AI Laws Around the World: Global AI Regulation by Country

Compare AI laws around the world in 2026, including binding laws, proposed rules, regulatory frameworks, effective dates and business implications by country.

  • Oct 01, 2026
  • 21 min read
Isometric infographic about global AI regulation featuring a 3D world map, legal symbols, and policy workflow icons.

AI regulation is expanding globally, but there is no single global model of AI regulation. Some jurisdictions have enacted comprehensive or cross-sector AI legislation. Others regulate AI through privacy, consumer protection, employment, discrimination, cybersecurity, product safety and sector-specific laws. Some rely substantially on regulatory guidance, governance frameworks and government policy while considering further legislation.

 

For international businesses, these differences matter. The same AI system can face different requirements depending on where it is developed, supplied or deployed, who uses it, whether personal data is involved, what decisions it supports and whether the system falls into a regulated or higher-risk category.

 

This guide compares major AI laws around the world as of September 2026. It distinguishes binding legislation from regulatory guidance, voluntary frameworks, government policy and proposed measures so that businesses can understand what applies now, what is changing and what still remains a proposal.

Global AI regulation at a glance

Jurisdiction

Main approach

AI-specific law or binding AI rules?

Position in September 2026

European Union

Horizontal risk-based regulation

Yes

EU AI Act applies in phases, with important dates amended in 2026

United States

Federal, state and sector-based

Yes at state level; existing federal laws also apply

No single comprehensive federal AI Act

China

Layered AI, algorithm, content and data regulation

Yes

Multiple binding AI-related measures apply

United Kingdom

Existing-law and regulator-led

No horizontal AI Act

AI is mainly regulated through existing legal regimes

Canada

Privacy-led with developing legislation

No comprehensive AI Act

Former AIDA proposal did not become law

Japan

AI-specific promotion and governance legislation

Yes

AI-specific legislation is in effect

South Korea

Cross-sector AI framework legislation

Yes

AI Basic Act is in force

Singapore

Governance and assurance-led

Mainly frameworks plus existing laws

Model frameworks are guidance, not a general AI Act

India

Data, digital and sector-based

No comprehensive AI Act

DPDP implementation and synthetic-content rules are important

Vietnam

Risk-based AI legislation

Yes

National AI Law has been in force since March 2026

Brazil

Privacy law plus developing AI legislation

Comprehensive AI legislation remains proposed

Bill remains in the legislative process

Australia

Existing-law model plus guidance

No comprehensive AI Act

Earlier mandatory high-risk guardrail proposal is not proceeding at this time

The absence of a comprehensive AI Act does not mean that a jurisdiction has no legally binding AI-related obligations.

How AI Regulation Differs Around the World

Countries regulate artificial intelligence through very different legal architectures.

 

The EU uses horizontal legislation that classifies AI according to risk and assigns responsibilities to actors including providers and deployers. Vietnam has also adopted a statutory risk-classification approach. China regulates important AI activities through several binding measures covering algorithms, generative AI, synthetic content and digital services. South Korea uses a framework statute that combines AI development policy with transparency, trust and safety requirements.

 

Other countries distribute AI regulation across existing laws. The United States combines federal statutes and agency authority with state legislation. The UK relies substantially on established regulators and existing legal regimes. Australia currently combines existing legislation with responsible-AI guidance, while Singapore has developed governance and assurance frameworks without making its Model AI Governance Framework a general AI statute.

AI-specific laws vs. existing laws that regulate AI

AI-related legal obligations can exist even when a country has no comprehensive AI-specific law.

 

For example, an AI recruitment tool may fall under employment and discrimination laws. A generative AI service that processes personal information may trigger privacy requirements. AI-generated advertising can be subject to consumer-protection rules. AI deployed in healthcare, financial services, transport or other regulated industries may face additional sector-specific requirements.

 

Businesses therefore need to ask two separate questions:

  1. Does the jurisdiction have an AI-specific law?

  2. Which existing laws apply to this particular AI use?

 

The answers are often different.

