AI Regulation and Compliance Global Landscape

By Last Updated: September 1st, 202611.2 min readViews: 913
Table of contents

AI Regulation and Compliance Global Landscape

EU AI Act, US guidance, India’s AI policy direction, sector-specific compliance, and audit readiness.


Introduction

Artificial intelligence regulation has entered a new phase. Until recently, much of the global discussion revolved around principles such as fairness, transparency, explainability, privacy and human oversight. By September 2026, the important question for companies is no longer whether responsible AI matters. It is whether an organisation can prove, with evidence, that its AI systems are classified correctly, governed appropriately, tested before deployment, monitored after deployment and used in accordance with the laws that apply to its market, sector and customers.

There is still no single global AI rulebook. Europe has constructed the most comprehensive horizontal regulatory regime through the EU AI Act, while the United States continues to rely on federal policy, procurement requirements, sector regulators, existing law, voluntary standards and state-level legislation. India is following a different path again, favouring a principle-based and sector-aware governance model built around existing law, the India AI Governance Guidelines, data protection rules and targeted intervention where particular harms arise. The result is not regulatory convergence in the traditional sense. What is emerging instead is a common operational vocabulary built around risk assessment, accountability, documentation, human oversight, testing, transparency, cybersecurity and auditability.

Let’s dive deep into the topic now.

1. AI regulation is moving from ethical principles to operational controls

For several years, organisations could describe an AI programme as “responsible” by publishing principles or establishing an ethics committee. That is becoming insufficient. Regulators increasingly expect governance to reach the level of the individual AI system. Companies need to know what models they use, who owns them, what data enters them, what decisions they influence, who can override them, what tests have been performed and how incidents will be detected and escalated.

This marks an important change in the intellectual structure of AI governance. Compliance is moving from abstract statements about trustworthy AI towards what may be called an evidence architecture. A company should be capable of connecting a principle such as fairness to a control, the control to a test, the test to documented results, the results to an accountable owner and the owner to a remediation process. That logic appears across the EU AI Act, NIST’s AI Risk Management Framework and international standards such as ISO/IEC 42001 and ISO/IEC 42005, even though their legal status and terminology differ.

2. The EU AI Act is now an operating compliance regime, but its timetable requires careful reading

The EU AI Act became generally applicable on 2 August 2026. Important provisions had already arrived earlier. Prohibited AI practices and AI-literacy obligations started applying in February 2025, while governance rules and obligations for providers of general-purpose AI models began applying in August 2025. Article 50 transparency obligations, including requirements relevant to certain AI interactions and synthetic content, became applicable from 2 August 2026.

However, businesses should not interpret 2 August 2026 as the single deadline for everything in the Act. Following the EU’s AI Omnibus changes, requirements for Annex III high-risk systems, covering areas such as employment, education, biometrics and certain public-sector uses, are scheduled to apply from 2 December 2027. High-risk AI embedded in regulated products under Annex I receives a longer transition until 2 August 2028. For compliance teams, this creates a preparation window, not a reason for inactivity. Systems must first be inventoried and classified before an organisation can know whether later high-risk obligations will apply. An excellent collection of learning videos awaits you on our Youtube channel.

3. General-purpose AI has moved from policy discussion into enforcement

One of the most significant developments of 2026 concerns general-purpose AI, or GPAI. Providers placing GPAI models on the EU market have been subject to relevant AI Act obligations since 2 August 2025. These include transparency obligations towards downstream providers and copyright-related requirements. More advanced GPAI models with systemic risk face additional expectations concerning risk assessment, safety and security.

The critical September 2026 development is enforcement. From 2 August 2026, the European Commission’s enforcement powers regarding GPAI obligations became applicable, including the possibility of fines. Models placed on the market before 2 August 2025 receive a longer transition and must comply by 2 August 2027. This makes the relationship between foundation-model providers and enterprise customers increasingly important. A company buying API access may not be the model provider under the Act, but it still needs sufficient technical, contractual and governance information to understand what it is deploying downstream.

