Public Education · September 27, 2026
Who Regulates AI? A Simple Guide to a Complicated Landscape
Who Regulates AI? A Simple Guide to a Complicated Landscape
Introduction
If you want to understand how AI is governed in the United States, imagine a map of the London Underground being used to navigate Tokyo. That is roughly the situation today: the systems we most depend on are global, fast-moving, and increasingly powerful, while the rules that govern them are fragmented, slow-moving, and written for technologies that no longer exist.
This is not because regulators are lazy or corrupt (though individual cases exist). It is because AI governance is genuinely hard. It spans multiple levels of government, multiple sectors of the economy, and multiple definitions of what “AI” even means. This article is a map of that complicated landscape - not a legal treatise, but a practical guide for real people who want to know who, exactly, is responsible for keeping these systems in check.
The Three Major Models of AI Governance
Most AI governance around the world falls into one of three models, though many countries blend elements of all three:
- The US approach: sector-specific, largely voluntary, incentive-driven
- The EU approach: comprehensive, horizontal, rights-based
- Global bodies: principles, standards, and coordination without binding authority
Understanding which model a country follows tells you a great deal about what its rules can and cannot do.
The US Approach: Sector-Specific and Voluntary
The United States does not have a comprehensive AI law. Instead, it relies on:
- Existing regulators applying old laws to new systems (FTC on deception and unfairness, EEOC on hiring discrimination, CFPB on lending)
- Executive actions that direct agencies but bind only the executive branch
- Voluntary frameworks that companies adopt by choice, not obligation
- State-level laws filling the federal gap (Colorado’s AI Act, Illinois’ BIPA, Texas’ responsible AI law)
The result is a patchwork that protects consumers unevenly depending on the sector and the state.
The EU AI Act: The World’s First Comprehensive AI Law
The European Union took a different approach: the AI Act, passed in 2024, is the world’s first comprehensive AI regulation. It classifies AI systems into risk tiers:
- Unacceptable risk: banned outright (social scoring, manipulative systems)
- High risk: heavily regulated (employment, credit, essential services, law enforcement)
- Limited risk: transparency requirements (chatbots that must disclose they are AI)
- Minimal risk: unregulated
The Act applies to any company serving EU customers regardless of where it is headquartered - which is why it has become the de facto global standard, a phenomenon known as the “Brussels Effect.”
Global Bodies: Coordination Without Authority
UNESCO, the OECD, the Council of Europe, and the UN have all issued AI principles and recommendations. The G7 launched the Hiroshima Process. The UK hosted the first AI Safety Summit. These efforts matter because they build consensus and vocabulary - but none of them can enforce anything. They are soft power in a hard-power problem.
Key Frameworks: What Each Actually Does
NIST AI Risk Management Framework
The US National Institute of Standards and Technology released its AI Risk Management Framework (RMF) in January 2023. It is voluntary. It organizes AI governance into four functions:
- Govern: culture, processes, structures
- Map: context and risks
- Measure: test and evaluate
- Manage: allocate resources and mitigate
Its strength is specificity; its weakness is that nobody has to follow it.
US Executive Orders
Executive Order 14110 (October 2023) was the most significant US action to date. It required:
- Safety testing for models above a compute threshold
- Reporting requirements for large training runs
- NIST guidance on red-teaming
- Safety programs for critical infrastructure
Its vulnerability is structural: an executive order binds the executive branch and can be rescinded by the next president, which is exactly what happened in January 2025.
The EU AI Act
The Act entered into force in August 2024 with obligations phasing in through 2026-2027. It bans practices like emotion recognition in workplaces and schools, restricts facial recognition databases, and requires fundamental rights impact assessments for high-risk systems.
Why Regulation Lags Behind Innovation
The Pacing Problem
AI development cycles are measured in months. Legislative cycles are measured in years. By the time a law is passed, the technology it targets has already been replaced by something its drafters never imagined.
The Complexity Problem
AI systems are opaque even to their builders. Asking a legislature to write precise technical requirements for systems that evolve faster than committees can meet is asking for either vagueness (which lacks teeth) or specificity (which is obsolete on arrival).
The Political Problem
AI governance crosses traditional ideological lines in strange ways. It touches free speech, copyright, national security, labor, and civil rights simultaneously. Coalitions that form for one issue dissolve for the next.
The Role of Companies vs. Governments
Voluntary Commitments and Their Limits
The White House secured voluntary commitments from major AI companies in July 2023. Seven companies promised safety testing, watermarks, and vulnerability disclosure. These commitments matter as signals, but they have three structural limits:
- They bind only the companies that made them
- They can be abandoned when boards or markets change
- There is no consequence for non-compliance
Mandatory Standards and Enforcement
The pattern across history - auto safety, aviation, pharmaceuticals, food - is consistent: voluntary standards raised the floor somewhat, but binding rules with enforcement are what actually protected the public. The question for AI is not whether this pattern will repeat, but when and at what cost of waiting.
What “Responsible AI” Means in Policy Terms
In policy documents, “responsible AI” typically bundles:
- Risk management before and after deployment
- Transparency and disclosure obligations
- Human oversight requirements
- Bias testing and impact assessments
- Accountability and redress mechanisms
The term is doing real work, but it is also in danger of becoming what “organic” was before standards defined it: a meaningful word stretched until it loses meaning.
Conclusion: Governance as a Living System
AI governance is not a single law to pass but a system to maintain - closer to environmental regulation or financial oversight than to a one-time product standard. The lesson from every mature governance domain is the same: start early, build capacity, expect iteration, and never mistake the absence of catastrophe for the presence of safety.