REGULATIONS ACROSS REGIONS / BEGINNER

AI Regulation At A Glance: Binding Laws Versus Voluntary Frameworks By Region

A one-page comparison of AI rules by region as of October 2026, separating binding laws from guidance, with the next dates to watch and links to deeper reading.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

AI rules are moving faster than cryptography rules, and they differ more between regions. Some jurisdictions have passed horizontal AI laws that apply across sectors. Others rely on voluntary frameworks, sector supervisors or targeted rules on issues such as labelling synthetic content.

This page is a short map, as of October 2026. It gives each region’s main instrument, its legal force and the next date to watch. For how the EU AI Act works, risk tiers, general-purpose AI models and frameworks such as the NIST AI RMF and ISO/IEC 42001, see AI Governance And Regulation. This is general information, not legal advice.

The Comparison Table

JurisdictionMain InstrumentStatusNext Date Or Note
European UnionAI Act, amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744)BindingAnnex III high-risk duties from 2 December 2027; Annex I product duties from 2 August 2028
United States (federal)Executive Order 14365 (December 2025)Directive to federal agenciesSets up a task force to challenge state AI laws; does not itself pre-empt them
United States (states)Texas HB 149; California SB 53; Colorado SB 26-189; New York RAISE ActBindingTexas in force 1 January 2026; Colorado and New York from 1 January 2027
United KingdomPrinciples-based approach; no government cross-sector AI billGuidanceA Lords debate in June 2026 considered the case for a cross-sector AI bill; no government bill
SwitzerlandSectoral approach and Council of Europe AI ConventionGuidance (strategy)Consultation draft expected by end 2026
CanadaNo federal AI statute; Ontario Bill 194 for its public sectorBinding (Ontario public sector only)Federal privacy Bill C-36 introduced June 2026 (Draft)
SingaporeMAS Guidelines on AI Risk Management; IMDA agentic AI frameworkSupervisory; GuidanceMAS guidelines effective 7 October 2027, phased to 7 October 2028
IndiaIT Intermediary Amendment Rules 2026; MeitY AI Governance GuidelinesBinding (labelling); GuidanceSynthetic content labelling in force since 20 February 2026
ChinaMeasures for Labelling AI-Generated Synthetic ContentBindingIn force since 1 September 2025
JapanAI Promotion ActBinding (promotion law)Fully in force since 1 September 2025
South KoreaAI Framework Act (Act No. 20676)BindingIn force since 22 January 2026
United Arab EmiratesUAE Charter for the Development and Use of AI (2024)GuidanceNo federal AI statute found as of October 2026
Saudi ArabiaSDAIA AI Ethics PrinciplesGuidanceSee the AI Governance group article on UAE and Saudi rules
QatarQatar Central Bank Artificial Intelligence Guideline (2024); National AI Strategy (2019)Supervisory (QCB-licensed firms); Guidance (strategy)Guideline in force since 4 September 2024; no binding AI law found as of October 2026
BahrainGeneral Policy for the Use of AI, version 1.0 (2025)Binding on government entities (policy, not law)Applies since 20 May 2025; a standalone AI law was under parliamentary review in November 2025, per UNESCO
OmanGeneral Policy for the Safe and Ethical Use of AI Systems (April 2025)Ministry policy requiring compliance (not a law)Covers government units and regulated private institutions
KuwaitNo government AI instrument retrievedNone foundNo binding AI law found as of October 2026
Main AI instruments by jurisdiction, as of October 2026. Status labels follow the overview article. A blank in a source search is noted as not verified, not as absence.

How To Read The Labels For AI

The word “law” covers very different things in AI. A horizontal law, such as the EU AI Act or South Korea’s AI Framework Act, applies across sectors and sets duties that regulators can enforce. A promotion law sets out national goals, plans and the role of government, and asks businesses to cooperate, but it may carry no penalties. Targeted rules deal with one issue, such as labelling content made by AI, and can be strictly binding within that narrow field.

