AI Compliance Academy

🏭 Industries

Pick your sector to see which AI uses are regulated, the laws by region, and a checklist you can start on today.

HR & hiringRecruiting and people decisions are the most regulated use of AI for ordinary businesses. CV screeners, video-interview scoring, chatbots that pre-screen, promotion or scheduling algorithms and productivity monitoring all count. The EU treats employment AI as high-risk (from December 2027), Illinois bans discriminatory effect and requires notice, NYC requires annual bias audits, Ontario requires disclosure in job ads, and US courts are letting applicants sue the software vendors themselves.6 regulated usesFinance, credit & lendingCredit scoring, loan approval, fraud detection, tenant and customer screening and robo-advice are classic 'consequential decisions'. The EU AI Act lists creditworthiness assessment of natural persons as high-risk; Colorado's ADMT Act covers lending from 2027; Quebec requires notice and human review of fully automated decisions; and US fair-lending and fair-housing law already impose disparate-impact liability, as the SafeRent settlement shows. Existing sector rules (adverse-action notices, model risk management) apply on top.5 regulated usesInsuranceUnderwriting, pricing, claims triage and fraud models decide who gets cover and at what price. The EU AI Act treats risk assessment and pricing in life and health insurance as high-risk; Colorado's ADMT Act names insurance as a consequential-decision sector from 2027; Quebec's Law 25 gives policyholders rights over fully automated decisions; and state insurance regulators increasingly expect governance programmes for AI models. Proxy discrimination through postcode, credit or occupation data is the central risk.5 regulated usesHealthcare & wellbeingClinical decision support, triage bots, scribing tools, mental-health chatbots and eligibility decisions sit at the sharp end of AI regulation. Medical-device rules already apply to diagnostic software; the EU AI Act adds high-risk duties for AI in regulated medical devices (Annex I, from August 2028) and for access to healthcare services (Annex III, December 2027). Texas requires providers to disclose AI used in treatment; Utah requires AI disclosure in medical and mental-health interactions and regulates mental-health chatbots. Health data is special-category data everywhere.5 regulated usesEducation & trainingAdmissions scoring, automated grading, proctoring, plagiarism/AI-detection tools and adaptive tutoring systems all make decisions about learners, many of them minors. The EU AI Act lists admissions, assessment and proctoring as high-risk (December 2027) and bans emotion recognition in schools; Colorado names education as a consequential-decision sector; Canadian and EU privacy law limit what you can collect about students. False positives from AI-detection tools and biased proctoring are the most frequent complaints.5 regulated usesPublic sector & government suppliersGovernments face the strictest rules and the most public scrutiny. Canada's Treasury Board Directive requires a published Algorithmic Impact Assessment before any federal automated decision system launches; the EU AI Act treats benefits eligibility, law enforcement, migration and justice uses as high-risk and bans social scoring and most real-time biometric identification; Texas bans government social scoring and biometric identification and requires agencies to disclose AI interactions. Vendors selling to the public sector inherit these duties by contract.5 regulated usesMarketing, media & customer-facing AIGenerative content, customer-service chatbots, personalisation and synthetic media are where most SMBs first meet AI law. The EU AI Act's transparency rules (chatbot disclosure, deepfake labelling, machine-readable marking) have applied since August 2026; California requires large providers to embed provenance and offer detection tools and all generative developers to publish training-data summaries; Utah requires chatbots to admit they are AI when asked; and courts and regulators hold you to whatever your bot tells customers, as Air Canada learned.6 regulated usesLegal & professional servicesLaw firms, accountants, advisers and legal-tech products use AI for research, drafting, review and client-facing advice. The risks are confidentiality, hallucinated citations, unauthorised practice and over-claiming. The FTC's DoNotPay case shows that calling a product a 'robot lawyer' without testing is deceptive advertising; Utah requires licensed professionals to disclose generative AI use up front; the EU AI Act treats AI that assists judicial authorities as high-risk; and professional conduct rules everywhere require competence and supervision of tools.5 regulated uses

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.