Title banner for ''AI regulation' is not one thing': three regions — Japan (promotion / voluntary), the EU (hard law / risk-based), and the US (swings by administration + state-by-state) — each taking a different direction, with a subtitle on sorting out which one reaches you.

Key Points

  1. "AI regulation" is not one thing. The EU, the US, and Japan pull in fundamentally different directions, so the same phrase points to a different beast in each jurisdiction. The first move is not to ask "what does the law say" but to sort out which regime actually reaches your product.
  2. Who this is for: solo and side-project developers building AI / DX products (the main audience), plus engineers, IT, and legal teams running internal AI governance at a company. No prior legal knowledge needed.
  3. What you get: a map of how the three poles differ (EU = hard law, US = swings + state patchwork, Japan = promotion) + an attribute-based filter for which regime reaches you (EU extraterritorial reach / high-risk use / embedded generative AI) + the order to check primary sources in an area where every date goes stale fast.
  4. Out of scope (consult a lawyer): confirming whether a specific product is regulated / clause-by-clause comparison / individual contract or terms interpretation. This article is a map to which regime to investigate, not a compliance determination.

この記事の要点(日本語版はこちら)

  1. 本記事は 米国・EU 法を背骨にした「国際版」 です(日本語版の翻訳ではなく、対象法域が異なる対の記事)。EU AI Act(ハードロー・域外適用)と米国の州法パッチワーク + 連邦の振動を主軸に、自分のプロダクトにどの制度が効くかを属性で切り分けます。
  2. 日本法(AI 推進法 = 振興型・罰則なし、AI 事業者ガイドライン)を主役にした解説は 日本語版 を参照してください。

Written: 2026-06 / Jurisdiction focus: United States & EU (Japan is covered in the Japanese edition) / last_updated: 2026-07-17 Changelog: 2026-06-04 first published as an international (US/EU) edition / 2026-07-17 recorded the promulgation of Japan's privacy-law reform (17 July 2026, per the PPC announcement; commencement still left to a cabinet order) and corrected existing claims against the primary sources (US: split the Colorado dates into the act's own effective date (14 May 2026, Chapter 131), the developer duty's 1 Jan 2027 start, and the litigation stay; recorded the DOJ intervention (24 Apr) and the joint-motion enforcement stay (27 Apr) as the record shows them, and dropped the "first time the federal government has stepped in" claim the DOJ release does not make; corrected the CA SB 942 threshold to "visitors or users" and noted AB 853; added the CA FEHA employment-ADS regulations to the examples; EU: added the Art. 6(3) derogation and Art. 6(4) documentation duty, the Art. 50 application date, and the €15 million alternative in the Art. 99(4) cap; Japan: added the AI Promotion Act's Art. 7 / Art. 16 duties; softened the NIST AI RMF claim; wired the glossary terms and cut the provider/deployer mini-term back; unified the confirmation date) / 2026-07-16 reflected the Diet passage of Japan's 2026 privacy-law reform (passed the House of Councillors on 10 July 2026), recording — per the primary sources (both Houses' bill-progress pages) — that no promulgation date or law number had been assigned as of that vote, and the effective date is set by cabinet order within two years of promulgation / 2026-07-11 corrected the provider / deployer definitions against the primary text (Art. 3(3), 3(4) and 3(11): both roles cover public authorities and natural persons acting professionally; a provider's supply may be free of charge; "putting into service" covers own use in the Union), split the high-risk duties by role (conformity assessment is a provider duty; deployers owe use monitoring, logging and — where applicable — a fundamental-rights impact assessment), narrowed the Annex III scope of "health" (medical devices run through Annex I instead), added the SME fine cap under Art. 99(6) ("whichever thereof is lower"), separated the AI Act (Art. 2(1)) and GDPR (Art. 3(2)) extraterritoriality tests, and noted that Colorado's deployer is a separate statutory concept / 2026-06-20 added the deployer personal-use caveat (Art. 2(10) exempts only deployer duties; Art. 5 and other laws still apply), tightened the Annex III high-risk scope (housing/legal) and the GDPR Art. 3(2) wording

This article is educational material, not legal advice

AI / DX law is moving violently across 2024–2026. The statute names, effective dates, and penalty ceilings here reflect the picture as confirmed on 17 July 2026, but the moving parts shift on a scale of months: the US is simultaneously running administration-driven executive-order reversals, state-law delays, and federal-vs-state preemption litigation; the EU's amending regulation on the high-risk AI application dates was adopted in June 2026 but is not yet in force (awaiting Official Journal publication); and Japan's privacy-law reform, promulgated on 17 July 2026, still has no commencement date (it is left to a cabinet order). This article is a general educational overview; it does not determine or guarantee whether any specific product is regulated. Out of scope: final suitability assessments / clause-by-clause comparison / the legality of any specific matter. For real decisions, always confirm with a qualified attorney, the relevant authority in each jurisdiction, or an industry body (US: ITI, SIIA; EU: national DPAs and the European Commission). All information is provided "AS IS," without warranty of any kind. To the maximum extent permitted by law, the author and YATA-NODE accept no liability for any loss or damage arising from the use of or reliance on this article. Use it at your own risk. Because this area is exceptionally fluid, re-check the primary sources for the latest version right before you ship.

About this series: part of YATA-NODE's "rights basics" series. The hub is the pre-ship rights checklist. Related deep-dives are how to read AI service terms (the contract on the AI you use) and AI-generated content copyright (the rights in the output). For a cross-border angle, see also export control for builders. Each piece stands on its own (no reading order required).

A few terms (for newcomers):

  • Hard law: legally binding law — statutes passed by a legislature, or regulations issued by an agency. What follows a breach (criminal penalties, administrative sanctions, private-law consequences) varies by regime; binding does not always mean penalised. The EU AI Act and Japan's privacy law are hard law.
  • Soft law: guidelines, agency documents, and industry self-standards. Weakly binding at best, but they can become a de facto standard and a reference point in court or administrative guidance. Japan's "AI Guidelines for Business" are a leading example.
  • Risk-based regulation: a framework that classes systems by their impact on people and society, loading heavy duties onto high-risk uses and light ones onto low-risk uses. The EU AI Act and some US state laws use this shape.
  • High-risk AI: AI that materially feeds into important decisions about people — employment, credit, education, health, housing, legal. It is defined separately in each jurisdiction. Whether you step into this zone is the line that sets how heavy your duties are.
  • Provider vs. deployer: the AI Act's core distinction. A provider places an AI system on the market, or puts it into service, under its own name or trademark, whether for payment or free of charge (Art. 3(3)) — including "for own use in the Union" (Art. 3(11)), so an internal-only system counts. A deployer uses AI under its own authority (Art. 3(4)); public authorities and professionals included. Purely personal, non-professional use falls outside deployer duties (Art. 2(10)).
  • Extraterritorial reach: a mechanism that applies a law to operators outside its own borders. The tests differ by statute. For providers and deployers, the AI Act (Art. 2(1)) reaches you if you place an AI system on the EU market or put it into service there (a), if you are a deployer located in the Union (b), or if you are a third-country provider or deployer and "the output produced by the AI system is used in the Union" (c) — "targeting" is not an AI Act test. (Article 2(1) also lists further roles — importers and distributors, product manufacturers, authorised representatives, and affected persons in the Union.) GDPR (Art. 3(2)) uses a different test: offering goods or services to, or monitoring the behaviour of, people who are in the Union. "I'm not in the EU, so it doesn't apply" does not hold.

Don't lump "AI regulation" into one thing — three poles, three directions

A 3-column comparison of AI-regulation directions: Japan (promotion / voluntary — 'no penalty' is not 'no rules'), the EU (hard law / risk-based, extraterritorial reach), and the US (federal swings by administration plus state laws; the Dec 2025 EO is not immediate, working via litigation). As of 2026-06; fine percentages, statute names, and EO details are in the body.

