Practical AI and SaaS for Business

International AI Regulations Explained

If your business uses AI tools built in the EU, serves customers in the US, or processes data across borders, international AI regulation is relevant to you even if your business is based in Australia. This guide explains the four major international frameworks. The EU AI Act, the US approach, the UK framework, and Singapore's model. And what Australian businesses operating cross-border should monitor.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You sell software or services into more than one country, and it feels like a new AI rule lands every month: the EU AI Act, a US executive order, UK guidance. Working out which of these actually apply to your business, versus your AI vendor's problem to solve, eats time you don't have. In five minutes you'll know how each major framework treats a business like yours and what you actually need to act on. No legal background needed.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

AI regulation is no longer just a domestic question for any single jurisdiction. The major AI tools in widespread business use. ChatGPT, Claude, Gemini, Microsoft Copilot, and the dozens of AI-powered software tools built on top of them. Are developed, trained, and operated by companies subject to US and EU law. The AI tools your business uses today are already shaped by those regulatory frameworks, whether you are aware of it or not. And if your business serves customers in more than one country, handles data belonging to residents of multiple jurisdictions, or operates as a cross-border entity, the relevant regulatory picture spans several frameworks at once. This guide explains what the EU AI Act, the US approach, the UK framework, Singapore's Model AI Governance Framework, and Australia's regulatory position each say in plain terms, and what a business operating across any of these jurisdictions should monitor.

In short: This guide describes what the EU AI Act, US approach, UK framework, Singapore's model, and Australia's regulatory position each say, not your business's specific obligations under foreign law. The EU AI Act directly affects the AI tools you use no matter where your business is based, because it shapes what your vendors build. Direct compliance obligations for SMBs using off-the-shelf tools are limited in every covered jurisdiction; the heavier obligations fall primarily on AI providers and deployers placing systems on a given market. For cross-border or sector-specific obligations, seek legal advice for your specific circumstances.

Why International AI Regulation Matters

The most direct way international AI regulation affects any business, in any country, is through the vendors you use. When a vendor operating under the EU AI Act classifies a model as high-risk, or when a US executive order changes what AI companies must disclose, those regulatory responses reshape what those vendors build, how they design their products, and what contractual terms they offer. The EU AI Act has already influenced the terms of service, privacy policies, and feature availability of major AI platforms globally, in the same way that GDPR reshaped data handling practices for every global software vendor.

The second way international regulation matters is for businesses that operate across borders. If your business has customers in the EU, handles personal data of EU residents, or has any form of EU establishment, the EU AI Act's obligations for deployers and users of AI systems may apply to you. The same question applies to the US state-level AI laws that are emerging rapidly in California, Colorado, and other states, and to the UK's GDPR-based AI guidance if you have UK customers or data. Local privacy and AI frameworks and these international regulatory regimes are not competing alternatives; for a business with a genuinely cross-border footprint, several of them can apply at once.

The third reason to follow international developments is that domestic regulatory approaches are shaped by them, wherever you are. Australia's DISR Voluntary AI Safety Standard draws on the NIST AI Risk Management Framework; its Privacy Act amendments around automated decision-making reflect awareness of GDPR and EU AI Act obligations. Singapore's Model AI Governance Framework has influenced governance frameworks elsewhere in the Asia-Pacific region. Understanding the international landscape helps you anticipate where the rules in your own jurisdiction are likely to move next.

The EU AI Act

The EU AI Act is the world's first comprehensive binding legislation specifically regulating AI. It was adopted by the European Parliament in 2024 and entered into force in August 2024, with a phased application timeline running from 2025 to 2027. It applies to AI systems that are placed on the EU market or put into service in the EU, regardless of where the provider is based. A non-EU company that sells an AI product to EU businesses or consumers is subject to the Act for that product.

The Risk-Tier Structure

The EU AI Act organises AI systems into four risk categories:

Prohibited AI. Certain AI applications are prohibited outright under the Act. These include AI that manipulates people through subliminal techniques to influence their behaviour, social scoring systems by public authorities, most uses of real-time remote biometric identification in public spaces, and AI that exploits vulnerabilities of specific groups. These prohibitions applied from February 2025.

High-risk AI. AI systems used in certain high-stakes domains are classified as high-risk and subject to significant compliance obligations before they can be placed on the EU market. High-risk categories include AI in critical infrastructure, education and vocational training, employment decisions, access to essential private and public services (including credit scoring), law enforcement, migration and border management, and administration of justice. High-risk AI providers must conduct conformity assessments, maintain technical documentation, ensure human oversight, implement quality management systems, and register their systems in an EU database. The full requirements for high-risk AI apply from 2 December 2027 for standalone systems (2 August 2028 for AI embedded in already-regulated products), pushed back from an original 2 August 2026 date under a mid-2026 legislative delay known as the Digital Omnibus.

