Enable the builder on the Regulations page, then click + on any regulation to add it to your custom framework.
Custom AI Compliance Framework
Framework Builder
0 frameworks selected
Document Name
⬡
Enable the builder on the Frameworks page, then click any framework card to add it to your synthesis document. Mix frameworks from multiple regions.
Custom AI Governance Document
The Global Workforce Imperative
We need a common language for AI fluency.
Across industries, roles, and geographies — there is no shared standard for what it means to work effectively with AI. That gap is costing organisations productivity, resilience, and competitive edge. It is time for a new shift. Until everyone in the organisation has an understanding of how and when to use AI, it remains an enigma with low returns.
92%
of executives say AI fluency will be critical within 2 years, yet fewer than 1 in 3 have a training framework in place.
$4.4T
estimated annual productivity gain possible from effective AI adoption across the global workforce.
40%
of all working hours globally are exposed to automation or augmentation by large language models.
7 in 10
employees say they need better AI tools and training but don't know where to begin or what standard to meet.
AI capability is advancing faster than our collective ability to harness it. Most organisations treat AI training as a technology question — when in reality it is a human capability question.
The missing piece is a universal, industry-agnostic benchmark for AI fluency: knowing not just how to use AI tools, but how to evaluate outputs, integrate AI into workflows, manage risks, and continuously adapt. Without that benchmark, no consistent upskilling is possible. This platform is built to change that.
"The capacity of humans to work with AI — not just alongside it — will define the economic winners and losers of the next decade."
World Economic Forum — Future of Jobs Report 2025
01 — Global Landscape
Global AI Frameworks
Governments, intergovernmental bodies, and leading AI organisations have published frameworks to guide responsible AI development. Select a region to explore the frameworks most relevant to your context — then use the Framework Builder to synthesise a custom governance document.
⬡
Governance Document Builder
Enable builder mode, then click any framework card to select it. Mix frameworks from multiple regions to generate a synthesised governance blueprint tailored to your organisation.
OECD
OECD Principles on AI
Adopted in 2019 and updated in May 2024 to address generative AI and foundation models, these principles have now been endorsed by 47 jurisdictions globally — including all OECD members and the EU. They form the source language for the EU AI Act's values clauses, the NIST AI RMF's trustworthiness characterisation, and most national AI strategies worldwide.
Policy Guidance
UNESCO
Recommendation on the Ethics of AI
UNESCO's 2021 global standard covers 11 core values and remains the only global normative instrument on AI ethics signed by 193 member states. In 2025 UNESCO launched its AI Competency Frameworks for Students and Teachers — the first intergovernmental attempt to define AI literacy as an educational standard across all member nations.
Ethics Standard
G7
Hiroshima AI Process & Code of Conduct
The G7's Hiroshima AI Process (2023) established a voluntary Code of Conduct for advanced AI developers, now adopted by over 50 leading AI organisations. In 2025 the G7 extended the process with updated guidance on agentic AI systems — marking the first intergovernmental framework to explicitly address AI that acts autonomously on behalf of users.
Intergovernmental
WEF
AI Governance Alliance Frameworks
The World Economic Forum's AI Governance Alliance, launched in 2023, now operates across more than 300 member organisations. In 2025 it published its AI Readiness Toolkit for boards and its Responsible AI Playbook for SMEs — practical instruments that explicitly embed workforce AI fluency as a measurable governance dimension.
Industry Alliance
Council of Europe
Framework Convention on AI (CETS No. 225)
The world's first binding international treaty on AI, opened for signature in September 2024 and signed by the EU, US, UK, and 45 other nations. It applies human rights, democracy, and rule of law principles to the full AI lifecycle and requires signatory states to ensure AI systems do not undermine human dignity — including through adequate workforce training and oversight requirements.
Binding Treaty
ISO/IEC
ISO/IEC 42001:2023 — AI Management Systems
The first internationally certifiable AI governance standard, gaining rapid adoption in 2025–2026 as regulators globally recognise certification as evidence of adequate AI governance. The companion standard BS ISO/IEC 42006:2025 (published 2025) defines qualification requirements for AI auditors. An official crosswalk to the NIST AI RMF enables organisations to satisfy both frameworks simultaneously.
Certifiable Standard
IEEE
Ethically Aligned Design
The IEEE's comprehensive guidance document — now in its third iteration — addresses how engineers and deployers should embed human values into AI systems. In 2025 IEEE also published P2863, its recommended practice for organisational governance of AI, providing enterprises with a structured implementation companion to the EAD principles.
Technical Standard
EU AI Office
GPAI Code of Practice
Developed through a multi-stakeholder process in 2025, the EU AI Office's General-Purpose AI Code of Practice became applicable to GPAI model providers from August 2, 2025. It sets detailed transparency, safety evaluation, and incident reporting requirements — and has been adopted by major AI labs including OpenAI, Google, Anthropic, and Meta as their primary EU compliance instrument.
Compliance Code
NIST
AI Risk Management Framework 1.0 + GenAI Profile
The NIST AI RMF (January 2023) was updated in March 2025 to address generative AI risks, supply chain vulnerabilities, and third-party model assessment. The NIST AI 600-1 Generative AI Profile (July 2024) adds 12 GenAI-specific risk categories across all four RMF functions — making it the most operationally detailed US AI risk standard in 2026.
Risk Framework
NIST
AI Risk Management Framework 1.0 + GenAI Profile
Updated March 2025 to address generative AI risks, supply chain vulnerabilities, and third-party model assessment. The NIST AI 600-1 Generative AI Profile (July 2024) adds 12 GenAI-specific risk categories. NIST IR 8596 (December 2025) bridges the AI RMF with the Cybersecurity Framework 2.0. Referenced by the FTC, FDA, SEC, and EEOC in enforcement guidance — making it de facto mandatory for federal contractors.
Risk Framework
White House
America's AI Action Plan (July 2025)
Released July 23, 2025, the Trump Administration's AI Action Plan establishes the US strategy for maintaining global AI dominance. It calls for a national, innovation-focused AI framework, workforce AI education initiatives through NSF and DOE, and federal investment in AI research infrastructure — while explicitly steering away from prescriptive enterprise AI mandates.
