Open, source-backed tracking of AI regulation

AI Policy Tracker is an open-source reference for AI laws, guidance and the duties they create, with every record linked to its official source. Dignep built it and maintains it in the open, and both the code and the data are free to reuse.

  • Code: Apache-2.0
  • Data: CC BY 4.0
  • 212 jurisdictions listed
  • Human-verified records

The problem: AI rules are global, the tracking isn't

Compliance teams, product owners and public-sector buyers now have to follow AI regulation in several countries at once. The tools for that are uneven. Large jurisdictions such as the EU and the US are covered by many trackers, while South Asia, ASEAN, Africa, the Gulf and Latin America often get a paragraph.

Two more problems make the existing summaries hard to act on. Many don't link to the instrument they describe, and readers can't tell whether a date was checked last week or two years ago. If you're building controls or answering an auditor, an unsourced summary isn't evidence.

AI Policy Tracker takes a narrower, deeper position: every claim can be traced back to the official text.

What we built

A public site, an open dataset and a read-only API, organised around one chain: a law creates a duty, a duty is met by a control, and a control produces evidence.

Jurisdictions and instruments

Start from a country or bloc and see its regulatory status, binding rules versus guidance, regulators and official sources. Each law or strategy has a plain-language record with scope, dates and obligations.

Obligations and controls

Requirements are broken out as practical duties with the article they come from and who they bind. Each one maps to the controls that meet it and the evidence a reviewer would expect.

Changes and deadlines

A dated change log with an RSS feed and a weekly email digest, a deadline calendar, and a side-by-side comparison of two to four jurisdictions.

AI risk and incidents

Recorded AI incidents from the AI Incident Database and the MIT AI Risk Repository taxonomy, linked to the policies that respond to each category of harm.

Templates and guides

XLSX and DOCX templates, such as an AI inventory, risk register and EU AI Act and ISO/IEC 42001 kits, generated from the records and versioned when the law changes. No account needed.

Open data and API

JSON and CSV exports, a read-only REST API that needs no key, an OpenAPI description and an llms.txt file.

How a record goes from source to site

Records are never inferred. If a date, penalty or obligation can't be established from the source, the field stays empty and the confidence level says so.

  1. Start from an official document

    Each record is created from legislation, a gazette, or a regulator or ministry publication, with its URL, publisher and access date.

  2. Write it in plain language

    Status, dates, scope and obligations are summarised in original wording with article references. No legal commentary or standards text is copied.

  3. Store it as reviewable data

    Records live as YAML files in the repository, each type checked against a JSON Schema. A validation command runs in CI, and the database is rebuilt from these files on every deploy.

  4. Have a person verify it

    A named reviewer opens the source, confirms each field and sets the verification date. Until then the record is labelled source-linked, not verified.

  5. Log every change

    Each development becomes a dated change event. Affected records are re-verified and versioned in the repository.

Tech stack

Taken from the repository's README and dependency files.

LayerTechnology
ApplicationPHP 8.3 and Laravel, server-rendered Blade templates
Front endTailwind CSS 3 and a small progressive-enhancement script; React with Inertia for the account and sign-in screens
DatabasePostgreSQL in production; SQLite for local development and fast test runs
DataYAML records with a JSON Schema per record type
TemplatesXLSX and DOCX files generated from the records with PhpSpreadsheet and PhpWord
Tooling and CIVite, ESLint, Laravel Pint, PHPUnit and GitHub Actions; the test suite runs on both SQLite and PostgreSQL 16, plus security scans
DeploymentDocker containers behind nginx, deployed from GitHub Actions with automatic rollback if the new release doesn't come up

Open-source licence and how to contribute

Licences

The code is released under the Apache License 2.0 and the policy data under Creative Commons Attribution 4.0 (CC BY 4.0). Third-party datasets keep their own licences: the AI Incident Database is CC BY-SA 4.0 and the MIT AI Risk Repository is CC BY 4.0.

Contributing

Corrections to the data are the fastest way to help. Use "Report a correction" on any record, the contribution form, or a GitHub issue. Code and data changes come in as pull requests that pass lint, tests and five review gates: engineering, UI/UX, documentation, compliance and security.

Reviewers wanted. The project needs people with legal, policy or compliance expertise in specific jurisdictions to verify records. Reviewers are credited on the records they verify.

How it connects to our AI governance work

The repository's NOTICE file states the project is built by Dignep Group Pvt. Ltd., and it is founded and maintained by Bhaskar Bhatt, Dignep's founder. We use the same law-to-duty-to-control-to-evidence model in client engagements.

When we scope AI governance and security work, the first questions are always which rules apply and what evidence will be asked for. Keeping that research in the open means clients, auditors and anyone else can check our reading of a regulation against the source. Certifyi, the GRC platform, is a separate product for running compliance tasks; the tracker doesn't depend on it.

Questions about the project

Is AI Policy Tracker legal advice?

No. The site is informational. A verified record means a reviewer has checked it against the official source, not that anyone has given a legal opinion. Confirm dates and obligations in the linked source, and talk to qualified counsel before acting on them.

Can we reuse the data in our own tools?

Yes. The policy dataset is published under CC BY 4.0, so you can reuse it with attribution, through the JSON and CSV exports or the read-only API, which needs no key. Third-party datasets shown on the site, such as the AI Incident Database, keep their own licences.

Do we need a Certifyi account to use it?

No. Certifyi is a separate product for turning obligations into owned tasks and evidence. AI Policy Tracker is the open, public reference, and nothing on it requires an account there.

Need to know which AI rules apply to you?

Book a 30-minute discovery call. We'll map the regulations that reach your AI systems and the evidence you'll need, then send a written proposal within two working days.

Scroll to Top