Artificial IntelligenceRegulations

Generative AI and foundation models

Rules aimed at general-purpose models and the companies that build them.

A newer layer of rules targets the largest general-purpose and frontier models directly. The EU AI Act imposes transparency, documentation, and copyright duties on all general-purpose AI model providers from August 2025, with added systemic-risk obligations above a compute threshold. California's Transparency in Frontier Artificial Intelligence Act requires the largest developers to publish safety frameworks and report incidents. China requires security assessment and filing for public-facing generative services. South Korea adds duties for large-scale advanced AI.

Why it matters

If you build or fine-tune large models rather than just deploy them, this is the category written for you, and it sits on top of the deployment rules everyone else follows.

How each jurisdiction handles it

Recent developments

July 7, 2026
European Commission

Commission presents EU Action Plan on Cybersecurity and AI

The Commission set out a coordinated plan to help member states and businesses handle the security risks of the most advanced AI models, and signaled a call to build EU capacity to evaluate models before they reach the market, expected operational by 2027.

July 6, 2026
Skadden

Illinois signs the third frontier AI law, the first anywhere to mandate independent audits

Governor Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315), putting Illinois beside California and New York with the same frontier template: models trained past 10^26 operations, developers above 500 million dollars in revenue, safety frameworks, transparency reports, and incident reporting. Illinois goes one step further than either coast: from January 1, 2028, large frontier developers must retain an independent third party to audit their compliance annually and publish the results. The act takes effect January 1, 2027, enforced exclusively by the attorney general, with no private right of action, and it preempts local AI regulation inside the state.

January 22, 2026
Cooley

South Korea's AI Basic Act takes effect, Asia's first comprehensive AI law

The AI Basic Act and its Enforcement Decree came into force. It sets transparency and high-impact duties, reaches foreign providers serving Korean users, and runs a one-year grace period before most fines apply. It joins the EU AI Act as one of only two comprehensive regimes in force.

January 1, 2026
King & Spalding

A wave of US state AI laws takes effect: California, Texas, Illinois

California's frontier transparency and training-data laws, Texas TRAIGA, and Illinois' AI employment amendment all took effect on the same day, a month after the federal preemption order. For now every one of them remains enforceable, and most follow the affected resident rather than the company's location.

Common questions

What does generative ai and foundation models mean in AI regulation?
A newer layer of rules targets the largest general-purpose and frontier models directly. The EU AI Act imposes transparency, documentation, and copyright duties on all general-purpose AI model providers from August 2025, with added systemic-risk obligations above a compute threshold. California's Transparency in Frontier Artificial Intelligence Act requires the largest developers to publish safety frameworks and report incidents. China requires security assessment and filing for public-facing generative services. South Korea adds duties for large-scale advanced AI.
Why does generative ai and foundation models matter for compliance?
If you build or fine-tune large models rather than just deploy them, this is the category written for you, and it sits on top of the deployment rules everyone else follows.
Cite this page

Artificial Intelligence Regulations, "Generative AI and foundation models in AI Regulation," reviewed July 28, 2026, https://artificialintelligenceregulations.com/topics/generative-foundation-models.html.

Entries state the position as of the review date and link to the primary text for verification.