Artificial IntelligenceRegulations
A worldwide reference · current to July 28, 2026

The law is catching up
to artificial intelligence.

A complete, cited record of how every major jurisdiction regulates AI, filed the same way, linked to the primary text, and kept current.

33national and EU regimes
11US states tracked separately
3comprehensive AI laws in force
7%of global turnover, the top EU fine

For most of the past decade, artificial intelligence outran the law. That has reversed. In two years the European Union put the first comprehensive AI statute into force, South Korea and Vietnam followed with binding laws of their own, and the United States chose the opposite path and moved to stop its own states from regulating at all.

There is no single global rulebook, and there will not be one soon. What exists instead is a set of distinct national bets about how to govern a technology that crosses borders by default. The European Union bet on one horizontal law that scales its demands to the risk of each use. China bet on a dense stack of targeted rules tied to content and security, enforced without a single statute to point to. The United Kingdom bet on its existing regulators and declined to write an AI act at all. The United States, for now, has bet on doing very little at the federal level while trying to stop its states from filling the gap.

The map is also no longer a Brussels-and-Washington story. Vietnam's AI Law, effective March 2026, is Southeast Asia's first binding comprehensive statute and reaches foreign providers directly. Taiwan put a framework act into force in January. Peru, which quietly passed Latin America's first AI law back in 2023, gave it real structure with a regulation that took effect this year. Australia looked at all of this and formally decided not to legislate. Each of those choices now sits in the register with the same fields and the same sourcing.

These choices reach well past their own borders. The EU AI Act binds any company whose systems are used in the Union, wherever that company sits, and its penalties run to 7 percent of worldwide turnover, the top of a wildly uneven global penalty table. South Korea's law reaches foreign providers serving Korean users, and Vietnam's does the same. A product built in one country now answers to the strictest regime it touches, which is why most global firms build to the European standard and treat the rest as a subtraction from it.

The American picture is the messiest and the fastest-moving. Congress has passed nothing. In its place, dozens of states have written their own measures, eleven of which are filed in the state tracker, and in December 2025 the White House signed an order directing the Justice Department to challenge them and threatening federal funding for states that keep them. Colorado, the first state to pass a comprehensive AI law, repealed it before it ever took effect. Virginia's legislature passed one and watched it die by veto. Until the courts settle the preemption fight, every state law on the books remains enforceable, and most follow the person affected rather than the company's address, so one national product can trigger several at once.

This is a working map of all of it. Every jurisdiction is filed the same way: the governing instrument named, the status and dates stated plainly, and a link to the primary text so you can check the wording yourself. The deadline calendar tracks every date that matters through 2028, and the glossary defines the terms of art the statutes lean on. It is free, and it is kept current, because currency is the whole point. A guide that still lists Colorado's original act as law, or the EU's high-risk deadline as August 2026, is worse than no guide at all.

The register

Every regime, at a glance

Search and filter all →

National and EU regimes, with status reflecting binding law rather than proposals or guidance. The United States sits as one entry, because its federal posture and its state laws are two different questions. Select any row for the governing laws, timeline, penalties, and primary sources.

