AI Center › AI by Industry: Which Authority Governs What
1ArtificialIntelligence · The Global AI Ecosystem
AI by Industry: Which Authority Governs What
AI by Industry records, sector by sector, which named authority governs artificial intelligence and under which instrument — an AI system regulated as a medical device, an automated driving system approved for road use, an automated hiring tool, an AI-driven credit or coverage decision. Each entry names the authority, states what the instrument requires and of whom, and links to the official text.
This page is deliberately partial. It covers five sectors and says plainly which it does not cover. Entries record what an instrument requires; where a document is published but not yet operative, or recommends rather than commands, that is stated rather than glossed over.
Five sectors are covered here: health and medical devices, road transport and automated driving, employment and hiring, consumer credit and financial services, and insurance and health coverage decisions. Aviation, energy, education, defence, telecommunications and agriculture are NOT covered — in aviation the only candidate instrument is still a consultation proposal, and no adopted sector rule was verified for the others. The gaps here are larger than the coverage, and naming them is part of the record.
Health and medical devices
Instruments that reach an AI system because it is a medical device or a clinical tool. FDA guidance recommends rather than commands; the binding hook is the marketing-authorisation pathway.
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
Recommends that a manufacturer seeking to modify an AI-enabled device after authorisation include in its 510(k), De Novo or PMA submission a predetermined change control plan describing the planned modifications, the methodology to develop, validate and implement them, and an assessment of their impact, which FDA reviews so that changes within the plan may be made without a new marketing submission.
Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations (DRAFT)
Proposes the documentation a manufacturer would include in a marketing submission for a device with AI-enabled software functions to support FDA's evaluation of safety and effectiveness, and proposes design, development and implementation practices across the device total product life cycle. Issued as a draft marked 'not for implementation'; it is published but not operative.
Clinical Decision Support Software (final guidance)
Sets out FDA's interpretation of the criteria in section 520(o)(1)(E) of the Federal Food, Drug, and Cosmetic Act that exclude certain clinical decision support software functions from the statutory definition of a device, with worked examples distinguishing Non-Device CDS from device software functions that remain subject to FDA regulation. This edition supersedes the earlier version still cited in much secondary commentary.
Content of Premarket Submissions for Device Software Functions (final guidance)
Recommends the software documentation a manufacturer includes in any premarket submission containing a device software function, using a risk-based determination of the submission's Documentation Level (Basic or Enhanced) to set the minimum information provided.
Regulation (EU) 2017/745 on medical devices (MDR), Annex VIII Rule 11
Requires manufacturers to classify medical device software by risk before conformity assessment, so that software intended to provide information used to take decisions with diagnostic or therapeutic purposes is class IIa, rising to class III where such decisions may cause death or irreversible deterioration of health and class IIb where they may cause serious deterioration or a surgical intervention, while software intended to monitor physiological processes is class IIa, or class IIb where it monitors vital physiological parameters whose variation could result in immediate danger to the patient.
Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR), Article 47 and Annex VIII
Requires that in vitro diagnostic devices, including software that is itself an IVD, be divided into classes A, B, C and D according to intended purpose and inherent risk in accordance with Annex VIII, which determines the conformity assessment route and the degree of notified body involvement.
MDCG 2019-11 rev.1 — Qualification and classification of software under Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR)
Guides manufacturers on deciding whether a given piece of software qualifies as a medical device or an IVD under the MDR and IVDR and, if so, which risk class it falls into, with worked examples. This edition supersedes the earlier version still cited in much secondary commentary.
The Medical Devices (Post-market Surveillance Requirements) (Amendment) (Great Britain) Regulations 2024 (SI 2024/1368)
Inserts a new Part 4A into the Medical Devices Regulations 2002, imposing post-market surveillance duties on manufacturers placing medical devices and in vitro diagnostic devices — including software and AI-enabled devices — on the Great Britain market.
45 CFR 92.210 — Nondiscrimination in the use of patient care decision support tools (Section 1557, Affordable Care Act)
Prohibits a covered entity from discriminating on the basis of race, colour, national origin, sex, age or disability through its use of patient care decision support tools, and imposes an ongoing duty to make reasonable efforts to identify such tools that employ input variables or factors measuring those characteristics and to mitigate the resulting risk of discrimination.
