Skip to main content
v2026.11,858 entries · CC-BY 4.0

AI Regulations Around the World: A Jurisdiction Map

A jurisdiction-by-jurisdiction map of AI regulation: the EU AI Act, US federal and state law (California, New York, Colorado, Texas, Utah), China, and the international summit/coordination track — each linking to CASRAI’s deep-dive guide.

Written and maintained by CASRAI Editorial Board

Last updated

Why a fragmented AI regulatory landscape matters

There is no single “AI law.” A compliance team building or deploying a frontier AI model today has to track a patchwork of binding statutes, voluntary codes, and international declarations that overlap in subject matter but differ — often sharply — in who they cover, what they require, and when they bite. The European Union regulates by risk category. California and New York regulate by compute threshold. Colorado regulates by use case. Texas regulates by intent. None of these frameworks defer to each other, and several are moving targets: Colorado’s original AI Act was repealed and reenacted before it ever took effect, and the EU AI Act’s high-risk deadlines have already been amended once by the 2026 AI Omnibus.

This page is a map, not a manual. Each section below covers one jurisdiction or coordination body in a few sentences — scope, who it applies to, and the effective date where one exists — and links out to CASRAI’s deep-dive guide or comparison for the full detail. If you’re building a compliance program that has to satisfy more than one of these at once, start with the jurisdiction closest to a binding deadline and work outward.

European Union

The EU AI Act is the most comprehensive framework in force, regulating AI systems by risk tier rather than by developer size or compute. Two live compliance tracks matter most right now: the General-Purpose AI (GPAI) Code of Practice, a voluntary-but-favored mechanism that creates a presumption of conformity under Article 53(4) for signatories, and the high-risk system obligations, whose deadlines were pushed by the 2026 AI Omnibus to 2 December 2027 (Annex III systems) and 2 August 2028 (Annex I systems).

United States — federal

There is no binding federal AI statute. The closest thing to a federal position is the White House’s 2022 Blueprint for an AI Bill of Rights — five non-binding principles for automated systems that carry no enforcement mechanism of their own, but that shaped the language later state laws borrowed. In the absence of federal legislation, the state laws below are where the actual binding obligations sit.

United States — states

Five states have live or imminent AI-specific statutes, and no two use the same trigger. California and New York regulate frontier models by compute threshold; Colorado regulates any automated system, however small, that materially influences a consequential decision about a person; Texas bans specific uses by intent rather than regulating model scale or decision type; Utah is narrower still, largely a disclosure requirement.

State Law Trigger Effective / enforcement date
California SB 53 (Transparency in Frontier AI Act) Compute threshold (frontier models) In effect
New York RAISE Act Compute threshold (frontier models) 72-hour Critical Safety Incident reporting to DFS
Colorado AI Act (reenacted as SB 26-189) Use case (consequential automated decisions) January 1, 2027
Texas TRAIGA (HB 149) Intent (specific banned uses) January 1, 2026
Utah AI Policy Act Disclosure-focused, narrower scope In effect

China

China’s Cyberspace Administration (CAC), jointly with six other central agencies, issued the Interim Measures for the Management of Generative AI Services on July 10, 2023, effective August 15, 2023. It applies to organizations and individuals that use generative AI to provide public-facing content-generating services — text, images, audio, video — within China, and it explicitly excludes R&D that isn’t offered as a public service. It’s a narrower, service-facing rule rather than a general-purpose AI-safety statute, which is why it sits alongside rather than in place of China’s broader cybersecurity and data-export regime. This summary is sourced directly from CAC’s own published notice; for the full picture — including the 2025 Measures for Labeling of AI-Generated Synthetic Content and where a national AI Law currently stands — see CASRAI’s dedicated deep-dive on China’s AI regulatory program.

Other national frameworks

Beyond the EU, the US, and China, six more jurisdictions each have a real, distinct approach worth knowing before assuming any one model is the default — several are voluntary where the EU and US states are binding, and one (Canada) never became law at all.

International coordination

Outside binding national law, a parallel track of summits, voluntary pledges, and coordination bodies has emerged since the first AI Safety Summit at Bletchley Park in November 2023. None of these are enforceable in the way a statute is, but several — especially the Seoul Commitments — are being used as the de facto baseline that binding laws like SB 53 and the RAISE Act now reference.

How CASRAI tracks ongoing changes

This landscape moves fast enough that any static snapshot goes stale within months — Colorado’s law was rewritten before taking effect, and the EU’s high-risk deadlines have already shifted once. CASRAI’s frontier-ai-safety content cluster follows each jurisdiction’s deep dive individually rather than trying to keep one page current on everything, and NIKOLAI, CASRAI’s structured-metadata initiative, is building out elements like accountable decision-makers (N9) that map directly onto what these statutes require in practice. Bookmark the jurisdiction pages linked above rather than this overview if you need to track a specific deadline — they’re the ones that get updated when a law changes.

Frequently asked questions

When did the EU AI Act actually take effect?

In stages, not all at once. The Act entered into force on 1 August 2024, but no obligations applied yet at that point. Prohibited practices — things like social-scoring systems and certain biometric uses — became applicable on 2 February 2025, and obligations for general-purpose AI (GPAI) model providers followed on 2 August 2025. The high-risk system deadlines came later still, and those are the ones the 2026 AI Omnibus moved: 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, both covered above. Whether the Act currently binds a given AI system depends on which of these dates its category falls under, not on one effective date for the whole Act.

Does the EU AI Act apply to AI companies based outside the EU?

Yes. Under Article 2(1)(c), the Act applies to providers and deployers established in a third country whenever the output of their AI system is used in the Union — where a company is headquartered doesn’t exempt it. A US-based lab offering a model to users in the EU is covered on the same terms as an EU-based one.

Do any of these laws apply directly to frontier labs like OpenAI, Anthropic, or Google DeepMind?

Yes — the compute-threshold laws are built specifically to catch companies training models at that scale. California SB 53 and New York’s RAISE Act both define coverage by training compute (more than 1026 operations), not by what the model is used for, and SB 53’s heavier obligations attach once a frontier developer’s annual revenue with affiliates passes $500 million — a bar the major frontier labs clear. In the EU, any provider placing a general-purpose AI model on the EU market owes GPAI obligations under the AI Act regardless of company size, and a model trained above 1025 cumulative FLOPs triggers an additional systemic-risk presumption under Article 51. See California SB 53 vs Colorado AI Act vs New York RAISE Act for how the thresholds compare.

Which came first — the EU AI Act or China’s AI regulation?

It depends what’s being compared. China’s Interim Measures for the Management of Generative AI Services took effect first, on 15 August 2023 — about a year before the EU AI Act entered into force on 1 August 2024. But China’s rule only covers public-facing generative-AI services, not AI systems generally. The EU AI Act regulates by risk category across sectors, which is the basis for calling it the first comprehensive AI law — a claim about scope, not about which rule took effect earliest.

Why This Matters for Research Administration

University research-security offices already have a federally mandated reason to track a jurisdiction map that looks almost exactly like this one. Under NSPM-33, institutions receiving more than $50 million a year in federal research funding must certify they operate a research security program, and NSF’s own implementation requires annual Foreign Financial Disclosure Reports for gifts or contracts of $50,000 or more from a foreign source, plus PI-level certification against participation in a Malign Foreign Talent Recruitment Program. A research-security officer evaluating a proposed AI-related collaboration with a partner in the EU, China, or South Korea needs to know which regime governs that partner’s side of the work, for the same reason a compliance team building a global AI product does.

Related reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about AI Regulations Around the World: A Jurisdiction Map

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.