What the law makes you constrain

About this documentUpdated 2026-09-20ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.

Every law named here links to its summary page on lexlint.org, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same licence. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.

Corpus figures as of 2026-09-21.

Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice at the foot says what that means.

Eight places a duty can land on a running agent: the model itself, the instructions it runs on, the safeguards around it, the tools it can reach, the environment it runs in, what watches it, the people accountable, and what it is built from. Each with the law that already asks for something there, and how much of it the corpus holds.

1What this document is

An AGENT is a program that picks its own next action, and the law does not reach it as one thing. It reaches the model that generates, the OPERATOR that runs it, the data it touches, the systems it calls and the people it acts on, each through a different statute with a different addressee. Introduction: The 6 parties in AI law sets out who those parties are. Global AI law: 8 common threads sets out the AI law itself, and the older privacy, security and scraping law that binds an AGENT without naming one.

This document cuts the same body of law along the line an engineer actually works in: the eight places a duty can land on a system while it is running. It is the before half of a pair. What the law makes you able to show once the system has run is What the law makes you able to show; when you have to report what happened, and to whom, is Incident reporting clocks; what it has cost the organisations that could not is Does legal action really happen?.

Each of the eight sections below states the layer in its own terms, names the law that already asks for something there, and then shows what the corpus holds: how many requirement lines in force speak to that layer, from how many provisions and places, with a sample you can read against the statutes themselves. It describes the law as written and dated. It does not say what any particular system should do, and a layer with a large count is not a layer you are behind on.

2How to read a layer

Reading the layers

Ours first
The eight layers are this section's own vocabulary, named for what an engineer constrains rather than for any framework's headings. The document reads the same with every alignment note removed.
The instruments
Every law named in the prose is linked to its page on lexlint.org, which carries the citation, the status, the source and the date the corpus read it. The name and the date you see are read from the corpus when this page is built, never typed here.
The count
A requirement line joins a layer when its own wording speaks to that layer. The test is words, not judgment, and it is applied to the line and not to the instrument around it, so a count is a floor rather than a ceiling: a duty stated in words the test does not carry is missed, and no duty is admitted because the statute it sits in happens to carry a class.
In force
The counted lines are the ones whose instrument binds on the corpus date in the byline. Law that is enacted and waiting for its commencement is named in the prose as something coming, with its date.
One refusal
A line about the safeguards a cross-border transfer needs is read as a boundary of the environment the data sits in, not as a guardrail around the model, so the word "safeguard" alone does not move a transfer rule into the third layer.
A proposal, not a law
The note under each layer quotes the SAFE proposal published by the OSAA, read 2026-09-20 from its request for comments. It is a voluntary scheme among members and binds nobody. It is shown because a reader who has that framework in hand should be able to find the same ground here, not because the law follows it.
Not here
Whether any of this reaches your system is the applicability question, answered per deployment from the roles the system holds and where its parties are. This document does not answer it, and neither does any table on it.
Eight places a duty can land on a running agent Eight labelled cells, one per control layer. The model itself: What the law asks of the model you ship. The instructions it runs on: The authority a run is given, and its purpose. The safeguards around it: What has to sit between the model and the act. The tools it can reach: Limits on what it may reach, send, spend or publish. The environment it runs in: Where the data may sit, and what it may touch. What watches it: The duty to notice, and to be able to stop it. The people accountable: The named person a duty lands on. What it is built from: Duties that follow the parts and the parties behind them. The model itself What the law asks of the model you ship The instructions it runs on The authority a run is given, and its purpose The safeguards around it What has to sit between the model and the act The tools it can reach Limits on what it may reach, send, spend or publish The environment it runs in Where the data may sit, and what it may touch What watches it The duty to notice, and to be able to stop it The people accountable The named person a duty lands on What it is built from Duties that follow the parts and the parties behind them
Figure 1. The eight layers, in the order the sections below take them: from the model at the centre out to the parts and parties it was built from.

3The eight layers

In order. Each section names the law first and shows the corpus second.

1 · The model itself

What the law asks of the model you ship.

