Six major jurisdictions now regulate AI in six different ways. The EU writes risk tiers into law, US states pass narrow statutes while Washington argues about preemption, the UK relies on existing regulators, and China issues rule-by-rule mandates. South Korea has a framework act with light penalties. If you ship a model or an AI product across borders, you need a map. This guide gives you one, current as of October 2026.
Quick Takeaways
- EU: The AI Act is law, but the Digital Omnibus pushed Annex III high-risk obligations from August 2, 2026 to December 2, 2027. Transparency duties were not delayed.
- US: There is still no comprehensive federal AI Act. State laws in California, Texas, Illinois, and New York carry the binding obligations.
- UK: There is no AI statute and no AI bill before Parliament. Existing regulators (ICO, FCA, Ofcom, MHRA) apply their own rules to AI.
- China and South Korea: China layers binding CAC rules (labeling, companion AI). South Korea’s AI Basic Act has applied since January 22, 2026, with a maximum administrative fine of KRW 30 million.
Global Snapshot
| Jurisdiction | Model | Core instrument | Binding? | Max penalty (headline) |
|---|---|---|---|---|
| EU | Horizontal, risk-tiered | EU AI Act + Digital Omnibus | Yes | Up to €35M or 7% of global turnover (prohibited practices) |
| US (federal) | Executive orders, agency enforcement | EO 14365 | Mostly no | Via FTC Section 5 and sector laws |
| US (states) | Patchwork statutes | CA SB 53, TX TRAIGA, NY RAISE | Yes | $1M per violation (CA SB 53) |
| UK | Sectoral, principles-based | Existing regulators + DUAA | Indirectly | Depends on regulator |
| China | Vertical, rule-by-rule | CAC measures, GB 45438-2025 | Yes | Warnings, rectification, suspension |
| South Korea | Framework act | AI Basic Act | Yes | KRW 30M (about $20K) |
The European Union: The Risk-Tier Benchmark
The EU AI Act (Regulation (EU) 2024/1689) sorts AI systems into four tiers: unacceptable risk (banned), high risk, limited risk (transparency duties), and minimal risk. It is the closest thing the world has to a global reference design.
What Changed in 2026
The Commission proposed the Digital Omnibus on AI in November 2025 because harmonized standards were not ready. The Parliament approved it on 16 June 2026, the Council adopted it on 29 June, and it entered into force on 27 July 2026 as Regulation (EU) 2026/1744. The resulting calendar:
| Date | Obligation | Status |
|---|---|---|
| Feb 2, 2025 | Prohibited practices | In force |
| Aug 2, 2025 | General-purpose AI (GPAI) model obligations | In force |
| Aug 2, 2026 | Article 50 transparency duties | In force |
| Dec 2, 2026 | Watermarking for systems already on the market; new ban on nudifier apps | Upcoming |
| Dec 2, 2027 | Annex III stand-alone high-risk systems | Deferred |
| Aug 2, 2028 | Annex I product-embedded high-risk systems | Deferred |
Two details trip people up. First, most Article 50 transparency obligations still applied on August 2, 2026, so chatbots must disclose that they are AI. Second, systems placed on the market before that date get a grace period for marking and detection duties until 2 December 2026.
Who Is Covered
- Providers that place AI on the EU market, wherever they are based.
- Deployers that use AI systems inside the EU.
- Non-EU companies whose AI output is used in the EU.
Annex III high-risk categories include biometrics, employment, credit scoring, education, and critical infrastructure. Expect conformity assessments, risk management systems, technical documentation, human oversight, and post-market monitoring.
United States: A Federal Vacuum and a State Patchwork
The US has no single AI statute. Binding rules come from states, plus existing federal law (Title VII, ADA, FCRA, FTC Section 5).
The Federal Layer
On December 11, 2025, President Trump signed an executive order proposing to preempt inconsistent state AI laws and naming the Colorado AI Act. It created a DOJ AI Litigation Task Force, but the order is nonbinding on preemption. A bipartisan preemption bill has been stalled since June. Until Congress acts, state laws apply.
The State Layer
| Law | Targets | Key specs | Status |
|---|---|---|---|
| California SB 53 | Frontier developers | Models trained above 10²⁶ FLOPs; publish risk frameworks; report critical incidents within 15 days; whistleblower protections; up to $1M per violation | In force Jan 1, 2026 |
| California SB 942 / AB 853 | GenAI providers | AI content disclosure and provenance; covered-provider duties operative August 2, 2026 | In force |
| Texas TRAIGA | Developers and deployers | $10,000–$200,000 per violation | In force Jan 2026 |
| Illinois HB 3773 | AI in employment | Anti-discrimination in hiring decisions | In force Jan 2026 |
| Colorado SB 26-189 | Automated decision-making tech | Repealed and replaced the 2024 AI Act; compliance from January 1, 2027 | Scheduled |
| New York RAISE Act | Frontier developers | Signed 27 March 2026; effective 1 January 2027 | Scheduled |
Colorado is the cautionary tale. The first comprehensive US “high-risk AI” statute was delayed twice and then rewritten. SB 189 removed the deployer risk-management and impact-assessment duties. Treat any US compliance plan as provisional.
United Kingdom: Regulators, Not a Statute
The UK deliberately skipped an EU-style act. Five non-statutory principles are applied by existing regulators: the ICO for data protection, the FCA for financial services, and Ofcom for online safety. The principles are safety, transparency, fairness, accountability, and contestability.
- No bill is coming soon. There was no AI bill in the May 2026 King’s Speech.
