AI regulation by industry
AI is not regulated by one law. The EU AI Act sets horizontal rules, but the obligations an AI system actually carries depend on its sector: healthcare, insurance, lending, hiring, critical infrastructure and machinery each add their own. This guide lists the rules that apply to AI in each, what they require and when, with a primary source for every one.
Last reviewed 24 September 2026 · Sources linked for every rule
How AI is regulated in healthcare and medical devices
Clinical AI is regulated as a medical device when it informs diagnosis or treatment; in the EU it also becomes high-risk AI from 2 August 2028, and in the US HIPAA and Section 1557 govern the data it uses and the fairness of its decisions.
| Rule | What it requires of AI | Status |
|---|---|---|
| EU AI Act — AI in medical devices (Art. 6(1), Annex I)EU | AI that is, or is a safety component of, a device under the MDR or IVDR is high-risk: risk management, data governance, logging, human oversight and post-market monitoring. Source ↗ | Applies from 2 August 2028 |
| FDA device software and clinical decision supportUS | Software that informs clinical decisions is a device unless it meets all four non-device CDS criteria, including that the clinician can independently review the basis for the recommendation. Source ↗ | In force; AI lifecycle guidance still draft (Jan 2025); change-control-plan guidance final (Dec 2024) |
| HIPAA Privacy and Security RulesUS | Protected health information may not be used or disclosed beyond what is permitted; de-identification under Safe Harbor removes 18 identifier types (45 CFR 164.514(b)). Source ↗ | In force; Security Rule overhaul still proposed, final action not expected before July 2027 |
| Section 1557 — patient care decision support tools (45 CFR 92.210)US | Covered entities must make reasonable efforts to identify and mitigate the risk of discrimination from decision-support tools they use. Source ↗ | In force since 1 May 2025 |
How AI is regulated in insurance
AI used in insurance underwriting, pricing and claims is regulated today in the US through the NAIC model bulletin (adopted by 25 states as of July 2026) and Colorado's testing rules, and in the EU AI for life and health insurance pricing becomes high-risk from 2 December 2027.
| Rule | What it requires of AI | Status |
|---|---|---|
| EU AI Act — life and health insurance (Annex III, point 5(c))EU | AI used for risk assessment and pricing of natural persons in life and health insurance is high-risk. Source ↗ | Applies from 2 December 2027 |
| NAIC Model Bulletin on the Use of AI Systems by InsurersUS states | Insurers must maintain a written AI systems program covering governance, risk management, internal controls and third-party AI, and must not produce unfair discrimination. Source ↗ | Adopted by 25 states as of July 2026; more in progress |
| Colorado SB21-169 and Regulation 10-1-1Colorado | Governance and quantitative testing to show external consumer data and algorithms do not unfairly discriminate, with annual compliance reports. Source ↗ | Life insurers since November 2023; private passenger auto and health benefit plans since 1 July 2026 |
How AI is regulated in banking, lending and financial services
Lenders using AI must still give specific reasons for every credit denial under ECOA and Regulation B, must govern models under supervisory model-risk guidance (SR 26-2), and in the EU AI credit scoring of individuals becomes high-risk from 2 December 2027.
| Rule | What it requires of AI | Status |
|---|---|---|
| EU AI Act — creditworthiness and credit scoring (Annex III, point 5(b))EU | AI that evaluates the creditworthiness of natural persons or sets their credit score is high-risk (fraud detection is excluded). Source ↗ | Applies from 2 December 2027 |
| ECOA and Regulation B adverse action notices (12 CFR 1002.9)US | A creditor that denies or changes credit terms must state the specific principal reasons, including when the decision came from a complex AI model. Source ↗ | In force; the CFPB withdrew its AI-specific circulars in May 2025, but the regulation itself is unchanged |
| Model risk management (Federal Reserve SR 26-2)US | Banks must validate models, govern their use and monitor their performance, and supervisors apply this to AI and machine-learning models. Source ↗ | In force; SR 26-2 replaced SR 11-7 on 17 April 2026 |
| Colorado AI Act, as rewritten by SB 189 (2026)Colorado | Narrowed in May 2026 to disclosure and transparency duties around automated decision-making in consequential decisions such as lending. Source ↗ | Effective 1 January 2027 |
How AI is regulated in employment and hr
AI used to recruit, promote, fire or monitor workers is high-risk under the EU AI Act from 2 December 2027, workplace emotion recognition has been banned in the EU since 2 February 2025, and New York City requires annual bias audits of automated hiring tools.