Law binds conduct far more readily than it binds an artefact, so the duties that attach to the model itself are few, recent, and aimed at whoever makes it. In the European Union the general-purpose model duties of AI Act, Article 53 (obligations for providers of general-purpose AI models) bind now (since 2025-08-02): publish a training-content summary, adopt and follow a copyright policy that respects mining opt-outs, and keep technical documentation available for the AI Office. Where the Commission classifies a model as carrying systemic risk, AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk) adds evaluation with documented adversarial testing, mitigation of those risks at Union level, cybersecurity for the model and its physical infrastructure, and reports of serious incidents to the AI Office without undue delay.

Two other places set a duty at the model rather than at its use. AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) turns on a compute threshold and asks for risk identified, assessed and mitigated across the life cycle, with the results submitted to the Ministry of Science and ICT. Transparency in Frontier Artificial Intelligence Act (SB 53) asks a large frontier developer to write, implement and publish a frontier framework.

Two things follow for anyone building on a model rather than training one. Nearly all of this binds the MAKER, and an OPERATOR inherits none of it directly; what it inherits is whatever the maker's documentation lets it show. And the corpus is thin here, which is the finding rather than a gap in the reading: where a framework has a great deal to say about the model, binding law says little, and what it does say it says to somebody else.

43 requirement lines in force · 44 provisions · 33 jurisdictions · from: AI 35 · scraping 14 · privacy 5 · cybersecurity 4

The law behind the layer Show 7 of the 43 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Publish a training-content summary if you provide a general-purpose model
European Union AI Act, Article 53 (obligations for providers of general-purpose AI models), Regulation (EU) 2024/1689, Article 53 Source as of 2026-08-15
If you are a large frontier developer (a frontier developer whose group had annual gross revenues over $500,000,000 in the prior calendar year), write, implement and publish on your website a frontier AI framework describing how you define and assess catastrophic-risk thresholds for your frontier models and apply mitigations, and review that framework at least once a year
California Transparency in Frontier Artificial Intelligence Act (SB 53), Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16 Source as of 2026-09-08
A general-purpose AI application or software provider has an affirmative defense only if its terms prohibit creating this content and it takes active technical steps against it, such as training the system to identify such media, providing reporting tools, and filtering it from outputs and training data.
Establish and carry out a plan to explain, so far as technically feasible, your AI's final output, the main criteria it used to reach that output, and an overview of the training data you used to develop or use it.
South Korea AI Framework Act, Article 34 (business-operator duties for high-impact AI), Act No. 20676, Article 34 Source as of 2026-09-20
Get the rights holder's authorisation before reproducing or reusing copyrighted material, including a copyrighted database or compilation, to train an AI model; the fair-dealing exceptions do not name text-and-data-mining or AI training as a covered purpose.
India Copyright Act, No Text-and-Data-Mining Exception, Database Compilations, and Technological Protection Measures, Copyright Act, 1957 (No. 14 of 1957), ss. 2(o), 51, 52, 63, 65A Source as of 2026-09-07
For a high-risk AI system, complete a conformity assessment before putting it into service or after a significant change, and maintain that conformity throughout operation.
Vietnam Law on Artificial Intelligence, risk classification and conformity assessment, Law No. 134/2025/QH15, arts. 9-10, 13-14 Source as of 2026-09-06
Establish a lawful basis before collecting or otherwise using personal data, including publicly accessible personal data, to train an AI model on people in Ireland, and account for the purpose the person originally made that data public for, not only whether it was public.
Ireland DPC Guidance: AI, Large Language Models and Data Protection, Data Protection Commission, "AI, Large Language Models and Data Protection" guidance (18 July 2024) Source as of 2026-08-24
The alliance's words for the same ground

Model. Did the model recognize uncertainty, scope boundaries and stop conditions?

SAFE Review Framework, read 2026-09-20.

2 · The instructions it runs on

The authority a run is given, and its purpose.

