AI regulation overview
The AI rules that matter to Hong Kong businesses
Laws, regulations and guidelines on AI in Hong Kong, Mainland China, the European Union and the United States, with their status, the next key dates and a plain-language summary of each. HKAIIA members also see who each rule applies to, the key obligations and penalties, and what to do now.
- rules tracked
- 50rules tracked
- in force
- 26in force
- key dates in the next 12 months
- 20key dates in the next 12 months
- rated high relevance
- 21rated high relevance
General information, not legal advice
This overview summarises public sources as last verified on 1 October 2026. Rules and dates change, and whether a rule applies to you depends on your circumstances. Please check the official source and take legal advice before you act on anything here.
Key dates ahead
What changes next, earliest first.
30 October 2026
Public consultation on the EDPB anonymisation and web-scraping guidelines closes.
European Union · GDPR (AI development and use)
10 November 2026
The suspension ends unless extended, after which the October 2025 controls, including the extraterritorial rare earth rule, would apply.
Mainland China · Export controls (rare earths, batteries, technology)
10 November 2026
The Affiliates Rule returns automatically unless BIS extends the suspension.
United States · EAR AI chip export controls
2 December 2026
New bans on AI that generates non-consensual intimate imagery or child sexual abuse material apply, and generative AI systems placed on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking duty.
European Union · EU AI Act
9 December 2026
Member States must transpose the Directive by this date, and the new liability rules apply to products placed on the market or put into service after it.
European Union · New Product Liability Directive (PLD)
31 December 2026
The FSTB is expected to hold a public consultation later in 2026 on a legal framework for detecting and removing fraudulent content, including AI-generated fraud.
Hong Kong · 2026 Policy Address AI governance plan
Show all 34 datesShow fewer dates
31 December 2026
The Hong Kong AI Research and Development Institute (AIRDI) is expected to begin operation in 2026.
Hong Kong · 2026 Policy Address AI governance plan
1 January 2027
Businesses already using ADMT for significant decisions must comply with the ADMT rules on pre-use notice, opt-out and access.
United States · CCPA ADMT regulations
1 January 2027
Duties for large online platforms and GenAI hosting platforms begin, requiring them to detect and display provenance data.
United States · California AI Transparency Act (content provenance)
1 January 2027
SB 867's ban on toys containing companion chatbots takes effect.
United States · California GenAI developer and chatbot laws
1 January 2027
SB 26-189 takes effect, and the Attorney General's rules are due by this date.
United States · Colorado ADMT law (formerly Colorado AI Act)
12 January 2027
Providers of cloud and other data processing services may no longer charge switching fees.
European Union · Data Act
20 January 2027
The Machinery Regulation applies and the Machinery Directive 2006/42/EC is repealed, with no transition period.
European Union · Machinery Regulation
31 January 2027
This is the annual deadline for reporting the 2026 compliance audit on minors' personal information.
Mainland China · PIPL
1 March 2027
Annual reports covering calendar year 2026 are due for restricted cloud-computing transactions with 25% or more country-of-concern or covered-person ownership.
United States · DOJ bulk sensitive data rule (Data Security Program)
13 March 2027
This is the 450-day statutory deadline for the Treasury to issue regulations implementing the COINS Act, and existing rules apply until then.
United States · US outbound investment rules (OISP / COINS Act)
1 July 2027
SB 243 annual reports to the Office of Suicide Prevention begin, and SB 1119 core duties are expected to start.
United States · California GenAI developer and chatbot laws
1 July 2027
California SB 947 becomes operative.
United States · US AI-in-hiring laws
2 August 2027
General-purpose AI models placed on the market before 2 August 2025 must comply.
European Union · GPAI model obligations and Code of Practice
12 September 2027
Unfair contract term rules extend to certain long-term data-sharing contracts concluded on or before 12 September 2025.
European Union · Data Act
2 December 2027
Obligations for high-risk AI systems listed in Annex III apply, for example in recruitment, credit scoring, education, biometrics and critical infrastructure.
European Union · EU AI Act
11 December 2027
The CRA applies in full, covering essential cybersecurity requirements, conformity assessment and CE marking, and the RED cybersecurity Delegated Regulation (EU) 2022/30 is repealed.
European Union · Cyber Resilience Act (CRA) and RED cybersecurity rules
31 December 2027
AI agent safety-management guidelines for society at large, prepared with the AIRDI, are expected in 2027.
Hong Kong · 2026 Policy Address AI governance plan
31 December 2027
Risk assessments must be completed for processing that began before 2026 and continues.
United States · CCPA ADMT regulations
1 January 2028
Capture device manufacturer duties apply to cameras, phones and recorders first produced for sale in California from this date.
United States · California AI Transparency Act (content provenance)
1 April 2028
First risk assessment submissions to CalPrivacy are due, along with the first cybersecurity audit certifications for businesses with 2026 revenue above US$100 million.
United States · CCPA ADMT regulations
2 August 2028
Obligations for high-risk AI embedded in regulated products covered by Annex I apply.
European Union · EU AI Act
2 August 2028
This is the legal deadline for Commission delegated acts adding AI Act-based requirements for high-risk AI safety functions to the Machinery Regulation.
European Union · Machinery Regulation
1 January 2029
The ban on importing vehicle connectivity system (VCS) hardware with a China or Russia nexus applies to components without a model year, and from Model Year 2030 to others.
United States · Connected vehicles rule (ICTS)
1 April 2029
Cybersecurity audit certifications are due for businesses with revenue of US$50–100 million.
United States · CCPA ADMT regulations
1 January 2030
The 60-day right to cure before enforcement expires.
United States · Colorado ADMT law (formerly Colorado AI Act)
1 April 2030
Cybersecurity audit certifications are due for smaller covered businesses.
United States · CCPA ADMT regulations
1 August 2030
In a related sector rule, the new Toy Safety Regulation (EU) 2025/2509 applies, including rules for connected and AI-enabled toys.
European Union · General Product Safety Regulation (GPSR)
1 January 2031
SB 867's toy ban expires unless extended.
