The sixteen themes, filled from binding law

About this documentUpdated 2026-09-18ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages.

Every law named here links to its summary page on lexlint.org, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text, the figures and the theme-register file are licensed under Creative Commons Attribution-NonCommercial 4.0: share and adapt them for noncommercial purposes with credit to LexLint (UnGovr). Please contact LexLint at hello@ungovr.org to discuss commercial use. Logos and wordmarks belong to their owners.

Corpus figures as of 2026-09-18.

The Agentic AI Foundation's governance working group is extracting requirements from frameworks under the sixteen themes below. This register runs the same extraction against statutes by jurisdiction instead: what the law already says under each theme, whom it binds, and where it reaches from, with the full register as a file.

1What this is

Agentic AI Foundation

The Agentic AI Foundation (AAIF), a Linux Foundation foundation, runs a Governance, Risk and Regulatory Alignment working group whose charter sets three deliverables: a landscape of agentic-AI policy frameworks, a gap analysis, and distilled recommendations. Its monthly reports record the method it chose: about a dozen common themes, and extraction prompts to map frameworks, standards and legislation onto them consistently. In August 2026 the group circulated a workbook to its members with sixteen such themes, each with an extraction prompt to be run against one framework document at a time, and a reference guide of thirty frameworks to run them against. The workbook is not public; the themes are summarised here in the group's own words.

The prompts share one contract: classify every provision by type, decompose compound statements into atomic requirements, keep the exact modal language, and record for each requirement an identifier, the text, the type, the obligation strength, the applicable entity, the source clause and a confidence. Two of the prompts' rules matter most: do not infer applicability beyond what the source states, and say "legal interpretation required" where legal analysis is needed.

The working group's sixteen themes Sixteen labelled cells, one per theme, each with its identifier and icon. Governance & Accountability: Ownership; approvals; RACI; risk acceptance; governance bodies; accountability structures. Use-case Classification & Risk Tiering: Allowed/prohibited uses; risk tiers; tiered controls; autonomy levels; classification criteria; re-classification triggers. Architecture: Reference patterns; trust boundaries; control placement; multi-agent topology; isolation; separation of concerns. Agent Identity & Delegation: AuthN/Z model; acting-on-behalf-of; agent registry; credential lifecycle; delegation scope; non-repudiation. Guardrails & Policy Constraints: Business rules; policy-as-code; content filters; hard stops; behavioral boundaries; policy enforcement points; constraint override. Data Protection & Privacy: Personal data; data minimization; retention; residency; consent; cross-border transfer; special category data; privacy-by-design. Security & Access Controls: Least privilege; secrets management; network segmentation; tool permissions; authentication; vulnerability management; capability confinement. Model/Agent Risk Management: Validation; robustness; drift monitoring; change control; benchmarking; bias/fairness; decommissioning; version control. Human Oversight: Human in or on the loop; escalation paths; human waterfall; override/kill switch; mandatory approval; supervision frequency; automated oversight. Action Management: Pre-execution checks; dual control; reversibility tiers; undo infrastructure; action scope limits; side-effect disclosure. Monitoring & Logging: Audit trails; prompt/tool logs; decision logs; log retention; log integrity; tamper-evidence; real-time alerting. Testing & Red Teaming: Prompt injection; tool abuse; autonomy failures; adversarial testing; pre-deployment testing; test coverage; remediation. Third-Party & Supply Chain: Vendor due diligence; model provenance; tool vetting; AI bill of materials; service levels; supply chain risk; third-party incident notification. Incident Response: Detection; containment; incident classification; regulatory notification; root cause analysis; recovery; post-incident review. Transparency & User Disclosure: AI disclosure; user notices; explanations; user expectations; consent; labeling; deception prohibition; capability limits. Recordkeeping & Auditability: Retention schedules; reproducibility; audit readiness; record integrity; regulatory reporting; archival; destruction. T01 Governance & Accountability T02 Use-case Classification & Risk Tiering T03 Architecture T04 Agent Identity & Delegation T05 Guardrails & Policy Constraints T06 Data Protection & Privacy T07 Security & Access Controls T08 Model/Agent Risk Management T09 Human Oversight T10 Action Management T11 Monitoring & Logging T12 Testing & Red Teaming T13 Third-Party & Supply Chain T14 Incident Response T15 Transparency & User Disclosure T16 Recordkeeping & Auditability
Figure 1. The sixteen themes, each with the icon this section uses for it.

This register runs the same contract against a different source. Instead of thirty frameworks, the input is binding law by jurisdiction: the requirement statements the LexLint software-law corpus carries for every AI, privacy, scraping and cybersecurity instrument it holds, each one already atomic, already tied to a citation, and already dated. The output keeps the group's columns and adds the two a statute needs that a framework does not: the party the duty is addressed to, and the territorial hook it reaches through. Where a requirement has been classified for what a runtime control can do about it, that tier is shown too.

The point of doing it is the one the group's own June 2026 report made: a gap analysis needs a baseline. A framework register says what good looks like. This register says what is already required, of whom, and where, so that the gap between the two can be measured rather than described.

2Method

Source. 4,756 requirement lines drawn from the LexLint software-law corpus on 2026-09-18, across the four topics that carry them: AI (1,006), privacy (1,791), scraping (1,139), cybersecurity (820). Of those, 3,979 belong to an instrument in force on that date; the rest are enacted but not yet commenced, and are kept in the register with their lifecycle band so a reader can see what is coming.

Theme membership. A line joins a theme when its instrument's obligation class is one the theme owns, or when the line's own wording matches the theme's rule. A line can sit in more than one theme, as the group's own prompts allow. The rules are deliberately generous, so a theme's count is an upper bound on what a careful reader would keep, and the thin themes are thin because the law says little there, not because the rule missed it.

Type and obligation strength. The group's six types are derived from the line's wording and, where one exists, from an independent hand classification of the same line (obligation, prohibition, scope condition, remedy note, permission). Two values the group's list lacks are added because the law needs them: a consequence (a penalty or remedy stated as a requirement line) and a permission or exemption. The modal language preserves the verbs the line uses, as the prompts' rule 3 asks.

Applicable entity. Read off the line's own wording where it names a role (provider, deployer, controller, processor, platform, employer, manufacturer). Where it names none, the entity is the OPERATOR, the party running the application, which is whom the LexLint software-law corpus binds by default.

Territorial hook. Derived from the instrument's topic and law family under a stated rule: a privacy duty reaches through the data subject's residence and the OPERATOR's establishment, a transfer duty through the destination, a scraping duty through the COUNTERPARTY's location, an AI transparency duty through where the output is used and the market it was placed on, a security duty through the OPERATOR's establishment or the placing on the market. The column is a rule applied to every line, and it is the first thing a reviewer should correct.

Party whose position triggers scope, and runtime tier. Both come from a separate hand classification of 2,589 of the lines, made for a study of what an AGENT gateway can enforce. The party is the one of six (OPERATOR, principal, provider, COUNTERPARTY, affected person, data subject) whose location or status the duty turns on; the tier says whether a control on the request path can prevent the conduct, detect it, evidence it, or never sees it. Lines the classification has not reached say so.

Line identifier. Every line carries an identifier of the form topic:instrument-code:position, which is the topic it was researched under, the instrument's code on lexlint.org, and the line's position in that instrument's requirement list. It is stable for as long as the wording is unchanged: a reworded line gets a new identity rather than a silent change under the old one. It appears at the end of each entry below and in the file, so that a row in the group's own register can cite one.

3The register in one table

One row per theme. "Lines" is every requirement line the theme's rule admits, in force or not; "in force" is the subset whose instrument binds today; "instruments" and "jurisdictions" count the distinct sources those lines come from. The last column says which of the four topics the lines were researched under, largest first, which is a fair proxy for which body of law a theme really lives in.

ThemeLinesIn forceInstrumentsJurisdictionsWhere the lines come from
T01 Governance & Accountability 163 137 137 98 cybersecurity 78 · privacy 54 · AI 24 · scraping 7
T02 Use-case Classification & Risk Tiering 521 456 258 149 AI 350 · privacy 88 · scraping 57 · cybersecurity 26
T03 Architecture 20 17 20 20 privacy 12 · AI 3 · cybersecurity 3 · scraping 2
T04 Agent Identity & Delegation 141 124 130 97 privacy 53 · cybersecurity 34 · AI 33 · scraping 21
T05 Guardrails & Policy Constraints 196 177 182 134 privacy 71 · AI 59 · scraping 40 · cybersecurity 26
T06 Data Protection & Privacy 1,907 1,611 1,014 246 privacy 1,400 · AI 173 · cybersecurity 168 · scraping 166
T07 Security & Access Controls 1,871 1,696 637 239 cybersecurity 777 · scraping 617 · privacy 457 · AI 20
T08 Model/Agent Risk Management 306 240 183 115 privacy 152 · AI 84 · cybersecurity 50 · scraping 20
T09 Human Oversight 82 71 80 67 privacy 45 · AI 18 · scraping 15 · cybersecurity 4
T10 Action Management 97 83 88 77 scraping 51 · privacy 30 · AI 12 · cybersecurity 4
T11 Monitoring & Logging 79 65 65 58 cybersecurity 39 · privacy 21 · AI 10 · scraping 9
T12 Testing & Red Teaming 9 9 8 7 cybersecurity 5 · AI 2 · privacy 1 · scraping 1
T13 Third-Party & Supply Chain 658 579 429 204 privacy 298 · scraping 172 · cybersecurity 95 · AI 93
T14 Incident Response 887 717 379 182 privacy 549 · cybersecurity 299 · AI 25 · scraping 14
T15 Transparency & User Disclosure 1,800 1,447 845 233 privacy 780 · AI 466 · cybersecurity 357 · scraping 197
T16 Recordkeeping & Auditability 1,546 1,290 574 222 cybersecurity 621 · privacy 489 · scraping 240 · AI 196

4What the distribution says

Four themes carry most of the binding law: data protection and privacy (1,611 lines in force), security and access controls (1,696), transparency and USER disclosure (1,447) and recordkeeping and auditability (1,290). These are the themes where a statute, rather than a framework, is the source of the requirement, and they are where a gap analysis against binding law will find the most to measure.

Three themes are thin, and the thinness is the finding. Architecture has 20 lines, testing and red teaming 9, monitoring and logging 79. Binding law rarely tells an OPERATOR how to structure a system, how to test it, or what to log in what format; it tells the OPERATOR what outcome to secure and what record to be able to produce. Those three themes are framework territory, and the frameworks in the group's reference guide are the right source for them. What a statute adds is the outcome the framework control has to serve, which is why the recordkeeping theme is large while the logging theme is small.

Use-case classification and risk tiering (521 lines) is dominated by prohibitions: the law's way of tiering is to name what may not be done at all. Human oversight (82) and action management (97) are small but spread across many jurisdictions (67 and 77 respectively), which is the pattern of a duty that arrives through privacy law's automated-decision rules rather than through an AI statute. Incident response (887) is almost entirely breach notification, the oldest and most uniform family in the LexLint software-law corpus.

5The sixteen themes

Each theme below quotes the group's own key concepts, gives the counts, and holds a sample of up to fourteen lines in force, drawn to span jurisdictions rather than to rank them, folded away until you open it. The requirement is stated first, as the LexLint software-law corpus records it; under it, the facts the group's columns ask for, then the jurisdiction, the instrument and its date, and the line identifier. The full register, every line in every theme, is the file in section 6.

