AI Governance Frameworks

Mark BarclayMark Barclay·Founder & Curator, SynaBot·

A Comparison of Global Approaches

This article is part of my series on AI safety and governance. If you're new to this topic, I'd suggest starting with the pillar article for the broader context before diving into this comparison.

Why I Wanted to Write This Piece

When I first tried to get a handle on how AI is regulated around the world, I expected to find something like a single emerging standard, the way I'd seen happen with, say, data privacy law following the EU's lead. What I found instead was something messier: three major jurisdictions taking genuinely different approaches, each shaped by different political priorities, and each still actively evolving as I write this.

I want to walk through the European Union, the United States, and China, not because these are the only places that matter, but because I think they illustrate three distinct philosophies that I see echoed in how other countries are approaching this space too.

The European Union: A Comprehensive, Risk-Tiered Approach

Of the three, I think the EU has gone furthest in building a single, comprehensive law specifically for AI. The EU AI Act entered into force in August 2024, but I want to stress that "entered into force" and "fully in effect" are different things here. The Act has a phased rollout, with different obligations kicking in at different dates.

As of where things stand now, the prohibitions on certain AI practices and AI literacy obligations have already applied since early 2025, and rules for general-purpose AI models, including the regime for systemic-risk models, became applicable in August 2025, alongside the establishment of governance structures like the EU AI Office. The bulk of the remaining provisions, including the high-risk system requirements that I think most businesses are watching most closely, were set to become applicable in August 2026.

What I find most interesting, though, is how much this timeline has been shifting even in the lead-up to that date. In May 2026, the EU provisionally agreed to material changes through what's being called the Digital Omnibus on AI, which postponed key compliance deadlines and published draft guidance on high-risk system classification and transparency requirements. As part of that agreement, the deadline for member states to establish AI regulatory sandboxes was pushed back to August 2027, while the grace period for providers to implement transparency solutions for AI-generated content was actually shortened, from six months to three, with a new deadline of December 2026.

I think the lesson I take from this is that even the most comprehensive AI law in the world is still very much a living document. The core structure, a risk-based tiering system with prohibited practices at the top and lighter obligations for lower-risk uses, seems stable. But the specific dates, thresholds, and implementation details are being actively negotiated even now.

The United States: A Shifting, Federalism-Driven Approach

If the EU's approach is defined by comprehensiveness, I think the US approach right now is defined by flux, specifically around the question of who gets to regulate AI at all: the federal government or individual states.

For a while, I watched a growing number of US states move to fill the regulatory gap left by the absence of comprehensive federal AI legislation. California's Transparency in Frontier Artificial Intelligence Act and Texas's Responsible Artificial Intelligence Governance Act were two prominent examples of state AI laws that went into effect on January 1, 2026.

But the federal posture toward this state-level activity shifted significantly. In December 2025, an executive order titled "Ensuring a National Policy Framework for Artificial Intelligence" established a federal policy aimed at promoting a uniform national framework for AI regulation and limiting the impact of conflicting state laws. I think the practical mechanisms here are worth understanding, because they're somewhat unusual. The order uses federal funding as leverage, authorizing agencies to condition discretionary grants on states refraining from enacting AI laws deemed inconsistent with the order's policy, and it directs the Federal Trade Commission to consider classifying state-mandated bias mitigation as a deceptive trade practice. It also conditions a significant amount of previously allocated broadband infrastructure funding on states repealing AI regulations the administration considers onerous.

This built on an even broader push. In July 2025, the White House released a three-pillar strategy focused on accelerating AI innovation, building infrastructure, and leading internationally, explicitly framed around removing what it called red tape and onerous regulation. By March 2026, the administration had gone further still, releasing a National Policy Framework that proposed Congress adopt legislation broadly preempting state AI laws deemed to impose undue burdens.

