Select your language
Blog
Blog description
Global AI Regulation: EU AI Act, U.S., UK, China, and Key Compliance Risks for Companies
Artificial intelligence regulation has moved from policy discussion to an immediate compliance issue for companies operating internationally. Governments are responding, but they are not following a single regulatory model.
Businesses now use AI to recruit employees, communicate with customers, generate content, analyze investments, develop software, provide professional services, make credit and insurance decisions, design products, manage supply chains, detect fraud, and automate increasingly consequential business processes.
Governments are responding, but they are not following a single regulatory model.
The European Union has established a comprehensive, risk-based regulatory regime through the EU Artificial Intelligence Act. The United States continues to rely on a combination of federal laws, agency enforcement, voluntary frameworks, and increasingly significant state legislation. The United Kingdom largely regulates AI through existing laws and sector-specific regulators. China has constructed a detailed framework combining generative-AI rules with cybersecurity, data, algorithm, content, and synthetic-media requirements.
The result is a fragmented global regulatory environment.
A single AI system can be subject to different legal requirements depending on where it is developed, where it is offered, how it is used, what data it processes, what decisions it makes, and which individuals are affected.
For multinational companies, the relevant question is therefore no longer simply:
“Do we use artificial intelligence?”
The more important questions are:
- What does the AI system do?
- What data does it use?
- Who is affected by its decisions?
- In which jurisdictions is it deployed?
- What level of autonomy does it have?
- And which entity is legally responsible for its operation?
AI Law Is Becoming a Distinct but Highly Fragmented Compliance Field
There is no single body of global “AI law.”
Instead, AI systems may simultaneously implicate:
- AI-specific legislation;
- Privacy and data-protection law;
- Consumer-protection law;
- Employment and anti-discrimination law;
- Intellectual-property law;
- Cybersecurity requirements;
- Product-liability rules;
- Financial-services regulation;
- Healthcare regulation;
- Competition law;
- Advertising law;
- Contract law;
- Export controls and economic sanctions;
- Online-content and platform regulation.
This is important because the absence of a comprehensive national AI statute does not mean that AI is unregulated.
An automated hiring system, for example, may be governed by employment and anti-discrimination law even if no dedicated AI statute applies. An AI-powered financial product may trigger banking, securities, consumer-credit, or insurance regulation. A generative-AI service may raise copyright, privacy, consumer-protection, and content-labeling issues simultaneously.
AI compliance therefore begins with the use case, not with the technology label.
European Union: The EU AI Act Moves Into Enforcement
The European Union has adopted the world's most comprehensive horizontal AI regulatory framework.
The EU AI Act uses a risk-based structure that distinguishes among prohibited AI practices, high-risk AI systems, systems subject to transparency obligations, general-purpose AI models, and lower-risk applications.
Several parts of the regulatory framework are already applicable.
Prohibited AI practices began applying in February 2025. Obligations for providers of general-purpose AI models became applicable in August 2025.
On August 2, 2026, the European Commission's AI Office and national authorities began exercising significant enforcement powers, and the AI Act's Article 50 transparency requirements became applicable. Those requirements include disclosure obligations for certain human-AI interactions and rules concerning AI-generated or manipulated content.
Following changes to the implementation timetable, obligations for certain high-risk systems listed in Annex III, including specified uses involving employment, education, biometrics, essential services, migration, and other consequential areas, are scheduled to apply from December 2, 2027. Requirements for certain AI systems integrated into regulated products are scheduled to apply from August 2, 2028.
For companies doing business in Europe, the AI Act is therefore no longer a future legislative development. Material parts of the regime are already operational.
General-Purpose AI Has Its Own Regulatory Framework
The EU AI Act also imposes specific obligations on providers of general-purpose AI models.
These can include requirements to:

Providers of general-purpose AI models presenting systemic risk face additional safety, cybersecurity, risk-management, and reporting obligations. Providers established outside the EU may also be required to appoint an authorized representative within the Union.
This has important implications beyond companies developing foundation models.
A business that modifies, fine-tunes, integrates, or commercially distributes another company's model should determine whether its activities change its legal status within the AI supply chain.
Companies should not automatically assume that regulatory responsibility remains entirely with the original model developer.
Transparency Has Become a Product Requirement
Transparency is one of the clearest examples of AI regulation moving directly into product design.
Article 50 requirements now apply to specified AI systems. The European Commission identifies obligations involving, among other things, notifying individuals when they are interacting with certain AI systems and labeling certain deepfakes and AI-generated or manipulated content.
For businesses, this means transparency cannot always be handled through a general privacy policy or terms of service.
Compliance may need to be built into:

Companies operating globally should therefore determine whether a disclosure architecture designed for one market will satisfy the requirements of another.
