Short answer: the EU is the only one of the four with a single, horizontal AI law, the AI Act, and it reaches any company whose AI is used in the EU. The US has no federal AI statute and regulates through agencies and a growing set of state laws; the UK applies five principles through existing regulators; China regulates specific AI services directly, with mandatory filing and content labelling. Build your programme on the EU AI Act and add each country's specific duties on top.
Start here: whether the EU AI Act treats your system as high-risk takes about five minutes to check with the free EU AI Act assessment.
If your AI product serves users in multiple countries, you don't face one regulatory framework, you face several. The EU AI Act, the United States' patchwork of sector-specific rules and state laws, the United Kingdom's regulator-led adaptive approach, and China's content-focused and state-controlled regulations each take fundamentally different approaches to the same core question: how should governments manage the risks and benefits of artificial intelligence?
For companies developing or deploying AI systems across borders, the differences are not academic. A hiring algorithm that is perfectly lawful to operate in Singapore may require a conformity assessment in Brussels, an algorithmic audit in New York, and mandatory filing with the Cyberspace Administration of China. Understanding these divergences, and the growing areas of convergence, is essential for any organisation building a viable global compliance strategy.
Sector-specific regimes then layer on top of these frameworks. The toughest in the EU is medical devices, where the AI Act meets the MDR/IVDR: see Is my medical AI high-risk? and the health-AI hub.
This guide provides a detailed, side-by-side comparison of the four most consequential AI regulatory regimes in the world, along with practical guidance on how to build a single compliance programme that satisfies multiple jurisdictions simultaneously. If you are new to the EU AI Act specifically, start with our complete guide to the EU AI Act before diving into this global comparison.
Reviewed 9 October 2026. Every jurisdiction in this guide was re-checked against official sources. New since the last update: Colorado repealed and re-enacted its AI Act (obligations from 1 January 2027), California's AI Transparency Act became operative, the UK's new automated decision-making rules are in force, China's AI-content labelling rules and anthropomorphic-AI measures apply, and South Korea and Vietnam now have AI laws in force. Canada's AIDA was never enacted; an earlier version of this guide said otherwise. EU changes: What actually applies on 2 August 2026.
October 2026: what changed outside the EU
- United States. Still no federal AI statute and no federal preemption of state laws. Executive Order 14365 (11 December 2025) set up a Justice Department AI Litigation Task Force against state AI laws, and the Department intervened in xAI's challenge to the Colorado law in April 2026. Colorado replaced its 2024 AI Act with SB26-189 (signed 14 May 2026), whose duties apply from 1 January 2027. California's AI Transparency Act (SB 942, as amended) has applied since 2 August 2026, and New York's RAISE Act for frontier-model developers takes effect on 1 January 2027.
- United Kingdom. Still no AI bill: the King's Speech of 13 May 2026 did not include one. The Data (Use and Access) Act 2025 rewrote the rules on solely automated decisions, in force since 5 February 2026, and the ICO must now produce a statutory code of practice on AI and automated decision-making.
- China. Mandatory labelling of AI-generated content (explicit labels plus metadata) has applied since 1 September 2025. Measures for anthropomorphic, emotionally interactive AI services apply from 15 July 2026. By 31 August 2026, 1,112 generative AI services had been filed with the Cyberspace Administration of China.
- Elsewhere. South Korea's AI Basic Act has been in force since 22 January 2026 and Vietnam's AI Law since 1 March 2026. Japan's AI Promotion Act has applied since 1 September 2025, without penalties.
July 2026: the EU Digital Omnibus is law
The most consequential development since the original publication of this guide is the EU AI Act Digital Omnibus package, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. For multi-jurisdiction planners, four points matter:
- The high-risk deadline moved from Aug 2026 to Dec 2027. Standalone high-risk systems (Annex III) are now deferred to 2 December 2027, and AI embedded in sectoral products (medical devices, machinery, automotive) from 2 August 2027 to 2 August 2028. These are binding calendar dates.
- Transparency did not move. Synthetic-content marking duties under Article 50 still apply from 2 August 2026 (unchanged by the Omnibus). Systems already on the market before that date get a marking grace period to 2 December 2026, the same transitional date as the new Article 5 ban on AI-generated non-consensual intimate imagery ("nudifier" apps) and AI-generated child sexual abuse material. If you ship generative AI to the EU market, treat the watermarking conformance question as a 2026 problem, not a 2027 one.
