Situation report active Rev. 2026.4 119 reports 237 source records updated
Real Life After AGI The human survival briefing

AI regulation, country by country: where the rules actually stand

A September 2026 country-by-country snapshot: the EU's delayed AI Act, the US state patchwork, the UK's no-statute stance, China's labeling rules, and more.

Written by
Dwight Ringdahl
Status
Reviewed
Revised
Sources
13 cited
Reading
7 min

No single answer, because there is no single regime

Ask “is AI regulated?” and the answer depends on which country, and which layer of its government. As of September 2026, one binding, cross-sectoral AI law covers a major market — the EU’s — and it just had a chunk of its own timeline pushed back over a year. Elsewhere the picture mixes binding sectoral law, narrow statutes, non-binding guidance, and pending bills. This page lines up ten jurisdictions, as a companion to AI law and enforcement in 2026 and international treaties and summits.

The European Union: binding, staged, and now genuinely delayed

The EU AI Act is still the only comprehensive, binding AI statute covering a major economic bloc. Prohibited-practices and AI-literacy rules have applied since February 2, 2025; general-purpose-model duties since August 2, 2025; and Article 50 transparency rules plus AI Office enforcement powers since August 2, 2026, exactly as scheduled.

What didn’t hold is the high-risk timeline — the most surprising AI-law development anywhere this year. The “Digital Omnibus” amendment entered into force July 27, 2026, after Parliament and Council approval in June, and pushed the Annex III high-risk rules (hiring, credit scoring, education, law enforcement) from August 2, 2026 to December 2, 2027 — over a year’s delay on the Act’s centerpiece obligation. High-risk AI embedded in already-regulated products (medical devices, machinery, toys) moved further out, to August 2, 2028 (European Commission, July 27, 2026). The Omnibus also delayed synthetic-content marking and national sandboxes while adding a new ban on AI-generated non-consensual sexual content. Penalties on schedule are unchanged: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for most other violations (EU AI Act tracker, Article 99). “In force” for the Act and “in force” for any one obligation are different facts, and that gap just widened.

The United States: no federal statute, a hardening state patchwork

Congress still hasn’t passed a federal AI statute. Two attempts to impose a ten-year moratorium on state AI laws failed in 2025 — stripped from the “One Big Beautiful Bill Act” by a 99–1 Senate vote, and left out of the FY2026 NDAA. The White House tried an executive route instead: EO 14365, signed December 11, 2025, directs a DOJ “AI Litigation Task Force” to challenge state AI laws and has Commerce weighing whether broadband funding can be conditioned on states not enacting “onerous” AI rules. Because Congress hasn’t legislated preemption, the order’s force against state law is contested, not settled.

Into that vacuum, roughly 29 states had enacted some AI legislation by mid-2026. Four stand out:

  • Colorado scrapped its 2024 risk-based AI Act before it took effect. After a constitutional challenge from xAI and a DOJ intervention motion, Colorado replaced it: SB 26-189, signed May 14, 2026, substitutes a narrower, notice-based Automated Decision-Making Technology regime — developer documentation, consumer notice of adverse decisions, a right to human review — enforced only by the state AG, effective January 1, 2027 (Colorado General Assembly).
  • California’s SB 53, signed September 29, 2025, effective January 1, 2026, is the closest US analogue to a frontier-safety law: developers above roughly 10²⁶ FLOPs and $500 million in revenue must publish safety frameworks, report catastrophic incidents within 15 days, and protect whistleblowers, with penalties up to $1 million per violation (Governor’s Office). (On compute as a regulatory proxy, see compute governance.)
  • Texas’s TRAIGA, effective January 1, 2026, went narrower still: an intent-based law targeting specific harms (social scoring, manipulation toward self-harm, CSAM), enforced solely by the AG with a 60-day cure period and penalties from $10,000 to $200,000 per violation (Baker Botts LLP).
  • Illinois’s HB 3773, effective January 1, 2026, amends the state Human Rights Act to bar AI-driven employment discrimination and zip-code proxies for protected classes (Illinois Public Act 103-0804).

New York’s RAISE Act (effective January 2027) extends California’s model — see AI law and enforcement in 2026. The US isn’t “unregulated”; it’s regulated unevenly, state by state.

