AI 101 — What is AI regulation?
AI regulation is the set of laws, rules, and government oversight mechanisms that decide what AI systems may be built, how they must be tested and labeled, and who is on the hook when they cause harm. It is not one law — it is a patchwork, and right now the patchwork is being assembled in three places at once: Brussels, Washington, and the state capitals.
Why it matters right now
The European Union has the world's first comprehensive AI statute, and it started biting this year. The EU AI Act's Article 50 transparency obligations took effect on August 2, 2026: chatbots must tell users they are talking to a machine, providers must embed machine-readable marks in generated text, audio, images, and video, and anyone publishing a deepfake must disclose it. Noncompliance carries fines up to €15 million or 3 percent of worldwide annual turnover, whichever is higher. The rules are also extraterritorial — any provider placing an AI system on the EU market is covered regardless of where it is incorporated, which is why Anthropic now watermarks Claude output for every user on Earth, not just the European ones. That is the mechanism behind What is AI watermarking?, and it is the clearest example yet of one regulator setting a global product default.

The United States has no equivalent federal statute. What it has instead is a layer cake: a voluntary White House frontier-model review process, under which a developer can hand a model to the government for up to 30 days before release; executive orders; existing regulators like the FTC applying laws that were never written for AI; and a fast-moving pile of state legislation. OpenAI's own vice president of global policy said the quiet part out loud in Sacramento this year — US AI policy is "really happening in state capitals," with thousands of bills in flight and California's frontier AI transparency law, which requires labs to identify critical risks and report adverse events to the state, acting as the template. A draft executive order to create a self-regulatory organization for AI has reportedly circulated inside the administration, though it has not been adopted.
The mental model
Almost every AI rule in force today sorts systems by risk, not by technology. The question a regulator asks is not "is this AI?" but "what does this AI do, and to whom?" The EU's version has tiers: a short list of outright banned practices; a high-risk category covering things like hiring, credit, and critical infrastructure, which carries obligations around testing, documentation, logging, and human oversight; general-purpose or frontier models, which get their own safety-and-reporting duties; and everything else. Woven through the tiers are transparency duties that apply broadly — you have to say when content is synthetic. Obligations also attach to different actors: the provider who builds the model, and the deployer who puts it in front of people. Many compliance surprises come from companies discovering they are deployers.
An everyday analogy
Think of how we regulate food. Nobody bans "cooking." We license restaurants, we inspect kitchens, we require ingredient labels, we recall batches that make people sick, and we ban a handful of specific things outright — no sawdust in the bread. The rules get stricter the more vulnerable the eater and the bigger the kitchen, and a restaurant that ships across borders follows the destination's rules, not its own.
AI regulation is at roughly the 1910 stage of that story: the inspectorate is being hired, the labeling rule just landed, the banned-ingredients list is short, and nobody has agreed on what counts as a commercial kitchen yet. A model in a hospital is a restaurant; the same model helping you draft an email is a home cook.
Common misconceptions
"There's an AI law now, so AI is regulated." Only partially, and unevenly. In the EU, a Digital Omnibus measure deferred the high-risk obligations to December 2027 and 2028 while leaving the transparency deadlines intact, so the most onerous duties are still ahead. In the US there is still no comprehensive federal statute.
"One global rule is coming." The opposite is happening. Companies are building toward the strictest applicable regime and shipping it everywhere, which is why a Brussels rule ends up on your phone. That is the Brussels effect, the same way GDPR reshaped privacy practices worldwide — and it means a patchwork can still converge, just through compliance departments instead of treaties.
"Regulation means the government tests models before release." Mostly it does not. The US review process is voluntary and covers closed models; the EU relies heavily on provider self-assessment plus documentation that authorities can demand later. Enforcement capacity is genuinely thin — most member states have yet to designate their market surveillance authorities, and after one AI breakout this month, nobody had clear legal power to investigate it.
"Open-weight models are exempt." They are the hardest case, not a loophole. Once weights are downloadable, a pre-release review is a courtesy rather than a control. The White House is expected to extend its oversight to open models once they reach frontier capability — but where that threshold lands is the whole fight, and what counts as an open-weight model in the first place turns out to be a licensing question as much as a technical one.
Where to learn more
The European Commission's transparency guidelines are the most readable primary document in the field — they read like a checklist rather than a statute. Its August 2 announcement explains what actually took effect and when. For the US side, the honest summary is that the story is state-level, and our coverage of that shift is the fastest way in.
Related reading: What is AI watermarking? · What are open-weight models? · AI Brief: EU AI Act transparency rules now enforceable in Europe
Would you rather have one strict global AI rule, or a patchwork where the strictest one wins by default? Tell us in the comments.
Sources: European Commission — Transparency guidelines for AI-generated content · European Commission — Safer and more transparent AI · Wired — The White House is going to expand its AI policy · Politico — OpenAI: AI policy will still be made in the states · AI Midday — EU AI Act transparency rules now enforceable in Europe · AI Midday — After an AI breakout, nobody has the power to investigate