The regulatory landscape for AI in the workplace is moving fast and unevenly across jurisdictions. This page tracks the frameworks most relevant to AI in occupational health, safety, environment and risk management.
European Union
The EU AI Act is the most comprehensive framework in force, with specific obligations for "high-risk" AI systems — a category that explicitly includes AI used in employment, worker management and access to essential services. Core high-risk provisions carry substantial penalties for non-compliance and require demonstrable, competent human oversight. See our full coverage in The EU AI Act's High-Risk Rules.
International standards adopted as regulatory reference points
ISO/IEC 42001 is increasingly cited by regulators and procurement teams as evidence of a credible AI governance programme, even where it isn't yet a hard legal requirement. Our ISO/IEC 42001 coverage tracks its adoption. NIST's AI Risk Management Framework plays a similar reference role in the US, particularly for federal contractors and regulated industries.
Occupational health and safety regulators
Traditional OHS regulators (OSHA in the US, HSE in the UK, and their international counterparts) are beginning to address AI-augmented workplaces within existing safety-management frameworks rather than issuing AI-specific rules outright — meaning organisations are often expected to fit AI oversight into general duty-of-care and risk-assessment obligations that predate AI entirely.
What this means in practice
Regulatory requirements are converging on a consistent expectation: organisations must be able to demonstrate competent, accountable human oversight of AI in safety-relevant contexts. Independently verified certification — AISP, AIRP, AIIP — is one of the clearest ways to produce that evidence.
