Back to insights
Checking Compliance Practices

Where is it illegal to use AI?

Discover where AI use is banned or restricted, from the EU AI Act's prohibited practices to US state laws, and how to choose a compliant AI provider.

Where is it illegal to use AI?

Where is it illegal to use AI?

Key Facts

The Patchwork Problem: Why There's No Single 'AI Law'

Here's the problem most businesses don't see coming: 47 countries now have active AI legislation, but only 12 actually enforce it. That gap — flagged in global AI regulation research drawing on Stanford HAI data — means a provider can look compliant on paper while operating in a legal gray zone that's closing fast.

There's no "comply with one, comply with all" option anywhere. In the United States, meeting Colorado's requirements does nothing for your obligations under California, New York City's Local Law 144, or Illinois law, according to comparative analysis of US and EU AI rules. Each state sets its own triggers, scopes, and penalties.

The EU sits at the strict end. Its AI Act outright bans certain practices — social scoring, real-time biometric identification in public spaces, and subliminal manipulation — with violations carrying fines up to €35 million or 7% of worldwide annual turnover, per the official regulation text. And because the Act applies to any provider whose AI output is used inside the EU, where a company is headquartered doesn't exempt it, as jurisdictional guidance explains.

So what does this mean when you're choosing a provider?

  • Ask where their compliance baseline is set — not just where they're based.
  • Ask how they handle consent and disclosure in automated outreach.
  • Ask whether a human stays in the loop for consequential decisions.
  • Ask if they track regulatory changes as an ongoing practice, not a one-time checkbox.

That last point matters more than it sounds. The landscape moves fast enough that static snapshots go stale within months — Colorado's law was rewritten before it even took effect, and EU high-risk deadlines have already shifted once.

This is why compliance practices factor into how we work at Worqd. Our home base in Halifax, Canada has no binding AI statute — AIDA, the proposed law, died in January 2025 before taking effect. But our clients' buyers can be anywhere, so we hold our outreach to the stricter standard: permission-aware messaging, explicit consent before contact, and no sensitive form fields sent to public analytics.

The rules are arriving faster than most providers are ready for. Asking the four questions above puts you ahead of most of them.

Where AI Use Is Actually Banned: The EU's Prohibited List

If you're looking for the place where using AI is actually, literally illegal, start with Europe. The EU AI Act is the world's first comprehensive AI law, and it doesn't just regulate risky AI — it bans certain uses outright.

The prohibited practices took effect on February 2, 2025. That means these bans aren't proposals or future deadlines. They're live law right now, and they include:

  • Social scoring — AI systems that rank people based on behavior or characteristics, leading to unfair treatment
  • Real-time biometric identification in public spaces by law enforcement (with narrow exceptions)
  • Subliminal manipulation — AI that exploits vulnerabilities or manipulates people below their awareness in ways that cause harm

The penalties match the seriousness. Under Article 99 of the regulation, deploying a prohibited AI practice can cost up to €35 million or 7% of total worldwide annual turnover, whichever is higher. To put that in perspective, a company with $10 billion in global revenue faces a potential $700 million penalty — a scale no US state law comes close to.

Beyond the bans, the Act sorts everything else into a four-tier risk model. High-risk uses — hiring, credit decisions, education, healthcare, critical infrastructure — face conformity assessments and strict obligations. Limited-risk systems like chatbots and deepfakes carry transparency requirements. Minimal-risk tools like spam filters go largely unregulated. Only two jurisdictions worldwide have comprehensive, binding, risk-based AI laws of this kind: the EU and South Korea.

Here's the part that surprises most businesses: where your provider is located doesn't protect you. Under Article 2(1)(c), the Act applies to providers and deployers in third countries whenever their AI system's output is used in the EU — a reach that mirrors GDPR's extraterritorial scope. A Canadian or American agency serving clients whose customers live in Europe falls squarely within scope.

This is exactly why compliance can't be an afterthought when choosing an AI partner. At Worqd, our AI SDR and outreach systems are built around permission-aware outreach, explicit consent capture, and human handoff with full context — practices that align with the disclosure and oversight themes EU regulators prioritize. The regulation even rewards this: the official penalty framework weighs an operator's cooperation with authorities and the technical and organizational measures they've implemented when setting fines.

One caveat worth remembering: this landscape moves fast. The EU's high-risk deadlines have already shifted once, with Annex III obligations pushed to December 2, 2027 under the 2026 AI Omnibus. Compliance is ongoing monitoring, not a one-time checkbox — and any provider that treats it as a finished task is already behind.

The US State-by-State Maze and Canada's Regulatory Near-Miss

If you're looking for one clear answer on where AI use crosses legal lines in North America, you won't find it. The US has no comprehensive federal AI law — just a state-by-state patchwork where there is no "comply with one, comply with all" option, and each state law triggers differently.

