Regulation of artificial intelligence is being developed at multiple levels, including international treaties, United Nations work, G7 commitments, and national laws. These frameworks involve different actors and responsibilities, with some allowing for the sanctioning of companies and others organizing research, cooperation, or the publication of information. As of October 5, 2026, a model can be developed in one country, hosted in another, and used on the other side of the world. This circulation gives international initiatives particular importance. The challenge remains to distinguish between a political agreement, a legally binding treaty, a technical standard, and an effectively applicable law. Sectoral regulations on personal data, health, finance, or product safety continue to apply according to usage. The absence of a general AI law does not mean the absence of rules.
At the international level, the Council of Europe has a convention on AI, human rights, democracy, and the rule of law, open for signature since September 2024. It is intended to create legal obligations for its parties, including non-European states, but has not yet entered into force as of October 5, 2026. The European Union ratified it in May 2026. The treaty requires five ratifications, including three from Council of Europe member states, followed by the expiration of the scheduled period. Its scope excludes national defense and leaves room for choice for states regarding the processing of private actors other than those acting for a public authority.
At the United Nations, the Global Digital Compact of September 2024 led to the creation in August 2025 of the independent international scientific panel and the Global Dialogue on AI Governance. These frameworks provide a common expertise and a discussion venue but do not have the power to sanction developers. The first Dialogue was held in Geneva on July 6 and 7, 2026. A recent initiative aims to go further. On September 21, 2026, Finland and Norway launched a call for the control of advanced models, supported notably by France, Germany, Canada, and Singapore. The signatories demand mandatory tests before deployment, independent evaluations, and the study of an international institution. At this stage, these measures are political requests; the call does not make them mandatory.
The UNESCO Recommendation, adopted in 2021, is a non-binding recommendation on ethical principles, human rights, and human supervision. The OECD Principles, adopted in 2019 and revised in 2024, serve as a reference for national policies and organizational practices. A 2026 due diligence guide specifies risk management but does not directly enforce regulations against companies. The Global Partnership on AI, GPAI/OCDE, involves participating countries and an expert network, focusing on cooperation and practical projects without the power to sanction companies.
The Hiroshima Process of the G7 includes participating companies and OECD monitoring, with a voluntary code of conduct adopted in 2023. A simplified declaration framework was introduced in May 2026, with company reports accessible but not verified by the OECD. Participation does not equate to certification. The Bletchley, Seoul, Paris, and New Delhi Summits involve states and organizations, with political declarations and cooperation on safety, access to AI, and its development. New Delhi plans to share tools and methods via the Trusted AI Commons.
The Seoul Safety Commitments, taken in May 2024, involve developers of advanced models with voluntary commitments on evaluations, risk thresholds, and publication of safety frameworks. The Finland-Norway Appeal, a political appeal of September 21, 2026, demands independent evaluations, cooperation on serious incidents, and examination of an international institution. The requested mechanisms are not established by the appeal itself.
The International Network for Measurement and Evaluation of Advanced AI (NAAIMES) involves public evaluation organizations, including those of France, the United States, and the United Kingdom, focusing on operational technical cooperation. The World Association for AI Cooperation (WAICO), signed in Shanghai on July 16, 2026, is a new international cooperation organization on AI with headquarters planned in Shanghai. The signing of its constitutive agreement does not equate to the adoption of a globally applicable regulation for developers.
ASEAN member states have voluntary guides on AI, with a 2024 guide and a 2025 guide for generative AI. The guide specifies that it does not modify obligations derived from national laws. The African Union has a continental strategy adopted in July 2024 and an AI for Africa initiative launched in 2025, focusing on governance and support for national policies. The ISO/IEC 42001 standard, published in 2023, is a voluntary standard for AI management systems, with certification possible by a third party but not guaranteeing the absence of risks in a model.
The work on autonomous weapons continues under the Convention on Certain Conventional Weapons (CCW), with the process still ongoing in 2026. International humanitarian law already applies, and the expert group works on the elements of an instrument without finalizing its nature. The REAIM initiative, a political declaration from February 2026, focuses on the responsible use of AI in the military domain, distinct from the CCW process.
