The European Union and the United States have adopted different structural approaches to AI governance. The EU has enacted comprehensive legislation — the EU AI Act (Regulation 2024/1689) — while the US operates through a fragmented landscape of eight or nine distinct regulatory approaches that do not add up to comprehensive coverage. The comparison bears on multinational AI companies, which must navigate both regimes, and on the question of which approach may become the de facto global standard.
This page compares the two regimes across five dimensions: regulatory philosophy, what is regulated, accountability architecture, rules for general-purpose AI (GPAI) models, and innovation impact. It then sets out the structural tensions between them and the points on which they are converging.
Regulatory philosophy
| EU AI Act | US approaches | |
|---|---|---|
| Metaphor | Product safety regulation (CE marking) | Common law + sector-specific rules |
| Core principle | Risk proportionality: more dangerous → more obligations | Diverse: transparency, liability, standards, preemption |
| Rights framing | Fundamental rights protection as explicit goal | Varies: innovation, consumer protection, national security |
| Precautionary posture | High: prohibited practices banned outright | Low (federal); medium (some states) |
| Treaty/constitutional basis | EU internal market + fundamental rights charter | First Amendment, Supremacy Clause, state police powers |
The EU Act's fundamental rights framing means certain applications are prohibited outright — real-time biometric surveillance and social scoring — regardless of developer arguments about innovation benefits. US approaches generally do not prohibit; they regulate conditions of use.
What is regulated
The clearest structural difference between the two regimes is the object of regulation. The EU AI Act regulates AI systems and models directly, on three bases: the category a system falls into (prohibited / high-risk / GPAI); the compute used to train the model (above 10^25 FLOP marks systemic risk); and the domain in which the system is deployed.
US approaches instead regulate applications or actors, not AI systems directly. The principal forms are:
- California SB 53 and the New York RAISE Act: frontier AI developers must publish safety frameworks.
- The Colorado AI Act: deployers of high-risk AI in specific consequential-decision domains.
- The AI LEAD Act: AI treated as a product, with developer/deployer liability for defects.
- State attorney general guidances: existing laws (consumer protection, anti-discrimination) applied to AI.
- The NIST AI RMF: voluntary organizational practices.
- EO 14365: state regulations preempted.
The EU regulates horizontally — the same rules apply to a given AI category across all sectors — while the US regulates vertically, with sector-specific rules, different responsible actors, and no unified regime. The fragmentation dynamics within the US system are examined in Techno-Federalism.
Accountability architecture
| EU AI Act | US (best approximation) | |
|---|---|---|
| Regulator | EU AI Office (GPAI) + national authorities (high-risk) | FTC, CFPB, sector agencies (EEOC, OCC) — fragmented |
| Enforcement mechanism | Conformity assessments, registration, CE marking | Litigation (product liability), state AG enforcement, federal agency action |
| Who is responsible? | Providers (developers) + deployers, with explicit allocation | Varies by law: developer (LEAD Act), deployer (Colorado) |
| Penalties | Up to €35M or 7% global turnover | Varies; AI LEAD Act: compensatory + punitive |
| Third-party audit | Required for high-risk AI (notified bodies) | Not required; voluntary under NIST RMF |
| Incident reporting | Mandatory for high-risk AI | Not required (federal); limited (state) |
The EU's third-party conformity assessments create institutional accountability and, at the same time, barriers to entry for smaller companies. The US reliance on litigation makes accountability reactive — arising after harm — rather than preventive. Third-party accountability mechanisms under both regimes are discussed in AI Ethics Auditing.
GPAI model rules
The EU AI Act regulates AI models at the model level rather than only at the application level. Its GPAI obligations for frontier labs are:
- Technical documentation, a training-data summary, and a copyright policy (for all GPAI models).
- Adversarial testing, incident reporting, and energy disclosures (for models above 10^25 FLOP).
- Compliance evidenced through the Frontier Compliance Framework.
There is no federal US analog. California SB 53 requires safety frameworks from frontier developers but does not mandate specific evaluations or set capability thresholds, and the AI LEAD Act imposes liability without requiring pre-market evaluations.
One illustration of the difference: under the EU Act, Anthropic's Mythos Preview would require adversarial-testing documentation and incident reporting even in its current non-public-release form, if deployed to EU users. The Frontier Compliance Framework appears designed partly for this purpose. The academic mapping in Taxonomy of Systemic Risks from GPAI explicitly follows the EU Act's definitions.
Innovation impact
Defenders of the EU AI Act argue that its risk-proportionality structure leaves most AI — minimal- and limited-risk systems — facing only transparency requirements, while critics argue the compliance burden falls hardest on smaller companies.
Arguments that the EU approach hurts innovation:
- Conformity assessments add time and cost, estimated at €6,000–$200,000 per high-risk system.
- GPAI technical-documentation requirements may expose trade secrets.
- The prohibited-practice list is potentially broad in interpretation.
