AI Laws Compared: EU vs US vs China vs the World

Regulating AI · Index

Thank you for reading this post, don't forget to subscribe!

Home / Indexes / Regulating AI / Laws Compared

AI Laws Compared: EU vs US vs China vs the World

Every major economy is regulating AI — but they disagree on almost everything: whether to write one law or many, whether to protect rights or promote industry, and whether the state, the market, or the labs should hold the controls. This is the side-by-side scorecard of the three models that matter most, plus the soft-law challengers, on the dimensions that decide who actually has to comply.

Last updated: July 2026. Companion to our country-by-country map. Every figure is sourced below.

7%
EU max fine as a share of global turnover — the world’s steepest
EU AI Act, Art. 99
3
Distinct philosophies: rights-based, market-led, security-led
EU / US / China
$0
Monetary penalty under Japan’s deliberately non-punitive AI law
AI Promotion Act

The master scorecard

The clearest way to see the divergence is dimension by dimension. Read down a column for one jurisdiction’s whole philosophy; read across a row to see how differently the same question gets answered.

DimensionEuropean UnionUnited StatesChina
Legal instrumentOne binding regulation (AI Act 2024/1689)No federal law; ~50 state laws + executive ordersSeveral binding administrative rules (CAC-led)
Core philosophyRights-based, precautionaryMarket-led, pro-innovationState control, content & security
Coverage triggerRisk tier of the use + GPAI compute (10^25 FLOP)Varies by state; frontier compute (CA: 10^26)Public-facing service + content type
Headline obligationConformity assessment for high-risk systemsTransparency & anti-discrimination (state-dependent)Algorithm registration + content labeling
Max penalty€35M or 7% global turnovere.g. TX $200k/violation; UT $2,500; no federal capTakedown, suspension, license revocation
EnforcerAI Office + national authoritiesState AGs, FTC, EEOC, sector agenciesCyberspace Administration (CAC) + agencies
Extraterritorial?Yes — providers serving the EUEffectively, via state reach & export controlsApplies to services offered in China
Frontier focusYes — GPAI systemic-risk tierYes at state level (CA SB 53); no federalIndirect (security review, algorithm filing)
Status (mid-2026)In force; high-risk rules delayed to Dec 2027Patchwork live; federal preemption threatenedIn force (layered)

Three philosophies, three answers

The EU protects rights first. The AI Act starts from the citizen: it bans uses deemed unacceptable (social scoring, most real-time biometric surveillance), then loads the heaviest duties onto “high-risk” systems that touch employment, credit, education, and essential services. Compliance is a conformity assessment — paperwork, testing, and CE-style marking before deployment. The logic is precautionary: prove it’s safe before it ships.

The US protects the market first. Federal policy in 2025–2026 is explicitly deregulatory, framing rules as a competitiveness risk and even threatening to preempt the states. Real obligations therefore live at the state level and cluster around two narrow concerns: tell people when AI is being used (Utah, Texas) and don’t let it discriminate (Illinois, Colorado’s surviving core). California’s SB 53 is the lone frontier-safety statute — and even it is transparency, not pre-approval.

China protects the state first. There is no single AI Act; instead, targeted rules govern the things the government cares about most — recommendation algorithms, deep synthesis, generative-AI services, and, since September 2025, mandatory labeling of AI content with both visible marks and hidden metadata. Enforcement is fast and administrative: register your algorithm, or lose the service.

Where the rivals actually agree

For all the divergence, three points of convergence are emerging — and they’re the safest bets for where global norms settle:

  • Label synthetic content. The EU (Art. 50 transparency), China (2025 labeling standard), and South Korea all now require AI-generated content to be marked. This is the single most globally consistent rule.
  • Watch the frontier. Both the EU (10^25 FLOP systemic-risk tier) and California (10^26 frontier threshold) single out the largest models for special duties — a shared instinct that scale equals risk.
  • Report serious incidents. The EU’s GPAI Code of Practice, California SB 53, and South Korea’s Act all create channels to report critical safety incidents to regulators.

Who bites hardest?

On paper, the enforcement gradient runs steeply downhill from Brussels. The EU’s 7% of global turnover is an existential number for a large developer — for a $50B-revenue firm, up to $3.5B per prohibited-use finding. The US has no federal cap and modest state fines (Texas tops out at $200,000 per violation; Utah at $2,500), but its real leverage is different: litigation and export controls. China’s penalties look mild in dollar terms but are arguably the most immediate — a service can simply be switched off. Japan, by design, imposes no fine at all; its only sanction is public naming.

The paradox: the jurisdiction with the smallest headline fines (China) can act fastest, while the one with the largest (the EU) is delaying its toughest rules to 2027–2028. Severity on paper and speed in practice are not the same thing.

What none of them has solved

Every framework above assumes a model its author can reach. None cleanly answers the open-weights problem: once a frontier model’s weights are public, no conformity assessment, licensing gate, or content rule can be enforced against the countless copies. That gap — and the US “kill switch” proposal that tries to close it — is the subject of our forecast on the AI shutdown bill.

Frequently asked questions

Is the EU or the US stricter on AI?
The EU, decisively. It has a binding, comprehensive law with fines up to 7% of global turnover, while the US has no federal AI statute and a deregulatory federal posture — only a patchwork of narrower state laws.

What’s the biggest difference between EU and Chinese AI regulation?
Focus. The EU regulates AI to protect individual rights (bias, safety, transparency); China regulates it to protect state control over information (algorithm registration, content labeling, security review). The EU fines; China switches services off.

Do these laws apply to foreign companies?
Largely yes. The EU AI Act, China’s rules, and South Korea’s Act all reach providers that serve users in their territory, regardless of where the company is based.

Sources

• EU AI Act, Article 99 (penalties) — artificialintelligenceact.eu/article/99
• EU AI Act, Article 51 (GPAI systemic risk) — artificialintelligenceact.eu/article/51
• White & Case, California SB 53 frontier transparency — whitecase.com
• Norton Rose Fulbright, Texas TRAIGA — nortonrosefulbright.com
• China Law Translate, AI content-labeling measures — chinalawtranslate.com
• White & Case, Japan AI Promotion Act — whitecase.com
• Cooley, South Korea AI Basic Act — cooley.com
• EU AI Act GPAI Code of Practice — artificialintelligenceact.eu