal unless Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
GDPR Articles 33-34, Breach Notification in Germany, Regulation (EU) 2016/679, Arts. 33-34 Source as of 2026-08-24 privacy:de-eu-2016-679-33-34:0

Ireland

An administrative fine imposed on a public body for an AI Act breach is capped at EUR 1,000,000 regardless of the Article 99 tier that would otherwise apply; a fine on any other person or undertaking instead follows the EU AI Act's own Article 99 tiers (s. 105(2)-(5)).
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market; where the output is used Runtime not a duty
Regulation of Artificial Intelligence Act 2026, Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026) Source as of 2026-09-06 ai:ie-regulation-of-artificial-intelligence-2026:1

Italy

Notify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
GDPR Articles 33-34, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34 Source as of 2026-08-24 privacy:it-eu-2016-679-33-34:0

Spain

Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s) Source as of 2026-08-24 privacy:es-eu-2016-679-33-34-lopdgdd-69-73-r-s:0

798 more lines in force under this theme, and 1,000 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T15 · Transparency & User Disclosure

The group's key concepts: AI disclosure; user notices; explanations; user expectations; consent; labeling; deception prohibition; capability limits

2,708 lines 2,224 in force 1,156 provisions 244 jurisdictions by type: mandatory obligation 1,173, conditional obligation 675, prohibition 436, definition 216, consequence (penalty or remedy) 109, permission or exemption 91, recommendation/guidance 8

Classes its lines carry: disclose the use of AI (1,104), secure the system and the data in it (792), govern the system: policies, roles, assessments (621), honour the person's rights over their data (588); 548 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 2,224 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

This is one listed risk-mitigation measure for a Commission-designated very large online platform or search engine, not a freestanding labeling mandate on every provider
Type Definition Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on not a duty Hook Where the output is used; placing on the market Runtime not a duty
Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking), Regulation (EU) 2022/2065, Article 35(1)(k) Source as of 2026-08-14 ai:eu-2022-2065-35-1-k:0

California

If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 Source as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0

Colorado

Carry a clear and conspicuous disclosure that the communication has been edited and falsely appears authentic, when you distribute, publish, broadcast, or display a communication about a candidate that includes a deepfake
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
HB 24-1147, Candidate Election Deepfake Disclosures, C.R.S. 1-46-103 Source as of 2026-08-14 ai:us-co-c-r-s-1-46-103:0

Texas

If you are a governmental agency making an AI system available to interact with consumers, disclose before or at the time of interaction that the consumer is interacting with an AI system, even if that would already be obvious to a reasonable consumer.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
TRAIGA (H.B. 149, 2025), consumer AI-interaction disclosure duty, Tex. Bus. & Com. Code § 552.051 Source as of 2026-09-06 ai:us-tx-tex-bus-com-552-051:0

South Korea

Check the Enforcement Decree for labeling specifics as they phase in
Type Definition Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Where the output is used; placing on the market Runtime not a duty
AI Framework Act, Article 31 (transparency obligations for AI outputs), Act No. 20676, Article 31 Source as of 2026-08-14 ai:kr-no-20676-31:1

United Kingdom

Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 Source as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0

Brazil

Disclose, explicitly, prominently, and accessibly, when electoral advertising uses AI-generated synthetic content to create, replace, omit, merge, alter the speed of, or overlay images or sounds, and name the technology used.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
TSE Resolution, AI-Generated Content Disclosure Duty, Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) Source as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-b-reda-o-dada-pe:0

India

If you operate a computer resource that may enable the creation, generation, modification, alteration, publication, transmission, sharing or dissemination of synthetically generated information, prominently label such information, in the visual display or by a prefixed audio disclosure, so a viewer can immediately identify it as synthetically generated.
Type Conditional Obligation Modal may Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026) Source as of 2026-09-07 ai:in-information-technology-intermediary-guideline:0

Vietnam

Design an AI system that interacts directly with users so that users can recognise they are interacting with an AI system, unless the law provides otherwise.
Type Conditional Obligation Modal unless Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Law on Artificial Intelligence, transparency obligation, Law No. 134/2025/QH15, art. 11 Source as of 2026-09-06 ai:vn-no-134-2025-qh15-11:0

Germany

Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 Source as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:1

Ireland

Comply with information requests, contravention notices and prohibition notices issued by an authorised officer of a relevant market surveillance authority in respect of an AI system you provide or deploy (Part 5).
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Regulation of Artificial Intelligence Act 2026, Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026) Source as of 2026-09-06 ai:ie-regulation-of-artificial-intelligence-2026:0

