Ask where AI regulation stands in mid-2026 and you get three different answers depending on the map. The EU wrote one statute for everything and is phasing it in - with a late course-correction. The UK deliberately wrote no statute and routed AI through existing regulators. The US wrote no federal statute, watched its states legislate instead, and is now testing whether Washington can switch the states off.

For legal teams advising across borders - or just buying AI tools used across borders - the three models produce genuinely different obligations on different dates. This flagship comparison in our EU AI Act series sets them side by side.

Legal information, not legal advice - three fast-moving regimes are summarised here as of mid-July 2026, and each entry should be re-verified before you rely on it.

Three models at a glance

The direct comparison: the EU regulates AI through one horizontal, risk-based statute with extraterritorial reach and fines up to EUR 35 million or 7% of worldwide turnover. The UK regulates AI through existing regulators applying five non-statutory principles, with no AI act on the books. The US regulates AI - to the extent it does - through a patchwork of state statutes over a thin federal layer of executive orders, with preemption litigation now shaping the map.

DimensionEUUKUS
InstrumentAI Act (Regulation 2024/1689), amended by the 2026 Digital OmnibusNo AI statute; 2023 white-paper principles via existing regulatorsNo federal statute; state laws plus executive orders
LogicRisk tiers: prohibited, high-risk, transparency, minimalContext-based: same principles, sector by sectorIssue-based: hiring, frontier models, disclosure, per state
Key datesFeb 2025, Aug 2025, Aug 2026; high-risk now Dec 2027Rolling regulator guidance; Growth Bill announced May 2026Most state laws live 1 Jan 2026; Colorado replacement Jan 2027
PenaltiesUp to EUR 35M / 7% of turnoverExisting regimes (e.g. data protection fines)Per statute - e.g. up to USD 200,000 per violation (TX), USD 1M (CA SB 53)
Direction (mid-2026)Simplifying and deferring, core intactPro-innovation; sandbox legislation, still no rulebookStates legislating, federal push to preempt

The EU: one statute, risk tiers, phased enforcement

The EU AI Act is the only comprehensive, binding AI statute among the three. Its architecture is risk-based: eight prohibited practices (banned since February 2025), a high-risk tier with heavy provider and deployer duties, transparency duties for interactive and generative systems (from August 2026), and nothing new for everything else. It reaches any provider or deployer whose system or output is used in the EU, and its general-purpose AI rules have applied to new models since August 2025.

The 2026 twist is the Digital Omnibus: with harmonised standards late and national authorities unready, the EU deferred the stand-alone high-risk regime to 2 December 2027 and embedded high-risk AI to 2028, while adding a new prohibition on non-consensual intimate imagery. The recalibration is significant - and easy to overread. The prohibitions, GPAI duties, transparency wave, and penalty ceilings all stand. The full dates are in our corrected timeline, and the classification logic in our high-risk guide.

The UK: principles, regulators, and still no AI act

The UK chose the opposite instrument: none. The March 2023 white paper "A pro-innovation approach to AI regulation" set five cross-sector principles - safety, transparency, fairness, accountability, contestability - and asked existing regulators (the ICO, FCA, CMA, Ofcom, MHRA and peers) to apply them within their remits. Successive governments have kept that posture; the current one restated in February 2025 that most AI should be regulated at the point of use, while promising targeted legislation for the most powerful models that had still not been introduced by mid-2026 (the running status is tracked in the House of Commons Library briefing).

What has changed is the plumbing around that posture. The Data (Use and Access) Act 2025 loosened the UK GDPR's automated-decision-making restrictions. The May 2026 King's Speech announced the Regulating for Growth Bill, whose AI centrepiece - an "AI Growth Lab" - is a statutory cross-economy sandbox letting ministers licence real-world AI testing with targeted regulatory modifications: an accelerator, not a rulebook. For legal teams the practical source of UK AI obligations therefore remains existing law - data protection under the ICO's AI guidance, equality law, professional conduct rules - rather than anything labelled "AI act".

