← All resources Guide

Introducing BASTYN Global AI Regulations and Standards Registry

BASTYN team · 24 Sept 2026 · 2 min read

Global AI Regulations and Standards Registry

Introducing BASTYN Global AI Regulations and Standards Registry

AI regulation and trust is no longer defined by a single law or standard.

An AI system may be affected simultaneously by horizontal AI legislation, data-protection law, cybersecurity requirements, sector-specific regulation, product-safety rules and voluntary assurance frameworks. What applies depends on where the system operates, what it does, the data it processes, who it affects and how much authority it has.

The first public release of the BASTYN Global AI Regulations and Standards Registry provides a structured starting point for answering that question.

What the registry contains

The registry includes binding regulations, regulatory milestones, standards, government guidance, security frameworks and relevant assurance schemes.

The registry breaks standards down into operative obligations, restrictions, and binding enforcement milestones. Each record includes:

    Who should use the register

    The registry is designed for organisations developing, deploying, procuring or providing assurance over AI systems.

    It is particularly relevant to

    a) Product leaders and engineering teams determining which regulatory obligations are applicable for requirements, technical controls, testing before development, procurement or deployment.

    b) Risk, Compliance and Audit teams screening applicable legal requirements and establishing which evidence and coverage should exist.

    Users can filter the registry using their system’s jurisdiction, sector, organisational role, capabilities and deployment characteristics. The resulting records provide a prioritised set of candidate requirements for legal, technical and assurance review.

    The registry can also be filtered by theme so you can see the overlapping requirements across multiple standards and regulations. 

    The registry is not intended to produce an automatic legal conclusion or compliance certificate. Applicability still depends on the facts of the deployment, local implementation and current regulatory interpretation.

    Scope of first v1 release

    Version 1.0 prioritises major markets and high-impact AI use cases.

    It includes the EU and EEA, United Kingdom, Switzerland, United States federal law and selected states, Canada, China, Hong Kong, Japan, South Korea, Singapore, India, Australia, the United Arab Emirates, Saudi Arabia, Qatar and Israel.

    It also includes major international and technical frameworks from organisations including ISO/IEC, CEN-CENELEC, ETSI, NIST, IEEE, OWASP, OECD, UNESCO and the Council of Europe.

    Relevant additions include the EU AI Act transparency requirements, the Cyber Resilience Act, EN 18286, emerging NIST AI evaluation and monitoring guidance, agentic-security frameworks, MCP security guidance and AIUC-1.

    The registry is not represented as an exhaustive statement of every law, regulatory interpretation or sector-specific requirement worldwide. Local implementation, regulatory guidance and enforcement positions can also change without the underlying legislation being replaced.

    Every release therefore carries a defined evidence cut-off date. 

    Help us identify missing scope

     

    Download Version 1.0

    Download the first release of the BASTYN Global AI Regulations and Standards Registry.

    Evidence cut-off: 24 September 2026
    Version: 1.0

    -----------------------------------------

    Contribute to the next registry release

    The quality of the registry depends on its completeness. 

    Help us maintain the standards registry. We welcome contributions to advise of any missing standards or regulations not covered or any incorrect data. Each submission will be reviewed before inclusion in the next release version.

    contribute here or https://trustyouragent.org/contact

    The registry is provided for regulatory and assurance screening. It does not constitute legal advice, certification or a determination that a particular requirement applies to a specific AI system.

     

    Subscribe for latest BASTYN Trust Intelligence

    For risk, compliance, product and security experts