What are the emerging regulations to rein in AI harms?有哪些新兴法规旨在遏制人工智能带来的危害?
Read more at straitstimes.com.
The EU AI Act governs the development, deployment, distribution and use of AI systems in all member states of the bloc.
Published Sep 20, 2026, 05:00 AM
Updated Sep 20, 2026, 05:00 AM
SINGAPORE - Global artificial intelligence (AI) regulations are rapidly evolving, with the European Union already establishing its pioneering laws and United States lawmakers debating the need for a mandatory AI “kill switch” . The Straits Times looks at how these rules compare to rules and frameworks in China and Singapore.
The world’s first comprehensive AI law came into force in the EU in 2024. The EU AI Act governs the development, deployment, distribution and use of AI systems in all member states of the bloc. It takes a risk-based approach to regulation.
Enforcement of the AI Act is carried out by the European Commission’s AI Office, the European Data Protection Supervisor and authorities designated by EU member states.
The Act classifies AI systems according to four risk categories: minimal, limited, high and unacceptable.
AI systems with minimal risks do not need to meet specific requirements, and include spam filters and AI-enabled video games.
AI systems with limited risks cover chatbots and they need to meet transparency requirements. For instance, AI-generated content must be clearly labelled, and firms must be upfront when users are interacting with AI chatbots.
High-risk AI systems are those that pose serious risks to health, safety or fundamental rights, including AI recruitment tools for sorting resumes, AI safety features in critical infrastructure. From late 2027, AI systems sold must have activity logs so results can be traced, as well as ensure a high level of robustness, cybersecurity and accuracy.
AI systems with unacceptable risks pose a clear threat to the safety, livelihoods and rights of people. The Act bans such AI, including systems that can manipulate and deceive, and those that generate non-consensual sexually explicit material and child sexual abuse content.
The US does not have a comprehensive national AI law but several states have their own rules. At the same time, the White House is pushing for light-touch, market-driven regulations through federal executive orders that run counter to state AI laws.
There is no single federal AI regulator in the US. Several federal authorities, such as the Federal Trade Commission and Department of Justice, do cover software and algorithmic process, which includes AI. States with AI laws have their own regulatory bodies.
Notable state-level AI regulations include the first comprehensive law in Colorado in 2024 that applies to developers and deployers of high-risk AI in the state. These organisations must, for instance, protect consumers from risks arising from algorithms discriminating people.
But the Colorado act was repealed and replaced with a more limited law that replaces “high-risk AI systems” with “automated decision-making technology”, and avoids mentioning “discrimination”.
This has also been seen as a response to industry complaints and a federal executive order that takes aim against “onerous” state AI laws with threats of withholding certain types of federal funding.
The White House has also issued a National Policy Framework for AI to eventually establish a “minimally burdensome national standard” that prevents state AI laws from hampering innovation in the tech. It also suggests relying on existing agencies and industry standards instead of setting up new federal regulators.
The framework suggests protecting vulnerable groups like children too, such as with tools for parents to manage their kids’ privacy settings and requiring AI platforms to have features to lower risks of sexual exploitation and self harm among minors.
Other rules proposed include an AI “kill switch” legislation that would mandate businesses to be able to shut down dangerous AI tools.
China does not have a single AI law but instead relies on various regulations, binding rules, targeted measures and non-binding technical standards with government oversight. They include the Cybersecurity Law for AI security and interim measures for governing generative AI, including data privacy issues.
The main regulator is the Cyberspace Administration of China, with supporting authorities such as the Ministry of Public Security and the State Administration for Market Regulation.
AI services deemed by regulators to shape public opinion or mobilise society need to be registered with the authorities before they can be publicly launched.
Data used to train generative AI models must be legally obtained and cannot infringe on third-party intellectual property rights. Personal information can only be used for training with a person’s consent.
AI-generated content needs to be clearly labelled too, and prohibited content cannot be generated. Prohibited content includes those endangering national security and interests, and those propagating ethnic discrimination, terrorism, pornography, violence, as well as fake and harmful information.
There are also safeguards for AI companions, including mandatory anti-addiction breaks and reminders that the bot if not a real person . Age verification of users is required as there are time limits for minors. Intimate virtual relationships for minors are not allowed.
Singapore does not have a single AI regulation but instead relies on voluntary best practices, targeted efforts for high-risk sectors and existing laws. They include the Personal Data Protection Act for AI use of personal information , and a voluntary framework for governing AI agents.
There is no single AI regulator in Singapore. Several agencies are involved, including the Infocomm Media Development Authority, Monetary Authority of Singapore and Cyber Security Agency of Singapore.
Singapore has a voluntary governance framework for AI to guide responsible deployment of the tech. It has been updated over time to cover generative AI and AI agents.
For example, on generative AI, the framework recommends transparency over AI training data sources and how users’ data will be protected. For AI agents, there are suggestions to require human approvals for high-risk actions agents may take to prevent the AI from going rogue.
Specific sectors have targeted measures for AI, such as detailed and practical guidance for financial institutions on implementing AI risk management frameworks.
Guidelines to clarify AI use under existing laws have also been issued, including measures that require organisations in Singapore to inform consumers when they use personal data to train generative AI models.
