AI Governance & Regulation
The EU AI Act: The Anchor Regulation
The EU AI Act is the world's first comprehensive horizontal AI law and the de facto global reference point. It entered into force in August 2024 and phases in over several years: prohibitions on unacceptable practices (social scoring, certain biometric uses) applied first, obligations for general-purpose AI model providers took effect in August 2025, and the high-risk system requirements — conformity assessments, risk management, logging, human oversight — phase in through 2026 and 2027. Like GDPR, it reaches beyond Europe: any provider placing AI on the EU market or whose outputs are used in the EU is in scope. GPAI providers must maintain technical documentation, publish training-data summaries, respect copyright, and — above a systemic-risk compute threshold — run adversarial testing and report serious incidents.
- Risk-tiered: prohibited practices, high-risk systems, transparency-tier systems, minimal risk
- GPAI obligations live since August 2025: documentation, training-data summaries, copyright policy
- Systemic-risk GPAI: additional evals, adversarial testing, incident reporting, cybersecurity duties
- High-risk obligations phase in through 2026–2027 — the compliance work for deployers is happening now
The US: A Patchwork, Not a Framework
The United States has no comprehensive federal AI law — and its trajectory reversed sharply. The October 2023 Executive Order on AI, which required frontier training-run reporting and directed agency safety standards, was rescinded in January 2025 by the incoming administration, which replaced it with a deregulatory posture prioritising American AI leadership and reduced barriers to development. The practical result is a patchwork: state legislatures have moved into the gap with laws targeting algorithmic discrimination, deepfakes, transparency, and AI in hiring, while sectoral regulators (FTC, financial and health agencies) apply existing consumer-protection and safety authority to AI conduct. For anyone deploying in the US, compliance means tracking a moving mosaic of state statutes and agency guidance rather than reading one act.
- The 2023 AI Executive Order was rescinded in January 2025 — do not cite it as current US policy
- State laws lead: algorithmic discrimination, deepfake, and transparency statutes vary by state
- Sectoral enforcement: existing FTC, employment, and financial rules apply to AI conduct today
- Federal preemption of state AI laws is a recurring, unresolved political fight — the map keeps shifting
China and the Voluntary Layer
China regulates generative AI through binding administrative measures rather than one omnibus law: providers of public-facing generative services must undergo security assessments and algorithm filings before launch, ensure content reflects mandated values, watermark and label synthetic media (explicit labelling rules took effect in 2025), and take responsibility for generated content. Alongside binding law worldwide sits an influential voluntary layer: the NIST AI Risk Management Framework gives organisations a shared vocabulary for mapping, measuring, and managing AI risk and is widely referenced in US procurement; ISO/IEC 42001 defines a certifiable AI management system standard; and international efforts — the AI safety-summit process, national AI safety institutes, codes of practice — coordinate evaluation norms across borders. Voluntary does not mean toothless: these frameworks become contractually binding the moment a customer writes them into procurement requirements.
- China: pre-launch security assessment, algorithm registration, synthetic-content labelling obligations
- NIST AI RMF: voluntary govern-map-measure-manage framework, common in US enterprise and government procurement
- ISO/IEC 42001: certifiable AI management standard — increasingly requested in vendor due diligence
- Safety institutes and summit commitments: cross-border evaluation cooperation without treaty force
Compliance Is Now an Engineering Requirement
The common thread across every regime is that compliance obligations resolve into engineering artefacts. Risk classification requires knowing what your system does and where its outputs land. Documentation duties require model cards, data provenance records, and decision logs that must be generated by the pipeline, not reconstructed for an audit. Logging and traceability requirements mean prompt and output records with retention policies. Human-oversight provisions dictate actual UX and workflow design. Incident-reporting duties require monitoring capable of detecting reportable events. Teams that treat this as legal paperwork bolt it on late and expensively; teams that treat it as system requirements build the evidence trail into the architecture — the same tracing, evals, and documentation that good AI engineering needs anyway.
- Map every deployment to jurisdiction and risk tier before build, not before launch
- Automate the artefacts: model cards, eval reports, and data lineage as pipeline outputs
- Logging with retention and access controls is a near-universal requirement across regimes
- The overlap is the strategy: observability and evals built for quality double as compliance evidence
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.