Executive report · CriterIA© 25 client access
Confirming your payment with Stripe. One moment.
Executive report · EstratégicaMente
A comparative analysis of the main national regulatory frameworks against the European AI Regulation — Regulation (EU) 2024/1689.
27 July 2026 · v2.0
01 · Executive summary
The European Union retains the world's only horizontal, binding, risk-based framework, but has just made it more flexible.
South Korea becomes the world's second jurisdiction with a comprehensive AI law in force, partly inspired by the European model.
For any organisation operating internationally, the European Regulation acts as the de facto regulatory reference.
02 · The reference framework
The AI Act is the world's first horizontal law on artificial intelligence. In force since 1 August 2024, it applies in stages.
Prohibited practices under Art. 5 (extended by the Omnibus) and the AI literacy duty, now reformulated.
Substantive obligations for providers of general-purpose models.
Art. 50 transparency from 2/8/2026; Chapter V GPAI obligations have applied since 2/8/2025, with the Art. 101 enforcement power from August 2026; supervisory authorities are still being rolled out.
For generative AI systems placed on the market before 2/8/2026.
Biometrics, employment, education, migration, essential services (Art. 6.2). Deferred by 16 months under the Omnibus.
Regulated products: medical devices, lifts and similar.
Public debate has focused on the postponement. But Regulation (EU) 2026/1744 introduces six changes that deserve attention.
The duty to support staff literacy remains, according to knowledge, experience and context of use. Clarified rather than removed.
An exceptional legal basis for processing special categories of data in order to detect and correct bias, with safeguards.
Exclusive competence over systems based on GPAI from the same provider or group, and over those embedded in large platforms.
Simplified technical documentation, proportionality of the quality system and a cap on fines — three SME privileges extended.
The national sandbox obligation is postponed to 2/8/2027; an EU-wide testing space is confirmed as a possibility.
Reg. 2023/1230 moves to section B of Annex I: the substantive requirements will be incorporated into the AI Regulation itself.
03 · Comparative landscape
Position as at 27 July 2026. Each entry summarises the regulatory model, the most recent milestone and the level of enforcement.
European Union
Horizontal · risk-based
The AI Act is in force; the Omnibus (Reg. 2026/1744) defers Annex III high risk to 2/12/2027 and Annex I to 2/8/2028. Chapter V GPAI obligations have applied since 2/8/2025, with the Art. 111.3 transition for pre-existing models; the Art. 101 enforcement power operates from August 2026; and Art. 50 from 2/8/2026.
€35 M or 7 % of global turnover
United States
No federal law · state-level layers
EO 14365 seeks to pre-empt state laws; the legislative recommendations of March 2026 are not yet binding rules.
Varies by state
China
Sectoral · no framework law
A layered architecture built on cybersecurity, data and PIPL. The anthropomorphic interaction measures are a world first.
RMB 50 M or 5 % of turnover
United Kingdom
Sectoral · pro-innovation
No horizontal law: the DSIT Blueprint backs sectoral sandboxes. The AI Growth Lab has been running since 8/6/2026.
Through sectoral regulators
South Korea
Horizontal · 2nd comprehensive law
The AI Basic Act has been in force since 22/1/2026: high-impact AI, content labelling and a compute threshold of 10²⁶ FLOPs.
30 M KRW (≈19.000 €)
Japan
Promotion · no penalties
The AI Promotion Act has applied since September 2025: institutional coordination, voluntary guidelines and name and shame.
No direct fines
Canada
Through privacy law · no AI act
AIDA lapsed in 2025 and will not return: the «AI for All» strategy opts for specific legislation and privacy modernisation.
To be defined in C-36
Brazil
Horizontal · in progress
PL 2338/2023, inspired by the AI Act, is still in the Chamber awaiting the rapporteur's opinion; the vote has been announced but not scheduled.
Up to BRL 50 M (expected)
India
Light touch · no dedicated law
Non-binding governance guidelines (11/2025) under the IndiaAI Mission (~€1,100 M). Indirect regulation through data protection.
Up to INR 250 crore via DPDPA
04 · Global comparative table
| Jurisdiction | Model | Regulatory status 07/2026 | Key milestone 2026–2027 | Extraterr. | Max. penalty |
|---|---|---|---|---|---|
| European Union | Horizontal, risk-based | AI Act in force; Omnibus applicable since 27/07/2026 | GPAI (Chapter V) since 2/8/2025, Art. 101 enforcement from August 2026; Art. 50 from 2/8/2026; Annex III deferred to 2/12/2027 and Annex I to 2/8/2028 | Sí | 35 M€ o 7 % |
| United States | No federal law; state-level layers | EO 14365; recommendations with no rule adopted | Colorado repeals (SB 26-189); AI Kill Switch Act introduced | Partial | Varies |
| China | Sectoral, no framework law | Architecture of measures in force | Anthropomorphic interaction from 15/7/2026 | Sí | 50 M RMB o 5 % |
| United Kingdom | Sectoral and principles-based | DSIT Blueprint replaces the draft bill | AI Growth Lab operating since 8/6/2026 | Limited | Through regulators |
| South Korea | Horizontal (2nd comprehensive law) | AI Basic Act in force since 22/1/2026 | Grace period ≥1 year; fines deferred | Sí | 30 M KRW (≈19.000 €) |
| Japan | Promotional, no penalties | AI Promotion Act since Sept. 2025 | Definition of «high impact» in Q3 2026 | No | No fines |
| Canada | No AI law; through privacy law | AIDA lapsed; «AI for All» strategy | Bill C-36 introduced 15/6/2026 | No | To be defined |
| Brazil | Horizontal, in progress | PL 2338/2023 in the Chamber | No vote scheduled; election year | Expected | Up to BRL 50 M |
| India | No dedicated law; light touch | Non-binding guidelines + DPDPA | IndiaAI Mission (~€1,100 M) | No | INR 250 crore |
Position as at 27 July 2026. Each entry summarises the regulatory model, the most recent milestone and the level of enforcement.
General laws with risk classification and penalties. Korea is the closest case to the AI Act — with different enforcement intensity.
They regulate AI through pre-existing laws and sectoral guidelines, avoiding a binding general rule. The Chinese case is the clearest.
They prioritise promoting R&D over imposing obligations: Japan with a law without penalties; Canada through privacy law.
05 · Strategic implications
For Art. 50 transparency and, from August 2026, for the Art. 101 enforcement power over GPAI providers, regardless of the high-risk postponement.
Anyone designing to the AI Act sits above the threshold required in most jurisdictions: one standard covers many markets.
Simplified documentation, proportionality of the quality system and a cap on penalties. The Omnibus novelty extends them.
The closest to converging with the European model, with open timelines: the end of the grace period in Korea is the date to watch.
An unresolved tension between federal deregulation, state laws in force, ongoing litigation and simultaneous proposals.
Article 14 of the AI Act already requires it for high risk and the US debate places it centre stage. Whoever deploys, must be able to stop.
06 · Sources and methodological note
This report has been produced from official sources — the Official Journal of the European Union, national gazettes and supervisory authorities.
Given the pace of regulatory change — especially in the European Union, the United States and Brazil — we recommend checking the primary source before deciding.
CriterIA© · AI with criterion
The CriterIA© 25 tells you in 25 points, with an instant report and a 30-day action plan. And if you want the full diagnosis, the CriterIA© 60.
Contratar el CriterIA© 60 Pedir el descuento