Skip to content
💡 Innovation Ecosystem

AI Regulation Comparison 2026: Four Regimes, One Shipping Product

Francis Okafor Francis Okafor
10 min read
AI governance AI regulation EU AI Act China AI regulation African Union compliance engineering Shenzhen
AI Regulation Comparison 2026: Four Regimes, One Shipping Product
On this page
  1. The EU regulates the product before it moves
  2. The US optimises for speed, then argues over who may slow it
  3. China regulates the output, and puts the compliance on screen
  4. The African Union is building the thing it intends to govern
  5. What one product actually has to ship into all four
  6. Where an AI regulation comparison usually goes wrong
  7. The asymmetry nobody has priced
  8. Tools referenced
  9. Sources

Four governments looked at the same technology and produced four different kinds of document. Any honest AI regulation comparison starts there, not with a ranking of who is strictest. The European Union wrote a product safety regulation. The United States wrote executive orders and then went to court against one of its own states. China wrote a filing system with a visible label attached. The African Union wrote a strategy with a phase plan and a review scheduled for 2027.

Same technology. Four instruments. Four theories of where the risk actually sits, and four different moments at which a duty attaches to you.

I have spent eight years in Shenzhen writing software that ships into more than one of these at once. The useful question is never which regime is right. It is which artefact each one asks you to produce, and when.

The EU regulates the product before it moves

Brussels treats an AI system roughly the way it treats a lift or a medical device. Assess the risk class, assemble the technical file, place it on the market, keep the file inspectable. The underlying theory is that risk is a property of the product and can be established before anyone is harmed.

That theory got stress-tested in July 2026. The AI Act's obligations for stand-alone high-risk systems under Annex III, covering employment, education, credit, law enforcement and critical infrastructure, were due on 2 August 2026. Six days before that cliff, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 after publication in the Official Journal on 24 July. Annex III high-risk moved to 2 December 2027. High-risk AI embedded in products already covered by EU product safety law moved to 2 August 2028.

What did not move is the part most builders actually touch. The Article 5 prohibitions have applied since 2 February 2025. General-purpose AI model obligations have applied since 2 August 2025, with the Code of Practice published on 10 July 2025 and the mandatory public training-data summary template on 24 July 2025. Article 50 landed on schedule on 2 August 2026: disclose when a person is interacting with an AI system, mark generative output in a machine-readable format, label deepfakes visibly. A four-month grace applies only to machine-readable marking for generative systems already on the market before that date. The Commission published a Code of Practice on Transparency of AI-generated Content on 10 June 2026 and confirmed it as an adequate route to compliance.

Penalties sort the priorities. Prohibited practices reach 35 million euros or 7 per cent of worldwide turnover. Article 50 breaches reach 15 million euros or 3 per cent.

What the EU optimises for is certainty, in advance, in writing.

Each regime asks the same product for a different artefact. The EU wants a conformity file assembled before launch. The US produces a court record after. China wants a filing number and a visible label written at the point of generation. The African Union wants capability built before duties attach.
Each regime asks the same product for a different artefact. The EU wants a conformity file assembled before launch. The US produces a court record after. China wants a filing number and a visible label written at the point of generation. The African Union wants capability built before duties attach.
One artefact carries three different failure modes: a fine, a takedown, a docket.

The US optimises for speed, then argues over who may slow it

There is still no comprehensive federal AI statute. In August 2026 that remains true, and Congress has declined blanket preemption more than once, including in the FY2026 National Defense Authorization Act.

What exists instead is executive action and litigation. America's AI Action Plan arrived on 23 July 2025, alongside Executive Order 14319 on federal procurement of language models. Then Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence", signed 11 December 2025 and published in the Federal Register on 16 December. It directs the Attorney General to stand up an AI Litigation Task Force to challenge state AI laws, conditions some federal broadband funding on state regulatory choices and tasks the FTC and FCC with follow-on action.

The states legislated anyway. Texas brought TRAIGA into effect on 1 January 2026. California's Transparency in Frontier Artificial Intelligence Act, SB 53, signed 29 September 2025, took effect the same day, carrying penalties up to a million dollars per violation plus duties to publish a safety framework and report critical safety incidents.

Colorado shows the mechanism running end to end. xAI sued the Colorado Attorney General on 9 April 2026 over SB 24-205. The Department of Justice moved to intervene. A federal judge stayed enforcement on 27 April. On 14 May 2026 Colorado repealed its own law and replaced it with SB 26-189, a narrower automated decision-making framework effective 1 January 2027.

What the US optimises for is not being slowed down. The instrument is not a conformity file. It is a docket and a funding condition.

China regulates the output, and puts the compliance on screen

Chinese regulation attaches to the service and to what comes out of it.

The Interim Measures for generative AI services have applied since 15 August 2023. Public-facing services with public-opinion attributes must complete security assessment and algorithm filing before launch. As of 30 June 2026 the Cyberspace Administration of China reported 988 filed generative AI services and 598 registered applications or functions built on already-filed models.