Two bodies of law decide what an AGENT may be told to do. The first is the authority to process at all: General Data Protection Regulation (GDPR), Comprehensive Regime requires a lawful basis established and documented before any personal data of a person in the Union is processed, and the same requirement, in its own words, is the opening line of most of the privacy statutes in the corpus. The second is access law, which asks whether the system was allowed on the machine it reached: Computer Fraud and Abuse Act (unauthorized access and the gates-based authorization test) does not reach a public, unauthenticated page, and does reach the same crawl once an operator has revoked access individually or a technical block has been circumvented.

A third sits between them and matters to anything that reads the web to learn: DSM Directive, Article 4 (text-and-data-mining exception and rights reservation) asks a miner to check for machine-readable rights reservations before mining content accessible from the Union, to skip or license what has been reserved, and to mine only content it accessed lawfully to begin with.

The practical point is that a prompt is not an authority. A system prompt telling an AGENT that it may read a site does not make the reading lawful, and "use the data we already hold" is not a lawful basis. What the law calls instructions is narrower and more formal than what an engineer calls them, and the OPERATOR owns the difference.

335 requirement lines in force · 293 provisions · 179 jurisdictions · from: scraping 207 · privacy 147 · AI 6

The law behind the layer Show 8 of the 335 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU.
European Union General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 Source as of 2026-08-23
Note that this statute's without permission standard has no threshold requirement that your initial access be unauthorized, unlike the federal CFAA.
Do not collect a minor's precise geolocation data beyond what is necessary to provide the service, and do not use a design feature meant to significantly increase, sustain, or extend a minor's use of the service without consent.
Colorado SB 24-041, Protecting Minors' Online Data, C.R.S. sections 6-1-1305.5, 6-1-1308.5, 6-1-1309.5, 6-1-1311(1)(d)(II) (2024 Colo. Sess. Laws ch. 296) Source as of 2026-08-23
An app processing Korean personal data must be able to answer to the PIPC for its lawful basis and safeguards, and an individual harmed by a security failure may bring a private civil claim for statutory damages, or damages up to five times the actual loss, without needing to prove the controller's negligence.
South Korea Personal Information Protection Act, enforcement and private civil remedy, Act No. 10465 (as amended by Act No. 19234, 2023), Arts. 39, 39-2, 51, 64-2 Source as of 2026-09-02
Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
United Kingdom UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 Source as of 2026-08-24
Establish a lawful basis under article 7 before processing personal data, including data the person has made public.
Brazil Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19
Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Germany.
Germany Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act, Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017), as amended Source as of 2026-08-24
Do not knowingly give false or misleading information to an adjudicator, or disclose confidential material relevant to an adjudicator's finding without authorisation (ss. 95, 104).
Ireland Regulation of Artificial Intelligence Act 2026, Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026) Source as of 2026-09-06
The alliance's words for the same ground

Instructions. Were authorization and environmental assumptions explicit and correct?

SAFE Review Framework, read 2026-09-20.

3 · The safeguards around it

What has to sit between the model and the act.

The law names outcomes, and only rarely the mechanism that secures them. AI Act, Article 50 (transparency obligations for AI systems and synthetic content) (since 2026-08-02) requires that a person interacting with an AI system be told so, and that synthetic content be marked in a machine-readable way; AI Framework Act, Article 31 (transparency obligations for AI outputs) asks the same of AI outputs in Korea. NIS2 Directive, Cybersecurity Risk-Management Measures asks for measures appropriate to the risk covering incident handling, continuity, supply chain and the security of development, with basic cyber hygiene, training, and multi-factor or continuous authentication where appropriate.

That shape is worth taking seriously when a control is being designed. A classifier, an approval step or an action limit is not compliant because it exists, and no statute in the corpus asks for one by name. Each is evidence that an outcome the law does require has been secured, which is why this layer cannot be turned into a checklist, by us or by anyone else.

