Brazil
◆Binding
Binds Suppliers of information-technology products or services (including internet application providers, social networks, app stores, electronic games and child-monitoring products) that are directed at children and adolescents or likely to be accessed by them, offered in Brazilian territory, including foreign companies, which must keep a legal representative in Brazil (Art. 40). Art. 39 modulates the duties in Arts. 6, 17, 18, 19, 20, 27, 28, 29, 31, 32 and 40 by the product's characteristics and functionalities, the provider's degree of interference over content, user numbers and size, and exempts editorially-controlled services and licensed-content providers that meet the four conditions in Art. 39 s.1. Impact tier: all entities, modulated by size and degree of content control.. Providers of information-technology products or services directed at, or likely accessed by, children and adolescents must give parents control over personalised recommendation systems, including the option to switch them off, and must regularly review the artificial-intelligence tools in the service with the participation of specialists and competent bodies against technical criteria that ensure their safety and suitability for use by minors, with non-essential functionalities capable of being disabled. Behavioural profiling of child and adolescent users for advertising is prohibited, as is profiling-based ad targeting and the use of emotional analysis, augmented, extended or virtual reality for that purpose. Where content is removed, the provider must tell the user whether the content was identified by human or automated analysis.
Lei 15.211/2025 ("ECA Digital"), sanctioned 17 September 2025 and published DOU 17.9.2025 extra edition. Art. 41-A originally set entry into force at six months after publication (inserted by MP 1.319/2025); the version now in force, inserted by Lei 15.352/2026, fixes the date expressly: "Esta Lei entra em vigor em 17 de março de 2026." Scope call 2026-08-14: kept in the tracker because the statute imposes express algorithmic-system duties rather than only platform-safety duties — Art. 17 s.4 V (control over personalised recommender systems with an off switch as a default parental-supervision setting), Art. 17 s.4 VIII (regular expert review of AI tools in the service), Art. 30 II (disclosure of whether a removal decision came from human or automated analysis), Art. 22 (ban on profiling for ad targeting and on emotional analysis / AR / XR / VR for that purpose) and Art. 26 (ban on building behavioural profiles of minors from personal, group or collective data, including data obtained in age verification, for advertising). Art. 24 s.3 age-assurance and Art. 27 automated illicit-content detection duties feed the separate transparency-report obligation tracked as br-lei15211-art31-report. Enforcement: Art. 34 gives the autonomous administrative authority for the protection of children's and adolescents' rights in the digital environment supervisory and complementary-rulemaking power; Decreto 12.622/2025 designates the ANPD as that authority and Decreto 12.880/2026 (DOU 18.3.2026 extra edition) is the implementing regulation. Distinct from br-lgpd-art20, which is a data-subject right under the LGPD.
Stated maximum penalty — Art. 35: warning with up to 30 days to take corrective measures; simple fine of up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped in total at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. Fines and warnings are applied by the ANPD; suspension and prohibition by the Judiciary (Art. 35 s.5) and enforced if needed by blocking orders to connectivity providers, IXPs and DNS resolvers (Art. 35 s.6). A foreign company's Brazilian branch or establishment is jointly liable for the fine (Art. 35 s.2); fine amounts are indexed annually to the IPCA (Art. 35 s.4).
Brazil
◆Binding
Binds Internet application providers directed at or likely accessed by children and adolescents with more than 1,000,000 registered users in that age band with an internet connection in Brazilian territory. Exempt: providers below that threshold, and editorially-controlled services and licensed-content providers meeting the four conditions in Art. 39 s.1 (Despacho Decisório CD/ANPD 122/2026 item VII). Impact tier: enterprise.. Internet application providers directed at, or likely accessed by, children and adolescents with more than 1,000,000 registered users in that age band connecting from Brazil must publish semi-annual reports in Portuguese on their own website. The report must cover the complaint channels and investigation systems, the number of complaints received, the volume of content and account moderation by type, the measures used to identify child accounts on social networks under Art. 24 s.3 and to identify illicit acts under Art. 27, technical improvements for personal-data protection and privacy and for ascertaining parental consent under LGPD Art. 14 s.1, and the methods used and results of impact assessments and of the identification and management of risks to the safety and health of children and adolescents. Providers must also give academic, scientific, technological, innovation and journalistic institutions free access to the data needed to research the service's impact on minors.
