AI LAW RADAR · Daily Last verified 23 Sep 2026

Topic dossier

Prohibited & banned AI practices

The AI uses that are forbidden outright — manipulative systems, social scoring, non-consensual intimate imagery and algorithmic price coordination — regardless of safeguards. 35 obligations across 20 jurisdictions — 28 in force, 2 proposed. Next dated deadline: 1 Dec 2026.

Above the risk tiers sits a smaller set of outright bans. The EU AI Act’s Article 5 is the broadest: it prohibits social scoring, manipulative and exploitative systems, untargeted facial-image scraping and more. Texas, Peru and the US TAKE IT DOWN Act add their own prohibitions. A second, newer family bans a specific commercial use of algorithms rather than a technique: New Jersey and Illinois forbid software that coordinates residential rents between competing landlords, and Maryland forbids setting retail food prices from an individual shopper’s personal data. These are the lines that hold regardless of safeguards or consent.

The Register

35 obligations · 20 jurisdictions

Albania 1

Albania Binding

Law 124/2024 art. 53 — solely automated decisions banned for police, prosecutors and security bodies, plus an exceptionless ban on discriminatory profiling

Binds Competent authorities only, and the Law defines the trigger by purpose rather than by institution. Part III of the Law (arts. 47-74) governs the processing of personal data by competent authorities for public or national security and for the prevention, investigation, detection or prosecution of criminal offences and the execution of criminal penalties, and art. 53 sits inside it. The division from art. 20 is by purpose: the same police force processing its own payroll answers to art. 20. Private controllers are outside art. 53 entirely, with one edge — a private body exercising delegated public powers for one of those purposes is a competent authority for these provisions. Art. 61 separately requires the controller's record of processing to carry information on the use of profiling where profiling is used, which gives the supervisor a documentary route into art. 53. Art. 100(1) repeals the whole Law on the date of Albania's accession to the European Union with the express exception of Parts III and IV, so art. 53 is one of the provisions drafted to survive accession; art. 100(2) keeps those provisions of the rest of the Law that Part III cross-refers to alive for competent-authority processing.. Art. 53 is the law-enforcement counterpart of art. 20 and, following art. 11 of Directive (EU) 2016/680, it is drafted as a prohibition on the authority rather than as a right the individual must invoke. Art. 53(1): «Ndalohet marrja e vendimeve të bazuara vetëm te përpunimi automatik, përfshirë profilizimin, të cilat sjellin pasoja ligjore negative për subjektin e të dhënave ose mund të ndikojnë ndjeshëm te subjekti i të dhënave, me përjashtim të rastit kur parashikohen shprehimisht me ligj, i cili parashikon masa të përshtatshme mbrojtëse për të drejtat e liritë themelore të subjektit të të dhënave dhe të drejtën që t'i sigurohet ndërhyrje manuale nga ana e kontrolluesit.» Three drafting choices matter. The effects limb is narrowed by «negative» — the legal consequences must be adverse — but widened by «mund të ndikojnë», so the prohibition bites on the capacity to affect the person significantly rather than on realised effect. There is no consent exit and no contract exit: the single way out is an express statutory basis that itself prescribes appropriate safeguards, and the floor for those safeguards is named in the article — the right to manual intervention by the controller. And unlike art. 20(4), the person is given no right here to express a view or to contest the decision; the enabling statute must supply whatever more it supplies. Art. 53(2) does two things: such decisions may not rest on sensitive data unless appropriate measures protecting the data subject's rights, fundamental freedoms and legitimate interests are in place, and — as a separate sentence — decisions under para. 1 that result in discrimination against natural persons on the basis of sensitive data are prohibited outright. Art. 53(3) then goes wider than any decision: «Profilizimi që sjell si pasojë diskriminimin e personave për shkak të të dhënave sensitive është i ndaluar.» That is a flat, exceptionless ban on profiling which results in discrimination on sensitive-data grounds — tied to no decision, to no effects threshold and to no «solely automated» qualifier, so it reaches profiling that merely feeds a human decision, and it admits no statutory override. It is the near-exact twin of art. 39(3) of Serbia's Personal Data Law, and the two are the only provisions of their kind in this dataset. Art. 52(2) makes the specific limits of art. 53(2) a condition on any processing of sensitive data by a competent authority.

In force since 1 February 2025 on the same art. 101(1) timetable as art. 20; art. 53 is not in the art. 101(2) list of articles deferred to 17 January 2027. Art. 101(1): «Ky ligj hyn në fuqi 15 ditë pas botimit në Fletoren Zyrtare.» Publication in Fletorja Zyrtare nr. 9 was on 17 January 2025, so the Law entered into force on 1 February 2025. Art. 101(2) defers a closed list of articles — 29(3), 31, 32, 35, 36, 64, 65 and 67(2), (3) and (5) — to two years after publication, that is 17 January 2027; the deferred list covers the data-protection impact assessment at art. 31, prior consultation at art. 32, codes of conduct at art. 35 and monitoring bodies at art. 36, and it does NOT contain art. 20 or art. 53, both of which have applied since 1 February 2025. Art. 99(1) repealed Law no. 9887 of 10 March 2008 on the protection of personal data, as amended, on the same day, so the 2008 regime is superseded rather than supplemented; art. 99(2) keeps the sub-legal acts made under the 2008 Law alive until replaced, so far as they do not conflict. Art. 98 converts every reference to the 2008 Law in other legislation into a reference to this Law. Art. 100 is unusual and worth reading before relying on this row long term: on the date of Albania's accession to the European Union all provisions of this Law are repealed except those of Parts III and IV, so art. 20 is drafted to fall away in favour of the GDPR itself while art. 53 is drafted to survive. Art. 53 is new law rather than a re-enactment: the repealed Law no. 9887/2008 had a single automated-decision provision and no prohibition addressed to law-enforcement bodies, and nothing resembling the art. 53(3) discriminatory-profiling ban. Supersession check, 27 August 2026: no amending act to Law 124/2024 is recorded in the QBZ repository and the corrigendum reprint of 24 June 2025 leaves art. 53 byte-identical. Albania has no AI-specific statute in force and no published bill. A draft National AI Strategy 2025-2030 went to public consultation in 2025 and has not been adopted; the Digital Agenda 2022-2026 and a Council of Ministers decision on methodology and technical standards for the use of AI in public administration are policy instruments addressed to state bodies, not obligations on controllers, and formal drafting of an EU AI Act-aligned law is expected only on the accession timetable. Nothing is tracked as an obligation on that basis. The text relied on is the promulgated Law as published by the Qendra e Botimeve Zyrtare in Fletorja Zyrtare nr. 9, dated 17 January 2025, read end to end from the QBZ repository's own PDF at https://qbz.gov.al/alfresco/api/-default-/public/alfresco/versions/1/nodes/921d3810-ab2a-4e45-bdca-bef3a84b2721/content — 327,906 bytes, closing «Miratuar në datën 19.12.2024. Shpallur me dekretin nr. 5, datë 15.1.2025, të Presidentit të Republikës së Shqipërisë, Bajram Begaj.» The ELI cited as the source is the official QBZ permalink for the same act and is the human-facing citation; qbz.gov.al is an Angular single-page application that answers a 4,274-byte shell to every path, so a fetch of the ELI proves nothing — that is the shell, not rot, the same pattern as Serbia's pravno-informacioni-sistem.rs and Senegal's cdp.sn. QBZ also carries a corrected reprint, ligj-2024-12-19-124-korrigjuar.pdf, published 24 June 2025 under the consolidated ELI http://qbz.gov.al/eli/ligj/2024/12/19/124/cons/202506-24; it was downloaded and diffed against the original, and the text of arts. 20 and 53 is byte-identical in both, so the corrigendum does not touch either rule.

Stated maximum penalty — No fine ceiling is stated for this article, and that gap is on the face of the Law rather than a gap in this research. Art. 92 states generally that breaches of the Law by controllers or processors are punished with administrative sanctions in accordance with the following articles of the chapter, and art. 93(1) then directs the Commissioner to impose sanctions «për shkeljet e këtij ligji, sipas pikave 1, 2 dhe 3, të nenit 94» — that is, according to the enumeration in art. 94. That enumeration is drawn entirely from Part II and from the Commissioner's own orders: art. 94(1) covers arts. 8(6) and 11 and Chapter III of Part II, certification bodies under arts. 37-38 and monitoring bodies under art. 36(3); art. 94(2) covers the principles at arts. 6-9, data-subject rights at arts. 12-20, third-country transfers at arts. 39-42 and the duties at arts. 43-46; art. 94(3) covers non-cooperation with the Commissioner and breach of an order, temporary or definitive processing limitation or suspension of data flows issued under art. 83(2)(b), at up to 2,000,000,000 lekë or 4% of global turnover. None of those items reaches Part III, so a breach of art. 53 attracts no article-specific fine tier; what remains against a competent authority is the Commissioner's corrective powers, the art. 83(2)(b) orders whose breach IS fineable at the top band under art. 94(3), and the individual's remedies under Part V, including the art. 90 right to have the Commissioner review the lawfulness of a competent authority's response and the processing behind it, and the art. 91 preliminary limitation order. The same structural gap exists in Serbia, where art. 95(1)(19) is written around a decision producing legal consequences and does not obviously reach the standalone art. 39(3) profiling ban. Impact tier: public sector.

In force · 1 Feb 2025 checked 10 Sep 2026 Law 124/2024 art. 53 ↗ high confidence

Argentina 1

Argentina Binding

Ley 25.326 Art. 20 — judicial and administrative decisions may not rest solely on automated profiling

Binds Courts issuing judicial decisions and public bodies issuing administrative acts in Argentina where the decision appraises or evaluates human conduct, whatever the underlying data file (Art. 20 sits in Chapter III, on the rights of data subjects, and applies alongside the general scope in Art. 1). Impact tier: all entities in the sense that any public or private data file feeding such a decision is exposed to the nullity, but the duty itself falls on the public decision-maker.. Art. 20 of the Ley de Protección de los Datos Personales (Ley 25.326), headed 'Impugnación de valoraciones personales', provides that judicial decisions and administrative acts which involve the appraisal or evaluation of human conduct may not have as their sole basis the result of automated processing of personal data that yields a definition of the data subject's profile or personality, and that acts contrary to that rule are incurably void ('insanablemente nulos'). It is Argentina's only in-force statutory constraint on automated decision-making: unlike LGPD Art. 20 in Brazil or PIPA Art. 37-2 in Korea it confers no request-for-review procedure and does not reach private-sector recommender systems or algorithmic work dispatch, and its remedy is nullity of the act rather than a right exercised against a controller. The related access right in Art. 15 requires information held about the subject to be supplied in clear form, and Art. 43 of the Constitution supplies the habeas data action used to enforce Chapter VII.

Ley 25.326 was sanctioned 4 October 2000 and partially promulgated by Decreto 995/2000, published in the Boletín Oficial on 2 November 2000. The law contains no commencement clause, so the residual rule of the Código Civil then in force (Art. 2, Ley 340) applied — laws bind after the eight days following official publication — giving 11 November 2000. Art. 20 was not among the provisions vetoed by Decreto 995/2000, which struck only points 2 and 3 of Art. 29 inc. 1 and Art. 47; the text was read in the Ministerio de Justicia InfoLeg consolidated version, which records the veto history in its Antecedentes Normativos. The commencement date is a derivation from the residual civil-law rule rather than a date stated in the instrument; the substance of the article, and the fact that it binds today, are not in doubt. Added in the AIL-211 LATAM coverage-symmetry sweep as Argentina's nearest peer of cn-pipl-art24 and br-lgpd-art20; no Argentine in-force peer of the recommendation off-switch (CAC Art. 17) or algorithmic work dispatch (CAC Art. 20) was found.

Stated maximum penalty — The sanction attached to Art. 20 itself is civil: an act founded solely on automated profiling is incurably void (Art. 20.2), which the data subject may pursue through the habeas data action of Arts. 33-43. Separately, Art. 31 empowers the supervisory authority (now the Agencia de Acceso a la Información Pública) to impose a warning, suspension, a fine of ARS 1,000 to ARS 100,000, or closure or cancellation of the data file, without prejudice to civil damages and to the criminal offences in Arts. 117 bis and 157 bis of the Código Penal; the peso figures are the un-indexed statutory amounts as enacted in 2000.

