Skip to content

AI Act (EU) vs United States: two models of AI regulation in 2026

We already covered how AI is regulated across 10 Latin American countries. Across the Atlantic, the contrast with the EU couldn't be sharper: while the AI Act moves into effective enforcement with multimillion-euro fines, the United States still has no federal law — and the White House is actively litigating against the states that do legislate.

The EU: a single regulation, centralized enforcement

As of August 2, 2026, the European Commission's AI Office and national authorities are effectively enforcing the AI Act. Chatbots must disclose they're AI, deepfakes must be labeled, and AI-generated content must carry machine-readable markings — these are the Art. 50 transparency obligations. Non-compliance can bring fines of up to €15 million or 3% of global turnover, whichever is higher. It's a single regulation, directly applicable across all 27 member states, with no need for case-by-case national transposition.

The US: no federal law, and the White House against the states

The United States has no comprehensive federal AI law equivalent. What does exist is an open front between the federal government and the states. Executive Order 14365 ("Ensuring a National Policy Framework for Artificial Intelligence"), signed on December 11, 2025, creates a litigation task force at the Department of Justice dedicated exclusively to challenging state AI laws, and directs the FTC to issue a statement within 90 days on when those laws are preempted by federal rules against deceptive practices — while also asking the FCC to explore a federal disclosure standard to replace state ones.

Meanwhile, the states haven't slowed down. California enacted the Transparency in Frontier AI Act (SB 53) on September 29, 2025, requiring large frontier model developers (over $500 million in annual revenue) to publish a safety framework, transparency reports, and notify critical incidents. During 2026, at least 19 more states passed chatbot safety laws — Connecticut, California SB 243, Utah, among others.

The voluntary standard filling the gap: the NIST AI RMF

In the absence of a federal law, the NIST AI Risk Management Framework has become the de facto reference vocabulary that corporate buyers and insurers in the US use to assess a vendor's AI risk-management maturity. It isn't mandatory, but it functions similarly to how an ISO framework operates outside a legal mandate: a company that can't demonstrate alignment with it loses competitiveness in corporate procurement, even though no authority requires it by law.

What this means if you operate on both sides

For a company with operations in both the EU and the US, the challenge isn't just complying with two different frameworks — it's managing opposite regulatory directions: in the EU, obligations are growing and centralizing; in the US, uncertainty is growing because the legal framework itself is disputed between levels of government. The most robust strategy is to build the governance program around the more demanding standard (the AI Act) and use it as the base for responding to both US state laws and the NIST AI RMF, rather than maintaining separate compliance programs that fall out of sync every time the US legal map changes.

Build your program on the more demanding standard

AI Act Starter Kit to kick off European compliance, and the Risk Classification Checklist to know which category each system falls into.

View AI Act Starter Kit → View Risk Classification →