Who Regulates AI?

Mark BarclayMark Barclay·Founder & Curator, SynaBot·

A Guide to Government Bodies and Agencies

This article is part of my series on AI safety and governance. If you haven't read the pillar article yet, it'll help orient you to how this piece fits into the bigger picture. I'd also suggest reading my comparison of global governance frameworks alongside this one, since the two are closely related: that article covers what the rules say, while this one covers who's actually responsible for writing, applying, and enforcing them.

Why I Think This Is Its Own Topic

When I started mapping out who regulates AI, I expected to find a short list. What I found instead was something closer to a web: dedicated AI-specific bodies, existing regulators applying their authority to AI for the first time, voluntary standards organizations whose frameworks end up functioning almost like regulation in practice, and international bodies trying to coordinate across all of it. I think understanding this landscape matters because "is this AI system compliant" often depends entirely on which of these bodies you're asking.

The EU AI Office: A Body Built Specifically for This

I think the European Artificial Intelligence Office is the closest thing I've found to a regulator built from scratch specifically for AI. It was formed in early 2024 within the European Commission, and its core role is supporting the implementation of the EU AI Act and, at the EU level, supervising and enforcing obligations for providers of general-purpose AI models.

What strikes me about the AI Office is how it sits within a larger structure. I've seen it described as part of a multi-level governance arrangement that also includes the AI Board, sectoral regulators, and national authorities across the EU's member states. I think this layered structure makes sense given how broad the AI Act's scope is, but I also think it creates real coordination challenges. Larger member states tend to have more administrative capacity than smaller ones, and I think that gap could lead to uneven enforcement depending on where in the EU a system is being deployed or assessed.

I also want to flag something I think is easy to miss: enforcement of the AI Act's general provisions by the European Commission was set to begin around August 2026, while providers of general-purpose AI models already on the market before mid-2025 have a longer runway, until 2027, to come into compliance. I think this means the AI Office's practical role is still very much in the process of ramping up even as I write this.

The United States: Regulation Through Existing Agencies

I think the contrast with the US is stark. Rather than a dedicated AI regulator, the US approach relies on existing agencies applying their existing authority to AI-related issues, plus voluntary frameworks that function as informal standards even without the force of law.

The agency I see referenced most often is the National Institute of Standards and Technology, through its AI Risk Management Framework. I think it's important to be clear that this framework is voluntary, it doesn't carry legal force the way the EU AI Act does, but I've also seen it described as the de facto standard that other US guidance increasingly builds on. The framework is organized around functions like governing, mapping, measuring, and managing AI risk, and I think of it less as a law and more as a shared vocabulary that other parts of the US system, including sector regulators, have started to build on top of.

Beyond NIST, I think the Federal Trade Commission plays a more concrete enforcement role than people sometimes realize. My understanding is that the FTC continues to use its existing authority over unfair and deceptive practices as a tool against AI-related claims, particularly when companies overstate what their systems can do or fail to disclose that AI is processing consumer data.

I also think sector-specific regulation is where a lot of the real action is happening in the US. I've seen this play out concretely in financial services, where the Treasury Department released a framework in early 2026 that translates NIST's risk management principles into a large set of specific control objectives for financial institutions, covering things like model lifecycle governance and data governance, and ties into existing frameworks like SOC 2. I've also seen state-level activity in healthcare, where California's Health Care Services AI Act requires providers using generative AI for patient communications to disclose that fact and tell patients how to reach a human.

I think the honest summary of the US picture is that there's no single agency to point to. Instead, there's a voluntary framework that's become an informal baseline, layered underneath a set of existing regulators each applying their own authority to AI within their sector, plus an evolving and contested relationship between federal and state authority that I covered in more depth in my governance frameworks article.

Voluntary Standards Bodies That Function Like Regulators

I think one of the more interesting things I've learned in researching this topic is how much weight voluntary, non-governmental standards can carry in practice, even when they're not legally binding anywhere.

ISO/IEC 42001, the international standard for AI management systems, is the example I keep coming back to. It's certifiable, meaning organizations can actually be audited and certified against it, and while no regulation requires this certification, I've seen it described as increasingly expected in enterprise procurement, functioning almost as a trust signal between companies even in the absence of a legal mandate.

I think what's happening here is that organizations facing a fragmented regulatory landscape, the EU AI Act, NIST's framework, sector rules, state laws, are looking for something that lets them build one governance program that can be mapped onto multiple sets of requirements at once. I've seen NIST's framework and ISO 42001 described as complementary in this respect: NIST provides a risk management methodology, while frameworks like the EU AI Act define specific binding legal requirements, and ISO 42001 sits in between as a certifiable structure that can be mapped to both.

International Coordination Efforts

Beyond individual countries and standards bodies, I think it's worth knowing that there's a broader layer of international coordination happening, even if it's less binding than anything I've described so far. I've seen the OECD's AI Policy Observatory cited as tracking over a thousand AI policy initiatives across dozens of countries, which gives some sense of just how much activity is happening globally, even if much of it doesn't rise to the level of enforceable regulation.

I've also seen individual countries carve out distinctive positions worth watching. The UK, for instance, has taken what I'd describe as a deliberately light-touch, outcome-based approach, relying on existing regulators across different sectors rather than a single AI law, while also setting up a central function to monitor risks and coordinate across that fragmented landscape. I've seen Singapore highlighted as an early mover specifically on governance frameworks for agentic AI, systems that take actions rather than just producing outputs, which I think is a sign of where some regulatory attention is heading next.

China's regulatory bodies, which I covered in more depth in my governance frameworks piece, operate somewhat differently again, with the Cyberspace Administration of China playing a central role across multiple sector-specific measures, supported by national standards bodies that issue detailed technical specifications.

What I Think This Means in Practice

If I try to draw this together, I think the practical reality is that "who regulates AI" doesn't have a single answer, and I don't think it's likely to get a single answer anytime soon. For an organization operating across jurisdictions, I think this means dealing with at least three layers at once: dedicated AI regulators where they exist, like the EU AI Office; existing sector and consumer-protection regulators applying their authority to AI, which I think is the dominant pattern in the US; and voluntary standards that, while not legally binding anywhere, increasingly function as a shared baseline that other requirements get mapped onto.

I think the practical response I've seen organizations adopt is to build governance programs around the more general frameworks, like NIST's risk management approach or ISO 42001, and then layer jurisdiction-specific requirements on top, rather than trying to build a separate compliance program from scratch for every regulator they might encounter. Whether that approach holds up as enforcement actually ramps up, particularly in the EU from 2026 onward, I think is one of the more important open questions in this space right now.

If you're trying to figure out how your own organization should respond to this landscape, I think the more useful next step than trying to track every regulator individually is to look at the kind of internal practices I describe in my article on responsible AI development, since a solid internal governance program tends to translate reasonably well across most of the external frameworks I've described here.