4. The EU Digital Services Act now matters directly to OpenAI through ChatGPT’s VLOSE designation

A particularly important development occurred on 31 August 2026, just before this September 2026 snapshot. The European Commission designated ChatGPT as a Very Large Online Search Engine, or VLOSE, under the Digital Services Act. Reddit and Roblox were designated as Very Large Online Platforms at the same time. According to the Commission, the services had declared that they reached at least 45 million average monthly users in the European Union, the threshold used for VLOP and VLOSE designation.

This is significant because the DSA and AI Act regulate different dimensions of the digital ecosystem. The AI Act focuses on AI systems, models, risk categories and responsibilities across the AI value chain. The DSA focuses on platform and search-engine responsibilities, including systemic risks associated with large-scale information services. Following the VLOSE designation, ChatGPT has four months, by the end of November 2026, to meet the additional DSA requirements applicable to very large services, including assessment and mitigation of systemic risks involving illegal content, minors, fundamental rights, electoral processes, public security and other societal effects. The lesson for corporate leaders is broader than OpenAI itself. An AI product can simultaneously fall within multiple regulatory regimes depending on what the product does, how many people use it and the role it plays in the information ecosystem. A constantly updated Whatsapp channel awaits your participation.

bh-superclass-banner

 

5. The United States is pursuing AI governance without constructing an EU-style AI Act

The US approach remains structurally different. President Donald Trump’s January 2025 executive order, Removing Barriers to American Leadership in Artificial Intelligence, revoked the previous administration’s AI executive-order framework and directed the development of a new national strategy. The White House subsequently published America’s AI Action Plan in July 2025, organised around accelerating innovation, building AI infrastructure and strengthening US international leadership.

Federal governance has therefore not disappeared. It has changed direction. OMB issued revised policies governing federal agency use and procurement of AI, while NIST’s AI Risk Management Framework continues to provide a widely used voluntary structure for AI risk management and is itself being revised as part of the federal AI agenda. In December 2025, the administration also issued an executive order seeking a stronger national AI policy framework and addressing what it regards as obstructive state-level regulation. Companies should nevertheless avoid reducing US compliance to White House policy. Privacy, discrimination, consumer protection, medical-device regulation, employment law, financial regulation and state legislation can all affect AI systems independently of a single federal AI statute.

6. India’s AI strategy favours a principle-based, techno-legal and sector-aware model

India has consciously avoided simply copying the EU AI Act. In November 2025, MeitY released the India AI Governance Guidelines, establishing a national framework around seven guiding “Sutras”: Trust is the Foundation, People First, Innovation over Restraint, Fairness and Equity, Accountability, Understandable by Design, and Safety, Resilience and Sustainability. The framework also organises recommendations across infrastructure, capacity building, policy and regulation, risk mitigation, accountability and institutions.

The underlying philosophy is important. India’s framework argues for using existing laws and sector regulators wherever possible rather than immediately creating a single comprehensive AI statute. A January 2026 white paper from the Office of the Principal Scientific Adviser similarly described a “techno-legal” approach combining baseline legislation, sector regulation, policy guidance and technical safeguards. This does not mean AI in India operates without regulation. The Digital Personal Data Protection Act and the DPDP Rules notified in November 2025 govern digital personal-data processing, while February 2026 amendments to the IT Rules added provisions dealing with synthetically generated information. India’s model is therefore better understood as distributed AI governance rather than regulatory absence. Excellent individualised mentoring programmes available.

7. Sector-specific regulation may matter more than a country’s headline AI policy

For many companies, the most consequential AI rule will not carry the words “Artificial Intelligence Act” in its title. It may instead come from the regulator that already supervises the company’s industry. Finance, healthcare, insurance, securities, telecommunications and critical infrastructure all operate within established regulatory environments where requirements concerning confidentiality, model risk, cybersecurity, consumer protection and accountability can apply to AI even without AI-specific legislation.

India’s financial sector provides a useful example. RBI’s 2025 FREE-AI Committee report developed a framework for responsible and ethical AI in finance. SEBI has gone further in several regulated contexts by making entities responsible for AI and machine-learning tools they use, including tools obtained from third parties. In the United States, the FDA’s growing body of guidance for AI-enabled medical devices addresses lifecycle management, predetermined change-control plans, clinical decision-support software and machine-learning practices. The wider lesson is that sector regulation frequently follows the risk created by the application, not the novelty of the underlying model.

