AIセキュリティ

Second-Tier AI Regulation Map — Latin America, Middle East, and Australia: Hard Law, Existing Law, and Soft-Law Chaos at a Glance

Published2026-05-20Updated2026-08-01Ryuta Hamamoto

A one-page map of the "second tier" of AI regulation that is easy to miss behind the EU, US, China, Korea, Vietnam, and India.

Second-Tier AI Regulation Map — Latin America, Middle East, and Australia: Hard Law, Existing Law, and Soft-Law Chaos at a Glance
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

EU AI Act, US SB 53, Korea's AI Basic Act, Vietnam's AI Law, India's DPDP — this series has covered country-by-country regimes. For Japanese companies going global, there is another set of markets that get little press but still matter: Latin America (Brazil, Mexico, Chile), the Middle East (UAE, Saudi Arabia), and Australia.

I call these the "second tier of AI regulation." Mentions in the media are less than a third of first-tier coverage (EU, US, China, Korea, Vietnam, India). For Japanese firms with global SaaS, fintech, or manufacturing subsidiaries, they are landmines that surface as compliance findings long after you have stopped thinking about them.

Each region takes a different stance. Latin America is hard-law in progress; the Middle East mixes existing law with sector strategy; Australia is soft-law and confused. Here is how I read each one.

TL;DR

  • Six jurisdictions across three regions, sorted into hard-law progress / existing-law leverage / soft-law continuation
  • Brazil PL 2338: Senate-passed, lower house pending; force expected H2 2026 or later
  • Mexico and Chile: EU AI Act-style risk-based bills under debate in 2026
  • UAE: PDPL + DIFC Regulation 10 two-layer model; human oversight for automated decisions
  • Saudi Arabia: 2026 Year of AI; SDAIA Framework is a de facto government procurement requirement
  • Australia: VAISS (2024) → GfAA (2025); Mandatory Guardrails effectively collapsed

Second tier at a glance — three-stance table

Start with the full map.

Jurisdiction Stance Comprehensive AI law Main rules Lead body Status
Brazil Hard law in progress PL 2338 (pending) 4-tier risk base ANPD Force expected H2 2026
Mexico Hard law in progress Federal AI bill (draft) Risk base, CONAIA CONAIA (planned) Approval target 2026
Chile Hard law in progress AI bill (pending) 4-tier risk base TBD Lower house passed Aug 2025
UAE Existing law + sector None PDPL + DIFC Reg 10 TDRA / DIFC DPA PDPL full force 2027
Saudi Arabia Soft law (semi-mandatory) None SDAIA Framework SDAIA 2026 Year of AI
Australia Soft-law chaos None VAISS → GfAA DISR / NAIC Mandatory dissolved

When I put this table in front of Japanese executive teams, the line that lands hardest is "Saudi SDAIA certification is effectively mandatory for government procurement." Informal commercial practice has become an explicit certification gate. Second tier does not mean low stakes.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

Latin America — EU AI Act-style hard-law wave

Latin America is unusual: three countries are debating EU AI Act-style risk-based bills in parallel.

Brazil PL 2338/2023 is furthest along. It passed the Senate on December 10, 2024 and is still in the Chamber of Deputies.1 Design is a four-tier risk model (excessive / high / medium / low) plus a Brazil-specific subject-based axis (who is harmed). Penalties top out at 2% of Brazilian revenue — milder than the EU's 7% — but ANPD holds strong enforcement power as coordinator of SIA (National AI Regulation System).

Force was once expected in H1 2026; politics (coalition friction, industry lobby, human-rights amendments) have delayed it. My current read is H2 2026 through H1 2027. Signature under Lula is nearly certain; a six-month grace period after signature is the likely model.

Mexico is still at federal draft stage. The bill contemplates CONAIA (National Commission for AI), risk tiers, and EU-style impact assessments, with a 2026 Senate science and technology committee approval target.2 In parallel, CNBV (finance), COFEPRIS (medical devices / SaMD), and LFPDPPP (privacy) move sector by sector — Japanese fintech and medical AI firms often feel sector rules first.

Chile is further than many expect. The AI bill passed the Chamber of Deputies in August 2025 and is in the Senate.3 Four risk tiers mirror the EU, with an explicit ban on deepfake sexual content involving children and youth as unacceptable use — a Global South pattern that puts child protection at the center, alongside Korea's treble damages approach.

Chile also enacted Law No. 21.719 (December 2024), a GDPR-style privacy framework that takes effect December 2026, creating a two-layer stack with the AI bill.

The shared Latin American pattern is EU AI Act as reference, reinterpreted for Global South politics. A Japanese subsidiary operating AI in Brazil can end up facing EU + Brazil + subject-based uplift — heavier compliance than the map suggests.

Middle East — UAE's two layers and Saudi strategic soft law

Same region, different strategies.

UAE chose no comprehensive AI law. Instead it combines federal PDPL (Federal Decree-Law No. 45/2021) with free-zone rules (DIFC, ADGM, DHCC, and others) in a two-layer stack.4

Federal PDPL was enacted September 2021, with full force in January 2027. Article 22 is the AI-critical piece: right to object to automated decisions and right to human intervention — structurally close to GDPR Article 22, and directly relevant to HR tech, credit, and scoring.

On the free-zone side, DIFC Regulation 10 is the one to open first: human oversight for employment screening, financial assessment, and legal determinations. Global banks, fintech, and legal tech with DIFC presence need this on the checklist from day one.

Saudi Arabia chose "strategic soft law." SDAIA's AI Adoption Framework (November 2025) is voluntary on paper but functions as a de facto government procurement requirement.5

Five pillars:

Pillar Content
Data governance Quality, lifecycle, localization
Model accountability Versioning, change history, clear ownership
Transparency User notice, AI-use disclosure
Human oversight Human intervention for critical decisions
Risk management Impact assessment, continuous monitoring, incident response

Saudi Arabia officially designated 2026 the Year of Artificial Intelligence, with about USD 56 billion a year in expected government AI productivity gains. Under Vision 2030, public AI procurement is scaling fast. Japanese vendors selling AI into the Saudi government effectively need SDAIA-aligned certification.

PDPL fines top out at SAR 5 million (roughly JPY 200 million); the SDAIA Framework itself has no penalty. The model is certification = market access, with economic force comparable to hard law. Honestly, that commercial gate bites harder than many statute fines I see elsewhere.

Australia — soft law continues; Mandatory Guardrails collapsed

Australia is the hardest of the three regions to forecast.

Timeline:6

When What
Sep 2024 Voluntary AI Safety Standard (VAISS), 10 guardrails
2024–2025 Mandatory Guardrails for High-Risk AI consultation
Oct 2025 Guidance for AI Adoption (GfAA) published; replaces VAISS
2026 now Future of Mandatory Guardrails unclear

VAISS was built on the assumption that a mandatory high-risk version would follow. Within about twelve months GfAA replaced it, and Mandatory Guardrails debate effectively stalled. DISR and the National AI Centre now frame GfAA as comprehensive enough that mandatory rules may not be needed — a post-2025 election policy shift under the Albanese Labor government is a major factor.

For Japanese operations in Australia, the near term remains existing-law compliance:

  • Privacy Act 1988: personal information, APP principles, breach notification
  • Australian Consumer Law: AI product safety, misleading claims
  • Anti-discrimination statutes: AI hiring tools
  • Online Safety Act 2021: AI-generated content safety
  • Sector rules: APRA (finance), TGA (medical devices)

Australia is a "strengthen existing law rather than write new AI law" model — opposite the EU/US drift, and a legitimate strategic choice.

Priority order for Japanese companies

Treating all six as equal is not realistic. Here is the field frame I use.

Tier A (must address now) — live penalties, heavy Japanese presence

  • UAE PDPL + DIFC Regulation 10: hits financial AI and HR tech
  • Saudi SDAIA: mandatory if you have government deals

Tier B (must address in 2026–2027) — legislation nearly certain

  • Brazil PL 2338: Senate-passed → signature after lower house → force 2026–2027
  • Chile AI bill: lower house passed; force after Senate

Tier C (keep watching) — unclear or existing law enough for now

  • Mexico AI bill: still draft; sector rules (CNBV, COFEPRIS) bite first
  • Australia Mandatory Guardrails: unclear; existing law covers the near term

My usual advice: start Tier A, stand up Tier B projects inside 2026, and review Tier C quarterly. "We deprioritized Saudi SDAIA and got burned" has become more common this year — Tier A especially.

One integrated map — how WARP SECURITY helps

TIMEWELL's WARP SECURITY builds a single compliance chart that puts first and second tiers on one map per company. Splitting "first tier precise, second tier separate" always fails, for three reasons.

First, shared core requirements — risk tiers, human oversight, impact assessment, labeling — so dual systems create duplicate work and inconsistent rules.

Second, market priority is a business decision. Putting "Brazil subsidiary ramps next year; Saudi government deal in 2026 Q4" on the same calendar as six compliance timelines is what makes the trade-offs governable.

Third, second tier can become first tier overnight. If three Latin American bills pass together, the map flips. Without an extensible integrated map, every new law restarts design from zero.

Typical map components:

  • Market timelines: force date, grace period, penalty activation per market
  • Requirement matrix: risk classification, human oversight, impact assessment, labeling, local representative × nine markets (EU + first tier + second tier) = 45-cell checklist
  • Evidence folder design: one audit pack reusable across jurisdictions

Unsexy work — but building it once in 2026 is what enables portfolio-level optimization when 2027's regulatory wave hits.

What is moving on the first-tier benchmark — the EU AI Act's staged application

The first-tier benchmarks these regimes reference are moving too. The EU AI Act (Regulation (EU) 2024/1689) has a general application date of 2 August 2026, but not every provision starts on that day. What does start then is Chapter IV (the Article 50 transparency obligations), Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration — Articles 40–49), Chapter VI, Chapters VIII–XI, and Article 101 (the Commission's power to fine general-purpose AI (GPAI) providers). Fines run up to €35 million or 7% of global turnover for prohibited practices under Article 5, and up to €15 million or 3% for GPAI-related and other breaches, whichever is higher.

The substantive high-risk obligations, however, do not begin on that date. Under the amending act Regulation (EU) 2026/1744 (the Digital Omnibus — adopted 8 July 2026, published in the Official Journal on 24 July 2026, in force from 27 July 2026), Chapter III Sections 1, 2 and 3 apply to Annex III high-risk AI (Article 6(2)) from 2 December 2027, and to Annex I product-embedded high-risk AI (Article 6(1)) from 2 August 2028. Article 22 (authorised representative), Article 25 (value chain), Article 26 (deployer obligations) and Article 27 (FRIA) switch on at the same points. "The EU AI Act applies in full from 2 August 2026" is not an accurate reading, so keep the two apart when you build an internal schedule.

On 2 December 2026, the newly added prohibitions take effect — Article 5(1)(ba) (non-consensual sexual deepfakes), Article 5(1)(bb) (CSAM generation), and Articles 5(1a) and 5(1b). The new Article 111(4) also requires providers of synthetic-content-generating AI placed on the market before 2 August 2026 to comply with Article 50(2) by that same date. For high-risk systems already on the market, the rules bite only where significant changes in their designs are made on or after the relevant Chapter III application date.

Because Latin America's three bills track EU-style risk design, EU enforcement practice may become a reference for second-tier interpretation — not a certainty, but something to watch as Brazil and Chile interpret their texts. For integrated governance operations, see also Governed AI enterprise agents.

Summary

  • Six second-tier markets sorted into hard-law progress / existing-law leverage / soft-law continuation
  • Latin America's three countries are debating EU AI Act-style hard law in parallel
  • UAE is federal PDPL + DIFC Reg 10; Saudi SDAIA Framework is de facto mandatory for government procurement
  • Australia's Mandatory Guardrails have collapsed; existing law continues
  • Japanese priority: Tier A (UAE, KSA) → Tier B (Brazil, Chile) → Tier C (Mexico, Australia)

Low media frequency is not low importance. Saudi SDAIA and UAE DIFC Regulation 10 already function as market-access preconditions through certification and free-zone rules.

While first-tier regimes dominate the agenda, more teams will discover a Saudi deal blocked for missing SDAIA alignment — or a DIFC subsidiary with a Regulation 10 issue. I share this piece so second tier is not parked as "later." If you have either market on the 2026 pipeline, put Tier A on this quarter's board before the next first-tier memo.

Further reading: Korea AI Basic Act, January 2026, Vietnam AI Law — ASEAN's first comprehensive statute, Singapore Agentic AI Governance Framework, India DPDP + AI Sutras.

References

Footnotes

  1. Brazil AI Regulation: Bill 2338, ANPD, Current Status (2026) - Nathaly Calixto

  2. AI laws and regulations in Mexico - CMS Expert Guide

  3. Chile AI Bill Signals Global Governance Shift - AI CERTs News

  4. AI in the UAE: Understanding the Regulatory Landscape - Latham & Watkins

  5. Saudi Arabia's AI governance framework: what it means for 2026 - 6clicks

  6. Voluntary AI Safety Standard - Department of Industry Science and Resources

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles