Which rules apply where

The most common misconception in AI governance is that regulation follows your head office. It follows your conduct and your market. Here is who is caught by what.

1 · How GDPR reach actually works (Art. 3)

Article 3 has two limbs. 3(1) catches processing in the context of the activities of an EU establishment, regardless of where processing occurs. 3(2) catches a controller or processor outside the EU where it either (a) offers goods or services to people in the Union, or (b) monitors their behaviour.

Scenario Caught by the GDPR?
US company, US customers only, no EU targeting No. Merely being accessible from the EU is not enough — Recital 23 requires evidence of intent to target, such as EU languages, currencies, or country-specific marketing.
US company with an EU branch or subsidiary Yes — Art. 3(1). Processing "in the context of the activities of" an EU establishment is caught, even where the processing itself happens in the US.
US SaaS selling to EU consumers Yes — Art. 3(2)(a). Offering goods or services to people in the Union, paid or free.
US analytics or ad-tech tracking EU web users Yes — Art. 3(2)(b). Monitoring behaviour of people in the Union. This is the limb that catches most AI and profiling products.
US company training a model on an EU-sourced dataset Usually yes, via 3(2)(b) or through the controller relationship — and the transfer rules in Arts. 44–49 apply on top.
EU company processing US residents’ data Yes. The GDPR follows the establishment, not the data subject’s nationality — a point exam questions like to invert.

2 · The EU AI Act reaches even further

The AI Act is market-access legislation, so its reach follows the product. It applies to:

It does not apply to military, defence and national security uses, to pure scientific research and development, or to purely personal non-professional use.

3 · The United States: layers, not a law

No comprehensive federal privacy law The US regulates by sector and by state. There is no US GDPR equivalent, which is why "which law applies?" is harder in the US than in the EU.
Sectoral federal laws HIPAA (health), GLBA (financial), FCRA (consumer reporting — directly relevant to credit scoring models), COPPA (children), plus FTC Act §5 on unfair or deceptive practices, which the FTC has used against AI claims and to order algorithmic disgorgement.
State comprehensive privacy laws California (the California Consumer Privacy Act, CCPA, as amended by the CPRA), Virginia, Colorado, Connecticut, Utah and a growing list. Most include rights around profiling and automated decisions.
State AI-specific laws Colorado, Texas, California and others — see below.
State biometric laws Illinois BIPA is the outlier that matters: a private right of action with statutory damages per violation, which has produced the largest US biometric settlements.

4 · US state AI laws

Colorado

SB 24-205, amended by SB 189 (signed 14 May 2026)

Originally the most EU-like US law. The 2026 amendment delayed it from 30 June 2026 to 1 January 2027 and substantially narrowed it: the risk-management programme, impact assessments and duty of care were removed, replaced by pre-use consumer notices, adverse-outcome explanations within 30 days, meaningful human review rights and developer documentation duties.

Texas

TRAIGA (HB 149), effective 1 January 2026

Much narrower than early drafts. A short list of prohibited uses plus rules for state-government AI — not a general high-risk regime.

California

CPPA ADMT regulations; SB 53

ADMT rules are in force, with significant-decision obligations phasing in from 1 April 2027. SB 53 (Frontier AI Transparency) targets large frontier model developers.

Illinois

BIPA; AI Video Interview Act

BIPA governs biometric identifiers; the video interview law requires notice and consent for AI analysis of candidate interviews.

New York City

Local Law 144

Automated employment decision tools require an annual independent bias audit, published results, and candidate notice. Narrow scope, but the first of its kind.

5 · The global map

Jurisdiction Instrument What to know
European Union AI Act (Reg. 2024/1689) + GDPR The reference regime. Extraterritorial: applies to providers placing systems on the EU market wherever established, and where system output is used in the Union.
United Kingdom UK GDPR + DPA 2018; no AI act Deliberately principles-based and regulator-led rather than a single statute. ICO guidance carries the weight.
South Korea AI Basic Act — in force 22 January 2026 The second comprehensive AI regime after the EU. Explicitly extraterritorial; advance notice required for high-impact and generative AI. A one-year grace period on administrative fines was signalled.
Canada No federal AI law AIDA died when Parliament was prorogued in January 2025 and was confirmed off the table in June 2025. Governance runs through PIPEDA and provincial law — Quebec’s Law 25 is the strictest.
Brazil Bill 2338 — not yet law Risk-based and EU-influenced. Passed the Senate; still pending in the Chamber of Deputies as of mid-2026. LGPD applies to personal data in the meantime.
China Sectoral and rapidly iterated Algorithmic recommendation, deep synthesis and generative AI measures, plus PIPL for personal information. Filing and labelling obligations rather than a single risk-tiered act.
Japan Light-touch, promotion-oriented Guidance and a promotion-focused statute rather than prescriptive obligations.
Council of Europe Framework Convention on AI The first legally binding international AI treaty, opened for signature 5 September 2024. Around 20 signatories by May 2026, with the EU ratifying on 15 May 2026. Binds parties, not companies directly — it obliges states to legislate.

6 · How to answer a jurisdiction question

  1. Where are the people? Not the company, not the servers. Data subjects in the Union trigger the GDPR; output used in the Union triggers the AI Act.
  2. What is the conduct? Targeting or monitoring, versus merely being reachable online.
  3. What role do you hold? Controller/processor under the GDPR; provider/deployer under the AI Act. They are independent — you can be a processor and a provider at once.
  4. Which layer bites hardest? Where several regimes apply, they apply cumulatively. Comply with the strictest.
  5. Is there a sectoral law? Health, finance, employment and children’s data usually carry additional rules that outrank the general analysis.

Currency note. Status is stated as at August 2026 and this area moves fast — the Colorado delay, the South Korean act coming into force and the EU’s ratification of the Council of Europe convention all happened in 2026. The AIGP Body of Knowledge v2.1 predates several of these, so the exam may still describe an earlier position. Where the exam and current news disagree, answer from the Body of Knowledge.

Not legal advice — verify current status before relying on any of this operationally.

Test yourself

Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.

Quick check: which rules apply where1 / 5 · score 0

A US analytics company with no EU establishment tracks the browsing behaviour of users located in Germany. Does the GDPR apply?

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →