The Nine Different Things “AI Regulation” Can Mean
The nine different things “AI regulation” can mean.
The EU AI Act and the NIST AI Risk Management Framework both get called “AI regulation” in casual conversation. A compliance team preparing for one would get almost nothing useful out of preparing for the other.
UNESCO’s Consultation Paper on AI Regulation: Emerging Approaches Across the World makes a simple, useful point that gets lost whenever “AI regulation” is used as if it names one thing: it does not. The paper sets out nine distinct regulatory strategies governments are actually using, deliberately ordered from the lightest touch to the most binding, and the honest reading of any new AI law starts with placing it on that list, not with asking whether it “counts” as regulation.
Several of these approaches are already sitting on our own Statute, doing genuinely different jobs under the same label.
Same shelf, different tools
At the enabling end, a facilitating approach tries to shape a market rather than restrain one. The NIST AI Risk Management Framework, is the clean example: nobody is fined for ignoring it, and it is increasingly cited in contracts and procurement anyway, because a shared vocabulary for AI risk turned out to be worth adopting on its own merits.
A standards-based approach sits a step further along, where a technical standard becomes the practical yardstick a binding rule points to, rather than the rule spelling out every requirement itself, the way ISO/IEC 42001 functions for organisations building an AI management system even without a personal certification behind it.
Further along still, a risk-based approach stops treating “AI” as one category and sorts systems by what they could actually do to someone. The EU AI Act is the reference case for this: prohibited practices, high-risk obligations, and light-touch transparency duties are three different regimes inside one law, sorted by risk tier rather than by technology. Layered on top of that same Act, its Article 50 duties are a separate approach in their own right, an access-to-information mandate that does not classify risk at all; it just requires telling people plainly when they are looking at AI-generated content, regardless of what tier the system sits in.
A mandatory rights-based approach skips technical classification altogether and starts from a right. The Council of Europe’s AI treaty, binds signatory states to protect human rights, democracy, and the rule of law against AI harms, full stop, with no risk tier to argue about first. And where nobody has written new AI-specific law at all, an adapting existing laws approach reaches for what is already on the books: Illinois amended its Human Rights Act, not a new AI statute, to cover AI in hiring decisions, which means the reference point for what counts as a violation is decades of existing employment law, not a new AI-specific test.
Two we haven’t seen much of yet, on our own Atlas at least
An agile and experimentalist approach, regulatory sandboxes that let a company test something under looser rules with a regulator watching directly, is one UNESCO documents as a real, growing pattern elsewhere, but it is not something we have a clean Statute example of yet… The same goes for a pure liability approach, assigning responsibility and consequences after something goes wrong rather than setting rules in advance: still more emergent than established, and arguably the approach with the most room left to develop.
Why the distinction is the useful part
None of these nine are mutually exclusive, and most real AI laws combine two or three at once, which is exactly why treating “is my organisation AI-regulated” as a yes-or-no question misses the actual work!
The EU AI Act alone runs a risk-based core with a rights-based backbone and a transparency mandate bolted on. Knowing which of the nine you are actually looking at, for any specific obligation, is what tells you whether the right response is a policy document, a technical standard to adopt, a risk assessment, or a straightforward disclosure to the people affected. Those are four different jobs, and “we are compliant with AI regulation” is not a sentence that tells you which one got done.
Our own Statute tracks sixteen of these laws and frameworks, updated as they change, precisely so a specific obligation can be checked against a specific approach rather than a vague category.
Written by us at Ethics Directive, drawing on UNESCO’s Consultation Paper on AI Regulation: Emerging Approaches Across the World for the nine-approach framework, applied here to laws already verified on our own Atlas. Summarised and applied in our own words, not reproduced from any single source. If anything here needs correcting, we will say so in the open, dated.
See where your own obligations actually sit.
Sixteen laws and frameworks, tracked and dated, from binding regulation to voluntary frameworks that shape the market anyway. Updated as they change, not written once and left.