Global AI regulation tracker

Independent, primary-source-verified coverage of AI regulation by jurisdiction. We publish what is checkable against the actual legislation and clearly flag what is still reporting. Each jurisdiction we cover gets its own live page, updated as the regulation moves.

Last updated: 26 August 2026  ·  Maintained by: Regula (open source)  ·  Report a correction

Live tracker

South Africa — Draft National AI Policy

Gazetted 10 Apr 2026 · withdrawal announced 26 Apr 2026 · gazetted 12 Jun 2026 · revised draft reported for Jan 2027

The draft National AI Policy was gazetted on 10 April 2026. After fictitious references were identified the Minister announced the withdrawal on 26 April 2026, Cabinet approved it on 5 June, and Notice 3880 was withdrawn by gazette on 12 June 2026, which is the operative act. The tracker separates that withdrawn draft from existing law, including POPIA.

Read the tracker →
Live in scanner

EU — Artificial Intelligence Act

Regulation (EU) 2024/1689 · Digital Omnibus in the OJ 24 July 2026 (Regulation (EU) 2026/1744), in force from 27 July 2026

The EU AI Act is Regula's primary detection target. Regulation (EU) 2026/1744 is in force and sets 2 December 2027 for Annex III high-risk provisions and 2 August 2028 for the Annex I product path. Article 50 generally has applied since 2 August 2026, with a specific 2 December 2026 transition for providers of Article 50(2) systems already on the market. Regula reports indicators; it does not decide legal classification or applicable duties.

See Regula CLI →
Live landing page

UAE & GCC — sector rules and cross-border exposure

No federal horizontal AI Act identified in the 26 August 2026 review · sector and free-zone rules still matter

The tracker separates UAE sector, data-protection and free-zone requirements from EU exposure. An EU AI Act territorial-scope analysis depends on the operator, market and output-use facts in Article 2; merely serving a globally accessible product is not itself the complete test. The page records what Regula can map and what requires UAE, sector, data-protection and qualified legal review.

Read the UAE tracker →
Live tracker

United Kingdom — AI regulation framework

Principles-based, sector-specific · ICO & DSIT · no dedicated AI Act

The UK has taken a principles-based, sector-specific approach distinct from the EU AI Act. ICO leads on data protection and automated decision-making (UK GDPR Art. 22), DSIT on cross-cutting policy, with FCA, MHRA, Ofcom and CMA applying their own mandates. Live tracker plus ICO/DSIT baseline plus what UK organisations should do today.

Read the tracker →
Live tracker

Brazil — Marco Legal da IA & LGPD

PL 2338/2023 in committee · LGPD Art. 20 in force · ANPD enforcement 2026–2027

PL 2338/2023 (Marco Legal da IA) passed the Senate on 10 December 2024 and is in a Special Commission at the Chamber of Deputies. LGPD already applies to AI via Article 20 (automated decisions), Article 38 (impact reports), and Article 11 (sensitive data). Regula's framework crosswalk covers both LGPD and Marco Legal. Penalties if enacted: up to R$50M or 2% annual revenue.

Read the tracker →
Live tracker

Colorado — SB 205 Repealed, Replaced by SB 189

SB 24-205 repealed May 2026 · replaced by SB 26-189 (disclosure-focused, duties from 1 Jan 2027)

SB 24-205 (the Colorado Artificial Intelligence Act) was repealed in May 2026 before taking effect. It was replaced by SB 26-189, a narrower disclosure-focused regime whose duties apply from 1 January 2027 — developer documentation, consumer notice, and correction and human-review rights, enforced by the AG. The original SB 24-205 duties (developer reasonable-care, deployer impact assessments) were not reenacted. This page documents the legislative history and what SB 189 requires.

Read the tracker →
Live tracker

South Korea — AI Basic Act

In force 22 January 2026 · MSIT · extraterritorial

The second major horizontal AI statute after the EU AI Act took effect on 22 January 2026 with its Enforcement Decree. It defines high-impact AI by use and impact. The separate Article 32 safety path requires all three Decree Article 24 criteria: at least 10²⁶ training FLOPs, current frontier-level configuration and operation, and risk likely to have a widespread and significant impact. The tracker also covers Article 31 transparency and the conditional Article 36 domestic-agent rule.

Read the tracker →
Planned

United States — federal & other state laws

NIST AI RMF · NIST AI 600-1 · Texas TRAIGA · California successors

Beyond Colorado, the US approach remains a patchwork: federal NIST AI RMF 1.0 and the 2024 GenAI Profile (NIST AI 600-1) serve as voluntary frameworks, while Texas, California, Connecticut and New York have passed or proposed state-level AI laws. Regula's framework crosswalk maps findings to NIST AI 600-1's 12 GenAI risks. Additional state pages will land as statutes are enacted.

Coming soon
Planned

African Union — Continental AI Strategy

AU CAIS 2024 · SADC digital frameworks

The AU Continental AI Strategy (2024) sets the continental direction and several SADC member states are developing national responses. A regional tracker page is on the roadmap once the South Africa gazette clarifies the baseline.

Coming soon

Our coverage principles

Every claim on this site about regulation is either (a) checkable against the actual legislation or an official government source, or (b) explicitly labelled as secondary reporting with the secondary source named. Where a jurisdiction's text is not in the public domain, we say so, label the claim, and commit to verifying it against the primary source as soon as it publishes. We would rather publish a short page with clear provenance than a long page with silent assumptions.

If a jurisdiction matters to you and it is not yet on this list, open an issue. We prioritise coverage by reader demand and by the quality of the primary source we can cite.

Last reviewed: 26 August 2026 · Report a correction