Ten Jurisdictions Beyond the EU, the US, and China
The one-paragraph answer
Global AI laws are far less uniform than the coverage suggests. Across ten major jurisdictions outside the EU, the US, and China, exactly one, South Korea, has a comprehensive binding AI statute in force, and even there a one-year enforcement grace period defers most fines. Japan enacted an AI law with no fines and no bans. Singapore leads on agentic-AI governance with a framework that binds nobody. Canada's proposed AI act died in Parliament and was never reintroduced. Brazil's passed the Senate and stalled in the Chamber. Australia examined mandatory guardrails and then formally abandoned them. The UK never proposed a comprehensive law at all. India, the UAE, and Saudi Arabia regulate AI through privacy statutes and sector regulators. The correction this page exists to make: for most of the world, the binding layer for AI is not an AI act. It is the data protection law, the sector regulator, and the procurement rule, and a compliance program that waits for an "AI Act" to appear before acting has misread how most jurisdictions actually govern. China is covered separately on its own page because its instrument stack is deep enough to warrant it: see China AI Regulation.
A US company with customers in Seoul, Tokyo, Singapore, Toronto, São Paulo, London, Dubai, Riyadh, Mumbai, and Sydney asks its counsel a simple question: which AI laws apply to us? The honest answer is ten different regimes with ten different architectures, and almost none of them look like the EU AI Act. The compliance team that assumes "no AI act means no AI obligations" walks into Korea's extraterritorial statute, India's DPDP enforcement, and the UAE free-zone rules. The team that assumes every jurisdiction is building an EU-style act wastes budget preparing for laws that died, stalled, or were never proposed. Both errors come from the same source: reading headlines about global AI laws instead of reading the instruments.
South Korea's AI Basic Act (formally the Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness) and its Enforcement Decree took effect January 22, 2026, making Korea the first jurisdiction after the EU with a comprehensive AI statute in force. It applies extraterritorially to any foreign business whose AI affects Korean users, defines high-impact AI in employment, healthcare, financial services, public safety, education, and similar domains, imposes generative-AI labeling duties, sets a high-performance threshold at 10^26 cumulative FLOPs, and requires certain foreign providers to designate a domestic representative. Two facts routinely dropped from summaries: maximum administrative fines are modest, ₩30 million (roughly $21,000), and MSIT is operating an enforcement grace period of at least one year, deferring investigations and fines through early 2027 except in exceptional cases involving serious harm. The Act binds now; the financial bite is deferred and light. The compliance case for acting anyway is the extraterritorial scope and the domestic-representative requirement, both of which are structural rather than fine-driven.
Japan's AI Promotion Act (Act on the Promotion of Research and Development and the Utilization of AI-Related Technologies) was enacted May 28, 2025 and came into full force September 1, 2025. It is a real statute and it contains no fines, no bans, and no mandatory requirements. That is deliberate: Japan's model relies on administrative guidance, government coordination through an AI Strategic Headquarters, an AI Basic Plan (Cabinet-approved December 2025), and reputational enforcement, the state can publicly identify non-compliant operators. The framing that Japan "has no AI regulation" is wrong; it has a regulatory model built on reputation risk rather than legal penalty. Watch two things: an expert process defining what counts as high-impact AI, and a proposed amendment to Japan's privacy law (the APPI) that would introduce administrative fines for the first time, likely around 2027, which would put teeth into the layer that actually binds.
Singapore has no binding AI statute and leads the world anyway. IMDA's Model AI Governance Framework for Agentic AI, launched at Davos on January 22, 2026 and updated to version 1.5 on May 20, 2026, is the first comprehensive governance framework specifically for AI agents: defining agent boundaries, risk factors, human-oversight design against automation bias, and technical controls across the agent lifecycle, with more than ten real-world case studies from organizations including DBS, Google, AWS, and GovTech. It is entirely voluntary. The binding layer in Singapore is the PDPA, and alignment with the framework functions as a market-trust signal rather than a legal mandate. For any operator deploying agents anywhere, the framework is worth reading regardless of Singapore exposure, because it is currently the most operationally specific agent-governance document any government has produced.
