AI by Industry: Which Authority Governs What

AI Center › AI by Industry: Which Authority Governs What

1ArtificialIntelligence · The Global AI Ecosystem

AI by Industry: Which Authority Governs What

AI by Industry records, sector by sector, which named authority governs artificial intelligence and under which instrument — an AI system regulated as a medical device, an automated driving system approved for road use, an automated hiring tool, an AI-driven credit or coverage decision. Each entry names the authority, states what the instrument requires and of whom, and links to the official text.

This page is deliberately partial. It covers five sectors and says plainly which it does not cover. Entries record what an instrument requires; where a document is published but not yet operative, or recommends rather than commands, that is stated rather than glossed over.

Five sectors are covered here: health and medical devices, road transport and automated driving, employment and hiring, consumer credit and financial services, and insurance and health coverage decisions. Aviation, energy, education, defence, telecommunications and agriculture are NOT covered — in aviation the only candidate instrument is still a consultation proposal, and no adopted sector rule was verified for the others. The gaps here are larger than the coverage, and naming them is part of the record.

Health and medical devices

Instruments that reach an AI system because it is a medical device or a clinical tool. FDA guidance recommends rather than commands; the binding hook is the marketing-authorisation pathway.

US Food and Drug Administration — Center for Devices and Radiological Health, with CBER, CDER and the Office of Combination Products

Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions

Recommends that a manufacturer seeking to modify an AI-enabled device after authorisation include in its 510(k), De Novo or PMA submission a predetermined change control plan describing the planned modifications, the methodology to develop, validate and implement them, and an assessment of their impact, which FDA reviews so that changes within the plan may be made without a new marketing submission.

As of July 31, 2026
US Food and Drug Administration — Center for Devices and Radiological Health, with CBER and CDER

Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations (DRAFT)

Proposes the documentation a manufacturer would include in a marketing submission for a device with AI-enabled software functions to support FDA's evaluation of safety and effectiveness, and proposes design, development and implementation practices across the device total product life cycle. Issued as a draft marked 'not for implementation'; it is published but not operative.

As of July 31, 2026
US Food and Drug Administration — Center for Devices and Radiological Health, with CBER and CDER

Clinical Decision Support Software (final guidance)

Sets out FDA's interpretation of the criteria in section 520(o)(1)(E) of the Federal Food, Drug, and Cosmetic Act that exclude certain clinical decision support software functions from the statutory definition of a device, with worked examples distinguishing Non-Device CDS from device software functions that remain subject to FDA regulation. This edition supersedes the earlier version still cited in much secondary commentary.

As of July 31, 2026
US Food and Drug Administration — Center for Devices and Radiological Health, with CBER, CDER and the Office of Combination Products

Content of Premarket Submissions for Device Software Functions (final guidance)

Recommends the software documentation a manufacturer includes in any premarket submission containing a device software function, using a risk-based determination of the submission's Documentation Level (Basic or Enhanced) to set the minimum information provided.

As of July 31, 2026
European Parliament and Council of the European Union (applied by Member State competent authorities and notified bodies)

Regulation (EU) 2017/745 on medical devices (MDR), Annex VIII Rule 11

Requires manufacturers to classify medical device software by risk before conformity assessment, so that software intended to provide information used to take decisions with diagnostic or therapeutic purposes is class IIa, rising to class III where such decisions may cause death or irreversible deterioration of health and class IIb where they may cause serious deterioration or a surgical intervention, while software intended to monitor physiological processes is class IIa, or class IIb where it monitors vital physiological parameters whose variation could result in immediate danger to the patient.

As of July 31, 2026
European Parliament and Council of the European Union (applied by Member State competent authorities and notified bodies)

Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR), Article 47 and Annex VIII

Requires that in vitro diagnostic devices, including software that is itself an IVD, be divided into classes A, B, C and D according to intended purpose and inherent risk in accordance with Annex VIII, which determines the conformity assessment route and the degree of notified body involvement.

