NVDA 223.96 ▲2.27%GOOGL 354.30 ▼0.96%MSFT 499.99 ▲0.03%AMD 483.36 ▼1.21%INTC 101.65 ▲1.84%TSMC 420.04 ▲0.44%AMZN 274.48 ▲0.82%META 592.10 ▲0.37%AAPL 313.33 ▲0.29%PLTR 172.01 ▲10.32%
Markets at last close

Policy

AI regulation splinters across major markets

·1 min read

Global AI governance has split between comprehensive, risk-based statutes and lighter principles-based regimes. The EU AI Act remains the main benchmark, with banned practices already applying and high-risk systems subject to requirements covering risk management, documentation, logging, human oversight, post-market monitoring, incident reporting, accuracy, robustness, and cybersecurity. South Korea’s AI Basic Act follows a similar risk-based path and reaches foreign providers.

The US has no comprehensive federal AI law, leaving companies to navigate a volatile state patchwork. Colorado, California, Texas, Utah, and Illinois have enacted or updated AI rules, while a federal executive order seeks to challenge state laws but does not preempt them. In the 2025 session, all 50 states introduced AI legislation and 38 enacted around 100 measures.

The UK, Canada, Japan, Australia, Singapore, and India largely rely on existing regulators, privacy law, voluntary standards, or advisory frameworks rather than dedicated AI statutes. China takes a more operationally demanding route, requiring security assessments, algorithm filings, content controls, and labels for synthetic media. Brazil’s risk-based bill remains in progress.

Security teams are urged to build governance around the strictest regime they touch, starting with an inventory of AI systems and user geography. The recommended operational stack combines the NIST AI Risk Management Framework, ISO/IEC 42001, and the OWASP Top 10 for LLM Applications to turn legal duties into auditable controls.

Originally reported by app.stationx.netRead the source →
Related coverage