Skip to content

Global AGI Regulations in 2026 (September 2026 Update)

As of September 2026, AGI is not a single regulated object. This update maps EU GPAI enforcement, U.S. voluntary federal rules plus California SB 53, China CAC filing, UK sectoral oversight, Japan and Korea statutes, and OECD soft law.

Share
Global AGI Regulations: September 2026 Update

As of September 2026, nobody regulates "AGI" as a single statutory object. What exists instead is a patchwork that hits general-purpose and frontier model providers through compute thresholds, documentation duties, filing regimes, and voluntary government testing.

This September update maps the concrete regimes that matter for labs, cloud providers, and deep-tech investors right now: the EU AI Act after the July 2026 Omnibus, the U.S. federal voluntary framework plus California SB 53, China's CAC filing and labeling stack, the UK's sectoral approach, Japan and Korea's 2025-2026 statutes, Canada's stalled federal bill, and the OECD / Council of Europe soft-law layer. Claims are date-stamped. Unverified "2026 AGI bans" are omitted.

Key Takeaways

  • EU GPAI duties apply; Commission fines live since 2 Aug 2026.
  • U.S. federal path stays voluntary under EO 14409 (June 2026).
  • California SB 53 frontier transparency took effect 1 Jan 2026.
  • China runs filing plus labeling, not an AGI statute.
  • No single global AGI license exists as of September 2026.
📌
Scope note: this is a jurisdiction map for frontier / GPAI model providers and their buyers, not a glossary of AGI definitions or a how-to compliance checklist for every Annex III high-risk system.

Jurisdiction snapshot (as of September 2026)

Start with the comparison table, then dig into the regimes that actually bind model weights, training compute, or public-facing generative services.

JurisdictionInstrument that bites frontier / GPAIStatus as of Sep 2026Hard obligation?
EU / EEAAI Act Ch. V GPAI + AI Office enforcement; Omnibus delays some high-risk datesGPAI obligations since 2 Aug 2025; Commission GPAI enforcement powers since 2 Aug 2026Yes (fines up to €15M / 3% turnover for GPAI breaches)
United States (federal)EO 14409 (2 Jun 2026) voluntary covered-frontier framework; NIST/CAISI testingVoluntary pre-release access / cyber benchmarking; explicitly not a licensing regimeNo federal AGI license
CaliforniaTransparency in Frontier AI Act (SB 53 / BPC Ch. 25.1)In force since 1 Jan 2026 for frontier developers above 10^26 FLOPsYes (civil penalties up to $1M per violation)
ChinaGenerative AI Interim Measures (2023); labeling measures (2025); ongoing CAC filing988 generative services filed as of 30 Jun 2026; labeling since 1 Sep 2025Yes (filing, labeling, content rules)
United KingdomSectoral regulators + AI Opportunities Action Plan; no UK AI ActDSIT one-year progress report 29 Jan 2026; ICO / Ofcom / FCA apply existing lawNo dedicated AI Act
JapanAct on Promotion of R&D and Utilisation of AI-related TechnologyFully in force since 1 Sep 2025; promotion + Basic Plan, not EU-style bansSoft / promotional
South KoreaFramework Act on AI Development and Trust FoundationAct No. 20676 (2025), amended Jan 2026; high-impact AI duties in statuteYes (framework statute)
CanadaAIDA (Bill C-27) died; CoE AI Convention signed 11 Feb 2025No federal AIDA reintroduction as of this writing; voluntary generative AI code remainsNo federal AI Act
OECD / G7 / GPAIHiroshima AI Process Code + HAIP Reporting Framework 2.0Voluntary reporting; v2.0 launched 28 May 2026No
Council of EuropeFramework Convention on AI (opened Sep 2024)Signed by EU, US, UK, Canada, Japan and others; needs ratifications to enter into forceTreaty pending entry into force

European Union: GPAI is live, Omnibus moved high-risk dates

The EU remains the only large market with a cross-sector statute that names general-purpose AI models and attaches documentation, copyright, and systemic-risk duties to them.

According to the European Commission's AI Act overview (updated through the 2026 Omnibus), GPAI Chapter V rules became applicable on 2 August 2025. Providers must maintain technical documentation, give downstream information, publish a training-content summary using the Commission template, and respect EU copyright rules. Models presumed to present systemic risk (the Act's compute presumption sits at 10²⁵ FLOPs of training compute) face extra evaluation and incident-reporting duties.

Here's why September 2026 feels different from September 2025. From 2 August 2026, the AI Office's supervision and enforcement powers over GPAI providers apply, including document requests, evaluations, corrective measures, and fines. The Commission's own page states GPAI non-compliance can attract administrative fines of up to €15 million or 3% of worldwide annual turnover (higher ceilings apply to prohibited practices).

The AI Omnibus entered into force on 27 July 2026 (final text in the Official Journal as OJ L 2026/1744). It did not push GPAI or Article 50 transparency dates. It did extend Annex III standalone high-risk obligations to 2 December 2027 and Annex I product-embedded high-risk AI to 2 August 2028. If you sell a frontier base model into the EU, the GPAI clock already started. If you embed that model into certain high-risk products, the Omnibus bought calendar time.

