Skip to content

International AI Legal Landscape (2026) — What Australian Businesses Should Know

Purpose: Navigate international AI regulations affecting Australian organisations operating globally Audience: Legal, compliance, international business and governance teams | Time: 60-90 minutes

This page is informational and not legal advice.

Rapidly evolving landscape

International AI regulations are changing fast. The Digital Omnibus on AI (Regulation (EU) 2026/1744) was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, making its revised dates legally effective. Article 50 transparency duties generally began applying on 2 August 2026; the 2 December 2026 transition is limited to Article 50(2) marking and detection obligations for systems placed on the market before 2 August 2026. South Korea's AI Basic Act and Enforcement Decree took effect in January 2026, with an enforcement grace period of at least one year. Canada's AIDA died on the Order Paper and any replacement may differ substantially. Always verify current status with official sources before making compliance decisions.

As AI regulation accelerates globally, many jurisdictions already impose binding requirements or have near-term obligations that will affect Australian organisations exporting, operating, or handling data linked to those regions.

Below is a practical snapshot of the US, Canada, EU, UK, Japan, South Korea, Singapore and recent bilateral agreements, plus the global frameworks most often referenced by regulators.


Executive Snapshot

Key Jurisdictions at a Glance

  • 🇪🇺 EU — The EU AI Act is in force with staged obligations. Bans on "unacceptable risk" uses started 2 Feb 2025; general-purpose AI (GPAI) duties started 2 Aug 2025. The EU Digital Omnibus on AI entered into force on 27 July 2026. Article 50 transparency duties generally apply from 2 August 2026, with a limited transition to 2 December 2026 for Article 50(2) marking and detection obligations for systems placed on the market before 2 August 2026. High-risk system duties apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems; the new NCII/CSAM prohibition applies from 2 December 2026 and national sandboxes are due by 2 August 2027.

  • 🇺🇸 US — No single federal AI law. Federal direction runs through NIST AI RMF 1.0 and public-sector guidance (OMB M-25-21 and M-25-22). States are moving: Colorado's AI Act (effective 30 June 2026) requires risk programs, impact assessments and notices for "high-risk" AI. NYC mandates bias audits for automated hiring tools.

  • 🇨🇦 Canada — The federal Artificial Intelligence and Data Act (AIDA) (within Bill C-27) died on the Order Paper in January 2025 when Parliament was prorogued. It has not been reintroduced. A narrower private member's bill on online deepfakes, Bill C-277, received first reading on 6 May 2026 and remains outside the order of precedence.

  • 🇬🇧 UK — No single AI Act; regulator-led, "pro-innovation" model with central government coordination and the AI Security Institute (rebranded Feb 2025). Regulators are issuing sector guidance and pilots (assurance, sandboxes). The Data (Use and Access) Act 2025 changed automated decision-making rules and required government reporting on AI and copyright, completed in March 2026; it did not itself create general AI-training data access or transparency duties.

  • 🇯🇵 Japan — On 28 May 2025 Parliament approved the AI Promotion Act (Japan's first AI law). It was promulgated and partially commenced on 4 June 2025, then fully commenced on 1 September 2025, including the provisions establishing the AI Strategy Headquarters. Compliance remains guideline-driven via the AI Guidelines for Business (2024) and existing laws (privacy, consumer).

  • 🇰🇷 South Korea — Passed the AI Basic Act (promulgated 21 Jan 2025; effective 22 Jan 2026). It establishes national governance and trustworthiness requirements and applies to overseas conduct affecting the Korean market or users. The Enforcement Decree and guidelines are in force, but MSIT granted a grace period of at least one year before routine investigations and penalties.

  • 🇸🇬 Singapore — Leading with Model AI Governance Framework (GenAI) and the open-source AI Verify testing toolkit. Often used as a practical implementation benchmark, interoperable with NIST AI RMF.


Why This Matters for Australian Businesses

  • 🌏 Export exposure: Selling AI products/services into the EU, UK or Korea may trigger local provider/deployer duties even if you're based in Australia
  • 📋 Procurement pressure: Multinationals will increasingly require AI risk assessments, bias testing and documentation aligned to EU/US frameworks (EU AI Act, NIST AI RMF, ISO/IEC 42001)
  • 🔄 Interoperability benefits: Adopting risk-based governance now reduces later retrofit costs and smooths compliance across markets

Jurisdiction Guides

European Union (EU)

