ai-regulationlisted
Install: claude install-skill VandanaAjayDubey111/great-pm
# AI regulation — product-side playbook
AI regulation moved from theoretical to operational in 2024-2026. EU AI
Act phased in 2025-2026. NYC LL 144 (AI hiring) enforced. Colorado SB
205, NY DFS AI guidance, state AI bills proliferating. The classic
mistake: assuming "we're not high-risk" without doing the analysis.
## 1. EU AI Act — the most comprehensive frame
In force, phasing 2025-2027.
### Risk tiers
| Tier | Examples | Obligation |
|---|---|---|
| Unacceptable risk | Social scoring; emotion recognition in workplace/school; predictive policing on protected characteristics | PROHIBITED |
| High risk | AI in: hiring, lending, education access, healthcare diagnostics, law enforcement decisions, critical infrastructure | Conformity assessment, risk management, transparency, human oversight, accuracy + robustness, post-market monitoring |
| Limited risk | Chatbots, deepfakes | Transparency (disclose AI involvement) |
| Minimal risk | Spam filter, video game AI | No obligation |
### General-purpose AI (GPAI) — separate frame
Applies to foundation models (LLMs, multimodal). Obligations vary by
"systemic risk" threshold (compute, capability).
**Most products using third-party LLMs**: deploy-side obligations apply
(transparency, risk mgmt for high-risk use cases).
### Timeline
- Prohibited practices: Feb 2025
- GPAI rules: Aug 2025
- High-risk obligations: Aug 2026
- Full enforcement: 2027
## 2. US federal — non-binding but influential
### NIST AI RMF (Risk Management