NextTechBlog

Technology, explained properly.

The European Parliament, seat of the institutions behind the EU AI Act

AI Regulation Around the World: Where the Rules Stand

For two years, 2 August 2026 was circled on every AI compliance calendar in Europe. It was the day the EU AI Act’s obligations for high-risk systems — hiring tools, credit scoring, education software — were supposed to bite. Then, days before the deadline, the EU changed it.

Regulation (EU) 2026/1744, the “Digital Omnibus on AI,” was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It pushed the main high-risk deadline to 2 December 2027 and the deadline for AI embedded in regulated products to 2 August 2028. The rest of the Act stayed put.

That episode captures AI regulation in 2026: the rules are real, and their timelines still move. Here is what is in force in each major jurisdiction as of early September 2026, what is only proposed, and what a small business has to do about it.

This is general information, not legal advice. AI rules vary by sector and by where your customers are. Talk to a qualified lawyer before making compliance decisions.

The EU AI Act: in force, but on a longer runway

The AI Act is the world’s only comprehensive, horizontal AI law, sorting systems into four tiers: unacceptable risk (banned), high risk (heavily regulated), transparency risk (disclosure duties), and minimal risk (no specific rules). The European Commission’s own summary notes that most AI systems used in the EU — spam filters, game AI, recommendation features — fall into that last bucket and attract no new obligations at all.

What applies right now

The prohibitions came into effect on 2 February 2025, covering manipulative techniques that cause significant harm, social scoring by public authorities, untargeted scraping of facial images, and emotion recognition in workplaces and schools, among others.

Obligations for general-purpose AI models — the foundation models underneath most chatbots — applied from 2 August 2025, and fall on model providers rather than businesses using their APIs.

The transparency rules in Article 50 took effect on 2 August 2026 as originally planned, and this is the part most ordinary businesses touch. Deploy a chatbot and you must tell people they are talking to a machine unless it is obvious. Publish AI-generated or manipulated images, audio or video that could pass for real and you must disclose it. AI-generated text published to inform the public on matters of public interest also needs disclosure, unless a human reviewed it and took editorial responsibility.

What the Digital Omnibus changed

Analysis from White & Case and Gibson Dunn sets out the substance. Both high-risk deadlines moved. Watermarking of systems already on the market got a grace period to 2 December 2026. The definition of a “safety component” was narrowed to exclude systems that merely assist a human. SME documentation relief was extended, and the AI literacy duty was softened from ensuring staff competence to supporting its development.

One thing was added rather than delayed: a prohibition on AI systems that generate non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026.

Calling this deregulation would overstate it. The obligations were deferred, not deleted, and the EU AI Office gained expanded supervisory powers over general-purpose model providers.

The current EU timeline

DateWhat applies
2 February 2025Prohibited practices; AI literacy duty
2 August 2025General-purpose AI model obligations; governance rules
2 August 2026Article 50 transparency duties; general enforcement
2 December 2026Watermarking grace period ends; NCII/CSAM prohibition applies
2 December 2027Annex III high-risk systems (hiring, credit, education, law enforcement)
2 August 2028Annex I high-risk systems embedded in regulated products

Penalties are set by Article 99: up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other breaches including Article 50, and up to €7.5 million or 1% for misleading information supplied to authorities. For SMEs, the fine is capped at whichever of the euro figure or the percentage is lower.

Canada: there is no Canadian AI act

This is the fact most often reported wrongly. The Artificial Intelligence and Data Act (AIDA) was Part 3 of Bill C-27. It never became law. When Prime Minister Justin Trudeau announced his resignation and Parliament was prorogued on 6 January 2025, C-27 died on the order paper along with the privacy reforms bundled with it. As the Schwartz Reisman Institute at the University of Toronto documented, nearly three years of committee work went with it.

It has not been reintroduced. On 4 June 2026 Prime Minister Mark Carney launched “AI for All,” Canada’s refreshed national AI strategy, built on three pillars: trust, opportunity and sovereignty. It projects $200 billion in additional economic growth and 250,000 new AI-related jobs over five years, and targets raising business AI adoption from 12% to 60% by 2034.

On regulation, the strategy signals a deliberate change of direction. A Baker McKenzie analysis published 9 June 2026 reads it as targeted legislative intervention on specific harms — deepfakes, surveillance pricing, online safety for social media and chatbot users, election integrity — rather than a comprehensive AI act on the European model.

