AI is no longer just a technical project. NSP builds governance into the architecture — so what the system does, what data it uses, who supervises it and how it is logged are answered by design, not bolted on after launch.
As of June 2026 — reviewed periodically
AI rules differ by market and move quickly. NSP does not promise legal compliance; we design systems to the principles these regimes share — documentation, oversight, transparency and accountability — so the work holds up wherever it is deployed.
In force and phasing in. Prohibited practices and general-purpose-AI model rules already apply; the main high-risk obligations now phase in toward December 2027, with transparency and content-labelling duties through 2026. We design to its risk-based, documentation-heavy model.
No single federal statute. NIST AI RMF is the practical anchor, alongside active state laws (Texas, California, Colorado) and an unresolved federal preemption push. We build to NIST AI RMF and ISO 42001 as the highest common denominator.
A sector-regulator, principles-led approach rather than one broad AI statute. We align to existing regulator expectations and document accordingly.
AI exposure runs largely through the Digital Personal Data Protection Act and its data-processing obligations. We design with data protection at the centre.
Relies on existing laws plus voluntary Guidance for AI Adoption and a new AI Safety Institute; economy-wide mandatory guardrails were set aside in late 2025. We follow the voluntary best-practice standard.
Brazil and Chile are moving toward risk-based AI frameworks. We track these and design to their emerging principles.
Important: NSP is not a law firm and does not provide legal advice. Our work supports technical and operational AI governance. Clients should obtain qualified legal advice for jurisdiction-specific compliance obligations.