Study conducted in partnership with IntelligenceArtificielle.com.
Council of Europe treaty, UN work, G7 commitments, national laws: regulation of artificial intelligence is being built at multiple levels. But the frameworks do not bind the same actors nor assign the same responsibilities. Some allow sanctioning a company; others organise research, cooperation or the publication of information. Status as of 5 October 2026.
A model can be developed in one country, hosted in another and used on the other side of the world. This circulation gives international initiatives particular importance. It remains necessary to distinguish a political agreement, a legally binding treaty, a technical standard and a law that is actually enforceable.
The frameworks listed below cover the main international settings, general AI laws and several representative national approaches. Sectoral regulations, on personal data, health, finance or product safety, continue to apply depending on use. The absence of a general AI law therefore does not mean the absence of rules.
International initiatives · National and regional frameworks
At the international level, commitments of very different nature
The Council of Europe, an organisation distinct from the European Union, is the sponsor of a convention on AI, human rights, democracy and the rule of law. Open for signature in September 2024, it is intended to create legal obligations for its parties, including non‑European States. As of 5 October 2026, however, it has not yet entered into force. The European Union ratified it in May 2026.
This treaty illustrates the gap between adopting a text and implementing it. Its entry into force requires five ratifications, including three by member States of the Council of Europe, followed by the expiry of the prescribed period. It sets up monitoring by the parties and national oversight mechanisms. Its scope also has limits: national defence is excluded and the treatment of private actors other than those acting for a public authority leaves room for national choice.
At the UN, the approach is different. The Global Digital Compact of September 2024 led to the creation, in August 2025, of the Independent International Scientific Panel and of the Global Dialogue on AI Governance. These mechanisms bring respectively common expertise and a forum for discussion. They do not have powers to sanction developers. The first Dialogue took place in Geneva on 6–7 July 2026.
A recent initiative is precisely trying to go further. On 21 September 2026, Finland and Norway launched a call for controls on frontier models, supported notably by France, Germany, Canada and Singapore. Signatories call for mandatory tests before deployment, independent evaluations and the study of an international institution. At this stage, these measures are political requests; the call does not make them legally compulsory.
| Instrument and participants | Nature and stage of progress | What it produces, and its limits |
|---|---|---|
| Council of Europe Convention Signatory States and the European Union | Treaty adopted, not yet in force. Open for signature since September 2024. | Provides obligations on human rights, democracy and the rule of law; national monitoring and a conference of parties. No global authority to authorize models. National defense is excluded. |
| UN Global Digital Compact Member states and multi-stakeholder cooperation | Policy framework adopted in September 2024. | Commitments on digital cooperation, data and AI. Origin of the Independent Panel and the Global Dialogue below; does not directly create new obligations for companies. |
| UN Independent International Scientific Panel on AI Independent experts | Scientific mechanism established. Created in 2025; initial work in 2026. | Assesses knowledge on AI capabilities, benefits and risks. Non-military and non-prescriptive mandate; no product approvals. |
| UN Global Dialogue on AI Governance States and stakeholders | Governance forum. First meeting in July 2026. | Public policy and cooperation discussions. The co-chairs’ summary does not constitute a negotiated agreement imposing obligations on companies. |
| UNESCO Recommendation Member states | Non-binding recommendation. Adopted in 2021. | Ethical principles, human rights and human oversight. Supports national policies, readiness assessments and impact studies; no sanctions tied to this mechanism. |
| OECD Principles Member countries, including some non-members | Recommendation. Adopted 2019, revised 2024. | Reference for national policies and for the practices of organisations. A 2026 due diligence guide sets out risk management in more detail. No regulation directly enforceable against companies. |
| Global Partnership on AI (GPAI/OECD) Participating countries and expert network | Cooperation and expertise. Integrated with OECD since July 2024. | Practical projects and implementation of OECD principles. Cooperation and practical projects, without corporate enforcement power. |
