Brazil
◆Binding
Binds Suppliers of information-technology products or services (including internet application providers, social networks, app stores, electronic games and child-monitoring products) that are directed at children and adolescents or likely to be accessed by them, offered in Brazilian territory, including foreign companies, which must keep a legal representative in Brazil (Art. 40). Art. 39 modulates the duties in Arts. 6, 17, 18, 19, 20, 27, 28, 29, 31, 32 and 40 by the product's characteristics and functionalities, the provider's degree of interference over content, user numbers and size, and exempts editorially-controlled services and licensed-content providers that meet the four conditions in Art. 39 s.1. Impact tier: all entities, modulated by size and degree of content control.. Providers of information-technology products or services directed at, or likely accessed by, children and adolescents must give parents control over personalised recommendation systems, including the option to switch them off, and must regularly review the artificial-intelligence tools in the service with the participation of specialists and competent bodies against technical criteria that ensure their safety and suitability for use by minors, with non-essential functionalities capable of being disabled. Behavioural profiling of child and adolescent users for advertising is prohibited, as is profiling-based ad targeting and the use of emotional analysis, augmented, extended or virtual reality for that purpose. Where content is removed, the provider must tell the user whether the content was identified by human or automated analysis.
Lei 15.211/2025 ("ECA Digital"), sanctioned 17 September 2025 and published DOU 17.9.2025 extra edition. Art. 41-A originally set entry into force at six months after publication (inserted by MP 1.319/2025); the version now in force, inserted by Lei 15.352/2026, fixes the date expressly: "Esta Lei entra em vigor em 17 de março de 2026." Scope call 2026-08-14: kept in the tracker because the statute imposes express algorithmic-system duties rather than only platform-safety duties — Art. 17 s.4 V (control over personalised recommender systems with an off switch as a default parental-supervision setting), Art. 17 s.4 VIII (regular expert review of AI tools in the service), Art. 30 II (disclosure of whether a removal decision came from human or automated analysis), Art. 22 (ban on profiling for ad targeting and on emotional analysis / AR / XR / VR for that purpose) and Art. 26 (ban on building behavioural profiles of minors from personal, group or collective data, including data obtained in age verification, for advertising). Art. 24 s.3 age-assurance and Art. 27 automated illicit-content detection duties feed the separate transparency-report obligation tracked as br-lei15211-art31-report. Enforcement: Art. 34 gives the autonomous administrative authority for the protection of children's and adolescents' rights in the digital environment supervisory and complementary-rulemaking power; Decreto 12.622/2025 designates the ANPD as that authority and Decreto 12.880/2026 (DOU 18.3.2026 extra edition) is the implementing regulation. Distinct from br-lgpd-art20, which is a data-subject right under the LGPD. AIL-300 computation check (2026-08-31): out of scope for the publication-relative sweep as the law now stands. Art. 41-A's original six-months-from-publication formula was replaced by Lei 15.352/2026 with an express calendar date — «Esta Lei entra em vigor em 17 de março de 2026» — so the in-force text sets no period to compute and LINDB art. 1's counting rule does not engage.
Stated maximum penalty — Art. 35: warning with up to 30 days to take corrective measures; simple fine of up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped in total at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. Fines and warnings are applied by the ANPD; suspension and prohibition by the Judiciary (Art. 35 s.5) and enforced if needed by blocking orders to connectivity providers, IXPs and DNS resolvers (Art. 35 s.6). A foreign company's Brazilian branch or establishment is jointly liable for the fine (Art. 35 s.2); fine amounts are indexed annually to the IPCA (Art. 35 s.4).
Brazil
◆Binding
Binds Internet application providers directed at or likely accessed by children and adolescents with more than 1,000,000 registered users in that age band with an internet connection in Brazilian territory. Exempt: providers below that threshold, and editorially-controlled services and licensed-content providers meeting the four conditions in Art. 39 s.1 (Despacho Decisório CD/ANPD 122/2026 item VII). Impact tier: enterprise.. Internet application providers directed at, or likely accessed by, children and adolescents with more than 1,000,000 registered users in that age band connecting from Brazil must publish semi-annual reports in Portuguese on their own website. The report must cover the complaint channels and investigation systems, the number of complaints received, the volume of content and account moderation by type, the measures used to identify child accounts on social networks under Art. 24 s.3 and to identify illicit acts under Art. 27, technical improvements for personal-data protection and privacy and for ascertaining parental consent under LGPD Art. 14 s.1, and the methods used and results of impact assessments and of the identification and management of risks to the safety and health of children and adolescents. Providers must also give academic, scientific, technological, innovation and journalistic institutions free access to the data needed to research the service's impact on minors.