T01 · Governance & Accountability

The group's key concepts: Ownership; approvals; RACI; risk acceptance; governance bodies; accountability structures

163 lines · 137 in force · 137 instruments · 98 jurisdictions · type: mandatory obligation 76, conditional obligation 52, consequence (penalty or remedy) 13, prohibition 6, definition 6, permission or exemption 5, recommendation/guidance 5

Sample requirement lines Show 13 of the 137 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Adopt and follow a copyright policy that respects TDM opt-outs
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Counterparty Hook Establishment of the operator; placing on the market; where the output is used Runtime Enforceable at a runtime control
European Union AI Act, Article 53 (obligations for providers of general-purpose AI models), Regulation (EU) 2024/1689, Article 53 as of 2026-08-15 ai:eu-2024-1689-53:1
If you use an internal auditor, have the highest-ranking auditor report to, and have their performance evaluation and compensation determined by, a member of executive management who does not have direct responsibility for the cybersecurity program.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Residence of the data subject; establishment of the operator Runtime not classified
California CCPA Cybersecurity Audit Regulations, Cal. Code Regs. tit. 11, Sections 7120 to 7124 as of 2026-09-15 privacy:us-ca-cal-regs-tit-11-sections-7120-7124:2
Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Colorado HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) as of 2026-08-23 privacy:us-co-c-r-s-sections-6-1-1303-2-2-2-4-6-1-1314-2:1
You must provide an easily accessible system for a depicted person to request removal, and a clear, plain-language notice describing that process and your responsibilities under it.
Type Mandatory Obligation Modal must Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Texas S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009 as of 2026-09-06 ai:us-tx-tex-civ-prac-rem-98b-0021-98b-009:3
Publish a clear support policy stating how long and in what circumstances you will provide security updates, and provide security updates free of charge for at least 2 years after the product's launch or for as long as you keep distributing it to consumers, whichever period is longer.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market Runtime not classified
Brazil Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment), Ato nº 2.436, de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019 as of 2026-09-14 security:br-ato-n-2-436-de-7-de-mar-o-de-2023-superintend:4
The Data Protection Board of India exists, is administratively operational, and its jurisdiction ousts the civil courts over matters within its remit, but its penalty Schedule, complaint, and appeal machinery has not yet commenced and is scheduled for 13 May 2027, and no provision of the Act as read gives the Board power to award compensation to an individual complainant. Once fully in force, an app processing Indian personal data, including biometric identifiers, will answer only to the Board; India's DPDPA arms no private plaintiff, and a data principal who misuses their own rights under the Act, for example by impersonation or a frivolous complaint, risks a penalty of their own under section 15.
Type Consequence (penalty or remedy) Modal may Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
India Digital Personal Data Protection Act, 2023, Data Protection Board and penalties, Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39 as of 2026-08-29 privacy:in-digital-personal-data-protection-2023-dpdpa-d:0
Cover at least: risk analysis and information-security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluation of your measures' effectiveness; basic cyber-hygiene training; cryptography; personnel security and access control; and multi-factor or continuous authentication.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities, BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38 as of 2026-09-12 security:de-bsi-gesetz-bsig-vom-2-dezember-2025-28-30-38:2
If your AI service can be accessed by a minor under fourteen, obtain the consent of whoever holds parental responsibility before processing their personal data; a minor between fourteen and eighteen may consent alone if the required information is easily accessible and understandable (art. 4).
Type Conditional Obligation Modal may Binds Operator (the party running the application) Scope turns on Principal Hook Establishment of the operator; placing on the market; where the output is used Runtime Enforceable at a runtime control
Italy Legge 132/2025, Sector Human-Oversight and Disclosure Duties (Artt. 4, 11, 13), Legge 23 settembre 2025, n. 132, artt. 4, 11, 13 as of 2026-09-06 ai:it-l-132-2025-sector-oversight-disclosure:0
If designated an operator of essential services, designate a responsable de la seguridad de la informacion within three months of your designation, notify the competent authority of the appointment, and file a Declaracion de Aplicabilidad of the security measures you apply within six months of designation, reviewing it at least every three years.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Spain Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers, Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero as of 2026-09-12 security:es-rdl-12-2018-art16-seguridad:2
Where you are instead designated as an operator of essential services, apply the security rules the Premier ministre sets under Article 6 at your own expense, covering governance, protection, defence and resilience of your networks and systems.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements, Loi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 as of 2026-09-12 security:fr-loi-n-2018-133-du-26-f-vrier-2018-titre-ier-c:3
Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.
Type Conditional Obligation Modal where applicable Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Netherlands Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance, Cyberbeveiligingswet, Artt. 21 en 24 as of 2026-09-12 security:nl-cyberbeveiligingswet-artt-21-en-24:2
An app processing the personal data of a person in Japan must be prepared to answer to the Personal Information Protection Commission's investigative, recommendation, and order powers, and a responsible individual risks criminal liability for violating a PPC order; Japan has no APPI-specific private right of action, so an aggrieved person's civil remedy runs through general tort law instead.
Type Consequence (penalty or remedy) Modal must Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
Japan Act on the Protection of Personal Information, enforcement, Act No. 57 of 2003, as amended by Act No. 37 of 2021, Chapters VI, VIII as of 2026-08-29 privacy:jp-no-57-2003-as-amended-by-no-37-2021-chapters:0
If you were responsible for creating or altering the non-consensual material yourself, or if you have 3 or more prior civil penalty orders for failing to comply with an Online Safety Act 2021 removal notice, you face a higher maximum penalty than a person who merely transmits such material.
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
Australia Using a Carriage Service to Transmit Sexual Material Without Consent (Deepfake Offences), Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth), No. 78, 2024, inserting ss. 474.17A, 474.17AA into the Criminal Code Act 1995 (Cth), No. 12, 1995 as of 2026-09-06 ai:au-criminal-amendment-deepfake-sexual-material-2:2

124 more lines in force under this theme, and 163 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T02 · Use-case Classification & Risk Tiering

The group's key concepts: Allowed/prohibited uses; risk tiers; tiered controls; autonomy levels; classification criteria; re-classification triggers

521 lines · 456 in force · 258 instruments · 149 jurisdictions · type: prohibition 230, conditional obligation 91, mandatory obligation 69, consequence (penalty or remedy) 52, permission or exemption 45, definition 34

Sample requirement lines Show 13 of the 456 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

If your high-risk AI system is placed on the EU market and you are its provider, report any serious incident to the market surveillance authority of the Member State where the incident occurred.
Type Conditional Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
European Union AI Act, Article 73 (reporting of serious incidents), Regulation (EU) 2024/1689, Article 73 as of 2026-09-18 ai:eu-2024-1689-73:0
Disclose that the media has been manipulated when you distribute materially deceptive audio or visual election media depicting a candidate within 60 days of an election
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
California AB 730, as extended by AB 972, election deepfake disclosure law, Cal. Elec. Code Section 20010 as of 2026-08-14 ai:us-ca-cal-elec-20010:0
Do not develop or deploy an AI system that intentionally aims to incite or encourage physical self-harm, harm to another person, or criminal activity.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Texas TRAIGA (H.B. 149, 2025), prohibited AI practices binding any person, Tex. Bus. & Com. Code §§ 552.052, 552.055-552.057 as of 2026-09-06 ai:us-tx-tex-bus-com-552-052-552-055-552-057:0
Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.
Type Conditional Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
United Kingdom UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom, UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025 as of 2026-08-24 privacy:gb-uk-gdpr-33-34-privacy-electronic-communicatio:1
Do not use fabricated or manipulated content in electoral advertising to spread notoriously untrue or gravely decontextualized facts capable of harming the balance of the election or the integrity of the electoral process.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Brazil TSE Resolution, Prohibition on Electoral Deepfakes, Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-c-reda-o-dada-pe:0
Classify your AI system's risk level (high, medium, or low) before putting it into service, based on its potential impact on rights, safety, security, and public interest, and the scale and context of its use.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Vietnam Law on Artificial Intelligence, risk classification and conformity assessment, Law No. 134/2025/QH15, arts. 9-10, 13-14 as of 2026-09-06 ai:vn-no-134-2025-qh15-9-10-13-14:0
Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Germany Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:1
Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Ireland GDPR Articles 33-34, Breach Notification in Ireland, Regulation (EU) 2016/679, Arts. 33-34 as of 2026-08-24 privacy:ie-eu-2016-679-33-34:1
Notify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Italy GDPR Articles 33-34, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34 as of 2026-08-24 privacy:it-eu-2016-679-33-34:0
Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Spain GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s) as of 2026-08-24 privacy:es-eu-2016-679-33-34-lopdgdd-69-73-r-s:0
Do not create or share, by any means, a non-consensual sexual montage, or a non-consensual, algorithmically generated sexual image, video, or audio reproducing a real person's likeness or voice; France punishes this with two years' imprisonment and a 60,000 euro fine.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
France Code Penal Article 226-8-1, Non-Consensual Sexual Montage and Algorithmically Generated Sexual Content, Code penal, art. 226-8-1, insere par la loi n. 2024-449 du 21 mai 2024 visant a securiser et a reguler l'espace numerique (SREN), art. 21 as of 2026-09-06 ai:fr-penal-226-8-1-insere-par-la-loi-n-2024-449-du:0
Notify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception.
Type Conditional Obligation Modal subject to Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Netherlands GDPR Articles 33-34 and UAVG Article 42, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42 as of 2026-08-24 privacy:nl-eu-2016-679-33-34-uavg-42:0
Do not use a carriage service to transmit material that depicts, or appears to depict, a person aged 18 or over in a sexual pose or sexual activity, or their sexual organ, anal region, or, for a female, breasts, without that person's consent, knowing of the lack of consent or reckless as to it.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Australia Using a Carriage Service to Transmit Sexual Material Without Consent (Deepfake Offences), Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth), No. 78, 2024, inserting ss. 474.17A, 474.17AA into the Criminal Code Act 1995 (Cth), No. 12, 1995 as of 2026-09-06 ai:au-criminal-amendment-deepfake-sexual-material-2:0

443 more lines in force under this theme, and 521 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T03 · Architecture

The group's key concepts: Reference patterns; trust boundaries; control placement; multi-agent topology; isolation; separation of concerns

20 lines · 17 in force · 20 instruments · 20 jurisdictions · type: prohibition 8, mandatory obligation 5, conditional obligation 4, recommendation/guidance 1, consequence (penalty or remedy) 1, definition 1

Sample requirement lines Show 14 of the 17 lines in forceHide the sample

What follows is a sample of 14 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

For a user you know is a minor, disclose that they are interacting with artificial intelligence, and provide a clear and conspicuous break reminder by default at least every three hours during continuing interactions
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
California Companion Chatbot Safety and Accountability Act (SB 243), Cal. Bus. and Prof. Code Sections 22601 to 22606 as of 2026-09-08 ai:us-ca-cal-bus-prof-sections-22601-22606:2
Failing to make this report is itself an offence: a fine of up to two hundred thousand shillings, imprisonment of up to two years, or both; the Committee may separately propose isolating a suspected system pending resolution.
Type Mandatory Obligation Modal may Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market; establishment of the manufacturer Runtime not classified
Kenya Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat, Computer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40 as of 2026-09-14 security:ke-computer-misuse-cybercrimes-no-5-2018-s-40:3
An app that negligently fails to implement reasonable security practices for personal data of a person in Bhutan, including a biometric identifier, and thereby causes wrongful loss or gain, is liable to pay court-determined compensation to the victim, and unlawfully disclosing another's personal data without consent is a separate offence under section 388.
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
Bhutan Information, Communications and Media Act of Bhutan 2018, offences and compensation for data failures, Information, Communications and Media Act of Bhutan 2018, ss.387-388 as of 2026-09-02 privacy:bt-information-communications-media-bhutan-201-4:0
Apply privacy by design and by default, including techniques such as differential privacy, so that data used to train an artificial intelligence system does not allow the person who provided it to be identified.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Colombia Superintendencia Circular on AI and Personal Data, SIC Circular Externa 002 de 2024 (Lineamientos sobre Tratamiento de Datos Personales en Sistemas de Inteligencia Artificial), 21 de agosto de 2024 as of 2026-09-05 privacy:co-sic-circular-externa-002-de-2024-lineamientos:2
Where your online service is aimed at children, build in technical measures protecting their data and privacy by design, write information for them in terms they can understand, and keep advertising and marketing clearly distinct from content, never inciting a child to buy goods or enter into an online contract.
Type Conditional Obligation Modal never Binds Platform or intermediary Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Gabon Loi n°001/2011 relative à la protection des données à caractère personnel, modifiée par la loi n°025/2023, Loi n°001/2011 du 25 septembre 2011 relative à la protection des données à caractère personnel, telle que modifiée et complétée par la loi n°025/2023 du 9 juillet 2023, Journal Officiel n°218 bis du 15 juillet 2023 as of 2026-09-04 privacy:ga-loi-n-001-2011-du-25-septembre-2011-relative:6
This binds an essential entity or an important entity drawn from Annex I (high-criticality sectors) or Annex II (other critical sectors), which the law's own table of contents captions as corresponding directly to NIS2 Directive Annexes I and II; Annex II's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform (each a defined term in Article 6), reached at the medium-enterprise threshold of Commission Recommendation 2003/361/EC or above (Article 3(1)); the wider sector classes Annexes I and II reach by designation (energy, transport, banking, health, drinking water, public administration and the rest) are not expressed in this vocabulary and are not raised here on that account.
Type Mandatory Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Greece Law 5160/2024, Cybersecurity Risk-Management Measures and Governance, Law 5160/2024 (Ν. 5160/2024), Arts. 14-15 as of 2026-09-15 security:gr-law-5160-2024-arts-14-15:0
An app that processes biometric data for the digital identification of a Kyrgyzstani data subject, including a voiceprint or faceprint, must satisfy one of Art. 80(2)'s narrow lawful grounds before processing; such processing is prohibited by default otherwise. The Code itself supplies no illustrative list of biometric modalities for this general provision.
Type Prohibition Modal must Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Kyrgyzstan Digital Code, special categories of personal data, Digital Code, Law No. 178, Art. 80 as of 2026-08-29 privacy:kg-digital-no-178-80:0
An app transferring the personal data of a Mongolian data subject, including a voiceprint or other biometric identifier, to a person, legal entity, or organization in another country must have a statutory basis, an applicable international treaty, or the subject's consent; transfer is prohibited by default otherwise, and Mongolia imposes no separate domestic-storage requirement on the underlying data.
Type Prohibition Modal must Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Mongolia Law on Protection of Personal Data, cross-border transfer, Law on Protection of Personal Data (17 December 2021), Art. 14 as of 2026-08-29 privacy:mn-protection-personal-data-17-december-2021-14:0
An app that collects, uses, or discloses the personal data of an individual in Oman must treat that processing as covered by the Personal Data Protection Law by default, unless it falls within one of Article 3's enumerated exclusions such as publicly available data collected lawfully.
Type Definition Modal must, unless Binds Operator (the party running the application) Scope turns on not classified Hook Residence of the data subject; establishment of the operator Runtime not classified
Oman Personal Data Protection Law, comprehensive regime and scope, Royal Decree No. 6/2022, Arts. 3-4, 7 as of 2026-08-29 privacy:om-royal-decree-no-6-2022-3-4-7:0
Do not produce, obtain, sell, or supply a device, computer program, password, or access code adapted to commit an Art. 267, 268a, 269, or 269a offense; doing so is a separate offense under Art. 269b carrying imprisonment up to 5 years, unless you act solely to secure a system or to develop a securing method.
Type Prohibition Modal do not, unless Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Outside any runtime path
Poland Kodeks karny, Unauthorized Access to Information and Computer-Misuse Offenses, Ustawa z dnia 6 czerwca 1997 r. Kodeks karny (Dz.U. 1997 nr 88 poz. 553, tekst jednolity), art. 267-269c as of 2026-09-06 scraping:pl-ustawa-z-dnia-6-czerwca-1997-r-kodeks-karny-2:1
Treat biometric-data processing in Slovenia as prohibited by default under ZVOP-2 Article 81 unless another Slovenian law both authorizes it and sets its conditions of use; a bare GDPR Article 9(2) basis alone is not sufficient in this jurisdiction.
Type Prohibition Modal unless Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Slovenia ZVOP-2 Chapter 4 (Articles 81-84) and Article 80, Biometric and Genetic Data, ZVOP-2, Arts. 80-84, 105 as of 2026-08-24 privacy:si-zvop-2-80-84-105:0
An app that collects, uses, or discloses the personal data of an individual in Thailand must obtain consent by default before processing, unless a Section 24 statutory exception applies.
Type Conditional Obligation Modal must, unless Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Enforceable at a runtime control
Thailand Personal Data Protection Act, comprehensive regime, Personal Data Protection Act B.E. 2562 (2019), Government Gazette Vol. 136, Special Issue 69 Kor, fully enforceable 2022-06-01 as of 2026-08-29 privacy:th-personal-data-protection-b-e-2562-2019-govern:0
An app storing or processing the personal data of individuals in Tajikistan, including a voiceprint or other biometric identifier, must by default keep the database exclusively inside Tajikistan, unless it has an arrangement agreed with the authorized state body for personal data protection. Transferring that data abroad separately requires the subject's consent, a ratified treaty, statutory necessity, or protection of constitutional rights where consent cannot be obtained.
Type Conditional Obligation Modal must, unless Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Tajikistan Law on the Protection of Personal Data, localization and cross-border transfer, Law No. 1537 (3 August 2018), Art. 14; Art. 18 as of 2026-08-29 privacy:tj-no-1537-3-august-2018-14-18:0
An app processing a Turkmen data subject's nationality, skin color, religious attitude, political conviction, health, or intimate-life data must have the subject's written consent, rely on publicly available data, or fall within a narrow list of justice, health, or membership-organization exceptions; such processing is prohibited by default otherwise.
Type Prohibition Modal must Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Turkmenistan Law on Information About Private Life, special categories of personal information, Law No. 519-V (20 March 2017), Art. 21 as of 2026-08-29 privacy:tm-no-519-v-20-march-2017-21:0

