AI & Machine Learning

AI Regulation Goes Global: EU AI Act, US Executive Orders and China’s Approach

As artificial intelligence has moved from research labs into everyday life, governments have confronted a difficult question: how do you regulate a technology that is general-purpose, rapidly evolving, poorly understood, and globally distributed? There is no consensus answer. The European Union, the United States, and China have each taken markedly different approaches, and those differences will shape where AI is built, deployed, and used.

The EU AI Act: Comprehensive and Risk-Based

The European Union’s AI Act, which entered into force on August 1, 2024, is the world’s most comprehensive AI regulation. It takes a risk-based approach: the higher the potential harm of an AI system, the stricter the requirements. Obligations are being phased in over several years.

The Act classifies AI systems into four tiers:

  • Unacceptable risk: Prohibited applications, including social scoring by governments, manipulative techniques exploiting vulnerabilities, and certain real-time biometric surveillance in public spaces (with narrow exceptions for law enforcement).
  • High risk: Systems used in critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice. These face extensive requirements — risk management systems, data governance, technical documentation, human oversight, and conformity assessments.
  • Limited risk: Systems like chatbots, which face transparency obligations (users must know they are interacting with AI).
  • Minimal risk: Most AI applications, including spam filters and video games, which are largely unregulated.

General-purpose AI models, including large language models, face separate obligations. Providers of the most capable models — those trained with very large compute budgets — must conduct model evaluations, report serious incidents, and disclose information about training data and energy use. The Act also includes provisions on copyright, requiring providers to respect rights-holders’ opt-outs.

Critics argue the Act is complex, slow to implement, and may disadvantage European startups. Supporters argue it establishes a global standard by setting a precedent that other jurisdictions may copy.

The United States: Executive Action and Uncertainty

The U.S. approach has been far less comprehensive and more volatile. In October 2023, President Biden issued an executive order on AI requiring developers of powerful models to report safety test results, directing agencies to set standards for AI safety and security, and addressing risks related to critical infrastructure, biosecurity, and civil rights. The order leaned on existing agencies rather than creating a new regulator.

That order was rescinded in January 2025 by the incoming administration, which signalled a deregulatory posture favouring competitiveness over precaution. A new AI Action Plan released in July 2025 emphasised removing barriers to AI development, accelerating data centre construction, and promoting American AI exports, while retaining some national-security screening of frontier models. The policy direction shifted from “safety first” to “speed and dominance.”

Congress, meanwhile, has struggled to pass comprehensive AI legislation. State-level activity has filled the gap, with Colorado, California, and Texas passing AI laws addressing algorithmic discrimination, transparency, and deepfakes. The resulting patchwork creates compliance complexity, and a federal moratorium on state AI regulation has been debated.

The net effect is a U.S. landscape characterised by sectoral regulation (healthcare via FDA, finance via SEC and banking regulators, consumer protection via the FTC), national security controls, and state-level rules — but no single framework.

China: State-Led, Content-Focused

China’s approach differs fundamentally. Rather than an omnibus AI law, China has issued targeted regulations, often focused on content and social stability. The Interim Measures for the Management of Generative AI Services, effective in August 2023, require that generative AI services align with socialist core values, that training data be lawful, and that providers obtain security assessments and algorithm registrations for public-facing services.

China also requires algorithm registration and has issued rules on deep synthesis (deepfakes), recommendation algorithms, and facial recognition. In 2024, it published a framework for AI safety governance emphasising both development and security. The state’s capacity to enforce is high, and compliance requires navigating multiple regulators.

Notably, China has simultaneously promoted AI development aggressively, viewing AI leadership as a strategic national priority. Its approach combines tight content control with strong industrial policy.

The UK and Canada

The United Kingdom has taken a deliberately “pro-innovation” stance, establishing the AI Safety Institute (now the AI Security Institute) while declining to pass a sweeping AI law, preferring sectoral guidance. Canada, after extensive consultation, introduced the Artificial Intelligence and Data Act (AIDA) as part of a broader privacy bill, but the legislation died when Parliament was prorogued in early 2025. Its future is uncertain, leaving Canada without comprehensive federal AI regulation.

