Canada, Japan, Korea, Brazil and India
11 min read · updated August 4, 2026
Of these five jurisdictions, two have enacted an AI-specific law, one has a bill that died when parliament was prorogued, one has a bill that passed a single chamber, and one has no AI statute at all. Coverage that treats them as five variants of the same thing is the reason companies prepare for obligations that do not exist.
The answer in one table
| Jurisdiction | Description |
|---|---|
| Canada | NO AI STATUTE IN FORCE. The Artificial Intelligence and Data Act was Part 3 of Bill C-27, which died when Parliament was prorogued in January 2025 and has not been reintroduced in the same form. Privacy law, the Quebec provincial regime, a federal directive on government use, and a voluntary code apply instead. |
| Japan | AI LAW IN FORCE, BUT IT IS A PROMOTION LAW. Legislation on the promotion of research, development and utilisation of AI-related technologies was enacted in 2025. It sets direction, creates a strategy body and imposes a duty of cooperation. It contains no prohibitions and no penalties. |
| Korea | COMPREHENSIVE AI ACT ENACTED. The Framework Act on AI Development and Establishment of a Foundation for Trust passed the National Assembly in December 2024, was promulgated in January 2025 and takes effect from 22 January 2026, with an enforcement decree filling in the detail. |
| Brazil | NOT ENACTED. PL 2338/2023, a risk-based bill resembling the EU Act, was approved by the Federal Senate in December 2024 and went to the Chamber of Deputies, where it remained pending. The LGPD applies in the meantime. |
| India | NO AI STATUTE. Governance is through non-binding guidelines, advisories to intermediaries, and the Digital Personal Data Protection Act 2023, whose rules were notified in late 2025 with phased commencement. |
Canada: the bill died
The Artificial Intelligence and Data Act would have created obligations for “high-impact” AI systems, an AI and Data Commissioner, and criminal provisions. It was Part 3 of Bill C-27, introduced in 2022, amended substantially in committee, and it never became law. Parliament was prorogued in January 2025 and every bill on the order paper died with it, C-27 included. Subsequent governments have signalled different priorities and, at this review date, no successor bill had been enacted.
What actually applies in Canada:
- PIPEDA, the federal private-sector privacy statute, and provincial equivalents. Consent, accountability and openness principles reach automated processing without naming it.
- Quebec’s Law 25, which since September 2023 requires a person to be informed when a decision about them is based exclusively on automated processing, and on request to be told the personal information used, the principal factors and parameters, and of the right to have the information corrected. This is the closest thing Canada has to a binding automated decision rule and it applies in one province.
- The Treasury Board Directive on Automated Decision-Making, in force since 2019, which binds federal government departments rather than private companies. It requires an Algorithmic Impact Assessment, published, with the required safeguards scaling to the assessed impact level. It is a genuinely good template even for organisations it does not bind.
- The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, published in 2023, which is exactly what its title says: voluntary, with signatories.
- Human rights, competition and consumer law, which apply to outcomes regardless of the mechanism.
Japan: a promotion law with no penalties
Japan enacted AI legislation in 2025 whose purpose, stated in its own title, is the promotion of research, development and utilisation of AI-related technologies. It establishes an AI Strategy Headquarters within the Cabinet, requires a Basic Plan, and imposes duties of cooperation on national and local government, research institutions and businesses.
What it does not contain is as important: no risk tiers, no prohibitions, no conformity assessment, no registration, no fines. It is a framework for policy, not a compliance regime. Describing Japan as having “passed an AI law” without that qualification misleads badly.
What binds businesses in Japan:
- The Act on the Protection of Personal Information, enforced by the Personal Information Protection Commission, which has issued material on generative AI use and personal data.
- The AI Guidelines for Business, published jointly by the Ministry of Economy, Trade and Industry and the Ministry of Internal Affairs and Communications, first issued in 2024 and revised since. Non-binding, and the most detailed statement of what the Japanese government expects in practice.
- Article 30-4 of the Copyright Act, which permits exploitation of works for information analysis and other purposes not aimed at enjoying the expression, subject to a proviso excluding uses that would unreasonably prejudice the copyright owner’s interests. This is one of the most permissive training-data positions in any major jurisdiction, and it is why Japan appears in every comparison of training data law. The Agency for Cultural Affairs published a general understanding of the provision’s application to AI in 2024, which narrowed the popular reading of it considerably.