3 more lines in force under this theme, and 20 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T04 · Agent Identity & Delegation

The group's key concepts: AuthN/Z model; acting-on-behalf-of; agent registry; credential lifecycle; delegation scope; non-repudiation

141 lines · 124 in force · 130 instruments · 97 jurisdictions · type: prohibition 39, mandatory obligation 37, conditional obligation 30, definition 16, consequence (penalty or remedy) 13, permission or exemption 6

Sample requirement lines Show 13 of the 124 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Maintain basic cyber hygiene practices and cybersecurity training, policies on cryptography and encryption where appropriate, human resources security and access control, and multi-factor authentication or continuous authentication solutions where appropriate.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator (entity in scope) Runtime Outside any runtime path
European Union NIS2 Directive, Cybersecurity Risk-Management Measures, Directive (EU) 2022/2555, Art. 21 as of 2026-09-08 security:eu-2022-2555-21:2
The prohibition reaches using a bot to mislead a Californian about its artificial identity in order to incentivize a commercial transaction or influence a vote
Type Prohibition Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
California Bolstering Online Transparency Act (SB 1001), Cal. Bus. and Prof. Code Sections 17940 to 17943 as of 2026-08-14 ai:us-ca-cal-bus-prof-sections-17940-17943:1
Do not develop or distribute an AI system with the sole intent of producing or distributing AI-generated child pornography or deepfake sexually explicit media, or that engages in text-based sexual conversation while impersonating a child younger than 18.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Texas TRAIGA (H.B. 149, 2025), prohibited AI practices binding any person, Tex. Bus. & Com. Code §§ 552.052, 552.055-552.057 as of 2026-09-06 ai:us-tx-tex-bus-com-552-052-552-055-552-057:3
Do not build, install, or distribute a tool whose purpose is to bypass a network's normal access-control or authentication procedures.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Operator Hook Location of the counterparty's machine Runtime Outside any runtime path
South Korea Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention), Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 21305, as amended), Art. 48 as of 2026-08-29 scraping:kr-promotion-information-communications-network:1
This duty does not reach ordinary image- or sound-quality adjustments, graphic identity elements, or customary campaign marketing techniques such as composite photos.
Type Permission or exemption Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Where the output is used; placing on the market Runtime not classified
Brazil TSE Resolution, AI-Generated Content Disclosure Duty, Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-b-reda-o-dada-pe:2
The Data Protection Board of India exists, is administratively operational, and its jurisdiction ousts the civil courts over matters within its remit, but its penalty Schedule, complaint, and appeal machinery has not yet commenced and is scheduled for 13 May 2027, and no provision of the Act as read gives the Board power to award compensation to an individual complainant. Once fully in force, an app processing Indian personal data, including biometric identifiers, will answer only to the Board; India's DPDPA arms no private plaintiff, and a data principal who misuses their own rights under the Act, for example by impersonation or a frivolous complaint, risks a penalty of their own under section 15.
Type Consequence (penalty or remedy) Modal may Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
India Digital Personal Data Protection Act, 2023, Data Protection Board and penalties, Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39 as of 2026-08-29 privacy:in-digital-personal-data-protection-2023-dpdpa-d:0
Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82, and expect a qualifying consumer-protection association to be able to bring a representative claim on behalf of a group of affected consumers under the VDuG.
Type Consequence (penalty or remedy) Modal imperative Binds Controller (the party that decides why and how personal data is processed) Scope turns on not classified Hook Establishment of the operator Runtime not classified
Germany GDPR Article 82, BDSG Sections 41-43, and BfDI and Landesdatenschutzbehorden Enforcement in Germany, Regulation (EU) 2016/679, Arts. 82-83; Bundesdatenschutzgesetz (BDSG) §§41-43 as of 2026-09-02 privacy:de-eu-2016-679-82-83-bundesdatenschutzgesetz-bds:1
Do not distribute, publish or threaten to distribute or publish an intimate image of another person without that person's consent, with intent to cause harm or being reckless as to whether harm is caused, including an image that only purports to be that person's intimate depiction, such as an AI-generated or digitally altered synthetic image (s. 2).
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Ireland Harassment, Harmful Communications and Related Offences Act 2020, Intimate Image Offences, Harassment, Harmful Communications and Related Offences Act 2020 (No. 32 of 2020), ss. 1-3 as of 2026-09-06 ai:ie-harassment-harmful-communications-2020-ss-2-3:0
A contract clause purporting to override these database-right rules is void.
Type Definition Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook The counterparty's establishment (rightsholder) Runtime not classified
Italy Legge sul Diritto d'Autore Artt. 102-bis and 102-ter, Sui Generis Database Right, Legge 22 aprile 1941, n. 633, artt. 102-bis, 102-ter, inserted by Decreto Legislativo 6 maggio 1999, n. 169 as of 2026-09-06 scraping:it-lda-102bis-102ter-database-right:2
Do not circumvent a technical security measure, such as authentication, to access an information system without authorization; Article 197 bis does not reach access to a page that carries no such measure.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Spain Codigo Penal Article 197 bis, Unauthorized Access to an Information System, Ley Organica 10/1995, de 23 de noviembre, del Codigo Penal, art. 197 bis, added by Ley Organica 1/2015, de 30 de marzo, art. unico.107 (BOE-A-1995-25444, BOE-A-2015-3439) as of 2026-09-02 scraping:es-codigo-penal-lo-10-1995-197-bis:0
Rely only on an authentication-or-security purpose, or another GDPR Article 9(2) basis, before processing biometric data of a person in the Netherlands for unique identification; UAVG Article 29's exception reaches no broader purpose on its face.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Netherlands UAVG Article 29, Biometric-Data Exception for Authentication or Security, UAVG, Art. 29 as of 2026-08-24 privacy:nl-uavg-29:0
A contract term purporting to exclude or restrict this computational data analysis exception is void and does not bind the app.
Type Permission or exemption Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook The counterparty's establishment (rightsholder); where the copy is made Runtime not classified
Singapore Copyright Act, Computational Data Analysis Exception and Non-Override Rule, Copyright Act 2021, ss. 243-244 and s. 187 (Computational Data Analysis Exception) as of 2026-09-07 scraping:sg-copyright-2021-ss-243-244-s-187-computational:1
Do not assume New York law clears a faceprint or voiceprint you extract from a recording to authenticate or ascertain identity. SHIELD's biometric-information trigger carries no recording-derived exclusion, so an extracted identifier plausibly falls within it if a later breach exposes it, though this reading is untested in New York case law or Attorney General guidance.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on not classified Hook Residence of the affected person Runtime not classified
New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty, N.Y. Gen. Bus. Law § 899-aa as of 2026-08-27 privacy:us-ny-n-y-gen-bus-899-aa:2

111 more lines in force under this theme, and 141 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T05 · Guardrails & Policy Constraints

The group's key concepts: Business rules; policy-as-code; content filters; hard stops; behavioral boundaries; PEP; constraint override

196 lines · 177 in force · 182 instruments · 134 jurisdictions · type: prohibition 101, mandatory obligation 54, conditional obligation 23, definition 9, consequence (penalty or remedy) 5, permission or exemption 3, recommendation/guidance 1

Sample requirement lines Show 13 of the 177 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Do not continue accessing a California site, or circumvent a technical block, after the operator has sent a cease-and-desist notice (Facebook v. Power Ventures, 9th Cir. 2016; Craigslist v. 3Taps, N.D. Cal. 2013).
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
California Comprehensive Computer Data Access and Fraud Act (unauthorized access, broader than the federal without-authorization test), Cal. Penal Code § 502 as of 2026-08-29 scraping:us-ca-cal-penal-502:0
Do not create a deep fake video and cause it to be published or distributed within 30 days of an election, if you intend to injure a candidate or influence the election's result.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Texas Political deep fake video ban (originally S.B. 751, 2019), Tex. Elec. Code § 255.004(d)-(e) as of 2026-09-06 ai:us-tx-tex-elec-255-004-d-e:0
An app processing Korean personal data must be able to answer to the PIPC for its lawful basis and safeguards, and an individual harmed by a security failure may bring a private civil claim for statutory damages, or damages up to five times the actual loss, without needing to prove the controller's negligence.
Type Consequence (penalty or remedy) Modal must, may Binds Controller (the party that decides why and how personal data is processed) Scope turns on not classified Hook Establishment of the operator Runtime not classified
South Korea Personal Information Protection Act, enforcement and private civil remedy, Act No. 10465 (as amended by Act No. 19234, 2023), Arts. 39, 39-2, 51, 64-2 as of 2026-09-02 privacy:kr-no-10465-as-amended-by-no-19234-2023-39-39-2:0
Before moving personal data of a person in the United Kingdom outside the UK, either rely on a UK adequacy regulation, put appropriate safeguards in place such as the ICO's International Data Transfer Agreement or Addendum, or rely on a narrow Article 49 derogation, under UK GDPR Article 44A.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
United Kingdom UK GDPR Articles 44A-50, Cross-Border Transfer of Personal Data from the United Kingdom, UK GDPR, Arts. 44A-50, as amended by the Data (Use and Access) Act 2025 as of 2026-08-24 privacy:gb-uk-gdpr-44a-50-as-amended-by-data-use-access:0
Do not generate or digitally manipulate synthetic audio, video, or combined audio-video content to create, replace, or alter a living, deceased, or fictitious person's image or voice, even with that person's authorization, to harm or benefit a candidacy.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Brazil TSE Resolution, Prohibition on Electoral Deepfakes, Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-c-reda-o-dada-pe:1
The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.
Type Definition Modal may, must Binds Operator (the party running the application) Scope turns on not classified Hook Residence of the data subject; establishment of the operator Runtime not classified
India Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025 as of 2026-08-29 privacy:in-g-s-r-846-e-digital-personal-data-protection:0
Do not produce, obtain, sell, or distribute passwords, security codes, or software designed to commit these offences.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Outside any runtime path
Germany Ausspaehen, Abfangen und Manipulation von Daten (Computer Misuse and Data Interference), Strafgesetzbuch (StGB), §§ 202a, 202b, 202c, 202d, 303a, 303b as of 2026-09-06 scraping:de-strafgesetzbuch-stgb-202a-202b-202c-202d-303a:2
Where you process special category data, including biometric data, about an employee in Ireland, ground it in a legitimate argument tied to vital interests or another Article 9(2) condition with a public-interest character, and put suitable and specific safeguarding measures in place, under Data Protection Act 2018 Section 46.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Ireland GDPR Article 9 and Data Protection Act 2018 Section 46, Special Categories and Employment Biometric Data in Ireland, Regulation (EU) 2016/679, Art. 9; Data Protection Act 2018 §46 as of 2026-08-24 privacy:ie-eu-2016-679-9-data-protection-2018-46:0
Do not create or share, by any means, a non-consensual sexual montage, or a non-consensual, algorithmically generated sexual image, video, or audio reproducing a real person's likeness or voice; France punishes this with two years' imprisonment and a 60,000 euro fine.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
France Code Penal Article 226-8-1, Non-Consensual Sexual Montage and Algorithmically Generated Sexual Content, Code penal, art. 226-8-1, insere par la loi n. 2024-449 du 21 mai 2024 visant a securiser et a reguler l'espace numerique (SREN), art. 21 as of 2026-09-06 ai:fr-penal-226-8-1-insere-par-la-loi-n-2024-449-du:0
Do not produce, distribute, offer, publicly display, import, export, acquire, or possess a sexual image of a person who apparently has not yet reached the age of eighteen, whether or not that person is real; a computer-generated or synthetic depiction is reached on the same terms as a real one.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Netherlands Wetboek van Strafrecht, art. 252, Sexual Imagery of an Apparent Minor (Virtual Child Sexual Abuse Material), Wetboek van Strafrecht, art. 252 (until 1 July 2024: art. 240b) (BWBR0001854) as of 2026-09-06 ai:nl-wetboek-van-strafrecht-252-voorheen-240b:0
Report any breach of security safeguards involving personal information under the organization's control to the Privacy Commissioner as soon as feasible, if it is reasonable to believe the breach creates a real risk of significant harm to an individual.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Canada PIPEDA breach of security safeguards regime, S.C. 2000, c. 5, ss. 10.1-10.3 as of 2026-09-02 privacy:ca-s-c-2000-c-5-ss-10-1-10-3:0
Do not continue accessing a New York-connected system, or circumvent a technical security measure, after the operator has given you actual notice, including a cease-and-desist letter, that your access is unwanted; this statute treats notice alone as sufficient to convert continued access into unauthorized access, without needing a technical block.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
New York New York Computer Trespass, notice-based revocation and circumvention presumption, N.Y. Penal Law §§ 156.00, 156.05, 156.10 as of 2026-08-29 scraping:us-ny-n-y-penal-156-00-156-05-156-10:0
Give the Data Commissioner proof of appropriate safeguards, or otherwise satisfy a condition under section 48, before transferring personal data outside Kenya.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Kenya Data Protection Act, 2019, transfer of personal data outside Kenya, Data Protection Act, 2019 (No. 24 of 2019), Part VI (ss. 48-54) as of 2026-09-04 privacy:ke-data-protection-2019-no-24-2019-part-vi-ss-48:0