When a headline says "AI regulation is getting stricter," the meaning flips depending on which country and which instrument it means. The three major poles run in different directions, and getting the map of how each one bites into your head first makes everything downstream easier.

The EU points toward hard law, risk-based. The EU (Regulation (EU) 2024/1689), in force since August 2024, is often described as the world's first comprehensive AI law. It is commonly described as sorting AI into four risk tiers (unacceptable = prohibited / high-risk / limited-transparency / minimal), but that is the European Commission's explanatory model, not a statutory taxonomy: the Regulation itself is structured as Article 5 (prohibitions), Article 6 + Annex III (high-risk), Article 50 (transparency for certain systems), and Chapter V (general-purpose AI models — a separate regime the four-tier picture does not capture). Heavier duties (conformity assessment, technical documentation, risk management) land on the higher tiers. The fines are in a different league: up to 7% of total worldwide annual turnover (or €35 million, whichever is higher) for the prohibited-practices breaches in Article 5 — set out in the penalty provision, Article 99. For SMEs, including start-ups, the cap flips: Article 99(6) provides that each fine "shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower" — so a small builder is capped at the lower of the two, not the higher. High-risk breaches and the Article 50 transparency duties sit on a separate, lower ceiling — "administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher" (Article 99(4)); a still-lower ceiling of up to €7.5 million or 1%, whichever is higher, applies only to supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in reply to a request (Article 99(5)). And through extraterritorial reach (Article 2), it can pull in a Japanese or US operator whose outputs are used in the EU. The framework is steadily strict; mostly the dates are in motion (a few substantive obligations are also under simplification via the Digital Omnibus — see below).

The US points toward a federal level that swings by administration, plus a state patchwork. Federal executive orders (EOs) are reversed and reissued with each administration — the Biden-era comprehensive EO 14110 was rescinded by the Trump administration in January 2025, and in December 2025 an EO aimed at federal preemption of state AI laws followed. That December 2025 EO does not itself instantly void state laws. But it is not merely declaratory either: it orders concrete, deadline-bound measures — a DOJ litigation task force (within 30 days), a Commerce Department evaluation of state laws (90 days), conditioning of federal funding (e.g., BEAD), and the start of FCC proceedings — so pressure from the federal level, through litigation, administrative action, and funding conditions, is in progress. By April 2026 this had moved from paper to court: xAI sued to block Colorado's AI Act (SB 24-205) on 9 April, and on 24 April 2026 the DOJ moved to intervene as a plaintiff — via its Civil Rights Division, on Equal Protection grounds. The court granted the unopposed motion the same day, reasoning that the Civil Rights Act of 1964 gives the United States an unconditional right to intervene in Equal Protection cases once the Attorney General certifies the case as one of general public importance (42 U.S.C. § 2000h-2). On 27 April 2026 the court stayed enforcement of the Act — on the parties' joint motion and stipulation, not on the merits — barring enforcement for conduct occurring on or before 14 days after the court rules on xAI's forthcoming preliminary-injunction motion (case 1:26-cv-01515, D. Colo.; in the RECAP mirror of the docket as retrieved on 17 July 2026, the latest visible filing is that 27 April order and no ruling on the injunction appears — the official record is on PACER). So the litigation pressure is no longer hypothetical — re-check the docket and the primary sources for the current posture. Because the federal layer is fluid, the things that reliably bite are existing sector regulators (securities = SEC / consumer protection = FTC / employment = EEOC / finance = CFPB / medical devices = FDA) plus state laws — Colorado's AI Act and the transparency and bias statutes already live in California, Texas, and Illinois (see the next section). The technical-standard NIST AI RMF (voluntary) has so far continued across administrations and is widely used as a voluntary industry reference.