- SME relief now reaches small mid-caps. The Omnibus extends some SME measures to small mid-cap enterprises as defined in Commission Recommendation (EU) 2025/1099 (fewer than 750 staff and up to €150M turnover or €129M balance sheet), including simplified technical documentation under Article 11. It narrows, but does not close, the gap between the EU and UK burden for growing companies.
- A narrow basis for bias-detection data processing was added. The Omnibus inserts a new Article 4a into the AI Act allowing processing of special-category data specifically to detect and correct bias, with safeguards. This does not amend the GDPR itself.
Note that Article 50 transparency, GPAI model obligations, and AI Office enforcement powers all still apply from 2 August 2026, the Omnibus did not move them. The operating posture for the rest of 2026: transparency and content-marking are live now, high-risk conformity work has more runway.
TL;DR, Global AI regulation at a glance
- No two major jurisdictions regulate AI the same way. The EU has a comprehensive, horizontal law. The US relies on existing agencies and voluntary frameworks. The UK delegates to sector regulators. China enacts narrowly targeted regulations at speed.
- The EU AI Act has the broadest extraterritorial reach. It applies to any company placing an AI system on the EU market or whose system's output is used in the EU, regardless of where the company is headquartered, similar to the GDPR's global reach.
- The United States has no single federal AI law. Compliance depends on which federal agency oversees your sector (FDA, FTC, CFPB and others) and which states you operate in: Colorado, California, Texas, Illinois, New York and New York City each have distinct AI requirements.
- The UK deliberately avoids a single AI statute. Instead, existing regulators, the FCA, ICO, Ofcom, CMA, apply five cross-cutting AI principles within their existing mandates.
- China regulates AI content and algorithms directly. Binding rules govern algorithmic recommendations, deep synthesis, generative AI, AI-content labelling and anthropomorphic AI, with mandatory government filing.
- Practical strategy: build to the EU AI Act as the highest common denominator, then map jurisdiction-specific requirements using NIST AI RMF and ISO 42001 to fill gaps.
The four major regulatory approaches
Before examining each jurisdiction in detail, the table below provides a high-level comparison of the four major AI regulatory regimes as they stand in 2026.
This table reveals a fundamental truth: there is no single "global AI regulation." Each jurisdiction reflects different policy priorities, consumer protection, innovation promotion, content control, or fundamental rights, and organisations operating internationally must navigate all of them.
European Union: Comprehensive risk-based regulation
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive, binding legal framework for artificial intelligence. It entered into force on 1 August 2024, with obligations phasing in from February 2025; after the Digital Omnibus, the last high-risk obligations apply from 2 August 2028. For a detailed timeline, see our EU AI Act compliance checklist for 2026.
Risk-based four-tier classification
The AI Act classifies AI systems into four tiers based on their potential risk to health, safety, and fundamental rights:
The classification rules are set out in Article 6, and the prohibited practices are defined in Article 5. If you're unsure how your system is classified, our free AI Act risk classification tool can help you determine your obligations in under five minutes.
Extraterritorial scope, the "Brussels Effect"
One of the AI Act's most consequential features is its extraterritorial scope, defined in Article 2. The regulation applies to:
- Providers (developers) of AI systems that are placed on the EU market or put into service in the EU, regardless of where the provider is established.
- Deployers (users) of AI systems that are located within the EU.
- Providers and deployers located in third countries where the output produced by the AI system is used in the EU.
This means a US-based company that builds an AI hiring tool used by a German employer must comply with the AI Act, even if the company has no office, server, or employee in the European Union. This mirrors the GDPR's extraterritorial model and is widely expected to produce a "Brussels Effect": companies will build to the EU's standard globally rather than maintain separate compliance programmes for different markets.
GPAI model obligations
The AI Act introduced a separate category for general-purpose AI (GPAI) models, foundation models and large language models that can be adapted for many downstream tasks. Under Article 53, providers of GPAI models must:
- Maintain and make available technical documentation, including training and testing processes.
- Provide information and documentation to downstream providers integrating the GPAI model into their AI systems.
- Establish a policy to respect copyright law, including the EU Copyright Directive.
- Publish a sufficiently detailed summary of training data.
