AI regulation suffers from a perception problem: it sounds like a specialist topic, and it is actually a civic one. The rules being drafted now will shape who is accountable when an AI system denies your loan, whose voice can be cloned, what training data is fair game, and how much testing a powerful model gets before deployment. This guide is the citizen's map — the major approaches, what they actually regulate, and the underappreciated fact that does the most explanatory work: most AI harm is governed by laws that never mention AI. Details in this field move quarterly; the shapes below move slowly, and the shapes are what a reader needs.
The three great approaches
Europe: regulate by risk, comprehensively. The EU's AI Act — the world's first comprehensive AI law, phasing in across the mid-2020s — sorts uses into tiers: a banned category (social scoring, certain manipulative and surveillance uses), a high-risk category (hiring, credit, medical, critical infrastructure) carrying testing, documentation, and human-oversight obligations, transparency duties for chatbots and synthetic media, and additional obligations for the most powerful general-purpose models. Like the GDPR before it, its reach extends beyond Europe — it applies to systems placed on the EU market wherever built — and 'comply with the strictest regime once' economics give it influence far beyond its borders. [Businesses met this logic already](/work/ai-use-policy/) in this site's workplace track.
The United States: many hands, no single law. America has repeatedly come close to, and so far declined, a comprehensive federal AI statute. What exists instead is a working patchwork: existing federal agencies applying existing powers (the trade regulator on deceptive AI claims, employment and credit regulators on discriminatory systems), state legislatures moving faster than Congress on specific harms — deepfakes, hiring transparency, companion chatbots — executive actions that shift with administrations, and influential voluntary frameworks, led by the NIST AI Risk Management Framework. The recurring fights: whether federal law should preempt the states, and whether safety rules entrench incumbents or restrain them. The honest description of the US posture is *unsettled by design* — which means it is unusually responsive to who shows up.
China: state-directed and content-focused. The third major approach regulates earlier and harder on content and social stability — algorithm registration, synthetic-media labeling mandates, generated content aligned with state content rules — while simultaneously promoting AI development as national strategy. Its global relevance is twofold: it shapes what the second-largest AI ecosystem builds, and it stands as the standing reminder that 'more AI regulation' is not one direction — what gets regulated, and in whose interest, is the entire question.
The connective tissue
Around the big three: standards bodies (ISO's AI management standard, technical norms that quietly become procurement requirements), international forums producing mostly-voluntary coordination — safety summits, OECD principles, treaty efforts — and sectoral regulators everywhere applying medical, financial, and aviation rules to AI entering their domains. Unglamorous, and collectively influential: much of what companies actually do is set here, where compliance departments live.
The fact that reframes the whole map
Hold the headlines against this: fraud is already illegal when done with AI. Discrimination is illegal when a model does it. Defamation, harassment, false advertising, product liability — none of these lapse because the harm arrived through a model. A large share of 'unregulated AI' is really *under-enforced existing law*, straining against questions of attribution (who is liable — developer, deployer, user?) and capacity (regulators policing systems they lack the expertise to audit). This is why the serious policy agenda is less exotic than the discourse: clarify liability, fund enforcement, require the transparency that makes enforcement possible — [incident reporting, evaluation, disclosure](/society/understanding-ai-safety-debate/) — the same items both safety camps endorse. New law matters most at the frontier: training-data rights, frontier-model testing, and harms with no pre-AI analogue.
Reading it, and joining it
Three habits keep a citizen oriented: read regulatory news with [the same incentive lens as all AI news](/society/how-to-read-ai-news/) — 'innovation-killing red tape' and 'toothless giveaway' are usually the same bill described by its opponents; watch implementation rather than passage, since a law's meaning is set in enforcement actions and court tests years after the signing photo; and notice the leverage points that are actually open — state legislation, agency comment periods, and sectoral rules move on timescales where organized attention genuinely registers. The technology's trajectory may be set in a handful of labs. The rules it operates under are set in rooms with public doors — and the era in which showing up matters most is precisely the unsettled one you are living in.