Interactive explorer · Updated July 2026

Global AI Regulations Map & Tracker

A human-verified, interactive map of AI laws across 70+ jurisdictions. Pick your role — develop, deploy, or use AI — select a country, and see what applies, its status, key dates, and the practical steps an SME should take.

Updated July 2026 — reflects the EU AI Act Digital Omnibus (post-Omnibus high-risk dates)
My role(s):
Loading world map…
Binding Law29Actively Enforced1Voluntary / Guidelines18Draft / Proposed19No AI Regulation3

United States

📋 Voluntary / Guidelines

No federal AI law. Patchwork of state laws + voluntary NIST framework. Federal push to preempt state laws.

NIST AI Risk Management Framework

Voluntary / Guidelines

2023

Develop AI

Govern, Map, Measure, Manage. Safe harbor in CO & TX. Flexible adoption.

Deploy AI

Demonstrates 'reasonable care'. Document implementation.

Use AI Tools

Lightweight adoption for due diligence.

  • 4 functions: Govern, Map, Measure, Manage
  • Safe harbor in CO & TX laws
  • Voluntary but key compliance benchmark
SME note: THE framework to adopt. Creates legal defense in states with binding laws.
Read the guide

Colorado AI Act (SB 24-205)

Binding Law

Effective June 30, 2026

Develop AI

Documentation, risk info, known limitations. Publish transparency statements.

Deploy AI

Annual impact assessments for high-risk AI. Consumer notification. Risk management required.

  • High-risk: employment, housing, healthcare, finance, education, insurance, legal
  • Fines: $20K/violation
  • NIST/ISO 42001 = affirmative defense
SME note: Businesses <50 employees exempt from some requirements. Adopt NIST AI RMF.
Read the guide

Texas TRAIGA (HB 149)

Binding Law

Effective Jan 1, 2026

Develop AI

Must not design for discrimination, manipulation, rights infringement. Red-team testing = defense.

Deploy AI

Disclose AI interactions. No deployment for prohibited purposes.

  • Prohibited-practices approach
  • NIST compliance = safe harbor
  • Fines: $12K/violation
  • Regulatory sandbox
SME note: Simpler than Colorado — what you CAN'T do. NIST adoption = key defense.
Read the guide

California AB 2013

Binding Law

Effective Jan 1, 2026

Develop AI

Publish training dataset summaries: sources, licensing, personal/synthetic data.

  • Training data transparency for GenAI developers
SME note: Applies to GenAI model developers only.
Read the guide

NYC Local Law 144

Actively Enforced

2023

Deploy AI

Annual third-party bias audits for AI hiring tools.

Use AI Tools

Ensure AI hiring tools are audited.

  • Annual bias audit
  • Public disclosure
SME note: Applies if you use AI in hiring for NYC roles.
Read the guide

International frameworks

OECD AI PrinciplesG7 HiroshimaCouncil of Europe Convention

Snapshot for education only, human-verified to July 2026 — not legal advice. Laws evolve quickly; verify details with official sources or qualified counsel before acting.

Region by region

AI regulations around the world, decoded for operators

European Union — the EU AI Act (post-Omnibus)

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive AI law, using a four-tier risk model from banned practices through high-risk to minimal-risk uses. Following the Digital Omnibus approved in June 2026, the high-risk timeline shifted: Annex III obligations (employment, credit, essential services and more) now apply from 2 December 2027, and Annex I regulated-product rules from 2 August 2028. Article 50 transparency duties — telling users they are interacting with AI and labelling AI-generated content — still land on 2 August 2026, with watermarking following on 2 December 2026. SMEs benefit from reduced documentation, proportionate fines and free regulatory-sandbox access. Norway applies the same rules via the EEA, and members like France (CNIL), Germany (DSK guidance and works-council rights), Italy (its national AI law) and Spain (the AESIA agency) layer national measures on top.

United States — NIST plus a patchwork of state laws

There is no comprehensive US federal AI law. The voluntary NIST AI Risk Management Framework (Govern, Map, Measure, Manage) has become the de-facto benchmark and provides an affirmative defence or safe harbour under several state laws. Binding state rules are arriving fast: Colorado's AI Act (SB 24-205) governs high-risk consequential decisions from June 2026, Texas TRAIGA takes a prohibited-practices approach from January 2026, California AB 2013 requires GenAI training-data transparency, and NYC Local Law 144 mandates annual bias audits for AI hiring tools. For most SMEs, adopting the NIST framework is the single highest-value step because it travels across states.

United Kingdom & the rest of Europe

The UK takes a principles-based, regulator-led approach — safety, transparency, fairness, accountability and contestability applied by existing regulators such as the ICO and FCA — while binding legislation is signalled. UK GDPR and the Data Protection Act already govern AI that processes personal data. Switzerland issues voluntary guidance but Swiss firms selling into the EU must still meet the EU AI Act, and Turkey has an EU-influenced bill progressing through its legislature.

Asia-Pacific — from binding laws to innovation-first codes

China enforces a layered regime: algorithm-recommendation rules, deep-synthesis provisions, the Interim Measures for Generative AI, and standardised AI-content labelling. South Korea's AI Basic Act — the world's second comprehensive AI framework — took effect in January 2026 and reaches foreign companies serving Korean users. Japan favours an innovation-first promotion law backed by soft-law guidelines, while Singapore's Model AI Governance Framework and AI Verify toolkit are Asia's most-adopted voluntary standards. Australia pairs ten voluntary safety guardrails with proposed mandatory rules for high-risk settings.

Middle East, Latin America & Africa

Adoption is accelerating but uneven. Saudi Arabia and the UAE lead the Gulf with national AI strategies and ethics frameworks; Israel favours a sector-based, principles-led approach. In Latin America, Brazil's risk-based AI bill (PL 2338) is advancing while its LGPD already governs AI personal-data processing, and Mexico, Chile and others have bills in progress. Across Africa, Rwanda, Nigeria, Kenya, South Africa and Egypt are publishing national AI strategies and draft policies, with existing data-protection laws doing much of the enforcing today.

Common questions

AI regulations map — FAQ

Which AI regulations apply to a small business?

It depends on where your customers are and how you use AI. If you handle EU residents' data, GDPR applies today and the EU AI Act's transparency and AI-literacy duties reach businesses of every size. US businesses face the voluntary NIST AI RMF plus binding state laws such as Colorado's AI Act, Texas TRAIGA and NYC Local Law 144. The map lets you filter by your role — develop, deploy, or use AI — to see exactly what applies.

What changed with the EU AI Act Digital Omnibus in 2026?

The Digital Omnibus, approved in June 2026, deferred the EU AI Act's high-risk obligations. Annex III high-risk duties now apply from 2 December 2027 (previously 2 August 2026) and Annex I regulated-product rules from 2 August 2028. Article 50 transparency duties still take effect 2 August 2026, and AI-generated-content watermarking moved to 2 December 2026. This map reflects the post-Omnibus timeline.

How often is this AI regulation tracker updated?

This map is human-verified and last reviewed in July 2026. Because AI law is moving quickly across every continent, we re-check the headline dates and status of each jurisdiction regularly and flag material changes such as the EU Digital Omnibus.

Is this legal advice?

No. This is educational guidance to help SMEs understand the landscape and ask the right questions. Regulations change and apply differently by jurisdiction, sector and circumstance — always confirm decisions with qualified counsel.

Not sure which of these applies to you?

The free AI Starter Pack includes a one-page worksheet that maps your business to the regulations that actually reach it.