National Strategy
White House
National Policy Framework for AI (March 2026)
Released March 20, 2026, pursuant to EO 14365, this legislative blueprint recommends Congress adopt a unified national AI law preempting state regulations. It proposes targeted federal standards in child safety, digital replicas, and infrastructure — representing the most concrete federal AI governance proposal in US history and shaping enterprise compliance expectations for 2026–2027.
Legislative Blueprint
DHS / CISA
AI Safety and Security Guidelines (Updated 2025)
CISA updated its AI safety guidance in 2025 to cover agentic AI systems and AI-assisted cyberattacks. The updated guidelines include workforce competency requirements for AI security personnel in critical infrastructure sectors — reflecting growing recognition that AI fluency is a national security prerequisite, not just a business efficiency metric.
Security Guidance
NSA
Deploying AI Systems Securely (2025)
The NSA, in collaboration with CISA and international partners including the UK NCSC and Australian ASD, published updated guidance on securing AI systems in 2025. It covers LLM deployment security, model poisoning defence, and output monitoring — with explicit staff training requirements for personnel responsible for AI system operation in classified and sensitive contexts.
Security Standard
NIST / FTC
AI and Algorithmic Accountability
The FTC's AI enforcement actions have accelerated through 2025–2026, creating a growing body of case law on responsible AI. The FTC's 2025 report on AI in commerce identified opacity, unfair personalisation, and discriminatory outputs as primary enforcement priorities — placing direct pressure on organisations to demonstrate staff AI literacy as part of their accountability posture.
Enforcement Guidance
European Commission
EU AI Act Conformity Framework
Sets out requirements for high-risk AI systems including mandatory staff training and competency requirements. Establishes the most comprehensive legally binding AI governance structure in the world, with full enforcement from 2026.
Regulatory
EU HLEG
Ethics Guidelines for Trustworthy AI
Seven requirements for trustworthy AI — human agency, robustness, privacy, transparency, diversity, societal wellbeing, and accountability. These guidelines underpin the EU's entire AI policy architecture and are referenced by regulators across all member states.
Ethics Guidelines
European Parliament
AI Liability Directive
The proposed directive creates a harmonised framework for civil liability from AI-related harms, introducing a presumption of causal link when organisations cannot demonstrate adequate oversight — making workforce AI fluency a legal imperative.
Liability Framework
ENISA
AI Cybersecurity Guidelines
AI-specific security guidance covering the full AI system lifecycle, including requirements for personnel with roles in AI development, deployment, and monitoring — shaping AI competency expectations across all EU member states.
Cybersecurity
EDPB
GDPR Guidance on AI & Personal Data
Guidelines on automated decision-making and profiling under GDPR — requiring human oversight, explainability, and individual rights. Organisations using AI in HR, credit, or healthcare must ensure relevant staff understand these obligations.
Data Protection
Germany / France
Franco-German Trustworthy AI Initiative
A bilateral initiative including a joint proposal for AI skills certification aligned with the EU Digital Competence Framework (DigComp) — positioning AI fluency as a core pillar of European digital sovereignty and competitiveness.
Member State Initiative
UK DSIT
Pro-Innovation AI Regulation (Reaffirmed 2025)
As of July 2026, the UK has no standalone AI Act. The Labour Government reaffirmed the principles-based, sector-led approach in 2025 — but shifted focus from safety to economic growth. The AI Safety Institute was renamed the AI Security Institute in February 2025, reflecting a strategic pivot toward national security and misuse risk rather than content governance. A Frontier AI Bill has been signalled but is not expected before 2027.
Policy Framework
AISI → AI Security Institute
Frontier AI Trends Report (December 2025)
The AI Security Institute (rebranded February 2025) published its first Frontier AI Trends Report in December 2025 — assessing capability trajectories of leading AI systems across reasoning, autonomy, and misuse potential. The UK holds the role of Network Coordinator of the 11-nation International AI Security Institute network, sharing evaluation methodologies that are shaping global AI assessment standards.
Safety Evaluation
UK DSIT
AI Growth Lab (October 2025)
Launched October 2025, the AI Growth Lab creates cross-economy regulatory sandboxes enabling organisations to pilot AI innovations under modified regulatory conditions. Successful pilots can trigger permanent regulatory reform through updated guidance, codes of practice, or statutory amendments — making it one of the most practically responsive AI governance mechanisms globally.
Regulatory Sandbox
ICO
ICO AI & Data Protection Guidance Suite
The ICO has continued expanding its AI guidance through 2025–2026, with priority areas including AI in the workplace, agentic AI systems, and AI explainability. Working jointly with the FCA on financial services AI, and with Ofcom on AI in media — this multi-regulator approach means UK AI compliance obligations are sector-specific and require sector-literate AI-competent staff across functions.
Data Governance
FCA
Consumer Duty as AI Accountability Framework
The FCA's Consumer Duty (July 2023) has become the primary AI accountability tool for UK financial services, requiring firms to demonstrate AI-driven products deliver good consumer outcomes. Updated AI guidance in 2025 and anticipated AI-specific Consumer Duty implementation guidance in 2026 create a de facto AI competency requirement for all regulated financial firms.
Sector-Specific
NHS England
AI Framework for Health and Care (Updated 2025)
NHS England's clinical AI framework was updated in 2025 to address generative AI in clinical settings — including LLM use in clinical documentation, diagnosis support, and patient communication. The updated framework introduces explicit requirements for clinical AI literacy at individual, team, and organisational levels — cited as a model for healthcare AI governance by the WHO and several EU health systems.
Healthcare
MIIT / MOST
New Generation AI Development Plan
China's national AI strategy targets AI leadership by 2030 with explicit workforce development goals — mandatory AI education integration at all curriculum levels and a 500,000-strong AI specialist workforce target, one of the most ambitious globally.
National Strategy
CAC
Algorithmic Recommendation Management
China's 2022 algorithm regulation requires operators to maintain algorithm transparency, give users opt-out rights, and train staff on algorithm management obligations — creating one of the most operationally detailed AI workforce competency mandates globally.