Japan points toward promotion and self-direction — covered in depth in the Japanese edition, so just the headline here. Its core AI Promotion Act carries no penalty-backed prohibitions: the statute's purpose is to promote R&D, competitiveness, and talent — a promotion law, not a regulatory one. That is not the same as "nothing binds you," though: businesses that build, supply, or otherwise use AI in their operations owe a statutory duty to cooperate with national and local measures (Art. 7 — a category defined by the Act itself, not the AI Act's "deployer"), and the state runs fact-finding on AI-related harms and issues guidance (Art. 16). The practical guidance, the "AI Guidelines for Business" (METI / MIC), is soft law (non-binding best practice), and the government steers through a cabinet-decided AI Basic Plan. So Japan directs through duties, guidance, and planning rather than penalty-backed prohibitions — thin on hard penalty lines. It is best read as another pole on the same map, not a smaller version of the EU.

The three poles in a line: EU = "depends on the risk tier, heavy if you step in + extraterritorial" / US = "don't count on the federal layer; look at existing sector law + state laws" / Japan = "the AI Promotion Act sets out duties for operators but carries no penalties of its own (easy to comply at first)." Same phrase, three completely different kinds of force. Note that Japan's other statutes — privacy law, copyright law — still bite as usual: "no penalties in the AI Promotion Act" is not "nothing regulates AI in Japan."

Which regime applies to your product — sorting by attribute

An attribute-based flowchart (simplified) for finding which AI regime applies to your product: Q1 EU users/outputs (extraterritorial) -> EU AI Act Art. 2 / GDPR Art. 3; Q2 high-risk use -> EU AI Act Annex III / US state & federal sector laws; Q3 Japan only -> AI Promotion Act + guidelines / Personal Info Act / Copyright Act Art. 30-4; Q4 embedded generative AI -> EU AI Act Art. 50 / some US state laws. High-risk use examples and specific agencies are in the article's table. As of 2026-06.

Once the three-pole map is in your head, sort out which one reaches your product. The trick is to think by attribute, not by country name. Run the next four questions in order, and the regimes you need to investigate come into focus.

Question (attribute)Regimes that may bite if "yes"
1. EU users or outputs used in the EU? (entry point to extraterritorial reach)EU AI Act (Art. 2(1)) / GDPR (Art. 3(2)). Reaches you even from outside the EU. Note: a "yes" here is a flag to go check each statute's own test — the question itself is not the test
2. High-risk use? (employment / credit / education / health / housing / legal)EU AI Act Annex III / US state laws (e.g., the Colorado AI Act; Texas HB 149, effective 2026-01-01; California's FEHA automated-decision-system employment regulations, effective 2025-10-01) / US federal sector regulators (EEOC, CFPB, FDA)
3. US domestic, broad consumer scale?State transparency / bias laws (CA AB 2013, TX TRAIGA (HB 149), IL HB 3773, CA SB 942 — representative examples, not an exhaustive list) — several carry scale thresholds
4. Embed generative AI? (output transparency)EU AI Act Art. 50 (chatbot disclosure / AI-output marking) / some US state laws

Here is the good news for solo developers: scale and use thresholds let you sidestep a lot. California's generative-AI transparency rule (SB 942) reaches only a "covered provider" — a person that creates, codes, or otherwise produces a generative AI system with "over 1,000,000 monthly visitors or users" that is publicly accessible in the state — so most individual-scale projects fall outside it (the 2025 amendment, AB 853, pushed the Act's operative date to 2 August 2026 and layers separate duties, from 1 January 2027, onto large online platforms that exceeded 2,000,000 unique monthly users in the preceding 12 months and onto GenAI hosting platforms). The federally fluid layer aside, the duties that actually reach a small builder cluster around two boundaries.

