Regulatory Radar
AI and data protection regulation updates, region by region — EU, US, and Latin America. No noise: only what actually changes.
Now enforceable: Law 31814's first deadline for health, education, justice, security, economy and finance
Law 31814's implementing regulation (Supreme Decree 115-2025-PCM), in force since January 2026, phases in private-sector obligations by year from its publication date. The first deadline (one year) landed on 10 September 2026: AI developers and deployers in health, education, justice, security, economy and finance must now meet algorithmic transparency, human oversight for high-risk systems, up-to-date documentation, and internal security and accountability policies. Transport, commerce, and labor have until 2027; production, agriculture, energy, and mining until 2028; every other use, until 2029. No single AI fines schedule — non-compliance triggers Peru's existing enforcement regimes (data protection, consumer protection/INDECOPI, cybercrime).
The real numbers behind ISO/IEC 42001 certification: around 640 certificates worldwide
IAF CertSearch data circulated in September 2026 puts the United States in the lead with 206 certificates (32% of the total), followed by India (75), the UK (44), South Korea (39), Australia (27), Türkiye (25), China (23), Italy (14), Canada (13) and Germany (12). The worldwide total is around 640 certificates.
The figure that gives it context: ISO/IEC 27001 has 96,709 valid certificates per the ISO Survey 2024. That puts 42001 at roughly 0.7% of that volume. Calling adoption "growing" is fair, but the base is tiny: certifying today isn't aligning with an established market standard — it's getting ahead of almost everyone.
Two important caveats. First: ISO does not yet include 42001 in its official Survey, so any global figure comes from IAF CertSearch rather than ISO — it should be cited as such. Second: Spain does not appear in the top 10, whose tenth place is Germany with 12 certificates. The Spanish market is at a very early stage.
This reinforces what we covered in ISO 42001 vs AI Act: certification is a credibility signal and a solid organisational foundation, but it is neither an established market requirement nor a route to presumption of conformity with the AI Act.
ChatGPT designated a Very Large Online Search Engine under the DSA — the first AI chatbot in that tier
On 31 August 2026 the European Commission designated ChatGPT as a VLOSE (Very Large Online Search Engine) under the Digital Services Act, and Reddit and Roblox as VLOPs. All three declared they exceed the threshold of 45 million average monthly users in the EU (DSA Art. 33(1)). It's the first time an AI chatbot has entered this tier, and the Commission chose "search engine" — not "platform" — because of its ability to retrieve information from the live web.
What it triggers: systemic risk assessment, mitigation measures, annual independent audits, an internal compliance function, enhanced transparency, and data access for regulators and vetted researchers. The deadline is four months from notification; worth noting that the Commission's own sources differ between end of December 2026 and January 2027. DSA fines reach 6% of global annual turnover.
The nuance that matters most: this is a DSA designation, not an AI Act enforcement action. They are two parallel regimes overlapping on the same product. A control implemented for one may help with the other, but the obligations can't be collapsed into a single generic "AI compliance" checklist. And because the classification turns on function (retrieving information from the web) rather than product category, it's a template the Commission can extend to other assistants as they scale.
Bill 2338 confirms delay: no floor vote before October's elections
The most advanced framework in the region after Peru's (passed by the Senate in December 2024). Closely modeled on the AI Act, it prohibits social scoring and mass surveillance, and imposes strict oversight on high-risk applications (hiring, clinical diagnostics, credit scoring). Still pending approval by the Chamber of Deputies: a Special Committee has been reviewing it since May 2025 (rapporteur: congressman Aguinaldo Ribeiro), with more than 40 public hearings requested. The rapporteur himself confirmed on 24 August 2026 that the floor vote will happen "still in 2026, but only after" October's general elections (first round 4 October, runoff 25 October) — he explicitly ruled out including it in August's legislative package. The text remains under negotiation with the Senate; no exact date is confirmed yet.
AI Act enforcement begins, along with Article 50 transparency obligations
From 2 August 2026, the Commission's AI Office and national authorities actively enforce the AI Act. Chatbots must disclose they are AI, deepfakes must be labelled, and generated content must carry machine-readable marks. Fines up to €15 million or 3% of worldwide annual turnover.
The detail most often missed: unlike almost everything else in the Regulation, these obligations apply from day one to all in-scope systems, regardless of when they were placed on the market. There's no transition period for existing systems. Conversely, synthetic content generated before 2 August 2026 does not need to be marked retroactively.
On 20 July 2026 the Commission published the final version of its Article 50 Guidelines, replacing the May draft and serving as the reference document national market surveillance authorities will use. In parallel, the Code of Practice on Transparency of AI-Generated Content was confirmed by the Commission and the AI Board as an adequate route to demonstrate compliance — voluntary, with around 190 organisations signed up by the end of July.
Digital Omnibus in force — Regulation (EU) 2026/1744
Published in the Official Journal of the EU on July 24, 2026 and in force since July 27 — ahead of the August 2 deadline. High-risk obligations for Annex III systems (risk management, technical documentation, human oversight) are now firmly postponed from August 2, 2026 to December 2, 2027; Annex I obligations (AI embedded in regulated products) move to August 2, 2028. August 2, 2026 remains a real date — but only for Art. 50 transparency obligations. The Regulation also adds a new prohibition (non-consensual intimate content and AI-generated CSAM), with a compliance deadline of December 2, 2026.
