Skip to main content

Panorama regulatorio global

Regulación de la IA en el mundo

Cómo el Reglamento IA europeo se compara con los marcos regulatorios de otras jurisdicciones.

Verified against Regulation (EU) 2024/1689 — 27 August 2026

El motor de AZComply cubre el Reglamento IA europeo en su totalidad — la normativa de IA más completa del mundo.

European Union

EU AI Act

Vigente

Regulation (EU) 2024/1689 — the world's first comprehensive, binding AI legal framework. Establishes a risk-based classification system covering all AI systems placed on the EU market or affecting EU persons. As amended by the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), which extended high-risk deadlines and added new prohibited practices.

Fecha de entrada en vigor: August 1, 2024

Enfoque de riesgo
Four-tier risk pyramid: Prohibited (Article 5), High-Risk (Annex III), Limited Risk (Article 50), Minimal Risk. Plus a separate GPAI track for foundation models.
Sanciones
Up to €35M or 7% of global annual turnover for prohibited practices; up to €15M or 3% for high-risk violations; up to €7.5M or 1.5% for misinformation to authorities.
Alcance extraterritorial
Strong extraterritorial reach — applies when AI output is used in the EU, regardless of provider location.
Características clave
  • Deterministic risk-based classification across 4 levels
  • Amended by Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) — Annex III high-risk compliance 2 Dec 2027; Annex I product-embedded 2 Aug 2028; new Art. 5.1.i/j prohibitions (nudifier AI, AI-generated CSAM) effective 2 Dec 2026
  • Annex III lists 8 high-risk sectors including biometrics, employment, critical infrastructure
  • GPAI obligations with systemic risk threshold at 10^25 FLOPs
  • Mandatory technical documentation, human oversight, transparency
  • Fundamental Rights Impact Assessment (Article 27) for deployers
  • EU AI Office as central supervisory authority
  • EU-wide public database for high-risk AI systems (Article 71)
  • AI literacy obligations for all operators (Article 4)

United Kingdom

UK AI Safety

Voluntario

Pro-innovation, principles-based approach administered by sector-specific regulators. The AI Safety Institute (now DSIT) focuses on frontier model evaluation. No single binding AI Act equivalent; sector regulators (FCA, ICO, CMA) apply existing legislation to AI.

Enfoque de riesgo
No formal tiered risk classification system. Sector regulators assess risk within their own frameworks.
Sanciones
No AI-specific penalties. Enforcement via existing sectoral legislation (FCA, ICO, CMA fines apply in respective domains).
Alcance extraterritorial
Limited extraterritorial reach based on existing UK GDPR and sector-specific rules.
Características clave
  • Pro-innovation stance — no binding AI Act
  • AI Safety Institute leads frontier model evaluation (Bletchley Park legacy)
  • Cross-sector AI principles: safety, security, fairness, accountability, contestability, redress
  • ICO guidance on data protection implications of AI
  • FCA guidance on AI in financial services
  • Regulatory sandbox for AI innovation
  • Voluntary AI Code of Practice for general-purpose AI

United States

US AI Framework

Voluntario

Executive Order 14110 (October 2023) directed federal agencies on safe AI development. NIST AI Risk Management Framework (AI RMF 1.0) provides voluntary guidance. No federal AI Act; sector-specific rules apply (FDA for medical AI, banking regulators for fintech, etc.).

Fecha de entrada en vigor: October 30, 2023

Enfoque de riesgo
No binding federal risk tiers. NIST AI RMF provides voluntary risk management guidance across four functions: Govern, Map, Measure, Manage.
Sanciones
No AI-specific federal penalties. FTC enforcement powers apply to unfair/deceptive AI practices. Sector regulators (FDA, OCC, CFPB) enforce in respective domains.
Alcance extraterritorial
No extraterritorial AI-specific reach. Standard US jurisdictional rules apply.
Características clave
  • EO 14110 directed NIST, agencies on AI safety standards
  • NIST AI RMF 1.0 (2023) — voluntary governance framework
  • NIST Generative AI Profile (NIST AI 600-1) for GenAI risks
  • Sector-specific guidance: FDA for AI/ML medical devices (predetermined change control)
  • FTC enforcement on deceptive AI claims
  • State-level legislation active: California SB 1047, Colorado AI Act, Texas HB 149
  • No federal pre-market approval for most AI systems

China

China AI

Vigente

China has enacted three major AI regulations: Algorithm Recommendation Management Provisions (2022), Deep Synthesis (Deepfake) Provisions (2023), and Interim Measures for Generative AI Services (2023). Additional draft regulations on facial recognition and AI security assessment are in progress.

