A crisp, evenhanded side-by-side of the European Union, United States, and Chinese approaches to AI governance — one clean comparison table plus analysis of the philosophical divides and cross-border conflicts. A policy-audience map of the global regulatory landscape.
Author: Krishita Sanjay Choksi (@Krishita17) As-of date: 25 August 2026 · Stance: descriptive and non-advocacy · Type: comparative policy analysis (not legal advice)
Three regimes shape the rules for most of the world's AI, and each answers the same question — how should a powerful, general technology be governed? — from a different starting philosophy:
- The European Union enacts one comprehensive, risk-tiered statute that applies horizontally across sectors before systems reach the market.
- The United States relies on a distributed mix of executive action, voluntary frameworks, sectoral agency authority, and state laws rather than a single omnibus statute — governing largely after the fact through existing law.
- China issues targeted, application-specific rules that arrive quickly as each new class of AI service emerges, combining ex-ante filing and security review with ex-post enforcement.
This report is deliberately evenhanded. It describes each regime in its own terms —
rights-centric, innovation-centric, and stability/control-centric respectively — without
ranking them morally or claiming one is "best." The value of a comparison like this is
its neutrality and its currency; AI governance moves fast, so every claim below is dated
and mapped to a source in data/sources.csv.
The table is the centerpiece. It stays factual and short; the analysis sections carry the
nuance. A machine-readable version lives in
data/comparison_table.csv and
data/comparison_table.json.
| Dimension | European Union | United States | China |
|---|---|---|---|
| Primary instrument(s) | Regulation (EU) 2024/1689 (the "AI Act") — a single binding horizontal statute — plus the voluntary GPAI Code of Practice (Jul 2025). | No omnibus statute. Executive Orders (14179, Jan 2025; the Jul 2025 AI Action Plan orders; 14365, Dec 2025), the voluntary NIST AI RMF, sectoral agency authority, and state laws (e.g., Colorado AI Act, Texas TRAIGA). A National AI Policy Framework (Mar 2026) proposes legislation. | A suite of targeted CAC rules: Algorithm Recommendation (2022), Deep Synthesis (2023), Generative AI Interim Measures (2023), AI-Generated Content Labeling + standard GB 45438-2025 (2025), Humanised AI Interactive Services (2026), atop the amended Cybersecurity Law. A comprehensive AI Law remains in draft. |
| Regulatory philosophy | Comprehensive, horizontal, risk-tiered. Ex-ante, rights-centric. | Distributed and sectoral. Innovation-centric, largely ex-post; federal deregulation and preemption vs. active state legislation. | Targeted, application-specific. Stability/control- and industrial-policy-centric; ex-ante filing plus ex-post enforcement. |
| Scope | Providers, deployers, importers, distributors of AI systems, plus GPAI model providers, where systems reach the EU market or outputs are used in the EU. | No single scope: federal focus on agencies, procurement, and frontier developers; state laws reach "consequential decisions"; sector regulators apply existing mandates. | Providers of covered public-facing services in China (recommendation, deep synthesis, generative and human-like AI). Non-public R&D largely excluded. |
| Risk approach | Four tiers — unacceptable (banned), high-risk, limited (transparency), minimal — plus a separate GPAI / systemic-risk track. | Principles/risk-based but voluntary federally (NIST's Govern-Map-Measure-Manage). Some states import risk-tiering for algorithmic discrimination. | No single taxonomy; duties keyed to the application, intensifying where a service has "public-opinion properties or social-mobilization capacity." |
| Prohibited / restricted uses | Bans social scoring, manipulative/subliminal techniques, untargeted facial scraping, emotion recognition at work/school, most real-time public biometric ID by police. | No AI-specific federal bans; existing anti-discrimination, consumer-protection and fraud law applies. Procurement policy presses for "objective" models. | Bars content endangering national security or "core socialist values," inciting subversion, or spreading false/harmful information; unregistered public generative services not permitted. |
| Transparency / disclosure | Art. 50: disclose AI interaction and mark synthetic content; high-risk documentation and logging; GPAI technical docs + training-data summary. | No general federal mandate; NIST RMF encourages documentation. States (e.g., Colorado) require notice for consequential decisions; sectoral deepfake/election/biometric rules. | Mandatory explicit + implicit (metadata) labeling of AI content under the 2025 Measures/GB 45438-2025; provider registration, real-name users, content-moderation duties. |
| Enforcement | National market-surveillance authorities + EU AI Office (GPAI). Fines up to €35M/7% (prohibited), €15M/3% (obligations), €7.5M/1% (misinformation). | Distributed across existing agencies (FTC, EEOC, FDA, CFPB) and state AGs; no AI-specific federal penalty regime. A federal AI Litigation Task Force challenges state laws. | CAC-led with sectoral bodies; filing, security assessment, rectification, takedowns, suspension, licence revocation. Amended CSL raises fines up to CNY 50M or 5% of turnover. |
| Extraterritorial reach | Broad: binds non-EU actors when a system reaches the EU market or its output is used in the EU. | Limited/indirect: no AI-specific extraterritorial statute; foreign firms reached via general US market jurisdiction and state law. | Primarily domestic, but the Generative AI Interim Measures reach services offered to the public in China regardless of provider location. |