First, the EU's extraterritorial reach. Article 2 of the AI Act reaches a third-country operator not only for "placing AI on the EU market" but where the output is used inside the EU. (Art. 3(2)) likewise reaches a non-EU operator that offers goods or services to, or monitors the behavior of, people physically in the EU (the text says "data subjects who are in the Union" — not only residents, but travelers in the EU too). So "I develop solo in Japan or the US, so the EU is irrelevant" is wrong. The burden, though, scales with the risk tier: a general usually carries none of the duties specific to high-risk AI (conformity assessment and the rest). That is not the same as "nothing applies" — the Article 4 AI-literacy duty binds every provider and deployer regardless of risk tier (in force since 2 February 2025), and if you touch generative AI you still have to check Article 50 transparency, the Article 5 prohibitions, and the general-purpose AI model regime in Chapter V. The adopted Digital Omnibus (publication in the Official Journal not yet confirmed as of July 2026) replaces Article 4 but keeps the duty on providers and deployers: the standard softens from "ensure ... a sufficient level of AI literacy" to "take measures to support the development of" it, with an explicit clarification that it does not require you to guarantee any specific level for any individual. The duty is relaxed, not removed — and until that text is in force, the current Article 4 applies as written. Separately, a natural person using AI in a purely personal, non-professional capacity falls outside deployer duties (Art. 2(10) — the test is whether the use is professional, not whether it is "for yourself"). That exemption concerns deployer duties under the AI Act; providers still carry their duties, and laws like criminal law and data protection (GDPR) apply independently where their own conditions are met. How far the Article 5 prohibited practices reach a purely private user is not settled by the text alone (Article 99 penalties are addressed to operators). If you embed generative AI, the one thing worth internalizing early is the Article 50 transparency duty — and Article 50 is not "one label on everything": it splits into provider-side machine-readable marking (making synthetic output detectable) and deployer-side disclosure (that something is a deepfake, or public-facing AI text). It applies from 2 August 2026 (Art. 113); the adopted-but-not-yet-in-force Digital Omnibus adds a transitional window, giving systems already on the market before that date until 2 December 2026 to comply with the Art. 50(2) marking duty.

Second, high-risk use. Step into uses that touch important decisions about people — employment, credit, education, health, housing, legal — and the duties bite hard: in the EU, the Annex III high-risk obligations; in the US, state laws like the Colorado AI Act plus the EEOC / CFPB / FDA sector regulators. A general tool SaaS is mostly out of scope, but it pays to carry the instinct, at the use-design stage, that the moment you edge into "hiring support," "credit scoring," or "clinical decision support," you enter the high-difficulty zone.

But who owes what depends on your role. Conformity assessment (Art. 43), technical documentation, the quality-management system and CE marking are provider duties (Art. 16(f)); they are not imposed on deployers across the board. A deployer's duties (Art. 26) center on using the system per the instructions for use, assigning human oversight, input-data suitability, monitoring and log retention — and the fundamental-rights impact assessment (Art. 27) is confined to public-law bodies, private entities providing public services, and deployers of Annex III 5(b)-(c) systems. Note also Art. 25: put your own name or trademark on a high-risk system already on the market, substantially modify it, or change its intended purpose, and you are treated as the provider.

One scoping caveat on "housing," "legal," and "health": under the EU AI Act these are narrower than the bare list suggests. "Housing" as such is not an Annex III category at all; "legal" is limited to Annex III point 8(a) — AI used by a judicial authority or on its behalf to assist in researching and interpreting facts and the law and applying the law to concrete facts, or used in a similar way in alternative dispute resolution — not general legal-support tools; and "health" as such is not an Annex III category either — Annex III reaches only AI used by (or for) public authorities to evaluate eligibility for "essential public assistance benefits and services, including healthcare services," and to grant, reduce, revoke or reclaim them (point 5(a)); risk assessment and pricing for life and health insurance (5(c)); and emergency patient triage (5(d)). Medical devices and clinical decision-support software take a different route entirely: they are high-risk via Article 6(1) and the Annex I harmonisation legislation (e.g. the MDR), not Annex III — while US state laws define their "consequential decisions" on their own terms. And even inside an Annex III use, Article 6(3) takes a system out of the high-risk class where it "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons" — where it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations from prior patterns without being meant to replace or influence the previously completed human assessment (absent proper human review), or performs a preparatory task. Profiling of natural persons is always high-risk, and a provider relying on the derogation must document that assessment before the system goes on the market (Art. 6(4)). So read "housing / legal / health" in this list as a flag to go check, not a finding that your tool is high-risk.