So what governs AI in Canada today? Existing law, mostly. Federal privacy law applies to personal data used to train or run a system. The Treasury Board’s Directive on Automated Decision-Making, with its Algorithmic Impact Assessment tool, binds federal institutions. Ontario’s Bill 194 received Royal Assent in November 2024 and governs public sector AI use in hospitals, schools and policing. The Office of the Superintendent of Financial Institutions has issued Guideline E-23 on model risk management. Human rights, consumer protection and employment law apply to AI-driven decisions exactly as they apply to human ones.

For a Canadian business serving customers abroad, the practical consequence is that binding AI obligations are more likely to come from Brussels or Sacramento than from Ottawa.

The United States: states legislate, Washington pushes back

There is no comprehensive federal AI statute. There is instead a conflict between state legislatures and the federal executive.

On 11 December 2025 President Trump signed an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence.” Per Latham & Watkins, it directs the Attorney General to establish an AI Litigation Task Force to challenge state AI laws as unconstitutional or preempted, conditions certain federal broadband funding on states not enforcing “onerous” AI laws, and tasks the FTC and FCC with related actions. Colorado’s law was named as an example.

An executive order cannot itself preempt state law. Preemption requires a federal statute or a valid agency rule, and litigation of this kind takes years. But the pressure has had effects.

State legislating continued regardless. Tech Policy Press reported on 6 July 2026 that states had enacted 109 AI laws and 28 data centre laws by 1 July, with roughly 29 states passing AI legislation during the year. The dominant theme was companion chatbots — 14 laws enacted, over 100 bills introduced — typically requiring disclosure that the chatbot is not human. Their assessment is that federal preemption pressure likely reduced the count relative to 2025.

Colorado: repealed and replaced

Colorado’s SB 24-205, signed in May 2024, was the first US law to impose EU-style duties on developers and deployers of high-risk AI. Its start date was pushed to 30 June 2026, then it was scrapped. Per Seyfarth Shaw, replacement legislation SB 26-189 was signed on 14 May 2026, effective 1 January 2027.

The replacement is narrower, framed around “automated decision-making technology” used in consequential decisions in employment, education, housing, lending, insurance, healthcare and essential government services. Developers must give deployers a statement of intended uses, known limitations and training data categories, and keep records for three years. Deployers must give advance notice and, after an adverse decision, a plain-language explanation within 30 days plus information about human review. Scheduling, summarisation, fraud prevention and internal research tools are carved out. The Attorney General has exclusive enforcement, with a 60-day cure period sunsetting on 1 January 2030.

California: transparency for the largest developers

SB 53, the Transparency in Frontier Artificial Intelligence Act, was signed on 29 September 2025 and took effect on 1 January 2026. Per White & Case, a “frontier model” is one trained using more than 10^26 operations, and a “large frontier developer” additionally has over US$500 million in annual gross revenue.

Those developers must publish and annually update a frontier AI framework covering governance, mitigations and cybersecurity, and publish transparency reports when deploying new models. Critical safety incidents must be reported to California’s Office of Emergency Services within 15 days, or 24 hours where there is imminent risk of death or serious injury. Penalties run up to $1 million per violation. This is a law aimed at roughly a dozen companies; almost no ordinary business meets the thresholds.

Texas: intent-based, not impact-based

The Texas Responsible Artificial Intelligence Governance Act (HB 149) took effect on 1 January 2026. As Baker Botts explains, it differs deliberately from Colorado’s original law: liability turns on intentional misconduct, not on discriminatory outcomes. Prohibited uses include systems built to incite self-harm or crime, to intentionally discriminate against protected classes, or to produce CSAM or explicit deepfakes. Government bodies face stricter rules, including a ban on social scoring.

Penalties are tiered: $10,000–$12,000 per uncured curable violation, $80,000–$200,000 for uncurable ones, and $2,000–$40,000 per day for continuing violations, after a 60-day cure period. Texas also created a 36-month regulatory sandbox.

The UK: still no AI act

The UK has no AI-specific legislation. The House of Commons Library briefing, updated 8 July 2026, describes a context-based model in which existing regulators handle AI within their sectors: the ICO on data protection, Ofcom on online services including chatbots under the Online Safety Act 2023, and financial and energy regulators in their domains.

