AI STRATEGY

Global AI Regulatory Landscape 2026: What AI PMs Need to Know Beyond the EU AI Act

By Institute of AI PM·16 min read·Aug 23, 2026

TL;DR

The EU AI Act gets most of the attention, but in 2026 the UK, Japan, Canada, China, Brazil, and Australia each have distinct AI regulatory postures that affect what you can build, where you can deploy, and what compliance infrastructure your product needs. The EU took the most prescriptive approach. The UK is betting on sector-specific guidance rather than a cross-cutting AI Act. Japan is deliberately light-touch to attract AI investment. China is the most aggressive regulator for content and algorithmic systems. If your product serves users in more than one of these markets, you are operating across multiple simultaneous compliance requirements. This guide maps each jurisdiction and translates it into concrete product team actions.

The AI PM Minute

One tactic to make you a sharper AI PM, twice a week. 60 seconds to read. Free.

No fluff. Unsubscribe anytime.

The Global Regulatory Map at a Glance

Every major AI market regulator has moved in 2025-2026, but in fundamentally different directions. The EU chose comprehensive horizontal legislation. The UK chose a principles-based, sector-specific approach. Japan chose to stay permissive to attract AI investment. China moved fastest on content control. Canada lost its AI legislation in an election. Brazil is following the EU's lead. Australia is reviewing existing laws rather than writing new ones.

The practical consequence: a product that is fully compliant in the EU may not be compliant in China, and vice versa. A product built for the UK market may face fewer prescriptive requirements than an EU-facing product but more uncertainty about what the regulators will do next. AI PMs need a working mental model of each jurisdiction's philosophy before they can make sensible architecture and feature decisions.

Enforcing

European Union (Prescriptive horizontal legislation)

Risk-tiered system with prohibited uses, high-risk obligations, and transparency requirements. Digital Omnibus (July 2026) delayed high-risk enforcement to December 2027.

Developing

United Kingdom (Principles-based, sector-specific)

No single AI Act. Each sector regulator (ICO, FCA, Ofcom) applies its existing mandate to AI. Government publishes non-binding principles. AI Security Institute advises on frontier model safety.

Light-touch

Japan (Voluntary guidelines, investment-friendly)

METI AI Business Guidelines updated in 2025. No mandatory requirements for most AI products. Voluntary adherence to Hiroshima AI Process principles.

Enforcing

China (Content control and algorithmic rules)

Generative AI Interim Measures (2023) and Deep Synthesis Regulations require real-name registration, content labeling, and government content review for many AI-generated outputs.

Paused

Canada (Voluntary code while legislation stalled)

AIDA (Artificial Intelligence and Data Act) died in the 2025 election. Voluntary Code of Conduct for AI developers is in place. No mandatory federal AI law anticipated before 2027.

In progress

Brazil (EU-inspired national legislation)

Lei de Inteligência Artificial in committee as of 2026. Likely to follow EU risk-tiered structure but with modifications for the Brazilian digital economy and LGPD data framework.

Reviewing

Australia (Existing law review plus voluntary AI ethics)

Voluntary AI Ethics Framework published by CSIRO. Government reviewing whether existing consumer, privacy, and IP laws cover AI adequately rather than writing new legislation.

The UK: Sector-by-Sector, Not a Single Act

The UK government made a deliberate choice not to follow the EU with a comprehensive AI Act. The 2023 AI White Paper established five cross-sector principles: safety and security, transparency and explainability, fairness, accountability and governance, and contestability and redress. But these are principles, not law. The enforcement mechanism is each existing sector regulator applying them within their own frameworks.

For AI product teams this means compliance looks different depending on your sector. A fintech AI product is primarily answerable to the FCA. A healthcare AI product is regulated by MHRA and CQC. A platform that hosts AI-generated content is subject to Ofcom under the Online Safety Act. A product that processes personal data has the ICO as its primary AI regulator.

Information Commissioner's Office (ICO)

Any AI that processes UK personal data

GDPR-aligned (UK GDPR). Automated decision-making rules under Article 22. AI and data protection guidance updated 2025. Explicit guidance on AI model training and legitimate interest.

Financial Conduct Authority (FCA)

Financial services AI products

DP5/22 guidance on AI and ML in financial services. SMCR holds senior managers accountable for AI system decisions. Model risk management frameworks. ESG and fairness in credit and insurance AI.