These frameworks fulfill complementary functions but their juxtaposition leaves several questions open. An institute can test a model without being able to impose its modification. A code can request the publication of information without providing for its verification. A treaty can be adopted before sufficient states have accepted to be bound by its obligations. Governments also diverge on the authority they wish to delegate at the international level. In New Delhi, in February 2026, the U.S. administration explicitly defended national sovereignty and rejected centralized global AI governance. The creation of common forums does not mean an agreement on common mandatory rules.
The military scope highlights another separation. The Council of Europe convention excludes national defense, just as the AI Act excludes systems exclusively intended for military, defense, or national security purposes. Civil initiatives do not cover these uses on their own; these are subject to existing international law and specific discussions. The difficulty remains also scientific. The International AI Safety Report 2026 describes the limits of evaluations, the inequality of access to information, and coordination problems. The behavior of a system in test does not always allow prediction of its behavior once deployed. This limits what an evaluation can attest, regardless of the level at which it is organized.
National regulations can concern foreign suppliers. A national or regional regulation can have a scope beyond the place where the model is developed. The European AI Act targets suppliers who place their systems or models on the European market, even if they are established elsewhere. It also provides for certain cases where the results of a system developed or used from a third country are used in the Union. This scope gives European authorities means of action, without creating a universal competence over all AI uses.
In the European Union, several steps have already been taken: first prohibitions since February 2025, obligations concerning general-purpose AI models since August 2025, with transitional provisions, and transparency rules since August 2026. The European AI Office has had enforcement powers over models within its jurisdiction since August 2, 2026, including document requests, evaluations, and corrective measures. The AI Omnibus, which entered into force on July 27, 2026, postponed the application of rules for the uses in Annex III to December 2, 2027, and those for systems integrated into certain regulated products to August 2, 2028.
France has the AI Act, GDPR, and competent authorities, with the CNIL retaining its competence over personal data and the INESIA providing scientific evaluation capabilities. Italy's Law 132/2025, in force since October 10, 2025, complements the European AI Act with rules for health, work, administration, and justice. Spain's AESIA has existed since 2023, with an AI governance law project still in amendment phase at the Congress beginning October 2026.
The United Kingdom has existing law and sectoral regulation, with additional protections under study in September 2026. Switzerland is preparing a preliminary draft with consultation expected by the end of 2026. Russia's Law on support for AI technologies, adopted in July 2026, entered into force on September 1, 2026, with definitions, support measures for developers, and labeling of AI content.
The United States has existing law, decrees, and voluntary commitments. The June 2026 decree organizes voluntary evaluations before deployment of advanced models. The agreement of September 29 provides for controls and audits among its signatories but does not constitute a general federal law. California's SB 53 is applicable since January 2026 with additional provisions adopted in September. Colorado's law, adopted in May 2026, has obligations effective January 1, 2027. New York's RAISE Act, adopted in March 2026, is effective January 1, 2027. Texas's TRAIGA law is applicable since January 2026 with targeted prohibitions.
Canada's former AIDA project expired, with consultation on transparency closed September 23, 2026. Brazil's PL 2338/2023 is still under examination in the Chamber. Peru's Law 31814 and implementing decree have staggered obligations from 2026 to 2029. El Salvador's AI promotion law, adopted in 2025, includes the creation of the ANIA.
China has successive binding rules, including generative AI since 2023, labeling since 2025, and conversational companions since July 2026. South Korea's AI Basic Act, in force since January 22, 2026, includes a grace period for repressive application. Japan's AI promotion law is fully applicable since September 2025. Taiwan's AI Basic Act, in force since January 14, 2026, includes rule adaptation planned within two years. Vietnam's AI law, in force since March 1, 2026, includes a transition period. Kazakhstan's AI law, effective in 2026, includes classification, risk management, and prohibitions. India has guidelines and targeted rules. Singapore has existing laws and voluntary frameworks. Australia has existing law and a national plan. DIFC, Dubai, and the United Arab Emirates have Regulation 10, limited to the DIFC jurisdiction. Saudi Arabia's SDAIA framework includes ethical principles and risk management. South Africa retracted its national policy project in June 2026.
Global AI Regulation Frameworks and Their Implementation Challenges
AI-rewritten from original reportingHow it works
ai-regulationinternational-treatiesun-frameworksnational-lawsai-governance