GPAI models presenting systemic risk (Article 51: presumed above 10²⁵ FLOPs of training compute) face additional obligations under Article 55, including adversarial testing, incident reporting, and cybersecurity protections. For a complete breakdown of GPAI obligations, see our guide to general-purpose AI model obligations.
Enforcement and penalties
The EU AI Act's penalty regime is among the strictest in the world. Maximum fines are:
- EUR 35 million or 7% of global annual turnover for prohibited AI practices.
- EUR 15 million or 3% of global annual turnover for violations of high-risk requirements.
- EUR 7.5 million or 1% of global annual turnover for supplying incorrect information to authorities.
Enforcement is split between the EU AI Office (for GPAI model obligations) and national market surveillance authorities designated by each Member State (Article 74). The fines are set in Article 99.
Why it matters
The EU AI Act matters beyond Europe's borders because of its scale and ambition. With 450 million consumers in the single market and a regulatory tradition that has already reshaped global data protection (GDPR) and product safety, the AI Act is positioned to become the de facto global baseline for AI governance. Companies that comply with the AI Act will find it substantially easier to meet requirements in most other jurisdictions.
For startups and SMEs deciding how to operationalise this without a Big-4 budget, our comparison of the best EU AI Act compliance software breaks down the practical options.
United States: Sector-specific and innovation-first
The United States takes a fundamentally different approach to AI regulation: rather than enacting a single comprehensive law, it relies on existing federal agencies, voluntary frameworks, and an increasingly active state-level legislative landscape. The underlying philosophy prioritises innovation and economic competitiveness, with regulation targeted at specific harms rather than AI as a technology category.
No comprehensive federal AI law
As of October 2026, the United States has no binding, horizontal federal AI statute comparable to the EU AI Act. Federal AI governance is shaped by:
- Executive Orders: The Biden-era Executive Order 14110 (October 2023), which established reporting requirements for developers of powerful AI models, was rescinded in January 2025 and replaced by Executive Order 14179, "Removing Barriers to American Leadership in Artificial Intelligence," which pivoted federal policy toward deregulation. On 11 December 2025, President Trump signed Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence," directing the Attorney General to establish an AI Litigation Task Force to challenge state AI laws seen as inconsistent with federal policy. The Justice Department set the task force up in January 2026 and in April 2026 intervened in xAI's lawsuit against the Colorado AI law. In March 2026 the White House sent Congress legislative recommendations urging federal preemption of state AI laws; as of October 2026 Congress has not enacted any. This illustrates how reliant US federal AI policy is on executive action, orders can be modified or rescinded by subsequent administrations.
- NIST AI Risk Management Framework (AI RMF 1.0): Published in January 2023, the AI RMF provides a voluntary, structured approach to managing AI risks across the lifecycle. It organises risk management into four functions, Govern, Map, Measure, Manage, and has become the primary reference framework for organisations seeking a systematic approach to AI governance in the US.
- Agency-specific guidance: Individual agencies have issued binding or semi-binding guidance within their existing mandates, without waiting for new legislation.
Federal agency enforcement landscape
The practical consequence is that US AI compliance is sector-dependent. A healthcare AI company faces FDA oversight; an AI hiring platform faces EEOC scrutiny; a consumer-facing chatbot falls under FTC jurisdiction. Organisations must identify which agencies have oversight authority over their specific use case.
State-level laws, the emerging patchwork
The most significant legislative activity in the US is happening at the state level. Several states have enacted or are advancing AI-specific legislation:
- Colorado (SB26-189): The 2024 Colorado AI Act, the first comprehensive US state law on "high-risk AI systems", was repealed and re-enacted by SB26-189, signed on 14 May 2026. The new law's duties apply from 1 January 2027 and are narrower: developer documentation, notice to consumers before automated decision-making technology is used, an explanation within 30 days of an adverse decision, data correction, and human review on request. The duty of care, risk-management programme and impact assessments of the 2024 act are gone. Enforcement is by the Attorney General only. The law is being challenged in federal court by xAI, with the US Justice Department intervening.
- New York City Local Law 144: Requires annual bias audits for automated employment decision tools used by employers in New York City, with results posted publicly. A December 2025 audit by the New York State Comptroller found the city's enforcement ineffective, which raises the odds of stricter enforcement, not lower.
- New York RAISE Act: Signed in December 2025 and effective 1 January 2027, it requires large frontier-model developers to publish safety frameworks and report safety incidents, with penalties of up to $1 million for a first violation.