Road transport and automated driving
Type-approval and road-use rules for automated driving systems, plus reporting duties on manufacturers and operators.
UN Regulation No. 157 — Automated Lane Keeping Systems (ALKS), Revision 1 (01 series of amendments)
Sets the uniform type-approval conditions a vehicle manufacturer must satisfy before an automated lane keeping system — which takes primary control of the vehicle within its operational design domain while the driver remains available to respond to a transition demand — may be approved in a Contracting Party to the 1958 Agreement, covering system safety and failsafe response, the transition demand and minimum risk manoeuvre, driver availability recognition, and an in-vehicle data storage system for automated driving.
UN Regulation No. 171 — Driver Control Assistance Systems (DCAS)
Sets the type-approval safety and performance requirements a vehicle manufacturer must meet for systems that assist the driver in controlling the vehicle's longitudinal and lateral motion on a sustained basis without taking over the entire driving task, including warning strategies that trigger when a lack of driver engagement is detected, and an obligation on manufacturers to communicate the system's limitations and the driver's retained responsibility through all available channels including online, in advertising and at the point of sale.
Commission Implementing Regulation (EU) 2022/1426 — type-approval of the automated driving system (ADS) of fully automated vehicles
Requires a manufacturer seeking EU type-approval of a fully automated vehicle of category M or N to demonstrate to the approval authority and technical service that the automated driving system is free from unreasonable risk, through a safety case covering the operational design domain, safety documentation, verification and validation, cybersecurity compliance, event data recording, and in-service monitoring and reporting after placing on the market.
Standing General Order 2021-01 (Third Amended) — crash reporting for ADS and Level 2 ADAS
Requires the manufacturers and operators named in the Order to report to NHTSA crashes involving vehicles equipped with an automated driving system or SAE Level 2 advanced driver assistance system — for ADS, where the system was in use at any time within 30 seconds of a crash resulting in certain property damage or injury; for Level 2 ADAS, where the system was in use at any time within 30 seconds of a crash that involved a vulnerable road user being struck or resulted in a fatality, an air bag deployment, or a person being transported for treatment.
Automated Vehicles Act 2024 (c. 10)
Creates the Great Britain authorisation scheme under which a road vehicle may only be marketed and used as self-driving if it is authorised against authorisation requirements set by reference to a statement of safety principles, requires every authorised automation feature to have a nominated authorised self-driving entity answerable for the vehicle's behaviour, provides for licensing of no-user-in-charge operators, and restricts the use of terms implying self-driving capability to authorised vehicles.
The Automated Vehicles (Permits for Automated Passenger Services) Regulations 2026 (SI 2026/439)
Sets the procedural and administrative rules for the permit scheme under which an operator must hold a permit granted by the Secretary of State in order to provide an automated passenger service using vehicles with no human driver, covering application and renewal, a maximum permit duration of five years, grounds and procedures for varying, suspending or withdrawing a permit, internal review, and information sharing with emergency services and authorities.
Employment and hiring
Rules on automated tools used to screen, interview or manage workers.
New York City Local Law 144 of 2021 (Automated Employment Decision Tools) and the DCWP implementing rule (6 RCNY Subchapter T)
Prohibits an employer or employment agency from using an automated employment decision tool unless the tool has been subject to a bias audit within one year of its use, information about the bias audit is publicly available, and certain notices have been provided to employees or job candidates.
Illinois Public Act 103-0804 (HB 3773), amending the Illinois Human Rights Act on artificial intelligence in employment
Makes it a civil rights violation for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of a protected class with respect to recruitment, hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure or the terms, privileges or conditions of employment, to use zip codes as a proxy for a protected class, or to fail to give notice to employees that the employer is using artificial intelligence for those purposes.
Illinois Artificial Intelligence Video Interview Act, 820 ILCS 42
Requires an employer that asks applicants to record a video interview and uses artificial intelligence analysis of that video to notify each applicant before the interview that AI may be used to analyse it, to provide information explaining how the AI works and what general types of characteristics it uses to evaluate applicants, to obtain the applicant's consent before the interview, to refrain from sharing the videos except with persons whose expertise or technology is necessary to evaluate an applicant's fitness for a position, and to delete the videos and instruct any recipients to delete their copies within 30 days of an applicant's request.
