Regulating AI · Index
Thank you for reading this post, don't forget to subscribe!
Home / Indexes / Regulating AI / Laws Compared
AI Laws Compared: EU vs US vs China vs the World
Every major economy is regulating AI — but they disagree on almost everything: whether to write one law or many, whether to protect rights or promote industry, and whether the state, the market, or the labs should hold the controls. This is the side-by-side scorecard of the three models that matter most, plus the soft-law challengers, on the dimensions that decide who actually has to comply.
Last updated: July 2026. Companion to our country-by-country map. Every figure is sourced below.
The master scorecard
The clearest way to see the divergence is dimension by dimension. Read down a column for one jurisdiction’s whole philosophy; read across a row to see how differently the same question gets answered.
| Dimension | European Union | United States | China |
|---|---|---|---|
| Legal instrument | One binding regulation (AI Act 2024/1689) | No federal law; ~50 state laws + executive orders | Several binding administrative rules (CAC-led) |
| Core philosophy | Rights-based, precautionary | Market-led, pro-innovation | State control, content & security |
| Coverage trigger | Risk tier of the use + GPAI compute (10^25 FLOP) | Varies by state; frontier compute (CA: 10^26) | Public-facing service + content type |
| Headline obligation | Conformity assessment for high-risk systems | Transparency & anti-discrimination (state-dependent) | Algorithm registration + content labeling |
| Max penalty | €35M or 7% global turnover | e.g. TX $200k/violation; UT $2,500; no federal cap | Takedown, suspension, license revocation |
| Enforcer | AI Office + national authorities | State AGs, FTC, EEOC, sector agencies | Cyberspace Administration (CAC) + agencies |
| Extraterritorial? | Yes — providers serving the EU | Effectively, via state reach & export controls | Applies to services offered in China |
| Frontier focus | Yes — GPAI systemic-risk tier | Yes at state level (CA SB 53); no federal | Indirect (security review, algorithm filing) |
| Status (mid-2026) | In force; high-risk rules delayed to Dec 2027 | Patchwork live; federal preemption threatened | In force (layered) |
Three philosophies, three answers
The EU protects rights first. The AI Act starts from the citizen: it bans uses deemed unacceptable (social scoring, most real-time biometric surveillance), then loads the heaviest duties onto “high-risk” systems that touch employment, credit, education, and essential services. Compliance is a conformity assessment — paperwork, testing, and CE-style marking before deployment. The logic is precautionary: prove it’s safe before it ships.
The US protects the market first. Federal policy in 2025–2026 is explicitly deregulatory, framing rules as a competitiveness risk and even threatening to preempt the states. Real obligations therefore live at the state level and cluster around two narrow concerns: tell people when AI is being used (Utah, Texas) and don’t let it discriminate (Illinois, Colorado’s surviving core). California’s SB 53 is the lone frontier-safety statute — and even it is transparency, not pre-approval.
China protects the state first. There is no single AI Act; instead, targeted rules govern the things the government cares about most — recommendation algorithms, deep synthesis, generative-AI services, and, since September 2025, mandatory labeling of AI content with both visible marks and hidden metadata. Enforcement is fast and administrative: register your algorithm, or lose the service.
Where the rivals actually agree
For all the divergence, three points of convergence are emerging — and they’re the safest bets for where global norms settle:
- Label synthetic content. The EU (Art. 50 transparency), China (2025 labeling standard), and South Korea all now require AI-generated content to be marked. This is the single most globally consistent rule.
- Watch the frontier. Both the EU (10^25 FLOP systemic-risk tier) and California (10^26 frontier threshold) single out the largest models for special duties — a shared instinct that scale equals risk.
- Report serious incidents. The EU’s GPAI Code of Practice, California SB 53, and South Korea’s Act all create channels to report critical safety incidents to regulators.
Who bites hardest?
On paper, the enforcement gradient runs steeply downhill from Brussels. The EU’s 7% of global turnover is an existential number for a large developer — for a $50B-revenue firm, up to $3.5B per prohibited-use finding. The US has no federal cap and modest state fines (Texas tops out at $200,000 per violation; Utah at $2,500), but its real leverage is different: litigation and export controls. China’s penalties look mild in dollar terms but are arguably the most immediate — a service can simply be switched off. Japan, by design, imposes no fine at all; its only sanction is public naming.
What none of them has solved
Every framework above assumes a model its author can reach. None cleanly answers the open-weights problem: once a frontier model’s weights are public, no conformity assessment, licensing gate, or content rule can be enforced against the countless copies. That gap — and the US “kill switch” proposal that tries to close it — is the subject of our forecast on the AI shutdown bill.
Frequently asked questions
Is the EU or the US stricter on AI?
The EU, decisively. It has a binding, comprehensive law with fines up to 7% of global turnover, while the US has no federal AI statute and a deregulatory federal posture — only a patchwork of narrower state laws.
What’s the biggest difference between EU and Chinese AI regulation?
Focus. The EU regulates AI to protect individual rights (bias, safety, transparency); China regulates it to protect state control over information (algorithm registration, content labeling, security review). The EU fines; China switches services off.
Do these laws apply to foreign companies?
Largely yes. The EU AI Act, China’s rules, and South Korea’s Act all reach providers that serve users in their territory, regardless of where the company is based.
Sources
• EU AI Act, Article 51 (GPAI systemic risk) — artificialintelligenceact.eu/article/51
• White & Case, California SB 53 frontier transparency — whitecase.com
• Norton Rose Fulbright, Texas TRAIGA — nortonrosefulbright.com
• China Law Translate, AI content-labeling measures — chinalawtranslate.com
• White & Case, Japan AI Promotion Act — whitecase.com
• Cooley, South Korea AI Basic Act — cooley.com
• EU AI Act GPAI Code of Practice — artificialintelligenceact.eu