Why This Matters
AI regulation will determine the shape of the industry for decades. The rules being written right now — in Brussels, Washington, Beijing, and state capitals across the US — will decide which models can be deployed, what disclosures are required, who is liable when AI systems cause harm, and whether open-weights development remains legal. For companies building AI products, regulatory compliance is becoming as significant a cost as compute. For companies deploying AI, the risk of building on a model or architecture that later becomes restricted or prohibited is existential.
The regulatory landscape is also deeply fragmented. The EU AI Act imposes risk-based classification with significant compliance obligations for “high-risk” systems. The US has no federal AI legislation but a patchwork of state-level bills, executive orders, and agency guidance that creates a confusing compliance environment. China regulates AI through a different paradigm entirely — requiring government registration of algorithms and content-level control over model outputs. These three approaches are incompatible in fundamental ways, creating a geopolitical divergence that will force multinational AI companies to maintain separate model variants and compliance regimes for different markets.
Understanding this landscape — what is law, what is proposed, what is being enforced, and what is likely to pass — is essential for anyone building, deploying, or investing in AI.
Current Landscape
As of mid-2026, the global AI regulatory picture can be summarized as follows: the EU is enforcing, the US is debating, and China is controlling.
European Union: The AI Act is live. The EU AI Act entered into force in August 2024, with enforcement provisions taking effect in stages through 2027. The first enforcement deadline — the ban on prohibited AI practices — took effect on February 2, 2025. This includes bans on social scoring systems, real-time biometric surveillance in public spaces (with narrow law enforcement exceptions), and AI systems that exploit vulnerabilities of specific groups. The compliance deadline for general-purpose AI (GPAI) model providers — including frontier labs like OpenAI, Anthropic, and Google that serve EU customers — arrived in August 2025. These providers must publish training data summaries, comply with copyright obligations, and implement risk management frameworks. The final compliance deadline for high-risk AI systems (medical devices, hiring tools, law enforcement applications) is August 2027.
United States: Fragmented and gridlocked. Congress has failed to pass any comprehensive federal AI legislation. The bipartisan AI Research, Innovation, and Accountability Act, introduced in late 2025, stalled in committee. The AI Disclosure Act, which would require labeling of AI-generated content, has bipartisan support but has not reached a floor vote. In the absence of federal action, regulation has devolved to the states. Over 45 state-level AI bills are currently in various stages of progress. Colorado’s AI Consumer Protections Act (SB 24-205), which took effect in February 2026, is the most significant — it requires deployers of “high-risk” AI systems to conduct impact assessments and provide consumers with disclosure and opt-out rights. California’s SB 1047, which would have imposed liability on developers of frontier AI models, was vetoed by Governor Newsom in September 2024 but has been reintroduced in modified form.
China: Algorithm registration and content control. China’s Cyberspace Administration (CAC) requires all AI models available to the public to be registered in the national algorithm registry. As of May 2026, over 300 models have been registered. The registration process includes content safety reviews — models must demonstrate alignment with Chinese government content policies before deployment. China’s approach is less about safety in the Western sense and more about content control and social stability. The Interim Measures for the Management of Generative AI Services, effective since August 2023, require that AI-generated content “reflect core socialist values.” This creates a fundamentally different regulatory paradigm that makes Chinese AI models unusable in Western markets and vice versa.
United Kingdom: Light-touch and pro-innovation. The UK has deliberately positioned itself as an alternative to the EU’s prescriptive approach. Rather than comprehensive legislation, the UK relies on existing regulators — the FCA for financial services, the MHRA for healthcare, the ICO for data protection — to apply AI-specific guidance within their existing frameworks. The UK AI Safety Institute (AISI), established after the November 2023 AI Safety Summit at Bletchley Park, conducts pre-deployment safety evaluations of frontier models on a voluntary basis. AISI has published evaluations of models from OpenAI, Anthropic, Google, and Meta. The UK approach bets that flexibility and speed-to-market will attract AI investment that the EU’s regulatory burden pushes away.