A rough sorting guide: (1) US domestic only + not high-risk → most of the state AI laws cited here (CA SB 942 / Colorado / TX / IL) carry scale or use thresholds, and your existing duties (consumer protection via the FTC, sector regulators) are the baseline; in Japan-only scope, the AI Promotion Act and guidelines carry no penalties, but non-AI-specific existing law (privacy, copyright) still applies separately. (2) EU users / outputs, or high-risk use → this is past the reach of this article; name the specific regime, investigate it, and bring in a lawyer if needed. If you embed generative AI, Article 50 binds you with no scale threshold, so keep in mind which of its duties attach to your role and output type (it is not one label on everything).

The order to check — treat this area as one where dates go stale

A four-lane list of primary sources to check, by jurisdiction: Japan (e-Gov Law Search / Cabinet Office / PPC / Agency for Cultural Affairs / Digital Agency), EU (EUR-Lex / EC Digital Strategy / EDPB), US federal (Federal Register / NIST / agencies SEC/FTC/EEOC/CFPB/FDA), and US states (state legislatures), with a footer note to always re-check enforcement dates in primary sources. As of 2026-06.

The single most important mindset in this area is to read every date and effective-status as perishable. In fact, the picture has moved in a matter of weeks. As of 17 July 2026:

  • US — the Colorado AI Act: once framed as a comprehensive risk-based regime taking effect in 2026, it was overhauled: the 2026 amendment (SB 26-189, signed 14 May 2026 — after the April stay described above, and it covers "any legislation replacing or amending SB24-205 enacted during this legislative session") repealed and reenacted the 2024 Act's provisions (SB 24-205) ("The act repeals and reenacts those provisions with new requirements regarding the use of automated decision-making technology in consequential decisions"). Read the dates carefully: under the signed act's Section 5, "this act takes effect January 1, 2027" except for a listed handful of provisions that take effect upon passage, and "this act applies to consequential decisions made on or after January 1, 2027" — so 1 January 2027 is the date for the developer duties (which the official summary marks "starting January 1, 2027"), the deployer duties, and the attorney general's rulemaking deadline alike. Separately, the April stay above reaches "SB24-205 (or any legislation replacing or amending SB24-205 enacted during this legislative session)", so enforcement of this amended regime is paused too, until 14 days after the preliminary-injunction ruling. The original risk-based duties (duty of care, impact assessments, risk-management programs) are gone. But it did not shrink to "transparency only": developers and deployers (here in Colorado's own sense — a business deploying an automated decision system, not a consumer; a separate statute with a separate definition from the EU AI Act's deployer) still owe duties, split by role: technical documentation on the developer, consumer notice on the deployer, and record retention (3+ years) on both. After an adverse automated decision the deployer must give the consumer a plain-language description of the system's role within 30 days, and consumers retain the right to request their personal data and its correction, and to request meaningful human review and reconsideration. Enforcement sits with the state Attorney General. Treat "a comprehensive regime is about to take effect" as outdated, and don't over-build against the original version.
  • EU — the AI Act's high-risk application dates: against a backdrop of delayed harmonized standards, the simplification package ("Digital Omnibus") was formally adopted — the European Parliament voted it through on 16 June 2026, the Council adopted it on 29 June 2026, and the final act was signed on 8 July 2026. As of 17 July 2026 publication in the Official Journal is not yet confirmed (the procedure file reads "Procedure completed, awaiting publication in Official Journal"). Under Article 4 of the adopted text, it "shall enter into force on the third day following that of its publication in the Official Journal of the European Union." The dates move as follows: standalone high-risk (Annex III) from 2 August 2026 to 2 December 2027, and product-embedded (Annex I) to 2 August 2028. Verify the dates against the published text before you rely on them.
  • Japan — the privacy-law reform: the bill (adding a surcharge (kachōkin) regime and a narrow consent exemption for statistics creation — it is not a general carve-out for AI training) cleared the Diet on 10 July 2026 (House of Councillors plenary; the House of Representatives had passed it on 26 May 2026) and was promulgated on 17 July 2026 (announced by the Personal Information Protection Commission the same day). It takes effect — except for certain provisions — on a date set by cabinet order within two years of promulgation, so the commencement date is still open while the cabinet order, commission rules and guidelines are worked out (this article has not verified the law number). The Japanese-law specifics live in the Japanese edition.