171 requirement lines in force · 172 provisions · 115 jurisdictions · from: privacy 117 · cybersecurity 64 · AI 17 · scraping 4

The law behind the layer Show 8 of the 171 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

If you are a Commission-designated very large online platform or very large online search engine, commission an independent audit, at your own expense and at least once a year, of your compliance with Chapter III's due diligence obligations, including the systemic-risk mitigation measures for generated and manipulated content, and with any codes of conduct or crisis protocols you have joined.
European Union Digital Services Act, Article 37 (independent audit of very large online platforms and search engines), Regulation (EU) 2022/2065, Article 37, supplemented by Commission Delegated Regulation (EU) 2024/436 Source as of 2026-09-15
It is a safe harbor, not a duty: if such an entity is sued over a breach of system security and demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program meeting Section 542.004's requirements, the claimant may not recover exemplary damages from it. A qualifying program must contain administrative, technical, and physical safeguards; conform to a named industry-recognized cybersecurity framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, the HITRUST Common Security Framework, the Secure Controls Framework, SOC 2, or a similar framework); and be scaled by headcount: simplified measures such as password policies and employee training below 20 employees, the CIS Controls Implementation Group 1 from 20 to 99 employees, and full conformance with a named framework from 100 to 249 employees.
Texas Cybersecurity Program safe harbor from exemplary damages (S.B. 2610), Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004) Source as of 2026-09-12
Build a risk-management system that monitors and responds to AI-related safety accidents involving your system.
South Korea AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems), Act No. 20676, Article 32 Source as of 2026-09-20
The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.
India Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025 Source as of 2026-08-29
Expect a fine for a substantive EU AI Act violation, such as a prohibited practice or a transparency failure, to be pursued in Germany through the same national administrative-offense procedure, at the amount the Regulation itself sets.
Germany Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 Source as of 2026-09-06
Where you process special category data, including biometric data, about an employee in Ireland, ground it in a legitimate argument tied to vital interests or another Article 9(2) condition with a public-interest character, and put suitable and specific safeguarding measures in place, under Data Protection Act 2018 Section 46.
Ireland GDPR Article 9 and Data Protection Act 2018 Section 46, Special Categories and Employment Biometric Data in Ireland, Regulation (EU) 2016/679, Art. 9; Data Protection Act 2018 §46 Source as of 2026-08-24
Expect CSIRT Italia to respond within 24 hours of your pre-notification with an initial assessment and, on request, guidance or technical support on mitigation measures.
Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification, D.Lgs. 4 settembre 2024, n. 138, Art. 25 Source as of 2026-09-12
Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.
Netherlands Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance, Cyberbeveiligingswet, Artt. 21 en 24 Source as of 2026-09-12
The alliance's words for the same ground

Safeguards. Were classifiers, policies, approvals and action limits operating as intended?

SAFE Review Framework, read 2026-09-20.

4 · The tools it can reach

Limits on what it may reach, send, spend or publish.

Every tool an AGENT holds reaches a different body of law. Credentials and access: NIS2 Directive, Cybersecurity Risk-Management Measures names access control and multi-factor authentication among its minimum measures. Getting past a barrier: Computer Fraud and Abuse Act (unauthorized access and the gates-based authorization test) is the United States example, and the corpus's scraping topic is largely this layer, one national computer-misuse statute at a time. Anything the AGENT sends reaches communications and marketing law; anything it spends reaches payments law.

This is the layer where an agentic system differs most from the software the statutes were written for. A tool list is a list of legal exposures, and the exposure attaches at the moment the tool is available rather than at the moment it is used: a capability the AGENT could reach without a second authorisation is one the OPERATOR has already granted.

271 requirement lines in force · 255 provisions · 162 jurisdictions · from: scraping 158 · privacy 69 · cybersecurity 62 · AI 3

