Plain-English references for the regulations and frameworks that shape AI risk today — the EU AI Act, the NIST AI Risk Management Framework, and the fast-moving US landscape. These are the same sources Shadow AI Discovery maps your findings against, so your reports and your reading share one vocabulary.
The world's first horizontal AI law — the four risk tiers, GPAI and systemic-risk models, the key articles (5, 9, 10, 13, 14, 50, 53, 55, 72), Annex III & IV, the compliance timeline, and penalties up to €35M / 7%.
Read the explainer →The voluntary US framework built on four functions — Govern, Map, Measure, Manage — plus the Generative AI Profile (NIST AI 600-1) that adapts it to foundation models and agents.
Read the explainer →The patchwork: federal posture and OMB guidance, state laws (Colorado AI Act, California AB 2013 & SB 942, Utah AI Policy Act), and sector enforcement via the FTC and HIPAA.
Read the explainer →AI risk lives at the intersection of several rulebooks at once — a single deployed model can be a high-risk system under the EU AI Act, a "GAI" risk under the NIST profile, and subject to a US state transparency law. Rather than repeat definitions in every report, we keep one authoritative, plain-English reference here and map every framework to the same evidence you already collect.