The contenders
Three ways to govern a machine
Same technology, three governing instincts. The EU regulates the use, the United States regulates after the fact and mostly at state level, China regulates before launch. Compare the doctrine, then open each dossier.
| Dimension | European UnionThe Pyramid | United StatesThe Patchwork | ChinaThe Registry |
|---|---|---|---|
| Core doctrine | Fundamental-rights-first, risk-proportionate: regulates what AI is used for, not the technology | Pro-innovation, deregulatory federal posture; binding rules come from states, cities, sectoral agencies | State-led, content-control-first; market access conditional on state review |
| Legal shape | One horizontal law for 27 states: Reg. (EU) 2024/1689 + Digital Omnibus Reg. (EU) 2026/1744 | No comprehensive federal AI statute: EOs + voluntary NIST AI RMF + pre-existing statutes + state patchwork | Vertical rules, one per technology (2022 algorithms → 2026 companions); no enacted comprehensive AI law |
| Signature mechanism | Four-tier risk pyramid + CE-marked conformity assessments | Litigation, agency enforcement, and a 50-state laboratory | Pre-launch filing (备案) + security assessments with the CAC |
| Regulator | European AI Office (GPAI) + national market-surveillance authorities | FTC, FDA, EEOC, CFPB + state AGs; DOJ now sues states over AI laws | Cyberspace Administration of China (+ MPS, NMPA, PBOC by sector) |
| Max penalty | €35M or 7% of global turnover | No general AI fine; state fines ($10k to $200k/violation TX) and FTC penalties (e.g. $48.6M Growth Cave) | Fines per instrument (e.g. RMB 200k companion-AI); plus loss of market access: unfiled services are blocked |
| Extraterritorial reach | Yes: output used in the EU is in scope | No general regime; per-statute | Effectively: foreign-hosted public GenAI can't pass filing; services geoblock or localize |
| Global posture | Export the rulebook (“Brussels effect”) | “Winning the Race”: AI diplomacy + export promotion | Global AI Governance Initiative + proposed Global AI Cooperation Organization (Shanghai) |
- Core doctrine
- Fundamental-rights-first, risk-proportionate: regulates what AI is used for, not the technology
- Legal shape
- One horizontal law for 27 states: Reg. (EU) 2024/1689 + Digital Omnibus Reg. (EU) 2026/1744
- Signature mechanism
- Four-tier risk pyramid + CE-marked conformity assessments
- Regulator
- European AI Office (GPAI) + national market-surveillance authorities
- Max penalty
- €35M or 7% of global turnover
- Extraterritorial reach
- Yes: output used in the EU is in scope
- Global posture
- Export the rulebook (“Brussels effect”)
- Core doctrine
- Pro-innovation, deregulatory federal posture; binding rules come from states, cities, sectoral agencies
- Legal shape
- No comprehensive federal AI statute: EOs + voluntary NIST AI RMF + pre-existing statutes + state patchwork
- Signature mechanism
- Litigation, agency enforcement, and a 50-state laboratory
- Regulator
- FTC, FDA, EEOC, CFPB + state AGs; DOJ now sues states over AI laws
- Max penalty
- No general AI fine; state fines ($10k to $200k/violation TX) and FTC penalties (e.g. $48.6M Growth Cave)
- Extraterritorial reach
- No general regime; per-statute
- Global posture
- “Winning the Race”: AI diplomacy + export promotion
- Core doctrine
- State-led, content-control-first; market access conditional on state review
- Legal shape
- Vertical rules, one per technology (2022 algorithms → 2026 companions); no enacted comprehensive AI law
- Signature mechanism
- Pre-launch filing (备案) + security assessments with the CAC
- Regulator
- Cyberspace Administration of China (+ MPS, NMPA, PBOC by sector)
- Max penalty
- Fines per instrument (e.g. RMB 200k companion-AI); plus loss of market access: unfiled services are blocked
- Extraterritorial reach
- Effectively: foreign-hosted public GenAI can't pass filing; services geoblock or localize
- Global posture
- Global AI Governance Initiative + proposed Global AI Cooperation Organization (Shanghai)
Dossier 01: European Union
The rulebook.
The law does not regulate AI as a technology. It regulates what AI is used for.
A single rulebook for all 27 member states sorts every AI system into a four tier risk pyramid: the more a system can affect lives, dignity or rights, the heavier the obligations. It reaches beyond Europe, because if your AI output is used in the EU, the Brussels rules follow you home.
Most AI never meets the heavy end. The Commission estimates about 85% of systems, spam filters and game AI among them, face no new duties at all.