Primary text: Regulation (EU) 2024/1689.

United States: federal voluntary framework, California hard law

Federal: EO 14409 (2 June 2026)

On 2 June 2026 the White House issued Executive Order 14409, Promoting Advanced Artificial Intelligence Innovation and Security. Section 3 directs NSA, CISA, Treasury, and NIST (among others) to build a classified cyber-capability benchmarking process and to designate "covered frontier models."

The same section designs a voluntary developer framework: engage on designation, give the federal government up to 30 days of model access before release to other trusted partners, and help select early-access partners for critical-infrastructure cyber defense. The order expressly says nothing in that section authorizes a mandatory governmental licensing, preclearance, or permitting requirement for developing or releasing AI models.

That means: as of September 2026, Washington's frontier posture is still voluntary access + agency evaluation, not an FAA-style pre-deployment license. Treat press claims of a U.S. "AGI ban" or mandatory federal permit as unverified unless Congress passes a statute.

California: SB 53 frontier transparency (effective 1 January 2026)

California filled part of the federal gap. The Transparency in Frontier Artificial Intelligence Act (Business and Professions Code Chapter 25.1), enacted via SB 53, took effect 1 January 2026. It defines a frontier model by training compute above 10²⁶ FLOPs (higher than the EU systemic-risk presumption) and imposes transparency reports on frontier developers before deployment. "Large frontier developers" (annual revenue above $500 million) must also publish a frontier AI framework and transmit catastrophic-risk assessments on a statutory cadence. Civil penalties can reach $1 million per violation.

Important correction for older decks: California SB 1047 was vetoed in 2024 and is not law. SB 53 is the frontier statute that actually applies in 2026.

💡
Inside Deep Tech's take: the practical U.S. compliance map for a frontier lab in September 2026 is California transparency + voluntary federal evaluation access, not a single national AI Act. Budget legal time for SB 53 disclosures before you budget for a fictional federal license.

China: filing, labeling, and generative-service control

China does not brand a statute "AGI regulation." It regulates generative and deep-synthesis services through the Cyberspace Administration of China (CAC) stack.

The Interim Measures for the Management of Generative AI Services have applied since 15 August 2023. Providers of services with public-opinion or social-mobilization attributes must complete security assessment and algorithm filing. On 1 September 2025, the Measures for Labeling AI-Generated Synthetic Content took effect, requiring explicit labels where applicable and implicit metadata labels.

Filing is not theoretical. CAC's May-June 2026 filing bulletin reported that as of 30 June 2026, 988 generative AI services had completed national filing and 598 applications or functions had completed local registration. If you ship a Chinese-facing generative product, the filing queue is the gate, not a Western AGI definition.

United Kingdom: still no AI Act

As of September 2026 the UK has not enacted an EU-style AI Act. Policy runs through the AI Opportunities Action Plan: One Year On progress report published by DSIT on 29 January 2026, which reported delivery against 38 of 50 plan actions.

Enforcement still sits with existing regulators: the ICO on personal data and automated decision-making, Ofcom on online safety and telecoms security, and the FCA on financial services conduct. Frontier-model safety work continues through the AI Security Institute and voluntary cyber codes rather than a single licensing statute. Watch for a future UK AI Bill, but do not treat one as enacted.

Japan, Korea, and Canada

Japan's Act on Promotion of Research and Development, and Utilisation of AI-related Technology was promulgated on 4 June 2025 and fully entered into force on 1 September 2025. It is a promotion statute: Basic Plan, coordination, and risk-mitigation principles, not a carbon copy of EU prohibited-practice bans.

South Korea's Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (Act No. 20676 of 21 January 2025, amended by Act No. 21311 of 20 January 2026) creates a presidential strategy council and sets out high-impact AI confirmation and business-operator responsibilities. Treat it as a live framework statute with implementing detail still maturing, not as an EU twin.

Canada's proposed Artificial Intelligence and Data Act (AIDA, part of Bill C-27) died on the order paper when Parliament prorogued in January 2025 and has not been reintroduced as of this September 2026 update. Canada signed the Council of Europe AI Framework Convention on 11 February 2025. Signature is not ratification, and the convention enters into force only after enough ratifications accumulate.

OECD, GPAI, and the Council of Europe layer

Soft law still matters for procurement language and investor diligence even when it is not enforceable as statute.

The G7 Hiroshima AI Process International Code of Conduct feeds the OECD-hosted Hiroshima AI Reporting Framework. Version 2.0 launched on 28 May 2026 (OECD announcement). Participation is voluntary for organisations in OECD, GPAI, or OECD AI Recommendation adherent jurisdictions. Submissions by 1 September 2026 feed the next analytical review. GPAI ministers also convened in New Delhi on 20 February 2026 under the integrated OECD/GPAI partnership.

The Council of Europe Framework Convention on AI remains the first dedicated international treaty text on AI and human rights. It is signed widely (including the EU, United States, United Kingdom, Canada, and Japan) but is not yet in force until the ratification threshold is met. Do not cite it as binding domestic law.