In force · 11 Nov 2000 checked 18 Sep 2026 Ley 25.326 Art. 20 ↗ high confidence

Azerbaijan 1

Azerbaijan Binding

Law on Personal Data art. 7.3 — an objection right against decisions taken by information technology, whose remedy is re-processing by another method or a full stop

Binds Owners («mülkiyyətçi») and operators («operator»), the Law's two controller-analogues — art. 2.1 defines the owner as the person who owns the information system and determines the purpose and scope of collection and processing, and the operator as the person who carries out collection and processing under a contract with or on the instruction of the owner. Art. 10.2 applies the operator's duties to an owner that performs them itself. The Law's preamble extends it to state and local self-government bodies and to legal and natural persons alike, so public-sector deployers are inside it on the same terms as private ones. There is no size threshold, no sectoral limit and no turnover test anywhere in art. 7. The reach is territorial and system-based rather than targeting-based: the Law regulates collection, processing and protection of personal data and the formation of the personal-data segment of the national information space, and art. 15 requires state registration of personal-data information systems, which is the hook that brings a system within the regime. Art. 3.2 carves out processing outside the Law's scope, and art. 10.5 requires operators to facilitate intelligence, counter-intelligence and operative-search measures and to keep the methods used confidential.. Art. 7.3 of the Law of the Republic of Azerbaijan on Personal Data (No. 998-IIIQ of 11 May 2010) is an automated-decision rule that never uses the word automated, which is why keyword sweeps miss it: the operative term is «informasiya texnologiyaları vasitəsilə» — by means of information technologies. The sentence reads «İnformasiya texnologiyaları vasitəsilə fərdi məlumatların toplanılması və işlənilməsi nəticəsində qəbul olunan qərar subyektin mənafeyini pozduğu halda, qanunvericiliklə müəyyən olunmuş qaydada məcburi xarakter daşıdığı hallar istisna olmaqla, subyektin bu məlumatların göstərilən üsulla toplanılmasına və işlənilməsinə etiraz etmək hüququ vardır» — where a decision taken as a result of the collection and processing of personal data by means of information technologies infringes the subject's interests, the subject has the right to object to the collection and processing of that data by that method, save where the processing is mandatory in the manner established by legislation. The whole of the Law was read end to end in its consolidated text on e-qanun.az, the official corpus of the Ministry of Justice; the words «avtomat» and «profil» appear nowhere in its nineteen articles. Four features set it apart from the GDPR art. 22 family. First, there is no «solely» qualifier and no profiling concept: the trigger is the method of processing, so a decision produced with information technology in the loop and a human signing it off is caught, where GDPR art. 22 and the Kazakh, Uzbek and Russian analogues would let it through. Second, the effects threshold is «subyektin mənafeyini pozduğu halda» — infringes the subject's interests. That is lower and wider than legal effects or similarly significant effects, and like the Turkish art. 11(g) it is adverse-only, so a favourable machine-made decision produces no right. Third, the remedy is not human intervention. Art. 7.3 second sentence obliges the owner or operator, on receiving the objection, either to obtain the subject's consent to process the data «digər üsulla» — by another method — or to stop the processing «təxirə salmadan», without delay. The subject cannot demand that a person re-take the decision, but can force the processing off the information-technology track altogether, which no GDPR-family rule offers. Fourth, the exception architecture is a single item: processing made mandatory by legislation. There is no consent limb and no contract limb, so a controller cannot buy its way out with a consent click. There is no explanation or logic-disclosure limb tied to automation. Art. 7.1.2 gives a general right to demand the legal justification for collection, processing and third-party disclosure and to be told what legal consequences these will have for the subject, and art. 11.2 lists what must be told at collection — identity, purpose and its legal basis, the protection level of the information system, whether that system holds a conformity certificate and has passed state expert examination, the circle of intended users, and the subject's rights under the Law — but neither list carries an automated-decision or logic item. Art. 7.5 adds real procedural friction: the art. 7.1 to 7.3 rights are exercised only by a written paper application presented with an identity document, or by an electronic request bearing an enhanced electronic signature. Art. 7.2 sits alongside it as a general objection right with the same stop-immediately consequence and no requirement to give reasons, so a subject who cannot show that a decision infringed their interests can often reach the same outcome by the more general route.

In force, and art. 7.3 is original 2010 text: the consolidated version on e-qanun.az marks amended provisions with bracketed source-document numbers — art. 8.2 carries [3] and art. 8.6 carries [4] — and art. 7 carries none across all five of its paragraphs, so none of the six amending laws listed in the source-document schedule (20 June 2014, 3 April 2018, 8 July 2022 and later) touched it. The commencement date is derived rather than stated, which is why confidence on the date alone is medium. The Law has no entry-into-force article: art. 19 is the last article and deals with liability, after which the text runs straight to the President's signature of 11 May 2010. It was published in «Azərbaycan» gazette on 6 June 2010, no. 121, and in the Collection of Legislative Acts of 30 June 2010, no. 06, art. 480, which under the ordinary rule puts it in force on publication. The e-qanun record separately carries a registration date of 1 July 2011 in its «registerDate» field and leaves «effectDate» null; that field tracks the state registry entry, not commencement, but the discrepancy is recorded here rather than resolved silently. Nothing turns on it for a reader today — the rule has been binding for well over a decade on either reading. Azerbaijan has no AI-specific statute and no GDPR-style replacement law in force.

Stated maximum penalty — 300 to 500 manat, roughly USD 175 to 295 — the lowest ceiling in the atlas. Art. 19 of the Law itself sets no figure, providing only that those guilty of violating it bear liability in the manner prescribed by the legislation of Azerbaijan. The quantum sits in art. 375 of the Code of Administrative Offences (Law No. 96-VQ of 29 December 2015), «violation of the legislation on personal data». Art. 375.0.2 is the limb that reaches art. 7.3: it penalises an owner or operator for failing to ensure the protection of personal data, for failing to destroy personal data in the cases and within the periods the Law requires, and — the operative words here — «fərdi məlumatların toplanılmasının, işlənilməsinin və ya verilməsinin dayandırılmamasına görə», for failing to stop the collection, processing or transfer of personal data. That is exactly the duty art. 7.3 imposes once an objection is received, so ignoring an objection is a discrete administrative offence rather than a matter for damages alone. Art. 375.0.1 covers collecting or processing in an information system that has not passed the state registration the Law requires. Unusually, art. 375.0 draws no distinction between natural persons, officials and legal persons and applies no turnover multiplier: the band is flat at 300 to 500 manat however large the offender. The separate civil route is art. 7.4 and art. 10.1 of the Law — complaint to the relevant executive authority or to a court, with material and moral damage assessed by the court and paid by the owner.

In force · 6 Jun 2010 checked 20 Sep 2026 Personal Data Law art. 7.3 ↗ medium confidence

Chile 1

Chile Binding

Ley 19.628 Art. 8° bis (inserted by Ley 21.719) — right to object to solely-automated decisions and profiling

Binds Controllers of personal data ('responsables de datos'), public and private, within the scope of Ley 19.628 as amended, including controllers not established in Chile whose processing is aimed at offering goods or services to data subjects in Chile or at monitoring their behaviour, expressly including its analysis, tracking, profiling or prediction. Impact tier: all entities.. Ley 21.719, which overhauls Chilean data-protection law and creates the Agencia de Protección de Datos Personales, inserts a new Art. 8° bis into Ley 19.628 headed 'Decisiones individuales automatizadas, incluida la elaboración de perfiles'. The data subject has the right to object to, and not to be subject to, decisions based on the automated processing of their personal data, including profiling, that produce legal effects on them or significantly affect them. The right does not apply where the decision is necessary to conclude or perform a contract between the subject and the controller, where the subject has given prior express consent in the form prescribed by Art. 12, or where a law so provides and lays down safeguards. In all cases of automated decision-making, including those three exceptions, the controller must adopt the measures needed to secure the subject's rights and freedoms, their right to information and transparency, and their right to obtain an explanation, to human intervention, to express their point of view and to request review of the decision. 'Elaboración de perfiles' is defined in the new Art. 2 w) as any automated processing used to evaluate, analyse or predict a person's professional performance, economic situation, health, preferences, interests, reliability, behaviour, location or movements. Two related duties attach: Art. 14 ter l) requires the controller to disclose the existence of automated decisions and profiling together with meaningful information on the logic applied and the expected consequences, and Art. 15 bis makes a data-protection impact assessment mandatory where there is systematic and exhaustive evaluation of personal aspects based on automated processing or decisions, such as profiling, producing significant legal effects.

Ley 21.719 was published in the Diario Oficial on 13 December 2024. Artículo primero transitorio provides that the amendments to Ley 19.628, Ley 20.285 and Ley 19.496 contained in the first, second and third permanent articles enter into force on the first day of the twenty-fourth month after publication, i.e. 1 December 2026 — the same date carried in the BCN norm metadata (fecha_vigencia 2026-12-01, idNorma 1209272). Artículo segundo transitorio required the implementing regulations within six months of publication and Artículo cuarto transitorio required the first Agency board to be appointed six months before entry into force; implementation instruments already published include Decreto 12 of 17 June 2025 creating the ministerial implementation commission, Resolución Exenta 202503748 of 19 December 2025 approving the model contractual clauses for international transfers, and Resolución Exenta 1400 of 24 June 2026 on the procedures for Arts. 54 and 55, the last two of which themselves take effect on 1 December 2026. Text read in the Biblioteca del Congreso Nacional LeyChile XML for idNorma 1209272 via the backend host servicios-leychile.bcn.cl after the public www.bcn.cl endpoint returned HTTP 429. Chile's peer of br-lgpd-art20, cn-pipl-art24, kr-pipa-art37-2-adm and ar-ley25326-art20; unlike Argentina's Art. 20 it is a full GDPR-style right with explanation, human intervention and review, and unlike Brazil's Art. 20 it is not yet in force. Postponement risk (as of 2026-08-17): 1 December 2026 remains the legally operative date on the face of the law — no decree or amending law has changed it — but on 4 August 2026 co-Minister of Economy Daniel Mas publicly confirmed the government is evaluating postponing entry into force, because the Agencia de Protección de Datos Personales still has no seated Consejo Directivo: the Senate rejected the President's first slate of three nominees in May 2026 for lack of the required two-thirds quorum, and the June 2026 statutory deadline to appoint the board has lapsed. No amending bill has yet been introduced. Source: https://www.emol.com/noticias/Economia/2026/08/04/1207539/gobierno-postergar-ley-datos-personales.html Update (2026-09-04): on 1 September 2026 the Executive formally introduced a bill to the Senate, with urgency, to postpone Ley 21.719's entry into force from 1 December 2026 to 1 December 2027 and to expand the Agencia's Consejo Directivo from 3 to 5 members; the bill has not passed, so 1 December 2026 remains the operative statutory date. Source: https://www.df.cl/economia-y-politica/congreso/gobierno-ingresa-al-congreso-proyecto-que-posterga-por-un-ano-la-entrada-en AIL-300 computation check (2026-08-31): 1 December 2026 is verified against the statutory text, not derived by arithmetic. Artículo primero transitorio reads verbatim «entrarán en vigencia el día primero del mes vigésimo cuarto posterior a la publicación de esta ley en el Diario Oficial» (LeyChile XML for idNorma 1209272 via servicios-leychile.bcn.cl, fechaPublicacion 2024-12-13). That clause designates a calendar day, not a plazo, so the Código Civil rules on computing statutory terms have nothing to move: art. 48 governs «todos los plazos de días, meses o años» and fixes the same-numbered-day rule for month-plazos, and art. 49 provides that where «se exige que haya transcurrido un espacio de tiempo para que nazcan o expiren ciertos derechos» those rights arise only «después de la medianoche» ending the last day — which is precisely the trap that moved py-ley7593-art33 by a day. Neither applies here, because no period has to elapse: the article names the first day of a stated month. December 2024 is the month of publication and so is not «posterior a la publicación»; the first posterior month is January 2025 and the twenty-fourth is December 2026, giving 1 December 2026 — the same date carried in the BCN norm metadata.

Stated maximum penalty — Enforced by the Agencia de Protección de Datos Personales under the new sanction regime of Ley 19.628. Art. 35: minor infringements draw a written warning or a fine of up to 5,000 UTM, serious infringements up to 10,000 UTM and very serious infringements up to 20,000 UTM. Obstructing or impeding the legitimate exercise of the right to object is a serious infringement under Art. 34 ter e); any other breach of the rights and duties of the law that is not classified as serious or very serious is a minor infringement under Art. 34 bis f). Repeat infringement allows a fine of up to three times the amount for the infringement committed, and for an infringer that is not a smaller enterprise under Art. segundo of Ley 20.416 repeating a serious or very serious infringement, up to 2% or 4% of annual turnover from sales, services and other business activities in the last calendar year. Repeated very serious fines within twenty-four months allow suspension of processing operations for up to thirty days (Art. 38). For public bodies the fine is 20% to 50% of the monthly salary of the head of the infringing body.

Applies 1 Dec 2026 checked 22 Sep 2026 Ley 19.628 Art. 8° bis (Ley 21.719) ↗ high confidence

China 1

China Binding

Anthropomorphic AI Interactive Services Measures

Binds Providers of anthropomorphic AI interactive services (virtual companions, emotional chatbots, human-like AI) publicly available in mainland China. Dedicated compliance regime for AI companion services, virtual chatbots and emotionally interactive AI; mandates AI-identity disclosure, minor protections, usage-time warnings, and prohibits inducing emotional dependence.

In force 15 Jul 2026. No confirmed enforcement actions as of 2026-08-08: exhaustive cross-check (Bird & Bird, IAPP, Covington, CAC official news/enforcement index, DigitalPolicyAlert) found no penalty decisions or enforcement notices. CAC does not publish a searchable administrative-penalty registry. A claim of 12 fines / RMB 4.2M circulates in AI-generated blog content (Cubbbix, Aug 2026; republished by Ethicore Substack verbatim) — not independently verifiable and treated as unconfirmed.

