Future ProofThe Authority Stack
Independent Cross-Jurisdictional ReviewCorrections · Global DeskUpdated 17 August 2026
Agent LiabilityGlobal Desk
Editorial · Corrections

Corrections.

This is the log of material corrections, kept under section 4 of our editorial standards. A material error is one that, left uncorrected, would cause a reader to hold a false belief about a fact of regulatory, legal, or market significance. Each entry states what was published, what the correct position is, and where the correct position was verified.

Material corrections

Corrections are listed newest first. Where a claim could not be verified at the administering body’s own domain, the claim was removed rather than softened. Where a claim was verified, the source is named.

17 August 2026

Taiwan. The Basic Act was called a draft. It had been law for six months.

Published. The Taiwan guide said Taiwan had no enacted, standalone AI statute, that the Executive Yuan had approved a draft in July 2024, and that the Legislative Yuan had not passed it. It told operators to treat the draft as a policy signal rather than a source of binding obligations. It also said 2023 amendments established a Personal Data Protection Commission that now enforces the data protection act.

Corrected to. The Artificial Intelligence Basic Act passed third reading on 23 December 2025 and was promulgated on 14 January 2026 by presidential order 華總一義字第11500001671號, twenty articles, effective on the date of promulgation. It had been in force for six months and a week when the guide was published. Article 2 makes the National Science and Technology Council the central competent authority and Article 6 establishes a National AI Strategic Committee convened by the Premier, so the claim that no single AI regulator exists was also wrong. Article 5 creates a sectorally triggered high-risk designation route carrying an advisory notice and warning duty, which the guide missed. On data protection, the 31 May 2023 amendment added Article 1-1 naming a Personal Data Protection Commission, but Article 1-1 is not in force and its commencement is still to be set by the Executive Yuan; what exists is a preparatory office. A further substantial amendment passed on 11 November 2025 and is also awaiting commencement.

Verified at. law.moj.gov.tw and lis.ly.gov.tw

17 August 2026

Poland. The Act was called a draft. It had been in force since 11 August 2026.

Published. The Poland guide said Poland had not enacted a standalone AI statute and that the bill remained in the legislative process, in the deck, the key takeaways, all six FAQ answers, the meta description and both JSON-LD blocks. It also said the Digital Omnibus deferral was never adopted, so the 2 August 2026 high-risk deadline stood, and that KRiBSI has no members, no confirmed budget and no legal existence.

Corrected to. The Act of 3 July 2026 on artificial intelligence systems was published at Dz.U. 2026 poz. 1003 on 27 July 2026, a week before the guide's own publication date, and entered into force on 11 August 2026. Its inspection, procedure, settlement, fine and criminal chapters apply from 28 October 2026. KRiBSI is created by Article 125(1) and designated by Article 5; what is outstanding is appointment, not legislation, with the Chair due within two months and the first sitting within three. Poland sets no separate ceilings: Article 104(1) applies the amounts in Chapter XII of the Regulation, converted to zloty at the NBP rate published on 28 January. Articles 8 to 14 create a binding individual opinion, the most useful instrument in the Act, which the guide omitted. Two article numbers were also wrong: the operator ceiling is Article 99(4) not 99(2), and the duty to designate data protection authorities is Article 74(8), covering law enforcement and fundamental rights categories, not Article 70(2). A claim that KNF has issued AI model risk guidance could not be confirmed and has been removed.

Verified at. dziennikustaw.gov.pl, api.sejm.gov.pl, uodo.gov.pl and the EU Publications Office

17 August 2026

Vietnam. The guide was built on a chapter that had been repealed.

Published. The Vietnam guide was written around the AI chapter of the Law on Digital Technology Industry, Law No. 71/2025/QH15, and named the Ministry of Information and Communications as lead supervisor eleven times, including in its structured data. It described a two-tier risk model and a registry of high-risk systems maintained by that ministry.

Corrected to. Article 33 of the Law on Artificial Intelligence, Law No. 134/2025/QH15, passed 10 December 2025 and in force since 1 March 2026, repealed Chapter IV of Law 71/2025. That chapter was binding for two months. The Ministry of Information and Communications ceased to exist on 1 March 2025 under National Assembly Resolution 176/2025/QH15, and mic.gov.vn no longer resolves; AI competence sits with the Ministry of Science and Technology. Article 9 sets three tiers, including a medium tier for systems liable to confuse or manipulate users who cannot tell they are dealing with AI. Article 10 requires provider self-classification and notification before service; Article 13 makes conformity assessment a precondition for high-risk use; Article 14(6) requires a foreign provider to have a contact point in Vietnam, and commercial presence or an authorised representative where certification is mandatory; and Article 29(2) puts compensation on the deployer even where the system was operated correctly. Administrative fines are left to a future regulation under Article 29(5) and none has issued.

Verified at. congbao.chinhphu.vn and congbaocdn.chinhphu.vn

17 August 2026

South Africa. The wrong POPIA section, and an exception that does not exist.

Published. The South Africa guide attributed the automated decision-making rule to POPIA section 26 in the body, the key takeaways, the FAQ and twice in the structured data, and said consent is one of its exceptions. It cited section 107 for a ZAR 10 million administrative fine, a SARB Prudential Standard FSR01 on technology risk management, an FSCA Guidance Note 2 of 2023 on digital tools and AI in financial advice, a ZAR 5 million penalty against a credit bureau, an Information Regulator annual report RP350/2024, and a Cabinet-approved 2023 National AI Policy Framework with eight principles.

Corrected to. Section 26 is the prohibition on processing special personal information. Automated decision making is section 71, and section 71(2) has two gateways, contract and law or code of conduct. There is no consent exception, so an operator relying on consent would have been non-compliant. Section 107 is criminal; the R10 million administrative fine is section 109(2)(c), delivered by infringement notice for an offence with a right to elect trial. Section 71(3), which requires an opportunity to make representations and sufficient information about the underlying logic, is the real South African explainability duty and was absent. Neither the SARB standard nor the FSCA guidance note exists at those bodies; the FSCA's own document store returns 854 records with none matching. The credit bureau penalty does not appear in the Regulator's published enforcement notices, and the TransUnion matter was an enforcement notice. The annual report is RP290/2024, and the full text of the 2023/24 and 2024/25 reports contains no reference to artificial intelligence, profiling or automated decision making. The draft National AI Policy was withdrawn on 12 May 2026 after the Minister disclosed that generative AI had been used irresponsibly in drafting it; an independent expert review panel chaired by Professor Benjamin Rosman is preparing a replacement.

Verified at. gov.za, dcdt.gov.za, inforegulator.org.za, resbank.co.za, fsca.co.za and icasa.org.za

17 August 2026

Switzerland. A signature six months early, a FINMA paper that does not exist, and two invented bodies.

Published. The Switzerland guide said Switzerland signed the Council of Europe Framework Convention in September 2024, in six places including the structured data. It cited a FINMA December 2023 position paper on artificial intelligence in financial services five times, said FADP Article 21 requires the controller to explain the key parameters of an automated decision four times, described FINMA Circular 2023/1 as applying to insurers, said FINMA can impose fines, and cited a body called Syna, the Swiss AI Network for the Administration, and a SECO AI and Employment Policy Monitoring Report 2024.

Corrected to. Switzerland signed CETS No. 225 on 27 March 2025 and has not ratified; the Convention is not in force anywhere, needing five ratifications including three Council of Europe member states and having one. No FINMA position paper on AI exists; the real document is FINMA Guidance 08/2024 of 18 December 2024, whose opening line is that there is no AI-specific legislation in Switzerland. Article 21 contains no explainability duty; that right is Article 25(2)(f), and the guide also omitted the Article 21(3) contract and consent exceptions. Circular 2023/1 is titled Operational risks and resilience, banks, and does not address insurers. FINMA's own enforcement tool list does not include fines. Neither Syna nor the SECO report could be found at any Swiss federal domain, and both have been removed; the real federal structures are the Guidelines on Artificial Intelligence for the Confederation of November 2020 and the Competence Network for Artificial Intelligence. The organising fact the guide missed entirely, the Federal Council decision of 12 February 2025 and the end-of-2026 consultation deadline, has been added.

Verified at. admin.ch, fedlex.admin.ch, bj.admin.ch, bakom.admin.ch, edoeb.admin.ch, finma.ch and the Council of Europe treaty office

17 August 2026

Turkey. A treaty signature that never happened, and two instruments that do not exist.

Published. The Turkey guide asserted at least six times, including in its structured data, that Turkiye signed the Council of Europe Framework Convention on AI at its opening in September 2024, and advised operators to align their governance to a Convention Turkey has signed. It cited SPK Communique III-43.5 on algorithmic trading and automated advisory systems, a BDDK regulation at gazette 31086 of 15 March 2021, a 2021 amendment to KVKK, fines of TRY 15,000 to 1,000,000, a right to human review under Article 11(f), and BDDK remediation orders to three banks in 2024 that it conceded were not made public.

