Comparative Matrix: AI Regulation Across Jurisdictions
A side-by-side view of how sixteen jurisdictions regulate AI, with an executive summary of the cross-jurisdiction picture. Snapshot as of 2026-10-10.
Executive summary
Two models, one direction of travel
Of the sixteen jurisdictions profiled here, only a minority have a binding AI-specific regime in force: the European Union (the AI Act as amended by the Digital Omnibus, Regulation (EU) 2026/1744, in force since 2026-07-27), South Korea (the AI Basic Act, in force since 2026-01-22, with a fines grace period reported to run to at least 2027-01-22) and, through departmental measures rather than a single statute, China. Germany has completed national implementation of the AI Act (KI-MIG, in force 2026-07-29). Most others are policy-led: Canada, Australia, Singapore and Japan rely on strategies, guidelines, sectoral rules and promotion-style statutes, while France, the Netherlands and Spain still have national implementing bills pending. A recurring lesson is that “issued” is not “effective”: the MAS guidelines and China’s “AI+” Opinion, for example, are in different stages of phase-in or are policy rather than rules.
Privacy and data-protection law is today’s enforcement lever
Where dedicated AI statutes are absent or not yet applicable, regulators are applying existing law. The Office of the Privacy Commissioner of Canada found complaints against OpenAI (#2026-002, 2026-05-06) and X Corp./xAI’s Grok (#2026-004, 2026-06-11) well-founded; the CNIL’s GDPR sanction of Uber (EUR 824,990,000, 2026-08-24; Dutch authority leading) targeted automated decision-making; Spain’s AEPD has issued AI guidance and surveillance warnings; Australia’s eSafety codes reach generative AI through online-safety law. Japan’s amended APPI and Korea’s PIPA reforms (effective 2027-03-09) are moving data law further toward AI use.
EU timeline
The Omnibus entered into force on 2026-07-27. Enforcement powers and Article 50 transparency duties apply from 2026-08-02; a new prohibition on non-consensual sexually explicit and child-abuse content (“nudification”) applies from 2026-12-02; high-risk obligations are deferred to 2027-12-02 (Annex III) and 2028-08-02 (Annex I). Penalty tiers remain EUR 35M/7%, EUR 15M/3% and EUR 7.5M/1%. Caveats: article-level text of Regulation 2026/1744 has not been checked against the Official Journal (EUR-Lex was unavailable during the research run); one genAI transparency sub-date is not reconciled across sources; and 2026-10-10 press reports of information requests to “30+” AI companies are reported but unconfirmed.
United States: federal posture, state substance
There is no comprehensive federal AI statute. Executive Order 14434 (signed 2026-09-29) is largely terminological, and EO 14365 (2025-12-11) sets a preemption posture backed by a DOJ AI Litigation Task Force, which intervened in xAI v. Weiser against Colorado. Binding duties sit in state law: Texas TRAIGA and California SB 53 have applied since 2026-01-01; Colorado repealed SB 24-205 and replaced it with SB 26-189 (effective 2027-01-01), with draft implementing rules open for comment to 2026-10-26. A reported FTC probe of leading AI developers (2026-09-30) is press-sourced and unverified.
Asia-Pacific and the Council of Europe
The region shows distinct models: China’s targeted, multi-regulator rules (including the Interim Measures for Anthropomorphic Interactive AI Services, in force 2026-07-15); Korea’s comprehensive Act with extraterritorial reach; Japan’s no-penalty promotion framework; Singapore’s voluntary frameworks plus MAS supervisory expectations for financial institutions (issued 2026-10-07, applying from 2027-10-07 and 2028-10-07); and Australia’s pivot from a proposed guardrails regime to mandatory “Australian Standards for AI” (frontier standards signalled for end-2026; legislation targeted for early 2027; the July 2026 Office of AI announcement lacks a primary source). The Council of Europe Framework Convention (CETS 225) is not in force: 21 signatories and one ratification (the EU, 2026-05-15) as of 2026-10-10; entry into force requires five ratifications including at least three Council of Europe member states, so it is not expected before 2027 at the current pace.
Snapshot as of 2026-10-10. Several statuses rely on secondary or press sources and are flagged unverified on the individual profiles. This is research assistance, not legal advice; verify against primary sources before reliance.