Italy

Do not transfer, publish, or otherwise disseminate a falsified or altered image, video, or voice recording generated using an AI system, capable of misleading others as to its genuineness, without the depicted or recorded person's consent.
Type Prohibition Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Codice Penale Art. 612-quater, Illicit Dissemination of AI-Generated or AI-Altered Content, Codice Penale, art. 612-quater, inserted by Legge 23 settembre 2025, n. 132, art. 26, comma 1, lettera c) Source as of 2026-09-06 ai:it-cp-612quater-ai-deepfake-dissemination:0

Spain

Inform the works council of the parameters, rules, and instructions on which any algorithm or AI system that affects decisions on working conditions, access to employment, or continued employment is based, including any profiling, per Estatuto de los Trabajadores Article 64.4.d).
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Estatuto de los Trabajadores Article 64.4.d), Algorithmic Management Works Council Information Right, Ley 12/2021, de 28 de septiembre, articulo unico.Uno, inserting art. 64.4.d) into the Texto Refundido de la Ley del Estatuto de los Trabajadores (Real Decreto Legislativo 2/2015) (BOE-A-2021-15767) Source as of 2026-09-02 ai:es-ley-12-2021-unico-1-et-64-4-d:0

2,211 more lines in force under this theme, and 2,708 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

T16 · Recordkeeping & Auditability

The group's key concepts: Retention schedules; reproducibility; audit readiness; record integrity; regulatory reporting; archival; destruction

2,693 lines 2,241 in force 836 provisions 239 jurisdictions by type: mandatory obligation 1,261, conditional obligation 684, prohibition 270, definition 256, consequence (penalty or remedy) 139, permission or exemption 74, recommendation/guidance 9

Classes its lines carry: govern the system: policies, roles, assessments (1,530), secure the system and the data in it (1,332), report to a regulator (1,046), get consent first (637); 179 from an instrument with no class recorded.

Sample requirement lines Show 13 of the 2,241 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

European Union

This is one listed risk-mitigation measure for a Commission-designated very large online platform or search engine, not a freestanding labeling mandate on every provider
Type Definition Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on not a duty Hook Where the output is used; placing on the market Runtime not a duty
Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking), Regulation (EU) 2022/2065, Article 35(1)(k) Source as of 2026-08-14 ai:eu-2022-2065-35-1-k:0

California

If a reasonable person interacting with your companion chatbot could be misled into believing they are talking to a human, issue a clear and conspicuous notification that the chatbot is artificially generated and not human
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Companion Chatbot Safety and Accountability Act (SB 243), Cal. Bus. and Prof. Code Sections 22601 to 22606 Source as of 2026-09-08 ai:us-ca-cal-bus-prof-sections-22601-22606:0

Colorado

Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) Source as of 2026-08-23 privacy:us-co-c-r-s-sections-6-1-1303-2-2-2-4-6-1-1314-2:1

Texas

If you operate a social media platform, provide an easily accessible complaint system letting a user report explicit deep fake material, alongside illegal content and content-removal decisions.
Type Conditional Obligation Modal imperative Binds, by its wording Platform or intermediary Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
H.B. 3133 (2025), social media platform complaint system for explicit deep fake material, Tex. Bus. & Com. Code §§ 120.101, 120.1001, 120.102, 120.1015, 120.1025, 120.152 Source as of 2026-09-06 ai:us-tx-tex-bus-com-ch-120-subch-c:0

South Korea

If your AI system was trained using cumulative compute of 10^26 floating-point operations or more, applies the most advanced AI technology currently in use, and could broadly and seriously affect people's life, physical safety or fundamental rights, identify, assess and mitigate risk across the system's full life cycle.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems), Act No. 20676, Article 32 Source as of 2026-09-20 ai:kr-no-20676-32:0

United Kingdom

Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 Source as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0

Brazil

Establish a lawful basis under article 7 before processing personal data, including data the person has made public.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:0

India

Get the rights holder's authorisation before reproducing or reusing copyrighted material, including a copyrighted database or compilation, to train an AI model; the fair-dealing exceptions do not name text-and-data-mining or AI training as a covered purpose.
Type Mandatory Obligation Modal do not Binds, by its wording Operator (the party running the application) Scope turns on Counterparty Hook The counterparty's establishment (rightsholder); where the copy is made Runtime Enforceable at a runtime control
Copyright Act, No Text-and-Data-Mining Exception, Database Compilations, and Technological Protection Measures, Copyright Act, 1957 (No. 14 of 1957), ss. 2(o), 51, 52, 63, 65A Source as of 2026-09-07 scraping:in-copyright-1957-no-14-1957-ss-2-o-51-52-63-65a:0