Sources: CMS, European Commission, IMDA, Latham & Watkins, McDermott Will & Schulte, Oxford China Policy Lab, Pertama Partners, Regulations.ai, Skadden, White & Case
AI/artificial intelligence
欧盟人工智能法案规范了欧盟所有成员国人工智能系统的开发、部署、分发和使用。
发布于 2026 年 9 月 20 日上午 5:00
更新于2026年9月20日 上午5:00
新加坡——全球人工智能(AI)监管法规正在迅速发展,欧盟已制定了开创性的法律,而美国立法者正在辩论是否需要强制性的人工智能“终止开关”。《海峡时报》探讨了这些规则与中国和新加坡的规则和框架有何异同。
全球首部全面的人工智能法律于2024年在欧盟生效。欧盟人工智能法案规范了欧盟所有成员国人工智能系统的开发、部署、分发和使用,并采用基于风险的监管方法。
《人工智能法》的执行由欧盟委员会人工智能办公室、欧洲数据保护监管机构和欧盟成员国指定的机构负责。
该法案根据四个风险等级对人工智能系统进行分类:最低风险、有限风险、高风险和不可接受风险。
风险最小的人工智能系统不需要满足特定要求,包括垃圾邮件过滤器和人工智能视频游戏。
风险有限的人工智能系统涵盖聊天机器人,但这些系统必须满足透明度要求。例如,人工智能生成的内容必须清晰标注,企业在用户与人工智能聊天机器人互动时必须主动告知用户。
高风险人工智能系统是指那些对健康、安全或基本权利构成严重威胁的系统,例如用于简历筛选的人工智能招聘工具、关键基础设施中的人工智能安全功能等。从2027年底开始,所有售出的人工智能系统都必须具备活动日志功能,以便追踪结果,并确保高度的稳健性、网络安全性和准确性。
存在不可接受风险的人工智能系统对人们的安全、生计和权利构成明显威胁。该法案禁止此类人工智能,包括能够操纵和欺骗用户的系统,以及生成未经同意的性露骨材料和儿童性虐待内容的系统。
美国没有全国性的人工智能法律,但一些州制定了自己的相关规定。与此同时,白宫正通过联邦行政命令推动宽松的、市场驱动的监管,而这些命令与各州的人工智能法律相悖。
美国没有统一的联邦人工智能监管机构。虽然包括联邦贸易委员会和司法部在内的多个联邦机构负责监管软件和算法流程(其中也包括人工智能),但各州也都有各自的人工智能监管机构。
值得关注的州级人工智能监管法规包括科罗拉多州于2024年颁布的首部综合性法律,该法律适用于该州高风险人工智能的开发商和部署者。例如,这些机构必须保护消费者免受因算法歧视而产生的风险。
但科罗拉多州的这项法案被废除,取而代之的是一项范围更窄的法律,该法律用“自动化决策技术”取代了“高风险人工智能系统”,并且避免提及“歧视”。
这也被视为对行业投诉和一项联邦行政命令的回应,该行政命令旨在打击“繁琐”的州人工智能法律,并威胁要扣留某些类型的联邦资金。
白宫还发布了《国家人工智能政策框架》,旨在最终建立“负担最小的国家标准”,防止各州的人工智能法律阻碍该领域的创新。该框架还建议依靠现有机构和行业标准,而不是设立新的联邦监管机构。
该框架还建议保护儿童等弱势群体,例如为家长提供管理孩子隐私设置的工具,并要求人工智能平台具备降低未成年人遭受性剥削和自残风险的功能。
其他提议的规则包括一项人工智能“终止开关”立法,该立法将强制要求企业能够关闭危险的人工智能工具。
中国没有统一的人工智能法律,而是依靠各种法规、具有约束力的规则、针对性的措施以及不具约束力的技术标准,并在政府的监督下进行管理。这些措施包括保障人工智能安全的《网络安全法》以及针对生成式人工智能(包括数据隐私问题)的临时管理办法。
主要监管机构是中国国家互联网信息办公室,其支持机构包括公安部和国家市场监督管理总局。
监管机构认为能够影响公众舆论或动员社会的AI服务,在正式推出前需要向有关部门注册。
用于训练生成式人工智能模型的数据必须合法获取,且不得侵犯第三方知识产权。个人信息只有在获得本人同意的情况下才能用于训练。
人工智能生成的内容也需要明确标注,并且不能生成违禁内容。违禁内容包括危害国家安全和利益的内容,以及传播种族歧视、恐怖主义、色情、暴力以及虚假和有害信息的内容。
人工智能伴侣也受到一些安全保障措施的保护,包括强制性的防成瘾休息时间和提醒用户该机器人并非真人。由于未成年人使用时间有限制,因此需要对用户进行年龄验证。未成年人之间建立亲密的虚拟关系是被禁止的。
新加坡没有统一的人工智能监管法规,而是依赖于自愿性最佳实践、针对高风险行业的专项措施以及现有法律。这些措施包括《个人数据保护法》(用于规范人工智能对个人信息的使用)以及一套用于管理人工智能代理的自愿性框架。
新加坡没有单一的人工智能监管机构。多个机构参与其中,包括新加坡资讯通信媒体发展局、新加坡金融管理局和新加坡网络安全局。
新加坡制定了一套人工智能自愿治理框架,旨在指导这项技术的负责任部署。该框架已不断更新,涵盖了生成式人工智能和人工智能代理。
例如,在生成式人工智能方面,该框架建议公开人工智能训练数据来源以及用户数据保护方式。对于人工智能代理,建议要求对代理可能采取的高风险操作进行人工审批,以防止人工智能失控。
针对特定行业已采取有针对性的人工智能措施,例如为金融机构提供关于实施人工智能风险管理框架的详细实用指南。
新加坡还发布了明确现有法律下人工智能使用规范的指导方针,其中包括要求新加坡的组织在使用个人数据训练生成式人工智能模型时告知消费者的措施。
资料来源:CMS、欧盟委员会、新加坡资讯通信媒体发展局 (IMDA)、Latham & Watkins律师事务所、McDermott Will & Schulte律师事务所、牛津中国政策实验室、Pertama Partners律师事务所、Regulations.ai、Skadden律师事务所、White & Case律师事务所
人工智能