Corrected to. Turkiye has neither signed nor ratified CETS No. 225. The SPK communique does not exist; SPK's own list contains no III-43 series at all. The BDDK instrument is the Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik, gazette 31069 of 15 March 2020. There was no 2021 amendment to Law 6698; the reform is Law 7499 of 2 March 2024, in force 1 June 2024, which rebuilt transfers abroad. The 2026 fine figures, published 31 December 2025, reach TRY 17,092,242 on three of the five limbs. The automated decision right is Article 11(g) and grants only an objection, with no human review entitlement. The unverifiable BDDK orders have been deleted. Added: the actual AI bill, Esas No 2/2234, submitted 24 June 2024 and still in committee; the TBMM parliamentary research commission on AI; and the Board's own AI publications, including a forty six page study on agentic AI of February 2026.

Verified at. tbmm.gov.tr, resmigazete.gov.tr, mevzuat.gov.tr, kvkk.gov.tr, mevzuat.spk.gov.tr and the Council of Europe treaty office

17 August 2026

Peru. The regulation is 2025, and there are three risk tiers, not four.

Published. The Peru guide said an implementing regulation was approved by supreme decree in 2024, introducing unacceptable, high-risk, limited-risk and minimal-risk tiers on the EU model. It attributed a list of principles including legality, precaution, proportionality and human oversight to Law 31814, said limited-risk uses face transparency duties, and described the framework as early with enforcement practice still developing.

Corrected to. The regulation is Decreto Supremo No. 115-2025-PCM, signed 8 September 2025 and published 9 September 2025; a draft was pre-published in 2024, which is the likely source of the error. Article 22 sets three categories: uso indebido, prohibited and enumerated in Article 23; uso de riesgo alto, enumerated in Article 24; and riesgo aceptable as the residual. The strings riesgo limitado and riesgo minimo appear nowhere in it, and Article 25 transparency is a high-risk duty rather than a lighter-tier one. Law 31814's Preliminary Title has six principles and none is legality or precaution. The impact assessment is mandatory for the public sector under Article 30.1 and expressly voluntary for the private sector under Article 32.1. And the deadlines are live: the First Final Complementary Provision gives private operators in health, education, justice, security, economy and finance one year, falling in September 2026. Added: the Article 23 prohibited-use list, the Article 24 high-risk list, the Articles 23.3 and 24.2 consultation routes, and Decreto Supremo No. 016-2024-JUS, the new data protection regulation with the sanctions title that is where fines actually come from.

Verified at. busquedas.elperuano.pe and gob.pe

17 August 2026

United Kingdom. Article 22 had been replaced three months before the guide said it applied.

Published. The UK guide told deployers three times that they face the right not to be subject to solely automated decisions with significant effects under Article 22 UK GDPR, and never mentioned the Data (Use and Access) Act 2025. It cited Discussion Paper DP24/1 on artificial intelligence and machine learning in financial services, dated the AI Opportunities Action Plan to January 2026 and attributed the AI Safety Institute's rename to it, said the ICO's AI guidance was updated in 2024, described an ICO ChatGPT investigation, said a named senior manager must be accountable for AI governance under SM and CR, and said the Ofcom online safety regime was fully in force from 2024.

Corrected to. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 with Articles 22A to 22D and was fully in force on 5 February 2026, nearly three months before the guide was published. FCA DP24/1 is about the regulation of commercial and bespoke insurance business; there is no FCA AI discussion paper, and the real publication is the AI Update of 22 April 2024. The Action Plan was published 13 January 2025, and the rename to AI Security Institute was announced by DSIT on 14 February 2025. The ICO's AI guidance was last updated 15 March 2023 and now carries a notice that it is under review because of the same Act; its generative AI material is a consultation response of 12 December 2024, not guidance. No ICO ChatGPT investigation appears anywhere on ico.org.uk and the claim has been removed. There is no prescribed senior manager responsibility for AI governance, and the FCA's own published position is that it does not plan to introduce extra regulations for AI. Ofcom published its illegal harms codes on 16 December 2024 with measures from March 2025. Added: PRA SS1/23, which expressly covers machine learning and is the closest thing in UK financial services to a binding AI-adjacent expectation, the FCA AI Live Testing service, the ICO AI and biometrics strategy, and the GBP 17.5 million floor on ICO fines.

Verified at. gov.uk, legislation.gov.uk, the Parliament bills API, ico.org.uk, fca.org.uk, bankofengland.co.uk, ofcom.org.uk and aisi.gov.uk

17 August 2026

United States. A revoked executive order, a vetoed statute, and a report that could not be found.

Published. The US guide presented Executive Order 14110 as operative in seven places and OMB Memorandum M-24-10 in four. It said California had enacted SB 1047 three times. It said Texas TRAIGA applies to companies with at least USD 25 million in annual revenue and mandates a risk management programme, bias testing, transparency disclosures and an AI governance officer. It cited CFPB Circular 2022-03 as current in four places, EEOC technical assistance as current, and an FTC report titled Protecting Consumers in the Era of Generative AI. It also told operators to plan against the original EU high-risk date while monitoring the Omnibus adoption process.

Corrected to. EO 14110 was revoked by EO 14148 on 20 January 2025 and replaced by EO 14179; M-24-10 was rescinded and replaced by M-25-21 on 3 April 2025. SB 1047 was vetoed on 29 September 2024; the California frontier-model statute is SB 53, chaptered 29 September 2025. TRAIGA has no revenue threshold and mandates none of those things; its standard is intent-based, and it states expressly that disparate impact alone is not sufficient to show intent. CFPB Circulars 2022-03, 2023-03 and 2024-06 were withdrawn with effect from 12 May 2025, and the EEOC's AI technical assistance documents now return 404. The FTC report could not be located at ftc.gov and has been removed, replaced with the agency's actual Operation AI Comply record of 25 September 2024. Regulation (EU) 2026/1744 entered into force on 27 July 2026. The Colorado effective date the guide gave, 30 June 2026 after SB 25B-004, is correct. Added: Executive Order 14365 of 11 December 2025 and its Department of Justice AI Litigation Task Force challenging state AI laws, which names Colorado; the America's AI Action Plan; the stripped state moratorium; California SB 942 and the CPPA ADMT regulations; and Colorado's insurer and bank full-compliance carve-outs and consumer appeal right. The Colorado statutory text itself returns 403 at leg.colorado.gov, so the ten-category count, the fifty-employee threshold and the USD 20,000 penalty now carry a sourcing note.

Verified at. federalregister.gov, whitehouse.gov, govinfo.gov, nist.gov, ftc.gov, leg.colorado.gov, capitol.texas.gov, leginfo.legislature.ca.gov and cppa.ca.gov

17 August 2026

Spain. AESIA's decree and its sixteen guides are real. Its designation and its sanctioning power are not.

Published. The Spain guide said AESIA is Spain's designated national competent authority under Article 70 with sanctioning powers in place since 2 August 2025, that Royal Decree 729/2023 could not be confirmed and carried the identifier BOE-A-2023-18942, that the sixteen compliance guides were published on 16 December 2025, that the Spanish organic law entered into force on 27 July 2026, that Article 26 obligations applied from 2 August 2026 and that relying on the Omnibus deferral was a regulatory risk, and that AESIA operates a sandbox in its third cohort which operators should apply to.

Corrected to. Two open questions close. Real Decreto 729/2023 of 22 August 2023 is real, was read at the BOE under identifier BOE-A-2023-18911, published 2 September 2023, and places AESIA's seat in A Coruna; the identifier the guide carried resolves to an unrelated personnel appointment. And the sixteen guides exist, in Spanish and English, though they are outputs of the Spanish AI sandbox pilot prepared by SEDIA rather than AESIA enforcement guidance, and no publication date appears on them. What does not survive: AESIA is not designated under Article 70 by any BOE instrument, and its own guides page still refers to potential national competent authorities. Spain has no domestic AI sanctioning power, because Ley 40/2015 requires a statute defining infringements, penalties and procedure and that statute is expediente 121/000096, in committee with the amendment deadline extended to 2 September 2026. The 27 July 2026 date the guide gave for the Spanish law is the EU Digital Omnibus date. Annex III now applies from 2 December 2027. The sandbox was Real Decreto 817/2023, run by SEDIA, had one call selecting up to twelve systems, and digital.gob.es recorded on 1 July 2026 that it has finished, so the guide was sending operators to a closed programme. Human oversight is guide 06, not guide 10. A director named Belda and a formal AESIA and AEPD cooperation protocol could not be confirmed and have been removed; the Director is Alberto Gago Fernandez.

Verified at. boe.es, congreso.es, lamoncloa.gob.es, aesia.digital.gob.es, digital.gob.es and aepd.es

17 August 2026

UAE and the Gulf. The federal law is less operative than the guide said, and the instrument that matters was missing.

