Clear AI News newsletter preview

Enter your email address below and subscribe to our newsletter

AI Regulation Changes by Country: What Businesses Need to Know Now

AI Regulation Changes by Country: What Businesses Need to Know Now

9 min read 2,022 words
⏱ 7 min read

aug. 30, 2026

By Alex Clearfield

Share:
𝕏
P
f

Disclosure: ClearAINews may earn a commission from qualifying purchases through affiliate links in this article. This helps support our work at no additional cost to you. Learn more.

This article contains affiliate links. We may earn a commission at no extra cost to you. Full disclosure.




⚠ Duplicate check: This draft looks similar to an existing post (semantic match, 82% similarity) — AI Regulation Updates: What the Data Actually Shows (2026). Decide to merge, rewrite angle, or publish as follow-up before going live.

In April 2024, the European Parliament gave final approval to the EU AI Act, imposing fines of up to 35 million euros or 7% of global annual turnover—whichever is higher—for the most serious violations. Yet a survey by IBM in May 2024 found that only 38% of European businesses had even started mapping their AI systems against the new risk categories. The first compliance deadline, covering prohibited practices like social scoring and real-time biometric surveillance, arrives in February 2025—not 2026 as many assume. Meanwhile, the United States has taken a different path with a presidential executive order that sets a compute threshold of 1026 FLOPs for mandatory safety reporting, and China now requires algorithm filing for any generative AI service used by the public. For companies developing or deploying AI systems, the regulatory landscape is no longer theoretical—it is a patchwork of overlapping, sometimes contradictory, compliance obligations that demand immediate attention.

The EU AI Act: Risk-Based Tiers and Compute Thresholds

The EU AI Act classifies AI systems into four risk categories: unacceptable, high, limited, and minimal. Unacceptable risk systems, such as those using subliminal manipulation or social scoring by governments, are banned outright from February 2025. High-risk systems—including those used in employment, credit scoring, law enforcement, and critical infrastructure—must undergo conformity assessments, maintain detailed technical documentation, and ensure human oversight. The Act also introduces rules for general-purpose AI (GPAI) models, with an additional tier for those posing “systemic risk,” defined as models trained using a total computing power exceeding 1025 FLOPs.

This compute threshold is not arbitrary: it captures models such as OpenAI’s GPT-4 (estimated at 2.1×1025 FLOPs), Meta’s Llama 3 405B (estimated 3.8×1025 FLOPs), and Google’s Gemini Ultra (estimated 5.0×1025 FLOPs). However, the European Commission has not yet published a standardised methodology for measuring FLOPs across different hardware architectures—a gap that could lead to disputes. The timeline is aggressive: GPAI rules take effect in August 2025, and high-risk system requirements in August 2026. Companies must appoint an EU-based representative if they are not established in the Union, and they must register their high-risk systems in a public EU database. Fines for non-compliance with GPAI obligations are up to 3% of global turnover or 15 million euros.

⭐ Notion

Top-rated Notion — check latest deals.


Check Notion →

Affiliate link

⭐ NordVPN

Top-rated VPN for online privacy and security. Lightning-fast servers.


Check NordVPN →

Affiliate link

A critical nuance: the Act exempts AI systems developed solely for research or released under open-source licenses, provided they are not placed on the market as a product. This has led to debate over whether open-weight models like Llama 3 fall under GPAI rules when used commercially. The European Commission’s AI Office, which began work in June 2024, is expected to issue interpretive guidelines by early 2025, but businesses should not wait—preparing documentation now is the only way to meet the August 2025 deadline for GPAI providers.

United States: Executive Orders, State Laws, and FTC Enforcement

Stay in the loop

Get the latest insights delivered straight to your inbox.

The US approach remains fragmented. President Biden’s Executive Order 14110, signed in October 2023, requires developers of “dual-use foundation models” to report safety test results, red teaming outcomes, and training compute to the Department of Commerce. The threshold is set at 1026 FLOPs—ten times higher than the EU’s systemic risk trigger—meaning only the largest training runs, such as those for GPT-4 or Gemini Ultra, are captured. The order also mandates that federal agencies develop standards for AI safety, watermarking, and synthetic content detection, but it does not impose direct penalties on companies.

State-level activity is more concrete. Colorado passed the AI Act in May 2024, which classifies AI systems used in employment, housing, and insurance as high-risk and requires impact assessments by February 2026. California’s SB 1047, which would have imposed liability on developers of large models, was vetoed in September 2024, but Governor Newsom signed several narrower bills targeting deepfakes and algorithmic discrimination. The FTC has been active: in March 2024, it settled with DoNotPay over claims that its AI chatbot could replace lawyers, and in July 2024 it warned companies against making unsubstantiated claims about AI capabilities. The agency’s “Operation AI Comply” initiative, launched in September 2024, has already issued five enforcement actions.

For businesses, the US presents a compliance puzzle. Federal reporting applies only to companies training models above the 1026 FLOPs threshold—essentially frontier labs. But state laws apply to any company deploying AI in covered sectors within that state. A hiring algorithm used in Colorado must undergo an impact assessment even if the developer is based in New York. The patchwork means that a single AI system may need to comply with multiple, sometimes conflicting, state requirements. The National Institute of Standards and Technology (NIST) published its AI Risk Management Framework in January 2023, which many companies use as a voluntary baseline, but it has no enforcement power.