164 more lines in force under this theme, and 196 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T06 · Data Protection & Privacy

The group's key concepts: PII; data minimization; retention; residency; consent; cross-border transfer; special category data; privacy-by-design

1,907 lines · 1,611 in force · 1,014 instruments · 246 jurisdictions · type: mandatory obligation 852, prohibition 387, conditional obligation 322, definition 171, consequence (penalty or remedy) 120, permission or exemption 49, recommendation/guidance 6

Sample requirement lines Show 13 of the 1,611 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
European Union General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 as of 2026-08-23 privacy:eu-2016-679:0
If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
California CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0
If you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Colorado C.R.S. 6-1-716, Notification of Security Breach, C.R.S. section 6-1-716 as of 2026-08-23 privacy:us-co-c-r-s-6-1-716:0
A person depicted in artificial intimate visual material, produced or disclosed without their consent and with intent to harm them, can sue the creator, solicitor, discloser, or promoter for damages if the material reveals their identity.
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
Texas S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009 as of 2026-09-06 ai:us-tx-tex-civ-prac-rem-98b-0021-98b-009:0
An app transferring the personal data of a Korean data subject to a recipient outside South Korea must obtain the data subject's separate consent, or rely on a qualifying treaty, PIPC certification, or PIPC adequacy recognition instead.
Type Conditional Obligation Modal subject to, must Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
South Korea Personal Information Protection Act, cross-border transfer restrictions, Act No. 10465 (as amended by Act No. 19234, 2023), Art. 28-8(1), Arts. 28-8 to 28-11 as of 2026-08-23 privacy:kr-no-10465-as-amended-by-no-19234-2023-17-3-28:0
Do not intentionally create an image that appears to be an intimate photograph or film of another adult without that adult's consent.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
United Kingdom Creating, or Requesting the Creation of, Purported Intimate Image of Adult, Data (Use and Access) Act 2025, c. 18, s. 138, inserting ss. 66E-66H into the Sexual Offences Act 2003 as of 2026-09-06 ai:gb-data-use-access-2025-c-18-ss-138-66e-66h-sexu:0
Establish a lawful basis under article 7 before processing personal data, including data the person has made public.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Brazil Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD) as of 2026-09-05 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:0
The Data Protection Board of India exists, is administratively operational, and its jurisdiction ousts the civil courts over matters within its remit, but its penalty Schedule, complaint, and appeal machinery has not yet commenced and is scheduled for 13 May 2027, and no provision of the Act as read gives the Board power to award compensation to an individual complainant. Once fully in force, an app processing Indian personal data, including biometric identifiers, will answer only to the Board; India's DPDPA arms no private plaintiff, and a data principal who misuses their own rights under the Act, for example by impersonation or a frivolous complaint, risks a penalty of their own under section 15.
Type Consequence (penalty or remedy) Modal may Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
India Digital Personal Data Protection Act, 2023, Data Protection Board and penalties, Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39 as of 2026-08-29 privacy:in-digital-personal-data-protection-2023-dpdpa-d:0
Do not collect, process, or use data to develop, train, test, or operate an AI system in violation of Vietnam's data, personal data protection, intellectual property, or cybersecurity law.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Data subject Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Vietnam Law on Artificial Intelligence, prohibited practices, Law No. 134/2025/QH15, art. 7 as of 2026-09-06 ai:vn-no-134-2025-qh15-7:2
Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Germany.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Germany Bundesdatenschutzgesetz (BDSG), Federal Data Protection Act, Bundesdatenschutzgesetz (BDSG), BGBl. I S. 2097 (2017), as amended as of 2026-08-24 privacy:de-bundesdatenschutzgesetz-bdsg-bgbl-i-s-2097-20:0
Do not distribute, publish or threaten to distribute or publish an intimate image of another person without that person's consent, with intent to cause harm or being reckless as to whether harm is caused, including an image that only purports to be that person's intimate depiction, such as an AI-generated or digitally altered synthetic image (s. 2).
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Ireland Harassment, Harmful Communications and Related Offences Act 2020, Intimate Image Offences, Harassment, Harmful Communications and Related Offences Act 2020 (No. 32 of 2020), ss. 1-3 as of 2026-09-06 ai:ie-harassment-harmful-communications-2020-ss-2-3:0
Do not transfer, publish, or otherwise disseminate a falsified or altered image, video, or voice recording generated using an AI system, capable of misleading others as to its genuineness, without the depicted or recorded person's consent.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Italy Codice Penale Art. 612-quater, Illicit Dissemination of AI-Generated or AI-Altered Content, Codice Penale, art. 612-quater, inserted by Legge 23 settembre 2025, n. 132, art. 26, comma 1, lettera c) as of 2026-09-06 ai:it-cp-612quater-ai-deepfake-dissemination:0
Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Spain outside the EEA, and check whether LOPDGDD Articles 41-43 require AEPD authorization or prior notice for the specific transfer.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Spain LOPDGDD Titulo VI, International Transfers, Layered on GDPR Chapter V, Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l) as of 2026-08-24 privacy:es-eu-2016-679-44-49-83-5-lopdgdd-40-43-72-1-l:0

1,598 more lines in force under this theme, and 1,907 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T07 · Security & Access Controls

The group's key concepts: Least privilege; secrets management; network segmentation; tool permissions; authentication; vulnerability management; capability confinement

1,871 lines · 1,696 in force · 637 instruments · 239 jurisdictions · type: mandatory obligation 754, prohibition 540, conditional obligation 351, permission or exemption 89, definition 70, consequence (penalty or remedy) 60, recommendation/guidance 7

Sample requirement lines Show 13 of the 1,696 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
European Union General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 as of 2026-08-23 privacy:eu-2016-679:0
If your app is a for-profit business meeting the CCPA's revenue or data-volume threshold and it determines the purposes and means of processing a California consumer's personal information, honor the CCPA/CPRA's notice, opt-out, and non-discrimination duties before collecting, selling, or sharing that data.
Type Definition Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
California California Consumer Privacy Act, as amended by the California Privacy Rights Act (Proposition 24), Cal. Civ. Code section 1798.100 et seq. (CCPA, as amended by the CPRA) as of 2026-08-23 privacy:us-ca-cal-civ-1798-100-et-seq-ccpa-as-amended-by:0
Do not access a Colorado-connected computer without authorization, or beyond the scope of granted authorization, to collect data; this statute's language closely tracks the federal CFAA rather than a broader state standard.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Colorado Colorado Cybercrime statute (unauthorized access, tracking the federal CFAA), C.R.S. § 18-5.5-102 as of 2026-08-29 scraping:us-co-c-r-s-18-5-5-102:0
This chapter applies only to a business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information, as those terms are defined by Section 521.002.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market Runtime not classified
Texas Cybersecurity Program safe harbor from exemplary damages (S.B. 2610), Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004) as of 2026-09-12 security:us-tx-tex-bus-com-ch-542-secs-542-001-542-004:0
Do not access an information and communications network without authorization, or beyond the scope of granted authorization, to collect data.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
South Korea Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention), Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (Act No. 21305, as amended), Art. 48 as of 2026-08-29 scraping:kr-promotion-information-communications-network:0
Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
United Kingdom UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0
Do not generate or digitally manipulate synthetic audio, video, or combined audio-video content to create, replace, or alter a living, deceased, or fictitious person's image or voice, even with that person's authorization, to harm or benefit a candidacy.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Brazil TSE Resolution, Prohibition on Electoral Deepfakes, Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-c-reda-o-dada-pe:1
Get the rights holder's authorisation before reproducing or reusing copyrighted material, including a copyrighted database or compilation, to train an AI model; the fair-dealing exceptions do not name text-and-data-mining or AI training as a covered purpose.
Type Mandatory Obligation Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook The counterparty's establishment (rightsholder); where the copy is made Runtime Enforceable at a runtime control
India Copyright Act, No Text-and-Data-Mining Exception, Database Compilations, and Technological Protection Measures, Copyright Act, 1957 (No. 14 of 1957), ss. 2(o), 51, 52, 63, 65A as of 2026-09-07 scraping:in-copyright-1957-no-14-1957-ss-2-o-51-52-63-65a:0
An app that collects or processes biometric data, meaning physical attributes and unique, stable biological characteristics used to identify a person, from an individual in Vietnam must apply physical security measures, limit access, and maintain a monitoring system to detect infringement, and is liable for damage its processing causes.
Type Mandatory Obligation Modal must Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Vietnam Law on Personal Data Protection, biometric and location data protection, Law No. 91/2025/QH15, Article 31 as of 2026-08-29 privacy:vn-no-91-2025-qh15-31:0
Where you deploy a biometric time clock, access control system, or voice-authentication system for employees in Germany, satisfy BDSG Section 26(3)'s conditions rather than relying on employee consent as the sole basis.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Germany GDPR Article 9 and BDSG Section 26(3), Special Categories and Employment Biometric Data in Germany, Regulation (EU) 2016/679, Art. 9; Bundesdatenschutzgesetz (BDSG) §26(3) as of 2026-08-24 privacy:de-eu-2016-679-9-bundesdatenschutzgesetz-bdsg-26:0
Do not knowingly give false or misleading information to an adjudicator, or disclose confidential material relevant to an adjudicator's finding without authorisation (ss. 95, 104).
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Ireland Regulation of Artificial Intelligence Act 2026, Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026) as of 2026-09-06 ai:ie-regulation-of-artificial-intelligence-2026:2
Apply Provvedimento 146/2019's security measures (documented access controls, encryption or pseudonymization, controlled transmission) before processing genetic data of a person in Italy.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Italy Garante Provvedimento n. 146/2019, Genetic, Health, and Biometric Data Prescriptions, Garante Provvedimento n. 146 del 5 giugno 2019 as of 2026-08-24 privacy:it-garante-provvedimento-n-146-del-5-giugno-2019:0
Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Spain outside the EEA, and check whether LOPDGDD Articles 41-43 require AEPD authorization or prior notice for the specific transfer.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Spain LOPDGDD Titulo VI, International Transfers, Layered on GDPR Chapter V, Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l) as of 2026-08-24 privacy:es-eu-2016-679-44-49-83-5-lopdgdd-40-43-72-1-l:0

1,683 more lines in force under this theme, and 1,871 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T08 · Model/Agent Risk Management

The group's key concepts: Validation; robustness; drift monitoring; change control; benchmarking; bias/fairness; decommissioning; version control

