9 min read

AI regulation isn't one law. It's a patchwork of federal guidance, state statutes, and international regimes, and it's moving faster than most compliance teams can track. In 2026, the United States is fighting over whether states can regulate AI at all, the EU AI Act has moved from theory to enforcement, and China continues to layer new rules onto its generative AI, deep synthesis, and facial recognition regimes.
This guide breaks down where AI regulation stands today in the US, EU, and China: what's already enforceable, and what's still ahead. If you're building or scaling AI initiatives, these laws aren't optional reading. They're the guardrails your data has to clear before your next launch.
For a primer on the basics, see our guide to what encoded AI governance means in practice.
The US still doesn't have a comprehensive federal AI law. What it has instead is a fast-moving mix of state statutes, agency enforcement, and an active, unresolved fight over who gets to regulate AI at all.
For years, federal AI policy in the US was mostly guidance, not law. The White House's 2022 Blueprint for an AI Bill of Rights laid out voluntary principles for fairness, transparency, and privacy in automated systems. It was never binding, and it's now archived material from the prior administration rather than active federal policy.
That shift became explicit in 2025. The current administration rescinded the prior administration's AI executive order and replaced it with an approach focused on removing barriers to AI development. In December 2025, a new executive order went further: it directed the Commerce Department to identify “onerous” state AI laws, created an AI Litigation Task Force to challenge state statutes in court, and proposed tying federal broadband funding to states limiting their own AI regulation.
Here's the part that matters for compliance teams: the order doesn't preempt state law on its own. Preemption requires either a court ruling or an act of Congress, and Congress has twice declined to pass broad preemption language. Until that changes, state AI laws remain enforceable, and companies that pause compliance while waiting for federal clarity are taking on real exposure in the meantime.

A handful of state laws are doing most of the regulatory work right now:
This law requires deployers of high-risk AI systems, those making consequential decisions in employment, lending, housing, healthcare, insurance, education, government services, and legal services, to run impact assessments, maintain a risk management program, and report algorithmic discrimination to the attorney general within 90 days of discovery. Its enforcement date was pushed from February 1 to June 30, 2026
Having taken effect on January 1, 2026, this law takes an intent-based approach, prohibiting AI built to incite self-harm, harm others, or facilitate illegal discrimination, and it includes a safe harbor for organizations that substantially comply with the NIST AI Risk Management Framework
This law targets frontier model developers directly, requiring safety protocols and incident reporting for models built above a defined compute threshold, with civil penalties of up to $1 million per violation
The Illinois Artificial Intelligence Video Interview Act (AIVIA), passed in 2019 and enacted in 2020, is a pioneering piece of legislation that directly addresses the use of AI during the hiring process. This law requires that employers inform applicants if they intend to use AI systems when evaluating video interviews—ensuring that candidates are aware of their rights and can consent to the use of AI prior to the interview.
The AIVIA also outlines protocols for handling video interview data, including its destruction within 30 days upon request. An early effort to shape the ethical use of AI in employment, this law will likely set a precedent for future AI-related employment legislation.
Going into effect on July 5, 2023, New York’s AI Bias Law requires that companies conduct regular audits of their hiring algorithms for bias. These audits must look for bias, both intentional and unintentional, that could discriminate against protected classes.
The law also requires that companies publish the findings of these audits, in order to support greater transparency about how AI tools are used during the hiring process. By encouraging transparency and accountability, New York's AI bias law aims to minimize the perpetuation of systematic bias and inequality in employment processes through the use of AI.
While requirements vary from state to state, most US state privacy laws on the books today have stipulations around the use of automated decision making and profiling. Most states require that companies disclose when they are using AI for automated decision-making processes and give consumers a way to opt-out of this type of data processing.
Some states go even further, requiring companies to disclose the logic their AI systems use when making decisions and conduct assessments on how these processes may impact consumers. This additional transparency allows consumers to understand how decisions about them are being made and can potentially challenge them if they appear unfair or discriminatory.
These privacy laws demonstrate a significant step towards holding companies accountable for their use of AI and can serve as a model for comprehensive federal legislation in the future. However, as AI continues to evolve rapidly, there is a need for ongoing evaluation of these laws to ensure that they adequately protect consumers and keep pace with technological advancements.
Introduced in October 2022, the AI Bill of Rights represents a significant stride towards the ethical use of artificial intelligence in the United States. This document, supported by the Biden administration, lays out a set of voluntary commitments for companies involved in the development, deployment, and management of AI technologies.
The AI Bill of Rights’ goal is to ensure fairness, inclusivity, and accountability in AI systems: emphasizing the principles of transparency and privacy, as well as advocating for users' rights to know when they are interacting with AI systems and how their personal information is being used.
Copyright law is still catching up to generative AI. In August 2023, a federal judge ruled that AI-generated artwork without human creative input can't be copyrighted, a case brought against the US Copyright Office over images produced entirely by an algorithm.
That principle, that copyright protects human authorship rather than machine output, has held up in the cases that followed, even as questions about AI training data and fair use continue working their way through the courts.
The FTC has kept up its scrutiny of AI-powered products, focusing on false or misleading claims about what a company's AI can actually do and on data practices that don't hold up to the promises made to consumers.
That enforcement authority under Section 5 of the FTC Act is also, notably, part of the current federal preemption debate. Whatever happens there, the underlying standard hasn't changed: if you make a claim about your AI, you need to be able to back it up.