Supervisory guidelines sit in between. A financial regulator’s AI guidelines do not create offences, but supervised firms are expected to follow them and to explain any gap. Voluntary frameworks and charters, such as a national AI governance framework or ethics principles, describe good practice and carry no direct sanction.

That is why the same kind of date means different things. A date under a horizontal law is when duties become enforceable. A date in a promotion law is when the state’s own plans start. A date in supervisory guidelines is when a regulator expects to see the practice in place, and a date in a voluntary framework is simply when it was published. The table labels each instrument so the dates can be read in that light.

What The Table Shows

Binding, cross-sector AI laws are in force in the EU and South Korea.12 Japan’s AI Act has applied in full since 1 September 2025, but it is a promotion law, and its text contains no penalty provisions.3 The EU’s high-risk duties moved later under the Digital Omnibus on AI, which was adopted on 8 July 2026. Annex III uses such as hiring and credit scoring now apply from 2 December 2027.1

The United States has no comprehensive federal AI statute. Executive Order 14365 tells the Justice Department to set up a task force to challenge state AI laws, but it does not override them.4 States have moved on their own: Texas’s AI governance act took effect on 1 January 2026,5 California’s frontier AI transparency law was signed in September 2025,6 Colorado replaced its 2024 AI law with SB 26-189, whose main duties start on 1 January 2027,7 and New York’s RAISE Act, rewritten by a chapter amendment, takes effect on the same day, with an oversight office inside the Department of Financial Services.8

Two other Asian jurisdictions regulate a narrow AI issue with binding rules. China’s labelling measures for AI-generated content have applied since 1 September 2025,9 and India’s amended intermediary rules have, since 20 February 2026, required intermediaries whose services create or share synthetically generated information to label it. The rules define that as realistic audio, visual or audiovisual content made or altered by computer, and they exclude routine editing and ordinary document preparation.10 India’s Ministry of Electronics and Information Technology also published AI governance guidelines in November 2025, which are guidance rather than law.11 Singapore relies on supervisors and frameworks: MAS issued its AI risk management guidelines for financial institutions on 7 October 2026,12 and the Infocomm Media Development Authority launched a model governance framework for agentic AI in January 2026.13

In the Gulf, the UAE has a non-binding AI Charter from 2024, and no federal AI statute was found as of October 2026.14 Saudi Arabia’s main instrument is the SDAIA AI Ethics Principles, which are guidance; AI rules in the UAE and Saudi Arabia explains both countries in detail. No binding AI law was found in Qatar, Bahrain, Oman or Kuwait as of October 2026. Qatar’s central bank has applied an AI guideline to its licensed firms since 4 September 2024,15 alongside a national AI strategy adopted in 2019.16 Bahrain’s government entities have had to follow a national AI policy since 20 May 2025,17 and Oman’s April 2025 AI policy requires compliance from government units and regulated private institutions.18 UNESCO’s November 2025 readiness assessment of Bahrain describes a standalone AI law still under parliamentary review, and no enacted AI law was found as of October 2026.19 Qatar, Bahrain, Oman And Kuwait gives the detail.

The UK, Switzerland And Canada

The UK still takes a principles-based approach, leaving AI to existing sector regulators, and the government has not introduced an AI bill. On 4 June 2026 a Lords Grand Committee debate, led by Lord Holmes of Richmond, considered the case for a cross-sector AI bill.20 A debate of this kind does not change the law.

Switzerland has chosen to work sector by sector and to ratify the Council of Europe AI Convention. The Federal Office of Justice is preparing a consultation draft due by the end of 2026, which had not been published as of October 2026.21

Canada has no federal AI statute. Bill C-36, a federal privacy bill introduced on 15 June 2026, is a Draft.22 Ontario’s Bill 194, which received Royal Assent on 25 November 2024, gives the province binding powers over cyber security and AI use in its own public sector, much of it exercised through regulations.23

Dates To Watch

  1. In effect

    Qatar · Qatar Central Bank Supervisory

    The guideline enters into force, including the AI register disclosed to QCB annually, QCB approval before launching a new AI system as provider or signing a high-risk AI purchase, licensing or outsourcing agreement, human oversight protocols and customer notification.

