# wheresthe.ai > A sourced registry of where AI is regulated, registered and approved: 129 AI laws, regulations, guidelines and bills across 33 jurisdictions, China's 1,115 filed generative-AI services in English, and 1,614 FDA-cleared AI medical devices by company country. Every record links to its official source. Data as of 2026-10-07. Not legal advice. Agents can use this site three ways, none needing a key: - **MCP server:** https://wheresthe.ai/mcp (Streamable HTTP). Tools: search_rules, get_rule, list_jurisdictions, get_jurisdiction, upcoming_deadlines, recent_changes, compare_jurisdictions, search_china_ai_registry, search_fda_ai_devices, country_ai_indicators. - **JSON API:** https://wheresthe.ai/api/v1/index.json (OpenAPI: https://wheresthe.ai/openapi.json). - **Markdown:** append `index.md` to any rule or jurisdiction URL, e.g. https://wheresthe.ai/j/in/index.md. Please credit "Source: wheresthe.ai" and link the rule page when you use a record. ## Jurisdictions - [India](https://wheresthe.ai/j/in/index.md): India has no AI-specific statute; it governs AI through principle-based MeitY guidelines, binding deepfake-labelling duties in the IT Rules, the phased DPDP privacy regime and sector regulators (RBI, SEBI, ICMR). - [China](https://wheresthe.ai/j/cn/index.md): China regulates AI through binding CAC rules built on mandatory algorithm filing and security assessment, plus mandatory content-labelling rules and standards, and has put a comprehensive AI law on its 2026 legislative plans. - [Japan](https://wheresthe.ai/j/jp/index.md): Japan's AI Promotion Act (in force 2025) is a light-touch framework law without fines, operationalised through a Cabinet AI Basic Plan and voluntary government guidelines. - [South Korea](https://wheresthe.ai/j/kr/index.md): Korea's AI Basic Act took effect on 22 Jan 2026 with high-impact AI, labelling and domestic-representative duties, but MSIT has deferred fines and investigations for at least a year. - [Singapore](https://wheresthe.ai/j/sg/index.md): Singapore relies on voluntary model governance frameworks and testing tools (including the first agentic-AI framework) plus targeted laws on election deepfakes and online harms, with MAS AI risk guidelines for finance pending. - [United Arab Emirates](https://wheresthe.ai/j/ae/index.md): The UAE has no federal AI law; it relies on a national AI strategy and a non-binding AI Charter, with binding AI-specific data rules only in the DIFC free zone, and created a Federal Authority for AI and Data in June 2026. - [Saudi Arabia](https://wheresthe.ai/j/sa/index.md): Saudi Arabia has no AI statute; SDAIA steers AI through ethics principles and guidelines (including 2026 deepfake guidance), alongside the Personal Data Protection Law and a draft Global AI Hub Law. - [Vietnam](https://wheresthe.ai/j/vn/index.md): Vietnam's risk-based Law on Artificial Intelligence took effect on 1 Mar 2026, with an implementing decree from 1 May 2026 and transition deadlines for existing systems in 2027. - [Indonesia](https://wheresthe.ai/j/id/index.md): Indonesia has only non-binding AI ethics guidance and an OJK banking AI governance guide; presidential regulations on a national AI roadmap and AI ethics are still in preparation. - [Australia](https://wheresthe.ai/j/au/index.md): Australia decided in its December 2025 National AI Plan to rely on existing laws rather than mandatory AI guardrails, adding an AI Safety Institute, a binding AI policy for federal agencies and new privacy transparency duties for automated decisions from Dec 2026. - [Taiwan](https://wheresthe.ai/j/tw/index.md): Taiwan's AI Basic Act took effect on 14 Jan 2026 as a principles-based framework law, with MODA's risk classification framework (Jul 2026) guiding sector regulators' forthcoming rules. - [United States (federal)](https://wheresthe.ai/j/us/index.md): No comprehensive federal AI statute: Washington governs AI through executive orders, OMB rules for federal agencies, export controls and sector regulators, while the White House and DOJ try to preempt or litigate against state AI laws. - [California](https://wheresthe.ai/j/us-ca/index.md): The most active US AI rule-maker: a frontier-model transparency law (SB 53), training-data disclosure, CCPA automated-decision rules, companion-chatbot and provenance laws are in force, and a 2026 wave adds child-safety audits, workplace ADS limits and an AI auditor regime. - [Colorado](https://wheresthe.ai/j/us-co/index.md): Colorado repealed its first-in-the-nation risk-based AI Act (SB 24-205) before it ever applied and replaced it with a narrower automated-decision disclosure law (SB 26-189) effective 1 Jan 2027, whose enforcement is paused by a stipulated federal-court stay (27 Apr 2026) in the suit brought by xAI and joined by the DOJ. - [Texas](https://wheresthe.ai/j/us-tx/index.md): The Texas Responsible AI Governance Act (TRAIGA) has applied since 1 Jan 2026: it bans a short list of intentional harmful AI uses, imposes disclosure duties on government and health-care AI, and creates a 36-month regulatory