Major AI Regulations Explained
AI systems are making consequential decisions about credit, hiring, medical diagnosis, and criminal justice. Governments around the world have decided that "move fast and break things" is not an acceptable philosophy when the things being broken are people's lives. The result is a wave of regulation that is reshaping how AI gets built, deployed, and audited - and who is legally responsible when something goes wrong.
This page gives you a working understanding of the most significant frameworks: what they say, who they cover, and what compliance actually looks like in practice.
This content was developed with AI assistance and is regularly reviewed for accuracy.
Learning Objectives
By the end of this page you will be able to:
- Explain the EU AI Act's four-tier risk classification system and what each tier requires
- Describe the key US federal actions on AI, including executive orders and proposed legislation
- Identify major regulatory approaches taken by China, the UK, and Canada
- Recognize which types of AI systems face the most stringent requirements globally
The EU AI Act: The World's First Comprehensive AI Law
The EU AI Act entered into force in August 2024, making it the first binding, comprehensive AI regulation in the world. It applies not just to companies inside the EU, but to any organization offering AI systems to EU users or deploying AI that affects people in the EU. Its scope is genuinely global.
The Act's defining architectural choice is a risk-based tiered system. Rather than regulating AI generically, it assigns obligations based on how much harm a given application can cause.
Tier 1: Unacceptable Risk (Banned)
Certain AI applications are prohibited outright. These include:
- Social scoring systems run by governments that evaluate citizens' behavior and grant or restrict access to services
- Real-time biometric surveillance in public spaces by law enforcement (with narrow exceptions)
- AI systems that exploit psychological vulnerabilities to manipulate behavior
- Predictive policing systems that profile individuals based on characteristics like ethnicity or religion
These bans took effect in February 2025 and are now in active enforcement. Organizations found operating banned systems face fines of up to 35 million euros or 7% of global annual turnover - whichever is higher.
Tier 2: High Risk
This is the most consequential tier for most businesses. High-risk AI systems are not banned, but they face substantial compliance requirements before they can be deployed.
High-risk categories include AI used in:
- Critical infrastructure (energy grids, water systems, transportation)
- Education (automated grading, admission decisions)
- Employment (CV screening, performance monitoring, termination decisions)
- Essential services (credit scoring, insurance underwriting)
- Law enforcement (crime prediction, evidence evaluation)
- Migration and border control
- Administration of justice
Before deploying a high-risk system, providers must conduct a conformity assessment, maintain comprehensive technical documentation, implement human oversight mechanisms, register the system in an EU database, and demonstrate the system meets accuracy, robustness, and cybersecurity requirements. These obligations place real operational costs on companies - particularly smaller ones.
Tier 3: Limited Risk
Systems like chatbots and AI-generated content fall here. The primary obligation is transparency: users must be told they are interacting with an AI. Deepfake content must be labeled as artificially generated. These requirements are relatively lightweight but still legally binding.
Tier 4: Minimal Risk
AI used in spam filters, video games, or product recommendations faces no additional requirements beyond existing law. Most AI applications in use today fall into this category.
General Purpose AI (GPAI) Models
The Act added a separate framework for foundation models and large general-purpose AI systems (like the Claude 5, GPT-5.x, and Gemini 3 families). All GPAI providers must publish technical documentation and comply with EU copyright law. Providers of the most powerful models - those trained above a defined compute threshold - face additional obligations, including systematic adversarial testing and cybersecurity reporting.
United States: A Patchwork in Progress
The US has taken a fundamentally different approach. Rather than a single comprehensive law, federal AI governance has developed through executive action, agency rulemaking, and a growing collection of state-level bills.
Executive Orders
In October 2023, the Biden administration issued Executive Order 14110 on Safe, Secure, and Trustworthy AI. It was one of the most expansive uses of executive authority on AI to date. Key provisions required:
- Developers of powerful AI systems to share safety test results with the federal government before public release
- NIST to develop standards for AI red-teaming and safety evaluations
- Federal agencies to assess AI risks in their own operations
- New guidance on AI use in hiring, housing, and credit decisions under existing civil rights law
The order also directed agencies including HHS, DOD, and DHS to develop sector-specific AI guidance, creating a network of agency-level rules rather than one central statute.
In January 2025, the Trump administration revoked Executive Order 14110 and issued a replacement order focused on removing what it characterized as barriers to American AI leadership. The replacement directed agencies to develop an AI Action Plan and emphasized deregulation over mandated safety testing. Executive-branch AI direction has continued to shift through subsequent orders and agency actions since then. This pattern of repeated policy swings illustrates how dependent US AI policy remains on the current administration's priorities — and why organizations increasingly plan around durable frameworks (statute, state law, EU AI Act) rather than any single executive order.