Why the same AI system can face different rules in different countries

Regulatory exposure can depend on the provider's location, where the system is supplied, where users or affected individuals are located, its intended purpose, sector, risk classification and use of personal data.

 

Organisations should therefore avoid treating global AI compliance as a single classification exercise. The same system may be classified as high risk in one jurisdiction, regulated principally through privacy law in another, and subject to content or platform requirements elsewhere.

What Changed in Global AI Regulation in 2026?

Several developments materially changed the regulatory landscape in 2026.

 

The EU amended important parts of the AI Act implementation timetable through its 2026 AI Omnibus. South Korea's AI Basic Act moved into force. Vietnam's first dedicated national AI Law became effective. Colorado enacted revised rules governing automated decision-making. India continued implementing its data-protection framework and strengthened requirements concerning synthetically generated information. Australia confirmed that its previous proposal for mandatory high-risk AI guardrails would not proceed at this time.

 

These developments demonstrate why legal status matters. An article written only one year earlier could now contain incorrect implementation dates or describe measures as proposals that have since become law.

AI Laws and Regulations in the European Union

The European Union's principal AI-specific legislation is Regulation (EU) 2024/1689, commonly known as the EU AI Act.

 

The Act establishes a horizontal risk-based framework covering prohibited AI practices, high-risk systems, transparency requirements, general-purpose AI models and institutional governance. The European Commission's official AI Act regulatory framework guidance explains the structure and phased implementation of the regime.

 

The AI Act entered into force on 1 August 2024. Prohibited practices and initial AI-literacy provisions began applying on 2 February 2025, while governance rules and obligations concerning general-purpose AI began applying from 2 August 2025.

 

High-risk systems can be subject to requirements involving risk management, data governance, technical documentation, logging, information for deployers, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.

What businesses need to watch in the EU

Organisations first need to determine their role. The AI Act distinguishes between providers, deployers, importers, distributors and other participants in the AI value chain.

 

Classification also matters. A system classified as high risk can trigger significantly more extensive governance and documentation requirements than an AI system outside that category.

 

Transparency duties apply separately to certain AI systems and AI-generated or manipulated content. General-purpose AI providers also have a distinct regulatory framework, with additional obligations for models presenting systemic risk.

 

AI literacy remains relevant after the 2026 amendments. Providers and deployers must take measures supporting the development of appropriate AI literacy among people dealing with AI systems on their behalf.

The 2026 AI Omnibus changes

Businesses should be particularly careful with older AI Act implementation calendars.

 

The 2026 amendments changed important application dates. Under the amended legal framework, requirements for relevant Annex III high-risk AI systems apply from 2 December 2027, while requirements for high-risk AI systems connected with regulated products under Annex I apply from 2 August 2028.

 

The authoritative amended legislation is available through EUR-Lex Regulation (EU) 2026/1744.

 

The European Commission also provides a current explanation of the changes through its AI Omnibus update.

 

The Omnibus also introduced additional prohibited practices concerning specified non-consensual intimate material and child sexual abuse material, which begin applying on 2 December 2026.

National AI laws within the EU

The EU AI Act does not eliminate every possibility for national AI-related legislation.

 

Italy, for example, enacted Law No. 132 of 23 September 2025 concerning artificial intelligence. The law entered into force in October 2025 and operates alongside the EU regulatory framework. The official legislation can be accessed through the Italian Official Gazette.

 

International businesses may therefore need to assess both EU-wide requirements and relevant national provisions.

AI Laws and Regulations in the United States

The United States does not currently have one comprehensive horizontal federal AI statute equivalent to the EU AI Act.

 

Instead, AI regulation involves existing federal laws, federal regulatory agencies, executive policy and an expanding body of state legislation.

 

Consumer protection, discrimination, employment, privacy, financial-services, healthcare and other federal rules can apply when AI is used within activities those laws already regulate.

Why U.S. AI regulation is different

The country's federal-state structure is fundamental.

