How Is AI Regulated? The EU AI Act and the Global Rulebook

Artificial Intelligence Published: 14 min read Pravesh Garcia
AI Regulation_ Four Global Rulebooks
Rate this post

Picture an ordinary Tuesday. Software ranks a pile of job applications before any human reads one. Another model prices your car insurance, and a third flags a benefits claim for a second look. You’d probably never know any of it happened. That’s why “how is AI regulated?” is really a question about your own life.

The honest answer depends on where you’re standing. Europe has written a sweeping, binding AI law, then moved some of its own deadlines. The United States has no comprehensive federal law and is now fighting its own states over who gets to write one. China labels. Britain delegates.

And the rules move fast enough that a lot of what’s online is already wrong. Plenty of explainers still say Europe’s high-risk rules start in August 2026. They don’t anymore.

So, How Is AI Regulated Right Now?

Four major jurisdictions, four very different philosophies. The short version first:

  • The European Union has one binding law, the AI Act, in force since 1 August 2024. It sorts AI by the risk a given use poses to people.
  • The United States has no comprehensive federal AI law. The federal government is actively pushing back against state AI laws through litigation and funding pressure.
  • China writes targeted rules for specific problems. Its most visible one requires labels on AI-generated content.
  • The United Kingdom has no AI-specific statute. Existing regulators apply five broad principles inside their own sectors.

Notice the question each one is really asking. Brussels asks how dangerous a particular use is. Washington is busy asking who gets to set the rules at all. Beijing wants to see what the machine made. London wants to know which regulator already owns the problem.

Each one is a different bet about where harm comes from.

The EU AI Act in Plain Language: Four Tiers of Risk

The idea that makes the AI Act click: it doesn’t regulate “AI” as a technology. It regulates uses. The same underlying model could sit harmlessly inside a playlist feature or decide whether you get a job interview, and the law cares about the second case far more than the first.

The European Commission’s overview of the AI Act sets out four tiers.

Unacceptable risk: what the EU bans outright

The top tier is a list of practices the Act simply forbids. Article 5 rules out:

  • AI that manipulates or deceives people in ways that cause significant harm
  • Systems that exploit vulnerabilities linked to age, disability or socioeconomic status
  • Social scoring
  • Predicting that someone will commit a crime based solely on profiling
  • Untargeted scraping of faces from the internet or CCTV footage
  • Biometric categorization that infers race, political views, religion, sexual orientation or union membership
  • Emotion recognition in workplaces and schools, except for medical or safety reasons
  • Real-time remote biometric identification by police in public spaces, with narrow exceptions (missing persons, imminent threats, serious crime suspects) that need judicial authorization

The Digital Omnibus adds one more from 2 December 2026: AI that generates child sexual abuse material or non-consensual intimate imagery. With that addition, the Commission counts nine prohibited practices.

The emotion-recognition ban deserves a second look. It draws a hard line around machines inferring what’s going on inside your head. That theme keeps coming up on this site, most recently in our piece on neuroprivacy and what governments can subpoena.

High risk: the decisions that shape a life

The second tier is where the Act gets personal. Annex III names the areas it treats as high-risk:

  • Biometrics
  • Critical infrastructure
  • Education, such as admissions and exam monitoring
  • Employment, such as recruitment and performance monitoring
  • Essential services and credit, including public benefits, creditworthiness checks, insurance pricing and emergency call triage
  • Law enforcement
  • Migration, asylum and border control
  • Justice and democratic processes, including systems built to influence elections

Read that list as a person rather than a compliance officer. It’s the CV filter, the online exam proctor, the loan decision, the benefits review. These systems stay legal, but they sit in the Act’s most heavily regulated AI tier.

The catch is timing, which we’ll get to in a moment. We dug into exactly who that delay leaves exposed in our breakdown of the EU AI Act high-risk compliance deadline.

Transparency risk: the chatbot and deepfake rules

The third tier is about honesty rather than danger. If you want to see how AI is regulated at the exact moment you meet it, this is the tier to watch. Under Article 50:

  • Chatbots must tell you you’re talking to AI, unless that’s obvious.
  • Providers must mark synthetic audio, images, video and text in a machine-readable way.
  • Anyone deploying a deepfake must disclose it, with a lighter duty for clearly artistic or satirical work.
  • People exposed to emotion recognition or biometric categorization must be told.

The Act also says how. You get that information “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure.” A disclosure buried deep in the terms of service is hard to square with that wording.

Minimal risk: most of what you already use

The base of the pyramid is enormous. The Commission says the vast majority of AI systems currently in use in the EU fall here, and the Act places no rules on them. That’s a deliberate choice. Europe concentrated its effort on a narrow band of uses instead of trying to police every algorithm.

