Global AI Regulation Explained

What business leaders need to know about Canada, the EU, the United States and the frameworks shaping responsible AI
A person focused on a laptop displaying a graph, analyzing data for a project or presentation.

Executive summary

  • AI regulation is not converging around one global law. It is developing through different models: binding legislation, existing-law enforcement, sector rules, state laws, international treaties and voluntary standards.
  • The EU AI Act is already moving through phased application. Canada’s AIDA influenced the policy debate but has not been enacted. The United States remains a federal-and-state patchwork rather than a single EU-style statute.

Organizations should not build a separate governance program for every jurisdiction. A single enterprise capability – inventory, risk classification, accountability, lifecycle controls, monitoring and evidence – can be mapped to multiple requirements.

One technology, several regulatory models.

The question is no longer whether artificial intelligence will be governed. The question is how organizations can keep pace as different jurisdictions pursue different approaches. Europe has enacted a comprehensive risk-based law. The United States relies on executive policy, existing regulators and increasingly active states. Canada is continuing to shape its approach after AIDA did not become law. Standards bodies, meanwhile, are defining practical management systems that organizations can apply across borders.

Despite these differences, the direction of travel is remarkably consistent. Leaders are increasingly expected to know where AI is used, understand the purpose and risk of each system, assign accountable ownership, manage data and third parties, test and monitor outcomes, retain evidence and provide meaningful human oversight.

Canada: AIDA shaped the debate, but it is not law

Canada introduced the Artificial Intelligence and Data Act (AIDA) as part of Bill C-27 in 2022. The proposal focused on high-impact AI systems and concepts such as accountability, risk mitigation, monitoring, record keeping and transparency. Bill C-27 did not become law, so organizations should not describe AIDA as a current Canadian compliance requirement.

That does not mean Canada has stepped away from responsible AI. Existing privacy, human-rights, consumer-protection and sector-specific obligations continue to apply. Federal departments also operate under the Directive on Automated Decision-Making, and Canada’s 2026 national AI strategy places continued emphasis on safety, trust, privacy modernization and responsible adoption. For business leaders, AIDA remains useful as a policy signal – but future readiness must be distinguished from current legal compliance.

European Union: the AI Act is the global reference point

The EU AI Act is the world’s first comprehensive AI law. It uses a risk-based model, prohibiting certain practices and imposing stronger obligations on high-risk systems, general-purpose AI models and selected transparency use cases. Its requirements have been entering into application in stages since 2025, with broader obligations continuing through 2026 and 2027.

The Act matters well beyond Europe. Organizations may be affected if they place AI systems or models on the EU market, deploy them in the EU, or produce outputs used there. The practical starting point is exposure mapping: identify relevant systems, determine the organization’s role, classify risk and establish the documentation, testing, oversight and monitoring required for each use case.

United States: no single AI Act, but no regulatory vacuum

The United States has not adopted one comprehensive federal AI statute equivalent to the EU AI Act. Its model is decentralized. Federal policy currently emphasizes innovation, infrastructure, competitiveness and national security, while agencies continue to apply existing consumer-protection, employment, civil-rights, privacy, competition and sector laws to AI-enabled activities.

State activity is becoming increasingly important. Colorado, for example, enacted a revised Automated Decision-Making Technology Act in 2026 addressing consequential automated decisions and algorithmic discrimination. Other states are developing rules covering automated decisions, disclosures, deepfakes, privacy and frontier models. For organizations operating in the U.S., the absence of a single federal law does not mean the absence of obligations; it means exposure must be assessed across federal law, sector regulators and the states in which the organization operates.

ISO/IEC 42001 and NIST AI RMF: turning principles into operating practice

ISO/IEC 42001 and the NIST AI Risk Management Framework are not laws, but they are among the most useful tools for operationalizing responsible AI. ISO/IEC 42001 is a certifiable AI management-system standard covering leadership, policy, risk management, data governance, lifecycle controls, monitoring and continual improvement.

NIST AI RMF is a voluntary, outcome-oriented framework organized around four functions: Govern, Map, Measure and Manage. It provides a practical common language for business, technology, risk, legal and compliance teams. Used together, ISO and NIST can provide the repeatable operating model beneath jurisdiction-specific obligations.

Other markets and international instruments to watch

Market / instrument

Approach

Why it matters

United Kingdom

Sector-led, pro-innovation regulation through existing regulators.

Organizations should monitor sector-specific expectations rather than wait for one omnibus AI law.

China

Binding rules covering recommendation algorithms, synthetic content and generative AI services.

AI governance may need to address content, data, security, registration and local operating requirements.

Council of Europe Convention

The first legally binding international treaty focused on AI, human rights, democracy and the rule of law.

It signals growing international convergence around rights, accountability, transparency and risk-based governance.

What business leaders should do now

1. Build an AI inventory

Record use cases, owners, vendors, models, data, affected users, geography and business purpose.

2. Classify risk and exposure

Assess impact, affected people, jurisdictions, sector requirements and the organization’s role as developer, provider or deployer.

3. Assign accountable ownership

Define executive, business, technology, data, risk, legal and compliance responsibilities.

4. Establish lifecycle controls

Set requirements for approval, data, testing, security, human oversight, monitoring, incidents and retirement.

5. Create defensible evidence

Maintain impact assessments, risk decisions, test results, model and vendor documentation, approvals and monitoring records.

6. Prepare people and partners

Provide AI literacy and extend governance expectations to vendors, platforms and other third parties.

Executive perspective

Do not build a separate governance program for every new law or framework. Build one right-sized enterprise capability with common ownership, risk classification, lifecycle controls, evidence and monitoring – then map it to applicable requirements. Done well, governance is not a brake on innovation. It is what makes AI adoption repeatable, defensible and scalable.

Key takeaways

  • Canada’s AIDA is not enacted law, but its concepts remain useful indicators of likely Canadian policy direction.
  • The EU AI Act is binding and can apply to organizations outside Europe based on how systems and outputs enter the EU market.
  • The U.S. is a federal-and-state patchwork: existing laws, sector enforcement and state AI rules all matter.
  • ISO/IEC 42001 and NIST AI RMF provide practical foundations for a single, cross-jurisdictional governance model.
  • The objective is not more policy. It is clear accountability and reliable controls that allow the organization to make faster, better AI decisions.

Official sources and further reading

Prefer the concise version?

Get the two-page executive brief

A concise overview of the regulatory models shaping responsible AI – including Canada, the EU, the United States, ISO/IEC 42001 and NIST AI RMF.
By submitting this form, you agree to receive the requested content and occasional DataFuel insights. You can unsubscribe at any time.