Regulating AI · Index
Thank you for reading this post, don't forget to subscribe!
Home / Indexes / Regulating AI / By Country
AI Regulation by Country 2026: A Global Map
There is no single way the world regulates AI. The EU wrote a binding, risk-tiered rulebook; the US has no federal statute and a fast-growing state patchwork; China governs through layered administrative rules; and Japan and the UK have deliberately chosen soft law. This is the sourced, jurisdiction-by-jurisdiction map of who regulates AI, how, and what it costs to get it wrong — as of mid-2026.
Last updated: July 2026. Every figure links to a primary text or authoritative legal source. Fast-moving items are flagged.
The world at a glance
Four broad models have emerged: comprehensive risk-based law (EU, and on paper South Korea and Brazil), state-led patchwork (the US), layered administrative control (China), and principles-based soft law (UK, Japan). The table below is the one-screen summary; the sections beneath it give the sourced detail.
| Jurisdiction | Flagship framework | Approach | Status | Max penalty |
|---|---|---|---|---|
| European Union | AI Act (Reg. 2024/1689) | Risk-tiered + GPAI layer | In force; high-risk rules delayed to Dec 2027 | €35M / 7% turnover |
| United States (federal) | Executive orders only | Pro-innovation / deregulatory | No comprehensive law | — (sector agencies) |
| US states | Colorado, Texas, California, Utah, Illinois… | Patchwork (transparency + anti-discrimination) | Live & phasing in through 2027 | e.g. TX $200k/violation |
| China | CAC generative-AI & labeling rules | State-led, content & security | In force (layered) | Takedowns, suspension, license loss |
| United Kingdom | Pro-innovation White Paper | Principles, sector regulators | No statute; AI Security Institute active | — |
| South Korea | AI Basic Act | Promotion + baseline trust duties | In force 22 Jan 2026 (1-yr grace) | ~KRW 30M (~$20k) |
| Japan | AI Promotion Act | Innovation-first soft law | In force Sep 2025 | None (non-punitive) |
| Canada | AIDA (Bill C-27) | Would have been risk-based | Died on Order Paper, Jan 2025 | — (lapsed) |
| Brazil | PL 2338/2023 | Risk-based (EU-style) | Passed Senate 2024; pending in Chamber | — (not yet law) |
European Union — the world’s rulebook In force
The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024 and is the most comprehensive AI law anywhere. It sorts systems into four risk tiers — unacceptable (banned), high, limited (transparency), and minimal — plus a separate layer for general-purpose AI (GPAI) models. Bans on prohibited practices have applied since 2 February 2025 and GPAI-model duties since 2 August 2025.
Implementation is now slipping. Under the Digital Omnibus — proposed by the Commission on 19 November 2025 and moving through the institutions in the first half of 2026 — the main high-risk (Annex III) compliance date is pushed from 2 August 2026 to 2 December 2027, and AI embedded in regulated products to 2 August 2028. Fines are tiered: up to €35M or 7% of worldwide turnover for prohibited uses, €15M/3% for most other breaches, and €7.5M/1% for supplying misleading information (Art. 99). A GPAI model is presumed to carry “systemic risk” above 1025 FLOP of training compute (Art. 51).
United States — federal vacuum, state scramble No federal law
There is still no comprehensive federal AI statute. Federal policy runs through executive orders: the Biden-era EO 14110 was rescinded on 20 January 2025 and replaced by a deregulatory “Removing Barriers to American Leadership in AI” order; a December 2025 order went further, framing the state “patchwork” as a threat to competitiveness and signaling possible federal preemption. Enforcement, for now, falls to existing agencies (FTC, EEOC, sector regulators).
The state patchwork
With Washington quiet, states moved first. In 2025 alone the NCSL counted roughly 1,130 AI bills introduced across ~40 states, with ~131 enacted. The most consequential:
| State | Law | What it does | Effective |
|---|---|---|---|
| Colorado | SB 24-205 (amended by SB 25-189) | First US comprehensive AI law — but 2026 amendments gutted the risk-based core, leaving a narrower disclosure model | 1 Jan 2027 |
| Texas | TRAIGA (HB 149) | Intent-based bans (self-harm, crime, unlawful discrimination, deepfakes); AG-only enforcement; sandbox | 1 Jan 2026 |
| California | SB 53 (TFAIA) | First US frontier-model transparency law; safety frameworks, incident reports, whistleblower protection | 1 Jan 2026 |
| Utah | AI Policy Act (SB 149) | First state generative-AI law; disclosure that a user is talking to AI; up to $2,500/violation | 1 May 2024 |
| Illinois | HB 3773 | Bars AI that causes employment discrimination (incl. disparate impact); ZIP-code proxy ban | 1 Jan 2026 |
The result is exactly the compliance fragmentation the December 2025 executive order complains about: national developers increasingly build to the strictest state. California’s SB 53 is the narrower successor to SB 1047, the sweeping 2024 frontier-AI bill that Governor Newsom vetoed — a useful marker of how far US politics will actually go.
China — layered control, no single act In force
China regulates AI not with one omnibus law but with a stack of binding administrative rules from the Cyberspace Administration (CAC) and partner agencies, each already in force:
- Algorithmic Recommendation Provisions (1 March 2022) — algorithm filing/registration for recommendation systems.
- Deep Synthesis Provisions (10 January 2023) — deepfakes and synthetic media.
