ZABTA DOCS

Jurisdiction Coverage

Zabta supports 14 jurisdictions, each containing policy templates grounded in actual legislation. Jurisdiction packs activate from the dashboard — once active, every agent evaluation is checked against that region's regulatory requirements in addition to universal policies.

Jurisdiction packs

All 14 packs are fully implemented — real policy templates, regulatory citations, risk taxonomies, and penalty tracking. These 12 additionally have production activation evidence: at least one tenant has turned the pack on.

JurisdictionRegulationsMax penaltyKey date

European Union

Europe

EU AI Act, GDPR€35M or 7% global revenueAug 2, 2026

United States (Federal)

North America

Executive Order on AI, NIST AI RMFVaries by sectorIn force

Colorado

North America

SB 26-189 (replaces SB 24-205)Not yet confirmedJan 1, 2027*

California

North America

SB 942, CCPA/CPRACPPA enforcementAug 2, 2026

South Korea

East Asia

AI Basic ActKRW 30M + criminalJan 22, 2026

Singapore

Southeast Asia

Model AI Governance Framework, PDPASGD 1M or 10% SG turnoverIn force

India

South Asia

DPDP Act, 7 Sutras₹250 crore (~$30M)May 13, 2027

Brazil

Latin America

LGPD, Marco Legal de IAR$50M or 2% Brazil revenueDec 31, 2026

United Kingdom

Europe

Pro-Innovation AI Framework, UK GDPRSector regulator finesIn force

Canada

North America

AIDA (Artificial Intelligence and Data Act)CAD $10M or 3% revenueIn force

Australia

Oceania

AI Ethics Framework, Privacy ActAUD $50MIn force

Japan

East Asia

AI governance guidelines, APPIPIPC enforcementIn force

* Colorado's original law (SB 24-205) was superseded before it took effect. SB 26-189 is the current law; see the Colorado AI Law guide for status and what Zabta's pack currently enforces.

Available, not yet field-proven

These 2 packs are just as fully implemented as the ones above — same policy templates, same citation depth — but no tenant has activated either in production yet. That is the honest distinction: available capability, not a lesser build.

JurisdictionRegulationsMax penaltyStatus

Texas

North America

TRAIGA$200,000 + $40,000/dayNot yet activated

China

East Asia

AI Compliance, PIPL, GB 45438-2025RMB 50M or 5% turnoverNot yet activated

Activating a jurisdiction

  1. Navigate to the Jurisdictions page in the Zabta dashboard
  2. Find the region you need
  3. Click Activate
  4. The pack's policies are immediately added to your evaluation pipeline
  5. Check the compliance dashboard for your score against that jurisdiction

What's inside a jurisdiction pack

Each jurisdiction pack is a structured bundle of regulatory data:

Policy templates

Rules grounded in specific regulatory articles with citations. Each template maps a regulatory requirement to an evaluable policy condition.

Risk taxonomy

Region-specific risk categories. The EU uses prohibited/high/limited/minimal. Colorado uses high_risk. Singapore uses nine governance dimensions.

Decision rules

What triggers DENY vs ESCALATE vs ALLOW for each policy. Higher-risk actions default to stricter decisions.

Incident timers

Breach notification timelines required by regulation. The EU requires 360-hour standard reporting and 48-hour reporting for widespread harm.

Penalty metadata

Maximum fines, penalty calculation basis (revenue percentage vs flat amount), and enforcement body information.

Critical dates

Enforcement deadlines and phase-in schedules so you know when requirements become binding.

Multiple jurisdictions

Agents operating across regions can have multiple jurisdiction packs active simultaneously. The policy engine evaluates against all active packs — if an action is denied by any jurisdiction's policies, it's denied. This ensures compliance with the strictest applicable standard.

Conflict resolution: When jurisdictions conflict (e.g., EU AI Act vs UK Pro-Innovation Framework), Zabta defaults to the stricter standard. You can configure manual conflict resolution in the dashboard for specific edge cases.

Sectoral overlays

Sectoral overlays add industry-specific rules on top of jurisdiction packs. Available sectors include healthcare (HIPAA-aligned), finance (algorithmic trading, credit decisioning), and education (student data, algorithmic grading). Sectoral overlays inherit the risk taxonomy of their parent jurisdiction and add domain-specific policy checks. See the Policy Engine documentation for the full three-layer architecture.

Related