Direct comparison
Frontier AI Law: 10 Jurisdictions
10 frontier-AI jurisdictions compared: binding vs. voluntary, centralized vs. sector-led regulator, and risk-tiered vs. uniform structure, with sources.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about Frontier AI Law: 10 Jurisdictions
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do California SB 53, New York RAISE Act, Colorado AI Act, Texas TRAIGA, Utah AI Policy Act, UK AI White Paper, Canada AIDA, Japan AI Promotion Act, Korea AI Basic Act, EU AI Act (high-risk track) compare side by side?
The table below compares California SB 53, New York RAISE Act, Colorado AI Act, Texas TRAIGA, Utah AI Policy Act, UK AI White Paper, Canada AIDA, Japan AI Promotion Act, Korea AI Basic Act, EU AI Act (high-risk track) across 6 procurement-relevant dimensions, from binding or voluntary, and since/from when through casrai foundational source.
Side-by-side comparison
| Dimension | California SB 53 | New York RAISE Act | Colorado AI Act | Texas TRAIGA | Utah AI Policy Act | UK AI White Paper | Canada AIDA | Japan AI Promotion Act | Korea AI Basic Act | EU AI Act (high-risk track) |
|---|---|---|---|---|---|---|---|---|---|---|
| Binding or voluntary, and since/from when | Binding. Signed Sept 29, 2025; core obligations effective Jan 1, 2026. | Binding. Signed Dec 19, 2025; chapter-amended Mar 27, 2026; takes effect Jan 1, 2027. | Binding, not yet in force. SB26-189 (reenacting SB24-205) signed May 14, 2026; effective Jan 1, 2027. | Binding. HB 149, effective Jan 1, 2026. | Binding. SB 149 effective May 1, 2024; SB 226 amendment effective May 7, 2025. | Voluntary, non-statutory. Published Mar 29, 2023, updated Aug 3, 2023. No date set for any future statutory duty. | Never enacted. Bill C-27 (first reading June 16, 2022) died on prorogation Jan 6, 2025. | Binding as a statute, but with no penalty provision — the only lever is non-binding "administrative guidance." | Binding, in force since January 2026. Passed by the National Assembly December 2024. | Binding, staggered dates under the 2026 AI Omnibus: Dec 2, 2027 (Annex III) / Aug 2, 2028 (Annex I) / Aug 2, 2030 (public authorities). |
| Regulator model: centralized vs. sector-led | Centralized — enforced exclusively by the California Attorney General; no new agency. | Centralized, dual-track — the NY Attorney General plus a new DFS oversight office with its own penalty track. | Centralized — the Colorado Attorney General, under the state Consumer Protection Act. | Centralized — the Texas Attorney General has exclusive enforcement authority; no private right of action. | Centralized — a new, dedicated Office of Artificial Intelligence Policy; violations run through existing consumer-protection statutes. | Sector-led — no central AI regulator. Existing regulators (ICO, MHRA, FCA, and others) each apply the principles within their own remit. | Would have been centralized — a proposed AI and Data Commissioner, appointed to support the Minister of Innovation, Science and Industry rather than acting as an independent regulator. | Centralized in form — the AI Strategy Headquarters, chaired by the Prime Minister — but with no independent, binding enforcement power. | Centralized — administered by MSIT, Korea’s Ministry of Science and ICT. | Hybrid — rulemaking centralized at the EU level; enforced by each member state’s own market surveillance authority. |
| Structure: risk/compute-tiered vs. uniform | Risk-tiered by compute + revenue — "frontier developer" (>10^26 FLOP) vs. heavier-duty "large frontier developer" (also >$500M revenue). | Risk-tiered by compute + revenue — frontier model (>10^26 FLOP and >$100M training cost) vs. "large frontier developer" (>$500M revenue) for the heaviest duties. | Uniform — no compute or revenue threshold at all. Coverage turns entirely on whether an automated system is used in a "consequential decision." | Uniform bright-line bans — the same prohibitions apply to every covered person regardless of size, with two narrow duties added only for government entities. | Mostly uniform — a disclosure-on-request duty for all covered interactions, with one narrower, stricter tier added by a 2025 amendment for higher-stakes (health/financial/biometric) interactions. | Uniform — the same five cross-sector principles apply regardless of a system’s scale; no risk classification tiers at all. | Would have been risk-tiered — obligations attached only to systems classified "high-impact" under four example categories. | Uniform, promotional — no risk classification or compliance tiering; the law is built around encouragement, not obligation. | Risk-tiered — obligations attach to systems classified "high-impact" or generative; a Korea-based local representative is separately required for foreign businesses. | Risk-tiered by design — this track exists only as a defined list of Annex I / Annex III high-risk use cases. |
| What triggers coverage | >10^26 FLOP training compute (any entity); >$500M prior-year revenue additionally for the "large frontier developer" tier. | >10^26 FLOP and >$100M training cost for "frontier model" status; >$500M revenue for the heaviest duties. | Use of automated decision-making technology (ADMT) as a substantial factor in a "consequential decision" — education, employment, housing, lending, insurance, health care, or government benefits. | No threshold — applies to anyone who promotes, does business in, or deploys an AI system reaching Texas residents. | No threshold — triggered by using generative AI to interact with a Utah consumer. | None — non-binding; nothing compels a specific action. | "High-impact" classification (proposed); no compute threshold was ever written into implementing regulations, because none were finalized. | None — no compute, revenue, or use-case gate; the law functions as general policy, not a compliance trigger. | "High-impact" or generative AI classification; specific quantitative criteria are not detailed in the ITA’s public summary and are not independently verified by CASRAI as of publication. | Classification under Annex I (safety component of an already-regulated product) or Annex III (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice). No compute threshold on this track — the compute-based GPAI systemic-risk tier is a separate track under Article 51. |