Stated maximum penalty — CAC administrative penalties, including fines of RMB 10,000-200,000; service suspension

In force · 15 Jul 2026 checked 4 Sep 2026 CAC Anthropomorphic AI Interim Measures (2026) ↗ high confidence

Ecuador 1

Ecuador Binding

LOPDP art. 20 — the automated-decision right that drops «solely»: «única o parcialmente»

Binds Responsables and encargados del tratamiento — controllers and processors. Art. 3 reaches processing carried out anywhere in national territory, controllers or processors domiciled in Ecuador, and controllers or processors not established in Ecuador that process the data of subjects residing in Ecuador where the activity relates to offering goods or services to them, payment required or not, or to monitoring their behaviour in Ecuador; a fourth limb picks up cases where Ecuadorian law applies by contract or by public international law. Art. 20 covers administrative acts and private decisions alike, so there is no public-sector carve-out — the sanctions articles instead split the tariff between public servants and private or state-owned entities. Impact tier: all entities.. Art. 20 of the Ley Orgánica de Protección de Datos Personales (Quinto Suplemento del Registro Oficial Nº 459 of 26 May 2021, adopted 10 May 2021) is titled «Derecho a no ser objeto de una decisión basada única o parcialmente en valoraciones automatizadas» — a right not to be subject to a decision based wholly OR PARTLY on automated valuations. The two words «o parcialmente» are the finding. Every other transposition in the atlas of the GDPR art. 22 family keeps the «solely» limb, and the argument that partial automation with a human rubber-stamp escapes the rule is the most contested question in that family; Ecuador removed the question from the text in 2021. The effects threshold is widened in the same sentence: the decision has to «produzcan efectos jurídicos en él o que atenten contra sus derechos y libertades fundamentales» — produce legal effects in the subject OR infringe their fundamental rights and freedoms — where GDPR art. 22(1) asks for a similarly significant effect. The right is also built as a bundle of five active entitlements rather than an abstention: a reasoned explanation of the decision taken (a), the filing of observations (b), «los criterios de valoración sobre el programa automatizado» — the valuation criteria bearing on the automated program itself (c), the types of data used and the source they were obtained from (d), and challenge of the decision before the controller or processor (e). There are four exceptions, one more than the GDPR has: contract, authorising law (widened to include a judicial order or the reasoned mandate of a competent technical authority, with adequate safeguards established), explicit consent, and — with no counterpart in the GDPR — «la decisión no conlleve impactos graves o riesgos verificables para el titular», a de minimis exit for decisions carrying no serious impact or verifiable risk for the subject. Two closing sentences have no GDPR counterpart either: advance waiver of the right through mass adhesion contracts cannot be required, and the right is stated explicitly to the subject, by any suitable medium, no later than the first communication. That last sentence reverts to «basada únicamente en valoraciones automatizadas» — the notification duty is drawn back to solely-automated decisions while the right itself covers partly-automated ones, an internal inconsistency present in the gazette text. Art. 21 carries a dedicated companion right for children and adolescents: on top of art. 20, sensitive data and the data of children and adolescents are not processed this way absent the express authorisation of the subject or their legal representative, or an essential public interest assessed against international human-rights standards satisfying legality, proportionality and necessity and including specific safeguards; adolescents from 15 may consent as subjects in their own right. Arts. 12(14) and 12(17) make the transparency proactive — the existence of automated valuations and decisions, profiling included, forms part of the information given at collection.

In force since 26 May 2021: the Disposición Final states «La presente Ley entrará en vigencia una vez publicada en el Registro Oficial», and publication was in the Quinto Suplemento del Registro Oficial Nº 459 of that date. The corrective-measures and sanctions regime is the exception — Disposición Transitoria Primera delayed it by two years from publication, so fines became available on 26 May 2023, and Disposición General Séptima states in terms that the rights «podrá ser exigido por el titular independientemente de la entrada en vigor del régimen sancionatorio», an explicitly enforceable-but-unfineable interval that no other instrument in the atlas spells out. Art. 20 was verified against the scanned gazette itself — page 23 of the Asamblea Nacional's copy of the Quinto Suplemento — and that reading corrected the commercial rendering: the gazette lists five lettered entitlements a) to e), where the widely circulated Lexis-typeset edition folds «e. Impugnar la decisión» into item d) by reading the letter «e» as the conjunction. Ecuador's data-protection authority, the Superintendencia de Protección de Datos Personales, has been operating since 2023 and issues general norms under art. 76(5) of the Law. No amendment: the government-hosted consolidated editions of November 2024 and July 2025 both carry «Estado: Vigente / Fecha de última reforma: No aplica», and no reforming law was found through August 2026.

Stated maximum penalty — Split by the identity of the offender, not by the article breached. Art. 71 sets the light tariff — 1 to 10 unified basic salaries for a public servant, or 0.1% to 0.7% of the previous financial year's turnover for a private entity or state-owned enterprise. Art. 72 sets the serious tariff — 10 to 20 unified basic salaries, or 0.7% to 1% of turnover. Art. 73 defines turnover as sales of goods and services net of VAT and directly related taxes. There is a finding in the lists themselves. Neither art. 67 nor art. 68 names art. 20, so a controller that denies the right lands in art. 67(1) — failing to process, processing out of time or unjustifiably refusing a subject's petition — which is a LIGHT infraction; art. 70(1), the processor's list, is a catch-all reaching any processing «sin observar los principios y derechos desarrollados en la presente Ley», which is a SERIOUS one. The same refusal is therefore fined an order of magnitude apart depending on whether the entity acted as controller or as processor. Art. 72 also carries a cross-border enforcement fallback: where the offender has no domicile or legal representation in Ecuador, the resolution is notified to the data-protection authority of its principal place of business to carry the measures through.

In force · 26 May 2021 checked 15 Sep 2026 LOPDP art. 20 ↗ high confidence

Egypt 1

Egypt Binding

Executive Regulations of the Personal Data Protection Law (Ministerial Decree 816/2025) art. 14 — data taken from a child who takes part in a game, competition or other activity may not be used to classify, track or behaviourally monitor children

Binds كل من المتحكم أو المعالج، بحسب الأحوال، سواء كان شخصًا طبيعيًا أو اعتباريًا — the controller or the processor as the case may be, natural or legal person — in the terms of the opening words of مادة (١٤). The trigger is the child's participation in a game, competition or other activity, so the duty reaches games publishers, competition and promotion operators, ad-tech and analytics recipients of that data, and education and entertainment platforms, without any size or sector threshold. «الطفل» takes its meaning from the Egyptian Child Law No. 12 of 1996, which the enacting decree recites among its legal bases; مادة (١٥) of the Regulations treats under-15s and the 15-to-18 band differently for consent purposes but مادة (١٤) item 5 draws no such line and refers simply to الأطفال. Supervision is by the Personal Data Protection Centre. Impact tier: all entities.. Article 14 of the Executive Regulations, headed «المعايير والضوابط الخاصة بالتعامل على البيانات الشخصية الحساسة», binds the controller and the processor alike, natural or legal person, whenever sensitive personal data is collected, transferred, stored, kept, processed or made available. Its fifth item is the closest thing in Egyptian law to a profiling prohibition: «٥- فى حالة مشاركة الطفل فى لعبة أو مسابقة أو أى نشاط آخر يجب ألا يتحصل منه على أكثر مما هو ضرورى للمشاركة وألا تُستخدم هذه البيانات فى عمليات تصنيف أو تتبع أو مراقبة سلوكية للأطفال .» — where a child takes part in a game, a competition or any other activity, no more may be obtained from the child than is necessary for the participation, and that data may not be used in classification, tracking or behavioural-monitoring operations on children. The rule has two limbs that operate independently: a data-minimisation limb tied to the purpose of participating, and a flat use prohibition on three named operations. The prohibition is absolute on its face — it is not subject to consent, not subject to a legitimate-interest balance, and carries no exception for a parent's or guardian's authorisation, which is a notable contrast with the rest of the children's regime in مادة (١٥), where written parental consent is what unlocks processing for under-15s and the child's own consent joins it from 15 to 18. «تصنيف» (classification), «تتبع» (tracking) and «مراقبة سلوكية» (behavioural monitoring) are not defined in the Regulations, and the Centre's published bilingual glossary is a term list without definitions, so the scope of the three operations is not further specified in any primary text read here.

Primary source read: the certified gazette copy of the Executive Regulations published by the Personal Data Protection Centre itself, i.e. الوقائع المصرية — العدد ٢٤٤ تابع (أ) فى أول نوفمبر سنة ٢٠٢٥. The file is an MRC scan whose page text is JBIG2-coded with a /JBIG2Globals segment, which is why three earlier passes on this issue recorded it as unreadable; it is readable once the globals stream is prepended to the JBIG2 chunk list, and all 41 pages were decoded and read in the Arabic. Printed page 2 carries the enacting instrument, قرار وزير الاتصالات وتكنولوجيا المعلومات رقم ٨١٦ لسنة ٢٠٢٥ بإصدار اللائحة التنفيذية لقانون حماية البيانات الشخصية الصادر بالقانون رقم ١٥١ لسنة ٢٠٢٠; printed page 3 carries its المادة الأولى (the annexed Regulations are put into effect) and its المادة الثانية, «يُنشر هذا القرار فى الوقائع المصرية ، ويُعمل به من اليوم التالى لتاريخ نشره», signed د/ عمرو سميح طلعت. Gazette date 1 November 2025 and entry into force 2 November 2025 are therefore taken from the gazette, not from the regulator's website prose. The item was read at printed page 20 of that issue, where مادة (١٤) items 5 to 7 continue from items 1 to 4 at printed page 19. It is carried as a separate row from eg-erpdpl-art4-ai-training because it binds a different set of actors (controller and processor, not the processor alone), rests on a different trigger (a child's participation, not the use of a training technique), and is a prohibition rather than a standard of conduct. Checked negative, recorded so no later pass re-derives it: the Egyptian framework has NO GDPR art. 22 analogue. The Regulations' own الفهرس (printed pages 4 to 6) lists every heading through printed page 41 and contains no automated-decision or profiling heading; مادة (١) is a purely referential definitions article that takes the Law's definitions and adds none of its own; and the substantive articles 2 to 18 were read in full without finding a right not to be subject to a solely-automated decision. On the Law side, مادة (٢) of the Regulations, ثانيًا, item 1 confirms that PDPL art. 2 is the data-subject-rights article («إعلام الشخص المعنى بالبيانات بحقوقه وفق المادة (٢) من القانون»), and the Centre's own «Egypt's Personal Data Protection Framework» deck states at its page 12 that «the PDPL establishes nine fundamental rights for data subjects (PDPL Article 2)» and enumerates all nine — to be informed, of access, of withdrawal, of rectification, to erasure, to restrict, to object, of portability, and to be notified in case of data breach. No automated-decision or profiling right appears. The gazetted Arabic of the Law itself remains unreadable in this environment (the Centre's PDPL PDF draws every glyph as vector outlines, carries no text layer, no ToUnicode CMap and no page raster, and a full Wayback CDX sweep of mcit.gov.eg returns no copy of Law 151/2020), so the nine-rights list rests on a regulator publication rather than on statutory text and the absence of an art. 22 analogue is stated at that strength. The Centre's guidance treats automated decision-making as a factor inside the fairness principle rather than as a standalone right: its Data Protection Principles guideline lists «the use of automated decision-making and profiling: whether the processing involves automated decisions producing legal or significant effects on the data subject without human oversight» among the matters that bear on whether processing is fair. The practical effect is that Egypt regulates profiling only where children are concerned and only as a use prohibition, with no general profiling right or general profiling ban for adults anywhere in the Law or the Regulations as read.

Stated maximum penalty — Not quantified here, deliberately. The Regulations create the duty but carry no fine of their own: enforcement runs through the licence and permit regime they build, under which a متحكم or معالج must hold a licence or تصريح from the Centre before collecting or processing at all (مادة (٢) أولاً item 1, مادة (٣) أولاً item 1 and مادة (٤) أولاً item 1), the Centre's inspectors are مأمورو الضبط القضائى with a right of access to the electronic records (مادة (٣) أولاً item 7, مادة (٤) أولاً item 4), and every licence application must carry an إقرار بالوفاء بالجزاءات المالية والتعويضات التى يقرها المركز (printed page 42, item 8). The monetary scale sits in the penalties chapter of Law 151/2020 itself, and that text could not be read from any reachable official host this run, so no figure is published rather than a figure taken from a secondary summary.

In force · 2 Nov 2025 checked 14 Sep 2026 Executive Regulations of the PDPL art. 14 (Ministerial Decree 816/2025) ↗ high confidence

European Union 2

EU Comprehensive

Prohibited AI practices (Art. 5)

Binds All providers & deployers of AI systems in the EU. Bans on social scoring, manipulative AI, untargeted scraping.

Stated maximum penalty — Up to 7% global turnover or €35M

In force · 2 Feb 2025 checked 10 Sep 2026 EU AI Act ↗ high confidence
EU Comprehensive

New prohibitions — AI CSAM / intimate imagery

Binds All providers / deployers of such AI systems. New Art. 5 prohibition added by Digital Omnibus (Reg. EU 2026/1744, OJ L 2026/1744 published 24 Jul 2026); prohibits AI generation of CSAM and non-consensual intimate imagery. Applies from 2 Dec 2026.

Prohibition introduced by Regulation (EU) 2026/1744; the new Article 5 prohibition applies from 2 December 2026. Re-verified 2026-09-20 directly against the Official Journal PDF (CELEX 32026R1744): the Omnibus's Art. 1(7)(a) inserts new Art. 5(1) first subparagraph points (ba) [non-consensual intimate imagery] and (bb) [CSAM, referencing Directive 2011/93/EU Art. 2(c)/(e)]; Art. 1(40)(a) amends AI Act Art. 113 third paragraph point (a) to read "...with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026." Confidence restored to high.