As of July 31, 2026
Medical Device Coordination Group (MDCG), established under Article 103 MDR; published by the European Commission, DG SANTE

MDCG 2019-11 rev.1 — Qualification and classification of software under Regulation (EU) 2017/745 (MDR) and Regulation (EU) 2017/746 (IVDR)

Guides manufacturers on deciding whether a given piece of software qualifies as a medical device or an IVD under the MDR and IVDR and, if so, which risk class it falls into, with worked examples. This edition supersedes the earlier version still cited in much secondary commentary.

As of July 31, 2026
UK Secretary of State for Health and Social Care; enforced by the Medicines and Healthcare products Regulatory Agency (MHRA)

The Medical Devices (Post-market Surveillance Requirements) (Amendment) (Great Britain) Regulations 2024 (SI 2024/1368)

Inserts a new Part 4A into the Medical Devices Regulations 2002, imposing post-market surveillance duties on manufacturers placing medical devices and in vitro diagnostic devices — including software and AI-enabled devices — on the Great Britain market.

As of July 31, 2026
US Department of Health and Human Services — Office for Civil Rights

45 CFR 92.210 — Nondiscrimination in the use of patient care decision support tools (Section 1557, Affordable Care Act)

Prohibits a covered entity from discriminating on the basis of race, colour, national origin, sex, age or disability through its use of patient care decision support tools, and imposes an ongoing duty to make reasonable efforts to identify such tools that employ input variables or factors measuring those characteristics and to mitigate the resulting risk of discrimination.

As of July 31, 2026

Road transport and automated driving

Type-approval and road-use rules for automated driving systems, plus reporting duties on manufacturers and operators.

United Nations Economic Commission for Europe (UNECE), World Forum for Harmonization of Vehicle Regulations (WP.29) — Addendum 156 to the 1958 Agreement

UN Regulation No. 157 — Automated Lane Keeping Systems (ALKS), Revision 1 (01 series of amendments)

Sets the uniform type-approval conditions a vehicle manufacturer must satisfy before an automated lane keeping system — which takes primary control of the vehicle within its operational design domain while the driver remains available to respond to a transition demand — may be approved in a Contracting Party to the 1958 Agreement, covering system safety and failsafe response, the transition demand and minimum risk manoeuvre, driver availability recognition, and an in-vehicle data storage system for automated driving.

As of July 31, 2026
United Nations Economic Commission for Europe (UNECE), World Forum for Harmonization of Vehicle Regulations (WP.29) — Addendum 170 to the 1958 Agreement

UN Regulation No. 171 — Driver Control Assistance Systems (DCAS)

Sets the type-approval safety and performance requirements a vehicle manufacturer must meet for systems that assist the driver in controlling the vehicle's longitudinal and lateral motion on a sustained basis without taking over the entire driving task, including warning strategies that trigger when a lack of driver engagement is detected, and an obligation on manufacturers to communicate the system's limitations and the driver's retained responsibility through all available channels including online, in advertising and at the point of sale.

As of July 31, 2026
European Commission (implementing Regulation (EU) 2019/2144, the General Safety Regulation)

Commission Implementing Regulation (EU) 2022/1426 — type-approval of the automated driving system (ADS) of fully automated vehicles

Requires a manufacturer seeking EU type-approval of a fully automated vehicle of category M or N to demonstrate to the approval authority and technical service that the automated driving system is free from unreasonable risk, through a safety case covering the operational design domain, safety documentation, verification and validation, cybersecurity compliance, event data recording, and in-service monitoring and reporting after placing on the market.

As of July 31, 2026
US National Highway Traffic Safety Administration (NHTSA), Department of Transportation

Standing General Order 2021-01 (Third Amended) — crash reporting for ADS and Level 2 ADAS

Requires the manufacturers and operators named in the Order to report to NHTSA crashes involving vehicles equipped with an automated driving system or SAE Level 2 advanced driver assistance system — for ADS, where the system was in use at any time within 30 seconds of a crash resulting in certain property damage or injury; for Level 2 ADAS, where the system was in use at any time within 30 seconds of a crash that involved a vulnerable road user being struck or resulted in a fatality, an air bag deployment, or a person being transported for treatment.

