The Regulatory Landscape in AI


How Governments Are Racing To Keep Pace With The Machine

Image denoting AI regulation, it visually communicates our topic 'The Regulatory Landscape in AI'

Artificial Intelligence (AI) is transitioning from a technological phenomenon to a transformative force reshaping economies, societies, and regulatory regimes worldwide. In 2026, AI governance is no longer a theoretical debate –  it’s a practical reality that businesses must navigate.

Governments are pursuing regulations to ensure AI systems are safe, ethical, transparent, and compatible with fundamental rights. From the European Union’s groundbreaking Artificial Intelligence Act (AI Act) to evolving frameworks in the United States and beyond, regulators are stepping into terrain that once seemed too complex to legislate.

Below, we unpack what’s here, what’s coming, and what organizations should prepare for now.

What’s Here: Regulatory Foundations and Emerging Frameworks

AI governance has begun to crystallize around several key regulatory efforts that balance innovation with safety and accountability.

Europe’s Comprehensive Framework: The EU AI Act

The European Union has taken a pioneering role in AI regulation with the Artificial Intelligence Act, often referred to as the world’s first comprehensive AI regulation. Adopted in May 2024 and in force since August 1, 2024, the AI Act creates a unified legal framework applicable across all 27 EU member states.

Under this regulation:

  • AI systems are classified by risk level –  from minimal and limited risk systems to high-risk systems and those posing unacceptable risk.
  • Unacceptable risk AI (e.g., social scoring, manipulative systems) is banned, while high-risk AI (e.g., biometric identification, medical diagnostics) must meet stringent obligations on transparency, human oversight, and conformity assessments.
  • Limited-risk systems are subject to transparency obligations, and minimal-risk systems are largely unregulated.

This risk-based structure aims to protect fundamental rights, ensure safety, and provide legal clarity for developers and deployers of AI technologies. The AI Act also has extraterritorial implications –  non-EU businesses offering AI services to EU users must comply with its provisions irrespective of where they are based.

To support compliance, the EU has also introduced a General-Purpose AI Code of Practice focused on transparency, copyright, and safety, helping organizations interpret and meet certain legal obligations.

United States: A Patchwork of Initiatives

Unlike the EU’s consolidated approach, the U.S. regulatory landscape is fragmented, with activity dispersed across federal agencies, state governments, and executive actions.

At the federal level, previous executive orders –  such as Executive Order 14110 on safe and trustworthy AI –  have shaped foundational policy goals but have seen reversals and uncertainty with changes in administration.

At the same time, state-level laws are emerging. For example, California’s Transparency in Frontier Artificial Intelligence Act requires companies to publicly disclose catastrophic risk assessments for certain large AI models and establish whistleblower protections.

Beyond specific statutes, U.S. regulators like the Federal Trade Commission (FTC) and agencies overseeing sectors like healthcare and transportation are issuing guidelines and enforcing existing consumer protection, data privacy, and safety laws against harmful AI practices –  even in the absence of a comprehensive federal AI law.

Global Momentum Beyond the EU and U.S.

Internationally, other jurisdictions are moving toward AI governance through treaties and national laws. For instance, the Framework Convention on Artificial Intelligence, adopted under the Council of Europe in 2024, promotes transparency, accountability, non-discrimination, and human rights protection across more than 50 countries.

Even within Europe, individual countries like Italy have passed comprehensive AI laws aligned with the EU AI Act –  including criminal penalties for harmful AI misuse and protections for minors –  signaling how national implementation may vary within the broader EU regulatory architecture.

Image of small pawns denoting companies strategic movement around bureaucratic red tape.

EU AI Act, US Developments: Divergent Yet Growing

EU AI Act: A Model for Global Governance

The EU AI Act seeks not only to regulate but to shape the global AI ecosystem. It is built on principles similar to the EU’s General Data Protection Regulation (GDPR) –  aiming to safeguard individual rights while creating a predictable environment for innovation.

The Act’s phased implementation means obligations for most high-risk systems will be fully enforceable by mid- to late-2027, giving organizations a timeline to adapt.

Its prescriptive nature has drawn mixed reactions from the private sector. Some major tech companies have expressed concern about compliance burdens, while others view early adherence as providing competitive clarity.

U.S. Approach: Innovation-First and Decentralized

The U.S. approach continues to emphasize innovation and flexibility, with no overarching federal AI regulatory regime matching the EU’s breadth.

Instead, a combination of:

  • Executive guidelines,
  • Agency-specific rules,
  • State AI laws, and
  • Industry standards and voluntary frameworks shape the landscape.

This decentralization can spur innovation by avoiding one-size-fits-all mandates, but it also brings compliance complexity, especially for multinational companies that must navigate varying state and sectoral requirements.

What to Prepare for Now: Strategic Steps for Organizations

AI regulation isn’t on the horizon –  it’s unfolding now. Companies and institutions using AI need proactive strategies to stay compliant and competitive.

1. Understand Your Risk Profile

Start by mapping your AI systems according to risk categories –  especially under risk-based regimes like the EU AI Act. Determine which systems trigger high-risk compliance obligations (e.g., those influencing healthcare, hiring, criminal justice, or biometric identification).

2. Build Governance and Documentation Frameworks

Regulators, particularly in the EU, expect clear documentation, transparency, and human oversight. Establish internal governance structures for AI stewardship, including roles and responsibilities for compliance, impact assessments, and accountability reporting.

In the U.S., state laws like California’s SB-53 also require public documentation of risk assessments and safety measures.

3. Monitor Regulatory Timelines and Standards

AI regulatory frameworks are evolving. Track deadlines for phased implementation (e.g., the EU’s mid-2027 timelines) and participate in relevant codes of practice or standards consortia to shape compliance best practices.

4. Align with International Norms Where Possible

Even if operating outside the EU, consider aligning your AI practices with EU regulatory principles –  risk mitigation, transparency, data governance, and human oversight –  as these principles are increasingly influencing global norms.

5. Invest in Compliance Tools and Expertise

AI compliance intersects with data privacy, cybersecurity, and ethical AI use. Invest in tooling for model auditing, explainability, and risk assessment. Legal and compliance expertise –  including cross-jurisdiction counsel –  will be essential.

An image showing us the words 'regulation', this image is relevant to our understanding of the regulatory landscape in the AI space.

Conclusion: Regulation as an Opportunity

AI regulation is shaping into a defining pillar of technology governance in the 2020s. While the EU sets a structured, risk-based regulatory model, the U.S. leans toward decentralized, innovation-centric policies. Together, these regimes and emerging international agreements are establishing a new environment where responsible AI is not just best practice –  it’s required.

For organizations navigating this changing landscape, preparation now is synonymous with strategic advantage. By embracing governance frameworks, aligning with global standards, and anticipating regulatory shifts, businesses can turn compliance obligations into credibility and trust –  essential assets in the AI-powered future.