Artificial Intelligence in Australia

Law / proposed law

Australia has not enacted a standalone, comprehensive AI Act or another generally applicable AI-specific statute equivalent to the European Union’s AI Act. The current Australian approach is to apply existing technology-neutral laws, sector-specific regulation, enforceable online-safety instruments, public-sector policy and voluntary responsible-AI guidance. Whether a rule applies turns on the use case, the data and parties involved, the sector, the deployment model and the system’s effects.

The National AI Plan, released in early December 2025, sets the Australian Government’s policy direction around three objectives: capturing the opportunity, spreading the benefits, and keeping Australians safe. For regulation, the Government’s stated preference is to build on existing legal and regulatory frameworks. Targeted intervention may still be considered where existing frameworks cannot adequately address a demonstrated risk.

On 15 July 2026, Prime Minister Anthony Albanese announced proposed Australian Standards for AI and the establishment of an Office of AI within the Department of the Prime Minister and Cabinet. The proposal is expected to be considered by National Cabinet in August 2026, with legislation expected in early 2027, and may result in a more targeted mandatory framework for aspects of AI regulation in Australia.

Existing laws potentially relevant to AI include the Privacy Act 1988 (Cth), the Australian Consumer Law, competition law, copyright and other intellectual-property laws, breach of confidence, contract law, defamation, anti-discrimination law, employment and workplace-surveillance law, work health and safety law, product-liability law, directors’ duties, criminal and cybercrime law, the Online Safety Act 2021 (Cth), the Security of Critical Infrastructure Act 2018 (Cth), administrative law, financial-services and prudential regulation, health and therapeutic-goods regulation, education law and state and territory privacy, health-records, surveillance and public-sector laws. The list is not exhaustive, and no single regime governs all AI activity.

AI.gov.au was published in May 2026 as the consolidated Australian Government portal for responsible-AI guidance, tools and resources. It is operated through the National AI Centre within the Department of Industry, Science and Resources.

Automated decision-making transparency under the Privacy Act

From 10 December 2026, an Australian Privacy Principle (APP) entity must include additional information in its privacy policy under APPs 1.7–1.9 where it has arranged for a computer program to make a decision, or to do a thing substantially and directly related to making a decision, that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about the individual is used in operating that program. The policy must describe the kinds of personal information used, the kinds of decisions made solely by those programs and the kinds of decisions for which those programs do something substantially and directly related to making the decision.

These are transparency obligations. They do not, by themselves, create a general right not to be subject to automated decision-making. The Office of the Australian Information Commissioner (OAIC) consulted on implementation guidance in May 2026; the final guidance should be checked before the provisions commence.

State and territory overlays

State and territory laws can be material, particularly for public-sector, health, education, law-enforcement, surveillance and workplace uses. Relevant overlays may include privacy and health-records statutes, information-sharing laws, surveillance-device and workplace-surveillance legislation, public-records requirements, anti-discrimination law and sector-specific governance duties.

Last modified 20 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Austria

Austria has not yet completed the transposition of the Product Liability Directive into its national legal framework.

Last modified 28 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

The Product Liability Directive has not been yet transposed into Belgian law. Belgium has until 9 December 2026 to formally transpose the new rules into national legislation.

Last modified 16 July 2026

Laws specifically addressing AI have not been introduced in Brazil yet. The Brazilian Federal Senate's Bill No. 2338 of 2023 (Brazilian AI Bill) seeking to legislate for the development, implementation, and responsible use of AI systems in Brazil was proposed on 3 May 2023 and is progressing through the legislation adoption process. The Brazilian AI Bill was approved by the Federal Senate on 10 December 2024 and has been passed to the Chamber of Deputies for analysis, where it is awaiting to be discussed, potentially amended and voted on. If approved, it will be submitted to be sanctioned by the President of the Republic. The proposal has been the subject of extensive debate with various entities in the technology sector, among the houses of the National Congress. Since April 2025, the Brazilian AI Bill is under review by the Special Committee of the Chamber of Deputies. However, it is not yet possible to predict when the Bill will be enacted into law. The Brazilian AI Bill emphasises the protection of fundamental rights and the implementation of safe and reliable AI systems, focusing on human centrality, respect for human rights and the support of democratic values. It also encourages innovation through regulatory sandboxes, allowing entities to experiment with AI technologies under specific conditions (draft Article 55).

Last modified 7 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Bulgaria

There is no proposed legislation or any legislation in force to regulate AI in Bulgaria yet. It remains to be seen how AI will be regulated at a national level.

With respect to the implementation of the Product Liability Directive (Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products) (Product Liability Directive) in Bulgaria, the Product Liability Directive has not yet been transposed into national legislation. On 23 January 2026, the Bulgarian government adopted Decision No 84/2026, by means of which it approved a legislative timeline for its transposition. Pursuant to this timetable, the Minister of Justice is required to prepare and submit a draft implementing law to the Council of Ministers by 16 September 2026. In turn, the Council of Ministers is then expected to review the draft by 23 September 2026, with the ultimate objective for the law to be adopted by the National Assembly by 20 November 2026 and, respectively, be notified to the European Commission within the transposition deadline prescribed by the Product Liability Directive.

Last modified 24 July 2026

AI-specific laws have not yet passed in Canada at the federal level. In June 2026, the federal government launched ‘AI for All’, Canada’s new national AI strategy, which sets out six pillars covering protecting Canada and democracy, empowering Canadians, powering prosperity, sovereign AI infrastructure, scaling Canadian AI, and international partnerships. It identifies five priority sectors: health and life sciences, energy and natural resources, transportation, agriculture, and manufacturing and robotics. The strategy is presented as a five-year plan, with ‘trust’ described as its ‘north star’ and a stated goal of increasing Canadian business AI adoption from 12% to 60% by 2034. While the strategy does not itself introduce new AI-specific legislation, it signals the government’s ongoing commitment to developing a comprehensive regulatory framework for AI.

An Artificial Intelligence and Data Act (AIDA) was proposed as part 3 of Bill C-27 in June 2022, with the stated purpose of regulating AI systems in interprovincial and international trade and prohibiting certain conduct that may result in serious harm. AIDA died on the order paper in January 2025 when Prime Minister Trudeau prorogued government. The bill faced criticism for being part of a sweeping privacy omnibus and for deferring key details to regulations, which limited parliamentary focus on AI-specific issues. AIDA had also drawn significant criticism from Canada’s technology sector as potentially more restrictive than the European Union’s Artificial Intelligence Act—an approach seen as untenable for a middle power seeking to attract and retain AI companies.

Perhaps in response, the 2026 ‘AI for All’ strategy does not signal any intention to reintroduce standalone AI legislation comparable to AIDA. Instead, AI-related risks are expected to be addressed through targeted legislation, including promised privacy modernisation (see Bill C-36 introduced 15 June 2026) and online safety (see Bill C-34 introduced 10 June 2026) legislation, rather than through a single comprehensive regulatory framework.

Although there is no AI-specific federal legislation, AI-related rules appear in provincial legislation and federal privacy law. At the provincial level:

  • Quebec’s Act respecting the protection of personal information in the private sector (as amended by ‘Law 25’) imposes transparency and disclosure obligations on organisations that use personal information to render a decision based exclusively on automated processing. Individuals may request information about the personal information used, the reasons for the decision, and their right to have the information corrected.
  • As of January 2026, Ontario’s Employment Standards Act, 2000 requires employers that advertise publicly-advertised job postings to disclose to applicants when they implement AI to screen, assess, or select applicants (see Ontario confirms new regulations addressing pay transparency and job posting requirements).
  • In November 2024, Ontario passed the Enhancing Digital Security and Trust Act, 2024 (EDSTA), establishing public sector transparency, accountability, and risk management frameworks for the use of AI. Regulations under EDSTA take effect on 1 July 2026. Ontario’s Responsible Use of Artificial Intelligence Directive, effective since December 2024, also sets requirements for AI risk management and transparency across Ontario ministries and provincial agencies.
  • British Columbia has appointed a Minister of State for Artificial Intelligence and New Technologies, with a mandate to engage on federal AI law and policy development and to promote AI adoption by BC businesses.
  • At the federal level, on 10 June 2026, the Government of Canada introduced Bill C-34, the Safe Social Media Act, for First Reading in the House of Commons. The bill proposes sweeping new legislation to regulate social media platforms, AI-powered chatbot services, and other online services operating in Canada. The bill’s centrepiece is a temporary prohibition on social media accounts for persons under age 16, backed by age-verification obligations. It also introduces broad content-moderation duties, new obligations specific to AI chatbot services (including crisis intervention requirements and a prohibition on chatbots posing as humans), and a new independent regulator, the Digital Safety Commission of Canada, with substantial investigatory and enforcement powers. If enacted, Bill C-34 would represent one of the first frameworks globally to treat chatbot services as a distinct statutory category with tailored duties.
Last modified 24 June 2026

To date, Chile has not adopted specific regulations regarding AI. However, on 7 May 2024, a bill to regulate artificial intelligence systems (Chilean AI Bill) was proposed by the government of President Boric. Later, the Government submitted indications on 19 August 2025, based on which the purpose of the law evolved towards regulating uses of AI systems, while still promoting the creation, development, innovation and implementation; adding an express focus on sustainable and ethical AI, which shall serve the people, respect democratic principles and rule of law. The government indications are:

  • Express references to the infrastructure needed for the use and development of AI systems;
  • Deadline for implementing the law would be extended to the fifth year after its publication;
  • Article 20 allowing public bodies with controlled test sites to give operators temporary, restricted and audited access to structured, interoperable and secure data, subject to privacy, access-to-information, digital government and cybersecurity rules; and
  • Article 22 extending support measures beyond smaller companies to civil society organisations that develop or use AI systems.

