Medium angle of red, abstract data lines and dots.
Client Alert

AI Regulation in APAC: Diverging Approaches Across the Region

September 15, 2026
The past 12 months have seen a significant acceleration in the enactment of AI regulation across the Asia-Pacific (APAC) region. We explore these developments, from comprehensive legislative frameworks to targeted content labelling rules.

Businesses developing, deploying, or distributing AI systems in APAC face a rapidly evolving regulatory landscape with varying compliance obligations by jurisdiction. Regulatory approaches across the region currently fall into three broad categories: (1) binding, risk-based frameworks with tiered compliance obligations, exemplified by South Korea and Vietnam; (2) targeted AI regulation, such as in China; and (3) voluntary, principles-based approaches prioritising innovation and industry self-governance, the dominant model in Japan, Singapore, and Australia.

This Client Alert provides a high-level overview of the key jurisdictions in APAC that have introduced AI-specific legislation or regulation and examines the broader regional picture.

South Korea: Comprehensive Risk-Based AI Law

In South Korea, the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (the AI Framework Act or AI Basic Act) took effect on 22 January 2026, with an enforcement decree entering into force at the same time.

The AI Framework Act regulates all AI businesses, including AI developers (defined as persons developing and providing AI) and AI deployers (defined as persons providing AI products and services using AI developed by the AI developer).

The AI Framework Act has extraterritorial reach, applying to acts conducted overseas that impact the South Korean market or users. Therefore, foreign organisations providing AI systems to users in South Korea will need to comply with the Act. Non-Korean providers offering AI services directly to Korean users must designate a domestic representative and report such designation to the Ministry of Science and ICT (MSIT) if they meet specified criteria, such as prior year total revenue exceeding KRW 1 trillion, prior-year AI service-segment revenue exceeding KRW 10 billion, or an average of over 1 million domestic daily users.

For most businesses developing or deploying AI, compliance obligations under the AI Framework Act remain relatively light. However, the Act introduces a tiered framework under which “high-impact AI,” generative AI, and certain state-of-the-art AI systems are subject to additional obligations.

Operators who deploy “high-impact AI” (defined as AI systems that “may have a significant impact on or pose a risk to human life, physical safety, and basic rights” in critical sectors) face a materially more demanding set of obligations. Sectors covered include energy, drinking water, healthcare, nuclear operations, crime investigations, transportation, public services, childhood education, and judgments that have significant impact on individuals such as hiring and credit decisions. When deploying AI or products and services using AI, businesses must evaluate whether such AI is high-impact AI, and may request confirmation from the MSIT in case of doubt.

Operators of high-impact AI must, among other things:

  • conduct advance impact assessments on individuals’ fundamental rights prior to deployment;
  • establish and operate risk management and user protection plans;
  • provide explanations of AI-generated outputs and decision criteria;
  • ensure human-oversight mechanisms are in place; and
  • notify users when products or services involve high-impact AI.

The AI Framework Act also applies to cutting-edge AI systems: operators of systems trained using at least 10²⁶ FLOPS (floating-point operations per second), incorporating state-of-the-art technologies, and posing a risk of broad and significant impact on human life, bodily safety, and fundamental human rights must identify, assess, and mitigate risks across the AI lifecycle and establish a risk management system to monitor safety incidents.

Regarding transparency and labelling obligations, the AI Framework Act establishes the following three layers of obligation:

  1. Operators that provide products or services using high-impact AI or generative AI must proactively notify users in advance that AI is being used. This is a forward-looking, pre-deployment disclosure obligation; it applies before the user interacts with the AI-driven product or service, rather than after the fact.
  2. Operators that provide generative AI (or products and services using it) must label outputs to indicate that they were generated by generative AI.
  3. Where an AI system produces virtual sound, image, or video outputs that are difficult to distinguish from real content (i.e., deepfakes or near-photorealistic synthetic media), the operator must notify or label in a manner that users can “clearly recognize” the AI origin.

The MSIT has indicated that 2026 will effectively serve as a pilot period with limited enforcement, with a one-year grace period for penalties to help the private sector adjust to the new rules.

The South Korean model is often described as a “risk-based” approach, drawing conceptual parallels with the EU AI Act, though it is generally regarded as less prescriptive in its current form. South Korean legislators have sought to strike a balance between fostering the AI industry and regulating it. The AI Framework Act not only introduces measures directed at AI businesses, but also introduces a framework for developing AI-related policies and various measures supporting AI adoption and development such as public data sharing, R&D support, standardisation, and providing support to SMEs and startups.