| Status / maturity | In force (Aug 2024); phasing in — prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk Dec 2027 / Aug 2028 (some dates adjusted by the 2025 Digital Omnibus). | Evolving and administration-dependent; deregulatory + preemption trend vs. an expanding state patchwork. No omnibus law as of Aug 2026. | In force and fast-moving; earliest rules 2022, layered additions through 2026; comprehensive law still pending. |
European Union. The AI Act is the world's first comprehensive, horizontal AI statute. It sorts systems into risk tiers: a short list of unacceptable uses is banned outright; high-risk systems (in areas such as employment, education, biometrics, and critical infrastructure) carry heavy duties around risk management, data quality, documentation, human oversight, and conformity assessment; limited-risk systems owe transparency; and everything else is largely unregulated. A parallel track governs general-purpose AI (GPAI) models, with extra duties for those posing "systemic risk." The philosophy is ex-ante and rights-centric: obligations attach before a product reaches users, proportionate to the risk it poses to health, safety, and fundamental rights.
United States. There is no federal omnibus AI law. Governance is distributed across the executive branch (a sequence of Executive Orders and the July 2025 AI Action Plan), the voluntary NIST AI Risk Management Framework, existing sector regulators applying existing law (employment, credit, health, consumer protection), and — most consequentially in practice — a growing patchwork of state statutes. The federal posture in this period is deliberately deregulatory and innovation-centric, and it actively seeks to preempt state rules it views as fragmenting the market (via EO 14365's litigation task force and the March 2026 National AI Policy Framework's legislative proposals). The result is a regime defined by tension between federal restraint and state activism.
China. China governs AI through a series of targeted, application-specific regulations issued mainly by the Cyberspace Administration of China (CAC), each aimed at a particular class of service: recommendation algorithms (2022), deep-synthesis/synthetic media (2023), generative AI (2023), AI-content labeling (2025), and human-like interactive services (2026). Common threads run through them — algorithm registry filing, security assessment, real-name identification, content-moderation duties, and an overriding requirement that services uphold social stability and "core socialist values." The philosophy blends ex-ante control (filing and pre-clearance for higher-impact services) with fast, iterative rulemaking and industrial-policy support for the domestic AI sector.
Figure 1 places the three regimes on two descriptive axes — regulatory form and timing of obligation. Positions are analytical framing, not a ranking.
The three diverge along several axes at once:
- Form: comprehensive vs. distributed vs. targeted. The EU writes one statute for all AI. The US spreads authority across many instruments and levels of government. China writes many narrow rules, one application at a time.
- Timing: ex-ante vs. ex-post. The EU and China impose duties before a system reaches (or as it reaches) the public — conformity assessment in the EU, filing and security review in China. The US federal approach leans ex-post, letting existing law catch harms after they occur, though several state laws add ex-ante notice duties.
- Primary value: rights vs. innovation vs. stability. The EU frames AI risk around fundamental rights and safety. The US frames it around competitiveness, innovation, and now free-expression and national-security concerns. China frames it around social stability, information control, and national technological strength.
None of these framings is reducible to the others, and each is internally coherent on its own terms — which is precisely why cross-border compliance is hard.
Figure 2: which layers of the AI stack each regime touches directly. Coverage gaps and overlaps are where cross-border friction lives.
For a company deploying one model across all three markets, obligations do not simply stack — they can pull in different directions:
- Synthetic-content disclosure. All three now require some labeling of AI-generated content, but the what, how, and when differ: China mandates both visible labels and embedded metadata under a national standard; the EU's Art. 50 requires marking in a machine-readable, detectable way; US obligations are sectoral and state-specific. A single labeling implementation rarely satisfies all three cleanly.
- Content and values restrictions. China requires outputs to uphold "core socialist values" and to filter prohibited content; the EU and US protect expression and non-discrimination in ways that can be in direct tension with those content mandates. A model tuned for one market may be non-compliant or commercially unviable in another.
- Transparency and documentation. The EU's high-risk and GPAI documentation duties are detailed and prescriptive; the US relies on voluntary frameworks; China ties disclosure to registration and moderation. Meeting the EU's paperwork does not discharge China's filing duties, and vice versa.
- Filing and pre-clearance. China's registry filing and security assessment have no clean US analogue and only partial EU overlap (conformity assessment for high-risk), so global deployers maintain parallel compliance tracks.
Figure 3 summarizes where obligations pull apart most sharply for a deployer serving two regimes at once. This "interoperability gap" — the absence of mutual recognition or common formats — is the report's central analytical point.
Where they are quietly converging:
- Transparency for synthetic media. All three regimes are moving toward mandatory labeling/disclosure of AI-generated content — arguably the strongest point of de facto common ground.
- Risk assessment as method. The vocabulary of risk assessment, documentation, and post-deployment monitoring appears in all three (the EU's conformity assessment, the US NIST RMF and state risk-based laws, China's security assessments), even if the legal force differs.
- Attention to frontier / general-purpose models. Each regime has, in its own idiom, turned to the most capable models as a distinct governance object.
Where differences are hardening:
- The role of the state in content. China's content-and-values requirements and the US's free-expression framing are moving further apart, with the EU somewhere in between.
- Federal vs. supranational vs. central authority. The EU centralizes at the Union level, China at the national level, while the US is actively contesting whether authority sits federally or with the states.
- Ex-ante burden. The EU's and China's pre-market duties contrast with a US federal turn toward reducing regulatory burden — a widening gap in when obligations bite.
Figure 4: relative maturity and momentum. The EU and China have been building binding rules since 2022–2024; the US picture is the most recent and the most in-flux.
Figure 5: headline maximum penalty caps as a share of turnover. The US bar is zero because federal enforcement is not AI-specific — not because exposure is absent — so this is only partly like-for-like.
Figure 6: cumulative binding, AI-specific instruments in force. Illustrative of pace, not completeness; US state laws and voluntary frameworks are deliberately excluded.
Responsible experts disagree, in good faith, on several tensions this landscape raises. Presented as positions with tradeoffs, not a verdict:
- Ex-ante certainty vs. ex-post flexibility. Pre-market rules give clarity and protect rights early, but risk freezing fast-moving technology; ex-post regimes preserve flexibility but leave harms to be litigated after the fact. Reasonable people weigh these differently.
- Harmonization vs. sovereignty. Common formats (e.g., for content provenance) would ease the interoperability gap, but each regime guards its own values and security priorities. How much convergence is achievable without one regime importing another's value choices is genuinely contested.
- Innovation vs. precaution. Whether heavier ex-ante rules meaningfully slow beneficial innovation — or simply raise the floor — is an open empirical question the three regimes are, in effect, running as a natural experiment.
- Who governs frontier models. Voluntary codes, binding statutes, and registry-plus- assessment regimes are three live answers; none has yet proven itself at scale.
AI governance is a live, fast-moving field, and the US picture in particular shifts with
administrations while the EU and Chinese rules keep phasing in. This analysis is a
snapshot as of 25 August 2026. Every table cell and claim is mapped to a dated source in
data/sources.csv; primary/official texts are preferred over
aggregators, and each regime is described as its own drafters frame it. Where the situation
is contested or in flux (e.g., the EU's Digital Omnibus adjustments, US state-preemption
litigation, China's pending comprehensive AI Law), the report says so explicitly. See
docs/methodology.md for chosen dimensions, sourcing rules, and
limitations.
GovCompass/
├── README.md # this report (short form)
├── LICENSE # CC-BY-4.0 (docs/data); code portions MIT
├── CITATION.cff # citation metadata (author: Krishita Sanjay Choksi)
├── data/
│ ├── comparison_table.csv # machine-readable master table
│ ├── comparison_table.json # generated JSON mirror
│ └── sources.csv # every claim ↔ dated source
├── figures/ # generated: spectrum, coverage, conflict, timeline, penalties, momentum
├── scripts/
│ └── build_figures.py # regenerates figures + JSON from data/
├── report/
│ └── full_report.md # long-form version
├── paper/
│ ├── govcompass_ieee.tex # IEEE-format paper
│ └── govcompass.bib # references
└── docs/
├── methodology.md # dimensions, sourcing rules, as-of date, limitations
└── executive_summary.md # one-page summary
python3 -m venv .venv && source .venv/bin/activate
pip install matplotlib
python scripts/build_figures.pyIf you use this work, please cite it (see CITATION.cff):
Choksi, Krishita Sanjay. GovCompass: A Comparative Analysis of AI Governance — EU vs. US vs. China. 2026. https://github.com/Krishita17/GovCompass
Report, table, and documentation: CC-BY-4.0. Code in scripts/: MIT.
© 2026 Krishita Sanjay Choksi. See LICENSE.
This is descriptive comparative policy analysis for a general policy audience. It is not legal advice, is not exhaustive of every sub-rule or sector carve-out, and reflects a stated as-of date in a fast-moving field. Verify against primary sources before relying on any point.