Fecha de entrada en vigor: Multiple (2022-2023)

Enfoque de riesgo
Security assessment required for AI services with "public opinion attributes" or "social mobilization capability." Generative AI services face specific content obligations.
Sanciones
Fines up to RMB 100,000 (approx. €13,000) for data-related violations. Potential service suspension and security assessment denial. CAC (Cyberspace Administration of China) enforcement.
Alcance extraterritorial
Applies to services accessed by users in China, including foreign providers.
Características clave
  • Algorithm Recommendation Provisions (2022) — transparency, opt-out rights
  • Deep Synthesis Provisions (2023) — deepfake labelling, watermarking
  • Generative AI Interim Measures (2023) — content obligations, security assessment
  • CAC registration required for public-facing generative AI
  • Training data must comply with data security and personal information laws
  • AI must align with "socialist core values"
  • Security assessment for AI with "public opinion formation" or "social mobilization" capability

Canada

AIDA (C-27)

Propuesto

AIDA is Part 3 of Bill C-27 (Digital Charter Implementation Act, 2022). It establishes a risk-based framework for AI systems, focusing on "high-impact AI systems." Bill C-27 stalled in Parliament; the incoming government may revise or replace it.

Enfoque de riesgo
Risk-based: "High-impact" AI systems face core obligations. Definition of "high-impact" to be set by regulation, expected to align broadly with Annex III categories.
Sanciones
Proposed: up to C$25M or 5% of global revenues for intentional violations. C$10M or 3% for non-intentional. Criminal penalties for reckless high-impact AI harm.
Alcance extraterritorial
Applies in the context of international and interprovincial trade. Foreign providers offering services in Canada would be captured.
Características clave
  • Part of Bill C-27 alongside CPPA (consumer privacy reform)
  • Focus on high-impact AI systems — definition by regulation
  • Mandatory impact assessment, risk mitigation, and anomaly monitoring
  • Transparency obligations including making assessments publicly available
  • Designated AI systems face additional human oversight requirements
  • AI and Data Commissioner to be established
  • Criminal penalties for reckless deployment causing serious harm

Brazil

Brazil AI (PL 2338)

Propuesto

Bill 2338/2023, approved by the Brazilian Senate in November 2024. Now pending in the Chamber of Deputies. Risk-based approach inspired by the EU AI Act, with adaptations for Brazil's digital economy context and constitutional framework.

Enfoque de riesgo
Two-tier risk system: excessive-risk (prohibited) and high-risk systems face stringent obligations. Risk categories broadly align with EU AI Act sectors.
Sanciones
Proposed: up to R$50M (approx. €9M) or 2% of Brazilian revenues. Stricter penalties for systemic violations. National Data Protection Authority (ANPD) enforcement.
Alcance extraterritorial
Applies when AI output affects persons located in Brazil, regardless of where processing occurs.
Características clave
  • Approved by Senate November 2024; pending Chamber of Deputies
  • Two risk tiers: excessive-risk (prohibited) and high-risk
  • Algorithmic Impact Assessment (AIA) for public sector high-risk AI
  • Transparency: users must be informed of AI interaction
  • Human review right for automated decisions affecting rights
  • ANPD (data protection authority) as primary AI enforcer
  • Special protections for vulnerable groups including children and workers

Regulatory landscape comparison — information only. This page describes publicly available regulatory frameworks and does not constitute legal advice. Regulatory status and requirements change frequently; verify current requirements with qualified counsel.

Regulación de la IA en el mundo | AZComply