    Artificial Intelligence Guideline (Regulating the Use of Artificial Intelligence by QCB Licensed Entities). Applies to entities regulated by the Qatar Central Bank that develop, buy or outsource AI. Source · Explainer · Verified 7 Oct 2026

  2. In effect

    Bahrain · Information and eGovernment Authority (approved by the Ministerial Committee for Information and Communication Technology) Binding

    Government entities must comply with the rules, requirements and guiding principles of the policy from the date of its approval.

    General Policy for the Use of Artificial Intelligence, version 1.0. Applies to government entities in Bahrain only (a government policy, not a law). Source · Explainer · Verified 7 Oct 2026

  3. In effect

    China · Cyberspace Administration of China with MIIT, MPS and NRTA Binding

    Labelling duties for AI-generated synthetic content take effect.

    Measures for Labelling AI-Generated Synthetic Content. Applies to internet information service providers that generate or distribute synthetic content in China. Source · Explainer · Verified 7 Oct 2026

  4. In effect

    South Korea · National Assembly of Korea Binding

    The AI Framework Act takes effect.

    Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust (Act No. 20676). Applies to AI businesses covered by the Act. Source · Explainer · Verified 7 Oct 2026

  5. In effect

    India · Ministry of Electronics and Information Technology Binding

    Due diligence and labelling duties for synthetically generated information, meaning realistic AI-made or altered audio, visual or audiovisual content, take effect.

    IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E)). Applies to intermediaries whose services enable the creation or sharing of such content, with extra duties for significant social media intermediaries. Source · Explainer · Verified 7 Oct 2026

  6. Upcoming

    European Union · European Parliament and Council Binding

    New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material apply.

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 113(a). Applies to providers and deployers of AI systems in or affecting the EU. Source · Explainer · Verified 7 Oct 2026

  7. Upcoming

    United States (Colorado) · Colorado General Assembly Binding

    Main developer and deployer duties for automated decision-making technology in consequential decisions apply.

    SB 26-189, Automated Decision-Making Technology (replacing the provisions of SB 24-205). Applies to developers and deployers of automated decision-making technology used in consequential decisions in Colorado. Source · Explainer · Verified 7 Oct 2026

  8. Upcoming

    United States (New York) · New York State Legislature Binding

    Transparency and safety incident reporting duties for large frontier AI developers apply, overseen by an office within the Department of Financial Services.

    RAISE Act as amended by S8828 (Chapter 96 of 2026). Applies to large frontier AI model developers, as defined in the Act. Source · Explainer · Verified 7 Oct 2026

  9. Upcoming

    Singapore · Monetary Authority of Singapore Supervisory

    Sections 3 and 4 of the AI risk management guidelines take effect.

    Guidelines on Artificial Intelligence Risk Management (7 October 2026). Applies to financial institutions regulated by MAS. Source · Explainer · Verified 7 Oct 2026

  10. Upcoming

    European Union · European Parliament and Council Binding

    High-risk requirements apply to the Annex III use cases, such as hiring, credit scoring, education and biometrics. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities, which must comply by 2 August 2030 (Article 111(2)).

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 113(c)(i). Applies to providers and deployers of high-risk AI systems listed in Annex III. Source · Explainer · Verified 7 Oct 2026

  11. Upcoming

    European Union · European Parliament and Council Binding

    High-risk requirements apply to AI in products covered by the EU product laws in Section A of Annex I. For Section B laws, such as machinery, vehicles and aviation, the requirements come mainly through those sector rules. Where the type and model was already placed on the market or put into service before this date, units are covered only after a significant design change, except systems intended for public authorities (2 August 2030).

    Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 113(c)(ii). Applies to providers of AI that is, or is a safety component of, an Annex I product that must undergo third-party conformity assessment. Source · Explainer · Verified 7 Oct 2026

Selected AI dates by region. The full list, including all EU AI Act milestones, is in the deadline tracker.

