
AI governance is no longer an EU story. Binding AI rules now apply across Europe, Asia and North America, and the calendars keep moving. In July 2026 the EU pushed its high-risk deadlines to December 2027, days before they were due. Meanwhile, Asia-Pacific governments brought framework AI laws into force, US states switched on their own rules, and privacy and anti-discrimination law kept reaching AI without waiting for new statutes.
This map is for organizations that deploy AI, not the companies that train frontier models. Dates show when obligations apply, sector rules are summarized, and the unit that matters is the use case, not the model: a hiring screen and a marketing draft carry very different duties, even on the same model.
The timeline: what is in force, and what is coming
Most of the rules below took effect in 2026, and the next wave runs through 2028.

Everything left of the dashed line already applies; the shaded side is what is coming. The tables below carry the detail for each date.
Already in force
| Date | Jurisdiction | What applies to deployers |
|---|---|---|
| Feb. 2, 2025 | European Union | AI Act: prohibited practices and AI literacy |
| Sept. 1, 2025 | China | Labeling Measures: visible and invisible labels on AI content |
| Oct. 10, 2025 | Italy | Law 132/2025: worker notice, parental consent under 14 |
| Jan. 1, 2026 | Texas | HB 149 (TRAIGA): prohibited AI uses, government AI disclosure |
| Jan. 1, 2026 | Illinois | Public Act 103-0804: no discriminatory AI in employment, worker notice |
| Jan. 1, 2026 | California | CPPA regulations take effect; SB 243 companion chatbot duties |
| Jan. 1, 2026 | Ontario | Employment Standards Act: AI disclosure in job postings, 25+ employees |
| Jan. 14, 2026 | Taiwan | AI Basic Act: principles now, sector rules to follow |
| Jan. 22, 2026 | South Korea | AI Basic Act: high-impact AI duties, generative AI labeling |
| Feb. 5, 2026 | United Kingdom | Data (Use and Access) Act, s. 80: new automated decision rules and safeguards |
| Feb. 20, 2026 | India | IT Rules amendment: labels and provenance for synthetic media |
| March 1, 2026 | Vietnam | Law on AI: risk classification, labeling, deployer duties |
| July 15, 2026 | China | Anthropomorphic AI Measures: companion and emotional-support services |
| Aug. 2, 2026 | European Union | AI Act, Article 50: AI interaction disclosure, deepfake labels |
Coming next
| Date | Jurisdiction | What applies to deployers |
|---|---|---|
| Dec. 10, 2026 | Australia | Privacy Act, APP 1.7 to 1.9: disclose automated decisions in privacy policies |
| Jan. 1, 2027 | Colorado | SB 26-189: pre-use notice, adverse-outcome explanation, human review |
| Jan. 1, 2027 | California | ADMT duties for significant decisions: pre-use notice, opt-out, access |
| Early 2027 | South Korea | Ministry’s grace period on fines expected to end |
| March 1, 2027 | Vietnam | Existing systems must comply; Sept. 1, 2027 for health, education and finance |
| May 1, 2027 | Canada | OSFI Guideline E-23: model risk management, including AI, for federal financial institutions |
| Dec. 2, 2027 | European Union | Digital Omnibus: high-risk rules for hiring, credit, education, essential services |
| Jan. 14, 2028 | Taiwan | Deadline to align national laws with the AI Basic Act |
| Aug. 2, 2028 | European Union | High-risk rules for AI in regulated products, such as medical devices |
On the horizon, no date yet
- Brazil: PL 2338/2023 awaits a vote in the Chamber of Deputies.
- Council of Europe: the Framework Convention on AI needs five ratifications to enter into force.
What the map shows
Europe sets the frame, but it is not alone. The EU’s Digital Omnibus deferred the high-risk regime rather than dismantling it, and Article 50 transparency duties already apply. Italy layered a national AI law on top of the EU Act, and the UK rewrote its automated decision rules instead of passing an AI statute.
Asia-Pacific moved fastest in 2026. South Korea, Taiwan and Vietnam all brought framework AI laws into force in the first quarter. China keeps adding targeted measures, most recently for companion AI. India regulates synthetic media through platform rules, and Japan has chosen to influence rather than regulate, with an AI Promotion Act that carries no penalties.
The Americas regulate without a federal AI statute. Executive Order 14365 is pressure, not preemption: state laws remain enforceable until a court or Congress says otherwise. Colorado is the cautionary tale. Its first comprehensive AI law was delayed once and then replaced before it bound anyone, so a program built to one statute carries repeal risk as well as deadline risk. Canada and Brazil still regulate largely through existing law, and Brazil’s data protection law already gives people a right to review solely automated decisions.
Sector rules, in brief
Children and minors. Companion chatbots are the main target. New York and California already require operators to disclose that users are talking to AI and to run self-harm crisis protocols, and more states follow in 2027. China’s companion AI measures and Italy’s under-14 consent rule point the same way: if an AI system can reach minors, age awareness, disclosure and crisis escalation are becoming baseline.
Health. The emerging rule is that AI may assist but may not decide alone or impersonate a clinician. US states are requiring patient disclosure, human review of insurer coverage denials and limits on AI therapy. Abroad, health is treated as high-risk or high-impact almost everywhere, while HIPAA, GDPR and national health privacy laws still govern the data.
Employment. Hiring is the most consistently regulated AI use case in the world, covered by the EU, South Korea, Illinois, Colorado, California, New York City and Ontario. The common requirements are notice, testing for discriminatory outcomes and a path to human review.
One control set, many frameworks
Across every jurisdiction above, the same five expectations recur: know which AI you run, tell people when it affects them, assess the high-stakes uses, keep a human able to intervene, and prove the controls operated. The deadlines differ. The controls mostly do not.
That is why Airia treats framework support and mapping as the core of AI governance, not an add-on. The platform carries regulatory content as structured, versioned frameworks, including the EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, GDPR, HIPAA, California’s ADMT regulations, Texas TRAIGA, Colorado SB 26-189, Singapore’s Model AI Governance Framework and Australia’s Privacy Act. In practice, that means:
- One control, many obligations. Each requirement maps to a common control layer, so a single pre-use notice, impact assessment or human-review path can satisfy overlapping duties across jurisdictions.
- Applicability by use case. Obligations attach to each AI use case based on its purpose, the jurisdictions it touches and your role, so teams see what applies to a system without reading every statute.
- Versioned frameworks. When a regulator moves a date, as the EU did in July, the change lands as a framework update, and the mapped controls and evidence carry forward.
- Evidence as a byproduct. Controls produce records as work happens, ready for auditors, customers and regulators, instead of being assembled the week before a review.
The global map will keep changing. A governance program built on mapped frameworks absorbs those changes instead of starting over.
A note on dates
Dates are current as of September 28, 2026 and reflect when obligations apply, not when laws passed. Links go to official legal texts. Several regimes phase in or depend on implementing rules, so confirm against the current text before relying on a single date. This post is general information, not legal advice.
Put these ideas to work.
Schedule a 30-minute walkthrough with our team.