Platform Regulation
CAICT
White Paper on Trustworthy AI
Frameworks for trustworthy AI covering safety, explainability, privacy, and fairness. Guide domestic enterprise AI governance and are referenced in sector-specific deployment guidelines across banking, healthcare, and manufacturing in China.
Industry Framework
Ministry of Education
AI Literacy Curriculum Standards
China's Ministry of Education has mandated AI literacy as a core component of secondary and higher education curricula — one of the most institutionalised AI fluency pipelines globally with defined competency outcomes by graduation level.
Education Standard
PBOC / CBIRC
Financial AI Governance Guidelines
Guidance on AI use in financial services covering model risk, algorithmic credit scoring, and automated trading. Staff in AI-enabled financial roles are expected to meet defined competency standards and undergo regular AI ethics training.
Financial Services
CAC
Generative AI Interim Measures
Enterprises deploying generative AI tools for business use are required to document their AI governance processes and demonstrate user competency oversight — creating explicit enterprise-level AI fluency requirements for GenAI deployment in China.
GenAI Regulation
Singapore IMDA
Model AI Governance Framework (GenAI Edition, May 2025)
Singapore updated its AI Verify testing toolkit on May 29, 2025 to cover generative AI systems alongside traditional AI — introducing new testing dimensions for hallucination, attribution, and adversarial robustness. Singapore maintains a voluntary governance model with no comprehensive AI statute, but its practical frameworks are the most widely adopted AI governance reference across ASEAN, influencing national strategies in Malaysia, Thailand, and Indonesia.
Governance Toolkit
Japan
AI Guidelines for Business + AI Promotion Act (June 2025)
Japan's Parliament approved the AI Promotion Act on May 28, 2025 (effective June 4, 2025) — Japan's first AI law, establishing the AI Strategy Headquarters. Compliance remains guideline-driven under the 2024 AI Guidelines for Business, which map across sectors including finance, healthcare, and manufacturing. Japan has chosen an innovation-first approach, explicitly designed to avoid the prescriptiveness of the EU AI Act.
National Framework
South Korea
AI Basic Act (Effective January 22, 2026)
South Korea became the first Asian nation with a comprehensive AI framework statute, effective January 22, 2026. The Act establishes national governance institutions, trustworthiness requirements for high-impact AI, and mandatory risk assessments. South Korea is now building sector-specific supplementary guidance for financial services, healthcare, and employment — which will define role-specific AI competency requirements in those industries.
National Legislation
India NITI Aayog / MeitY
India AI Mission & National Framework (2025)
India's AI Mission, launched March 2024, allocated INR 10,371 crore for AI infrastructure and skills development. In 2025, MeitY published updated Responsible AI guidelines with sector-specific supplements for healthcare, agriculture, and financial services. India is in active consultation on a standalone AI Act as of 2026, with public drafts expected. The India AI mission explicitly targets training 25,000 AI researchers and 1 million AI-skilled graduates by 2028.
National Strategy
ASEAN
ASEAN Guide on AI Governance & Ethics (Updated 2025)
The ASEAN Guide on AI Governance and Ethics was updated in 2025 to address generative AI — adding guidance on content authenticity, automated decision-making, and cross-border AI data flows. ASEAN is developing a regional AI governance interoperability framework to enable mutual recognition of national AI standards across its 10 member states by 2027.
Regional Framework
MAS Singapore
FEAT Principles & Project MindForge (2025)
MAS expanded its FEAT principles framework in 2025 through Project MindForge — a collaborative initiative with major financial institutions to develop GenAI risk assessment standards for financial services. MindForge's outputs include a GenAI risk taxonomy and evaluation methodology being adopted by banks across Singapore, Hong Kong, and Malaysia as the de facto regional standard for AI risk governance in finance.
Financial Services
DISR
Australia's AI Ethics Principles & Mandatory Guardrails (2024–2025)
Australia's eight voluntary AI ethics principles were complemented in 2024–2025 by 10 proposed mandatory guardrails for high-risk AI, covering human oversight, transparency, accountability, and contestability. The guardrails are currently applied voluntarily pending legislative backing, but are referenced in government procurement requirements and are shaping enterprise AI governance practices across regulated sectors.
National Framework
CSIRO
Responsible AI Network — National AI Standards (2025)
CSIRO's Responsible AI Network published sector-specific responsible AI toolkits for agriculture, mining, healthcare, and financial services in 2024–2025. In 2026, CSIRO is developing an AI Assurance Framework intended to become Australia's national reference standard for AI governance — aligned to ISO 42001 and designed to be adopted by organisations of all sizes, not just large enterprises.
Research Standards
DTA / APSC
APS Mandatory AI Policy & AI Literacy Uplift (2023–2025)
The Australian Public Service Commission's mandatory AI policy — requiring AI literacy for all Commonwealth employees — was updated in 2025 with role-specific competency expectations for Senior Executives and Secretaries. This has made Australia's federal public sector one of the most advanced AI-literate government workforces globally, creating a benchmark increasingly referenced by state governments and private sector organisations.
Government Policy
APRA
AI & Model Risk — CPG 220 Supplement (2024)
APRA's 2024 supplement to Prudential Practice Guide CPG 220 sets specific expectations for AI model validation, explainability, and ongoing monitoring in financial services. The supplement explicitly places AI governance accountability at board and senior management level — creating a de facto executive AI fluency mandate for Australia's banking, insurance, and superannuation sectors.
Financial Regulation
OAIC
Privacy Act Reform & AI Transparency (2025)
The OAIC is driving Privacy Act reforms that, when enacted, will introduce new rights around automated decision-making and AI transparency. The OAIC published updated guidance in 2025 on GenAI and privacy — covering training data, output accuracy, and data minimisation — and is expected to prioritise AI-related enforcement actions in 2026 as organisations deploy AI in consumer-facing contexts without adequate governance.
Privacy
Safe Work Australia
AI in the Workplace — Psychosocial & WHS Guidance (2025)
Safe Work Australia published specific guidance in 2025 on AI as an occupational health and safety risk — covering algorithmic management, AI performance monitoring, and psychosocial hazards from AI-driven work intensification. Australia is among the first jurisdictions globally to formally address AI as a workplace safety issue, creating novel obligations for employers in gig economy, logistics, and professional services sectors.