The United Kingdom: still no AI statute

The UK hasn’t shifted from its March 2023 position. The “Pro-Innovation Approach to AI Regulation” White Paper declined to legislate a cross-sector AI law, issuing five non-statutory principles — safety, transparency, fairness, accountability, contestability — for existing regulators (the ICO, FCA, MHRA, CMA) to apply within their own remits, reasoning that a new cross-sector regulator “would introduce complexity and confusion” (UK Government White Paper, March 29, 2023). The former AI Safety Institute was renamed the AI Security Institute in February 2025 and remains an evaluation body, not a regulator with binding powers. Trackers have called a statutory AI bill “expected in 2026” for over a year; none has been introduced as of this writing. Treat “the UK is about to legislate” as a prediction, not a fact in evidence.

China: binding, and enforced through labeling

China’s Generative AI Interim Measures (effective August 2023) already require security assessment, algorithm registration, and content moderation before public launch. The newer piece is labeling: the Measures for Labeling AI-Generated Content, finalized March 14, 2025, plus mandatory national standard GB 45438-2025, took effect September 1, 2025, requiring both visible labels and embedded machine-readable metadata on AI text, image, audio, and video, extending to distribution platforms (Covington & Burling, March 18, 2025). China’s Cyberspace Administration reported 796 generative AI services and 481 applications formally filed as of February 2026 — a functioning registration regime, whatever one thinks of its substance.

South Korea and Japan: two different bets

South Korea’s AI Basic Act took effect January 22, 2026, joining the EU among the few comprehensive statutory AI regimes anywhere, with extraterritorial reach for large foreign firms and a “high-performance AI” designation triggered around 10²⁶ cumulative training FLOPs — aimed at frontier developers like OpenAI, Google, and Anthropic. Its regulator is deferring most fines for at least a year while enforcement machinery stands up (Cooley LLP). Japan bet the opposite way: its AI Promotion Act, effective June 4, 2025, sets national R&D goals through a Prime-Minister-chaired strategy headquarters but imposes no prohibitions, no pre-deployment registration, and — deliberately — no monetary penalties (White & Case LLP). Both are “AI laws.” One has teeth; the other, by design, does not.

Everyone else: pending, disputed, or non-binding

Brazil’s PL 2338/2023 cleared the Senate in December 2024 and has sat in a Chamber of Deputies committee since, unresolved as of September 2026, with mandatory AI-training-data licensing the main sticking point (Library of Congress). India has declined a binding AI statute, instead releasing non-binding “AI Governance Guidelines” at its February 2026 AI Impact Summit (Press Information Bureau of India).

The Council of Europe’s Framework Convention on Artificial Intelligence deserves a flag, not a claim. Sources genuinely conflict on whether it has entered into force: some summaries assert a November 2025 date, while the treaty office’s own ratification table and independent trackers were, as of early September 2026, still describing entry into force in future tense with no confirmed date. Don’t treat either claim as settled — check the CETS 225 ratification table directly, and see international treaties and summits for fuller context.

The summary table

Jurisdiction Instrument Status Key date
EU AI Act, Annex III high-risk rules Delayed (Omnibus) Dec 2, 2027 (was Aug 2, 2026)
US federal EO 14365 preemption push Contested Dec 11, 2025
Colorado SB 26-189 (ADMT) Enacted Jan 1, 2027
California SB 53 In force Jan 1, 2026
Texas TRAIGA In force Jan 1, 2026
Illinois HB 3773 In force Jan 1, 2026
UK No AI statute Unchanged White Paper, Mar 2023
China AI labeling (GB 45438-2025) In force Sept 1, 2025
South Korea AI Basic Act In force Jan 22, 2026
Japan AI Promotion Act In force, no penalties Jun 4, 2025
Council of Europe Framework Convention on AI Disputed See CETS 225
Brazil PL 2338/2023 Pending Not enacted
India AI Governance Guidelines Non-binding Feb 2026

How to use this page

Every row is a snapshot, and several dates are recent enough that a tracker may not yet reflect them. Before relying on any line, ask: is the instrument actually in force, who enforces it, and what happens after a violation? A signed bill, an executive order, and a non-binding guideline are different levels of commitment, often flattened by casual reporting. The pattern is regional, not global: Europe and a handful of US states have built binding, if staggered, obligations; the UK, Japan, and the federal US government have each chosen, for different reasons, to hold off on binding cross-sector law; China and South Korea have built binding regimes narrower than the EU’s but backed by real registration and labeling infrastructure. No jurisdiction yet regulates frontier compute or model capability directly at the point of training — see compute governance for how governments have tried to reach that layer instead.

