AI Regulatory Frameworks: EU, UK, China, and US Compared.
AI is subject to divergent rules across regions. The EU applies a binding regulation since 2024, the UK favours a sectoral approach, while China and the US adopt fragmented strategies. Analysis of the implications for companies operating in multiple markets.

The EU and the AI Act: A Binding and Extraterritorial Framework
The European Union has adopted a comprehensive regulatory approach with the AI Act, which entered into force on 1 August 2024.
Regulation (EU) 2024/1689 classifies AI systems according to their level of risk. Prohibited practices, such as subliminal manipulation or social scoring, have been applicable since February 2025. Obligations for high-risk AI systems, particularly regarding technical documentation and transparency, will be phased in until 2028.
The AI Act stands out for its extraterritorial applicability. Any company, regardless of its location, is subject to the regulation if its AI systems are used in the EU or if their outputs affect individuals located in the Union. This approach, similar to that of the GDPR, requires multinational companies to integrate compliance for their European activities. Fines for non-compliance can reach 7% of global turnover, with a cap of €35 million.
Companies must also comply with transparency requirements for generative AI systems, applicable since 2 August 2026. This includes labelling synthetic content and disclosing copyright-protected data used to train models.
UK: A Sectoral and Flexible Approach
The UK has opted for a different strategy to the EU, favouring sectoral and flexible regulation.
In the absence of a centralised law, the Department for Science, Innovation and Technology (DSIT) published a white paper in 2023 entitled A pro-innovation approach to AI regulation. This document sets out five guiding principles for AI: safety, transparency, fairness, accountability, and contestability. Each sectoral regulator, such as the Financial Conduct Authority (FCA) for finance or the Information Commissioner's Office (ICO) for data protection, is responsible for applying these principles within its remit.
This approach allows for rapid adaptation to the specificities of each sector, but it also creates a fragmented regulatory landscape. Companies operating in the UK must therefore navigate multiple regulatory frameworks without guaranteed harmonisation. For example, an AI system used in finance will be subject to FCA rules, while a recruitment tool will fall under the Equality and Human Rights Commission.
The UK also relies on voluntary initiatives, such as the AI Safety Institute, to test AI models before deployment. This approach aims to encourage innovation while mitigating risks, but it remains less binding than the European framework.
China: Targeted and Binding Regulations
China has adopted a fragmented but binding approach, with regulations targeting specific sectors.
China's regulatory framework focuses on three main areas: generative AI, algorithmic recommendations, and deepfakes. The Regulation on Generative AI Services, which entered into force in 2023, imposes strict obligations on AI model providers regarding security, transparency, and data protection. Companies must obtain a licence before offering generative AI services to the public.
The Regulation on the Management of Algorithmic Recommendations, applicable since 2022, governs the use of algorithms in digital platforms. It requires transparency and non-discrimination obligations, as well as the option for users to disable personalised recommendations. Deepfakes have also been regulated since 2022, with requirements for labelling and consent for synthetic content.
The Cyberspace Administration of China (CAC) is the primary regulator for AI. Its approach combines binding rules with close supervision of technology companies. Non-compliance penalties may include fines, service suspensions, or even criminal prosecution.
US: Balancing Innovation and Fragmented Regulation
The US oscillates between promoting innovation and regulation, with a legal framework still under construction.
The Biden administration had adopted an Executive Order on Safe, Secure and Trustworthy Artificial Intelligence in October 2023, establishing principles for responsible AI. This order imposed transparency obligations for high-risk AI systems and security testing for critical systems. However, the Executive Order was revoked by the Trump administration in January 2025, leaving the US without a binding federal framework.
In the absence of federal legislation, several states have adopted their own regulations. California, for example, introduced the California AI Transparency Act in 2024, which imposes transparency obligations for AI systems used in automated decision-making. Other states, such as New York, have passed laws targeting specific sectors, like facial recognition.
The US regulatory landscape remains fragmented, with limited federal initiatives. The Trump administration is currently working on an AI Action Plan, which is expected to prioritise innovation and limit regulations deemed overly restrictive. US companies must therefore navigate divergent state rules and an uncertain federal framework.
Strategies for Multinational Companies
Companies operating in multiple markets must adapt their compliance strategies to the specificities of each regulatory framework.
For companies present in the EU, the priority is to comply with the AI Act, particularly for high-risk AI systems and transparency obligations applicable since August 2026. An integrated approach, combining GDPR and AI Act compliance, can streamline documentation efforts. Multinationals can also leverage tools such as regulatory sandboxes to test their systems in real-world conditions.
In the UK, companies must identify the relevant sectoral regulators and adapt their compliance to the guiding principles. Close collaboration with legal teams and local regulators is essential to anticipate regulatory developments. Voluntary initiatives, such as security testing, can also enhance user trust.
In China, compliance requires precise sectoral analysis. Companies must identify the regulations applicable to their activities and work closely with the CAC. Transparency and data security are priorities, particularly for generative AI systems and algorithmic recommendations.
In the US, companies must monitor regulatory developments at both federal and state levels. A proactive approach, including internal audits and security testing, can mitigate legal risks. Companies can also rely on international standards, such as ISO, to demonstrate their commitment to responsible AI.
Identify Your Obligations in 3 Minutes
Our free assessment analyses your exposure to AI regulations in each region.
Frequently Asked Questions
Answers to the most common questions about AI regulatory frameworks.
Yes, if its AI systems are used in the EU or if their outputs affect individuals located in the Union. The AI Act applies extraterritorially, similar to the GDPR. For example, a US company selling an AI system to a French company must comply with the AI Act's obligations, particularly regarding transparency and technical documentation.
The five principles are: safety, transparency, fairness, accountability, and contestability. Each sectoral regulator is responsible for applying these principles within its remit. For example, the ICO focuses on transparency and data protection, while the FCA applies these principles in the financial sector.
Providers of generative AI systems must obtain a licence before offering their services to the public. They must also ensure data security, algorithmic transparency, and non-discrimination. Generated content must be labelled as such, and users must be able to report illegal or inappropriate content.
Enacted in 2024, this legislation imposes transparency obligations for AI systems used in automated decision-making in California. Companies must disclose the criteria used by their algorithms and allow users to challenge automated decisions. This law applies to companies operating in California, regardless of their location.
An integrated approach is recommended. Start by identifying the applicable regulations in each region. Prioritise compliance with the AI Act if you operate in the EU, as it is the most binding framework. Then adapt your strategy to local specificities, collaborating with legal and technical experts. Use tools such as internal audits and regulatory sandboxes to test your systems.