In addition to the AI Bill of Law, the following are the most relevant AI-related bills currently under discussion in Congress, which address AI regulation among electoral integrity, deepfakes and synthetic content, education, biomedical research, or criminal misuse of AI:

  • Bill No. 16821-19 – Regulates AI systems (7 May 2024). This is the broader AI bill that establishes a general regulatory framework for AI systems in Chile, including risk-based rules and governance mechanisms.
  • Bill No. 17112-19 – Establishes limits regarding the development of AI to protect fundamental human rights (3 September 2024). This bill is relevant due to its focus on rights-based limits to AI development and could overlap with, or influence, the broader risk-based framework.
  • Bill No. 17977-06 – Regulates the use of AI in electoral campaigns by amending the Constitutional Organic Law on Popular Votes and Scrutinies (10 November 2025). Its main impact would be on transparency and integrity of political communications and campaign materials.
  • Bill No. 17795-19 – Regulates the creation and dissemination of realistic digital imitations of a person’s image, body or voice generated through AI (21 August 2025). It is relevant for deepfakes, personality rights, consent and reputational harms.
  • Bill No. 17810-19 – States obligations for AI content generators and sanctions non-compliance (2 September 2025). It would affect transparency duties for AI-generated content and could impose compliance obligations on content generators.
  • Bill No. 17618-19 – Requires a clear and traceable label for AI-generated content (17 June 2025). It is relevant because it creates a labelling or traceability standard for synthetic content.
  • Bill No. 17982-19 – Promotes the ethical use of AI in biomedical research (25 November 2025). States research governance, ethics review and safeguards around sensitive health-related AI uses.
  • Bill No. 17808-07 – Increases penalties for certain offences against private and public life when committed using AI (2 September 2025). Its practical impact would be to consider AI-enabled privacy violations as more serious criminal conduct.
  • Bill No. 17307-07 – Criminalises the generation and dissemination of private or intimate images or facts created with AI tools (17 December 2024). It is relevant for non-consensual intimate deepfakes and AI-enabled digital sexual violence.
  • Bill No. 13928-07 – Criminalises and sanctions digital violence, including AI-related aspects (1 December 2020). Although this regulation is broader than AI, it remains relevant because it is in second constitutional stage and could interact with specific AI/deepfake initiatives.
  • Bill No. 16112-07 – Amends the Criminal Code regarding identity usurpation in the context of AI use (17 July 2023). It addresses AI-enabled impersonation as a specific criminal-law concern.
  • Bill No. 16021-07 – Amends the Criminal Code to include the use of AI in the commission of a crime as an aggravating circumstance (13 June 2023), increasing criminal exposure when AI is used to commit offences.
  • Bill No. 15935-07 – Amends the Criminal Code to sanction the misuse of AI (15 May 2023). It is relevant as an early criminal-law initiative aimed broadly at harmful or improper uses of AI.
Last modified 2 July 2026

There is no single comprehensive AI law in the People's Republic of China (PRC). Instead, rules relating to the use and deployment of AI are found in a number of specific laws, regulations and mandatory national standards that regulate different subcategories of AI technologies and services. These include:

  • The Interim Measures for the Management of Generative Artificial Intelligence Services (GenAI Measures), which came into force on 15 August 2023 and are the first piece of generative AI-specific regulation for the PRC, regulating the development and application of generative AI technology. The GenAI Measures apply to the use of generative AI technology to provide services that generate contents (including any texts, images, audios, and videos) to the 'public within the PRC' (which has a very wide interpretation). The GenAI Measures outline service providers' obligations in various areas, including model training, content management, service management and user protection.
  • The Administrative Provisions on Deep Synthesis in Internet-based Information Services (Deep Synthesis Provisions) came into force on 10 January 2023 and apply to the provision of internet-based information services using deep synthesis technologies within the PRC. Deep synthesis technology is broadly defined, and includes any technology that employs deep learning, virtual reality, or other algorithms that are synthetic or generative (such as text/Q&A generation, image generation and voice attribute editing). The Deep Synthesis Provisions impose compliance obligations on various players, including providers of deep synthesis services, providers of technical support for deep synthesis services and users of such services. Particularly, there is a requirement for deep synthesis service providers to verify the real identity of users (by way of mobile phone number, ID card number, unified social credit code or national online identity authentication services) before they can release the services to the users.
  • The Administrative Provisions on Recommendation Algorithms in Internet-based Information Services of the Cyberspace Administration of China came into force on 1 March 2022 (Recommendation Algorithms Provisions) and apply to any entity that uses recommendation algorithm technologies to provide internet-based information services within PRC. This includes the use of algorithm technologies, including generation and synthesis technology, personalised pushing technology and ranking and selection technology, etc., to provide users with information. The Recommendation Algorithms Provisions also emphasise the protection of the user. Service providers are required to inform users about the provision of algorithm services, including the principles behind them, their intended purposes and how they operate.
  • The Measures for the Labeling of Artificial Intelligence Generated and Synthesized Content (AIGC Labelling Measures) took effect on 1 September 2025. The AIGC Labelling Measures apply to online information service providers that offer AI generative and synthetic services. Such providers are required to add different types of explicit and/or implicit labels to AI-generated content based on contexts, and to restrict the dissemination of non-labelled content via their service platforms either by user terms or by implementing technical measures.
  • The mandatory national standard the Cybersecurity Technology—Labelling Method for Content Generated by Artificial Intelligence (AIGC Labelling Standard) took effect on 1 September 2025. The AIGC Labelling Standard implements the AIGC Labelling Measures and sets out detailed standards, specifications, and operational procedures for labelling AI-generated content.
  • The Interim Measures for the Administration of Humanised Artificial Intelligence Interactive Services were released by the CAC on 10 April 2026 and will take effect on 15 July 2026. The measures apply to AI services offered to the public in China that present simulated human personality traits, thinking patterns and communication styles, and interact with users emotionally through text, images, audio, video or other means. The measures have a particular focus on addressing psychological risks by requiring providers to identify user states, assess users’ emotions and their level of dependence on the service, warn users against excessive use and intervene when users show signs of addiction or extreme emotions. The measures also set content and conduct red lines, stating that services must not generate content that endangers national security, spreads rumours or promotes violence or obscenity. The measures also establish heightened protections for minors by categorically prohibiting service providers from offering virtual relatives, virtual companions, or other virtual intimate relationship services to any minor user. Service providers must make available a dedicated ‘minor mode’ offering customisable safety settings such as periodic reality reminders, usage time limits, and parental controls.
  • The Amendment to the Cybersecurity Law took effect on 1 January 2026. A general clause on AI is introduced, stating that the government will improve ethical norms for AI while strengthening AI risk monitoring and assessment and safety oversight — potentially paving the way for further AI regulations.
  • The Administrative Measures for Digital Virtual Avatars Information Services (Draft for Public Comments) were released by the CAC on 3 April 2026, with public comments sought until 6 May 2026. These measures apply to digital virtual avatar services offered to the public in China. It emphasises that service providers must protect personal information, the right to one’s likeness, the right to reputation, and intellectual property rights during processes such as modelling, image generation, and scene construction. Clear labels must be displayed on the interface where virtual avatars appear. The draft encourages industry self-regulation, innovation and adherence to social ethics. Additional sector-specific regulations may apply in sectors such as healthcare and finance.
  • The Trial Measures for Ethical Review and Service of Artificial Intelligence Technology were issued on 3 April 2026 by the Ministry of Industry and Information Technology (MIIT), in collaboration with ten government departments. These trial guidelines emphasise the need for technological innovation in AI ethics review and the implementation of technical measures to mitigate ethical risks associated with AI. Key review focuses include human well-being, fairness, justice, controllability and trustworthiness, while addressing specific issues such as training data selection criteria, algorithm rationality and measures to prevent bias and discrimination. The guidelines also promote the orderly open-sourcing of high-quality datasets, the development of risk management and auditing tools, and the encouragement of AI products that adhere to ethical standards and protect intellectual property rights.
  • The Implementation Guidelines for Promoting the Standardised Application and Innovative Development of AI Agents were jointly issued by the CAC, the National Development and Reform Commission (NDRC) and MIIT on 8 May 2026. These guidelines apply to intelligent agents (defined as autonomous systems with capabilities in perception, memory, decision-making and execution) integrating advanced technologies such as large language models. The guidelines emphasise safety, controllability, innovation-driven growth and application-oriented traction, outlining four major areas of focus: consolidating development foundations, ensuring safety and security, promoting application-driven traction across 19 identified scenarios, and fostering an innovation ecosystem. The initiative seeks to enhance technological infrastructure, establish standards and drive the application of intelligent agents in sectors such as scientific research and public services, while ensuring compliance with ethical standards and promoting collaboration.

During the 2025 National People’s Congress, several delegates proposed the drafting of a specific AI law to address emerging risks, encourage innovation and establish a more consistent AI governance system. In particular, the possibility of classifying AI services into different risk categories and regulating them accordingly has been discussed.

The State Council’s 2026 Legislative Work Plan, approved by the CPC Central Committee and issued on 12 May 2026, expressly addresses AI legislation, stating that the government will ‘improve the governance of artificial intelligence, accelerate comprehensive legislation for the healthy development of artificial intelligence, and expedite the improvement of legislation to protect common elements of artificial intelligence such as data, computing power, algorithms, intellectual property rights, network security, and supply chain security, as well as to regulate key application scenarios’. This signals that comprehensive AI legislation is now a formally recognised priority, however specific details and timelines are yet to be revealed.

 

Last modified 7 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Croatia

In January 2025, the ‘Draft Plan for the Harmonization of Croatian Legislation with the European Union Acquis for 2025’ was published. This document anticipated the adoption of an implementing law for the EU AI Act in 2025; however, the implementing law was not adopted in 2025.

The Plan for the Harmonization of Croatian Legislation with the European Union Acquis for 2026, adopted by the Croatian Parliament on 6 March 2026, again envisages the adoption of the implementing act for the EU AI Act in the course of 2026. As of the date of this update, the draft implementing law has not been adopted and has not yet entered parliamentary procedure.

In November 2025, amendments to the Criminal Code entered into force introducing a statutory definition of an ‘artificial intelligence system’ modelled on Article 3(1) of the EU AI Act, and a new criminal offence of endangering life and property by means of an artificial intelligence system.

The Product Liability Directive has been transposed into Croatian law by the Act on Amendments to the Civil Obligations Act, adopted by the Croatian Parliament on 19 June 2026. The provisions transposing the Product Liability Directive enter into force on 9 December 2026 and will apply to products placed on the market or put into service after that date, in line with the Directive.

Last modified 24 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Cyprus

Cyprus has commenced the requisite actions for the implementation of the EU AI Act, including the preparation of the relevant national legislation. 

Member States are required to transpose the Product Liability Directive (EU) 2024/2853 into national law by 9 December 2026. Cyprus has not yet transposed the Directive into law, nevertheless on 25 February 2026, the Consumer Protection Service published a draft law entitled the Liability for Defective Products Law of 2026 for public consultation. The consultation was open for comments until 26 March 2026.  

Last modified 22 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in the Czech Republic

Within the Czech Republic, the Product Liability Directive (PLD) has not yet been transposed. The PLD shall be implemented into Czech law as an amendment to Act No. 89/2012 Coll., the Civil Code, through Sections 2939 to 2942. The draft amendment was introduced for the first time in late 2025 and currently remains in the ongoing legislative process; the latest version of the amendment (from 10 April 2026) is still expected to be adopted by Parliament. The amendment is expected to enter into effect on 9 December 2026 in accordance with the PLD.