Limited-risk AI. AI systems with specific transparency risks. Primarily chatbots and systems that generate deepfakes or synthetic content. Must disclose to users that they are interacting with AI. This disclosure obligation has applied since August 2025.

Minimal-risk AI. The vast majority of AI applications. AI tools for business productivity, content generation, data analysis, scheduling, and most other common SMB use cases. Fall into the minimal-risk category and are not subject to specific EU AI Act obligations beyond the general prohibited categories. Providers and deployers of minimal-risk AI are encouraged but not required to follow voluntary codes of practice.

General-Purpose AI Models

The EU AI Act also introduces obligations for providers of general-purpose AI models (GPAIs). The large foundation models like GPT-4, Claude, and Gemini that power a broad range of downstream applications. GPAI providers must provide technical documentation, comply with EU copyright law, and publish summaries of training data. Providers of GPAI models that pose systemic risk (broadly, models above a certain computational threshold) face additional obligations including adversarial testing, incident reporting, and cybersecurity measures. These obligations applied to GPAI models from August 2025. For businesses using these models, wherever they are based, the practical implication is that the major model providers are subject to these requirements and that their compliance may affect their terms, their documentation, and their incident notification obligations to customers.

What Businesses Outside the EU Should Monitor

If your business is an SMB outside the EU using off-the-shelf AI tools for internal business tasks, the EU AI Act is unlikely to create direct compliance obligations for you. Most common SMB AI use cases are minimal-risk and the Act focuses primarily on providers and deployers placing AI on the EU market. The EU AI Act is most likely to be directly relevant if your business develops or customises AI systems for sale to EU customers, if you use high-risk AI systems in employment, credit, or service access decisions affecting EU residents, or if you are a deployer of a high-risk AI system in the EU market. The European AI Office's guidance is at digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.

The United States: Federal and State Approaches

The United States does not have a comprehensive federal AI law equivalent to the EU AI Act. The US approach to AI regulation is characterised by a combination of executive action at the federal level, existing agency authority applied to AI, and an increasingly active wave of state-level legislation. Understanding the US approach requires understanding these three levels separately.

Federal Level: Executive Orders and Agency Guidance

The Biden administration's 2023 Executive Order on AI directed federal agencies to establish safety standards for AI, develop guidance for AI use in government contracting, and work toward international AI governance coordination. The Trump administration issued its own AI executive order in January 2025, rescinding the 2023 order and taking a more deregulatory approach focused on AI leadership and competitiveness rather than safety mandates. The direction of US federal AI regulation is in flux as of mid-2026, reflecting the change in administration.

The National Institute of Standards and Technology (NIST) published the AI Risk Management Framework (AI RMF) in January 2023. The AI RMF is voluntary guidance rather than binding law, but it is widely used as a reference framework by US businesses and is influential in how procurement requirements, industry standards, and sector-specific guidance are structured. It is organised around four functions: Govern, Map, Measure, and Manage. Australia's DISR Voluntary AI Safety Standard draws on similar concepts. The AI RMF is at nist.gov/artificial-intelligence.

Agency-Level Regulation

Several US agencies are applying their existing statutory authority to AI-related conduct in their sectors. The Federal Trade Commission (FTC) has taken action against companies making deceptive claims about AI capabilities and has published guidance on AI and consumer protection. The Equal Employment Opportunity Commission (EEOC) has published guidance on AI in hiring and employment decisions. The Consumer Financial Protection Bureau (CFPB) has addressed AI in credit decisions. The Securities and Exchange Commission (SEC) has published guidance on AI disclosures for investment advisers. These sector-specific actions are more immediately relevant to US-regulated businesses but reflect the direction of regulatory thinking that may inform Australian sector regulators over time.

State-Level Legislation

US state legislatures have been significantly more active on AI regulation than the federal government. Colorado enacted AI legislation in 2024 creating requirements for high-risk AI systems in consequential decisions. Illinois has AI legislation covering employment decisions. Texas enacted a biometric data law. California, which enacted the CCPA and leads on privacy law, is active on AI regulation though Governor Newsom vetoed major AI safety legislation in 2024. As of mid-2026, dozens of states have enacted or are considering AI-specific legislation, creating a complex patchwork for businesses operating across multiple US states. Businesses selling software or services into the US, or processing data of US state residents, wherever they are based, may need to monitor state-level developments in the specific states where their customers are located.

