← Back to Hub
🌍 AI Governance Race

EU, US, China all have AI Rules.
UK Has None.

The global AI regulatory patchwork is creating compliance nightmares and competitive gaps. Who gets the balance right — and who gets left behind?

EUAI Act — comprehensive, risk-tiered (passed 2024)
USExecutive Order — guidance only, no binding law
ChinaAlgorithm regs + generative AI rules (passed)
UKNo binding AI law — "pro-innovation" soft approach

Choose your depth. The data doesn't change — just the explanation.

Countries are making rules for AI — like a rulebook for how AI can and can't be used. Europe has made the most rules, covering everything from dangerous AI to chatbots. The US has some guidelines but no real law yet. China has rules mostly about AI content. The UK decided not to make rules yet. Because AI is everywhere, the gap between what different countries allow is creating big headaches for companies trying to follow all the different rules.
The EU AI Act (passed March 2024, effective August 2024) is the world's first comprehensive AI law — risk-based tiering from "unacceptable risk" (banned) to high-risk (regulated) to limited-risk (transparency) to minimal risk. The US has the October 2023 Biden AI Executive Order — guidance and voluntary commitments, no binding legislation. China passed its Algorithm Recommendation Regulations (2022) and Generative AI Interim Measures (2023). The UK's "pro-innovation" approach relies on existing sector regulators rather than a new AI-specific law. This creates a compliance mosaic for multinational AI deployments.
EU AI Act (Regulation 2024/1689): GPAI models >10^25 FLOPs = "systemic risk" tier with mandatory incident reporting, red-teaming, adversarial testing. Prohibited: social scoring, real-time remote biometric ID (with police exceptions), manipulative AI. High-risk: employment AI, credit scoring, critical infrastructure management, law enforcement — requires conformity assessments, human oversight, audit logs. Extraterritoriality: applies to AI systems used in EU regardless of developer location (GDPR precedent). US EO 14110: safety testing, watermarking, NSF grants, NIST AI Risk Management Framework reference. No preemption of state AI laws (California SB 1047 failed; Colorado AI law passed 2024). China GPAI: content must align with "core socialist values"; explicit content filtering requirements. UK: FCA, CMA, ICO, Ofcom all claiming AI jurisdiction — fragmented but not lawless.
EU AI Act text: eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689. US EO 14110: federalregister.gov/d/2023-24283. China GPAI Interim Measures (2023): cac.gov.cn/generative-AI-measures. UK AI regulation response: gov.uk/ai-regulation-white-paper. NIST AI RMF: nist.gov/system/files/documents/2023/01/26/AI-RMF-1.0.pdf. Colorado AI Act (2024): leg.colorado.gov/bills/sb24-205. EU GPAI code of practice: digital-strategy.ec.europa.eu/GPAI-code.

The Global AI Regulatory Landscape

European Union
EU AI Act
✓ Passed — Aug 2024

Comprehensive risk-tiered regulation. Bans: social scoring, real-time biometric surveillance. High-risk AI requires conformity assessments. GPAI systemic risk tier for large foundation models. Fines up to €35M or 7% global revenue.

United States
Executive Order 14110
⚡ EO only — No binding law

Biden EO (Oct 2023): voluntary safety commitments from major labs, NIST AI Safety Institute, watermarking requirements. No federal AI law. Colorado passed state AI law (2024). California SB 1047 (safety testing for large models) failed.

China
Algorithm + Generative AI Regs
✓ Passed — 2022, 2023

Algorithm Recommendation Regulations (2022): transparency, opt-out. Generative AI Interim Measures (2023): content must align with "core socialist values," explicit content filtering, security assessments required. Focused on content control.

United Kingdom
Pro-Innovation Approach
✗ No binding AI law

"Pro-innovation" white paper (2023): sector-based approach using existing regulators (FCA, CMA, ICO, Ofcom). No new AI-specific legislation planned. Emphasis on voluntary principles. AI Safety Institute established for frontier model assessment.

Canada
AIDA (Bill C-27)
⏳ In Parliament

Artificial Intelligence and Data Act — proposed as part of C-27 omnibus. High-impact system requirements for transparency, human oversight. Killed when parliament prorogued Jan 2025. Likely reintroduced.

Japan / South Korea
Voluntary Frameworks
⚡ Soft law only

Japan: AI governance guidelines, G7 Hiroshima AI Process participant. South Korea: AI Basic Law (2024) — principles-based, limited binding requirements. Both focus on trustworthy AI without prohibitions.

Regulatory Stringency Score by Jurisdiction

0 = no regulation, 10 = most comprehensive binding rules

🌐 The Brussels Effect — AI Edition

The EU has 450 million consumers. Any global AI company wanting EU market access must comply with the AI Act — regardless of where they're headquartered. This is the "Brussels Effect": the EU's strict standards become global de facto standards because multinationals can't maintain separate product versions. GDPR already reshaped global data practices. The AI Act's extraterritorial provisions (Article 2) mean US companies deploying AI used by EU residents must meet EU standards. The compliance cost is significant — but so is the leverage. Companies that build EU-compliant AI will have products that are arguably safer everywhere.