Another draft law currently in the legislative process — and therefore not yet transposed — is the new Czech Artificial Intelligence Act (Czech AI Act), which implements the EU AI Act into Czech law. The draft Act aims to establish the necessary institutional, procedural, and penalty mechanisms. These include harmonised rules for the deployment and operation of AI systems, transparency rules, as well as rules for market monitoring, supervisory, and enforcement of the AI Act. In addition, the draft establishes a regulatory sandbox for AI, which will support innovation and testing of AI technologies (in accordance with Article 57(1) of the EU AI Act). Both drafts have been prepared and introduced by the Ministry of Industry and Trade (MIT), which is responsible for the overall implementation of the EU AI Act and which will serve as the Central Liaison Office.

As far as the legal regulation of AI is concerned, Czech law regulates only for text data mining, following the introduction of exceptions to copyright law that allow for the legal implementation of rapid data analysis and processing. This is a transposition of Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market (DSM Directive), through Sections 39c and 39d of Act No. 121/2000 Coll. Both provisions are based entirely on the criteria and almost literal diction of the DSM Directive. Therefore, for example, the question of remuneration of authors (and other rights holders) has not yet been addressed. And, while authors may be able to opt-out of the exemption, this is likely to be possible only in cases where it is possible to exclude the opt-out by machine-readable means, such as through the use of metadata.

There is one higher court ruling on the issue of AI, in particular in the form of the judgment of the Municipal Court in Prague No. 10 C 13/2023-16, which states that ‘An image created by artificial intelligence does not constitute a work of authorship under Section 2 of the Copyright Act, as it does not meet the conceptual characteristics of a work of authorship, because it is not a unique result of the creative activity of a natural person - the author’.

Last modified 8 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Denmark

In Denmark, the primary rules governing AI are set out in the EU AI Act, which applies directly within the Danish legal framework without the need for national implementing legislation. Apart from that, Denmark has adopted Law no. 467 of 14 May 2025, which provides supplementary provisions to the EU AI Act, including the designation of national competent authorities and the establishment of oversight mechanisms. The law enters into force on 2 August 2025.

Last modified 21 July 2025

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Estonia

In Estonia, the Ministry of Justice and Digital Affairs has developed a draft law which intends to amend the Estonian Personal Data Protection Act so that the processing of personal data for scientific research purposes includes technological development, which also covers the development of artificial intelligence.

In addition, amendments to the Basic Schools and Upper Secondary Schools Act entered into force in January 2026. These amendments create a legal basis for the use of artificial intelligence applications in teaching and learning activities, including the processing of students’ personal data for that purpose, subject to data protection safeguards and deletion requirements.

As of July 2026, Directive (EU) 2024/2853 on liability for defective products has not yet been transposed into Estonian law. The Estonian Ministry of Justice and Digital Affairs has started the national transposition process and confirmed that the directive must be transposed by 9 December 2026. Although no official draft law has been made public, the Ministry has sent out a letter to the relevant ministries, authorities and other interested parties, outlining the planned amendments and asking for feedback.

Last modified 23 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Last modified 11 February 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Finland

Most AI-related rules in Finland originate from the EU's AI Act, owing to its direct applicability. However, some national laws have been proposed to supplement the Act. In general, the implementation in Finland is still in progress, but the Finnish Act on the Supervision of Certain AI Systems (1377/2025) entered into force on 1 January 2026. The Act establishes the national enforcement framework by designating the competent authorities responsible for supervising compliance with the AI Act, appointing the Finnish Transport and Communications Agency (Traficom) as the national single point of contact, and providing the authorities with powers to investigate infringements and impose administrative sanctions. The Act also integrates AI supervision into Finland's existing market surveillance system and establishes a sanctions board with authority to impose administrative fines for the most serious violations of the AI Act.

The second phase of implementation is still under legislative preparation and has not yet been submitted to Parliament. This proposal is intended to introduce national legislation to establish AI regulation testbeds, and a national register of high-risk AI systems related to critical infrastructure. Additionally, it would include other necessary provisions to implement the EU AI Regulation.

The new Product Liability Directive (EU) 2024/2853 has not yet been transposed into Finnish law - the legislative process is currently ongoing.

Last modified 24 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in France

In France, the main applicable rules related to AI consist in the EU AI Act as it is a text with direct application into the French legislative framework without need for transposition. In addition, the French Parliament has issued a few laws imposing specific rules when dealing with AI in certain cases, and France is developing its national framework required for the national implementation and enforcement of the EU AI Act.

Law no. 2023-451 of 9 June 2023 on the regulation of commercial influence on social networks (French Influencer Law) imposes requirements on influencers to include warning notes on images modified by AI.

Law no. 2024-449 of 21 May 2024 on the digital space (French Digital Space Law) introduces a new criminal offence for persons who publish deepfakes of other persons in a way that modifies their image and/or voice without their consent.

The Draft Law of 18 February 2026 containing various provisions for alignment with European Union law (DDADUE) is expected to designate the competent authorities responsible for the supervision and enforcement of the Regulation and establish the corresponding national enforcement framework.

The Product Liability Directive has not yet been transposed into French law. France is preparing the implementing measures and is participating in the European Commission's expert group on the transposition of the Directive. According to the French Government, consultations with stakeholders from the main affected sectors have been conducted as part of the preparation of the national implementing measures. Given the Directive's maximum harmonisation approach and the autonomous nature of the strict liability regime, a dedicated implementing instrument is envisaged. The transposition deadline remains 9 December 2026. Pending transposition, the existing French strict liability regime for defective products (Articles 1245 to 1245-17 of the French Civil Code, which implement Directive 85/374/EEC) remains applicable.

Last modified 20 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

AI compliance in Germany

Germany did not meet the EU AI Act’s 2 August 2025 deadline for putting in place its national implementing rules. This particularly concerns the designation of the competent national authorities responsible for monitoring AI compliance and for imposing penalties. The delay was largely due to the 2025 federal elections and the formation of a new government. The Federal Ministry for Digital Transformation and Government Modernisation (Bundesministerium für Digitales und Staatsmodernisierung) published a first draft implementing act in September 2025 and, following a consultation phase with the Federal States and industry associations, the Federal Government introduced a formal government bill in March 2026.

On 11 June 2026, the German Federal Parliament (Bundestag) passed the implementing act – the Act implementing the AI Regulation (Gesetz zur Durchführung der Verordnung über künstliche Intelligenz), the core element of which (Article 1) is the AI Market Surveillance and Innovation Promotion Act (KI-Marktüberwachungs- und InnovationsförderungsgesetzKI-MIG). This Act was approved by the Federal Council (Bundesrat) in its session on 10 July 2026. The law may now be signed and published. It will take effect on the day after its publication.

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

The German Federal Network Agency (BundesnetzagenturBNetzA) has already launched their ‘AI Service Desk’ in July 2025. This is a new advisory service aimed at giving companies practical guidance on the EU AI Act’s requirements. Its centrepiece, the interactive ‘AI Compliance Compass’, lets organisations run through a guided dialogue to check whether and to what extent the AI Act applies to their systems, including whether transparency duties apply or a system counts as high-risk or prohibited. The AI Service Desk also explains obligations that are already binding, such as the AI-literacy rule requiring every organisation using, providing, or developing AI systems to ensure adequate staff competence since February 2025, and points users to free training. BNetzA has been explicit that this is groundwork: they expect to take on a central role in implementing the EU AI Act in Germany and they are already carrying out preparatory work ahead of a formal mandate.

Last modified 17 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

AI compliance in Greece

In July 2026, Greece enacted the law titled ‘Implementing Measures for Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (the AI Act) – Amendments to Law 4961/2022 and Other Provisions’ (Government Gazette A' 114/20 July 2026, hereinafter the Greek AI Act Implementation Law or the Law). The new law establishes the national legal framework for the implementation of the AI Act in Greece, while simultaneously repealing Chapter B of Part A of Law 4961/2022, which had constituted the first legislative attempt to regulate issues relating to the development and use of artificial intelligence. It is also worth noting that, in Opinion No. 9/2026 on the draft Law, the Hellenic Data Protection Authority (HDPA) welcomed the proposed supervisory framework while stressing that the effective implementation of the AI Act would require adequate organisational, financial and human resources.

The Law establishes the institutional, supervisory and enforcement framework for the application of the AI Act in Greece and designates the competent national authorities responsible for market surveillance and regulatory oversight. It further establishes a dedicated coordination and expertise centre for artificial intelligence and provides mechanisms for the submission and handling of complaints relating to AI systems. In addition, the Law requires the registration of AI systems used by public sector entities and strengthens the monitoring of AI developments at national level. In addition, the Law provides for the establishment of an AI Regulatory Sandbox to support innovation and the testing of AI systems under regulatory supervision. However, at the time of writing, there is no official confirmation that the sandbox is operational. Taken together, these measures form the core of Greece's national AI governance framework and seek to ensure the effective implementation of the AI Act.

Furthermore, regarding the use of artificial intelligence systems in the educational process and the protection of personal data, Greece has adopted Joint Ministerial Decision No. 55909/Δ6 (Government Gazette B΄ 2639/12.05.2026) (the Decision). The Decision applies to all secondary schools in Greece and requires that AI systems be used solely as tools to support teaching and learning under human supervision. It prohibits, inter alia, the fully automated assessment of students or teachers, the profiling of students and educators, and the submission of AI-generated content as a substitute for students’ own work. In addition, the Decision imposes specific transparency, security and data protection obligations, including the conduct of prior impact assessments, the implementation of data minimisation measures, restrictions on the input of personal data into AI systems, mandatory training for teachers, awareness-raising activities for students, and safeguards against misinformation, algorithmic bias and harmful content.

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Product Liability Directive in Greece

Lastly, it should be noted that Greece has not yet transposed the revised Product Liability Directive into national law.

Last modified 24 July 2026

Laws specifically addressing AI have not yet been introduced in Hong Kong.

That said, the Government is actively reviewing whether current legislation is sufficient to cope with the development of AI, including through the establishment of an inter-departmental working group to review the existing legal framework for AI usage, with a view to, among others, considering the need for and feasibility of enacting bespoke legislation and implementing administrative measures.

Last modified 3 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Last modified 24 July 2025

India does not have a single codified statute regulating AI. Central laws frequently referred to or applied in the context of AI are discussed below.