Art. 31 of Lei 15.211/2025 has been in force since 17 March 2026 (Art. 41-A as amended by Lei 15.352/2026), but the statute only says the reports are semi-annual and sets no publication date. Despacho Decisório CD/ANPD 122/2026 (DOU 11.8.2026, Section 1, p. 59) fixes the calendar until specific regulation supervenes: the time runs from entry into force on 17 March 2026; the first report covers 1 January to 30 June 2026, and providers without data for January and February may limit it to 17 March to 30 June 2026; the first report must be published by 17 September 2026 (item III); from the second report the periods follow the civil semesters, published by 1 August for the first semester and by 1 February for the second (item IV). Art. 45 of Decreto 12.880/2026 adds, under Art. 31 II, the number of notifications received by category and proportional data on how they were followed up. Art. 47 of the decree requires the child-safety-and-health impact assessment behind Art. 31 VII, with a plain-language summary made public, and lets an ANPD act set its minimum content and periodicity. The ANPD recommends emailing a copy of each report to monitoramento@anpd.gov.br at publication (item VIII). Tracked separately from br-lei15211-eca-digital because 17 September 2026 is a distinct near-term deadline.
Stated maximum penalty — Art. 35: warning with up to 30 days to correct; simple fine up to 10% of the economic group's Brazilian turnover in its last financial year or, absent turnover, R$10 to R$1,000 per registered user, capped at R$50,000,000 per infraction; temporary suspension of activities; prohibition of activities. ANPD applies the warning and fine (Art. 35 s.5).
China
◆Binding
Binds Any provider applying algorithmic recommendation technology to supply internet information services within the territory of the PRC (Art. 2). 'Applying algorithmic recommendation technology' is defined as using generative/synthetic, personalised push, ranking and selection, retrieval and filtering, or scheduling and decision-making algorithms to provide information to users — a definition wide enough to cover feeds, search ranking, content moderation filters and platform dispatch systems, not only recommender feeds. The filing, disclosure-number and security-assessment duties in Arts. 24, 26 and 27 bind only the subset of providers with public-opinion attributes or social-mobilisation capacity. Impact tier: all entities.. Providers of internet information services that use recommendation algorithms must tell users conspicuously that an algorithmic recommendation service is being provided and publicise its basic principles, purpose and main operating mechanisms (Art. 16); offer an option not targeted at the user's personal characteristics or a convenient way to switch the recommendation service off, and let users select or delete the personal-characteristic tags used for recommendation (Art. 17); periodically review, assess and verify the algorithm's mechanisms, models, data and outputs, and not deploy models that induce addiction or excessive consumption (Art. 8); and label unlabelled algorithmically generated or synthesised information before further transmission (Art. 9). Providers with public-opinion attributes or social-mobilisation capacity must additionally file with the CAC internet information service algorithm filing system within 10 working days of starting service — submitting the provider name, service form, application field, algorithm type, algorithm self-assessment report and the intended public-disclosure content — file changes within 10 working days and deregister within 20 working days of termination (Art. 24), display the filing number and a link to the disclosure on their site or app (Art. 26), and carry out a security assessment (Art. 27). Sector rules also apply: protection duties for minors (Art. 18), the elderly (Art. 19), gig workers subject to algorithmic work dispatch (Art. 20), and a ban on unreasonable differential treatment of consumers on price or other transaction terms — algorithmic price discrimination (Art. 21).
Commencement is on the face of the instrument: Art. 35 states the Provisions take effect 1 March 2022, and the promulgation order records adoption at the 20th CAC executive meeting of 2021 on 16 November 2021, agreement by MIIT, the Ministry of Public Security and SAMR, and signature on 31 December 2021 (published 4 January 2022) as Order No. 9 of the four departments. Full Chinese text of Arts. 1-35 read at the cited CAC page. Distinct from, and cumulative with, the CAC instruments already tracked: cn-pipl-art24 is the statutory personal-information basis for the Art. 17 off-switch, while these Provisions are the operative administrative regime (filing system, self-assessment report, filing number display). Where a service also generates or synthesises content, cn-deep-synthesis, cn-genai-interim and cn-ai-labelling apply in parallel. Note npc.gov.cn is http-only; this instrument is a departmental rule (bumen guizhang), so the CAC publication is the authoritative text.
