AI Regulation in 2026: What Rules Are Actually in Place and Who They Apply To

Remy Torres

Remy Torres

July 7, 2026

AI regulation has moved from a policy discussion topic to enacted law in several major jurisdictions. The landscape in 2026 is fragmented—different rules in different regions, applying differently depending on the type of AI system and its use case—but increasingly concrete. Here’s what the actual regulatory picture looks like, what it requires, and who bears the compliance burden.

The EU AI Act: The World’s Most Comprehensive Framework

The European Union’s AI Act, which entered into force in August 2024, is the world’s most comprehensive AI regulation and will become the reference point against which other jurisdictions’ approaches are compared. Its core structure is a risk-based hierarchy that applies progressively more stringent requirements to AI systems as their risk level increases.

Prohibited AI practices (applicable from February 2025): The Act bans several AI applications outright, including social scoring systems operated by governments, real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions), AI systems that manipulate people using subliminal techniques, and AI systems that exploit vulnerabilities of specific groups. These prohibitions apply regardless of where the AI system is developed if it’s deployed in the EU.

High-risk AI systems (applicable from August 2026): AI systems in high-risk categories—including AI in critical infrastructure, educational admissions, employment decisions, essential services (credit scoring, insurance underwriting), law enforcement, and administration of justice—face extensive compliance requirements. Providers must: conduct conformity assessments before deployment; maintain detailed technical documentation; implement quality management systems; ensure human oversight mechanisms; maintain logs; and register in an EU database. High-risk systems used by public authorities (law enforcement, border control, administration of justice) face the strictest requirements.

Technology compliance legal documents court AI digital law regulation

General purpose AI models (GPAI, applicable from August 2025): The Act adds specific obligations for powerful general-purpose AI models—including large language models like GPT-4, Claude, and Gemini. Providers must provide technical documentation, ensure compliance with copyright law (transparency about training data), and provide summaries of training data used. For “systemic risk” GPAI models (trained with over 10^25 FLOPs), additional obligations apply: adversarial testing, incident reporting to the EU, and cybersecurity measures.

The penalties are structured to be meaningful: fines of up to 35 million euros or 7% of global annual turnover for violations of prohibited practices, and up to 15 million or 3% for other violations. These are large enough to create genuine compliance incentive for major technology companies, though enforcement capability is still being built.

The United States: A Fragmented Approach

The US has not enacted comprehensive federal AI legislation as of mid-2026. The federal approach has instead been through executive action and sector-specific regulation from existing agencies.

President Biden’s October 2023 Executive Order on AI established requirements for AI safety standards, reporting obligations for powerful AI models (above certain compute thresholds), and directed existing regulatory agencies to use their authorities to address AI risks in their sectors. The EO’s implementation has proceeded unevenly following the change of administration in January 2025, with some aspects maintained and others de-prioritised.

Sector-specific regulation has proceeded more consistently: the SEC has guidance on AI use in financial advice and asset management; the FDA has cleared AI-enabled medical devices through existing pathways; the FTC has brought enforcement actions under existing consumer protection law against deceptive AI practices. The CFPB has issued guidance on the use of AI in credit decisions under existing equal credit opportunity law.

State-level regulation has been active where federal regulation is absent. California has passed several AI-related laws covering AI-generated content disclosure, automated decision systems in employment, and deepfake restrictions. Colorado has enacted AI requirements for insurance underwriting. Other states have various AI-related legislation in various stages. The result is a patchwork of state requirements that create compliance complexity for companies operating nationally.

China’s Approach

China has implemented a series of targeted AI regulations since 2021, covering specific AI application areas rather than a comprehensive framework: algorithm recommendation rules (2021), deep synthesis (deepfake) regulations (2022), and generative AI regulation (2023). The generative AI regulation requires security assessments and content filtering for generative AI products available to Chinese users, and imposes obligations around training data sourcing and content moderation.

China’s regulatory approach combines technology governance with state supervision requirements—AI systems must support government oversight mechanisms—which creates a fundamentally different compliance environment than the EU’s human-rights-based framework or the US’s sector-specific approach.

AI surveillance facial recognition camera biometric data privacy ethics

Who Bears the Compliance Burden

Under the EU AI Act, the primary compliance burden falls on “providers”—the companies or individuals who develop and place AI systems on the EU market. For foundation model providers (OpenAI, Anthropic, Google, Meta), the GPAI obligations apply regardless of where the provider is based if their models are deployed in the EU. This gives EU regulation significant extraterritorial reach.

“Deployers”—companies that use AI systems built by others—have lighter obligations but are not exempt. Deployers of high-risk AI systems must ensure the system is used as intended, implement appropriate human oversight, inform employees working with AI systems, and monitor for risks. A company using an AI system for employee performance evaluation, credit decisioning, or health assessment is a deployer subject to the high-risk AI regime.

Small and medium enterprises (SMEs) have some procedural relief provisions in the EU Act, but the substantive requirements are not waived for SMEs deploying high-risk AI systems—a company of ten people using AI for hiring decisions still faces high-risk obligations if that use falls in a covered category.

The Practical Impact

The most immediate practical impact of the EU AI Act for technology companies is in the GPAI model obligations—the documentation, training data transparency, and adversarial testing requirements for large models that apply from August 2025. Major AI labs (OpenAI, Google DeepMind, Anthropic, Meta) have compliance programmes underway for these obligations.

The high-risk AI requirements coming into full effect in August 2026 will have significant impact on enterprise AI deployments in HR, finance, healthcare, and public sector contexts in the EU. Companies deploying AI in these contexts need to have conducted conformity assessments, established quality management systems, and documented their systems in detail before deployment—requirements that require substantial preparation, particularly for smaller companies without dedicated compliance resources.

The regulatory landscape will continue to evolve. The EU Act includes review provisions; the US may yet pass federal legislation in some form; other jurisdictions (UK, Canada, Brazil, Singapore) are developing their own frameworks with varying degrees of alignment with the EU approach. For technology companies with global reach, navigating this fragmented landscape while it stabilises is the near-term compliance reality.

More articles for you