
Image: Olkeri
By Olkeri.space
How AI Regulation Differs Around the World, and Why It Matters to You
The EU regulates comprehensively, the US enforces sectorally, China licenses content. Here is what each means in practice.
Read this story in: Deutsch · Español · Français
Three major approaches to regulating artificial intelligence have emerged, and most other countries are borrowing from one of them. The differences are substantive and determine what companies can build and deploy.
The European model: comprehensive and risk-based:
The European Union legislated broadly, sorting AI systems by risk. Some uses are prohibited outright. A defined set of high-risk applications, including employment, education access, credit, essential services, law enforcement and critical infrastructure, carries substantial obligations: risk management, data governance, documentation, logging, human oversight and conformity assessment before deployment.
Systems interacting with people must disclose that they are AI, and synthetic content must be labelled. General-purpose models carry their own documentation and copyright obligations, with additional requirements for the largest.
Two features give it global reach: it applies to anyone placing systems on the EU market regardless of where they are based, and penalties scale with global turnover.
The American model: sectoral and enforcement-led:
The United States has no comprehensive federal AI statute, and federal posture shifts between administrations. Existing law applies regardless: employment discrimination law covers biased hiring algorithms, consumer protection law covers deceptive AI claims, financial regulation requires explainable credit decisions, and health regulators approve AI medical devices.
The more active layer is state law. Several states regulate automated decisions in employment and consequential services, requiring impact assessments and notice. Comprehensive state privacy laws govern automated profiling. California's rules function as de facto national standards because companies rarely build state-specific products.
The Chinese model: licensing and content control:
China regulates actively with different priorities. Rules govern recommendation algorithms, synthetic media and generative AI services, requiring registration with authorities, labelling of AI-generated content, security assessment before public release, and alignment with content requirements.
Compliance precedes market entry rather than following it.
Everyone else:
The United Kingdom favoured sector regulators applying existing rules rather than a single statute. Canada, Brazil, South Korea, Japan and others have frameworks at various stages, generally borrowing risk-tiering while adjusting scope. Singapore emphasises practical governance toolkits over binding rules. Most African, Latin American and Asian jurisdictions regulate AI primarily through data protection law.
What applies almost everywhere:
Beneath the differences, several obligations recur globally. Personal data used in training or inference remains subject to privacy law. Consequential automated decisions about people typically require notice, explanation and a route to human review. Discrimination law applies to outcomes however produced. Sector rules in finance, health and safety-critical systems apply to AI within them. Consumer law prohibits overstating capabilities.
An organisation that handles these well is broadly prepared for most regimes.
What it means practically:
For a company operating internationally, the binding constraint is usually the strictest applicable regime, which for most is the European framework combined with the most demanding American state rules.
The practical implications are: know where AI is used across your operations, classify by impact on people, document the systems that matter, ensure meaningful human oversight where decisions affect rights, and test for disparate outcomes.
That last point is where legal exposure concentrates and where problems are invisible without deliberate measurement.
The direction:
Regulation is converging on the principle that obligations should scale with impact on people, and enforcement is moving from announced frameworks to actual cases. The organisations that will find this manageable are those with an inventory and evidence, not those with the longest policy documents.