FlagJurisdictionRegulatory approachStatus
ChinaExtensive binding sectoral rules; no single comprehensive actIn forceEuropean UnionComprehensive, horizontal, risk-based statutePhasing inSouth KoreaComprehensive risk-based act with a light enforcement postureIn forceUnited KingdomSectoral, principles-based; no horizontal AI act by designNo comprehensive lawUnited StatesNo comprehensive federal law; active state legislation and a preemption fightNo comprehensive lawAustraliaNo AI act; existing laws plus voluntary guidance, by explicit choiceNo comprehensive lawBrazilComprehensive EU-style bill advancing through the legislatureProposedCanadaProposed federal act lapsed; voluntary code plus provincial rulesLapsed / failedCouncil of EuropeFirst binding international AI treaty (framework convention)Partially in forceJapanInnovation-first framework law; light-touch and non-punitiveIn forceMexicoNo AI law; bills pending, data protection reform added ADM rightsProposedPeruFirst AI law in Latin America; promotional statute with risk-based regulationIn forceSaudi ArabiaCentralized governance through SDAIA; principles and drafts, no AI actNo comprehensive lawSwitzerlandDeliberate counter-model to the EU: sectoral, with a treaty-implementation bill dueProposedTaiwanFramework statute; principles in force, obligations to followIn forceUAELayered model: charters and strategy federally, binding rules in zones and financePartially in forceVietnamComprehensive, risk-based AI law with extraterritorial reachIn forceArgentinaNo AI law; guidance and hearings, momentum without a vehicleNo comprehensive lawChileEU-inspired risk-based bill in Congress; updated national policyProposedColombiaThree bills in play; policy framework set, no lawProposedEgyptStrategy and charter; data protection law binds, no AI actNo comprehensive lawHong KongNo AI law; dense sectoral guidance, hardest in financeNo comprehensive lawIndiaPrinciples-based guidelines plus targeted synthetic-media rulesNo comprehensive lawIndonesiaRoadmap and ethics guidance; binding rules in developmentProposedIsraelDeliberately decentralized: sectoral regulators, soft law, no AI actNo comprehensive lawKenyaAI Bill tabled 2026: classification, high-risk duties, and a registerProposedMalaysiaVoluntary governance guidelines; no binding AI lawNo comprehensive lawNew ZealandNo AI-specific law; existing technology-neutral statutesNo comprehensive lawNigeriaBinding framework in motion: risk-based bill with licensing for high-risk AIProposedSingaporeVoluntary frameworks and testing tools; no binding AI lawNo comprehensive lawSouth AfricaDraft national AI policy; POPIA binds, no AI legislation proposed yetNo comprehensive lawThailandDraft AI law in development; data protection already appliesProposedTurkeyDraft AI framework pending; data protection and cybersecurity law bind nowProposed
In forcePartially in forcePhasing inProposedNo comprehensive lawRepealed / replacedLapsed / failed
United States, state by state. Eleven states sit on the tracker, from comprehensive frameworks to single-issue statutes to one vetoed law, and most follow the resident rather than the company. Open the state tracker to sort and filter them. State tracker →
The two models

Two ways to regulate a technology

Almost every regime falls into one of two shapes, with China standing apart. Knowing which shape governs you tells you where to look first.

Model 01

Comprehensive and risk-based

One law covers the whole economy and scales its obligations to how much harm a use could cause. Banned uses at the top, heavy duties for high-risk uses, light disclosure for the rest. The template is the EU AI Act. These regimes tend to reach across borders and carry the largest fines.

Model 02

Sectoral and principles-based

No dedicated AI law. Existing regulators apply broad principles or established statutes to whatever AI does inside their remit. Lighter and more adaptable, and harder to map, because the rule that governs you depends on what the system is used for, not on the fact that it is AI.

A model of its own

China

China fits neither. It runs the most operationally demanding regime in the world through a stack of binding rules on recommendation algorithms, deep synthesis, generative services, and content labeling, all tied to content control and national security, and all enforced without a single comprehensive act.

What is coming

Key deadlines through 2028

Full calendar →

The dates that will actually change how AI is built and shipped. Most of the near-term pressure is European, and most of it lands in the second half of 2026.

  • August 2, 2026EU Article 50 transparency duties and California's AI Transparency Act apply
    Chatbot disclosure and synthetic-content marking in the EU; watermarking, latent disclosure, and a public detection tool for large generative providers in California.
  • Early August 2026Saudi Arabia's draft AI Cybersecurity Guidelines consultation closes
    The NCA's lifecycle security guidelines move toward finalization.
  • December 2, 2026EU ban on non-consensual intimate imagery generators; watermark grace period ends
    The Digital Omnibus's Article 5 addition takes effect and the transitional accommodation on marking closes.
  • End of 2026Switzerland's AI consultation bill due
    The FDJP's draft implementing the Council of Europe convention, covering transparency, data protection, non-discrimination, and oversight.
  • January 1, 2027Colorado ADMT law, New York frontier law, and Illinois' AI Safety Measures Act take effect; Peru's first sector wave completes
    Colorado's replacement statute, New York's frontier transparency law, and Illinois' frontier safety act all begin; Peru's health, education, justice, security, and finance sectors reach their compliance mark.
  • December 2, 2027EU high-risk (Annex III) obligations apply
    Recruitment, credit, education, law enforcement, and other consequential-decision systems face the full high-risk regime.
Enforcement

The teeth vary wildly

All 44 compared →

Headlines fixate on the size of European fines, but the real deterrent differs by jurisdiction. In some places the risk is a fine; in others it is losing the right to operate, or a class action.

