AI rules differ sharply from one market to the next. The EU has a horizontal AI Act with risk tiers, the UK takes a principles-based route with no single statute, the UAE runs three regimes at once with the DIFC's Regulation 10 as hard law, Saudi Arabia leads with SDAIA's AI ethics, and India relies on its DPDP Act and IT Rules advisories. We track how 12 AI-governance controls are treated in each market, cited to source.
Six AI-governance overviews, each grading all 12 tracked controls by how firmly the law requires them.
7 required controls · View overview →
First horizontal AI law; risk tiers; transparency live Aug 2026.
5 required controls · View overview →
No AI Act; five cross-sector principles; ICO guidance.
5 required controls · View overview →
Three regimes; DIFC Regulation 10 is hard AI law.
5 required controls · View overview →
SDAIA is data and AI authority; AI Ethics Principles.
2 required controls · View overview →
No AI Act; synthetic-media labelling and CERT-In live now.
2 required controls · View overview →
Soft-law strategy; PDPPL supplies the binding duties.
Every control on a market page carries one of these grades. Read them as how firmly that market's law requires the control, not as a score.
Binding law or regulation mandates it, with a cited provision.
Near-mandatory once a common trigger is met, or backed by binding guidance.
Advisable and risk-reducing, but not strictly mandated.
Emerging - worth monitoring as the law develops.
The control does not apply in this market.
Answer a few questions and PrivMatrix shows exactly which AI-governance controls your market requires, then generates the policies, registers and disclosures that close each gap.