Global AI Regulation in 2026: US, EU & China Guide

9 min read

Digital scales of justice on a glowing circuit board background with "AI GOVERNANCE" text.

At a glance

AI regulation isn't one law. It's a patchwork of federal guidance, state statutes, and international regimes, and it's moving faster than most compliance teams can track. In 2026, the United States is fighting over whether states can regulate AI at all, the EU AI Act has moved from theory to enforcement, and China continues to layer new rules onto its generative AI, deep synthesis, and facial recognition regimes.

This guide breaks down where AI regulation stands today in the US, EU, and China: what's already enforceable, and what's still ahead. If you're building or scaling AI initiatives, these laws aren't optional reading. They're the guardrails your data has to clear before your next launch.

For a primer on the basics, see our guide to what AI governance actually means in practice.

AI regulation in the United States

The US still doesn't have a comprehensive federal AI law. What it has instead is a fast-moving mix of state statutes, agency enforcement, and an active, unresolved fight over who gets to regulate AI at all.

Federal policy: From voluntary guardrails to a fight over state authority

For years, federal AI policy in the US was mostly guidance, not law. The White House's 2022 Blueprint for an AI Bill of Rights laid out voluntary principles for fairness, transparency, and privacy in automated systems. It was never binding, and it's now archived material from the prior administration rather than active federal policy.

That shift became explicit in 2025. The current administration rescinded the prior administration's AI executive order and replaced it with an approach focused on removing barriers to AI development. In December 2025, a new executive order went further: it directed the Commerce Department to identify “onerous” state AI laws, created an AI Litigation Task Force to challenge state statutes in court, and proposed tying federal broadband funding to states limiting their own AI regulation.

Here's the part that matters for compliance teams: the order doesn't preempt state law on its own. Preemption requires either a court ruling or an act of Congress, and Congress has twice declined to pass broad preemption language. Until that changes, state AI laws remain enforceable, and companies that pause compliance while waiting for federal clarity are taking on real exposure in the meantime.

The USA flag waving in front of blue background

State AI laws to know

A handful of state laws are doing most of the regulatory work right now:

  • Colorado: The Colorado AI Act (SB 24-205) requires deployers of high-risk AI systems, those making consequential decisions in employment, lending, housing, healthcare, insurance, education, government services, and legal services, to run impact assessments, maintain a risk management program, and report algorithmic discrimination to the attorney general within 90 days of discovery. Its enforcement date was pushed from February 1 to June 30, 2026
  • Texas: The Responsible Artificial Intelligence Governance Act (TRAIGA) took effect January 1, 2026. It takes an intent-based approach, prohibiting AI built to incite self-harm, harm others, or facilitate illegal discrimination, and it includes a safe harbor for organizations that substantially comply with the NIST AI Risk Management Framework
  • California: SB 53 targets frontier model developers directly, requiring safety protocols and incident reporting for models built above a defined compute threshold, with civil penalties of up to $1 million per violation
  • Illinois and New York: Illinois' Artificial Intelligence Video Interview Act requires employer disclosure before using AI to evaluate video interviews. New York City's Local Law 144 requires annual bias audits of automated employment decision tools, building on the law that first put algorithmic hiring audits on the books

Most US state privacy laws also layer on their own automated decision-making and profiling requirements, typically a disclosure obligation and an opt-out right for consumers. Some go further, requiring companies to explain the logic behind an automated decision. None of this is going away. If anything, it's compounding: every new state that passes its own AI law is one more jurisdiction your systems need to already be able to answer for.

81% of enterprises delayed an AI initiative in the past year, and most say data governance issues are why, not a lack of ambition or technology. See what's actually stalling AI programs, and what's fixing it.

The hidden force behind every stalled AI initiative

Copyright law is still catching up to generative AI. In August 2023, a federal judge ruled that AI-generated artwork without human creative input can't be copyrighted, a case brought against the US Copyright Office over images produced entirely by an algorithm.

That principle, that copyright protects human authorship rather than machine output, has held up in the cases that followed, even as questions about AI training data and fair use continue working their way through the courts.

AI and the Federal Trade Commission

The FTC has kept up its scrutiny of AI-powered products, focusing on false or misleading claims about what a company's AI can actually do and on data practices that don't hold up to the promises made to consumers.

That enforcement authority under Section 5 of the FTC Act is also, notably, part of the current federal preemption debate. Whatever happens there, the underlying standard hasn't changed: if you make a claim about your AI, you need to be able to back it up.

The EU flag waving in the sky with sunlight passing through

The EU AI Act

The EU AI Act is the most comprehensive AI law in the world, and unlike the US patchwork, it's a single risk-based framework that applies across all 27 member states. It sorts AI systems into four risk tiers:

  • Unacceptable risk: AI systems that manipulate human behavior, exploit vulnerable groups, or enable social scoring. These are banned outright
  • High risk: AI systems used in regulated products like medical devices and vehicles, or in sensitive contexts such as biometric identification, employment, education, critical infrastructure, and law enforcement. These systems must meet requirements around risk management, data quality, documentation, human oversight, and security before they reach the market
  • Limited risk: Chatbots and systems that generate or manipulate content, which must meet transparency requirements so people know they're interacting with AI
  • Minimal risk: Everything else, including tools like spam filters, which can operate with no additional obligations

The law also established a European Artificial Intelligence Board to help apply the regulation consistently across the EU.

Where enforcement stands in 2026

The EU AI Act has moved in phases, and several are already in force. Bans on unacceptable-risk systems took effect in February 2025. Obligations for general-purpose AI model providers, technical documentation, training-content summaries, and copyright compliance, took effect in August 2025.