References

Summarized position

European Commission the EU's Digital Omnibus amendment entered into force July 27, 2026 and pushed the AI Act's Annex III high-risk rules from August 2, 2026 to December 2, 2027, with embedded-product (Annex I) high-risk rules pushed to August 2, 2028.

European Commission, EU executive body
European Commission, Digital Strategy, Primary
Summarized position

Colorado General Assembly Colorado's SB 26-189, signed May 14, 2026, repeals the 2024 Colorado AI Act and replaces it with a narrower, notice-based Automated Decision-Making Technology regime, effective January 1, 2027 and enforced only by the state attorney general.

Colorado General Assembly, State legislature
Colorado General Assembly, SB26-189 bill page, Primary
Summarized position

Office of Governor Gavin Newsom California's SB 53, signed September 29, 2025 and effective January 1, 2026, requires large frontier AI developers to publish safety frameworks, report catastrophic incidents within 15 days, and protect whistleblowers, with penalties up to $1 million per violation.

Office of Governor Gavin Newsom, Governor of California
Office of the Governor of California, Primary
Summarized position

Baker Botts LLP Texas's TRAIGA, effective January 1, 2026, is an intent-based law enforced solely by the state attorney general, with a 60-day cure period and penalties ranging from $10,000 to $200,000 per violation.

Baker Botts LLP, Law firm client alert
Baker Botts, Thought Leadership, Report
Summarized position

Illinois General Assembly Illinois's HB 3773 (Public Act 103-0804), effective January 1, 2026, amends the state Human Rights Act to bar AI-driven employment discrimination and the use of zip codes as a proxy for protected classes.

Illinois General Assembly, State legislature
Illinois General Assembly, Public Act 103-0804, Primary
Summarized position

UK Department for Science, Innovation and Technology the UK's March 2023 white paper declined to create a cross-sector AI statute, instead issuing five non-statutory principles for existing sectoral regulators to apply, reasoning that a new AI-specific regulator would introduce complexity and confusion.

UK Department for Science, Innovation and Technology, UK Government
GOV.UK, "A pro-innovation approach to AI regulation" white paper, Primary
Summarized position

Covington & Burling LLP China's Measures for Labeling AI-Generated Content, plus mandatory national standard GB 45438-2025, took effect September 1, 2025, requiring both visible labels and embedded machine-readable metadata on AI-generated content.

Covington & Burling LLP, Law firm client alert ("Inside Privacy")
Inside Privacy, Report
Summarized position

Cooley LLP South Korea's AI Basic Act took effect January 22, 2026, with extraterritorial reach for large foreign firms and a "high-performance AI" designation triggered around 10^26 cumulative training FLOPs, though the regulator is deferring most fines for at least a year.

Cooley LLP, Law firm client alert
Cooley, Insights, Report
Summarized position

White & Case LLP Japan's AI Promotion Act, effective June 4, 2025, sets national R&D goals through a Prime-Minister-chaired strategy headquarters but imposes no prohibitions, no pre-deployment registration, and deliberately no monetary penalties for noncompliance.

White & Case LLP, Law firm client alert
White & Case, Insight, Report
Summarized position

Council of Europe Treaty Office sources conflict on whether the Council of Europe's Framework Convention on Artificial Intelligence has entered into force; the treaty office's own ratification table and independent trackers, as of early September 2026, still describe entry into force in future tense with no confirmed date listed.

Council of Europe Treaty Office, Treaty depositary
Council of Europe, CETS 225 ratification table, Primary
  1. EU AI Act tracker, Article 99 artificialintelligenceact.eu
  2. Library of Congress loc.gov
  3. Press Information Bureau of India static.pib.gov.in

The source index also tracks the manual's recurring core sources and expert positions.

Type to search the manual.

navigate open esc close