Written and maintained by CASRAI Editorial Board
Last updated
Why a fragmented AI regulatory landscape matters
There is no single “AI law.” A compliance team building or deploying a frontier AI model today has to track a patchwork of binding statutes, voluntary codes, and international declarations that overlap in subject matter but differ — often sharply — in who they cover, what they require, and when they bite. The European Union regulates by risk category. California and New York regulate by compute threshold. Colorado regulates by use case. Texas regulates by intent. None of these frameworks defer to each other, and several are moving targets: Colorado’s original AI Act was repealed and reenacted before it ever took effect, and the EU AI Act’s high-risk deadlines have already been amended once by the 2026 AI Omnibus.
This page is a map, not a manual. Each section below covers one jurisdiction or coordination body in a few sentences — scope, who it applies to, and the effective date where one exists — and links out to CASRAI’s deep-dive guide or comparison for the full detail. If you’re building a compliance program that has to satisfy more than one of these at once, start with the jurisdiction closest to a binding deadline and work outward.
European Union
The EU AI Act is the most comprehensive framework in force, regulating AI systems by risk tier rather than by developer size or compute. Two live compliance tracks matter most right now: the General-Purpose AI (GPAI) Code of Practice, a voluntary-but-favored mechanism that creates a presumption of conformity under Article 53(4) for signatories, and the high-risk system obligations, whose deadlines were pushed by the 2026 AI Omnibus to 2 December 2027 (Annex III systems) and 2 August 2028 (Annex I systems).
- GPAI Code of Practice, its three chapters, and which labs signed: The EU AI Act GPAI Code of Practice
- Deadline-by-deadline compliance checklist for high-risk systems: EU AI Act High-Risk System Compliance Checklist
- How the EU’s disclosure-based model differs from California’s binding-framework model: EU AI Act vs California SB 53
United States — federal
There is no binding federal AI statute. The closest thing to a federal position is the White House’s 2022 Blueprint for an AI Bill of Rights — five non-binding principles for automated systems that carry no enforcement mechanism of their own, but that shaped the language later state laws borrowed. In the absence of federal legislation, the state laws below are where the actual binding obligations sit.
- What the Blueprint says, and its non-binding status relative to state law: The Blueprint for an AI Bill of Rights
United States — states
Five states have live or imminent AI-specific statutes, and no two use the same trigger. California and New York regulate frontier models by compute threshold; Colorado regulates any automated system, however small, that materially influences a consequential decision about a person; Texas bans specific uses by intent rather than regulating model scale or decision type; Utah is narrower still, largely a disclosure requirement.
| State | Law | Trigger | Effective / enforcement date |
|---|---|---|---|
| California | SB 53 (Transparency in Frontier AI Act) | Compute threshold (frontier models) | In effect |
| New York | RAISE Act | Compute threshold (frontier models) | 72-hour Critical Safety Incident reporting to DFS |
| Colorado | AI Act (reenacted as SB 26-189) | Use case (consequential automated decisions) | January 1, 2027 |
| Texas | TRAIGA (HB 149) | Intent (specific banned uses) | January 1, 2026 |
| Utah | AI Policy Act | Disclosure-focused, narrower scope | In effect |
- Side-by-side on triggers, requirements, and dates: California SB 53 vs Colorado AI Act vs New York RAISE Act
- What SB 53 actually requires of accountable decision-makers: Accountable Decision-Makers Under SB 53
- New York’s tighter 72-hour incident-reporting window compared to SB 53’s 15 days: New York RAISE Act: What It Requires
- Colorado’s repeal-and-reenactment history and the real 2027 enforcement date: The Colorado AI Act
- Texas’s intent-based bans versus Colorado’s use-case model: The Texas Responsible AI Governance Act (TRAIGA)
- Utah’s narrower, disclosure-focused scope: The Utah AI Policy Act
China
China’s Cyberspace Administration (CAC), jointly with six other central agencies, issued the Interim Measures for the Management of Generative AI Services on July 10, 2023, effective August 15, 2023. It applies to organizations and individuals that use generative AI to provide public-facing content-generating services — text, images, audio, video — within China, and it explicitly excludes R&D that isn’t offered as a public service. It’s a narrower, service-facing rule rather than a general-purpose AI-safety statute, which is why it sits alongside rather than in place of China’s broader cybersecurity and data-export regime. This summary is sourced directly from CAC’s own published notice; for the full picture — including the 2025 Measures for Labeling of AI-Generated Synthetic Content and where a national AI Law currently stands — see CASRAI’s dedicated deep-dive on China’s AI regulatory program.
Other national frameworks
Beyond the EU, the US, and China, six more jurisdictions each have a real, distinct approach worth knowing before assuming any one model is the default — several are voluntary where the EU and US states are binding, and one (Canada) never became law at all.
