Hello, this is Ryuta Hamamoto from TIMEWELL.
EU AI Act, US SB 53, Korea's AI Basic Act, Vietnam's AI Law, India's DPDP — this series has covered country-by-country regimes. For Japanese companies going global, there is another set of markets that get little press but still matter: Latin America (Brazil, Mexico, Chile), the Middle East (UAE, Saudi Arabia), and Australia.
I call these the "second tier of AI regulation." Mentions in the media are less than a third of first-tier coverage (EU, US, China, Korea, Vietnam, India). For Japanese firms with global SaaS, fintech, or manufacturing subsidiaries, they are landmines that surface as compliance findings long after you have stopped thinking about them.
Each region takes a different stance. Latin America is hard-law in progress; the Middle East mixes existing law with sector strategy; Australia is soft-law and confused. Here is how I read each one.
TL;DR
- Six jurisdictions across three regions, sorted into hard-law progress / existing-law leverage / soft-law continuation
- Brazil PL 2338: Senate-passed, lower house pending; force expected H2 2026 or later
- Mexico and Chile: EU AI Act-style risk-based bills under debate in 2026
- UAE: PDPL + DIFC Regulation 10 two-layer model; human oversight for automated decisions
- Saudi Arabia: 2026 Year of AI; SDAIA Framework is a de facto government procurement requirement
- Australia: VAISS (2024) → GfAA (2025); Mandatory Guardrails effectively collapsed
Second tier at a glance — three-stance table
Start with the full map.
| Jurisdiction | Stance | Comprehensive AI law | Main rules | Lead body | Status |
|---|---|---|---|---|---|
| Brazil | Hard law in progress | PL 2338 (pending) | 4-tier risk base | ANPD | Force expected H2 2026 |
| Mexico | Hard law in progress | Federal AI bill (draft) | Risk base, CONAIA | CONAIA (planned) | Approval target 2026 |
| Chile | Hard law in progress | AI bill (pending) | 4-tier risk base | TBD | Lower house passed Aug 2025 |
| UAE | Existing law + sector | None | PDPL + DIFC Reg 10 | TDRA / DIFC DPA | PDPL full force 2027 |
| Saudi Arabia | Soft law (semi-mandatory) | None | SDAIA Framework | SDAIA | 2026 Year of AI |
| Australia | Soft-law chaos | None | VAISS → GfAA | DISR / NAIC | Mandatory dissolved |
When I put this table in front of Japanese executive teams, the line that lands hardest is "Saudi SDAIA certification is effectively mandatory for government procurement." Informal commercial practice has become an explicit certification gate. Second tier does not mean low stakes.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
Latin America — EU AI Act-style hard-law wave
Latin America is unusual: three countries are debating EU AI Act-style risk-based bills in parallel.
Brazil PL 2338/2023 is furthest along. It passed the Senate on December 10, 2024 and is still in the Chamber of Deputies.1 Design is a four-tier risk model (excessive / high / medium / low) plus a Brazil-specific subject-based axis (who is harmed). Penalties top out at 2% of Brazilian revenue — milder than the EU's 7% — but ANPD holds strong enforcement power as coordinator of SIA (National AI Regulation System).
Force was once expected in H1 2026; politics (coalition friction, industry lobby, human-rights amendments) have delayed it. My current read is H2 2026 through H1 2027. Signature under Lula is nearly certain; a six-month grace period after signature is the likely model.
Mexico is still at federal draft stage. The bill contemplates CONAIA (National Commission for AI), risk tiers, and EU-style impact assessments, with a 2026 Senate science and technology committee approval target.2 In parallel, CNBV (finance), COFEPRIS (medical devices / SaMD), and LFPDPPP (privacy) move sector by sector — Japanese fintech and medical AI firms often feel sector rules first.
Chile is further than many expect. The AI bill passed the Chamber of Deputies in August 2025 and is in the Senate.3 Four risk tiers mirror the EU, with an explicit ban on deepfake sexual content involving children and youth as unacceptable use — a Global South pattern that puts child protection at the center, alongside Korea's treble damages approach.
Chile also enacted Law No. 21.719 (December 2024), a GDPR-style privacy framework that takes effect December 2026, creating a two-layer stack with the AI bill.
The shared Latin American pattern is EU AI Act as reference, reinterpreted for Global South politics. A Japanese subsidiary operating AI in Brazil can end up facing EU + Brazil + subject-based uplift — heavier compliance than the map suggests.
Middle East — UAE's two layers and Saudi strategic soft law
Same region, different strategies.
