AI Regulation by Country 2026: A Global Map

Regulating AI · Index

Thank you for reading this post, don't forget to subscribe!

Home / Indexes / Regulating AI / By Country

AI Regulation by Country 2026: A Global Map

There is no single way the world regulates AI. The EU wrote a binding, risk-tiered rulebook; the US has no federal statute and a fast-growing state patchwork; China governs through layered administrative rules; and Japan and the UK have deliberately chosen soft law. This is the sourced, jurisdiction-by-jurisdiction map of who regulates AI, how, and what it costs to get it wrong — as of mid-2026.

Last updated: July 2026. Every figure links to a primary text or authoritative legal source. Fast-moving items are flagged.

€35M
Top EU AI Act fine — or 7% of global turnover
EU AI Act, Art. 99
~1,130
AI bills introduced across ~40 US states in 2025
NCSL, 2025
1025
FLOP: EU threshold for “systemic-risk” AI models
EU AI Act, Art. 51
Jan 2026
South Korea’s AI Basic Act takes effect — Asia’s first
AI Basic Act

The world at a glance

Four broad models have emerged: comprehensive risk-based law (EU, and on paper South Korea and Brazil), state-led patchwork (the US), layered administrative control (China), and principles-based soft law (UK, Japan). The table below is the one-screen summary; the sections beneath it give the sourced detail.

JurisdictionFlagship frameworkApproachStatusMax penalty
European UnionAI Act (Reg. 2024/1689)Risk-tiered + GPAI layerIn force; high-risk rules delayed to Dec 2027€35M / 7% turnover
United States (federal)Executive orders onlyPro-innovation / deregulatoryNo comprehensive law— (sector agencies)
US statesColorado, Texas, California, Utah, Illinois…Patchwork (transparency + anti-discrimination)Live & phasing in through 2027e.g. TX $200k/violation
ChinaCAC generative-AI & labeling rulesState-led, content & securityIn force (layered)Takedowns, suspension, license loss
United KingdomPro-innovation White PaperPrinciples, sector regulatorsNo statute; AI Security Institute active
South KoreaAI Basic ActPromotion + baseline trust dutiesIn force 22 Jan 2026 (1-yr grace)~KRW 30M (~$20k)
JapanAI Promotion ActInnovation-first soft lawIn force Sep 2025None (non-punitive)
CanadaAIDA (Bill C-27)Would have been risk-basedDied on Order Paper, Jan 2025— (lapsed)
BrazilPL 2338/2023Risk-based (EU-style)Passed Senate 2024; pending in Chamber— (not yet law)

European Union — the world’s rulebook In force

The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024 and is the most comprehensive AI law anywhere. It sorts systems into four risk tiers — unacceptable (banned), high, limited (transparency), and minimal — plus a separate layer for general-purpose AI (GPAI) models. Bans on prohibited practices have applied since 2 February 2025 and GPAI-model duties since 2 August 2025.

Implementation is now slipping. Under the Digital Omnibus — proposed by the Commission on 19 November 2025 and moving through the institutions in the first half of 2026 — the main high-risk (Annex III) compliance date is pushed from 2 August 2026 to 2 December 2027, and AI embedded in regulated products to 2 August 2028. Fines are tiered: up to €35M or 7% of worldwide turnover for prohibited uses, €15M/3% for most other breaches, and €7.5M/1% for supplying misleading information (Art. 99). A GPAI model is presumed to carry “systemic risk” above 1025 FLOP of training compute (Art. 51).

Watch this: The Digital Omnibus reached political agreement in May 2026 with parliamentary and Council endorsements reported in June 2026, but confirm the Official Journal publication before treating the new high-risk dates as legally final.

United States — federal vacuum, state scramble No federal law

There is still no comprehensive federal AI statute. Federal policy runs through executive orders: the Biden-era EO 14110 was rescinded on 20 January 2025 and replaced by a deregulatory “Removing Barriers to American Leadership in AI” order; a December 2025 order went further, framing the state “patchwork” as a threat to competitiveness and signaling possible federal preemption. Enforcement, for now, falls to existing agencies (FTC, EEOC, sector regulators).

The state patchwork

With Washington quiet, states moved first. In 2025 alone the NCSL counted roughly 1,130 AI bills introduced across ~40 states, with ~131 enacted. The most consequential:

StateLawWhat it doesEffective
ColoradoSB 24-205 (amended by SB 25-189)First US comprehensive AI law — but 2026 amendments gutted the risk-based core, leaving a narrower disclosure model1 Jan 2027
TexasTRAIGA (HB 149)Intent-based bans (self-harm, crime, unlawful discrimination, deepfakes); AG-only enforcement; sandbox1 Jan 2026
CaliforniaSB 53 (TFAIA)First US frontier-model transparency law; safety frameworks, incident reports, whistleblower protection1 Jan 2026
UtahAI Policy Act (SB 149)First state generative-AI law; disclosure that a user is talking to AI; up to $2,500/violation1 May 2024
IllinoisHB 3773Bars AI that causes employment discrimination (incl. disparate impact); ZIP-code proxy ban1 Jan 2026

The result is exactly the compliance fragmentation the December 2025 executive order complains about: national developers increasingly build to the strictest state. California’s SB 53 is the narrower successor to SB 1047, the sweeping 2024 frontier-AI bill that Governor Newsom vetoed — a useful marker of how far US politics will actually go.

China — layered control, no single act In force

China regulates AI not with one omnibus law but with a stack of binding administrative rules from the Cyberspace Administration (CAC) and partner agencies, each already in force:

  • Algorithmic Recommendation Provisions (1 March 2022) — algorithm filing/registration for recommendation systems.
  • Deep Synthesis Provisions (10 January 2023) — deepfakes and synthetic media.
  • Interim Measures for Generative AI Services (15 August 2023) — China’s first binding generative-AI rules, from seven agencies led by the CAC.
  • AI content-labeling measures + national standard GB 45438-2025 (effective 1 September 2025) — mandating both visible labels and metadata-embedded markers on AI-generated text, image, audio and video.

