Which rules apply where
The most common misconception in AI governance is that regulation follows your head office. It follows your conduct and your market. Here is who is caught by what.
1 · How GDPR reach actually works (Art. 3)
Article 3 has two limbs. 3(1) catches processing in the context of the activities of an EU establishment, regardless of where processing occurs. 3(2) catches a controller or processor outside the EU where it either (a) offers goods or services to people in the Union, or (b) monitors their behaviour.
| Scenario | Caught by the GDPR? |
|---|---|
| US company, US customers only, no EU targeting | No. Merely being accessible from the EU is not enough — Recital 23 requires evidence of intent to target, such as EU languages, currencies, or country-specific marketing. |
| US company with an EU branch or subsidiary | Yes — Art. 3(1). Processing "in the context of the activities of" an EU establishment is caught, even where the processing itself happens in the US. |
| US SaaS selling to EU consumers | Yes — Art. 3(2)(a). Offering goods or services to people in the Union, paid or free. |
| US analytics or ad-tech tracking EU web users | Yes — Art. 3(2)(b). Monitoring behaviour of people in the Union. This is the limb that catches most AI and profiling products. |
| US company training a model on an EU-sourced dataset | Usually yes, via 3(2)(b) or through the controller relationship — and the transfer rules in Arts. 44–49 apply on top. |
| EU company processing US residents’ data | Yes. The GDPR follows the establishment, not the data subject’s nationality — a point exam questions like to invert. |
2 · The EU AI Act reaches even further
The AI Act is market-access legislation, so its reach follows the product. It applies to:
- Providers placing systems on the EU market or putting them into service in the Union — irrespective of where the provider is established;
- Deployers established or located in the Union;
- Providers and deployers in third countries where the output produced by the system is used in the Union — the broadest limb, and the one that catches a US company scoring EU job applicants from Ohio.
It does not apply to military, defence and national security uses, to pure scientific research and development, or to purely personal non-professional use.
3 · The United States: layers, not a law
| No comprehensive federal privacy law | The US regulates by sector and by state. There is no US GDPR equivalent, which is why "which law applies?" is harder in the US than in the EU. |
|---|---|
| Sectoral federal laws | HIPAA (health), GLBA (financial), FCRA (consumer reporting — directly relevant to credit scoring models), COPPA (children), plus FTC Act §5 on unfair or deceptive practices, which the FTC has used against AI claims and to order algorithmic disgorgement. |
| State comprehensive privacy laws | California (the California Consumer Privacy Act, CCPA, as amended by the CPRA), Virginia, Colorado, Connecticut, Utah and a growing list. Most include rights around profiling and automated decisions. |
| State AI-specific laws | Colorado, Texas, California and others — see below. |
| State biometric laws | Illinois BIPA is the outlier that matters: a private right of action with statutory damages per violation, which has produced the largest US biometric settlements. |
4 · US state AI laws
Colorado
SB 24-205, amended by SB 189 (signed 14 May 2026)Originally the most EU-like US law. The 2026 amendment delayed it from 30 June 2026 to 1 January 2027 and substantially narrowed it: the risk-management programme, impact assessments and duty of care were removed, replaced by pre-use consumer notices, adverse-outcome explanations within 30 days, meaningful human review rights and developer documentation duties.
Texas
TRAIGA (HB 149), effective 1 January 2026Much narrower than early drafts. A short list of prohibited uses plus rules for state-government AI — not a general high-risk regime.
California
CPPA ADMT regulations; SB 53ADMT rules are in force, with significant-decision obligations phasing in from 1 April 2027. SB 53 (Frontier AI Transparency) targets large frontier model developers.
Illinois
BIPA; AI Video Interview ActBIPA governs biometric identifiers; the video interview law requires notice and consent for AI analysis of candidate interviews.
New York City
Local Law 144Automated employment decision tools require an annual independent bias audit, published results, and candidate notice. Narrow scope, but the first of its kind.
5 · The global map
| Jurisdiction | Instrument | What to know |
|---|---|---|
| European Union | AI Act (Reg. 2024/1689) + GDPR | The reference regime. Extraterritorial: applies to providers placing systems on the EU market wherever established, and where system output is used in the Union. |
| United Kingdom | UK GDPR + DPA 2018; no AI act | Deliberately principles-based and regulator-led rather than a single statute. ICO guidance carries the weight. |
| South Korea | AI Basic Act — in force 22 January 2026 | The second comprehensive AI regime after the EU. Explicitly extraterritorial; advance notice required for high-impact and generative AI. A one-year grace period on administrative fines was signalled. |
| Canada | No federal AI law | AIDA died when Parliament was prorogued in January 2025 and was confirmed off the table in June 2025. Governance runs through PIPEDA and provincial law — Quebec’s Law 25 is the strictest. |
| Brazil | Bill 2338 — not yet law | Risk-based and EU-influenced. Passed the Senate; still pending in the Chamber of Deputies as of mid-2026. LGPD applies to personal data in the meantime. |
| China | Sectoral and rapidly iterated | Algorithmic recommendation, deep synthesis and generative AI measures, plus PIPL for personal information. Filing and labelling obligations rather than a single risk-tiered act. |
| Japan | Light-touch, promotion-oriented | Guidance and a promotion-focused statute rather than prescriptive obligations. |
| Council of Europe | Framework Convention on AI | The first legally binding international AI treaty, opened for signature 5 September 2024. Around 20 signatories by May 2026, with the EU ratifying on 15 May 2026. Binds parties, not companies directly — it obliges states to legislate. |
6 · How to answer a jurisdiction question
- Where are the people? Not the company, not the servers. Data subjects in the Union trigger the GDPR; output used in the Union triggers the AI Act.
- What is the conduct? Targeting or monitoring, versus merely being reachable online.
- What role do you hold? Controller/processor under the GDPR; provider/deployer under the AI Act. They are independent — you can be a processor and a provider at once.
- Which layer bites hardest? Where several regimes apply, they apply cumulatively. Comply with the strictest.
- Is there a sectoral law? Health, finance, employment and children’s data usually carry additional rules that outrank the general analysis.
Currency note. Status is stated as at August 2026 and this area moves fast — the Colorado delay, the South Korean act coming into force and the EU’s ratification of the Council of Europe convention all happened in 2026. The AIGP Body of Knowledge v2.1 predates several of these, so the exam may still describe an earlier position. Where the exam and current news disagree, answer from the Body of Knowledge.
Not legal advice — verify current status before relying on any of this operationally.
Test yourself
Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.
A US analytics company with no EU establishment tracks the browsing behaviour of users located in Germany. Does the GDPR apply?
- ANo — unless the data is physically stored on servers inside the Union.
- BNo — without an EU establishment, Art. 3 cannot reach the company.
- CYes — Art. 3(2)(b) catches monitoring the behaviour of people in the Union.
- DYes — but only once the company begins offering services to EU customers.