China: Generative AI Regulation and Algorithm Filing

China’s Interim Measures for Generative AI, effective since August 2023, require providers of generative AI services to the public to register their algorithms, conduct security assessments, and ensure that generated content aligns with “socialist core values.” The algorithm filing system, managed by the Cyberspace Administration of China (CAC), had registered over 1,400 algorithms by October 2024, covering everything from Baidu’s ERNIE Bot to Alibaba’s Tongyi Qianwen. Non-compliance can result in fines of up to 100,000 RMB (approximately $14,000) for individuals and 300,000 RMB for companies, but the CAC also has the power to suspend services or revoke licenses.

Foreign companies face additional hurdles. To offer generative AI services in China, a foreign entity must partner with a Chinese company that holds the required licenses—a process that can take six to twelve months. The security assessment, which includes a review of training data sources and model behaviour, is conducted by the CAC and can require multiple rounds of revisions. In practice, only a handful of foreign AI models have been approved: Microsoft’s Copilot, for instance, is available only through a joint venture with 21Vianet, while OpenAI’s ChatGPT is blocked entirely. The filing process also requires disclosure of model architecture and training compute, which many companies consider proprietary.

China’s approach is often described as “tough but vague.” The requirement to “uphold socialist core values” leaves room for interpretation, and enforcement has been uneven. In early 2024, the CAC fined a local startup for generating images that allegedly distorted historical events, but many other violations go unpunished. For businesses, the key takeaway is clear: if you plan to offer AI services to users in mainland China, you must engage local legal counsel early, expect a six-month approval timeline, and prepare to submit detailed technical documentation. The alternative—serving Chinese users from outside the country—risks being blocked by China’s firewall.

Asia: Japan, Singapore, South Korea

Japan has taken a light-touch approach. The Ministry of Economy, Trade and Industry (METI) released its AI Guidelines for Business in April 2024, which encourage transparency, safety, and fairness but impose no penalties. Instead, METI is working with industry groups to develop voluntary standards, and the government has stated it prefers to avoid legislation that could stifle innovation. Japan’s stance is partly pragmatic: the country lags in AI development, and heavy regulation could push talent elsewhere. However, companies operating in Japan should still document their AI governance practices, as the guidelines are expected to inform future legal frameworks.

Singapore offers a more structured voluntary model. The Infocomm Media Development Authority (IMDA) launched the Model AI Governance Framework in 2019 and updated it in 2024 to include generative AI. The framework provides detailed guidance on accountability, transparency, and fairness, and is accompanied by the AI Verify testing toolkit, which allows companies to self-assess their systems. Singapore has also introduced a “sandbox” regime for high-risk applications, such as AI in healthcare, where companies can test under regulatory supervision. While voluntary, the framework is influential across Southeast Asia, and companies that adopt it often use it as a reference for other jurisdictions.

South Korea passed its AI Act in December 2024, effective January 2026. The law is modelled closely on the EU AI Act, with risk-based tiers, conformity assessments for high-risk systems, and fines of up to 30 million won (approximately $22,000) for violations. However, it includes a notable carve-out: AI systems used solely for research or for internal business processes that do not affect third parties are exempt. South Korea’s Act also requires developers of generative AI to label AI-generated content, a requirement similar to the EU’s but with a shorter implementation timeline. For businesses, South Korea represents a middle ground between the EU’s heavy obligations and Japan’s hands-off approach.

Immediate Compliance Steps for Businesses

Given the divergence across jurisdictions, a one-size-fits-all compliance strategy is impossible. However, several universal steps can reduce risk. First, inventory all AI systems in use or development, and classify them by risk category using the EU’s definitions as a baseline—even if your company is not EU-based, this framework is becoming the global de facto standard. Second, document training data sources, model architecture, and training compute for every foundation model you develop or fine-tune. The compute threshold of 1025 FLOPs is likely to become a regulatory trigger in multiple countries; knowing where you stand is essential.

Third, appoint a responsible person or team for AI governance, ideally with legal and technical expertise. The EU requires an EU-based representative; the US executive order expects a point of contact for safety reports; China requires a legal representative for algorithm filing. Having a single cross-jurisdictional team can avoid duplication. Fourth, engage with third-party auditing tools where available. Singapore’s AI Verify toolkit is free and can be used anywhere; the EU’s CEN-CENELEC standards for high-risk AI are expected in late 2025, but early adoption of similar frameworks (such as NIST’s AI RMF) will speed later compliance.

The cost of non-compliance can be severe. A conformity assessment for a single high-risk AI system under the EU AI Act can range from €50,000 to €200,000, according to estimates from law firm Osborne Clarke. But the cost of ignoring the deadlines is higher: in addition to fines, companies risk reputational damage and forced service shutdowns. The first deadline—February 2025 for prohibited practices—is only months away. Any company that uses AI for social scoring

Get the AI Edge, Weekly

The tools, tutorials, and trends that actually pay — no hype.

Enjoyed this article?

Join ClearAINews for exclusive content and updates.

Subscribe Free
Alex Clearfield
Written byAlex Clearfield

Alex Clearfield reports on AI industry news, product launches, and technology trends for Clear AI News. With a commitment to factual reporting, Alex provides balanced coverage of the rapidly evolving artificial intelligence landscape.

Împărtășește-ți dragostea
Alex Clearfield
Alex Clearfield

Alex Clearfield reports on AI industry news, product launches, and technology trends for Clear AI News. With a commitment to factual reporting, Alex provides balanced coverage of the rapidly evolving artificial intelligence landscape.

Articole: 319

Stay informed and not overwhelmed, subscribe now!

Enjoyed this article?

Join thousands of readers who get our best insights delivered weekly. Free, no spam, unsubscribe anytime.

Subscribe Free →
Featured on
Listed on DevTool.ioListed on SaaSHubFeatured on FoundrListFeatured on Twelve Tools
Featured on
Listed on DevTool.ioListed on SaaSHubFeatured on FoundrList