- The 10^25 FLOP compute threshold creates incentives to train just below the line.
Arguments that the EU approach helps innovation:
- Legal clarity: companies know what is permitted versus prohibited.
- Harmonized rules within the EU produce a larger unified market than the US state patchwork.
- Safety requirements can serve as a differentiation signal in enterprise and government markets.
- Reduced liability uncertainty relative to US litigation risk.
On the US side, EO 14365's federal preemption strategy and the AI Action Plan's deregulatory posture reflect a bet that the US innovation advantage depends on lighter-touch regulation. The AIN's "Little Tech" argument extends this case to state laws. The view that the US regime is shifting toward a procurement-led model is set out in procurement-driven AI governance.
Structural tensions
Five tensions run through the comparison.
Precautionary versus permissive. The EU prohibits certain practices outright and requires pre-market evaluation for high-risk AI; the US allows innovation to proceed and imposes liability after harm occurs. The question this raises is who bears the cost of AI-enabled harm — developers, under the EU approach, or victims, under the US default.
Horizontal versus vertical regulation. The EU applies the same rules to a given AI category across all sectors; US sector-specific rules create inconsistency and regulatory gaps. GPAI models that operate across sectors fit poorly into US vertical regulation, and the EU horizontal approach may be better suited to GPAI's generality.
Model versus application accountability. EU model-level compute thresholds aim to capture systemic risks regardless of application, whereas US application-level regulation can miss risks from GPAI used for purposes the regulator did not anticipate. Emergent capabilities in frontier models create risks at the model level that application regulation may not fully capture.
Rights versus innovation. The EU explicitly frames the Act around protecting fundamental rights, with absolute prohibitions; the US explicitly frames deregulation around protecting innovation and national security. Divergence on prohibited practices produces a two-standard world in which technologies legal in the US, such as real-time biometric surveillance, are illegal in the EU.
Global standard competition. The EU's comprehensive legislation may become the de facto global standard through market power, as GDPR did for privacy: if companies must comply with EU rules to access the EU market, they may apply EU standards globally rather than maintain two separate compliance regimes — the dynamic described in the Brussels Effect. The US's fragmented approach may cede standard-setting to the EU, or may produce lighter-touch global norms if US companies remain the primary global AI providers.
Points of convergence
Despite their differences, the two systems are converging on several elements:
- Incident reporting: the EU AI Act mandates it; US labs increasingly do it voluntarily through system cards and Frontier Model Forum reports.
- Safety frameworks: the EU mandates them; the US NIST RMF encourages them; both produce similar internal governance documents.
- Foundation-model documentation: the EU requires it; US labs publish system cards, which are essentially the same artifact produced voluntarily.
- Compute thresholds: the EU uses 10^25 FLOP; US export controls use compute thresholds for chips; both reflect an emerging consensus that compute is the key input to governance.
Industry has begun pressing for formal coordination between the two systems: on July 13, 2026, a coalition of major US and foreign technology companies urged Washington and Brussels to formalize a dialogue on digital-policy tensions, naming AI and cybersecurity as top priorities (Source: insideaipolicy.com).
Status and forecasts
The state of US AI regulation battles as of April 2026 is described in a Washington Post AI & Tech Brief (Source: washingtonpost.com).
Several forecasts have been advanced about how the comparison evolves. Drawing on April–May 2026 trilogue tensions, observers expected the EU AI Act's high-risk implementation to resolve with a material delay of at least six months past the original timeline, with the final EU position on the high-risk schedule due by end of 2026. On the basis of the EU AI Act's Article 50 transparency obligations, at least one major non-EU frontier-AI deployment was projected to be cited as an Article 50 compliance failure — through a public EU AI Office enforcement action or formal complaint — by mid-2027. Framing introduced in May 2026 anticipated that US-EU regulatory divergence would widen, with the US regime characterized as procurement-led rather than mandate-led (per procurement-driven AI governance); the resolution criterion is qualitative assessment by at least two of the WSJ AI policy editor, the FT AI editor, and The Economist tech editor by end of 2027. Drawing on the GDPR precedent and 2026 EU AI Act enforcement, the Brussels Effect was projected to take hold for AI — evidenced by a public statement from Anthropic, OpenAI, or Google adopting EU AI Act standards globally — by end of 2027, with a partial precedent already visible in GDPR-style global privacy compliance.
Sources
- EU AI Act / EU AI Act source summary
- US AI Regulatory Approaches Compared
- Frontier Compliance Framework — Anthropic's response to EU + US compliance obligations
- Taxonomy of Systemic Risks from GPAI — academic mapping that explicitly follows EU Act definitions
- AI Ethics Auditing — third-party accountability mechanisms under both regimes
- Techno-Federalism — the fragmentation dynamics within the US system
- AI & Tech Brief: Radical Activists (Source: washingtonpost.com) — current state of US AI regulation battles (April 2026)