| Enforcement / penalties | CA Attorney General civil actions only; no private right of action. | AG civil penalties ($1M first violation / $3M subsequent); DFS can separately assess $1,000/day for disclosure-statement failures. | Colorado Attorney General, under the state Consumer Protection Act. | TX Attorney General; $80,000–$200,000 per uncurable violation, plus $2,000–$40,000 per day a violation continues. No private right of action. | Handled through Utah’s existing consumer-protection statutes rather than a standalone AI penalty scheme. | None — sector regulators act, if at all, under their own pre-existing statutory powers, not new AI-specific ones. | None — the bill died before any enforcement mechanism took effect. | None binding — "administrative guidance" only, with no compulsion behind it. | MSIT-administered; the act establishes legal grounds for a national AI control tower and AI safety institute. | National market surveillance authorities per member state; some Annex III categories additionally require a notified-body conformity assessment. |
| CASRAI foundational source | <a href="/guides/california-sb-53-frontier-ai-transparency-act">California SB 53: The Foundational Explainer</a> | <a href="/guides/new-york-raise-act-explained">New York RAISE Act: What It Requires</a> | <a href="/guides/colorado-ai-act-explained">The Colorado AI Act: What It Requires</a> | <a href="/guides/texas-traiga-explained">Texas TRAIGA: What It Requires</a> | <a href="/guides/utah-ai-act-explained">The Utah AI Policy Act: What It Requires</a> | <a href="/guides/uk-ai-white-paper-regulatory-framework">The UK’s AI White Paper: A Regulatory Framework Without a Regulator</a> | <a href="/guides/aida-bill-c27-what-it-would-have-required">What AIDA Would Have Required — and Why It Died</a> | <a href="/guides/japan-ai-promotion-act-no-penalties-grok-deepfakes">Japan’s AI Law Has No Penalties — and a Live Test Case</a> | <a href="/guides/korea-ai-basic-act">Korea’s AI Basic Act: What Took Effect in January 2026</a> | <a href="/guides/eu-ai-act-high-risk-compliance-checklist">EU AI Act High-Risk System Compliance Checklist</a> (high-risk track only — not a general EU AI Act overview) |
Common questions
Common questions about California SB 53 vs New York RAISE Act vs Colorado AI Act vs Texas TRAIGA vs Utah AI Policy Act vs UK AI White Paper vs Canada AIDA vs Japan AI Promotion Act vs Korea AI Basic Act vs EU AI Act (high-risk track)
Is there one CASRAI guide that covers the whole EU AI Act?
+
No, and this comparison doesn't claim there is. CASRAI's EU AI Act coverage is split by track — this page uses the EU AI Act High-Risk System Compliance Checklist, scoped specifically to the Annex I/III high-risk track, as its EU source. The Act's general-purpose AI (GPAI) obligations, including the systemic-risk compute threshold discussed in the NIKOLAI section below, are covered separately in CASRAI's GPAI Code of Practice and GPAI systemic risk guides.
Which of these ten laws are actually in force right now?
+
As of this comparison’s last verification (September 20, 2026): California SB 53, Texas TRAIGA, the Utah AI Policy Act (as amended), and Korea’s AI Basic Act are in force. Japan’s AI Promotion Act is a binding statute with no penalty provision. The New York RAISE Act and the Colorado AI Act (SB26-189) are binding but not yet effective. The EU AI Act’s high-risk track has binding but staggered future dates. The UK AI White Paper is voluntary and non-statutory. Canada’s AIDA never became law.
Do any of these laws share the same compute threshold?
+
California SB 53 and the New York RAISE Act both use the same >10^26 FLOP figure to define a "frontier model." The EU AI Act uses a different, lower figure — >10^25 FLOP — as a rebuttable presumption for general-purpose AI systemic risk under Article 51. Both figures, and the primary-source language behind them, are documented in CASRAI’s own NIKOLAI project, in the Coverage scope threshold element.
Why does Colorado not appear as "risk-tiered" the way California and the EU do?
+
Colorado’s law has no compute or revenue threshold anywhere in it. It regulates by use case — whether an automated decision-making system is a substantial factor in a "consequential decision" like employment, housing, or credit — not by the size or training scale of the model itself. That is a fundamentally different regulatory mechanism from a compute-gated tier, even though both are sometimes loosely described as "risk-based."
Why does this matter for research administration?
+
Two rows in this comparison land directly on university administrative offices. The EU AI Act's Annex III high-risk list names "education and vocational training" as one of its eight categories, covering AI systems used to determine admission, evaluate learning outcomes, or monitor prohibited behaviour during tests — squarely reaching admissions-scoring, automated-grading, and remote-proctoring tools at any university with EU campuses or EU-resident applicants. Colorado's ADMT framework reaches the same functions domestically: its "consequential decision" trigger explicitly names "education" and "employment" alongside housing and credit.
Going deeper







