Five claims about global AI regulation are repeated so widely that they have stopped being checked. Each one fails against the text of the instrument it describes, and each failure sends a compliance budget somewhere it should not go.
Correcting them is more useful than another country list, because the errors are not at the edges. Each error sits somewhere load-bearing: the headline penalty figure, the count of binding regimes, what a treaty does, whether federal law will rescue American companies, and whether the absence of a statute means the absence of a duty.
Claim one: only two jurisdictions have a binding AI law in force
Vietnam’s AI law ends this one. The Law on Artificial Intelligence No. 134/2025/QH15 passed on 10 December 2025 and entered into force on 1 March 2026, with a three-tier risk model, conformity assessment, mandatory marking of AI-generated media, incident reporting inside 72 hours and administrative or criminal liability under Article 29. Guidance still naming the European Union and South Korea as the only two is counting from data that went stale in the first quarter.
AI regulation trackers carry a deeper problem than a stale count, which is the binary itself. Sorting jurisdictions into regulated and unregulated forces two questions onto one axis, and they come apart constantly.
AI law exposure resolves once the two questions are asked separately. Does an instrument exist that names AI, and can an authority do anything to you. Four outcomes follow, and the awkward jurisdictions land cleanly.
An AI instrument with its own sanction. The European Union, South Korea, Vietnam and six United States jurisdictions. Duties and penalties in the same text.
An AI instrument with no sanction. Japan alone. The AI Promotion Act, Act No. 53 of 2025, asks AI business actors under Article 7 to make reasonable efforts to follow its principles, and contains no penal provision, no fine and no corrective order power. The government can name a business publicly, and public naming is the whole enforcement toolkit.
An AI instrument whose sanction lives elsewhere. China. The Generative AI Interim Measures and the Labelling Measures are AI-specific and route their penalties through the Cybersecurity Law, the Data Security Law and PIPL. The ceiling reached RMB 10 million when the amended Cybersecurity Law took effect on 1 January 2026, and enforcement is real: the Cyberspace Administration penalised three AI platforms for labelling failures on 29 April 2026.
No AI instrument and a duty anyway. Australia, India and Illinois, covered under claim five.
Japan’s AI statute is the case that breaks the binary. Calling Japan regulated puts budget against a risk that does not exist. Calling Japan unregulated hides statutory duties and the frame on which later Japanese rules will hang.
Claim two: the EU AI Act fine is 35 million euro or 7 percent, whichever is higher
The EU AI Act says that in one place, about one tier, and for a large share of readers the formula inverts.
Article 99(3) of Regulation (EU) 2024/1689 sets EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher, and only for breaching the Article 5 prohibitions. Two further tiers sit underneath. Article 99(4) sets EUR 15 million or 3 percent for the operative duties of providers, importers, distributors, deployers and notified bodies, and for the Article 50 transparency duties. Article 99(5) sets EUR 7.5 million or 1 percent for supplying incorrect, incomplete or misleading information.
Most organisations will never touch Article 5. Realistic exposure sits in the 3 percent tier, which is where technical documentation, human oversight and transparency failures land.
The EU AI Act then reverses that formula at Article 99(6). For SMEs including start-ups, the fine is the percentage or the fixed amount, whichever is lower, and Regulation (EU) 2026/1744 inserted a new paragraph 6a extending that to small mid-cap companies for the 99(4) and 99(5) tiers. A small European provider facing a documentation failure is not looking at 15 million euro. The exposure is 3 percent of its own turnover.
General-purpose AI model providers sit outside this scheme entirely. Article 101 lets the Commission itself impose fines of up to 3 percent or EUR 15 million, whichever is higher, without going through a national authority.
Four different formulas, one sentence in circulation.
Claim three: the Council of Europe treaty is the first binding international AI law
The only binding international AI law on offer is inert, because CETS 225 has not entered into force.
The Framework Convention on Artificial Intelligence opened for signature on 5 September 2024. Article 30 requires five ratifications including at least three Council of Europe member states. The Treaty Office chart shows 20 signatures not followed by ratification and one ratification, so 21 signatories and a single Party.
The European Union is that Party, having ratified on 15 May 2026. No state has ratified. Not the United Kingdom, not Japan, not Canada, not the United States, all of which signed.
