SINGAPORE, 5 AUG 2026 — Korea now has a comprehensive national AI law in force, the first jurisdiction after the European Union to get one. Australia has decided not to have one at all. Japan is running a voluntary disclosure mechanism. India is heading towards mandatory licensing. Vietnam is passing a stack of separate statutes.

This looks like fragmentation, and the software industry has begun describing it that way. But on the single question of whether AI models can be lawfully trained on copyrighted data, three of the five markets are moving in the same direction — one the industry opposes.

Where each market has landed

The survey below is drawn from BSA, the trade association representing enterprise software firms, which published a review of the region's first half on 29 July.

Computed by RECATOOLS5 August 2026
MarketPosition on a general AI lawRecent move
KoreaAI Basic Act in force — first after the EUGrace period with penalties suspended
JapanAI Promotion Act, deliberately flexibleRevised AI Basic Plan approved 14 July 2026
IndiaSignalled dedicated AI legislation in July 2026Labelling rules for synthetic content
VietnamSeparate AI, Data and Cybersecurity lawsFour-tier data classification in development
AustraliaNo standalone AI law, by choiceOffice of AI established July 2026

RECATOOLS summary of BSA's 29 July 2026 review of APAC technology policy. BSA is a trade association for enterprise software companies and its review is written from that perspective; the positions are reported as it describes them.

Korea's law is the furthest advanced. Its Act on the Development of Artificial Intelligence and Establishment of Trust — the AI Basic Act — took effect on 22 January 2026, making it the second jurisdiction after the European Union with a comprehensive AI statute.

Its enforcement is deliberately staged. The science and ICT ministry is running a grace period of at least a year, during which investigations and administrative fines are generally deferred except in exceptional cases involving serious social harm such as loss of life or human-rights violations. The obligations bind now; the penalties wait. The Act also asserts extraterritorial application, which is what makes it a compliance question for firms with no Korean entity at all. Separately, amendments to its Personal Information Protection Act raise the maximum fine to 10 per cent of global turnover, which is more than double the ceiling in the European GDPR.

Japan is the outlier, having taken a different path on both the substance of its policy and the legal instruments used to enforce it. Its AI Promotion Act is built to be permissive, and the revised AI Basic Plan approved on 14 July proposes a voluntary compliance mechanism for disclosing AI training data rather than a mandatory one.

India is the most active and the least settled. It hosted a Global AI Impact Summit in February, signalled in July that it will pursue dedicated AI legislation, has issued rules requiring visible labelling of synthetically generated content, and — the significant part — its Department for Promotion of Industry and Internal Trade has proposed a mandatory licensing regime for AI training. Its IT ministry is separately developing a Sovereign Cloud Framework.

Vietnam, whose strategic technology lists we reported on 4 August, is legislating in parallel tracks: cybersecurity updates, a personal data protection law, a data law, an AI law, and a data security law carrying a four-tier classification scheme.

Australia has made the clearest negative decision. It considered a standalone AI act and chose not to pass one, opting instead for a set of instruments — AI data-centre standards, a digital duty of care, Privacy Act reform, transparency requirements for automated decisions — coordinated through an Office of AI the prime minister established in July.

The question they actually agree on

The statutory divergence is less important than a narrower question with a bigger commercial consequence: can a company mine copyrighted text and data to train a model without permission?

Korea decided in February not to introduce a text and data mining exception into its Copyright Act, issuing non-binding fair-use guidelines instead. Australia has ruled out a TDM exception and is exploring licensing arrangements. India's proposal goes furthest, contemplating a mandatory licensing regime for training.

Three of the five markets have therefore declined to give model developers a free-use pathway, and two of them are actively designing a paid one. This is not fragmentation but a regional consensus forming against the position of the largest model developers. It is happening quietly while attention is focused on whether each country passes a dedicated AI act.

An AI act sets obligations on deployment — transparency, risk tiers, human oversight. A TDM decision sets the cost of the input. A company can comply with five different transparency regimes at some expense. It cannot train on material it has no licence to use, and no amount of compliance spending changes that.

The quieter convergence: where the compute lives

A second convergence is happening on procurement rather than principle.

Korea is transitioning its Cloud Security Assurance Program, the certification a cloud provider needs to serve government workloads, from state administration to private-sector certification. India's IT ministry is developing a Sovereign Cloud Framework. Vietnam's data security law carries a four-tier classification scheme, which is in practice a rule about which data may sit where.

Each is a different mechanism and they point the same way: governments deciding, in law rather than by preference, which categories of data may be processed on infrastructure they do not control. For a model developer that is a more immediate constraint than any disclosure obligation, because it determines where training and inference can physically happen.

Together, the positions on training data and data sovereignty form a coherent regional policy that nobody has stated in one place: pay for the inputs, and keep sensitive processing onshore. It is not a position anyone has legislated as a package, and it is what the individual measures add up to.

Whose framing this is

The review these facts come from argues that prescriptive, country-specific approaches risk raising costs and slowing deployment, and calls for risk-based, internationally interoperable frameworks instead.

The argument is both coherent and self-interested. BSA's members are the firms that would bear the cost of complying with five regimes, and "internationally interoperable" in practice means rules close enough to each other that one compliance programme serves all of them. Nothing about that makes the underlying facts wrong — the dates, statutes and positions check out — but the word fragmentation carries an assumption, which is that convergence is the natural and desirable state.

A government that has just decided its copyright holders should be paid for training data does not experience that decision as fragmentation. It experiences it as policy. The same is true of Australia deciding it does not need an AI act, which is a considered position rather than a gap.

What it means for anyone operating across the region

The compliance question splits in two.

On deployment, the region is fragmenting. A firm operating in Korea, Japan, India, Vietnam and Australia now faces five different disclosure and oversight regimes, at least one of which — Korea's — carries a penalty ceiling higher than Europe's. That is expensive, and it is the kind of expense that scales with legal headcount rather than with risk.

On training data, the region is converging, and the cost is unbounded in a way that legal headcount does not fix. If licensing becomes the default across three large markets, the input cost of building a model rises for everyone, including the regional champions their governments are simultaneously trying to promote. Vietnam has named domestic language models a strategic product. India is proposing a licensing regime for the data those models would need. Both positions are defensible. Held together, they are expensive.

That tension will be settled in copyright law, not AI law, and it is the main thing to watch over the next year.