The Divergence and Its Consequences

The three approaches reflect deeper differences in political economy. The EU privileges fundamental rights and precaution. The U.S. under the current administration privileges innovation and national competitiveness. China privileges state control and strategic development.

For companies, this means that a globally deployed AI product must satisfy multiple, sometimes conflicting regimes. The EU’s extraterritorial reach, like that of the GDPR before it, may push the “Brussels effect” — raising global standards. Or the U.S. deregulatory turn may pull standards down in the name of competitiveness. Much depends on enforcement and on which market companies prioritise.

The Compliance Burden in Practice

For organisations operating in Europe, the AI Act creates concrete obligations. Providers of high-risk systems must establish risk-management systems, prepare technical documentation, ensure human oversight, maintain logs, and undergo conformity assessment before deployment. Deployers — organisations using high-risk systems, not just building them — have duties too, including monitoring and reporting. General-purpose model providers must publish training-data summaries and respect rights-holder opt-outs. Compliance is not a one-time exercise; it continues through the system’s life. For smaller firms, the cost of legal, technical, and documentation work is significant, which is why critics warn the law may entrench large incumbents.

Standards and the Machinery of Enforcement

Laws are only as strong as their standards and enforcers. The EU is developing harmonised standards that will define what compliance technically means, and a new AI Office coordinates implementation. National authorities in each member state enforce. Whether these bodies have the expertise and funding to assess complex AI systems is an open question. Enforcement timelines are long, and the first penalties for the most serious violations will not appear for years. The gap between passage and effective enforcement is where a great deal of the real-world impact will be decided.

The Innovation Argument

Opponents of aggressive regulation argue it will push AI development to jurisdictions with lighter rules, benefiting the United States or China at Europe’s expense. This “regulatory arbitrage” concern is real, though the evidence from data protection suggests the picture is mixed: the GDPR’s extraterritorial reach forced global firms to adapt, spreading European standards outward rather than causing an exodus. Whether the AI Act does the same — or simply disadvantages European firms — depends on enforcement, market size, and whether other jurisdictions converge or diverge.

Fragmentation and the Cost of Divergence

For companies, the deepest pain is not the strictness of any single regime but their incompatibility. A model deemed compliant in Brussels may raise questions in Washington; a chatbot acceptable in the U.S. may require changes for China. Multinational firms must navigate conflicting transparency rules, content requirements, and risk categories. The result is higher compliance costs, market fragmentation, and in some cases the decision to forgo a market entirely. Harmonisation efforts — through forums like the G7 and OECD — aim to reduce this friction, but meaningful convergence remains distant.

Canada’s Position in the Gap

Canada, a pioneer in AI research, finds itself without a comprehensive federal framework after AIDA’s collapse. Its options are unappealing: adopt a European-style law and bear the compliance burden, follow the U.S. deregulatory turn, or muddle through with sectoral rules. Each has costs. Choosing quickly matters, because the countries that write the rules early shape the standards others adopt. Canada’s research excellence gives it a voice in the technical debates; its regulatory indecision weakens it in the political ones.

Beyond Law: Technical Governance

Regulation is only one lever. Technical standards, professional norms, and internal governance at AI companies also shape behaviour. Model cards, datasheets for datasets, red-teaming practices, and safety frameworks developed by labs themselves establish expectations that regulators can later codify. Industry consortia such as the Frontier Model Forum and the Partnership on AI attempt to coordinate practice. The risk is that self-governance substitutes for binding rules, which companies prefer because it is flexible and cheap. The opportunity is that technical standards can move faster than legislation and can globalise more easily. The most effective governance is likely a layered system — law setting the outer bounds, standards providing the technical detail, and internal practices filling the gaps — rather than any single instrument alone.

Conclusion

AI regulation is no longer hypothetical. It is being written, implemented, and contested in real time, and the frameworks being established now will shape the technology’s trajectory for years. The absence of global consensus is not a temporary condition; it reflects genuine disagreement about values. For readers following the field, the most useful posture is neither complacency nor alarm, but attention — to what the rules say, who enforces them, and how the gap between ambition and implementation plays out.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button