July 2026 is the month AI compliance stopped being a European planning exercise and became a global operational reality simultaneously across multiple binding regimes. The question is no longer whether regulation is coming. It is whether your compliance infrastructure was built for one framework or for the world as it actually is.

EU: Digital Omnibus enters into force

The AI Omnibus became law this month, moving the Annex III high-risk deadline to December 2027 and the product safety route to August 2028. Two new Article 5 prohibitions entered into force simultaneously: non-consensual intimate imagery and CSAM generation. Both carry the full €35 million / 7% penalty ceiling with no transitional period. The European Commission also unveiled a Cybersecurity Action Plan in July, shifting focus from writing AI regulations to actively testing AI within secure pan-European cybersecurity environments.

EU: AliExpress fined €550 million under the Digital Services Act

The largest DSA fine to date, issued for failing to adequately prevent the sale of illegal, unsafe, and counterfeit products. The structural parallels with the AI Act are direct: risk assessment obligations, human oversight requirements, and documented evidence behind mitigation measures. The DSA enforcement timeline, investigation opened March 2024, fine issued July 2026, gives a twenty-eight month read on how quickly the AI Act enforcement machinery will move once it loads.

China: Companion AI rules now enforceable

China began enforcing companion AI and emotional support AI rules on 15 July. These govern AI systems designed for emotional interaction, relationship simulation, and social companionship. China now has six binding AI-specific regulations in force. The companion AI rules are among the least discussed outside specialist practice and among the most commercially relevant for consumer AI product companies with any China exposure.

UK: AI Regulation and Safety Bill passes second Lords reading

The UK AI Regulation and Safety Bill passed its second House of Lords reading on 3 July, introducing a legal duty of care for frontier AI developers, mandatory safety evaluations before deployment, and statutory authority for the UK AI Safety Institute to audit AI systems.

Enforcement will not arrive in 2026, but the voluntary framework UK businesses have been operating under is acquiring a statutory floor. UK companies already subject to the EU AI Act’s extraterritorial reach are now preparing for dual compliance across two binding regimes.

India: Draft Digital India Act published

India published its Draft Digital India Act on 1 July, containing the first statutory AI liability framework for Indian operators. India has been regulated by the DPDP Act and sector rules in the interim. The Reserve Bank of India proposed in June that banks establish formal AI and ML governance frameworks, meaning financial sector AI in India is acquiring binding governance requirements through sector regulation regardless of whether the Digital India Act passes.

US: Federal preemption fight intensifies

The Great American AI Act passed the US Senate with preemption language that would override state-level AI laws. If the House concurs, the compliance maps that US businesses have been building against approximately 38 state-level AI measures may need to be substantially rebuilt. The preemption question is the single largest source of US AI compliance uncertainty heading into Q3.

Vietnam: Among the strictest AI regimes globally

Vietnam’s Law 134/2025, effective March 2026, is a standalone binding AI statute covering high-risk AI systems, transparency obligations, and data governance. It is among the strictest globally and receives almost no coverage in Western compliance literature. Any company with Vietnamese user exposure is already subject to binding obligations that predate the EU AI Act’s high-risk enforcement phase.

South Korea: Enforcement active

South Korea’s AI Basic Act entered into force in January 2026, making it the second country globally after the EU with a comprehensive, risk-based AI law. Enforcement is active. Companies with Korean market exposure are operating under a binding risk-based framework with penalty exposure, not a voluntary code.

The pattern across all of it

The teams struggling most right now built point solutions: one policy page for GDPR, one for the EU AI Act, one for California. Every new rule requires a new document from scratch. The teams handling this well built a compliance architecture: a system inventory, a jurisdiction map, an evidence log, and a documentation owner for each system. New rules mean updating parameters, not starting over.