Art. 31 of Lei 15.211/2025 has been in force since 17 March 2026 (Art. 41-A as amended by Lei 15.352/2026), but the statute only says the reports are semi-annual and sets no publication date. Despacho Decisório CD/ANPD 122/2026 (DOU 11.8.2026, Section 1, p. 59) fixes the calendar until specific regulation supervenes: the time runs from entry into force on 17 March 2026; the first report covers 1 January to 30 June 2026, and providers without data for January and February may limit it to 17 March to 30 June 2026; the first report must be published by 17 September 2026 (item III); from the second report the periods follow the civil semesters, published by 1 August for the first semester and by 1 February for the second (item IV). Art. 45 of Decreto 12.880/2026 adds, under Art. 31 II, the number of notifications received by category and proportional data on how they were followed up. Art. 47 of the decree requires the child-safety-and-health impact assessment behind Art. 31 VII, with a plain-language summary made public, and lets an ANPD act set its minimum content and periodicity. The ANPD recommends emailing a copy of each report to monitoramento@anpd.gov.br at publication (item VIII). Tracked separately from br-lei15211-eca-digital because 17 September 2026 is a distinct near-term deadline.
Stated maximum penalty — Art. 35: warning with up to 30 days to correct; simple fine up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. ANPD applies the warning and fine (Art. 35 s.5).
China
◆Binding
Binds Any provider applying algorithmic recommendation technology to supply internet information services within the territory of the PRC (Art. 2). 'Applying algorithmic recommendation technology' is defined as using generative/synthetic, personalised push, ranking and selection, retrieval and filtering, or scheduling and decision-making algorithms to provide information to users — a definition wide enough to cover feeds, search ranking, content moderation filters and platform dispatch systems, not only recommender feeds. The filing, disclosure-number and security-assessment duties in Arts. 24, 26 and 27 bind only the subset of providers with public-opinion attributes or social-mobilisation capacity. Impact tier: all entities.. Providers of internet information services that use recommendation algorithms must tell users conspicuously that an algorithmic recommendation service is being provided and publicise its basic principles, purpose and main operating mechanisms (Art. 16); offer an option not targeted at the user's personal characteristics or a convenient way to switch the recommendation service off, and let users select or delete the personal-characteristic tags used for recommendation (Art. 17); periodically review, assess and verify the algorithm's mechanisms, models, data and outputs, and not deploy models that induce addiction or excessive consumption (Art. 8); and label unlabelled algorithmically generated or synthesised information before further transmission (Art. 9). Providers with public-opinion attributes or social-mobilisation capacity must additionally file with the CAC internet information service algorithm filing system within 10 working days of starting service — submitting the provider name, service form, application field, algorithm type, algorithm self-assessment report and the intended public-disclosure content — file changes within 10 working days and deregister within 20 working days of termination (Art. 24), display the filing number and a link to the disclosure on their site or app (Art. 26), and carry out a security assessment (Art. 27). Sector rules also apply: protection duties for minors (Art. 18), the elderly (Art. 19), gig workers subject to algorithmic work dispatch (Art. 20), and a ban on unreasonable differential treatment of consumers on price or other transaction terms — algorithmic price discrimination (Art. 21).
Commencement is on the face of the instrument: Art. 35 states the Provisions take effect 1 March 2022, and the promulgation order records adoption at the 20th CAC executive meeting of 2021 on 16 November 2021, agreement by MIIT, the Ministry of Public Security and SAMR, and signature on 31 December 2021 (published 4 January 2022) as Order No. 9 of the four departments. Full Chinese text of Arts. 1-35 read at the cited CAC page. Distinct from, and cumulative with, the CAC instruments already tracked: cn-pipl-art24 is the statutory personal-information basis for the Art. 17 off-switch, while these Provisions are the operative administrative regime (filing system, self-assessment report, filing number display). Where a service also generates or synthesises content, cn-deep-synthesis, cn-genai-interim and cn-ai-labelling apply in parallel. Note npc.gov.cn is http-only; this instrument is a departmental rule (bumen guizhang), so the CAC publication is the authoritative text.
Stated maximum penalty — Art. 31: for breach of Arts. 7, 8, 9(1), 10, 14, 16, 17, 22, 24 or 26, where no other law or administrative regulation provides otherwise — warning, circulated criticism and an order to rectify within a time limit; if rectification is refused or the circumstances are serious, an order to suspend information updates plus a fine of RMB 10,000 to 100,000, with public-security penalties or criminal liability where applicable. Art. 33: obtaining a filing by concealment or false material means revocation of the filing, warning, circulated criticism and, in serious cases, suspension of information updates plus a fine of RMB 10,000 to 100,000. Art. 32 routes breaches of Arts. 6, 9(2), 11, 13, 15, 18, 19, 20, 21, 27 and 28(2) to the penalties of the underlying laws (e.g. PIPL Art. 66, up to RMB 50,000,000 or 5% of turnover, and the Minors Protection Law). Enforced by the CAC with MIIT, public-security and market-regulation authorities.
UK
◆Binding
Binds Information Commissioner (duty to prepare the code); indirectly all UK controllers and processors developing or using AI or making automated decisions under the UK GDPR and DPA 2018 (except Part 4, intelligence services). Requires the Information Commissioner to prepare a statutory code of practice on good practice in processing personal data for (a) developing and using AI and (b) automated decision-making under Arts. 22C(1) UK GDPR / s.50C(1) DPA 2018. The code must include guidance on children's personal data. Once issued, the code is admissible in evidence and regulators and courts must take it into account, so it will set the compliance benchmark for UK controllers developing or deploying AI.