Vietnam

If a serious incident occurs in your AI system and you are its developer or provider, urgently apply technical measures to remedy, suspend, or recall the system, and at the same time notify the competent state authority of the incident.
Type Conditional Obligation Modal imperative Binds, by its wording Provider (the party that develops or places the system on the market) Scope turns on not yet classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not yet classified
Law on Artificial Intelligence, incident management and reporting obligation, Law No. 134/2025/QH15, art. 12 Source as of 2026-09-20 ai:vn-no-134-2025-qh15-12:0

Germany

Expect the Bundesnetzagentur to be Germany's central market surveillance authority, single point of contact, and central complaints office under the EU AI Act, unless your AI system is directly tied to a regulated financial activity that the Bundesanstalt für Finanzdienstleistungsaufsicht already supervises, in which case expect that authority instead.
Type Consequence (penalty or remedy) Modal unless Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator; placing on the market; where the output is used Runtime not a duty
Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 Source as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:0

Ireland

Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Ireland.
Type Mandatory Obligation Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Data Protection Act 2018, Data Protection Act 2018 (No. 7 of 2018) Source as of 2026-08-24 privacy:ie-data-protection-2018-no-7-2018:0

Italy

Expect the Garante to have GDPR Article 83 fining power over your processing of personal data of a person in Italy.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
GDPR Article 82 and Azione di Classe (Codice di Procedura Civile Art. 840-bis), Regulation (EU) 2016/679, Art. 82; Codice di procedura civile, Art. 840-bis (as reformed by Legge 12 aprile 2019, n. 31) Source as of 2026-09-02 privacy:it-eu-2016-679-82-codice-di-procedura-civile-840:0

Spain

Expect the AEPD to sort a violation into a muy grave, grave, or leve infraction tied to a GDPR Article 83 fine tier when assessing exposure for processing personal data of a person in Spain.
Type Consequence (penalty or remedy) Modal imperative Binds, by its wording Operator (the party running the application) Scope turns on not a duty Hook Establishment of the operator Runtime not a duty
AEPD Enforcement, GDPR Article 82 and LOPDGDD Título IX, Regulation (EU) 2016/679, Arts. 82-83; LOPDGDD, Art. 47, Arts. 70-78 Source as of 2026-09-02 privacy:es-eu-2016-679-82-83-lopdgdd-47-70-78:0

2,228 more lines in force under this theme, and 2,693 lines in all, are in the LexLint software-law corpus; the full register is the file in section 3.

3The full register as a file

theme-register.csv holds every line that falls under at least one theme, one row per line, with the theme identifiers it belongs to, the columns above, and the topic, instrument, citation, summary page, source, lifecycle band and as-of date. It is generated from the LexLint software-law corpus on the date in this page's byline and it will be regenerated when the corpus moves; a copy taken today is a snapshot with that date on it.

Two links per row. Instrument page is LexLint's own summary of the instrument. Source URL, after it, is the link the LexLint software-law corpus researched the instrument from: for most rows the law's own text at its publisher (a gazette, a legislature, a regulator) or in a repository of legal texts such as WIPO Lex or an archived copy, and for a few rows the secondary source the research read, which is why the column is named for the source rather than for the law.

Classification. A Classification column after the runtime tier says which of four states the line is in: classified, not a duty, not yet classified, or reworded since it was classified. The party, party group and tier columns print the same words in place of a value for every line in the other three states, so a blank never has to be guessed at.

Party group. Party group (LexLint six parties), after the party column, restates the party whose position triggers scope as one of The 6 parties, so a row can be read against that document, by the mapping below. A line with no party has no group.

Party whose position triggers scopeParty group
OperatorOPERATOR
PrincipalUSER
ProviderMAKER
CounterpartyCOUNTERPARTY
Affected personUSER
Data subjectUSER

The theme columns are this page's, not the corpus's: the corpus records obligation classes and wording, and the mapping from those to the sixteen themes is the rule stated in section 1 and printed on the page before this one. The same lines with the classes and without the theme columns are the handbook's file, described in the requirement register. The file is licensed separately from the text and figures around it, under Creative Commons Attribution-NonCommercial 4.0 rather than the ShareAlike terms in the byline: use it for noncommercial purposes with credit to LexLint (UnGovr), and contact LexLint at hello@ungovr.org to discuss commercial use.