EU AI Act Timeline: What Applies Now and What the Digital Omnibus Delayed

The AI Act was always going to arrive in stages. Then, in 2026, the EU passed a simplification package known as the Digital Omnibus on AI, and it reshuffled the calendar.

Reports differ on exactly when lawmakers struck the political deal (somewhere in spring to early summer 2026). The end point is clear, though. According to CMS’s analysis of the Omnibus, the text appeared in the Official Journal on 24 July 2026 and took effect on 27 July 2026.

The corrected calendar, as of October 2026:

[TIMESTAMP] [MANDATE / APPLIES] [TELEMETRY STATUS]
1 Aug 2024 AI Act enters into force  

Done

2 Feb 2025 Banned practices; AI literacy duties  

In effect

2 Aug 2025 General-purpose AI model obligations; governance  

In effect

2 Aug 2026 Article 50 transparency: chatbot disclosure, deepfake labels, synthetic content marking  

In effect

2 Dec 2026 Grace period ends for machine-readable marking on generative systems already on the market before 2 Aug 2026; new ban on AI-generated abuse imagery  

Coming soon

2 Aug 2027 Deadline for national AI regulatory sandboxes  

Pushed back by the Omnibus

2 Dec 2027 High-risk obligations for standalone (Annex III) systems  

Delayed from 2 Aug 2026

2 Aug 2028 High-risk obligations for AI built into regulated products  

Delayed by the Omnibus

The Omnibus did a few quieter things too. It extended relief meant for small and medium firms to “small mid-caps,” and it simplified registration for systems that claim an exemption under Article 6(3).

The headline change is the high-risk delay. Standalone high-risk rules slid 16 months, from August 2026 to December 2027. CMS’s own read is that companies should keep preparing rather than treat the extension as a full pause. That’s sensible advice. It’s also cold comfort if you’re the person being screened by a hiring algorithm in the meantime.

What the EU Rules Change for You Today

Strip away the legal machinery and one question matters: which protections can you actually rely on right now?

[PROTECTION_PROTOCOL] [LIVE_SINCE / TIMELINE]
Ban on social scoring and manipulative AI
2 Feb 2025
ACTIVE

Ban on emotion recognition at work and school
2 Feb 2025
ACTIVE

Being told you’re talking to a chatbot
Aug 2026
ENFORCED

Deepfake disclosure
Aug 2026
ENFORCED

Machine-readable marking of AI-generated content
Aug 2026

// Grace window: Dec 2, 2026 (legacy gen systems)
Ban on AI-generated child abuse and non-consensual intimate imagery
From 2 Dec 2026
UPCOMING

High-risk duties for AI in hiring, credit, exams and benefits
Not until 2 Dec 2027
DEFERRED

High-risk duties for AI inside regulated products
Not until 2 Aug 2028
DEFERRED

That table tells an uncomfortable story. The bans and the disclosure rules are live. The protections around the decisions that most change a life, such as a job, a loan or an exam result, still sit more than a year away.

General-purpose AI models

The big foundation models behind today’s chatbots have their own chapter. Since 2 August 2025, providers of general-purpose AI models must:

  • Keep technical documentation
  • Give downstream developers information on what the model can and can’t do
  • Put in place a policy to comply with EU copyright law
  • Publish a summary of the content they used for training, using a template from the EU’s AI Office

Open-source models skip some of the documentation duties, unless they carry systemic risk. Providers can also show compliance by following approved codes of practice.

That training-summary duty lands right on top of a fight we’ve covered before: whether training AI on copyrighted work counts as fair use. Europe hasn’t settled that argument. It has made it harder to keep training data a secret.

Penalties

Article 99 sets three tiers of fines:

  • Prohibited practices: up to €35 million or 7% of global annual turnover, whichever is higher
  • Most other obligations, including transparency: up to €15 million or 3%
  • False or incomplete information to authorities: up to €7.5 million or 1%

Smaller companies pay the lower of the two figures rather than the higher. For the largest tech firms, though, a percentage of global turnover is the number that gets a board’s attention.

How the United States Regulates AI: Washington Versus the States

If Europe’s model is a single rulebook, America’s is a tug-of-war.

There’s still no comprehensive federal AI law. Instead, on 11 December 2025, President Trump signed an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence.” As Paul Hastings explains in its analysis of the order, it does three main things:

  1. It created a Justice Department AI Litigation Task Force, active from 10 January 2026, to challenge state AI laws in court.
  2. It directed the Commerce Department to tie roughly $42 billion in BEAD broadband funding to states’ AI rules.
  3. It named Colorado’s AI Act specifically.

One detail matters a lot here. An executive order can’t erase a state law by itself. Existing state laws stay enforceable until courts or Congress act. So Washington is leaning on lawsuits and money instead.

