10. Who Writes the Rules
Every rule in this chapter was verified in September 2026. Regulation is the part of this book that ages fastest: dates move, bills pass or die, authorities publish guidance. The online edition keeps every country entry current; treat the print version as a map, and check the date on the road sign.
This chapter exists for a simple reason: the person who answers for AI rules is the person who runs the company, not the consultant and not IT. You do not need to become a lawyer. You need to know what is mandatory today in the markets that set the tone, what is coming, and what those rules have in common — because the common core is what you build once and reuse everywhere. Chapter 11 covers the rest of the world and how to operate across borders; chapter 12 turns all of it into what you do and what you delegate.
By the end of this chapter you will be able to say, for each of the four markets that matter most, whether you are affected today, when the next deadline falls, and which of the six common obligations you must already be meeting.
The common core: what every framework asks for
Strip away the legal language and every AI framework in the world — binding or voluntary, from Brussels to Beijing — asks companies for the same six things. Learn these and you have learned 70-80% of every rulebook.
| # | Obligation | In plain terms |
|---|---|---|
| 1 | Transparency | People know when they are dealing with AI, and AI-generated content says so |
| 2 | Human oversight | A person can intervene on decisions that matter, and does |
| 3 | Data governance | Data is lawful, minimal, protected and traceable |
| 4 | Documentation | You can show what the system does, on what data, with what limits, who approved it |
| 5 | AI literacy | The people who operate AI know what they are doing, and you can prove it |
| 6 | Risk tiering | Obligations scale with the harm a use can cause: hiring, credit, health and safety sit at the top |
Everything else — filings, labels, registers, impact assessments — is a local way of enforcing one of the six.
The international baseline
Above the national laws sits a layer of frameworks that bind no company directly but shape every contract, tender and audit you will face.
- OECD AI Principles (2019, updated 2024): the first intergovernmental AI standard, adopted by 47 countries including non-members such as Brazil and Singapore; the source text for the G20 principles and for most national strategies.
- G7 Hiroshima Process (2023) and its Reporting Framework (February 2025): a voluntary code of conduct for developers of advanced AI, with a public reporting mechanism; 19 organizations reported in its first round. It is aimed at model makers — but it is the checklist large customers borrow when they audit suppliers.
- Council of Europe Framework Convention on AI (opened September 2024): the first legally binding international AI treaty, signed by the EU, the UK, the US, Canada, Israel and others, and ratified by the EU in 2026. It binds states, not companies, but it is the text national laws will converge on.
- ISO/IEC 42001 (2023): the certifiable AI management-system standard — the AI equivalent of ISO 27001 for security. More than 350 organizations were certified by April 2026, including the largest cloud and model providers. For you it is the one certificate to ask a supplier or consultant about, and the framework to borrow even if you never certify.
- NIST AI Risk Management Framework (US, 2023; generative-AI profile 2024): voluntary, four functions — govern, map, measure, manage — and the de-facto reference in US procurement and in most US state laws.
Try this. If you sell to large companies or to governments anywhere, ask your consultant to map your first AI Team against ISO 42001's clauses. It takes a day, costs nothing, and produces the document your customers' procurement teams will ask for within a year.
European Union
Status. Comprehensive, binding, in force. The AI Act (Regulation 2024/1689) is the world's first full AI law; the Digital Omnibus (Regulation 2026/1744, in force July 27, 2026) postponed the high-risk deadlines and confirmed everything else. It applies to any company that places AI on the EU market or whose AI affects people in the EU — including companies based elsewhere.
What applies today to a company using AI. You are almost always a deployer — a user of AI in your own business — and your obligations are lighter than those of the provider who builds the system. Since February 2025: prohibited practices (social scoring, manipulation, and similar) and AI literacy — staff who use AI must have adequate, documented competence. Since August 2, 2026: transparency — people must be told when they interact with AI; AI-generated or manipulated content intended to inform the public must be labeled; deployers must label deepfakes. Systems already on the market have until December 2, 2026, for machine-readable marking. Penalties are active: up to €35 million or 7% of global turnover for prohibited practices, €15 million or 3% for transparency breaches; for SMEs the lower of the two figures applies.
What is coming. December 2, 2027: full obligations for high-risk uses — employment and HR decisions, credit, education, essential services, biometrics, critical infrastructure — with risk management, documentation, human oversight and conformity assessment. August 2, 2028: AI embedded in regulated products such as machinery and medical devices. August 2027: regulatory sandboxes for SMEs. Throughout: the GDPR is unchanged and fully applicable to every AI data flow.
What it means for you. Literacy, transparency, documentation and human oversight are due now. Any agent that helps you hire, evaluate staff, grant credit or decide access to a service will be high-risk in fifteen months and must be designed as such today. And because the EU rulebook is the one most other jurisdictions are converging on, meeting it is a reasonable "highest common denominator" for a company operating across borders.