Then labelling. The Measures for Labelling AI-Generated Synthetic Content, issued 14 March 2025 by the CAC with three other ministries, took effect on 1 September 2025 alongside the mandatory national standard GB 45438-2025. Two label types, both required. An explicit label a person can see. An implicit label written into file metadata, with fields such as provider code, content identifier and generation timestamp.

The amended Cybersecurity Law took effect on 1 January 2026 and names artificial intelligence directly for the first time. On 10 April 2026 the CAC and four other departments issued interim measures for anthropomorphic AI interaction services, effective 15 July 2026, covering companion chatbots and emotionally responsive assistants, with hard limits on virtual intimate relationships for minors and guardian consent required below fourteen. Ninety-six days from publication to enforcement.

Here is the thing you only notice by living with these products. In the EU, compliance is a document almost nobody outside the company will ever read. In China it is on screen. Open the About page of a domestic AI app in Shenzhen and the model name and filing number are printed there like a serial. Generated images carry a corner label with metadata underneath it. Compliance sits in the product surface, which changes who has to care about it. Not the legal team. The engineer who owns that view.

What China optimises for is a controllable output and a revocable permission.

The African Union is building the thing it intends to govern

The African Union Executive Council endorsed the Continental AI Strategy at its 45th Ordinary Session in Accra on 18 and 19 July 2024. It is a strategy, not a regulation. Five focus areas, an implementation plan running 2025 to 2030, a first phase across 2025 and 2026 aimed at governance structures, national strategies and resource mobilisation, and a review in 2027.

At the Global AI Summit on Africa in Kigali on 3 and 4 April 2025, forty-nine countries endorsed the Africa Declaration on AI across seven pillars, and delegates resolved to establish a 60 billion dollar fund and an Africa AI Council. The one binding continental instrument nearby is the Malabo Convention, adopted in 2014 and in force since 8 June 2023, and it governs cybersecurity and personal data rather than models.

The gap is in implementation. An OECD case study published in April 2026 counted sixteen of fifty-four African countries with a national AI strategy or policy framework. Nigeria, where I am from, published a draft national AI strategy through NITDA's research centre on 2 August 2024 and has been working toward a governance body since.

Reading this as absence misses what it is. You do not write conformity assessment procedures for an industry that has no domestic supply side yet. The AU is optimising for capability first: compute, data and people. Duties come after there is something local for them to attach to.

What one product actually has to ship into all four

Strip the politics and these four reduce to a small number of engineering decisions.

Provenance is written at generation time or not at all. Article 50 wants machine-readable marking on generative output. GB 45438-2025 wants metadata plus a visible label. That is one provenance writer and two label renderers, and it has to sit where the bytes are produced rather than in a wrapper bolted on later. Retrofitting means reprocessing everything already shipped. I have watched a team discover in week three that their image pipeline stripped metadata on the resize step, which had been correct engineering for four years and was now a compliance defect.

Assume the metadata will be destroyed. A screenshot removes it. So does most re-encoding. The visible label is the only marking that survives contact with a real user, which is precisely why both regimes demand both and why the visible one deserves the design attention nobody gives it.

Filing is a launch gate in one jurisdiction and nowhere else. In China the filing number goes into the product, so it belongs on the release checklist next to the version string, not in a legal folder.

The documentation set needs a single source. The GPAI public training-data summary uses the Commission's template. SB 53 wants a published frontier framework and incident reports. These describe the same system to different readers and they will drift apart the moment two teams own them separately.

Human review is the next deadline, not the last one. Colorado's replacement law lands on 1 January 2027 with pre-use notice, meaningful human review and a thirty-day explanation for adverse outcomes. EU Annex III high-risk lands on 2 December 2027. Eleven months apart. Build the review path once.

Make jurisdiction a runtime value. Region-scoped policy resolved per request, not a build flag frozen at deploy time. Every date in this article has already moved once.

Where an AI regulation comparison usually goes wrong

The strongest objection to all of the above is that these regimes are converging and the differences are mostly cosmetic.

There is real evidence for it. Article 50 and GB 45438-2025 ask for near-identical artefacts. California's SB 53 reads like a thinner version of the AI Act's general-purpose chapter. Incident reporting, transparency, provenance and content labelling appear in every one of them. So build a single global baseline at the strictest level, ship it everywhere and stop modelling four jurisdictions.

I concede most of that on the artefacts, and I have argued for exactly that baseline on the provenance layer. Where it breaks is the trigger.

The obligated party differs. The EU fixes your role, provider or deployer, before market placement, and the duty follows the role. China attaches the duty to a filing that gates launch and can be withdrawn. The US attaches it to whoever a plaintiff can reach, and in April 2026 the federal government intervened on the side of the company suing the state.