Workplace Safety
UAE MOCAI
UAE National AI Strategy 2031 & AI-Powered Regulatory Ecosystem (2025)
The UAE extended its National AI Strategy 2031 in 2025 with a landmark initiative: an AI-powered regulatory intelligence ecosystem that uses AI to draft, update, and monitor laws in near-real-time — the world's first AI-native governance infrastructure. The UAE has also mandated AI literacy programmes for all federal employees and positioned AI fluency as a core national development priority alongside economic diversification.
National Strategy
UAE MOCAI
UAE AI Ethics Guidelines (Updated 2025)
The UAE updated its AI Ethics Guidelines in 2025 to address generative AI — adding principles on content authenticity, AI-human collaboration boundaries, and cross-sector AI accountability. All entities operating in the UAE are expected to align with the guidelines, with sector regulators in financial services, healthcare, and media developing implementation guidance for their respective domains.
Ethics Guidelines
Saudi SDAIA
Saudi National AI Strategy & AI Governance Regulations (2024–2025)
Saudi Arabia's SDAIA published updated AI governance regulations in 2024 and is conducting compliance audits across Vision 2030 priority sectors from 2025. The strategy targets 20,000 AI specialists by 2025 and 100,000 by 2030, with a national AI skills programme embedded in university curricula across the Kingdom. SDAIA is developing sector-specific AI governance supplements for fintech, healthcare, and smart cities.
National Strategy
Qatar MCIT
Qatar National AI Strategy & Governance Framework (In Development 2026)
Qatar's MCIT is finalising a National AI Governance Framework expected for publication in 2026, targeting high-risk AI in finance, healthcare, and government services. Early consultation documents indicate a mandatory AI governance certification scheme aligned to ISO 42001, and AI literacy requirements for civil servants as part of Qatar's broader digital transformation under National Vision 2030.
National Strategy
DIFC / ADGM
Financial Free Zone AI Governance (Updated 2024–2025)
DIFC and ADGM both updated their AI governance frameworks in 2024–2025 to address GenAI in financial services. DIFC's updated Commissioner guidance extended senior management accountability to AI governance under the FSMR. ADGM published GenAI-specific risk guidance for asset managers in 2025 — making the UAE's financial free zones among the most advanced AI governance environments in the Middle East and Africa.
Financial Services
Israel
Israel AI Innovation Authority Framework (Updated 2025)
Israel's Innovation Authority updated its responsible AI framework in 2025 with sector-specific guidance for healthcare and financial services — reflecting Israel's globally significant AI ecosystem (ranked among the top 5 nations for AI R&D intensity per capita). The framework is referenced in defence procurement, health technology certification, and public sector AI deployment standards, with workforce AI competency assessments integrated into government AI vendor qualification processes.
National Framework
02 — Regulatory Landscape
Global AI Regulations
The regulatory environment for AI is tightening across every major jurisdiction. Select a region to explore the laws, acts, and bills most relevant to your organisation — then use the Framework Builder to create a customised compliance framework.
◈
Custom Framework Builder
Enable builder mode, then click + on any regulation to add it to your personalised compliance framework. Mix regulations from multiple regions.
2025
ISO/IEC 42001 — AI Management System Standard
The first internationally certifiable standard for AI governance. Increasingly referenced in regulatory compliance programmes worldwide, it includes explicit requirements for competence, training, and awareness of AI across all organisational levels.
Active
2023
G7 Hiroshima Code of Conduct for AI Developers
A voluntary but politically significant code of conduct agreed by G7 nations, setting expectations for frontier AI developers on safety testing, transparency, and incident reporting — establishing a global baseline for responsible AI deployment.
Active
2024
Bletchley Declaration & Seoul AI Safety Commitments
Signed by 28 nations, these declarations established international consensus on frontier AI risk. Participating nations committed to developing national AI safety frameworks — each with implications for how organisations train and govern their AI-enabled workforce.
Active
2025
EO 14179 — Removing Barriers to American Leadership in AI (January 2025)
Signed January 23, 2025, this executive order revoked Biden's EO 14110 and established the Trump administration's AI policy: sustaining US global AI dominance through a deregulatory, innovation-first approach. It directed the development of an AI Action Plan (released July 2025) and shifted federal AI governance from oversight-first to competitiveness-first — fundamentally reshaping US enterprise AI obligations.
Active
2025
EO 14365 — Ensuring a National Policy Framework for AI (December 2025)
Signed December 11, 2025, this executive order establishes a federal policy to create a "minimally burdensome" national standard for AI and directed the DOJ to challenge state laws deemed inconsistent with federal goals. The White House followed with a National Policy Framework (March 20, 2026) recommending Congress adopt legislation broadly preempting state AI laws — the most significant AI governance shift in US history.
Active
2026
Colorado AI Act (SB 205) — Effective June 30, 2026
The first US state to pass comprehensive AI legislation (signed 2024, enforcement delayed to June 30, 2026). Requires developers and deployers of high-risk AI to conduct impact assessments, disclose AI use, and implement governance programmes including staff training on bias detection. Under active federal scrutiny from EO 14365's AI Litigation Task Force, which may challenge the law.
Active
2026
California AI Transparency Act (SB 53) — Effective January 1, 2026
Requires developers of covered generative AI systems to implement AI detection tools and disclose when AI has been used to generate content. Live from January 1, 2026 — making California one of the first US states with active GenAI-specific disclosure obligations. Accompanied by AB 2013, requiring public disclosure of training data used in GenAI systems.
Active
2026
Texas Responsible AI Governance Act (TRAIGA) — Effective January 1, 2026
Texas enacted TRAIGA as a comprehensive AI governance statute covering high-impact AI systems in employment, healthcare, finance, and housing. Effective January 1, 2026, it imposes impact assessment, transparency, and human oversight requirements — making Texas, alongside Colorado, one of the two states with active comprehensive AI compliance obligations.