The five live or imminent state statutes each pick their own tripwire. According to jurisdictional analysis, California's SB 53 and New York's RAISE Act use compute thresholds of over 10^26 operations, Colorado regulates by use case (consequential automated decisions, effective January 1, 2027), Texas bans specific uses by intent under TRAIGA (January 1, 2026), and Utah focuses on disclosure.

  • Colorado: use-case based, covering consequential automated decisions
  • California SB 53: compute threshold, with heavier obligations above $500M annual revenue
  • Texas TRAIGA: bans specific uses by intent, effective January 1, 2026
  • NYC Local Law 144: $1,500 per day per violation for unreviewed automated hiring tools

Penalties vary just as widely. US state AI laws carry fixed penalties of $500–$20,000 per violation, while California's AB 325 and SB 763 reach $6M per violation for corporations plus treble damages in private actions. The volume is staggering too: tracking data shows 131 state AI laws were enacted in 2024, with over 1,200 AI bills introduced in 2025.

Here's the honest part for us: Canada — Worqd's home base — has no binding AI statute at all. AIDA (Bill C-27) would have created a risk-tiered regime, but it died on prorogation in January 2025 before taking effect. One analysis puts Canada as having less regulatory infrastructure than Nigeria, with only a voluntary code remaining.

We don't treat that as a loophole. Because our clients' buyers can be anywhere, we hold our outreach and AI SDR practices to the stricter EU-aligned standard — permission-aware outreach, explicit consent capture, and human handoff of AI calls with full context.

One final caution: this landscape is a moving target. Colorado's law was rewritten before it even took effect — SB 24-205 was repealed and replaced by SB 26-189 — and the EU's high-risk deadlines have already shifted once, with Annex III obligations deferred to December 2, 2027. Any static snapshot goes stale within months, which is why continuous monitoring, not a one-time checkbox, is the real compliance practice.

What Compliant AI Use Actually Looks Like in Practice

Most companies don't get fined for using AI — they get fined for how they use it. The pattern across every major regulation is remarkably consistent: regulators punish manipulation, missing disclosure, and automated decisions nobody reviewed.

Look at what the EU AI Act actually bans: subliminal manipulation, social scoring, and real-time biometric identification in public spaces. Violations carry fines up to €35 million or 7% of worldwide annual turnover, per the official regulation text. US state laws follow the same logic, targeting undisclosed AI interactions and consequential automated decisions in hiring, credit, and housing.

That pattern translates directly into a practical checklist. If you use AI in your sales and marketing — or you're evaluating a partner who does — these are the practices that matter:

  • Capture explicit consent. Every form and booking flow should state plainly what someone is agreeing to and how their details will be used. Vague pre-ticked boxes are exactly what disclosure-focused laws target.
  • Keep outreach permission-aware. Personalized outreach to relevant accounts is the opposite of a template blast — and it's what separates legitimate B2B contact from the mass-messaging behavior regulators scrutinize.
  • Give AI decisions a human exit. When an AI qualifies a lead or handles a call, a real person should be able to step in with full context. Unreviewed automated decisions are a named regulatory trigger.
  • Keep sensitive data out of analytics. No sensitive form fields should flow to public analytics tools — a simple rule that closes a common privacy gap.

These aren't theoretical. At Worqd, consent capture in the booking funnel, permission-aware outreach, human handoff with full context, and a strict no-sensitive-data analytics policy are standard operating practice — because the research shows that's where enforcement actually lands.

One more strategic point: you don't need to track 47 countries' worth of rules individually. According to global regulation tracking, 47 countries have active AI legislation, but only 12 have functional enforcement mechanisms. The smarter move is picking the right baseline. Analysts at ailawsbystate.com recommend building on EU AI Act compliance first, then mapping US state obligations onto it — because of the "Brussels Effect," where companies worldwide adopt EU standards out of economic necessity, as academic research confirms.

The EU baseline also travels well. The Act applies extraterritorially to any provider whose AI output is used in the EU, per the CASRAI jurisdictional guide — so EU-alignment covers you even when your buyers are scattered across borders.

Finally, treat compliance as ongoing, not a one-time checkbox. Colorado repealed and replaced its AI law within two years, and the EU has already shifted its high-risk deadlines once. IBM's compliance guidance recommends maintaining continuous "AI compliance intelligence" — monitoring requirements as they evolve rather than auditing once and forgetting.

The bottom line: compliant AI use isn't about avoiding AI. It's about consent, disclosure, human oversight, and clean data handling — anchored to the strictest standard so everything else falls into place.

