Skip to content

AI regulation in the US, UK, Canada, and Australia

If your company operates in any of these four countries, the first question you ask is "what's their AI Act?" — and in all four cases, the answer is that they don't have one. Each country regulates AI in its own fragmented way. Here's a practical map of what actually applies today.

United States — no federal law, three states setting the pace

The US has no federal AI law, and none is moving through Congress with real prospects of passing soon. The real activity is at the state level:

  • Texas — TRAIGA (HB 149): in force since January 1, 2026. Bans manipulative or discriminatory AI use, government social scoring, and biometric identification without consent.
  • California — several distinct laws, not one: SB 53 (Transparency in Frontier AI Act, large-scale models, fines up to $1 million) and AB 2013 (training data transparency) — both in force since January 1, 2026 — plus SB 942, operative for covered providers since August 2, 2026.
  • Colorado — a major change most trackers haven't caught up on: the original Colorado AI Act (SB 24-205, risk-based, delayed multiple times) was fully repealed and replaced with a new law, SB 26-189 (Automated Decision-Making Technology Act), signed May 14, 2026 — narrower than the original, focused on ADM transparency, with substantive obligations from January 1, 2027.

Over 30 states have introduced some form of AI-related legislation, though most are narrow deepfake or election-advertising laws, not comprehensive frameworks like the three above.

United Kingdom — no AI law, but a statutory code is coming

The UK regulates AI through sectoral regulators (ICO, FCA, MHRA, Ofcom) under a "pro-innovation" approach, with no cross-cutting AI law. The real 2026 development: regulation UKSI 2026/425, in force since May 12, requires the ICO for the first time to draft a statutory code of practice on AI and automated decision-making — final guidance expected summer 2026, statutory code with legal force in 2027. The Data (Use and Access) Act 2025 already amended UK GDPR, with most provisions in force since February 2026. More detail on the Regulatory Radar.

Canada — AIDA died, and there's still no replacement

The Artificial Intelligence and Data Act (AIDA), which was set to be Canada's first federal AI framework, was part of Bill C-27 — and died along with the rest of the bill when Parliament was prorogued in January 2025. As of mid-2026 it hasn't been reintroduced, and the government has signaled any future law will be a new design, not an AIDA revival. In the meantime, Canada regulates AI through PIPEDA at the federal level and Quebec's Law 25, today the country's most demanding framework.

Australia — no AI law, but a concrete December deadline

Australia abandoned its proposed mandatory "guardrails" for high-risk AI, opting instead for a 3-pillar approach (existing law + AI Safety Institute + voluntary guidance). What is a real obligation: on December 10, 2026, the new automated decision-making transparency obligation (APP 1.7-1.9) under the Privacy Act takes effect — any entity that uses a program to make decisions that could significantly affect a person (credit, employment, insurance, housing) must disclose this in its privacy policy. The OAIC (the regulator) has signaled a broad interpretive stance on scope, with final guidance expected in September 2026.

What all four have in common

  • None has a single EU-style AI Act — all regulate through privacy law, sectoral rules, or sub-national legislation.
  • All four are actively moving — none of this is a final state; guidance, consultations, and codes are in development in all four.
  • The risk-classification, data-management, and human-oversight methodology you've already built for the EU AI Act works as a foundation in all four — what changes is the name of the authority and some deadlines, not the principles.

Sources

Digital AI Omnibus tracking, DLA Piper GENIE; State AI Laws Tracker, GLACIS (August 2026); Colorado SB 26-189, Colorado General Assembly; UKSI 2026/425, legislation.gov.uk; Montreal AI Ethics Institute on AIDA; OAIC, Issues Paper on ADM transparency (May 2026).

The same principles, applicable in any country

Our free assessment and our risk classification and data governance templates are built on common regulatory principles — checkout shows the price in your local currency, wherever you buy from.

Take the free assessment → See the Risk Classification Checklist →