Key Regulatory Frameworks Compared
| Dimension | EU AI Act | US (Federal + State) | China | UK |
|---|---|---|---|---|
| Approach | Risk-based classification | Patchwork, sector-specific | Registration + content control | Principles-based, regulator-led |
| Scope | All AI systems in EU market | Varies by state/agency | Public-facing generative AI | Voluntary for frontier models |
| Enforcement | EU AI Office + national authorities | FTC, state AGs, sector regulators | CAC, MIIT | Existing regulators |
| Penalties | Up to 7% global revenue | Varies; mostly civil | License revocation, fines | Existing regulatory penalties |
| Open-source treatment | Partial exemption for open-weights | Generally unregulated | Must register if public-facing | Not specifically addressed |
| Status | Enforcing (staged through 2027) | No comprehensive federal law | Enforcing | Voluntary framework |
Key Players
EU Commission and the AI Office. The European AI Office, established within the Commission, is the primary enforcement body for the AI Act’s provisions on general-purpose AI models. It has the power to request information from model providers, conduct evaluations, and impose fines up to 3% of global revenue (or 7% for violations of the prohibited practices provisions). The AI Office issued its first formal information requests to frontier model providers in Q1 2026, asking for details on training data, compute used, and safety evaluation results.
US Federal Trade Commission (FTC). In the absence of federal AI legislation, the FTC has become the de facto US AI regulator through its existing authority over unfair and deceptive trade practices. The FTC has opened investigations into AI acqui-hires (questioning whether the Inflection, Adept, and Character.ai deals constituted unreported mergers), issued guidance on AI-generated deceptive content, and signaled willingness to take enforcement action against companies making false claims about AI capabilities. Chair Lina Khan’s departure in early 2025 shifted the agency’s posture somewhat, but investigations opened under her tenure continue.
US Congress. The Senate AI Caucus, co-chaired by Senators Schumer and Rounds, has held over 20 “AI Insight Forums” but produced no legislation. The House Science Committee has advanced several narrower bills — on AI in government, AI workforce training, and AI transparency — but none has reached the floor for a full vote. The fundamental disagreement is between members who want to regulate AI developers (imposing liability on model creators) and those who want to regulate AI deployers (imposing obligations on companies that use AI systems in specific contexts). This disagreement has prevented any comprehensive bill from advancing.
China’s Cyberspace Administration (CAC). The CAC operates with speed and authority that Western regulators lack. New regulations can move from proposal to enforcement in months rather than years. The CAC’s algorithm registry gives the Chinese government a complete inventory of all AI models deployed to Chinese citizens, along with technical details about their capabilities and limitations. This level of visibility and control has no equivalent in any Western jurisdiction.
State Attorneys General. In the US, state AGs have emerged as significant AI enforcement actors. The New York AG’s investigation into AI-driven discrimination in insurance pricing, the Texas AG’s action against AI-generated deepfakes, and the California AG’s enforcement of the CCPA’s AI-related provisions all demonstrate that state-level enforcement is filling the federal vacuum.
What We’re Tracking
JustSaid monitors AI regulatory developments through systematic tracking of primary sources across multiple jurisdictions.
Legislative tracking. Every AI-related bill introduced in the US Congress, EU Parliament, UK Parliament, and major state legislatures is captured with its text, sponsors, committee assignments, and progress. The pipeline currently tracks 45+ active US state bills, 12 pending EU implementing regulations, and 8 UK regulatory guidance documents.
Enforcement actions. FTC investigations, EU AI Office information requests, state AG actions, and CAC enforcement decisions are tracked with full documentation. Enforcement actions often reveal regulatory priorities more clearly than legislation — what agencies choose to investigate signals what they care about enforcing.
Compliance deadlines. The staggered enforcement timeline of the EU AI Act creates a rolling series of compliance deadlines through 2027. Each deadline triggers obligations for specific categories of AI systems and providers. The tracker maintains a forward-looking calendar of upcoming deadlines and the companies they affect.
Industry lobbying and public comments. When major AI companies file public comments on proposed regulations — as OpenAI, Google, Meta, and Anthropic did during the EU AI Act’s implementing regulation process — those positions are captured and analyzed. The gap between a company’s public safety rhetoric and its lobbying positions is often revealing.
Recent Developments
May 2026: EU AI Office issues first formal guidance on GPAI model compliance. The guidance clarifies what training data documentation is required, how systemic risk assessments should be conducted, and what safety evaluation protocols are acceptable. Frontier model providers have 6 months to demonstrate compliance.
April 2026: Colorado AI Act takes effect. The first comprehensive US state AI law enters enforcement, requiring impact assessments for high-risk AI systems in employment, lending, insurance, and housing. Early compliance reports suggest significant confusion among deployers about what constitutes a “high-risk” system.
March 2026: California reintroduces frontier model liability bill. A modified version of SB 1047, renamed the California AI Accountability Act, is introduced with narrower scope — focusing on models trained with more than 10^26 FLOPs and imposing liability only for “critical harms” including mass casualties and infrastructure attacks. The bill has support from Anthropic and opposition from Meta and Google.