United States · California GenAI developer and chatbot laws
Browse the rules
50 of 50 shown
- Hong KongGuidanceGuidanceHigh relevance
PCPD AI Model Framework
Artificial Intelligence: Model Personal Data Protection Framework (with the supplementary guidance 'Protecting Personal Data Privacy in the Use of Agentic AI')
The Privacy Commissioner's main reference for organisations that buy, customise or use AI systems involving personal data. It recommends measures in four areas, covering AI strategy and governance, risk assessment and human oversight, customisation and management of AI systems, and stakeholder communication. A 2026 supplement applies the same approach to agentic AI. It is guidance, not law.
- Issuer:
- Office of the Privacy Commissioner for Personal Data (PCPD)
- Last verified:
- 1 October 2026
- Official sources:
- Artificial Intelligence: Model Personal Data Protection Framework (PCPD, PDF), PCPD media statement, 11 June 2024, Protecting Personal Data Privacy in the Use of Agentic AI (PCPD, PDF), PCPD media statement, 25 August 2026 (agentic AI guidance), PCPD media statement, 19 May 2026 (AI compliance checks on 60 organisations), PCPD media statement, 16 March 2026 (agentic AI alert), Guidance on the Ethical Development and Use of Artificial Intelligence, 2021 (PCPD, PDF), PCPD AI Privacy Protection resource page
- Hong KongGuidanceGuidanceHigh relevance
PCPD GenAI Employee Checklist
Checklist on Guidelines for the Use of Generative AI by Employees
A practical checklist to help organisations write an internal policy on staff use of generative AI tools at work while complying with the PDPO. It covers permitted tools and purposes, what data may be entered, checking outputs, security and the consequences of breaches. It is guidance, not law.
- Issuer:
- Office of the Privacy Commissioner for Personal Data (PCPD)
- Last verified:
- 1 October 2026
- Hong KongGuidanceGuidanceHigh relevance
DPO GenAI Guideline
Hong Kong Generative Artificial Intelligence Technical and Application Guideline (read with the Ethical Artificial Intelligence Framework)
The Government's practical guide for developers, service providers and users of generative AI in Hong Kong. It sets out a governance framework built on five dimensions (personal data privacy, intellectual property, crime prevention, reliability and trustworthiness, and system security) and recommends that AI-generated content be identified by watermarks, labels or metadata. The companion Ethical AI Framework provides principles and an AI assessment template. Both are voluntary.
- Issuer:
- Digital Policy Office (DPO), HKSAR Government; Guideline prepared with the Hong Kong Generative AI Research and Development Center (HKGAI)
- Last verified:
- 1 October 2026
- Official sources:
- DPO: Ethical AI Framework and Generative AI Guideline page, Hong Kong Generative AI Technical and Application Guideline v1.1 (DPO, PDF), Ethical AI Framework v2.0 (DPO, PDF), DPO press release, 15 April 2025, LCQ11: Regulating use of AI-generated synthetic content (15 July 2026), 2026 Policy Address, paragraph 123(iii) (procurement declarations)
- Hong KongIn forceLawHigh relevance
PDPO
Personal Data (Privacy) Ordinance
Hong Kong's general data protection law. It is technology-neutral and principle-based, so its six Data Protection Principles apply whenever an AI system collects, uses, stores or produces personal data. Hong Kong has no AI-specific statute, which makes the PDPO the main binding law for AI that touches personal data.
- Issuer:
- Legislative Council of the HKSAR; regulated by the Office of the Privacy Commissioner for Personal Data (PCPD)
- Last verified:
- 1 October 2026
- Official sources:
- Personal Data (Privacy) Ordinance, Cap. 486 (Hong Kong e-Legislation), PCPD: The Ordinance at a Glance (principles and penalties), LCQ2: Prevention of personal data breaches and financial crimes (22 January 2025), PCPD paper to LegCo Panel on Constitutional Affairs (13 February 2026), CMAB paper to LegCo Panel on Constitutional Affairs (23 September 2026)
- Hong KongIn forceMeasuresHigh relevance
GBA Standard Contract
Standard Contract for Cross-boundary Flow of Personal Information Within the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland, Hong Kong)
A voluntary, pre-set contract that lets organisations move personal information between Hong Kong and the nine Mainland cities of the Greater Bay Area through a simpler process than the general Mainland export routes. Both parties sign the standard terms, carry out a simplified impact assessment and file the contract within 10 working days. This entry covers the Hong Kong side's requirements and benefits; the Mainland side is covered separately.
- Issuer:
- Cyberspace Administration of China (CAC) and HKSAR Innovation, Technology and Industry Bureau (ITIB); administered in Hong Kong by the Digital Policy Office; PCPD guidance
- Last verified:
- 1 October 2026
- Official sources:
- Digital Policy Office: GBA Standard Contract facilitation measure, Digital Policy Office: Facilitating cross-boundary data flow within the GBA, Implementation Guidelines on the GBA Standard Contract (English translation, PCPD, PDF), PCPD Guidance on Cross-boundary Data Transfer: GBA Standard Contract (PDF), Government press release: facilitation measure extended to all sectors (1 November 2024), PCPD: LegCo Panel on Constitutional Affairs meeting, 23 September 2026
- Hong KongProposedPolicyHigh relevance
2026 Policy Address AI governance plan
The Chief Executive's 2026 Policy Address: Application and Risk Governance of Artificial Intelligence (paragraphs 102–123)
Hong Kong's first broad plan for governing AI risks. It does not create a general AI law, but it sets seven priorities, covering AI-enabled crime, protection of minors, an ethics governance framework, application safety, liability for accidents caused by AI products, AI Agent guidelines and the impact on employment. Most items are studies, consultations or guidelines, and none is yet law.
- Issuer:
- Chief Executive of the HKSAR; coordinated by the Chief Secretary for Administration, with a new Commissioner for AI under the Digital Policy Office
- Next key date:
- 31 December 2026. An FSTB public consultation on a legal framework for detecting and removing fraudulent content, including AI-generated fraud, is expected later in 2026.
