The global AI regulatory patchwork is creating compliance nightmares and competitive gaps. Who gets the balance right — and who gets left behind?
Choose your depth. The data doesn't change — just the explanation.
Comprehensive risk-tiered regulation. Bans: social scoring, real-time biometric surveillance. High-risk AI requires conformity assessments. GPAI systemic risk tier for large foundation models. Fines up to €35M or 7% global revenue.
Biden EO (Oct 2023): voluntary safety commitments from major labs, NIST AI Safety Institute, watermarking requirements. No federal AI law. Colorado passed state AI law (2024). California SB 1047 (safety testing for large models) failed.
Algorithm Recommendation Regulations (2022): transparency, opt-out. Generative AI Interim Measures (2023): content must align with "core socialist values," explicit content filtering, security assessments required. Focused on content control.
"Pro-innovation" white paper (2023): sector-based approach using existing regulators (FCA, CMA, ICO, Ofcom). No new AI-specific legislation planned. Emphasis on voluntary principles. AI Safety Institute established for frontier model assessment.
Artificial Intelligence and Data Act — proposed as part of C-27 omnibus. High-impact system requirements for transparency, human oversight. Killed when parliament prorogued Jan 2025. Likely reintroduced.
Japan: AI governance guidelines, G7 Hiroshima AI Process participant. South Korea: AI Basic Law (2024) — principles-based, limited binding requirements. Both focus on trustworthy AI without prohibitions.
0 = no regulation, 10 = most comprehensive binding rules
The EU has 450 million consumers. Any global AI company wanting EU market access must comply with the AI Act — regardless of where they're headquartered. This is the "Brussels Effect": the EU's strict standards become global de facto standards because multinationals can't maintain separate product versions. GDPR already reshaped global data practices. The AI Act's extraterritorial provisions (Article 2) mean US companies deploying AI used by EU residents must meet EU standards. The compliance cost is significant — but so is the leverage. Companies that build EU-compliant AI will have products that are arguably safer everywhere.