The law behind the layer Show 7 of the 271 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Maintain basic cyber hygiene practices and cybersecurity training, policies on cryptography and encryption where appropriate, human resources security and access control, and multi-factor authentication or continuous authentication solutions where appropriate.
European Union NIS2 Directive, Cybersecurity Risk-Management Measures, Directive (EU) 2022/2555, Art. 21 Source as of 2026-09-08
Do not continue accessing a California site, or circumvent a technical block, after the operator has sent a cease-and-desist notice (Facebook v. Power Ventures, 9th Cir. 2016; Craigslist v. 3Taps, N.D. Cal. 2013).
Implement and maintain reasonable security procedures and practices, appropriate to the nature of the information and the nature and size of the business, to protect personal identifying information (a Social Security number, a personal identification number, a password or pass code, a state driver's license or identification card number, a government passport number, biometric data, an employer, student, or military identification number, or a financial transaction device) from unauthorized access, use, modification, disclosure, or destruction.
Colorado Protection of personal identifying information, reasonable security procedures duty, C.R.S. 6-1-713.5 (added by HB 18-1128, 2018 Colo. Sess. Laws ch. 266, section 2) Source as of 2026-09-12
Do not sell, lease, or disclose a captured biometric identifier except for the narrow statutory exceptions covering identification of a missing or deceased person, a requested financial transaction, legal compulsion, or a law enforcement warrant.
Texas Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149, Tex. Bus. & Com. Code sec. 503.001, as amended by Tex. HB 149, 89th Legislature (2025) Source as of 2026-08-23
Do not build, install, or distribute a tool whose purpose is to bypass a network's normal access-control or authentication procedures.
South Korea Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention), Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 21305, as amended), Art. 48 Source as of 2026-08-29
Ban universal default passwords and easily guessable passwords across the product's hardware and pre-installed or required software; a password must be unique per unit or set by the user, and must not be built from incremental counters or from publicly derivable identifiers.
United Kingdom Product Security Requirements for Connectable Products, Product Security and Telecommunications Infrastructure Act 2022, c. 46, Part 1; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007 Source as of 2026-09-12
Adopt technical and administrative security measures suited to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or improper processing, from the design of the product or service through its execution.
Brazil Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance) Source as of 2026-09-19
The alliance's words for the same ground

Tools. Were credentials, permissions, spending, publishing and execution constrained?

SAFE Review Framework, read 2026-09-20.

5 · The environment it runs in

Where the data may sit, and what it may touch.

Two questions live here: what the system may touch, and where the data may sit. The first is ordinary security law, stated as measures appropriate to the risk. The second is the transfer and localisation rules, which are the sharpest constraint on an agent's architecture that most teams meet: GDPR Chapter V, Cross-Border Transfer Restrictions conditions any movement of personal data out of the Union, and the rest of the corpus holds the same question answered differently in over a hundred places.

Localisation goes further than conditioning a transfer. CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation requires the logs an organisation is told to keep to be maintained within Indian jurisdiction, which is a duty about where a record lives rather than about what it says. An AGENT that moves work to whichever region has capacity is making a legal choice in a scheduler.

176 requirement lines in force · 173 provisions · 112 jurisdictions · from: privacy 151 · cybersecurity 48 · scraping 2

The law behind the layer Show 8 of the 176 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Maintain basic cyber hygiene practices and cybersecurity training, policies on cryptography and encryption where appropriate, human resources security and access control, and multi-factor authentication or continuous authentication solutions where appropriate.
European Union NIS2 Directive, Cybersecurity Risk-Management Measures, Directive (EU) 2022/2555, Art. 21 Source as of 2026-09-08
Transfer personal data outside Brazil only to a country or organization with an adequate level of protection, or under contractual clauses, corporate rules, or another article 33 safeguard.
Brazil LGPD, international transfer of data, Lei nº 13.709, de 2018 (LGPD), arts. 33-36 (international transfer of data) Source as of 2026-09-19
An app transferring the personal data of an individual in Vietnam, including biometric data, to a recipient outside the country must satisfy Article 20's cross-border transfer conditions; a violation risks a fine of up to 5 percent of the organization's prior-year revenue, a materially higher tier than the Law's general penalty.
Vietnam Law on Personal Data Protection, cross-border transfer, Law No. 91/2025/QH15, Article 20 Source as of 2026-08-29
Adopt technical and organisational measures adequate and proportionate to the risks facing the network and information systems you use to provide your services, and to minimise the impact of a security incident on your services and on others.
Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 Source as of 2026-09-12
Take appropriate and proportionate technical and organisational measures, having regard to the state of the art, to manage the risks to the network and information systems you use and to prevent or minimise the impact of an incident on the continuity of your service.
Ireland European Union (NIS) Regulations 2018, Security Requirements, S.I. No. 360/2018, Regs. 17 and 21 Source as of 2026-09-12
Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy.
Italy Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions, Garante Provvedimento n. 146 del 5 giugno 2019 Source as of 2026-08-24
Adopt technical and organisational measures, proportionate to the risk and reflecting the state of the art, to manage the risks to the networks and information systems you use to provide the service, even where that management is outsourced; as a digital service provider, address at minimum the security of your systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with relevant international standards.
Spain Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers, Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero Source as of 2026-09-12
Identify the risks that threaten the security of the networks and information systems you use to provide your services in the European Union, and take the necessary and proportionate technical and organisational measures to manage those risks, prevent an incident from compromising your networks and systems, and minimise its impact, so as to guarantee the continuity of your services.
France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements, Loi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 Source as of 2026-09-12
The alliance's words for the same ground