- Illinois: BIPA's consent requirements for biometric data directly affect AI using facial recognition or voiceprints. Separately, HB 3773 has made it a civil-rights violation since 1 January 2026 for employers to use AI that discriminates, and requires notice when AI is used in employment decisions.
- California: SB 1047 was vetoed in September 2024; the frontier-AI law is SB 53, the Transparency in Frontier Artificial Intelligence Act, signed in September 2025 and effective 1 January 2026. The AI Transparency Act (SB 942, as amended by AB 853) has applied since 2 August 2026, requiring covered generative AI providers to offer detection tools and embed provenance disclosures. Privacy-agency rules on automated decision-making technology apply from 1 January 2027, and a further package of AI bills, including human review of AI-driven discipline and firing, was signed in September 2026.
- Texas TRAIGA (HB 149): The Texas Responsible Artificial Intelligence Governance Act, signed in June 2025 and effective 1 January 2026, prohibits AI used to manipulate human behaviour, capture biometric identifiers without consent, conduct unlawful discrimination, or generate certain explicit content, and adds disclosure duties for state agencies plus a regulatory sandbox. Enforcement sits exclusively with the Texas Attorney General.
The state-level patchwork creates compliance complexity for companies operating nationally. A company deploying the same AI hiring system in New York City, Colorado and Illinois may face three distinct sets of obligations, bias audits, adverse-decision explanations and AI-use notices, none of which are harmonised.
NIST AI Risk Management Framework
Although voluntary, the NIST AI RMF has become the closest thing to a national AI compliance standard in the United States. Its four core functions map reasonably well to the EU AI Act's requirements:
Organisations building a governance framework that maps NIST AI RMF to the EU AI Act's requirements are well-positioned to demonstrate compliance in both jurisdictions.
United Kingdom: Regulator-led adaptive governance
The United Kingdom has deliberately chosen not to enact a single AI statute equivalent to the EU AI Act. Instead, the UK government published a pro-innovation AI white paper in March 2023, setting out a framework of principles that existing sector regulators are expected to apply within their domains.
Five cross-cutting principles
The UK's regulatory approach is built on five principles that all sector regulators are expected to interpret and enforce:
- Safety, security, and robustness, AI systems should function reliably and securely.
- Appropriate transparency and explainability, Users should understand when they are interacting with AI and how decisions are made.
- Fairness, AI should not produce discriminatory outcomes or undermine legal rights.
- Accountability and governance, Clear lines of responsibility must exist for AI outcomes.
- Contestability and redress, Individuals should be able to challenge AI-driven decisions that affect them.
These principles are intentionally high-level and non-prescriptive. The government has explicitly stated that it does not want to create a rigid, one-size-fits-all regulatory framework, arguing that sector regulators are better positioned to understand the specific risks AI poses within their domains.
Sector regulators and the DRCF
The following regulators are responsible for applying the five AI principles:
The Digital Regulation Cooperation Forum (DRCF), comprising the ICO, FCA, Ofcom, and CMA, coordinates cross-cutting AI regulatory issues to avoid conflicting guidance.
Automated decisions: the Data (Use and Access) Act 2025
The UK's most concrete AI-relevant legal change is in data protection. The Data (Use and Access) Act 2025 replaced the UK GDPR's Article 22 with new rules that allow solely automated decisions with significant effects, provided safeguards are in place: information about the decision, the chance to make representations, human intervention and the right to contest. Stricter limits remain where special-category data is involved. These rules have applied since 5 February 2026. The Act also requires the ICO to produce a statutory code of practice on AI and automated decision-making, which had not been published by October 2026.
The government has not introduced an AI bill: the King's Speech of 13 May 2026 did not include one.
AI Security Institute
The UK established the AI Safety Institute in November 2023 and renamed it the AI Security Institute in February 2025. It focuses on frontier AI model evaluations and conducts pre-deployment testing of advanced AI models, publishes safety assessments, and contributes to international AI safety standards. While AISI does not have regulatory enforcement power, its evaluations are influential and increasingly referenced in procurement and governance frameworks.
Pro-innovation vs precautionary
The UK's approach is explicitly pro-innovation, contrasting with the EU's more precautionary stance. Key differences include:
The UK approach has advantages in flexibility and speed of adaptation, but creates uncertainty for companies that prefer clear, codified rules. It also creates potential for regulatory fragmentation if different sector regulators interpret the five principles inconsistently.