Status & scope: The EU AI Act (Regulation (EU) 2024/1689) is live with a risk-tiered regime (prohibited, high, limited, minimal), dedicated GPAI obligations and strong enforcement (up to 7% global turnover). Key dates under the original Act include 2 Feb 2025 (prohibitions), 2 Aug 2025 (GPAI, governance/penalties) and 2 Aug 2026 (the original high-risk AI deadline). The Digital Omnibus on AI (Regulation (EU) 2026/1744) was published on 24 July 2026 and entered into force on 27 July 2026. It moved the Annex III high-risk system deadline to 2 December 2027 and the Annex I deadline to 2 August 2028. Article 50 transparency duties generally apply from 2 August 2026; the 2 December 2026 transition applies only to Article 50(2) marking and detection obligations for systems placed on the market before 2 August 2026.

EU Digital Omnibus on AI — In force

The European Parliament adopted the EU Digital Omnibus on AI on 16 June 2026 (423 to 57, 174 abstentions), followed by formal adoption by the Council of the EU on 29 June 2026. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force three days later, on 27 July 2026.

Key amended dates and transitions include:

  • High-risk AI standalone systems (Annex III): new compliance deadline 2 December 2027 (deferred from 2 August 2026)
  • High-risk AI embedded in regulated products (Annex I): new compliance deadline 2 August 2028
  • Article 50 transparency obligations: generally apply from 2 August 2026; providers of systems placed on the market before that date have until 2 December 2026 to meet the Article 50(2) marking and detection obligations
  • New Article 5 prohibition: AI systems generating non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM), including "nudifier" tools — compliance required by 2 December 2026
  • AI regulatory sandboxes (national-level): now 2 August 2027
  • Machinery Regulation: moved to Annex I Section B — AI in machinery-regulated products falls primarily under the Machinery Regulation rather than direct AI Act high-risk requirements
  • SME exemption extended to small mid-cap companies (SMCs)

Australian businesses supplying AI into the EU should work to the dates now in force and distinguish the narrow Article 50(2) transition from the other Article 50 duties. (Updated: 23 August 2026; sources: Regulation (EU) 2026/1744 (EUR-Lex); European Commission Article 50 Q&A)

What to Do

  • ✅ Map any EU-facing AI systems to risk categories; identify if you're a provider, deployer, importer or distributor
  • ✅ For GPAI/models, prepare training-data summaries, technical documentation and risk-mitigation processes (red-teaming, incident reporting)
  • ✅ Work to the Omnibus dates now in force (2 December 2027 for Annex III; 2 August 2028 for Annex I), and distinguish the limited Article 50(2) transition from the Article 50 duties already applying.

United States (US)

Status & scope: No omnibus federal AI law. Federal levers include NIST AI RMF 1.0 (widely adopted), OMB M-25-21 (governance for US federal agencies, replacing M-24-10) and OMB M-25-22 (federal AI acquisition). Two NIST publications extend the framework:

  • NIST IR 8596 — Cybersecurity Framework Profile for AI (initial preliminary draft, December 2025): voluntary framework extending NIST CSF 2.0 to AI-specific cybersecurity risks. Organised around three focus areas (Secure, Defend, Thwart) and the six CSF 2.0 core functions. Its initial public comment period is closed and development continues (NIST IR 8596 publication page, accessed 23 August 2026).
  • AI RMF Critical Infrastructure Profile (concept note, 7 April 2026): new profile under development to guide critical infrastructure operators on AI risk management practices. Full profile in development (NIST AI RMF homepage, accessed 19 May 2026).

States and cities are active: Colorado SB24-205 (effective 30 June 2026, delayed from the original February 2026 date via SB 25B-004) mandates risk management programs, impact assessments, consumer notices and appeal/human review for "high-risk" AI; NYC Local Law 144 requires bias audits and notices for automated hiring tools.

What to Do

  • ✅ Align your program to NIST AI RMF (often accepted as a defence/interoperability baseline, including in Colorado's framework)
  • ✅ If serving US customers/employers, build impact assessment and bias-audit capability into your lifecycle

Canada

Status & scope: Bill C-27 (which included the federal Artificial Intelligence and Data Act, AIDA) died on the Order Paper on 6 January 2025 when Parliament was prorogued. AIDA has not been reintroduced. A narrower private member's bill, Bill C-277, would regulate online deepfakes and related transparency; it received first reading on 6 May 2026 and remains outside the order of precedence. Note: Ontario's Bill 194 (passed November 2024) regulates public sector AI use provincially.