Timeline that actually moved the needle

DateWhat happenedWhy labs care
15 Aug 2023China Generative AI Interim Measures applyFiling + content duties for public generative services
1 Aug 2024EU AI Act enters into forceClock starts on phased application
2 Feb 2025EU prohibited practices / AI literacy applyHard bans on listed practices
1 Sep 2025Japan AI promotion Act fully in force; China labeling measures applyJP governance plan; CN explicit/implicit labels
2 Aug 2025EU GPAI Chapter V appliesDocs, training summary, copyright, systemic-risk extras
1 Jan 2026California SB 53 frontier transparency appliesU.S. hard law for 10^26 FLOP developers
2 Jun 2026U.S. EO 14409 signedVoluntary covered-frontier access framework
27 Jul 2026EU AI Omnibus enters into forceHigh-risk dates move; GPAI dates stay
2 Aug 2026EU AI Office GPAI enforcement + Art. 50 transparencyFines and transparency duties go live
2 Dec 2027 / 2 Aug 2028EU Annex III / Annex I high-risk (post-Omnibus)Product and use-case compliance calendars

Why this matters for AI infrastructure buyers

Regulation now tracks training compute, documentation, and release process as much as product UX. That couples policy risk to the same bottlenecks Inside Deep Tech already covers on the hardware side: packaging and memory bandwidth, rack power, and interconnect choice.

If your diligence package already includes The State of Data Centers 2026 and how AI GPUs actually talk, add a one-page jurisdiction matrix for every model you train above 10^25 to 10^26 FLOPs. Capital allocators tracking where deep-tech funding went in 2026 should treat EU GPAI enforcement and California SB 53 as underwriting inputs, not footnotes.

The State of Data Centers 2026
Where AI capex is going, why the grid became the bottleneck, and who pays.

Named downside: what this map does not give you

This update will not tell you whether any specific lab has "achieved AGI." Regulators are not waiting for that philosophical finish line. They are regulating capability proxies (compute, systemic risk, public generative services) and process duties (docs, labels, filings, voluntary evaluations).

It also will not replace counsel. Fine ceilings, extraterritorial reach, open-source carve-outs, and downstream-provider duties turn on facts the public page of a blog cannot litigate. China's filing practice evolves through bulletin lists. U.S. state bills beyond California continue to move. The Council of Europe convention can change status with a handful of ratifications.

Who this is not for: teams shipping narrow, on-prem classical ML with no public generative interface and training compute far below frontier thresholds. Your risk is still privacy, product liability, and sector rules, not GPAI Chapter V.

⚠️
Honest limit: if a LinkedIn thread claims a "global AGI licensing regime" started in 2026, ask for the statute number. As of 10 September 2026, Inside Deep Tech cannot verify any such global license from primary sources.

FAQ

Is there a global AGI law in 2026?

No. As of September 2026 there is no single global AGI statute or license. What exists is a set of national and regional regimes aimed at general-purpose, frontier, or generative systems.

When did EU GPAI enforcement fines become available?

The AI Office's enforcement powers over GPAI providers apply from 2 August 2026, after GPAI obligations themselves applied from 2 August 2025. Check the Commission's AI Act pages and Regulation (EU) 2024/1689 for ceilings and procedures.

Did the 2026 EU AI Omnibus delay GPAI rules?

No. The Omnibus, in force from 27 July 2026, extended certain high-risk Annex III and Annex I dates. GPAI Chapter V and Article 50 transparency timelines were left in place.

Does the United States require a federal license to release a frontier model?

Not under EO 14409. That June 2026 order creates a voluntary covered-frontier access framework and states it does not authorize mandatory licensing or preclearance.

What California law actually applies to frontier models in 2026?

SB 53's Transparency in Frontier Artificial Intelligence Act (BPC Chapter 25.1), effective 1 January 2026. SB 1047 was vetoed in 2024 and is not law.

How does China regulate generative AI services now?

Through CAC interim measures (since August 2023), labeling measures (since September 2025), and ongoing filing. CAC reported 988 filed generative services as of 30 June 2026.

Does the UK have an AI Act yet?

No. As of September 2026 the UK relies on existing regulators and the AI Opportunities Action Plan, with DSIT's one-year progress report published 29 January 2026.

Should startups worry about the Council of Europe AI Convention today?

Treat it as a signed treaty text that is not yet in force pending ratifications. It shapes diplomacy and future implementing laws more than day-one product compliance.


What happens next

The next twelve months will not produce a single AGI constitution. They will produce enforcement samples: first AI Office GPAI actions in the EU, first California SB 53 penalty patterns, more CAC filing cohorts, and whatever voluntary covered-frontier evaluations U.S. agencies actually run under EO 14409.

For operators, Monday looks like this: classify every model by training compute and public release path, map it against EU GPAI, California SB 53, and any China-facing filing duty, then decide whether voluntary U.S. federal evaluation access is a commercial asset or a process cost. The labs that treat regulation as a release-engineering problem will outrun the ones still arguing about AGI definitions.

Deep Tech Funding Hit Records in 2026
Where foundational-tech capital actually went, with sector context for AI infrastructure.