| G7 Hiroshima Process Participating companies; OECD monitoring | Voluntary code of conduct. Code from 2023; streamlined reporting framework in May 2026. | Disclosure of risk management practices. The companies' reports are publicly available; the OECD does not verify their statements. Participation does not amount to certification. |
| Summits at Bletchley, Seoul, Paris and New Delhi States and organisations signatories according to texts | Policy statements. Summits from 2023 to 2026. | Cooperation on safety, AI access and development. New Delhi notably includes sharing tools and methodologies via the Trusted AI Commons. Signatories vary; no global market authorization. |
| Seoul Frontier AI Safety Commitments Signatory developers of advanced models | Voluntary commitments. Made in May 2024. | Assessments, risk thresholds, publication of safety frameworks and internal responsibilities. To be distinguished from state commitments and mandatory public oversight. |
| Finland–Norway Call Open coalition of signatory leaders | Political call of September 21, 2026. | Requests for independent evaluations, cooperation on serious incidents and consideration of an international institution. Mechanisms requested are not laid out by the call itself. |
| NAAIMES (International AI Measurement and Evaluation Network) Public bodies evaluating AI, including France, the United States and the United Kingdom | Operational technical cooperation. Former network of AI Safety Institutes. | Joint work on measurement, evaluation and research; first common best practices released July 2026. The network is not a supranational regulator. |
| World AI Cooperation Organization (WAICO) China and other founding countries, including Russia, Kazakhstan and Pakistan | Creation agreement signed. Signing in Shanghai on July 16, 2026, per the Chinese Ministry of Foreign Affairs. | New international AI cooperation organization with a planned Shanghai seat. Signing of its founding agreement does not imply adoption of a global regulation applicable to developers. |
| ASEAN ASEAN member states | Voluntary guides. Guide published in 2024, updated for Generative AI in 2025. | Recommendations for organizations and alignment of practices. The guide clarifies it does not modify obligations arising from national laws. |
| African Union Member states; cooperation with UNESCO and G20 | Continental strategy adopted July 2024. AI for Africa initiative launched in 2025. | Governance and support for national policies. AI for Africa provides a framework for voluntary cooperation. No uniform continental regime directly applicable to companies. |
| ISO/IEC 42001 Organizations and certification bodies | Voluntary standard published in 2023. | Requirements for an AI management system. Third-party certification possible, covering the organisation and its processes. It does not guarantee that a model is free of risk. ISO does not issue certificates. |
| Autonomous Weapons: CCW proceedings States party to the Convention on Certain Conventional Weapons | Work on a future instrument. Process ongoing in 2026. | International humanitarian law already applies. The experts’ group works on instrument elements without deciding its nature; no new treaty on autonomous weapons is adopted through this process. |
| REAIM States participating in the military AI process | Political declaration. Pathways to Action, La Coruña, February 2026. | Cooperation on responsible use of AI in military contexts beyond autonomous weapons. A separate process from CCW, without a global authorization regime. |
Why these initiatives do not form a global regulator
These mechanisms fulfil complementary functions, but placing them side by side leaves several questions open. An institute can test a model without being able to require its modification. A code can ask for the publication of information without providing for its verification. A treaty can be adopted before a sufficient number of States have accepted to be bound by its obligations.
Governments also differ on the authority they wish to confer at the international level. In New Delhi in February 2026, the US administration explicitly defended national sovereignty and rejected a centralised global governance of AI. The creation of shared forums therefore does not mean agreement on common mandatory rules.
The military perimeter underlines another separation. The Council of Europe convention excludes national defence, just as the AI Act excludes systems designed exclusively for military, defence or national security purposes. Civil processes do not cover these uses by themselves; they fall notably under existing international law and specific discussions.
Finally, the difficulty is also scientific. The International AI Safety Report 2026 describes the limits of assessments, unequal access to information and coordination problems. The behaviour of a system in testing does not always predict its behaviour once deployed. That limits what an evaluation can attest to, whatever the level at which it is organised.
