ES

Executive report · CriterIA© 25 client access

Verifying your access…

Confirming your payment with Stripe. One moment.

Executive report · EstratégicaMente

Global AI Legislative Landscape

A comparative analysis of the main national regulatory frameworks against the European AI Regulation — Regulation (EU) 2024/1689.

Escrito por
Guillermo Taboada Martínez
CEO & Founding Partner — EstratégicaMente
Profesor de la Universidade da Coruña (UDC) y de BEYOND AI Finance & Business School

27 July 2026 · v2.0

01 · Executive summary

2026 consolidates divergence, not convergence.

The European Union retains the world's only horizontal, binding, risk-based framework, but has just made it more flexible.

South Korea becomes the world's second jurisdiction with a comprehensive AI law in force, partly inspired by the European model.

Lectura ejecutiva El aplazamiento europeo no es una retirada: es un reajuste de calendario ante la falta de normas armonizadas. El 2 de agosto de 2026 conserva obligaciones exigibles — transparencia, modelos de propósito general, gobernanza — y el régimen sancionador permanece intacto en 35 M€ o el 7 % de la facturación global.

For any organisation operating internationally, the European Regulation acts as the de facto regulatory reference.

2
jurisdicciones con ley integral de IA en vigor: UE y Corea del Sur
16 meses
de aplazamiento del alto riesgo del anexo III: del 2/8/2026 al 2/12/2027
35 M€ · 7 %
sanción máxima europea, intacta tras el Ómnibus
×1.800
la distancia entre la sanción máxima de la UE y la de Corea (≈19.000 €)

02 · The reference framework

The European AI Regulation, after the Omnibus.

The AI Act is the world's first horizontal law on artificial intelligence. In force since 1 August 2024, it applies in stages.

Febrero 2025 · vigente

Prohibitions and literacy

Prohibited practices under Art. 5 (extended by the Omnibus) and the AI literacy duty, now reformulated.

Agosto 2025 · vigente

General-purpose AI models (GPAI)

Substantive obligations for providers of general-purpose models.

2 agosto 2026 · fecha activa

Transparency, GPAI and governance

Art. 50 transparency from 2/8/2026; Chapter V GPAI obligations have applied since 2/8/2025, with the Art. 101 enforcement power from August 2026; supervisory authorities are still being rolled out.

2 diciembre 2026

End of the marking transition (Art. 50.2)

For generative AI systems placed on the market before 2/8/2026.

2 diciembre 2027

High risk · Annex III

Biometrics, employment, education, migration, essential services (Art. 6.2). Deferred by 16 months under the Omnibus.

2 agosto 2028

High risk · Annex I, section A

Regulated products: medical devices, lifts and similar.

The six Omnibus blocks that usually go unnoticed.

Public debate has focused on the postponement. But Regulation (EU) 2026/1744 introduces six changes that deserve attention.

a · Art. 4

AI literacy, reformulated

The duty to support staff literacy remains, according to knowledge, experience and context of use. Clarified rather than removed.

b · Art. 4 bis

Sensitive data to detect bias

An exceptional legal basis for processing special categories of data in order to detect and correct bias, with safeguards.

c · Arts. 75 y ss.

A strengthened AI Office

Exclusive competence over systems based on GPAI from the same provider or group, and over those embedded in large platforms.

d · Art. 3

Privileges for small mid-caps

Simplified technical documentation, proportionality of the quality system and a cap on fines — three SME privileges extended.

e · Art. 60 bis

Sandboxes, with more time

The national sandbox obligation is postponed to 2/8/2027; an EU-wide testing space is confirmed as a possibility.

f · Anexo I

Interaction with the Machinery Regulation

Reg. 2023/1230 moves to section B of Annex I: the substantive requirements will be incorporated into the AI Regulation itself.

Nuevas prácticas prohibidas · art. 5 El Ómnibus incorpora la prohibición de generar o manipular imágenes, vídeos o audios íntimos realistas de personas identificables sin consentimiento inequívoco, y de material de abuso sexual infantil. El régimen sancionador no cambia: hasta 35 millones de euros o el 7 % de la facturación global anual, lo que sea mayor.