Made 16 April 2026, laid before Parliament 21 April 2026, in force 12 May 2026 (reg. 1(2): 21 days after laying). Powers: DPA 2018 ss.124A(1)-(2) and 124B(11), inserted by Data (Use and Access) Act 2025 ss.92(2) and 93. Reg. 3 modifies the s.124B panel requirement so the panel must not consider or report on any aspect of the code relating to national security. The code itself has NOT yet been issued or consulted on — no publication date is set in the instrument, so the code's own commencement is date TBD; the ICO lists 'Code of Practice on AI and Automated Decision Making' among its current AI work areas. The Explanatory Note states no significant sector impact from the instrument itself; the impact falls when the ICO produces the code (for which the ICO must produce its own impact assessment). Extends to England and Wales, Scotland and Northern Ireland. Companion to uk-duaa-adm.
Stated maximum penalty — No penalty in the instrument itself; the resulting code is enforced through UK GDPR/DPA 2018 powers (up to £17.5M or 4% of global annual turnover, whichever is higher)
UK
◆Binding
Binds Individual developers, distributors, and corporate bodies (criminal offences); Ofcom-regulated platforms (OSA priority-content duty). Criminalises making, adapting, possessing, supplying, or offering to supply AI models optimised to generate CSAM (up to 5 years imprisonment). Separately criminalises AI “nudification” tools/deepfake intimate image generators. Upgrades AI-generated intimate image creation to priority offences under the Online Safety Act; Ofcom-regulated platforms must prevent and remove such content (up to £3M penalty for non-compliance).
Royal Assent: 29 April 2026 (2026 c.20). Section 99 (purported intimate image generators) and related provisions commenced 29 June 2026 via UKSI 2026/689 (Commencement No. 1). CSAM generator offences (Pt.3 Ch.3) commenced on same SI.
Stated maximum penalty — 5 years imprisonment (CSA/deepfake AI generator offences); £3M Ofcom fine (platform intimate image duty)
US · TN
◆Binding
Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.
Effective 2026-05-22, the date carried in the "Effective date(s)" field of the Tennessee General Assembly bill-status record; Section 4 of Public Chapter 1082 reads "This act takes effect upon becoming a law, the public welfare requiring it" (publications.tnsosfiles.com/acts/114/pub/pc1082.pdf), so there is no deferred application. The same record lists the governor's signature action on 2026-05-27; the enrolled chapter's approval stamp is a handwritten scan and is not machine-readable, so the 05/22 effective date is taken from the legislature's own field rather than reconstructed from the signature. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.
Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators
US · HI
◆Binding
Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.
Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.
Stated maximum penalty — $1,000/violation up to $1,000,000/operator
US · CT
◆Binding
Binds Operators who provide or operate an artificial intelligence companion for users in Connecticut, with heightened duties where the user is under 18. Operators of AI companions have until 1 Jan 2027 before disclosure, crisis-referral and minor-protection duties bite.
Public Act No. 26-15 ss 4-6, each expressly '(Effective January 1, 2027)'. s 5 sets baseline operator duties; s 6 adds under-18 duties, including a clear and conspicuous statement at the start of each interaction that the companion is not a licensed mental health professional, bars on romantic/erotic interaction with minors, bars on discouraging a minor from seeking mental health services or adult help, and bars on manipulative engagement-extension techniques. Violations of ss 5 and 6 are unfair or deceptive trade practices enforced solely by the Attorney General.
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)
US · WA
◆Binding
Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.
Disclosures every 3 hours (all users) or 1 hour (minor users).
Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)
US · OR
◆Binding
Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.
Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees
US · CO
◆Binding
Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.
Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01.
Stated maximum penalty — CO AG enforcement
US · GA
◆Binding
Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.
Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)
US · ID
◆Binding
Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.
Modeled on Nebraska LB 525. Signed 2026-04-01.
Stated maximum penalty — Idaho AG enforcement (amount TBD)
US · NE
◆Binding
Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.
Signed April 14, 2026; operative July 1, 2027 (sections 12–18).
Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only
US · CT
◆Binding
Binds Covered operators of covered platforms serving Connecticut users who are under eighteen. Covered platform operators have until 1 Jan 2028 before personalised feed and related restrictions apply to users under 18.
Public Act No. 26-15 s 39, expressly '(Effective January 1, 2028)'. Bars a covered operator from serving a covered minor a personalised recommendation feed based on information associated with the user or the user's device unless one of the listed conditions is met, including commercially reasonable and technically feasible age determination or verifiable parental consent. s 39(g) deems violations of subsections (b)-(e) unfair or deceptive trade practices under Conn. Gen. Stat. s 42-110b(a).
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)