- Last verified:
- 1 October 2026
- Official sources:
- Full text of the Chief Executive's 2026 Policy Address (4), paragraphs 102-123, 2026 Policy Address (full text, PDF), LCQ11: Regulating use of AI-generated synthetic content (15 July 2026), Digital Policy Office: Hong Kong AI Research and Development Institute, CMAB paper to LegCo Panel on Constitutional Affairs (23 September 2026)
- Hong KongGuidanceGuidance
SFC GenAI circular
Circular to licensed corporations: Use of generative AI language models
The SFC expects licensed corporations that use generative AI language models in regulated activities to apply four core principles, namely senior management oversight, AI model risk management, cybersecurity and data risk management, and third-party provider risk management. Investment advice, recommendations and research are treated as high-risk uses needing extra safeguards. A June 2026 circular adds expectations on defending against AI-enabled cyberattacks.
- Issuer:
- Securities and Futures Commission (SFC)
- Last verified:
- 1 October 2026
- Hong KongGuidanceGuidance
HKMA GenAI guidance
Consumer Protection in respect of Use of Generative Artificial Intelligence (HKMA circular) and related HKMA AI supervisory guidance
The HKMA expects banks using generative AI in customer-facing services to apply its 2019 big data and AI principles plus extra safeguards covering board accountability, fair outcomes, disclosure to customers and data protection. In the early stage of deployment, banks should keep a human in the loop and, as far as practicable, let customers opt out and ask for human review. These are supervisory expectations, not statute.
- Issuer:
- Hong Kong Monetary Authority (HKMA)
- Last verified:
- 1 October 2026
- Official sources:
- HKMA circular, 19 August 2024 (Banking Regulatory Document Repository, PDF), HKMA press release: GenA.I. Sandbox++ launched (5 March 2026), HKMA press release: First cohort of GenA.I. Sandbox++ (27 August 2026), HKMA press release: Fintech 2030 (3 November 2025), HKMA report: Supporting A.I. Adoption in Fighting Financial Crime (June 2026, PDF), HKMA circular: Use of AI for Monitoring of Suspicious Activities (9 September 2024, PDF)
- Hong KongIn forceLaw
Deepfake intimate images offence
Crimes Ordinance offence of publishing or threatening to publish intimate images without consent (covers AI-altered and deepfake images), and the pending review of deepfake law
Publishing, or threatening to publish, an intimate image of a person without consent is an offence under the Crimes Ordinance, including where the image has been altered with deepfake technology. Creating such an image without publishing it is not a specific offence. The Law Reform Commission is studying deepfake-related crime and legislation is under consideration, but no bill exists.
- Issuer:
- Legislative Council of the HKSAR; enforced by the Hong Kong Police Force; law reform review by the Law Reform Commission and the Department of Justice
- Last verified:
- 1 October 2026
- Official sources:
- LCQ2: Combating use of AI technology to create indecent images (28 January 2026), LCQ11: Regulating use of AI-generated synthetic content (15 July 2026), 2026 Policy Address, paragraph 123(i), PCPD: Abuse of AI Deepfakes, Toolkit for Schools and Parents (2025, PDF; cites ss.159AA and 159AAE), Crimes Ordinance, Cap. 200 (Hong Kong e-Legislation)
- Hong KongProposedLaw
Copyright TDM exception (proposed)
Proposed text and data mining exception for AI under the Copyright Ordinance
In 2025 the Government proposed a new copyright exception allowing copies of works to be made for computational data analysis, including AI model training, for commercial and non-commercial use, subject to conditions and an opt-out for rights holders. The bill was not introduced, and reports in September 2026 say the Government will first issue operational guidelines. The exception is not law.
- Issuer:
- Commerce and Economic Development Bureau (CEDB) and Intellectual Property Department (IPD)
- Last verified:
- 1 October 2026
- Hong KongIn forceLaw
Critical infrastructure cybersecurity law
Protection of Critical Infrastructures (Computer Systems) Ordinance
Hong Kong's cybersecurity law for critical infrastructure has been in force since 1 January 2026. Operators designated by the Commissioner must keep a security management unit, run risk assessments and audits, have an emergency response plan and report security incidents within tight deadlines. It is not AI-specific, but it covers AI systems that form part of designated critical computer systems.
- Issuer:
- Security Bureau; enforced by the Commissioner of Critical Infrastructure (Computer-system Security), with the HKMA and the Communications Authority as designated authorities for their sectors
- Last verified:
- 1 October 2026
- Official sources:
- Government press release: Ordinance to come into effect on 1 January 2026 (27 June 2025), Government press release: Appointment of Commissioner (1 January 2026), Communications Authority: PCICSO overview (obligations and Code of Practice), Office of the Commissioner of Critical Infrastructure (Computer-system Security): press releases, Cap. 653 (Hong Kong e-Legislation)
- Mainland ChinaIn forceLawHigh relevance
Cybersecurity Law (CSL) amendment
Cybersecurity Law of the People's Republic of China (as amended on 28 October 2025)
The first major revision of the 2017 Cybersecurity Law adds Mainland China's first statutory article on AI (new Art. 20), under which the state supports AI research, training data and computing infrastructure, improves AI ethics norms and strengthens AI risk monitoring, assessment and safety supervision. The amendment raises fines substantially, adds personal liability for managers, links personal information duties to the Civil Code and the PIPL, and widens liability for overseas conduct that endangers Mainland cybersecurity.
- Issuer:
- Standing Committee of the National People's Congress; enforced mainly by the Cyberspace Administration of China and public security authorities
- Last verified:
- 1 October 2026
- Mainland ChinaIn forceMeasuresHigh relevance
GBA Standard Contract
Implementation Guidelines on the Standard Contract for the Cross-boundary Flow of Personal Information Within the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland, Hong Kong)
The GBA Standard Contract is a simplified, voluntary route for moving personal information in either direction between the nine Mainland GBA cities and Hong Kong. Parties sign a fixed template, carry out a simplified impact assessment and file within 10 working days, and the national volume thresholds do not apply. Data moved under it must stay within the Greater Bay Area.
- Issuer:
- Cyberspace Administration of China and Innovation, Technology and Industry Bureau of the HKSAR Government; filings handled by the Cyberspace Administration of Guangdong Province and the Digital Policy Office (DPO)
- Last verified:
- 1 October 2026
- Official sources:
- Facilitation measure page (Digital Policy Office), Implementation Guidelines, English translation (DPO, PDF), Extension to all sectors from 1 November 2024 (HKSAR Government press release), Data export Q&A, January 2026 (CAC), Implementation Guidelines, Chinese text (MOFCOM legal database)
- Mainland ChinaIn forceMeasuresHigh relevance
Generative AI Measures
Interim Measures for the Management of Generative Artificial Intelligence Services
The Measures govern generative AI services that produce text, images, audio, video and other content for the public in Mainland China. Providers must keep content lawful, use lawfully sourced training data, protect personal information, label generated content and, where a service has public opinion attributes or social mobilisation capacity, pass a security assessment and complete an algorithm filing before launch. By 31 August 2026, 1,112 generative AI services had been filed with the CAC and 731 applications built on filed models had been registered locally.