As of July 31, 2026
United Kingdom Parliament; implemented by the Secretary of State for Transport (Department for Transport)

Automated Vehicles Act 2024 (c. 10)

Creates the Great Britain authorisation scheme under which a road vehicle may only be marketed and used as self-driving if it is authorised against authorisation requirements set by reference to a statement of safety principles, requires every authorised automation feature to have a nominated authorised self-driving entity answerable for the vehicle's behaviour, provides for licensing of no-user-in-charge operators, and restricts the use of terms implying self-driving capability to authorised vehicles.

As of July 31, 2026
Secretary of State for Transport, United Kingdom (made under Part 5 of the Automated Vehicles Act 2024)

The Automated Vehicles (Permits for Automated Passenger Services) Regulations 2026 (SI 2026/439)

Sets the procedural and administrative rules for the permit scheme under which an operator must hold a permit granted by the Secretary of State in order to provide an automated passenger service using vehicles with no human driver, covering application and renewal, a maximum permit duration of five years, grounds and procedures for varying, suspending or withdrawing a permit, internal review, and information sharing with emergency services and authorities.

As of July 31, 2026

Employment and hiring

Rules on automated tools used to screen, interview or manage workers.

New York City Department of Consumer and Worker Protection (DCWP)

New York City Local Law 144 of 2021 (Automated Employment Decision Tools) and the DCWP implementing rule (6 RCNY Subchapter T)

Prohibits an employer or employment agency from using an automated employment decision tool unless the tool has been subject to a bias audit within one year of its use, information about the bias audit is publicly available, and certain notices have been provided to employees or job candidates.

As of July 31, 2026
Illinois General Assembly; enforced by the Illinois Department of Human Rights (IDHR)

Illinois Public Act 103-0804 (HB 3773), amending the Illinois Human Rights Act on artificial intelligence in employment

Makes it a civil rights violation for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of a protected class with respect to recruitment, hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure or the terms, privileges or conditions of employment, to use zip codes as a proxy for a protected class, or to fail to give notice to employees that the employer is using artificial intelligence for those purposes.

As of July 31, 2026
Illinois General Assembly (with demographic reporting to the Illinois Department of Commerce and Economic Opportunity)

Illinois Artificial Intelligence Video Interview Act, 820 ILCS 42

Requires an employer that asks applicants to record a video interview and uses artificial intelligence analysis of that video to notify each applicant before the interview that AI may be used to analyse it, to provide information explaining how the AI works and what general types of characteristics it uses to evaluate applicants, to obtain the applicant's consent before the interview, to refrain from sharing the videos except with persons whose expertise or technology is necessary to evaluate an applicant's fitness for a position, and to delete the videos and instruct any recipients to delete their copies within 30 days of an applicant's request.

As of July 31, 2026
California Civil Rights Council, within the California Civil Rights Department (CRD)

California Civil Rights Council regulations on automated-decision systems in employment (amendments to the FEHA employment regulations)

Provides that a covered entity's use of an automated-decision system may violate the Fair Employment and Housing Act where it harms applicants or employees on the basis of a protected characteristic, treats automated-decision system assessments — including tests, questions or puzzle games that elicit information about a disability — as potentially unlawful medical inquiries, and requires covered entities to preserve employment records including automated-decision system data for a minimum of four years.

As of July 31, 2026
European Parliament and Council of the European Union (enforced by Member State labour authorities after transposition)

Directive (EU) 2024/2831 on improving working conditions in platform work — algorithmic management (Chapter III)

Requires digital labour platforms to inform persons performing platform work about automated monitoring and automated decision-making systems and the main parameters those systems use, prohibits such systems from processing defined categories of personal data including data on emotional or psychological state, private conversations, data gathered outside work activity, and data used to predict the exercise of fundamental rights such as association and collective bargaining, requires that decisions to restrict, suspend or terminate an account or contractual relationship be taken by a human being, and gives workers rights to an explanation of and human review of significant automated decisions.