Penalties run through existing cybersecurity and content law — takedowns, rectification orders, service suspension, and license consequences — rather than a single AI fine schedule. As of mid-2026 China is reportedly moving toward a comprehensive national “AI Law,” but none has been enacted.

United Kingdom — principles over statute No statute

The UK deliberately avoided a comprehensive AI law. Its 2023 “pro-innovation” White Paper set five cross-sector principles — safety, transparency, fairness, accountability, and contestability — enforced through existing sector regulators rather than a central AI authority. The AI Safety Institute, launched at Bletchley Park in November 2023, was rebranded the AI Security Institute in February 2025, tilting toward national-security and misuse risk. Ministers have floated a fuller AI Bill, but as of mid-2026 no government statute has been enacted.

South Korea — Asia’s first comprehensive act In force

South Korea’s AI Basic Act (Framework Act on AI Development and Trust) took effect on 22 January 2026, making it Asia’s first comprehensive national AI statute. It blends industrial promotion with baseline trust duties: obligations for “high-impact” AI (healthcare, energy, public services) and labeling for generative-AI content, with extraterritorial reach to foreign providers serving Korean users. Enforcement is gentle by design — administrative fines up to roughly KRW 30 million (~US$20,000), and a grace period through 2026 deferring most fines except in cases of serious harm.

Japan — soft law by choice In force

Japan’s AI Promotion Act (passed 28 May 2025, fully in effect 1 September 2025) is its first AI-specific statute — and it is explicitly non-punitive. There are no monetary penalties. The Act sets principles, creates a Cabinet-level AI Strategy Headquarters, and relies on voluntary guidance; the government’s only real leverage is investigating and publicly naming actors in cases of serious harm. It is the clearest example of the innovation-first model.

Canada & Brazil — the ones that didn’t land (yet) Pending / lapsed

Canada: The Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died on the Order Paper when Parliament was prorogued on 6 January 2025. Canada currently has no binding federal AI statute, relying on a voluntary code and existing privacy law; a replacement is anticipated but not yet tabled.

Brazil: PL 2338/2023, an EU-style risk-based bill, passed the Senate in December 2024 and moved to the Chamber of Deputies, where it remained under committee review through mid-2026. It classifies systems from minimal to “excessive” risk, bans excessive-risk uses, and mandates impact assessments for high-risk applications — but it is not yet law, so no penalties are in force.

The thin thread of coordination

Above the national rules sits a fragile diplomatic layer. The summit series ran from the Bletchley Declaration (28 countries + EU, November 2023) to the Seoul Summit (May 2024, where 16 companies signed the Frontier AI Safety Commitments) to the Paris “AI Action Summit” (February 2025) — where the very rename from “Safety” to “Action,” and the refusal of the US and UK to sign the main statement, signaled a shift toward competitiveness. India hosted the next summit in February 2026. A parallel International Network of AI Safety Institutes launched in November 2024, and a Bengio-chaired International AI Safety Report (first published January 2025) gives summits a shared evidence base. But China sits outside both the institute network and the export-control regime, and the network’s momentum depends heavily on a US institute whose mandate shifted after January 2025.

Want the head-to-head? See AI Laws Compared: EU vs US vs China for a dimension-by-dimension scorecard, or Regulating AI for the pillar and the US “kill switch” story.

Frequently asked questions

Which country has the strictest AI law?
The European Union. Its AI Act is the only comprehensive, binding, risk-tiered regime with heavy fines (up to €35M or 7% of global turnover) — though its toughest high-risk obligations are now delayed to December 2027.

Does the United States regulate AI?
Not at the federal level — there is no comprehensive US AI statute. Regulation comes from a patchwork of state laws (Colorado, Texas, California, Utah, Illinois and others) and enforcement by existing agencies. A December 2025 executive order even signals possible federal preemption of state rules.

How does China regulate AI?
Through layered administrative rules rather than one law: algorithm-recommendation provisions (2022), deep-synthesis rules (2023), interim generative-AI measures (2023), and a 2025 content-labeling regime requiring both visible and metadata labels.

Which countries chose not to pass a strict AI law?
The UK (principles-based, sector regulators) and Japan (a deliberately non-punitive AI Promotion Act) both opted for soft law. Canada’s AIDA lapsed in 2025, and Brazil’s bill is still pending.

Sources

• EU AI Act, Article 99 (penalties) — artificialintelligenceact.eu/article/99
• European Commission, Digital Omnibus proposal (19 Nov 2025) — digital-strategy.ec.europa.eu
• Council of the EU, simplification agreement (7 May 2026) — consilium.europa.eu
• Mayer Brown, US federal AI executive order (Dec 2025) — mayerbrown.com
• NCSL, 2025 state AI legislation summary — ncsl.org
• Hunton, Colorado AI Act amended & delayed — hunton.com
• Norton Rose Fulbright, Texas TRAIGA — nortonrosefulbright.com
• White & Case, California SB 53 — whitecase.com
• China Law Translate, AI labeling measures — chinalawtranslate.com
• Alan Turing Institute, UK AI governance profile (Jan 2026) — turing.ac.uk
• Cooley, South Korea AI Basic Act (Jan 2026) — cooley.com
• White & Case, Japan AI Promotion Act — whitecase.com
• Fasken, Canada Bill C-27 prorogation — fasken.com
• Library of Congress, Brazil PL 2338 — loc.gov
• Future of Life Institute, AI Safety Summits — futureoflife.org