- Issuer:
- Cyberspace Administration of China (CAC) with the National Development and Reform Commission, Ministry of Education, Ministry of Science and Technology, Ministry of Industry and Information Technology, Ministry of Public Security and National Radio and Television Administration
- Last verified:
- 1 October 2026
- Official sources:
- Interim Measures, official text (CAC), Generative AI filing announcement, July to August 2026 (CAC, 14 Sep 2026), Filing announcement for on-device generative AI services on mobile phones (CAC, 15 Jul 2026), GB/T 45654-2025 Basic security requirements for generative AI services (SAMR national standards portal), AI Safety Governance Framework 3.0 released (CAC, 14 Sep 2026)
- Mainland ChinaIn forceMeasuresHigh relevance
AI Content Labelling Measures (with GB 45438-2025)
Measures for Labelling Artificial Intelligence-Generated and Synthetic Content
Since 1 September 2025, AI-generated and synthetic text, images, audio, video and virtual scenes distributed through internet services in Mainland China must carry an implicit label in the file metadata and, where the content could confuse or mislead the public, a visible label as well. Platforms that distribute content must check for labels and add notices, and nobody may remove or forge them. The technical method is fixed by the mandatory national standard GB 45438-2025.
- Issuer:
- Cyberspace Administration of China, Ministry of Industry and Information Technology, Ministry of Public Security and National Radio and Television Administration; standard issued by the State Administration for Market Regulation and the Standardization Administration of China
- Last verified:
- 1 October 2026
- Mainland ChinaIn forceLawHigh relevance
PIPL
Personal Information Protection Law of the People's Republic of China
The PIPL is Mainland China's comprehensive personal information law. It requires a legal basis (often consent, and separate consent for sensitive data and transfers abroad), transparency, impact assessments and security measures, and it gives individuals rights including the right to refuse decisions made solely by automated means. It reaches organisations outside the Mainland that target Mainland individuals, and enforcement intensified in 2026.
- Issuer:
- Standing Committee of the National People's Congress; implementing rules and enforcement led by the Cyberspace Administration of China
- Next key date:
- 31 January 2027. Annual deadline to report the 2026 compliance audit on minors' personal information.
- Last verified:
- 1 October 2026
- Official sources:
- PIPL, official text (CAC), Compliance Audit Measures (CAC), 2026 personal information protection campaigns: stage results (CAC, 19 Aug 2026), Draft Provisions on Personal Information Protection by Large Processors, consultation (CAC, 7 Aug 2026), Mainland PIPL information page (PCPD Hong Kong)
- Mainland ChinaIn forceRegulationHigh relevance
Cross-border data rules
Provisions on Promoting and Regulating Cross-Border Data Flows (with the standard contract, certification and security assessment regimes)
Data leaving Mainland China, including to Hong Kong, must go through one of three routes depending on volume and sensitivity: a CAC security assessment, a filed standard contract, or certification, which has had its own measures since 1 January 2026. The 2024 Provisions created broad exemptions, for example for small volumes, contract performance and cross-border HR management, and let free trade zones publish negative lists outside which data can flow freely.
- Issuer:
- Cyberspace Administration of China (with the State Administration for Market Regulation for certification); provincial cyberspace authorities handle filings
- Last verified:
- 1 October 2026
- Mainland ChinaProposedLaw
Proposed AI Law
Comprehensive legislation on the healthy development of artificial intelligence (proposed national AI law)
Mainland China has no comprehensive AI law, and no official draft had been published as at 1 October 2026. The State Council's 2026 legislative plan commits to accelerate comprehensive legislation for the healthy development of AI and to complete rules on data, computing power, algorithms, intellectual property, cybersecurity, supply chain security and key application scenarios. The NPC Standing Committee lists AI legislation as a preparatory project still being researched and drafted.
- Issuer:
- State Council; Standing Committee of the National People's Congress
- Last verified:
- 1 October 2026
- Mainland ChinaIn forceLaw
Export controls (rare earths, batteries, technology)
Export Control Law of the People's Republic of China and related controls on rare earths, lithium batteries and technologies
Mainland China requires export licences for listed dual-use items and restricted technologies. Licences have been required since April 2025 for seven medium and heavy rare earths and related magnet materials, while a wider October 2025 package covering rare earth technologies, foreign-made products with Chinese rare earth content, lithium batteries and graphite anodes is suspended only until 10 November 2026. Certain lithium battery cathode technologies became restricted technology exports in July 2025.
- Issuer:
- Standing Committee of the National People's Congress; State Council; Ministry of Commerce (MOFCOM); General Administration of Customs (GAC); Ministry of Science and Technology
- Next key date:
- 10 November 2026. The suspension ends unless extended, and the October 2025 controls, including the extraterritorial rare earth rule, would then apply.
- Last verified:
- 1 October 2026
- Mainland ChinaIn forceMeasures
Anthropomorphic AI (AI Companion) Measures
Interim Measures for the Administration of Anthropomorphic Artificial Intelligence Interaction Services
These are Mainland China's first rules for AI companions and other services that simulate human personality and hold sustained emotional interaction with users. Providers must make clear that users are talking to AI, remind users after two hours of continuous use, avoid fostering emotional dependence, respond to signs of distress and protect minors and the elderly. Ordinary customer service bots, knowledge assistants and work tools without sustained emotional interaction are excluded.