The danger of this area is that treating a six-month-old explainer, or a generative-AI answer, as current will mislead you. So the final check goes to primary sources, in roughly this order:

  1. Narrow to the one or two jurisdictions that reach you first (the attribute sorting above). Don't try to cover everything.
  2. Go to that jurisdiction's primary sources. EU: EUR-Lex (eur-lex.europa.eu), the European Commission's digital-strategy pages, the EDPB. US federal: the Federal Register (federalregister.gov), NIST, and the agencies (SEC / FTC / EEOC / CFPB / FDA). US states: each state legislature (leg.colorado.gov, leginfo.legislature.ca.gov, etc.). Japan: e-Gov Law Search, the Cabinet Office, the PPC, the Agency for Cultural Affairs, the Digital Agency.
  3. Always confirm the effective date and the latest amendment status. Effective dates move often, so read the authority's latest, not an explainer's date.
  4. Hand the individual suitability call to a professional. Primary sources get you to "which regime probably bites"; the final legality call belongs to a lawyer, the authority, or an industry body.

So this article runs only to the entry point of which regime to investigate, and hands the determination downstream to a professional. In a fast-moving area, picking the right entry point is the shortest path to cutting both wasted research and over-compliance.

Summary — a self-check checklist of "which one reaches you"

You don't need a "yes" on everything. Use it as a map to sort out which regime to investigate for your product and where you ship it. Paste the relevant list into a dev note or an internal check sheet.

text
[If you're a solo / side-project AI/DX developer]
□ 1. Checked whether your product has EU users or outputs used in the EU (if so, investigate extraterritorial reach = EU AI Act / GDPR)
□ 2. Checked whether the use steps into high-risk territory (employment / credit / education / health / housing / legal) (if so, investigate EU Annex III + US state laws)
□ 3. If you embed generative AI, checked the Article 50 transparency duty for your role — provider = machine-readable marking of synthetic output (50(2)) and disclosing that a user is interacting with an AI (50(1)); deployer = disclosing deepfakes and public-interest AI text (50(4)). Article 50 has no scale threshold, but the 50(2) marking duty does not apply where the system performs "an assistive function for standard editing" or does not substantially alter the deployer's input data or its semantics. Note: "I only call someone else's model through an API" does not settle your role. If you offer the resulting AI system under your own name or trademark, you can be the provider *of that system* even though the underlying model is someone else's (Art. 3(3)); putting your trademark on an existing high-risk system, substantially modifying it, or changing its intended purpose also makes you the provider (Art. 25). Decide separately for internal use and for what you ship to customers
□ 4. Understood that even US- or Japan-domestic, existing non-AI law (privacy, copyright) applies separately — "no AI-specific penalty" is not "no rules"
□ 5. Set up a habit of confirming effective dates in primary sources, not trusting a six-month-old explainer or an AI answer
□ 6. Ready to hand off to a professional (a lawyer) if high-risk use or extraterritorial reach looks likely

[If you're a company practitioner (DX / IT / legal)]
□ 1. Sorted out whether you are a provider, a deployer, or both (the roles can stack)
□ 2. Sorted out whether you have EU customers / outputs (building an internal AI system and using it yourself in the Union, under your own name or trademark, can make you a provider as well as a deployer)
□ 3. Inventoried high-risk uses, and if any apply, considered the structure for your role — conformity assessment and technical documentation (as provider) / use monitoring, log retention, and where applicable a fundamental-rights impact assessment (as deployer)
□ 4. Confirmed the existing sector regulators (SEC / FTC / EEOC / CFPB / FDA) + applicable state laws, not relying on the federal layer
□ 5. Built a "re-check right before ship" step for effective dates and amendment status into the internal flow (especially the CO AI Act / EU Omnibus / state laws)
□ 6. Considered adopting NIST AI RMF (voluntary; has so far continued across administrations) as an internal standard

