AI Regulations by Jurisdiction
Where each major AI law actually stands right now — enacted, proposed, or stalled — tracked jurisdiction by jurisdiction and kept current in place.
"AI regulation" isn't one law you can read once and be done with. It's a different statute in every jurisdiction, moving at a different pace, using different definitions of the same underlying idea — and the gap between what a law says on paper and what's actually being enforced is often the most important detail in the whole analysis.
This hub is organized by jurisdiction because that's how the obligations actually attach: a system that's high-risk under the EU AI Act may sit entirely outside a comparable U.S. state law's scope, and a company operating in three of our four target markets is really managing three or four independent compliance programs that happen to overlap in places.
Every regulation page here carries a status — proposed, enacted, in force, amended, or repealed — and a last-reviewed date that's tied to an actual review, not a decorative timestamp. When a tracked law changes, we update the page in place rather than burying the change in a separate news post you'd have to go find.
Jurisdictions
EU AI Regulations
The EU AI Act is the most comprehensive AI-specific law in force anywhere, phasing in on a multi-year schedule — here's where it actually stands today.
US AI Regulations
No federal AI statute yet — instead, a fast-growing patchwork of state laws, agency guidance, and sector-specific rules that a compliance program has to track state by state.
UK AI Regulations
The UK has deliberately avoided a single AI statute in favor of empowering existing sector regulators to apply a shared set of principles within their own remits.
Canada AI Regulations
Canada's federal AI bill has stalled in Parliament — provincial privacy regulators and existing federal law are doing most of the practical work in the meantime.
Australia AI Regulations
Australia has proposed mandatory guardrails for high-risk AI following a lengthy consultation process, but has not yet enacted a comprehensive AI statute.
Recently updated
regulations australia
Australia AI Regulation
regulations canada
Canada AI Regulation
regulations uk
UK AI Regulation
regulations us california
California AI Regulations
regulations us colorado
Colorado AI Act (SB 205)
regulations us
US Federal AI Regulation: What Actually Exists Today
regulations eu
The EU AI Act
Frequently asked questions
- Is there a single global AI law companies need to comply with?
- No. There's no global AI statute — every jurisdiction covered here has written (or is writing) its own law, with its own definitions, thresholds, and enforcement mechanism. The closest thing to international alignment is voluntary frameworks like the OECD AI Principles, which shape national laws but don't themselves create legal obligations.
- Which AI regulations are already in effect, not just proposed?
- The EU AI Act is the furthest along, with prohibitions and literacy obligations already applicable and high-risk provisions phasing in on a set schedule. Several U.S. states, including Colorado, have enacted AI-specific statutes with their own effective dates. Track the status badge on each jurisdiction page here rather than assuming — "passed" and "in force" are not the same thing, and the gap between them is often a year or more.
- Do I need to comply with the EU AI Act if my company isn't based in the EU?
- Often yes. Like the GDPR before it, the EU AI Act applies extraterritorially: if your AI system's output is used within the EU, you can fall within scope regardless of where your company is incorporated. This is one of the most commonly missed points in early compliance planning — see our EU AI Act coverage for the specific triggers.
- What's the difference between a regulation and a framework?
- A regulation is a binding law with a government enforcement mechanism behind it — the EU AI Act, a state statute. A framework, like the NIST AI RMF, is voluntary guidance with no legal force on its own, though regulators and courts increasingly point to frameworks as evidence of what "reasonable" AI risk management looks like. See our frameworks hub for that side of the picture.