The World Is Building AI Rules in Real Time: A Review of the Global Conversation on AI Governance

TRM Team
The World Is Building AI Rules in Real Time: A Review of the Global Conversation on AI Governance

AI is changing the way we live and work, the way governments make decisions, the way armies fight wars, the way criminals launder money, and the way investigators track them down. It’s compressing decades of technological change into months, and in some cases, months into days and minutes.

According to TRM Labs' 2026 Crypto Crime Report, AI-enabled scam activity rose 500% in a single year. Large language models (LLMs) allow fraud networks to cross language and cultural barriers with minimal friction. 

Voice cloning, deepfake video, and AI-generated personas have eliminated the human bottlenecks that once constrained the scale of impersonation scams. Pig butchering operations are leveraging AI bots to maintain conversations for months before defrauding victims. And AI-powered identity fabrication tools are being used to open accounts and move criminal proceeds through the financial system. According to TRM’s research, investment scam losses reached USD 23 billion in verified inflows in 2025. Illicit crypto flows hit a record USD 158 billion, up 145% year over year. And ransomware variants grew 94%. 

AI is removing the bottlenecks that once limited how fast and far criminal networks could scale. And the defenders are running the same race with older infrastructure and slower legal authorities.

The world is now moving in several directions simultaneously on governance, at different speeds, with different assumptions about the risks that come with AI and whose job it is to manage them. The best work is being done by jurisdictions that are thinking about both liability and opportunity. What’s emerging is a patchwork — sometimes complementary, sometimes contradictory — that will define how AI develops for the next generation.

Key takeaways

  • The EU AI Act is the world's first comprehensive, legally binding AI legislation. Now, Brussels is considering how to balance future AI regulation with its own digital sovereignty.  
  • The Trump administration has moved through three phases of AI regulation in eighteen months: revoking Biden's framework, using a DOJ litigation task force to challenge state AI laws, and signing EO 14409 (the first federal acknowledgment that frontier AI poses national security risks requiring government engagement).
  • Peru has the first enacted AI law in Latin America. Brazil's bill is one Senate chamber away. 
  • No multilateral body has produced an enforceable global standard. Enforcement remains the missing element across the globe.

{{horizontal-line}}

Global AI regulation at a glance (July 2026)

Country / geography Current AI regulatory status
Europe
European Union EU AI Act (August 2024) — world's first comprehensive, binding AI law; risk-tiered framework. Unacceptable-risk bans effective February 2025; GPAI rules effective August 2025; high-risk obligations due August 2026 (timeline under review via the Digital Omnibus proposal).
United Kingdom No comprehensive AI statute. Regulator-by-regulator approach (e.g. FCA relying on existing Consumer Duty/SM&CR rules rather than new AI rules), plus the 2023 Bletchley Declaration on frontier-model safety.
United States
California Enacted (September 2024) — Defending Democracy from Deepfake Deception Act, AI Transparency Act
Colorado Active AI-related legislation in progress
Federal No comprehensive federal AI law. Governed by executive orders: EO 14110 (revoked), EO 14179 (deregulatory), EO 14365 (December 2025 — DOJ task force challenging state AI laws), EO 14409 (June 2026 — voluntary frontier-model review + Treasury cybersecurity clearinghouse). Congressional bills (CREATE AI Act, AI Accountability Act, AI PLAN Act) remain unenacted.
Illinois Active AI-related legislation in progress
New York Active AI-related legislation in progress
Texas Enacted — Responsible AI Governance Act
Utah Enacted, since narrowed — AI law scope reduced, safe harbor protections extended
APAC
Australia No mandatory guardrails — National AI Plan (December 2025) relies on existing laws/regulators. Privacy and Other Legislation Amendment Act 2024 (automated decision-making transparency) takes effect December 2026; AI Safety Institute expected early 2026.
China Layered, sector-specific regulations, not a single statute: Generative AI Regulations (2023), AI Safety Governance Framework (2024), Network Data Security Management Regulations (January 2025), AI-content-labeling rules (September 2025). Functions as a state-control mechanism rather than a rights-based framework.
India Draft stage — Digital India Bill (2024) addresses AI accountability; National AI Mission Framework expected to follow
Singapore Voluntary — Model AI Governance Framework (2nd edition); Expanded Global AI Assurance Sandbox launched 2025
South Korea Enacted (December 2024) — Framework Act on the Development of AI and Establishment of Trust; comprehensive with extraterritorial reach
Taiwan Enacted — AI Basic Act, plus AI Action Plan 3.0 (2025)
Latin America
Argentina Non-binding — AI Strategy guidelines (2025), no binding law
Brazil Near-enacted — AI Bill No. 2338/2023 passed the Senate (December 2024), modeled on the EU AI Act; awaiting Chamber of Deputies approval
Chile Draft stage — risk-based AI bill in active development
Mexico Proposed — Federal Law Regulating Artificial Intelligence; under Senate discussion, passage expected 2026
Peru Enacted (September 2025) — Regulation of Law No. 31814; first enacted AI law in Latin America
International / multilateral
Council of Europe Enacted treaty (2024) — Framework Convention on Artificial Intelligence; first legally binding international AI treaty, open beyond its 46 members
Financial Stability Board Non-binding — Sound Practices for Responsible Adoption of AI (June 2026), scoped to financial institutions
G7 Non-binding — Hiroshima AI Process best practices
OECD Non-binding — AI Policy Observatory, coordinating 44 countries
UN Non-binding — AI Advisory Body recommendations (2024)