 

Federal authorities can regulate activities within their existing statutory powers, while individual states can create separate privacy, employment, consumer and automated-decision rules unless those requirements are legally pre-empted.

 

A company operating nationally therefore cannot assume that monitoring Washington alone provides a complete picture of U.S. AI regulation.

State AI regulation

Texas's Responsible Artificial Intelligence Governance Act provides one example of state-level AI legislation. The official Texas Legislature text for House Bill 149 establishes rules governing specified AI uses and related enforcement.

 

Colorado also materially revised its AI framework in 2026.

 

Colorado Senate Bill 26-189 became law in May 2026 and regulates automated decision-making technology used in consequential decisions. Important provisions begin applying from 1 January 2027.

What U.S. businesses should monitor

Businesses should monitor federal regulatory activity, state AI statutes, privacy legislation, employment and discrimination rules, automated-decision requirements and sector regulators.

 

The relevant compliance question is not simply whether the U.S. has "an AI Act." It is which combination of federal, state and sector-specific rules applies to a particular system and use.

AI Regulation in China

China regulates AI through several binding measures rather than through one comprehensive horizontal AI Act.

 

The Interim Measures for the Management of Generative Artificial Intelligence Services have applied since August 2023 and cover generative AI services offered to the public in mainland China. The official rules published by the Cyberspace Administration of China address areas including training data, personal information, content governance and provider responsibilities. See the official CAC Generative AI Measures.

 

China separately regulates algorithmic recommendation services and deep-synthesis technologies.

 

A further development is the Measures for the Identification of Artificial Intelligence Generated and Synthetic Content, which took effect on 1 September 2025. The official CAC announcement on AI-generated content identification explains the identification and labelling regime.

 

For businesses, China's model can require simultaneous consideration of AI-specific rules, content regulation, cybersecurity, personal-information protection, platform duties and algorithm-related requirements.

AI Regulation in the United Kingdom

As of September 2026, the UK has not enacted a horizontal AI Act equivalent to the EU AI Act.

 

The government continues to rely mainly on existing regulators and legal regimes covering data protection, competition, equality, consumer protection, product safety and regulated sectors.

 

A July 2026 UK parliamentary answer on AI regulation confirmed that existing expert regulators remain central to the government's approach while additional legislation may be considered where existing rules are insufficient.

 

A subsequent September 2026 parliamentary response showed that further AI legislation remained under consideration rather than already forming a comprehensive UK AI statute.

How UK AI regulation differs from the EU AI Act

The EU has enacted a horizontal law containing specific AI classifications, regulated roles and phased obligations.

 

The UK currently relies more heavily on laws and regulators that already govern the context in which AI is used.

 

A business operating in both markets therefore requires separate legal mapping. An AI application might require classification under the EU AI Act while its UK deployment is assessed mainly through data protection, equality, consumer, competition or sector-specific law.

AI Regulation in Canada

Canada currently has no enacted comprehensive federal AI Act.

 

The proposed Artificial Intelligence and Data Act, or AIDA, appeared within Bill C-27 during Canada's previous Parliament, but it did not become law. The legislative history remains available through the Parliament of Canada Bill C-27 record.

 

Existing privacy laws nevertheless apply to AI-related processing.

 

In May 2026, Canada's federal and provincial privacy regulators published findings from a joint investigation of OpenAI. The Office of the Privacy Commissioner investigation report examined consent, transparency, accuracy, collection and accountability issues under existing privacy laws.

 

The investigation demonstrates an important global principle: the absence of a comprehensive AI Act does not prevent regulators from applying existing legislation to AI systems.

 

Canada also introduced further privacy and consumer-data legislation in 2026. Businesses should distinguish these developing proposals from legislation already in force.

AI Regulation in Japan

Japan now has AI-specific legislation.

 

The Act on Promotion of Research and Development and Utilization of Artificial Intelligence Related Technology, Act No. 53 of 2025, established a national legal framework focusing on AI development, utilisation, responsibilities and government strategy.

 

Official information about the legislation is available through the Cabinet Office AI Act resource.

 

Japan's framework is not structured like the EU's detailed high-risk conformity regime. It places substantial emphasis on national strategy, responsible adoption, innovation and governance while existing privacy, consumer, intellectual-property, competition and sector laws continue to apply.

 

Japan also adopted an updated Artificial Intelligence Basic Plan in July 2026. The plan is government policy rather than a separate statutory compliance regime. The Cabinet Office AI Basic Plan page records its adoption on 14 July 2026.

AI Regulation in South Korea

South Korea has enacted comprehensive AI framework legislation.

 

The Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust, commonly called the AI Basic Act, entered into force in 2026 and was subsequently amended.

 

The current legislative text is available through South Korea's official national legislation database.

 

The law addresses AI development, transparency, generative AI, safety and high-impact AI systems. It also includes extra-territorial provisions where conduct outside South Korea affects the domestic market or users.

 

For example, the legislation requires businesses to assess whether systems fall within the high-impact AI category, while separate provisions impose transparency duties concerning high-impact and generative AI products and services.

 

South Korea's government has also announced a grace period relating to aspects of enforcement. That policy should not be confused with the legal effective date of the Act itself.

AI Regulation in Singapore

Singapore's approach relies heavily on AI governance, testing and assurance frameworks rather than one comprehensive AI statute.

 

The country's Model AI Governance Framework and AI Verify provide organisations with tools for responsible AI governance, but these instruments should not be described as general binding legislation.

 

Singapore expanded this approach in 2026 through its Model AI Governance Framework for Agentic AI.

 

According to the Infocomm Media Development Authority's 2026 framework update, the framework focuses on issues including risk boundaries, meaningful human accountability, technical controls, transparency and responsible deployment of AI agents.

 

Binding obligations can still arise from Singapore's Personal Data Protection Act and sector-specific laws.

 

Businesses should therefore distinguish voluntary AI-governance tools from binding legislation that applies to the underlying activity.

AI Regulation in India

India does not currently have a comprehensive horizontal AI Act.

 

However, AI systems can fall within data-protection, information-technology, consumer and sector-specific regulation.

 

The Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025 are particularly important where AI systems process digital personal data.

 

India's Ministry of Electronics and Information Technology provides the final rules and an official implementation timetable through its Digital Personal Data Protection Rules 2025 resource.

 

Implementation is phased, so organisations should confirm whether a particular requirement is currently operative rather than treating every provision as having the same commencement date.

 

India also continued work on rules concerning synthetically generated information and deepfake content. These developments demonstrate that AI regulation can evolve through amendments to broader digital regulation even without a standalone AI Act.

AI Regulation in Vietnam

Vietnam has become one of the most significant new AI-law jurisdictions in Asia.

 

Law No. 134/2025/QH15 on Artificial Intelligence was enacted on 10 December 2025 and became effective on 1 March 2026. The official status, enactment date and effective date can be verified through the Vietnamese Government legislation database.

 

The legislation establishes a risk-based framework governing the development, provision, deployment and use of AI.

 

AI systems are divided into risk categories, with additional requirements applying to higher-risk systems. These can include risk management, documentation, transparency, human oversight, conformity assessment and incident management.

 

For companies operating across Asia, Vietnam should therefore no longer be treated simply as a jurisdiction with an emerging AI policy. It now has enacted AI-specific legislation in force.

AI Regulation in Brazil

Brazil already regulates personal-data processing through the Lei Geral de Proteção de Dados Pessoais, or LGPD, which can apply when AI systems collect, use, infer or otherwise process personal information.

 

Brazil has also been developing comprehensive AI legislation.

 

PL 2338/2023 remains within the legislative process rather than constituting enacted comprehensive AI law. Organisations can track its current progress through the Brazilian Chamber of Deputies legislative record.

 

This distinction is important. Businesses already have obligations under existing Brazilian legislation, while potential additional AI-specific obligations remain dependent on the legislative process.