  1. Information Technology Act, 2000 (IT Act), and Rules:
    • The IT Act, which pre-dates mainstream AI by several years, is India’s information technology law statute. It focuses on internet-based principles (such as electronic contracts, signatures and records), offences (such as unauthorised access, identity theft, cheating by impersonation and publication of obscene/sexually explicit material), intermediary liability and safe harbour, among others.
    • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules): These rules impose due-diligence obligations on intermediaries. Among other obligations, intermediaries are required to publish their rules, privacy policies and user agreements on their websites/apps and take reasonable steps to prevent users from engaging in unlawful activities, such as hosting, displaying, uploading or sharing obscene content, impersonating others, etc. Intermediaries are also obligated to take down unlawful content in a time-bound manner.
    • The IT Rules were amended in February 2026 to define ‘synthetically generated information’ (SGI) (which covers AI-generated works within its ambit). The amended rules imposed additional due diligence obligations on intermediaries, specifically in connection with SGI. They require intermediaries to deploy technical measures and tools such that users cannot create, publish or transmit SGI in violation of any law. The amended IT Rules also impose mandatory labelling and identification requirements (use of metadata, unique identifiers) to identify the source of SGI content created. Significant Social Media Intermediaries (i.e. those with over five million registered users) have to ensure that users declare SGI content, such content is appropriately labelled, and appropriate measures are used to verify such declarations. This obligation needs to be discharged before the content goes live on the platform.
    • The framework under the IT Act and IT Rules have been collectively used to tackle online harms, including those stemming from use of AI. The Ministry of Electronics and Information Technology (MeitY), India’s central authority for information technology, also issued advisories in December 2023 and March 2024, directing intermediaries to abide by the IT Act and the IT Rules, highlighting that its principles apply to issues such as online misinformation and AI-generated deepfakes. The March 2024 advisory urged platforms to ensure that their computer resources, including those using AI models, do not allow bias or discrimination. It also detailed requirements for labelling and metadata on AI-generated content. Additionally, it recommended that untested or unavailable AI models are appropriately labelled before being made available to users.
  1. Digital Personal Data Protection Act, 2023 (DPDPA): India’s privacy law, which is set to come into effect by May 2027, aims to protect the processing of personal data of individuals by giving them broad rights, including the right to consent to the processing of their data, and the ability to modify or withdraw any such consent. Once fully operational, the law will have implications for AI models, which often rely on large datasets for training and may scrape, collect or process personal data without obtaining the requisite consents, giving rise to potential privacy violations.
  2. (Proposed) Digital India Act (DIA): MeitY proposed the DIA as a successor to the IT Act, aimed at covering emerging technologies, online safety, cybersecurity and digital user rights. Early consultations in 2023 suggested it would place specific obligations on social media platforms, e-commerce entities and AI systems, with a particular focus on ‘high-risk’ AI. The DIA has not progressed since then, with limited information of its drafting progress or enactment in the public domain to

In addition to these central laws, sectoral regulators have issued sector-specific guidelines, advisories and voluntary frameworks to address AI in their respective domains. Some of these are discussed in the Regulatory guidance/voluntary codes section.

Last modified 13 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Ireland

In Ireland, the Product Liability Directive has not yet been implemented into law.

Last modified 23 July 2025

A comprehensive, cross‑sector AI statute has not yet been enacted in Israel. Instead, Israel has adopted a principle-based, pro-innovation and sector-specific approach to AI governance.

The Government’s professional policy paper ‘Israel’s Policy on Artificial Intelligence Regulation and Ethics’ (December 2023) (the 2023 AI Policy Paper) articulates cross‑cutting expectations for trustworthy AI (including accountability, transparency, fairness, safety and human oversight) and signals a gradual, risk‑based regulatory approach coordinated across ministries (available here, in Hebrew).

The 2023 AI Policy Paper recommends, among others, adopting a common set of responsible AI principles, largely based on the Organisation for Economic Co-operation and Development (OECD) AI Principles. These include growth and sustainable development, human-centric AI, non-discrimination, transparency and explainability, reliability, robustness, security, safety and accountability. Importantly, the AI Policy itself states that these principles are not legally binding on regulators or organisations; rather, they are intended to reflect considerations that should be taken into account in the development and use of AI and in drafting any regulation in this area.

Last modified 8 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

AI compliance in Italy

On 10 October 2025, the Italian Artificial Intelligence Law (Law No. 132/2025) (Italian AI Law) entered into force, completing the national AI regulatory framework and complementing the EU AI Act without introducing divergent definitions or obligations. The Italian AI Law consists of 28 articles and is grounded in the core principles of the EU AI Act, including the protection of fundamental rights, proportionality, safety, and transparency. Articles 3 and 4 set out the general principles applicable to all AI systems, notably human oversight, the prevention of discriminatory or harmful effects, and compliance with constitutional and fundamental rights, including the protection of personal data.

Unlike the EU AI Act, however, the Italian AI Law adopts a sector-specific regulatory approach rather than a general risk-based framework. In the healthcare sector (Article 7), AI systems can only support medical decision-making, may not determine access to services, and require patient notification, while full responsibility remains with medical professionals. Article 8 governs scientific research, permitting the processing of personal and sensitive data without consent for public-interest AI development, subject to prior notification to the Data Protection Authority, and allowing anonymisation or data synthetisation for research purposes. In line with the current obligations under Italian employment law, Article 11 requires employers to inform workers of the use of AI systems, while Article 12 establishes a National AI Observatory tasked with monitoring the impact of AI on employment and informing regulatory strategies. Intellectual professions (Article 13) are prohibited from fully delegating professional activities to AI systems and must ensure clear disclosure to clients. For public administration and justice (Articles 14–15), AI may be used solely as a decision-support tool and cannot replace human evaluation, alongside measures promoting training for responsible use. Finally, the Italian AI Law addresses intellectual property and enforcement issues. Article 25 protects works created by humans with AI assistance (provided that the work is a product of human intellectual labour) and permits text and data mining for AI training purposes. Procedural and criminal provisions assign exclusive jurisdiction for AI-related disputes to ordinary courts, introduce AI-related aggravating circumstances under the Italian Criminal Code, and criminalise the unlawful dissemination of deepfakes.

Notwithstanding the foregoing, it is important to note that Article 24 further grants the government broad delegated powers to adopt legislative decrees on sector-specific AI regulation, public administration, system deployment, and sanctions. Given the central role assigned to delegated legislation in specifying the concrete powers of the designated authorities, including the sanctioning powers provided for under the EU AI Act, several provisions remain contingent upon implementing measures. Consequently, economic operators must continue to rely primarily on the EU AI Act while closely monitoring the evolving Italian regulatory framework.

With regard to the Product Liability Directive (Directive (EU) 2024/2853), Italy has not transposed this.

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Last modified 7 August 2026

On 16 February 2024, the ruling party’s project team on the ‘Evolution and Implementation of AI’ released ‘the rough draft of the Basic Law for the Promotion of Responsible AI’. This rough draft of the AI Act intends to propose legal governance for frontier AI models. Frontier AI models are recognised as high-performance, general-purpose AI models capable of performing a wide variety of tasks and are as capable or more capable than today’s most advanced models. The AI Act seeks to minimise risks and maximise benefits through appropriate AI governance.

Subsequently, the Act on Promotion of Research and Development, and Utilization of AI-related Technology (AI Act) was enacted on 28 May 2025, and promulgated on 4 June 2025, with many of its provisions (except for certain sections) coming into force on the same day. The remaining provisions, including those concerning the establishment of the AI Strategy Headquarters, came into force on 1 September 2025, and the AI Act is now fully in force. While the AI Act primarily serves as a basic framework law targeting the national and local governments, it also sets forth responsibilities for AI-utilising business operators to proactively strive to improve the efficiency and sophistication of their business operations and to create new industries through the use of AI-related technologies, as well as to cooperate with measures implemented by national and local governments.

Separately, proposed amendments to the Act on the Protection of Personal Information may also affect AI development in Japan. The amendment bill reportedly includes measures to facilitate the use of data for AI development in certain cases where the data is used in a manner that does not identify individuals.

Following the full enforcement of the AI Act, the AI Strategy Headquarters was established as the government body responsible for promoting AI-related policy measures. The AI Act also provides for the formulation of an AI Basic Plan and guidelines concerning the appropriate research, development and utilisation of AI-related technologies.

The AI Basic Plan, which was adopted by the Japanese government on 23 December 2025, sets out the Japanese government’s basic policy for promoting the research, development and utilisation of AI-related technologies. It emphasises both the promotion of AI development and utilisation and the need to address AI-related risks, with a view to strengthening Japan’s AI competitiveness, improving productivity and addressing social challenges.

Last modified 29 June 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

AI compliance in Latvia

In Latvia, an Information Report (Information Report) has been prepared by the Ministry of Smart Administration and Regional Development on how the requirements of the EU AI Act may be implemented in Latvia. Most of the suggested amendments to existing laws and regulations specified in the Information Report are intended to give the competent authorities the power to monitor compliance with the EU AI Act. For example, amendments to the Cabinet of Ministers Regulations No. 309, “By-laws of the Health Inspectorate”, are planned to, in accordance with the Inspectorates competences, define the functions as the supervisory authority in market surveillance.

The Law on the Artificial Intelligence Centre entered into force on 20 March 2025. This law establishes the Artificial Intelligence Centre in Latvia with the aim of fostering cooperation between the public and private sectors and higher education institutions in the field of artificial intelligence. The Centre will coordinate innovation projects, provide consultations, promote public competence, and ensure the ethical and secure use of AI. Its operations will be financed through the state budget, donations, and other sources, and it will also serve as a platform for a special regulatory environment for testing AI systems. The law also sets out strict conditions for the processing of personal data within this environment.

The Ministry of Smart Administration and Regional Development has prepared a draft Cabinet Regulation entitled "Procedures by which the Artificial Intelligence Centre, in cooperation with competent institutions, organizes the special regulatory environment, and procedures for the processing of personal data within the framework of the special regulatory environment". The draft Cabinet Regulation establishes the procedures by which the Artificial Intelligence Centre, in cooperation with competent institutions, organizes a special regulatory environment for the development, testing, and deployment of artificial intelligence (AI) systems, as well as the procedures for processing personal data within this environment. These regulations are necessary to ensure the safe, innovative, and socially responsible implementation of AI solutions in Latvia, while fulfilling the mandate set out in the Law on the Artificial Intelligence Centre, which authorizes the Cabinet to regulate the functioning of the regulatory environment, the involvement of competent institutions, and the conditions for data processing.

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Last modified 14 July 2025

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

EU AI Act: While Law No. XV-105 amending the Law on Technology and Innovation and Law No. XV-106 amending the Law on Information Society Services have already established Lithuania’s principal EU AI Act authorities and related institutional arrangements, Lithuania’s broader national implementation framework is expected to be established through a dedicated Law on the Implementation of the European Union Artificial Intelligence Act. The relevant Draft Law No. XVP-1564, together with related draft amendments, was submitted to the Seimas in May 2026 and remained pending as at 7 August 2026. Once adopted, the legislation is intended to provide the principal national framework for enforcing the EU AI Act, including rules on supervisory powers, procedures, penalties, and other enforcement measures.

Product Liability Directive: Lithuania has adopted Law No. XV-1080 of 25 June 2026 amending Section Four of Chapter XXII, Part III of Book Six, and the Annex to the Lithuanian Civil Code and implemented Directive (EU) 2024/2853 (Product Liability Directive) requirements. The law is scheduled to enter into force on 9 December 2026.