What to Do

Do not treat AIDA as current legislation. Continue monitoring Bill C-277 and any future government bill. Organisations can still reference AIDA's former companion guidance for voluntary best practices (risk-based duties for "high-impact" systems, impact assessments, incident reporting), but recognise any future legislation may differ substantially.

United Kingdom (UK)

Status & scope: No single AI Act; the UK follows a contextual, regulator-led approach under the Government Response (Feb 2024) to its AI White Paper. Central functions coordinate regulators; the AI Security Institute (rebranded from "AI Safety Institute" in February 2025) evaluates advanced systems and supports guidance/testing. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Its AI-relevant measures include changes to automated decision-making rules and requirements for government reports on AI and copyright, which were completed in March 2026. The Act did not itself establish general AI-training data access or transparency duties.

What to Do

  • ✅ Track sector regulators (ICO, CMA, FCA, MHRA etc.)
  • ✅ Expect assurance, transparency, and evaluation asks for frontier/GPAI uses
  • ✅ Apply the amended automated decision-making safeguards where relevant, and monitor subsequent government policy on AI and copyright rather than treating the Act's reporting duties as AI-training rules

Japan

Status & scope: Japan emphasises soft-law via the AI Guidelines for Business (2024, METI/MIC), updated subsequently. On 28 May 2025 Parliament approved the AI Promotion Act (Japan's first AI law). It was promulgated and partially commenced on 4 June 2025, then fully commenced on 1 September 2025, including the provisions establishing the AI Strategy Headquarters. The Act focuses on R&D promotion and voluntary guidelines rather than hard restrictions.

What to Do

  • ✅ Apply the Guidelines lifecycle controls (risk identification, governance, transparency)
  • ✅ Ensure compliance with APPI and sector rules

Republic of Korea (South Korea)

Status & scope: AI Basic Act (officially "Basic Act on the Development of AI and the Establishment of a Foundation for Trustworthiness") passed 26 Dec 2024, promulgated 21 Jan 2025, effective 22 Jan 2026. Creates national governance (AI committee, safety institute) and a trustworthiness baseline, and applies to conduct outside Korea that affects the domestic market or users. The Enforcement Decree and implementation guidelines are in force. Administrative fines up to KRW 30 million apply to specified failures, including required notification, designation of a domestic representative and compliance with a corrective order, but MSIT has deferred routine investigations and penalties for a grace period of at least one year. The Act's imprisonment provision concerns unauthorised disclosure or use of confidential information learned through committee duties, not general provider non-compliance.

What to Do

  • ✅ If offering AI into Korea, assess the transparency, high-impact AI, safety, and domestic representative duties; use the grace period to prepare rather than treating it as an exemption

Singapore

Status & scope: Model AI Governance Framework (GenAI) and the AI Verify testing toolkit provide practical, testable governance guidance; mapped to NIST AI RMF for interoperability. Frequently used by multinationals for assurance.

What to Do

  • ✅ Use AI Verify (or equivalent) for bias, robustness, transparency testing
  • ✅ Publish assurance artefacts for enterprise buyers

Bilateral: Australia–Canada AI Safety Cooperation

Status & scope: On 5 March 2026, Australia and Canada signed an AI Safety Cooperation MoU to strengthen bilateral cooperation on AI safety through the International Network for Advanced AI Measurement, Evaluation and Science. The MoU provides a framework for joint research, information sharing and coordinated approaches to evaluating advanced AI systems (industry.gov.au, accessed 23 August 2026).

What to Do

  • ✅ Monitor outcomes from the International Network of AI Safety Institutes — shared evaluation frameworks and safety benchmarks may influence future Australian regulatory expectations

Bilateral: Australia–UK AI Safety MoU (Signed 25 May 2026)

Status & scope: Australia and the UK signed a Memorandum of Understanding on 25 May 2026, deepening cooperation on the responsible development, deployment, governance and use of safe and trustworthy AI. The MoU was signed during a visit to Australia by the UK Minister for AI and Online Safety. Under the MoU, the Australian AI Safety Institute (currently being established) and the UK AI Security Institute will collaborate on:

  • Sharing information and expertise on emerging AI capabilities and risks
  • Best practices for testing AI systems
  • Conducting joint research, including novel approaches to measure, test and manage risks
  • Supporting the International Network for Advanced AI Measurement, Evaluation and Science

Australia has now signed bilateral AI safety cooperation instruments with Canada (5 March 2026) and the UK (25 May 2026), in addition to an industry MoU with Anthropic. This network of agreements is shaping the AISI's international partnerships even as its formal operational launch remains pending.