A treaty with no Conference of the Parties sitting, no court and no fining power imposes nothing on a company today. Where it will matter is Switzerland, where the Federal Council decided on 12 February 2025 to ratify and to amend Swiss law accordingly, with a draft bill due for consultation by the end of 2026. Ratification is the mechanism by which this text becomes domestic duties, and that mechanism has fired once.
Claim four: federal law will preempt the United States patchwork
Federal AI law has failed to arrive twice, and the second failure was not close.
A ten-year moratorium on state AI laws was stripped from the One Big Beautiful Bill Act by the Blackburn Amendment No. 2814. Senate Roll Call Vote 363, taken at 4.08 in the morning on 1 July 2025, carried it 99 to 1, with Senator Thom Tillis the only Nay. Congress then left a moratorium out of the FY2026 defence bill. A bipartisan discussion draft circulated on 4 June 2026 was never formally introduced.
The instrument that does exist is Executive Order 14365 of 11 December 2025, which created a Department of Justice litigation task force, directed Commerce to evaluate state AI laws and conditioned some federal funding. Litigation and funding pressure are not preemption. The Department of Justice intervened on 24 April 2026 in the challenge to Colorado’s 2024 act, and Colorado replaced that act three weeks later anyway.
Meanwhile six United States jurisdictions carry live AI duties, and the newest of them attach on 1 January 2027. What Colorado now requires is set out in the SB 26-189 checklist, and the wider American position sits in the US laws and the records they demand.
Claim five: no AI law in a country means no AI duty
An absent AI law is the assumption that catches the most organisations, because nobody assigns an owner to a duty they believe does not exist.
Australia decided against an AI Act. Mandatory guardrails were formally abandoned in the National AI Plan of 2 December 2025, and Guidance for AI Adoption binds nobody. A binding duty arrives regardless on 10 December 2026, when the Privacy Act 1988 automated decision-making transparency obligation commences under the Privacy and Other Legislation Amendment Act 2024. Entities must disclose in their privacy policy where a computer program makes, or does something substantially and directly related to making, a decision that significantly affects an individual. Section 13G exposure runs to AUD 50 million for serious interference.
India published AI governance guidelines that bind nobody, and IT Amendment Rules that bind platforms hard. In force from 20 February 2026, they require synthetically generated content to carry a prominent label and embedded metadata that cannot be removed, and require significant social media intermediaries to run technical verification rather than trusting user declarations. The sanction is loss of intermediary safe harbour, which converts a labelling failure into liability for everything users post.
Illinois amended its Human Rights Act instead of writing a statute of its own. Public Act 103-0804 has made it a civil rights violation since 1 January 2026 to use AI that has the effect of discriminating, or to use a postcode as a proxy for a protected class. The penalties are the ordinary Human Rights Act tiers, reaching USD 70,000 per act per aggrieved person for repeat violations, and the Department of Human Rights withdrew its draft notice rules on 2 June 2026, leaving live duties with no rule-level guidance.
Note who owns the risk in each case. Privacy in Australia, platform policy in India, employment law in Illinois. None of these lands on the desk of whoever is reading the AI regulation tracker, which is exactly why they get missed.
The jurisdiction table, read against the two axes
AI-specific and sanction are read as separate columns below, because the second does not follow from the first.