Stated maximum penalty — Art. 31: for breach of Arts. 7, 8, 9(1), 10, 14, 16, 17, 22, 24 or 26, where no other law or administrative regulation provides otherwise — warning, circulated criticism and an order to rectify within a time limit; if rectification is refused or the circumstances are serious, an order to suspend information updates plus a fine of RMB 10,000 to 100,000, with public-security penalties or criminal liability where applicable. Art. 33: obtaining a filing by concealment or false material means revocation of the filing, warning, circulated criticism and, in serious cases, suspension of information updates plus a fine of RMB 10,000 to 100,000. Art. 32 routes breaches of Arts. 6, 9(2), 11, 13, 15, 18, 19, 20, 21, 27 and 28(2) to the penalties of the underlying laws (e.g. PIPL Art. 66, up to RMB 50,000,000 or 5% of turnover, and the Minors Protection Law). Enforced by the CAC with MIIT, public-security and market-regulation authorities.
Ecuador
◆Binding
Binds Responsables and encargados del tratamiento — controllers and processors. Art. 3 reaches processing carried out anywhere in national territory, controllers or processors domiciled in Ecuador, and controllers or processors not established in Ecuador that process the data of subjects residing in Ecuador where the activity relates to offering goods or services to them, payment required or not, or to monitoring their behaviour in Ecuador; a fourth limb picks up cases where Ecuadorian law applies by contract or by public international law. Art. 20 covers administrative acts and private decisions alike, so there is no public-sector carve-out — the sanctions articles instead split the tariff between public servants and private or state-owned entities. Impact tier: all entities.. Art. 20 of the Ley Orgánica de Protección de Datos Personales (Quinto Suplemento del Registro Oficial Nº 459 of 26 May 2021, adopted 10 May 2021) is titled «Derecho a no ser objeto de una decisión basada única o parcialmente en valoraciones automatizadas» — a right not to be subject to a decision based wholly OR PARTLY on automated valuations. The two words «o parcialmente» are the finding. Every other transposition in the atlas of the GDPR art. 22 family keeps the «solely» limb, and the argument that partial automation with a human rubber-stamp escapes the rule is the most contested question in that family; Ecuador removed the question from the text in 2021. The effects threshold is widened in the same sentence: the decision has to «produzcan efectos jurídicos en él o que atenten contra sus derechos y libertades fundamentales» — produce legal effects in the subject OR infringe their fundamental rights and freedoms — where GDPR art. 22(1) asks for a similarly significant effect. The right is also built as a bundle of five active entitlements rather than an abstention: a reasoned explanation of the decision taken (a), the filing of observations (b), «los criterios de valoración sobre el programa automatizado» — the valuation criteria bearing on the automated program itself (c), the types of data used and the source they were obtained from (d), and challenge of the decision before the controller or processor (e). There are four exceptions, one more than the GDPR has: contract, authorising law (widened to include a judicial order or the reasoned mandate of a competent technical authority, with adequate safeguards established), explicit consent, and — with no counterpart in the GDPR — «la decisión no conlleve impactos graves o riesgos verificables para el titular», a de minimis exit for decisions carrying no serious impact or verifiable risk for the subject. Two closing sentences have no GDPR counterpart either: advance waiver of the right through mass adhesion contracts cannot be required, and the right is stated explicitly to the subject, by any suitable medium, no later than the first communication. That last sentence reverts to «basada únicamente en valoraciones automatizadas» — the notification duty is drawn back to solely-automated decisions while the right itself covers partly-automated ones, an internal inconsistency present in the gazette text. Art. 21 carries a dedicated companion right for children and adolescents: on top of art. 20, sensitive data and the data of children and adolescents are not processed this way absent the express authorisation of the subject or their legal representative, or an essential public interest assessed against international human-rights standards satisfying legality, proportionality and necessity and including specific safeguards; adolescents from 15 may consent as subjects in their own right. Arts. 12(14) and 12(17) make the transparency proactive — the existence of automated valuations and decisions, profiling included, forms part of the information given at collection.