California Civil Rights Council regulations on automated-decision systems in employment (amendments to the FEHA employment regulations)
Provides that a covered entity's use of an automated-decision system may violate the Fair Employment and Housing Act where it harms applicants or employees on the basis of a protected characteristic, treats automated-decision system assessments — including tests, questions or puzzle games that elicit information about a disability — as potentially unlawful medical inquiries, and requires covered entities to preserve employment records including automated-decision system data for a minimum of four years.
Directive (EU) 2024/2831 on improving working conditions in platform work — algorithmic management (Chapter III)
Requires digital labour platforms to inform persons performing platform work about automated monitoring and automated decision-making systems and the main parameters those systems use, prohibits such systems from processing defined categories of personal data including data on emotional or psychological state, private conversations, data gathered outside work activity, and data used to predict the exercise of fundamental rights such as association and collective bargaining, requires that decisions to restrict, suspend or terminate an account or contractual relationship be taken by a human being, and gives workers rights to an explanation of and human review of significant automated decisions.
Spain — Estatuto de los Trabajadores article 64.4(d) (algorithmic information right), introduced by Ley 12/2021
Gives the works council the right to be informed by the company of the parameters, rules and instructions on which are based the algorithms or artificial intelligence systems that affect decision-making capable of influencing working conditions and access to and retention of employment, including profiling.
Consumer credit and financial services (product/service rules only)
Consumer-facing duties on automated credit, valuation and trading decisions. Model risk management and outsourcing are on the AI in the Enterprise page, not here.
Equal Credit Opportunity Act / Regulation B — adverse action notification, 12 CFR 1002.9
Requires a creditor that takes adverse action on a credit application to give the applicant a statement of the specific principal reasons for that action, and provides that a statement that the decision rested on the creditor's internal standards or that the applicant failed to achieve a qualifying score on the creditor's credit scoring system is insufficient — a duty that applies whatever technology produced the decision.
Quality Control Standards for Automated Valuation Models (interagency final rule), 89 FR 64538
Requires mortgage originators and secondary market issuers that use automated valuation models to determine the collateral value of a mortgage secured by a consumer's principal dwelling to adopt and maintain policies, practices, procedures and control systems designed to produce reliable valuations, guard against data manipulation, avoid conflicts of interest, conduct random sample testing and reviews, and comply with applicable nondiscrimination law.
Directive (EU) 2023/2225 on credit agreements for consumers (Consumer Credit Directive II), Article 18
Provides that where a creditor assesses a consumer's creditworthiness by automated processing of personal data, the consumer may obtain human intervention on the part of the creditor, receive a meaningful and comprehensible explanation of the assessment and of the functioning of the automated processing, express their point of view, and request a review of both the creditworthiness assessment and the credit decision.
Commission Delegated Regulation (EU) 2017/589 (RTS 6) — organisational requirements for investment firms engaged in algorithmic trading
Requires investment firms engaged in algorithmic trading to apply a documented methodology to develop and test trading algorithms before deployment and after material updates, obtain senior-management authorisation for deployment, conformance-test interaction with trading venues, test in an environment separated from production, deploy under pre-set limits on instruments, order values, positions and venues, and carry out an annual self-assessment and validation of their algorithmic systems and controls.
SEC Rule 15c3-5 — Risk Management Controls for Brokers or Dealers with Market Access (17 CFR 240.15c3-5)
Requires a broker-dealer with access to trading securities directly on an exchange or alternative trading system, including one providing sponsored or direct market access to customers, to establish, document and maintain risk management controls and supervisory procedures reasonably designed to limit its financial exposure and to ensure compliance with applicable regulatory requirements, including pre-order-entry controls that prevent orders exceeding pre-set credit or capital thresholds, orders that appear erroneous, and orders in securities the firm or customer is restricted from trading.
Insurance and health coverage decisions
Rules on automated decisions in insurance underwriting and health coverage.