Signature mechanism: the four tier risk pyramid
Social scoring, manipulation, vulnerability exploitation, untargeted face scraping, workplace/school emotion recognition, sensitive-trait biometric categorisation, most real-time police facial ID.
Banned outright since 2 Feb 2025: offering or deploying these uses is illegal. From 2 Dec 2026, “nudifier”/NCII and AI-CSAM generators join the list. Top-tier fines: €35M or 7% of global turnover.
Open a tier to read its obligations
Chapter V: general purpose AI models
- Chapter V in force since 2 Aug 2025 for new models; legacy (pre-Aug-2025) models must comply by 2 Aug 2027.
- All providers: technical documentation, downstream-builder info, EU copyright policy, public training-data summary.
- Systemic-risk tier (> 10²⁵ FLOPs): adversarial testing, EU-level risk assessment, serious-incident reporting.
- Open-source carve-out: free/open-licence models skip the two documentation duties, but the exemption vanishes at systemic-risk level.
- Code of Practice signatories include OpenAI, Google, Microsoft, Anthropic, Mistral: Meta declined.
- Commission enforcement powers, fines up to €15M or 3%, activate 2 Aug 2026.
The delay that was not a retreat.
The Digital Omnibus on AI, proposed 19 Nov 2025, adopted June 2026 and in force 27 Jul 2026 as Reg. (EU) 2026/1744, moved only the high risk application dates: to 2 Dec 2027 for Annex III and 2 Aug 2028 for Annex I. The substance of the high risk requirements was not watered down, and the transparency duties, the GPAI rules, the prohibitions and the full penalty regime all stayed on track.
Penalty ladder: Art. 99, unchanged by the Omnibus
Prohibited practices (Art. 5)
€35M or 7% of global turnover
Most breaches (high-risk, transparency, GPAI)
€15M or 3%
Misleading info to authorities
€7.5M or 1%
Whichever is higher, except for SMEs, who pay the lower of the fixed amount and the percentage. Providers of general purpose AI models answer directly to the Commission under Art. 101.
Dossier 02: United States
The patchwork.
The most binding AI rules in America come from states, cities and sectoral agencies, not from Washington.
There is no comprehensive federal AI statute. The Biden executive order EO 14110 was revoked on day one, 20 Jan 2025, and replaced by EO 14179 on removing barriers, signed 23 Jan 2025. America's AI Action Plan of 23 Jul 2025 runs on three pillars: accelerate innovation, build infrastructure, and lead on diplomacy and security.
EO 14365 of 11 Dec 2025 goes further, with a DOJ AI Litigation Task Force and BEAD funding leverage aimed at state AI laws. The federal government is not merely declining to regulate. It is trying to stop the states from regulating.
Three layers of American AI governance
The real regulatory layer: where binding AI rules actually live.
TX TRAIGA (HB 149)
IN FORCEFirst major comprehensive state AI law live (1 Jan 2026): prohibited-practices model, $10k to $200k/violation, NIST safe harbor, AG-only enforcement.
CA SB 53: frontier transparency
IN FORCEFirst-in-nation frontier-model law: published safety frameworks, transparency reports, incident reporting to Cal OES.
CA AB 2013: training data
IN FORCEGenAI developers must post high-level summaries of training datasets (from 1 Jan 2026).
CA SB 243: companion chatbots
IN FORCEFirst state companion-chatbot safety law: disclosure, crisis protocols, minor protections, private right of action (≥$1,000).
CA SB 942: content provenance
UPCOMINGLatent disclosures/watermarking + free AI-detection tools from large GenAI platforms, from 2 Aug 2026.
Utah AI Policy Act
IN FORCEFirst state GenAI consumer-protection law (2024): disclose AI on request; no “the AI did it” defense.
Illinois HB 3773 + AIVIA
IN FORCEAI-driven employment discrimination is a civil-rights violation; AIVIA has regulated AI video interviews since 2020.
NYC Local Law 144
IN FORCEFirst US bias-audit mandate (enforced since Jul 2023): annual independent audits of hiring algorithms; $500 to $1,500/day.
CO SB 26-189 (ADMT Act)
UPCOMINGFrom 1 Jan 2027: the narrower transparency law that replaced the collapsed Colorado AI Act.
NY RAISE Act
UPCOMINGSigned 19 Dec 2025: frontier-model safety obligations paralleling CA SB 53, phased.
CT SB 5
UPCOMINGSigned May 2026, phased Oct 2026 to 2028: AI-layoff notices, whistleblower protections, chatbot rules.
109 new state AI laws in H1 2026 alone (159 in 2025), despite the federal preemption push.