306 lines · 240 in force · 183 instruments · 115 jurisdictions · type: mandatory obligation 149, conditional obligation 79, prohibition 38, definition 20, consequence (penalty or remedy) 10, permission or exemption 8, recommendation/guidance 2

Sample requirement lines Show 13 of the 240 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

This is one listed risk-mitigation measure for a Commission-designated very large online platform or search engine, not a freestanding labeling mandate on every provider
Type Definition Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Where the output is used; placing on the market Runtime not classified
European Union Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking), Regulation (EU) 2022/2065, Article 35(1)(k) as of 2026-08-14 ai:eu-2022-2065-35-1-k:0
If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
California CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0
Do not develop or deploy an AI system with intent to unlawfully discriminate against a protected class; a disparate impact alone is not enough to show that intent.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Texas TRAIGA (H.B. 149, 2025), prohibited AI practices binding any person, Tex. Bus. & Com. Code §§ 552.052, 552.055-552.057 as of 2026-09-06 ai:us-tx-tex-bus-com-552-052-552-055-552-057:2
Document a balancing assessment showing your interest clearly overrides the affected individuals' rights, and adopt the named technical and procedural safeguards, including a disclosure, impact assessment, and an erasure or objection mechanism.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Location of the counterparty (site, machine, rightsholder) Runtime Outside any runtime path
South Korea Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline, Personal Information Protection Act (Act No. 18972, as amended), Art. 15(1)(vi); PIPC Guideline for Personal Data Processing for the Development and Utilization of Generative AI (issued 2024-07-18) as of 2026-08-29 scraping:kr-personal-information-protection-no-18972-as-a:2
Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
United Kingdom UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0
Demonstrate this compliance to Anatel's conformity-assessment agent when you seek homologação for the device, or by presenting your own Cybersecurity Policy showing you meet the full set of supplier requirements; Anatel can suspend a homologação it already granted if it later finds a security flaw or vulnerability, and a suspended homologação bars the product from being distributed in the Brazilian market until the problem is fixed.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market Runtime not classified
Brazil Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment), Ato nº 2.436, de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019 as of 2026-09-14 security:br-ato-n-2-436-de-7-de-mar-o-de-2023-superintend:7
Classify your AI system's risk level (high, medium, or low) before putting it into service, based on its potential impact on rights, safety, security, and public interest, and the scale and context of its use.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Vietnam Law on Artificial Intelligence, risk classification and conformity assessment, Law No. 134/2025/QH15, arts. 9-10, 13-14 as of 2026-09-06 ai:vn-no-134-2025-qh15-9-10-13-14:0
Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Germany Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:1
Establish a lawful basis before collecting or otherwise using personal data, including publicly accessible personal data, to train an AI model on people in Ireland, and account for the purpose the person originally made that data public for, not only whether it was public.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Ireland DPC Guidance: AI, Large Language Models and Data Protection, Data Protection Commission, "AI, Large Language Models and Data Protection" guidance (18 July 2024) as of 2026-08-24 privacy:ie-data-protection-commission-ai-large-language:0
Expect AgID to handle AI innovation promotion and the notification, assessment, accreditation and monitoring of conformity-assessment bodies for AI systems placed on the Italian market.
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
Italy Legge 132/2025 Art. 20, National AI Authorities (AgID and ACN), Legge 23 settembre 2025, n. 132, art. 20 as of 2026-09-06 ai:it-l-132-2025-agid-acn-national-authorities:0
Do not extract or reuse the whole, or a substantial part evaluated qualitatively or quantitatively, of a database that reflects a substantial investment by its maker, absent authorization or a statutory exception, per TRLPI Article 133.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook The counterparty's establishment (rightsholder) Runtime Enforceable at a runtime control
Spain TRLPI Articles 133 to 137, Sui Generis Database Right, Real Decreto Legislativo 1/1996 (TRLPI), arts. 133-137, added by Ley 5/1998, de 6 de marzo (BOE-A-1996-8930, BOE-A-1998-5568) as of 2026-09-02 scraping:es-trlpi-133-137:0
Run a data protection impact assessment and document why a less intrusive alternative was rejected before deploying a biometric access-control system for employees or building access in France.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
France CNIL Standard Regulation on Workplace Biometric Access Control (Deliberation No. 2019-001), CNIL Deliberation n. 2019-001 du 10 janvier 2019 portant reglement type relatif a la mise en oeuvre de dispositifs de controle d'acces biometrique as of 2026-08-24 privacy:fr-cnil-deliberation-n-2019-001-du-10-janvier-20:0
Absent that safe harbor, develop, implement, and maintain a data security program with reasonable administrative safeguards (a designated coordinator, a risk assessment, employee training, vetted service-provider contracts, and periodic adjustment), reasonable technical safeguards (assessing network and software design risk, detecting and responding to attacks, and testing controls), and reasonable physical safeguards (securing storage and disposal and limiting access during and after collection).
Type Mandatory Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator; placing on the market Runtime not classified
New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty, N.Y. Gen. Bus. Law section 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), section 4) as of 2026-09-12 security:us-ny-n-y-gen-bus-899-bb:1

227 more lines in force under this theme, and 306 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T09 · Human Oversight

The group's key concepts: HITL/HOTL; escalation paths; human waterfall; override/kill switch; mandatory approval; supervision frequency; automated oversight

82 lines · 71 in force · 80 instruments · 67 jurisdictions · type: mandatory obligation 47, prohibition 15, conditional obligation 9, definition 5, consequence (penalty or remedy) 4, permission or exemption 1, recommendation/guidance 1

Sample requirement lines Show 14 of the 71 lines in forceHide the sample

What follows is a sample of 14 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in the EU.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
European Union GDPR Articles 12-22, Data Subject Rights, Regulation (EU) 2016/679, Arts. 12-22 as of 2026-08-23 privacy:eu-2016-679-12-22:1
Let a consumer opt out of your use of ADMT to make a significant decision about them, unless you offer an appeal to a human reviewer with authority to overturn the decision or another exception listed in the regulation applies
Type Conditional Obligation Modal unless Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Enforceable at a runtime control
California CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:1
Document a balancing assessment showing your interest clearly overrides the affected individuals' rights, and adopt the named technical and procedural safeguards, including a disclosure, impact assessment, and an erasure or objection mechanism.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Location of the counterparty (site, machine, rightsholder) Runtime Outside any runtime path
South Korea Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline, Personal Information Protection Act (Act No. 18972, as amended), Art. 15(1)(vi); PIPC Guideline for Personal Data Processing for the Development and Utilization of Generative AI (issued 2024-07-18) as of 2026-08-29 scraping:kr-personal-information-protection-no-18972-as-a:2
Before finalizing a solely automated decision producing legal or similarly significant effects for a person in the United Kingdom, inform them in advance, and provide a meaningful human review and a right to contest the decision on request, under UK GDPR Articles 22A to 22D.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
United Kingdom Data (Use and Access) Act 2025 Section 80, Automated Decision-Making, UK GDPR Articles 22A-22D, Data (Use and Access) Act 2025, c. 18, §80 (new UK GDPR Arts. 22A-22D); S.I. 2026/425 as of 2026-08-24 privacy:gb-data-use-access-2025-c-18-80-new-uk-gdpr-22a:0
Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Germany, including a credit score generated for a third party's determinative use, under GDPR Article 22 and BDSG Section 31.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
Germany GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany, Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37 as of 2026-08-24 privacy:de-eu-2016-679-22-bundesdatenschutzgesetz-bdsg-3:1
Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Ireland, under GDPR Article 22.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
Ireland GDPR Article 22, Automated Decision-Making in Ireland, Regulation (EU) 2016/679, Art. 22, as transposed by the Data Protection Act 2018 as of 2026-08-24 privacy:ie-eu-2016-679-22-as-transposed-by-data-protecti:1
Give a person in Italy a path to obtain human intervention, express their view, and contest a decision made solely by automated processing that produces a legal or similarly significant effect on them.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Outside any runtime path
Italy GDPR Article 22 and the Garante's OpenAI/ChatGPT Enforcement, Regulation (EU) 2016/679, Art. 22; Garante Provvedimento 30 marzo 2023 as of 2026-08-24 privacy:it-eu-2016-679-22-garante-provvedimento-30-marzo:0
Give a person in France a path to obtain human intervention, express their view, and contest a decision made solely by automated processing, including profiling, that produces a legal or similarly significant effect on them.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Outside any runtime path
France GDPR Article 22, Right Against Automated Individual Decision-Making, Regulation (EU) 2016/679, Art. 22 as of 2026-08-24 privacy:fr-eu-2016-679-22:0
Give a person in the Netherlands a path to obtain human intervention, express their view, and contest a decision made solely by automated processing that produces a legal or similarly significant effect on them, subject to UAVG Article 40's exceptions.
Type Conditional Obligation Modal subject to Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Outside any runtime path
Netherlands GDPR and UAVG Articles 40-43, Data-Subject Rights and Journalistic Exception, Regulation (EU) 2016/679, Arts. 12-23; UAVG, Arts. 40, 41, 43 as of 2026-08-24 privacy:nl-eu-2016-679-12-23-uavg-40-41-43:0
This binds any person, including a natural person, a corporation, another legal entity, a unit of local government, or the State of Illinois or one of its agencies, that disposes of materials containing personal information about an Illinois resident, except a financial institution regulated under Gramm-Leach-Bliley Act Title V or a person subject to the disposal rule at 15 U.S.C. 1681w.
Type Conditional Obligation Modal subject to Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market Runtime not classified
Illinois Personal Information Protection Act, safe disposal of personal information, 815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01) as of 2026-09-14 security:us-il-815-ilcs-530-40-disposal-materials-contain:0
Do not deploy an autonomous lethal capability that decides without human supervision and can cause physical harm or affect life or physical integrity in a civilian setting.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Peru Reglamento de la Ley 31814, prohibited AI uses, Decreto Supremo 115-2025-PCM, arts. 22-23 (Reglamento de la Ley 31814, Clasificación de Riesgos: Uso Indebido) as of 2026-09-05 ai:pe-decreto-supremo-115-2025-pcm-22-23-reglamento:1
Do not obstruct or interrupt a network or information system, or delete, damage, alter, or make inaccessible data within one, without authorization.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Andorra Penal Code, Attacks on Information Systems, Codi penal, Llei 9/2005, del 21 de febrer, qualificada del Codi penal, as consolidated, art. 225 (Atacs contra els sistemes d'informació) as of 2026-09-05 scraping:ad-codi-penal-llei-9-2005-del-21-de-febrer-quali:1
An app that is a controller or processor established in or targeting the DIFC free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier used to uniquely identify a natural person, including one derived from a photo, video, or audio recording.
Type Mandatory Obligation Modal must Binds Controller (the party that decides why and how personal data is processed) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Enforceable at a runtime control
United Arab Emirates DIFC Data Protection Law, comprehensive regime, DIFC Law No. 5 of 2020 as of 2026-08-29 privacy:ae-difc-no-5-2020:0
Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Austria, under GDPR Article 22 and DSG Sections 42 to 45.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
Austria GDPR Article 22 and DSG Sections 42-45, Automated Decision-Making in Austria, Regulation (EU) 2016/679, Art. 22; Datenschutzgesetz (DSG) §§42-45 as of 2026-08-24 privacy:at-eu-2016-679-22-datenschutzgesetz-dsg-42-45:1

57 more lines in force under this theme, and 82 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T10 · Action Management

The group's key concepts: Pre-execution checks; dual control; reversibility tiers; undo infrastructure; action scope limits; side-effect disclosure

97 lines · 83 in force · 88 instruments · 77 jurisdictions · type: prohibition 36, mandatory obligation 23, conditional obligation 17, permission or exemption 9, consequence (penalty or remedy) 7, definition 5