The United Kingdom: Pro-Innovation, Sector-Led

The UK Regulatory Approach

The United Kingdom has taken a deliberately different approach from the EU, choosing not to enact a comprehensive AI law and instead directing existing sector regulators to apply their existing remit to AI. The UK government's stated objective is a pro-innovation regulatory environment that avoids imposing compliance costs that could disadvantage UK AI development. Existing UK regulators. The ICO for data protection, the FCA for financial services, the CMA for competition, the MHRA for medical devices. Are responsible for addressing AI-related issues within their sectors using existing law.

The UK AI Safety Institute (now renamed the AI Security Institute) was established in 2023 to conduct evaluations of advanced AI models, particularly for frontier risks such as misuse for biological weapons, cyberattacks, and societal harm. The AI Security Institute works with major AI labs to conduct safety evaluations before model deployment. It is research-focused rather than a regulatory body with enforcement powers, and its work is most relevant to organisations developing or deploying frontier AI models rather than businesses using existing AI tools.

The ICO (Information Commissioner's Office) has been the most active UK regulator on practical AI governance for businesses. The ICO has published detailed guidance on how the UK GDPR applies to AI, including data protection impact assessments for AI, automated decision-making and profiling, and AI in employment. UK GDPR applies to businesses established in the UK and to businesses established outside the UK that offer goods or services to, or monitor, individuals in the UK. Businesses with UK customers or UK data subjects, wherever they are based, should review the ICO's AI guidance. The ICO guidance is at ico.org.uk/for-organisations/guide-to-data-protection/key-dp-themes/guidance-on-ai-and-data-protection.

Singapore: The Model AI Governance Framework

Singapore has taken a governance-framework approach to AI regulation rather than binding legislation. The Personal Data Protection Commission (PDPC) published the Model AI Governance Framework in 2019 (updated 2020), which is a voluntary reference framework for organisations deploying AI in their business. Singapore's approach emphasises practical, business-applicable guidance over regulatory mandates, making it particularly relevant as a reference for small and medium-sized businesses.

The Model AI Governance Framework is organised around two core principles: decisions should be explainable, transparent, and fair, and AI solutions should be human-centric. The framework covers four areas: internal governance structures and measures, determining the level of human involvement in AI-augmented decisions, operations management, and stakeholder interaction and communication. Singapore has also published the AI Verify Toolkit, a testing toolkit that allows organisations to assess their AI systems against the principles in the governance framework.

Singapore's approach is relevant well beyond its own borders for two reasons. First, Singapore is a significant trade and technology hub, and many businesses. Including Australian businesses, for whom Singapore is a major trade partner. Operate across Singapore and one or more other jurisdictions covered in this guide. Second, the Model AI Governance Framework's practical, principles-based structure has influenced governance frameworks in other Asia-Pacific jurisdictions and is a useful reference document for any business designing its own AI governance processes, regardless of where it is based. The framework is at pdpc.gov.sg/help-and-resources/2020/01/model-ai-governance-framework-second-edition.

Australia: Voluntary Standards and Privacy Reform

Australia has not yet enacted binding AI-specific legislation at the federal level. Its regulatory response to AI, as of mid-2026, rests on the DISR Voluntary AI Safety Standard (10 guardrails, voluntary for Australian businesses) alongside existing sector-specific regulation applied to AI by ASIC, APRA, and the OAIC, and the Australian Human Rights Commission's guidance on AI and human rights. The government has indicated an intent to monitor international developments and consider binding regulation for high-risk AI applications, but no binding AI law was in place or imminent as of mid-2026.

The most significant near-term compliance obligation for Australian businesses is the Privacy Act 1988's automated decision-making amendments, which take effect from December 2026 and require disclosure when automated decision-making is used to make decisions that significantly affect individuals. Our guide to the Privacy Act and AI covers the Australian obligations in detail, and our AI governance by region hub compares Australia's position against the EU, UK, US, and Canada side by side.

Cross-Border Monitoring Priorities

For a business with international operations or customers, the practical monitoring priorities differ by jurisdiction:

EU exposure: If your business sells to EU customers, handles personal data of EU residents, or uses AI in employment, credit, or service access decisions that affect EU individuals, monitor the EU AI Act's high-risk classification list and the European AI Office's guidance for deployers. If you are a software business selling AI-enhanced products into the EU, you may be an AI system provider under the Act's definitions.

US exposure: If your business handles personal data of California residents, monitor the CCPA and California's ongoing AI legislation. If you operate in sectors covered by active US agency guidance (financial services, employment, healthcare), monitor the relevant agency's AI publications. If you sell software into the US, monitor the state-level legislation in your target states.

UK exposure: If your business has UK customers or processes data of UK residents, the ICO's AI and UK GDPR guidance applies. Monitor the ICO's AI enforcement actions as indicators of where practical compliance attention is focused.