- Issuer:
- Cyberspace Administration of China with the National Development and Reform Commission, Ministry of Industry and Information Technology, Ministry of Public Security and State Administration for Market Regulation
- Last verified:
- 1 October 2026
- Official sources:
- Interim Measures, official text (CAC), Draft for consultation (CAC, 27 Dec 2025)
- Mainland ChinaIn forceMeasures
AI Ethics Review Measures
Measures for the Ethical Review and Services of Artificial Intelligence Science and Technology (Trial)
These AI-specific rules require universities, research institutes, medical institutions and enterprises engaged in AI science and technology activities in Mainland China to run ethics reviews, normally through their own AI ethics committee or an AI ethics review and service centre. Three categories of high-risk AI activity need an additional expert review by the authorities. They refine the general 2023 science and technology ethics review regime.
- Issuer:
- Ministry of Industry and Information Technology with the NDRC, Ministry of Education, Ministry of Science and Technology, Ministry of Agriculture and Rural Affairs, National Health Commission, People's Bank of China, Cyberspace Administration of China, Chinese Academy of Sciences and China Association for Science and Technology
- Last verified:
- 1 October 2026
- Mainland ChinaGuidancePolicy
AI Plus Action Plan
Opinions of the State Council on Deepening the Implementation of the 'AI Plus' Action
The AI Plus Opinions are Mainland China's national plan to embed AI across science, industry, consumption, public services and governance, targeting adoption rates of more than 70% for new intelligent terminals and AI agents by 2027 and more than 90% by 2030. The AI Plus Manufacturing opinions set 2027 goals including 3 to 5 general-purpose models deeply applied in manufacturing, 100 high-quality industrial datasets and 500 typical application scenarios. The May 2026 AI agent opinions add safety principles and 19 typical application scenarios for agents.
- Issuer:
- State Council; MIIT with seven other authorities (AI Plus Manufacturing); CAC, NDRC and MIIT (AI agents)
- Last verified:
- 1 October 2026
- Mainland ChinaIn forceRegulation
Algorithm Recommendation Provisions
Provisions on the Administration of Algorithmic Recommendation of Internet Information Services
The Provisions cover apps and platforms in Mainland China that use algorithms to generate content, personalise feeds, rank, filter search results or dispatch work. Providers must be transparent, let users switch off personalised recommendation, avoid unreasonable differential pricing and protect workers, minors and the elderly; services with public opinion attributes must file their algorithms with the CAC. A broader State Council regulation with an AI section is in draft.
- Issuer:
- Cyberspace Administration of China, Ministry of Industry and Information Technology, Ministry of Public Security and State Administration for Market Regulation
- Last verified:
- 1 October 2026
- Mainland ChinaIn forceRegulation
Deep Synthesis Provisions
Provisions on the Administration of Deep Synthesis of Internet Information Services
The Provisions regulate services in Mainland China that use deep synthesis technology, including deepfakes, to generate or edit text, voice, images, video and virtual scenes. Providers must obtain separate consent before editing a person's face or voice, label content that could mislead, verify user identities and file algorithms that have public opinion attributes. They continue to apply alongside the generative AI and labelling measures.
- Issuer:
- Cyberspace Administration of China, Ministry of Industry and Information Technology and Ministry of Public Security
- Last verified:
- 1 October 2026
- Official sources:
- Deep Synthesis Provisions, official text (CAC)
- Mainland ChinaIn forceRegulation
Network Data Regulations / Data Security Law
Regulations on Network Data Security Management (implementing the Data Security Law)
The Data Security Law sets up data classification, special protection for 'important data' and 'core data', and controls on exporting important data. The 2025 Regulations turn this into detailed duties for anyone processing network data in Mainland China, including annual risk assessments for important data, rules for personal information and platforms, and a specific duty for generative AI providers to secure training data (Art. 19).
- Issuer:
- State Council (Regulations); Standing Committee of the National People's Congress (Data Security Law); enforcement led by the Cyberspace Administration of China and sector regulators
- Last verified:
- 1 October 2026
- European UnionAdopted, not yet applicableLawHigh relevance
New Product Liability Directive (PLD)
Directive (EU) 2024/2853 on liability for defective products
The new Product Liability Directive makes it easier for people in the EU to claim compensation for damage caused by defective products, and it expressly treats software, including AI systems, as a product. It covers defects arising from updates, machine learning and missing security updates, and it eases the burden of proof for claimants in technically complex cases. Member States must transpose it by 9 December 2026, and it applies to products placed on the market after that date.
- Issuer:
- European Parliament and Council of the European Union
- Next key date:
- 9 December 2026. Transposition deadline for Member States; new liability rules apply to products placed on the market or put into service after this date.
- Last verified:
- 1 October 2026
- European UnionIn forceRegulationHigh relevance
GDPR (AI development and use)
Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), as applied to AI
The GDPR governs any processing of personal data, including when personal data are used to train, fine-tune or run AI systems. It reaches companies outside the EU that offer goods or services to people in the EU or monitor their behaviour. EDPB Opinion 28/2024 explains when an AI model trained on personal data can be considered anonymous, how legitimate interest can serve as a legal basis, and what follows when a model was trained on unlawfully processed data.
- Issuer:
- European Parliament and Council (Regulation); European Data Protection Board (opinions and guidelines)
- Next key date:
- 30 October 2026. Public consultation on the EDPB anonymisation and web-scraping guidelines closes.
- Last verified:
- 1 October 2026
- Official sources:
- Regulation (EU) 2016/679, official text (EUR-Lex), EDPB Opinion 28/2024 on AI models (PDF), EDPB opinion on AI models: GDPR principles support responsible AI (EDPB news), EDPB sheds light on anonymisation and web scraping for generative AI, 8 July 2026 (EDPB news), Guidelines 03/2026 on web scraping in the context of generative AI, public consultation (EDPB)
- European UnionPhasing inRegulationHigh relevance
Data Act
Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)
The Data Act gives users of connected products, such as smart appliances, wearables and industrial equipment, the right to access the data their use generates and to share it with third parties such as repairers. Manufacturers must design products placed on the EU market after 12 September 2026 so that this data is accessible, directly where relevant and technically feasible. It also sets fair-contract rules for data sharing and makes it easier for customers to switch cloud providers.
- Issuer:
- European Parliament and Council of the European Union
- Next key date:
- 12 January 2027. Providers of cloud and other data processing services may no longer charge switching fees.
