11. Crossing Borders
The four markets in the previous chapter set the tone. The rest of the world is not silent: it is choosing between three paths. Some countries have written a full law and are now enforcing it. Some have decided, deliberately, not to write one, and govern AI through data-protection law, sector regulators and voluntary guidance. A few small, well-run economies write frameworks that everyone else copies. For a company that sells, hires or processes data in more than one country, the map matters less than the method for reading it.
This chapter has two parts. The first is a tour: the countries that matter to an internationally active SME, each in a few lines — what is binding today, what is coming, what it means for you. The second is the part I would read first if I were you: how to operate in several countries without running several compliance programs. By the end you will be able to decide which single baseline your company adopts, and how to add a country to it in a week rather than a quarter.
The second wave: countries with a law
South Korea
Status. The AI Basic Act came into force on January 22, 2026 — the second comprehensive national AI law in the world after the EU's — with a one-year grace period on fines. Today. It reaches companies abroad: a foreign company above certain thresholds (roughly, very large revenue or more than a million daily Korean users) must appoint a domestic representative. "High-impact" uses — health, energy, transport, hiring, biometrics — require a self-assessment before deployment, a meaningful explanation to the person affected, a user-protection plan and human oversight. Generative AI must be announced to users, and AI-generated sound, image and video must be labeled. Coming. Fines start when the grace period ends in January 2027; they are modest, up to KRW 30 million (about $21,000). For you. Small fines, real duties. The notice-and-labeling rule and the high-impact self-assessment are already in force, and the law was designed to be compatible with the EU's: one design serves both.
Japan
Status. The AI Promotion Act, in force since June 2025, is a promotion-and-governance framework, not an obligations regime; the AI Basic Plan of July 2026 is non-binding. Today. Companies have a duty to cooperate with government measures and are expected to follow the AI Guidelines for Business (version 1.2, March 2026): voluntary, lifecycle-based, no fines, no bans, no mandates. The Digital Agency's procurement guideline and the AI Safety Institute's evaluation guides for agents (July 2026) show what public buyers will ask for. For you. The lightest regime among the major economies. The guidelines are not law, but they are what your large Japanese customers and any public tender will require you to follow.
India
Status. No standalone AI law and none planned. The AI Governance Guidelines of April 2026 are voluntary; the binding layer is the Digital Personal Data Protection Act 2023, whose rules are being phased in, plus the sector regulators for banking, securities and insurance. Today. Consent architecture, impact assessments for larger data holders, vendor compliance for third-party AI, and a 72-hour breach notice. The approach is "techno-legal": self-certification, sandboxes, and ISO/IEC 42001 recommended as the governance backbone. For you. Map your AI to the data law and the sector rules; adopt ISO 42001 as the reference; test for bias in hiring and credit. And note the size of the public investment behind it (chapter 9).
Brazil
Status. Bill PL 2338/2023 — the Marco Legal da IA — passed the Senate in December 2024 and is pending in the Chamber of Deputies. Today's binding layer is the LGPD, the data-protection law, enforced by the ANPD, which the bill designates as AI authority. What the bill does. Three tiers, modeled on the EU: prohibited uses (public social scoring, real-time biometric identification in public spaces), high-risk uses requiring an algorithmic impact assessment before deployment (credit, hiring, education, justice, public services), and transparency for most consumer-facing AI. Penalties up to R$50 million per infraction or 2% of Brazilian revenue. For you. The LGPD applies now. If you hire, lend or serve consumers in Brazil, design as high-risk today: the bill's structure mirrors the EU's, and a system built for Brussels will not need rebuilding for Brasília.
Watch out. "There is no AI law here yet" is the most expensive sentence in this chapter. In every country on this page without a law, the data-protection authority is already the AI regulator in practice: consent, purpose, minimization, automated-decision rights and breach notices apply to every agent that touches personal data. Companies that wait for the AI bill accumulate what Canadian commentators call "retrofit debt" — the cost of redesigning what could have been designed right once.
The deliberate abstainers
Canada
Status. No AI law. The Artificial Intelligence and Data Act died when Parliament was prorogued in January 2025 and was not reintroduced; the government signaled it will regulate through privacy law, policy and investment, and consultations in February 2026 point to future duties on safety evaluation, human oversight and traceability. Today. Federal privacy law applies to personal data in training, retrieval and outputs; Quebec's Law 25 requires disclosure of automated decisions; the financial regulator's Guideline E-23 governs model risk in banks and insurers; human-rights codes cover discriminatory outcomes. For you. No AI-specific duty yet, but the principles are visible and exporters already treat the EU AI Act as the de-facto standard.