- Interim Measures for Generative AI Services (15 August 2023) — China’s first binding generative-AI rules, from seven agencies led by the CAC.
- AI content-labeling measures + national standard GB 45438-2025 (effective 1 September 2025) — mandating both visible labels and metadata-embedded markers on AI-generated text, image, audio and video.
Penalties run through existing cybersecurity and content law — takedowns, rectification orders, service suspension, and license consequences — rather than a single AI fine schedule. As of mid-2026 China is reportedly moving toward a comprehensive national “AI Law,” but none has been enacted.
United Kingdom — principles over statute No statute
The UK deliberately avoided a comprehensive AI law. Its 2023 “pro-innovation” White Paper set five cross-sector principles — safety, transparency, fairness, accountability, and contestability — enforced through existing sector regulators rather than a central AI authority. The AI Safety Institute, launched at Bletchley Park in November 2023, was rebranded the AI Security Institute in February 2025, tilting toward national-security and misuse risk. Ministers have floated a fuller AI Bill, but as of mid-2026 no government statute has been enacted.
South Korea — Asia’s first comprehensive act In force
South Korea’s AI Basic Act (Framework Act on AI Development and Trust) took effect on 22 January 2026, making it Asia’s first comprehensive national AI statute. It blends industrial promotion with baseline trust duties: obligations for “high-impact” AI (healthcare, energy, public services) and labeling for generative-AI content, with extraterritorial reach to foreign providers serving Korean users. Enforcement is gentle by design — administrative fines up to roughly KRW 30 million (~US$20,000), and a grace period through 2026 deferring most fines except in cases of serious harm.
Japan — soft law by choice In force
Japan’s AI Promotion Act (passed 28 May 2025, fully in effect 1 September 2025) is its first AI-specific statute — and it is explicitly non-punitive. There are no monetary penalties. The Act sets principles, creates a Cabinet-level AI Strategy Headquarters, and relies on voluntary guidance; the government’s only real leverage is investigating and publicly naming actors in cases of serious harm. It is the clearest example of the innovation-first model.
Canada & Brazil — the ones that didn’t land (yet) Pending / lapsed
Canada: The Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died on the Order Paper when Parliament was prorogued on 6 January 2025. Canada currently has no binding federal AI statute, relying on a voluntary code and existing privacy law; a replacement is anticipated but not yet tabled.
Brazil: PL 2338/2023, an EU-style risk-based bill, passed the Senate in December 2024 and moved to the Chamber of Deputies, where it remained under committee review through mid-2026. It classifies systems from minimal to “excessive” risk, bans excessive-risk uses, and mandates impact assessments for high-risk applications — but it is not yet law, so no penalties are in force.
The thin thread of coordination
Above the national rules sits a fragile diplomatic layer. The summit series ran from the Bletchley Declaration (28 countries + EU, November 2023) to the Seoul Summit (May 2024, where 16 companies signed the Frontier AI Safety Commitments) to the Paris “AI Action Summit” (February 2025) — where the very rename from “Safety” to “Action,” and the refusal of the US and UK to sign the main statement, signaled a shift toward competitiveness. India hosted the next summit in February 2026. A parallel International Network of AI Safety Institutes launched in November 2024, and a Bengio-chaired International AI Safety Report (first published January 2025) gives summits a shared evidence base. But China sits outside both the institute network and the export-control regime, and the network’s momentum depends heavily on a US institute whose mandate shifted after January 2025.
Frequently asked questions
Which country has the strictest AI law?
The European Union. Its AI Act is the only comprehensive, binding, risk-tiered regime with heavy fines (up to €35M or 7% of global turnover) — though its toughest high-risk obligations are now delayed to December 2027.
Does the United States regulate AI?
Not at the federal level — there is no comprehensive US AI statute. Regulation comes from a patchwork of state laws (Colorado, Texas, California, Utah, Illinois and others) and enforcement by existing agencies. A December 2025 executive order even signals possible federal preemption of state rules.
How does China regulate AI?
Through layered administrative rules rather than one law: algorithm-recommendation provisions (2022), deep-synthesis rules (2023), interim generative-AI measures (2023), and a 2025 content-labeling regime requiring both visible and metadata labels.
Which countries chose not to pass a strict AI law?
The UK (principles-based, sector regulators) and Japan (a deliberately non-punitive AI Promotion Act) both opted for soft law. Canada’s AIDA lapsed in 2025, and Brazil’s bill is still pending.
Sources
• European Commission, Digital Omnibus proposal (19 Nov 2025) — digital-strategy.ec.europa.eu
• Council of the EU, simplification agreement (7 May 2026) — consilium.europa.eu
• Mayer Brown, US federal AI executive order (Dec 2025) — mayerbrown.com
• NCSL, 2025 state AI legislation summary — ncsl.org
• Hunton, Colorado AI Act amended & delayed — hunton.com
• Norton Rose Fulbright, Texas TRAIGA — nortonrosefulbright.com
• White & Case, California SB 53 — whitecase.com
• China Law Translate, AI labeling measures — chinalawtranslate.com
• Alan Turing Institute, UK AI governance profile (Jan 2026) — turing.ac.uk
• Cooley, South Korea AI Basic Act (Jan 2026) — cooley.com
• White & Case, Japan AI Promotion Act — whitecase.com
• Fasken, Canada Bill C-27 prorogation — fasken.com
• Library of Congress, Brazil PL 2338 — loc.gov
• Future of Life Institute, AI Safety Summits — futureoflife.org