Active
2020
Illinois AI Video Interview Act (amended 2024)
Requires employers using AI to evaluate video interviews to notify candidates and obtain consent. Amended in 2024 to extend to AI used in all stages of candidate screening. HR professionals must demonstrate understanding of the system's factors and limitations — a widely cited model for role-specific AI fluency as a legal requirement now influencing similar laws in 12+ states.
Active
2024
EU Artificial Intelligence Act — Regulation (EU) 2024/1689
The world's first comprehensive AI law. Entered into force August 1, 2024. Enforcement timeline: prohibited AI practices from February 2, 2025; GPAI model obligations from August 2, 2025; high-risk AI systems by August 2, 2026 — the operative deadline for most enterprises. The EU Digital Omnibus (proposed November 2025) introduced simplification amendments but did not delay the core timeline. Fines reach €35M or 7% of global turnover for prohibited practices.
Active
2025
EU AI Office — GPAI Model Enforcement Active from August 2025
The European AI Office directly supervises general-purpose AI (GPAI) models from August 2, 2025, with Commission enforcement powers commencing August 2026. The AI Office published implementing rules in early 2026 on how investigators may access model weights, code, and infrastructure — signalling that "paper compliance" will not suffice. The GPAI Code of Practice is the primary compliance instrument for frontier AI labs operating in the EU.
Active
2018
GDPR — Article 22 & Automated Decision-Making
Article 22 of GDPR restricts solely automated decisions with significant effects and grants individuals the right to an explanation. The EDPB published updated guidance on GenAI and GDPR in 2025 — clarifying that LLM outputs used in hiring, credit, or content moderation decisions trigger Article 22 obligations and require staff capable of meaningfully explaining AI-assisted decisions to affected individuals.
Active
2025
EU Data Act — Effective September 12, 2025
The EU Data Act, effective September 12, 2025, creates new rights and obligations around data generated by connected devices and AI systems. It regulates data access and sharing across industrial sectors — with compliance implications for how organisations train AI systems and what data governance competencies their staff must hold. Works in tandem with the EU AI Act's data quality requirements for high-risk systems.
Active
2026
AI Liability Directive — Under Revision (Digital Omnibus, November 2025)
The original AI Liability Directive proposal created a presumption of causality when organisations cannot demonstrate adequate oversight. The European Commission's November 2025 Digital Omnibus proposed amendments to simplify the liability framework, but the core principle — that inadequate AI governance creates legal exposure — remains intact. Legislative progression expected through 2026–2027.
Under Revision
2025
Data (Use and Access) Act 2025 — In Force February 5, 2026
The UK's first statutory step toward AI-relevant data obligations. Replaced GDPR Article 22 with new Articles 22A–22D, making solely automated decisions lawful in more circumstances but only where defined safeguards — transparency, human review, the right to contest — are documented. In force from February 5, 2026, this is the most significant UK AI-adjacent legislation as of mid-2026, as no standalone AI Act has passed Parliament.
Active
2023
AI Regulation White Paper — Pro-Innovation Approach (2023, Reaffirmed 2025)
As of July 2026, the UK has no standalone AI Act and no AI Bill before Parliament. The Labour Government reaffirmed the pro-innovation principles-based approach in 2025, but shifted the language from "safety" to "growth." The AI Safety Institute was renamed the AI Security Institute in February 2025, signalling a focus on national security and misuse risks rather than content governance. A Frontier AI Bill has been signalled but is not expected before 2027.
Active
2024
ICO Guidance on Generative AI and Data Protection (Updated 2025)
The ICO has continued expanding its GenAI guidance through 2025, covering AI in the workplace, agentic AI systems, and AI explainability — signalling its next major enforcement priorities. The ICO increasingly works jointly with the FCA on AI in financial services, reflecting the multi-regulator enforcement model the UK has adopted in place of a single AI Act.
Active
2025
FCA Consumer Duty & AI Governance in Financial Services (2025)
The FCA's Consumer Duty (in force July 2023) has become the primary AI accountability mechanism for UK financial services, requiring firms to demonstrate that AI-driven products and services deliver good consumer outcomes. The FCA issued updated AI guidance in 2025 and is expected to publish AI-specific Consumer Duty implementation guidance in 2026 — creating a de facto AI competency requirement for all regulated firms.
Active
2026
AI Security Institute — Frontier AI Trends Report & AI Growth Lab (2025–2026)
The AI Security Institute (rebranded February 2025) published its first Frontier AI Trends Report in December 2025, assessing the capability trajectory of leading AI systems. In parallel, the UK DSIT launched the AI Growth Lab in October 2025 — a regulatory sandbox enabling cross-economy pilots of AI innovations under modified regulatory conditions, with successful pilots able to trigger permanent regulatory reform.
Active
2023
Interim Measures for the Management of Generative AI Services (Effective August 2023)
China's generative AI regulations require providers to conduct security assessments, label AI-generated content, and ensure training data legality. Revised guidance issued in 2025 tightened content labelling requirements and extended obligations to enterprises deploying third-party GenAI APIs. As of 2026, this remains one of the most operationally active AI compliance regimes globally, with regular enforcement actions published by the CAC.
Active
2025
Measures for the Management of AI-Generated Synthetic Content (2025)
Building on the 2022 deepfake regulations, China's 2025 synthetic content rules require all AI-generated images, audio, and video to carry both visible and invisible digital watermarks — a global first in technically mandated AI provenance. Providers must implement content authenticity infrastructure and train staff on watermarking compliance processes.
Active
2022
Provisions on the Management of Algorithmic Recommendations
Governs algorithmic recommendation systems used in content platforms, e-commerce, and search. Requires operators to give users opt-out rights, conduct regular algorithm audits, and train staff on algorithm management obligations. Updated guidance in 2025 extended obligations to recommender systems embedded in enterprise productivity tools and internal HR platforms.
Active
2026
Draft Comprehensive AI Law — Under Legislative Development (2026)
China's forthcoming comprehensive AI law — in active legislative development as of mid-2026 — is expected to consolidate existing sectoral regulations into a unified risk-tiered framework. Early drafts reviewed by legal observers indicate provisions for mandatory AI literacy certification in regulated industries, enterprise AI impact assessment registries, and national AI safety review processes for high-capability systems.