In force since 26 May 2021: the Disposición Final states «La presente Ley entrará en vigencia una vez publicada en el Registro Oficial», and publication was in the Quinto Suplemento del Registro Oficial Nº 459 of that date. The corrective-measures and sanctions regime is the exception — Disposición Transitoria Primera delayed it by two years from publication, so fines became available on 26 May 2023, and Disposición General Séptima states in terms that the rights «podrá ser exigido por el titular independientemente de la entrada en vigor del régimen sancionatorio», an explicitly enforceable-but-unfineable interval that no other instrument in the atlas spells out. Art. 20 was verified against the scanned gazette itself — page 23 of the Asamblea Nacional's copy of the Quinto Suplemento — and that reading corrected the commercial rendering: the gazette lists five lettered entitlements a) to e), where the widely circulated Lexis-typeset edition folds «e. Impugnar la decisión» into item d) by reading the letter «e» as the conjunction. Ecuador's data-protection authority, the Superintendencia de Protección de Datos Personales, has been operating since 2023 and issues general norms under art. 76(5) of the Law. No amendment: the government-hosted consolidated editions of November 2024 and July 2025 both carry «Estado: Vigente / Fecha de última reforma: No aplica», and no reforming law was found through August 2026.
Stated maximum penalty — Split by the identity of the offender, not by the article breached. Art. 71 sets the light tariff — 1 to 10 unified basic salaries for a public servant, or 0.1% to 0.7% of the previous financial year's turnover for a private entity or state-owned enterprise. Art. 72 sets the serious tariff — 10 to 20 unified basic salaries, or 0.7% to 1% of turnover. Art. 73 defines turnover as sales of goods and services net of VAT and directly related taxes. There is a finding in the lists themselves. Neither art. 67 nor art. 68 names art. 20, so a controller that denies the right lands in art. 67(1) — failing to process, processing out of time or unjustifiably refusing a subject's petition — which is a LIGHT infraction; art. 70(1), the processor's list, is a catch-all reaching any processing «sin observar los principios y derechos desarrollados en la presente Ley», which is a SERIOUS one. The same refusal is therefore fined an order of magnitude apart depending on whether the entity acted as controller or as processor. Art. 72 also carries a cross-border enforcement fallback: where the offender has no domicile or legal representation in Ecuador, the resolution is notified to the data-protection authority of its principal place of business to carry the measures through.
Egypt
◆Binding
Binds كل من المتحكم أو المعالج، بحسب الأحوال، سواء كان شخصًا طبيعيًا أو اعتباريًا — the controller or the processor as the case may be, natural or legal person — in the terms of the opening words of مادة (١٤). The trigger is the child's participation in a game, competition or other activity, so the duty reaches games publishers, competition and promotion operators, ad-tech and analytics recipients of that data, and education and entertainment platforms, without any size or sector threshold. «الطفل» takes its meaning from the Egyptian Child Law No. 12 of 1996, which the enacting decree recites among its legal bases; مادة (١٥) of the Regulations treats under-15s and the 15-to-18 band differently for consent purposes but مادة (١٤) item 5 draws no such line and refers simply to الأطفال. Supervision is by the Personal Data Protection Centre. Impact tier: all entities.. Article 14 of the Executive Regulations, headed «المعايير والضوابط الخاصة بالتعامل على البيانات الشخصية الحساسة», binds the controller and the processor alike, natural or legal person, whenever sensitive personal data is collected, transferred, stored, kept, processed or made available. Its fifth item is the closest thing in Egyptian law to a profiling prohibition: «٥- فى حالة مشاركة الطفل فى لعبة أو مسابقة أو أى نشاط آخر يجب ألا يتحصل منه على أكثر مما هو ضرورى للمشاركة وألا تُستخدم هذه البيانات فى عمليات تصنيف أو تتبع أو مراقبة سلوكية للأطفال .» — where a child takes part in a game, a competition or any other activity, no more may be obtained from the child than is necessary for the participation, and that data may not be used in classification, tracking or behavioural-monitoring operations on children. The rule has two limbs that operate independently: a data-minimisation limb tied to the purpose of participating, and a flat use prohibition on three named operations. The prohibition is absolute on its face — it is not subject to consent, not subject to a legitimate-interest balance, and carries no exception for a parent's or guardian's authorisation, which is a notable contrast with the rest of the children's regime in مادة (١٥), where written parental consent is what unlocks processing for under-15s and the child's own consent joins it from 15 to 18. «تصنيف» (classification), «تتبع» (tracking) and «مراقبة سلوكية» (behavioural monitoring) are not defined in the Regulations, and the Centre's published bilingual glossary is a term list without definitions, so the scope of the three operations is not further specified in any primary text read here.