Stated maximum penalty — Up to 7% turnover or €35M

Applies 2 Dec 2026 checked 23 Sep 2026 EU AI Act (Digital Omnibus) ↗ high confidence

Gabon 1

Gabon Binding

Ordonnance n° 0011/PR/2026 Chapitre VII (arts. 32-34) — deepfake prohibitions, a 24-hour AI-content takedown right, and the audit of AI detection and marking systems

Binds Art. 2 scope: the ordonnance applies to every user, editor or host of online social networks and digital platforms as soon as the content diffused is accessible on, or produces its effects on, Gabonese territory, and it also covers the treatment of any offer of publicly accessible online communication goods or services, whether free or for consideration. Art. 32's prohibitions attach to the content itself «indépendamment de leur lieu de création», so they reach content generated abroad; art. 41 gives the référé judge express extraterritorial competence. Art. 33's twenty-four-hour takedown duty binds the éditeur and the hébergeur as defined in art. 3 — respectively the person who by an active role and moderation power controls and implements diffusion, and the person who supplies the technical means of storage and public availability of third-party content. Art. 34's audit power reaches any social network or platform on which AI detection and marking systems are deployed. No size, turnover or user-number threshold appears anywhere in the ordonnance. Impact tier: all entities.. Chapitre VII of Ordonnance n° 0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux et des plateformes numériques — «De la régulation des contenus générés par intelligence artificielle» — is Gabon's first AI-specific binding rule, and it consists of exactly three articles. Art. 32 prohibits on national territory, «indépendamment de leur lieu de création», four classes of AI-generated content: hypertrucages realistically depicting an identifiable natural person in sexual situations without their express consent; hypertrucages of a public or private figure attributing to them false statements or conduct of a nature to cause serious harm to public order, national security or the dignity of persons; the representation of sexual situations involving minors, whatever the technical modality; and imitation of the visual or sound identity of a Gabonese State institution for disinformation purposes. Its closing paragraph makes content falling under those prohibitions liable to «la saisine immédiate du juge des référés». Art. 33 gives any identifiable natural person represented in AI-generated content published on a social network or digital platform without their consent a droit de signalement: the right to seise the editor or host to remove the illicit content within a maximum of twenty-four hours from the report, and, on refusal or inaction within that period, to go directly to the Haute Autorité de la Communication or the competent courts. Art. 34 lets the Haute Autorité de la Communication or the Ministère Public, on its own initiative, commission an independent technical audit of the AI-content detection and marking systems deployed on a social network or platform. Two provisions outside the chapter carry the AI rule further. Art. 42, in the référé numérique procedure created by arts. 39 to 44, lists among the provisional measures the juge des référés may order «l'apposition forcée d'un marquage d'origine sur un contenu généré par intelligence artificielle» — a court-ordered origin marking, alongside temporary suspension of an account or content, targeted de-referencing and publication of a correction; art. 41 gives that judge expressly territorial and extraterritorial competence and requires a ruling «d'heure à heure». Art. 52 supplies the one AI-specific criminal aggravator in the ordonnance: identity usurpation via a social network or platform is punished by five years' imprisonment and a fine of up to 20,000,000 FCFA, but where the same offences are committed «par le biais d'une intelligence artificielle» the penalty rises to ten years' imprisonment and a fine of up to 50,000,000 FCFA. The definitions article, art. 3, defines Contenu généré par intelligence artificielle as any text, image, video, audio or synthetic content created or substantially modified by an automated algorithmic system; Hypertrucage ou deepfake as image, audio or video content generated or manipulated by an artificial intelligence resembling existing persons, objects, places, entities or events and which would falsely appear authentic or truthful to a person; Intelligence Artificielle as a logical and automated process generally resting on an algorithm able to carry out well-defined tasks — the same formula as the Loi n° 025/2023 definition; and Marquage d'origine as a technical process allowing persistent and verifiable identification that a content was generated or modified by an artificial-intelligence system. The general labelling duty that gives that last definition its operative effect is not here: it sits in art. 53, in the transitional chapter, and is deferred — tracked separately as ga-ord0011-2026-art53-marquage.

Corrected 1 September 2026 against the primary gazette text, which had not been read when this row was first written on the same date; the original row rested on secondary legal commentary and was wrong in two respects that mattered. First, it recorded a labelling duty for AI-generated content as in force from 8 April 2026. The ordonnance contains no labelling duty in Chapitre VII at all: the marking obligation is in art. 53, in Chapitre XI «Des dispositions transitoires, diverses et finales», and it is expressly subject to a twelve-month period running from publication, so it does not bite until April 2027. That limb has been split out into ga-ord0011-2026-art53-marquage at lifecycle dateset. Second, the original row carried «fines up to 50,000,000 FCFA» as the penalty, taken from press reporting. Chapitre X, arts. 45 to 52, is the penal chapter, and none of arts. 45, 46, 47, 48, 50 or 51 attaches to arts. 32, 33 or 34: they punish, respectively, failure to publish mandatory identity information, an host's failure to give the editor identification means, failure to insert a right of reply within forty-eight hours, failure in the duty to combat the diffusion of illicit content, obstruction of the Haute Autorité de la Communication, and phishing. The 5,000,000 to 50,000,000 FCFA band the press attributed to the AI rules is the band of arts. 45, 46 and 48. The only penalty in the ordonnance that is AI-specific on its face is the final paragraph of art. 52, recorded in the penalty field here. There is no criminal penalty attached to art. 32 itself; its enforcement route is the référé numérique of arts. 39 to 44, which is a provisional-measures procedure, and art. 43 provides that any measure the référé judge orders expires automatically if no proceedings on the merits are commenced within one month of the seisin. Structure confirmed against the text: 55 articles in 11 chapters, signed at Libreville 26 February 2026 by the President of the Republic and countersigned by the Ministers of the Digital Economy, Defence, Communication and Media, the Interior and Justice. Art. 55 is a bare abrogation-of-contrary-provisions, registration and publication clause with no deferred commencement, so arts. 32 to 34, 39 to 44 and 52 took effect on publication. The date recorded is the opening date of the gazette issue in which the ordonnance was published, Journal Officiel de la République Gabonaise n° 110 covering 8 to 15 April 2026; the issue is dated as a week rather than as a day, so the true publication date lies between 8 and 15 April 2026, and confidence is set to medium on that account alone — every other statement in this row is read directly off the gazette text at pages 135 to 141. On sourcing: the official gazette host journal-officiel.ga carries the landing page for this instrument at https://journal-officiel.ga/22404-0011-pr-2026-/ but its port 443 timed out on every attempt this session, as it did when the Loi n° 025/2023 row was first written. The source_url therefore points at a complete scan of Journal Officiel n° 110 itself — every page carries the gazette's own running head «JOURNAL OFFICIEL DE LA REPUBLIQUE GABONAISE — 8 AU 15 AVRIL 2026 — N° 110» and its own pagination — rather than at a landing page that cannot be opened. Note one scanning artefact in the gazette itself: the AI aggravator paragraph of art. 52 prints the currency as «FCEA», a typographic error for FCFA, which is the unit used in every other penal article of the same chapter. Two companion ordonnances of the same date in the same issue, 0012/PR/2026 amending the Code de la Communication and 0013/PR/2026 on the Haute Autorité de la Communication, are not separately tracked: neither carries an AI-specific rule. Distinct from, and additional to, the automated-decision rule of the data-protection statute at Loi n° 025/2023 art. 77 — see ga-loi0252023-art77. Source moved 16 September 2026 off directinfosgabon.com (a Gabonese news site) onto the Journal Officiel's own host: the live page at https://journal-officiel.ga/22404-0011-pr-2026-/ still times out on port 443 from this egress, as it has every session since this row was written, so the citation is the Internet Archive's capture of that same official page — https://web.archive.org/web/20260611101549/https://journal-officiel.ga/22404-0011-pr-2026-/ — the CAR/Senegal/São Tomé remedy. The archived page is the gazette's own HTML rendering of Ordonnance n° 0011/PR/2026, not a scan, and its full text of arts. 32-34, 42, 45-53 and the signature block (Libreville, 26 February 2026, Brice Clotaire Oligui Nguema, countersigned by the Ministers of Digital Economy, Defence, Communications, Interior and Justice) was re-read end to end against this row and against ga-ord0011-2026-art53-marquage; every fact, including the «FCEA» typo for FCFA in art. 52's AI aggravator, matches verbatim. No substantive change.

Stated maximum penalty — No penal article of the ordonnance attaches to arts. 32, 33 or 34. Enforcement of the art. 32 prohibitions runs through the référé numérique of arts. 39 to 44: the juge des référés, seised by the Ministère Public, the Haute Autorité de la Communication or any person justifying an interest to act, rules «d'heure à heure» with territorial and extraterritorial competence and may order temporary suspension of an account or of a content, targeted de-referencing, publication of a correction, and forced application of an origin marking on AI-generated content; where a viral content causes manifestly serious disturbance, art. 44 adds temporary traffic slowing in identified zones, restriction of specific functionalities and temporary suspension of access to a platform, for a maximum of seventy-two hours. Art. 43 makes every such measure temporary and expires it automatically if no proceedings on the merits begin within one month of the seisin. The single AI-specific criminal penalty is the final paragraph of art. 52: where identity usurpation by means of a social network or digital platform — usurping a third party's identity or using data identifying them, so as to disturb their tranquillity or that of others, harm their honour, standing or interests, or with intent to commit, aid or encourage an illegal activity constituting a délit or a crime, which the preceding paragraph punishes with five years' imprisonment and a fine of up to 20,000,000 FCFA — is committed «par le biais d'une intelligence artificielle», the penalty is ten years' imprisonment and a fine of up to 50,000,000 FCFA. Breach of the art. 33 twenty-four-hour takedown duty is reachable in practice only through art. 48, the general duty of editors and hosts to combat the diffusion of illicit content, punished by one year's imprisonment and a fine of 5,000,000 to 50,000,000 FCFA or one of those penalties only — art. 3 defines contenu illicite as content harming human dignity, privacy, honour, bonnes mœurs or administrative security, which the art. 32 categories will usually satisfy, but the ordonnance does not make that link expressly.

In force · 8 Apr 2026 checked 21 Sep 2026 Ordonnance 0011/PR/2026 arts. 32-34 ↗ medium confidence

Georgia 1

Georgia Binding

Law on Personal Data Protection art. 19 — a GDPR-shaped automated-decision right whose exceptions cover only profiling, whose safeguards must be asked for, and whose fine tops out at GEL 20 000

Binds Controllers and processors. Art. 2(1) applies the Law to processing wholly or partly by automated means within the territory of Georgia, to non-automated processing of data forming part of or destined for a filing system, and — the extraterritorial hook — to processing by a controller not established in Georgia using technical means available in Georgia, except where those means serve solely to transit data. That is a means-based test rather than the GDPR's targeting test, so it can reach a foreign operator with equipment in Georgia and no Georgian customers. Such a controller must appoint a special representative in Georgia before processing begins (art. 36). Art. 19 sits in Chapter III (arts. 13-25), the rights chapter, so it binds anyone who is a controller for the decision in question. Art. 2(2)-(4) carve out purely personal or household processing and put semi-automated and non-automated processing of state-secret data for crime prevention, investigation and prosecution outside the Law; automated and semi-automated processing by those same institutions stays inside it. No sectoral limit and no size threshold applies to art. 19 — the SME relief in this Law runs to the data protection officer duty (art. 33) and to the size of the fine, never to the automated-decision right.. Art. 19 of the Law of Georgia on Personal Data Protection (No. 3144-XIმც-Xმპ of 14 June 2023) is titled «ავტომატიზებული ინდივიდუალური გადაწყვეტილების მიღება და მასთან დაკავშირებული უფლებები» — automated individual decision-making and related rights. Art. 19(1) gives the data subject the right not to be subject to a decision taken solely by automated means, including on the basis of profiling, which produces for them a legal effect or an effect of other substantial significance. Three features separate it from GDPR art. 22, and all three are in the Georgian text, not artefacts of translation. First, the exception clause is narrower than the prohibition it qualifies. Art. 19(1) reads «გარდა იმ შემთხვევისა, როდესაც პროფაილინგის საფუძველზე გადაწყვეტილების მიღება» — except where the taking of the decision *on the basis of profiling* is (a) based on the data subject's explicitly expressed consent; (b) necessary for concluding or performing a contract between the data subject and the controller; or (c) provided for by law or by a subordinate normative act issued within delegated statutory powers. The prohibition in the opening limb covers any solely automated decision; the escape hatches are drafted only for profiling-based ones. On the face of the text a solely automated decision that does not rest on profiling — a hard-coded threshold rule, for instance — has no exception route at all. Second, the safeguards are reactive. Art. 19(2) opens «მონაცემთა სუბიექტის შესაბამისი მოთხოვნისა» — upon the data subject's respective request — the controller must take appropriate measures to protect the subject's rights, freedoms and legitimate interests, including by involving human resource in the decision-making process, and by giving the subject the possibility to express a view and to contest the decision. GDPR art. 22(3) makes the same three safeguards a standing duty the controller owes without being asked; Georgia makes the subject go first, and gives no deadline for the controller's answer. Third, the human-review carve-out is inverted in the official English translation and must be read from the Georgian. The Georgian parenthesis is «(გარდა ამ მუხლის პირველი პუნქტის „გ“ ქვეპუნქტით გათვალისწინებული შემთხვევისა)» — human involvement is required *except* in the case under paragraph 1(c), the law-or-subordinate-act limb. matsne's English renders this as «including by involving human resources in the decision-making as provided for by paragraph 1(c)», which says the opposite: that human involvement attaches to the statutory limb. The Georgian reading is the GDPR-aligned one — human review for the consent and contract routes, none for decisions the legislature itself mandated — and the Georgian text governs. Art. 19(3) permits special-category data in such decisions only in the cases at art. 6(1)(a), (f) and (j), and only where appropriate safeguards for the subject's rights, freedoms and legitimate interests exist. The transparency limb is request-triggered, not proactive. Art. 13(1)(g) entitles the data subject, on request and free of charge, to «the decision made as a result of automated processing, including profiling, and the logic involved in making such a decision, as well as its impact on the processing and the expected results of the processing», answered within 10 working days and extensible by 10 more. But arts. 24 and 25 — the proactive notice lists for data collected from the subject and from third parties, the slots occupied by GDPR arts. 13(2)(f) and 14(2)(g) — were read item by item and contain no automated-decision or logic item at all. A Georgian controller therefore never has to volunteer that a decision was machine-made; the subject has to know to ask. The DPIA duty is independent and unconditional. Art. 31(2)(a) makes a data protection impact assessment mandatory whenever a controller «makes decisions, in a fully automated manner, including on the basis of profiling, having legal, financial or other significant consequences for a data subject» — no high-risk screening test first, and note that it adds *financial* consequences to the trigger, which GDPR art. 35(3)(a) does not name. Art. 31 and its penalty at art. 80 commenced on 1 June 2024, three months after art. 19 itself.