{{horizontal-line}}

Europe

The EU AI Act, which entered into force on August 1, 2024, is the world's first comprehensive, legally binding AI legislation, built on a risk-classification framework. AI systems are tiered by the harm they can cause — from unacceptable risk (social scoring, mass surveillance, real-time biometric identification in public spaces) to high risk (AI used in hiring, education, critical infrastructure, and law enforcement) to minimal risk (systems that face essentially no obligations).

Prohibitions on unacceptable-risk AI took effect February 2, 2025. Rules for general-purpose AI models began applying August 2, 2025. And high-risk obligations are soon to follow in August 2026. The EU is building a governance architecture in parallel, including notified bodies, a European AI Office, and national competent authorities in each member state.

The EU is betting it can set the global baseline for AI governance the way GDPR did for data protection. However, after years of implementation, GDPR produced compliance while arguably stifling data-driven innovation in Europe — a burden American and Asian competitors never faced. The EU AI Act may produce similar tradeoffs at a larger scale. The European Commission's Digital Omnibus proposal, now under discussion, signals that Brussels recognizes the timeline for implementation may need adjustment — with the high-risk compliance obligations expected in August 2026 already under review.

Brussels is now tackling an even harder question: how to regulate AI while building genuine digital sovereignty. Europe's AI ecosystem still relies heavily on non-European cloud providers, AI systems, and semiconductors — a dependency policymakers increasingly treat as a strategic vulnerability rather than a neutral market outcome. But the sovereignty push has its own critics. Some are warning that mandating EU-based compute or data residency could raise costs and slow deployment for European AI firms already competing against better-funded US and Chinese rivals. This is the same innovation-versus-regulation trade-off running through the AI Act itself, just one layer down, at the infrastructure level rather than the application level.

United Kingdom

Just across the Channel, the UK has made a different bet. 

Rather than one comprehensive AI statute, successive UK governments have wagered that existing regulators, applying existing powers, can manage AI risk sector by sector — while a small number of central institutions handle frontier-model safety specifically. That approach traces back to Rishi Sunak's AI Safety Summit at Bletchley Park in November 2023, the first global gathering dedicated to frontier AI risk. It produced the Bletchley Declaration, signed by 28 countries including the US and China. 

The FCA is one of the UK’s clearest examples of leaning on current regulatory frameworks for AI guardrails. The FCA stated in 2026 that it does not plan to introduce extra regulation for AI, relying instead on existing frameworks such as the Consumer Duty and the Senior Managers and Certification Regime — a principles-based, outcomes-focused stance the regulator argues is best suited to a fast-moving technology

Taken together, the UK is the clearest live test of a third model sitting alongside the EU's comprehensive statute and the fragmented US state-federal fight explored next: regulate through the regulators you already have, and reserve new statutory power only for the handful of frontier-model risks no existing body was built to catch.

{{horizontal-line}}

United States

The United States currently does not have a single comprehensive federal AI law. A sequence of executive orders, agency guidance, state legislation, and federal bills have not yet crossed the finish line.

The US Executive Orders

The Biden Administration's Executive Order 14110, issued in October 2023, directed safety standards, civil rights protections, interagency coordination, and national security reviews across the federal government. On January 20, 2025 — day one of the Trump Administration — it was revoked.

Executive Order 14179, "Removing Barriers to American Leadership in Artificial Intelligence," replaced it. Then in July 2025, the administration released an AI Action Plan calling for the removal of regulations hindering US AI leadership.

The most consequential domestic action arrived December 11, 2025, with Executive Order 14365, targeting the states. A DOJ AI Litigation Task Force, operational from January 2026, is authorized to challenge state AI laws in federal court — with the Dormant Commerce Clause as the primary legal theory. The downstream effects are already visible. Colorado delayed its AI Act from February 2026 to June 2026. And Utah narrowed its AI law's scope and extended safe harbor protections.

Then on June 2, 2026, the administration moved in a direction that surprised many observers. Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," requests that AI companies voluntarily provide government access to covered frontier models for a cybersecurity review up to thirty days before release, and establishes a Treasury-led clearinghouse to coordinate vulnerability discovery across AI firms, technology companies, and critical infrastructure operators. A deregulatory administration confronted the reality that the most capable AI systems create national security risks requiring federal engagement.