Comparative matrix
| Jurisdiction | Region | Regulator(s) | Key instrument(s) | Status | Approach / scope | Enforcement | Latest development |
|---|---|---|---|---|---|---|---|
| Canada | North America | OPC; Québec CAI; ISED; TBS | No federal AI statute (AIDA lapsed 2025-01-06); Bill C-34 (proposed); TBS ADM Directive; “AI for All” strategy | Policy-led; binding via privacy and public-sector rules | Distributed model: PIPEDA, Québec Law 25, public-sector ADM Directive | OPC findings: OpenAI #2026-002; xAI/Grok #2026-004 | National Council on AI launched 2026-10-02 (advisory); C-34 at second reading |
| United States | North America | FTC; DOJ; state AGs; NIST CAISSI (non-regulatory) | EO 14434; EO 14365; TX TRAIGA; CA SB 53; CO SB 26-189 | No federal statute; state laws in force or pending | Executive-led federally; binding duties in state law | State AGs (TX: up to $200k/violation); FTC Act s.5; DOJ challenges to state laws | CO draft ADMT rules, comments to 2026-10-26; reported FTC probe (unverified) |
| European Union | Europe | AI Office; national market-surveillance authorities; EDPS | AI Act, Reg. (EU) 2024/1689 as amended by Omnibus Reg. (EU) 2026/1744 | Binding; in force (Omnibus 2026-07-27); phased | Risk-based; GPAI models; extraterritorial | Fines up to EUR 35M / 7%; AI Office oversees GPAI | Annex III to 2027-12-02; Annex I to 2028-08-02; new prohibition 2026-12-02 (article text unverified) |
| United Kingdom | Europe | Not tracked in the 2026-10 research run | No UK-specific profile yet; UK is a CoE Convention signatory | Not assessed (placeholder) | Profile to be expanded | Not assessed | Placeholder; see non-official policy analysis |
| China | Asia-Pacific | CAC (lead); NDRC; MIIT; MPS; SAMR | Amended Cybersecurity Law (2026-01-01); Anthropomorphic AI Measures, Order No. 21 (2026-07-15); genAI filing and labelling rules | Binding; administrative-measures-led | Multi-regulator departmental rules; no comprehensive AI law (preparatory item) | CAC fines (RMB 10k–200k under Order 21); filings; Qinglang campaigns | Opinion on new quality productive forces (“AI+”) issued 2026-10-09 (policy) |
| South Korea | Asia-Pacific | MSIT; PIPC | AI Basic Act (in force 2026-01-22) and enforcement decree | Binding; fines grace period to at least 2027-01-22 | Comprehensive; high-impact and genAI notice, labelling, frontier safety (10^26 FLOP), domestic representative; extraterritorial | Direct fines limited (max KRW 30m, unverified); corrective orders | No new decree found 2026-10-07 to 10-10; PIPA Art. 28-12 effective 2027-03-09 |
| Japan | Asia-Pacific | PPC; METI / MIC; AI Strategy HQ | AI Promotion Act (Act 53/2025); AI Basic Plan II; amended APPI (Act 56/2026) | Promotion Act in force (no penalties); APPI transitional | Light-touch framework; non-binding guidelines | PPC under APPI (surcharges once in force) | Call for information on regulations obstructing AI, 2026-10-19 to 10-30 |
| Australia | Asia-Pacific | eSafety Commissioner; DISR / Office of AI (policy) | No AI Act; eSafety Phase 2 codes (2026-03-09); frontier-AI and AI-infrastructure standards (proposed) | Policy-led; standards proposed | Technology-neutral law; 2024 guardrails proposal superseded; legislation targeted early 2027 | eSafety penalties up to about A$49.5m | Frontier-AI standards due end-2026; infrastructure consultation closed 2026-10-09 |
| Africa | Africa | National legislatures (e.g. Kenya Senate); African Union | Kenya AI Bill 2026 (proposed); AU Continental AI Strategy (2024); Nigeria and South Africa efforts (unverified) | Proposed / policy | Strategies and bills rather than statutes | None identified | No confirmed October 2026 development; secondary sources only |
| South America | Latin America | Brazil Câmara / Senado; Chile Senado | Brazil PL 2338/2023; Chile Boletín 16.821-19 | Proposed | Risk-based framework bills | None yet | Brazil vote reported to slip past the October 2026 elections |
| Germany | Europe | Bundesnetzagentur; BaFin; Länder; BfDI | KI-MIG (AI Act implementation) | Binding; in force 2026-07-29 | Implements the AI Act: BNetzA as central authority; independent surveillance chamber; sandbox | AI Act fines apply | AISI Deutschland launched 2026-08-31; Länder media-treaty draft, comments to 2026-11-13 |