In force since 1 March 2024. Art. 90(2) of the Law names articles 7-30 among those commencing on that date, which carries art. 19 and its penalty route at art. 72; the Law itself was promulgated on the website of the Legislative Herald on 3 July 2023 but art. 90(1) commenced only the final provisions then. The DPIA trigger at art. 31(2)(a) and its penalty at art. 80 followed on 1 June 2024 under art. 90(3). Art. 89 declared the previous Law on Personal Data Protection of 28 December 2011 invalid from the same 1 March 2024 date, and art. 88(1) keeps the 2011 Law alive only for administrative liability for offences committed before it. Art. 19 has not been amended: the consolidated text as at 10 June 2026 carries no amendment footnote on art. 19, while thirteen other articles carry one for Law of Georgia No 1289 of 17 December 2025. That amendment did not touch the rule but did move the regulator — see the max_penalty field.

Stated maximum penalty — GEL 20 000 in total, which is roughly USD 7 400 — the lowest ceiling of any GDPR-family automated-decision rule in the atlas. Breach of art. 19 is an administrative offence under art. 72, «violation of the rights of a data subject provided for by Chapter III (except for Article 22)». The tariff is fixed, not a range: art. 72(1) gives a warning or GEL 1 000 for a natural person, public institution, non-commercial legal entity, or an undertaking whose annual turnover does not exceed GEL 500 000, and GEL 1 500 for a legal person, branch of a foreign enterprise or individual entrepreneur above that turnover line. Art. 72(2) raises it to GEL 2 000 / 3 000 where two or more Chapter III rights are violated; art. 72(3) and (4) raise the same two tiers to GEL 1 500 / 3 000 and GEL 3 000 / 5 000 respectively where an aggravating circumstance is present. Failing the art. 31 impact assessment is a separate offence under art. 80 at GEL 2 000 / 3 000, or GEL 3 000 / 5 000 aggravated. Art. 64(2) then caps the aggregate: where offences are found in a single inspection or dealt with in one set of proceedings, total fines may not exceed GEL 10 000 for the lower tier and GEL 20 000 for the upper. Art. 64(3) bars double-counting the same act across articles. Enforcement passed from the Personal Data Protection Service to the State Audit Office of Georgia and the Auditor General under Law of Georgia No 1289 of 17 December 2025 (website, 23 December 2025), which rewrote Chapter VI as «Principles of Activities of the State Audit Office in the Field of Data Protection»; the data subject's route under art. 22 now runs to the State Audit Office, a court, or a superior administrative body. Art. 52 non-monetary measures may be imposed alongside a fine.

In force · 1 Mar 2024 checked 23 Sep 2026 PDP Law art. 19 ↗ high confidence

Kyrgyzstan 1

Kyrgyzstan Binding

Digital Code arts. 191-193 - every AI system used in the country must be danger-assessed, and both the method and the result must be published

Binds Владельцы систем искусственного интеллекта - the owners of AI systems applied in the Kyrgyz Republic, with the art. 192(3) risk-minimisation duty extending to users as well. Resolution No. 770 para. 2 spells the scope out: owners of AI systems applied in Kyrgyzstan 'irrespective of organisational-legal form, departmental (sectoral) affiliation and form of ownership'. There is no turnover, headcount, sector or nationality threshold anywhere in Chapter 23, so a sole trader running one model and a state body running a national platform owe the same assessment and the same publication.. Chapter 23 of the Digital Code of the Kyrgyz Republic (Code No. 178 of 31 July 2025), arts. 191 to 193, is the base layer of Kyrgyzstan's AI regime and it is unusual in applying to every AI system without a risk gate. Art. 191(1) starts from permission: AI systems are designed, developed and applied without restriction except where this Code says otherwise. Art. 191(2) then fixes seven sectoral principles that owners must build to - risk reduction, openness, explainability, human controllability, accuracy, reliability and security - and art. 191(3) makes them the basis on which every requirement for AI systems is set and read. Art. 192(1) limits what those requirements may protect to six enumerated goods (life and health, human and civil rights and freedoms, the environment, defence capability, national security, public order), art. 192(2) prohibits outright the design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to those goods, and art. 192(3) puts a general duty on owners and users of AI systems irrespective of danger level to take all reasonable and necessary measures to minimise the risk of such harm. Art. 193 is the operative obligation: ALL AI systems applied in Kyrgyzstan are subject to a danger assessment, carried out by the system's owner at the design stage, again on completion of development and before application, and again on any unplanned change to the system or its environment of use that could alter the result. The owner writes the methodology itself, but under requirements set by the Cabinet of Ministers, and art. 193(4) requires BOTH the assessment result AND the methodology to be posted on the owner's website in a form simple and intelligible to natural persons and additionally as open data, state secrets excepted. Those Cabinet requirements exist: Resolution No. 770 of 2 December 2025 approved a Requirements-for-the-danger-assessment-methodology annex, so this is a filled slot and not a deferred one.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The implementing act is Cabinet of Ministers Resolution No. 770 of 2 December 2025, published in «Эркин-Тоо» No. 96 (3753) of 5 December 2025, which approves five annexes under arts. 193 and 194 - the danger-assessment methodology requirements, and requirements for risk management, for system characteristics, for digital data quality and for technical documentation. Its para. 4 commences it 'fifteen days after the entry into force of the Digital Code', which computed from 6 February 2026 puts it at 21 February 2026; the ЦБД record card carries no dateOfEntry for the Resolution, so that single date is arithmetic from the Resolution's own text rather than a stated date. The Resolution's status in ЦБД is «Действует».

Stated maximum penalty — Nothing. There is no administrative offence for failing to run the danger assessment, for using a methodology that does not meet the Resolution No. 770 requirements, or for not publishing the result and the methodology. The only AI-specific offence Kyrgyzstan created is art. 228-10 of the Code of Offences (Code No. 128 of 28 October 2021, article inserted by Law No. 180 of 31 July 2025), and it reaches only the art. 192(2) prohibition: design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to the protected goods, fined at 200 расчетных показателей for natural persons and 650 for legal persons. The расчетный показатель has been 100 som since 1 January 2006 (Law No. 13 of 27 January 2006 art. 2; Jogorku Kenesh Resolution No. 1115-III of 15 June 2006, still «Действует»), so the ceiling is 20,000 som for a natural person and 65,000 som for a legal person - roughly 230 and 745 US dollars. This is the same enforcement gap Kazakhstan has: a fully drafted duty layer sitting on a single narrow offence.

In force · 6 Feb 2026 checked 5 Sep 2026 KG Digital Code arts. 191-193 ↗ high confidence

Kazakhstan 1

Kazakhstan Binding

AI Law art. 17(3) — seven AI capabilities banned outright, and the owner classifies its own risk tier

Binds Собственники и владельцы систем искусственного интеллекта — the owners and holders of AI systems. The Law states no size, sector, turnover or nationality threshold, so enterprise, SME, sole trader and public body are all covered on the same terms; the administrative fines in KoAP art. 641-1 are the place where size enters, and they are graded across natural persons, small business and non-commercial organisations, medium business and large business.. Law of the Republic of Kazakhstan No. 230-VIII ЗРК of 17 November 2025 «Об искусственном интеллекте» is Kazakhstan's first standalone AI statute and the first in Central Asia, and art. 17 is its structural core. Art. 17(3) forbids, on the territory of Kazakhstan, the creation and operation of AI systems possessing any one of seven functional capabilities: (1) use of subconscious, manipulative or other methods that distort a natural person's behaviour and limit their capacity to take informed decisions, or that push them into decisions capable of causing or threatening harm; (2) exploitation of a person's moral or physical vulnerability arising from age, disability, social position or any other circumstance, with the aim of causing or threatening harm; (3) evaluation and classification of natural persons or groups over a period of time on the basis of their social behaviour or known, assumed or predicted personal characteristics — a social-scoring ban, subject to cases provided by law; (4) collection and processing of personal data in breach of the personal-data legislation; (5) classification of natural persons on the basis of biometric data to infer race, political views, religious affiliation or any other criterion for the purpose of discriminating against them; (6) determination of a person's emotions without their consent, save in cases provided by law; and (7) creation and dissemination of results of AI activity that the laws prohibit. The list is close enough to EU AI Act art. 5 to be read against it, but it is a prohibition on creation and operation rather than on placing on the market, it has no law-enforcement-carve-out architecture, and the emotion-recognition limb is a consent rule rather than a workplace-and-education ban. Art. 17(1) then sets the three risk tiers — minimal, medium and high — and, unlike the EU's annex-driven scheme, assigns the classification to the owner and (or) holder of the system itself, applying the rules on classification of informatisation objects. High-risk systems that are also critically important information-and-communication infrastructure, or that are intended to form state electronic information resources, are treated as state systems for information-security purposes. Art. 17(2) adds a second, orthogonal axis of autonomy — low (a human always makes the final choice), medium (human correction or reversal remains possible) and high (human correction or reversal is wholly excluded or technically impossible) — and defers the rules on creating and operating high-autonomy systems to other laws, which is a real gap rather than a filled slot.

In force since 18 January 2026. Art. 31 commences the Law «по истечении шестидесяти календарных дней после дня его первого официального опубликования», with no article carved out. The А́ділет record card gives first official publication as the newspapers «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both of 18 November 2025, with the Reference Control Bank of NPA in electronic form following on 20 November 2025. The sixty days run from 19 November 2025 and expire at the end of 17 January 2026, so the Law entered into force on 18 January 2026. А́ділет serves the text as «Обновленный» (consolidated and current), database state 19 August 2026, and flags the only pending change — Law No. 326-VIII of 24 June 2026 — as a future «Примечание ИЗПИ» note rather than as applied text.

Stated maximum penalty — The Law itself sets no figure: art. 30 is a bare referral to responsibility «в соответствии с законами Республики Казахстан». The companion Law No. 232-VIII of 17 November 2025 inserted KoAP art. 641-1, but its part one reaches only two things — failure to inform users about misleading synthetic outputs, and failure to manage the risks of a high-risk system where that failure caused harm — so breach of the art. 17(3) prohibitions is NOT itself an enumerated administrative offence. In practice an art. 17(3) capability is reached indirectly: through art. 18(2), which obliges immediate suspension or termination once such a risk is identified and whose breach is penalised by art. 641-1, through art. 20(2)(2), which makes the presence of prohibited capabilities an express object of AI system audit, through the personal-data offences in KoAP art. 79-1 and following where limb (4) is engaged, and through the criminal law, since art. 641-1 applies only «если это действие (бездействие) не содержит признаков уголовно наказуемого деяния». This entry states no figure for art. 17(3) itself rather than importing the art. 641-1 band, which on its face does not cover it.

In force · 18 Jan 2026 checked 5 Sep 2026 KZ AI Law art. 17 ↗ high confidence

Moldova 1

Moldova Binding

Law 160/2026 art. 11 — a flat ban on solely automated decisions by police, prosecutors, courts and prisons

Binds Competent authorities only, and the Law defines the purpose rather than the institution. Art. 1(1) covers processing by competent authorities for the prevention of criminal offences, including prevention of and protection against threats to public order and public security; the detection or investigation of offences or the conduct of criminal prosecution; the trial of criminal cases; and the execution of criminal penalties or safety measures. Art. 2(2) applies it to processing wholly or partly by automated means and to non-automated processing of data forming part of a filing system. Art. 2(3) excludes processing of state-secret data under Law no. 245/2008 so far as necessary and proportionate for national security and defence. The division of labour with the general statute is clean: art. 2(2)(c) of Law 195/2024 carves the same law-enforcement purposes out of the general regime, so a Moldovan police, prosecution, judicial or prison body processing for those purposes answers to art. 11 of this Law and not to art. 22 of Law 195/2024, while the same body processing for any other purpose — its own staff records, for instance — answers to art. 22. Art. 3(1) imports the art. 4 definitions of Law 195/2024, including «creare de profiluri», so the profiling concept is identical across the two. Private controllers are outside this Law entirely.. Law no. 160 of 30 July 2026 on the protection of personal data processed for the purpose of preventing and combating crime transposes Directive (EU) 2016/680, and its art. 11 is drafted as a prohibition rather than as a right the data subject must assert. Art. 11(1): «O decizie întemeiată exclusiv pe prelucrarea automată, inclusiv pe crearea de profiluri, care produce un efect juridic negativ pentru persoana vizată sau care o afectează în mod semnificativ se interzice, cu excepția cazului în care este autorizată de actele normative ce prevăd garanții adecvate pentru drepturile și libertățile persoanei vizate, cel puțin dreptul de a obține intervenția umană din partea operatorului» — a decision based solely on automated processing, including profiling, which produces an adverse legal effect for the data subject or significantly affects them is prohibited, unless authorised by normative acts that provide adequate safeguards, at minimum the right to obtain human intervention from the controller. Two differences from the general regime at art. 22 of Law 195/2024 are load-bearing. First, the only way out is a normative act: there is no contract limb and no consent limb, so a competent authority cannot cure a solely automated decision by obtaining agreement. Second, the effect that triggers the bar is an adverse one — «un efect juridic negativ» — rather than any legal effect. Art. 11(2) bars such decisions from resting on the special categories of data at art. 7 unless appropriate safeguards for the rights, freedoms and legitimate interests of the data subject are in place, and art. 11(3) separately prohibits profiling that results in discrimination against natural persons on the basis of those special categories — an outright ban with no authorisation route at all.

In force since 23 August 2026, stated as a calendar date rather than derived: art. 45(1) reads «Prezenta lege intră în vigoare la data de 23 august 2026». That is 3 days after publication — the Law was adopted on 30 July 2026, promulgated by Presidential Decree no. 729-X of 14 August 2026 and published in Monitorul Oficial nr. 382-385 of 20 August 2026 at art. 404 — and it is the same day the general statute Law 195/2024 took effect, which is plainly deliberate: art. 45(2) uses the occasion to amend arts. 63(3), 86(1) and 87(3) of Law 195/2024 so that the Centre's fining powers reach processors and not only controllers. The two acts were designed as a pair and neither can be read alone: this Law borrows the general statute's definitions (art. 3(1)), its complaint procedure (art. 44(2), citing Chapter VIII section 2 of Law 195/2024) and its fine-setting criteria (art. 43(2), citing art. 87). Moldova had no separate law-enforcement data-protection regime before this — the repealed Law no. 133/2011 covered both spheres — so art. 11 is a new rule rather than a re-enactment. AIL-300 computation check (2026-08-31): out of scope for the publication-relative sweep. Art. 45(1) fixes an express calendar date — «Prezenta lege intră în vigoare la data de 23 august 2026» — rather than a period running from publication, so no rule on the reckoning of terms applies.