| Rule | What it requires of AI | Status |
|---|---|---|
| EU AI Act — employment (Annex III, point 4)EU | AI for recruitment and selection, decisions on promotion or termination, task allocation and monitoring of workers is high-risk. Source ↗ | Applies from 2 December 2027 |
| EU AI Act — emotion recognition at work (Art. 5(1)(f))EU | Inferring the emotions of people in the workplace is prohibited, except for medical or safety reasons. Source ↗ | Prohibited since 2 February 2025 |
| NYC Local Law 144 — automated employment decision toolsNew York City | An independent bias audit within the past year, a public summary of results, and notice to candidates before an automated tool is used. Source ↗ | Enforced since 5 July 2023 |
| Title VII of the Civil Rights ActUS | Selection procedures, including AI tools, that cause disparate impact on protected groups must be job-related and consistent with business necessity. Source ↗ | In force |
How AI is regulated in utilities and critical infrastructure
AI that acts as a safety component in running electricity, gas, heating, water or critical digital infrastructure is high-risk under the EU AI Act from 2 December 2027, on top of sector cybersecurity rules such as NIS2 and NERC CIP.
| Rule | What it requires of AI | Status |
|---|---|---|
| EU AI Act — critical infrastructure (Annex III, point 2)EU | AI used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity is high-risk. Source ↗ | Applies from 2 December 2027 |
| NIS2 Directive (EU) 2022/2555EU | Essential entities in energy, water and digital infrastructure must manage cybersecurity risk, including in the systems AI runs on, and report significant incidents. Source ↗ | In force (national transposition) |
| NERC CIP reliability standardsNorth America | Cyber systems that operate the bulk electric system, including AI-enabled tools in scope, must meet NERC critical infrastructure protection standards. Source ↗ | In force |
How AI is regulated in construction, machinery and industrial equipment
From 20 January 2027 the EU Machinery Regulation requires third-party conformity assessment for machinery whose safety functions rely on AI, and from 2 August 2028 such AI is also high-risk under the EU AI Act; site safety duties apply whatever tools are used.
| Rule | What it requires of AI | Status |
|---|---|---|
| Machinery Regulation (EU) 2023/1230EU | Safety components and machinery with self-evolving (AI) behaviour in safety functions need third-party conformity assessment, plus new cybersecurity requirements for safety control systems. Source ↗ | Applies from 20 January 2027 |
| EU AI Act — AI in regulated products (Art. 6(1), Annex I)EU | AI that is a safety component of machinery covered by EU harmonisation law is high-risk. Source ↗ | Applies from 2 August 2028 |
| OSHA construction standards (29 CFR 1926)US | Employers remain responsible for site safety, including hazards introduced by AI-guided equipment, robotics and monitoring systems. Source ↗ | In force |
Frequently asked questions
How is AI regulated in healthcare and medical devices?
Clinical AI is regulated as a medical device when it informs diagnosis or treatment; in the EU it also becomes high-risk AI from 2 August 2028, and in the US HIPAA and Section 1557 govern the data it uses and the fairness of its decisions.
How is AI regulated in insurance?
AI used in insurance underwriting, pricing and claims is regulated today in the US through the NAIC model bulletin (adopted by 25 states as of July 2026) and Colorado's testing rules, and in the EU AI for life and health insurance pricing becomes high-risk from 2 December 2027.
How is AI regulated in banking, lending and financial services?
Lenders using AI must still give specific reasons for every credit denial under ECOA and Regulation B, must govern models under supervisory model-risk guidance (SR 26-2), and in the EU AI credit scoring of individuals becomes high-risk from 2 December 2027.
How is AI regulated in employment and hr?
AI used to recruit, promote, fire or monitor workers is high-risk under the EU AI Act from 2 December 2027, workplace emotion recognition has been banned in the EU since 2 February 2025, and New York City requires annual bias audits of automated hiring tools.
How is AI regulated in utilities and critical infrastructure?
AI that acts as a safety component in running electricity, gas, heating, water or critical digital infrastructure is high-risk under the EU AI Act from 2 December 2027, on top of sector cybersecurity rules such as NIS2 and NERC CIP.
How is AI regulated in construction, machinery and industrial equipment?
From 20 January 2027 the EU Machinery Regulation requires third-party conformity assessment for machinery whose safety functions rely on AI, and from 2 August 2028 such AI is also high-risk under the EU AI Act; site safety duties apply whatever tools are used.
Sources
- Regulation (EU) 2026/1744 (EUR-Lex)
- FDA: AI in software as a medical device
- HHS: HIPAA
- HHS: Section 1557
- NAIC: Artificial intelligence
- Colorado Division of Insurance
- eCFR: 12 CFR 1002.9
- Federal Reserve SR 26-2
- Colorado General Assembly: SB24-205
- Regulation (EU) 2024/1689 (EUR-Lex)
- NYC DCWP: AEDT
- EEOC: Title VII
- EUR-Lex: Directive (EU) 2022/2555
- NERC: CIP standards
- EUR-Lex: Regulation (EU) 2023/1230
- OSHA: Construction
This guide summarises obligations for orientation; it is not legal advice.