- The AI Security Institute (renamed from the AI Safety Institute in February 2025) says it is not a regulator and will not determine government regulation. It tests frontier models for national-security risks.
- The Data (Use and Access) Act 2025 reformed automated decision-making rules.
- Growth tools: the AI Growth Lab, a regulatory sandbox, was introduced in DSIT’s October 2025 blueprint.
For a UK-only product, your compliance surface is UK GDPR, sector rules, and consumer law, not an AI act.
China: Vertical, Fast, Enforced Through Filings
China regulates by use case. The Cyberspace Administration of China (CAC) issues a rule, a standard follows, and providers file with the regulator.
| Instrument | Scope | Effective |
|---|---|---|
| Algorithmic Recommendation Provisions | Recommender systems | 2022 |
| Deep Synthesis Provisions | Synthetic media | Jan 2023 |
| Generative AI Measures | Public-facing GenAI | Aug 15, 2023 |
| AI Content Labeling Measures + GB 45438-2025 | Visible and invisible labels on AI-generated content | Sept 1, 2025 |
| Cybersecurity Law amendments | Core security layer for AI services | Jan 1, 2026 |
| Anthropomorphic AI Interaction Measures | Continuous emotional interaction simulating human personality traits | Jul 15, 2026 |
The anthropomorphic AI rules matter for companion apps. Users must be told they are talking to an AI, and minors and the elderly receive extra protections. Intelligent customer service, knowledge Q&A, and work assistants are explicitly excluded. Companion AI providers must comply cumulatively with the algorithmic recommendation, deep synthesis, and generative AI rules.
South Korea, Japan, India, and Brazil
| Country | Approach | Status | Notable detail |
|---|---|---|---|
| South Korea | Comprehensive framework act | In force Jan 22, 2026 | Providers of high-impact or generative AI must notify users in advance; foreign operators may need a domestic representative |
| Japan | Innovation-first promotion law | Non-binding, no penalty framework | Business guidelines instead of fines |
| India | Guidelines plus IT Rules | Guidelines in late 2025; synthetic content rules amended February 2026; no comprehensive AI law | Sectoral, “techno-legal” |
| Brazil | EU-inspired risk bill | Bill 2338/2023 pending in the lower house | Not yet law |
South Korea is the one to watch. Its penalties are mild, but it is the only major Asian jurisdiction with a horizontal statute. A one-year grace period on fines is running.
How the Models Compare
| Dimension | EU | US States | UK | China | South Korea |
|---|---|---|---|---|---|
| Philosophy | Precaution | Targeted harm | Pro-innovation | State control + safety | Minimum regulation |
| Trigger | Risk tier | Compute or use case | Sector | Service type | Impact tier |
| GPAI/frontier rules | Yes (since Aug 2025) | CA, NY | Voluntary | Via GenAI Measures | Limited |
| Content labeling | Art. 50 | CA SB 942 | No mandate | Mandatory, dual-layer | GenAI notices |
| Extraterritorial | Yes | Yes (state nexus) | Limited | Yes (domestic public) | Yes (representative) |
Practical Workflow: Mapping One Product Across Jurisdictions
Say you run a customer-support chatbot built on a hosted LLM, sold in the EU, California, and South Korea. Here is the sequence.
- Inventory every AI system. Record model, vendor, use case, user groups, and markets.
- Classify by jurisdiction. Use the snippet below as a starting scaffold.
- Apply the strictest common control. AI disclosure and content labeling appear in the EU, California, China, and South Korea. Build them once.
- Assign owners and dates. Track December 2, 2026 (EU watermarking) and January 1, 2027 (Colorado, New York).
# Minimal AI-system inventory with jurisdiction flags
from dataclasses import dataclass, field
@dataclass
class AISystem:
name: str
use_case: str
markets: list[str]
interacts_with_humans: bool
generates_content: bool
flags: list[str] = field(default_factory=list)
def classify(s: AISystem) -> AISystem:
if "EU" in s.markets and s.interacts_with_humans:
s.flags.append("EU AI Act Art. 50: disclose AI interaction")
if "EU" in s.markets and s.generates_content:
s.flags.append("EU Art. 50: machine-readable marking (Dec 2, 2026 for legacy)")
if "CA" in s.markets and s.generates_content:
s.flags.append("CA SB 942: AI content disclosure")
if "KR" in s.markets:
s.flags.append("KR AI Basic Act: advance AI notice; check domestic rep threshold")
return s
bot = AISystem("support-bot", "customer service", ["EU", "CA", "KR"], True, True)
print(classify(bot).flags)
For hiring tools, add Annex III review for the EU and Illinois HB 3773. For companion apps in China, add a CAC filing and minor-protection controls.
FAQ
Is there a federal AI law in the United States?
No. As of October 2026, the US has no comprehensive federal AI Act. Executive Order 14365 pushes preemption of state laws but is nonbinding on that point. State statutes and existing federal laws govern.
When does the EU AI Act apply to high-risk systems?
Annex III high-risk obligations apply from December 2, 2027. Product-embedded systems under Annex I apply from August 2, 2028. Prohibited practices and GPAI duties already apply, and Article 50 transparency duties took effect August 2, 2026.
Does the UK have an AI Act?
No. The UK regulates AI through existing laws and regulators such as the ICO, FCA, and Ofcom. No AI bill is currently before Parliament.
Does China require labels on AI-generated content?
Yes. Since September 1, 2025, providers must apply both explicit (visible) and implicit (metadata) labels to AI-generated content. The mandatory standard is GB 45438-2025.