Amended Colorado Insurance Regulation 10-1-1 (3 CCR 702-10) — governance and risk management framework requirements for insurers' use of external consumer data and information sources, algorithms and predictive models
Requires insurers authorised in Colorado that offer individual life insurance, private passenger automobile insurance or health benefit plans and that use external consumer data and information sources, or algorithms and predictive models that use such sources, in any insurance practice to establish a risk-based governance and risk management framework with policies, procedures, systems and controls designed to determine whether that use results in unfair discrimination with respect to race and to remediate it where detected.
California SB 1120 (2024, Chapter 879) — artificial intelligence in health coverage utilization review
Requires a health care service plan or disability insurer that uses artificial intelligence, an algorithm or other software tool for utilization review to base determinations on the enrollee's own clinical history, circumstances and records rather than solely on a group dataset, prohibits the tool from denying, delaying or modifying services based on medical necessity — reserving that determination to a licensed physician or licensed health care professional — and requires the tool to be applied fairly, reviewed periodically for accuracy and reliability, and open to inspection for audit or compliance review.
How this switchboard is maintained
- Each entry names the issuing authority, states what the instrument requires and of whom, and links to the authority's own official text.
- Only instruments are listed. Programmes of work, published lists, roadmaps and consultation proposals are excluded however informative they are, because none of them requires anything of anyone.
- Sector rules are amended and renumbered constantly, so each entry is checked against the issuing authority's current version. Where a newer version exists, the current reference is given; where a document is published but not yet operative, that is stated.
- Where an instrument recommends rather than binds — as United States Food and Drug Administration guidance does by its own terms — the entry says so.
- Coverage is partial by design, and the sectors that are not covered are named rather than left to inference.
- Cross-sector duties on organisations deploying AI — model risk management, outsourcing, procurement — are recorded separately, on the AI in the Enterprise page.
Does an AI system that is a medical device also fall under AI-specific law?
It can fall under both. The EU Medical Device Regulation classifies medical device software by risk and predates the EU AI Act; an AI system that is a medical device is subject to the sector regime and to the horizontal AI regime, each administered by its own authorities.
That is why sector rules are recorded here and horizontal AI statutes are recorded separately in the Global AI Governance Register. The two answer different questions: the Register answers whether AI law binds you in a given jurisdiction, while this page answers which sector authority regulates the product or service you are building and under which instrument. Where they overlap, both apply.
Source: Regulation (EU) 2017/745 on medical devices — consolidated text ↗
Why are some entries marked as published but not operative?
Because on a page about what is required, the difference between a document existing and a document binding is the whole point. A draft guidance carrying the words 'not for implementation' imposes nothing, and recording it as a requirement would be wrong.
Several instruments here sit in that state, and each says so. Others recommend rather than command: United States Food and Drug Administration guidance documents state on their face that they contain non-binding recommendations, with the binding obligation arising from the marketing-authorisation pathway rather than the guidance. The AI Center records the instrument's own characterisation of itself rather than describing everything as a rule.
Cite this directory
1BusinessWorld AI Center, "AI by Industry: Which Authority Governs What." https://1businessworld.com/ai-center/ai-by-industry/ Version as of July 31, 2026.
The AI Center is informational only. It is provided by 1BusinessWorld strictly for general informational and educational purposes. Nothing in the AI Center constitutes, or should be construed as, legal, regulatory, compliance, technical, engineering, security, investment, financial, or other professional advice, or a recommendation, endorsement, solicitation, or offer regarding any technology, product, model, provider, framework, or course of action. 1BusinessWorld is not a law firm, regulatory authority, standards body, conformity-assessment or certification body, or investment adviser, and nothing in the AI Center creates any advisory, fiduciary, attorney-client, or other professional relationship with 1BusinessWorld. Although the AI Center references official materials published by legislatures, regulators, standards bodies, research organizations, and other named authorities, 1BusinessWorld makes no representation or warranty, express or implied, as to the accuracy, completeness, timeliness, or fitness for any purpose of any content, and, to the fullest extent permitted by law, disclaims all liability for any loss or damage of any kind arising directly or indirectly from the use of, or reliance on, any information presented. Laws, regulations, standards, technical practices, and AI capabilities change frequently and differ by jurisdiction; readers must verify all information against the current official text or source and consult qualified legal, compliance, technical, and other professional advisors before acting. Any decision relating to the development, deployment, procurement, or governance of AI systems is made solely at the reader's own risk. Last reviewed: July 31, 2026.