A state-by-state patchwork

California enacted a package of AI legislation in September 2024, including the Defending Democracy from Deepfake Deception Act and the AI Transparency Act. Texas passed the Responsible AI Governance Act. Colorado, New York, and Illinois have active AI-related legislation. 

States moved because Congress did not, and the result is a compliance environment that is hard to navigate and even harder to enforce coherently.

The CREATE AI Act would establish a National AI Research Resource. The AI Accountability Act directs NTIA to study accountability mechanisms, and the AI PLAN Act requires a federal strategy to defend against AI-enabled financial crime. But so far, none have become law. The central question is whether Washington can produce a coherent federal framework before the state-by-state patchwork becomes permanent infrastructure.

{{horizontal-line}}

APAC

South Korea's Framework Act on the Development of Artificial Intelligence and Establishment of Trust, enacted December 2024, is one of the earliest comprehensive AI statutes in Asia, with extraterritorial provisions that will affect foreign companies doing AI-related business connected to the Korean market. Taiwan's Legislative Yuan similarly passed an Artificial Intelligence Basic Act and released AI Action Plan 3.0 in 2025.

Singapore's Model AI Governance Framework, now in its second edition, is one of the most widely referenced voluntary AI governance documents in the world. In 2025, Singapore launched an Expanded Global AI Assurance Sandbox, giving businesses tools to test AI applications against real-world data protection standards before deployment.

India's Draft Digital India Bill (2024) addresses AI accountability and platform responsibility. A National AI Mission Framework is expected to follow, with a voluntary AI Safety Board and sector-specific standards for health technology and fintech.

Australia's December 2025 National AI Plan stepped back from mandatory guardrails entirely, choosing to rely on existing laws and sector regulators. The Privacy and Other Legislation Amendment Act 2024 introduces automated decision-making transparency requirements, effective December 2026. And an Australian AI Safety Institute is expected to become operational in early 2026. Australia and the EU now represent the clearest contrast in regulatory philosophy in the democratic world.

China's AI governance

China has built a layered set of AI regulations targeting specific categories of system or risk. The Generative AI Regulations (2023) govern GPAI services, covering content moderation, training data sourcing, and registration. The AI Safety Governance Framework (September 2024) aligned with Beijing's Global AI Governance Initiative. The Network Data Security Management Regulations took effect January 2025. Final rules on AI-generated content labeling take effect September 1, 2025.

AI development and deployment in China must stay aligned with social stability and national development as the party defines them, and every piece of the regulatory architecture built around that goal serves the same end. Content controls dictate what generative systems can produce and how outputs get filtered before they reach users. Algorithm registration gives regulators visibility into the underlying models and a mechanism to intervene when a system's behavior drifts from what the state considers acceptable. Data localization keeps the training and operating data inside borders the party can reach. Together these requirements function as a single control system rather than a set of independent rules, and the party's authority over what AI systems can say, do, and produce operates as the constraint that shapes the rest of the framework.

{{horizontal-line}}

Latin America

Brazil's AI Bill No. 2338/2023 passed a Senate vote in December 2024 — the most developed AI framework in the region. Modeled closely on the EU AI Act, it prohibits social scoring systems, mass public surveillance, and predictive policing tools. It also imposes strict oversight on high-risk applications including hiring tools, clinical diagnostics, and credit scoring. It still requires approval from Brazil's Chamber of Deputies.

Peru is already there. The Regulation of Law No. 31814, published September 2025, is the first enacted AI law in Latin America — a risk-based framework with prohibited practices, mandatory human oversight for high-risk uses, and regulatory sandboxes.

Chile has a risk-based AI bill in active development. Mexico's proposed Federal Law Regulating Artificial Intelligence remains under Senate discussion, with passage expected in 2026. Argentina has published non-binding AI Strategy guidelines for 2025. And the ECLAC 2024 Digital Agenda, endorsed by all 33 member countries, calls for regional coordination — but the landscape remains fragmented.

{{horizontal-line}}

International architecture

The Council of Europe's Framework Convention on Artificial Intelligence, completed in 2024, is the world's first legally binding international AI treaty, focused on human rights, democracy, and the rule of law — and open beyond Council of Europe members.

The G7 Hiroshima AI Process has produced best practices for frontier AI systems. The OECD AI Policy Observatory coordinates across 44 countries. The Global Partnership on AI, now integrated with the OECD, operates Expert Support Centers in Canada, France, and Japan. The UN AI Advisory Body published governance recommendations in 2024.

On June 10, 2026, the Financial Stability Board published a consultation report on Sound Practices for Responsible Adoption of Artificial Intelligence — notably scoped specifically to how financial institutions adopt, use, and innovate with AI, rather than general AI governance. The 12 practices cover organization-wide governance and the AI lifecycle, and are explicitly non-binding and non-prescriptive.