NIS2 transposition remains uneven across member states — Spain still has no law
Not all EU countries have completed national transposition of the NIS2 Directive at the same pace — if you operate across several European countries, check the specific status in each jurisdiction rather than assuming one EU-wide date.
Spain's case: still no law, and the delay has now escalated. Spain missed the 17 October 2024 transposition deadline; the government approved a draft bill (Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad) in January 2025, which remains in parliamentary process without reaching Spain's official gazette (BOE). Following the reasoned opinion of May 2025, the European Commission decided on 9 July 2026 to refer Spain to the Court of Justice of the EU for failing to notify transposition measures — it is seeking a lump-sum penalty plus daily fines that keep accruing while the law remains unpassed. The old NIS1 framework (Real Decreto-ley 12/2018) stays in force in the meantime. There's no confirmed entry-into-force date yet, but NIS2's technical and organisational requirements are already known and take months to implement — there's no reason to wait for the law to start.
EU Action Plan on Cybersecurity and Artificial Intelligence
The Commission presented a coordinated plan to help Member States, businesses and public authorities address the cybersecurity and resilience challenges posed by the most advanced AI models. It includes a call to expand EU capacity to evaluate AI models before they are placed on the market, expected to be operational by 2027 — strengthening third-party assessment and the AI Office's regulatory function.
Why it matters: it connects the AI Act's Article 15 cybersecurity requirement with the wider European cybersecurity framework (NIS2). If you already have NIS2 compliance, much of the infrastructure exists — but AI-specific threats (data and model poisoning, adversarial examples) remain a separate vector.
General AI Law shelved indefinitely — but sector-specific rules are already in force
The General Law to Regulate and Promote Artificial Intelligence isn't moving in the Senate: it requires a constitutional reform to Article 73 that hasn't advanced, and as of July 2026 it remained "just a working document." Meanwhile, concrete sector-specific rules are already in force and do bind companies: the Federal Copyright Law requires prior consent to clone voice or likeness; Article 305 Bis of the Federal Labor Law requires prior agreement to use algorithms in workplace decisions; and Article 291-J requires algorithmic transparency on digital platforms. If you operate in Mexico, the relevant question is no longer "when does the general law arrive" but which sector-specific rules already apply to you today.
Council gives final approval to the Digital Omnibus
The Council of the EU gave final approval on June 29, 2026, following the European Parliament's sign-off on June 16. The text was published a month later as Regulation (EU) 2026/1744.
No standalone AI Act — but the first statutory AI/automated-decisions code is already underway
The UK still has no single AI law — no bill is before Parliament — and regulates AI through its sectoral regulators (ICO, FCA, MHRA, Ofcom) under a "pro-innovation" approach. What did change: UKSI 2026/425, in force since 12 May 2026, gives the ICO a statutory duty for the first time to produce a code of practice on AI and automated decision-making. The consultation on the draft automated-decision-making guidance closed on 29 May 2026; as of August 2026 the ICO is pointing to winter 2026 for final guidance rather than the summer originally floated, still ahead of the legally binding code, not expected until 2027. Meanwhile, the Data (Use and Access) Act 2025 has already amended UK GDPR, with most provisions in force since 5 February 2026. For businesses with EU exposure, the European AI Act still applies regardless of the UK not adopting it. Full comparison with the US, Canada and Australia: dedicated article here.
No comprehensive federal law — but the White House has declared war on state AI laws
The US still has no comprehensive federal AI law. What it does have is an open fight between the White House and the states: Executive Order 14365 ("Ensuring a National Policy Framework for Artificial Intelligence"), signed 11 December 2025, creates a Department of Justice litigation task force whose sole job is to challenge state AI laws, and directs the FTC to issue a policy statement within 90 days on when such laws are preempted by federal rules against deceptive practices — while asking the FCC to explore a federal disclosure standard that would displace state ones. States haven't slowed down in response: California enacted the Transparency in Frontier AI Act (SB 53) on 29 September 2025 — requiring published safety frameworks, transparency reports, and critical-incident reporting from large frontier-model developers (over $500 million in annual revenue) — and during 2026 at least 19 more states passed chatbot-safety laws (Connecticut, California's SB 243, Utah, among others). The NIST AI RMF remains the de facto voluntary reference vocabulary corporate buyers and insurers use to evaluate vendors.
First country in the region to sign the Council of Europe's AI Framework Convention
Uruguay became the first Latin American country to sign the Council of Europe's binding treaty on AI, human rights, democracy, and the rule of law — a signal it wants to lead the region's regulatory approach.
Risk-tiered bill, plus an updated National AI Policy
Chile combines an already-updated National AI Policy with a risk-based bill focused on transparency, fairness, and human oversight, still moving through Congress.
No AI-specific law yet — operating through general data protection
These countries don't yet have an AI-specific law; AI uses that process personal data are already covered by their general data protection laws (Law 25.326 in Argentina, Law 1581 in Colombia). Argentina shows recent Congressional movement on AI-related election manipulation and privacy.