Stated maximum penalty — Up to 2 000 000 Moldovan lei, imposed by the National Centre for Personal Data Protection on the controller or the processor. Art. 43(1) sets a single band, without the turnover alternative that art. 88 of Law 195/2024 carries, and it attaches to two triggers: (a) a finding of an infringement of this Law, which includes art. 11, and (b) failure to comply with a corrective measure, a temporary or definitive limitation on processing, or a suspension of data flows ordered by the Centre, or refusal of access. Art. 43(2) applies the art. 87 criteria of Law 195/2024 to the setting of the amount, and art. 43(3) sends the money to the state budget. The same taper applies: art. 46(1) sets the fine actually applied at 10 per cent of the amount determined in the first year, 40 per cent in the second and 100 per cent from the third, so the effective ceiling in the year to 23 August 2027 is 200 000 lei. Art. 44 adds an internal-reporting channel — any employee of a competent authority may complain to the Centre about a suspected infringement, the Centre must keep the reporter's identity confidential, and retaliation in the professional context is prohibited. Impact tier: public sector.

In force · 23 Aug 2026 checked 14 Sep 2026 Law 160/2026 art. 11 ↗ high confidence

Panama 1

Panama Binding

Ley 81 art. 19 — a Directive 95/46 automated-decision right that fires only on NEGATIVE legal effects, with three exits and no safeguards at all

Binds Responsables del tratamiento de los datos and custodios de la base de datos — controllers and the parties holding custody of the database on the controller's behalf — public or private, for profit or not. Art. 5 fixes the reach: databases located in the territory of the Republic of Panama that store personal data of nationals or foreigners, and databases whose controller is domiciled in the country, are subject to the Law and its regulation. There is no GDPR art. 3(2) targeting limb: a purely foreign controller with no Panamanian database and no Panamanian domicile is outside the Law even when it decides about people in Panama. Databases of subjects governed by leyes especiales are excluded, but only where those special laws or their implementing rules set the minimum technical standards needed for correct protection of personal data conforming to this Law; and art. 36 makes this Law's sanctions apply supletoriamente where a sector regulator's own statute does not expressly define the penalty for the breach complained of.. Art. 19 of Ley 81 de 26 de marzo de 2019, «Sobre Protección de Datos Personales» (Gaceta Oficial Digital Nº 28743-A of 29 March 2019), gives the data subject «derecho a no ser sujeto de una decisión basada únicamente en el tratamiento automatizado de sus datos personales, que produzca efectos jurídicos negativos o le produzca un detrimento a un derecho, cuyo objeto sea evaluar determinados aspectos de su personalidad, estado de salud, rendimiento laboral, crédito, fiabilidad, conducta, características o personalidad, entre otros». The shape is Directive 95/46 art. 15(1) rather than GDPR art. 22: the trigger is cumulative and its third limb is an OBJECT requirement — the decision must be one whose purpose is to evaluate personal aspects — and the illustrative list (work performance, creditworthiness, reliability, conduct) is the Directive's list carried across almost word for word. Two things are done to the effects threshold that no other rule in the atlas does together. First, «efectos jurídicos» is qualified as «NEGATIVOS»: a legal effect that helps the subject does not engage the right at all, where GDPR art. 22 and the whole Directive family are indifferent to whether the effect is adverse. Second, the alternative limb is not «significantly affects» but «le produzca un detrimento a un derecho» — detriment to a right — which trades an open-ended severity test for a narrower requirement that some right be impaired. The exits are three: consent of the subject; necessity to conclude or perform a contract or legal relationship between the controller and the subject; and authorisation by special laws or the norms developing them. Panama therefore adds a consent exit to the Directive's two — and then attaches NOTHING to any of them. There is no right to obtain human intervention, no right to express a point of view, no right to contest the decision, and no bar on running such decisions on sensitive data. Art. 19 is one sentence of prohibition followed by three ways out, and it is the barest automated-decision provision in the atlas: even Montenegro's pre-GDPR art. 15a folded the chance to express a view into its contract exit. The word «perfil» never appears in Ley 81. Profiling enters Panamanian law only through the reglamento, Decreto Ejecutivo Nº 285 de 28 de mayo de 2021 (Gaceta Oficial Digital Nº 29296-A of the same date), whose art. 2(7) defines «elaboración de perfiles» in the GDPR art. 4(4) terms and whose transparency articles then speak of «la existencia de decisiones automatizadas, incluida la elaboración de perfiles, a que se refiere el artículo 19 de la Ley 81 de 2019» — attributing to art. 19 a concept the article does not contain. The same reglamento supplies the disclosure limb the statute omits: on collection and on a subject access request the controller must give «información significativa sobre la lógica aplicada, así como la importancia y las consecuencias previstas de dicho tratamiento», which is GDPR art. 13(2)(f)/15(1)(h) language grafted on by executive decree rather than enacted by the legislature. Art. 21 of the Law voids any act or agreement between parties that limits the subject's rights — but it lists «acceso, revocación, cancelación, oposición o bloqueo» and does not name art. 19, so the anti-waiver clause does not on its face reach the automated-decision right, which the consent exit already lets a controller contract around.

In force since 29 March 2021. Art. 47 is the whole vigencia clause — «Esta Ley comenzará a regir a los dos años de su promulgación» — and it names no date, so the date has to be computed. The Law is dated 26 March 2019 and was published in Gaceta Oficial Digital Nº 28743-A of 29 March 2019, which on the Panamanian understanding of promulgación (publication in the Gaceta Oficial) puts entry into force two years later, on 29 March 2021. That reading is confirmed by the Executive itself in a primary source: the considerandos of the reglamento, Decreto Ejecutivo Nº 285 de 28 de mayo de 2021, record that Ley 81 «estableció, además, una prórroga para su entrada en vigor, efectiva a partir del 29 de marzo de 2021». Taking the date of the Law instead of the date of the gazette would give 26 March 2021; the Executive's own published reading is preferred over that computation and no conflict between two primary sources arises. The reglamento entered into force on its own promulgation (its art. 65), i.e. 28 May 2021. The Law was Proyecto 665 de 2018, approved in third debate on 24 October 2018. No amendment to Ley 81 has been located on the gazette record.

Stated maximum penalty — B/.1,000 to B/.10,000 — the whole range, with no turnover alternative and no separate corporate ceiling. Art. 38 grades infractions as leves, graves or muy graves; art. 40(2) makes it a GRAVE infraction to «infringir los principios y garantías establecidos en la presente Ley o en su reglamentación», and that catch-all is the route by which a breach of art. 19 is fineable, since neither art. 40 nor art. 41 names art. 19 and the ARCO-specific item at art. 40(4) reaches only access, rectification, cancellation and objection. Art. 43 attaches the consequences: a falta leve draws only a citación before the Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI), a falta grave draws «multas según su proporcionalidad», and a falta muy grave draws closure of the database registers or temporary or permanent suspension and disqualification of the processing activity, in each case without prejudice to the corresponding fine. The only figures in the statute are in art. 36, which directs ANTAI to fix the amounts by gravity «desde mil balboas (B/.1 000.00) hasta diez mil balboas (B/.10 000.00)». The balboa is at par with the US dollar, so the maximum exposure for the gravest breach of Panamanian data-protection law is about USD 10,000 — the lowest absolute ceiling of any rule in the atlas, and the reglamento does not raise it: Decreto Ejecutivo Nº 285 art. 62 supplies only graduation criteria (intent, recidivism, harm, duration, benefit obtained, turnover affected) within that band. Limitation runs at one year for leves, three for graves and five for muy graves (art. 63 of the reglamento). Art. 37 preserves a separate civil action before the courts for patrimonial and moral damage.

In force · 29 Mar 2021 checked 14 Sep 2026 Ley 81 art. 19 ↗ high confidence

Peru 1

Peru Comprehensive

AI Law 31814 + Reglamento — risk-based regime

Binds Public and private AI developers / deployers. Prohibited / high-risk / acceptable tiers; high-risk AI needs prior evaluation, human oversight and transparency.

DS 115-2025-PCM, approving the Reglamento of Ley 31814, was published in El Peruano on 9 September 2025. The Reglamento entered into force 90 business days after publication, i.e. 22 January 2026, except for four provisions (creation of a digital AI channel and the National AI Strategy) that took effect the day after publication. The Reglamento sets an implementation schedule by sector: health, education, justice, security, economy and finance obligations apply from 10 September 2026; transport, commerce and work from 10 September 2027; production, agriculture, energy and mining from 10 September 2028. Computation of the ninety-business-day vacatio verified 31 Aug 2026 and it does not move, but this is the one row in the sweep where the arithmetic and the statutory count come apart unless a second decree is brought in, and that is recorded here so it is never re-derived. The Disposición Complementaria Final of DS 115-2025-PCM provides that the Decreto Supremo «entra en vigencia a partir de los noventa (90) días hábiles siguientes de su publicación en el diario oficial El Peruano», with the First, Second, Fourth and Fifth Disposiciones Complementarias Finales of the Reglamento in force the day after publication. Publication was 9 September 2025. The counting rule is the TUO de la Ley 27444, under which a term stated in days «se entenderá por hábiles consecutivos, excluyendo del cómputo aquellos no laborables del servicio, y los feriados no laborables de orden nacional o regional», with the initial day excluded, so business day 1 is Wednesday 10 September 2025. Excluded as feriados nacionales: 8 October, 1 November (a Saturday in any event), 8 December, 9 December — a feriado since Ley 31381, which amended art. 6 of Decreto Legislativo 713 — and 25 December 2025, then 1 January 2026. Excluded in addition, and this is the decisive point, are the días no laborables declared for the public sector at national level by Decreto Supremo n.º 042-2025-PCM, published in El Peruano on 3 April 2025: Friday 26 December 2025 and Friday 2 January 2026. Counting on that basis, business day 90 falls on Thursday 22 January 2026, the date carried. Counting the national feriados alone and omitting the two decreed días no laborables puts day 90 on 20 January 2026 instead. The published date is therefore correct, but it is correct only by reason of an unrelated decree issued four months before the Reglamento, and the two-day margin was previously undocumented.

Stated maximum penalty — Referral to data-protection / Indecopi

In force · 22 Jan 2026 checked 15 Sep 2026 Ley 31814 + DS 115-2025-PCM ↗ high confidence

Serbia 1

Serbia Binding

Personal Data Law art. 39 — solely automated decisions banned for police, prosecutors and prisons, plus an exceptionless ban on discriminatory profiling

Binds Competent authorities only, and the Law defines the trigger by purpose rather than by institution. Art. 6(3) defines the «posebne svrhe» as processing by competent authorities for the prevention, investigation and detection of criminal offences, the prosecution of their perpetrators or the execution of criminal sanctions, including the prevention of and protection against threats to public and national security. Art. 1(2) brings that sphere inside this same statute, so Serbia — unlike Moldova, which split the GDPR and LED regimes into two acts — carries both regimes in one Law and divides them by article. The division is clean at the edges: art. 38(5) removes special-purpose processing from art. 38, and art. 7(1) forbids repurposing data collected for the special purposes unless a law provides for it. The same body processing for an ordinary purpose, its own staff records for instance, answers to art. 38 and not to art. 39. Private controllers are outside art. 39 entirely, with one edge: a private body exercising delegated public powers for a special purpose is a «nadležni organ» for these purposes. Art. 40(1) permits arts. 36 to 39 to be restricted by law on national-security, defence, public-security and criminal-justice grounds subject to the essence, necessity and proportionality test.. Art. 39 is the law-enforcement counterpart of art. 38 and, following LED art. 11, it is drafted as a prohibition on the authority rather than as a right the individual must invoke. Art. 39(1): «Zabranjeno je donošenje odluke isključivo na osnovu automatizovane obrade koju vrše nadležni organi u posebne svrhe, uključujući i profilisanje, ako takva odluka može da proizvede štetne pravne posledice po lice na koje se podaci odnose ili značajno utiče na položaj tog lica, osim ako je donošenje te odluke zasnovano na zakonu i ako su tim zakonom propisane odgovarajuće mere zaštite prava i sloboda lica na koje se podaci odnose, a najmanje pravo da se obezbedi učešće fizičkog lica pod kontrolom rukovaoca u donošenju odluke.» Three drafting choices matter. The effects limb is widened by «štetne» — the legal consequences must be harmful — but it also reaches a decision that merely «može» produce them, so the prohibition bites on capacity to harm rather than on realised harm. There is no consent exit and no contract exit: the single way out is a statutory basis that itself prescribes safeguards, and the floor for those safeguards is named in the article — the right to secure the participation of a natural person under the controller's control in the taking of the decision. And unlike art. 38(3), the person is given no right here to express a view or to contest the decision; the enabling statute must supply whatever more it supplies. Art. 39(2) bars such a decision from resting on the special categories of art. 18(1) unless appropriate protective measures are applied. Art. 39(3) is the provision with no analogue in art. 38 and the one most likely to be overlooked: «Zabranjeno je profilisanje koje dovodi do diskriminacije fizičkih lica na osnovu posebnih vrsta podataka o ličnosti iz člana 18. stav 1. ovog zakona.» That is a flat, exceptionless ban on discriminatory profiling on special-category grounds — it is not tied to any decision, to any effects threshold, or to the «isključivo automatizovana» qualifier, so it reaches profiling that merely feeds a human decision, and it admits no statutory override.