The flagship that never sailed.
Colorado SB 24-205 was America's first comprehensive state AI law. It was delayed once, sued over by xAI, opposed in court by its own federal government, stayed by a judge, then repealed and replaced before a single day of enforcement.
17 MAY 2024
SB 24-205 signed
America's first comprehensive state AI law: risk-based duties for “high-risk” consequential decisions.
28 AUG 2025
Delayed to 30 Jun 2026
SB 25B-004 pushes the effective date back a first time.
9 APR 2026
xAI sues
Elon Musk's xAI challenges the Act in federal court.
24 APR 2026
DOJ intervenes
Trump's DOJ joins the case against the law: via the EO 14365 AI Litigation Task Force.
27 APR 2026
Federal stay
A federal court stays enforcement, weeks before the Act was to take effect.
14 MAY 2026
Repealed & replaced
SB 26-189 swaps in a narrow disclosure regime (from 2027). Not one day of enforcement.
Never took effect
Enforcement character
99 to 1
SENATE VOTE
Killing the 10-year moratorium on state AI laws, 1 Jul 2025.
$53,088
PER VIOLATION
TAKE IT DOWN Act platform-takedown penalty, enforced by the FTC since 19 May 2026.
$1,000
MINIMUM / VIOLATION
CA SB 243 companion-chatbot private right of action.
$500 to 1,500/day
NYC LL144
Penalties for unaudited hiring algorithms, enforced since Jul 2023.
Dossier 03: China
The registry.
Market access is conditional on state review, not just liability after the fact.
China regulates vertically, one technology at a time: recommendation algorithms in 2022, deep synthesis in 2023, generative AI in 2023, facial recognition in 2025, and anthropomorphic AI in 2026. Content must stay aligned with what the rules call socialist core values.
A comprehensive national AI law has been debated since 2023 but never enacted. Instead, AI provisions were folded into the amended Cybersecurity Law, in force 1 Jan 2026.
The filing machine: public ledgers
868
GENAI SERVICES FILED
Plus 530 apps registered with provincial CACs, as of 30 Apr 2026: up from 61 in 2023.
5,672
DEEP-SYNTHESIS ALGORITHMS
Across 14 public batches (Jan 2026); 32 deregistered in 2025 when products shut down.
>5,000
RECOMMENDATION ALGORITHMS
In the CAC algorithm registry by Nov 2025: filed within 10 working days of launch.
Filings are published publicly, a transparency tool unmatched anywhere else. An unfiled chatbot simply cannot operate.
The vertical stack: one rule per technology
First binding algorithm rules anywhere: transparency, opt-out of personalized feeds, anti-“information cocoon,” gig/minor/elderly protection. Opened the CAC algorithm filing registry.
Strict for companies. Permissive for the state.
PIPL Art. 26 permits public security image capture and identity recognition in public places without individual consent. The 2025 Measures, meanwhile, impose consent, impact assessments, local storage and filing duties on commercial facial recognition. The technology China restricts for companies stays broadly available to the state.
The global play
The Global AI Governance Initiative of Oct 2023 grew into a 13 point action plan plus a proposed Global AI Cooperation Organization, potentially headquartered in Shanghai, announced at WAIC on 26 Jul 2025. It landed days after the US AI Action Plan: the counter offer on global AI rules.
The next bout
Now see them decide the same case
Each verdict stamp in the arena means one specific thing. Here is the legend, and the three routes that use it.
Read the stamps
- PROHIBITEDBanned outright: offering or deploying this use is illegal.
- HEAVILY REGULATEDLegal, but gated by conformity, licensing, oversight and documentation duties.
- LICENSED: FILING REQUIREDMust register with the state and pass review before launch.
- TRANSPARENCY DUTYAllowed, provided users are told AI is involved and content is labeled.
- LIGHT-TOUCHNo dedicated AI law, only general consumer/deception rules apply.
- MOSTLY UNREGULATEDNo AI-specific obligations in this jurisdiction.
- N/A / PENDINGNot enacted, not in force, or undecided.
Run the simulator
One AI use, three jurisdictions. Pick a scenario and read the verdict each regime returns.
Open
Watch the timeline
Who regulated what, and when. Three parallel lanes from 2016 to 2026.
Open
Drill the frameworks
Every law, executive order, provision, standard and filing regime, searchable.
Open
Study it properly
EU AI Act Implementation Expert
The full compliance path through Regulation (EU) 2024/1689, article by article.
China AI Regulation Program
The filing regime, the vertical rules and what market access actually requires.
EU AI Act Explorer
The whole Regulation as an interactive map of provisions and cross references.