What to Do

  • ✅ Monitor outcomes from Australia's bilateral AI safety agreements. Joint evaluation frameworks and safety benchmarks from these partnerships may influence future Australian regulatory expectations and guidance

Australia–Anthropic MoU (1 April 2026)

On 1 April 2026, the Australian Government and Anthropic signed an MoU described as the first formal arrangement executed under the National AI Plan. The agreement is a statement of intent (not legally binding) covering AI safety, research collaboration and workforce development. Key elements include Anthropic extending its AI for Science program to Australia, with an investment of AUD $3 million in Claude API credits to four institutions (ANU, Murdoch Children's Research Institute, Garvan Institute of Medical Research and Curtin University), and Anthropic planning to open a Sydney office in 2026. The MoU was formalised during a meeting between Anthropic CEO Dario Amodei and Prime Minister Albanese. (industry.gov.au, accessed 31 May 2026; anthropic.com, accessed 31 May 2026)


Side-by-Side Summary

Jurisdiction Legal posture (August 2026) Primary instruments Key dates Headline obligations (examples)
EU Binding, phased EU AI Act; EU Digital Omnibus (Regulation (EU) 2026/1744, in force) Feb 2025 (bans); Aug 2025 (GPAI); Aug 2026 (Article 50 generally); Dec 2026 (limited Article 50(2) transition and NCII/CSAM prohibition); Dec 2027 (Annex III high-risk); Aug 2028 (Annex I high-risk) Risk-tiered duties, GPAI transparency/docs, post-market monitoring, penalties up to 7% turnover
US Patchwork + federal guidance NIST AI RMF; OMB M-25-21 and M-25-22; Colorado AI Act; NYC AEDT law CO: 30 June 2026; NYC AEDT: in force Risk programs, impact assessments, notices, bias audits (hiring), consumer appeal/human review
Canada No omnibus AI law; targeted private member's bill introduced AIDA (Bill C-27) – terminated; Bill C-277 – online deepfakes C-277 first reading 6 May 2026; outside order of precedence AIDA is not current legislation; C-277 has not passed
UK Regulator-led framework Gov't Response (Feb 2024); AI Security Institute; Data (Use and Access) Act 2025 Royal Assent June 2025; main data-protection changes commenced Feb 2026; AI/copyright report published Mar 2026 Sector regulators issue guidance; evaluation and assurance focus; amended automated decision-making safeguards
Japan Soft-law + promotion act AI Guidelines for Business; AI Promotion Act Partially commenced 4 June 2025; fully commenced 1 Sept 2025 Lifecycle governance guidance; R&D promotion; voluntary compliance (no direct penalties)
Korea Binding (framework) AI Basic Act and Enforcement Decree Effective 22 Jan 2026; enforcement grace period of at least one year National governance; transparency and trust/safety duties; specified administrative fines up to KRW 30M
Singapore Voluntary but influential Model AI Governance (GenAI); AI Verify Framework updated 2024–25; OECD/GPAI alignment 2025 Testing toolkit + governance guidance; NIST RMF cross-walk; red-teaming benchmarks
AU–CA Bilateral cooperation AI Safety Cooperation MoU Signed 5 March 2026 Joint research and evaluation via International Network for Advanced AI Measurement, Evaluation and Science
AU–UK Bilateral cooperation Australia–UK AI Safety MoU Signed 25 May 2026 Joint research and evaluation on AI safety; cooperation between AISI and UK AI Security Institute

Global Reference Frameworks (useful everywhere)

  • 🌐 NIST AI Risk Management Framework 1.0 — broad, practical and widely referenced (US and beyond)
  • 📋 ISO/IEC 42001:2023 — AI management system standard (AIMS) for organisations building/using AI
  • 🤝 OECD AI Principles — internationally endorsed principles aligned with human-centred, trustworthy AI

Related SafeAI-Aus Tools

This page should be read together with our governance tools:


Key References

European Union

United States

Canada

United Kingdom

Japan

South Korea

Singapore

Australia–Canada Bilateral

Global Standards


Disclaimer & Licence

Disclaimer: This guide provides general information about international AI regulations and is not legal advice. SafeAI-Aus has exercised care in preparation but does not guarantee accuracy, reliability, or completeness. International AI laws change rapidly. Organisations should adapt to their specific context and seek advice from legal professionals with expertise in relevant jurisdictions before making decisions based on this information.

Licence: Licensed under Creative Commons Attribution 4.0 (CC BY 4.0). You are free to copy, adapt and redistribute with attribution: "Source: SafeAI-Aus (safeaiaus.org)"