As of July 31, 2026
Kingdom of Spain, published in the Boletín Oficial del Estado (BOE); supervised in practice by the Inspección de Trabajo y Seguridad Social

Spain — Estatuto de los Trabajadores article 64.4(d) (algorithmic information right), introduced by Ley 12/2021

Gives the works council the right to be informed by the company of the parameters, rules and instructions on which are based the algorithms or artificial intelligence systems that affect decision-making capable of influencing working conditions and access to and retention of employment, including profiling.

As of July 31, 2026

Consumer credit and financial services (product/service rules only)

Consumer-facing duties on automated credit, valuation and trading decisions. Model risk management and outsourcing are on the AI in the Enterprise page, not here.

Consumer Financial Protection Bureau (CFPB)

Equal Credit Opportunity Act / Regulation B — adverse action notification, 12 CFR 1002.9

Requires a creditor that takes adverse action on a credit application to give the applicant a statement of the specific principal reasons for that action, and provides that a statement that the decision rested on the creditor's internal standards or that the applicant failed to achieve a qualifying score on the creditor's credit scoring system is insufficient — a duty that applies whatever technology produced the decision.

As of July 31, 2026
CFPB, OCC, Federal Reserve Board, FDIC, NCUA and FHFA (six agencies jointly)

Quality Control Standards for Automated Valuation Models (interagency final rule), 89 FR 64538

Requires mortgage originators and secondary market issuers that use automated valuation models to determine the collateral value of a mortgage secured by a consumer's principal dwelling to adopt and maintain policies, practices, procedures and control systems designed to produce reliable valuations, guard against data manipulation, avoid conflicts of interest, conduct random sample testing and reviews, and comply with applicable nondiscrimination law.

As of July 31, 2026
European Parliament and Council of the European Union

Directive (EU) 2023/2225 on credit agreements for consumers (Consumer Credit Directive II), Article 18

Provides that where a creditor assesses a consumer's creditworthiness by automated processing of personal data, the consumer may obtain human intervention on the part of the creditor, receive a meaningful and comprehensible explanation of the assessment and of the functioning of the automated processing, express their point of view, and request a review of both the creditworthiness assessment and the credit decision.

As of July 31, 2026
European Commission (delegated act adopted on ESMA draft regulatory technical standards), supplementing Directive 2014/65/EU (MiFID II) Article 17

Commission Delegated Regulation (EU) 2017/589 (RTS 6) — organisational requirements for investment firms engaged in algorithmic trading

Requires investment firms engaged in algorithmic trading to apply a documented methodology to develop and test trading algorithms before deployment and after material updates, obtain senior-management authorisation for deployment, conformance-test interaction with trading venues, test in an environment separated from production, deploy under pre-set limits on instruments, order values, positions and venues, and carry out an annual self-assessment and validation of their algorithmic systems and controls.

As of July 31, 2026
US Securities and Exchange Commission (SEC)

SEC Rule 15c3-5 — Risk Management Controls for Brokers or Dealers with Market Access (17 CFR 240.15c3-5)

Requires a broker-dealer with access to trading securities directly on an exchange or alternative trading system, including one providing sponsored or direct market access to customers, to establish, document and maintain risk management controls and supervisory procedures reasonably designed to limit its financial exposure and to ensure compliance with applicable regulatory requirements, including pre-order-entry controls that prevent orders exceeding pre-set credit or capital thresholds, orders that appear erroneous, and orders in securities the firm or customer is restricted from trading.

As of July 31, 2026

Insurance and health coverage decisions

Rules on automated decisions in insurance underwriting and health coverage.

Colorado Commissioner of Insurance, Colorado Division of Insurance (DORA), under SB21-169

Amended Colorado Insurance Regulation 10-1-1 (3 CCR 702-10) — governance and risk management framework requirements for insurers' use of external consumer data and information sources, algorithms and predictive models

Requires insurers authorised in Colorado that offer individual life insurance, private passenger automobile insurance or health benefit plans and that use external consumer data and information sources, or algorithms and predictive models that use such sources, in any insurance practice to establish a risk-based governance and risk management framework with policies, procedures, systems and controls designed to determine whether that use results in unfair discrimination with respect to race and to remediate it where detected.