sandbox, enforced only by the Attorney General. - [New York](https://wheresthe.ai/j/us-ny/index.md): New York has an AI-companion safeguard law in force, New York City's bias-audit rule for hiring tools, and the RAISE Act on frontier-model safety (overhauled in March 2026 to track California's SB 53) taking effect 1 Jan 2027. - [Illinois](https://wheresthe.ai/j/us-il/index.md): Illinois regulates AI in hiring (Human Rights Act amendment in force 1 Jan 2026), bans AI-delivered therapy, and in July 2026 enacted a frontier-model safety law with mandatory annual third-party audits. - [Utah](https://wheresthe.ai/j/us-ut/index.md): Utah relies on a light-touch AI Policy Act (generative-AI disclosure in consumer and regulated-occupation settings, plus a state 'Learning Lab' sandbox) and a mental-health-chatbot law; 2026 bills on AI transparency and companion chatbots failed after White House opposition. - [European Union](https://wheresthe.ai/j/eu/index.md): The AI Act is partly in force (bans, AI literacy, GPAI and Article 50 transparency apply), and the July 2026 Digital Omnibus pushed high-risk obligations to Dec 2027/Aug 2028 while adding nudifier and CSAM bans from Dec 2026. - [United Kingdom](https://wheresthe.ai/j/gb/index.md): No AI bill (none in the May 2026 King's Speech); AI is governed by existing regulators plus targeted criminal laws on intimate deepfakes and nudification tools and reformed automated-decision rules under the Data (Use and Access) Act 2025. - [France](https://wheresthe.ai/j/fr/index.md): The EU AI Act applies directly; the bill designating the CNIL and sector regulators as AI Act authorities passed the Senate in Feb 2026 and awaits the National Assembly. - [Germany](https://wheresthe.ai/j/de/index.md): The EU AI Act applies directly and the KI-MIG implementation law in force since 29 Jul 2026 makes the Bundesnetzagentur the central AI supervisor. - [Italy](https://wheresthe.ai/j/it/index.md): Italy has its own national AI law (Law 132/2025, in force 10 Oct 2025) layered on the EU AI Act, with AgID and ACN as AI authorities and a criminal deepfake offence. - [Spain](https://wheresthe.ai/j/es/index.md): The EU AI Act applies directly; AESIA is operating as a dedicated AI supervisor and an organic law setting AI Act sanctions and authorities has been in Congress since June 2026. - [Canada](https://wheresthe.ai/j/ca/index.md): With AIDA dead since Jan 2025, Canada is regulating AI through its June 2026 'AI for All' strategy, a privacy bill (C-36) with automated-decision transparency, criminal deepfake law, federal and financial-sector directives and Ontario hiring rules. - [Brazil](https://wheresthe.ai/j/br/index.md): The Senate-passed AI bill PL 2338/2023 is still awaiting a rapporteur's report in a Chamber special committee, while binding TSE rules on AI labelling and deepfakes govern the October 2026 elections. - [Mexico](https://wheresthe.ai/j/mx/index.md): Mexico has no AI-specific law; dozens of initiatives, including a constitutional amendment and a general AI law, remain pending in Congress. - [Chile](https://wheresthe.ai/j/cl/index.md): Chile's EU-style AI bill passed the Chamber in Oct 2025 but is being rewritten as a lighter enabling law in the Senate; a new data law with automated-decision rights takes effect 1 Dec 2026. - [Peru](https://wheresthe.ai/j/pe/index.md): Peru has an AI promotion law (Law 31814) whose 2025 regulation adds risk tiers, prohibited uses and phased high-risk duties. - [Nigeria](https://wheresthe.ai/j/ng/index.md): Nigeria has a draft national AI strategy and a pending digital economy bill with AI deployment rules that had not received presidential assent by Oct 2026. - [Kenya](https://wheresthe.ai/j/ke/index.md): Kenya relies on its 2025-2030 National AI Strategy and Data Protection Act; an EU-style AI Bill 2026 has been published in the Senate but not enacted. - [South Africa](https://wheresthe.ai/j/za/index.md): South Africa has no AI policy or law in force after the Minister withdrew the draft National AI Policy in April 2026 over fictitious citations. - [International / multilateral](https://wheresthe.ai/j/intl/index.md): The Council of Europe AI Convention is signed but not yet in force (EU concluded it in Apr 2026); the UN Scientific Panel and Global Dialogue on AI Governance began work in 2026, alongside voluntary G7/OECD reporting. ## Registries - [China CAC generative AI registry (JSON)](https://wheresthe.ai/api/v1/registries/china-cac.json): 1115 filed and 731 registered services, as of 2026-09-23 - [FDA AI-enabled devices by country (JSON)](https://wheresthe.ai/api/v1/registries/fda.json): 1614 devices, list as of 2026-09-04 ## Data - [All rules (JSON)](https://wheresthe.ai/api/v1/rules.json) - [Upcoming deadlines (JSON)](https://wheresthe.ai/api/v1/deadlines.json) - [Recent changes (JSON)](https://wheresthe.ai/api/v1/changes.json) - [Methodology and sources](https://wheresthe.ai/methodology/) - [Use cases: who uses this and how](https://wheresthe.ai/use-cases/) ## Optional - [Everything in one file](https://wheresthe.ai/llms-full.txt)