- Last verified:
- 1 October 2026
- European UnionPhasing inRegulationHigh relevance
EU AI Act
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
The EU AI Act regulates AI according to risk: some practices are banned, high-risk systems must meet strict requirements before they are sold, and chatbots and generative AI carry transparency duties. It applies to companies outside the EU that place AI on the EU market or whose AI output is used in the EU. The Digital Omnibus on AI, in force since 27 July 2026, moved the high-risk dates to December 2027 and August 2028 and added two new bans that apply from 2 December 2026.
- Issuer:
- European Parliament and Council of the European Union
- Next key date:
- 2 December 2026. New bans on AI that generates non-consensual intimate imagery or child sexual abuse material apply; generative AI systems placed on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking duty.
- Last verified:
- 1 October 2026
- Official sources:
- Regulation (EU) 2024/1689, official text (EUR-Lex), Regulation (EU) 2026/1744, Digital Omnibus on AI (EUR-Lex), AI Act implementation timeline, updated for the Digital Omnibus (European Commission, AI Act Service Desk), AI Act policy page (European Commission), Commission publishes Code of Practice on marking and labelling AI-generated content, 10 June 2026, AI literacy questions and answers (European Commission)
- European UnionPhasing inRegulationHigh relevance
Cyber Resilience Act (CRA) and RED cybersecurity rules
Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act), together with the cybersecurity requirements under the Radio Equipment Directive (Commission Delegated Regulation (EU) 2022/30)
The Cyber Resilience Act sets mandatory cybersecurity requirements for hardware and software products sold in the EU that connect to a device or network, covering design, production and a support period of usually at least five years. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents, starting with an early warning within 24 hours. The full requirements, including CE marking for cybersecurity, apply from 11 December 2027. Until then, wireless products must meet the Radio Equipment Directive cybersecurity requirements that have applied since 1 August 2025.
- Issuer:
- European Parliament and Council (CRA); European Commission (delegated regulations)
- Next key date:
- 11 December 2027. The CRA applies in full (essential cybersecurity requirements, conformity assessment, CE marking), and the RED cybersecurity Delegated Regulation (EU) 2022/30 is repealed.
- Last verified:
- 1 October 2026
- Official sources:
- Regulation (EU) 2024/2847, official text (EUR-Lex), Cyber Resilience Act policy page (European Commission), Cyber Resilience Act: summary of the legislative text (European Commission), Cyber Resilience Act: reporting obligations (European Commission), CRA Single Reporting Platform: frequently asked questions (ENISA), The CRA Single Reporting Platform is launched (ENISA), Commission Delegated Regulation (EU) 2022/30, RED cybersecurity (EUR-Lex), Commission Delegated Regulation (EU) 2026/339 repealing Delegated Regulation (EU) 2022/30 (EUR-Lex)
- European UnionIn forceRegulation
GPAI model obligations and Code of Practice
Obligations for providers of general-purpose AI models under Chapter V of Regulation (EU) 2024/1689, and the General-Purpose AI Code of Practice
Companies that develop general-purpose AI models, such as large language models, and place them on the EU market must document the model, give downstream developers the information they need, adopt a copyright policy and publish a summary of the content used for training. The most capable models, presumed to carry systemic risk, face additional safety and security duties. The obligations have applied since 2 August 2025, and the Commission has been able to fine providers since 2 August 2026.
- Issuer:
- European Parliament and Council (Regulation); European Commission AI Office (Code of Practice and guidelines)
- Next key date:
- 2 August 2027. General-purpose AI models placed on the market before 2 August 2025 must comply.
- Last verified:
- 1 October 2026
- European UnionProposedRegulation
Digital Omnibus (data, privacy and cyber) proposal
Proposal for a Regulation on the simplification of the digital legislative framework (Digital Omnibus), amending among others the GDPR, the ePrivacy Directive and the Data Act
Separate from the Digital Omnibus on AI, which is already law, the Commission's broader Digital Omnibus proposal would amend the GDPR, the ePrivacy cookie rules and the Data Act, and create a single entry point for incident reporting. Among other things, it would confirm that personal data can be processed on the basis of legitimate interest to develop and operate AI models, subject to safeguards. As of 1 October 2026 it is a proposal under committee examination in the European Parliament and is not law.
- Issuer:
- European Commission (proposal); European Parliament and Council (co-legislators)
- Last verified:
- 1 October 2026
- European UnionAdopted, not yet applicableRegulation
Machinery Regulation
Regulation (EU) 2023/1230 on machinery
From 20 January 2027 the Machinery Regulation replaces the Machinery Directive as the legal basis for selling machinery in the EU, with no transition period. It adds requirements for AI-driven and self-learning safety functions, protection of control systems against corruption (including malicious attacks), and allows digital instructions. Machinery whose safety functions rely on machine learning that keeps evolving must undergo third-party conformity assessment by a notified body.
- Issuer:
- European Parliament and Council of the European Union
- Next key date:
- 20 January 2027. The Machinery Regulation applies and the Machinery Directive 2006/42/EC is repealed, with no transition period.
- Last verified:
- 1 October 2026
- European UnionIn forceRegulation
General Product Safety Regulation (GPSR)
Regulation (EU) 2023/988 on general product safety
The GPSR is the EU's safety net for consumer products, applying where more specific EU rules do not cover a risk. It requires safety assessments to consider a product's cybersecurity and its evolving, learning and predictive functionalities, which brings AI features in consumer products into scope. A consumer product can only be sold in the EU if an economic operator established in the EU is responsible for it.
- Issuer:
- European Parliament and Council of the European Union
- Next key date:
- 1 August 2030. Related sector rule: the new Toy Safety Regulation (EU) 2025/2509 applies, including rules for connected and AI-enabled toys.
- Last verified:
- 1 October 2026
- United StatesPhasing inLawHigh relevance
California AI Transparency Act (content provenance)
California AI Transparency Act (SB 942 of 2024, as amended by AB 853 of 2025 and SB 1000 and AB 2713 of 2026)
California requires providers of generative AI systems to embed hidden, machine-readable disclosures in AI-generated images, video and audio and to offer a free tool to check them. From 2027, large online platforms must read and display this provenance data, and from 2028 makers of cameras, phones and recorders sold in California must offer, and by default embed, provenance data in captured content. A September 2026 amendment extended the provider duties to all publicly accessible GenAI systems regardless of size.