- United Kingdom — voluntary and sector-led rather than a new statute: five cross-sector principles that existing regulators (ICO, MHRA, FCA, and others) apply within their own remit, with no central AI regulator and no date set for any future statutory duty. The UK’s AI White Paper: A Regulatory Framework Without a Regulator
- Japan — binding as a statute, but the AI Promotion Act carries no penalty provision at all; the only lever is non-binding administrative guidance, a genuinely different model from every hard-law jurisdiction above. Japan’s AI Law Has No Penalties — and a Live Test Case
- South Korea — the AI Basic Act has been in force since January 2026, administered by MSIT (Korea’s Ministry of Science and ICT), with obligations attaching to systems classified “high-impact” or generative. Korea’s AI Basic Act: What Took Effect in January 2026
- Canada — the Artificial Intelligence and Data Act (Bill C-27) would have created a risk-tiered regime under a new AI and Data Commissioner, but it died on prorogation in January 2025 before ever taking effect — a real near-miss, not live law. What AIDA Would Have Required — and Why It Died
- Singapore — a voluntary-framework approach run by IMDA and the AI Verify Foundation, with separate Model AI Governance Frameworks for generative AI and, more recently, for agentic AI. Singapore’s Model AI Governance Framework for Generative AI and Singapore’s Model AI Governance Framework for Agentic AI
- India — MeitY’s AI governance guidelines take a similarly non-binding approach, leaning on existing law rather than a new AI-specific statute. India’s AI Governance Guidelines Explained
International coordination
Outside binding national law, a parallel track of summits, voluntary pledges, and coordination bodies has emerged since the first AI Safety Summit at Bletchley Park in November 2023. None of these are enforceable in the way a statute is, but several — especially the Seoul Commitments — are being used as the de facto baseline that binding laws like SB 53 and the RAISE Act now reference.
- The independent, Bengio-chaired scientific baseline commissioned after Bletchley: International AI Safety Report 2026
- How the first two summit outputs differ — Bletchley’s single joint declaration versus Seoul’s split into a government declaration and a separate industry-commitments text: Bletchley Declaration vs Seoul Declaration
- The 20 signatories to the voluntary industry pledge and what each committed to: Seoul Frontier AI Safety Commitments
- The body coordinating national AI safety institutes (CAISI, UK AISI, and others), now renamed NAAIMES: The International AI Safety Institute Network
How CASRAI tracks ongoing changes
This landscape moves fast enough that any static snapshot goes stale within months — Colorado’s law was rewritten before taking effect, and the EU’s high-risk deadlines have already shifted once. CASRAI’s frontier-ai-safety content cluster follows each jurisdiction’s deep dive individually rather than trying to keep one page current on everything, and NIKOLAI, CASRAI’s structured-metadata initiative, is building out elements like accountable decision-makers (N9) that map directly onto what these statutes require in practice. Bookmark the jurisdiction pages linked above rather than this overview if you need to track a specific deadline — they’re the ones that get updated when a law changes.
Frequently asked questions
When did the EU AI Act actually take effect?
In stages, not all at once. The Act entered into force on 1 August 2024, but no obligations applied yet at that point. Prohibited practices — things like social-scoring systems and certain biometric uses — became applicable on 2 February 2025, and obligations for general-purpose AI (GPAI) model providers followed on 2 August 2025. The high-risk system deadlines came later still, and those are the ones the 2026 AI Omnibus moved: 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, both covered above. Whether the Act currently binds a given AI system depends on which of these dates its category falls under, not on one effective date for the whole Act.
Does the EU AI Act apply to AI companies based outside the EU?
Yes. Under Article 2(1)(c), the Act applies to providers and deployers established in a third country whenever the output of their AI system is used in the Union — where a company is headquartered doesn’t exempt it. A US-based lab offering a model to users in the EU is covered on the same terms as an EU-based one.
Do any of these laws apply directly to frontier labs like OpenAI, Anthropic, or Google DeepMind?
Yes — the compute-threshold laws are built specifically to catch companies training models at that scale. California SB 53 and New York’s RAISE Act both define coverage by training compute (more than 1026 operations), not by what the model is used for, and SB 53’s heavier obligations attach once a frontier developer’s annual revenue with affiliates passes $500 million — a bar the major frontier labs clear. In the EU, any provider placing a general-purpose AI model on the EU market owes GPAI obligations under the AI Act regardless of company size, and a model trained above 1025 cumulative FLOPs triggers an additional systemic-risk presumption under Article 51. See California SB 53 vs Colorado AI Act vs New York RAISE Act for how the thresholds compare.
Which came first — the EU AI Act or China’s AI regulation?
It depends what’s being compared. China’s Interim Measures for the Management of Generative AI Services took effect first, on 15 August 2023 — about a year before the EU AI Act entered into force on 1 August 2024. But China’s rule only covers public-facing generative-AI services, not AI systems generally. The EU AI Act regulates by risk category across sectors, which is the basis for calling it the first comprehensive AI law — a claim about scope, not about which rule took effect earliest.
Why This Matters for Research Administration
University research-security offices already have a federally mandated reason to track a jurisdiction map that looks almost exactly like this one. Under NSPM-33, institutions receiving more than $50 million a year in federal research funding must certify they operate a research security program, and NSF’s own implementation requires annual Foreign Financial Disclosure Reports for gifts or contracts of $50,000 or more from a foreign source, plus PI-level certification against participation in a Malign Foreign Talent Recruitment Program. A research-security officer evaluating a proposed AI-related collaboration with a partner in the EU, China, or South Korea needs to know which regime governs that partner’s side of the work, for the same reason a compliance team building a global AI product does.
Related reading
- Middle East and Africa: AI Governance Strategies, Not Laws
- The UN Global Dialogue on AI Governance
- The UK’s AI Code of Practice Regulations 2026
- AI and Elections: The State Disclosure-Law Landscape
- How Federal Financial Regulators Are Actually Treating Frontier AI
- AI in the Power Grid: CISA’s OT guidance
- Untangling the US AI safety bills
- Five Ways to Govern Frontier AI