Published. The Gulf guide said the UAE PDPL's implementing regulations were published in 2023, cited Article 17 for automated processing with a notification duty and a right to meaningful information about the logic involved, stated administrative fines reaching AED 20 million, cited Chapter X of the DIFC Data Protection Law, said DIFC and ADGM data protection is enforced by the DFSA and the FSRA, described a UAE Ministry of Artificial Intelligence, dated Saudi AI Ethics Principles to 2022, said the Saudi PDPL gives a right to object to automated processing, and said Gulf compliance adds data localisation.

Corrected to. The UAE PDPL's Executive Regulations have not been issued: Article 28 leaves them to the Cabinet and Article 29's compliance grace period runs from that issuance, so much of the law is not yet operative. Article 17 is the right to stop processing; automated processing is Article 18, which grants a right to object plus a human element in review on request, and contains no notification or logic-disclosure duty. The Decree-Law contains no fine amount at all; Article 26 leaves penalties to a future Cabinet resolution. DIFC automated decision-making is Article 38, and there is no Chapter X. Data protection in both free zones is administered by the Commissioner of Data Protection, not the DFSA or FSRA; ADGM fines reach USD 28 million. The Cabinet listing shows a Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications and no Ministry of AI. Saudi AI Ethics Principles are dated May 2025, SDAIA-P114E, seven principles; the Saudi PDPL contains no automated-decision provision, and the operative requirement in its Implementing Regulation is explicit consent, not a right to object. Gulf regimes impose cross-border transfer conditions, not localisation. Added: DIFC Regulation 10 on autonomous and semi-autonomous systems, in force 1 September 2023, which is the only AI-agent-specific binding instrument in the region and was absent entirely. Removed as unconfirmable: a UAE Charter for the Development and Use of AI, Dubai Ethical AI Principles issued by the Executive Council in 2019, a 2023 Dubai AI Governance Roadmap, a Qatar AI Committee, a QCSC framework, and a draft Saudi National AI Governance Framework consulted in late 2025.

Verified at. u.ae, uaelegislation.gov.ae, difc.com, adgm.com, sdaia.gov.sa, mcit.gov.qa and digitaldubai.ae

17 August 2026

Mexico. Three regulators the guide relied on were abolished in December 2024.

Published. That INAI is the constitutional autonomous body overseeing private sector data protection with power to investigate, audit, issue binding resolutions and impose fines; that the governing statute is the Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares of 2010; that Cofece is the competition authority and the IFT the telecommunications regulator; that the USMCA data localisation prohibition and the non-discrimination rule for digital products are both Article 19.11; and that the OECD AI Principles were revised in November 2024.

Corrected to. The constitutional reform on simplificacion organica published on 20 December 2024 provided for extinguishing INAI, Cofece and the IFT. Private sector data protection is now an attribution of the Secretaria Anticorrupcion y Buen Gobierno. The governing statute is the Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares expedited by decree published in the Diario Oficial de la Federacion on 20 March 2025, in the same decree that issued the Ley General de Transparencia y Acceso a la Informacion Publica and the Ley General de Proteccion de Datos Personales en Posesion de Sujetos Obligados. Competition sits with the Comision Nacional Antimonopolio and telecommunications with the Comision Reguladora de Telecomunicaciones inside the Agencia de Transformacion Digital y Telecomunicaciones. Data localisation is USMCA Article 19.12 and non-discriminatory treatment of digital products is Article 19.4. The OECD AI Principles were revised on 3 May 2024. Mexico has no enacted AI statute. Four claims were removed rather than hedged because they could not be read at source: every article number and the fine range of the 2025 statute, because the Diario Oficial serves that decree as a single oversized record and diputados.gob.mx refused connection; a CNBV instrument cited as Circular 4/2019, cnbv.gob.mx presenting an invalid certificate chain; a Cofece opinion on algorithmic collusion dated 2022; and a Senate Punto de Acuerdo of 2023 on a national AI strategy, senado.gob.mx returning 403.

Verified at. dof.gob.mx and gob.mx

17 August 2026

Australia. The guide described an AI Safety Institute and a treaty signature that could not be confirmed, and missed the one binding date Australian operators have.

Published. That Australia's Voluntary AI Safety Standard was published in January 2024; that an Australian AI Safety Institute was announced in October 2024 under DISR and operates within a Seoul AI Safety Declaration of November 2024 signed by 27 countries; that Australia signed the Council of Europe Framework Convention on AI in 2024, with a section of analysis built on that signature; that the Privacy Act was amended by a Privacy Legislation Amendment (Enhancing Online Privacy and Other Measures) Act 2021 and has no AI-specific provisions; that the OAIC published its AI guidance in 2023; that AEMO regulates the National Electricity Market; and a numbered walk-through assigning specific subject matter to each of the ten guardrails.

Corrected to. The month of publication has been removed. The AI Safety Institute, the Seoul declaration date and country count, and the Council of Europe signature have all been withdrawn, not reworded, and the section built on the treaty signature has been replaced with a sourcing note. The Privacy Act citation is corrected to the Privacy and Other Legislation Amendment Act 2024, which adds automated decision-making disclosure duties at APP 1.7 to 1.9 applying from 10 December 2026; that is now stated as the only fixed AI-relevant compliance date in Australian law. The OAIC guidance is corrected to two guides published on 21 October 2024. AEMO is described as the market and system operator, with the binding energy obligation placed where it belongs, in the Critical Infrastructure Risk Management Program under the Security of Critical Infrastructure Act 2018. The numbered guardrail walk-through is withdrawn.

Source. APP 1.7 to 1.9, the amending Act, and both OAIC guidance titles and dates verified at oaic.gov.au. industry.gov.au could not be read from this session, which is why the guardrail wording was withdrawn rather than restated, and the Council of Europe treaty office could not be read, which is why the signature claim was withdrawn rather than corrected.

17 August 2026

China. Three article numbers were wrong, the issuing bodies were miscounted, and the guide missed the labelling regime that has been in force since September 2025.

Published. That the Interim Measures were issued by six ministries, or by the CAC and five others; that Article 9 establishes the transparency obligation; that the security assessment applies to providers crossing defined thresholds of users or influence, under a CAC Security Assessment Measures for Internet Information Services (2022); and that content violations involving political or national security material may involve the Ministry of State Security.

Corrected to. Seven departments issued the Measures, and all seven are now named. The labelling obligation is in Article 12; Article 9 fixes the provider's responsibility as content producer and personal information handler. Article 17 triggers the security assessment and algorithm filing on a service having public opinion attributes or social mobilisation capacity, not on a user count, and the named 2022 assessment measures are withdrawn. The Ministry of State Security claim is withdrawn. Article 21 routes enforcement through the Cybersecurity Law, the Data Security Law and PIPL, with warnings, public notification, correction orders, suspension and criminal liability, and that is now stated in place of an unsourced fine description. The Measures for Labeling AI-Generated Synthetic Content, issued 7 March 2025 and effective 1 September 2025, are added with their explicit and implicit labelling requirements and the duty they place on distribution platforms.

Source. All of the above verified against the published texts at cac.gov.cn.

17 August 2026

Global AI regulation status tracker. The page said the Digital Omnibus was not adopted in time. It was.

Published. That the Digital Omnibus delay proposed on 19 November 2025 was not formally adopted before 2 August 2026, that the original deadline governed, and that the Article 26 deployer obligations and the Article 99 penalty regime entered into application on 2 August 2026 across the EU. The page also carried a Council of Europe entry naming Japan's signature on 11 February 2025 and an EU ratification on 15 May 2026; an AIUC founding year of 2024 with an additional named investor and two named vendor certifications; Armilla described as a Canadian managing general agent; a Colombian CONPES 3975 approval date of November 2020; and law-firm and trade publications as sources for US state law.

Corrected to. The Omnibus entered into force on 27 July 2026; Annex III applies from 2 December 2027 and Annex I from 2 August 2028. Every instance of the old claim has been rewritten, including the deck, the key takeaways, the outcome table, the operator guidance and the FAQ. The Colorado amending bill is SB26-189, signed 14 May 2026, with developer and deployer duties from 1 January 2027, following the SB25B-004 extension to 30 June 2026. The Council of Europe signature and ratification dates are withdrawn. The AIUC entry is replaced with the registered form: out of stealth July 2025, USD 15 million seed led by Nat Friedman at NFDG, AIUC-1 comprising 51 requirements and 130 controls across six pillars, first policy announced for ElevenLabs on 12 February 2026 with no carrier named at source. Armilla is a Lloyd's coverholder. The CONPES date is withdrawn. Law-firm sources are replaced with the issuing bodies' own records or removed.

Source. Colorado bills verified at leg.colorado.gov. The Council of Europe treaty office and eur-lex.europa.eu could not be read from this session; the amending regulation number and Official Journal date carry a sourcing note saying so.

17 August 2026

AI regulation by country. Four jurisdiction rows described a state of the law that had already changed.