United States: Federal Enforcement and a Growing State Patchwork
The United States has taken a markedly different approach.
As of September 2026, the United States does not have a comprehensive federal private-sector AI statute comparable to the EU AI Act. Instead, AI is governed through a combination of existing federal statutes, agency enforcement, sector-specific rules, policy initiatives, voluntary standards, and state legislation.
The federal government's current AI policy emphasizes innovation, infrastructure, national security, and American technological leadership. The White House's AI Action Plan identifies federal initiatives across innovation, AI infrastructure, and international diplomacy and security.
At the same time, existing federal laws continue to apply to AI.
The Federal Trade Commission, for example, has continued enforcement involving allegedly deceptive claims concerning AI products and AI-powered services. In August 2026, the FTC finalized orders resolving allegations involving claims about an “AI-powered” marketing product, illustrating that traditional consumer-protection principles remain applicable when AI is incorporated into commercial offerings.
The key principle is straightforward:
Calling a product “AI-powered” does not reduce the company's obligations under existing law.
Claims about accuracy, capabilities, performance, data practices, or expected financial results remain subject to ordinary consumer-protection principles.
State AI Laws Are Becoming Increasingly Important
The absence of comprehensive federal regulation has encouraged states to develop their own AI frameworks.
Texas's Responsible Artificial Intelligence Governance Act became effective on January 1, 2026. It establishes restrictions on specified AI practices and disclosure requirements in certain contexts.
Colorado also substantially revised its approach in 2026. Its new Automated Decision-Making Technology law addresses systems that materially influence consequential decisions involving matters such as employment, education, housing, lending, insurance, healthcare, and public benefits. Major requirements for developers and deployers are scheduled to begin on January 1, 2027, including documentation, notice, data-access and correction mechanisms, and meaningful human review following certain adverse outcomes.
Other states regulate particular issues including automated employment tools, biometric data, deepfakes, consumer privacy, healthcare applications, and AI-generated communications.
For businesses operating nationally, the practical consequence is a compliance environment that increasingly requires state-by-state analysis in addition to federal review.
United Kingdom: Regulation Through Existing Legal Frameworks
The United Kingdom has not adopted an EU-style comprehensive AI statute.
A June 2026 House of Commons Library review confirms that the UK continues to regulate AI principally through the legal context in which it is used rather than through one cross-sector AI law. Existing regulators apply laws governing areas such as data protection, financial services, consumer protection, equality, competition, and online safety to AI-enabled activities.
This means the regulator and legal framework depend heavily on the use case.
An AI system used by:
- a bank,
- an employer,
- an online platform,
- a healthcare provider,
- an insurer,
- a telecommunications business
may face substantially different regulatory obligations.
The UK model has generally emphasized principles including safety, security, transparency, explainability, fairness, accountability, governance, contestability, and redress, while relying on existing sector regulators to apply those principles within their respective areas.
For international companies, this can create a different form of complexity than the EU AI Act.
The EU asks businesses to determine where their AI system falls within a comprehensive statutory framework.
The UK frequently requires businesses to determine which existing body of law and which regulator governs the particular deployment.
China: Generative AI, Data, Algorithms, and Content Regulation
China has created another distinct model.
Its framework combines rules governing generative AI with broader requirements involving personal information, cybersecurity, data security, algorithms, deep synthesis, and online content.
China's Interim Measures for the Management of Generative Artificial Intelligence Services apply to generative-AI services that provide generated text, images, audio, video, and similar content to the public within China. They expressly extend to services provided through APIs.
The rules address issues including:
- Lawful sources of training data;
- Intellectual-property rights;
- Personal-information protection;
- Discriminatory outputs;
- Transparency and accuracy;
- Protection of user input and usage information;
- Security obligations;
- Content governance.
Providers using personal information in training must have an appropriate legal basis, and training data must come from lawful sources and respect intellectual-property rights.
Certain generative-AI services with public-opinion attributes or social-mobilization capabilities are also subject to security-assessment and algorithm-filing requirements. Chinese authorities may take technical or other measures against generative-AI services provided from outside China where those services do not comply with applicable Chinese requirements.
This is particularly important for foreign AI providers.
A company may be headquartered outside China and operate infrastructure outside China but still create Chinese regulatory exposure by providing qualifying services to users within the country.
AI-Generated Content Must Be Identifiable
China has also imposed detailed rules concerning AI-generated and synthetic content.
The Measures for Labeling Artificial Intelligence-Generated Synthetic Content became effective on September 1, 2025.
The framework distinguishes between explicit labels that users can perceive and implicit technical labels, including metadata identifying content as AI-generated or synthetic. It applies across text, images, audio, video, and virtual environments in covered circumstances.
Companies operating global content platforms therefore face a growing problem: AI-generated-content disclosure is becoming mandatory in multiple jurisdictions, but the technical and legal requirements are not necessarily identical.
The Biggest Global AI Compliance Risks
Differences between the EU, United States, United Kingdom, and China are significant, but certain legal risks appear repeatedly across jurisdictions.
1. Determining the Company's Legal Role
Companies should first establish their role in the AI ecosystem.
Depending on the jurisdiction, a company may be considered a:
- Model provider;
- AI-system provider;
- Developer;
- Deployer;
- Distributor;
- Importer;
- Platform operator;
- Professional user;
- Data controller or processor.
The applicable duties can change dramatically depending on that classification.
A company purchasing an AI system from another vendor cannot assume that all compliance responsibility belongs to the vendor.
A deployer may have independent duties involving notice, human oversight, impact assessments, recordkeeping, data governance, or adverse-decision procedures.
2. Data Protection and AI Training
AI systems can process vast quantities of personal information.
Companies need to understand not only what data an AI system receives during operation but also what information was used to train or fine-tune it.
Relevant questions include:
- Was the training data obtained lawfully?
- Does it contain personal information?
- Is consent required?
- Can customer information be reused for model training?
- Can employee information be processed?
- Are sensitive or biometric data involved?
- Where is the information stored?
- Is it transferred internationally?
- How long are prompts and outputs retained?
- Can users exercise access or deletion rights?
The distinction between using information to provide a requested service and using that information to train a broader commercial model can be legally significant.
3. Copyright and Training Data
Generative AI has also made copyright and data provenance central compliance issues.
Companies developing or fine-tuning models should determine where their training material came from and under what legal basis it was used.
The EU AI Act now expressly connects general-purpose AI obligations to copyright compliance. Covered model providers must maintain a copyright policy and publish a summary of the content used for training.
Companies using third-party models should also address ownership of generated outputs, infringement claims, training on company information, and whether confidential materials can be reused by the vendor.
4. Employment and Automated Decision-Making
Employment is becoming one of the highest-risk AI use cases.
AI may be used to:
- Screen résumés;
- Rank candidates;
- Analyze interviews;
- Recommend promotions;
- Evaluate performance;
- Monitor employees;
- Identify workers for termination.
These applications can trigger anti-discrimination law and, increasingly, AI-specific obligations.
A company may remain legally responsible for discriminatory outcomes even when the relevant algorithm was supplied by an external vendor.
Employers should understand what factors an AI system uses, whether protected characteristics or proxies can influence the result, how decisions are tested, and whether humans can meaningfully reconsider automated recommendations.
5. Transparency and AI-Generated Content
Companies increasingly need to answer a simple but legally significant question:
Must the user be told that AI is involved?
Depending on the jurisdiction and use case, disclosure obligations may apply to:
- Chatbots;
- Deepfakes;
- AI-generated advertising;
- Synthetic audio;
- Generated images;
- Customer-service systems;
- Public-interest content.
The EU and China already impose significant labeling requirements in covered circumstances.
Companies should therefore build disclosure analysis into product development rather than treating labeling as a final-stage marketing issue.
6. Consumer Protection and AI Claims
Companies should be cautious about claims such as:
- “100 percent accurate”;
- “Unbiased”;
- “Fully autonomous”;
- “Human-level”;
- “Guaranteed to increase revenue”;
- “Powered by proprietary AI.”
Regulators can evaluate these representations under ordinary consumer-protection and advertising laws.
The U.S. FTC's continuing AI-related enforcement activity demonstrates that existing prohibitions against deceptive commercial practices remain relevant regardless of whether the product uses sophisticated artificial intelligence.
Businesses should therefore be able to substantiate material claims about AI functionality and performance.
7. AI Vendors and Contractual Risk
For most businesses, AI regulation is also a procurement issue.
Before deploying a significant third-party AI system, companies should determine:
- Which model is being used;
- Where the model is hosted;
- Whether subcontractors are involved;
- What happens to submitted data;
- Whether customer data is used for training;
- Who owns generated outputs;
- Who bears intellectual-property risk;
- Whether the vendor will provide regulatory documentation;
- Whether the customer can audit compliance;
- How cybersecurity incidents will be handled;
- What happens if the vendor materially changes the model.
Contracts should allocate responsibilities, but contractual allocation does not eliminate regulatory obligations owed directly by the customer.
8. AI Agents and Autonomous Transactions
Agentic AI may become one of the most consequential legal developments.
Unlike traditional generative AI, an AI agent can potentially perform tasks and execute actions with limited human intervention.
An AI agent might:
- Select suppliers;
- Negotiate prices;
- Enter orders;
- Purchase software;
- Manage inventory;
- Execute payments;
- Communicate with customers;
- Adjust prices;
- Hire contractors.
