Hael
Sign inRequest a demo

AI GOVERNANCE FRAMEWORKS

Every AI framework, on one record.

ISO/IEC 42001 is the certificate enterprise buyers screen for. The EU AI Act is the law that will be enforced against you. NIST AI RMF is the method US buyers expect. Hael classifies every AI system against all of them, and produces the substantive artefact each regime demands — the Statement of Applicability, the Annex IV technical file, the impact assessment — generated from live operational state and sealed with hash-chained provenance.

INTERNATIONAL
ISO/IEC 42001
AI Management System (2023)

The certifiable AI management system standard. 72% of enterprise buyers screen for it before the first RFP round. Hael produces the full AIMS: Statement of Applicability across all Annex A controls, AI system register, risk assessments, internal audit pack and management review — audit-gated for your certification body.

EUROPEAN UNION
EU AI Act
Regulation (EU) 2024/1689

Risk-tiered AI regulation. Article 11 demands a complete technical documentation file in Annex IV order before high-risk systems are placed on the market. The artefact the regulator opens.

PHASED EFFECTIVE THROUGH 2027Coverage detail →
UNITED STATES
NIST AI RMF + GAI Profile
AI 100-1 / AI 600-1

GOVERN, MAP, MEASURE, MANAGE plus the July 2024 Generative AI Profile. The de-facto US AI risk-management language; named by Colorado and Texas as a recognised framework.

VOLUNTARY BASELINECoverage detail →
EUROPEAN UNION
GDPR
Regulation (EU) 2016/679

AI under GDPR: Article 22 safeguards for solely-automated decisions, Article 35 DPIAs, and the Article 5/6/9 lawful-basis duties that bite on training and inference. EDPB Opinion 28/2024 is current guidance.

UNITED KINGDOM
UK AI principles
Pro-innovation white paper + sector regulators

Five cross-sectoral principles enforced through ICO, FCA/PRA, MHRA, CMA and Ofcom. No horizontal Act yet; sector regulators carry the duties.

OPERATIVE — PRINCIPLES-BASEDCoverage detail →
COLORADO, USA
Colorado AI Act
SB 26-189 (ADMT Act, repealed & replaced SB 24-205)

ADMT disclosure duties · SB 26-189 · from Jan 2027. Pre-use notice, 30-day adverse-outcome explanation, human review, correction and three-year records. Hael runs each duty as a control on the record.

EFFECTIVE 1 JAN 2027Coverage detail →
TEXAS, USA
Texas RAIGA
HB 149

Intent-based prohibitions on harmful AI uses, enforced by the Texas AG with a 60-day cure period and a 36-month sandbox. Hael holds the acceptable-use policy and NIST-aligned risk programme that operate as affirmative defences.

EFFECTIVE 1 JAN 2026Coverage detail →
NEW YORK CITY
NYC Local Law 144
Automated Employment Decision Tools

Independent bias audit (≤12 months), published summary and candidate notice for AEDTs. Hael maintains the audit, summary and notice as living artefacts.

CALIFORNIA, USA
California ADMT / CCPA
CPPA ADMT regulations

Pre-use notice, opt-out, access and risk-assessment duties for ADMT used in significant decisions, behavioural-advertising profiling and extensive profiling. Hael generates each artefact.

FULL CONSUMER RIGHTS 1 JAN 2027Coverage detail →
ILLINOIS, USA
Illinois HB 3773 / AIVIA
IHRA AI amendment + AIVIA

Effects-based bar on AI that produces discriminatory outcomes across the employment lifecycle; mandatory worker notice; no zip-code proxies. Hael runs the disparate-impact testing and notice lifecycle.

EFFECTIVE 1 JAN 2026Coverage detail →
UTAH, USA
Utah AI Policy Act
SB 149 (as amended by HB 452)

Generative-AI consumer disclosure under UCSPA; up-front disclosure in regulated occupations; operator liability for AI acts. The OAIP runs the AI Learning Lab sandbox.

REPUBLIC OF KOREA
Korea AI Basic Act
인공지능 기본법

High-impact AI risk-management and documentation duties; generative-AI labelling; domestic-representative requirement for foreign operators above MSIT thresholds.

EFFECTIVE 22 JAN 2026Coverage detail →
CHINA
China Generative AI / Algo
CAC Generative AI · Algorithmic Recommendation · Deep Synthesis

Filing-and-evidence regime: CAC algorithm filing, security assessment where triggered, lawful-training-data records, and mandatory AI-generated-content labelling (in force 1 Sep 2025).

ALL FOUR OPERATIVECoverage detail →

ALSO RELEVANT

Hael also tracks the OECD AI Principles, Singapore's Model AI Governance Framework, California SB 53 (TFAIA), the New York RAISE Act, DORA, SOC 2 and the US Treasury FS AI RMF. They inform classification and reuse but are not part of the engine's resolved framework set — the thirteen above are what the Classify engine actually decides against, and what the Hael application generates artefacts for.

Talk to us about coverage for your specific exposure.

Request a demoSee the platform