AI regulation diverged sharply by region rather than converging toward one global standard. The EU built a single, binding, risk-tiered law that applies based on where an AI system's output lands, not where the company is headquartered. The United States kept relying on a patchwork of state laws and agency guidance without a comprehensive federal statute, and leaned more deregulatory at the federal level through 2025 and into 2026. China regulates through registration, security review, and content-control obligations rather than a Western-style risk framework. The practical result is that a company operating across all three needs three separate compliance postures, not one shared checklist.
What changed in 2026
- EU AI Act obligations kept phasing in on their staggered schedule, with high-risk system requirements and general-purpose AI model duties both further along than they were a year earlier, and enforcement guidance filling in some of the earlier ambiguity.
- The US federal posture stayed deregulatory relative to the EU, continuing a shift toward emphasizing AI competitiveness over new restrictions, while individual states such as Colorado and California kept advancing their own AI-specific laws independently of federal direction.
- China expanded mandatory labeling requirements for synthetic content, building on its generative AI rules with more specific obligations around marking AI-generated text, images, audio, and video so platforms and users can identify it.
- Other jurisdictions moved toward comprehensive frameworks of their own. South Korea's AI framework legislation advanced toward taking effect, and Brazil continued working a risk-based AI bill through its legislature, both drawing partial inspiration from the EU's tiered-risk structure rather than the lighter-touch US or UK models.
Regional comparison
| Region |
Core approach |
Key instrument |
Enforcement style |
Extraterritorial reach |
| European Union |
Binding, risk-tiered law with defined obligations per tier |
EU AI Act |
Regulatory fines, potentially up to roughly 7 percent of global annual turnover for the most serious violations |
Broad; applies if output reaches the EU market |
| United States |
Fragmented; state laws plus sector-specific agency guidance |
No single federal AI law; state statutes (e.g. Colorado, California) plus agency actions |
Varies widely by state and agency; federal posture has trended deregulatory |
Limited federally; state laws generally apply based on where affected users are located |
| China |
Registration, security review, and content-control obligations |
Generative AI Measures plus synthetic-content labeling rules |
Administrative penalties, service suspension, algorithm deregistration |
Applies to services offered to users within China regardless of where the company is based |
| United Kingdom |
Principle-based, enforced through existing sector regulators |
Cross-sectoral AI principles rather than one dedicated act |
Enforcement through existing regulators (data protection, financial conduct, competition) |
Narrower than the EU; tied to existing regulator jurisdiction |
Why the approaches diverged this much
The EU treated AI as warranting a dedicated, horizontal law because it wanted one consistent standard across all twenty-plus member states rather than a patchwork within its own borders, and extended that same logic to any company whose AI system affects EU users. The US, by contrast, has a long-standing preference for sector-specific regulation over broad horizontal statutes, and the political environment through 2025 favored minimizing new federal restrictions in the name of competitiveness against other AI powers, which pushed meaningful AI-specific legislation down to the state level instead. China's model reflects its broader regulatory posture toward information platforms generally: registration and content-control obligations sit alongside AI-specific rules because the government already regulates algorithmic recommendation systems and online content through similar mechanisms. The UK deliberately chose not to replicate the EU's dedicated law, betting instead that empowering existing regulators to apply purpose-specific guidance would move faster and burden innovation less, a bet that remains actively debated as the EU Act matures.
Common mistakes
- Assuming EU AI Act compliance automatically satisfies US state laws. State laws like Colorado's AI Act use different definitions of high-risk systems and different procedural obligations, so mapping compliance work across jurisdictions rather than copying it directly.
- Underestimating China's registration requirements for algorithm changes. Modifying a deployed algorithm can trigger a fresh filing obligation, which is easy to miss if a compliance process was only built around a single initial launch review.
- Treating the UK's lighter regulatory posture as permanent. The UK has repeatedly signaled it may introduce more binding AI-specific legislation, particularly for frontier models, so the current lighter-touch approach should not be assumed to be a fixed, long-term state.
- Ignoring smaller markets with their own emerging frameworks. South Korea, Brazil, and others are advancing comprehensive AI laws of their own; a company expanding into these markets without checking current requirements risks discovering obligations only after launch.
FAQ
Which region has the strictest AI regulation right now?
The EU generally has the most comprehensive and prescriptive binding framework, with defined risk tiers and specific documentation obligations. China's approach is arguably as strict in practice but structured differently, focused on registration and content control rather than risk tiers.
Does US federal law regulate AI at all?
There is no single comprehensive federal AI statute; regulation comes through existing agency authority applied to AI use cases, executive branch guidance, and a growing number of state laws that vary significantly by state.
If my AI system only serves users in one country, do I need to worry about rules in other regions?
Only if your system's output can reach users or be offered in other markets, which is common for anything available over the internet; the EU AI Act in particular applies based on where the output lands, not where the company is based.
How does this affect a business trying to build one compliance program instead of several?
Most multinational deployments end up building a baseline compliance program around the strictest applicable regime, typically the EU AI Act, and then layering region-specific requirements on top rather than starting from scratch in each market.
Where to go next
For the deep dive on the strictest regime and related legal and audit questions, see our guides to EU AI Act compliance for businesses, what an AI audit actually involves, and AI copyright lawsuits.