| France | Europe | CNIL; DGCCRF; sector authorities (planned) | DDADUE bill (AN n° 2518) (pending); PPL 3149 (proposed) | AI Act directly applicable; national architecture pending | Proposed: CNIL as central authority and notified body | CNIL under GDPR: Uber sanction (EUR 824.99M, 2026-08-24) | PPL 3149 deposited 2026-09-15 (ANIA authority; affective-AI ban) |
| Netherlands | Europe | Autoriteit Persoonsgegevens (AP); RDI; sector authorities | UAIV draft implementation act (proposed) | AI Act directly applicable; UAIV proposed | AP as residual supervisor; ten sectoral authorities | Via AI Act once designated | AP TCA directorate started 2026-10-08 |
| Spain | Europe | AESIA; AEPD | PLOIA bill 121/000096 (pending in Congress) | AI Act directly applicable; bill pending | Proposed: AESIA as central authority; sandboxes; public-sector AI inventory | AEPD under GDPR (guidance, surveillance warnings) | Manifiesto de Madrid 2026-10-08 (advisory); AEPD video-surveillance warnings 2026-10-06 |
| Singapore | Asia-Pacific | MAS; IMDA; PDPC | MAS Guidelines on AI Risk Management; MGF for Agentic AI v1.5 | Voluntary frameworks; MAS expectations transitional | Sector-led (finance) plus voluntary governance; no horizontal AI statute | MAS supervision; PDPA via PDPC (no new statutory fines) | MAS Guidelines issued 2026-10-07; apply 2027-10-07 / 2028-10-07 |
| Council of Europe | Europe (international) | None; Committee on AI (CAI) for the treaty | Framework Convention CETS 225 | Signed; not in force | Binds States (principles; legislate and supervise); no fines | None | 21 signatures, 1 ratification (EU, 2026-05-15); Microsoft MoU 2026-10-06 |
Not in the collection but tracked in the research run: Taiwan (AI Basic Act, in force 2026-01-14), India (non-binding AI Governance Guidelines, 2025-11-06), Mexico (sectoral amendments in force; general-law initiative unverified). Cells are deliberately brief; each jurisdiction profile carries the full detail and sources.
Jurisdiction profiles
Canada
No federal AI-specific statute. Governance is policy-led, with binding obligations coming from privacy law and from the federal public-sector Directive on Automated Decision-Making.
Profile →China
Regulates AI through layered administrative measures; no comprehensive AI statute exists, and a general AI Law is only a preparatory legislative item.
Profile →Council of Europe
The Framework Convention on AI (CETS 225) is not in force: 21 signatories and one ratification, by the European Union.
Profile →European Union
The AI Act is binding and in force, as amended by the Digital Omnibus on AI; the high-risk deadlines have been deferred.
Profile →France
France has not yet designated its AI Act authorities: the implementing bill (DDADUE) is still before Parliament, so the framework remains proposed.
Profile →Germany
Germany implemented the EU AI Act through the KI-MIG, in force since 2026-07-29, with the Bundesnetzagentur as lead supervisor.
Profile →Japan
A promotion-led, non-prohibitive model: a framework statute with no fines, supported by non-binding guidelines and a government AI Basic Plan.
Profile →Netherlands
Has proposed but not yet enacted its AI Act implementation act (UAIV), while the AP has already begun a dedicated AI supervision directorate.
Profile →South America
No comprehensive AI statute is in force in the countries covered. Brazil’s and Chile’s AI bills are proposed and have stalled or progressed slowly.
Profile →South Korea
A binding AI Basic Act, in force since 2026-01-22, with a policy-based enforcement grace period of at least one year.
Profile →Spain
Spain’s organic law on AI (PLOIA) is a bill pending before Congress as of the 2026-10-10 reports; an earlier note that it had lapsed is unreconciled.
Profile →United Kingdom
Not tracked in the October 2026 run; the entry is a placeholder and contains no verified statement of UK law or policy.
Profile →United States
No comprehensive federal AI statute: federal policy is set by executive order and agency enforcement, while binding AI obligations sit mainly in state law.
Profile →Singapore
Relies on voluntary frameworks plus a new sector-specific supervisory layer: the MAS AI risk guidelines were issued on 2026-10-07 but are not yet effective.
Profile →Africa
Continental policy and emerging national bills, with no in-force AI-specific statute identified; all items are proposed or policy-stage and unverified.
Profile →Australia
No AI Act. Relies on technology-neutral laws and planned mandatory AI standards, with legislation intended for early 2027 (proposed).
Profile →