Australia
Status. The mandatory guardrails for high-risk AI proposed in 2024 were dropped in December 2025 and replaced by a National AI Plan built on existing technology-neutral law, voluntary guidance and a new AI Safety Institute. Today. The Privacy Act, consumer law, anti-discrimination law and sector regulators; the Guidance for AI Adoption as the voluntary reference. For you. No AI-specific mandate. Follow the guidance anyway: it is the checklist public buyers and large corporates will use, and the Privacy Act reform on transparency of automated decisions is the item to watch.
The Gulf: UAE and Saudi Arabia
Status. No horizontal AI law in either country, and the largest state AI investments in the world (chapter 9). The UAE created a Federal Authority for AI and Data in June 2026 and runs a layered regime: the federal data-protection law is binding, the Central Bank's guidance note of February 2026 is prescriptive for financial institutions (board accountability, model inventories, annual bias testing, human review, a kill-switch), the AI Charter is voluntary. Saudi Arabia has a binding data-protection law with active enforcement, voluntary SDAIA ethics and generative-AI guidelines, and a National AI Risk Management Framework (July 2026) for public and private entities. For you. Data protection is the binding constraint; sector guidance is precise where it exists; the national frameworks are voluntary in law and expected in every public tender.
The framework exporters
Three small economies write the documents everyone else borrows. Singapore has no cross-sector AI law and the world's most used voluntary frameworks: the Model AI Governance Framework, its generative-AI edition, the AI Verify testing toolkit, and — since January 2026 — the first national framework for agentic AI, which addresses exactly the questions this book asks: levels of autonomy, what data an agent may access, whether its actions can be reversed, who in the human chain is accountable. Switzerland chose to ratify the Council of Europe convention and regulate sector by sector rather than copy the EU act; the implementing bill is due at the end of 2026, and public procurement will pass the convention's standards on to suppliers. Israel governs by policy, innovation first, with existing privacy law and the Council of Europe convention as the backbone.
Where to look. If you read one non-EU document, read Singapore's Model AI Governance Framework for Agentic AI (January 2026). It is short, written for companies rather than lawyers, and it is the best practical checklist I know for an AI Team: autonomy levels, data access, reversibility of actions, and a named human accountable for each agent. It maps directly onto the CoS you will write with your consultant.
Other markets in brief
| Country | Status in 2026 | What binds you today |
|---|---|---|
| Vietnam | Law in force — comprehensive AI Law effective March 2026, among Asia's first binding statutes | The AI Law itself; verify obligations for your use case |
| Turkey | Draft risk-based AI bill in parliament | Data-protection law (KVKK) |
| Mexico | No AI law; dozens of pending bills | Overhauled data-protection regime |
| South Africa | Draft National AI Policy Framework (2026) | Automated-decision controls under POPIA |
| Indonesia | National AI ethics guidelines in force; binding rules expected | Voluntary ethics; anticipate mandates |
| Nigeria | National AI Strategy; binding framework in preparation | Data-protection act (NDPA) |
If you operate in more than one country
Here is the part that saves money. Read this chapter together with chapter 10 and one fact stands out: the differences are in form, not in substance. Every country asks for the six things in the common core; each asks in its own paperwork. The mistake is to answer each country separately. The method is to build one baseline and add modules.
Map before you build. One sheet: every country where you have customers, employees, suppliers or data; for each, the AI systems and agents that touch it; for each system, the rule that applies and the date it bites. This is the regulatory matrix, and it is the first thing your consultant and your lawyer should see.
Adopt the highest standard as the common base. In practice that means the EU AI Act's core — transparency, human oversight, documentation, literacy, risk tiering — plus ISO/IEC 42001 as the management system and the NIST framework for US customers. A company that fully meets the EU act has, by default, covered roughly 70-80% of what other jurisdictions ask; the rest is modules: a domestic representative in Korea, an impact assessment in Brazil, a label format in China, a state notice in California or Texas.
Follow the data. Rules on where data may live and where it may travel are the one place where a module is not optional. China is the most restrictive (local storage, filings, security assessments for transfers); the EU requires a transfer mechanism; the US and the UK are mostly territorial with state and sector variations. Decide, agent by agent, where its data sits and who may see it, and write it down before the agent goes live.
Put it in the contracts. Four clauses do most of the work: a data-processing agreement that bars transfers to non-compliant systems; a duty to review outputs before they reach customers where the law requires it; an attestation from every model provider on training data, security and labeling; and an explicit allocation of who is responsible for conformity assessment when a rule requires one. Chapter 12 gives you the full list.
Know what breaks in the supply chain. When a supplier in one country uses AI to serve you in another, their obligations become your evidence problem. Ask every supplier that uses AI on your data or your customers for the same four things you ask of yourself: what system, what data, what oversight, what documentation.
