Artificial intelligence regulation is moving faster than most businesses anticipated. This ai regulation tracker maps the current legal landscape across the major jurisdictions - covering enacted laws, draft frameworks, enforcement timelines, and the compliance obligations that apply to companies deploying or developing AI systems. Whether you operate a single-market startup or a multinational enterprise, understanding where the rules apply, what they require, and when they take effect is now a core legal and commercial priority. This guide covers the European Union, the United States, the United Kingdom, China, and a selection of other significant markets, and explains what each framework means in practice.
AI regulation is no longer a theoretical concern. Governments on every continent have either enacted binding rules or are in advanced stages of doing so. The consequences of non-compliance range from administrative fines and product bans to reputational damage and civil liability. For companies that deploy AI in customer-facing products, hiring tools, credit scoring, healthcare, or critical infrastructure, the stakes are particularly high.
The challenge for international businesses is that no two frameworks are identical. The EU';s approach is risk-based and horizontal, applying across sectors. China';s rules are use-case specific and enforced through a licensing model. The United States has so far relied on a patchwork of sector-specific guidance and state-level legislation, with federal legislation still evolving. The United Kingdom has taken a principles-based, sector-led approach. Navigating these differences requires a structured, jurisdiction-by-jurisdiction view - which is precisely what this tracker provides.
A common mistake is assuming that compliance with one jurisdiction';s rules automatically satisfies another';s. In practice, the definitions of "AI system," "high-risk," and "prohibited use" vary materially between frameworks. A system that is permitted in one market may be restricted or banned in another.
The EU AI Act is a regulation of the European Parliament and of the Council that establishes a horizontal, risk-based framework for AI systems placed on the EU market or used within the EU. It applies to providers, deployers, importers, and distributors, regardless of where they are established. This extraterritorial reach means that any company whose AI system affects persons in the EU is potentially within scope.
The Act classifies AI systems into four risk tiers. Unacceptable-risk systems - such as real-time remote biometric identification in public spaces for law enforcement, social scoring by public authorities, and certain subliminal manipulation techniques - are prohibited outright. High-risk systems, which include AI used in recruitment, credit decisions, medical devices, critical infrastructure, and law enforcement, must meet strict requirements before deployment. These include conformity assessments, technical documentation, human oversight mechanisms, and registration in an EU database. Limited-risk systems face transparency obligations. Minimal-risk systems are largely unregulated.
The Act';s implementation is phased. Prohibitions on unacceptable-risk systems took effect first. Rules for general-purpose AI models - including large language models - followed. High-risk system requirements apply on a rolling basis depending on the sector. Providers of general-purpose AI models with systemic risk face additional obligations, including adversarial testing and incident reporting to the European AI Office, which is the primary enforcement body at EU level.
Penalties under the Act are substantial. Violations of prohibited-use provisions can attract fines of up to 3% of global annual turnover for general violations, with higher thresholds for the most serious breaches. National market surveillance authorities enforce the rules at member-state level, with the European AI Office coordinating cross-border cases.
In practice, founders and compliance teams should consider that the Act';s definitions are broad and that many software products previously not considered "AI" may now fall within scope. A non-obvious requirement is that even companies that merely deploy a third-party AI system - rather than develop it - carry compliance obligations as deployers.
The United States does not yet have a single federal AI law equivalent to the EU AI Act. Instead, the current framework consists of executive orders, agency guidance, sector-specific rules, and a growing body of state legislation. This fragmented landscape creates compliance complexity for businesses operating across multiple states or regulated sectors.
At the federal level, the National Institute of Standards and Technology (NIST) AI Risk Management Framework provides a voluntary but widely referenced structure for identifying, assessing, and managing AI-related risks. Several federal agencies - including the Federal Trade Commission, the Equal Employment Opportunity Commission, and the Consumer Financial Protection Bureau - have issued guidance applying existing laws to AI-driven decisions. The FTC has been particularly active in signalling that deceptive or unfair AI practices fall within its enforcement mandate under the FTC Act.
At the state level, Colorado enacted the Colorado AI Act, which imposes obligations on developers and deployers of high-risk AI systems, with a focus on algorithmic discrimination. Illinois, Texas, and several other states have enacted or are considering AI-specific legislation, particularly in the areas of employment, biometric data, and automated decision-making. California has been especially active, with multiple bills addressing AI transparency, deepfakes, and automated employment decisions.