Vietnam: Southeast Asia’s First AI Law

Vietnam enacted its dedicated AI law, Law No. 134/2025/QH15 on Artificial Intelligence (the Vietnam AI Law), on 1 March 2026. The law applies to both domestic entities and foreign technology companies participating in AI activities in Vietnam, giving it extraterritorial reach.

At its core, the Vietnam AI Law establishes a risk-based classification system with three tiers of AI risk, including high-risk, medium-risk, and low-risk, with more stringent requirements attaching to high-risk systems (those systems that can cause significant harm to the life, health, legitimate rights, and interests of organisations and individuals, national interests, public interests, and national security). Although providers and deployers can self-classify their AI systems, guidance from the Ministry of Science and Technology (MST) can be requested if they cannot determine the risk level.  

High-risk AI systems must undergo a conformity assessment prior to deployment, or when there is a significant change during operation, to assess whether they comply with the applicable regulations related to risk management, data quality, records-keeping, human monitoring and intervention, accountability, and transparency, among others. High-risk AI systems will be subject to inspections periodically and when there are signs of violation. In addition, foreign high-risk AI system providers must have a contact in Vietnam, and, where the system is subject to mandatory conformity certification prior to deployment, must maintain a commercial presence in Vietnam or appoint an authorised representative in the country.

On 2 July 2026, Decision No. 33/2026/QD-TTg was issued identifying high-risk AI systems, which cover certain types of AI systems in six sectors: education (e.g., automated assessment and behavioural monitoring) ethnic affairs and religion (e.g., automatic scoring or classification of applications for government ethnic policies or approval of regulatory applications); healthcare (AI-assisted surgical systems and autonomous AI-powered surgical robots); banking (autonomous electronic banking transactions or credit approval decisions); judicial proceedings (large-scale biometric identification systems used in public-interest civil proceedings); and transport (e.g., highly autonomous driving systems, AI-controlled critical transport infrastructure).

Many AI systems identified in the list are, however, considered high-risk only when the AI output is used as the sole basis for decisions without meaningful human review. The identified AI systems must comply with their obligations under the Vietnam AI Law by 1 March 2027, except for those in healthcare, education, and finance that were already in operation before 15 August 2026, in which case an additional six-month grace period applies.

Medium-risk AI systems are those that have the potential to confuse, influence, or manipulate users due to the user’s inability to recognise that they are interacting with an AI system or that certain content is AI-generated. Medium-risk AI systems are monitored through reporting, sample testing, or independent evaluations.

High- and medium-risk AI systems need to be notified to the MST of their classification results before putting the system into use.

Low-risk AI systems refer to all other AI systems that are not high- and medium-risk AI systems. In general, oversight of low-risk AI systems is conducted on a post hoc basis. Among the Vietnam AI Law’s most significant provisions are its transparency and content labelling requirements, including the following:

  • providers must ensure that AI systems interacting directly with individuals clearly disclose to users that they are engaging with an automated system;
  • AI-generated audio, image, and video content must carry machine-readable labels;
  • AI-created or edited content simulating or impersonating real persons, or recreating real events, must be labelled in a clear and distinguishable manner; and
  • deployers must notify the public when publishing AI-generated or edited content that could cause confusion about the authenticity of events or persons.

The Vietnamese government also issued Decree No. 142/2026/ND-CP on 30 April 2026, which provides detailed implementing rules for the Vietnam AI Law (the Implementing Decree). This Implementing Decree reiterates that providers are required to self-classify AI systems into one of three risk tiers before deployment, and clarifies that they are legally responsible for the accuracy and truthfulness of the classification results. For medium- and high-risk AI systems, a notification dossier of risk classification results must be submitted to the MST via a new one-stop online AI portal before the system is put into operation.

Among the transparency obligations, with respect to labelling, the Implementing Decree requires deployers to apply clearly recognisable labels to AI-generated audio, images, and video that simulate or mimic the appearance or voice of a real person, or that recreate factual events, and it further clarifies the scope of four narrowly drawn exemptions (technical editing, text-only processing, internal use, and controlled research or sandbox).

For incident reporting, providers or deployers must submit a preliminary report within 72 hours of confirming a serious incident (such as loss of life or severe harm to health, significant property damage, serious infringement of human rights, or severe disruption to the provision of public services or essential services), or within five working days for other serious incidents, with remediation results due within 15 days thereafter.

The Implementing Decree also operationalises the Vietnam AI Law’s regulatory sandbox, setting out detailed conditions for participation, including a requirement for civil liability insurance or equivalent financial guarantee where the AI system under test may pose direct risks to human life or health or create significant property damage.