In force and applicable since 22 August 2019 on the same art. 102 timetable as art. 38 — entry into force on 21 November 2018, the eighth day after publication in «Sl. glasnik RS» br. 87/2018 of 13 November 2018, and application upon the expiry of nine months from that day. Art. 39 is new law rather than a re-enactment: the repealed 2008 Law had a single automated-decision provision covering both spheres and no prohibition addressed to law-enforcement bodies, and it had nothing resembling the art. 39(3) discriminatory-profiling ban. Supersession check, 26 August 2026: no amending gazette number appears in the Law's masthead, so art. 39 stands as enacted. Note for readers comparing regimes: art. 39(1) is narrower than art. 11 of Directive (EU) 2016/680 in requiring the legal consequences to be harmful, and wider in reaching decisions that merely may produce them; art. 39(3) has no counterpart in art. 38 and no exception clause at all. The text relied on is the promulgated Law as published in «Službeni glasnik RS» br. 87/2018 of 13 November 2018, read end to end from the copy the Ministry of Public Administration and Local Self-Government hosts at https://mduls.gov.rs/wp-content/uploads/Zakon-o-zaštiti-podataka-o-ličnosti.pdf, which carries the Ukaz of promulgation signed by the President and the register masthead «Osnovni tekst na snazi od 21/11/2018, u primeni od 22/08/2019». The Pravno-informacioni sistem ELI cited as the source is the official gazette record but is served by a JavaScript-only portal, so it renders in a browser and not to a fetcher — that is the shell, not rot. Two government-hosted PDFs are traps and were ruled out: minrzs.gov.rs/sites/default/files/2018-11/Zakon o zastiti podataka o licnosti.pdf is the SUPERSEDED 2008 Law (97/08) despite its 2018 upload path, and it decodes only through a shifted-glyph font.

Stated maximum penalty — 50,000 to 2,000,000 dinara for a controller or processor that is a legal person, under the same art. 95(1)(19) that covers art. 38 — the item is drafted against «čl. 38. i 39.» together — with 20,000 to 500,000 dinara for an entrepreneur under art. 95(4) and 5,000 to 150,000 dinara for a natural person or the responsible person in a legal person, a state body, an authority of territorial autonomy or a local self-government unit under art. 95(5). Two limits are worth stating plainly. First, art. 95(1)(19) is written around a decision that «proizvodi pravne posledice» taken solely on automated processing, so it maps onto art. 39(1) but does not obviously reach a standalone breach of the art. 39(3) discriminatory-profiling ban, which involves no decision at all — that prohibition carries no misdemeanour of its own. Second, because art. 95(5) addresses the responsible person, the practical sanction against a state body falls on an individual official. Supervision is the Poverenik's, whose special-purpose powers run under Chapter VII of the Law. Impact tier: public sector.

In force · 22 Aug 2019 checked 1 Sep 2026 Personal Data Law art. 39 ↗ high confidence

United Kingdom 2

UK Binding

UK DUAA 2025 s.138 — Non-consensual deepfake creation/request offences

Binds Any person in the UK who creates or requests creation of a non-consensual intimate deepfake image. Section 138 of the Data (Use and Access) Act 2025 inserts ss.66E–66H into the Sexual Offences Act 2003, criminalising the creation of non-consensual 'purported intimate images' (deepfakes) and the act of requesting such creation, even if the image is never distributed.

In force February 6, 2026 per SI 2026/31 (Commencement No. 5 Regulations 2026). Distinct from Crime and Policing Act 2026 (ss.66I–66L) which targets tool suppliers; this section targets end-users who create or request deepfakes.

Stated maximum penalty — Unlimited fine and/or summary imprisonment (Sexual Offences Act 2003)

In force · 6 Feb 2026 checked 7 Sep 2026 DUAA 2025, s.138 / Sexual Offences Act 2003 ss.66E–66H ↗ high confidence
UK Binding

Crime and Policing Act 2026 — AI-generated CSAM and deepfake offences

Binds Individual developers, distributors, and corporate bodies (criminal offences); Ofcom-regulated platforms (OSA priority-content duty). Criminalises making, adapting, possessing, supplying, or offering to supply AI models optimised to generate CSAM (up to 5 years imprisonment). Separately criminalises AI “nudification” tools/deepfake intimate image generators. Upgrades AI-generated intimate image creation to priority offences under the Online Safety Act; Ofcom-regulated platforms must prevent and remove such content (up to £3M penalty for non-compliance).

Royal Assent: 29 April 2026 (2026 c.20). Section 99 (purported intimate image generators) commenced 29 June 2026 via UKSI 2026/689 (Commencement No. 1) reg. 2(i). The CSAM image-generator offences (ss.72-74) are NOT yet in force — legislation.gov.uk marks them "Prospective" (s.72 not in force at Royal Assent, see s.255(1)), pending a further commencement instrument.

Stated maximum penalty — 5 years imprisonment (CSA/deepfake AI generator offences, once commenced); £3M Ofcom fine (platform intimate image duty)

In force · 29 Jun 2026 checked 20 Sep 2026 Crime and Policing Act 2026 ↗ medium confidence

United States 14

US · Federal Binding

TAKE IT DOWN Act

Binds Anyone publishing non-consensual intimate imagery; covered online platforms (notice-and-removal). Bans non-consensual intimate imagery incl. AI deepfakes; covered platforms must remove within 48h (notice-and-removal duty live 19 May 2026).

Stated maximum penalty — FTC enforcement; criminal penalties

In force · 19 May 2025 checked 2 Sep 2026 TAKE IT DOWN Act (PL 119-12) ↗ high confidence
US · CA Binding

California Extends Health-Profession Title-Protection Law to AI (AB 489)

Binds Any person or entity that develops or deploys AI/GenAI systems using health-profession-protected terms, letters, or phrases (broader than nursing — covers all licensed healing-arts professions, e.g. medicine, dentistry, psychology). Adds Bus. & Prof. Code §§ 4999.8-4999.9: makes existing law that bars falsely indicating or implying possession of a health-care license (e.g., under the Medical Practice Act, Dental Practice Act) enforceable against any person or entity that develops or deploys an AI or GenAI system using protected terms, letters, or phrases in its advertising or functionality. Separately prohibits AI/GenAI use of terms implying that care, advice, reports, or assessments are provided by a licensed natural person. Each prohibited use is a separate violation.

AB 489 (Bonta), approved by Governor and filed with Secretary of State Oct. 11, 2025; no urgency clause, so it took effect Jan. 1, 2026 under the default California statutory effective-date rule (Cal. Const. art. IV, §8(c)).

Stated maximum penalty — Enforced via the applicable health-care licensing board's injunctive authority (Bus. & Prof. Code §125.5) plus the penalty already attached to the underlying title-protection provision being invoked (e.g., unauthorized practice of medicine under §2052 is a public offense punishable by up to 1 year in county jail and/or a $10,000 fine)

In force · 1 Jan 2026 checked 15 Sep 2026 CA AB 489 (Bus. & Prof. Code §§ 4999.8-4999.9) ↗ high confidence
US · OR Binding

Oregon Bars Nonhuman Entities from Nursing Titles (HB 2748)

Binds Any nonhuman entity, including AI systems, using a protected nursing title or abbreviation in Oregon. Codified as ORS 678.027: a nonhuman entity, including but not limited to an agent powered by artificial intelligence, may not use the titles or abbreviations Advanced Practice Registered Nurse (APRN), Certified Registered Nurse Anesthetist (CRNA), Clinical Nurse Specialist (CNS), Licensed Practical Nurse (LPN), Registered Nurse (RN), Nurse Practitioner (NP), Certified Medication Aide (CMA), or Certified Nursing Assistant (CNA).

Enrolled House Bill 2748 (HB 2748-A), 83rd Oregon Legislative Assembly — 2025 Regular Session; passed House June 13, 2025, Senate June 11, 2025, signed by Gov. Kotek; codified 2025 c.378 §2 (ORS 678.027). The enrolled act contains only Sections 1 and 2 and no effective-date clause, so ORS 171.022 controls: "Except as otherwise provided in the Act, an Act of the Legislative Assembly takes effect on January 1 of the year after passage of the Act" — passed 2025, therefore in force Jan. 1, 2026.

Stated maximum penalty — Violation of ORS 678.010 to 678.415 (which includes 678.027) is a Class C misdemeanor — ORS 678.990(1)

In force · 1 Jan 2026 checked 15 Sep 2026 OR HB 2748 (2025 c.378 §2; ORS 678.027) ↗ high confidence
US · TX Binding

Texas Responsible AI Governance Act (TRAIGA)

Binds Persons developing/deploying AI in Texas or serving Texas residents; state agencies. Bans manipulative/discriminatory AI; AG-enforced.

Stated maximum penalty — Up to $200k/violation; $40k/day

In force · 1 Jan 2026 checked 15 Sep 2026 HB 149 ↗ high confidence
US · DE Binding

Delaware AI Agents Barred from Medical/Nursing Licensure and Titles (HB 191)

Binds Any person or entity deploying or offering an AI agent in Delaware that would be licensed as, or presented under the title of, a nurse, physician, or physician assistant. A nonhuman entity, including an agent powered by artificial intelligence, may not be licensed or certified to practice professional nursing, advanced practice registered nursing, practical nursing, medicine, or as a physician assistant in Delaware, and may not use the associated protected titles — "Nurse", "RN", "LPN", "APRN", "CRNA", "CNS", "CNP", "CNM", "Doctor"/"Dr.", "Physician", "Surgeon", "MD", "DO", "Physician Assistant"/"PA". Amends 24 Del. C. §§ 1920, 1720, 1773. Does not restrict AI clinical decision-support or documentation tools that do not hold themselves out under a licensed title.

Signed by Gov. Meyer and approved April 23, 2026 as 85 Del. Laws ch. 250; no delayed-effective-date clause, so effective on enactment.

Stated maximum penalty — Medicine: class F felony, $1,000–$5,000 fine and/or up to 3 years (24 Del. C. § 1766(a)); other Ch. 17 violations class B misdemeanor (§ 1766(c)). Nursing/title misuse: up to $1,000 and/or 1 year (24 Del. C. § 1925)

In force · 23 Apr 2026 checked 15 Sep 2026 DE HB 191 (85 Del. Laws ch. 250) ↗ high confidence
US · WA Binding

Washington Bars Nonhuman Entities from Nursing Titles (HB 2155)

Binds Any person or nonhuman entity (including AI systems, chatbots, and automated triage/care tools) presenting itself under a protected nursing title or abbreviation in Washington. Amends RCW 18.79.030: only a human person licensed under ch. 18.79 RCW may practice as, or use the titles of, a registered nurse ("RN"), advanced practice registered nurse/nurse practitioner ("APRN"/"NP"), or licensed practical nurse ("LPN"). No other person or any nonhuman entity may assume those titles or abbreviations, or use other words, letters, signs, or figures indicating it is a nurse.

House Bill 2155, 2026 Regular Session, passed House Feb. 11, 2026 (87-8) and Senate Feb. 26, 2026 (46-2); delivered to Governor Mar. 3 and signed Mar. 9, 2026 as Chapter 6, 2026 Laws. The enrolled act contains no effective-date section; the Legislature's own bill record states "Effective date 6/11/2026" (Washington's default general effective date, 90 days after sine die). Sec. 1 (in force) expires June 30, 2027, when Sec. 2 (an equivalent re-enactment) takes over.

Stated maximum penalty — Enforced as unlicensed practice under RCW 18.130.190: civil fine up to $1,000/day (18.130.190(3)); first violation is a gross misdemeanor, subsequent violations a class C felony (18.130.190(7))

In force · 11 Jun 2026 checked 15 Sep 2026 WA HB 2155 (amending RCW 18.79.030) ↗ high confidence
US · WA Binding

Washington Forged Digital Likeness Protection Act (SB 5886 / Ch.69)

Binds Any person creating, distributing, or facilitating AI-generated/manipulated likenesses of Washington residents. Prohibits creating or using AI-generated forged digital likenesses without consent; amends WA Personality Rights Act.

Stated maximum penalty — $3,000/violation + noneconomic damages; private right of action

In force · 11 Jun 2026 checked 15 Sep 2026 SB 5886 / Ch.69 ↗ high confidence
US · RI Binding

Rhode Island Oversight of AI in Mental Health Care Act (H 7349 Sub A)

Binds Any individual, corporation or entity offering therapy/psychotherapy services in Rhode Island, and RI-licensed mental health professionals using AI. R.I. Gen. Laws ch. 40.1-5.5. No individual, corporation or entity may provide, advertise or offer therapy/psychotherapy services to the public in RI — including via Internet-based AI — unless conducted by a licensed professional (§ 40.1-5.5-3(b)). Licensed professionals may use emotional-attachment/companion AI in recorded or transcribed sessions only with prior written informed consent (§ 40.1-5.5-3(a)), and may not let AI make independent therapeutic decisions, conduct therapeutic communication without an established relationship, or set treatment plans (§ 40.1-5.5-3(c)). Carve-outs: religious counseling, peer support, public self-help materials, and FDA-cleared AI tools.

Enacted as Substitute A (LC004589/SUB A/2); signed by Governor McKee June 22, 2026; effective upon passage. Verified against the enacted Sub A text 2026-08-10.

Stated maximum penalty — Confidentiality violations: penalties under R.I. Gen. Laws § 5-37.3-9; EOHHS investigative authority; RI licensing enforcement

In force · 22 Jun 2026 checked 15 Sep 2026 H 7349 ↗ high confidence
US · IL Binding

Illinois AI Teacher Evaluation Restrictions (SB 2909 / PA 104-0565)

Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.

Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.

Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified

Applies 1 Jan 2027 checked 21 Sep 2026 SB 2909 / PA 104-0565 ↗ high confidence
US · NJ Binding

NJ FAIR Act — Algorithmic Rent-Setting Ban (A3497/S451)

Binds Residential rental property owners and algorithmic revenue management software coordinators operating in New Jersey. Prohibits residential landlords and algorithmic revenue-management software coordinators from using algorithms that share competing landlords' nonpublic pricing data to recommend rents; bans parallel pricing coordination via software.

