AI regulation enters enforcement phase in 2026
Enterprise AI regulation has moved from policy debate to enforcement, with binding regimes now shaping deployments across major markets. The EU AI Act is the central reference point for many compliance teams: banned practices came into force in February 2025, general-purpose AI model rules in August 2025, transparency obligations arrive in August 2026, standalone high-risk system obligations move to December 2027, and high-risk AI embedded in regulated products shifts to August 2028. Breaches of banned practices can carry penalties of up to 35 million euros or 7% of global annual turnover.
China is taking a more targeted approach through rules covering content governance, data obligations and platform responsibility. The Interim Measures for the Administration of AI Anthropomorphic Interactive Services took effect on 15 July 2026, requiring anti-addiction systems, usage notifications and instant-exit mechanisms for services that simulate human personality. Enterprises serving Chinese users may need product-level changes for content restrictions, data localisation and platform governance.
The US remains fragmented, with no comprehensive federal AI law and around 38 states adopting AI measures. Texas, Colorado, New York City and Illinois impose obligations such as transparency, testing, impact assessments, bias audits and biometric consent. Agentic AI adds another gap, as systems can act across borders faster than existing frameworks can clearly assign responsibility, making inventories, risk classification, accountability and audit trails core compliance requirements.