China: State-controlled and content-focused
China has taken the most targeted and rapid approach to AI regulation, enacting a series of binding regulations that focus on specific AI applications, particularly those with implications for content control, social stability, and data sovereignty. Unlike the EU's comprehensive model or the US's fragmented approach, China's strategy is to regulate specific AI use cases quickly and iteratively.
Binding AI regulations
China has enacted a series of AI-specific regulations in rapid succession:
Each regulation is administered by the Cyberspace Administration of China (CAC), jointly with other ministries. The amended Cybersecurity Law, in force since 1 January 2026, added China's first statutory AI article, but it sets policy direction rather than duties for providers. A comprehensive AI law remains a preparatory item on the 2026 legislative plan of the NPC Standing Committee, with no draft published.
Key regulatory requirements
China's AI regulations share several distinctive characteristics:
- Mandatory filing: Algorithmic recommendation systems and generative AI services must be filed with the CAC, disclosing the basic logic, purpose and operating mechanisms of the algorithm. Services built on their own models are filed nationally; apps that call an already-filed model are registered with local CAC offices. By 31 August 2026, 1,112 generative AI services had been filed and 731 apps registered, and live services must display their filing number.
- Content control obligations: AI-generated content must adhere to "core socialist values" and may not contain content that subverts state power, undermines national unity, promotes terrorism, or violates other content restrictions. This is a fundamentally different regulatory objective than the EU's focus on fundamental rights or the US's focus on consumer protection.
- Labelling and watermarking: Since 1 September 2025 the Labelling Measures require explicit labels visible to users and implicit labels in file metadata (provider name and content identifier) on AI-generated content; platforms must check for them and removing them is prohibited. This parallels the EU AI Act's transparency obligations under Article 50 but is motivated by different policy goals.
- Security assessments: Generative AI services with "public opinion attributes or social mobilisation capacity" must complete a security assessment before launch. This is a trigger-based duty, not a universal licence.
- Data sovereignty: Training data must comply with China's Personal Information Protection Law (PIPL) and Data Security Law (DSL). Cross-border data transfers face strict restrictions, particularly for data classified as "important" or involving personal information of Chinese residents.
User rights in algorithmic recommendation
Algorithmic recommendation systems used by internet platforms, from e-commerce product suggestions to news feed ranking, are subject to user-right requirements including the ability to opt out of personalised recommendations and to request explanations of algorithmic decisions. These rules are a CAC platform regime; they are not part of China's social credit system, which is a fragmented set of mostly business-focused records and blacklists rather than an algorithmic score.
While these user-rights provisions have surface-level similarities to European transparency requirements, they operate within a regulatory framework where the state retains overriding authority to direct algorithmic outcomes in the interest of social stability.
Implications for foreign companies
Foreign companies offering AI services accessible in China face direct regulatory obligations. The Generative AI Regulation applies to services "provided to the public within the territory of the People's Republic of China," which includes cloud-based AI services accessible by Chinese users. Compliance requires:
- Algorithmic filing with the CAC, and the filing number shown in the service.
- Explicit and metadata labels on AI-generated content.
- Training data compliance with PIPL and DSL.
- Content output aligned with Chinese content regulations.
- Cooperation with regulatory inspections and audits.
For many Western companies, meeting Chinese content-control requirements creates a direct conflict with EU and US regulatory expectations around freedom of expression and non-discrimination. This is one of the most challenging aspects of true multi-jurisdiction AI compliance.
Other notable jurisdictions
Beyond the four major regulatory regimes, several other jurisdictions are actively developing AI governance frameworks:
The OECD AI Principles deserve special mention as they represent the closest thing to a global consensus on AI governance. Endorsed by 47 adherents including all G7 members, the principles, human-centred values, transparency, robustness, accountability, and inclusive growth, have directly influenced both the EU AI Act and the NIST AI RMF.
Extraterritorial scope: When foreign laws apply to you
One of the most practically important questions for any company deploying AI across borders is: which foreign laws apply to me? The answer depends on the specific regulation and the nature of your activities.
Key takeaway on extraterritorial reach
The EU AI Act and Chinese regulations have the broadest extraterritorial reach. If your AI system is used by EU residents or accessible by Chinese users, you are likely subject to those jurisdictions' rules regardless of where your company is headquartered. US regulations are primarily territorial but state laws like Colorado's AI Act can reach companies serving residents of those states. UK regulations are largely territorial, applying to deployers within the UK, but the ICO's data protection enforcement has extraterritorial dimensions through the UK GDPR.
