Comparative AI Regulation and Technology Law
Introduction
Artificial intelligence regulation has emerged as one of the most dynamic and contested areas of comparative law in the 2020s. Jurisdictions worldwide are racing to develop legal frameworks that harness AI’s economic benefits while mitigating risks to fundamental rights, safety, democratic processes, and public trust. The regulatory landscape is characterized by three competing approaches: comprehensive horizontal regulation (the EU model), sectoral and industry-led governance (the US model), and state-directed development with selective controls (the China model). This article examines AI regulatory frameworks across the United States, United Kingdom, Germany, France, Russia, China, and the European Union.
The European Union: The AI Act
The EU Artificial Intelligence Act (Regulation 2024/1689), adopted in August 2024 and entering into force progressively through 2027, represents the world’s first comprehensive horizontal AI regulation. The Act adopts a risk-based approach categorizing AI systems into four tiers. Prohibited AI practices (Art 5) include social scoring by governments, real-time biometric surveillance in public spaces, and AI systems that exploit vulnerabilities or manipulate behaviour. High-risk AI systems (Annex III) — covering critical infrastructure, education, employment, law enforcement, migration, and access to essential services — must comply with mandatory requirements for risk management, data governance, transparency, human oversight, accuracy, and cybersecurity. Limited-risk systems face transparency obligations (disclosure that content is AI-generated). Minimal-risk systems are unregulated.
The Act establishes a governance architecture including the European Artificial Intelligence Board (EAIB) composed of member state representatives, a scientific panel of independent experts, and national competent authorities. Fines for non-compliance reach the higher of €35 million or 7% of global annual turnover for prohibited practices. The Act also addresses general-purpose AI models (including large language models) through a tiered system: all GPAI models must publish training data summaries and comply with copyright law; systemic GPAI models with significant impact must conduct model evaluations, adversarial testing, and incident reporting. The EU AI Office, established within the European Commission, oversees GPAI enforcement. The AI Liability Directive (proposed 2022, adopted 2024) harmonizes civil liability rules for AI-caused harm.
The United States: Sectoral and Executive Action
The United States has not adopted comprehensive federal AI legislation. Instead, AI governance proceeds through executive action, sectoral regulation, and state legislation. The Biden Administration’s Executive Order 14110 of October 2023 established the most comprehensive federal AI framework to date, requiring developers of powerful AI models to share safety test results with the Department of Commerce, directing agencies to develop AI safety standards, and addressing algorithmic discrimination, worker displacement, and privacy. The Executive Order invoked the Defense Production Act to compel reporting from AI developers.
Sectoral regulators apply existing authorities to AI. The FTC has taken enforcement action against deceptive AI claims (AI washing), algorithmic bias in automated decision-making, and unfair data practices. The Equal Employment Opportunity Commission issued guidance on AI-based hiring tools and adverse impact discrimination. The Consumer Financial Protection Bureau addressed algorithmic credit scoring and black-box underwriting models. The FDA regulates AI-enabled medical devices. At the state level, Colorado enacted the first comprehensive state AI law (SB 24-205, 2024), requiring risk assessments for high-risk AI systems. California, New York, and Washington have proposed similar legislation. The absence of federal pre-emption has produced a patchwork of state requirements.
The United Kingdom: A Pro-Innovation Approach
The UK has adopted a distinct pro-innovation, principles-based approach. The 2023 AI White Paper established five cross-sectoral principles — safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress — to be implemented by existing regulators (Ofcom, the FCA, the ICO, the CMA, and the Health and Safety Executive) within their domains. The approach rejects a single AI regulator or comprehensive statute in favour of iterative, context-sensitive adaptation of existing regulatory frameworks.
The UK hosted the first global AI Safety Summit at Bletchley Park in November 2023, producing the Bletchley Declaration signed by 28 countries and the EU, committing to international cooperation on frontier AI safety. The UK established the AI Safety Institute (AISI) to conduct government-led evaluation of advanced AI models. The Online Safety Act 2023 imposes duties on platforms to address algorithmic content moderation and illegal content, with Ofcom as the enforcement authority. The UK approach emphasizes regulatory agility and minimal legislative intervention, reflecting the government’s objective to position the UK as a global AI leader.
