9 min read

AI regulation isn't one law. It's a patchwork of federal guidance, state statutes, and international regimes, and it's moving faster than most compliance teams can track. In 2026, the United States is fighting over whether states can regulate AI at all, the EU AI Act has moved from theory to enforcement, and China continues to layer new rules onto its generative AI, deep synthesis, and facial recognition regimes.
This guide breaks down where AI regulation stands today in the US, EU, and China: what's already enforceable, and what's still ahead. If you're building or scaling AI initiatives, these laws aren't optional reading. They're the guardrails your data has to clear before your next launch.
For a primer on the basics, see our guide to what AI governance actually means in practice.
The US still doesn't have a comprehensive federal AI law. What it has instead is a fast-moving mix of state statutes, agency enforcement, and an active, unresolved fight over who gets to regulate AI at all.
For years, federal AI policy in the US was mostly guidance, not law. The White House's 2022 Blueprint for an AI Bill of Rights laid out voluntary principles for fairness, transparency, and privacy in automated systems. It was never binding, and it's now archived material from the prior administration rather than active federal policy.
That shift became explicit in 2025. The current administration rescinded the prior administration's AI executive order and replaced it with an approach focused on removing barriers to AI development. In December 2025, a new executive order went further: it directed the Commerce Department to identify “onerous” state AI laws, created an AI Litigation Task Force to challenge state statutes in court, and proposed tying federal broadband funding to states limiting their own AI regulation.
Here's the part that matters for compliance teams: the order doesn't preempt state law on its own. Preemption requires either a court ruling or an act of Congress, and Congress has twice declined to pass broad preemption language. Until that changes, state AI laws remain enforceable, and companies that pause compliance while waiting for federal clarity are taking on real exposure in the meantime.

A handful of state laws are doing most of the regulatory work right now:
Most US state privacy laws also layer on their own automated decision-making and profiling requirements, typically a disclosure obligation and an opt-out right for consumers. Some go further, requiring companies to explain the logic behind an automated decision. None of this is going away. If anything, it's compounding: every new state that passes its own AI law is one more jurisdiction your systems need to already be able to answer for.
81% of enterprises delayed an AI initiative in the past year, and most say data governance issues are why, not a lack of ambition or technology. See what's actually stalling AI programs, and what's fixing it.
The hidden force behind every stalled AI initiativeCopyright law is still catching up to generative AI. In August 2023, a federal judge ruled that AI-generated artwork without human creative input can't be copyrighted, a case brought against the US Copyright Office over images produced entirely by an algorithm.
That principle, that copyright protects human authorship rather than machine output, has held up in the cases that followed, even as questions about AI training data and fair use continue working their way through the courts.
The FTC has kept up its scrutiny of AI-powered products, focusing on false or misleading claims about what a company's AI can actually do and on data practices that don't hold up to the promises made to consumers.
That enforcement authority under Section 5 of the FTC Act is also, notably, part of the current federal preemption debate. Whatever happens there, the underlying standard hasn't changed: if you make a claim about your AI, you need to be able to back it up.

