Skip to content
← BlogComplianceAnalysis6 min read

AI regulation isn't just the EU: where the major jurisdictions actually stand

The EU AI Act gets headlines, but South Korea's AI Basic Act, China's companion-AI rules, and a stalled US preemption fight all moved this month too.

By Norbelys Chirinos, Co-founder

Founder-reviewed ·How we research and correct articles

The EU AI Act’s August 2 enforcement date has absorbed most of the compliance-press attention this month, and it deserves a chunk of it. But treating “AI regulation” as a single EU story is a mistake for any company operating across borders — three other jurisdictions moved in real, binding ways in the last few weeks, and a fourth is actively drafting. If your users or infrastructure touch more than one region, the rule that reaches you might not be the one making headlines.

Here’s where the jurisdictions that matter most actually stand, as of this week.

JurisdictionStatusWhat's binding now
European UnionIn force, enforcement rampingArticle 50 transparency duties binding Aug 2; AI Office gains GPAI fining power same date
South KoreaIn force since Jan 22, 2026AI Basic Act live; 1-year enforcement grace period — fines deferred except serious-harm cases
ChinaSector rules in forceCompanion/emotional-AI rules binding since Jul 15; broader AI stack enforced under existing cyber law
United StatesNo federal law; state patchwork109 state AI laws enacted in 2026 alone; federal preemption effort stalled in Senate
United KingdomBill in progress, not yet lawAI Regulation and Safety Bill passed Lords second reading Jul 3; no 2026 enforcement
IndiaDraft published Jul 1, 2026Digital India Act draft proposes EU-style risk tiers; not yet enacted

European Union — the deadline everyone’s watching

Covered in depth here and here: binding chatbot and AI-content disclosure rules activate August 2, 2026, alongside the AI Office’s new fining authority over general-purpose model providers. This is the only jurisdiction on this list with both a comprehensive AI law and an active, expanding enforcement apparatus.

South Korea — already enforcing, deliberately gently

South Korea’s AI Basic Act and its Enforcement Decree took effect January 22, 2026, making it the first comprehensive AI statute to actually go live this year, ahead of the EU’s own enforcement ramp. It sets a “high-performance AI” compute threshold roughly ten times higher than the EU’s GPAI trigger, and covers high-impact categories like employment, healthcare, and financial services with mandatory risk assessments. The notable difference from the EU’s posture: South Korea’s regulator, MSIT, is running a deliberate one-year grace period through most of 2026, holding back administrative fines except in cases involving serious harm, and prioritizing guidance over punishment while subordinate regulations get finalized. Extraterritorial application is confirmed in the statute, so foreign companies serving Korean users are in scope even during the grace period.

China — narrow but real, and it already shut things down

China’s Interim Measures for AI-Based Anthropomorphic Interactive Services — its rules for AI companion and emotional-support chatbots — took effect July 15, 2026, and had immediate, visible teeth: both ByteDance’s Doubao and Alibaba’s Qwen shut down personalized AI-companion features in response. The rules require clear disclosure that the service isn’t human, anti-addiction and self-harm safeguards, minor protections, and a ban on training on user data without consent. It’s a narrow slice of China’s overall AI governance approach (which otherwise runs through existing cybersecurity and internet-information law), but it’s a concrete example of a non-Western jurisdiction moving from rule to enforcement in a matter of days, with real product impact.

United States — no federal law, and that’s not changing soon

The US remains the most fragmented major jurisdiction on this list. A proposed 10-year federal preemption of state AI laws, folded into a 2026 budget bill, collapsed in the Senate on a 99-1 vote after a narrower compromise version also failed to hold. No federal AI statute has replaced the gap. States kept legislating anyway: 109 AI-related laws enacted by July 1, 2026 alone, concentrated in child safety, data centers, and consumer protection, on top of the roughly similar pace in 2025. The Trump administration has signaled it may pursue a unifying executive-order approach rather than legislation, but as of late July nothing has displaced the state-by-state patchwork as the operative US framework. For a company operating nationally, this means compliance is genuinely jurisdiction-by-jurisdiction within the US itself, not just internationally.

United Kingdom — still choosing the “pro-innovation” path, with a bill catching up

The UK has deliberately avoided a comprehensive AI statute in favor of assigning oversight to existing sector regulators. That’s shifting, slowly: the Artificial Intelligence (Regulation) Bill passed its second reading in the House of Lords on July 3, 2026, proposing a duty of care for frontier-model developers above a compute threshold, mandatory pre-deployment safety evaluations, and a new UK AI regulator role. It’s a private member’s bill still working through committee stage, and nothing in it will be enforceable within 2026 even in the best case. For now, the UK’s actual binding AI rules remain whatever your existing sector regulator (FCA, ICO, MHRA, and so on) already requires — the horizontal statute is a 2027-and-later story.

India — the newest entrant, still a draft

India published the draft Digital India Act on July 1, 2026, its most comprehensive technology-governance proposal to date. It borrows the EU’s structure directly: a four-tier risk classification (minimal, limited, high, critical), mandatory conformity assessments and registration for high-risk systems in healthcare, credit, and critical infrastructure, and — notably stricter than the EU original — strict liability (no negligence standard) for harm caused by critical-risk AI. This is a draft, not enacted law, and the timeline to passage is unclear. Worth tracking specifically because India’s market size means an enacted version would immediately matter to a large share of companies with any international user base.

For cold-email and outreach programs specifically, none of these AI-specific statutes replace the messaging-law patchwork you’re likely already tracking — GDPR, CASL, CCPA/CPRA, Australia’s Spam Act still govern how you can contact someone, independent of whether AI touched the message. What’s new across this list is a second, separate layer: rules about disclosing that AI was involved, which increasingly apply on top of the rules about consent to be contacted at all.

No platform can make a customer “compliant” with any of these jurisdictions on its own — that’s still the sender’s obligation, jurisdiction by jurisdiction. But the data-handling discipline this whole patchwork keeps converging on regardless of country is something a platform can either build in or leave for the customer to bolt on. Norbelys ships that discipline as first-class features rather than an afterthought: an actual right-to-erasure endpoint that removes a person’s data rather than soft-deleting it, and data minimization built into what gets collected and retained by default. None of that satisfies South Korea’s AI Basic Act or the EU’s Article 50 by itself — those are separate, jurisdiction-specific obligations — but it’s the same underlying posture every one of these frameworks is reaching for, and it’s why a Norbelys customer is starting from a real control instead of a policy-page promise when a new jurisdiction’s rule lands on their desk.