Primary source read: the certified gazette copy of the Executive Regulations published by the Personal Data Protection Centre itself, i.e. الوقائع المصرية — العدد ٢٤٤ تابع (أ) فى أول نوفمبر سنة ٢٠٢٥. The file is an MRC scan whose page text is JBIG2-coded with a /JBIG2Globals segment, which is why three earlier passes on this issue recorded it as unreadable; it is readable once the globals stream is prepended to the JBIG2 chunk list, and all 41 pages were decoded and read in the Arabic. Printed page 2 carries the enacting instrument, قرار وزير الاتصالات وتكنولوجيا المعلومات رقم ٨١٦ لسنة ٢٠٢٥ بإصدار اللائحة التنفيذية لقانون حماية البيانات الشخصية الصادر بالقانون رقم ١٥١ لسنة ٢٠٢٠; printed page 3 carries its المادة الأولى (the annexed Regulations are put into effect) and its المادة الثانية, «يُنشر هذا القرار فى الوقائع المصرية ، ويُعمل به من اليوم التالى لتاريخ نشره», signed د/ عمرو سميح طلعت. Gazette date 1 November 2025 and entry into force 2 November 2025 are therefore taken from the gazette, not from the regulator's website prose. The item was read at printed page 20 of that issue, where مادة (١٤) items 5 to 7 continue from items 1 to 4 at printed page 19. It is carried as a separate row from eg-erpdpl-art4-ai-training because it binds a different set of actors (controller and processor, not the processor alone), rests on a different trigger (a child's participation, not the use of a training technique), and is a prohibition rather than a standard of conduct. Checked negative, recorded so no later pass re-derives it: the Egyptian framework has NO GDPR art. 22 analogue. The Regulations' own الفهرس (printed pages 4 to 6) lists every heading through printed page 41 and contains no automated-decision or profiling heading; مادة (١) is a purely referential definitions article that takes the Law's definitions and adds none of its own; and the substantive articles 2 to 18 were read in full without finding a right not to be subject to a solely-automated decision. On the Law side, مادة (٢) of the Regulations, ثانيًا, item 1 confirms that PDPL art. 2 is the data-subject-rights article («إعلام الشخص المعنى بالبيانات بحقوقه وفق المادة (٢) من القانون»), and the Centre's own «Egypt's Personal Data Protection Framework» deck states at its page 12 that «the PDPL establishes nine fundamental rights for data subjects (PDPL Article 2)» and enumerates all nine — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability, and to be notified in case of data breach. No automated-decision or profiling right appears. The gazetted Arabic of the Law itself remains unreadable in this environment (the Centre's PDPL PDF draws every glyph as vector outlines, carries no text layer, no ToUnicode CMap and no page raster, and a full Wayback CDX sweep of mcit.gov.eg returns no copy of Law 151/2020), so the nine-rights list rests on a regulator publication rather than on statutory text and the absence of an art. 22 analogue is stated at that strength. The Centre's guidance treats automated decision-making as a factor inside the fairness principle rather than as a standalone right: its Data Protection Principles guideline lists «the use of automated decision-making and profiling: whether the processing involves automated decisions producing legal or significant effects on the data subject without human oversight» among the matters that bear on whether processing is fair. The practical effect is that Egypt regulates profiling only where children are concerned and only as a use prohibition, with no general profiling right or general profiling ban for adults anywhere in the Law or the Regulations as read.
Stated maximum penalty — Not quantified here, deliberately. The Regulations create the duty but carry no fine of their own: enforcement runs through the licence and permit regime they build, under which a متحكم or معالج must hold a licence or تصريح from the Centre before collecting or processing at all (مادة (٢) أولاً item 1, مادة (٣) أولاً item 1 and مادة (٤) أولاً item 1), the Centre's inspectors are مأمورو الضبط القضائى with a right of access to the electronic records (مادة (٣) أولاً item 7, مادة (٤) أولاً item 4), and every licence application must carry an إقرار بالوفاء بالجزاءات المالية والتعويضات التى يقرها المركز (printed page 42, item 8). The monetary scale sits in the penalties chapter of Law 151/2020 itself, and that text could not be read from any reachable official host this run, so no figure is published rather than a figure taken from a secondary summary.
