The regulatory environment for data, artificial intelligence, life sciences and digital evidence is changing rapidly across Europe, the United Kingdom and the United States.
The BioChain tracks the frameworks most relevant to data integrity, provenance, scientific evidence, AI-assisted analysis, regulated research and cross-border data use.
This resource is designed to answer three practical questions: what is changing, why does it matter, and where do provenance and evidence governance intersect with it?
The focus is not every law that touches data. It is the policies and regulatory frameworks most relevant to organisations that need to understand, preserve and demonstrate the history of their data and evidence.
This page is reviewed in full every quarter and updated between reviews whenever a tracked framework changes materially. Each entry carries its own review date, so that a reader can tell how current a particular item is rather than relying on a single date for the whole page.
Recent changes are listed below. Items expected to change in the next twelve months are listed at the end of the page under “What we are watching”.
Every entry links to the primary source — the instrument, the guidance document or the official page. Entries are summaries. Where the summary and the source differ, the source governs.
Last full review: 14 September 2026. Next scheduled review: December 2026.
In force — adopted and currently applying.
In application — applying in full from a stated date.
Staged application — in force, with provisions applying in tranches over time.
Proposed — published by the Commission, Government or agency but not yet adopted. Content may change.
Guidance — non-binding, but reflecting regulatory expectation.
Under revision — adopted and applying, but subject to an amendment process.
14 September 2026 — Added the Digital Omnibus, the European Biotech Act, the European Technological Sovereignty Package and Cloud and AI Development Act, and the European Open Science Cloud. Updated the AI Act entry to reflect Regulation (EU) 2026/1744. Updated the EHDS entry to reflect general application from 26 March 2027. Updated the Data Governance Act entry to reflect the proposed repeal. Added the data quality standardisation request to the Data Union Strategy entry. Updated the HIPAA and NIST entries. Added publication details for the National Commission into the Regulation of AI in Healthcare.
Earlier changes are retained in our internal revision log and are available on request.
Important: This page is provided for general information only. It is not legal advice and should not be relied upon as a substitute for advice from appropriately qualified legal or regulatory professionals. Where an entry describes a proposal, the final adopted text may differ.
The European Union, United Kingdom and United States do not regulate data, artificial intelligence or life sciences in the same way. Yet several recurring requirements appear across their regulatory environments.
Can the source of a record be established?
Can changes be reconstructed?
Are significant actions attributable?
Can the organisation identify which systems and versions produced a result?
Can protected information remain protected while authorised conclusions are reviewed?
Can evidence survive changes of system, supplier or organisation without losing its history?
Those questions sit at the centre of data integrity and evidence governance. They are also notably stable: the instruments move, and the questions do not.
The following are expected to change within the next twelve months. We will update the relevant entries as they do.
Negotiation continues on the proposal to repeal the Data Governance Act and consolidate its rules into the Data Act. Adoption would require re-pointing a significant number of compliance references. Watch: trilogue outcome.
Implementing acts and technical specifications are due by 26 March 2027, including provisions on secure processing environments, dataset descriptions and the data quality and utility label. Watch: draft implementing acts and accompanying technical work.
Early-stage proposal. The data quality accelerator provisions and any definition of verified dataset provenance are the elements most relevant to this page. Watch: European Parliament committee reports and Council position.
Early-stage proposal. Watch: the operative sovereignty criteria in Annex II, which are likely to attract amendment.
The standardisation request for a European data quality standard covering provenance is the most directly relevant European workstream to this page. Watch: issue of the request and the standardisation body to which it is assigned.
MHRA and Government response to the 10 September 2026 recommendations. Watch: the formal response and any consequent consultation.
Final action indicated for 2027, with the possibility of substantial narrowing or withdrawal. Watch: OCR final rule or withdrawal notice.
Revision in progress alongside sector profiles, including critical infrastructure. Watch: publication of the revised framework.
The BioChain is designed as a provenance and evidence layer across existing systems. It does not replace legal compliance, quality-management systems, laboratory platforms, secure data environments, clinical systems or regulatory expertise.
It addresses a narrower problem: how to preserve the relationships between source data, transformations, analytical processes and consequential evidence when those relationships cross systems and organisational boundaries. That includes persistent identity, lineage, material version information, integrity and controlled verification.
Our work on what should persist is published openly, including a proposed minimum evidence record and two papers in our Evidence Governance Series. We would rather those proposals were criticised and improved than adopted unchanged.
Our Advisory work helps organisations determine whether those foundations already exist, where their evidence chains break, and what needs to change before reliable cross-system provenance becomes possible.
Regulatory requirements are expressed in legal and policy language. Operational evidence exists in databases, laboratory systems, audit trails, infrastructure, backups, spreadsheets, analytical workflows and technical processes. The difficult part is often connecting the two.
The BioChain Advisory helps organisations understand what their systems can actually demonstrate today — and where the evidence chain needs to be strengthened.
This page tracks selected frameworks relevant to The BioChain’s work in evidence provenance, data integrity, research, artificial intelligence and life sciences. It is not intended to be a comprehensive catalogue of legislation in any jurisdiction.
Frameworks are included because they materially affect the way organisations create, process, govern or demonstrate digital evidence. Entries are summaries and are not a substitute for the underlying texts, which are cited in each entry.
If you believe an entry is wrong, out of date or missing, please tell us. Corrections are welcome and we will credit them where you would like us to.
Last full review: 14 September 2026. Next scheduled review: December 2026.
The page is reviewed in full every quarter, with updates between reviews whenever a tracked framework changes materially. The next scheduled full review is December 2026.
No. It is provided for general information only and is not a substitute for advice from appropriately qualified legal or regulatory professionals. Where an entry describes a proposal, the final adopted text may differ.
This is deliberately not a comprehensive catalogue of legislation in any jurisdiction. Frameworks are included because they materially affect how organisations create, process, govern or demonstrate digital evidence.
Tell us. We would rather be corrected than agreed with, and we will fix it and credit you if you would like us to.