- Issuer:
- California Legislature; enforced by the California Attorney General, city attorneys and county counsel
- Next key date:
- 1 January 2027. Duties for large online platforms and GenAI hosting platforms begin (detect and display provenance data).
- Last verified:
- 1 October 2026
- United StatesIn forceRegulationHigh relevance
DOJ bulk sensitive data rule (Data Security Program)
Data Security Program: Preventing Access to US Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons
This rule bars or restricts US companies from giving 'countries of concern', which include China with Hong Kong and Macau, and 'covered persons' access to bulk US sensitive personal data or US government-related data. Data brokerage to these parties is prohibited, while vendor, employment and investment arrangements are allowed only if strict US security requirements are met. Hong Kong companies are not regulated directly but are treated as covered persons, so US customers and partners must restrict what data they share with them.
- Issuer:
- US Department of Justice, National Security Division
- Next key date:
- 1 March 2027. Annual reports are due for restricted cloud-computing transactions with 25% or more country-of-concern or covered-person ownership, covering calendar year 2026.
- Last verified:
- 1 October 2026
- United StatesIn forceRegulationHigh relevance
EAR AI chip export controls
Export Administration Regulations: advanced computing and AI chip controls, Entity List and Affiliates Rule (China, including Hong Kong)
The EAR control exports, re-exports and in-country transfers of US-origin items and certain foreign-made items that rely on US technology. Since December 2020, Hong Kong has been treated in the same way as Mainland China, so the strict licence requirements for advanced AI chips, AI servers and semiconductor manufacturing items destined for China apply equally to Hong Kong. The Entity List names many Mainland and Hong Kong companies, and a rule extending these restrictions to companies majority-owned by listed parties is due to return on 10 November 2026.
- Issuer:
- US Department of Commerce, Bureau of Industry and Security (BIS)
- Next key date:
- 10 November 2026. The Affiliates Rule returns automatically unless BIS extends the suspension.
- Last verified:
- 1 October 2026
- Official sources:
- Federal Register: Removal of Hong Kong as a Separate Destination under the EAR (2020), Federal Register: Revision to License Review Policy for Advanced Computing Commodities (15 Jan 2026), BIS press release: revised licence review policy for semiconductors exported to China (Jan 2026), Federal Register: One-Year Suspension of the Affiliates Rule (12 Nov 2025), BIS press release: rescission of the AI Diffusion Rule and new guidance (13 May 2025), Proclamation 11002 on semiconductor imports (Section 232), 14 Jan 2026
- United StatesIn forceRegulationHigh relevance
US outbound investment rules (OISP / COINS Act)
Outbound Investment Security Program (31 CFR Part 850) and the Comprehensive Outbound Investment National Security Act of 2025 (COINS Act)
US persons are prohibited from, or must notify Treasury of, certain investments in companies from 'countries of concern' (currently China, including Hong Kong and Macau) that work on semiconductors, quantum technologies or AI. For AI, the rules turn on the computing power used to train a model and on its intended end uses. The COINS Act of December 2025 puts the programme on a statutory footing and will add high-performance computing and more countries once Treasury writes new rules.
- Issuer:
- US Department of the Treasury, Office of Investment Security (Office of Global Transactions)
- Next key date:
- 13 March 2027. Statutory deadline (450 days after enactment) for Treasury to issue regulations implementing the COINS Act; the existing rules apply until then.
- Last verified:
- 1 October 2026
- United StatesPhasing inRegulation
CCPA ADMT regulations
California Consumer Privacy Act regulations on automated decision-making technology, risk assessments and cybersecurity audits
California's privacy regulator has adopted rules giving consumers, including job applicants and employees, rights over automated decision-making technology used to make significant decisions about them. Businesses must give a pre-use notice, offer an opt-out or appeal, and explain the logic and outcome on request from 1 January 2027. The same package requires risk assessments for high-risk processing and annual cybersecurity audits for larger or data-intensive businesses.
- Issuer:
- California Privacy Protection Agency (CalPrivacy)
- Next key date:
- 1 January 2027. Businesses already using ADMT for significant decisions must comply with the ADMT rules (pre-use notice, opt-out, access).
- Last verified:
- 1 October 2026
- United StatesPhasing inLaw
California GenAI developer and chatbot laws
California laws on generative AI developers and chatbots: Transparency in Frontier AI Act (SB 53), training data transparency (AB 2013), companion chatbots (SB 243 and SB 1119), ban on companion chatbots in toys (SB 867) and customer service chatbots (AB 1609)
California has adopted several laws aimed at generative AI developers and chatbot operators. Large frontier model developers must publish safety frameworks and report critical incidents (SB 53); developers of public generative AI must publish training data summaries (AB 2013); companion chatbot operators must disclose that users are talking to AI and maintain self-harm protocols (SB 243, strengthened by SB 1119). From 2027, toys for children under 16 that include a companion chatbot may not be made, sold or offered to retailers in California (SB 867).
- Issuer:
- California Legislature; California Attorney General; California Office of Emergency Services
- Next key date:
- 1 January 2027. The SB 867 ban on toys that contain companion chatbots takes effect.
- Last verified:
- 1 October 2026
- Official sources:
- California Legislative Information: SB 53 (Transparency in Frontier AI Act), California Legislative Information: SB 243 (companion chatbots), California Legislative Information: SB 867 (toys and companion chatbots), California Legislative Information: SB 1119 status, California Legislative Information: AB 1609 status
- United StatesAdopted, not yet applicableLaw
Colorado ADMT law (formerly Colorado AI Act)
Colorado Senate Bill 26-189: Use of Automated Decision-Making Technology in Consequential Decisions (repealing and replacing the Colorado Artificial Intelligence Act, SB 24-205)
Colorado's 2024 AI Act, the first broad US state law on high-risk AI, was repealed before it took effect. Its replacement, SB 26-189, applies from 1 January 2027 and focuses on transparency for automated decision-making technology used in consequential decisions such as hiring, lending, housing, insurance, healthcare and education. It drops the original duty of care, impact assessments and algorithmic discrimination reporting.
- Issuer:
- Colorado General Assembly; enforced by the Colorado Attorney General
- Next key date:
- 1 January 2027. SB 26-189 takes effect, and the Attorney General's rules are due by this date.