Practical multi-jurisdiction compliance strategy
Building separate compliance programmes for each jurisdiction is unsustainable for most organisations. The more effective approach is to build a single, layered compliance programme anchored on the highest common denominator, the EU AI Act, and then add jurisdiction-specific requirements as needed.
Step 1: Anchor on the EU AI Act
The EU AI Act imposes the most comprehensive and prescriptive requirements of any current AI regulation. An organisation that fully complies with the AI Act will have addressed approximately 70-80% of requirements in other jurisdictions by default, because the AI Act requires:
- Risk classification and management (Article 6, Article 9)
- Technical documentation (Article 11)
- Human oversight mechanisms (Article 14)
- Transparency to users (Article 50, overview: AI labelling obligations 2026)
- Accuracy, robustness, and cybersecurity (Article 15)
- Quality management systems (Article 17)
- Post-market monitoring (Article 72)
- Conformity assessment (Article 43)
Whether your system is high-risk at all takes a few minutes to check with the free EU AI Act assessment. Medical AI adds the MDR or IVDR, and the two procedures can be combined: the EU AI Act for medical AI, without doing everything twice. Which tools SMEs use for this is compared in EU AI Act compliance software for startups and SMEs.
Step 2: Map NIST AI RMF to fill US-specific gaps
Organisations operating in the United States should map their EU AI Act compliance documentation to the NIST AI RMF structure. Because NIST is voluntary, the goal is not legal compliance but demonstrating due diligence to US regulators in the event of an enforcement action or litigation. A strong AI governance framework should address both.
Step 3: Layer jurisdiction-specific obligations
On top of the EU AI Act baseline and NIST mapping, add the jurisdiction-specific requirements that are not captured by either framework:
- China: Algorithmic filing, content compliance review, AI-content labelling (explicit and metadata), security assessment where triggered, PIPL data localisation requirements.
- UK: Sector-specific regulatory engagement (FCA for financial services, ICO for data-intensive AI) and the automated-decision safeguards of the Data (Use and Access) Act 2025.
- US states: NYC bias audit (Local Law 144), Colorado notices and explanations (from 1 Jan 2027), California AI Transparency Act and SB 53, New York RAISE Act (frontier developers, from 1 Jan 2027), Texas TRAIGA duties, Illinois HB 3773 and BIPA.
Step 4: Adopt ISO 42001 as the management system standard
ISO/IEC 42001:2023 (AI Management System) provides an internationally recognised framework for establishing, maintaining, and continuously improving an AI management system. Certification under ISO 42001 provides evidence of systematic AI governance that is recognised across jurisdictions and can simplify regulatory engagement in any market.
Step 5: Establish a regulatory monitoring function
The global AI regulatory landscape is evolving rapidly. Organisations need a dedicated function, whether an individual, a team, or an external provider, to monitor regulatory developments across their operating jurisdictions and update the compliance programme accordingly.
Real-world compliance scenarios
Scenario 1: US SaaS company selling AI HR tools in Europe
Real-world example: A San Francisco-based SaaS company develops an AI-powered resume screening tool and sells it to enterprise clients across the United States and Europe. The tool uses machine learning to rank job applicants based on predicted job performance.
Regulatory analysis:
- EU AI Act: The tool is a high-risk AI system under Annex III, Section 4(a), AI used in recruitment and selection of natural persons. The US company is a provider under the AI Act and must comply with the full set of high-risk obligations, including a conformity assessment, technical documentation, risk management system, bias testing, and human oversight mechanisms. The company must also appoint an authorised representative in the EU under Article 22. Maximum penalty for non-compliance: EUR 15 million or 3% of global turnover.
- US federal: The tool falls under EEOC jurisdiction. Any disparate impact on protected groups under Title VII could result in enforcement action. The company should document validation studies and adverse impact analyses.
- NYC Local Law 144: If any New York City-based employer uses the tool, the tool must undergo an annual independent bias audit, and the audit results must be publicly posted.
- Colorado (SB26-189): From 1 January 2027, if Colorado-based employers use the tool, the company must give them the documentation they need for pre-use notice, an explanation within 30 days of an adverse decision, data correction and human review on request.