The EU AI Act is the most comprehensive AI law in the world, and unlike the US patchwork, it's a single risk-based framework that applies across all 27 member states. It sorts AI systems into four risk tiers:
The law also established a European Artificial Intelligence Board to help apply the regulation consistently across the EU.
The EU AI Act has moved in phases, and several are already in force. Bans on unacceptable-risk systems took effect in February 2025. Obligations for general-purpose AI model providers, technical documentation, training-content summaries, and copyright compliance, took effect in August 2025.
Transparency requirements under Article 50 followed in August 2026, along with enforcement authority for the EU AI Office and penalties of up to €15 million or 3% of global turnover.
High-risk obligations are next: stand-alone high-risk systems must comply by December 2027, and high-risk systems embedded in regulated products follow in August 2028.
A July 2026 amendment, the Digital Omnibus, locked in those dates and gave small and mid-cap companies lighter compliance requirements, replacing the more conditional timeline the law originally set.
You documented the policy. Can you prove it was enforced? See how privacy and legal teams turn EU AI Act and state AI law obligations into real-time, audit-ready enforcement, instead of a manual review before every launch.
Privacy & Legal leaders
China's approach to AI regulation starts from a different premise than the US or EU: promote AI innovation while keeping the state firmly in control of it. That shows up in policy documents like the New Generation Artificial Intelligence Development Plan, which sets out China's ambition to lead globally in AI by 2030, and it shows up in how China regulates: one discrete rule at a time, rather than one horizontal law.
China's regulatory approach reflects its own political and economic priorities, but the underlying discipline, that every algorithm affecting consumers needs a clear, auditable basis for what it's doing, is one every AI regulation regime shares.
Three different regulatory philosophies, one shared requirement: prove what your AI systems are allowed to do with customer data, and prove it before something goes wrong, not after.
That's hard when the rules keep changing. A system built to Colorado's original timeline needed updating when the enforcement date moved. A model that sits in the EU's minimal-risk tier today could land in the high-risk tier tomorrow if its use case shifts. Do Not Train and other AI-specific opt-outs vary from state to state and country to country, but the customer's expectation, did you honor what I asked, doesn't vary at all.
Encoding those rules once, so every system and every new jurisdiction inherits them automatically, is the only version of this that scales. That's a different question than “do we have a policy?” It's “can our systems prove, record by record, that the policy held?”
Who owns AI governance at your company? Get the RACI framework for AI governance and give IT, legal, marketing, and leadership one clear map of who's responsible for what, across every jurisdiction you operate in.
Launch faster with the RACI Framework for AI GovernanceYes, but not through a single federal law. The US regulates AI through a mix of state statutes (Colorado, Texas, California, Illinois, and others), agency enforcement led primarily by the FTC, and sector-specific rules, alongside an active, unresolved fight over whether the federal government can preempt state AI laws.
The EU AI Act regulates AI systems based on their risk to health, safety, and fundamental rights. It bans a small set of unacceptable-risk uses, sets strict requirements for high-risk systems in areas like employment and biometric identification, requires transparency for limited-risk systems like chatbots, and leaves minimal-risk systems largely unregulated.
China regulates AI through targeted rules addressing specific technologies and use cases, including recommendation algorithms, deep synthesis, facial recognition, and, as of 2026, anthropomorphic AI services, rather than through one comprehensive AI law.
Not automatically. The executive branch has directed agencies to challenge state AI laws in court and has proposed conditioning federal funding on states limiting their own regulation, but preemption requires a court ruling or congressional action. Congress has declined to pass broad preemption language twice. Until that changes, state AI laws remain enforceable.
That's an active policy debate rather than a settled question. Supporters of regulation point to risks around bias, safety, and misuse; opponents point to the risk of slowing innovation and fragmenting compliance across jurisdictions. What's not in debate: enterprises operating today already have to comply with the AI laws on the books in the US, EU, China, and a growing list of other jurisdictions.
Ready to make sense of the patchwork? Talk to a Transcend solutions expert about turning AI governance policy into infrastructure your systems can prove, wherever you operate.
Contact usTranscend is the “Can I use this data?” platform: the real-time data governance and decision layer that helps enterprises encode business policy, regulatory context, and customer permissions directly into the systems that process customer data.
AI Governance encodes Do Not Train enforcement, purpose limits, and agent permissions into every system your models touch. Policy Engine combines business policy, regulatory context, and customer preferences into one real-time decision, so every system already knows what it's allowed to do before it acts. Consent & Preference Management captures consent once and propagates it everywhere. Data Discovery & Classification maps personal data across your stack, down to the column level. DSR Automation documents every privacy request and proves every outcome, and Assessments streamlines DPIAs, TIAs, and AI risk reviews.
Read Transcend's Data Practices and Privacy Policy.