European Union

Up to 35 million euros or 7 percent of worldwide turnover for a banned use, the steepest fines in force anywhere. They bind companies based outside the Union.

China

No headline fine, but harder teeth in practice: service suspension, content takedowns, and revoked filings, with more immediate penalties after the 2026 Cybersecurity Law amendment.

South Korea

Modest by design. Administrative fines up to about 30 million won, roughly twenty thousand dollars, with a grace period through 2026 to ease companies in.

United States

No federal AI fine exists. Exposure runs through state attorneys general, the FTC's deception authority, and private suits under biometric laws such as Illinois BIPA, where damages stack per violation.

News digest

What changed recently

Full digest →

Live headlines refresh automatically every six hours. Below them, original summaries of the moves that matter, each linked to the source.

July 20, 2026
European Commission

Commission adopts final Article 50 transparency guidelines, thirteen days before the deadline

The European Commission adopted the final 51-page guidelines on the AI Act's transparency obligations and assessed the Code of Practice on Transparency of AI-Generated Content as adequate. The final text softens the draft in one important place: image, audio, and video deepfakes generated before August 2, 2026 never need retroactive marking, with the date of generation governing, while AI-written text on matters of public interest is judged by its publication date, so older text published after the deadline must be labeled. Open-source systems get no exemption. Transparency violations carry fines up to 15 million euros or 3 percent of worldwide turnover.

July 10, 2026
European Commission

EU AI Act transparency phase goes live; chatbot disclosure now enforceable

The AI Act's Article 50 transparency duties are now in effect. Any business deploying a chatbot or conversational system for EU users has to disclose that the user is dealing with AI, and providers of generative systems must mark synthetic output. Machine-readable marking for content from systems already on the market has a grace period to December 2, 2026.

July 9, 2026
European Commission

Digital Omnibus receives final green light, locking in high-risk delay

The AI Act simplification package cleared its final approval. It confirms the deferral of stand-alone high-risk obligations to December 2, 2027 and product-embedded ones to August 2, 2028, narrows the 'safety component' test, and adds the nudifier and CSAM prohibition taking effect in December 2026.

July 7, 2026
European Commission

Commission presents EU Action Plan on Cybersecurity and AI

The Commission set out a coordinated plan to help member states and businesses handle the security risks of the most advanced AI models, and signaled a call to build EU capacity to evaluate models before they reach the market, expected operational by 2027.

How to read this

Common questions

Is there a global AI law?
No single global AI law exists, and none is close. As of July 2026 three comprehensive AI laws are in force: the European Union AI Act, South Korea's AI Basic Act, and Vietnam's AI Law. Taiwan and Peru have framework statutes, China enforces an extensive set of binding sectoral rules, the United States has no federal AI statute and regulates mainly through state law, and countries such as the United Kingdom, Japan, Australia, and Singapore rely on existing regulators and voluntary frameworks.
Which country has the strictest AI regulation?
The EU AI Act sets the strictest binding legal benchmark, with fines up to 35 million euros or 7 percent of worldwide turnover, which is why most global companies build to it. China's regime is often the most demanding to operate under, because of pre-deployment security assessment and dual visible-and-embedded content labeling.
Do US state AI laws still apply after the December 2025 federal executive order?
Yes. The federal preemption effort is ongoing and unsettled. State AI laws remain enforceable unless and until a court strikes them down or Congress passes a preempting statute. The prudent course is to keep complying with applicable state law while tracking the litigation.
Does a company outside the EU have to comply with the EU AI Act?
Often yes. The Act applies wherever the provider or deployer sits if the system's output is used in the EU. A model built and hosted elsewhere still falls in scope once its results reach users in the Union.
How current is this resource?
Each jurisdiction page carries a date it was last reviewed, and the register reflects binding law as of that review. AI law moves fast: Colorado repealed its landmark act before it took effect, and the EU deferred its high-risk deadlines by more than a year. Always confirm against the linked primary source before you rely on an entry.