National rules can concern foreign suppliers
A national or regional regulation can have reach beyond the place where the model is developed. The European AI Act notably targets suppliers who place their systems or models on the Union’s market, even if they are established elsewhere. It also provides for certain cases where outputs from a system developed or used from a third country are used within the Union.
This reach gives European authorities means of action without creating universal competence over all AI uses. The tables therefore show two simultaneous realities: territorial obligations that can reach foreign suppliers, and international cooperation much of which remains voluntary.
In the European Union, several steps have already been taken: first prohibitions since February 2025, obligations concerning general‑purpose AI models since August 2025 with transitional provisions, and transparency rules since August 2026. The European AI Office has had oversight powers since 2 August 2026 over models within its competence, including document requests, evaluations and corrective measures.
By contrast, the timetable for high‑risk systems has changed. The AI Omnibus, which entered into force on 27 July 2026, deferred the application of rules for the uses listed in Annex III to 2 December 2027, and those for systems integrated into certain regulated products to 2 August 2028. The code of good practice for general‑purpose models remains a voluntary tool to satisfy legal obligations: its voluntary character does not make those obligations optional.
| Territory and framework | Status | Scope and oversight |
|---|---|---|
| EU: AI Act | Regulation in force, phased implementation. Key remaining milestones in 2027 and 2028. | Prohibitions, transparency, risk-based obligations and rules for general-use models. Shared oversight between the Commission and national authorities; sanctions planned. |
| France: AI Act, GDPR and competent authorities | European law applicable per its timetable. | The CNIL retains its competencies on personal data. The INESIA provides scientific evaluation capabilities; its creation does not constitute a general authorisation regime for models. |
| Italy: Law 132/2025 | National law in force since October 10, 2025. Complements the European AI Act. | Rules especially for health, work, administration and justice. AgID and ACN designated as national authorities; some implementing texts fall under government delegation. |
| Spain: AESIA and national bill | Agency established; bill under discussion. The European AI Act follows its own timeline. | The AESIA has existed since 2023. The bill on AI governance remains in amendments in Congress as of early October 2026. |
| United Kingdom | Existing law and sectoral regulation. Additional protections still under study in September 2026. | Data, competition, product safety and equality fall under competent authorities. A proposed bill is not yet law. |
| Switzerland | Draft bill in preparation. Consultation expected end of 2026. | Implementation planned of the Council of Europe convention and targeted legal adaptations. Consultation deadline is not a date of entry into force. |
| Russia: AI technologies support law | Law enacted in July 2026. Effective date set to September 1, 2026. | Definitions, measures to support developers and possibility to mark AI-created content, per the Ministry of Economic Development. |
| United States: federal level | Existing law, executive orders and voluntary commitments. | The June 2026 executive order organises voluntary evaluations before advanced models are released. The 29 September agreement provides for checks and audits at its signatories; it does not amount to a general federal law. |
| United States: California | SB 53 in effect since January 2026. Supplementary provisions adopted in September. | Transparency and risk management obligations for covered developers, incident reporting and whistleblower protection. SB 53; SB 813 organises the designation of independent verification bodies by 1 January 2028, without requiring an audit of every developer. |
| United States: Colorado | Law enacted May 2026. Effective January 1, 2027. | New text replaces 2024 law. Documentation, information and human review for certain high-impact automated decisions; oversight by the Attorney General. |
| New York: RAISE Act | Law enacted, amended March 2026. Effective January 1, 2027. | Publication of safety frameworks, reporting of critical incidents and supervision of affected advanced model developers. Obligations not yet enforceable. |
| Texas, TRAIGA | Law in effect since January 2026. | Targeted prohibitions, notably for intentionally harmful or discriminatory uses. Health information and public sector; enforcement by the state attorney general. |
| Canada | Old AIDA project lapsed. Transparency consultation closed September 23, 2026. | Bill C-27 died in January 2025. The work undertaken in 2026 does not yet amount to new general obligations. Existing law and rules specific to the public administration continue to apply. |