Last modified 7 August 2025

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Luxembourg

On 23 December 2024, the Luxembourg government introduced Bill No. 8476 (Luxembourg Bill), which is still in a very early stage but represents a significant step toward aligning national legislation with the EU AI Act.

Last modified 23 July 2025

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

AI compliance in Malta

In Malta, the Artificial Intelligence Regulations (Subsidiary Legislation 591.05) and the Artificial Intelligence (Designation of The Information and Data Protection Commissioner for the Purposes of Regulation (EU) 2024/1689) Regulations (Subsidiary Legislation 586.14) implement the provisions of the EU AI Act. The Malta Digital Innovation Authority (MDIA) is the entity that is tasked with implementing the EU AI Act in Malta. The Malta Digital Innovation Authority Act (Chapter 591 of the Laws of Malta) serves as the legislation establishing the MDIA.

By contrast, the Product Liability Directive has yet to be transposed into Maltese law, with the transposition deadline falling on 9 December 2026.

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Last modified 24 July 2025

Laws specifically addressing AI have not been introduced in Mauritius yet.

The Government of Mauritius, through the Ministry of Information Technology, Communication and Innovation (MITCI) has published A Blueprint for Mauritius – A Bridge to the Future – Digital Transformation 2025-2029, dated May 2025 (Blueprint) as a strategic framework to guide the country’s digital transformation, including the development of AI governance structure.

The Blueprint announces the formulation of the Mauritius National Data Strategy (2025-2030) which inter alia aims at preparing Mauritius for a safe, trustworthy and ethical adoption of Artificial Intelligence.

The National Data Strategy will include:

  • Creation of a Data Management office
  • Adoption of a Data Governance Framework
  • Adoption of a Data Sharing Policy and Protocol
  • Adoption of a Data Retention Policy
  • Creation of a National Government Data Warehouse, which will in turn create:
    • Data Assurance
    • Data Sovereignty
    • Open Data and access to public information
    • Data Architecture and Harmonisation v. Data Usability
    • Data Literacy and Skills

This strategic direction is structured around four pillars and five enablers, which are as follows:

The Pillars:

  1. The Foundation: State of the Art Information Structure;
  2. Human Capital: Digital Skills for all;
  3. Economy: Innovation and private sector growth; and
  4. Planet: a Sustainable and resilient digital future.

The Enablers:

  1. Digital public infrastructure;
  2. Legal and regulatory reform;
  3. Institutional governance;
  4. Cyber resilience and trust; and
  5. Data governance and AI.

The four strategic pillars represent Mauritius’ core objectives for digital transformation across government, economy, society and infrastructure, while the five enablers provide the essential conditions that support the successful implementation of these pillars.

National AI Strategy and FAIR Guidelines

On 10 April 2026, Mauritius launched its National Artificial Intelligence Strategy and FAIR (Fair, Accountable, Inclusive and Responsible (FAIR Pillars)) Guidelines (FAIR Guidelines). The FAIR Guidelines are intended to help, through the FAIR Pillars, public institutions, private organisations, technopreneurs and other stakeholders understand what responsible AI use means in practice and how potential risks and impacts should be identified and managed.

The National AI Strategy provides a comprehensive roadmap to guide the transparent, safe and effective adoption of AI across priority sectors. The core objective is to leverage the potential of AI to significantly propel economic growth and enhance efficiency across various sectors of the economy and society.

 

Last modified 6 July 2026

Laws specifically addressing AI have not been introduced in Mexico yet. A draft bill to regulate AI (AI Bill) was presented to the Senate, by Ricardo Monreal Ávila, member of the Parliamentary Group of the MORENA Party, on 2 April 2024 aiming to create the first legal framework for artificial intelligence systems in Mexico, seeking to allow the country to take advantage of the benefits of using AI in various fields of application, whilst protecting the rights of third parties, users and the general public.

Article 1 of the AI Bill states that its objectives are to:

  • Regulate the development, marketing and use of artificial intelligence systems;
  • Ensure respect for the human rights of consumers and users and avoid any form of discrimination when using artificial intelligence systems;
  • Protect intellectual property rights; and
  • Facilitate the national development of artificial intelligence systems.

The AI Bill further aims to regulate AI applying a risk approach, classifying AI as either (i) unacceptable risk; (ii) high-risk; or (iii) low-risk. The AI Bill also provides that an authorisation must be obtained from the Federal Telecommunications Institute to be able to market such AI systems in Mexico.

To this date, the project is not expected to move forward during the remainder of 2026. The same situation applies to other projects that have tried to regulate AI without such a heavy regulatory burden.

Last modified 4 July 2026

Laws specifically addressing AI have not been introduced in Morocco yet.

There is no AI-specific law in force, and no published proposed law, although there have been discussions about drafts for over a year. Morocco’s approach to AI is, for the time being, driven by existing laws of general application rather than by AI-specific legislation.

A number of existing Moroccan laws apply to AI by virtue of their provisions and scope, even though they were not designed for AI. The most relevant are:

  • Data protection: Law No. 09-08 on the protection of individuals with regard to the processing of personal data (Law No. 09-08);
  • Intellectual property: Law No. 17-97 on the protection of industrial property (Law No. 17-97) and Law No. 2-00 on copyright and related rights (Law No. 2-00);
  • Cybercrime: Law No. 07-03 supplementing the penal code with respect to offences relating to automated data processing systems (Law No. 07-03); and
  • Cybersecurity: Law No. 05-20 on cybersecurity (Law No. 05-20).
Last modified 24 June 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in the Netherlands

In the Netherlands, the Product Liability Directive has not yet been implemented into Dutch law.

Last modified 23 July 2025

Laws specifically addressing AI have not been introduced in New Zealand, and, based on the current Government's recent policy decisions in respect of AI, New Zealand is unlikely to see any economy-wide specific AI legislative reforms in the foreseeable future. Instead, AI is regulated through existing technology-neutral laws, such as the Privacy Act 2020 (Privacy Act), consumer protection laws, and New Zealand's intellectual property and human rights legislation.

Last modified 8 July 2026

Laws specifically addressing AI have not yet been enacted in Nigeria. However, the Internet Code of Practice, 2026, which entered into force on 15 May 2026 and was issued by the Nigerian Communications Commission (NCC) under the Nigerian Communications Act, 2003, provides for AI and emerging technologies (see the Regulatory Guidance / Voluntary Codes section).

In February 2025, the Artificial Intelligence Management and Finance Institute (AIMFIN) (Establishment) Bill, 2025 (HB. 2063) was brought before the House of Representatives for first reading. In May 2025, another bill, the National Institute of Artificial Intelligence and Robotic Studies (Establishment) Bill, 2025 (HB.2243), was brought for first reading on the floor of the House of Representatives.

The National Digital Economy and E-Governance Bill, 2025, is currently in its final legislative stage in the Senate. The Bill seeks to provide a regulatory framework for the development, implementation, and responsible use of artificial intelligence systems and other emerging technologies. It also proposes to position the National Information Technology Development Agency (NITDA) as a ‘super-regulator’ for Nigeria's digital economy, with powers to classify AI systems by risk, mandate algorithmic transparency, and accredit AI auditors.

There are a number of Nigerian laws that, by virtue of their provisions and scope, indirectly apply to AI. These include laws on data protection, fundamental rights, intellectual property, employment, competition, consumer protection, and labour.

Last modified 2 July 2026

The Ministry of Digitalisation and Public Governance has issued a proposal for a law implementing the Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) into Norwegian law. The proposal was open for public hearing until 30 September 2025.

The proposed law is named ‘Artificial Intelligence Act’ or ‘Lov om kunstig intelligens’ in Norwegian (Norway AI Act) and will implement the EU AI Act in full. The law is expected to enter into force during 2027.

The new Product Liability Directive (Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products) (Product Liability Directive) has not yet been implemented in Norway. While EU Member States are required to transpose the Directive into national law by 9 December 2026, implementation in Norway will depend on its incorporation into the EEA Agreement and subsequent transposition into Norwegian law.

Last modified 5 August 2026

On 5 July 2023, Law No. 31814, Law Promoting the Use of Artificial Intelligence (AI Law) was published, which aims to promote and guarantee the ethical, sustainable, transparent and responsible use of AI within the framework of the national digital transformation process.

On 9 September 2025, Supreme Decree No. 115-2025-PCM was published, approving the Regulation of Law No. 31814, the Law Promoting the Use of Artificial Intelligence (AI Regulation). The AI Regulation establishes a regulatory framework governing the development and use of artificial intelligence systems in Peru, classifying such systems according to their level of risk and prohibiting certain practices that may adversely affect individuals’ fundamental rights. It also introduces principles and obligations aimed at ensuring transparency, human oversight and accountability in the use of artificial intelligence, applicable to both public entities and private-sector organisations. One of the AI Regulation's primary objectives is to promote the safe, responsible, ethical and human-centric use of artificial intelligence, in accordance with the human rights recognised under the Political Constitution of Peru.

Last modified 23 June 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Poland

The Draft AI Systems Act (Draft Act), which mainly establishes the procedural rules for the enforcement of the EU AI Act, was proposed by the Polish Ministry of Digital Affairs on 16 October 2024. The Draft Act sets out:

  • organisation and conduct of oversight of the market for AI systems and general purpose AI models;
  • rules for imposing administrative fines;
  • infringement proceedings;
  • conditions and procedure for the authorisation of conformity assessment bodies;
  • manner of reporting serious incidents related to the use of AI systems; and
  • types of public activities in support of the development of AI systems.
Last modified 23 July 2025

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

AI compliance in Portugal

In Portugal, no legislation to give further effect to the EU AI Act has been published yet.

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Product Liability Directive in Portugal

No national law transposing the Product Liability Directive in Portugal has been published yet.

Last modified 21 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

Last modified 25 July 2025

The Kingdom of Saudi Arabia (the Kingdom) does not yet have a single, comprehensive statute that regulates ‘artificial intelligence’ as such. In practice, AI use is primarily governed through existing cross‑sector frameworks, most notably data protection and cybersecurity, in addition to sectoral regulation.

The Kingdom's data protection regime applies to AI systems that process personal data in the Kingdom, or in relation to residents of the Kingdom. Specifically, the data protection framework in the Kingdom comprises:

  • Personal Data Protection Law (PDPL), issued by Royal Decree M/19 of 9/2/1443H (14 September 2021).
  • The Implementing Regulation of the Personal Data Protection Law (issued September 2023); and
  • The Regulation on Personal Data Transfer Outside the Kingdom (issued September 2024).

The PDPL and its Implementing Regulations’ core obligations concern purpose limitation, data minimisation, data subject rights, and transparency and disclosure requirements.

The PDPL governs how operators of AI systems can collect, train on, or otherwise handle identifiable personal data of Kingdom residents.