Example. A furniture manufacturer with $60 million in revenue sold in the EU, the UK, the US and the Gulf and had, without anyone deciding it, seven AI systems in use: two inside its ERP, a customer-service agent, a recruiting screener, a pricing tool, and two marketing tools. It started with a matrix — seven systems, four regions, one row each — and discovered that the recruiting screener was the only high-risk item everywhere. It rebuilt that one system on the EU standard, adopted ISO 42001 as the backbone, and handled the other six with notices, labels and a supplier attestation. Total effort: one quarter, one owner, one consultant, one law firm review. (Case anonymized.)
Where this is going: 2027-2028
Three movements are visible. Convergence: South Korea, Brazil, Vietnam and the Council of Europe signatories are building on the EU's tiers, so the baseline strategy gets cheaper every year. Enforcement: the EU's high-risk deadline (December 2027), Korea's end of grace (January 2027), the UK's AI code and the first Vietnamese cases will turn documents into inspections. Agents as the new object: Singapore's agentic framework, Japan's evaluation guides for agents and the US federal debate on agent liability all point the same way — the next round of rules will be about what autonomous systems may do, not only what they may say. A company that already governs its agents with CoS, thresholds and a named human on the loop will find that round easy.
What to take away
Outside the four tone-setting markets, the world splits into countries with a law (South Korea, Vietnam, soon Brazil), countries that abstain on purpose (Japan, Canada, Australia, the Gulf) and countries that export frameworks (Singapore, Switzerland). All of them ask for the same six things. Build one baseline — the EU core, ISO 42001, NIST — keep one regulatory matrix, name one owner, and let the contracts follow the data. Adding a country then becomes a module, not a program.
Your to-do list.
- Draw the matrix: countries in rows, AI systems in columns, in each cell the rule that applies and its date. The empty cells are the agenda for your lawyer and your consultant.
- Adopt one baseline — EU core, ISO 42001, NIST — and write it in one sentence for your suppliers.
- For every agent, decide where its data sits and who may see it, before it goes live.
Frequently asked questions
If I sell in multiple countries, do I need a separate AI compliance program for each one?
No — build one baseline instead. In practice that means the EU AI Act's core (transparency, human oversight, documentation, literacy, risk tiering) plus ISO/IEC 42001 as the management system and the NIST framework for US customers; a company that fully meets that baseline has, by default, covered roughly 70-80% of what other jurisdictions ask, and everything else becomes a small country-specific module rather than a new program.
My country does not have an AI law yet — does that mean I do not need to worry about compliance?
"There is no AI law here yet" is described as the most expensive sentence a CEO can say. In every country without a dedicated AI law, the existing data-protection authority is already acting as the AI regulator in practice, and companies that wait accumulate what is called "retrofit debt" — the cost of redoing later what could have been designed right the first time.
Which countries outside the EU and US already have binding AI laws?
South Korea's AI Basic Act, in force since January 2026 (which can require a foreign company to appoint a domestic representative), and Vietnam's comprehensive AI Law, effective March 2026, are the two most advanced. Brazil's bill has already passed the Senate and is expected to follow the EU's three-tier structure once it clears the Chamber of Deputies.
Is there a good practical framework for governing AI agents specifically, not just AI in general?
Singapore's Model AI Governance Framework for Agentic AI, published January 2026, is the one document worth reading if you read only one non-EU source. It is written for companies rather than lawyers and addresses exactly the questions this book asks: levels of autonomy, what data an agent may access, whether its actions can be reversed, and who in the human chain is accountable for it.
Sources
- Cooley, South Korea's AI Basic Act: Overview and Key Takeaways, January 2026.
- Library of Congress, South Korea: Comprehensive AI Legal Framework Takes Effect, February 2026.
- Vorp Labs, Japan AI regulatory update: AI Promotion Act, Basic Plan and business guidance, July 2026.
- Future of Privacy Forum, Understanding Japan's AI Promotion Act, 2025.
- SARC Global, India's AI Governance Guidelines, 2026.
- AIRiskAware, India AI Policy: DPDP, SEBI, RBI and What Applies, 2026.
- CMS, AI laws and regulations in Brazil, 2026.
- Library of Congress, Brazil: Senate Advances Discussions on Bill to Regulate AI Use, May 2025.
- ClarityArc, AI Regulation in Canada: What Actually Applies in 2026, 2026.
- Montreal AI Ethics Institute, From proposed mandatory guardrails to the National AI Plan: AI governance in Australia, 2026.
- The Middle East Insider, UAE AI Regulation 2026: Federal Framework Explained, April 2026.
- CMS, AI laws and regulations in Saudi Arabia, 2026.
- Regulations.ai, Singapore: Model AI Governance Framework for Agentic AI, January 2026.
- CMS, Switzerland to ratify Europe's landmark AI Framework Convention, 2025.
- VerifyWise, Global AI Regulations Tracker 2026, 2026.
- Legalithm, AI Regulation Compared: EU, US, UK, China, 2026.
- White & Case, AI Watch: Global regulatory tracker, 2026.
Comments & reviews
No comments yet.
Log in to leave a comment or review.