Sample requirement lines Show 13 of the 83 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Report immediately, and not later than 2 days after becoming aware of it, a widespread infringement or a serious incident causing a serious and irreversible disruption to the management or operation of critical infrastructure.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
European Union AI Act, Article 73 (reporting of serious incidents), Regulation (EU) 2024/1689, Article 73 as of 2026-09-18 ai:eu-2024-1689-73:2
Post training-data documentation on your website before making a generative AI system publicly available to Californians, and again before any substantial modification
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Provider Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
California Generative AI Training Data Transparency Act (AB 2013), Cal. Civ. Code Sections 3110 and 3111 as of 2026-08-14 ai:us-ca-cal-civ-sections-3110-3111:0
If you are a health care practitioner using AI for diagnostic purposes, including AI-generated recommendations on a diagnosis or course of treatment, stay within the scope of your license, do not use AI in a way state or federal law otherwise restricts, and review all AI-created records consistent with Texas Medical Board standards.
Type Conditional Obligation Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Texas S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records, Tex. Health & Safety Code § 183.005 as of 2026-09-06 ai:us-tx-tex-health-safety-183-005:0
Once access is without authorization or exceeds authorization, copying, transmitting, or disclosing computer data you accessed that way falls within this statute's plain text.
Type Prohibition Modal imperative Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Utah Utah Computer Crimes Act (unauthorized access, with an express implied-consent definition), Utah Code Ann. §§ 76-6-702, 76-6-703 as of 2026-08-29 scraping:us-ut-utah-ann-76-6-702-76-6-703:1
A quotation from a lawfully disclosed work may be made without the author's consent or payment if the author's name and the source are stated and the quotation follows proper practice and does not exceed what its purpose justifies.
Type Permission or exemption Modal may Binds Operator (the party running the application) Scope turns on not classified Hook The counterparty's establishment (rightsholder); where the copy is made Runtime not classified
Peru Decreto Legislativo 822, quotation exception, Decreto Legislativo 822, art. 44 (quotation exception), Ley sobre el Derecho de Autor, as consolidated to Decreto Legislativo 1391 (2018) as of 2026-09-05 scraping:pe-decreto-legislativo-822-44-quotation-exceptio:0
Obtain a data subject's consent before any direct marketing activity, before processing sensitive personal data, before further processing that is incompatible with the original purpose, before processing a child's personal data, before transferring personal data to a country the Commission has not made an adequacy decision for, and before making a decision based solely on automated processing that produces legal effects concerning or significantly affects the data subject.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Enforceable at a runtime control
Nigeria Nigeria Data Protection Act, 2023 (NDPA), general data protection duties, Nigeria Data Protection Act, 2023 (No. 37 of 2023) as of 2026-09-05 privacy:ng-nigeria-data-protection-2023-no-37-2023:0
This duty reaches your service where you employ 50 or more people, or your annual turnover or annual balance sheet total exceeds ten million euros, and you fall within an Annex I essential-entity sector (energy, transport, banking, financial-market infrastructure, health, water, digital infrastructure, public administration) or an Annex II important-entity sector, which names providers of online marketplaces, online search engines and social networking services platforms among Andorra's digital service providers.
Type Conditional Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Andorra Llei 22/2022, Cybersecurity Risk-Management Obligations, Llei 22/2022, del 9 de juny, arts. 12, 13, 17 i 18 as of 2026-09-18 security:ad-llei-22-2022-del-9-de-juny-12-13-17-i-18:0
Do not access a computer system or data of restricted access without due authorization, or by exceeding the authorization held.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Argentina Código Penal, art. 153 bis, unauthorized access to a restricted computer system or data, Código Penal (Ley 11.179, texto ordenado), art. 153 bis, incorporated by Ley N° 26.388 (B.O. 25/6/2008) as of 2026-09-05 scraping:ar-c-digo-penal-153-bis-incorporated-by-ley-n-26:0
Do not exceed your own access rights to a computer system with a fraudulent intent or an intent to harm.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Belgium Code pénal, Livre II, articles 524 à 527, accès non autorisé dans un système informatique, Code pénal, Livre II, arts. 524-527 (accès non autorisé dans un système informatique), inséré par la loi du 29 février 2024 introduisant le livre II du Code pénal; peines fixées au Livre Ier, art. 36 et 38 as of 2026-09-06 scraping:be-penal-livre-ii-524-527-acces-non-autorise-dan:1
Obtain a person's prior consent before sending them unsolicited direct-marketing communications of any kind, inform them before their data is first used for that purpose, and let them withdraw consent at any time.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Enforceable at a runtime control
Burkina Faso Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel, Loi n°001-2021/AN du 30 mars 2021 portant protection des personnes à l'égard du traitement des données à caractère personnel as of 2026-09-04 privacy:bf-loi-n-001-2021-du-30-mars-2021-portant-protec:4
An app processing the personal data of an individual in Bahrain without the required lawful basis, prior authorisation, or transfer safeguard risks both criminal penalties (imprisonment and fines up to BD 20,000) and administrative penalties (up to BD 20,000, plus a daily compliance penalty on repeat violation) from the Personal Data Protection Authority, and a data subject who suffers damage from unlawful processing may separately claim compensation directly from the app under Art. 57.
Type Consequence (penalty or remedy) Modal may Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
Bahrain Personal Data Protection Law, enforcement and penalties, Law No. 30 of 2018, Arts. 55, 57-60 as of 2026-09-02 privacy:bh-no-30-2018-55-57-60:0
Do not access, or remain present in, a computer system without right; the penalty escalates where the access or presence is aggravated by fraudulent intent, exceeds an authorized level of access, results in data being suppressed or modified, or is committed in violation of the system's security measures.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Benin Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybercriminalité), atteintes aux réseaux et systèmes d'information, Loi n°2017-20 du 20 avril 2018, Livre VI, Atteintes aux Réseaux et Systèmes d'Information, portant Code du Numérique en République du Bénin as of 2026-09-04 scraping:bj-loi-n-2017-20-du-20-avril-2018-livre-vi-attei:0
Do not access a computer system of another person without authorisation, in excess of authorisation, or by infringing a security measure, and do not continue to exceed authorised access once it is withdrawn.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Belize Cybercrime Act, illegal access to a computer system, Cybercrime Act, Cap. 106:01 (Act No. 32 of 2020), s. 3 as of 2026-09-05 scraping:bz-cybercrime-cap-106-01-s-3-illegal-access-comp:0

70 more lines in force under this theme, and 97 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T11 · Monitoring & Logging

The group's key concepts: Audit trails; prompt/tool logs; decision logs; log retention; log integrity; tamper-evidence; real-time alerting

79 lines · 65 in force · 65 instruments · 58 jurisdictions · type: mandatory obligation 39, conditional obligation 21, prohibition 11, definition 4, consequence (penalty or remedy) 2, permission or exemption 2

Sample requirement lines Show 13 of the 65 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing.
Type Conditional Obligation Modal imperative Binds Controller (the party that decides why and how personal data is processed) Scope turns on Operator Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
European Union General Data Protection Regulation (GDPR), Comprehensive Regime, Regulation (EU) 2016/679 as of 2026-08-23 privacy:eu-2016-679:1
Inform an individual and obtain consent before capturing their retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry for a commercial purpose in Texas.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Texas Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149, Tex. Bus. & Com. Code sec. 503.001, as amended by Tex. HB 149, 89th Legislature (2025) as of 2026-08-23 privacy:us-tx-tex-bus-com-sec-503-001-as-amended-by-tex:0
Connect all your ICT systems' clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to an NTP server traceable to one of them, and ensure any other time source you use does not deviate from NPL or NIC.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market; establishment of the manufacturer Runtime not classified
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation, Directions under section 70B(6) of the Information Technology Act, 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022) as of 2026-09-12 security:in-directions-under-70b-6-information-technology:1
An app that collects or processes biometric data, meaning physical attributes and unique, stable biological characteristics used to identify a person, from an individual in Vietnam must apply physical security measures, limit access, and maintain a monitoring system to detect infringement, and is liable for damage its processing causes.
Type Mandatory Obligation Modal must Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Vietnam Law on Personal Data Protection, biometric and location data protection, Law No. 91/2025/QH15, Article 31 as of 2026-08-29 privacy:vn-no-91-2025-qh15-31:0
As a relevant digital service provider, additionally take into account the security of your systems and facilities, incident handling, business continuity management, monitoring, auditing and testing, and compliance with international standards, and keep documentation sufficient for the competent authority to verify your compliance.
Type Mandatory Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Ireland European Union (NIS) Regulations 2018, Security Requirements, S.I. No. 360/2018, Regs. 17 and 21 as of 2026-09-12 security:ie-s-i-no-360-2018-regs-17-21:2
Expect AgID to handle AI innovation promotion and the notification, assessment, accreditation and monitoring of conformity-assessment bodies for AI systems placed on the Italian market.
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
Italy Legge 132/2025 Art. 20, National AI Authorities (AgID and ACN), Legge 23 settembre 2025, n. 132, art. 20 as of 2026-09-06 ai:it-l-132-2025-agid-acn-national-authorities:0
Adopt technical and organisational measures, proportionate to the risk and reflecting the state of the art, to manage the risks to the networks and information systems you use to provide the service, even where that management is outsourced; as a digital service provider, address at minimum the security of your systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with relevant international standards.
Type Conditional Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Spain Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers, Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de informacion, art. 16, developed by Real Decreto 43/2021, de 26 de enero as of 2026-09-12 security:es-rdl-12-2018-art16-seguridad:1
Cover each of: the security of your systems and installations; incident management; business-continuity management; monitoring, audit and control; and compliance with international standards.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements, Loi n° 2018-133 du 26 février 2018, Titre Ier, Chapitres II et III, art. 5, 6, 10, 11 et 12 as of 2026-09-12 security:fr-loi-n-2018-133-du-26-f-vrier-2018-titre-ier-c:2
After any access gained that way, do not copy, tap, or record the data stored on, processed by, or transferred through that system.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Netherlands Wetboek van Strafrecht, art. 138ab, Computervredebreuk (Computer Trespass), Wetboek van Strafrecht, art. 138ab (BWBR0001854) as of 2026-09-06 scraping:nl-wetboek-van-strafrecht-138ab-computervredebre:1
Where a third party is contracted to dispose of the materials, require it to implement and monitor policies and procedures that prohibit unauthorized access to, acquisition of, or use of personal information during collection, transportation, and disposal.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market Runtime not classified
Illinois Personal Information Protection Act, safe disposal of personal information, 815 ILCS 530/40 (P.A. 97-483, eff. 2012-01-01) as of 2026-09-14 security:us-il-815-ilcs-530-40-disposal-materials-contain:2
Report a significant or substantial cybersecurity incident to AKSK and the relevant CSIRTs, and inform the public or affected users where the incident reaches them; cooperate with AKSK and other operators in sharing cybersecurity threat, vulnerability and incident information. AKSK's own incident categorisation and log retention regulations set the reporting clock and severity thresholds that apply to your designated category.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Albania Law No. 25/2024, On Cybersecurity, Law No. 25/2024 (Ligj Nr. 25/2024), 21 March 2024, "Për sigurinë kibernetike" ("On Cybersecurity"), Fletorja Zyrtare No. 67/2024, p. 7767 as of 2026-09-18 security:al-ligj-25-2024-siguria-kibernetike:2
On an attack, computer theft or any computer incident, disseminate alerts and warnings; the text does not state to whom or within what deadline (Article 15(2)).
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market; establishment of the manufacturer Runtime not classified
Angola Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination Duties, Lei n.º 7/17, Artigos 15.º, 16.º, 40.º e 41.º as of 2026-09-18 security:ao-lei-7-17-arts-15-16-40-41:2
As a digital service provider, cover at minimum the security of your systems and facilities, incident handling, business-continuity management, monitoring, review and testing, and compliance with relevant international standards.
Type Mandatory Obligation Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Austria Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers, NISG, BGBl. I Nr. 111/2018, §§ 17 und 21 as of 2026-09-14 security:at-nisg-bgbl-i-nr-111-2018-17-und-21:2

52 more lines in force under this theme, and 79 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T12 · Testing & Red Teaming

The group's key concepts: Prompt injection; tool abuse; autonomy failures; adversarial testing; pre-deployment testing; test coverage; remediation

9 lines · 9 in force · 8 instruments · 7 jurisdictions · type: conditional obligation 3, mandatory obligation 3, definition 2, permission or exemption 1

Sample requirement lines Show 9 of the 9 lines in forceHide the sample

What follows is a sample of 9 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

