Status date and scope
This is a snapshot as of September 13, 2026, not legal advice. AI law changes quickly, and obligations depend on jurisdiction, actor, model, use, and effective date. A statute may be enacted but not yet applicable; guidance may influence enforcement without itself being binding; a voluntary code may help demonstrate compliance without becoming law.
There is no single global AI regulator and no comprehensive U.S. federal frontier-model statute. Existing law still applies: discrimination, privacy, consumer protection, product safety, copyright, contracts, sectoral regulation, criminal law, and constitutional limits do not vanish when AI is involved.
European Union: binding law in staged application
The EU Artificial Intelligence Act is binding regulation with risk-based duties. Prohibited-practice and AI-literacy provisions began earlier in the implementation schedule. Obligations for providers of general-purpose AI models began applying on August 2, 2025. From August 2, 2026, the Commission’s AI Office and national authorities began exercising enforcement powers for applicable provisions, and Article 50 transparency duties began applying to specified AI interactions and synthetic or manipulated content (European Commission enforcement framework).
Providers of general-purpose models must prepare technical documentation, provide downstream information, maintain an EU-copyright policy, and publish a training-content summary. Providers of general-purpose models with systemic risk face additional model evaluation, systemic-risk assessment and mitigation, incident reporting, and cybersecurity duties. A training-compute threshold creates a presumption of systemic risk, but the Commission can also designate models based on capability or impact (European Commission GPAI obligations).
The General-Purpose AI Code of Practice is voluntary. The Commission recognizes it as a method providers can use to demonstrate compliance; the underlying AI Act duties are binding for covered providers. A nonsignatory does not escape the law and may present alternative adequate means.
Article 50 requires specified disclosures and machine-readable marking, with exceptions and role-specific rules. It does not make every AI output illegal if unlabeled, and a label does not prove content is false. Commission guidance says relevant fines can reach €15 million or 3% of worldwide annual turnover, subject to legal conditions and proportionality (European Commission Article 50 FAQ, July 2026).
The 2026 AI Omnibus modified timelines and administration, including later application for important high-risk categories. Anyone planning compliance should use the consolidated legal text and current Commission timeline, not an article written before July 2026 (European Commission, July 2026).
United States federal policy: sectoral law and a changed executive approach
President Trump revoked Executive Order 14110 in January 2025 through Executive Order 14179 and directed review of measures adopted under the prior order (White House, January 23, 2025). A page that describes EO 14110’s frontier-training reports as current binding federal requirements is outdated unless another live authority independently requires them.
The July 2025 America’s AI Action Plan emphasizes innovation, infrastructure, exports, national security, and regulatory restraint (White House, July 2025). The plan is an executive-policy document, not a comprehensive statute enacted by Congress. Agency rules, procurement terms, export controls, and existing statutory authorities still have separate legal force.
The TAKE IT DOWN Act became federal law in May 2025. It criminalizes specified publication of non-consensual intimate visual depictions, including covered digital forgeries, and requires covered platforms to operate a notice-and-removal process on the statutory schedule. It is a targeted intimate-image law, not a universal deepfake-labeling regime (Public Law 119-12).
Federal civil-rights and consumer laws can reach automated systems. Employers can violate the ADA or Title VII through discriminatory tools; housing actors remain subject to the Fair Housing Act; lenders remain subject to credit law; and deceptive claims may trigger consumer-protection authority. Enforcement priorities and interpretations can change between administrations, but statutory duties remain unless courts or lawmakers change them.
NIST’s AI Risk Management Framework and Generative AI Profile are voluntary guidance, not binding federal law (NIST AI 600-1). Contracts or regulators may incorporate standards by reference, which can give them practical or legal significance in a specific setting.
California: frontier-model transparency and reporting
California’s SB 53, the Transparency in Frontier Artificial Intelligence Act, was signed September 29, 2025 and took effect in 2026. Within statutory definitions, large frontier developers must publish and follow frontier AI frameworks, report specified critical safety incidents, and protect covered employees who report violations or substantial dangers. The Attorney General has enforcement and intake responsibilities (California Governor; California DOJ).
This is binding state law, not a voluntary laboratory pledge. Coverage thresholds, definitions, reporting events, and available penalties matter. It should not be summarized as licensing every model or proving that compliant models are safe.
California also has other AI, privacy, employment, synthetic-media, and consumer laws. Applicability should be checked separately rather than treating “California AI law” as one instrument.
New York: the RAISE Act
New York’s Responsible AI Safety and Education Act was signed December 19, 2025. It requires covered frontier developers to create and follow safety frameworks and report critical safety incidents under its definitions, with state enforcement mechanisms (New York Governor).
The enacted version, not an earlier bill, controls. Thresholds and scope changed during negotiation. California and New York create meaningful state baselines but do not amount to a uniform U.S. regime. Litigation, federal preemption disputes, and later amendments may affect implementation.
Council of Europe: treaty status is not summit language
The Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law opened for signature on September 5, 2024. It is designed as a legally binding treaty for parties, implemented through domestic law, and addresses principles, risk assessment, accountability, and remedies (Council of Europe).
Signature expresses intent; ratification creates consent to be bound under the treaty process; entry into force depends on the conditions in the text. As of the Council of Europe’s September 11, 2026 status page, no entry-into-force date was listed. Check the live treaty chart before claiming a state is legally bound (CETS 225 status).
The convention is not a global AGI-development ban, compute-control treaty, or worldwide regulator. National-security scope and implementation flexibility limit what can be inferred from participation.
Voluntary commitments and corporate frameworks
Frontier developers publish responsible-scaling policies, preparedness frameworks, model cards, and summit commitments. These can guide internal decisions and provide evidence against which conduct is judged. They are not equivalent to legislation unless a contract, regulator, or law makes a specific commitment enforceable.
Voluntary frameworks can change when a company changes leadership or risk tolerance. Readers should track versions, thresholds, exceptions, who approves overrides, actual evaluation results, and whether violations have consequences. A promise to evaluate is not an evaluation; publication is not independent verification.
How to read any AI-law claim
Ask six questions:
- What jurisdiction and legal instrument?
- Is it enacted, applicable, and in force on the relevant date?
- Who and what are covered?
- Is the cited document law, regulation, guidance, code, contract, or pledge?
- Which authority investigates and what remedies exist?
- Has enforcement occurred, or is the claim only about formal rules?
The honest September 2026 picture is mixed. Europe has an active binding AI framework with staged and recently amended timelines. The United States relies on existing federal law, targeted statutes, executive policy, export controls, and leading state frontier laws. The Council of Europe has created a treaty framework, while global frontier-capability restraint remains absent. Governance is no longer merely aspirational, but passing a rule is only the beginning; budgets, expertise, audits, litigation, incident reports, and remedies determine whether it protects anyone.