Jurisdiction Coverage
Zabta supports 14 jurisdictions, each containing policy templates grounded in actual legislation. Jurisdiction packs activate from the dashboard — once active, every agent evaluation is checked against that region's regulatory requirements in addition to universal policies.
Jurisdiction packs
All 14 packs are fully implemented — real policy templates, regulatory citations, risk taxonomies, and penalty tracking. These 12 additionally have production activation evidence: at least one tenant has turned the pack on.
| Jurisdiction | Regulations | Max penalty | Key date |
|---|---|---|---|
European Union Europe | EU AI Act, GDPR | €35M or 7% global revenue | Aug 2, 2026 |
United States (Federal) North America | Executive Order on AI, NIST AI RMF | Varies by sector | In force |
Colorado North America | SB 26-189 (replaces SB 24-205) | Not yet confirmed | Jan 1, 2027* |
California North America | SB 942, CCPA/CPRA | CPPA enforcement | Aug 2, 2026 |
South Korea East Asia | AI Basic Act | KRW 30M + criminal | Jan 22, 2026 |
Singapore Southeast Asia | Model AI Governance Framework, PDPA | SGD 1M or 10% SG turnover | In force |
India South Asia | DPDP Act, 7 Sutras | ₹250 crore (~$30M) | May 13, 2027 |
Brazil Latin America | LGPD, Marco Legal de IA | R$50M or 2% Brazil revenue | Dec 31, 2026 |
United Kingdom Europe | Pro-Innovation AI Framework, UK GDPR | Sector regulator fines | In force |
Canada North America | AIDA (Artificial Intelligence and Data Act) | CAD $10M or 3% revenue | In force |
Australia Oceania | AI Ethics Framework, Privacy Act | AUD $50M | In force |
Japan East Asia | AI governance guidelines, APPI | PIPC enforcement | In force |
* Colorado's original law (SB 24-205) was superseded before it took effect. SB 26-189 is the current law; see the Colorado AI Law guide for status and what Zabta's pack currently enforces.
Available, not yet field-proven
These 2 packs are just as fully implemented as the ones above — same policy templates, same citation depth — but no tenant has activated either in production yet. That is the honest distinction: available capability, not a lesser build.
| Jurisdiction | Regulations | Max penalty | Status |
|---|---|---|---|
Texas North America | TRAIGA | $200,000 + $40,000/day | Not yet activated |
China East Asia | AI Compliance, PIPL, GB 45438-2025 | RMB 50M or 5% turnover | Not yet activated |
Activating a jurisdiction
- Navigate to the Jurisdictions page in the Zabta dashboard
- Find the region you need
- Click Activate
- The pack's policies are immediately added to your evaluation pipeline
- Check the compliance dashboard for your score against that jurisdiction
What's inside a jurisdiction pack
Each jurisdiction pack is a structured bundle of regulatory data:
Policy templates
Rules grounded in specific regulatory articles with citations. Each template maps a regulatory requirement to an evaluable policy condition.
Risk taxonomy
Region-specific risk categories. The EU uses prohibited/high/limited/minimal. Colorado uses high_risk. Singapore uses nine governance dimensions.
Decision rules
What triggers DENY vs ESCALATE vs ALLOW for each policy. Higher-risk actions default to stricter decisions.
Incident timers
Breach notification timelines required by regulation. The EU requires 360-hour standard reporting and 48-hour reporting for widespread harm.
Penalty metadata
Maximum fines, penalty calculation basis (revenue percentage vs flat amount), and enforcement body information.
Critical dates
Enforcement deadlines and phase-in schedules so you know when requirements become binding.
Multiple jurisdictions
Agents operating across regions can have multiple jurisdiction packs active simultaneously. The policy engine evaluates against all active packs — if an action is denied by any jurisdiction's policies, it's denied. This ensures compliance with the strictest applicable standard.
Sectoral overlays
Sectoral overlays add industry-specific rules on top of jurisdiction packs. Available sectors include healthcare (HIPAA-aligned), finance (algorithmic trading, credit decisioning), and education (student data, algorithmic grading). Sectoral overlays inherit the risk taxonomy of their parent jurisdiction and add domain-specific policy checks. See the Policy Engine documentation for the full three-layer architecture.
Related