India has no standalone AI act and no current plan for one. What it has is enforceable and layered: the Digital Personal Data Protection Act 2023 with its 2025 Rules, Phase 1 enforcement live since November 14, 2025 and consent-management rules arriving November 2026; MeitY governance guidelines building a whole-of-government AI architecture; rules on deepfakes and AI-content labeling introduced in February 2026; and the Reserve Bank of India's FREE-AI framework, released August 13, 2025, a 7-principle, 6-pillar, 26-recommendation framework for AI in RBI-regulated financial institutions. FREE-AI is advisory today, but it tells every bank, NBFC, and payment operator exactly what the RBI expects: board-approved AI policy, model risk management, independent validation, audits, and consumer-facing explainability. For financial-sector operators in India, treating FREE-AI as optional because it is not yet binding is the same mistake US banks made with model-risk guidance, supervisory expectations become examination findings long before they become statutes.
Canada's Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died on the Order Paper when Parliament was prorogued on January 6, 2025, and it has not been reintroduced; the responsible minister confirmed in June 2025 that AIDA is off the table as drafted. Canada therefore has no dedicated federal AI statute. The operative layer is PIPEDA federally, Quebec's Law 25 provincially (the strictest privacy regime in North America, with automated-decision transparency duties), the Treasury Board Directive on Automated Decision-Making for federal government systems, and sector guidance from OSFI and Health Canada. Any vendor material or compliance memo that still describes AIDA as pending is more than a year out of date.
Brazil's PL 2338/2023 is the most EU-like AI bill in the Americas: risk-based classification, prohibited practices, rights to contest AI decisions and demand human participation, mandatory impact assessments for high-risk systems, fines up to R$50 million or 2 percent of Brazilian revenue, and the data protection authority ANPD coordinating a national AI governance system. The Senate approved it December 10, 2024. It then went to a special committee in the Chamber of Deputies in April 2025 and, as of mid-2026, remains stalled there awaiting a rapporteur's opinion amid election-year gridlock, with the copyright provisions (payment to rights holders for training use) drawing the heaviest amendment pressure. Until it passes, Brazil's binding layer is the LGPD. Operational planning should not assume effective dates before late 2027 at the earliest, and should assume the text changes before passage.
The UK has no comprehensive AI statute and has chosen that position twice, once under the previous government's "pro-innovation" white paper and again under the current one, which has repeatedly deferred a promised AI bill. The model is sectoral and principles-based: existing regulators (the ICO, FCA, CMA, MHRA, Ofcom) apply cross-cutting principles within their remits, coordinated centrally. The AI Safety Institute was renamed the AI Security Institute in February 2025, signaling a national-security focus over a consumer-protection one. For operators, the practical consequence is that UK AI exposure runs through UK GDPR, sector rulebooks, and consumer law, and a UK-specific "AI Act readiness" program has nothing to be ready for yet.
The UAE has no horizontal AI statute; it has a layered regime that is more developed than commonly described, and one big structural change. The federal Personal Data Protection Law anchors data protection. In the financial free zones, DIFC Regulation 10, the first AI-specific regulation in the region, reached full enforcement on January 1, 2026, imposing duties on autonomous and semi-autonomous systems processing personal data, including an Autonomous Systems Officer role for high-risk processing, with fines of $25,000 to $50,000 per violation. The Central Bank issued AI guidance for financial institutions in February 2026 that is binding in practice for licensed entities. And on June 14, 2026 the UAE created the Federal Authority for Artificial Intelligence and Data, consolidating the AI Office, the Emirates Data Office, and TDRA's digital-government sector into a single national body reporting to Cabinet, with a mandate to set unified AI and data policy and propose legislation. That is a consolidation of oversight, not a new statute, but it is the institutional precondition for one, and it resolves the jurisdictional fragmentation that had made UAE AI enforcement questions genuinely hard to answer.