India: Regulating AI Outputs at the Platform Layer

India’s approach is to bring AI-generated content within its existing intermediary framework. In February 2026, the Ministry of Electronics and Information Technology (MEITY) formally notified amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, taking effect on 20 February 2026, which place obligations on intermediaries hosting information that is synthetically generated, artificially or algorithmically created, generated, modified, or altered using a computer resource, AI-generated content, and other forms of synthetically generated information (SGI).

The amendments introduce a new Rule 3(3), which creates a due diligence obligation regarding SGI covering AI-generated or AI-modified audio and/or visual, or other information that appears authentic or indistinguishable from natural persons or events. Rule 3(3) applies to intermediaries that offer generative AI tools or facilitate publication or dissemination of SGI and requires:

  • deploying reasonable and appropriate technical measures to prohibit unlawful SGI;
  • clearly and prominently labelling AI-generated content, including photos, videos, and audio, with a static label that is displayed throughout the display of the content;
  • where technically feasible, embedding permanent provenance metadata or mechanisms including a unique identifier to enable tracing of content origin; and
  • not enabling modification or removal of permanent metadata.

The amendments also introduce a new Rule 4(1A) under which platforms with more than 5 million registered users in India must, before allowing users to display, upload, or publish information:

  • seek user declaration for AI-generated content and deploy appropriate technical measures to verify the accuracy of user declarations, and prominently label any SGI as such; and
  • deploy appropriate technical measures to ensure no SGI is published without prominent labels.

The amendments also sharply accelerate takedown timelines for certain harmful content and SGI. Non-consensual intimate imagery and deepfakes must be removed within two hours of notification, and other illegal content must be removed within three hours of notification.

China: Expanding an Already Dense Framework

China continues to move at pace on AI regulation, building on a body of rules that is already among the most developed in the world. The most recent developments are:

  • the Measures for the Labelling of Artificial Intelligence-Generated and Synthetic Content (the Labelling Measures), issued on 7 March 2025, taking effect on 1 September 2025; and
  • the Interim Measures for the Administration of AI Anthropomorphic Interactive Services (the Anthropomorphic Services Measures), issued on 10 April 2026, taking effect on 15 July 2026.

These measures sit alongside China’s existing AI regulatory framework, which includes the Algorithm Recommendation Regulation (2022), the Deep Synthesis Regulation (2023), and the Generative AI Regulation (2023) (see this Latham Client Alert). Together, these laws establish a comprehensive compliance framework for AI services provided to the public in China.

Under the Labelling Measures, service providers face three core obligations:

  • add explicit, user-visible labels on AI-generated text, images, audio, and video, where the content may potentially be misleading to the public;
  • embed implicit, machine-readable labels (metadata with provider details and reference numbers) in all AI-generated synthetic content; and
  • for content-sharing platforms, verify incoming metadata, add labels in case the user declares content as AI-generated, and flag suspected AI content where identifiers are missing.

The Labelling Measures also require that users (i) proactively declare AI-generated synthetic content as such and use the labelling functions provided by the service providers, and (ii) prohibit organisations and individuals from maliciously removing, altering, falsifying, or concealing labels. A user may, under certain conditions, request that explicit labels be omitted from content, provided the service agreement sets out the user’s obligations, and the service provider retains logs for at least six months.

The Anthropomorphic Services Measures (see this Latham Client Alert) apply to AI services that provide users with continuous emotional interaction simulating a person’s personality, thought patterns, and communication. Such service providers face a range of obligations, including to:

  • comply with certain content standards, including, for example, not generating content that encourages self-harm or suicide, not excessively catering to users so as to induce emotional dependence or addiction or damage real interpersonal relationships, and not using emotional manipulation to induce unreasonable user decisions;
  • intervene in acute-risk situations by generating comforting content and contacting the user’s guardian or emergency contact where a user signals self-harm, suicide, or major financial loss;
  • protect vulnerable users, including by barring virtual intimate-relationship services for minors, or obtaining parental or guardian consent for children under 14, and providing enhanced safeguards to elderly users;
  • notify users that they are interacting with AI, and implement various anti-addiction measures such as convenient exit methods and dynamic prompts and pop-ups when excessive dependence or duration is detected; and
  • conduct and report a security assessment to the provincial cyberspace authority on specified triggers, including reaching 1 million registered or 100,000 monthly active users.

China’s approach is notable for its layered, state-directed model: binding rules, technical standards, and enforcement mechanisms apply in parallel, creating a high compliance burden for service providers operating in the Chinese market.