8. Third-party AI does not outsource corporate accountability

One of the most dangerous assumptions in enterprise AI is that responsibility moves to the vendor when the model is externally supplied. Regulation is increasingly moving in the opposite direction. Organisations need to distinguish between the responsibilities of a foundation-model provider, application provider, integrator and deployer, but being a customer rarely eliminates accountability for how an AI system is used inside the organisation.

This turns AI compliance into a supply-chain discipline. Vendor due diligence should examine data handling, model limitations, security practices, update mechanisms, subcontractors, intellectual-property conditions, logging, incident notification and the information available for regulatory documentation. Contracts increasingly need to answer practical questions: What happens when the provider changes the underlying model? Can the enterprise reproduce the version that made a historical decision? What evidence will the vendor supply during an audit? Can enterprise data be used for training? SEBI’s approach explicitly places responsibility on regulated entities even where AI tools are procured from third parties, while the EU GPAI framework requires information flows that support downstream compliance. Subscribe to our free AI newsletter now.

9. Audit readiness requires evidence, not merely an AI policy

An organisation can have a beautifully written responsible-AI policy and still be unprepared for regulatory scrutiny. Auditors and regulators need evidence that the policy actually operates. The starting point is a reliable AI inventory: system name, owner, vendor, model, purpose, affected population, data sources, geographic deployment, decision impact and risk classification. Higher-risk systems then require deeper evidence covering validation, bias testing, cybersecurity, human oversight, explainability, performance thresholds and post-deployment monitoring.

International standards are becoming useful in creating this control architecture. ISO/IEC 42001 provides requirements for establishing and continually improving an AI management system. ISO/IEC 23894 addresses AI-specific risk management, while ISO/IEC 42005, published in 2025, provides guidance for AI system impact assessments. These standards do not automatically create compliance with every country’s law, but they can help organisations create repeatable governance processes. A serious audit-readiness programme should be capable of producing documentation showing who approved an AI system, what risks were identified, how they were tested, what changes occurred and what happened when the system failed.

10. The winning compliance model will be “govern once, map many times”

A multinational company cannot realistically build a completely different AI governance programme for every jurisdiction. The more scalable approach is to identify the controls that appear repeatedly across major frameworks and implement them as an enterprise baseline. These typically include an AI inventory, risk classification, accountable ownership, impact assessment, privacy review, security testing, human oversight, performance evaluation, documentation, vendor governance, incident management, change control and continuous monitoring.

Jurisdiction-specific requirements can then be mapped onto that common architecture. The EU layer may add AI Act classifications, Article 50 transparency rules, GPAI obligations or DSA responsibilities. The United States may add agency, sector or state-specific requirements. India may add DPDP obligations, IT Rules, sectoral regulator requirements and India AI Governance Guidelines. Governance platforms from companies such as IBM, Microsoft and specialist AI-governance vendors can help manage inventories, workflows, risk assessments and evidence, but software cannot decide an organisation’s risk appetite or legal interpretation. Compliance tooling is an infrastructure layer. Accountability remains a management responsibility. Upgrade your AI-readiness with our masterclass.

Conclusion

The central lesson from the global landscape is that AI regulation is no longer a future problem for legal departments. It is becoming an operating discipline for boards, technology teams, compliance officers, risk managers, procurement teams and business leaders. The EU is moving deepest into formal cross-sector regulation, while the United States emphasises innovation alongside existing regulatory and institutional mechanisms, and India is developing a principle-based, techno-legal framework built around existing laws and sector regulators. At the same time, the new DSA designation of ChatGPT as a VLOSE demonstrates how quickly regulatory boundaries are expanding beyond traditional definitions of an AI model. Organisations that treat compliance as paperwork added after deployment will struggle with this complexity. Those that build inventory, evidence, testing, governance and accountability into the AI lifecycle itself will be far better prepared, regardless of which regulatory model ultimately dominates.

 

bh-superclass-banner

Share this with the world