Korea: a comprehensive act in force
Korea’s Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust is the second comprehensive AI law enacted anywhere, after the EU’s. It passed the National Assembly in December 2024, was promulgated in January 2025, and takes effect from 22 January 2026, with an enforcement decree supplying operational detail.
Its main elements:
- High-impact AI. A category defined by use in fields with significant effect on human life, safety or fundamental rights — healthcare, energy, hiring, lending, transport, biometrics and public decision-making among them. Operators must implement risk management, explanation measures, user protection and human oversight, and keep documentation.
- Generative AI transparency. Notice that content is generated by AI, with labelling requirements for content that is difficult to distinguish from reality.
- Domestic representative. Foreign operators above thresholds set by decree must designate a domestic representative in Korea. This is the provision that reaches non-Korean companies.
- Safety obligations for models trained above a compute threshold set by decree, echoing the EU’s systemic-risk structure.
- Enforcement by the Ministry of Science and ICT, with fact-finding powers and administrative fines. The penalty ceiling is modest by EU standards — tens of millions of won per violation rather than a percentage of turnover.
The important structural difference from the EU is that the Korean Act is a framework: much of what it means in practice is set by the enforcement decree and by guidelines, which have been developed alongside it. Read the decree, not just the Act.
Brazil: passed one chamber, not enacted
PL 2338/2023 is a risk-based bill closely modelled on the EU Act: excessive-risk practices prohibited, high-risk systems subject to governance obligations, rights for affected people including explanation and contestation, a coordinating authority, and provisions on copyright and remuneration for training data. The Federal Senate approved it in December 2024. It then went to the Chamber of Deputies, where it was still pending at this review date.
It is not law. Reports describing Brazil as having “passed” an AI law are describing a Senate vote, not enactment. Brazilian legislation requires passage by both chambers and presidential sanction.
What applies now:
- The LGPD (Law 13.709/2018). Its Article 20 gives a data subject the right to request review of decisions taken solely on the basis of automated processing of personal data affecting their interests, including decisions intended to define personal, professional, consumer or credit profiles or aspects of personality.
- The ANPD, the national data protection authority, which has been active on AI — most visibly in ordering the suspension of a large platform’s use of Brazilian personal data for AI training in 2024, on the basis that legitimate interests had not been adequately established.
- The Consumer Defence Code, which is unusually strong by international standards and reaches automated decisions affecting consumers directly.
India: no AI statute, a data act arriving
India has enacted no AI-specific legislation. Its governance approach has been non-binding guidance plus the use of intermediary rules under the Information Technology Act.
- The Digital Personal Data Protection Act, 2023 was enacted in August 2023 but did not commence on enactment; it awaited rules. The rules were notified in late 2025 with a phased commencement running over the following year and a half. This is the law that will actually govern personal data in AI systems in India, and its phasing is the date to track.
- MeitY advisories. In March 2024 the Ministry of Electronics and Information Technology issued an advisory to intermediaries about untested AI models, which was revised two weeks later after criticism to drop a government-permission requirement, retaining an expectation that outputs which may be unreliable are labelled and that synthetically generated content is identifiable. Advisories are not statutory instruments; their force comes from the safe-harbour conditions attached to intermediary status.
- AI governance guidelines. MeitY published non-binding national AI governance guidelines in 2025, setting out principles and an institutional approach rather than obligations.
- Proposed IT Rules amendments on labelling synthetically generated information were put out for consultation in late 2025. This page does not state whether they have been notified; check the gazette before assuming a labelling duty is in force in India.
The sectoral regulators are also moving independently — the Reserve Bank of India on AI in financial services, SEBI on AI use by market intermediaries — and for a regulated business those are more likely to bite first than anything general.
The pattern across the five
Three observations that are more durable than any of the individual dates above.
Comprehensive AI acts are rare and the EU is still the outlier. Only Korea has enacted something structurally similar to the EU Act. Everywhere else, the binding rules that reach AI systems are data protection law, consumer law, sectoral regulation and discrimination law — none of which mentions AI.
Transparency about synthetic content is where the world converges. China’s labelling measures, the EU’s Article 50, California’s provenance legislation, Korea’s generative AI notice and India’s proposed rules all point the same way. If you are picking one thing to engineer for globally, it is provenance metadata that survives your pipeline.
The distinction that matters commercially is enacted versus proposed, and it is the one most reporting collapses. A bill approved by one chamber, an advisory, a voluntary code and a statute in force impose four different levels of obligation, which is to say three of them impose none.