Colorado: the cautionary tale

Colorado passed SB24-205, the first comprehensive state law aimed at algorithmic discrimination. Then everything went sideways. As of May 2026:

  • Lawmakers had already pushed its effective date to 30 June 2026.
  • xAI sued the state on 9 April 2026.
  • The Justice Department intervened, the first federal action against a state AI law under the December 2025 order.
  • A magistrate judge stayed enforcement on 27 April 2026.
  • Colorado’s attorney general, Weiser, committed not to enforce the law.
  • A working group convened by the governor proposed narrowing the law and starting it on 1 January 2027.

Things may have moved since then, so treat that as a snapshot. But the shape is clear. In the US, the live fight is over who gets to regulate AI at all.

China Regulates AI by Labeling What It Makes

China’s approach is narrower and more targeted than the EU’s. Its clearest example is the set of Labeling Measures for AI-generated content, issued on 14 March 2025 and in force since 1 September 2025.

The rules require two kinds of label:

  • Explicit labels that people can see
  • Implicit labels hidden in the file’s metadata

A mandatory national standard, GB 45438-2025, sets out how. One rule reaches ordinary people directly: users who publish AI-generated content have to declare it themselves.

Set that next to Europe’s Article 50 and you’ll see two governments chasing the same problem. Both want you to know when a machine made what you’re looking at. China simply puts more of that duty on the person hitting “post.”

The UK: Principles Instead of a Statute

Britain has gone the other way. It has no AI-specific legislation, and as of early 2026 no comprehensive AI bill had passed.

Instead, the UK relies on five non-statutory principles:

  1. Safety, security and robustness
  2. Transparency and explainability
  3. Fairness
  4. Accountability and governance
  5. Contestability and redress

Existing regulators then apply those principles inside their own patch. The ICO handles data protection, the CMA covers competition, the FCA watches financial services, and Ofcom oversees communications. So in Britain, AI gets regulated by many watchdogs and no single law. The pitch is flexibility. The cost is that nothing in one place tells you, the person on the receiving end, what you’re entitled to.

Four AI Rulebooks Side by Side

[DIMENSION] EU [REGION_01] US [REGION_02] CHINA [REGION_03] UK [REGION_04]
CORE_LOGIC Regulate uses by risk
Four-tier horizontal risk-based classification system
Federal vs State tension
Federal pressure against disparate state rules
Targeted regulations
Granular rules mapped to specific problem vectors
Principle-based framework
Contextual rules applied through existing regulators
BINDING_LAW?
YES // ENFORCEABLE
The EU AI Act
NO // FEDERAL
Some state statutes active
YES // TARGETED
Content labeling mandates
NO // UNCODIFIED
Sector-bound guidance only
USER_IMPACT Chatbot & deepfake disclosure, machine marking, banned practices enforcement. Depends directly on your state of residence and emerging court precedents. Visible identifiers + invisible cryptographic metadata on AI-generated content. Sector-specific regulations, such as data privacy actions via the ICO.
OPEN_QUESTION Will delayed high-risk rules protect citizens before widespread frontier AI deployment? Who wins the federal-state preemption fight in congressional legislation? How far will mandatory content labeling and tracing duties extend across ecosystems? Will a dedicated, centralized AI statutory bill ever pass into law?

Why the EU Rulebook Reaches Beyond Europe

This is the part non-Europeans tend to miss. The AI Act doesn’t stop at the EU’s borders.

Article 2(1)(c) covers providers and deployers in other countries “where the output produced by the AI system is used in the Union.” A company in California or Singapore whose system produces decisions or content used in the EU can fall inside the Act. So how AI is regulated in Brussels matters even if you’ve never set foot there.

My read is that this will quietly shape products far outside Europe. A company that serves European users already has to build disclosure and documentation for Brussels. Once it has done that work, maintaining a second, looser version for everyone else gets less attractive. I could be wrong about this. But it’s why a law written in Brussels may end up shaping the chatbot you use in Chicago or Chennai.

Where AI Regulation Still Falls Short

Even the most detailed rulebook has gaps. Three stand out.

The delay cuts both ways. Supporters frame the Omnibus as simplification, a chance for technical standards to catch up. Critics see something simpler: people affected by AI in hiring, credit and public benefits wait until late 2027 for the protections written with them in mind.

Paper rules aren’t the same as enforced rules. The EU’s fines look fearsome. Yet the obligations attached to the most consequential decisions don’t bite for more than a year. In the US, Colorado shows how a law can pass, survive a delay, and still end up frozen in court.

The patchwork itself is a problem. An AI company can be tightly regulated in Europe, partly regulated in one US state, and barely touched in the next. For the people on the receiving end, protection can depend on your postcode more than on the actual risk.