More recently, I've seen the federal approach add a national security dimension on top of the deregulatory one. In June 2026, a new executive order titled "Promoting Advanced Artificial Intelligence Innovation and Security" established new cybersecurity mandates alongside a voluntary framework for the secure deployment of frontier AI models. Among its provisions, it calls for AI developers to voluntarily share certain new models with the federal government up to 30 days before providing access to other partners, and it directs national security agencies to build a framework for evaluating AI-related risks, including an AI-cybersecurity clearinghouse.

I think what's important for me to convey here is that the US doesn't currently have anything resembling the EU's single comprehensive law. What it has instead is a fast-moving contest between state-level rules and a federal push toward preemption, layered with executive actions that blend deregulatory goals with emerging national security concerns. If you're trying to operate in the US, I think the honest answer right now is that the ground is still moving.

China: Sector-by-Sector, Standards-Heavy Regulation

China's approach looks different from both of the above, and I think the difference reflects different underlying goals. Rather than one overarching AI law, China has built up its regulatory framework through a series of measures targeting specific areas: AI algorithms, deep synthesis technologies, and generative AI services, alongside guidance on AI standards and ethical norms.

The piece of this I think is most distinctive is how much weight China places on technical standards and content labeling. In March 2025, the Cyberspace Administration of China released final measures for labeling AI-generated content, alongside a mandatory national standard for labeling methods, which took effect in September 2025. These rules made it mandatory for AI-generated content to be implicitly labeled in file metadata, and explicitly labeled where applicable, such as visible markers on text, audio, images, and video.

Beyond labeling, China has issued a cluster of cybersecurity technology standards covering generative AI, including requirements for data annotation security, basic security requirements for generative AI services, and security specifications for pre-training and fine-tuning data. I find this approach notable because it operates through detailed technical specifications as much as through broad legal principles.

There's also a registration dimension I think is worth flagging. Generative AI services in China that could influence public opinion are required to register with the national Algorithm Registry and undergo security assessments, and the underlying law places limits on AI services that touch on politically sensitive content. By 2025, I think this had matured from aspirational guidance into a set of concrete, enforceable obligations that companies operating in China need to actively comply with, including filing registrations and conducting privacy audits.

China has also signaled ambitions beyond its own borders. The country has proposed establishing a global AI cooperation organization, potentially headquartered in Shanghai, intended to coordinate international efforts on AI governance and share China's own approach with other countries.

The Comparison I Keep Coming Back To

When I try to summarize these three approaches for myself, I think of it roughly this way:

The EU is building a comprehensive legal architecture, organized around risk tiers, with dedicated institutions to oversee it, even as the specific deadlines and obligations within that architecture continue to shift.

The US is, at least for now, prioritizing minimal federal regulation and innovation, while actively working to prevent a patchwork of state laws from filling that gap, with national security considerations increasingly layered on top.

China is using a dense web of sector-specific rules and technical standards, with a strong emphasis on content labeling, registration, and alignment with state priorities, to manage AI within a framework that predates the current generative AI wave but has rapidly adapted to it.

What I Think This Means If You're Operating Across Borders

I think the most practical takeaway from all of this is that "AI compliance" isn't a single thing you can solve once. An organization operating in all three jurisdictions I've described here is, in effect, dealing with three different regulatory philosophies simultaneously, each with its own pace of change.

I've found that the EU's risk-tiering approach is useful even outside the EU, as a mental model for thinking about which of your AI systems deserve the most scrutiny. But I don't think it's safe to assume that satisfying EU requirements gets you most of the way toward satisfying US or Chinese requirements, because the underlying goals of these frameworks aren't the same. The EU is oriented around fundamental rights and risk to individuals. China's framework is oriented in significant part around content control and alignment with state objectives. The US, at least under the current federal posture, is oriented around minimizing regulatory burden and maintaining competitive and security advantages.

If you want to go deeper on who actually enforces these rules day to day, I've written a separate guide to the regulatory bodies and agencies involved in AI oversight. And if you're trying to figure out how your own organization should respond to this landscape regardless of which rules apply, I think my piece on AI risk assessment is the more useful next step, since building good internal risk practices tends to put you in a better position no matter which direction the regulatory winds are blowing.