UAE chose no comprehensive AI law. Instead it combines federal PDPL (Federal Decree-Law No. 45/2021) with free-zone rules (DIFC, ADGM, DHCC, and others) in a two-layer stack.4
Federal PDPL was enacted September 2021, with full force in January 2027. Article 22 is the AI-critical piece: right to object to automated decisions and right to human intervention — structurally close to GDPR Article 22, and directly relevant to HR tech, credit, and scoring.
On the free-zone side, DIFC Regulation 10 is the one to open first: human oversight for employment screening, financial assessment, and legal determinations. Global banks, fintech, and legal tech with DIFC presence need this on the checklist from day one.
Saudi Arabia chose "strategic soft law." SDAIA's AI Adoption Framework (November 2025) is voluntary on paper but functions as a de facto government procurement requirement.5
Five pillars:
| Pillar | Content |
|---|---|
| Data governance | Quality, lifecycle, localization |
| Model accountability | Versioning, change history, clear ownership |
| Transparency | User notice, AI-use disclosure |
| Human oversight | Human intervention for critical decisions |
| Risk management | Impact assessment, continuous monitoring, incident response |
Saudi Arabia officially designated 2026 the Year of Artificial Intelligence, with about USD 56 billion a year in expected government AI productivity gains. Under Vision 2030, public AI procurement is scaling fast. Japanese vendors selling AI into the Saudi government effectively need SDAIA-aligned certification.
PDPL fines top out at SAR 5 million (roughly JPY 200 million); the SDAIA Framework itself has no penalty. The model is certification = market access, with economic force comparable to hard law. Honestly, that commercial gate bites harder than many statute fines I see elsewhere.
Australia — soft law continues; Mandatory Guardrails collapsed
Australia is the hardest of the three regions to forecast.
Timeline:6
| When | What |
|---|---|
| Sep 2024 | Voluntary AI Safety Standard (VAISS), 10 guardrails |
| 2024–2025 | Mandatory Guardrails for High-Risk AI consultation |
| Oct 2025 | Guidance for AI Adoption (GfAA) published; replaces VAISS |
| 2026 now | Future of Mandatory Guardrails unclear |
VAISS was built on the assumption that a mandatory high-risk version would follow. Within about twelve months GfAA replaced it, and Mandatory Guardrails debate effectively stalled. DISR and the National AI Centre now frame GfAA as comprehensive enough that mandatory rules may not be needed — a post-2025 election policy shift under the Albanese Labor government is a major factor.
For Japanese operations in Australia, the near term remains existing-law compliance:
- Privacy Act 1988: personal information, APP principles, breach notification
- Australian Consumer Law: AI product safety, misleading claims
- Anti-discrimination statutes: AI hiring tools
- Online Safety Act 2021: AI-generated content safety
- Sector rules: APRA (finance), TGA (medical devices)
Australia is a "strengthen existing law rather than write new AI law" model — opposite the EU/US drift, and a legitimate strategic choice.
Priority order for Japanese companies
Treating all six as equal is not realistic. Here is the field frame I use.
Tier A (must address now) — live penalties, heavy Japanese presence
- UAE PDPL + DIFC Regulation 10: hits financial AI and HR tech
- Saudi SDAIA: mandatory if you have government deals
Tier B (must address in 2026–2027) — legislation nearly certain
- Brazil PL 2338: Senate-passed → signature after lower house → force 2026–2027
- Chile AI bill: lower house passed; force after Senate
Tier C (keep watching) — unclear or existing law enough for now
- Mexico AI bill: still draft; sector rules (CNBV, COFEPRIS) bite first
- Australia Mandatory Guardrails: unclear; existing law covers the near term
My usual advice: start Tier A, stand up Tier B projects inside 2026, and review Tier C quarterly. "We deprioritized Saudi SDAIA and got burned" has become more common this year — Tier A especially.
One integrated map — how WARP SECURITY helps
TIMEWELL's WARP SECURITY builds a single compliance chart that puts first and second tiers on one map per company. Splitting "first tier precise, second tier separate" always fails, for three reasons.
First, shared core requirements — risk tiers, human oversight, impact assessment, labeling — so dual systems create duplicate work and inconsistent rules.
Second, market priority is a business decision. Putting "Brazil subsidiary ramps next year; Saudi government deal in 2026 Q4" on the same calendar as six compliance timelines is what makes the trade-offs governable.
Third, second tier can become first tier overnight. If three Latin American bills pass together, the map flips. Without an extensible integrated map, every new law restarts design from zero.
Typical map components:
- Market timelines: force date, grace period, penalty activation per market
- Requirement matrix: risk classification, human oversight, impact assessment, labeling, local representative × nine markets (EU + first tier + second tier) = 45-cell checklist
- Evidence folder design: one audit pack reusable across jurisdictions
Unsexy work — but building it once in 2026 is what enables portfolio-level optimization when 2027's regulatory wave hits.
What is moving on the first-tier benchmark — the EU AI Act's staged application
The first-tier benchmarks these regimes reference are moving too. The EU AI Act (Regulation (EU) 2024/1689) has a general application date of 2 August 2026, but not every provision starts on that day. What does start then is Chapter IV (the Article 50 transparency obligations), Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration — Articles 40–49), Chapter VI, Chapters VIII–XI, and Article 101 (the Commission's power to fine general-purpose AI (GPAI) providers). Fines run up to €35 million or 7% of global turnover for prohibited practices under Article 5, and up to €15 million or 3% for GPAI-related and other breaches, whichever is higher.
The substantive high-risk obligations, however, do not begin on that date. Under the amending act Regulation (EU) 2026/1744 (the Digital Omnibus — adopted 8 July 2026, published in the Official Journal on 24 July 2026, in force from 27 July 2026), Chapter III Sections 1, 2 and 3 apply to Annex III high-risk AI (Article 6(2)) from 2 December 2027, and to Annex I product-embedded high-risk AI (Article 6(1)) from 2 August 2028. Article 22 (authorised representative), Article 25 (value chain), Article 26 (deployer obligations) and Article 27 (FRIA) switch on at the same points. "The EU AI Act applies in full from 2 August 2026" is not an accurate reading, so keep the two apart when you build an internal schedule.
On 2 December 2026, the newly added prohibitions take effect — Article 5(1)(ba) (non-consensual sexual deepfakes), Article 5(1)(bb) (CSAM generation), and Articles 5(1a) and 5(1b). The new Article 111(4) also requires providers of synthetic-content-generating AI placed on the market before 2 August 2026 to comply with Article 50(2) by that same date. For high-risk systems already on the market, the rules bite only where significant changes in their designs are made on or after the relevant Chapter III application date.
Because Latin America's three bills track EU-style risk design, EU enforcement practice may become a reference for second-tier interpretation — not a certainty, but something to watch as Brazil and Chile interpret their texts. For integrated governance operations, see also Governed AI enterprise agents.
Summary
- Six second-tier markets sorted into hard-law progress / existing-law leverage / soft-law continuation
- Latin America's three countries are debating EU AI Act-style hard law in parallel
- UAE is federal PDPL + DIFC Reg 10; Saudi SDAIA Framework is de facto mandatory for government procurement
- Australia's Mandatory Guardrails have collapsed; existing law continues
- Japanese priority: Tier A (UAE, KSA) → Tier B (Brazil, Chile) → Tier C (Mexico, Australia)
Low media frequency is not low importance. Saudi SDAIA and UAE DIFC Regulation 10 already function as market-access preconditions through certification and free-zone rules.
While first-tier regimes dominate the agenda, more teams will discover a Saudi deal blocked for missing SDAIA alignment — or a DIFC subsidiary with a Regulation 10 issue. I share this piece so second tier is not parked as "later." If you have either market on the 2026 pipeline, put Tier A on this quarter's board before the next first-tier memo.
Further reading: Korea AI Basic Act, January 2026, Vietnam AI Law — ASEAN's first comprehensive statute, Singapore Agentic AI Governance Framework, India DPDP + AI Sutras.
References
- Brazil AI Act - Artificial Intelligence Act
- AI Regulation Chile 2025 - Nemko Digital
- Mexico AI Regulation 2025: Key Legal Insights - Nemko Digital
- The UAE's AI Governance Laws: PDPL, DIFC Rules - Captain Compliance
- Saudi Arabia designates 2026 as the Year of AI - Arab News
- Australia releases proposed mandatory guardrails - Corrs Chambers Westgarth
- AI Regulation in the Middle East: 14 Countries Scored - Verifywise
Footnotes
-
Brazil AI Regulation: Bill 2338, ANPD, Current Status (2026) - Nathaly Calixto ↩
-
Chile AI Bill Signals Global Governance Shift - AI CERTs News ↩
-
AI in the UAE: Understanding the Regulatory Landscape - Latham & Watkins ↩
-
Saudi Arabia's AI governance framework: what it means for 2026 - 6clicks ↩
-
Voluntary AI Safety Standard - Department of Industry Science and Resources ↩