How Worqd Stays Ahead of the Rules — and How to Vet Any Provider

Compliance isn't a certificate you hang on the wall — it's a habit. With 47 countries holding active AI legislation but only 12 with functional enforcement, the providers who win long-term are the ones who treat the rules as a moving target, not a one-time checkbox.

That's the approach Worqd takes as company policy. Because the EU AI Act applies to providers outside the EU whenever their AI output is used in the Union, location doesn't exempt anyone — so Worqd holds itself to the strictest global standard even though its home base in Canada currently has no binding AI statute, after AIDA died on prorogation in January 2025.

In practice, that means three things. First, consent-first booking: the funnel requires explicit agreement ("I agree to be contacted about my request") and states details are only used to prepare for the call. Second, fast but human-backed follow-up: AI responds to every inquiry in under 60 seconds, 24/7, but calls can be handed to a real person with full context — the human oversight regulators keep emphasizing. Third, continuous monitoring rather than checkbox compliance, mirroring IBM's recommendation of ongoing "compliance intelligence" across jurisdictions. Worqd also keeps sensitive form fields out of public analytics and describes its outreach as permission-aware — "the opposite of a template blast."

To be clear: these are stated company practices, not legal certification. No vendor can certify you compliant — but the right partner makes compliance easier. The stakes are real: under the EU AI Act's official penalty text, prohibited practices carry fines up to €35 million or 7% of worldwide turnover, and regulators weigh "the technical and organisational measures implemented" when setting fines — meaning demonstrable good practices can reduce your exposure.

Whether you work with Worqd or anyone else, ask every AI growth partner these questions:

  • How do you capture and document consent before any AI-powered outreach or follow-up?
  • When does a human take over from your AI, and does that person get full context?
  • What data do your systems send to analytics or third-party tools — and what's excluded?
  • How do you track regulatory changes, given that this landscape goes stale within months?
  • Which standard do you build against — and is it the strictest one your clients' buyers might fall under?

A provider who hesitates on these answers is telling you something. One who answers clearly — and can show the policies behind the words — is built for where regulation is heading, not just where it is today.

Want to see what compliant, fast follow-up looks like in practice? Book a free growth call and we'll walk through your funnel — from first click to booked call — with more demand, faster follow-up, and better creative. Worqd clients see AI SDRs deliver a claimed 4–7x conversion lift over unmanaged follow-up, with every inquiry qualified in under 60 seconds, around the clock.

Frequently Asked Questions

Is it actually illegal to use AI anywhere in the world?
Yes — in the European Union, certain AI uses are outright banned. Since February 2, 2025, the EU AI Act prohibits social scoring, real-time biometric identification in public spaces, and subliminal manipulation, with fines up to €35 million or 7% of worldwide annual turnover.
Is AI illegal to use in the United States?
There's no comprehensive federal AI ban in the US. Instead, states regulate by trigger type — California and New York use compute thresholds, Colorado targets consequential automated decisions, and Texas bans specific uses by intent. There's no 'comply with one, comply with all' option, per comparative analysis of US state AI laws.
Does it matter where my AI provider is located?
Less than you'd think. The EU AI Act applies extraterritorially — under Article 2(1)(c), it covers providers in any country whenever their AI system's output is used in the EU, a reach that mirrors GDPR's jurisdictional scope. A Canadian or American agency serving clients with European customers falls squarely within scope.
What do AI regulators actually penalize companies for?
The pattern is consistent: manipulation, missing disclosure, and unreviewed automated decisions. Most companies don't get fined for using AI — they get fined for how they use it, which is why consent capture, human oversight, and clean data handling are the practices that matter most.
Does Canada have any AI laws I need to worry about?
Not currently. AIDA (Bill C-27) would have created a risk-tiered regime, but it died on prorogation in January 2025 before taking effect, leaving only a voluntary code. Worqd is based in Halifax, but because clients' buyers can be anywhere, it holds its outreach to the stricter EU-aligned standard rather than treating Canada's gap as a loophole.
How should I vet an AI provider's compliance practices?
Ask five things: how they capture and document consent, when a human takes over from AI, what data flows to third-party analytics, how they track regulatory changes, and which standard they build against. With 47 countries holding active AI legislation but only 12 enforcing it, a provider who hesitates on these answers is telling you something.

Key Takeaways

{ "title": "The Rules Are Coming—Are You Ready?", "content": "So where is it illegal to use AI? The honest answer: nowhere bans AI outright — but the EU already prohibits social scoring, real-time biometric ID in public spaces, and subliminal manipulation, with fines up to €35 million or 7% of w

Want help putting this into action?

Book a Growth Call
Topicswhere is AI illegalEU AI Act banned practicesAI regulation by countryAI compliance for businessesUS state AI lawschoosing compliant AI providerAI legal restrictions 2025

Stay in the Loop