AI Regulation in Australia

Australia currently regulates AI mainly through existing legislation, regulatory oversight, national policy and responsible-AI guidance rather than a comprehensive AI Act.

 

The Australian Government launched its National AI Plan in December 2025. The official National AI Plan sets out the government's approach to AI opportunity, adoption and safety.

 

An important change concerns the previous proposal for mandatory guardrails for AI used in high-risk settings.

 

The Australian Government now explicitly states that it will not proceed at this time with the earlier mandatory-guardrail proposal. That current position is recorded on the Department of Industry's mandatory AI guardrails consultation page.

 

Australia instead provides responsible-AI guidance, including practical governance measures concerning accountability, risk management, data, testing and human oversight.

 

These frameworks are useful, but they should not be confused with a comprehensive statutory AI Act.

 

Existing privacy, consumer, discrimination, safety and other laws can still regulate particular AI uses.

AI Regulation in Other Countries and Regions

Europe beyond the EU

The Council of Europe's Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is an important international development.

 

The treaty opened for signature in September 2024. As of September 2026, the conditions required for entry into force had not yet been met.

 

The Council of Europe's official treaty-status page for Convention No. 225 provides the authoritative record of signatures, ratifications and entry-into-force requirements.

 

The Convention is therefore significant, but it should not yet be described as a treaty generally in force.

Latin America

Beyond Brazil, several Latin American jurisdictions continue developing AI legislation, strategies and governance frameworks.

 

Businesses should assess each country separately. A national AI strategy, consultation or parliamentary bill is not equivalent to binding legislation.

Africa

At continental level, the African Union has developed a Continental Artificial Intelligence Strategy intended to support responsible AI development and more coordinated national approaches.

 

It is a policy framework rather than continent-wide binding legislation.

 

Individual African countries can nevertheless regulate AI-related activities through privacy, employment, consumer, cybersecurity and sector-specific laws.

Middle East and emerging markets

Saudi Arabia provides another example of a mixed regulatory model.

 

Binding personal-data requirements operate alongside AI governance and responsible-use frameworks developed by the Saudi Data and AI Authority.

 

SDAIA's AI Adoption Framework incorporates responsible-AI principles including fairness, privacy, security, reliability, transparency and accountability.

 

These governance measures should be distinguished from binding statutory obligations under Saudi data-protection and other applicable laws.

Global AI Regulation Compared

Jurisdiction

Regulatory model

Main instrument

Legal status

Key business focus

EU

Horizontal risk-based

EU AI Act

In force with phased application

Classification, high-risk AI, GPAI, transparency

U.S.

Federal, state and sectoral

Existing federal laws and state AI statutes

Mixed

Consumer, privacy, employment, automated decisions

China

Layered binding regulation

Generative AI, algorithm and synthetic-content rules

In force

Content, algorithms, data, labelling

UK

Existing-law and regulator-led

Privacy, competition, equality, safety and sector laws

Binding existing laws

Context-specific AI use

Canada

Privacy-led

Existing privacy law; developing legislation

Existing privacy laws binding

Personal information, transparency, accountability

Japan

AI-specific promotion/governance

Act No. 53 of 2025

In force

Responsible development and national AI strategy

South Korea

Cross-sector framework

AI Basic Act

In force

High-impact AI, generative AI, transparency

Singapore

Governance and assurance

Model AI Governance Frameworks

Mainly guidance

Accountability, testing, agentic AI

India

Data and digital regulation

DPDP framework, IT rules

Phased/binding according to provision

Data protection, platforms, synthetic content

Vietnam

Risk-based statutory model

Law No. 134/2025/QH15

In force

Classification, conformity, transparency

Brazil

Privacy plus proposed AI law

LGPD and PL 2338/2023

LGPD binding; AI bill proposed

Privacy, proposed AI risk governance

Australia

Existing-law plus guidance

Existing law, National AI Plan and AI guidance

Mixed

Privacy, consumer protection, responsible adoption

What Global AI Regulation Means for International Businesses

International organisations should assume that several regulatory regimes may apply to one AI system.

