AI agent governance by region
AI agents are not governed by one law anywhere. They are governed by the intersection of AI-specific instruments, data protection, and sectoral supervision — and that intersection differs by region. These pages set out what actually binds, with named instruments and dates.
Get an Agent Trust Gap BriefThere is no global AI agent regulation. There are seven answers.
Every regime below governs agents differently — some by naming autonomy directly, most by extension from general AI, data protection or sectoral supervision. What they converge on is evidence: an action taken by software must be attributable to a policy and a person, and reconstructable afterwards.
| Region | Instruments that matter | How agents are governed |
|---|---|---|
| European Union | AI Act, Digital Omnibus deferral, DORA, GDPR Art. 22, Italy 132/2025, AESIA | Risk tier and role determine duties |
| United States | TRAIGA affirmative defence, CO SB 26-189, CA transparency, NYDFS, SR 11-7 | State patchwork over federal sectoral supervision |
| Middle East | DIFC Reg 10 (enforced 2026-01-01), Autonomous Systems Officer, UAE federal, SDAIA | Regulates autonomous systems directly |
| Canada | AIDA did not pass; OSFI E-23 from May 2027, PIPEDA, Quebec Law 25 | Model risk management is the operative regime |
| Asia-Pacific | Singapore agentic AI framework, Korea AI Basic Act, Japan guidance, APRA | Most agent-specific guidance published anywhere |
| Latin America | Brazil PL 2338 (in progress), LGPD in force | Data protection binds today, AI law is coming |
| United Kingdom | No AI act. FCA/PRA, ICO, UK GDPR, Ofcom | Regulator-led by sector remit |
Last verified 2026-08-07. This is a summary of published instruments for orientation, not legal advice. Obligations depend on your role, deployment and sector — confirm against the primary text and your counsel.
What transfers across every jurisdiction
Regimes differ on thresholds, definitions and timing. They do not differ much on what they will ask you to produce.
Attribution
Which agent, acting for which principal, under whose authority. An action nobody owns is a finding in every jurisdiction.
Authorisation
Which policy permitted this action, evaluated when. Not a policy document — a decision record tied to the specific action.
Reconstruction
What actually happened, verifiable after the fact. Logs that cannot be shown to be unaltered are weak evidence everywhere.
Common questions
Which jurisdiction regulates AI agents most directly?
DIFC Regulation 10 and Singapore's agentic AI framework are the two that address autonomous systems as a distinct category rather than extending general AI rules. Most other regimes govern agents by analogy.
Is there a single global compliance approach for AI agents?
No, and anyone selling one is overstating. What does transfer is the evidence: per-action records showing what was attempted, which policy applied, who approved it, and what happened. Every regime asks for some version of that.
What changed in the EU in 2026?
The Digital Omnibus package deferred and simplified parts of the AI Act's application. Deferral is not repeal — obligations already in force remained and deferred ones are still scheduled.
Does Canada have an AI act?
No. AIDA did not pass. For federally regulated financial institutions the operative deadline is OSFI Guideline E-23 in May 2027.
Where should a multinational start?
With an applicability register: which legal entity, in which jurisdiction, running which agent, under which instrument. Most compliance failures we see are register failures, not control failures.
The control set barely changes across jurisdictions; the examiner does. Build for the action inventory and every regime maps onto it.