Environment. Were network paths, isolation, targets and data boundaries independently verified?

SAFE Review Framework, read 2026-09-20.

6 · What watches it

The duty to notice, and to be able to stop it.

The duty to notice is mostly a shadow of the duty to report. Very few instruments in the corpus tell an OPERATOR to watch a system in a particular way; a great many tell it to report inside a fixed number of hours from the moment it became aware, which is only possible if something was watching. NIS2 Directive, Reporting Obligations and Cyber Resilience Act, Manufacturer Reporting Obligations are the clearest European examples, the second with a 24-hour early warning, a 72-hour notification and a final report within fourteen days of a corrective measure becoming available.

Because the duty is stated as a deadline, the clocks are where it can be read properly, and they have a document of their own: Incident reporting clocks draws every reporting deadline in the corpus on one time axis, with the sentence each was read from.

89 requirement lines in force · 96 provisions · 81 jurisdictions · from: cybersecurity 53 · privacy 41 · AI 10 · scraping 3

The law behind the layer Show 7 of the 89 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing.
European Union General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 Source as of 2026-08-23
Build a risk-management system that monitors and responds to AI-related safety accidents involving your system.
South Korea AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems), Act No. 20676, Article 32 Source as of 2026-09-20
An app that collects or processes biometric data, meaning physical attributes and unique, stable biological characteristics used to identify a person, from an individual in Vietnam must apply physical security measures, limit access, and maintain a monitoring system to detect infringement, and is liable for damage its processing causes.
Vietnam Law on Personal Data Protection, biometric and location data protection, Law No. 91/2025/QH15, Article 31 Source as of 2026-08-29
Cover at least: risk analysis and information-security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluation of your measures' effectiveness; basic cyber-hygiene training; cryptography; personnel security and access control; and multi-factor or continuous authentication.
Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 Source as of 2026-09-12
As a relevant digital service provider, additionally take into account the security of your systems and facilities, incident handling, business continuity management, monitoring, auditing and testing, and compliance with international standards, and keep documentation sufficient for the competent authority to verify your compliance.
Ireland European Union (NIS) Regulations 2018, Security Requirements, S.I. No. 360/2018, Regs. 17 and 21 Source as of 2026-09-12
Expect AgID to handle AI innovation promotion and the notification, assessment, accreditation and monitoring of conformity-assessment bodies for AI systems placed on the Italian market.
Italy Legge 132/2025 Art. 20, National AI Authorities (AgID and ACN), Legge 23 settembre 2025, n. 132, art. 20 Source as of 2026-09-06
Adopt technical and organisational measures, proportionate to the risk and reflecting the state of the art, to manage the risks to the networks and information systems you use to provide the service, even where that management is outsourced; as a digital service provider, address at minimum the security of your systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with relevant international standards.
Spain Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers, Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero Source as of 2026-09-12
The alliance's words for the same ground

Monitoring. Could operators detect and interrupt unexpected behavior in real time?

SAFE Review Framework, read 2026-09-20.