This binds a person who provides a cybersecurity service for reward in Ghana, a term the First Schedule defines to include designing, selling, importing, exporting, installing, maintaining, repairing or servicing a cybersecurity solution, so a vendor distributing a security software product for reward in Ghana falls within it even without performing penetration testing, forensic examination, monitoring or any of the Schedule's other listed services; a general-purpose software product with no security-specific function is not reached by this term on its own.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator (entity in scope) Runtime not classified
Ghana Cybersecurity Act, Licensing of Cybersecurity Service Providers, Cybersecurity Act, 2020 (Act 1038), ss. 49-53, First Schedule, and Second Schedule items 49(2) and 51(5) as of 2026-09-18 security:gh-cybersecurity-act-1038-s49-licensing:0
At the high tier, conduct a data security risk assessment and a penetration test of the database's systems at least once every 18 months, and hold a quarterly internal discussion of security incidents.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market Runtime not classified
Israel Privacy Protection Regulations (Data Security), information security programme, Privacy Protection Regulations (Data Security), 5777-2017, Regs. 1-10, 11(a)-(c), 12-20, 22; Protection of Privacy Law, 5741-1981, Art. 23KF and Third Schedule (enforcement) as of 2026-09-18 security:il-privacy-protection-regulations-data-security-2:2
Once the competent cyber incident prevention institution relays a substantiated report that a vulnerability exists in a system or network you operate, remediate it within the deadline the institution sets, no later than 90 days from when you received the information.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market; establishment of the manufacturer Runtime not classified
Latvia Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation, Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti as of 2026-09-15 security:lv-nacionalas-kiberdrosibas-likums-39-un-40-pant:1
Through the same reporting system, also report a significant cyber threat you become aware of, a near-miss event that could have caused a significant incident, and a vulnerability in your own publicly available networks or systems that you could not remediate or mitigate in reasonable time.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market; establishment of the manufacturer Runtime not classified
Slovakia Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification, Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplní niektorých zákonov, v znení zákona č. 366/2024 Z. z., § 24 a § 5 ods. 5 as of 2026-09-15 security:sk-zakon-c-69-2018-hlasenie-incidentov:6
If you provide or develop an AI system and conduct adversarial testing in good faith to prevent, detect, or mitigate the risk of that system generating this material, that testing is exempt, but only if it is not for personal, exploitative, or unrelated purposes.
Type Permission or exemption Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
Arkansas Act 977 of 2025 (HB 1877), AI-Generated Child Sexual Abuse Material Amendments, Ark. Code Ann. §§ 5-27-302, 5-27-304, 5-27-601 to 5-27-603, 5-27-609 as of 2026-09-06 ai:us-ar-ark-ann-5-27-302-5-27-304-5-27-601-5-27-60:1
Confirm whether you are a controller under Florida's narrow test before relying on FDBR: it binds only a for-profit entity conducting business in Florida that collects personal data, determines the purposes and means of processing, makes more than $1 billion in global gross annual revenue, and either derives 50 percent or more of that revenue from online advertising, operates a qualifying smart speaker service, or operates an app store or digital distribution platform offering at least 250,000 applications.
Type Definition Modal imperative Binds Controller (the party that decides why and how personal data is processed) Scope turns on not classified Hook Residence of the data subject; establishment of the operator Runtime not classified
Florida Florida Digital Bill of Rights, general applicability and large-platform threshold, Fla. Stat. §§ 501.701, 501.702(9) as of 2026-08-27 privacy:us-fl-fla-stat-501-701-501-702-9:0
If you create or develop synthetic media (audio or video generated or manipulated using generative adversarial network techniques or similar digital technology) that deceptively depicts a candidate's action or speech in an electioneering communication, disclose that the media has been manipulated; a stated on-screen disclosure for video, or a spoken disclosure at defined intervals for audio, is an affirmative defense to liability under this section.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Idaho FAIR Elections Act, disclosure duty for synthetic media in electioneering communications, Idaho Code section 67-6628A as of 2026-09-06 ai:us-id-idaho-67-6628a:0
Report your remediation progress to the institution as you go, and, if you cannot remediate within 90 days for objective reasons, request an extension, which the institution may grant up to a total of 180 days from the report's submission.
Type Conditional Obligation Modal may Binds Operator (the party running the application) Scope turns on not classified Hook Placing on the market; establishment of the manufacturer Runtime not classified
Latvia Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation, Nacionālās kiberdrošības likums (adopted 20.06.2024, in force 01.09.2024), 39.-40. panti as of 2026-09-15 security:lv-nacionalas-kiberdrosibas-likums-39-un-40-pant:2
Check the FDBR's unusually narrow applicability test before assuming it binds you: it reaches only a for-profit entity over $1 billion in global gross annual revenue that also meets an online-advertising, smart-speaker, or large app-store criterion.
Type Definition Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Location of the counterparty (site, machine, rightsholder) Runtime not classified
Florida Florida Digital Bill of Rights (FDBR), publicly available information exemption and narrow applicability, Fla. Stat. § 501.702 (SB 262, 2023 session) as of 2026-08-29 scraping:us-fl-fla-stat-501-702-sb-262-2023-session:0

0 more lines in force under this theme, and 9 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T13 · Third-Party & Supply Chain

The group's key concepts: Vendor due diligence; model provenance; tool vetting; AI BOM; SLA; supply chain risk; third-party incident notification

658 lines · 579 in force · 429 instruments · 204 jurisdictions · type: mandatory obligation 243, prohibition 143, conditional obligation 141, definition 52, permission or exemption 42, consequence (penalty or remedy) 36, recommendation/guidance 1

Sample requirement lines Show 13 of the 579 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Publish a training-content summary if you provide a general-purpose model
Type Conditional Obligation Modal imperative Binds Provider of a general-purpose model Scope turns on Provider Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
European Union AI Act, Article 53 (obligations for providers of general-purpose AI models), Regulation (EU) 2024/1689, Article 53 as of 2026-08-15 ai:eu-2024-1689-53:0
If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
California CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0
Do not sell, lease, or trade a biometric identifier, or disclose one to a third party, without the consumer's consent or a listed statutory exception.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject Runtime Enforceable at a runtime control
Colorado HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) as of 2026-08-23 privacy:us-co-c-r-s-sections-6-1-1303-2-2-2-4-6-1-1314-2:2
If you are a health care practitioner using AI for diagnostic purposes, including AI-generated recommendations on a diagnosis or course of treatment, stay within the scope of your license, do not use AI in a way state or federal law otherwise restricts, and review all AI-created records consistent with Texas Medical Board standards.
Type Conditional Obligation Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Texas S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records, Tex. Health & Safety Code § 183.005 as of 2026-09-06 ai:us-tx-tex-health-safety-183-005:0
Do not use, disclose, or provide to a third party, beyond a contractual access limit and for wrongful profit or to harm the data holder, data you accessed under that limit.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Where the counterparty competes Runtime Enforceable at a runtime control
South Korea Unfair Competition Prevention and Trade Secret Protection Act, Art. 2(1) items ka and pa (data misappropriation and general catch-all), Unfair Competition Prevention and Trade Secret Protection Act (Act No. 21065, as amended), Art. 2(1)(ka), (pa) as of 2026-08-29 scraping:kr-unfair-competition-prevention-trade-secret-pr:1
Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under UK GDPR Article 82, but expect a UK representative claim to require proof of unlawful use and resulting damage for each individual claimant, not a bare loss-of-control theory, per Lloyd v Google.
Type Consequence (penalty or remedy) Modal imperative Binds Controller (the party that decides why and how personal data is processed) Scope turns on not classified Hook Establishment of the operator Runtime not classified
United Kingdom UK GDPR Article 82, Data Protection Act 2018 Section 169, and ICO Enforcement, UK GDPR, Arts. 82-83; Data Protection Act 2018 §169 as of 2026-08-24 privacy:gb-uk-gdpr-82-83-data-protection-2018-169:1
Transfer personal data outside Brazil only to a country or organization with an adequate level of protection, or under contractual clauses, corporate rules, or another article 33 safeguard.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Enforceable at a runtime control
Brazil Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD) as of 2026-09-05 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:4
Embed synthetically generated information with permanent metadata or another technical provenance mechanism, including a unique identifier, to the extent technically feasible, and do not enable removal, suppression or modification of that label or metadata.
Type Conditional Obligation Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
India Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026) as of 2026-09-07 ai:in-information-technology-intermediary-guideline:1
At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market Runtime not classified
Vietnam Cybersecurity Law, Information System Classification and Protection Measures, Law No. 116/2025/QH15 (Law on Cybersecurity), arts. 8, 10 as of 2026-09-16 security:vn-no-116-2025-qh15-cybersecurity-8-10:3
Provide a meaningful human review before finalizing any decision based solely on automated processing that produces legal or similarly significant effects for a person in Germany, including a credit score generated for a third party's determinative use, under GDPR Article 22 and BDSG Section 31.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Residence of the data subject Runtime Enforceable at a runtime control
Germany GDPR Article 22 and BDSG Sections 31 and 37, Automated Decisions and Credit Scoring in Germany, Regulation (EU) 2016/679, Art. 22; Bundesdatenschutzgesetz (BDSG) §§31, 37 as of 2026-08-24 privacy:de-eu-2016-679-22-bundesdatenschutzgesetz-bdsg-3:1
Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Ireland outside the European Economic Area.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Ireland GDPR Chapter V, Cross-Border Transfer of Personal Data from Ireland, Regulation (EU) 2016/679, Arts. 44-49 as of 2026-08-24 privacy:ie-eu-2016-679-44-49:0
Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Italy outside the EEA.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Italy GDPR Chapter V, Cross-Border Transfer Restrictions, Regulation (EU) 2016/679, Arts. 44-49, 83(5) as of 2026-08-24 privacy:it-eu-2016-679-44-49-83-5:0
Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Spain outside the EEA, and check whether LOPDGDD Articles 41-43 require AEPD authorization or prior notice for the specific transfer.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Destination of a transfer Runtime Enforceable at a runtime control
Spain LOPDGDD Titulo VI, International Transfers, Layered on GDPR Chapter V, Regulation (EU) 2016/679, Arts. 44-49, 83(5); LOPDGDD, Arts. 40-43, 72.1(l) as of 2026-08-24 privacy:es-eu-2016-679-44-49-83-5-lopdgdd-40-43-72-1-l:0

566 more lines in force under this theme, and 658 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T14 · Incident Response

The group's key concepts: Detection; containment; incident classification; regulatory notification; root cause analysis; recovery; post-incident review

887 lines · 717 in force · 379 instruments · 182 jurisdictions · type: mandatory obligation 408, conditional obligation 318, prohibition 86, consequence (penalty or remedy) 43, definition 26, permission or exemption 3, recommendation/guidance 3

Sample requirement lines Show 13 of the 717 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

Transmit the audit report and the audit implementation report to your Digital Services Coordinator of establishment and the Commission without undue delay, and make them public, with confidential information removed where necessary, within three months of receiving the audit report.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
European Union Digital Services Act, Article 37 (independent audit of very large online platforms and search engines), Regulation (EU) 2022/2065, Article 37, supplemented by Commission Delegated Regulation (EU) 2024/436 as of 2026-09-15 ai:eu-2022-2065-37:4
Report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious injury
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Provider Hook Establishment of the operator; placing on the market; where the output is used Runtime Evidenced by the runtime's record
California Transparency in Frontier Artificial Intelligence Act (SB 53), Cal. Bus. and Prof. Code Sections 22757.10 to 22757.16 as of 2026-09-08 ai:us-ca-cal-bus-prof-sections-22757-10-22757-16:4
If you experience unauthorized acquisition of unencrypted computerized personal information of Colorado residents, notify affected residents without unreasonable delay and within 30 days of determining a breach occurred.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Colorado C.R.S. 6-1-716, Notification of Security Breach, C.R.S. section 6-1-716 as of 2026-08-23 privacy:us-co-c-r-s-6-1-716:0
If you own a website, application, or social media platform on which such material is disclosed, you are liable for damages if the depicted person requests removal and you fail to remove it, and known identical copies, within 72 hours.
Type Conditional Obligation Modal imperative Binds Platform or intermediary Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Texas S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications, Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009 as of 2026-09-06 ai:us-tx-tex-civ-prac-rem-98b-0021-98b-009:2
Notify users when content they see was produced by generative AI
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
South Korea AI Framework Act, Article 31 (transparency obligations for AI outputs), Act No. 20676, Article 31 as of 2026-08-14 ai:kr-no-20676-31:0
Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
United Kingdom UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0
Establish a lawful basis under article 7 before processing personal data, including data the person has made public.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Brazil Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018 (LGPD) as of 2026-09-05 privacy:br-lei-n-13-709-de-14-de-agosto-de-2018-lgpd:0
The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.
Type Definition Modal may, must Binds Operator (the party running the application) Scope turns on not classified Hook Residence of the data subject; establishment of the operator Runtime not classified
India Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025 as of 2026-08-29 privacy:in-g-s-r-846-e-digital-personal-data-protection:0
An app that detects a violation of Vietnam's personal data protection rules likely to cause harm to national defense and security, social order, or an individual's life, health, honor, dignity, or property must notify the agency in charge of personal data protection within 72 hours.
Type Mandatory Obligation Modal must Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Vietnam Law on Personal Data Protection, breach notification, Law No. 91/2025/QH15, Article 23 as of 2026-08-29 privacy:vn-no-91-2025-qh15-23:0
Notify the competent German data protection authority without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Germany, unless the breach is unlikely to risk their rights and freedoms.
Type Conditional Obligation Modal unless Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Germany GDPR Articles 33-34, Breach Notification in Germany, Regulation (EU) 2016/679, Arts. 33-34 as of 2026-08-24 privacy:de-eu-2016-679-33-34:0
An administrative fine imposed on a public body for an AI Act breach is capped at EUR 1,000,000 regardless of the Article 99 tier that would otherwise apply; a fine on any other person or undertaking instead follows the EU AI Act's own Article 99 tiers (s. 105(2)-(5)).
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
Ireland Regulation of Artificial Intelligence Act 2026, Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026) as of 2026-09-06 ai:ie-regulation-of-artificial-intelligence-2026:1
Notify the Garante within 72 hours of becoming aware of a personal-data breach affecting a person in Italy, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Italy GDPR Articles 33-34, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34 as of 2026-08-24 privacy:it-eu-2016-679-33-34:0
Notify the AEPD within 72 hours of becoming aware of a personal-data breach affecting a person in Spain, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the affected person Runtime Evidenced by the runtime's record
Spain GDPR Articles 33-34 and LOPDGDD Article 69, Breach Notification, Regulation (EU) 2016/679, Arts. 33-34; LOPDGDD, Art. 69, Art. 73(r)-(s) as of 2026-08-24 privacy:es-eu-2016-679-33-34-lopdgdd-69-73-r-s:0

704 more lines in force under this theme, and 887 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T15 · Transparency & User Disclosure

The group's key concepts: AI disclosure; user notices; explanations; user expectations; consent; labeling; deception prohibition; capability limits

1,800 lines · 1,447 in force · 845 instruments · 233 jurisdictions · type: mandatory obligation 764, conditional obligation 375, prohibition 373, definition 110, consequence (penalty or remedy) 95, permission or exemption 75, recommendation/guidance 8

Sample requirement lines Show 13 of the 1,447 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