Singapore and Asia-Pacific: If your business operates across Singapore, New Zealand, Japan, or other Asia-Pacific jurisdictions, each has its own data protection and emerging AI governance framework. The Asia Pacific Privacy Authorities (APPA) forum coordinates between the OAIC and its regional counterparts, and their published positions indicate where regional regulatory alignment is developing.

Australia exposure: If your business has customers or operations in Australia, monitor the DISR Voluntary AI Safety Standard's uptake and the Privacy Act 1988's automated decision-making amendments taking effect December 2026, plus sector-specific AI guidance from the OAIC, ASIC, and ACCC.

Last reviewed: June 2026 | Next review: September 2026

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Related reading: for Australian readers, our can staff upload customer data to AI tools guide covers this under the Privacy Act.

Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.

Does the EU AI Act apply to businesses outside the EU?

The EU AI Act applies to AI systems placed on the EU market or put into service in the EU, regardless of where the provider is based. For a business based outside the EU. Whether in Australia, the US, the UK, Singapore, or elsewhere. That does not sell AI systems or AI-enabled products into the EU and does not deploy AI systems in EU operations, the Act is unlikely to create direct compliance obligations. The Act is most likely to directly apply to businesses that develop AI systems and sell them to EU customers; businesses that deploy high-risk AI systems in EU-facing operations (employment decisions, credit decisions, or services to EU residents); and businesses that are deployers of AI systems covered by the Act's high-risk classifications in EU market contexts. For most SMBs anywhere using off-the-shelf AI tools for internal business tasks, the EU AI Act shapes the tools you use (because your vendors must comply) but is unlikely to impose direct obligations on you. If you are uncertain, the European AI Office's documentation on who the Act applies to is the starting point.

What is the NIST AI Risk Management Framework and should I use it?

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework published by the US National Institute of Standards and Technology for managing risks associated with AI systems. It is not a regulation and creates no compliance obligations for non-US businesses. It is, however, a well-structured practical reference for organisations designing their own AI governance processes. The framework's four functions. Govern, Map, Measure, and Manage. Are useful for thinking about the lifecycle of AI risk management from policy and accountability (Govern) through identifying how AI is being used (Map), assessing its performance and risks (Measure), and taking action (Manage). Australian organisations considering a structured AI governance approach may find the AI RMF a useful voluntary reference alongside the DISR Voluntary AI Safety Standard. The full framework is freely available at nist.gov/artificial-intelligence.

How does GDPR relate to AI regulation, and does it apply outside the EU and UK?

The GDPR (EU General Data Protection Regulation, now supplemented by UK GDPR for the UK post-Brexit) predates the EU AI Act and applies to all processing of personal data of EU and UK residents, regardless of where the processing organisation is based. GDPR has direct relevance to AI because: it restricts automated decision-making that has significant effects on individuals (Article 22), it requires lawful basis for processing personal data used to train AI models, it imposes data minimisation requirements that limit what data can be used in AI systems, and it requires data protection impact assessments for high-risk processing. GDPR applies to any business, wherever it is based. Australian, American, Singaporean, or otherwise. That offers goods or services to EU or UK residents or that monitors their behaviour. If this applies to your business, GDPR's AI-relevant provisions. Particularly Article 22 on automated decision-making. Are directly relevant, and the ICO's and EDPB's guidance on AI and GDPR are the primary references.

Is Australia likely to introduce binding AI legislation?

As one of the jurisdictions this guide covers, Australia's regulatory status as of mid-2026 is that no binding federal AI-specific legislation has been enacted or announced with a specific timeline; the government has indicated an intent to monitor international developments and consider binding regulation for high-risk AI applications. The December 2026 Privacy Act amendments. Introducing automated decision-making disclosure requirements. Are the most significant near-term AI-related compliance obligation for businesses operating in Australia. The DISR Voluntary AI Safety Standard remains voluntary. The government's approach to date has been to build voluntary frameworks and allow sector regulators to apply existing law to AI before considering whether new binding law is needed. Whether and when this changes will depend on how international regulatory developments evolve, particularly the EU AI Act's enforcement in practice and any significant AI-related harms that prompt regulatory response. The DISR's AI regulation consultation documents and the Attorney-General's Department's Privacy Act review are the primary sources for tracking where Australian regulation is heading.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

Want to compare how these frameworks stack up by jurisdiction, side by side? Our AI governance by region hub covers the EU, UK, US, Canada, and Australia in one place. If you're an Australia-based business specifically, our guide to AI risks by industry breaks down the regulatory bodies that apply in your sector.

See AI Governance by Region