- Illinois (HB 3773): Illinois employers using the tool must give notice of AI use in employment decisions and are liable if it discriminates.
Practical approach: Build the compliance programme around the EU AI Act's high-risk requirements, which will satisfy most US requirements by default. Add the NYC bias audit and Colorado ADMT disclosures (from 1 January 2027) as supplementary obligations. Use NIST AI RMF documentation to demonstrate due diligence to US regulators.
Scenario 2: European company using a Chinese generative AI model
Real-world example: A Berlin-based marketing agency integrates a generative AI model developed by a Chinese technology company into its content creation workflow. The model is accessed via API and generates marketing copy for the agency's European clients.
Regulatory analysis:
- EU AI Act: The Chinese model provider is subject to GPAI model obligations under Article 53 because the model is placed on the EU market through the API integration. The Berlin agency, as a deployer, has its own obligations including transparency to end users and compliance with the transparency obligations under Article 50. If the generated content could be mistaken for human-produced content, the agency must disclose its AI-generated nature.
- Chinese Generative AI Regulation: The Chinese model provider must have completed algorithmic filing and a security assessment with the CAC. Training data must comply with PIPL. Content outputs must align with Chinese content regulations, which may create tensions when the model is used to generate content for European audiences, particularly on topics the Chinese government considers sensitive.
- GDPR: If any personal data of EU individuals is processed by the Chinese model (including data sent via prompts), GDPR cross-border data transfer restrictions apply. An adequate transfer mechanism (such as Standard Contractual Clauses) is required.
Practical approach: The Berlin agency should conduct thorough due diligence on the Chinese model provider's compliance status under both the EU AI Act and Chinese regulations. Establish data processing agreements that prohibit personal data transmission to the model. Implement output review processes to ensure AI-generated content meets EU transparency requirements.
Scenario 3: Global enterprise deploying AI across all four jurisdictions
Real-world example: A Fortune 500 financial services company headquartered in London deploys AI systems across its operations in the UK, EU, US, and China. AI applications include credit risk scoring (EU and UK), fraud detection (US), algorithmic trading (UK and US), customer service chatbots (all jurisdictions), and anti-money laundering screening (all jurisdictions).
Regulatory analysis:
- EU AI Act: Credit risk scoring is high-risk under Annex III. The company is both a provider (for proprietary AI systems) and a deployer (for vendor-provided systems). Full compliance with the high-risk framework is required, including conformity assessment and fundamental rights impact assessments.
- UK: The FCA oversees AI in financial services. The company must demonstrate compliance with the five AI principles within the FCA's existing regulatory framework, including the Consumer Duty and Senior Managers and Certification Regime (SM&CR) accountability requirements.
- US: The SEC oversees algorithmic trading under existing rules (its proposed predictive-data-analytics rules were withdrawn in 2025). ECOA and Regulation B require specific reasons in adverse action notices, including for AI-assisted credit decisions. State-level requirements apply for consumer-facing operations.
- China: Customer service chatbots accessible in China fall under the Generative AI Regulation if they use generative AI. Anti-money laundering AI must comply with China's Data Security Law regarding cross-border data transfers of financial information.
Practical approach: Establish a centralised AI governance function reporting to the Chief Risk Officer. Build the compliance framework around the EU AI Act as the highest common denominator. Use ISO 42001 certification to demonstrate systematic governance to all regulators. Maintain a regulatory matrix that maps each AI system to its applicable jurisdictions and specific requirements. Engage with sector regulators proactively, particularly the FCA and SEC, rather than waiting for enforcement.
Frequently Asked Questions
Which AI regulation is the most strict?
The EU AI Act imposes the most comprehensive and prescriptive obligations, particularly for high-risk AI systems. Its combination of mandatory conformity assessments, extensive documentation requirements, and fines up to EUR 35 million or 7% of global turnover makes it the most demanding framework for regulated AI systems. However, China's regulations are arguably more restrictive in terms of content control and government oversight of algorithmic systems, requiring mandatory state filing and content alignment that has no equivalent in Western regulatory frameworks.
Does the EU AI Act apply to US companies?
Yes. The EU AI Act applies to any company, regardless of where it is headquartered, that places an AI system on the EU market or whose AI system's output is used within the EU. A US company whose AI product is used by customers in any EU Member State must comply with the applicable provisions. The scope is defined in Article 2. This extraterritorial reach mirrors the GDPR's approach to data protection.