This is one listed risk-mitigation measure for a Commission-designated very large online platform or search engine, not a freestanding labeling mandate on every provider
Type Definition Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Where the output is used; placing on the market Runtime not classified
European Union Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking), Regulation (EU) 2022/2065, Article 35(1)(k) as of 2026-08-14 ai:eu-2022-2065-35-1-k:0
If you use automated decisionmaking technology (ADMT) to make a significant decision about a consumer (granting or denying financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services), give the consumer a Pre-use Notice describing that use and the consumer's rights to opt out of and access information about it
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
California CCPA Automated Decisionmaking Technology Regulations, Cal. Code Regs. tit. 11, Sections 7200 to 7222 as of 2026-09-08 ai:us-ca-11-cal-regs-sections-7200-7222:0
Carry a clear and conspicuous disclosure that the communication has been edited and falsely appears authentic, when you distribute, publish, broadcast, or display a communication about a candidate that includes a deepfake
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Colorado HB 24-1147, Candidate Election Deepfake Disclosures, C.R.S. 1-46-103 as of 2026-08-14 ai:us-co-c-r-s-1-46-103:0
If you are a governmental agency making an AI system available to interact with consumers, disclose before or at the time of interaction that the consumer is interacting with an AI system, even if that would already be obvious to a reasonable consumer.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Texas TRAIGA (H.B. 149, 2025), consumer AI-interaction disclosure duty, Tex. Bus. & Com. Code § 552.051 as of 2026-09-06 ai:us-tx-tex-bus-com-552-051:0
Check the Enforcement Decree for labeling specifics as they phase in
Type Definition Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Where the output is used; placing on the market Runtime not classified
South Korea AI Framework Act, Article 31 (transparency obligations for AI outputs), Act No. 20676, Article 31 as of 2026-08-14 ai:kr-no-20676-31:1
Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
United Kingdom UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0
Disclose, explicitly, prominently, and accessibly, when electoral advertising uses AI-generated synthetic content to create, replace, omit, merge, alter the speed of, or overlay images or sounds, and name the technology used.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Brazil TSE Resolution, AI-Generated Content Disclosure Duty, Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024) as of 2026-09-05 ai:br-resolu-o-tse-n-23-610-2019-9-b-reda-o-dada-pe:0
If you operate a computer resource that may enable the creation, generation, modification, alteration, publication, transmission, sharing or dissemination of synthetically generated information, prominently label such information, in the visual display or by a prefixed audio disclosure, so a viewer can immediately identify it as synthetically generated.
Type Conditional Obligation Modal may Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
India Synthetically Generated Information Labelling Duty for Intermediaries, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026) as of 2026-09-07 ai:in-information-technology-intermediary-guideline:0
Design an AI system that interacts directly with users so that users can recognise they are interacting with an AI system, unless the law provides otherwise.
Type Conditional Obligation Modal unless Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
Vietnam Law on Artificial Intelligence, transparency obligation, Law No. 134/2025/QH15, art. 11 as of 2026-09-06 ai:vn-no-134-2025-qh15-11:0
Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Germany Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:1
Comply with information requests, contravention notices and prohibition notices issued by an authorised officer of a relevant market surveillance authority in respect of an AI system you provide or deploy (Part 5).
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Ireland Regulation of Artificial Intelligence Act 2026, Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026) as of 2026-09-06 ai:ie-regulation-of-artificial-intelligence-2026:0
Do not transfer, publish, or otherwise disseminate a falsified or altered image, video, or voice recording generated using an AI system, capable of misleading others as to its genuineness, without the depicted or recorded person's consent.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Detectable at a runtime control
Italy Codice Penale Art. 612-quater, Illicit Dissemination of AI-Generated or AI-Altered Content, Codice Penale, art. 612-quater, inserted by Legge 23 settembre 2025, n. 132, art. 26, comma 1, lettera c) as of 2026-09-06 ai:it-cp-612quater-ai-deepfake-dissemination:0
Inform the works council of the parameters, rules, and instructions on which any algorithm or AI system that affects decisions on working conditions, access to employment, or continued employment is based, including any profiling, per Estatuto de los Trabajadores Article 64.4.d).
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Spain Estatuto de los Trabajadores Article 64.4.d), Algorithmic Management Works Council Information Right, Ley 12/2021, de 28 de septiembre, articulo unico.Uno, inserting art. 64.4.d) into the Texto Refundido de la Ley del Estatuto de los Trabajadores (Real Decreto Legislativo 2/2015) (BOE-A-2021-15767) as of 2026-09-02 ai:es-ley-12-2021-unico-1-et-64-4-d:0

1,434 more lines in force under this theme, and 1,800 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

T16 · Recordkeeping & Auditability

The group's key concepts: Retention schedules; reproducibility; audit readiness; record integrity; regulatory reporting; archival; destruction

1,546 lines · 1,290 in force · 574 instruments · 222 jurisdictions · type: mandatory obligation 709, conditional obligation 370, prohibition 234, consequence (penalty or remedy) 110, definition 60, permission or exemption 56, recommendation/guidance 7

Sample requirement lines Show 13 of the 1,290 lines in forceHide the sample

What follows is a sample of 13 requirement lines from the LexLint software-law corpus, chosen to span jurisdictions.

This is one listed risk-mitigation measure for a Commission-designated very large online platform or search engine, not a freestanding labeling mandate on every provider
Type Definition Modal imperative Binds Provider (the party that develops or places the system on the market) Scope turns on not classified Hook Where the output is used; placing on the market Runtime not classified
European Union Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking), Regulation (EU) 2022/2065, Article 35(1)(k) as of 2026-08-14 ai:eu-2022-2065-35-1-k:0
If a reasonable person interacting with your companion chatbot could be misled into believing they are talking to a human, issue a clear and conspicuous notification that the chatbot is artificially generated and not human
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Affected person Hook Where the output is used; placing on the market Runtime Detectable at a runtime control
California Companion Chatbot Safety and Accountability Act (SB 243), Cal. Bus. and Prof. Code Sections 22601 to 22606 as of 2026-09-08 ai:us-ca-cal-bus-prof-sections-22601-22606:0
Adopt and publish a written policy that sets a retention schedule and a destruction timeline (the earliest of purpose satisfied, 24 months after the consumer's last interaction, or 45 days, extendable by up to 45 more, after the identifier is no longer needed) and a data-security-incident response protocol.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Residence of the data subject Runtime Outside any runtime path
Colorado HB 24-1130, Privacy of Biometric Identifiers and Data, C.R.S. sections 6-1-1303(2.2)-(2.4), 6-1-1314 (2024 Colo. Sess. Laws ch. 313) as of 2026-08-23 privacy:us-co-c-r-s-sections-6-1-1303-2-2-2-4-6-1-1314-2:1
If you operate a social media platform, provide an easily accessible complaint system letting a user report explicit deep fake material, alongside illegal content and content-removal decisions.
Type Conditional Obligation Modal imperative Binds Platform or intermediary Scope turns on Affected person Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Texas H.B. 3133 (2025), social media platform complaint system for explicit deep fake material, Tex. Bus. & Com. Code §§ 120.101, 120.1001, 120.102, 120.1015, 120.1025, 120.152 as of 2026-09-06 ai:us-tx-tex-bus-com-ch-120-subch-c:0
An app processing Korean personal data must be able to answer to the PIPC for its lawful basis and safeguards, and an individual harmed by a security failure may bring a private civil claim for statutory damages, or damages up to five times the actual loss, without needing to prove the controller's negligence.
Type Consequence (penalty or remedy) Modal must, may Binds Controller (the party that decides why and how personal data is processed) Scope turns on not classified Hook Establishment of the operator Runtime not classified
South Korea Personal Information Protection Act, enforcement and private civil remedy, Act No. 10465 (as amended by Act No. 19234, 2023), Arts. 39, 39-2, 51, 64-2 as of 2026-09-02 privacy:kr-no-10465-as-amended-by-no-19234-2023-39-39-2:0
Establish and document a lawful basis under UK GDPR Article 6 before processing any personal data of a person in the United Kingdom, including the new closed-list recognised legitimate interests basis where it applies.
Type Conditional Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
United Kingdom UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025, Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 as of 2026-08-24 privacy:gb-data-protection-2018-c-12-uk-gdpr-as-amended:0
Do not invade a computing device, connected to a network or not, to obtain, alter, or destroy data or information without the device user's authorization, or to install a vulnerability to obtain an unlawful advantage.
Type Prohibition Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook Location of the counterparty's machine Runtime Enforceable at a runtime control
Brazil Penal Code Art. 154-A, Invasion of a Computing Device, Código Penal (Decreto-Lei nº 2.848/1940), art. 154-A (redação dada pela Lei nº 14.155, de 2021, inserido pela Lei nº 12.737, de 2012) as of 2026-09-05 scraping:br-c-digo-penal-154-reda-o-dada-pela-lei-n-14-15:0
Get the rights holder's authorisation before reproducing or reusing copyrighted material, including a copyrighted database or compilation, to train an AI model; the fair-dealing exceptions do not name text-and-data-mining or AI training as a covered purpose.
Type Mandatory Obligation Modal do not Binds Operator (the party running the application) Scope turns on Counterparty Hook The counterparty's establishment (rightsholder); where the copy is made Runtime Enforceable at a runtime control
India Copyright Act, No Text-and-Data-Mining Exception, Database Compilations, and Technological Protection Measures, Copyright Act, 1957 (No. 14 of 1957), ss. 2(o), 51, 52, 63, 65A as of 2026-09-07 scraping:in-copyright-1957-no-14-1957-ss-2-o-51-52-63-65a:0
Classify your AI system's risk level (high, medium, or low) before putting it into service, based on its potential impact on rights, safety, security, and public interest, and the scale and context of its use.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Operator Hook Establishment of the operator; placing on the market; where the output is used Runtime Outside any runtime path
Vietnam Law on Artificial Intelligence, risk classification and conformity assessment, Law No. 134/2025/QH15, arts. 9-10, 13-14 as of 2026-09-06 ai:vn-no-134-2025-qh15-9-10-13-14:0
Expect the Bundesnetzagentur to be Germany's central market surveillance authority, single point of contact, and central complaints office under the EU AI Act, unless your AI system is directly tied to a regulated financial activity that the Bundesanstalt für Finanzdienstleistungsaufsicht already supervises, in which case expect that authority instead.
Type Consequence (penalty or remedy) Modal unless Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator; placing on the market; where the output is used Runtime not classified
Germany Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act, Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz, KI-MIG), §§ 2, 6, 8, 13, 15, 16 as of 2026-09-06 ai:de-gesetz-zur-markt-berwachung-und-innovationsf:0
Establish and document a lawful basis under GDPR Article 6 before processing any personal data of a person in Ireland.
Type Mandatory Obligation Modal imperative Binds Operator (the party running the application) Scope turns on Data subject Hook Residence of the data subject; establishment of the operator Runtime Outside any runtime path
Ireland Data Protection Act 2018, Data Protection Act 2018 (No. 7 of 2018) as of 2026-08-24 privacy:ie-data-protection-2018-no-7-2018:0
Expect the Garante to have GDPR Article 83 fining power over your processing of personal data of a person in Italy.
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
Italy GDPR Article 82 and Azione di Classe (Codice di Procedura Civile Art. 840-bis), Regulation (EU) 2016/679, Art. 82; Codice di procedura civile, Art. 840-bis (as reformed by Legge 12 aprile 2019, n. 31) as of 2026-09-02 privacy:it-eu-2016-679-82-codice-di-procedura-civile-840:0
Expect the AEPD to sort a violation into a muy grave, grave, or leve infraction tied to a GDPR Article 83 fine tier when assessing exposure for processing personal data of a person in Spain.
Type Consequence (penalty or remedy) Modal imperative Binds Operator (the party running the application) Scope turns on not classified Hook Establishment of the operator Runtime not classified
Spain AEPD Enforcement, GDPR Article 82 and LOPDGDD Titulo IX, Regulation (EU) 2016/679, Arts. 82-83; LOPDGDD, Art. 47, Arts. 70-78 as of 2026-09-02 privacy:es-eu-2016-679-82-83-lopdgdd-47-70-78:0

1,277 more lines in force under this theme, and 1,546 lines in all, are in the LexLint software-law corpus; the full register is the file in section 6.

6The full register as a file

theme-register.csv holds every line that falls under at least one theme, one row per line, with the theme identifiers it belongs to, the columns above, and the topic, instrument, citation, summary page, lifecycle band and as-of date. It is generated from the LexLint software-law corpus on the date in this page's byline and it will be regenerated when the corpus moves; a copy taken today is a snapshot with that date on it. The theme columns are the register's, not the corpus's: the corpus records obligation classes and wording, and the mapping from those to the group's sixteen themes is the rule stated in section 2, which the group is welcome to replace with its own. The file, like the documents, is licensed under Creative Commons Attribution-NonCommercial 4.0: use it for noncommercial purposes with credit to LexLint (UnGovr), and contact LexLint at hello@ungovr.org to discuss commercial use.

7What this register does not claim

It does not say that any line binds any particular organisation. That is the applicability question, and it is answered per deployment from the roles a system holds and where its parties are, which is what the first document in this section is about. The theme assignment, the addressee and the hook are rules applied to text, reviewed in samples, not findings made line by line. Every entry links to its source so that a reader can check the rule against the law, and the working group is the best reviewer the register could have.