For businesses in regulated sectors, the picture is more prescriptive. The Food and Drug Administration regulates AI-enabled medical devices. Financial regulators have issued model risk management guidance that applies to AI-driven credit and trading systems. The Department of Defense and intelligence community operate under separate AI ethics frameworks.
A practical scenario: a European company deploying an AI-driven hiring tool in the United States must assess not only federal anti-discrimination law but also state-level AI employment statutes, which may require bias audits, candidate disclosures, and data retention policies. Many underestimate the compliance burden at the state level, particularly in high-population states such as California, New York, and Illinois.
If you are mapping your US AI compliance obligations and need guidance on which federal and state rules apply to your product, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
The United Kingdom has deliberately chosen not to enact a single binding AI law. Instead, the government';s approach assigns responsibility for AI governance to existing sector regulators - the Financial Conduct Authority, the Information Commissioner';s Office, the Medicines and Healthcare products Regulatory Agency, and others - each applying their existing powers to AI within their domains.
The government has published a set of cross-sector AI principles: safety, security, fairness, accountability, transparency, and contestability. These are not legally binding in themselves, but regulators are expected to embed them into their sector-specific guidance and enforcement. The ICO, for example, has issued detailed guidance on the use of AI in automated decision-making under the UK GDPR, which retains the substance of the EU';s General Data Protection Regulation post-Brexit.
The UK';s approach creates a different compliance dynamic from the EU. There is no single conformity assessment or registration requirement. Instead, businesses must assess which regulators have jurisdiction over their AI use case and engage with each regulator';s specific expectations. The AI Safety Institute, established to evaluate the risks of frontier AI models, operates separately from sector regulators and focuses on systemic risk rather than product-level compliance.
A practical scenario: a fintech company using AI for credit scoring in the UK must satisfy the FCA';s model risk management expectations, the ICO';s automated decision-making rules under UK GDPR, and the Competition and Markets Authority';s guidance on algorithmic pricing - three separate regulatory touchpoints for a single product. This multi-regulator dynamic is a common source of compliance gaps for businesses entering the UK market.
Recent developments suggest the UK may introduce more targeted legislation for high-risk AI applications, particularly in response to developments in the EU and internationally. Businesses should monitor the AI and Intellectual Property Office';s consultations and the government';s annual reviews of the sector-led approach.
China has taken a distinctive approach to AI regulation, enacting a series of use-case-specific rules rather than a single horizontal framework. The Cyberspace Administration of China (CAC) is the primary regulator and has issued binding rules on algorithmic recommendations, deep synthesis (deepfakes), and generative AI services.
The Generative AI Measures, administered by the CAC and several co-regulators, require providers of generative AI services to the Chinese public to register with the authorities, conduct security assessments, and ensure that their training data and outputs comply with Chinese law. This includes requirements that AI-generated content does not undermine state authority, spread disinformation, or violate the personal information protection rules under the Personal Information Protection Law (PIPL).
The algorithm recommendation rules require platforms using algorithmic systems to recommend content or products to users to disclose the use of algorithms, provide opt-out mechanisms, and avoid using algorithms to engage in price discrimination or to manipulate public opinion. These rules apply to a wide range of digital services and have been actively enforced.
For foreign companies, the China AI framework presents particular challenges. The security assessment requirement for cross-border data transfers under the Data Security Law and PIPL intersects with AI compliance, since AI systems often process personal data at scale. Companies providing AI services in China through local entities must ensure that their models, training data, and outputs satisfy the CAC';s content requirements - which differ materially from the standards applied in Western markets.
A non-obvious requirement is that even AI systems not primarily designed for content generation may trigger the generative AI rules if they produce text, images, or audio as an output. Many foreign companies have discovered this only after their product was already live in the Chinese market.
Beyond the four major frameworks, several other jurisdictions are enacting or developing AI-specific rules that matter for international businesses.
Canada';s Artificial Intelligence and Data Act (AIDA), part of the broader Bill C-27 package, proposes a risk-based framework with obligations for high-impact AI systems, including impact assessments, mitigation measures, and transparency requirements. AIDA is still moving through the legislative process, but its passage would make Canada one of the few countries with a standalone federal AI law.