Gabon
◆Binding
Binds «Tout éditeur de réseau social ou de plateforme numérique» — the éditeur only, not the hébergeur, on the art. 3 definitions: the éditeur is the natural or legal person who, by an active role and a power of moderation, controls and implements the diffusion of communications, publications or information on a communication service, social network or online digital platform. Combined with the art. 2 scope, the duty reaches any such editor whose diffused content is accessible on, or produces its effects on, Gabonese territory, with no size, turnover or user-number threshold and no domestic establishment requirement. Impact tier: all entities.. Art. 53 is the opening article of Chapitre XI, «Des dispositions transitoires, diverses et finales», and it is where the operative AI-content labelling duty of the Gabonese ordonnance actually sits. Every editor of a social network or digital platform is required, within a period of twelve months from the publication of the ordonnance, to do four things. To implement effective technical age-verification mechanisms on every new registration. To deploy automatic detection tools for AI-generated content published or shared on its services, according to technical standards set by the texts in force — standards that art. 54 leaves to implementing regulations and that had not been issued as at 1 September 2026. To apply a visible, clear and permanent marking to any content identified as generated or substantially modified by an artificial-intelligence system, accessible to the user without any additional action on their part. And to preserve, and to transmit to the Haute Autorité de la Communication within eight days, the origin metadata of AI-generated content that is the subject of a judicial or administrative investigation. Read with art. 3, which defines Marquage d'origine as a technical process allowing persistent and verifiable identification that a content was generated or modified by an artificial-intelligence system, the third indent is a synthetic-content labelling mandate of the same family as EU AI Act art. 50, but placed on the platform rather than on the generator, and framed as a detection-and-marking duty rather than a provider disclosure. The second indent is unusual in a comparative view: it requires platforms to run AI-content detection, not merely to pass through a label the generator applied. Art. 34, in the AI chapter, presupposes this article by giving the Haute Autorité de la Communication and the Ministère Public power to commission an independent technical audit of «les systèmes de détection et de marquage des contenus générés par intelligence artificielle» deployed on a platform.
Split out of ga-ord0011-2026-ai-content on 1 September 2026 once the primary gazette text was read. The original single row recorded the labelling duty as in force from publication; it is not. Art. 53 opens the transitional chapter and gives «un délai de douze mois à compter de la publication de la présente ordonnance». Applying the commencement method: this is a direct offset from publication, not a named day and not an elapsed-term formula, so it is computed rather than looked up. The one uncertainty is the base date. Journal Officiel de la République Gabonaise n° 110 is dated as a week, «8 au 15 avril 2026», printed on the running head of every page, and not as a single day; Gabonese press reporting of the publication settles on 8 April. The date recorded here is therefore the earliest date on which the twelve-month period can expire, 8 April 2027, and the outer bound is 15 April 2027. Confidence is medium for that reason and for that reason only. Three further points on the shape of this deadline. It is a compliance deadline running against the editor, not a commencement date for the article: the ordonnance itself has been in force since publication, and art. 55 defers nothing. The second indent is conditioned on technical standards «définis par les dispositions des textes en vigueur», and art. 54 provides that regulatory texts determine as needed the provisions necessary for application of the ordonnance; no such text had been published as at 1 September 2026, so the detection-standard limb has no content yet and the deadline may in practice be reached with the standard still unissued. That is a watch item, not a reason to move the date. And the first indent, age verification, is not an AI duty at all; it is recorded here because it shares the article and the same twelve-month clock, and because art. 3 sets the digital age of majority at sixteen. Source: the same scan of Journal Officiel n° 110 used for the Chapitre VII row, art. 53 at page 141 of the issue; the official host journal-officiel.ga timed out on port 443 throughout this session. Source moved 16 September 2026 off directinfosgabon.com (a Gabonese news site) onto the Journal Officiel's own host: the live page at https://journal-officiel.ga/22404-0011-pr-2026-/ still times out on port 443 from this egress, as it has every session since this row was written, so the citation is the Internet Archive's capture of that same official page — https://web.archive.org/web/20260611101549/https://journal-officiel.ga/22404-0011-pr-2026-/ — the CAR/Senegal/São Tomé remedy. The archived page is the gazette's own HTML rendering of Ordonnance n° 0011/PR/2026, not a scan, and its full text of arts. 32-34, 42, 45-53 and the signature block (Libreville, 26 February 2026, Brice Clotaire Oligui Nguema, countersigned by the Ministers of Digital Economy, Defence, Communications, Interior and Justice) was re-read end to end against this row and against ga-ord0011-2026-art53-marquage; every fact, including the «FCEA» typo for FCFA in art. 52's AI aggravator, matches verbatim. No substantive change.