The EU AI Act is the most comprehensive AI law in the world, and unlike the US patchwork, it's a single risk-based framework that applies across all 27 member states. It sorts AI systems into four risk tiers:
The law also established a European Artificial Intelligence Board to help apply the regulation consistently across the EU.
The EU AI Act has moved in phases, and several are already in force. Bans on unacceptable-risk systems took effect in February 2025. Obligations for general-purpose AI model providers, technical documentation, training-content summaries, and copyright compliance, took effect in August 2025.
Transparency requirements under Article 50 followed in August 2026, along with enforcement authority for the EU AI Office and penalties of up to €15 million or 3% of global turnover.
High-risk obligations are next: stand-alone high-risk systems must comply by December 2027, and high-risk systems embedded in regulated products follow in August 2028.
A July 2026 amendment, the Digital Omnibus, locked in those dates and gave small and mid-cap companies lighter compliance requirements, replacing the more conditional timeline the law originally set.

China's approach to AI regulation starts from a different premise than the US or EU: promote AI innovation while keeping the state firmly in control of it. That shows up in policy documents like the New Generation Artificial Intelligence Development Plan, which sets out China's ambition to lead globally in AI by 2030, and it shows up in how China regulates: one discrete rule at a time, rather than one horizontal law.
China's regulatory approach reflects its own political and economic priorities, but the underlying discipline, that every algorithm affecting consumers needs a clear, auditable basis for what it's doing, is one every AI regulation regime shares.
Three different regulatory philosophies, one shared requirement: prove what your AI systems are allowed to do with customer data, and prove it before something goes wrong, not after.
That's hard when the rules keep changing. A system built to Colorado's original timeline needed updating when the enforcement date moved. A model that sits in the EU's minimal-risk tier today could land in the high-risk tier tomorrow if its use case shifts. Do Not Train and other AI-specific opt-outs vary from state to state and country to country, but the customer's expectation, did you honor what I asked, doesn't vary at all.
Encoding those rules once, so every system and every new jurisdiction inherits them automatically, is the only version of this that scales. That's a different question than “do we have a policy?” It's “can our systems prove, record by record, that the policy held?”
Yes, but not through a single federal law. The US regulates AI through a mix of state statutes (Colorado, Texas, California, Illinois, and others), agency enforcement led primarily by the FTC, and sector-specific rules, alongside an active, unresolved fight over whether the federal government can preempt state AI laws.
The EU AI Act regulates AI systems based on their risk to health, safety, and fundamental rights. It bans a small set of unacceptable-risk uses, sets strict requirements for high-risk systems in areas like employment and biometric identification, requires transparency for limited-risk systems like chatbots, and leaves minimal-risk systems largely unregulated.
China regulates AI through targeted rules addressing specific technologies and use cases, including recommendation algorithms, deep synthesis, facial recognition, and, as of 2026, anthropomorphic AI services, rather than through one comprehensive AI law.
Not automatically. The executive branch has directed agencies to challenge state AI laws in court and has proposed conditioning federal funding on states limiting their own regulation, but preemption requires a court ruling or congressional action. Congress has declined to pass broad preemption language twice. Until that changes, state AI laws remain enforceable.
That's an active policy debate rather than a settled question. Supporters of regulation point to risks around bias, safety, and misuse; opponents point to the risk of slowing innovation and fragmenting compliance across jurisdictions. What's not in debate: enterprises operating today already have to comply with the AI laws on the books in the US, EU, China, and a growing list of other jurisdictions.
Transcend is the “Can I use this data?” platform: the real-time data governance and decision layer that helps enterprises encode business policy, regulatory context, and customer permissions directly into the systems that process customer data.