The AI Learning Hub Journal

AI Regulation & Governance

AI Regulation & Governance: Risk Tiers and the Global Landscape Diagram showing the EU AI Act four-tier risk pyramid on the left, the global regulatory landscape on the right, and the compliance-ready checklist at the bottom. AI Regulation & Governance: Risk Tiers & the Global Landscape EU AI Act — risk-based tiering Unacceptable risk BANNED — social scoring, public biometric surveillance High risk Employment, credit, healthcare, law enforcement Conformity assessment · human oversight · audit trail Limited risk Chatbots, recommendation systems — disclose it's AI Minimal risk Spam filters, games — no specific obligations Global landscape — every major jurisdiction moving EU AI Act — comprehensive, in force 2024 Phased compliance through 2027 · up to €35M or 7% global revenue penalties US Executive Orders + sector-specific rules FDA · EEOC · CFPB issuing AI-specific guidance — no single horizontal law UK Pro-innovation principles-based Sector regulators apply existing powers — no dedicated AI statute (yet) CN Generative AI regulations (2023) Security assessment & content controls required before deployment Compliance-ready — the four pillars regulated buyers expect Model cards Data provenance, known limitations, eval results Living documentation Audit trails Every AI decision logged with inputs and outputs Immutable, retrievable Human oversight Review & override capability for consequential decisions Designed in, not bolted on Bias & risk audits Pre-deployment + recurring re-assessment Documented, third-party In regulated sectors, compliance readiness is now a sales qualification — not just a legal requirement

The Policy Layer Has Arrived

For most of AI's history, governance was voluntary — company policies, voluntary commitments, and industry best practices. That era has ended, but unevenly. The EU AI Act is in force, with general-purpose AI obligations already applying and high-risk obligations phasing in now. The US has moved the opposite direction federally — the 2023 Executive Order on AI was rescinded in January 2025 — leaving a growing patchwork of state laws to fill the gap. China, UK, Canada, and Brazil have active legislative or regulatory processes underway. Anyone building or deploying AI commercially today operates within a regulatory environment — whether they know it or not.

  • EU AI Act: risk-based tiering — entered into force August 2024; GPAI model obligations have applied since August 2025; high-risk obligations phasing in through 2026–2027 — the world's first comprehensive AI law
  • US: the 2023 Executive Order on AI was rescinded in January 2025 — federal policy has taken a deregulation turn, while a growing patchwork of state laws (e.g. the Colorado AI Act) fills the gap and NIST AI RMF remains the voluntary anchor
  • UK: pro-innovation principles-based approach — sector regulators apply existing powers to AI rather than a horizontal law
  • China: generative AI regulations (2023) requiring security assessments and content controls before deployment
  • The common thread: every major jurisdiction is moving from voluntary to binding — the question is when, not whether

EU AI Act: What It Requires and Who It Affects

The EU AI Act creates a risk-based tiering system for AI systems. The tier your product lands in determines your compliance obligations. Understanding the tiers — not just that the Act exists — is what allows you to assess your exposure accurately.

  • Unacceptable risk (banned): social scoring by governments, real-time biometric surveillance in public spaces, AI that exploits psychological vulnerabilities
  • High-risk: AI used in employment decisions, credit scoring, essential services access, law enforcement, medical devices, education — requires conformity assessment, human oversight, audit trail, documentation
  • Limited risk: chatbots, recommendation systems — transparency obligations (disclose it's AI)
  • Minimal risk: spam filters, AI-assisted games — no specific obligations beyond general law
  • Timeline: the Act entered into force August 2024; prohibited practices have been banned since February 2025; GPAI obligations applied August 2025; high-risk rules phase in through 2026–2027; penalties up to €35M or 7% global revenue

Compliance as Competitive Advantage

The instinctive reaction to AI regulation is to treat it as a cost. Sophisticated organisations are treating it as a differentiator. Customers in regulated industries — financial services, healthcare, government — increasingly require AI vendors to demonstrate compliance before signing contracts. Being compliance-ready is a sales qualification, not just a legal requirement.

  • The market signal: financial services buyers are increasingly asking for EU AI Act readiness in RFPs — before the deadlines
  • What compliance-ready means: model cards, audit trails, human oversight mechanisms, risk tier assessments, and incident response procedures
  • AI governance frameworks: NIST AI RMF (US), ISO/IEC 42001, and EU AI Act together form the compliance baseline serious buyers are referencing
  • Vendor differentiation: vendors who can demonstrate documented human oversight, explainability, and bias auditing win in regulated-sector sales
  • The governance gap: most organisations in scope have not started their compliance assessment — the first-mover advantage is real

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.