OLKERIAI News
← All AI news
AI Regulation Explained: How the World Is Governing Artificial Intelligence

Image: Olkeri

Policy & RegulationGlobal29 August 20265 min read

By Olkeri.space

AI Regulation Explained: How the World Is Governing Artificial Intelligence

A clear guide to how AI is being regulated worldwide, from the EU risk-based model to sectoral enforcement, and what organisations need to prepare for.

Read this story in: Français · Español · Deutsch

Artificial intelligence is moving from a largely unregulated technology to a governed one, and the rules are not arriving uniformly. Different jurisdictions have chosen fundamentally different approaches, and organisations operating across borders face several regimes at once.

This is a plain guide to how AI governance is actually structured and what it means in practice.

The European approach: comprehensive and risk-based:

The European Union produced the first comprehensive AI law, and its structure has become the reference point for the debate everywhere else.

The central idea is that obligations should scale with risk rather than applying uniformly to all AI. The framework sorts systems into tiers.

A small set of uses is prohibited outright, including social scoring by public authorities, exploiting vulnerabilities of specific groups, and certain forms of biometric surveillance and emotion inference in workplaces and schools.

A larger category is designated high risk, covering AI used in employment decisions, education access, essential services, credit, critical infrastructure, law enforcement and medical devices. These face substantive requirements: risk management, data governance, technical documentation, logging, human oversight, accuracy and security standards, and conformity assessment before deployment.

Systems that interact with people or generate content carry transparency duties: users must be told they are dealing with AI, and synthetic media must be labelled.

Everything else, which is most AI in commercial use, faces minimal obligations.

A separate track governs general-purpose models themselves, with documentation and copyright obligations for all such models and additional systemic-risk requirements for the largest.

Two features matter commercially. The law applies to anyone placing systems on the EU market regardless of where they are based, and penalties are set as a percentage of global turnover. That combination gives it reach well beyond Europe.

The American approach: sectoral and enforcement-driven:

The United States has no comprehensive federal AI statute, and the federal posture has shifted with administrations between emphasising safety obligations and emphasising innovation and deregulation.

This does not mean American AI is ungoverned. Existing law applies. Employment discrimination law covers discriminatory hiring algorithms whether the decision was made by a person or a model. Consumer protection authorities pursue deceptive claims about AI capabilities and unfair practices. Financial regulators require explainability in credit decisions. Health regulators approve AI medical devices. Sector regulators have been explicit that there is no AI exemption from the rules they already enforce.

The more active layer is state law. Several states have enacted AI-specific statutes covering automated decisions in employment and consequential services, requiring impact assessments, notice to affected individuals and, in some cases, the ability to appeal to a human. Comprehensive state privacy laws separately govern automated profiling. The practical result is a patchwork that national companies must navigate simultaneously.

China: control of content and algorithms:

China regulates AI actively, with an emphasis different from Western frameworks. Rules govern recommendation algorithms, synthetic media and generative AI services, requiring registration of algorithms with regulators, labelling of AI-generated content, security assessments before public release, and alignment of outputs with state content requirements. Compliance is a licensing prerequisite rather than a post-market obligation.

The rest of the world:

The United Kingdom has favoured guidance through existing sector regulators rather than a single statute, though the direction has been under review. Canada, Brazil, India, Japan, South Korea and others have developed frameworks at varying stages, generally borrowing the risk-tiering concept while adjusting scope. International bodies have produced principles and codes of conduct that shape norms without binding force.

For African markets, including Kenya and the wider region, data protection law is generally the operative constraint today, with AI-specific strategies and draft frameworks emerging. Organisations there most often encounter AI rules through export markets and through privacy regulators applying existing law to automated decisions.

What applies regardless of jurisdiction:

Beneath the differences, several obligations recur almost everywhere.

Personal data used to train or run AI remains subject to data protection law, including lawful basis, purpose limitation and individual rights. Automated decisions with significant effects on people typically require notice, an explanation and a route to human review. Discrimination law applies to outcomes irrespective of how they were produced. Sector rules for finance, healthcare, employment and safety-critical systems apply to AI within them. Consumer law prohibits overstating what a system can do.

An organisation that handles these well is substantially prepared for most emerging regimes.

Preparing without over-engineering:

Start with an inventory. Most organisations cannot say where AI is used across their operations, including embedded features in purchased software. You cannot govern what you have not catalogued.

Classify by consequence to people. A model scheduling maintenance and a model screening job applicants are not comparable, and effort should follow impact.

Document the systems that matter: purpose, data sources, limitations, testing performed, known failure modes and who is accountable. Most frameworks demand documentation, and reconstructing it later is far harder than maintaining it.

Ensure meaningful human oversight where decisions affect people. Meaningful means the reviewer has authority, information and time to disagree, not a formality.

Test for disparate outcomes across groups. This is where legal exposure is most concentrated and where problems are least visible without deliberate measurement.

The direction of travel:

Two things are reasonably clear. Regulation is converging on the principle that obligations scale with impact on people, and enforcement is shifting from announced frameworks to actual cases.

The organisations that will find this manageable are not the ones with the largest policy documents. They are the ones that know where AI is used in their business, understand which uses affect people's rights, and can produce evidence that those uses were tested and supervised.