Saudi Arabia governs AI through the Saudi Data and Artificial Intelligence Authority (SDAIA), which combines the roles of AI strategy owner, data regulator, and national AI developer, an unusual concentration. The binding layer is the Personal Data Protection Law (PDPL), enforced by SDAIA, which reaches AI systems processing personal data. On top of it sit non-binding instruments: AI ethics principles and generative-AI guidelines for government and public use. There is no binding horizontal AI statute and none imminent. The operational posture for Saudi exposure is PDPL compliance plus alignment with SDAIA guidance, particularly for any government-adjacent work, where the guidelines function as de facto procurement requirements.
Australia ran the full arc in fifteen months: proposed ten mandatory guardrails for high-risk AI in 2024, published a Voluntary AI Safety Standard, replaced it with the leaner Guidance for AI Adoption (the "AI6" six essential practices) on October 21, 2025, and then, in the National AI Plan of December 2, 2025, formally abandoned the mandatory guardrails and confirmed there will be no standalone AI act. Australia will rely on existing technology-neutral laws and sector regulators, supported by the AI6 and a new Australian AI Safety Institute, funded at A$29.9 million, with advisory and monitoring functions only, no enforcement powers. The one hard edge: the Digital Transformation Agency's policy made AI impact assessments and governance mandatory for Commonwealth agencies from June 15, 2026, which flows down to any vendor selling AI into the Australian government. Australia is the cleanest recent example of a government examining EU-style regulation and deciding against it, the same direction of travel as the Colorado repeal and the CMMC Phase II suspension covered elsewhere in this library.
Line the ten up and the pattern is unmistakable. One binding comprehensive act in force (Korea, fines deferred). One act with no penalties by design (Japan). Two dead or stalled acts (Canada, Brazil). Three jurisdictions that considered and declined (UK, Australia, and effectively Singapore). Three governing through authorities and privacy law (India, UAE, Saudi Arabia). In eight of ten, the instrument that can actually fine you today is the data protection law. The practical consequence: a multinational AI compliance program should be built on the privacy-law chassis it already has, PDPA, DPDP, PIPEDA, Law 25, LGPD, PDPL, UK GDPR, with AI-specific obligations layered per jurisdiction, rather than waiting for AI acts that most of these governments have explicitly decided not to pass. The exceptions worth watching for hard-law arrival: Brazil's Chamber vote, Korea's grace-period expiry in early 2027, and any legislative proposal from the UAE's new federal authority.
Existing governance frameworks such as the NIST AI RMF and the EU AI Act articulate essential principles of fairness, accountability, and transparency, but they remain largely static and principle-based, whereas agentic systems are dynamic, tool-using, and adaptive, requiring continuous oversight rather than one-time certification.
The divergence across the ten jurisdictions on this page is partly a divergence over exactly that problem: whether to freeze obligations into a statute (Korea, Brazil) or keep them in adaptable guidance (Singapore, Japan, Australia). Neither camp has evidence of superior outcomes yet, which is itself a reason to build compliance on the stable privacy-law layer.
Agent autonomy can be measured directly from the code that governs an agent, which allows autonomy levels to be classified and bounded as a governance control rather than inferred after the fact from behavior.
Among the ten on this page, only South Korea, effective January 22, 2026, with a one-year enforcement grace period deferring most fines. The EU AI Act is in force separately (see the EU AI Act page), and China's instrument stack is covered on the China AI Regulation page. Japan has a binding statute with no penalties. Everything else here is privacy law, sector rules, or voluntary frameworks.
No and not yet. Canada's AIDA died with the January 2025 prorogation and was never reintroduced. Brazil's PL 2338 passed the Senate in December 2024 and has been stalled in a Chamber of Deputies special committee since April 2025. Neither imposes any obligation today.
No. That is the central error this page corrects. India fines under the DPDP Act. The UAE's DIFC fines under Regulation 10. Quebec's Law 25 reaches automated decisions. Sector regulators in the UK, Japan, India, and the Gulf apply existing rulebooks to AI now. The binding layer exists in every jurisdiction on this page; it is just rarely labeled "AI."
The jurisdictional inventory and the privacy-chassis mapping in the 5-step path are core outputs of the AI Risk & Governance Review™, and the per-agent decision-rights register recommended for agentic deployments is built in Volume III of The Operating Discipline for AI Library™.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including Global AI Laws, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →