AI regulation may look static at the headline level, but AI Law Radar’s latest changelog illustrates how the ground is shifting underfoot through corrections, scope clarifications and newly catalogued obligations. The register, which tracks material changes to AI-related laws and proposals, logged a cluster of updates in late July that collectively tighten the net around deepfake abuse, automated decision-making, and algorithmic coordination in sensitive markets. Rather than marquee new statutes, the changes show regulators refining how existing and emerging rules will actually bite in practice, and analysts upgrading confidence as primary sources and official briefings fill in gaps.
In the United Kingdom, AI Law Radar raised its confidence that the flagship AI (Regulation) Bill [HL] is unlikely to advance in its current form. The change follows confirmation from the UK Parliament's Bills API that the Bill remains stuck at first reading in the House of Lords with no movement since introduction, and from DSIT’s published Blueprint for AI Regulation, which prefers an AI Growth Lab and sector sandbox approach over omnibus AI legislation. The facts and dates around the Bill were left unchanged, but the confidence upgrade crystallises what many practitioners have suspected: for now, the UK is doubling down on regulator-led and sandbox-based governance rather than racing toward a dedicated AI Act.
The UK’s Data (Use and Access) Act 2025 (DUAA) features prominently in the new entries and corrections, underlining how AI governance is increasingly being baked into data and criminal law rather than standalone AI statutes. AI Law Radar added the DUAA’s automated decision-making reform to its register, highlighting new sections of the UK GDPR that, as of early February, replace the old default prohibition on automated decisions with duties to notify people, allow representation, provide human review and offer contest mechanisms. In a separate correction, the service widened the scope of DUAA 2025 section 138, which inserts new offences into the Sexual Offences Act 2003, confirming that the criminalisation of non-consensual intimate deepfakes applies to any person in the UK who creates or requests such material, even if it is never shared. That brings the law’s reach beyond deployers and makes clear that both users and creators of abuse-enabling AI tools face direct liability, distinct from other offences that focus on tool suppliers.
U.S. states continue to serve as frontline laboratories for AI-specific rules, with AI Law Radar updating its tracking of several algorithm-focused laws. Illinois SB 343, which would amend the Illinois Antitrust Act to ban algorithmic coordination of rental prices, has now been added as a proposed measure awaiting the governor's signature with an action deadline at the end of August. The changelog also reclassified three state measures — New Jersey’s FAIR Act, Maryland’s Protection From Predatory Pricing Act, and Illinois SB 343 — under a "Prohibited AI practices" theme, on the basis that all three outright ban certain uses of algorithms, such as coordinated rent-setting. Meanwhile, an earlier mischaracterisation of Tennessee SB 1700 as a chatbot safety law was corrected; in its enacted form, the statute is now recognised as a study mandate directing a state commission to examine potential AI and chatbot regulation, without imposing compliance obligations.
Beyond the US and UK, AI Law Radar is filling out its global map of AI obligations with new entries and confidence upgrades for Asia-Pacific jurisdictions. The tracker added China’s AI Agents Implementation Opinions, jointly issued by key ministries, to cover obligations on AI agents in that market, signalling that China’s experiment with rules tailored to anthropomorphic and agentic systems is now part of the monitored landscape. In South Korea, an official government briefing allowed AI Law Radar to confirm that the country’s AI Basic Act carries at least a one-year grace period on fines for high-impact AI duties running from its late-January effective date. This did not alter any underlying deadlines or obligations, but it pushed the confidence level from medium to high, clarifying that enforcement pressure will ramp up over time rather than snapping into place immediately.
Other updates underscore how much of the regulatory story now turns on the fine print of transparency and documentation duties. In Australia, AI Law Radar corrected the citation for a new automated decision-making transparency requirement in the Privacy Act, confirming that the obligations will sit in APP 1.7–1.9 when they commence in December 2026. In the US, Rhode Island’s Healthcare AI Documentation Act was updated after law-firm trackers confirmed its effective date upon passage in June, removing a placeholder uncertainty note and raising confidence on when healthcare AI developers and providers must comply. Georgia’s Conversational AI Safety Act similarly saw its effective date confirmed via an official Senate press release, locking in a mid-2027 start for that state’s framework and reinforcing that conversational and companion chatbots remain a distinct focus for American legislators.
Why this matters
For AI builders and buyers, these changes matter less for their novelty than for the clarity they bring to how risk categories and enforcement will work in practice. The shift of UK automated decision rules from a flat prohibition to a bundle of notification and review duties illustrates a broader trend toward regulated use rather than outright bans, while the reclassification of US state laws under "Prohibited AI practices" shows that some algorithm-driven behaviours — like price coordination in housing markets — are being cordoned off entirely. The tightening of scope around non-consensual intimate deepfakes, and the addition of China’s AI Agents Opinions and South Korea’s grace periods, further signal that regulators are now drilling into specific AI abuse patterns and high-impact deployments, rather than treating "AI" as a monolith. In aggregate, AI Law Radar’s log suggests that the compliance burden is not just about looming EU-style horizontal acts, but about a patchwork of sector, state and criminal rules whose details are being continuously tuned.
Looking ahead, the pattern in the changelog hints at a regulatory environment that will likely grow more complex through incremental adjustment rather than dramatic, one-off legislation in many jurisdictions. The UK’s apparent preference for an AI Growth Lab and sector sandboxes over sweeping statutory reform means companies may face nuanced, regulator-specific guidance instead of a single AI code, even as criminal and data laws quietly absorb AI-enabled harms. In the US, study mandates like Tennessee’s, alongside targeted prohibitions and documentation rules in states from Illinois to Rhode Island and Georgia, suggest a mix of experimentation and tightening guardrails will continue at the sub-federal level. And in Asia-Pacific, the formalisation of duties around AI agents and high-impact systems, softened by initial grace periods, points to a phased but deliberate move toward enforceable AI conduct standards. For now, the most important development is not any single new law, but the growing precision with which existing and proposed rules define what constitutes unacceptable AI behaviour — and what documentation, transparency and human oversight will be expected when AI systems make decisions that matter.