What remains enforceable on 2 August 2026.

03 · Comparative landscape

Nine jurisdictions, three paths.

Position as at 27 July 2026. Each entry summarises the regulatory model, the most recent milestone and the level of enforcement.

European Union

Horizontal · risk-based

The AI Act is in force; the Omnibus (Reg. 2026/1744) defers Annex III high risk to 2/12/2027 and Annex I to 2/8/2028. Chapter V GPAI obligations have applied since 2/8/2025, with the Art. 111.3 transition for pre-existing models; the Art. 101 enforcement power operates from August 2026; and Art. 50 from 2/8/2026.

€35 M or 7 % of global turnover

United States

No federal law · state-level layers

EO 14365 seeks to pre-empt state laws; the legislative recommendations of March 2026 are not yet binding rules.

Varies by state

China

Sectoral · no framework law

A layered architecture built on cybersecurity, data and PIPL. The anthropomorphic interaction measures are a world first.

RMB 50 M or 5 % of turnover

United Kingdom

Sectoral · pro-innovation

No horizontal law: the DSIT Blueprint backs sectoral sandboxes. The AI Growth Lab has been running since 8/6/2026.

Through sectoral regulators

South Korea

Horizontal · 2nd comprehensive law

The AI Basic Act has been in force since 22/1/2026: high-impact AI, content labelling and a compute threshold of 10²⁶ FLOPs.

30 M KRW (≈19.000 €)

Japan

Promotion · no penalties

The AI Promotion Act has applied since September 2025: institutional coordination, voluntary guidelines and name and shame.

No direct fines

Canada

Through privacy law · no AI act

AIDA lapsed in 2025 and will not return: the «AI for All» strategy opts for specific legislation and privacy modernisation.

To be defined in C-36

Brazil

Horizontal · in progress

PL 2338/2023, inspired by the AI Act, is still in the Chamber awaiting the rapporteur's opinion; the vote has been announced but not scheduled.

Up to BRL 50 M (expected)

India

Light touch · no dedicated law

Non-binding governance guidelines (11/2025) under the IndiaAI Mission (~€1,100 M). Indirect regulation through data protection.

Up to INR 250 crore via DPDPA

El caso Colorado · señal del semestre Colorado no aplazó su ley: la derogó. Tras el bloqueo judicial de la SB 24-205 (demanda de xAI, con intervención del Departamento de Justicia), la SB 26-189 sustituye el marco de riesgo europeo por un régimen de notificación y divulgación centrado en tecnología de decisión automatizada, con efecto el 1/1/2027. El único estado que había importado la arquitectura europea la ha abandonado en dos años.
Adenda · AI Kill Switch Act (EE. UU., 23/7/2026) Proyecto bipartidista que obligaría a los desarrolladores de los sistemas más avanzados (más de 100 M$ de cómputo; ingresos vinculados superiores a 500 M$) a mantener la capacidad técnica de ralentizar, suspender o apagar sus modelos, con facultad del DHS para ordenarlo en escenarios de pérdida de control. No es derecho vigente: su valor es de señal — el eje del debate estadounidense ya no es «regular o no», sino qué nivel de gobierno regula y sobre qué capa. En Europa, el art. 14 del AI Act ya exige capacidad de interrupción para sistemas de alto riesgo; la novedad sería atribuir a una autoridad pública la facultad de ordenarla.

04 · Global comparative table

The whole map, in one table.

JurisdictionModelRegulatory status 07/2026Key milestone 2026–2027Extraterr.Max. penalty
European UnionHorizontal, risk-basedAI Act in force; Omnibus applicable since 27/07/2026GPAI (Chapter V) since 2/8/2025, Art. 101 enforcement from August 2026; Art. 50 from 2/8/2026; Annex III deferred to 2/12/2027 and Annex I to 2/8/202835 M€ o 7 %
United StatesNo federal law; state-level layersEO 14365; recommendations with no rule adoptedColorado repeals (SB 26-189); AI Kill Switch Act introducedPartialVaries
ChinaSectoral, no framework lawArchitecture of measures in forceAnthropomorphic interaction from 15/7/202650 M RMB o 5 %
United KingdomSectoral and principles-basedDSIT Blueprint replaces the draft billAI Growth Lab operating since 8/6/2026LimitedThrough regulators
South KoreaHorizontal (2nd comprehensive law)AI Basic Act in force since 22/1/2026Grace period ≥1 year; fines deferred30 M KRW (≈19.000 €)
JapanPromotional, no penaltiesAI Promotion Act since Sept. 2025Definition of «high impact» in Q3 2026NoNo fines
CanadaNo AI law; through privacy lawAIDA lapsed; «AI for All» strategyBill C-36 introduced 15/6/2026NoTo be defined
BrazilHorizontal, in progressPL 2338/2023 in the ChamberNo vote scheduled; election yearExpectedUp to BRL 50 M
IndiaNo dedicated law; light touchNon-binding guidelines + DPDPAIndiaAI Mission (~€1,100 M)NoINR 250 crore

Position as at 27 July 2026. Each entry summarises the regulatory model, the most recent milestone and the level of enforcement.

Who follows the European model?

UE · Corea del Sur

Horizontal and binding

General laws with risk classification and penalties. Korea is the closest case to the AI Act — with different enforcement intensity.

R. Unido · EE. UU. · China · India

Sectoral or principles-based

They regulate AI through pre-existing laws and sectoral guidelines, avoiding a binding general rule. The Chinese case is the clearest.

Japón · Canadá

Promotional or privacy-driven

They prioritise promoting R&D over imposing obligations: Japan with a law without penalties; Canada through privacy law.

La convergencia hacia el modelo europeo no se está produciendo: Colorado lo abandonó, Canadá lo descartó, India lo declinó, Reino Unido lo sustituyó por sandboxes, Corea lo adoptó en la forma pero no en la intensidad, Brasil lo mantiene sin fecha — y la propia Unión reajustó su calendario. El AI Act sigue siendo el techo regulatorio del planeta, pero es un techo cada vez más solitario. Para una organización internacional, eso significa cumplimiento multinivel donde el Reglamento europeo, por exigencia y extraterritorialidad, suele fijar el estándar de diseño.

05 · Strategic implications

Six takeaways for decision-makers.

2 August 2026 is still a live date in the EU

For Art. 50 transparency and, from August 2026, for the Art. 101 enforcement power over GPAI providers, regardless of the high-risk postponement.

Fragmentation increases the value of a single standard

Anyone designing to the AI Act sits above the threshold required in most jurisdictions: one standard covers many markets.

Small mid-caps gain three new privileges

Simplified documentation, proportionality of the quality system and a cap on penalties. The Omnibus novelty extends them.

South Korea and Brazil, markets to watch for 12–18 months

The closest to converging with the European model, with open timelines: the end of the grace period in Korea is the date to watch.

The United States, the greatest risk of unpredictability

An unresolved tension between federal deregulation, state laws in force, ongoing litigation and simultaneous proposals.

The ability to interrupt moves from good practice to requirement

Article 14 of the AI Act already requires it for high risk and the US debate places it centre stage. Whoever deploys, must be able to stop.

06 · Sources and methodological note

How it was produced.

This report has been produced from official sources — the Official Journal of the European Union, national gazettes and supervisory authorities.

Texto íntegro en EUR-Lex
Criterio del supervisor español
Marcado del contenido · art. 50
Comisión y Oficina de IA

CriterIA© · AI with criterion

And your organisation, where is it on this map?

The CriterIA© 25 tells you in 25 points, with an instant report and a 30-day action plan. And if you want the full diagnosis, the CriterIA© 60.

Contratar el CriterIA© 60 Pedir el descuento