This raises questions that existing AI statutes do not always answer directly.
- When is an AI agent authorized to bind the company?
- What happens if it accepts contractual terms?
- Who is responsible if it makes a discriminatory decision?
- What if it purchases from a sanctioned entity?
- What happens when an AI agent makes a mistake that no employee expressly approved?
As AI becomes more autonomous, corporate authority, internal controls, and transaction governance will become increasingly important components of AI law.
9. Export Controls, Sanctions, and National Security
AI regulation cannot be separated entirely from international trade and national-security law.
Advanced AI systems may involve:
- Controlled semiconductors;
- High-performance computing equipment;
- Cloud computing;
- Software;
- Technical data;
- Foreign-person access;
- Restricted end users;
- Sanctioned jurisdictions.
For multinational companies, an AI transaction may therefore require simultaneous consideration of AI regulation, export controls, and economic sanctions.
A transaction permitted under general AI legislation may still be prohibited under national-security or sanctions rules.
10. Cybersecurity and Model Security
AI systems introduce additional cybersecurity risks, including:
- Prompt injection;
- Data extraction;
- Model theft;
- Training-data poisoning;
- Unauthorized access;
- Manipulation of autonomous agents;
- Leakage of confidential information.
Companies should consider AI cybersecurity as part of their general information-security architecture rather than assigning it exclusively to an innovation team.
A Global AI Compliance Program
A multinational company generally cannot manage this environment through a single AI policy copied across every jurisdiction. A more practical approach is to establish a global baseline with jurisdiction-specific overlays.
A mature AI governance framework should generally include:
AI Inventory
Identify material AI systems used throughout the organization, including tools acquired independently by individual departments.
Risk Classification
Determine whether each system influences employment, financial, healthcare, educational, consumer, legal, safety, or other consequential decisions.
Jurisdictional Mapping
Identify where the system is developed, offered, accessed, and used—and where affected individuals are located.
Legal Role Analysis
Determine whether the company is acting as a provider, developer, deployer, distributor, importer, platform, controller, or processor.
Data Governance
Document what data enters the system, where it originates, whether it contains personal or confidential information, and whether the vendor uses it for further training.
Human Oversight
Identify decisions that require human approval or reconsideration.
Testing and Validation
Evaluate accuracy, reliability, discrimination, cybersecurity, foreseeable misuse, and material limitations.
Transparency
Determine whether customers, employees, users, or regulators must be informed about AI use or AI-generated content.
Vendor Due Diligence
Require appropriate documentation and contractual protections from AI vendors.
Recordkeeping
Preserve sufficient information to demonstrate why an AI system was approved and how compliance controls operate.
Incident Response
Establish procedures for data breaches, discriminatory outcomes, model failures, unlawful content, cybersecurity incidents, and regulatory inquiries.
Continuous Monitoring
AI regulation is developing too rapidly for an assessment performed only at procurement to remain sufficient indefinitely.
The Regulatory Difference Between the EU, U.S., UK, and China
The emerging global landscape can be summarized conceptually as follows.
The European Union regulates AI through a comprehensive statutory framework organized largely around risk and the role of actors within the AI supply chain.
The United States combines existing federal law, agency enforcement, national AI policy, voluntary technical frameworks, sector-specific regulation, and a growing body of state legislation.
The United Kingdom continues to rely principally on existing legal regimes and specialized regulators applying rules according to the context in which AI is used.
China integrates generative-AI regulation with data protection, cybersecurity, algorithm governance, content requirements, security assessments, and detailed synthetic-content labeling.
None of these systems should be treated as interchangeable.
Conclusion
Artificial intelligence regulation is becoming a major global compliance discipline, but there is no single global AI law.
- The European Union is implementing an extensive risk-based regime through the AI Act.
- The United States is developing a fragmented combination of federal enforcement and state legislation.
- The United Kingdom continues primarily to regulate AI through existing sectoral laws and regulators.
- China has established a detailed framework addressing generative AI, algorithms, training data, personal information, content, security, and synthetic-media labeling.
For multinational companies, the central challenge is therefore not simply complying with more regulation: it is complying with different regulatory models at the same time.
A single AI product may be considered a general-purpose model or AI system under European law, a regulated generative-AI service in China, subject to state requirements in the United States, and governed principally by sector-specific law in the United Kingdom.
The most effective compliance strategy is therefore not to ask whether a company “uses AI.” Companies should understand:

As AI becomes embedded in everyday business and increasingly capable of acting autonomously, those questions will move beyond technology governance.
They will become core questions of corporate governance, regulatory compliance, and legal risk management.

ES
RU
TR
FA
AR
ZH