As of July 31, 2026
California Legislature; enforced by the California Department of Managed Health Care (health care service plans) and the California Insurance Commissioner (disability insurers)

California SB 1120 (2024, Chapter 879) — artificial intelligence in health coverage utilization review

Requires a health care service plan or disability insurer that uses artificial intelligence, an algorithm or other software tool for utilization review to base determinations on the enrollee's own clinical history, circumstances and records rather than solely on a group dataset, prohibits the tool from denying, delaying or modifying services based on medical necessity — reserving that determination to a licensed physician or licensed health care professional — and requires the tool to be applied fairly, reviewed periodically for accuracy and reliability, and open to inspection for audit or compliance review.

As of July 31, 2026

How this switchboard is maintained

  • Each entry names the issuing authority, states what the instrument requires and of whom, and links to the authority's own official text.
  • Only instruments are listed. Programmes of work, published lists, roadmaps and consultation proposals are excluded however informative they are, because none of them requires anything of anyone.
  • Sector rules are amended and renumbered constantly, so each entry is checked against the issuing authority's current version. Where a newer version exists, the current reference is given; where a document is published but not yet operative, that is stated.
  • Where an instrument recommends rather than binds — as United States Food and Drug Administration guidance does by its own terms — the entry says so.
  • Coverage is partial by design, and the sectors that are not covered are named rather than left to inference.
  • Cross-sector duties on organisations deploying AI — model risk management, outsourcing, procurement — are recorded separately, on the AI in the Enterprise page.

Does an AI system that is a medical device also fall under AI-specific law?

It can fall under both. The EU Medical Device Regulation classifies medical device software by risk and predates the EU AI Act; an AI system that is a medical device is subject to the sector regime and to the horizontal AI regime, each administered by its own authorities.

That is why sector rules are recorded here and horizontal AI statutes are recorded separately in the Global AI Governance Register. The two answer different questions: the Register answers whether AI law binds you in a given jurisdiction, while this page answers which sector authority regulates the product or service you are building and under which instrument. Where they overlap, both apply.

Source: Regulation (EU) 2017/745 on medical devices — consolidated text ↗

Why are some entries marked as published but not operative?

Because on a page about what is required, the difference between a document existing and a document binding is the whole point. A draft guidance carrying the words 'not for implementation' imposes nothing, and recording it as a requirement would be wrong.

Several instruments here sit in that state, and each says so. Others recommend rather than command: United States Food and Drug Administration guidance documents state on their face that they contain non-binding recommendations, with the binding obligation arising from the marketing-authorisation pathway rather than the guidance. The AI Center records the instrument's own characterisation of itself rather than describing everything as a rule.

Source: 1BusinessWorld AI Center — Methodology & Sources ↗

Cite this directory

1BusinessWorld AI Center, "AI by Industry: Which Authority Governs What." https://1businessworld.com/ai-center/ai-by-industry/ Version as of July 31, 2026.

The AI Center is informational only. It is provided by 1BusinessWorld strictly for general informational and educational purposes. Nothing in the AI Center constitutes, or should be construed as, legal, regulatory, compliance, technical, engineering, security, investment, financial, or other professional advice, or a recommendation, endorsement, solicitation, or offer regarding any technology, product, model, provider, framework, or course of action. 1BusinessWorld is not a law firm, regulatory authority, standards body, conformity-assessment or certification body, or investment adviser, and nothing in the AI Center creates any advisory, fiduciary, attorney-client, or other professional relationship with 1BusinessWorld. Although the AI Center references official materials published by legislatures, regulators, standards bodies, research organizations, and other named authorities, 1BusinessWorld makes no representation or warranty, express or implied, as to the accuracy, completeness, timeliness, or fitness for any purpose of any content, and, to the fullest extent permitted by law, disclaims all liability for any loss or damage of any kind arising directly or indirectly from the use of, or reliance on, any information presented. Laws, regulations, standards, technical practices, and AI capabilities change frequently and differ by jurisdiction; readers must verify all information against the current official text or source and consult qualified legal, compliance, technical, and other professional advisors before acting. Any decision relating to the development, deployment, procurement, or governance of AI systems is made solely at the reader's own risk. Last reviewed: July 31, 2026.