Taiwan: A Principles-Based Framework With Innovation at Its Core

Taiwan’s Basic Law on Artificial Intelligence (the AI Basic Act) came into effect on 14 January 2026. The AI Basic Act is concise — comprising only 20 articles — and is intended to serve as a foundational framework law rather than a comprehensive regulatory regime. It does not impose direct operational obligations on private sector operators. Instead, the law is built on the following seven core governance principles, which are intended to guide both the formulation of subordinate legislation and the conduct of government AI activities:

  • sustainable development and well-being
  • human autonomy
  • privacy protection and data governance
  • cybersecurity and safety
  • transparency and explainability
  • fairness and non-discrimination
  • accountability

In line with these principles, Article 5 of the AI Basic Act generally requires the government to prevent the application of AI from infringing upon the people’s life, body, freedom, or property; undermining social order, national security, or the ecological environment; or engaging in illegal activities. The government must review and adapt existing laws to align with the AI Basic Act, and enact all relevant subordinate legislation within two years.

Recent developments signal that the implementation of the AI Basic Act is well underway. In March 2026, the Executive Yuan established the National Artificial Intelligence Strategy Special Committee (NAISSC), tasked under Article 6 of the AI Basic Act to coordinate, promote, and supervise national AI affairs. The Ministry of Digital Affairs (MODA) and individual sector authorities — such as the Financial Supervisory Authority, the Ministry of Health and Welfare, and the National Communications Commission — have started developing and publishing relevant risk frameworks. This is in accordance with Article 16 of the AI Basic Act, which sets out the following two-stage rule-making structure. MODA must first develop an AI risk classification framework that aligns with international standards, such as the US NIST AI Risk Management Framework, to serve as a common cross-departmental reference for identifying potential AI risk categories. Each sector regulator must then follow this framework to develop its own risk-based management regulations tailored to its domain and must assist its respective industries in formulating industry guidelines and codes of conduct.

Taiwan’s approach to transparency and labelling obligations operates at two levels, consistent with the AI Basic Act’s principles-based character:

  1. A general transparency principle requires that AI outputs be “appropriately disclosed or labelled” to facilitate risk assessment and enhance the trustworthiness of AI. This is framed as one of the seven core governance principles binding on the government in promoting AI, rather than a directly enforceable obligation on private operators at this stage.
  2. At a specific level, where a sector regulator designates an AI product or system as a high-risk application, it must be clearly marked with warnings or cautionary notes.

Beyond transparency, the AI Basic Act sends a deliberate signal of innovation primacy. In addition to setting out various measures to support AI development, Article 11 of the Act provides that, where the interpretation and application of AI-related regulations conflict with other existing laws, the principle of promoting the provision of new technologies and services takes precedence, provided it is consistent with the Act’s fundamental principles.

A Region of Contrasts: Key Takeaways

The APAC AI regulatory landscape as of mid-2026 can be characterised as a patchwork of three broad regulatory models operating simultaneously:

  • Binding, risk-based frameworks or comprehensive legislation: most prominently exemplified by South Korea and Vietnam, which have adopted comprehensive AI laws imposing tiered obligations calibrated to risk.
  • Targeted AI regulation: best illustrated by China, which has adopted layers of regulation targeting specific AI outputs, such as algorithmic recommendations, deepfakes, and generative AI, and India, which has addressed AI content labelling within existing sector-specific regulatory frameworks.
  • Voluntary, principles-based approaches: the dominant model in Japan, Singapore, and Australia, where governments have prioritised innovation and industry self-governance, though with an increasingly clear direction of travel toward more formal frameworks.

For businesses operating across APAC, the implications are material. Compliance strategies will need to reflect this patchwork: what constitutes adequate AI labelling in China (mandatory technical standards) differs substantially from what is expected in Singapore (voluntary best practice). The acceleration of content labelling requirements across multiple jurisdictions suggests that transparency around AI-generated content is becoming a baseline expectation across the region, regardless of whether a jurisdiction has enacted a comprehensive AI law.

This Client Alert was prepared with the assistance of Ernest Lok in the Hong Kong office of Latham & Watkins.

The authors would like to thank the following local counsel for their contributions to this Client Alert:

  • Anh Hoai Nguyen and Anh Ha Mai Ho of Tilleke & Gibbins (Vietnam)
  • Akash Karmakar of the Law Offices of Panag & Babu (India)

Endnotes

    This publication is produced by Latham & Watkins as a news reporting service to clients and other friends. The information contained in this publication should not be construed as legal advice. Should further analysis or explanation of the subject matter be required, please contact the lawyer with whom you normally consult. The invitation to contact is not a solicitation for legal work under the laws of any jurisdiction in which Latham lawyers are not authorized to practice. See our Attorney Advertising and Terms of Use.