Compliance & Regulation

A regulatory map, not a marketing checklist.

VerifAI is built against the enacted text, jurisdiction by jurisdiction. This page shows what we are aligned to, and — honestly — what any vendor cannot promise on your behalf.

EU

European Union

AI Act Articles 53 to 55 — enforcement floor: August 2, 2026

The EU AI Act's obligations on providers of general-purpose AI models begin to apply in full on August 2, 2026. Article 53 sets out documentation and transparency duties. Article 54 covers appointed representatives for non-EU providers. Article 55 adds evaluation, systemic-risk mitigation, and incident reporting for models designated as posing systemic risk.

VerifAI's Compliance Kit is written against the enacted text, not a summary of it. The evidence surface — training documentation, deployment records, incident trail — is structured to answer the questions the AI Office is expected to actually ask.

US

United States

Model risk (SR 11-7), critical-infrastructure kill switch, and state law

US federal AI regulation remains sectoral. For banks, SR 11-7 is the operative model-risk framework and now the de facto template for governing generative and agentic systems.

State law is moving faster than federal. Colorado's AI Act (SB24-205, effective 2026) sets consumer-notice and documentation duties for high-risk AI. California and New York are moving on shutdown authority and frontier-model safety reporting. Any US deployment worth defending needs an inventory of models, a documented kill path, and a clear owner.

UK

United Kingdom

Regulator-led, principles-first — with real teeth in FS and healthcare

The UK's AI Regulation White Paper approach places responsibility with existing regulators — the FCA, PRA, MHRA, ICO, and Ofcom — rather than a single AI act. In practice that means an AI system in UK financial services already sits inside SS1/23 model risk expectations, and one in health already sits inside MHRA software-as-a-medical-device.

JP

Japan

METI AI Guidelines + the Hiroshima Process

Japan has stayed lighter-touch than the EU but has converged on the same evidence expectations through the Hiroshima Process and the METI/MIC AI Guidelines for Business. A single evidence pipeline can satisfy EU Article 53 documentation and Japanese transparency expectations at the same time.

CN

China

GenAI Interim Measures — filing, labelling, content control

China's Interim Measures for the Management of Generative AI Services (in force since 2023, extended in 2025) require algorithm filing, content labelling for AI-generated media, and adherence to socialist core values. Multinationals operating in China maintain a separate compliance track; VerifAI's evidence layer is compatible with the filing structure but does not substitute for local filing itself.

AU

Australia

Voluntary AI Safety Standard, with a mandatory guardrail proposal

The Australian government has issued a Voluntary AI Safety Standard and is consulting on mandatory guardrails for high-risk AI. VerifAI's compliance surface is designed to satisfy the voluntary standard today and to convert cleanly into mandatory documentation when the guardrails become law.

GDPR — running verifiable AI in Europe.

If your AI runs in Europe, or touches an EU data subject, GDPR applies. VerifAI is designed so the evidence layer helps rather than fights the regulation.

EU data residency

Pin training and inference to an EU region — GCP europe-west, Azure Sweden Central or West Europe, AWS Frankfurt or Stockholm. Signed evidence and decision logs stay in the same region as the model that produced them.

Right to erasure (Art. 17)

Subject-level tags on training records let you locate a data subject's contribution and issue a documented erasure or retraining request. The evidence trail records the deletion, not the data.

Lawful basis & DPIA

Training documentation aligns with Article 35 DPIA questions and Article 22 (automated decisions). You get a structured input to your own DPIA — you still run and sign it.

DPA & sub-processors

Standard Data Processing Addendum on request, with SCCs where a transfer is unavoidable. Sub-processor list is short and disclosed; you decide who is in scope for your deployment.

Audit & access logs

Every VeriBOX decision is timestamped and attributable. Access to evidence is scoped by role and logged for a defensible audit trail.

Breach & notification

Incident hooks feed your 72-hour notification workflow (Art. 33). We help you evidence what was affected; the notification itself remains your controller obligation.

GDPR marketing copy, not legal advice. VerifAI acts as processor for the evidence layer; the controller obligations — lawful basis, DPIA sign-off, breach notification — stay with you. Confirm your posture with qualified EU counsel.

Nothing on this page is legal advice. VerifAI ships an evidence layer; it does not warrant regulatory compliance on your behalf. Verify the enacted text and consult qualified counsel in your jurisdiction.