The frameworks that apply to you
A reference map of the AI governance and AI security frameworks in force across APAC, the EU, the UK, and China. What each one is, who it binds, and whether compliance is mandatory.
Last reviewed 24 August 2026
HOW TO READ THIS
Binding or voluntary
Regulation carries penalties. Standards and guidance carry expectations, and increasingly appear in customer contracts.
Builder or deployer
Some frameworks govern the party building and selling the AI. Others govern the party deploying and operating it. Few organisations are only one.
NIST AI Risk Management Framework 1.0
Voluntary
Builder, Deployer
Cross-jurisdiction · NIST
A voluntary framework organised around four functions: govern, map, measure, and manage. Accompanied by a Generative AI Profile addressing risks specific to foundation models.
The most frequently named framework in APAC due-diligence questionnaires despite carrying no legal force outside US federal procurement. Note that version 1.0 is currently being revised.
Assessed under Framework Compliance Assessment
NIST Cybersecurity Framework 2.0
Voluntary
Builder, Deployer
Cross-jurisdiction · NIST
General cybersecurity risk framework covering govern, identify, protect, detect, respond and recover. Not AI-specific, but the control baseline most AI security expectations assume is already in place.
AI governance built on a weak security foundation fails at the first incident. This is the substrate, not an alternative to an AI framework.
Framework Compliance Assessment
ISO/IEC 42001:2023
Certifiable
Builder, Deployer
Cross-jurisdiction · ISO/IEC
A management system standard for artificial intelligence, structured like ISO 27001. The only AI framework currently supporting independent third-party certification.
Certification proves you have a system for managing AI risk. It does not prove any individual AI system behaves as intended.
Certification proves you have a system for managing AI risk. It does not prove any individual AI system behaves as intended. Buyers increasingly ask for both.
Covered by ISO 42001 Readiness Support
ISO/IEC 42005:2025
Certifiable
Builder, Deployer
Cross-jurisdiction · ISO/IEC
A practical standard for assessing the impacts of AI systems on people, organisations and society. It provides a structured methodology for identifying, evaluating and documenting potential harms, benefits and affected stakeholders throughout the AI lifecycle.
Think of ISO/IEC 42001 as the management system and ISO/IEC 42005 as the methodology for assessing the impact of specific AI systems.
Supports ISO 42001 Readiness
ISO/IEC 23894:2023
Voluntary
Builder, Deployer
Cross-jurisdiction · ISO/IEC
Guidance on AI risk management, applying the ISO 31000 risk process to AI-specific concerns. Frequently used alongside ISO/IEC 42001 as the risk methodology beneath the management system.
Rarely requested by name, but it is the practical bridge between an existing enterprise risk framework and a new AI management system.
ISO 42001 Readiness and Certification Support
AIUC-1
Certifiable
Builder
Cross-jurisdiction · Artificial Intelligence Underwriting Company
A certifiable standard built specifically for AI agents, spanning six risk pillars: safety, security, reliability, accountability, data and privacy, and society. Certification follows independent third-party audit, with quarterly adversarial retesting and crosswalks to ISO 42001, NIST AI RMF, MITRE ATLAS and OWASP.
The only major standard that ties certification to insurance underwriting. It governs how the agent you are selling behaves, not how your organisation is run.
Framework Compliance Assessment
MITRE ATLAS
Reference
Builder, Deployer
Cross-jurisdiction · MITRE
An adversarial threat landscape knowledge base for AI systems, structured like MITRE ATT&CK. Catalogues real-world tactics and techniques used against machine learning and generative AI systems.
A vocabulary for describing attacks, not a control set you can be assessed against. We use it to scope adversarial testing, not to score compliance.
Testing Programme Design
OWASP Top 10 for LLM Applications
Reference
Builder
Cross-jurisdiction · OWASP Foundation
A community-maintained list of the most critical security risks in large language model applications, covering prompt injection, insecure output handling, training data poisoning, excessive agency and related failure modes.
Engineering teams know it. Risk committees usually do not. It is the fastest way to make AI security concrete for a non-technical audience.
Testing Programme Design
Guidance for AI Adoption (AI6)
Voluntary
Builder, Deployer
Australia · National AI Centre
Published October 2025, this is now the primary Australian Government guidance for responsible AI adoption. It condenses the ten VAISS guardrails into six essential practices: decide accountability, understand impacts, measure and manage risks, share information, test and monitor, and maintain human control. Available in Foundations and Implementation editions.
With no Australian AI Act coming, this is the de facto standard of care. Compliance with legislation was never a defence here, and now it is not even available.
Framework Compliance Assessment
Voluntary AI Safety Standard (VAISS)
Voluntary
Builder, Deployer
Australia · Department of Industry, Science and Resources
Published 5 September 2024. Ten voluntary guardrails applying across the AI supply chain, covering accountability, risk management, data governance, testing, human control, transparency, stakeholder engagement and supply chain requirements.
Still published and still useful. The ten guardrails give a more granular assessment structure than the six practices that superseded them.
Framework Compliance Assessment
National AI Plan
Reference
Builder, Deployer
Australia · Australian Government
Announced 2 December 2025. Sets Australia's regulatory posture: govern AI through existing technology-neutral laws and sector regulators, supported by voluntary guidance and an advisory AI Safety Institute, rather than a standalone AI statute. The September 2024 proposals paper on mandatory guardrails for high-risk AI was not legislated.
The absence of an AI Act is not the absence of obligation. It moves the standard of care to regulators, insurers, and enterprise procurement clauses.
Privacy Act and OAIC guidance on AI
Mandatory
Deployer
Australia · Office of the Australian Information Commissioner
Existing privacy law applies in full to AI systems processing personal information. OAIC has issued specific guidance on commercially available AI products and on developing and training generative AI models.