{{horizontal-line}}

Three unresolved challenges

1. AI has the capacity for meaningful good — and meaningful harm

Every government wants to lead in AI. But every government also recognizes an important dichotomy: AI deployed badly causes real harm; AI deployed well could unlock enormous productivity and innovation gains (which for many economies, are badly needed). 

2. The compliance burden is scattered amongst the builders

The EU has bet on comprehensive risk-based rules. The US has bet on market-led development with targeted interventions. China has built a control architecture aligned with state objectives. But none of these approaches have been stress-tested against a serious AI-driven crisis.

The compliance burden will fall most heavily on smaller developers and enterprises. Large technology companies have compliance infrastructure, while startups and academic researchers frequently do not. Whether AI governance frameworks accelerate consolidation in the AI industry is one of the more consequential and, at present, least-discussed questions in the current regulatory cycle.

3. Regulation can’t keep up with the pace of AI innovation

The speed-of-AI-innovation problem cuts across every jurisdiction. For example, the EU AI Act was drafted before large language models became broadly available, and the Biden executive order was revoked before most of its provisions were implemented. Regulators everywhere are writing rules for a technology that will look different by the time the rules take effect.

{{horizontal-line}}

What comes next

AI is infrastructure. It will be — and in some cases, already is — the backbone on which our most critical financial, health, legal, and security systems run. The governance choices being made today will shape how that infrastructure is built, and by whom.

In the US, whether Congress produces federal AI legislation will determine whether the current US state patchwork calcifies into permanent compliance infrastructure or gives way to a coherent national framework. The Trump administration's December 2025 legislative framework signals intent, and the June 2026 cybersecurity executive order signals that even a deregulatory administration is discovering that frontier AI capabilities require federal engagement.

In Europe, the EU's implementation of the AI Act over the next two years will test whether comprehensive risk-based regulation is workable in practice. The Digital Omnibus review of the 2026 timeline is the first sign that implementation is harder than drafting.

At the frontier — in the development of the most capable AI systems — no government has yet produced a framework that addresses what happens when an AI system is capable enough to pose risks that existing regulatory categories did not anticipate. The Council of Europe's treaty, the G7 process, the UN advisory body — these are early attempts to build architecture for a problem whose full shape is still coming into view.

The technology isn’t waiting for the policy to catch up. That’s always been the condition under which consequential governance gets built.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. What is the EU AI Act and when does it take effect?

The EU AI Act is the world's first comprehensive, legally binding AI legislation, signed into law on August 1, 2024. It tiers AI applications from unacceptable risk — prohibited outright — to high risk, which faces strict compliance obligations, to minimal risk. Bans on the highest-risk applications took effect February 2, 2025. Rules for general-purpose AI models began applying August 2, 2025. High-risk compliance obligations follow in August 2026, though those timelines are under review through the Digital Omnibus process.

2. What did Trump's AI executive orders actually do?

EO 14179 (January 20, 2025) revoked Biden's EO 14110 and made US competitiveness the governing principle. EO 14365 (December 11, 2025) established a DOJ AI Litigation Task Force to challenge state AI laws and called for a national preemptive framework. EO 14409 (June 2, 2026) established the voluntary pre-release frontier model review process and Treasury-led cybersecurity clearinghouse — the administration's first substantive move toward federal AI oversight.

3. Which countries have actually passed AI laws?

As of June 2026, enacted binding AI legislation exists in the European Union (EU AI Act, 2024), South Korea (Framework Act on AI, 2024), Taiwan (AI Basic Act), and Peru (Regulation of Law No. 31814, 2025), along with a growing number of US states. Brazil's bill passed the Senate in December 2024 and awaits Chamber of Deputies approval. The United States currently has no federal AI law.

4. How does US AI policy compare to the EU approach?

The EU has taken a prescriptive, risk-based legislative approach with binding obligations and significant penalties. The US has relied on executive orders, voluntary standards, and market-led development, with the Trump administration actively working to preempt state-level regulation. EO 14409 is the first meaningful convergence point — a US administration acknowledging that frontier AI capabilities require federal engagement, even within a deregulatory framework.

5. Is there a global AI governance framework?

At present, no binding global AI governance framework exists. The Council of Europe's Framework Convention on Artificial Intelligence, opened for signature in September 2024, is the closest — legally binding, covering human rights, democracy, and rule of law, and open beyond the Council's 46 members. The G7 Hiroshima AI Process, OECD AI Policy Observatory, and UN AI Advisory Body have produced principles and best practices with no enforcement mechanisms comparable to FATF. Building enforceable international AI standards will require political coordination that no multilateral body has yet demonstrated.

This is some text inside of a div block.
Subscribe and stay up to date with our insights
No items found.