Draft
2025
Japan AI Promotion Act — Approved May 28, 2025; Effective June 4, 2025
Japan's first dedicated AI law, approved by Parliament on May 28, 2025 and effective June 4, 2025. It establishes the AI Strategy Headquarters under the Prime Minister's Office and takes an innovation-first approach — compliance remains guideline-driven under the 2024 AI Guidelines for Business, but the Act creates a legal architecture for future mandatory provisions. Japan becomes the third major Asian jurisdiction (after South Korea and China) with statutory AI governance.
Active
2026
South Korea AI Basic Act — Effective January 22, 2026
South Korea became the first Asian nation with a comprehensive AI framework law, promulgated January 21, 2025 and effective January 22, 2026. The Act establishes national AI governance institutions including an AI safety institute, trustworthiness requirements for high-impact AI systems, and mandatory risk assessments. Extra-territorial effects apply to some cross-border AI activities affecting Korean users — requiring global enterprises to assess applicability.
Active
2025
Singapore AI Verify — Updated for Generative AI (May 29, 2025)
Singapore's IMDA and AI Verify Foundation updated the AI Verify testing toolkit on May 29, 2025 to cover generative AI systems alongside traditional AI. Singapore maintains a voluntary governance model with no comprehensive AI statute — personal data in AI is governed by the PDPA 2012. The updated framework is widely used as a reference across ASEAN and has influenced AI governance toolkits in Malaysia, Thailand, and the Philippines.
Active
2024
India Digital Personal Data Protection Act (DPDP) — Rules Published 2025
India's DPDP Act passed in 2023; implementing rules were published in 2025, activating compliance obligations for data fiduciaries using AI in personal data processing. The rules require documented training programmes for staff managing AI-processed personal data. In parallel, the Indian government is developing a national AI policy framework and considering a standalone AI Act — with public consultation ongoing in 2026.
Active
2024
Canada — AIDA Lapsed (January 2025); Directive on Automated Decision-Making Updated
Canada's Artificial Intelligence and Data Act (AIDA, Bill C-27) died on the Order Paper on January 6, 2025 when Parliament was prorogued. A future AI law will require re-introduction under a new government. The existing Directive on Automated Decision-Making (updated June 24, 2025) requires government systems using AI to meet compliance obligations by June 2026. Ontario's Bill 194 (November 2024) regulates public sector AI provincially.
Lapsed
2025
Australian Govt Response to Safe & Responsible AI Consultation (2025)
Following extensive consultation in 2024, the Australian government published its response in 2025 — confirming mandatory guardrails for high-risk AI and establishing a phased approach to AI regulation. Rather than a standalone AI Act, Australia is embedding AI-specific obligations into existing regulatory frameworks sector by sector, while the Department of Industry develops a national AI governance infrastructure. A National AI Strategy refresh is expected in 2026.
Active
2024
Mandatory Guardrails for High-Risk AI — Voluntary Application Underway (2024–2026)
Australia's 10 mandatory guardrails for high-risk AI — covering human oversight, transparency, accountability, and contestability — are currently applied on a voluntary basis pending legislative backing. Organisations in regulated sectors are encouraged to self-assess against the guardrails, which align closely with the EU AI Act and ISO 42001. Mandatory legislative backing is expected through sector-specific legislation rather than a standalone AI Act.
Voluntary
2023
APS Mandatory AI Policy — Commonwealth AI Literacy Requirements
The Australian Public Service Commission mandated AI literacy training for all Commonwealth agency employees — one of the world's first government-wide mandatory AI fluency requirements. Updated in 2025 with more specific competency expectations for senior executives and Secretaries, making Australia's public sector one of the most AI-literate government workforces globally.
The Australian government released an exposure draft of Privacy Act amendments in 2025 introducing new rights around automated decision-making and AI transparency. When enacted, organisations will be required to notify individuals of AI involvement in significant decisions and provide human review pathways — with direct implications for staff AI competency in HR, credit, and healthcare roles.
Draft Legislation
2024
APRA Prudential Practice Guide — AI & Model Risk (CPG 220 Supplement)
APRA's model risk guidance applies directly to AI systems in credit, underwriting, and investment decisions. The 2024 supplement to CPG 220 sets specific expectations for AI model validation, explainability, and ongoing monitoring. Boards and senior management of regulated entities are expected to demonstrate AI governance literacy sufficient to exercise meaningful oversight — a de facto executive AI fluency mandate for Australia's financial sector.
The UAE approved in 2025 an AI-powered regulatory intelligence ecosystem — making it the first country to use AI to accelerate how laws are drafted, updated, and monitored. This positions the UAE as the global frontier of AI-native governance. The system enables near-real-time regulatory updates and is intended to reduce the lag between AI capability development and appropriate regulatory response across all UAE government sectors.
Active
2023
UAE Federal Decree Law on Personal Data Protection (PDPL) — Updated 2025
The UAE's PDPL governs the processing of personal data including by AI systems. Updated Executive Regulations published in 2025 added specific provisions on automated decision-making transparency and human oversight requirements — organisations must now document AI involvement in significant personal data decisions and ensure relevant staff hold defined AI governance competencies.
Active
2024
DIFC Data Protection Law Amendment — AI & Automated Processing (2024)
DIFC amended its data protection law to address AI specifically — adding algorithmic transparency requirements, profiling controls, and human review rights aligned with GDPR Article 22 principles. Updated DIFC Commissioner guidance in 2025 clarified that Senior Manager responsibility under DIFC's FSMR applies to AI governance — creating a direct C-suite accountability requirement for AI in Dubai's financial hub.
Active
2024
Saudi Arabia PDPL Amendments — AI & Automated Decisions (2024)
Saudi Arabia's updated PDPL regulations (effective 2024) address automated decision-making and AI processing of personal data — aligned with SDAIA's broader AI governance framework. Organisations in Vision 2030 priority sectors (finance, health, education, tourism) face sector-specific AI governance requirements overseen by SDAIA, with compliance audits beginning in 2025 for the largest enterprises.
