The global AI regulation landscape in 2026

The defining feature of global AI regulation in 2026 is fragmentation. There is no international AI governance treaty. There is no single global standard with binding force. What exists is an increasingly complex patchwork of national laws, sector-specific regulations, voluntary frameworks, and enforcement actions that organisations operating across borders must navigate simultaneously. The EU AI Act was the first comprehensive mandatory AI law in force, and South Korea's AI Framework Act joined it on 22 January 2026, the first such law in the Asia-Pacific region. The EU AI Act remains the de facto global standard for multinational organisations, not because it applies everywhere, but because organisations with EU exposure must comply with it, and compliance with the EU AI Act substantially addresses the requirements of other jurisdictions.

Europe: the EU AI Act and its neighbours

The EU AI Act is in force and its major compliance deadlines are approaching. Prohibited AI practices (social scoring, certain biometric surveillance) were prohibited from 2 February 2025 (the Act itself entered into force 1 August 2024). GPAI model obligations for general purpose AI model providers apply from 2 August 2025. High-risk AI obligations under Annex III apply from 2 December 2027, and Annex I embedded products from 2 August 2028, delayed from the original 2 August 2027 deadline under the Digital Omnibus, now Regulation (EU) 2026/1744, adopted by Parliament and Council and in force since 27 July 2026 (not merely a May 2026 political agreement). As of mid-2026, most EU member states have missed the 2 August 2025 deadline to designate their national market surveillance and notifying authorities: only 9 of 27 have completed both designations, 12 have partial or pending designations, and 6 have designated neither, a gap the European Commission itself cites as one of the reasons for the Digital Omnibus's high-risk deadline extension. Country-specific detail is available for Germany, France, the Netherlands, and Spain, each with its own designated authority and enforcement posture.

Outside the EU, European AI regulation reflects the AI Act's influence. Switzerland is aligning its AI guidance with EU AI Act principles. Norway and Iceland, as EEA members, will adopt the AI Act through the EEA agreement. The UK has maintained its pro-innovation sector-led approach post-Brexit, but UK regulators are closely monitoring EU AI Act implementation and their approaches are converging in practice.

Asia-Pacific: a diverse regulatory landscape

Australia has the most developed regulatory framework outside Europe, not through AI-specific legislation, but through active sector regulator engagement. APRA (Australian Prudential Regulation Authority), ASIC (Australian Securities and Investments Commission), the OAIC (Office of the Australian Information Commissioner), the ACCC, and the Fair Work Commission all have established AI governance expectations. The Privacy Act reforms of 2024 created new obligations relevant to AI. And the Guidance for AI Adoption (October 2025, six essential practices, superseding the 2024 Voluntary AI Safety Standard) provides voluntary guidance that is becoming a de facto standard for enterprise AI deployment. Singapore's MAS (Monetary Authority of Singapore) FEAT Principles and the Veritas Assessment Methodology create a financial services AI governance standard that is among the most technically sophisticated in the world. Japan enacted the AI Promotion Act in May 2025 (full enforcement from September 2025), a deliberately non-binding framework that establishes principles without mandatory requirements, carrying no penalties and no statutory power to name non-compliant operators, so the pressure to comply is commercial and reputational rather than legal. South Korea's AI Framework Act, passed December 2024 and promulgated January 2025, took effect on 22 January 2026, making it the first comprehensive, mandatory AI law in the Asia-Pacific region, a risk-based framework with sector-specific requirements and real financial penalties for high-impact AI operators. China has multiple AI-specific regulations in force: the Generative AI Regulation (2023), the Deep Synthesis Regulation (2022), and the Recommendation Algorithm Regulation (2022), collectively creating one of the most prescriptive AI regulatory frameworks in the world for specific use cases. India has no dedicated AI law but governs AI through the DPDP Act and its 2025 Rules, SEBI Regulation 16C, IT deepfake rules, the RBI FREE-AI framework, and voluntary MeitY guidelines. Hong Kong relies on the binding Personal Data (Privacy) Ordinance plus non-statutory PCPD guidance and HKMA/SFC circulars for finance, with a government legislative review ongoing.

Americas: enforcement without comprehensive law

The United States has no comprehensive federal AI law, but AI governance obligations are real and enforced. The FTC has enforcement authority over unfair or deceptive AI practices. The CFPB was historically active on AI in financial services (adverse action notices, algorithmic credit decisions), though its enforcement capacity has been sharply curtailed since a February 2025 stop-work order, shifting the practical enforcement centre of gravity toward state regulators. The EEOC has issued guidance on AI in employment that signals enforcement intent. State legislation is creating a patchwork: Colorado's original AI Act (repealed and replaced by SB 26-189, disclosure-only, effective 1 January 2027), Illinois's Artificial Intelligence Video Interview Act (employment AI disclosure), Texas's Responsible AI Governance Act (TRAIGA, HB 149, in force since January 2026), and California's enacted AI laws and executive orders. Brazil's LGPD (Lei Geral de Proteção de Dados) creates data protection obligations relevant to AI. The Brazilian Senate passed a comprehensive AI Act in 2024, pending House approval. Canada's Bill C-27, which included the AI and Data Act (AIDA), died on the order paper in January 2025 when Parliament was prorogued. A privacy-focused successor, Bill C-36, was tabled in June 2026, but it does not revive AIDA, leaving Canada without comprehensive federal AI legislation. Mexico has no comprehensive federal AI law enacted either, though several bills are pending; its data-protection role moved from the dissolved INAI to the Secretaria Anticorrupcion y Buen Gobierno, alongside binding algorithmic-transparency rights for platform workers.

Country flagship pages

For a deeper, single-country view than this global map provides, dedicated flagship pages cover the UK, Germany, France, the Netherlands, Spain, Australia, Singapore, Japan, South Korea, India, Hong Kong, the United States, Canada, and Mexico.

Related reading

Further reading: OECD AI Principles