The most likely source of an actual Australian enforcement action against an AI deployment in the next two years. It is already law.
AI Risk and Governance Review
Artificial Intelligence: Model Personal Data Protection Framework
Voluntary
Deployer
Hong Kong · Office of the Privacy Commissioner for Personal Data
Issued June 2024. Recommendations and best practices for organisations procuring, implementing and using AI, covering AI strategy and governance, risk assessment and human oversight, customisation and management, and communication with stakeholders.
The reference point Hong Kong regulators use when assessing whether an organisation took reasonable care. PCPD has since moved to an active compliance-check posture.
AI Risk and Governance Review
Checklist on Guidelines for the Use of Generative AI by Employees
Voluntary
Deployer
Hong Kong · Office of the Privacy Commissioner for Personal Data
Practical checklist for building an internal generative AI policy, covering scope of permissible use, protection of personal data, lawful and ethical use, data security, and consequences of policy violation.
The shortest route to a defensible internal AI policy in Hong Kong. Most organisations we see have shadow AI use and no policy at all.
AI Risk and Governance Review
HKMA guidance on AI and generative AI
Voluntary
Deployer
Hong Kong · Hong Kong Monetary Authority
A series of circulars and papers to authorised institutions, including high-level principles on AI, consumer protection in respect of big data analytics and AI, and guidance on generative AI in financial services. In March 2026 the HKMA joined the SFC, Insurance Authority and MPFA in launching GenA.I. Sandbox++.
Supervisory expectation, not statute, but for an authorised institution the practical difference is small.
AI Risk and Governance Review
Hong Kong Generative AI Technical and Application Guideline
Voluntary
Builder, Deployer
Hong Kong · Digital Policy Office
Operational guidance for technology developers, service providers and users of generative AI. Covers scope and limitations of application, governance principles, and technical risks including data leakage, model bias and output error.
The closest thing Hong Kong has to a developer-facing AI standard. Useful when the client builds rather than buys.
AI Risk and Governance Review
Model AI Governance Framework for Generative AI
Voluntary
Builder, Deployer
Singapore · Infocomm Media Development Authority
Framework setting out dimensions of trusted generative AI including accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance and safety.
Singapore leads on assurance infrastructure rather than prohibition. Expect its testing expectations to be copied elsewhere in APAC before they are legislated anywhere.
Framework Compliance Assessment
Model AI Governance Framework for Agentic AI
Voluntary
Builder, Deployer
Singapore · Infocomm Media Development Authority
Launched January 2026 and described by IMDA as the first governance framework addressing agentic AI specifically, building on the earlier traditional and generative AI frameworks.
Read alongside the TC260 agent guidance. Two jurisdictions arriving at agent governance from opposite directions within months of each other.
AI Risk and Governance Review
AI Verify
Voluntary
Builder
Singapore · AI Verify Foundation
An open-source testing framework and software toolkit that allows organisations to run technical tests against AI systems and produce standardised reports on governance principles.
One of very few places where an AI governance claim can be backed by an actual test result rather than a policy document.
Testing Programme Design
GB/T 45654-2025
Mandatory
Builder
China · TC260
Cybersecurity technology: basic security requirements for generative artificial intelligence services. Released 25 April 2025, effective 1 November 2025. Covers training data security, model security and safety measures. Targets services with public opinion or social mobilisation attributes, and supports filing, testing and evaluation.
Formally a recommended standard. In practice it is the baseline against which a filing is assessed, which makes it binding for anyone launching a public-facing GenAI service in China.
Framework Compliance Assessment
TC260 Security Guidance for Agent Deployment and Use
Voluntary
Deployer
China · TC260
Published July 2026. Addresses the security discipline expected of organisations deploying and operating AI agents, covering permissions, identity, monitoring and containment of agent actions within the deploying organisation's infrastructure.
TC260 governs the deploying party's infrastructure discipline. AIUC-1 governs the building party's product behaviour. Read together they cover opposite ends of the same agent lifecycle.
AI Risk and Governance Review
AIGC labelling rules (GB 45438-2025)
Mandatory
Builder, Deployer
China · Cyberspace Administration of China
Measures for the administration of labelling of AI-generated content, effective 1 September 2025, with the accompanying mandatory national standard specifying visible labels and embedded metadata identifiers for text, image, audio, video and virtual scenes.
The strictest AI transparency regime currently in force anywhere. Compare it with EU AI Act Article 50 before assuming the EU is the high-water mark.
Framework Compliance Assessment
EU AI Act
Mandatory
Builder, Deployer
EU · European Parliament and Council
Risk-tiered regulation of AI systems placed on or affecting the EU market, with prohibited practices, high-risk system obligations, general-purpose AI model duties, and transparency requirements. Obligations phase in on a staged timetable.
Extraterritorial. An APAC vendor with EU customers is in scope regardless of where the model runs or the company is incorporated.
Framework Compliance Assessment
EU AI Act Article 50 transparency obligations
Mandatory
Builder, Deployer
EU · European Parliament and Council
Requires that people are informed when they interact with an AI system, that synthetic content is machine-readably marked, that deepfakes and AI-generated public interest text are disclosed, and that emotion recognition and biometric categorisation use is notified. Applied from 2 August 2026.
The single obligation most likely to catch an organisation that believed the AI Act did not apply to it. If you run a customer-facing chatbot reachable from the EU, this is live now.
Framework Compliance Assessment
UK sectoral regulator approach to AI
Reference
Builder, Deployer
UK · UK Government
No cross-cutting AI statute. Five cross-sectoral principles are applied by existing regulators including the ICO, FCA, CMA, Ofcom and MHRA within their own remits.
Structurally similar to Australia's position. In both, the operative question is not what the AI rules say but what your sector regulator already expects.
AI Risk and Governance Review