The Labour government indicated in its 2024 manifesto and King’s Speech that it would introduce binding rules for developers of the most powerful models. As the briefing puts it, that legislation “has not yet been forthcoming.” A private member’s Artificial Intelligence (Regulation) Bill sits in the Lords, but such bills rarely become law without government backing.

China: rules on outputs and services

China has no single AI act. Its Interim Measures for the Management of Generative AI Services have applied since 15 August 2023, requiring security assessments and regulatory filing for services with public opinion or social mobilisation capacity.

The most consequential recent change is labelling. As Covington reported, the Cyberspace Administration of China released the Measures for Labeling AI-Generated Content alongside national standard GB 45438-2025 on 14 March 2025, effective 1 September 2025. They require explicit labels visible to users and implicit labels in file metadata identifying the provider and a content ID, and distribution platforms must detect and reinforce that labelling. Three further national standards on data annotation, training data security and baseline security took effect on 1 November 2025.

What compliance actually means for a small business

If you use AI tools rather than build models, your exposure is narrower than headlines suggest. Work through this in order.

  1. Establish where your users are. The EU AI Act reaches you if your system’s output is used in the EU. US state laws generally follow the residence of the affected person.
  2. Decide whether you are a provider or a deployer. Placing a system on the market makes you a provider, with far heavier duties; using someone else’s tool makes you a deployer. Rebranding a third-party system as your own can turn you into a provider.
  3. Handle disclosure first. Label chatbots. Label synthetic media. It is cheap, and it is live now in the EU.
  4. Identify consequential decisions. If AI influences hiring, firing, credit, housing, insurance, healthcare or education access, you are in the regulated zone almost everywhere. Keep a human in the loop, document how the tool was tested, and be able to explain a decision.
  5. Keep an inventory. One spreadsheet listing every AI tool in use, what it does, what data it touches and who owns it. Every regime assumes you have this; most organisations do not.
  6. Read your vendor contracts. Under Colorado’s new law, developers owe deployers documentation. Ask for it in writing before you need it.
  7. Do not over-engineer for deferred deadlines. EU high-risk conformity work is now due December 2027. Plan for it; do not spend 2026 budget on it.

The largest practical risk for a small business is not a regulator’s fine. It is using an AI tool in a way that breaches ordinary law — discriminating in hiring, misrepresenting a product, mishandling personal data — where AI-specific rules mainly make the failure easier to prove.

Frequently asked questions

Does the EU AI Act apply to my company if I am based in Canada or the US?

It can. The Act applies to providers placing systems on the EU market and where a system’s output is used in the EU, regardless of where the company is established. Serving EU customers is usually enough.

Is the EU AI Act being repealed or watered down?

No. The Digital Omnibus delayed the high-risk deadlines and simplified some requirements, but it also added a new prohibition and expanded the AI Office’s supervisory powers. The prohibitions, general-purpose model rules and transparency duties are all live.

Will Canada pass an AI act?

Nothing comparable is before Parliament. The June 2026 strategy points toward targeted legislation on specific harms rather than a comprehensive framework. That could change, but as of September 2026 there is no bill to track.

Can the White House executive order actually cancel state AI laws?

Not by itself. Preemption requires an act of Congress or a valid federal rule, and the order’s tools are litigation and funding conditions, both of which face legal challenges. State laws remain in force meanwhile.

What is the single most useful compliance step to take now?

Build the inventory of AI systems you use and the decisions they affect. Every framework starts from that document, and it takes a day to produce.

Where this is heading

Three patterns are visible as of September 2026. Europe decided its rules were right in principle but arriving too fast, and bought sixteen extra months on the hardest part. The United States is having an unresolved argument about whether AI rules belong to states or to Washington, and businesses are caught in the middle. Canada and the UK have both declined to build a comprehensive statute, betting that existing law plus targeted fixes will do.

None of these positions is stable. The EU’s deferred deadlines will arrive, and the US preemption fight will produce court decisions. Whether the “existing law is enough” bet holds depends on whether the harms people worry about turn out to be new in kind or merely new in scale.

For anyone running a business, the useful posture is unglamorous: know what AI you use, disclose it where required, keep humans accountable for consequential decisions, and check the dates again in six months, because they have moved before.

Sources

Image credit: Photo: jeffowenphotos — CC BY 2.0 (via Wikimedia Commons)

Leave a Reply

Your email address will not be published. Required fields are marked *