So one artefact carries three different failure modes: a fine, a takedown, a docket. A baseline built to the strictest text gets you the paperwork and none of the timing, and timing is the part that has actually moved. The high-risk deadline slipped sixteen months. Colorado's law was repealed by its own legislature five weeks after being stayed. A compliance posture pinned to a calendar decays faster than the code it governs.

The asymmetry nobody has priced

Notice what each regime can do quickly.

The EU can defer its own hardest deadline by sixteen months with a regulation that entered into force six days before the cliff. China can bring an entirely new service category under binding rules in ninety-six days. The United States can have a state law stayed eighteen days after a company files suit. Three levers, all fast, all aimed at different parts of the stack.

The African Union has a review date and no lever, which is the honest position for a continent still building its own supply side. Sixteen national strategies out of fifty-four reads like failure only if you assume the rules should arrive first. Sequencing looks like this when compute and talent are the binding constraint.

All three levers act on the same narrow thing: where a model is served. Not where it was trained. Not where the harm lands. A model trained in one jurisdiction, served from a second and used in a third answers mostly to the third, which means the fastest route to changing what any model may say is to regulate the shelf rather than the model. The shelf is an app store, a cloud region and a filing number. None of the four controls all three, and the regime closest to controlling its own shelf is the one whose rules everyone outside it finds hardest to read.

Tools referenced

Langfuse, reviewed here: Langfuse review.

Promptfoo, reviewed here: Promptfoo review.

Arize Phoenix, reviewed here: Arize Phoenix review.

garak, reviewed here: garak review.

NVIDIA NeMo Guardrails, reviewed here: NVIDIA NeMo Guardrails review.

vLLM, reviewed here: vLLM review.

Sources

EU AI Act, Article 50: Transparency Obligations: https://artificialintelligenceact.eu/article/50/

European Commission: Code of Practice on Transparency of AI-generated Content: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content

Cyber Law Watch (K&L Gates): EU Digital Omnibus on AI Enters Into Force: https://www.cyberlawwatch.com/2026/07/31/eu-digital-omnibus-on-ai-enters-into-force/

White House: Eliminating State Law Obstruction of National Artificial Intelligence Policy (EO 14365): https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/

Norton Rose Fulbright: xAI sues, DOJ intervenes, enforcement of Colorado's AI Act suspended: https://www.nortonrosefulbright.com/en/knowledge/publications/de3ad9de/xai-sues-doj-intervenes-enforcement-of-colorado-ai-act-suspended

China Law Translate: Measures for Labeling AI-Generated Synthetic Content: https://www.chinalawtranslate.com/en/ai-labeling/

African Union: Continental Artificial Intelligence Strategy (July 2024): https://au.int/sites/default/files/documents/44004-doc-EN-_Continental_AI_Strategy_July_2024.pdf

OECD: Strengthening AI Governance in Africa (April 2026): https://www.oecd.org/en/publications/oecd-artificial-intelligence-case-studies_c517fcf5-en/ai-governance-in-africa_1ff55135-en.html

Frequently Asked Questions

Which EU AI Act obligations actually applied from 2 August 2026?

From 2 August 2026 the Article 50 transparency duties applied: disclosing that a person is interacting with an AI system, marking generative output in a machine-readable format and visibly labelling deepfakes. General-purpose AI model obligations had already applied since 2 August 2025 and the Article 5 prohibitions since 2 February 2025. The high-risk obligations originally due on 2 August 2026 did not apply, because Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved stand-alone Annex III high-risk systems to 2 December 2027 and high-risk AI embedded in regulated products to 2 August 2028. Article 50 breaches carry fines up to 15 million euros or 3 per cent of worldwide turnover.

Does the United States have a federal AI law?

No. As of August 2026 there is no comprehensive federal AI statute. Federal AI policy runs through executive action, principally America's AI Action Plan of 23 July 2025 and Executive Order 14365 of 11 December 2025, which directs the Department of Justice to challenge state AI laws through an AI Litigation Task Force and conditions some federal funding on state regulatory choices. Binding obligations therefore come from the states. Texas TRAIGA and California's SB 53 both took effect on 1 January 2026, and Colorado repealed its 2024 AI Act and replaced it with SB 26-189, effective 1 January 2027, after a federal judge stayed enforcement of the original law in April 2026.

What do China's AI content labelling rules require?

Since 1 September 2025, China's Measures for Labelling AI-Generated Synthetic Content and the mandatory national standard GB 45438-2025 require two labels on AI-generated text, images, audio, video and virtual scenes distributed on Chinese platforms. An explicit label a user can see. An implicit label written into the file's metadata, with fields such as provider code, content identifier and generation timestamp. Removing or tampering with labels is prohibited, and public-facing generative services with public-opinion attributes must separately complete security assessment and filing with the Cyberspace Administration of China before launch, then display the model name and filing number in the product.