Brazil';s AI Bill follows a risk-tiered structure broadly similar to the EU AI Act and has been advancing through the Brazilian Congress. Brazil';s Lei Geral de Proteção de Dados (LGPD) already applies to automated decision-making that affects individuals, and the National Data Protection Authority (ANPD) has issued guidance on this. Companies with significant Brazilian operations should monitor the AI Bill';s progress closely.
India has so far taken a light-touch approach, with the government signalling a preference for voluntary frameworks and sector-specific guidance rather than binding legislation. The Ministry of Electronics and Information Technology has published advisory documents on responsible AI, but these are not legally enforceable. India';s Digital Personal Data Protection Act intersects with AI in the context of automated processing of personal data.
In the Gulf Cooperation Council region, the UAE has been the most active, establishing the AI Office and publishing a National AI Strategy. The UAE has enacted sector-specific AI rules in financial services and healthcare, and the Dubai International Financial Centre has issued its own AI governance framework for firms operating within the DIFC. Saudi Arabia is developing its own AI regulatory framework through the Saudi Data and AI Authority (SDAIA).
Despite the differences between national frameworks, several compliance themes recur across jurisdictions and represent a baseline that most businesses deploying AI should address.
Many underestimate the documentation burden. Regulators do not simply ask whether a company has complied - they ask for evidence. Building documentation practices into the AI development and deployment lifecycle from the outset is significantly less costly than reconstructing them after a regulatory inquiry.
For businesses that need a structured review of their AI compliance posture across multiple jurisdictions, contact info@vlolawfirm.com. We can assist with documents and filings across the relevant regulatory frameworks.
What is the difference between the EU AI Act and other national AI frameworks?
The EU AI Act is a binding horizontal regulation that applies across all sectors and all types of AI systems, using a risk-based classification model. Most other national frameworks are either sector-specific, voluntary, or still in draft form. The Act';s extraterritorial scope - applying to any provider or deployer whose AI system affects EU residents - makes it the single most significant compliance obligation for international businesses. Other frameworks, such as China';s generative AI rules or the US state-level laws, are narrower in scope but can be equally demanding within their specific domains. The key practical difference is that the EU Act requires formal conformity assessments and registration for high-risk systems, whereas most other frameworks rely on self-assessment and sector regulator oversight.
How long does it take to achieve AI compliance, and what does it cost?
The timeline and cost depend heavily on the complexity of the AI system, the number of jurisdictions involved, and the risk tier under the applicable frameworks. For a single-jurisdiction, limited-risk deployment, a compliance review and documentation exercise may take several weeks and involve professional fees in the low to mid thousands. For a high-risk system deployed across multiple jurisdictions - requiring conformity assessments, bias audits, technical documentation, and regulatory registrations - the process can take several months and involve significantly higher professional and technical costs. Ongoing compliance, including monitoring regulatory updates, maintaining documentation, and responding to regulator inquiries, adds a recurring cost that businesses should budget for from the outset.
Should a startup building an AI product prioritise EU AI Act compliance or focus on its home market first?
The answer depends on where the startup';s users are located and where it plans to scale. If the product is or will be used by EU residents, EU AI Act obligations apply regardless of where the company is incorporated. Startups that build compliance into their product architecture early - particularly around transparency, data governance, and human oversight - find it significantly easier to scale into regulated markets than those that retrofit compliance later. A practical approach is to conduct a risk classification exercise early, identify the highest-risk use cases, and build the documentation and oversight mechanisms required for those use cases first. This creates a compliance foundation that can be adapted to other jurisdictions as the business grows.
AI regulation is now a permanent feature of the international business environment. The frameworks differ in scope, structure, and enforcement intensity, but the direction of travel is consistent: greater accountability, more transparency, and binding obligations for high-risk applications. Businesses that treat compliance as a one-time exercise rather than an ongoing programme will find themselves exposed as rules tighten and enforcement increases.
VLO Law Firms advises international clients on AI regulation matters globally. We can assist with risk classification, compliance gap analysis, regulatory documentation, and cross-border filing requirements across the EU, UK, US, China, and other jurisdictions. To request a consultation, contact: info@vlolawfirm.com