The three axes: "AI regulation" is not one thing (map the difference between EU = hard law, US = swings, Japan = promotion first); sort by attribute, not by country (EU extraterritorial reach / high-risk use / embedded generative AI are the boundaries that matter most for a small builder); and read dates as perishable, go to primary sources, and hand the determination to a professional (this article runs to the entry point only).

From here, individual suitability assessments and the final call on whether a specific product is regulated are past this article's reach. The contract on the AI you use is in how to read AI service terms; the rights in the output are in AI-generated content copyright; the whole picture of rights starts at the pre-ship rights checklist. When in doubt, always confirm with a lawyer, the authority in each jurisdiction, or an industry body.

References

Primary materials where available; for the fast-moving parts, reputable analyses are used to locate the primaries. A trailing (primary) marks a primary source; (supporting) marks commentary used to locate primaries. Sources reflect verification as of 2026-06, with the moving items re-confirmed against the primaries on 2026-07-17 (the House of Councillors page is itself dated "as of 10 July 2026"). AI / DX law moves especially fast, so every point reflects the picture at its confirmation date — re-check the moving items at the time of use.

EU (primary — statutes / authorities)

US (primary — statutes / agencies)

Japan (supporting for this edition — primary in the Japanese edition)

Currency note (re-check at time of use)

  • Colorado AI Act: the 2026 amendment (SB 26-189, signed 2026-05-14) repealed and reenacted the earlier provisions; the signed act takes effect 2027-01-01 (Section 5; a listed few provisions on passage) and applies to consequential decisions made on or after that date — the same date the official summary gives for the developer's technical-documentation duty and the AG's rulemaking deadline. The original risk-based duties were removed, but technical documentation, notice, the deployer's 30-day plain-language explanation after an adverse outcome, human-review / correction rights, and AG enforcement remain (confirm against leg.colorado.gov).
  • EU Digital Omnibus: adopted (European Parliament 2026-06-16 / Council 2026-06-29) and the final act signed 2026-07-08; awaiting Official Journal publication as of 2026-07-17 = not yet in force (Annex III high-risk dates 2026-08-02 → 2027-12-02; product-embedded 2028-08-02 — confirm against EUR-Lex).
  • US Dec-2025 preemption EO (EO 14365, "Ensuring a National Policy Framework for Artificial Intelligence"): issued, ordering a DOJ litigation task force, state-law evaluation, BEAD funding conditions, and FCC proceedings. It does not instantly void state law, but it has produced concrete litigation — the DOJ intervened as a plaintiff on 24 April 2026 in xAI's challenge to the Colorado AI Act, and on 27 April 2026 the court, on the parties' joint motion and stipulation, stayed enforcement of that Act until 14 days after it rules on xAI's forthcoming preliminary-injunction motion (the docket as retrieved 2026-07-17; confirm against the DOJ release and the court docket).

On AI assistance: Starting from points the author already knew, the author used LLMs (Claude by Anthropic, with a second, independent model cross-checking the legal facts) to research, organize, and summarize, then verified the facts against the primary sources cited above. AI / DX law moves especially fast, so statute names, effective dates, and penalty ceilings reflect the picture as of 17 July 2026; the moving items are flagged in the currency note — re-check the latest version in primary sources at the time of use. For the "not legal advice" note and what is out of scope, see the disclaimer at the top.

About the author

More than 20 years of electrical and software development — from control engineering at a major electronics manufacturer — plus about 10 years of solo development. Across hardware and software, and across enterprise and individual work, I publish the basics that "become a risk if you don't know them," and I plan to cover practical ways to use AI as well. More at About this blog.