Ofcom

Online platforms with AI-generated content

Online Safety Act 2023 requires risk assessments for AI-generated illegal content. Age verification and safety-by-design requirements affect any AI product serving the UK that generates user-facing content.

AI Security Institute (AISI)

Frontier model developers (voluntary)

Publishes safety evaluations of frontier models. Voluntary safety testing agreements with major labs (Anthropic, OpenAI, Google DeepMind). Not a compliance authority, but findings influence UK government policy.

Japan, China, and the Asia-Pacific Divergence

Japan and China represent the two poles of the Asia-Pacific regulatory approach. Japan is the most permissive major AI market in the world by design: the government views AI as an economic competitiveness priority and has deliberately kept the regulatory environment light to attract AI investment and development. China is among the most prescriptive for content-generating AI, though its rules are focused on political and social content control rather than the safety-and-ethics framing of European regulation.

Japan (Voluntary, investment-friendly)

METI's AI Business Guidelines (2024, updated 2025) provide a voluntary compliance framework aligned with the OECD AI Principles and the Hiroshima G7 AI Process. The guidelines address transparency, accuracy, safety, and privacy but require nothing. No mandatory registration, no risk tiering, no conformity assessment. Japan is explicitly trying to differentiate itself from the EU's mandatory approach to attract AI companies expanding in Asia.

PM action: Japan is a low-regulatory-friction market. The primary compliance concern is existing data protection law (APPI, the Act on the Protection of Personal Information, updated 2022) rather than AI-specific regulation. If you handle Japanese user data, APPI applies. AI-specific regulation is largely voluntary.

China (Content control and platform accountability)

China has moved the fastest and most specifically on AI content regulation. The Deep Synthesis Regulations (2022) cover AI-generated video, audio, and images. The Generative AI Interim Measures (2023) require providers offering generative AI to Chinese users to register with the Cyberspace Administration of China (CAC), label AI-generated content, maintain logs of user queries, and ensure outputs comply with 'core socialist values' and existing content rules. Providers must conduct security assessments before launch.

PM action: If you offer a generative AI product to Chinese users you must register with the CAC, implement content filtering for prohibited categories, label AI outputs as AI-generated, and maintain user query logs for 6 months. Most Western AI product teams choose not to serve the Chinese market directly rather than meet these requirements, but if you do, localization of compliance infrastructure is a prerequisite.

South Korea (EU-aligned, moving toward comprehensive regulation)

South Korea passed an AI Framework Act in late 2024, creating a risk-tiered structure similar to the EU but with lighter obligations for most tiers. The Act focuses on high-impact AI systems in public sector, healthcare, and critical infrastructure. Korea's strong tech industry lobbied successfully for exemptions that the EU did not grant. Enforcement begins 2026-2027.

PM action: Monitor South Korea as a leading indicator for how other Asia-Pacific markets (Vietnam, Thailand, Singapore) may approach AI regulation. Singapore is working on a model AI governance framework with the IMDAs AI Verify toolkit.

Navigate AI Regulation Without Slowing Down Your Roadmap

The AI PM Masterclass covers how to build compliance into your product architecture rather than bolting it on, taught live by a Salesforce Sr. Director PM.

Canada, Brazil, and the Americas

Canada had the most ambitious AI legislation outside the EU with the Artificial Intelligence and Data Act (AIDA), introduced as part of Bill C-27 in 2022. AIDA would have created a risk-tiered system similar to the EU, with obligations for high-impact AI systems and a new AI and Data Commissioner. The bill died in 2025 when Prime Minister Trudeau called a snap election. The new government has not reintroduced comprehensive AI legislation as of August 2026.

What Canada does have is a Voluntary Code of Conduct for Responsible Development and Management of Advanced Generative AI Systems, endorsed by major AI developers including Anthropic, Google, Microsoft, OpenAI, and several Canadian companies. Signing the code commits companies to transparency, safety evaluations, and incident reporting, but enforcement is reputational rather than legal.

Canada

Now: Voluntary Code of Conduct. PIPEDA (federal privacy law) applies to AI that handles personal data.

Watch: New federal AI legislation is expected eventually but timeline unclear. Quebec Law 25 (data protection) is stricter than federal PIPEDA and applies to AI systems processing Quebec residents' data.

Brazil

Now: Lei de Inteligência Artificial in committee. LGPD (Lei Geral de Protecao de Dados) already applies to AI systems using personal data, including automated decision-making rules similar to GDPR Article 22.

Watch: Draft AI law follows EU risk-tiered model. If passed, it would be the most comprehensive AI regulation in South America. Timeline: 2026-2027 for passage, 2028 for enforcement.

United States

Now: No federal AI Act. Executive Order 14409 (2026) on frontier AI safety covers federal procurement and advanced model safety evaluations. FTC, EEOC, and sector regulators applying existing authority to AI.

Watch: US state laws are moving faster than federal. California AB 2013, SB 1047 successor bills, Colorado SB 205. If you serve US users, track state-level laws, not just federal.

Mexico

Now: No specific AI legislation. LFPDPPP (data protection law) applies to AI using personal data. Regulator is INAI.

Watch: Mexico has announced intent to study AI regulation in 2026 but no legislation introduced. Following rather than leading on AI policy.

How These Frameworks Interact: Strategic Implications

The most important strategic insight from the global regulatory landscape is that compliance requirements are not additive in a simple way. Building to the EU AI Act standard does not automatically make you compliant in China (different issues entirely) or in the UK (different enforcement mechanisms). But building to the highest standard in any dimension does give you a transferable compliance foundation in many markets.

The EU AI Act is the baseline for global market access

If your product is designed to the EU AI Act standard, you are over-compliant for Japan, Australia, and the current UK requirements. You are not compliant for China (different issues: content control, registration), but you are positioned for most other markets.

Data localization is an underappreciated constraint

Several markets require that data on their citizens be stored locally. China requires user data to be stored in China. India is moving toward data localization. Russia has strict data localization. Products serving these markets need localized infrastructure, not just localized compliance documents.

Transparency requirements are the safest common denominator

Every major regulatory framework, from the EU to the UK to Japan's voluntary guidelines, requires some form of transparency when AI is making or influencing consequential decisions. Building disclosure and explainability into your product from the start is universally applicable.

The EU compliance premium is real but finite

Enterprise buyers in non-EU markets increasingly ask about EU AI Act compliance as a proxy for AI governance maturity. Being EU-compliant signals process rigor even when it is not legally required. But this premium diminishes as other markets develop their own frameworks and certifications.

Extraterritorial reach is inconsistent

The EU AI Act applies to any AI system placed on the EU market, regardless of where the company is headquartered. China's regulations apply to services available to Chinese users. The UK applies existing law territorially. US federal law is narrowest. Know which markets your product actually reaches before assuming compliance scope.

A Practical Framework for Multi-Jurisdiction AI Products

If your product serves users in more than one of these markets, use this framework to build a defensible compliance posture without redesigning the product for every jurisdiction.

1

Map your actual user base geographically

Before you can know which regulations apply, you need to know where your users are. Regulatory scope typically follows user location, not company location. A US company with EU users is subject to the EU AI Act for those users.

2

Classify your product against the EU AI Act risk tiers

The EU framework is the most comprehensive and has the most useful classification system. Run your product through the EU risk-tiering exercise. If you are not high-risk under the EU Act, you are unlikely to face mandatory requirements in any other Western market.

3

Apply China compliance as a binary decision

China's requirements are so distinct from Western frameworks that you need to make a separate decision: do you serve Chinese users and meet the CAC requirements, or do you geo-restrict your product away from China? There is no partial compliance path.

4

Build transparency and disclosure as platform features

Mandatory disclosure of AI use is present in every major regulatory framework and is almost certainly coming in markets that do not have it yet. Build disclosure infrastructure (AI labeling, explanation APIs, audit logs) as platform features you can enable per-market, not as per-market patches.

5

Designate a regulatory owner in each major market

Regulations require an EU representative for non-EU companies under the EU AI Act. UK GDPR requires a local representative. Document who is responsible for regulatory correspondence and incident reporting in each market where you operate.

Build AI Products Ready for Global Markets

The AI PM Masterclass covers compliance strategy, global market positioning, and how to ship AI features that hold up in every major regulatory environment. Taught live by a Salesforce Sr. Director PM.

Before you go: get the AI PM Minute

One tactic to make you a sharper AI PM, twice a week. 60 seconds to read. Free.

No fluff. Unsubscribe anytime.