| Where | Instrument | AI-specific | Sanction | Enforcer | Key date |
| EU | AI Act 2024/1689 | Yes | EUR 35m or 7%, tiered | Market surveillance, AI Office | High-risk 2 Dec 2027 |
| Korea | AI Framework Act 21311 | Yes | KRW 30m ceiling | MSIT | In force 22 Jan 2026 |
| Vietnam | AI Law 134/2025/QH15 | Yes | Admin and criminal | Science and Technology | In force 1 Mar 2026 |
| China | GenAI Measures, Labelling | Yes | RMB 10m, via other law | CAC | Labelling 1 Sep 2025 |
| Japan | AI Promotion Act | Yes | None | AI Strategic HQ | In force 4 Jun 2025 |
| Colorado | SB 26-189 | Yes | USD 20,000, via CCPA | State AG | Duties 1 Jan 2027 |
| Texas | HB 149 TRAIGA | Yes | USD 80k to 200k | State AG | In force 1 Jan 2026 |
| California | SB 53, ADMT rules | Yes | USD 1m, large developers | AG and CPPA | ADMT 1 Jan 2027 |
| Illinois | HB 3773 | No | USD 70,000, via IHRA | Human Rights Dept | In force 1 Jan 2026 |
| New York City | Local Law 144 | Yes | USD 500 to 1,500 | DCWP | In force 5 Jul 2023 |
| Utah | SB 149 as amended | Yes | USD 2,500, via Ch. 75 | Consumer Protection | Repeals 1 Jul 2027 |
| India | IT Amendment Rules 2026 | No | Safe harbour loss | MeitY | In force 20 Feb 2026 |
| Australia | Privacy Act, APP 1.7 | No | AUD 50m | OAIC | Duty 10 Dec 2026 |
| UK | Sector regulators | No | None under AI rules | Existing bodies | No AI statute |
| Canada | AI for All | No | None | None | Strategy 4 Jun 2026 |
| Singapore | Model AI Framework | Yes | None | IMDA | Updated 20 May 2026 |
| New Zealand | AI Strategy | Yes | None | None | Published 10 Jul 2025 |
| Brazil | PL 2338/2023 | Bill | Not yet | Would be ANPD | In committee |
Three rows carry a caveat that AI regulation trackers rarely print.
Korea’s KRW 30 million reads as the ceiling because Article 43(1) says so, and the Enforcement Decree schedule reaches it only on a third or subsequent failure to obey a suspension or correction order. A first failure to give the Article 31(1) notice is KRW 5 million. Separately, the Ministry of Science and ICT is running a guidance period of at least a year from 22 January 2026 during which investigations and fines are deferred except where serious harm occurs. Small fines, deferred, against wide reach.
Utah’s penalty no longer sits in the AI Policy Act. SB 226 repealed the old enforcement section and moved the USD 2,500 administrative fine into a new Chapter 75, while Chapter 72 itself repeals on 1 July 2027 unless the legislature acts. Citations to Chapter 72 penalties point at a provision that no longer exists.
New York City runs two bands rather than one. Not more than USD 500 for a first violation and further violations the same day, then USD 500 to USD 1,500 for each subsequent violation, with each day of use and each missed notice counting separately.
Extraterritorial reach is the axis a multinational actually needs
AI laws vary more in their reach than in their duties, and four regimes use four different mechanisms to catch a company with no local entity.
The EU AI Act reaches providers placing systems on the Union market and providers outside the Union whose system output is used inside it. Establishment is not the test.
South Korea reaches acts abroad that affect the Korean market or Korean users under Article 4(1), and requires a foreign operator with no Korean establishment to appoint a domestic representative once it passes any of three thresholds: prior-year total revenue above KRW 1 trillion, prior-year AI service revenue above KRW 10 billion, or an average of one million daily Korean users across three months. Failing to appoint is itself fineable.
Vietnam asks for presence rather than a representative in the harder cases. Article 2 covers foreign organisations participating in AI activities in Vietnam, and foreign providers of high-risk systems requiring conformity certification must establish a commercial presence or an authorised representative.
Texas wrote the widest American reach into section 551.002, which captures any person producing a product or service used by Texas residents. No Texas office is required.
China uses blocking rather than money. Article 20 of the Interim Measures allows technical measures against non-compliant services provided from outside the mainland, and losing the market usually costs more than a fine.
Market placement, a representative threshold, local presence, and blocking. An inventory recording only where systems are hosted cannot answer any of them.
What lands between now and August 2028
Global AI regulation has five dated changes already fixed, and one of them is routinely stated wrong.
The EU AI Act’s high-risk obligations did not move to a single date. Regulation (EU) 2026/1744 split them: 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for systems classified under Article 6(1) and Annex I, meaning safety components in regulated products. A medical device manufacturer and a hiring platform now sit eight months apart. Every date that moved is traced in the amended EU timeline.
Generators of synthetic content placed on the market before 2 August 2026 must meet the Article 50(2) marking duty by 2 December 2026 under the new Article 111(4).
Australia’s automated decision-making disclosure duty commences on 10 December 2026.
Colorado’s ADMT duties and the California CPPA ADMT rules both attach on 1 January 2027, from two definitions that do not match.
Korea’s guidance period is expected to close around 22 January 2027, converting a dormant statute into an enforced one without a word of the text changing.