7 · The people accountable

The named person a duty lands on.

The law asks for a person, by name or by role, more often than it asks for a mechanism. General Data Protection Regulation (GDPR), Comprehensive Regime requires controller and processor responsibilities allocated and documented in a written agreement, and a data protection officer where core activities involve large-scale monitoring or large-scale special-category processing. NIS2 Directive, Cybersecurity Risk-Management Measures puts the management body itself in the loop: it approves the risk-management measures, oversees their implementation and completes training, and an entity outside the Union offering a covered service inside it designates a representative in a member state.

Human oversight arrives through privacy law rather than through AI law in most of the corpus, as the right not to be subject to a solely automated decision and the review that follows from it. For an AGENT that acts between a decision and a person, the question is not whether a human is available somewhere but whether the person affected can reach one.

166 requirement lines in force · 171 provisions · 105 jurisdictions · from: privacy 136 · cybersecurity 27 · AI 18 · scraping 10

The law behind the layer Show 7 of the 166 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing.
European Union General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 Source as of 2026-08-23
Let a consumer opt out of your use of ADMT to make a significant decision about them, unless you offer an appeal to a human reviewer with authority to overturn the decision or another exception listed in the regulation applies
California CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 Source as of 2026-09-08
Before finalizing a solely automated decision producing legal or similarly significant effects for a person in the United Kingdom, inform them in advance, and provide a meaningful human review and a right to contest the decision on request, under UK GDPR Articles 22A to 22D.
United Kingdom Data (Use and Access) Act 2025 Section 80, Automated Decision-Making, UK GDPR Articles 22A-22D, Data (Use and Access) Act 2025, c. 18, §80 (new UK GDPR Arts. 22A-22D); S.I. 2026/425 Source as of 2026-08-24
Comply with an ANPD warning's corrective-measures deadline before facing escalation to a fine, publicity of the infraction, blocking or deletion of the data involved, or suspension of the processing activity.
Brazil LGPD, civil liability, administrative sanctions and the ANPD, Lei nº 13.709, de 2018 (LGPD), arts. 42-45, 52-54, 55-A a 58-B (civil liability, administrative sanctions and the ANPD) Source as of 2026-09-19
Designate a Point of Contact to interface with CERT-In, using the format CERT-In publishes, and keep that designation current.
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) Source as of 2026-09-12
Expect the Bundesnetzagentur to be Germany's central market surveillance authority, single point of contact, and central complaints office under the EU AI Act, unless your AI system is directly tied to a regulated financial activity that the Bundesanstalt für Finanzdienstleistungsaufsicht already supervises, in which case expect that authority instead.
Germany Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 Source as of 2026-09-06
Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Ireland, under GDPR Article 22.
Ireland GDPR Article 22, Automated Decision-Making in Ireland, Regulation (EU) 2016/679, Art. 22, as transposed by the Data Protection Act 2018 Source as of 2026-08-24
The alliance's words for the same ground

Human operations. Were responsibilities, escalation paths and kill procedures clear?

SAFE Review Framework, read 2026-09-20.

8 · What it is built from

Duties that follow the parts and the parties behind them.

What an AGENT is built from carries duties of its own. Processor arrangements are contractual by statute under General Data Protection Regulation (GDPR), Comprehensive Regime. Supply-chain security is one of the minimum measures of NIS2 Directive, Cybersecurity Risk-Management Measures. Cyber Resilience Act, Essential Requirements and Manufacturer Obligations (from 2027-12-11, not yet in effect) puts essential requirements on a product with digital elements and on the manufacturer behind it, which reaches software an agent is assembled from rather than the agent's own behaviour. And training data is a supply question before it is a model question, which is where DSM Directive, Article 4 (text-and-data-mining exception and rights reservation) sits.

What an open-source project owes the people who run it takes the other end of this layer: what a project that agents are built from owes the people who run it, and what it can usefully ship to reduce their exposure rather than its own.