Active
2026
Qatar National AI Governance Framework — In Active Development (2026)
Qatar's MCIT is finalising a national AI governance framework expected for publication in 2026, covering high-risk AI in finance, healthcare, and government services. Early consultation documents indicate a mandatory AI governance certification scheme closely aligned to ISO 42001 — positioning Qatar to become the first Gulf state with a comprehensive AI certification requirement for enterprises operating in regulated sectors.
In Development
2025
Israel AI Innovation Authority — Responsible AI Policy Framework (Updated 2025)
Israel's Innovation Authority updated its responsible AI policy framework in 2025, adding sector-specific guidelines for healthcare and financial services AI. Despite ongoing geopolitical pressures, Israel's AI regulatory development has accelerated — driven by its globally significant AI R&D ecosystem. The updated framework is referenced in government procurement requirements and shapes expectations for Israeli tech companies in public-sector AI projects.
Active
03 — In Practice
Companies Doing It Right
A growing body of organisations are moving beyond AI experimentation to embed AI fluency as an operational capability — with measurable outcomes. These cases illustrate what responsible, strategic AI adoption looks like in practice.
i. Companies Adapting AI — News & Analysis
Financial Services · 2024
JPMorgan Chase: AI-First at Enterprise Scale
JPMorgan Chase deployed an internal LLM to over 60,000 employees across investment banking, asset management, and operations. Employees are required to complete AI fluency modules before access is granted, with outputs subject to a structured review process. The bank reports measurable gains in research synthesis, document review, and client reporting speed.
Sector: Finance | Scale: 60,000+ users
Healthcare · 2024
Mayo Clinic: Role-Stratified AI Governance
Mayo Clinic established an AI governance board and a clinical AI platform that vets all AI tools before deployment. Rather than training all staff uniformly, they developed role-stratified AI fluency requirements — radiologists, nurses, and administrators each have differentiated competency requirements. This model has been cited by the AMA as a best-practice template.
Sector: Healthcare | Model: Role-stratified
Professional Services · 2024
Deloitte: Embedding AI in Every Engagement
Deloitte announced a $1.4B investment in AI capabilities, including a global AI Academy that has trained over 75,000 professionals. Their model links AI training completion to performance reviews, explicitly connecting fluency to career progression.
Sector: Consulting | Trained: 75,000+
Retail · 2024
Walmart: AI at the Shelf Edge and Supply Chain
Walmart's AI programme is backed by mandatory AI literacy training for store managers and supply chain leads. Associates are assessed on their ability to interpret AI-generated recommendations rather than passively follow them — a crucial distinction that reflects genuine AI fluency.
Sector: Retail | Scope: Global ops
ii. Companies Training Their Employees
01
Amazon
AI Ready: Global Upskilling Initiative
Amazon committed to training 2 million people globally in AI skills through its AI Ready programme. All employees have access to an AI learning passport linked to role-specific competency paths via AWS Skill Builder.
02
Microsoft
AI Skills Initiative & Copilot Adoption
Microsoft pledged to train 2.5 million people across EMEA and APAC. Internally, every business division has Copilot champions — designated AI fluency leads — who track competency uplift via the Microsoft Viva platform.
03
PwC
AI Learning Exchange
PwC invested $1B in AI upskilling across all 75,000 US employees. Uniquely, PwC uses scenario-based assessments — testing judgment and application rather than recall — and uses results to guide individual development plans.
04
Accenture
The AI School for Business Leaders
Accenture's AI School has trained over 250,000 employees, stratified by role from frontline to C-suite, with formal competency certification tied to its LearnVantage platform. Accenture has published its curriculum as a reference for clients.
05
IBM
IBM SkillsBuild & watsonx Badges
IBM's SkillsBuild platform offers AI literacy pathways by job family — HR, finance, legal, IT. The watsonx badge programme provides industry-recognised credentials at three levels (Explorer to Expert), integrated with IBM's talent marketplace.
06
Unilever
AI-First HR: Fluency in People Processes
Unilever integrated AI fluency requirements into its global performance review cycle. Every employee has a documented AI learning goal; managers are assessed on team capability-building — treating fluency as a people metric rather than an IT outcome.
04 — The Framework
AI-Ready Workforce
Building an AI-ready workforce requires a structured, measurable, and continuously updated approach to human capability — spanning how we assess fluency, how we train, and how we integrate AI into the rhythms of work.
A shared language for human-AI capability — built for every role, every industry, every level of the organisation.
The AI Fluency Competency Framework defines what it means to work effectively with AI — not just technically, but strategically, ethically, and operationally. It establishes four progressive levels of fluency mapped across five core competency dimensions, giving organisations a consistent benchmark to assess, develop, and recognise AI capability in their workforce.
Unlike frameworks focused solely on technical skills, this framework is designed for the full workforce — from frontline employees to board directors — acknowledging that AI fluency looks different at every level, but matters at all of them.
4
Progressive fluency levels — from Foundational to Strategic
5
Core competency dimensions spanning understanding to leadership
20
Defined competency statements across the full framework
∞
Industries and roles the framework is designed to serve
The Four Levels of AI Fluency
Level 01
Foundational
All employees · Every function
Understands what AI is, what it can and cannot do, and can engage with AI-assisted tools responsibly in everyday work. Can identify when AI is in use and apply basic judgment about outputs.
AI AwarenessSafe UseBasic Evaluation
Level 02
Practitioner
Knowledge workers · Team leads
Can apply AI tools effectively within their domain, craft purposeful prompts, critically evaluate outputs, and identify when AI recommendations should be challenged or overridden.
Prompt CraftCritical EvaluationRisk Awareness
Level 03
Advanced
Specialists · Managers · Domain leads
Can design and oversee AI-integrated workflows, assess AI tools for organisational fit, manage AI-related risks within their function, and build team AI capability systematically.
Workflow DesignRisk ManagementTeam Development
Level 04
Strategic
Senior leaders · Executives · Board
Can set AI strategy, govern AI risk at an organisational level, engage with regulators and ethics bodies, and create the cultural and structural conditions for an AI-ready workforce.