Narrow AI Rules vs AGI Rules: Where Frontier Regulation Fits

Everything above deals with today’s systems: chatbots, hiring tools, image generators, face scanners. Regulating a hypothetical superintelligence is a different conversation, with far more guesswork.

The closest the EU gets to that frontier is its general-purpose AI chapter, where even open-source models lose some of their exemptions once they carry systemic risk. For the bigger-picture debate, read our companion piece on how governments plan for superintelligence. Think of this guide as the ground floor and that one as the roof.

What to Watch Next

A few dates and decisions will tell you which way the rulebook is heading:

  • 2 December 2026: the EU’s ban on AI-generated abuse imagery begins, and the marking grace period for older generative systems ends.
  • Colorado: whether the narrowed law and the proposed 1 January 2027 start date hold up, and how the court case resolves.
  • The DOJ task force: which state law it targets next.
  • 2 December 2027: the date Europe’s standalone high-risk rules finally apply, unless something moves them again.
  • The UK: whether a dedicated AI bill ever reaches Parliament.

My test for any AI rule is simple. Does it cover the decision someone makes about you? Does it apply today? Who hears your complaint if it goes wrong?

So how is AI regulated, by that test? Europe leads on paper and lags on the calendar. The US is still arguing over who holds the pen. And for most people in most places, AI is less regulated than the headlines suggest. If you read one more explainer on this topic, check its date first. In 2026, that alone tells you whether to trust it.

Frequently Asked Questions
How is AI regulated?
It depends on where you are. The EU has one binding law, the AI Act, which sorts AI uses into four risk tiers. The US has no comprehensive federal AI law, and the federal government is actively challenging state AI laws. China writes targeted rules, such as mandatory labels on AI-generated content. The UK has no AI-specific statute and relies on existing regulators applying five principles.
Is AI regulated in the US?
Only partly. There is no comprehensive federal AI law. A December 2025 executive order set up a Justice Department task force to challenge state AI laws and tied some federal broadband funding to state AI rules. State laws stay enforceable until courts or Congress act, but Colorado's AI Act stalled in 2026 after a lawsuit, federal intervention and a court-ordered stay.
What is the EU AI Act in simple terms?
It's the European Union's law on artificial intelligence, in force since 1 August 2024. It targets how AI gets used rather than the technology itself. It bans a short list of uses, puts the heaviest obligations on high-risk uses such as hiring and credit scoring, requires disclosure for chatbots and deepfakes, and leaves most everyday AI without specific rules.
What are the four risk levels in the EU AI Act?
Unacceptable risk (banned outright), high risk (allowed with strict obligations), transparency risk (chatbots, deepfakes and synthetic content must be disclosed or marked), and minimal or no risk, which covers the vast majority of AI systems in use in the EU and carries no rules under the Act.
When does the EU AI Act come into effect? Was it delayed?
It applies in phases. Bans took effect on 2 February 2025, general-purpose AI rules on 2 August 2025, and transparency rules in August 2026. The Digital Omnibus, in force since 27 July 2026, delayed high-risk obligations to 2 December 2027 for standalone systems and 2 August 2028 for AI built into regulated products.
Does the EU AI Act apply to companies outside Europe?
Yes. Article 2 covers providers and deployers based outside the EU where the output produced by the AI system is used in the Union. A company in the US or Asia whose system affects people in the EU can fall under the Act.
What AI practices are banned under the EU AI Act?
Banned practices include harmful manipulation, exploiting people's vulnerabilities, social scoring, predicting crime purely from profiling, untargeted scraping of facial images, biometric categorization by sensitive traits, emotion recognition at work and school, and most real-time remote biometric identification by police in public. From 2 December 2026, the ban also covers AI that generates child sexual abuse material or non-consensual intimate imagery.
Does the AI Act affect me as an ordinary user?
Yes. Since August 2026, chatbots must tell you that you're dealing with AI unless it's obvious, deployers must disclose deepfakes, and you must be told if a system is recognizing your emotions or categorizing you biometrically. The EU has also banned social scoring and several other practices since February 2025.
What are the penalties for breaking the EU AI Act?
Using a prohibited practice can cost up to 35 million euros or 7% of global annual turnover, whichever is higher. Breaching other obligations, including transparency duties, can cost up to 15 million euros or 3%. Supplying false or incomplete information can cost up to 7.5 million euros or 1%. Smaller companies pay the lower of the two amounts.
Which countries have AI laws?
The EU has the most comprehensive binding AI law, the AI Act. China has targeted rules, including AI content labeling measures in force since September 2025. In the US, individual states such as Colorado have passed AI laws, but there is no comprehensive federal statute. The UK has no AI-specific legislation and relies on existing regulators.