Stated maximum penalty — None stated. Art. 53 carries no penalty of its own, and Chapitre X, the penal chapter at arts. 45 to 52, does not reference it: arts. 45 and 46 punish identity-information failures, art. 47 the right of reply, art. 48 the general duty to combat illicit content, art. 50 obstruction of the Haute Autorité de la Communication, and arts. 51 and 52 phishing and identity usurpation. Because the ordonnance predates any implementing text under art. 54, there is at present no stated sanction for an editor that reaches April 2027 without detection tooling or origin marking in place. Two indirect routes exist. Art. 34 lets the Haute Autorité de la Communication or the Ministère Public commission an independent technical audit of the detection and marking systems on its own initiative, and art. 50 punishes obstruction of the Authority — refusing to communicate useful information or documents to its members or authorised agents, concealing or destroying them, or supplying information not conforming to the records — with one year's imprisonment and a fine of 2,000,000 to 20,000,000 FCFA or one of those penalties only, which is the sanction an editor would face for stonewalling such an audit rather than for failing the underlying duty. Separately art. 42 lets the juge des référés order forced application of an origin marking on a given AI-generated content, which is a per-content remedy and not a sanction for breach of art. 53.
UK
◆Binding
Binds Information Commissioner (duty to prepare the code); indirectly all UK controllers and processors developing or using AI or making automated decisions under the UK GDPR and DPA 2018 (except Part 4, intelligence services). Requires the Information Commissioner to prepare a statutory code of practice on good practice in processing personal data for (a) developing and using AI and (b) automated decision-making under Arts. 22C(1) UK GDPR / s.50C(1) DPA 2018. The code must include guidance on children's personal data. Once issued, the code is admissible in evidence and regulators and courts must take it into account, so it will set the compliance benchmark for UK controllers developing or deploying AI.
Made 16 April 2026, laid before Parliament 21 April 2026, in force 12 May 2026 (reg. 1(2): 21 days after laying). Powers: DPA 2018 ss.124A(1)-(2) and 124B(11), inserted by Data (Use and Access) Act 2025 ss.92(2) and 93. Reg. 3 modifies the s.124B panel requirement so the panel must not consider or report on any aspect of the code relating to national security. The code itself has NOT yet been issued or consulted on — no publication date is set in the instrument, so the code's own commencement is date TBD; the ICO lists 'Code of Practice on AI and Automated Decision Making' among its current AI work areas. The Explanatory Note states no significant sector impact from the instrument itself; the impact falls when the ICO produces the code (for which the ICO must produce its own impact assessment). Extends to England and Wales, Scotland and Northern Ireland. Companion to uk-duaa-adm.
Stated maximum penalty — No penalty in the instrument itself; the resulting code is enforced through UK GDPR/DPA 2018 powers (up to £17.5M or 4% of global annual turnover, whichever is higher)
UK
◆Binding
Binds Individual developers, distributors, and corporate bodies (criminal offences); Ofcom-regulated platforms (OSA priority-content duty). Criminalises making, adapting, possessing, supplying, or offering to supply AI models optimised to generate CSAM (up to 5 years imprisonment). Separately criminalises AI “nudification” tools/deepfake intimate image generators. Upgrades AI-generated intimate image creation to priority offences under the Online Safety Act; Ofcom-regulated platforms must prevent and remove such content (up to £3M penalty for non-compliance).
Royal Assent: 29 April 2026 (2026 c.20). Section 99 (purported intimate image generators) commenced 29 June 2026 via UKSI 2026/689 (Commencement No. 1) reg. 2(i). The CSAM image-generator offences (ss.72-74) are NOT yet in force — legislation.gov.uk marks them "Prospective" (s.72 not in force at Royal Assent, see s.255(1)), pending a further commencement instrument.
Stated maximum penalty — 5 years imprisonment (CSA/deepfake AI generator offences, once commenced); £3M Ofcom fine (platform intimate image duty)
US · TN
◆Binding
Binds Tennessee Advisory Commission on Intergovernmental Relations (TACIR) — study mandate only; imposes no compliance duties on AI operators. As enacted, SB 1700 does not impose chatbot safety requirements on operators. Senate amendments stripped the original companion-chatbot restrictions and replaced them with a directive for TACIR to study potential AI/chatbot regulation (federal law, other states' approaches, constitutional issues, minor/mental-health safeguards, economic impact); no report deadline is specified.
Effective 2026-05-22, the date carried in the "Effective date(s)" field of the Tennessee General Assembly bill-status record; Section 4 of Public Chapter 1082 reads "This act takes effect upon becoming a law, the public welfare requiring it" (publications.tnsosfiles.com/acts/114/pub/pc1082.pdf), so there is no deferred application. The same record lists the governor's signature action on 2026-05-27; the enrolled chapter's approval stamp is a handwritten scan and is not machine-readable, so the 05/22 effective date is taken from the legislature's own field rather than reconstructed from the signature. Bill was substantially amended (Senate amendments adopted 2026-04-14) before passage, removing the original chatbot-safety restrictions.