Germany and France: EU Implementation and National Positions
Germany and France, as EU member states, implement the AI Act through national legislation while advancing distinctive national positions. Germany has been among the most vocal advocates for strict AI regulation, particularly on biometric surveillance and high-risk systems. The German Federal Ministry for Digital and Transport published a national AI strategy emphasising trustworthy AI, worker protection (Betriebsrat consultation rights for AI-driven decisions under existing works council legislation), and research funding. German data protection authorities have been active in enforcing GDPR against AI systems, particularly regarding automated decision-making (Art 22 GDPR) and the legality of processing for AI training.
France has advocated for a balanced approach that supports European AI champions while protecting fundamental rights. The French data protection authority (CNIL) has published guidance on AI and data protection, addressing the legality of training data processing, the prohibition on fully automated high-risk decisions, and the right to explanation. Both countries participate in the European AI Board and are developing national AI regulatory sandboxes under the AI Act framework.
Russia: AI Governance Under State Control
Russia’s AI regulatory approach is characterized by state-led development combined with limited legal safeguards. The National Strategy for the Development of AI (2019, updated 2024) prioritises AI as a driver of economic growth and national security. The Strategy calls for increased research funding, AI education, and data availability. The Experimental Legal Regime (ELR) framework (Federal Law No. 258-FZ, 2020) permits regulatory sandboxes for AI projects in Moscow and other regions, allowing exemptions from certain legal requirements for testing autonomous vehicles, medical AI, and other applications.
Russia lacks comprehensive AI-specific regulation addressing bias, transparency, or accountability. Data localization requirements under Federal Law No. 242-FZ (2015) mandate that personal data processing use Russian servers, creating tensions with cross-border AI training. AI-generated content is not subject to special disclosure obligations. The use of AI in criminal justice, facial recognition in public spaces, and predictive policing operates without specific statutory frameworks, raising concerns about arbitrary application and lack of oversight.
China: State-Led Development with Selective Control
China’s AI governance model reflects the Party-state’s dual objective of technological leadership and social control. The New Generation AI Development Plan (2017) set the goal of making China the world’s leading AI innovator by 2030, backed by massive state investment, AI infrastructure, and government procurement of AI systems. The regulatory approach combines comprehensive framework legislation with targeted restrictions on specific AI applications.
China’s key AI regulations include the Algorithmic Recommendation Regulation (2022), requiring transparency in algorithm use, user control over recommendations, and alignment with socialist core values. The Deep Synthesis Regulation (2023) imposes disclosure, data subject consent, and content labelling requirements for AI-generated content, reflecting concerns about deepfakes and disinformation. The Generative AI Regulation (2023, effective August 2023) requires GenAI providers to conduct security assessments, ensure training data legality, prevent generation of illegal content, and implement content filtering. The regulation mandates that GenAI content align with socialist core values, refrain from inciting subversion of state power, and avoid discrimination, which effectively requires compliance with Party-state orthodoxy.
China’s distinctive approach includes the use of AI for state governance — social credit systems, facial recognition surveillance, predictive policing — while tightly controlling private-sector AI development through licensing, content moderation, and security review requirements. The Cyberspace Administration of China (CAC) serves as the primary AI regulator, enforcing rules that combine consumer protection with political control.
Comparison of Approaches
The four models — EU comprehensive rights-based regulation, US sectoral enforcement, UK pro-innovation principles, and Chinese state-led development with political control — reflect fundamentally different constitutional values, market structures, and governance traditions. The EU model prioritizes fundamental rights and democratic accountability through ex-ante compliance obligations. The US model relies on ex-post enforcement and agency guidance, producing regulatory fragmentation but enabling rapid innovation. The UK model bet on regulatory agility and international convening power, though its light-touch approach faces pressure as frontier AI capabilities accelerate. China’s model treats AI as a strategic asset for economic competitiveness and party-state control, with regulation serving both consumer protection and political stability objectives. The convergence of these models — through international bodies like the OECD AI Principles, the Global Partnership on AI, and the Council of Europe’s Framework Convention on AI — remains limited, reflecting deep differences in the values that AI regulation is meant to serve.
Emerging Issues
Key comparative issues include the regulation of frontier AI models (capabilities-based thresholds vs uniform rules), liability for AI-caused harm (strict vs fault-based), intellectual property for AI-generated works, the use of copyrighted training data, the legal status of autonomous systems (agency, criminal responsibility, contractual capacity), and the international governance of AI through global institutions. The Council of Europe’s Framework Convention on AI (May 2024), the first international AI treaty, establishes principles of human dignity, transparency, accountability, and non-discrimination, with signatories required to implement measures addressing AI risks while respecting human rights, democracy, and the rule of law.