The duties differ and the artefacts repeat
AI laws disagree about scope, thresholds, deadlines and who enforces, and agree about what they want to see. Reading them against each other produces the finding that makes multi-jurisdiction work affordable.
A system inventory with an owner and a risk classification is required by the EU AI Act, Korea’s high-impact regime, Vietnam’s risk dossiers and California’s ADMT pre-use notice. Documentation of intended purpose, training data categories and known limitations appears in Annex IV of the EU AI Act, Colorado’s developer pack, Korea’s explainability duty and Vietnam’s technical records. Notice that a person is dealing with a machine appears in the EU, Korea, Vietnam, China, India, Utah and Colorado. Marking of synthetic output appears in China, Korea, Vietnam, India, California and the EU. Human review of a consequential decision appears in the EU, Colorado, California and Illinois. Incident reporting appears in the EU, California and Vietnam, with only the clocks differing.
Six artefacts, produced once and held properly, answer most binding instruments in force. Which record answers which article is worked out in the records that prove conformity, and the control-level mapping between the EU AI Act, ISO/IEC 42001 and the NIST AI RMF sits in where these instruments overlap.
Standards carry the portability that AI laws cannot. ISO/IEC 42001 is law nowhere and is treated as evidence of reasonable practice in several places, including Texas, where substantial compliance with a recognised framework operates as a defence.
Where a multi-jurisdiction programme keeps its records
AI regulations across eighteen jurisdictions produce one inventory, not eighteen. Programmes fail here by running a workstream per country, each with its own spreadsheet, none reconciled, and no way to answer which systems a new instrument touches without starting a fresh survey.
Govern365 was built for that reconciliation. The AI System Registry holds each system once with its owner, purpose, risk tier and the markets it serves, so a new statute becomes a filter rather than a questionnaire. The Audit Evidence Manager attaches each artefact to every obligation it satisfies, which is what turns one Annex IV file into a Colorado developer pack and a Vietnamese technical record. Governance Workflows carry the human review and approval steps the EU, Colorado, California and Illinois each demand in slightly different words. Continuous Monitoring holds retention to the longest applicable clock rather than the nearest one. The platform sits at govern365.ai, and the route from intake to approved decision is shown on where these approvals are tracked.
Frequently asked questions
How many countries have a binding AI law in force in 2026?
Three have a binding AI statute with its own sanction: the European Union, South Korea since 22 January 2026 and Vietnam since 1 March 2026. Japan’s is binding and carries no sanction. China regulates AI through binding instruments of its own whose penalties sit in other laws. Guidance naming two is counting from data that went stale in the first quarter.
Does the EU AI Act apply to a company with no European entity?
Yes, in two situations. The EU AI Act catches a provider placing an AI system or a general-purpose AI model on the Union market regardless of establishment, and it catches output produced elsewhere that is used in the Union. Establishment in a member state is not the trigger.
What is the actual maximum fine under the EU AI Act?
The EU AI Act sets EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher, under Article 99(3), and only for the Article 5 prohibitions. Provider and deployer duties sit at 15 million or 3 percent, and information failures at 7.5 million or 1 percent. For SMEs, start-ups and small mid-caps the formula reverses to whichever is lower.
When do the EU high-risk obligations actually apply?
The EU AI Act now carries two dates. 2 December 2027 for systems classified under Article 6(2) and Annex III, and 2 August 2028 for systems classified under Article 6(1) and Annex I. Guidance giving a single December 2027 date understates the deadline for product-embedded systems by eight months.
Did the United States preempt state AI laws?
No. A ten-year moratorium was stripped from the 2025 budget bill by Senate Roll Call 363 on 1 July 2025, 99 to 1, and left out of the FY2026 defence bill. Executive Order 14365 directs litigation and conditions funding rather than preempting. Duties in Colorado, Texas, California and Illinois are in force.
Has the Council of Europe AI Convention entered into force?
No. CETS 225 needs five ratifications including three Council of Europe member states, and carries 21 signatories against one Party, the European Union, which ratified on 15 May 2026. No state has ratified.
Does one governance programme satisfy several jurisdictions?
Largely, because the artefacts repeat even where the duties differ. A system inventory, technical documentation, user notice, synthetic content marking, human review records and incident reports cover most binding instruments now in force. The differences sit in deadlines, thresholds and retention, which is configuration rather than a separate programme.