Of particular importance in relation to AI use are the following PDPL issues:

  • Additional transparency obligations: The Implementing Regulations impose heightened transparency requirements where a controller uses ‘newly adopted technologies’ or makes decisions based on automated processing, including an obligation to disclose whether decisions will be made based solely on automated processing.
  • Accuracy: Controllers must take sufficient steps to verify the accuracy, completeness, and timeliness of personal data before processing it, and must suspend processing where inaccurate data may cause harm to a data subject.
  • Consent: Explicit consent is required where decisions are made ‘solely’ based on automated processing.
  • Impact assessments: Controllers must document an impact assessment where processing involves ‘newly adopted technologies’ or automated decision-making. The assessment must address severity, likelihood, and potential psychological, social, physical, or financial impacts on data subjects.
  • Cross-border transfers: Any cross-border transfer of personal data that is subject to the PDPL, for the purpose of deployment of an AI model, must be legitimised in accordance with the PDPL, which at present generally involves the use of contractual safeguards and a transfer risk assessment.

Sectoral regulations from the Saudi Central Bank (SAMA), the Capital Market Authority (CMA), and the Communications, Space and Technology Commission (CST) may also apply to the use of AI.

SAMA is the Kingdom’s primary financial regulator, responsible for overseeing monetary policy and ensuring financial stability, including setting requirements relating to regulatory compliance, risk management, and cybersecurity.

Relevant binding circulars and regulatory frameworks applicable to financial institutions implementing AI include:

  • SAMA Cybersecurity Framework (issued May 2017): requires any 'material outsourcing' to be subject to a SAMA approval process.
  • SAMA Rules on Outsourcing (issued December 2019): requires financial institutions to undertake due diligence and risk assessments on providers, implement oversight and governance measures, ensure contractual safeguards, maintain records and reporting, and establish contingency arrangements.
  • SAMA Cyber Resilience Fundamental Requirements (CRFR) (issued January 2022): applies to IT systems that form part of regulated financial services infrastructure (e.g., payment systems, banking platforms, or digital financial services). Institutions subject to the CRFR must ensure that AI systems are subject to robust cybersecurity governance, ongoing risk management, and technical controls to safeguard the confidentiality, integrity, and availability of systems and data.

The CMA is responsible for the governance and oversight of Saudi Arabia’s capital markets. Relevant guidance includes the Business Risk Assessment Guideline, which requires financial institutions to ensure new and existing technologies, such as AI-driven processes that may introduce new vulnerabilities, are subject to comprehensive risk assessment, continuous monitoring, and proactive identification of emerging risks.

Last modified 19 June 2026

Laws specifically addressing AI have not yet been introduced in Singapore.

Last modified 4 August 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in the Slovak Republic

A Slovak draft law aiming to regulate the institutional conditions, competences of authorities, rights and obligations of subjects in connection with the use of AI systems has been produced. The aim of the draft law is to implement certain provisions of the EU AI Act. In March 2026, the designated advisory bodies initiated their review and deliberation of the draft law. The transposition of the Product Liability Directive into the Slovak legal framework is currently underway. The draft law is currently being considered by the National Council of the Slovak Republic as part of the ongoing legislative process.

Last modified 27 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Slovenia

Slovenia has adopted national legislation implementing the EU AI Act, namely the Act on the implementation of the Regulation (EU) laying down harmonised rules on artificial intelligence (Zakon o izvajanju uredbe (EU) o določitvi harmoniziranih pravil o umetni inteligenci, the SLO AI Act). The Product Liability Directive (EU) 2024/2853 has not yet been transposed into Slovenian law.

Last modified 20 July 2026

While various South African statutes and the common law apply to the use of AI, no specific legislation has been passed to govern AI.

On 7 August 2025, the South African Department of Communications and Digital Technologies (DCDT) released an AI Policy Framework. The AI Policy Framework was aimed at promoting the integration of AI technologies to drive economic growth, enhance societal well-being and position South Africa as a leader in AI innovation. It was the first step towards developing a National AI Policy.

On 10 April 2026, DCDT published a draft National AI Policy for comment. The draft policy was withdrawn on 26 April 2026, after it emerged that there were AI hallucinations in the draft. The draft is in the process of being revised but is unlikely to be published for comment before 2027.

Last modified 5 August 2026

On 26 December 2024, the ‘Framework Act on the Development of Artificial Intelligence and the Establishment of Foundation for Reliability’ (AI Act) passed the plenary session of the National Assembly. The AI Act was promulgated on 21 January 2025 (Law No. 20676) and came into effect on 22 January 2026. On 31 December 2025, the National Assembly passed an amendment (Law No. 21311, promulgated on 20 January 2026) that, among other matters, renamed the ‘National AI Committee’ (NAIC) to the ‘National AI Strategy Committee’ (NAISC), expanded its membership and mandate, introduced a definition of ‘training data’, established a legal basis for AI research institutes, and strengthened protections for AI-vulnerable groups in impact assessments. The Enforcement Decree (No. 36053) was promulgated on 21 January 2026 and came into effect together with the AI Act on 22 January 2026. On 20 July 2026, the Enforcement Decree (No. 36506) was amended to stipulate the details of the amendments to the AI Act.

The AI Act is intended to advance AI development and promote self-regulation by establishing a framework of the following initiatives: (i) formulating a master plan for AI by the Minister of the Ministry of Science and ICT (MSIT), creating the National AI Strategy Committee (NAISC, previously the ‘National AI Committee’) under the President’s office, establishing the AI Policy Center, and establishing the legal foundation for the AI Safety Institute’s operations; (ii) supporting industries related to the development and promotion of AI technology, including establishing standards for AI technology, defining ‘training data’ used in AI development and utilisation, and enabling universities and enterprises to establish AI research institutes with MSIT approval; and (iii) enacting and announcing the ‘AI Ethics Principles’ to support self-verification and certification by AI-related organisations, thereby ensuring the safety and reliability of AI and establishing the legal basis for autonomous ethics committees in the private sector.

Furthermore, the AI Act stipulates various obligations for AI business operators, such as operators involved with high-impact AI, businesses offering generative AI products or services, and operators whose AI systems exceed designated training compute thresholds, utilise cutting-edge technology and present a risk level capable of significantly impacting safety and fundamental rights of users (i.e., high-performance AI). It also requires that operators lacking a domicile or business location within Korea must appoint a domestic agent to comply with the regulatory framework and empowers the Minister of MSIT with the authority to conduct fact-finding inspections and to issue suspension or corrective orders where necessary.

The AI Act is the first statute to govern legal requirements specific to AI technologies and products in Korea.

Please note that AI in South Korea will still be regulated by existing rules governing personal information, copyright, and telecommunications. Therefore, the existing obligations and requirements under these laws and regulations will continue to apply to AI-related business and services.

Last modified 5 August 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Spain

On 11 March 2025, the Spanish Council of Ministers approved the Draft Bill on the Proper Use and Governance of Artificial Intelligence (Spanish Draft AI Bill). The bill has since been approved by the Council of Ministers as an Organic Bill and submitted to Parliament, where it is currently undergoing the legislative process.

Overall, the proposed legislation aims to designate the competent supervisory authorities and provide them with the necessary enforcement powers to ensure compliance with the EU AI Regulation. It also seeks to regulate controlled testing environments for AI systems and to define the conditions under which the use of real-time remote biometric identification systems may be authorised in publicly accessible spaces, specifically when necessary to safeguard fundamental rights.

Additionally, Spain has enacted two key pieces of legislation that, while not directly developing the EU AI Act or introducing new standards for AI deployment, are of significant relevance: (i) Royal Decree 729/2023 of 22 August 2023, which establishes the Statute of the Spanish Agency for the Supervision of Artificial Intelligence (Supervisory Agency Royal Decree); and (ii) Royal Decree 817/2023 of 8 November 2023, which creates a controlled testing environment to evaluate AI systems’ compliance with the proposed European Parliament and Council Regulation on harmonised AI standards (AI Testing Royal Decree). The AI Testing Royal Decree regulates the operation of controlled testing environments designed to assess the compliance of AI systems that may pose risks to security, health and fundamental rights.

It should be noted, however, that the Spanish Draft AI Bill does not seek to transpose Directive (EU) 2024/2853 on liability for defective products, which includes provisions relevant to AI-enabled products. At present, there are no clear indications or publicly announced legislative plans regarding the implementation of that Directive within the Spanish legal framework.

Last modified 22 July 2026

Regulation (EU) 2024/1689 of the European Parliament and of the Council on harmonised rules on artificial intelligence (EU AI Act) was published in the Official Journal of the European Union on 12 July 2024. It entered into force on 1 August 2024, although many of its provisions come into force on specific dates:

  • 2 February 2025: General provisions and provisions relating to prohibited AI practices and AI literacy (Chapter 1 and Chapter 2).
  • 2 August 2025: Provisions relating to general-purpose AI (GPAI) models (e.g. generative AI).
  • 2 August 2026: Most other provisions (including requirements for Annex III high-risk AI systems).
  • 2 August 2027: Provisions relating to high-risk AI systems that are safety components of products or products themselves (i.e. AI systems covered by Annex I).

A new EU Product Liability Directive, Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products (Product Liability Directive), was published in the Official Journal of the European Union on 18 November 2024 and entered into force on 8 December 2024. Member States have until 9 December 2026 to implement the Product Liability Directive into national law. The Product Liability Directive modernises the EU-level strict product liability regime, preserving the core principles of the previous law while adapting to new technologies by extending the scope to include software and AI. This regime is still limited to certain types of damages and applies only to consumers and other natural persons.

As part of its Digital Omnibus package, the European Commission has proposed amendments to the EU AI Act. While the Act’s core structure remains unchanged, the revisions aim to make compliance more amenable to businesses including shifting the burden of the AI literacy requirement, expanding reliefs for SMEs and "small mid-caps" and providing a new exemption from EU database registration. The proposals also suggest a delay in the applicability for rules for high-risk AI systems and some transparency requirements. Further updates are expected later in 2026 as the proposal makes its way through the European legislative process.

AI compliance in Sweden

The Product Liability Directive has not yet been transposed into national legislation. The consultation period preceding the legislative proposal closed on 9 January 2026, but no government bill has yet been presented.