Published. That Brazil's PL 2338 passed the Senate in 2024 and awaits presidential signature; that the CNIL is France's designated national supervisory authority; that the Colorado AI Act is in force in 2026 with risk management and impact assessment duties on deployers; that Executive Order 14110 was partially rescinded; a Council of Europe signatory list; a Coalition Deepfake Response Endorsement available in eight named countries; a verbatim quotation of Article 2(1)(c) of the AI Act; a Japanese guidelines version and date; a Korean act number and progressive commencement from 2025; and an FCA policy statement number.

Corrected to. PL 2338 was approved by the Senate on 10 December 2024 and remitted to the Chamber of Deputies on 17 March 2025; it is not awaiting signature. France has not completed its Article 70 designation, and the CNIL and DGCCRF are the practical contacts. Colorado was extended to 30 June 2026 by SB25B-004 and then rewritten by SB26-189 into a disclosure model with duties from 1 January 2027. Executive Order 14110 was revoked outright on 20 January 2025 by Executive Order 14148. The Council of Europe signatory list, the Coalition endorsement with eight countries, the Japanese guidelines version, the Korean act number and commencement schedule and the FCA number are all withdrawn. Coalition's affirmative AI endorsement of 26 March 2024 is described in its registered form: two limbs, an AI security event and deepfake funds transfer fraud, not responding to loss from a wrong AI output. The Article 2(1)(c) quotation is replaced with a paraphrase and a sourcing note.

Source. Brazil verified at senado.leg.br. Colorado verified at leg.colorado.gov. eur-lex.europa.eu and the Council of Europe treaty office could not be read from this session.

17 August 2026

Council of Europe Framework Convention. The signatory list, the chapter map and three article attributions were withdrawn.

Published. That signatories include all 46 Council of Europe member states and five non-member observer states, named as the United States, the United Kingdom, Canada, Israel and Australia; a mapping of the Convention's eight chapters to specific subject matter; an explanation right at Article 14, a remedies right at Article 15 and AI in judicial proceedings at Article 16; an opt-in mechanism at Article 3(1) and an equivalent safeguards test at Article 3(2); and Executive Order 14110 with OMB Memorandum M-24-10 as the live US federal baseline.

Corrected to. The signatory list, the chapter map, the Article 14, 15 and 16 attributions and the Article 3 subparagraph references are all withdrawn rather than reworded, with sourcing notes in each place explaining why. What remains is the shape of the obligation, which binds Parties rather than operators and reaches an operator only through domestic implementing law. Executive Order 14110 is marked as revoked on 20 January 2025 by Executive Order 14148, and the Colorado entry is updated to SB25B-004 and SB26-189. The guide records that it needs a second pass once the Council of Europe treaty office is reachable.

Source. The Council of Europe treaty office and the Convention text at coe.int could not be read from this session on 17 August 2026. Colorado verified at leg.colorado.gov.

17 August 2026

Germany and France. Both guides still told operators to plan against a high-risk deadline that had already moved.

Published. In the Germany guide: that the current legally binding date for high-risk Annex III systems is 2 August 2026, that the Digital Omnibus agreement has not been published and does not have legal force, that German operators should plan for 2 August 2026 and treat the deferral as conditional. It also carried a withdrawn citation to a European Commission Article 50 transparency guidance and code of practice still sitting in its reference list, a description of Article 27 as binding bodies governed by public law or operators of critical infrastructure, and a garbled reference to section 22 GDPR Bundesdatenschutzgesetz. In the France guide: that the legally binding deadline for high-risk Annex III systems is 2 August 2026 until formal adoption occurs, and that operators should plan against 2 August 2026.

Corrected to. In both guides the Omnibus is now stated as in force since 27 July 2026, with Annex III applying from 2 December 2027 and Annex I from 2 August 2028, and the passages telling operators to plan against 2 August 2026 have been rewritten. The withdrawn Commission citation is removed from the Germany reference list. The Article 27 description is withdrawn pending a reading of the Regulation text. The BDSG reference is corrected. The KI-MIG entry and Germany's designation of the Bundesnetzagentur now carry a sourcing note recording that they could not be confirmed. In France, the SREN law is confirmed as LOI n. 2024-449 du 21 mai 2024 with Article 15 amending Article 226-8 of the Code penal, and sourcing notes are added to the Article 226-8 penalty figures, the February and July 2025 CNIL dates, and the counts of 17 market surveillance authorities and 15 CNIL use categories.

Source. LOI n. 2024-449 verified at legifrance.gouv.fr. The EIOPA Opinion on Artificial Intelligence governance and risk management of 6 August 2025 verified at eiopa.europa.eu, where the reference code EIOPA-BoS-25-360 used elsewhere in this network does not appear. bundesnetzagentur.de, the Article 226-8 text and eur-lex.europa.eu could not be read from this session.

17 August 2026

Brazil, Canada, Argentina and Colombia. Residual claims that contradicted their own corrected text, or that could not be confirmed.

Published. The Brazil guide had been corrected in the body to two risk categories and no extraterritoriality clause, but its key takeaways, FAQ, practical steps, contents list and references still described three risk tiers, answered yes to whether the framework reaches companies outside Brazil, and cited an ANPD preliminary guidance the body had already shown did not exist. The Canada guide recorded Colorado as delayed to 30 June 2026 and still referred to an OSFI AI banking framework it had itself shown does not exist, plus an unsourced completion-time estimate for the Algorithmic Impact Assessment. The Argentina guide cited Article 2(1)(b) of the AI Act as covering third-country providers, gave a BCRA communication number, and stated what ANMAT has been monitoring. The Colombia guide dated CONPES 3975 to November 2020 and the DNP Ethical Framework to 2021, said Munich Re and Armilla products are accessible to Colombian enterprises through international broker channels, and said the SIC has exercised its consumer protection mandate over deceptive automated representations.

Corrected to. Every residual three-tier and extraterritoriality statement in the Brazil guide is corrected to match its own body text, and the ANPD and Argentine citations in its reference list are replaced. The Canada guide carries a superseding entry recording the SB26-189 rewrite, drops the OSFI framework reference and the completion-time estimate. The Argentina guide drops the subparagraph letter and the BCRA number, withdraws the ANMAT statement, and carries a sourcing note recording that Decreto 1001/2024 could not be confirmed and that this network's Brazil guide cites a different Argentine instrument, Disposicion 2/2023, which has not been reconciled with it. The Colombia guide withdraws both dates, restates the carrier products in the form the carriers themselves use with Armilla's own jurisdiction caveat, and withdraws the SIC claim while keeping the Moffatt v. Air Canada principle as a principle rather than as Colombian practice.

Source. Brazil verified at senado.leg.br. Colorado verified at leg.colorado.gov. dnp.gov.co, boletinoficial.gob.ar, Infoleg and eur-lex.europa.eu could not be read from this session.

17 August 2026

Chile, Egypt and Hong Kong. No claims removed. Verification boxes added recording that the sources could not be read.

Published. Nothing on these three pages was found to be false. All three already state plainly that the jurisdiction has no AI statute in force, which is the honest answer for each.

Corrected to. Each page now carries a dated verification box naming the government sources checked, stating that none could be read from this session, and naming the specific items a human should confirm: for Chile, the boletin number 15869-19, the bill's stage, and the publication and commencement dates of Ley 21.719; for Egypt, whether the executive regulations under Law 151 of 2020 have been issued and whether the Personal Data Protection Center is operational, and whether a National AI Strategy later than 2021 exists; for Hong Kong, the PCPD's August 2021 guidance and its seven principles, and whether the PCPD, HKMA or SFC has published AI material later than the items described.

Source. bcn.cl, camara.cl, senado.cl, mcit.gov.eg, cbe.org.eg, fra.gov.eg, pcpd.org.hk, hkma.gov.hk, sfc.hk, digitalpolicy.gov.hk and elegislation.gov.hk could not be read from this session on 17 August 2026.

17 August 2026

Netherlands. The AP does not lead AI Act market surveillance, and the supervisory architecture came from a law firm blog.

Published. That the Autoriteit Persoonsgegevens is the primary market surveillance authority for the EU AI Act in the Netherlands, that the RDI coordinates, that about eight sectoral authorities including the NZa, the Inspectie van het Onderwijs, the College voor de Rechten van de Mens and the ACM hold domain competence, and that the binding Annex III high-risk deadline remains 2 August 2026 because the Digital Omnibus has not been adopted. The sole source for that architecture was a Loyens and Loeff briefing, carried in the reference list.

Corrected to. The draft Uitvoeringswet AI-verordening, in consultation from 20 April to 1 June 2026 and still not introduced in parliament on 17 August 2026, proposes ten market surveillance authorities of which two, the RDI and the AP, jointly coordinate and one acts as central contact point. The ten are the AP, RDI, ILT, IGJ, NVWA, Nederlandse Arbeidsinspectie, AFM, DNB, the procureur-generaal of the Hoge Raad and the president of the Afdeling bestuursrechtspraak of the Raad van State. The NZa, the Inspectie van het Onderwijs, the College voor de Rechten van de Mens and the ACM are not among them. Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. Article 50(1) and 50(2) are provider duties, not deployer duties. Annex III numbers education at point 3, employment at point 4 and law enforcement at point 6, and medical devices sit in Annex I. Social scoring is prohibited whatever the actor. Deployer registration runs through Article 49 and reaches public authority deployers. The Wet bescherming persoonsgegevens was repealed on 25 May 2018 and is not the GDPR implementing act; the Uitvoeringswet AVG is. The EIOPA reference number EIOPA-BoS-25-360 appears nowhere at EIOPA and has been removed. The law firm reference has been removed.

Verified at. internetconsultatie.nl and rdi.nl

17 August 2026

Malaysia. A Bank Negara AI framework and a set of MDEC AI principles that do not exist.

Published. That Bank Negara Malaysia issued a Responsible AI Framework for Financial Institutions (RAFT) in 2024 built on five pillars, with duties to register material AI applications and give customers human review; that the Malaysia Digital Economy Corporation published AI Principles for Malaysia in 2024 across six named dimensions; that the National AI Roadmap 2021-2025 was an MDEC document; and that the data protection regulator, called the PDPC, had issued guidance requiring transparency for automated decisions.

Corrected to. No RAFT exists. Bank Negara’s index lists a Discussion Paper on Artificial Intelligence in the Malaysian Financial Sector of 5 August 2025, which binds nobody, and the Risk Management in Technology policy document of 28 November 2025, which does. Malaysia’s national AI instrument is the National Guidelines on AI Governance and Ethics, launched by MOSTI on 20 September 2024 and built on seven principles, not six. The AI Roadmap 2021-2025 is a MOSTI publication held by MASTIC, superseded by the National AI Action Plan 2026-2030 of 28 July 2026. The National AI Office, launched 12 December 2024, was replaced by AI Malaysia Berhad on 28 July 2026. The regulator is the Personal Data Protection Department, headed by the Personal Data Protection Commissioner; PDPC is Singapore’s regulator, it issued no such guidance, and the Personal Data Protection Act 2010 gives no right against solely automated decisions. Malaysia has no enacted AI statute.

Verified at. ai.gov.my and bnm.gov.my and mastic.mosti.gov.my and pdp.gov.my

17 August 2026

Ireland. The guide said Ireland has no AI statute. It has had one since 21 July 2026.

Published. That Ireland "has not passed, and under the structure of the EU AI Act does not need to pass, a domestic AI statute", that a National AI Office "is to be established by 2 August 2026", and that Ireland's market surveillance authorities are "led by the Health and Safety Authority". It also described a 2024 DPC intervention that caused Meta to pause AI training on EU user content, and listed Microsoft among the companies with their principal EU establishment in Dublin.

Corrected to. The Regulation of Artificial Intelligence Act 2026 was signed into law by the President on 21 July 2026 and established Oifig IS na hEireann, the AI Office of Ireland, as an independent statutory body and the central coordinating authority and single point of contact. The Department stated the Office was expected to be operational by 2 August 2026; Paul Byrne was announced as first Chief Executive on 30 July 2026 and a first board of seven, chaired by Mary Doyle, on 5 August 2026. The Health and Safety Authority is one of 15 national competent authorities designated on 16 September 2025 under what the Department calls a distributed model, and leads nothing. The Meta intervention could not be found in the DPC's own press releases and has been replaced with DPC actions the DPC published. Microsoft has been removed because no official Irish source read here names it. Citations to Article 288 TFEU, Articles 70 and 73 of the AI Act and Article 56 GDPR were removed because eur-lex.europa.eu, irishstatutebook.ie and oireachtas.ie all refused automated retrieval.

Verified at. enterprise.gov.ie and dataprotection.ie

17 August 2026

Italy. A national AI law described as adding obligations it expressly disclaims, and the two national authorities reversed.

Published. That Law 132/2025 "adds sector-specific obligations on top of the EU AI Act" and that the two layers are "cumulative, not alternative"; that AgID handles "market surveillance in domains within its remit"; that employers must give prior written notice to RSU or RSA under the AI law and that "an AI output cannot be the sole basis for dismissal"; that the law requires research publications to disclose AI involvement, requires universities to adopt internal AI policies, and gives the professional orders a guidance mandate; that the criminal provisions extend to platforms that knowingly host synthetic media; and that the binding Annex III high-risk date is 2 August 2026. The Gazzetta Ufficiale citation was given as Serie Generale n. 225.

Corrected to. Article 3, comma 5 states that the law produces no new obligations beyond Regulation (EU) 2024/1689. Article 20 designates AgID as the notifying authority under Article 70 and ACN as the market surveillance authority and single point of contact, with Banca d'Italia, CONSOB and IVASS preserved as market surveillance authorities under Article 74(6). Article 11 has three commas, routes the worker information duty through Article 1-bis of Legislative Decree 152/1997, and contains no dismissal rule. Articles 8 to 10 concern health data for research, not publication practice, and Article 13 addresses the individual professional, not the orders. Article 26 creates one offence, Article 612-quater of the codice penale, punishable by reclusione from one to five years, with no hosting offence. Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. The law was published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 and entered into force on 10 October 2025.

Verified at. normattiva.it and eiopa.europa.eu

17 August 2026

ISO 42001. Invented clause numbers, invented Annex A controls, and an insurance market that never said any of it.

Published. That Clause 8.6 covers AI objectives and Clause 8.8 covers supplier and customer relationships, that Annex A contains thirty eight controls across nine categories including named controls A.2.1, A.5.4 and A.9.1, that NIST GOVERN 1.1 reads "policies and procedures for AI risk management are in place" across approximately seventy subcategories, that Colorado SB 24-205 took effect on 1 February 2026 with a rebuttable presumption that ISO 42001 satisfies, that the Council of Europe Framework Convention is currently in force, and that insurers including Armilla, Munich Re and AIUC treat ISO 42001 certification as underwriting evidence that shortens timelines and affects premiums.

Corrected to. Clause 8 of ISO/IEC 42001:2023 has four subclauses and ends at 8.4; AI objectives are Clause 6.2 and there is no Clause 8.8. ISO sells the Annex A normative text, so the control count and all individual control wording are not publicly verifiable and have been removed rather than restated. NIST AI RMF 1.0 has 16 categories and 66 subcategories; GOVERN 1.1 reads "Legal and regulatory requirements involving AI are understood, managed, and documented" and MEASURE 2.5 concerns demonstrating validity and reliability. Colorado SB 25B-004 extends the requirements of SB 24-205 to 30 June 2026, and the recognised framework provision is an affirmative defence with the Attorney General designating frameworks. The Framework Convention has one ratification against the five required and is not in force. No insurer, underwriter or regulator publishes any recognition of, discount for, or reliance on ISO/IEC 42001 certification, and every such claim has been deleted. ISO/IEC 42006:2025, published July 2025, has been added.

Verified at. iso.org and airc.nist.gov and coe.int and leg.colorado.gov

17 August 2026

India. An IRDAI circular, an RBI rulebook and a statutory algorithmic audit duty that do not exist.

Published. That IRDAI had issued a circular requiring actuarial validation of AI underwriting models and human review of automated claims above defined thresholds; that RBI, SEBI and IRDAI had all issued binding AI governance guidance; that the Digital Personal Data Protection Act 2023 imposes an algorithmic audit duty on Significant Data Fiduciaries, establishes the Data Protection Board under Section 14 and carries penalties up to INR 250 crore; and that the EU AI Act entered into application in August 2024.

Corrected to. IRDAI has no AI circular. It constituted a Working Group on Artificial Intelligence Governance in the Insurance Sector on 17 June 2026. RBI's model risk guidance is a draft released for comment on 24 June 2026, comments closed 24 July 2026, preceded by the FREE-AI committee report of 13 August 2025 and its 26 recommendations. SEBI's AI instruments are three reporting circulars from 2019 and a cybersecurity advisory of 5 May 2026. The EU AI Act is Regulation (EU) 2024/1689 with phased application, changed by the Digital Omnibus in force 27 July 2026. All statutory detail attributed to the DPDP Act, to MeitY advisories and to the IndiaAI Mission has been removed, because meity.gov.in, indiacode.nic.in, pib.gov.in and egazette.gov.in could not be read at source.

Verified at. rbi.org.in and sebi.gov.in and irdai.gov.in and nist.gov

17 August 2026

Nigeria. The three NITDA AI instruments this desk built the guide on are not published by NITDA.

Published. That NITDA published a National AI Policy in 2021 and Guidelines on Artificial Intelligence in 2023 which "represent the de facto compliance baseline for AI operators in Nigeria", requiring contextual explainability, pre-deployment risk assessment, human oversight of consequential decisions and data governance; that the Federal Ministry of Communications, Innovation and Digital Economy issued a National AI Strategy 2024 with seven strategic pillars and six ethical principles; that the NDPC has published guidance expecting operators to explain automated decisions and provide human review; and that the Central Bank of Nigeria, the Nigerian Communications Commission, the Securities and Exchange Commission and the health regulators had each issued AI-specific requirements.

Corrected to. NITDA's own regulations register lists thirty six instruments and its publications list nine more. Neither contains a National AI Policy of 2021 or Guidelines on Artificial Intelligence of 2023. The only artificial intelligence document NITDA publishes is an AI Transformation Roadmap dated 11 March 2025, which is a plan for the Agency and creates no obligation. The Federal Ministry's public resources section carries no national AI strategy. The NDPC's resources section carries no guidance on automated decision making and none on artificial intelligence. No AI-specific instrument from the CBN, the NCC, the SEC or the health regulators could be read at their own domains. Every obligation attributed to those documents has been withdrawn. The guide also contradicted itself on the Digital Omnibus, saying in one place that the deferral was not adopted and in another that it was; it is adopted and in force since 27 July 2026. The NDPA penalty figures were removed because the Act and the General Application and Implementation Directive are published only as PDFs that automated retrieval could not read.

Verified at. nitda.gov.ng, ndpc.gov.ng and fmcide.gov.ng

17 August 2026

Israel. The wrong Bank of Israel directive, and three regulators' AI guidance that does not exist.

Published. That Bank of Israel Directive 355 governs model risk in credit decisioning, that the Capital Market, Insurance and Savings Authority had issued guidance on AI in underwriting and investment management, that the Ministry of Health and the Israel Medical Association had issued AI clinical guidance, that the National Cyber Directorate had published AI security guidance, that Israel holds observer status at the Council of Europe while considering ratification, and that EU AI Act provider violations carry up to EUR 30 million or 6 per cent.

Corrected to. The model risk instrument is Proper Conduct of Banking Business Directive 369, Management of Model Risk, dated 8/24, whose paragraph 5 states that "All the provisions of this directive also apply to models that include the use or reliance on artificial intelligence". Directive 355 governs business continuity. No AI instrument from the Capital Market Authority, the Ministry of Health or the National Cyber Directorate could be found at source and those claims were removed. Israel signed the Framework Convention, CETS No. 225, on 5 September 2024 and has not ratified it. Article 99 sets EUR 35 million or 7 per cent for prohibited practices, EUR 15 million or 3 per cent for other operator obligations and EUR 7.5 million or 1 per cent for incorrect information; the 30 million and 6 per cent figures are draft era numbers that never entered the Regulation. The Data Security Regulations set four categories, not three security levels, and Amendment No. 13 to the Privacy Protection Law, in force 14 August 2025, was missing entirely.

Verified at. boi.org.il and gov.il

17 August 2026

Indonesia. A national AI strategy, a financial services AI regulation and a breach deadline that do not exist.

Published. That Indonesia's AI governance rests on Presidential Regulation No. 24 of 2023 adopting a National AI Strategy, on OJK Regulation No. 11 of 2024 imposing a four tier AI risk framework on financial institutions with penalties up to Rp 15 billion, and on BSSN Regulation No. 4 of 2021; that the right to object to automated decisions is Article 25 of the Personal Data Protection Law, that cross border transfer is Articles 56 to 58, and that a personal data breach must be notified within 14 days.

Corrected to. Indonesia has enacted no AI statute. The ministry's own legal register, read year by year from 2016 to August 2026, contains no binding AI regulation; the only AI-specific instrument is Circular Letter of the Minister of Communication and Informatics No. 9 of 2023 on Artificial Intelligence Ethics of 19 December 2023, which is advisory, names nine values and carries no sanction. No Presidential Regulation No. 24 of 2023, no OJK AI regulation and no readable BSSN Regulation No. 4 of 2021 could be verified, and all three sections have been withdrawn. The objection right is Article 10, transfer is Article 56, and breach notice is 3 times 24 hours under Article 46 to both the data subject and the supervisory body. The supervisory body is established by the President and answers to the President under Article 58, not housed in the ministry. Law No. 1 of 2024 amending the Electronic Information and Transactions Law does not mention artificial intelligence anywhere, and its Article 28 offences all require intent, with Article 45A penalties of up to six years and Rp 1 billion.

Verified at. jdih.komdigi.go.id and ojk.go.id

17 August 2026

Kenya. The Continental AI Strategy was endorsed by the Executive Council, not the Assembly.

Published. That the African Union's Continental AI Strategy was "endorsed by the AU Assembly in July 2024", that the Office of the Data Protection Commissioner has been "operational since 2020", and that as of mid 2026 no draft AI bill had been tabled before the Kenyan Parliament.

Corrected to. The African Union Executive Council endorsed the Continental Artificial Intelligence Strategy at its 45th Ordinary Session in Accra on 18 and 19 July 2024. The claim that the ODPC has been operational since 2020 could not be confirmed at odpc.go.ke and has been removed. Section 35 is confirmed as the Data Protection Act's automated individual decision making provision; the Act is now cited as Cap. 411C in the revised Laws of Kenya, assented 8 November 2019 and commenced 25 November 2019. The finding that no AI bill sits before Parliament now rests, and says it rests, on the National Council for Law Reporting's own legislation and bills indexes rather than on a statement from Parliament. The Ministry of Information, Communications and the Digital Economy's domain did not resolve and the ICT Authority's returned a certificate error, so the March 2025 launch date of the National AI Strategy is marked as not confirmed at the issuing ministry.

Verified at. au.int and new.kenyalaw.org

17 August 2026

New Zealand. A privacy principle that came into force in May 2026 was missing.

Published. That the Privacy Act 2020's thirteen information privacy principles are what apply to AI processing, that more than twenty agencies have signed the Algorithm Charter, and that the Office of the Privacy Commissioner had indicated that principle 5 extends to safeguards against model inversion and data leakage.

Corrected to. The thirteen principles are confirmed, and so are the headings of principles 1, 5 and 10 relied on here. The guide omitted information privacy principle 3A, brought into force on 1 May 2026 by the Privacy Amendment Act 2025, which requires reasonable steps to notify an individual where personal information about them is collected from someone else. That is the principle most likely to bite on AI training and enrichment data, and it has been added throughout. The signatory count for the Algorithm Charter and the attribution to the OPC on model inversion could not be confirmed and were removed. legislation.govt.nz returned 403, and mbie.govt.nz and data.govt.nz returned no readable content, so the NZD 350,000 Tribunal cap, the Human Rights Act and Fair Trading Act readings, the national AI strategy's title and July 2025 date, and the Algorithm Charter's administration by Stats NZ now carry dated sourcing notes saying they are not confirmed at the issuing body.

Verified at. privacy.org.nz

17 August 2026

The Digital Omnibus. This desk said the delay was not adopted. It was.

Published. The global status tracker and the Omnibus timeline tracker both recorded that the Digital Omnibus delay proposal "was not formally adopted and published in the Official Journal before 2 August 2026, so it did not take legal effect". The sitewide banner, on 47 pages, still read "trilogue 28 April 2026. The 2 August 2026 high-risk deadline may shift to 2 December 2027."

Corrected to. The Digital Omnibus reached political agreement on 7 May 2026, the Council gave final approval on 29 June 2026, and it entered into force on 27 July 2026 as Regulation (EU) 2026/1744, six days before the original deadline. Annex III high-risk obligations now apply from 2 December 2027 and Annex I from 2 August 2028. The Article 5 prohibitions, the Article 50 transparency duties, the GPAI obligations and Article 4 AI literacy were not deferred and have been enforceable since 2 August 2026. The banner has been normalised across every page; there were thirteen different versions of it in circulation, several contradicting each other, and two asserting the opposite of the truth.

Verified at. digital-strategy.ec.europa.eu and ai-act-service-desk.ec.europa.eu

17 August 2026

Korea. The AI Basic Act, five material errors.

Published. The Korea guide stated that the AI Basic Act applies from August 2026, that it designates seven high-impact domains including legal services, that it imposes an incident notification duty on MSIT with a statutory definition of "serious incident", that MSIT operates a registry requiring registration and a registration number, and that fines are graduated with a higher tier above KRW 30 million.

Corrected to. The Act is Act No. 20676. It passed on 26 December 2024, was promulgated on 21 January 2025 and has been in force since 22 January 2026, together with its Enforcement Decree. Article 2(4) lists eleven high-impact categories and legal services is not among them; energy supply, drinking water production, nuclear material and facility safety, and public-body eligibility decisions are, and were missing. There is no incident notification duty and no definition of "serious incident" anywhere in the Act. There is no registry: the word does not appear. Article 43 sets a single maximum of KRW 30 million attaching to three failures only. The obligation the guide omitted, and the one that matters most to a foreign operator, is the Article 36 duty to designate a domestic representative in Korea.

Verified at. law.go.kr and msit.go.kr

17 August 2026

Singapore. GDPR rights described as Singapore law.

Published. The Singapore guide stated that the PDPA and the PDPC Advisory Guidelines give individuals a right to be notified that a decision is automated, a right to request human review of that decision, and a right to an explanation of the main factors, and told readers to review their privacy notices and complaint-handling procedures against those obligations. It also listed nine generative AI risk categories from the IMDA Model Framework, named ten AI Verify principles while saying eleven, dated the MAS FEAT Principles to November 2019 and the PDPC Advisory Guidelines to 2023, and placed those Guidelines in a binding tier.

Corrected to. The PDPA contains no automated decision-making regime. Those are GDPR Article 22 rights and they have been removed. The 2020 amendments introduced breach notification, data portability and the legitimate interests and business improvement exceptions, not automated decision provisions. The IMDA document is organised around nine governance dimensions, not risk categories, and none of the nine published here was one of them. The eleven AI Verify principles include Human Agency and Oversight and Inclusive Growth, Societal and Environmental Well-being, and do not include data privacy. FEAT was published in November 2018; the Veritas consortium was formed in November 2019, which is the likely source of the slip. The Advisory Guidelines were issued on 1 March 2024 and state at paragraph 2.2 that they are not legally binding.

Verified at. pdpc.gov.sg, aiverifyfoundation.sg, imda.gov.sg and mas.gov.sg

17 August 2026

Japan. The AI Promotion Act is a 2025 statute, not a 2024 one.

Published. The Japan guide dated the AI Promotion Act to 24 May 2024 with entry into force in June 2024, said the Act codifies seven principles superseding the April 2019 Social Principles, placed Japan AISI within AIST, cited a METI "AI Business Guidelines (Generative AI Edition)" of April 2024 and an FSA supervisory guidance on AI, and said Japan had ratified the Council of Europe Framework Convention.

Corrected to. The Act is Law No. 53 of 2025. It passed the House of Councillors on 28 May 2025, was promulgated on 4 June 2025 and came fully into force on 1 September 2025. Article 3 sets out five policy principles and none is the list published here; the Social Principles were finalised in March 2019 and were not superseded. Japan AISI was established on 14 February 2024 within IPA. The guidelines are the AI Business Guidelines, published jointly by MIC and METI, version 1.0 of 19 April 2024 and currently version 1.2 of 31 March 2026; there is no Generative AI Edition. The FSA item is an AI Discussion Paper, expressly an initial mapping of issues. Japan signed the Framework Convention on 11 February 2025 and has not ratified it. The Act is administered by the Cabinet Office through the AI Strategy Headquarters, which the guide did not mention. The file name and URL still carry 2024 and are left unchanged so existing links do not break.

Verified at. shugiin.go.jp, www8.cao.go.jp, meti.go.jp, fsa.go.jp and mofa.go.jp

17 August 2026

Brazil. Six errors in PL 2338, including an extraterritoriality clause that does not exist.

Published. The Brazil guide said PL 2338 was introduced by Senator Eduardo Gomes, that the jurists commission was coordinated by former Minister Cezar Peluso, that high risk covers eight domains including democratic processes and electoral contexts, that the framework has three risk tiers, that it follows a market-effects principle applying regardless of where the operator is established, that the impact assessment goes to the ANPD which may reject a deployment, and it cited a "G20 Brasilia Ministerial Declaration on AI" endorsing PL 2338 as a model.

Corrected to. The bill was introduced by Senator Rodrigo Pacheco; Eduardo Gomes was its rapporteur. The commission was chaired by Minister Ricardo Villas Boas Cueva of the Superior Tribunal de Justica. Article 14 lists twelve categories and there is no democratic processes or electoral category. The text has two risk categories, not three. It contains no territorial scope or extraterritoriality provision at all. Articles 25 and 26 send the assessment to the sector authority, not the ANPD, and no body holds a power of ex ante rejection. No G20 Brasilia declaration could be found; the G20 Brazil digital economy ministerial declaration was issued in Maceio on 13 September 2024. The guide also never stated the penalties, which are up to BRL 50 million per infraction or 2 per cent of Brazilian gross revenue under Article 50(II).

Verified at. senado.leg.br, camara.leg.br and gov.br

17 August 2026

Canada. An OSFI framework that does not exist.

Published. The Canada guide said OSFI published an "Artificial Intelligence in Banking Supervisory Framework" in 2024 imposing binding supervisory expectations, that AIDA would have created an independent AI and Data Commissioner with order-making powers, that Colorado SB 24-205 has been in force since 1 February 2026, and that Executive Order 14110 and OMB M-24-10 are the live US federal baseline.

Corrected to. No such OSFI framework exists. The instrument is Guideline E-23 on Model Risk Management, effective May 2027, alongside a joint OSFI and FCAC risk report of 24 September 2024 which imposes nothing. AIDA section 33 would have allowed the Minister to designate a departmental official as Commissioner to assist the Minister; the order-making powers sat with the Minister. Colorado SB 24-205 was delayed to 30 June 2026 by SB25B-004. Executive Order 14110 was revoked on 20 January 2025 by EO 14148 and superseded by EO 14179.

Verified at. osfi-bsif.gc.ca, parl.ca, leg.colorado.gov and govinfo.gov

17 August 2026

Saudi Arabia. There is no version 2.0, and the conformity assessment claim was backwards.

Published. The Saudi guide cited the SDAIA AI Ethics Principles "version 2.0, adopted 14 September 2023", the Deepfakes Guidelines "version 1.0, September 2024" and Generative AI Guidelines of January 2024, and drew its central comparison as Saudi self-assessment against EU conformity assessment.

Corrected to. There is no version 2.0. The September 2023 English edition is printed version 1.0, and the current edition is May 2025, document SDAIA-P114E. Every SDAIA instrument cited had been replaced by a May 2025 edition, including the Deepfakes Guidelines, now version 2 (SDAIA-P119), and both sets of Generative AI Guidelines (SDAIA-P115E and SDAIA-P116E). SDAIA's own text states that high-risk AI systems must undergo pre- and post-conformity assessments in addition to adhering to the ethics, which is the opposite of the comparison the guide drew. The PDPL Royal Decree numbers and enforcement dates could not be found on SDAIA's own pages and are now marked unconfirmed rather than stated.

Verified at. sdaia.gov.sa and dgp.sdaia.gov.sa

17 August 2026

Norway. A designation made seventeen months before publication.

Published. The Norway guide, published 10 August 2026, stated that Norway had not yet designated a market surveillance authority as of August 2026, and dated the Datatilsynet AI sandbox to 2021.

Corrected to. Nkom was designated the national coordinating AI supervisor on 21 March 2025, Norsk akkreditering the national accreditation body, and KI Norge was created inside Digdir and publicly launched on 12 June 2026. The sandbox was established in autumn 2020, with 2021 as its first operative year. The guide also omitted the draft lov om kunstig intelligens, consulted from 30 June 2025, with a second consultation planned for autumn 2026 and the bill due at the Storting in spring 2027, which the government announced six days before publication.

Verified at. regjeringen.no and datatilsynet.no

17 August 2026

Thailand. The National AI Strategy is not MDES alone.

Published. The Thailand guide attributed the National AI Strategy and Action Plan 2022 to 2027 to the Ministry of Digital Economy and Society.

Corrected to. It is a joint MHESI and MDES product, approved by Cabinet on 26 July 2022, with NSTDA, NECTEC and ONDE as joint secretariat. ETDA's live vehicle is also no longer the 2022 draft royal decree: since 11 June 2025 it has been a draft primary Act, consulted to 24 June 2025. The headline finding, that Thailand has no cross-sector AI statute, holds.

Verified at. nectec.or.th and etda.or.th

17 August 2026

The Council of Europe Framework Convention. Wrong treaty number.

Published. The Mexico guide cited the Council of Europe Framework Convention on Artificial Intelligence as "Convention 307".

Corrected to. The treaty is CETS No. 225, opened for signature at Vilnius on 5 September 2024. Sourcing note: coe.int returns 403 to automated fetch, so this was not read at the Council of Europe's own domain. It is corroborated at mofa.go.jp, which records Japan's signature on 11 February 2025.

Verified at. mofa.go.jp; not read at coe.int

17 August 2026

EU AI Act penalty ceilings and who enforces them.

Published. Several pages attributed the Article 5 ceiling of EUR 35 million or 7 per cent to the AI Office, and the Spain guide attributed the EUR 7.5 million or 1 per cent information ceiling to AESIA as though it were Spanish law.

Corrected to. Article 99 of Regulation (EU) 2024/1689 sets EUR 35 million or 7 per cent for prohibited practices, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for supplying incorrect, incomplete or misleading information, whichever is higher in each case, with the lower figure applying to SMEs and start-ups. National market surveillance authorities enforce them. The AI Office holds the separate general-purpose AI regime under Article 101, whose ceiling is EUR 15 million or 3 per cent. These are EU ceilings, not Spanish ones.

Verified at. ai-act-service-desk.ec.europa.eu

17 August 2026

The OECD AI Principles revision date.

Published. Several guides dated the OECD AI Principles revision to November 2024.

Corrected to. The Principles were revised on 3 May 2024 by the Council at Ministerial level.

Verified at. oecd.org

17 August 2026

A Commission Article 50 guidance and Code of Practice that could not be found.

Published. The France and Germany guides both stated that the European Commission published Article 50 implementation guidance and a Code of Practice for transparency labelling in June 2026, with compliance templates.

Corrected to. Neither the document nor the date could be confirmed at digital-strategy.ec.europa.eu on 17 August 2026. Both citations have been withdrawn with a sourcing note rather than restated. What is settled is the deadline: the Article 50(2) machine-readable marking transitional period ends on 2 December 2026.

Verified at. no source at issuer domain

17 August 2026

ISO CG 40 47. How the form number is sourced

Published. The AI Risk Index stated as fact that ISO endorsement CG 40 47 gives commercial general liability writers a standard-form AI exclusion.

Corrected to. The dataset now states that industry sources report that endorsement, and the record carries a note saying the form number is attested by trade and law-firm analysis only. We tried again on 17 August 2026 to confirm it against the filed forms, at ISO, at Verisk and through state filing portals, and could not. The number has not been removed, because the narrowing of silent AI cover at renewal is real and the form number is how a reader finds the endorsement on a renewal schedule. What has changed is that the file no longer asserts what it cannot verify. A caution for anyone checking this: a search engine will return a confident answer confirming the form and its January 2026 effective date, assembled from a cluster of pages that includes sites in this network. Our own pages reflected back at us are not verification.

Verified at. no source at issuer domain

15 August 2026

Germany. The name and status of the national AI Act implementation law

Published. The law was named the KI-Marktaufsichts- und Implementierungsgesetz and described as a February 2026 cabinet draft of uncertain parliamentary status.

Corrected to. The law is the Gesetz zur Marktueberwachung und Innovationsfoerderung von kuenstlicher Intelligenz (KI-MIG). The Bundestag adopted it on 11 June 2026 and it entered into force on 29 July 2026.

Verified at. bundesnetzagentur.de and bundestag.de

15 August 2026

Germany. The role of DAkkS under the AI Act

Published. DAkkS was described as Germany’s notifying authority under the AI Act.

Corrected to. DAkkS is Germany’s national accreditation body and accredits conformity assessment bodies. Notifying authority functions under Article 28 sit with the authorities already designated for the relevant Annex I harmonisation legislation. The Bundesnetzagentur holds that role for Directive 2014/53/EU on radio equipment.

Verified at. bundesnetzagentur.de

15 August 2026

Ireland. The coordinating authority for the AI Act

Published. The Health and Safety Authority was described as coordinating AI Act market surveillance nationally.

Corrected to. Ireland designated 15 national competent authorities on 16 September 2025, the Health and Safety Authority among them. A National AI Office is to be established by 2 August 2026 as the central coordinating authority and single point of contact.

Verified at. enterprise.gov.ie

15 August 2026

HSB. What the AI liability product covers

Published. HSB’s product was described as the first standalone SMB AI liability policy in the US market, covering AI model errors, biased outputs and AI-facilitated data loss.

Corrected to. HSB introduced AI Liability Insurance on 18 March 2026 for small and medium-sized businesses. It covers liability for bodily injury and property damage caused by the insured’s use of AI, and personal and advertising injury claims. Standard limits are USD 25,000 or USD 50,000 with a USD 500 deductible. The claim to be first was not stated by the carrier and has been withdrawn.

Verified at. munichre.com

15 August 2026

Armilla. Coverage limit and availability

Published. Armilla’s limit was given as approximately USD 25 million with an unverified marker attached, and European availability was asserted.

Corrected to. Armilla is a Lloyd’s of London coverholder writing affirmative AI liability insurance with limits up to USD 25 million per organisation. Armilla states that coverage may not be available in all jurisdictions and is offered only through properly licensed surplus lines brokers.

Verified at. armilla.ai

15 August 2026

Munich Re aiSure. Capacity

Published. aiSure was described without a capacity figure, or with a figure attributed only in passing.

Corrected to. Mosaic Insurance announced its partnership with Munich Re’s aiSure on 26 February 2026, providing an initial capacity of EUR, USD or CAD 15 million against defined AI performance failures.

Verified at. mosaicinsurance.com

15 August 2026

ElevenLabs. Who backed the first AI agent policy

Published. The ElevenLabs policy of February 2026 was described as backed by Munich Re, or by a Munich Re-linked insurer.

Corrected to. The policy was announced on 11 February 2026 and was written on the strength of AIUC-1 certification from the Artificial Intelligence Underwriting Company. No source at AIUC or ElevenLabs names Munich Re. The attribution has been removed.

Verified at. aiuc.com

15 August 2026

AIUC. The expansion of the acronym

Published. AIUC was expanded in places as the Coalition for Artificial Intelligence Underwriting Criteria.

Corrected to. AIUC is the Artificial Intelligence Underwriting Company. AIUC-1 is its published AI agent standard, covering data and privacy, security, safety, reliability, accountability and societal risk.

Verified at. aiuc.com

15 August 2026

Counterpart. Affirmative AI coverage

Published. Counterpart was listed as offering affirmative AI coverage launched 21 November 2025, backed by Aspen, Markel and Westfield Specialty, for businesses up to USD 10 million revenue.

Corrected to. Counterpart publishes management liability and professional liability products. No affirmative AI product, carrier panel or revenue threshold of that description is published at its own domain. The entry has been withdrawn from the article text and from the AI Risk Index dataset.

Verified at. yourcounterpart.com

15 August 2026

AIG, Great American and WR Berkley. Policy filings

Published. These carriers were described as having filed in late 2025 to limit AI liability under standard E&O, D&O and cyber policies.

Corrected to. No such filing could be verified at any of the three carriers’ own domains. The named-carrier attribution has been removed. The qualitative point is kept: the ISO CG 40 47 endorsement gives commercial general liability writers a standard-form AI exclusion, so silent AI cover is narrowing at renewal.

Verified at. no source at issuer domain

15 August 2026

AI liability insurance market size

Published. The dataset carried an estimate of USD 500 billion by 2030, attributed to AIUC founders’ July 2025 launch materials and flagged as a founder projection.

Corrected to. The figure could not be located at aiuc.com. The record has been removed from the AI Risk Index dataset rather than reworded.

Verified at. no source at issuer domain

15 August 2026

Munich Re aiSure. The word parametric

Published. aiSure was described as parametric cover, and in one country guide as a parametric or performance-based product, across 14 pages including the AI Risk Index dataset.

Corrected to. Munich Re does not describe aiSure as parametric anywhere it publishes. Munich Re and Mosaic Insurance describe it as a performance guarantee for AI systems that settles on measurable performance data, requiring Munich Re technical due diligence before cover is written. A parametric trigger pays on an index without asking about the loss, which is a different and consequential product design. The word was ours and has been removed from every description of aiSure and of Munich Re.

Verified at. munichre.com and mosaicinsurance.com

15 August 2026

ElevenLabs. The date of the first AIUC-1 backed policy

Published. The policy was dated 11 February 2026 on nine pages, including in the entry above.

Corrected to. Both aiuc.com and elevenlabs.io date the announcement 12 February 2026. Every page now reads 12 February 2026. This entry supersedes the date given in the ElevenLabs entry above, which is left as published because this log is not rewritten.

Verified at. aiuc.com and elevenlabs.io

15 August 2026

ElevenLabs. Residual carrier attributions

Published. Three country guides still said the ElevenLabs policy was backed by Munich Re, announced via Munich Re, or announced in partnership with an insurer linked to Munich Re.

Corrected to. Neither AIUC nor ElevenLabs names an insurer or a reinsurer for that policy. All three attributions have been removed. The policy was placed through Lloyd’s of London, which both parties publish.

Verified at. aiuc.com and elevenlabs.io

15 August 2026

Ireland. The coordinating authority, second pass

Published. The global regulation status tracker still stated in three places that the Health and Safety Authority coordinates AI Act market surveillance in Ireland.

Corrected to. The Health and Safety Authority is one of 15 national competent authorities designated on 16 September 2025. Central coordination and the single point of contact sit with a National AI Office due by 2 August 2026.

Verified at. enterprise.gov.ie

15 August 2026

Armilla. The USD 25 million figure in the AI Risk Index

Published. The AI Risk Index cited an Armilla page headlined as raising Lloyd’s-backed coverage to 25M, and the index entry described limits as raised to USD 25 million per organisation in January 2026.

Corrected to. The USD 25 million is the limit of Armilla’s Standalone AI Liability Policy, up to that amount per organisation. It is not a funding round. Armilla’s own announcement page carries two conflicting dates for it, one year apart, so this site now states the limit without a date and cites armilla.ai/ai-insurance.

Verified at. armilla.ai

Reporting an error

Readers who believe they have identified an error are invited to write to editors@agentliability.co. Please include the source and the date of your reference.

The Network

Five properties, one framework.