For the security side of AI, including prompt injection and the OWASP lists, see AI Security. For cryptography rules in each region, start from the overview.

Footnotes

  1. European Parliament and Council, Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026. eur-lex.europa.eu ↩ ↩2

  2. Republic of Korea, Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation of Trust, Act No. 20676, promulgated 21 January 2025, in force 22 January 2026. law.go.kr ↩

  3. Cabinet Office of Japan, “AI Act” (Act on the Promotion of Research, Development and Utilisation of AI-Related Technologies), full application from 1 September 2025. cao.go.jp ↩

  4. The White House, Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence”, 11 December 2025, 90 FR 58499. govinfo.gov ↩

  5. Texas Legislature, HB 149 (89th Legislature), bill history, signed 22 June 2025, effective 1 January 2026. capitol.texas.gov ↩

  6. Office of the Governor of California, “Governor Newsom signs SB 53, advancing California’s world-leading artificial intelligence industry”, 29 September 2025. gov.ca.gov ↩

  7. Colorado General Assembly, SB 26-189, “Automated Decision-Making Technology”, signed 14 May 2026. leg.colorado.gov ↩

  8. New York State Senate, S8828 (chapter amendment to the RAISE Act), signed 27 March 2026. nysenate.gov ↩

  9. Cyberspace Administration of China and others, “Measures for Labelling AI-Generated Synthetic Content”, published 14 March 2025, in force 1 September 2025. cac.gov.cn ↩

  10. Ministry of Electronics and Information Technology, G.S.R. 120(E), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, 10 February 2026. meity.gov.in ↩

  11. Press Information Bureau, release on MeitY’s India AI Governance Guidelines, 5 November 2025. pib.gov.in ↩

  12. Monetary Authority of Singapore, “MAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions”, 7 October 2026. mas.gov.sg ↩

  13. Infocomm Media Development Authority, “Singapore Launches New Model AI Governance Framework for Agentic AI”, 22 January 2026. imda.gov.sg ↩

  14. UAE Government, “The UAE Charter for the Development and Use of Artificial Intelligence”, 2024. uaelegislation.gov.ae ↩

  15. Qatar Central Bank, “Artificial Intelligence Guideline (Regulating the Use of Artificial Intelligence by QCB Licensed Entities)”, in force 4 September 2024, section 1. qcb.gov.qa ↩

  16. Hamad Bin Khalifa University, “Minister of Transport and Communications Announces Qatar’s National Artificial Intelligence Strategy Developed by HBKU’s Qatar Computing Research Institute”, 29 October 2019. hbku.edu.qa ↩

  17. Information and eGovernment Authority, Kingdom of Bahrain, “General Policy for the Use of Artificial Intelligence”, version 1.0, 20 May 2025, sections 3 and 8. iga.gov.bh ↩

  18. Ministry of Transport, Communications and Information Technology, Oman, “General Policy for the Safe and Ethical Use of Artificial Intelligence Systems” (Arabic), first version, April 2025, printed pp. 11, 14 and 26. mtcit.gov.om ↩

  19. UNESCO, “Kingdom of Bahrain: UNESCO’s Artificial Intelligence Readiness Assessment Methodology Report (RAM)”, 12 November 2025, Part III, p. 21. iga.gov.bh ↩

  20. UK Parliament, Hansard, House of Lords Grand Committee, “AI Regulation Bill” (question for short debate), 4 June 2026. hansard.parliament.uk ↩

  21. Federal Office of Justice, “Künstliche Intelligenz”, accessed October 2026. bj.admin.ch ↩

  22. Parliament of Canada, LEGISinfo, “Bill C-36 (45th Parliament, 1st Session)”, introduced 15 June 2026. parl.ca ↩

  23. Legislative Assembly of Ontario, “Bill 194, Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024”, Royal Assent 25 November 2024. ola.org ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.