Proposed Legislation
Congress has introduced dozens of AI-related bills, though few have become law. The most discussed proposals include:
- TAKE IT DOWN Act: Focused specifically on non-consensual intimate imagery generated by AI; signed into law in 2025 after passing the Senate earlier that year
- Algorithmic Accountability Act: Would require impact assessments for automated decision systems affecting consumers; has not advanced out of committee
- AI SAFETY Act: Would create mandatory incident reporting for AI systems causing harm; still in discussion phase
The absence of federal AI legislation has created a vacuum that states are filling rapidly. California, Colorado, Illinois, and Texas have passed or are advancing substantive AI laws. California's SB 1047 - which would have imposed safety requirements on developers of large AI models - was vetoed by Governor Newsom in 2024 after significant industry opposition. Colorado's original AI Act (SB 24-205), passed in 2024, never fully took effect — lawmakers delayed its start date twice, a federal court paused it in early 2026 amid a lawsuit the U.S. Department of Justice intervened to support, and Governor Polis ultimately signed a replacement law (SB 26-189) in May 2026 that takes effect January 1, 2027. The replacement narrows the original's scope, dropping risk-management-program and impact-assessment requirements in favor of more targeted duties: notifying users when they interact with AI, disclosing adverse automated decisions within 30 days, and providing human review on request. The episode is a useful case study in how hard it is to operationalize AI-specific rules once affected industries push back.
Federal Agency Actions
Several agencies have taken enforcement positions on AI under existing authority, though the posture has shifted with the change in administration:
- The FTC has continued pursuing "AI-washing" cases - deceptive advertising and false claims about AI capabilities - under both the Biden and Trump administrations, with more than a dozen such cases filed since 2024
- The EEOC withdrew its 2023 technical guidance on AI and Title VII compliance in January 2025 after a change in leadership. Federal anti-discrimination law (Title VII, the ADEA, the ADA) still applies to AI hiring tools, but employers no longer have the agency's earlier guidance spelling out how to assess them
- The CFPB has moved away from its 2023-era position that algorithmic credit decisions must be fully explainable under fair lending law - it rescinded dozens of guidance documents in 2025 and finalized a 2026 rule that eliminates the federal disparate-impact ("effects test") standard under the Equal Credit Opportunity Act altogether, leaving disparate-treatment liability, FHA disparate impact, and state-level disparate-impact regimes in place
This agency-first approach means US AI compliance is sector-specific and administration-dependent - what a healthcare company needs to worry about differs substantially from what a financial services firm faces, and both can shift significantly when federal leadership changes.
Other Significant Frameworks
China
China has moved aggressively to regulate specific AI application categories while simultaneously investing heavily in national AI development. Key regulations include:
Algorithmic Recommendation Rules (2022): Require recommendation algorithm providers to register with regulators, disclose how recommendations work to users, and offer opt-out options.
Deep Synthesis Regulations (2023): Require labeling of AI-generated content and real-name registration for users of deepfake services.
Generative AI Regulations (2023): Apply to public-facing generative AI services. Providers must register, submit security assessments, ensure training data is lawful, and prevent content that undermines state authority. The rules do not apply to AI used in internal research.
China's approach prioritizes content control and social stability alongside technical safety, making its regulatory philosophy distinct from both the EU's rights-based framework and the US's market-focused approach.
United Kingdom
The UK has explicitly rejected a single comprehensive AI law in favor of a principles-based, sector-led approach. Existing regulators - including the ICO (data protection), CMA (competition), FCA (financial services), and MHRA (medicines) - are responsible for AI in their sectors, guided by cross-cutting principles: safety, security, transparency, fairness, accountability, and contestability.
The AI Security Institute (renamed from the AI Safety Institute in February 2025) focuses on evaluating frontier AI models for national-security-relevant risks, signaling a shift toward security-specific risks like cyberattacks and bioweapons development over broader safety and ethics concerns. The UK's position reflects a deliberate bet that flexibility and speed-to-market matter more than legal harmonization.
Canada
Canada's Artificial Intelligence and Data Act (AIDA) was introduced as part of Bill C-27 and would have created a federal framework for "high-impact" AI systems requiring risk assessments, mitigation measures, record-keeping, and transparency with affected individuals. Bill C-27 died on the order paper when Parliament was prorogued in January 2025, and no successor bill has been reintroduced since the 2025 federal election. For now, Canada's existing PIPEDA privacy framework continues to apply to automated decision-making that affects individuals, and provincial laws — most notably Quebec's Law 25 — impose additional transparency obligations on automated decision systems.
Key Takeaways
The global regulatory picture has several consistent themes worth internalizing:
- Risk-based tiering is the dominant design pattern. The EU, Canada, and others organize obligations by how much harm an AI system can cause, not by the technology itself.
- Transparency is nearly universal. Every major framework requires some form of disclosure - that users are talking to AI, that automated decisions are being made, or that AI-generated content exists.
- Extraterritorial reach is real. The EU AI Act applies to non-EU companies serving EU users. Any organization with a global user base needs to treat EU requirements as their floor.
- The US is the major exception to the comprehensive-law approach. US companies face a patchwork of federal agency guidance and accelerating state legislation rather than one federal statute.
- Compliance costs fall unevenly. High-risk designations create documentation, audit, and oversight requirements that larger organizations absorb more easily than startups. This is a live policy debate in every jurisdiction.
Next Steps
Understanding the regulatory landscape is only half the picture. The more practical question is how these frameworks affect your work, your organization, and your decisions.
Continue to: How Regulations Affect You