Outside the EU AI Act and the United States' sector-by-sector rulebook, every other major economy is writing its own answer to the same question: who gets to decide how AI is built, sold, and used. The UK leans on existing regulators and voluntary principles, China runs a pre-launch registration gate through its cyberspace regulator, Canada lost its flagship AI bill and now governs through privacy law and sector guidance, and Brazil, South Korea, and Singapore each sit somewhere between those poles. For a governance professional, the practical skill is not memorizing any single regime, but recognizing which regulatory philosophy a country has chosen, because that philosophy predicts what a system actually has to do to comply. A single AI deployment routinely has to satisfy several of these regimes simultaneously, and the countries themselves increasingly borrow vocabulary and structure from each other, which is what makes a comparative view worth building deliberately rather than picking up one country at a time.
What This Cheat Sheet Covers
This topic spans 12 focused tables and 121 indexed concepts. Below is a complete table-by-table outline of this topic, spanning foundational concepts through advanced details.
A jump-to index of every table row in this cheat sheet.
An interactive map of every table and concept in this topic.
Table 1: Core Cross-Jurisdictional Vocabulary
Every regime below reuses a small set of concepts under different names; knowing the common vocabulary first makes each country's rules easier to place. These terms recur throughout international AI law even where the underlying statute uses its own local phrasing.
| Term | Example | Description |
|---|---|---|
EU AI Act's unacceptable/high/limited/minimal tiers; Brazil's excessive/high/non-high tiers | Obligations scale with the harm an AI system could cause rather than applying uniformly to all AI. | |
UK's five cross-sectoral principles implemented by existing regulators | Sets high-level outcomes (safety, fairness, transparency) rather than prescriptive rules, leaving implementation to context. | |
UK's FCA governs AI in finance, MHRA governs AI as a medical device | AI is regulated through the existing rulebook of the industry it's deployed in, with no single cross-cutting AI law. | |
A hospital (operator) using a diagnostic model built by a vendor (provider) | β’ Distinguishes the entity that builds and places an AI system on the market from the one that puts it to use. β’ Obligations differ between the two roles. | |
South Korea's AI Basic Act reaches a foreign AI system as soon as it affects Korean users, regardless of where the developer is based | A law applies to conduct or systems outside the country's borders if their effects are felt inside it. |