21 items in Compliance
The United States regulates enterprise AI through sector regulators, not a single AI law. Bank supervisors apply SR 11-7 model risk management, NYDFS applies its cybersecurity regulation, FDA regulates AI-enabled devices as products, and the FTC polices AI claims everywhere. Map each AI deployment to the sector rule that already covers it, then use RegTech to automate the tracking and reporting work.
Four regulatory regimes now shape how a global enterprise deploys AI: the EU AI Act, the GDPR, China's binding algorithm rules, and Brazil's risk-based bill. The practical answer is not four separate compliance programs — it is one governance chassis (inventory, risk classification, documentation, human oversight) with market-specific overlays. This guide maps what each regime requires and how to build that chassis once.