United States
Status. No comprehensive federal AI law. Federal policy is set by executive order, pro-innovation, and actively pushing to preempt state laws — but preemption has not been enacted: "a live push, not settled law." Binding obligations for private companies sit in state law and in existing sector regulators (consumer protection, employment, financial and health authorities).
What applies today. At federal level: the 2025 executive orders reset policy toward innovation and launched a preemption strategy through the Justice and Commerce departments; the only AI-specific federal statute is the TAKE IT DOWN Act (2025) on non-consensual intimate imagery, including deepfakes. The NIST framework is voluntary but expected. At state level, the map as of September 2026:
| State | Law | In effect | What it asks of a company using AI |
|---|---|---|---|
| Texas | TRAIGA | Jan 2026 | No AI for discrimination, manipulation, social scoring or biometric misuse; disclose consumer-facing AI in government and healthcare |
| Illinois | Human Rights Act amendment | Jan 2026 | Employers: no discriminatory AI; notify employees of AI use in employment decisions; older biometric and video-interview laws still bite |
| California | CCPA automated-decision rules | Jan 2026, significant decisions Jan 2027 | Pre-use notice, opt-out or human review, explain the logic, risk assessments, cybersecurity audits |
| California | AI Transparency Act; SB 53 | Aug 2026; Jan 2026 | Disclosure tools for large generative-AI providers; safety duties for frontier developers |
| Utah | AI Policy Act | May 2024 | Disclose that a person is interacting with generative AI |
| New York | RAISE Act | Jan 2027 | Safety duties for frontier developers; companion-AI safeguards |
| Colorado | Automated Decision-Making Technology Act (replaces the never-effective 2024 AI Act) | Jan 2027 | In employment, housing, credit, insurance, health, education: pre-use notice, post-decision disclosure, data correction, human review on request |
What is coming. More states every session; possible federal preemption that could freeze or replace state duties; Colorado's rulemaking through late 2026.
What it means for you. There is no single US rulebook; obligations follow where your customers and employees are. But the recurring duties across states are the same six as the common core — notice, human review, non-discrimination, risk assessment. A NIST-aligned risk process plus employee and consumer notice covers most of the map. Watch preemption: it is the one event that could change everything at once.
United Kingdom
Status. No AI Act, by deliberate choice. Principles-based regulation through existing regulators, with data-protection law as the binding backbone — reformed by the Data (Use and Access) Act 2025.
What applies today. Since February 5, 2026, the rules on automated decisions have flipped from "not permitted unless" to "permitted provided safeguards": you must be able to evidence notice, human intervention and a way to contest. The Information Commissioner is under a statutory duty (since May 2026) to publish an AI code; sector regulators — finance, medical, communications, competition, legal — publish their own AI expectations; the Online Safety Act covers AI-powered services. The five cross-sector principles are safety, transparency, fairness, accountability and contestability. The EU AI Act applies to UK companies selling into the EU.
What is coming. The ICO's final AI code; repeatedly delayed narrow legislation on frontier models; convergence pressure from the EU and the Council of Europe convention, which the UK has signed. A regulatory sandbox (AI Growth Lab) opened in June 2026.
What it means for you. Build an AI register that includes AI features inside the software you already use; map each system to the regulator that owns its sector; name one accountable person; do due diligence on third-party AI; keep evidence ready. Lighter than the EU, but not lighter on evidence.
China
Status. No single AI law yet — a comprehensive one is under review with no public draft — but a dense, binding, rule-by-rule regime enforced by the Cyberspace Administration of China, the strictest in the world on content and data.
What applies today. Algorithm filing with the regulator (since 2022). Labeling of synthetic media (since 2023). For any public-facing generative AI: security assessment and filing before launch, content aligned with state values, lawful training data, user identity verification, complaint channels (since August 2023). Since September 1, 2025: explicit and embedded labels on all AI-generated text, image, audio and video, with platforms required to detect and label. Four national technical standards (2025). And the data laws — Cybersecurity Law, Data Security Law, Personal Information Protection Law — with approvals required for cross-border data transfer.
What is coming. The comprehensive AI Law, on an unclear timeline; continued expansion of standards; enforcement campaigns.
What it means for you. If you sell or operate in China, any public-facing generative AI needs filing and assessment before launch, labeling is mandatory, and data localization bites hardest. If you use Chinese-hosted models for operations elsewhere, the data-transfer question runs the other way. Either direction, this is the market where "which cloud, under whose law" is not a preference but a requirement.