- Last verified:
- 1 October 2026
- United StatesIn forceExecutive order
US federal AI policy and state-law preemption push
Federal AI policy framework: Executive Orders 14179, 14365 and 14409, America's AI Action Plan and OMB AI memoranda M-25-21, M-25-22 and M-26-04
The United States has no comprehensive federal AI statute. Since January 2025, federal AI policy has been set by executive orders and OMB memoranda that prioritise AI development and adoption, steer federal agencies towards American-made AI, and seek to challenge or preempt state AI laws regarded as burdensome. These instruments bind federal agencies rather than private companies, but they shape government procurement, federal enforcement priorities and the future of state AI laws.
- Issuer:
- The White House (Executive Office of the President); Office of Management and Budget; Department of Justice AI Litigation Task Force
- Last verified:
- 1 October 2026
- Official sources:
- Federal Register: EO 14179 Removing Barriers to American Leadership in AI, Federal Register: EO 14365 Ensuring a National Policy Framework for AI, Federal Register: EO 14409 Promoting Advanced AI Innovation and Security, Federal Register: EO 14319 Preventing Woke AI in the Federal Government, Federal Register: EO 14320 Promoting the Export of the American AI Technology Stack, White House: America's AI Action Plan (PDF), OMB memoranda index (M-25-21, M-25-22, M-26-04), OMB M-25-22 Driving Efficient Acquisition of AI in Government (PDF), OMB M-26-04 Unbiased AI Principles (PDF)
- United StatesIn forceEnforcement practice
FTC AI enforcement (Section 5)
Federal Trade Commission Act, Section 5: enforcement against unfair or deceptive AI practices
Section 5 of the FTC Act prohibits unfair or deceptive practices and is the main federal tool against misleading AI claims. The current Commission has stepped back from cases based on the theory that an AI tool could be misused, but continues to pursue false or unsubstantiated claims about what AI products can do, deceptive AI-based earnings schemes and privacy breaches. A proposed policy statement would treat undisclosed steering of AI outputs as deception.
- Issuer:
- US Federal Trade Commission
- Last verified:
- 1 October 2026
- United StatesGuidanceStandard
NIST AI RMF
NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) and Generative AI Profile
The NIST AI Risk Management Framework is a voluntary framework for managing AI risks across four functions: Govern, Map, Measure and Manage. The Generative AI Profile applies it to risks specific to generative AI. It is not law, but US enterprise customers and public bodies often ask suppliers to show alignment with it, and Texas law treats substantial compliance as a defence.
- Issuer:
- US Department of Commerce, National Institute of Standards and Technology (NIST)
- Last verified:
- 1 October 2026
- United StatesPhasing inRegulation
Connected vehicles rule (ICTS)
Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles (final rule)
This rule bans the import and sale in the US of passenger vehicles that use connectivity or automated-driving software linked to China or Russia from Model Year 2027, and bans imports of linked connectivity hardware from Model Year 2030. The definition of China expressly includes Hong Kong and Macau. Vehicle makers and hardware importers must file annual declarations of conformity backed by supply-chain due diligence.
- Issuer:
- US Department of Commerce, Bureau of Industry and Security, Office of Information and Communications Technology and Services (OICTS)
- Next key date:
- 1 January 2029. The ban on importing vehicle connectivity system (VCS) hardware with a China or Russia nexus starts to apply to components without a model year (Model Year 2030 for others).
- Last verified:
- 1 October 2026
- United StatesPhasing inLaw
US AI-in-hiring laws
State and city rules on AI in hiring and employment: Illinois HB 3773, New York City Local Law 144, California Civil Rights Council automated-decision system regulations and California SB 947
There is no federal AI hiring law, but several states and New York City regulate the use of AI in employment decisions. New York City requires annual independent bias audits and advance notice for automated hiring tools. Illinois bans AI use that has a discriminatory effect and requires notice to workers. California treats discriminatory automated-decision systems as unlawful and, from July 2027, bars employers from relying solely on AI to discipline or dismiss staff. Colorado's ADMT law and California's CCPA ADMT rules also cover employment decisions.
- Issuer:
- Illinois General Assembly and Department of Human Rights; New York City Department of Consumer and Worker Protection; California Civil Rights Council; California Legislature and Labor Commissioner
- Next key date:
- 1 July 2027. California SB 947 becomes operative.
- Last verified:
- 1 October 2026
- United StatesIn forceLaw
Texas TRAIGA
Texas Responsible Artificial Intelligence Governance Act (HB 149)
Texas has a broad AI law that applies to anyone doing business in Texas or offering AI products used by Texas residents. For private companies it mainly bans developing or deploying AI with the intent to manipulate people into self-harm, harm or crime, to infringe constitutional rights, to discriminate unlawfully, or to produce child sexual abuse material or sexual deepfakes. Government bodies face additional disclosure and social-scoring rules, and healthcare providers must disclose AI use in treatment.
- Issuer:
- Texas Legislature; enforced by the Texas Attorney General
- Last verified:
- 1 October 2026
- United StatesIn forceLaw
TAKE IT DOWN Act
Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act)
The Act makes it a federal crime to knowingly publish non-consensual intimate images, including AI-generated 'digital forgeries'. Since 19 May 2026, online platforms that host user-generated content must offer a clear process for victims to request removal and must take the content and known identical copies down within 48 hours of a valid request. The FTC enforces the platform duties.
- Issuer:
- US Congress; Federal Trade Commission (platform duties); Department of Justice (criminal offences)
- Last verified:
- 1 October 2026
- InternationalGuidanceStandard
ISO/IEC 42001 (AI management system)
ISO/IEC 42001:2023 Information technology, Artificial intelligence, Management system
ISO/IEC 42001 is the international standard for an AI management system: a certifiable framework of policies, risk and impact assessments, controls and continual improvement for organisations that develop, provide or use AI. It is voluntary, but customers and investors increasingly ask for it as evidence of responsible AI governance. It is not a harmonised standard under the EU AI Act, so certification does not by itself create a presumption of conformity.
- Issuer:
- International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), ISO/IEC JTC 1/SC 42
- Last verified:
- 1 October 2026
Need help with AI compliance?
Several HKAIIA member companies work on AI governance, legal and compliance. Members can find them through member matchmaking and ask the secretariat for an introduction.