AI regulation: roll back or roll on?
Freshfields is a Lead Partner on The Observer Responsible AI Forum hosted at the Serpentine Gallery in London on 24 September 2026. The Responsible AI Forum sets out an agenda for the development, deployment and regulation of AI as a responsible technology for society, government and business. The article below was first published by The Observer in connection with the Forum.
A tempting narrative is taking hold in the AI landscape. After years of racing to regulate AI, the world’s major nations and regional blocs look to be easing off. From a high enough vantage point, this could be read as a coordinated retreat. Look closely, though, and the picture is more recalibration than capitulation. Moreover, the heavy lifting of AI regulation still rests on a patchwork of general laws — many of which are also expanding.
A tempting story
It’s easy to see why some conclude the regulatory tide is receding. The EU simplified its AI Act, including delaying some key high risk AI rules by up to two years. US Executive Orders have revoked the previous administration’s AI safety directive, called for a “minimally burdensome national policy framework”, set up a task force to challenge conflicting state laws, and directed other federal initiatives to limit state regulation. The UK has again pushed back its AI bill, Canada still has no equivalent to its defunct wide-ranging federal AI bill, and global AI safety summits command far less attention than they once did.
A common driver is a desire to champion AI for economic and geopolitical reasons and to strip out regulation seen as unduly burdensome. But this simple picture belies continuing efforts to surround the technology with guardrails.
Look closer
The US is one of the best illustrations of a nominal rollback being met by a deeper regulatory counter-current. While the executive branch generally pursues deregulation, the states have accelerated their regulatory efforts. For example, Texas’s Responsible Artificial Intelligence Governance Act took effect alongside California’s Transparency in Frontier Artificial Intelligence Act, and New York, Connecticut and Illinois have enacted their own AI safety regimes. A parallel wave of AI companion chatbot laws has swept states from Hawaii to Rhode Island. Even Colorado, despite replacing its comprehensive AI law with a narrower automated decision-making regime, enacted a new chatbot law. There are now well over 250 US state AI laws covering topics from employment to deepfakes. And even the federal government has itself begun regulating access to certain frontier models using its export control powers.
The EU’s reforms are targeted at simplification and delay, not widespread repeal — and even add new bans. Elsewhere, AI-specific rules are frequently getting tougher. For example, in 2026, Vietnam continues rolling out its AI Law, Taiwan's and South Korea’s new AI laws entered into effect, China issued new interim measures on AI companionship services and India, Mexico, Brazil and Thailand were among others progressing AI-focused regulatory reforms.
Table 1: AI-specific law(s) enacted or in the pipeline?
| Jurisdiction | AI-specific law(s) enacted or in the pipeline? |
| Australia | No |
| Brazil | Yes — Draft |
| Canada | No |
| China | Yes — Enacted |
| EU | Yes — Enacted |
| India* | Yes — Enacted |
| Mexico | Yes — Draft |
| Saudi Arabia | No |
| Singapore | No |
| South Korea | Yes — Draft |
| Switzerland | No |
| Thailand | Yes — Draft |
| UAE | No |
| US** | Yes — Enacted |
| Vietnam | Yes — Enacted |
Data: 1 June 2026. For federal states other than the US (e.g. Canada and UAE) the data reflects the position at federal level. Excludes narrowly focused AI laws and draft laws judged unlikely to pass or without published text. *Sector-specific. **US data reflects broad laws enacted in several US states.
What the headlines also miss
The rollback framing also overlooks that AI-specific laws are only one layer. Strip them away and AI remains heavily regulated by general consumer, intellectual property, data, digital, product safety and other laws that — globally — have done most of the heavy lifting.
Data protection regulators worldwide — the UK, EU, Singapore and Hong Kong among them — continue to focus heavily on AI. Freshfields’ tracking also shows that AI-focused enforcement by regulators across the UK and EU so far has been dominated by data protection issues. The practical question for businesses developing or deploying AI is not whether there is an AI law, but which legal frameworks govern the use case.
So what?
Talk of a wholesale retreat from AI regulation is overblown. The reality is subtler: the first wave of AI lawmaking is being recalibrated under economic and geopolitical pressure, even as a second wave — often more targeted — gathers pace. Europe, the US and China remain among the hotspots, but the tide of AI law is rising worldwide. Two themes should command particular business attention. First, the tangle of overlapping laws now bearing on AI is growing ever more complex. Second, policymakers are targeting common concerns — such as labelling duties and obligations on a variety of higher-risk uses of AI — in markedly different ways.
Companies that map the full legal stack now, across jurisdictions and themes, can turn a compliance headache into a competitive edge.