Transparency requirements under Article 50 followed in August 2026, along with enforcement authority for the EU AI Office and penalties of up to €15 million or 3% of global turnover.

High-risk obligations are next: stand-alone high-risk systems must comply by December 2027, and high-risk systems embedded in regulated products follow in August 2028.

A July 2026 amendment, the Digital Omnibus, locked in those dates and gave small and mid-cap companies lighter compliance requirements, replacing the more conditional timeline the law originally set.

You documented the policy. Can you prove it was enforced? See how privacy and legal teams turn EU AI Act and state AI law obligations into real-time, audit-ready enforcement, instead of a manual review before every launch.

Privacy & Legal leaders
The chinese flag waving in front of blue background

AI regulation in China

China's approach to AI regulation starts from a different premise than the US or EU: promote AI innovation while keeping the state firmly in control of it. That shows up in policy documents like the New Generation Artificial Intelligence Development Plan, which sets out China's ambition to lead globally in AI by 2030, and it shows up in how China regulates: one discrete rule at a time, rather than one horizontal law.

  • AI-driven recommendation algorithms: Providers must limit discrimination, mitigate the spread of harmful content, and address exploitative conditions for gig workers whose work is directed by algorithms. Consumers have the right to turn off algorithmic recommendations and to receive an explanation when an algorithm significantly affects their interests
  • Deep synthesis: Content generated or altered by AI, deepfakes included, must be labeled as synthetic, comply with information controls, and come from providers who register their algorithms with regulators
  • Facial recognition: Non-governmental use of facial recognition is restricted to specific, necessary purposes, and any use in public places must serve public safety
  • Anthropomorphic AI services: China expanded this framework further in 2026 with new rules governing AI systems designed to simulate human-like interaction, adding to its existing generative AI and algorithm registration requirements

China's regulatory approach reflects its own political and economic priorities, but the underlying discipline, that every algorithm affecting consumers needs a clear, auditable basis for what it's doing, is one every AI regulation regime shares.

What the patchwork means for compliance teams

Three different regulatory philosophies, one shared requirement: prove what your AI systems are allowed to do with customer data, and prove it before something goes wrong, not after.

That's hard when the rules keep changing. A system built to Colorado's original timeline needed updating when the enforcement date moved. A model that sits in the EU's minimal-risk tier today could land in the high-risk tier tomorrow if its use case shifts. Do Not Train and other AI-specific opt-outs vary from state to state and country to country, but the customer's expectation, did you honor what I asked, doesn't vary at all.

Encoding those rules once, so every system and every new jurisdiction inherits them automatically, is the only version of this that scales. That's a different question than “do we have a policy?” It's “can our systems prove, record by record, that the policy held?”

Who owns AI governance at your company? Get the RACI framework for AI governance and give IT, legal, marketing, and leadership one clear map of who's responsible for what, across every jurisdiction you operate in.

Launch faster with the RACI Framework for AI Governance

Frequently asked questions

Is AI regulated in the US?

Yes, but not through a single federal law. The US regulates AI through a mix of state statutes (Colorado, Texas, California, Illinois, and others), agency enforcement led primarily by the FTC, and sector-specific rules, alongside an active, unresolved fight over whether the federal government can preempt state AI laws.

What does the EU AI Act regulate?

The EU AI Act regulates AI systems based on their risk to health, safety, and fundamental rights. It bans a small set of unacceptable-risk uses, sets strict requirements for high-risk systems in areas like employment and biometric identification, requires transparency for limited-risk systems like chatbots, and leaves minimal-risk systems largely unregulated.

How is AI regulated in China?

China regulates AI through targeted rules addressing specific technologies and use cases, including recommendation algorithms, deep synthesis, facial recognition, and, as of 2026, anthropomorphic AI services, rather than through one comprehensive AI law.

Will federal AI regulation preempt state AI laws in the US?

Not automatically. The executive branch has directed agencies to challenge state AI laws in court and has proposed conditioning federal funding on states limiting their own regulation, but preemption requires a court ruling or congressional action. Congress has declined to pass broad preemption language twice. Until that changes, state AI laws remain enforceable.

Should AI be regulated?

That's an active policy debate rather than a settled question. Supporters of regulation point to risks around bias, safety, and misuse; opponents point to the risk of slowing innovation and fragmenting compliance across jurisdictions. What's not in debate: enterprises operating today already have to comply with the AI laws on the books in the US, EU, China, and a growing list of other jurisdictions.

Ready to make sense of the patchwork? Talk to a Transcend solutions expert about turning AI governance policy into infrastructure your systems can prove, wherever you operate.

Contact us

About Transcend

Transcend is the “Can I use this data?” platform: the real-time data governance and decision layer that helps enterprises encode business policy, regulatory context, and customer permissions directly into the systems that process customer data.

AI Governance encodes Do Not Train enforcement, purpose limits, and agent permissions into every system your models touch. Policy Engine combines business policy, regulatory context, and customer preferences into one real-time decision, so every system already knows what it's allowed to do before it acts. Consent & Preference Management captures consent once and propagates it everywhere. Data Discovery & Classification maps personal data across your stack, down to the column level. DSR Automation documents every privacy request and proves every outcome, and Assessments streamlines DPIAs, TIAs, and AI risk reviews.

Read Transcend's Data Practices and Privacy Policy.


A smiling woman with long, blond hair stands outdoors against a blurred background of greenery, wearing a maroon top.

By Morgan Sullivan

Senior Marketing Manager II, Strategic Accounts

September 2, 2026

Share this article