| Brazil: PL 2338/2023 | Bill. Approved by the Senate, still under House consideration. | Regulation by risk framing and rights protection. As of October 5, parliamentary note indicates a rapporteur’s report awaiting; no entry into force yet. |
| Peru: Law 31814 and implementing decree | Framework adopted. Phased obligations from 2026 to 2029. | Risk classification, prohibitions and transparency. The first deadline, on 10 September 2026, concerns certain sectors and public administrations; not all actors are on the same timetable. |
| El Salvador: AI Promotion Law | Law enacted in 2025. | Promotion and development framework for AI. Creation of ANIA, whose autonomy and legal personality were specified by a July 2025 amendment. |
| China | Successive binding rules. Generative AI since 2023; labeling since 2025; conversational assistants since July 2026. | Generative AI services offered to the public are regulated, with assessments and filings depending on the case. Specific texts on content labelling and interactions of an emotional nature. |
| South Korea: AI Basic Act | Law in force since January 22, 2026. Grace period for enforcement of penalties. | Transparency and obligations for certain high-impact or advanced AI. Investigations and penalties postponed by at least one year; grave cases may still be investigated. |
| Japan: AI Promotion Law | Fully applicable since September 2025. | Public strategy organization, information gathering, rights violation review and business guidance. Promotion and coordination approach, complemented by guidelines. |
| Taiwan: AI Basic Act | In force since January 14, 2026. Rule updates planned within two years. | Principles, governance, risk classification and obligations for public sector uses. Government to complete laws, regulations and administrative measures. |
| Vietnam: AI Law | In force since March 1, 2026. 12- to 18-month transition for pre-existing systems. | Three risk levels, transparency, prohibitions and compliance assessment for high-risk systems. Existing systems receive sector-based timelines. |
| Kazakhstan: AI Law | November 2025 law in force in 2026. | Classification, risk management, user information, synthetic-content labeling and prohibitions. Stricter requirements for critical sectors. |
| India | Guidelines and targeted rules. Guidelines of November 2025; IT Rules revised February 2026. | The general guidelines favour existing law. Labelling and traceability obligations target certain synthetic audio and visual content and the intermediaries concerned. |
| Singapore | Existing laws and voluntary frameworks. Guide on agents published January 2026. | Evaluation and oversight recommendations complement data obligations and sector rules. The agent guide does not create a general law. |
| Australia | Existing law and national plan. Plan adopted December 2025. | Implementation and adaptation of consumer, data and online safety rules. The AI Safety Institute provides scientific expertise to authorities; it does not issue a general commercialization permit. |
| DIFC, Dubai, United Arab Emirates | Regulation 10 adopted in 2023. Scope limited to the DIFC jurisdiction. | Regulation of personal data processing by autonomous or semi-autonomous systems, with oversight and certification. This regime does not automatically extend to all Emirates. |
| Saudi Arabia: SDAIA frameworks | Ethical principles and risk management framework. National framework published in 2026. | Guidance for public and private organisations. The scheme for adhering to the principles relies on voluntary participation, distinct from legal obligations on personal data. |
| South Africa | National policy proposal withdrawn. Official withdrawal in June 2026. | The April-dated draft was withdrawn for rewrite. It does not constitute an adopted framework; withdrawal does not remove the applicability of existing laws. |
Texts adopted and their application
Comparing frameworks requires holding together their legal force, scope and timetable. South Korea has a law in force with a grace period. Brazil is still debating its text. The Council of Europe has a treaty whose entry into force remains suspended on ratifications. These situations produce very different effects for organisations that develop or use AI.
Enforcement mechanisms also matter. The European Union provides powers of inquiry and correction, whereas the Hiroshima process publishes company statements without certifying them. In both cases, the mere existence of the framework is not sufficient to establish its effectiveness on risks. The first implementation measures were the subject of our September update on regulation; our review of training data summaries also shows what published information enables in practice.
As of 5 October 2026, international cooperation has therefore already produced principles, institutions, scientific work and public commitments. Obligations accompanied by sanctions rest mainly on national or regional frameworks. The Council of Europe treaty remains, for its part, awaiting the ratifications necessary for its entry into force.
