AI Compliance Standards
The standards that govern AI and your data, explained
Plain-language guides to the frameworks and laws organizations in Canada, the United States, and the EU are measured against when employees use AI on real data: what each one requires, who it applies to, what the penalties are, and the practical steps that satisfy it. Verified against primary sources, not summaries of summaries.
AI Governance Frameworks
EU AI Act
European Union, with extraterritorial reach
In force since August 1, 2024; obligations applying in phases through 2027
The world's first comprehensive AI law, with risk-based obligations, phased deadlines, and fines up to EUR 35 million or 7% of worldwide turnover. Explained here for organizations inside and outside the EU whose people and products touch AI.
Read the guideISO/IEC 42001
International (voluntary, certifiable)
Published December 2023; voluntary but certifiable by accredited auditors
The first certifiable international management-system standard for AI. Explained here through its risk and impact assessment requirements, and what they mean for data privacy when employees use AI tools at work.
Read the guideNIST AI RMF
United States (voluntary, used internationally)
Voluntary framework, published January 2023; Generative AI Profile added July 2024
The US government's voluntary framework for managing AI risk, built around four functions: Govern, Map, Measure, and Manage. Explained here as it applies to data privacy and everyday AI use at work.
Read the guideCanadian Privacy & AI Law
AIDA (Bill C-27)
Canada (federal, never enacted)
Died with Bill C-27 in January 2025; no successor AI act as of August 2026
Canada's proposed AI law died when Parliament was prorogued in January 2025, and no successor AI act has been tabled since. What AIDA would have required, what actually governs Canadian AI use now, and what to watch next.
Read the guidePIPEDA
Canada (federal, private-sector commercial activity)
In force since 2001; reform bill C-36 tabled June 2026 would replace its privacy part
Canada's federal private-sector privacy law, built on 10 fair information principles. Explained here as it applies to feeding personal information into AI tools, from consent and safeguards to prompts sent to US-hosted vendors.
Read the guideQuebec Law 25
Quebec, Canada (private and public sectors)
Fully in force; final phase (data portability) effective September 2024
Quebec's modernized privacy law, the strictest in North America, with fines up to C$25M or 4% of worldwide turnover. Explained here as it applies to AI tools: mandatory privacy impact assessments, automated-decision transparency, and data leaving Quebec.
Read the guideUS Education & Children’s Privacy
COPPA
United States (applies to operators worldwide whose services are directed to, or knowingly collect from, US children under 13)
In force since 2000; amended COPPA Rule effective June 23, 2025, full compliance required by April 22, 2026
The US federal law on collecting personal information from children under 13, updated in 2025 with direct consequences for AI: separate opt-in consent before children's data can train models, retention limits, and stronger safe-harbor oversight.
Read the guideFERPA
United States (all schools and postsecondary institutions receiving federal education funds)
In force since 1974; US Department of Education AI guidance issued 2023-2025
The US federal law protecting student education records, explained as it applies to AI: chatbots, AI graders, tutoring tools, and the teacher who pastes a student's file into a consumer chatbot.
Read the guideUS State AI & Privacy Laws
CCPA / CPRA
California, United States
In force; CPRA amendments effective January 1, 2023; ADMT, risk assessment, and cybersecurity audit regulations approved September 2025, phasing in through 2027 and beyond
California's privacy law, the strictest in the US, now reaches AI directly: prompts containing personal information count as disclosures, AI vendors can lose service-provider status, and the CPPA's ADMT regulations phase in through January 1, 2027.
Read the guideColorado AI Act
Colorado, United States
Enacted May 2024, twice delayed, then repealed and replaced by SB 26-189 in May 2026; the replacement takes effect January 1, 2027
Colorado passed the first comprehensive US state AI law in 2024, then rewrote it in 2026. Here is what the replacement law (SB 26-189) actually requires of organizations using AI in consequential decisions, and what it means for data privacy.
Read the guideNYC Local Law 144
New York City (jobs and promotions located in NYC, wherever the employer or tool vendor is based)
Enacted 2021; enforced since July 5, 2023
The first US law to regulate AI hiring tools directly: annual independent bias audits, public posting of results, and advance notice to candidates before an automated employment decision tool is used on them.
Read the guideSecurity & Audit Frameworks
ISO/IEC 27001
International (voluntary, certifiable)
In force, certifiable; current edition published October 2022
The world's leading certifiable standard for information security management, read here through an AI lens: what employee use of external AI tools means for your ISMS, your risk assessment, and controls like information transfer and data leakage prevention.
Read the guideSOC 2
United States origin; used globally as the B2B trust standard
Voluntary attestation standard; 2017 Trust Services Criteria with revised points of focus (2022) are current
SOC 2 is not a law, but for B2B software it is the de facto trust bar. Here is how employee use of external AI tools threatens the Confidentiality and Privacy criteria, and what auditors now ask about shadow AI in Type II audits.
Read the guideEvery standard here asks the same question: do you control what enters AI tools?
Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools are actually in use.