ApexClaw
Home › Regions
REGIONAL GOVERNANCE

AI agent governance by region

AI agents are not governed by one law anywhere. They are governed by the intersection of AI-specific instruments, data protection, and sectoral supervision — and that intersection differs by region. These pages set out what actually binds, with named instruments and dates.

Get an Agent Trust Gap Brief

There is no global AI agent regulation. There are seven answers.

Every regime below governs agents differently — some by naming autonomy directly, most by extension from general AI, data protection or sectoral supervision. What they converge on is evidence: an action taken by software must be attributable to a policy and a person, and reconstructable afterwards.

RegionInstruments that matterHow agents are governed
European UnionAI Act, Digital Omnibus deferral, DORA, GDPR Art. 22, Italy 132/2025, AESIARisk tier and role determine duties
United StatesTRAIGA affirmative defence, CO SB 26-189, CA transparency, NYDFS, SR 11-7State patchwork over federal sectoral supervision
Middle EastDIFC Reg 10 (enforced 2026-01-01), Autonomous Systems Officer, UAE federal, SDAIARegulates autonomous systems directly
CanadaAIDA did not pass; OSFI E-23 from May 2027, PIPEDA, Quebec Law 25Model risk management is the operative regime
Asia-PacificSingapore agentic AI framework, Korea AI Basic Act, Japan guidance, APRAMost agent-specific guidance published anywhere
Latin AmericaBrazil PL 2338 (in progress), LGPD in forceData protection binds today, AI law is coming
United KingdomNo AI act. FCA/PRA, ICO, UK GDPR, OfcomRegulator-led by sector remit

Last verified 2026-08-07. This is a summary of published instruments for orientation, not legal advice. Obligations depend on your role, deployment and sector — confirm against the primary text and your counsel.

What transfers across every jurisdiction

Regimes differ on thresholds, definitions and timing. They do not differ much on what they will ask you to produce.

Attribution

Which agent, acting for which principal, under whose authority. An action nobody owns is a finding in every jurisdiction.

Authorisation

Which policy permitted this action, evaluated when. Not a policy document — a decision record tied to the specific action.

Reconstruction

What actually happened, verifiable after the fact. Logs that cannot be shown to be unaltered are weak evidence everywhere.

Common questions

Which jurisdiction regulates AI agents most directly?

DIFC Regulation 10 and Singapore's agentic AI framework are the two that address autonomous systems as a distinct category rather than extending general AI rules. Most other regimes govern agents by analogy.

Is there a single global compliance approach for AI agents?

No, and anyone selling one is overstating. What does transfer is the evidence: per-action records showing what was attempted, which policy applied, who approved it, and what happened. Every regime asks for some version of that.

What changed in the EU in 2026?

The Digital Omnibus package deferred and simplified parts of the AI Act's application. Deferral is not repeal — obligations already in force remained and deferred ones are still scheduled.

Does Canada have an AI act?

No. AIDA did not pass. For federally regulated financial institutions the operative deadline is OSFI Guideline E-23 in May 2027.

Where should a multinational start?

With an applicability register: which legal entity, in which jurisdiction, running which agent, under which instrument. Most compliance failures we see are register failures, not control failures.

The control set barely changes across jurisdictions; the examiner does. Build for the action inventory and every regime maps onto it.
Julian Joseph, founder of ApexClaw