The AI Learning Hub Journal

AI Governance & Regulation

AI governance landscape — mid-2026EU AI Act — the anchorrisk-based · applies to anyone placing systems on the EU marketIn force 2024risk tiers and prohibitions setGPAI obligations 2025transparency, systemic-risk dutiesHigh-risk phasing 2026–2027obligations land in stagesPhased sequencing — the obligations arrive in waves, they do not all start at onceUNITED STATES — a patchworkState laws move first, and they differSector agencies issue guidance, not statuteFederal turn toward deregulation and preemptionNet effect: duties depend on where and whatCHINA — targeted measuresFiling regimes for algorithms and modelsRules aimed at generative and synthetic mediaLabelling duties for AI-generated contentSecurity review before public-facing launchVOLUNTARY FRAMEWORKS — not law, but how buyers and auditors ask you to prove itNIST AI RMFgovern · map · measure · manageISO/IEC 42001certifiable AI management system
One binding anchor, two very different national approaches, and a voluntary layer that shows up in every procurement questionnaire

The EU AI Act: The Anchor Regulation

The EU AI Act is the world's first comprehensive horizontal AI law and the de facto global reference point. It entered into force in August 2024 and phases in over several years: prohibitions on unacceptable practices (social scoring, certain biometric uses) applied first, obligations for general-purpose AI model providers took effect in August 2025, and the high-risk system requirements — conformity assessments, risk management, logging, human oversight — phase in through 2026 and 2027. Like GDPR, it reaches beyond Europe: any provider placing AI on the EU market or whose outputs are used in the EU is in scope. GPAI providers must maintain technical documentation, publish training-data summaries, respect copyright, and — above a systemic-risk compute threshold — run adversarial testing and report serious incidents.

  • Risk-tiered: prohibited practices, high-risk systems, transparency-tier systems, minimal risk
  • GPAI obligations live since August 2025: documentation, training-data summaries, copyright policy
  • Systemic-risk GPAI: additional evals, adversarial testing, incident reporting, cybersecurity duties
  • High-risk obligations phase in through 2026–2027 — the compliance work for deployers is happening now

The US: A Patchwork, Not a Framework

The United States has no comprehensive federal AI law — and its trajectory reversed sharply. The October 2023 Executive Order on AI, which required frontier training-run reporting and directed agency safety standards, was rescinded in January 2025 by the incoming administration, which replaced it with a deregulatory posture prioritising American AI leadership and reduced barriers to development. The practical result is a patchwork: state legislatures have moved into the gap with laws targeting algorithmic discrimination, deepfakes, transparency, and AI in hiring, while sectoral regulators (FTC, financial and health agencies) apply existing consumer-protection and safety authority to AI conduct. For anyone deploying in the US, compliance means tracking a moving mosaic of state statutes and agency guidance rather than reading one act.

  • The 2023 AI Executive Order was rescinded in January 2025 — do not cite it as current US policy
  • State laws lead: algorithmic discrimination, deepfake, and transparency statutes vary by state
  • Sectoral enforcement: existing FTC, employment, and financial rules apply to AI conduct today
  • Federal preemption of state AI laws is a recurring, unresolved political fight — the map keeps shifting

China and the Voluntary Layer

China regulates generative AI through binding administrative measures rather than one omnibus law: providers of public-facing generative services must undergo security assessments and algorithm filings before launch, ensure content reflects mandated values, watermark and label synthetic media (explicit labelling rules took effect in 2025), and take responsibility for generated content. Alongside binding law worldwide sits an influential voluntary layer: the NIST AI Risk Management Framework gives organisations a shared vocabulary for mapping, measuring, and managing AI risk and is widely referenced in US procurement; ISO/IEC 42001 defines a certifiable AI management system standard; and international efforts — the AI safety-summit process, national AI safety institutes, codes of practice — coordinate evaluation norms across borders. Voluntary does not mean toothless: these frameworks become contractually binding the moment a customer writes them into procurement requirements.

  • China: pre-launch security assessment, algorithm registration, synthetic-content labelling obligations
  • NIST AI RMF: voluntary govern-map-measure-manage framework, common in US enterprise and government procurement
  • ISO/IEC 42001: certifiable AI management standard — increasingly requested in vendor due diligence
  • Safety institutes and summit commitments: cross-border evaluation cooperation without treaty force

Compliance Is Now an Engineering Requirement

The common thread across every regime is that compliance obligations resolve into engineering artefacts. Risk classification requires knowing what your system does and where its outputs land. Documentation duties require model cards, data provenance records, and decision logs that must be generated by the pipeline, not reconstructed for an audit. Logging and traceability requirements mean prompt and output records with retention policies. Human-oversight provisions dictate actual UX and workflow design. Incident-reporting duties require monitoring capable of detecting reportable events. Teams that treat this as legal paperwork bolt it on late and expensively; teams that treat it as system requirements build the evidence trail into the architecture — the same tracing, evals, and documentation that good AI engineering needs anyway.

  • Map every deployment to jurisdiction and risk tier before build, not before launch
  • Automate the artefacts: model cards, eval reports, and data lineage as pipeline outputs
  • Logging with retention and access controls is a near-universal requirement across regimes
  • The overlap is the strategy: observability and evals built for quality double as compliance evidence

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.