382 requirement lines in force · 381 provisions · 184 jurisdictions · from: privacy 253 · cybersecurity 102 · AI 60 · scraping 31

The law behind the layer Show 7 of the 382 requirement lines in forceHide them

Drawn to span jurisdictions rather than to rank them. Each line is the corpus's own statement of the requirement, with the instrument it comes from, the page that carries the citation and the source, and the date the corpus read it.

If you are a Commission-designated very large online platform or very large online search engine, commission an independent audit, at your own expense and at least once a year, of your compliance with Chapter III's due diligence obligations, including the systemic-risk mitigation measures for generated and manipulated content, and with any codes of conduct or crisis protocols you have joined.
European Union Digital Services Act, Article 37 (independent audit of very large online platforms and search engines), Regulation (EU) 2022/2065, Article 37, supplemented by Commission Delegated Regulation (EU) 2024/436 Source as of 2026-09-15
Embed a latent disclosure of machine-readable provenance data in content the system creates
California California AI Transparency Act (SB 942, as amended by AB 853), Cal. Bus. and Prof. Code Sections 22757 to 22757.6 Source as of 2026-08-14
This binds any distributing party, not only the provider or deployer of the AI system
Colorado HB 24-1147, Candidate Election Deepfake Disclosures, C.R.S. 1-46-103 Source as of 2026-08-14
If you are a health care practitioner using AI for diagnostic purposes, including AI-generated recommendations on a diagnosis or course of treatment, stay within the scope of your license, do not use AI in a way state or federal law otherwise restricts, and review all AI-created records consistent with Texas Medical Board standards.
Texas S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records, Tex. Health & Safety Code § 183.005 Source as of 2026-09-06
Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under UK GDPR Article 82, but expect a UK representative claim to require proof of unlawful use and resulting damage for each individual claimant, not a bare loss-of-control theory, per Lloyd v Google.
United Kingdom UK GDPR Article 82, Data Protection Act 2018 Section 169, and ICO Enforcement, UK GDPR, Arts. 82-83; Data Protection Act 2018 §169 Source as of 2026-08-24
Transfer personal data outside Brazil only to a country or organization with an adequate level of protection, or under contractual clauses, corporate rules, or another article 33 safeguard.
Brazil LGPD, international transfer of data, Lei nº 13.709, de 2018 (LGPD), arts. 33-36 (international transfer of data) Source as of 2026-09-19
Embed synthetically generated information with permanent metadata or another technical provenance mechanism, including a unique identifier, to the extent technically feasible, and do not enable removal, suppression or modification of that label or metadata.
India Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026) Source as of 2026-09-07
The alliance's words for the same ground

Supply chain. Did a cloud, evaluation, data or tooling partner invalidate assumed controls?

SAFE Review Framework, read 2026-09-20.

4Where the law is quiet, and where we are

The distribution across the eight layers is itself a finding, and it runs the opposite way to most governance frameworks. The layer with the most binding law behind it is what it is built from (382 requirement lines in force across 184 jurisdictions). The layer with the least is the model itself (43). A framework has most to say about the model and the safeguards; statutes have most to say about the parties, the boundaries and the parts, because those are the things a legislature can name without describing an architecture.

There is also a gap on our side, and it belongs in the open. The corpus holds the EU AI Act as separate instruments per article, and the articles it holds are the transparency, logging, general-purpose and incident ones named above. The high-risk duties that would sit in this document's first and third layers, the risk-management system, data and data governance, human oversight, and accuracy, robustness and cybersecurity, are not in the corpus on the date in the byline. Four research requests were filed for them while this page was written, and the counts above do not include them. No figure on this page is adjusted for what is missing.

5What this document does not claim

It does not say that any layer is covered, or that a control satisfying one is compliant. The counts describe how much of a corpus of software law speaks to a layer, not how much of a layer is regulated: a single sentence in one statute can bind more of your system than forty lines elsewhere. The samples are samples, drawn to span jurisdictions rather than to rank them.

It also does not adopt anyone's framework. The alliance's review questions are quoted because a reader holding them should be able to find the same ground here, with the law underneath it. They are a proposal, they were open for comment when they were read, and they may be revised; the law they sit beside is dated on every line.