Signed 2026-07-20 by Gov. Mikie Sherrill; effective first day of the twelfth month following enactment (2027-07-01).

Stated maximum penalty — NJ Antitrust Act enforcement (P.L.1970, c.73); AG complaint portal required; penalty as provided under NJ Antitrust Act

Applies 1 Jul 2027 checked 15 Sep 2026 FAIR Act (A3497/S451) ↗ high confidence
US · IL Binding

Illinois Transparency in Downcoding Act (SB 3114 / PA 104-0568)

Binds Health insurance issuers and managed care organizations in Illinois (excludes self-insured ERISA plans and workers' compensation). Prohibits health insurers and managed care organizations from using algorithms or automated tools to downcode medical claims without comprehensive human review; requires AMA CPT coding guideline-compliant physician review of all downcoding determinations; bans discriminatory targeting of providers treating complex/chronic patients.

Signed 2026-07-10 by Governor Pritzker; effective 2028-01-01.

Stated maximum penalty — Fines, restitution, or license suspension (IL Department of Insurance enforcement)

Applies 1 Jan 2028 checked 15 Sep 2026 SB 3114 / PA 104-0568 ↗ high confidence
US · MD Proposed

Maryland Protection From Predatory Pricing Act (HB 895 / Ch. 154)

Binds Food retail stores ≥15,000 sq ft selling tax-exempt food, and third-party delivery service providers arranging delivery from such stores, operating in Maryland. First US state law banning AI-driven personalised (surveillance) pricing in food retail and delivery; prohibits setting prices based on individual consumer personal data.

EXCLUDED FROM ACTIVE COVERAGE — CEO ruling AIL-136 (2026-08-03): all AI/algorithm language was deliberately struck from HB 895 before enactment. The enacted Ch. 154 prohibits personalized data-driven pricing for tax-exempt food (retailers ≥15,000 sq ft + food delivery); no AI definition, no near-real-time AI dynamic-pricing clause, no §13-322 algorithmic-pricing disclosure. Enacted operative line is personal data, not AI. Narrow food scope, regulatory-only, no private right of action. Fails coverage prong (a): AI is not load-bearing in enacted text. REVERSAL TRIGGER: re-escalate to CEO if AI/algorithm language is re-introduced in a future MD legislative session, or if personalized/surveillance pricing becomes an AI-governance flashpoint with AI-specific statutory language.

Stated maximum penalty — Up to $10,000 per violation; up to $25,000 per violation for repeat offenders (Maryland AG enforcement)

Proposed · target 1 Oct 2026 checked 22 Sep 2026 MD HB 895 / Ch. 154 ↗ high confidence
US · IL Proposed

Illinois AI Rental Price Coordination Ban (SB 343)

Binds Landlords of residential units in Illinois and third-party algorithmic pricing service providers who facilitate rental price coordination. Amends the Illinois Antitrust Act to prohibit landlords and third-party services from using AI algorithms to coordinate residential rental pricing; specifically targets algorithmic platforms (e.g., RealPage) used by competing landlords to fix or stabilize rents.

The AI rental-pricing language no longer exists in this bill vehicle. Senate Floor Amendment No. 1 (adopted 2026-05-21) had added the algorithmic rental-price-coordination ban described above, but House Committee Amendment No. 1 (filed 2026-05-28, adopted 2026-05-29) replaced that content entirely with unrelated Cook County / Calumet City eminent-domain (quick-take) provisions for economic development. Governor Pritzker signed the bill on 2026-08-07 as Public Act 104-0805; the enacted text contains no AI or algorithmic-pricing provisions.

Stated maximum penalty — Illinois Antitrust Act — civil penalties (enforcement by Illinois AG)

Proposed checked 22 Sep 2026 SB 343 (IL 104th GA) ↗ high confidence

Uruguay 1

Uruguay Binding

Ley 18.331 art. 16 — an automated-decision right that started out automation-blind, and the only one that makes the program itself explainable

Binds Responsables de bases de datos and encargados de tratamiento — the controller and processor analogues — plus, in the words of art. 35, «demás sujetos alcanzados por el régimen legal». Art. 3 applies the Law to personal data recorded on any medium that makes them susceptible of processing, and art. 16 para. 2 names administrative acts and private decisions side by side, so the rule reaches the State and the private sector alike with no sectoral carve-out. Art. 2 extends the data-protection right by analogy to legal persons «en cuanto corresponda», which is unusual: most of the atlas protects natural persons only. Art. 46 gave existing databases one year from entry into force to comply. Impact tier: all entities.. Art. 16 of Ley Nº 18.331 de Protección de Datos Personales y Acción de «Habeas Data» (promulgated 11 August 2008, Diario Oficial of 18 August 2008, Registro Nacional de Leyes y Decretos 2008 t. 1 s. 2 p. 378) is Uruguay's automated-decision right, and it is the only entry in the atlas whose automation trigger was put there by amendment rather than by the original drafter. As enacted in 2008 the article read «que se base en un tratamiento automatizado o no de datos» — a processing of data, automated OR NOT. Art. 152 of Ley Nº 18.719 of 27 December 2010, the National Budget Act, struck the words «o no». Uruguay therefore began where Armenia still is, with a decision rule indifferent to whether a machine was involved, and legislated its way to the Directive 95/46 art. 15 shape; every other narrowing in the atlas runs from a European template outward, not the reverse. The current text has three paragraphs and each does distinct work. Para. 1 is the right proper: «Las personas tienen derecho a no verse sometidas a una decisión con efectos jurídicos que les afecte de manera significativa, que se base en un tratamiento automatizado de datos destinado a evaluar determinados aspectos de su personalidad, como su rendimiento laboral, crédito, fiabilidad, conducta, entre otros» — a right not to be subjected to a decision with legal effects significantly affecting the person, based on automated processing intended to evaluate certain aspects of their personality, such as work performance, credit, reliability or conduct. The list is open («entre otros»), and the trigger is cumulative in a way GDPR art. 22 is not: the decision must have legal effects AND affect the person significantly, where GDPR art. 22(1) offers legal effects OR similarly significant effect as alternatives. Para. 2 is a challenge right rather than an abstention right, and it is where the «solely» test sits: the affected person may contest «los actos administrativos o decisiones privadas» — administrative acts and private decisions — implying an assessment of their conduct «cuyo único fundamento sea un tratamiento de datos personales que ofrezca una definición de sus características o personalidad». Public and private decisions are named in the same breath, so there is no public-sector carve-out. Para. 3 is the finding. On challenging, the person is entitled to information from the controller «tanto sobre los criterios de valoración como sobre el programa utilizado en el tratamiento que sirvió para adoptar la decisión manifestada en el acto» — both the valuation criteria and THE PROGRAM used in the processing that served to adopt the decision. Only one other instrument in the atlas names the software itself in an explanation duty — art. 20(c) of Ecuador's LOPDP, which entitles the challenger to «los criterios de valoración sobre el programa automatizado», the criteria bearing on the program — and Uruguay goes a step further by making the program itself, and not only the criteria about it, part of what is disclosed. GDPR art. 15(1)(h) and its transpositions ask for meaningful information about the logic involved, which is deliberately one abstraction level above the program. Uruguay drafted it a level below, in 2008, and kept it through the 2010 recast. What the 2010 recast did remove, besides «o no», was a fourth paragraph with no counterpart anywhere in the atlas: «La valoración sobre el comportamiento de las personas, basada en un tratamiento de datos, únicamente podrá tener valor probatorio a petición del afectado» — an assessment of a person's conduct based on data processing could have evidentiary value only at the request of the affected person. That was an evidence rule, not a data-protection rule, and it is gone. There are no exits. Art. 16 states no contract, consent or authorising-law exception of the GDPR art. 22(2) kind, and no special-categories bar of the art. 22(4) kind. There is no express right to human intervention either: the remedy is impugnación plus the information duty in para. 3, backed by the habeas data action in arts. 37 to 45 and by the Unidad Reguladora y de Control de Datos Personales. The word «perfilado» does not appear in the Law; the concept is carried by the phrase «una definición de sus características o personalidad».

In force. Ley 18.331 contains no vigencia clause, so the default in art. 1 of the Código Civil applies — promulgation «se reputará sabida diez días después de verificada en la Capital» — which puts the Law, published in the Diario Oficial of 18 August 2008, in force on 28 August 2008; the date is computed from the statute rather than stated by it. The wording tracked here is not the 2008 wording: art. 152 of Ley 18.719 (promulgated 27 December 2010, published 5 January 2011, and carrying no special vigencia note for that article, so in force 15 January 2011 on the same ten-day rule) recast arts. 9, 14, 15, 16, 21, 22, 28 and 35 together. Both texts were read on IMPO, the official normative documentation service — the consolidated article at /bases/leyes/18331-2008/16 and the enacted article at /bases/leyes-originales/18331-2008/16 — and they differ in exactly two places in para. 1 and in the deletion of the original para. 4. IMPO records no later amendment to art. 16; Ley 19.670 (2018) and Ley 19.924 (2020) added arts. 37 to 40 on the data protection officer, impact assessment, breach notification and extraterritorial reach without touching it. No AI-specific statute imposes obligations: arts. 74 and 75 of Ley Nº 20.212 of 6 November 2023 are mandates addressed to AGESIC — to design a national data and AI strategy jointly with the URCDP wherever personal data are involved, to report to the Legislature within 180 days with recommendations for legal regulation, and to run controlled testing environments cleared by a technical committee — not duties on regulated entities, so they are not tracked as an obligation.

Stated maximum penalty — Up to 500,000 UI (unidades indexadas) under art. 35(3), on a five-rung ladder that runs observation, warning, fine, five-day suspension of the database and closure of the database, graduated by gravity, repetition and recidivism. The UI is an inflation-indexed unit, so the ceiling floats rather than eroding — the mechanism Uruguay uses instead of the GDPR's turnover percentage, and the reason the 2008 figure has not been overtaken. There is no turnover-linked band, no separate corporate tier and no minimum. Unlike Montenegro's art. 74 and Kosovo's art. 92, art. 35 does not enumerate offences by article number: it reaches any case «que se violen las normas de la presente ley», so art. 16 carries the full ceiling with no interpretive step. Art. 35 was itself recast by art. 152 of Ley 18.719, and its closure rung by art. 83 of Ley 19.355 of 19 December 2015. Final monetary resolutions of the URCDP are directly enforceable as título ejecutivo.

In force · 28 Aug 2008 checked 16 Sep 2026 Ley 18.331 art. 16 ↗ high confidence

Uzbekistan 1

Uzbekistan Binding

Administrative Liability Code art. 46² part 2 — unlawful AI processing of personal data

Binds Any person who unlawfully processes personal data using AI technologies and disseminates it in mass media, telecommunications networks or the Internet. Unlawfully processing personal data with AI technologies and disseminating it in the media, telecom networks or the Internet is an administrative offence carrying a fine and confiscation.

Part two was added to art. 46² of the Code on Administrative Liability (Law No. 2015-XII of 22 Sept 1994) by art. 2 of Law No. ЎРҚ-1115 of 21 January 2026, in force on publication (National Database of Legislation, 21.01.2026, No. 03/26/1115/0063). It reads: unlawful processing of personal data using artificial intelligence technologies, and their dissemination in mass media, telecommunications networks or the worldwide information network Internet, entails a fine of fifty to one hundred base calculation units (базовая расчетная величина, BRV — an index re-set periodically by presidential decree, so the soum figure moves) with confiscation of the objects of the offence. Note the cumulative structure: the text couples unlawful processing WITH dissemination, so AI processing that stays internal is charged under part one (7 BRV for citizens, 50 BRV for officials) rather than part two. ЎРҚ-1115 also added a matching ground to art. 12¹ of the Law on Informatization, which is the access-restriction route for the same conduct. This is the only penalty the 2026 AI amendment act created — art. 7¹ of the Law on Informatization has none.

Stated maximum penalty — Fine 50–100 BRV + confiscation of the objects of the offence

In force · 21 Jan 2026 checked 10 Sep 2026 KoAO art. 46²(2) ↗ high confidence

Questions & answers

From the data

What AI practices does the EU AI Act ban?

Article 5 prohibits, among others, harmful manipulation, exploitation of vulnerabilities, social scoring by public authorities, certain predictive policing, untargeted scraping of facial images and most real-time remote biometric identification in public spaces. The bans have applied since 2 February 2025.

Is non-consensual deepfake imagery banned?

Increasingly, yes. The US TAKE IT DOWN Act bans non-consensual intimate imagery, including AI deepfakes, and requires covered platforms to remove it; the EU has added a new Article 5 prohibition targeting AI-generated CSAM and intimate imagery.

Do the prohibitions apply to small companies?

Article 5-style bans generally apply to anyone placing such a system on the market or putting it into service in the jurisdiction, regardless of size. Scope and exemptions differ by instrument — check the linked source.

Is algorithmic rent-setting or personalised pricing banned?

In a growing number of US states. New Jersey’s FAIR Act and Illinois’ SB 343 prohibit landlords and revenue-management vendors from using algorithms fed with competitors’ nonpublic pricing data to set or coordinate residential rents; Maryland’s Protection From Predatory Pricing Act bans pricing food-retail and delivery items from an individual consumer’s personal data. Illinois’ bill had passed the legislature but was not yet signed as of 28 July 2026 — each row above carries its own status.

Which jurisdictions does AI Law Radar track for prohibited ai practices?

We currently track prohibited ai practices obligations across 20 jurisdictions: Albania, Argentina, Azerbaijan, Chile, China, Ecuador, Egypt, European Union, Gabon, Georgia, Kyrgyzstan, Kazakhstan, Moldova, Panama, Peru, Serbia, United Kingdom, United States, Uruguay and Uzbekistan. Each is dated and linked to its primary source on this page.