Can I comply with all four jurisdictions using one compliance programme?
In practice, yes, but with caveats. A compliance programme built on the EU AI Act as the baseline will cover most requirements in other jurisdictions. However, certain obligations are jurisdiction-specific and cannot be satisfied by EU compliance alone: US state-level bias audits, Chinese algorithmic filing, and UK sector-specific regulatory engagement all require targeted action. The recommended approach is a layered compliance programme using ISO 42001 as the management system and the EU AI Act as the substantive baseline, with jurisdiction-specific modules added on top.
How does China's approach differ from the EU's?
The most fundamental difference is regulatory objective. The EU AI Act is designed to protect fundamental rights, create legal certainty, and foster trustworthy innovation. China's AI regulations are primarily designed to maintain content control, social stability, and state oversight of algorithmic decision-making. Practically, this means Chinese regulations focus heavily on what AI systems can say (content control), while the EU focuses on how AI systems work (process and risk management). Both have extraterritorial reach, but the compliance requirements are often difficult to reconcile, particularly around content control, where Chinese requirements may conflict with EU principles on freedom of expression.
What should I prioritise if I'm just starting multi-jurisdiction AI compliance?
Start with three actions: (1) Classify your AI systems under the EU AI Act's risk framework using a tool like our AI Act assessment. (2) Map your regulatory exposure by identifying which jurisdictions your AI systems touch, not just where you are incorporated, but where your users, data subjects, and AI outputs are located. (3) Build your governance framework using our AI governance framework guide and align it with both the EU AI Act and NIST AI RMF from the start. This gives you a solid foundation that can be extended to additional jurisdictions as needed.
Which countries have a binding AI law in force in 2026?
As of October 2026: the EU (AI Act, in force since August 2024 and applying in stages to 2028), South Korea (AI Basic Act, since 22 January 2026), Vietnam (AI Law, since 1 March 2026) and Japan (AI Promotion Act, since September 2025, but without penalties). China has several binding AI-specific regulations rather than one law. The US has no federal AI law, but state laws apply in Texas, California, Illinois and New York City, with Colorado's and New York State's following on 1 January 2027. The UK and Canada have no AI statute.
Will there ever be a single global AI regulation?
It is unlikely in the foreseeable future. The OECD AI Principles represent the closest international consensus, but they are non-binding and high-level. The EU, US, UK, and China have fundamentally different governance philosophies, precautionary regulation, innovation-first, adaptive governance, and state control, that reflect deep-seated differences in political systems and policy priorities. The more realistic trajectory is regulatory convergence on principles (transparency, fairness, accountability) combined with continued divergence on specifics (enforcement mechanisms, content requirements, penalty regimes). Organisations should plan for a permanently multi-jurisdictional landscape and build compliance programmes accordingly.
Conclusion
Global AI regulation in 2026 is characterised by convergence on principles and divergence on implementation. The EU AI Act, US sector-specific approach, UK regulator-led governance, and China's content-focused regulations all acknowledge that AI systems require oversight, but they disagree profoundly on what that oversight should look like, who should provide it, and what values it should protect.
For organisations operating across borders, the practical implications are clear:
- Build to the EU AI Act as the global baseline. It is the most comprehensive framework and satisfying its requirements will address the majority of obligations elsewhere.
- Map NIST AI RMF and ISO 42001 to create a structured governance layer that demonstrates due diligence across jurisdictions.
- Maintain jurisdiction-specific compliance modules for obligations that cannot be satisfied by EU compliance alone, particularly Chinese content requirements and US state-level mandates.
- Invest in regulatory monitoring. The landscape is evolving rapidly: South Korea and Vietnam brought AI laws into force in 2026, Brazil is still legislating, and US states keep adding obligations that may apply to your AI systems.
- Use the EU AI Act's risk classification as your starting point. Our free AI Act risk classification tool and compliance checklist for 2026 can help you establish a baseline within minutes.
The organisations that will navigate this landscape most successfully are those that treat multi-jurisdiction compliance not as a burden but as a competitive advantage, building trust, reducing regulatory risk, and demonstrating to customers, investors, and regulators worldwide that their AI systems are developed and deployed responsibly.
Related articles
About the author
Pedram Madani, founder of Legalithm. He researches large language models in software engineering and has two peer-reviewed IEEE papers.
Publications