 

Market access can create regulatory exposure even where the provider is established elsewhere. Privacy laws can apply separately from AI-specific legislation. Employment use can introduce equality and labour-law considerations, while healthcare, finance, transport and other regulated sectors can add additional obligations.

 

Provider, deployer, distributor, controller, processor, employer and vendor status can also change legal responsibilities.

 

Third-party AI deserves particular attention. Purchasing a model from an external supplier does not automatically transfer all regulatory responsibility to that supplier. Organisations still need to know what data enters the system, what decisions rely on it, whether outputs are reviewed and what contractual protections exist.

Develop stronger regulatory awareness

Professionals who want a structured introduction to these issues can explore the AI Law & Regulation Essentials Training.

 

The course supports foundational understanding of AI law, regulatory approaches and the changing international governance landscape.

How to Build a Global AI Compliance Approach

Five-step process for global AI compliance.

Step 1: Create an AI inventory

Identify where AI is developed, purchased, embedded and used.

 

Include internal models, generative AI tools, automated-decision technologies, AI features inside larger software products and systems supplied to customers.

 

Record each system's purpose, owner, vendor, users, affected individuals, data categories, deployment locations and role in decision-making.

Step 2: Map jurisdictions

Determine where each system is developed, offered, deployed and accessed and where affected people are located.

 

Do not assume that corporate headquarters determine every legal obligation. Some regulations apply to foreign organisations when systems affect local users or markets.

Step 3: Classify regulatory requirements

Separate requirements into categories such as:

  • AI-specific legislation

  • privacy and data protection

  • consumer protection

  • employment and equality

  • cybersecurity

  • intellectual property

  • product safety

  • sector-specific regulation

  • regulatory guidance

  • voluntary standards

 

Then record whether each requirement is binding now, enacted for future application, proposed, under consultation or voluntary.

Step 4: Assess AI risk

Assess what the system does, who could be affected and how serious the consequences of failure may be.

 

Relevant considerations can include safety, fundamental rights, discrimination, financial impact, privacy, cybersecurity, misinformation and human oversight.

 

One internal corporate risk score should not be assumed to match the legal classification used by every jurisdiction.

Step 5: Establish governance and documentation

Assign responsibility for AI approval, procurement, testing, monitoring, vendor management, documentation, incident management and regulatory change.

 

Organisations developing a more mature governance system can connect these activities with building an AI compliance program, while recognising that no generic framework replaces jurisdiction-specific legal analysis.

AI Laws, Privacy and Data Protection

AI law and privacy law frequently overlap, but they are not the same regulatory field.

 

Model training, retrieval, profiling, inference, personalisation and automated decisions can involve personal information. Where they do, organisations may need to address lawful processing, transparency, data minimisation, purpose limitation, security, individual rights, retention and international transfers.

 

Canada provides a clear recent example. In 2026, privacy regulators investigated AI-model development and deployment under existing privacy laws rather than waiting for a comprehensive AI statute. The Canadian regulators' OpenAI investigation findings addressed issues including consent, transparency, data collection and accountability.

What Businesses Should Monitor as AI Laws Change

AI regulatory monitoring should cover more than newly passed legislation.

 

Organisations should monitor:

  • legislation and amendments

  • implementing regulations

  • regulator guidance

  • application and commencement dates

  • enforcement decisions

  • technical standards

  • sector-specific rules

  • AI safety requirements

  • privacy developments

  • international regulatory developments

 

The key question is often not simply, "Has a law been passed?" but, "What is its legal status today?"

 

The EU amended important implementation dates in 2026. South Korea's AI framework is already in force even though enforcement policy includes transition arrangements. Australia's mandatory high-risk guardrail proposal is not proceeding at this time. Brazil's broader AI legislation remains proposed. Vietnam has moved from policy development to an enacted AI law already in force.