The US: no federal statute and a contested state patchwork

The US federal layer is executive, not legislative. Executive Order 14179 (January 2025) reset federal policy toward accelerating AI leadership and revoked the previous administration's AI order; a proposed ten-year federal moratorium on state AI enforcement was stripped from the July 2025 budget bill by a 99-1 Senate vote; and in December 2025 Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence", directed the Justice Department to establish an AI Litigation Task Force to challenge state AI laws as unconstitutional or preempted. As of mid-July 2026 no state law had been struck down - but the pressure is already reshaping the map.

Colorado is the cautionary tale. Its 2024 AI Act - the first comprehensive state law, built on algorithmic-discrimination duties - never took effect: enforcement was blocked by a federal court in April 2026 after a challenge the DOJ joined, and in May 2026 the state repealed and replaced it with the narrower, notice-based SB 26-189, effective January 2027. The direction of travel: state laws that survive tend toward transparency and disclosure rather than EU-style risk management.

The US state laws that actually bind in 2026

LawWhat it regulatesStatus (mid-2026)
Texas TRAIGA (HB 149)Prohibited AI uses (manipulation, intentional discrimination, social scoring, biometric misuse); government disclosure dutiesIn force since 1 Jan 2026; AG-enforced
California SB 53 (TFAIA)Frontier-model developers: published safety frameworks, incident reporting, whistleblower protectionIn force since 1 Jan 2026
California AB 2013Training-data disclosure for generative AI offered in CaliforniaIn force since 1 Jan 2026
California AI Transparency Act (SB 942 as amended)Provenance disclosure and AI-detection tools for large generative platformsDelayed to 2 Aug 2026
Illinois HB 3773Employer AI discrimination and notice duties in employment decisionsIn force since 1 Jan 2026
NYC Local Law 144Bias audits and notices for automated employment decision toolsEnforced since July 2023
Colorado SB 26-189Notice, documentation, and human-review rights for automated decisions (replaces the 2024 AI Act)Effective 1 Jan 2027

New York's RAISE Act (signed December 2025) adds frontier-model duties on the coasts' pattern, and further statutes phase in from late 2026. The theme across survivors: employment AI and frontier-model transparency, enforced by attorneys general, with penalties per violation rather than turnover-based.

Where the three models quietly converge

Beneath the instruments, the demands rhyme. All three expect transparency to affected people - the EU's Article 50 disclosure duties, UK regulators' transparency principle, and the disclosure core of Texas, Illinois, and NYC law. All three converge on scrutiny of consequential decisions, above all in employment: high-risk under Annex III, discrimination law in the UK, and the one theme US states agree on. And all three reward documented governance - the EU explicitly, the UK through regulators asking how firms assure AI use, the US through AG investigations that begin with a document request.

That convergence is why a single programme can serve all three regimes. An inventory, per-system classification, disclosure where people interact with AI, human oversight of consequential outputs, and an evidence trail - built once, to the EU standard, then localised. Our governance policy template is structured exactly that way, and the professional-conduct layer for US lawyers is surveyed in our review of state bar AI ethics opinions.

Practical takeaways for cross-border legal teams

Three working rules travel well. Classify against the EU first: it is the strictest common denominator, and an EU-clean stack rarely fails the UK principles or US state disclosure rules on substance. Track dates, not vibes: the binding events of the next eighteen months are 2 August 2026 (EU transparency and enforcement), 2 December 2027 (EU high-risk), January 2027 (Colorado's replacement), and whatever the US preemption litigation produces - advice keyed to dates survives the noise. Watch the employment file everywhere: AI in hiring and people decisions is the one use regulated on all three maps today.

For research teams, the three-regime landscape is itself a workload: the same question - can our client deploy this system? - now has three jurisdictionally distinct answers that change quarterly. That is the work AI legal research with jurisdiction-aware, citation-grounded answers is built to compress, alongside our hubs for the EU, the UK, and the US. Judicio serves teams working across all three from one workspace - start a free trial or talk to us about multi-jurisdiction practice.