AI StrategyGovernanceCultural Leadership
Competency Dimensions × Fluency Levels
Dimension
Foundational
Practitioner
Advanced
Strategic
AI Conceptual Understanding
Knows what AI is and how common tools work at a conceptual level
Understands model types, capabilities, and limitations relevant to their domain
Can compare AI approaches and assess technical fit for business problems
Can engage credibly with AI developers, researchers, and external experts
Applied AI Use
Uses AI-assisted tools safely and appropriately in daily tasks
Designs effective prompts and applies AI to accelerate domain-specific work
Integrates AI into team workflows and measures impact on output quality
Champions AI adoption across the organisation and drives capability investment
Critical Evaluation
Can spot obvious errors or inappropriate AI outputs before acting on them
Systematically evaluates AI outputs for accuracy, bias, and fitness for purpose
Establishes team-level quality standards for AI-generated work
Sets organisational standards for AI output quality and human oversight
Ethics, Risk & Responsibility
Understands basic ethical obligations and when to flag AI concerns
Identifies bias, privacy risks, and ethical issues in AI use within their work
Manages AI risk within their function and escalates appropriately
Governs AI risk at an organisational level and engages with regulators
Adaptive & Continuous Learning
Open to learning new AI tools and updates their personal AI practices
Actively keeps pace with AI developments relevant to their domain
Builds team learning culture and keeps AI workflows current as tools evolve
Commits organisational resources to continuous AI capability development
Full Framework — Available on Request
The complete AI Fluency Framework goes deeper.
The detailed version includes the full set of competency descriptors, behavioural indicators, and assessment rubrics for every level and dimension — designed to be used directly by HR, L&D, and business leaders as an operational tool.
20 fully defined competency statements with behavioural indicators
Role-family mapping across 12 industry sectors
Assessment rubric and scoring guide for each competency
Integration guide for performance management and career frameworks
Benchmark data from early adopter organisations
Responded within 2 business days
◈
AI Fluency Assessment
Content to be added by the team
Effective AI training is contextual, continuous, and competency-linked. The most successful organisational programmes share common structural features — moving well beyond awareness sessions toward embedded, role-specific learning that changes how people actually work.
Foundational AI Literacy
Every employee needs a baseline understanding of what AI is, how large language models work conceptually, what they can and cannot do, and what responsible use looks like. This is not technical training — it is the equivalent of knowing how to evaluate information before acting on it.
Role-Specific AI Application
Generic AI training produces generic results. Leading organisations design AI learning pathways mapped to specific job families: HR professionals learn AI in talent acquisition; legal teams learn AI in contract review; finance professionals learn AI in forecasting and anomaly detection.
Critical Evaluation & Prompt Craft
A core AI fluency skill is critically assessing AI outputs — identifying hallucinations, bias, gaps, and risks before acting on AI-generated information. Complemented by practical prompt engineering: designing queries that yield reliable, usable outputs.
Ethical Judgment & Risk Awareness
AI fluency is incomplete without understanding the ethical dimensions of AI use — privacy, bias, accountability, and the human impact of automated decisions. Employees need a working framework for recognising when AI-assisted decisions require additional human scrutiny.
Continuous Learning & Adaptation
The AI landscape evolves at a pace that makes any one-time training programme obsolete within months. Effective architectures build in continuous learning loops — quarterly refreshers, curated news digests, model release briefings, and peer learning communities.
Leadership & Strategic AI Fluency
Executives require a distinct kind of AI fluency: the ability to make sound strategic decisions about AI investment, governance, and risk at an organisational level — including understanding AI capability limits, interpreting audit results, and engaging with regulators.
AI fluency cannot remain siloed in L&D. For it to drive real productivity, it must be integrated into the core processes through which organisations manage performance, risk, legal compliance, and ethical accountability.
05 — Operational Embedding
Process Integrations
AI fluency delivers its greatest value when embedded in the organisational processes that govern how work gets done — not treated as a standalone learning initiative. These four domains represent the most critical integration points for any AI-ready organisation.
⟁
Performance Management
Integrating AI fluency into performance management signals that AI capability is a professional expectation, not an optional extra. Leading organisations set AI learning goals in annual review cycles and recognise AI-augmented productivity in compensation frameworks.
AI fluency goals embedded in annual KPIs and OKRs
Manager certification as AI adoption leads
Competency-linked progression frameworks
AI-augmented output quality as a performance metric
360-degree feedback on AI judgment and ethical use
Quarterly AI fluency check-ins in review cycles
◫
Risk & Compliance
As AI is deployed in regulated contexts, risk and compliance functions must evolve to include AI-specific oversight — understanding model outputs as audit-relevant artefacts and ensuring employees can identify and report AI risk.
AI risk registers mapped to ISO/IEC 42001
Mandatory AI impact assessments for high-risk use cases
AI-specific incident reporting pathways
Compliance training on EU AI Act and sector regulations
Ongoing monitoring of AI outputs in regulated workflows
AI fluency requirements for compliance officers and auditors
◳
Legal
Legal teams face a dual challenge: advising on AI-related legal risk while using AI tools in their own work. AI fluency for legal professionals spans IP implications, liability in AI-assisted decisions, and the rapidly evolving global regulatory landscape.
AI in contract analysis: risk and quality controls
Intellectual property and AI-generated content policies
Liability frameworks for AI-assisted legal decisions
Data privacy compliance in AI tool deployment
AI-specific clauses in vendor and supplier contracts
Legal team AI fluency certification and CPD requirements
⬡
Ethics
Ethical AI use requires operational mechanisms. Leading organisations establish AI ethics review boards, build ethics checkpoints into deployment pipelines, and train employees to apply ethical judgment at the point of AI use.
AI ethics review board with cross-functional representation
Ethics-by-design checkpoints in AI deployment pipelines
Bias audit requirements for customer-facing AI systems
Whistleblower-equivalent pathways for AI misuse reporting
Ethics training embedded in all AI fluency programmes
Alignment with UNESCO AI Ethics Recommendations and ISO 42001
Request the Full Framework
Tell us about your organisation and we'll send the complete AI Fluency Framework.
Full Name
Work Email
Organisation
Role / Function
Primary interest (optional)
◈
Request received.
Thank you — we'll review your request and send the full AI Fluency Framework to your email within 2 business days.