Why regulatory status matters

A useful sequence is:

 

Proposed → Passed → Enacted → In force → Applicable → Enforced

 

These stages are not identical in every legal system.

 

A proposed law may still change. Legislative approval can precede formal enactment. A law may enter into force while particular obligations have later application dates. Regulators may then apply transition arrangements or enforcement policies.

 

Keeping those distinctions visible is essential for accurate global AI compliance monitoring.

Conclusion

Global AI regulation is becoming more developed, but it remains fragmented.

 

The EU, China, South Korea, Japan and Vietnam illustrate different approaches to AI-specific legislation and binding regulation. The United States, UK, Canada, Singapore, India, Brazil and Australia demonstrate alternative combinations of existing laws, state or sector regulation, governance frameworks and developing legislation.

 

For international organisations, the practical challenge is not simply identifying which countries have an AI Act. It is determining what type of regulatory instrument exists, whether it is legally binding, who it affects and when its requirements apply.

 

A structured approach to regulatory monitoring, supported by an accurate AI inventory and jurisdiction mapping, provides a stronger foundation for navigating that changing landscape.

 

The information in this article provides general educational information about AI regulation and should not be treated as legal advice. Organisations should assess their specific obligations with appropriate legal or compliance professionals.

 

Professionals seeking a structured foundation in this field can explore AI Law & Regulation Essentials Training to build their understanding of AI law, regulatory models and evolving governance requirements.

Frequently Asked Questions

Several jurisdictions now have AI-specific legislation or binding AI-related rules, including the European Union, China, Japan, South Korea and Vietnam. Other countries regulate AI primarily through existing legislation, state rules, sector regulation or governance frameworks.

No. AI can still be subject to legally binding privacy, consumer, employment, discrimination, cybersecurity and sector-specific rules even where no comprehensive AI statute exists.

Important examples include the EU AI Act, China's generative-AI and algorithm regulations, South Korea's AI Basic Act, Japan's AI legislation and Vietnam's Law on Artificial Intelligence.

The U.S., UK, Canada, Singapore, India, Brazil and Australia use different combinations of existing laws, state or sector regulation, governance frameworks and developing legislation.

The EU AI Act is binding EU legislation establishing a risk-based regulatory framework for artificial intelligence. It covers prohibited AI practices, high-risk systems, transparency, general-purpose AI and governance.

The European Commission maintains a current EU AI Act regulatory overview.

The United States does not currently have one comprehensive horizontal federal AI statute equivalent to the EU AI Act.

Existing federal laws can apply to AI-related conduct, while states have enacted separate AI, privacy and automated-decision requirements.

China uses several binding regulatory instruments addressing algorithms, generative AI, synthetic content, personal information and digital services rather than relying on one comprehensive AI Act.

As of September 2026, the UK has not enacted a horizontal AI Act comparable to the EU AI Act. Existing regulators and legal frameworks remain central to the UK model.

Yes. Vietnam's Law No. 134/2025/QH15 became effective on 1 March 2026 and establishes a risk-based AI regulatory framework. The official law is available through the Vietnamese Government legislation database.

An AI law creates legally binding obligations through the relevant legal system. A governance framework may provide principles, recommendations, testing methodologies or good practices without creating general statutory duties.

Singapore's Model AI Governance Framework is an example of governance guidance rather than a comprehensive AI Act.

Potentially. Application depends on the particular law's scope and the organisation's activities.

Supplying AI into a local market, processing local residents' data or operating through local entities can create obligations even where the developer is established elsewhere.

Both can apply simultaneously.

An AI system may fall within AI-specific regulation while its collection, training, inference or decision-making involving personal information is separately governed by privacy legislation.

Organisations can maintain a jurisdiction register, assign regulatory ownership, monitor official government and regulator sources, record commencement and application dates and reassess systems when laws or product functionality change.

A practical program can include an AI inventory, jurisdiction mapping, legal and risk classification, defined responsibilities, vendor review, testing, human oversight, privacy and security controls, documentation, incident management and regulatory-change tracking.