Reading the four together
| European Union | United States | United Kingdom | China | |
|---|---|---|---|---|
| Single AI law | Yes, in force | No (states + sectors) | No (principles + data law) | No (rule-by-rule, binding) |
| Transparency to users | Mandatory since Aug 2026 | Mandatory in several states | Expected; data-law based | Mandatory, with labels since 2025 |
| Human oversight | Mandatory; high-risk from Dec 2027 | State laws on significant decisions | Mandatory for automated decisions since Feb 2026 | Required in practice via filing and assessment |
| Documentation | Heavy for high-risk | Risk assessments in CA, CO | Evidence-based; AI register | Filing and security assessment |
| AI literacy | Mandatory since Feb 2025 | Not explicit | Expected | Not explicit |
| Penalties | Up to 7% of turnover | Per-violation fines, up to $200k (TX) | Data-protection fines | Administrative; license and platform sanctions |
| Direction of travel | Stable, deadlines fixed | Fragmenting, preemption pending | Codifying slowly | Tightening on content and data |
Data point. A company that fully meets the EU AI Act has, by default, addressed roughly 70-80% of the requirements of other jurisdictions. Building separate compliance programs for each market is "unsustainable for most organizations"; the workable strategy is one baseline plus country modules. Source: Legalithm, AI Regulation Compared: EU, US, UK, China, 2026.
What to take away
Four markets set the tone, and they are converging on the same six obligations while differing in form: the EU has one law with fixed dates, the US has a state patchwork with preemption pending, the UK regulates through data law and sector regulators, China through binding rules on content and data. The international layer — OECD, G7, Council of Europe, ISO 42001, NIST — binds no company directly but shapes every contract and tender. Build once on the EU core plus ISO 42001 and NIST, then add country modules.
Your to-do list.
- On one sheet, list every country where you have customers, employees or data, and next to each the date of the next AI rule that applies to you.
- Check the six obligations of the common core against your first agent: which ones does it already meet?
- If a date is within twelve months, make it the first agenda item with your consultant.
Frequently asked questions
Does the EU AI Act apply to my company if I am not based in Europe?
Yes, if your AI affects people in the EU or you place AI on the EU market, regardless of where your company is headquartered. Since August 2026, deployers must disclose AI interactions to users and label AI-generated content aimed at the public; penalties reach up to €35 million or 7% of global turnover for the most serious breaches, with lower caps for SMEs.
What AI rules actually apply to my business right now, today?
Strip away the legal language and every framework worldwide asks for the same six things: transparency, human oversight, data governance, documentation, AI literacy for the people operating it, and risk tiering that scales obligations with potential harm. Learning these six is learning 70-80% of every rulebook — everything else is a local way of enforcing one of them.
Is there one global AI law I need to follow, or does every country have different rules?
There is no single global AI law. The four markets that set the tone differ sharply in form — the EU has one comprehensive law with fixed dates, the US regulates through a state-by-state patchwork, the UK works through data-protection law and sector regulators, China through binding rule-by-rule enforcement — but all four converge on the same six common obligations.
What happens if my company does not comply with AI regulations?
Penalties are already active, not theoretical. In the EU, prohibited practices carry fines up to €35 million or 7% of global turnover, and transparency breaches up to €15 million or 3%, with the lower figure applying to SMEs; in the US, obligations and fines vary by state, with Texas reaching up to $200,000 per violation. Beyond fines, non-compliance in most jurisdictions today also means missing the case a large customer's procurement team will ask to see.
Sources
- OECD, Recommendation of the Council on Artificial Intelligence, 2019, updated 2024.
- OECD.AI, Early insights from the Hiroshima AI Process Reporting Framework, 2025.
- Council of Europe, The Framework Convention on Artificial Intelligence, 2024-2026.
- ISO, ISO/IEC 42001:2023 — AI management systems, 2023.
- NIST, AI Risk Management Framework, 2023-2024.
- European Union, Regulation (EU) 2024/1689 — Artificial Intelligence Act, 2024.
- Cooley, EU AI Act: Transparency Obligations Take Effect 2 August 2026, August 2026.
- Regulation-AI.eu, EU AI Act Enforcement Has Started: What Changed on 2 August 2026, 2026.
- Vorp Labs, US AI Regulation Update: August 2026 Laws & Policy, 2026.
- Glacis, US State AI Laws Tracker: What Changed in 2026, 2026.
- Ropes & Gray, The White House Legislative Recommendations and Federal Preemption of State AI Laws, March 2026.
- Scaffold Digital, UK AI Regulation in 2026: What's in Force, What's Coming, 2026.
- CMS, AI laws and regulations in China, 2026.
- Legalithm, AI Regulation Compared: EU, US, UK, China, 2026.
Comments & reviews
No comments yet.
Log in to leave a comment or review.