February 2026: FTC publishes staff report on AI acqui-hires. The report concludes that several recent AI talent acquisitions — including Microsoft-Inflection and Amazon-Adept — were structured to avoid merger review requirements and may constitute unfair methods of competition. No enforcement action was announced, but the report signals potential future challenges.
January 2026: UK AISI publishes frontier model evaluation framework. The framework establishes standardized testing protocols for dangerous capabilities including bioweapon synthesis, cyberattack generation, and autonomous replication. All major frontier labs have agreed to submit models for evaluation, though participation remains voluntary.
Active US State AI Bills
| State | Bill | Focus | Status |
|---|---|---|---|
| Colorado | SB 24-205 | High-risk AI system governance | Enacted, effective Feb 2026 |
| California | AI Accountability Act | Frontier model developer liability | Committee |
| Texas | HB 2060 | AI-generated deepfake prohibitions | Enacted |
| Illinois | AI Video Interview Act (amended) | Employment AI disclosure | Enacted |
| New York | S.7623 | Automated employment decision tools | Committee |
| Connecticut | SB 2 | AI risk assessments, consumer rights | Passed Senate |
| Virginia | HB 2094 | High-risk AI in government | Committee |
| Washington | SB 5838 | AI transparency in public services | Committee |
Outlook
The second half of 2026 will be a pivotal period for AI regulation globally.
The EU will become the de facto global standard. Just as GDPR became the global baseline for data protection, the EU AI Act’s compliance requirements will set the floor for AI governance worldwide. Companies that want to serve EU customers — which includes every major AI lab — must comply, and most will choose to implement EU-standard practices globally rather than maintaining separate compliance regimes. This “Brussels Effect” will shape AI governance even in jurisdictions that choose not to legislate.
US federal legislation remains unlikely before 2027. The combination of Congressional gridlock, election-year politics, and fundamental disagreement about the right regulatory approach makes comprehensive federal AI legislation improbable in 2026. The patchwork of state laws will continue to expand, creating increasing compliance complexity for companies operating nationally.
Open-weights regulation is the next battlefront. The question of whether and how to regulate open-weights AI models — which once released cannot be recalled or controlled — is the most contentious issue in AI policy. The EU AI Act provides partial exemptions for open-source models, but the exemption’s scope is contested. California’s reintroduced liability bill would apply to open-weights models above a compute threshold. Meta and the broader open-source community argue that regulating open weights will chill innovation and concentrate power among closed-model providers. Safety advocates argue that unrestricted release of increasingly capable models creates unacceptable risks. This debate will intensify as open-weights models approach frontier capability.
Enforcement will matter more than legislation. The laws on the books — the EU AI Act, Colorado’s law, the FTC’s existing authority — are sufficient to generate significant enforcement actions. The question is whether regulators will use them aggressively. The EU AI Office’s willingness to impose meaningful fines, the FTC’s appetite for challenging AI acqui-hires, and state AGs’ enforcement priorities will determine whether AI regulation has real teeth or remains largely theoretical.
Frequently Asked Questions
Does the EU AI Act apply to companies based in the US? Yes. The AI Act applies to any provider that places an AI system on the EU market or whose AI system’s output is used in the EU, regardless of where the provider is established. This means OpenAI, Anthropic, Google, Meta, and any other AI company serving EU customers must comply with the Act’s requirements.
What happens if a company violates the EU AI Act? Fines can reach up to 35 million euros or 7% of global annual revenue, whichever is higher, for violations of the prohibited practices provisions. For other violations, fines can reach 15 million euros or 3% of global revenue. The EU AI Office and national authorities have investigative powers including information requests, audits, and access to source code and training data.
Are open-source AI models regulated? Under the EU AI Act, open-source GPAI models receive a partial exemption from some transparency and documentation requirements, provided they are released under an approved open-source license and do not pose systemic risk. However, models classified as posing “systemic risk” (generally those trained with more than 10^25 FLOPs) must comply with additional obligations regardless of whether they are open-source. In the US, open-source models are currently unregulated at the federal level, though California’s proposed legislation would impose liability on developers of frontier open-weights models.
How does China’s AI regulation differ from the EU and US approaches? China’s approach prioritizes content control and social stability over the safety and rights-based frameworks used in the West. Chinese regulations require all public-facing AI models to be registered, mandate that outputs align with government content policies, and give regulators the authority to revoke deployment licenses. The Chinese system provides the government with comprehensive visibility into the AI ecosystem — a level of control that would be unconstitutional in the US and incompatible with EU fundamental rights frameworks.