Stated maximum penalty — None — study mandate only; no compliance obligation imposed on AI operators
US · HI
◆Binding
Binds Operators of conversational AI services accessible in Hawaii. AI-identity disclosure, minor safeguards, and suicide-prevention protocols for conversational AI operators.
Annual crisis-intervention referral reports to Behavioral Health Administration beginning 2028-01-01.
Stated maximum penalty — $1,000/violation up to $1,000,000/operator
US · CO
◆Binding
Binds Conversational AI operators serving Colorado users. Safety, disclosure, and minor protection obligations for conversational AI operators in Colorado.
Signed 2026-05-29; legal effective date 2026-08-12; compliance obligations from 2027-01-01. Implementing rules are in progress: the Colorado Department of Law filed proposed ADMT & Conversational AI Service rules (4 CCR 904-6) covering both this act and SB 26-189 with the Secretary of State on 11 Aug 2026, with comments open 11 Aug–26 Oct 2026 (4 Sep 2026 for comments feeding the revised draft) and a rulemaking hearing on 26 Oct 2026; the rules are slated to take effect 1 Jan 2027. This act is outside the X. AI LLC v. Weiser enforcement stay, which reaches only SB 24-205 and its in-session replacement SB 26-189.
Stated maximum penalty — CO AG enforcement
US · CT
◆Binding
Binds Operators who provide or operate an artificial intelligence companion for users in Connecticut, with heightened duties where the user is under 18. Operators of AI companions have until 1 Jan 2027 before disclosure, crisis-referral and minor-protection duties bite.
Public Act No. 26-15 ss 4-6, each expressly '(Effective January 1, 2027)'. s 5 sets baseline operator duties; s 6 adds under-18 duties, including a clear and conspicuous statement at the start of each interaction that the companion is not a licensed mental health professional, bars on romantic/erotic interaction with minors, bars on discouraging a minor from seeking mental health services or adult help, and bars on manipulative engagement-extension techniques. Violations of ss 5 and 6 are unfair or deceptive trade practices enforced solely by the Attorney General.
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)
US · OR
◆Binding
Binds AI companion and chatbot platform operators serving Oregon users. AI disclosure, self-harm protocols, and minor protections; first chatbot law with private right of action and per-violation statutory damages.
Stated maximum penalty — Greater of actual damages or $1,000 per violation; private right of action; attorney fees
US · WA
◆Binding
Binds AI companion chatbot operators serving Washington users. Non-human disclosure, minor safeguards, and self-harm protocols for AI companion chatbot operators.
Disclosures every 3 hours (all users) or 1 hour (minor users).
Stated maximum penalty — Actual damages + injunctive relief + attorney fees; WA AG (Consumer Protection Act)
US · GA
◆Binding
Binds Operators of conversational AI chatbot services accessible to the Georgia public. Age verification, parental controls, AI-identity disclosure, and crisis protocols for conversational AI chatbot operators.
Stated maximum penalty — Up to $10,000 per knowing violation (GA AG enforcement)
US · ID
◆Binding
Binds Consumer-facing conversational AI service operators serving Idaho users (excludes B2B, internal, customer-service bots). AI identity disclosure, crisis referral protocols, and minor safeguards for consumer-facing conversational AI operators.
Modeled on Nebraska LB 525. Signed 2026-03-31 (Idaho Legislature bill-status page; corrected from a prior 2026-04-01 note).
Stated maximum penalty — Idaho AG enforcement (amount TBD)
US · NE
◆Binding
Binds Conversational AI service operators serving Nebraska users. Operators of consumer-facing conversational AI services must disclose AI nature, apply enhanced safeguards for minors, avoid claiming to provide professional mental health care, and provide crisis intervention referrals.
Signed April 14, 2026; operative July 1, 2027 (sections 12–18).
Stated maximum penalty — $1,000 per violation; up to $500,000 per operator per enforcement action; Nebraska AG enforcement only
US · CT
◆Binding
Binds Covered operators of covered platforms serving Connecticut users who are under eighteen. Covered platform operators have until 1 Jan 2028 before personalised feed and related restrictions apply to users under 18.
Public Act No. 26-15 s 39, expressly '(Effective January 1, 2028)'. Bars a covered operator from serving a covered minor a personalised recommendation feed based on information associated with the user or the user's device unless one of the listed conditions is met, including commercially reasonable and technically feasible age determination or verifiable parental consent. s 39(g) deems violations of subsections (b)-(e) unfair or deceptive trade practices under Conn. Gen. Stat. s 42-110b(a).
Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)