Last modified 30 July 2026

Laws specifically addressing AI have not been introduced in Thailand yet. Previously, a Draft Royal Decree on Artificial Intelligence System Service Business was published for public hearing in October 2022. A Draft Act on the Promotion and Support of AI Innovations in Thailand as well as its subordinated regulations, i.e. a Draft Notification Regarding AI Innovation Testing Center (AI Sandbox) and a Draft Notification Regarding Guideline for Setting Criteria and Risk Assessment Methods from the Use of Artificial Intelligence System, were also published and the latest public hearing was held in August 2023. At present, the Electronic Transactions Development Agency (ETDA) has been assigned to revisit those draft laws and subsequently released a Draft Principles of the Law on Artificial Intelligence (Draft AI Law Principles) for public hearing in June 2025. The Draft AI Law Principles preliminarily sets out various principles, including principles relating to the fundamental concepts of AI (e.g. non-discrimination in relation to actions arising from AI), as well as principles governing the management of risks arising from AI (e.g. the designation of AI prohibited-risks and high-risk categories by sectoral regulators, risk management in accordance with international guidelines and standards, the appointment of legal representatives, the reporting of serious incidents, and the duties of AI deployers).

In addition, the Bank of Thailand (BOT) released the Guiding Principles for Artificial Intelligence Risk Management (BOT AI Guideline) for its regulated financial institutions and business operators in September 2025, and the National Cyber Security Agency (NCSA) released the AI Security Guideline in October 2025.

Last modified 4 July 2026

Laws specifically addressing AI have not been enacted in Türkiye yet. However, several draft AI-related bills are currently before the Turkish Grand National Assembly (TBMM). First and foremost, the Draft Artificial Intelligence Law (Bill No 2/2234), which was submitted to TBMM in June 2024, addresses risk management and assessment, compliance and audit, and violations and sanctions.

Since June 2024, there have been several bills submitted to TBMM proposing to amend existing legislation with the aim to regulate AI. Notably a bill (Bill No 2/3404), submitted in December 2025, proposes amendments to Law No 5651 on Regulation of Publications on the Internet and Combat Against Crimes Committed Through Such Publications to require content providers to visibly label AI-generated audio, written or visual content using a mark, logo or text, with non-compliance subject to criminal penalties under Article 217/A of the Turkish Criminal Code, which foresees imprisonment due to defamation.

There have also been bills submitted to TBMM (i) to amend multiple legislation to include regulations and sanctions for the unlawful use of AI systems (Bill No 2/3358, submitted in November 2025), (ii) to amend Law No 5846 on Intellectual and Artistic Works in order to regulate rights related to inputs and outputs of AI systems (Bill No 2/3634, submitted in April 2024), and (iii) to amend Law No 6698 on Personal Data Protection in order to regulate sanctions against the disclosure of audio, text or video messages generated by AI tools without the individual’s consent (Bill No 2/3465, submitted in January 2026).

Novel amendments made to the Regulation on Commercial Advertising and Unfair Commercial Practices (Advertising Regulation), which will take effect on 1 August 2026, require advertisements to clearly, understandably and distinguishably disclose the use of AI or other software where this may materially influence consumers’ economic behaviour, or where AI-generated digital characters that are indistinguishable from real persons are used. The amendments also prohibit advertisements that use AI-generated digital replicas of real persons in a manner that falsely suggests that the individual has personally experienced, used or endorsed a product or service.

Additionally, in October 2024 the TBMM General Assembly adopted Decision No 1426 to establish a parliamentary AI Research Commission, with the aim to identify steps for realising AI benefits, propose legal infrastructure and determine measures to prevent AI-related risks. The Commission was officially established in early 2025 and started holding its meetings and site visits throughout 2025, and published its first and detailed report in March 2026, setting out AI terms, opportunities, risks, global policies and regulations, ecosystem in Türkiye, legal and ethical frame, personal data and cyber security, sectoral practices and policy recommendations.

Last modified 3 July 2026

There is no unified federal law or emirate level law in the UAE that has a primary focus on regulating AI. Instead, AI is governed through a patchwork of non-AI-specific laws and non-binding guidelines.

However, the Dubai International Financial Centre (DIFC) – a financial free zone in the UAE that has its own civil and commercial laws, based on English common law – has introduced specific provisions in the DIFC’s Data Protection Regulations to address the processing of personal data in connection with AI systems (including as part of the training process).

The legal framework in the UAE is complex and comprises multiple jurisdictions. There are federal laws, emirate level laws and laws in specific free zones, as well as binding sectoral rules and regulations. This guide does not cover sectoral rules and regulations.

Last modified 4 August 2025

A single specific law addressing AI has not been implemented in the UK yet. The UK Government continues to favour a pro-innovation, sector-led model, with existing regulators applying current legal frameworks and sector-specific powers to AI-related risks.  That said: 

  • Two Private Members’ Bills relating to the regulation of the use of AI systems have been put before Parliament. The first relates to decision-making processes in the public sector, the Public Authority Algorithmic and Automated Decision-Making Systems Bill, introduced to the House of Lords by Lord Clement-Jones on 9 September 2024. The second is Lord Holmes’ Artificial Intelligence (Regulation) Bill, introduced on 4 March 2025, which would establish a central AI Authority, regulatory sandboxes and require an AI officer for organisations deploying AI. There has been little progress in the parliamentary programme.
  • In October 2025, the Government announced its blueprint for AI regulation, which identified some of the tools it sees as necessary to deliver this growth and drive modernisation of key UK sectors. Part of these proposals include the use of regulatory sandboxes in key sectors (such as healthcare, professional services, transport, and the use of robotics in advanced manufacturing) to foster responsible development of AI. While the proposals are cross-sector in nature, the focus appears to be more on reducing barriers to growth. The Government launched a call for evidence, which closed on 7 January 2026, to seek views on the AI Growth Lab. In June 2026, the Ministry of Justice announced the first sector-specific advisory AI Growth Lab for legal services, bringing together legal-sector regulators to support responsible AI innovation in LawTech.
  • Most recently, the King’s Speech of 13 May 2026 trailed a Regulating for Growth Bill, which aims to reduce the burden of unnecessary regulation through innovation, enable regulatory sandboxes, and help the UK safely seize opportunities from AI and other emerging technologies. More concrete proposals are expected as the legislative session progresses. In July 2026, following a change in Government leadership, incoming Prime Minister Andy Burnham’s team is reported to be seeking to revamp the UK’s AI strategy, addressing emerging challenges whilst fostering innovation and safeguarding public interests.

There are, however, many UK laws (relating to data protection, intellectual property, human rights, equalities, employment laws, etc.) that impact various aspects of AI development, deployment and use.  

On data protection for example, the Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025. Although not an AI-specific statute, the DUAA is expected to play a significant role in the UK’s AI ecosystem by improving access to and use of data across regulated sectors, in turn, supporting AI development and innovation. The most relevant amendments impacting the use of AI in the UK are those related to automated decision-making, which took effect on 5 February 2026. The previous regime generally prohibited solely automated decisions (with no meaningful human involvement), including profiling, that had a significant legal effect, unless there was explicit consent or it was necessary for the entry into or performance of a contract. The DUAA moves the dial to a more permissive framework, aimed at reducing compliance burdens while in parallel mandating new safeguards (outlined in more detail in our guide to Data Protection Laws of the World). Automated decision-making is now permitted with those new safeguards implemented, unless special category data (e.g. health data) is involved, and organisations can now rely on legitimate interests as a lawful basis (i.e. instead of consent, which is hard to obtain, or contractual necessity, which was often difficult to establish for efficiency gains). Notably, the DUAA clarifies that human review must be ‘substantive and informed’, i.e. a human must be able to challenge or override an AI-driven decision or profile generation, but they do not necessarily need to be involved at all stages. This is important, as the Information Commissioner’s Office (ICO) has indicated that enforcement action may be prioritised where automated decision-making systems fail to offer meaningful human intervention, or where the lack of these safeguards could lead to significant discrimination or unfair treatment of individuals.

Last modified 30 July 2026

AI laws and Proposed Laws

In the US, artificial intelligence (AI) is regulated at both the federal and state levels. While the US lacks a unified federal AI law, the states have been active in modifying existing laws to account for AI and, in some cases, passing targeted AI-specific legislation.

This section outlines the major enacted laws at both federal and state levels, highlighting how states have taken the lead in adapting existing legal frameworks and introducing AI-specific laws in the absence of a comprehensive federal approach.

Federal AI legislation landscape

The federal regulatory landscape for AI remains limited in scope. Although a significant volume of AI-related legislation has been introduced in Congress, only one standalone statute intended to regulate the posting and distribution of AI-generated content has been enacted to date: 

  • Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act): Although the statute does not regulate AI systems directly, it requires online platforms to delete flagged non-consensual intimate imagery, including AI-generated deepfakes, within 48 hours. The law creates criminal penalties for distributing such content and empowers the Federal Trade Commission (FTC) to enforce compliance.

Accordingly, federal policy is more defined by proposals than binding obligations, and most operational guidance continues to come from executive actions and agency-level enforcement.

Potential federal framework

On 20 March 2026, the White House released a National Policy Framework for Artificial Intelligence, a set of non-binding legislative recommendations urging Congress to enact a uniform national AI standard that would preempt conflicting state laws. The Framework is organised around a broad set of objectives, including protecting children and empowering parents; safeguarding American communities (such as streamlining data-centre construction while protecting residential ratepayers, and augmenting enforcement against AI-enabled impersonation scams); respecting intellectual property and supporting creators; preventing censorship and protecting free speech; enabling innovation and ensuring American AI dominance; and educating Americans and developing an AI-ready workforce. The Framework does not itself create new legal obligations, but it signals the Administration’s priorities for the AI legislation it hopes Congress will advance.

This Framework grew out of Executive Order 14365, ‘Ensuring a National Policy Framework for Artificial Intelligence’ (the EO), which President Trump signed on 11 December 2025 with the stated aim of creating American dominance in the field. The EO sought to replace the existing patchwork of state laws—which the Trump Administration views as burdensome and detrimental to innovation—with a unified standard, and it directed federal officials to develop the legislative recommendations that became the March 2026 Framework.

To achieve this, the EO outlined a two-pronged strategy: challenging existing state AI laws in court and establishing a new federal regulatory framework that would preempt them. Pursuant to the EO, on 9 January 2026, the Attorney General (AG) established an AI Litigation Task Force to raise legal challenges to state laws that are viewed as unconstitutional or otherwise conflicting with federal regulations; as of mid-2026, however, the Task Force had not yet filed any lawsuits. The EO also directed the Secretary of Commerce to publish, within 90 days, an evaluation identifying ‘onerous’ state AI laws for possible referral to the Task Force. The federal framework the EO envisioned focuses on key areas such as child safety, censorship prevention, and copyright protection, while preempting conflicting state-level regulations.

State-level AI legislation landscape

The lack of comprehensive federal AI legislation has led to a proliferation of state-level laws and regulations, with many more bills working their way through state legislatures in 2026. Some of these laws establish frameworks and requirements that impact both public- and private-sector use of AI technologies.

In 2025, all 50 states, Puerto Rico, the Virgin Islands, and Washington, D.C., introduced AI-related legislation. According to the National Conference of State Legislatures, 38 states adopted or enacted approximately 100 AI‑related measures. What materially changes in 2026 is enforceability: several major state AI laws take effect, significantly increasing the need for cross‑state governance frameworks, comprehensive inventories, and demonstrable evidence of controls.

These laws and regulations impose transparency and disclosure obligations, prohibit deceptive use of generative AI, and seek to mitigate algorithmic discrimination in certain domains. The following list includes the principal state laws shaping AI regulation in the US and a few examples of some of the narrower AI-focused laws:

California

  • California has enacted significant AI-related legislation, establishing new requirements for transparency, safety, and accountability across various AI applications. California’s SB53, the Transparency in Frontier Artificial Intelligence Act (TFAIA), was signed into law on 29 September 2025, and took effect on 1 January 2026. It requires large frontier AI developers to publish transparency reports and annually update a public frontier AI safety framework describing how they assess and mitigate ‘catastrophic risk’, secure unreleased model weights, and respond to critical safety incidents. Further, California’s AB2013, Generative Artificial Intelligence: Training Data Transparency Act (TDTA) was signed into law 28 September 2024, and took effect 1 January 2026. The TDTA requires AI developers to publicly post a high-level summary of the datasets used to train generative AI systems or services made available to the public since January 2022, enumerating specific categories of required disclosures.
  • During 2025, the California state legislature continued to pass many AI-related bills, most of which took effect on 1 January 2026. Signed into law on 13 October 2025, the California AI Transparency Act (AB853) mandates that developers of generative AI must embed ‘provenance data’ into digital content to verify its authenticity and origin. (This law has staggered effective dates through 1 January 2028.) AB489, signed into law on 11 October 2025, prohibits the use of AI to falsely imply that advice or services are being provided by a licensed healthcare professional. Further, enacted on 13 October 2025, SB243 imposes specific safety protocols on ‘companion bots’, requiring them to prevent harmful conversations and regularly remind users that they are interacting with an AI. Other new laws, also enacted on 13 October 2025, create liability for services that enable deepfake pornography (AB621) and bar defendants from claiming an AI ‘autonomously caused the harm’ in civil actions (AB316).

Connecticut

  • Connecticut enacted Substitute Senate Bill No. 5 (SB5), ‘An Act Concerning Online Safety’ (Public Act No. 26-15), which Governor Ned Lamont signed in May 2026. Rather than a single broad governance statute, the 67-page law links together several separate AI measures, but taken together it establishes Connecticut as a major AI-regulation state. SB5 addresses, among other things: safeguards and disclosure requirements for AI ‘companion’ chatbots, including extensive child-protection provisions; ‘provenance data’ transparency obligations for large generative-AI providers of synthetic audio, image, and video content; disclosure requirements for automated employment-related decision technology, together with an amendment providing that the use of such technology is not a defence to an employment-discrimination claim; whistleblower protections for employees of frontier-model developers; an AI regulatory sandbox; and governance requirements for state agencies’ use of AI. Its provisions take effect on a staggered basis, with several effective 1 October 2026 and others on 1 January 2027.

Colorado 

  • On 14 May 2026, Governor Jared Polis signed a new, narrower Colorado Automated Decision-Making Technology in Consequential Decisions Act (enacted as SB 189 and retaining the ‘Colorado AI Act’ short title), which takes effect 1 January 2027 and repeals and replaces the State’s broad 2024 Colorado AI Act before that earlier law ever took effect. As originally enacted, in May 2024, the Colorado Act had been recognised as the first comprehensive statute in the US specifically targeting ‘high-risk’ AI systems, requiring developers and deployers of qualifying AI applications to use reasonable care in preventing algorithmic discrimination, mandate clear documentation of AI activities, and hold entities accountable for the outputs of their AI systems in critical areas such as employment, healthcare, lending, housing, and government services. Its effective date was first delayed from 1 February 2026 to 30 June 2026 and then, following the enactment of SB 189 signed on 14 May 2026, postponed again to 1 January 2027. SB 189 also significantly narrowed the law before it took effect, eliminating the original risk-based framework—including the duty to use reasonable care to prevent algorithmic discrimination, deployer risk management programmes and impact assessments, and certain reporting obligations to the AG—and replacing it with a narrower set of disclosure and transparency requirements focused on automated decision-making technology (ADMT). As revised, developers must provide deployers with specified information about the ADMT they supply (such as intended uses, potentially harmful uses, and categories of training data), and the law preserves limited individual rights to access and correct data and to obtain meaningful human review of adverse automated decisions.

Illinois

  • In August 2025, Illinois enacted the Wellness and Oversight for Psychological Resources Act, which imposes significant restrictions on the use of AI in mental healthcare. The law, effective immediately, broadly prohibits any entity without a professional licence from offering therapy services, a rule that explicitly includes services delivered via AI, and bars licensed healthcare professionals from delegating therapeutic decisions to AI systems. More recently, on 6 July 2026, Governor JB Pritzker signed SB 315, a frontier model safety law that closely resembles California’s TFAIA and New York’s RAISE Act—requiring large frontier developers to implement and publicly post a frontier AI framework, publish transparency reports, and report critical safety incidents. Notably, however, SB 315 also imposes a third-party independent audit requirement found in neither the California nor the New York law, obligating large frontier developers to retain independent auditors to assess their compliance annually. The law takes effect on 1 January 2027, with transparency-reporting and audit obligations beginning 1 January 2028.

Kentucky

  • Signed and effective on 24 March 2025, Kentucky’s AI Governance Act (SB4) establishes a comprehensive framework for AI use within state government. It calls for adoption of uniform AI policy standards and creates a governance committee to oversee ethical, transparent, and responsible AI use across state agencies. It includes provisions for human oversight, public disclosure, and protection of personal and business information.

Nevada

  • On 5 June 2025, Nevada enacted AB406, which makes it a deceptive trade practice to misrepresent the capabilities of AI in mental healthcare. The law prohibits offering AI systems that are programmed to perform services that would constitute the practice of professional mental healthcare if done by a person. Furthermore, providers are barred from marketing or otherwise representing that their AI systems are capable of delivering such care. AB406 took effect on 1 July 2025.

New York

  • New York enacted the Responsible AI Safety and Education (RAISE) Act on 19 December 2025, which establishes a comprehensive regulatory framework for developers of large-scale ‘frontier’ AI models. Effective on 1 January 2027, this law requires large developers to implement and publicly disclose a detailed ‘safety and security protocol’ designed to mitigate the risk of ‘critical harm’, defined as events causing mass injury or over USD 1 billion in damages. It also requires developers to report any ‘safety incident’ that demonstrates an increased risk of such harm to the state attorney general within 72 hours.
  • Further, New York enacted a first-of-its-kind law requiring advertisers to disclose the use of AI-generated individuals in commercial advertising on 11 December 2025. The law mandates a conspicuous disclosure when a ‘synthetic performer’—a digitally created asset made with generative AI to resemble a human who is not an identifiable person—is featured in a visual or audiovisual advertisement. This rule is narrowly targeted at AI-generated actors and does not apply to audio-only ads, deepfakes of real performers, or AI enhancements of real performers. This law takes effect on 9 June 2026.
  • Enacted on 11 December 2021, New York City’s Local Law 144 regulates the use of ‘automated employment decision tools’ (AEDTs) in hiring and promotion decisions. Effective since 5 July 2023, the law imposes three core obligations on employers: they must conduct an annual independent bias audit to assess whether the tool has a disparate impact on candidates based on race, ethnicity, or sex; they must post a summary of the audit results publicly on their websites; and they must provide notice to candidates that an AEDT is being used and of their right to request an alternative screening process.

Texas

  • Texas enacted the Texas Responsible AI Governance Act (TRAIGA) on 22 June 2025, establishing foundational duties for state agencies, developers, and deployers of AI systems operating within Texas. The law went into effect on 1 January 2026, and prohibits state agencies from certain uses of social scoring and biometric data. Developers and deployers face prohibitions on the intentional misuse of AI for certain types of behavioural manipulation, unlawful discrimination, deepfakes, and infringement of constitutional rights. TRAIGA provides protections for organisations that follow recognised frameworks, such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework, as well as a 60-day cure period for violations, and the creation of a regulatory sandbox.

Utah 

  • Utah employed a relatively comprehensive approach to AI oversight by adopting, and making effective, the AI Policy Act (SB149) on 1 May 2024. This legislation requires professionals in regulated occupations—such as law, medicine, and financial services—to disclose their use of generative AI tools during high-risk interactions, such as when providing sensitive advice or handling personal data. Additionally, consumers must be informed if they explicitly enquire whether they are interacting with AI.

A handful of other U.S. states have considered and rejected broad AI laws. In addition, numerous other states and localities have enacted specific statutes or municipal ordinances that regulate discrete aspects of AI. The following list includes several such examples:  

Maine

  • Maine enacted ‘An Act to Ensure Transparency in Consumer Transactions Involving Artificial Intelligence’ (the Maine AI Chatbot Disclosure Act) on 12 June 2025. Effective 23 September 2025, the law establishes targeted disclosure requirements for AI‑driven interactions. It generally prohibits businesses (and other persons) from using an AI chatbot—or similar text or voice‑based computer technology—in trade or commerce in a manner that may mislead or deceive a reasonable consumer into believing they are interacting with a human, unless the business provides a clear and conspicuous disclosure that the interaction involves AI.

Maryland

  • Maryland enacted HB820 on 20 May 2025, regulating how health insurance plans and related entities may use AI in coverage and treatment decisions made in utilisation management and review decisions. Effective 1 October 2025, the law requires covered entities to ensure that the AI tool’s determinations are grounded in the enrollee’s individual clinical information, do not replace the role of a healthcare provider, and are applied fairly and equitably without resulting in unfair discrimination.

Pennsylvania

  • On 7 July 2025, Pennsylvania enacted Act 35 (formerly SB649) to address the malicious use of AI-generated deepfakes. Effective 5 September 2025, the law establishes criminal penalties for generating (or creating and distributing) a forged digital likeness with intent to defraud or injure, or with knowledge and intent to facilitate fraud or injury by another—including where the actor knows or reasonably should know the audio or visual at issue is forged.

Illinois

  • Illinois enacted HB3773 on 9 August 2024, amending the Illinois Human Rights Act to regulate the use of AI in employment decisions, prohibiting discriminatory practices. Effective 1 January 2026, the law requires employers to provide notice to applicants and workers if they use AI for hiring, discipline, discharge, or other workplace-related purposes.

This continued surge in state legislative activity reflects a wide range of approaches and priorities—from establishing task forces to study AI’s impact to imposing specific obligations on companies deploying AI systems. This dynamic landscape may underscore the growing value of state-level action in the absence of federal guidance, and organisations are encouraged to closely monitor both enacted laws and pending legislation in the jurisdictions in which they operate.

Last modified 29 July 2026

Continue reading

  • no results

Back to top