Tickd.ai
← The Tickd Guide

Ethics & Responsible Use

AI Regulation Around the World: A Plain-English Guide

The EU regulates by risk tier, the US mostly by sector and state, China by content and licensing. A plain-English map of the approaches — not legal advice.

Updated 9/13/2026

There is no global AI law and no sign of one. What exists is three broad philosophies plus a growing number of national variants. Understanding the philosophies is more durable than memorising clauses, which change constantly.

Nothing here is legal advice. If you are deploying AI in a regulated sector, get a lawyer in the relevant jurisdiction.

The European approach: risk tiers, ex ante

The EU's AI Act sorts systems by risk rather than technology. A small set of uses is prohibited outright. A larger "high risk" category — including employment, education, credit, essential services and some biometrics — carries obligations before you go to market: risk management, data governance, documentation, logging, human oversight and conformity assessment. General-purpose models carry transparency and, above a compute threshold, systemic-risk duties. Limited-risk uses mainly owe disclosure, such as telling people they are talking to a machine or that content is synthetic.

Supporters call it predictable and rights-protective. Critics call it heavy, ahead of the technology, and easiest to comply with if you are already large. Both critiques have evidence behind them.

The US approach: sectoral, enforcement-led, plural

No comprehensive federal statute. Instead, existing regulators apply existing law — consumer protection against deceptive AI claims, employment law against discriminatory screening, financial and medical regulators in their own lanes — supplemented by procurement rules, voluntary frameworks and a fast-growing patchwork of state laws on automated decisions, transparency and synthetic media.

Supporters argue this avoids freezing a moving target and keeps liability where harm occurs. Critics argue it produces inconsistency, weak deterrence and fifty different compliance regimes.

The Chinese approach: content, licensing, registration

Rules focus on generated content and its distribution: security assessments and registration for public-facing generative services, labelling of synthetic media, and obligations around training data and outputs consistent with state content requirements. Enforcement is comparatively fast and prescriptive.

Everyone else

The UK has leant on existing regulators with central coordination rather than a single act, alongside investment in evaluation capacity. Canada, Japan, Korea, Brazil, India and others sit at various points between the EU and US models, some with binding statutes, some with guidance. International bodies produce principles and interoperability work, none of it directly enforceable.

The real arguments

Ex ante versus ex post. Certify before deployment, or punish harm after? One prevents damage and slows shipping; the other preserves flexibility and asks victims to litigate.

Model layer versus use layer. Regulate the general-purpose model, or the specific application? Regulating models is tractable and captures things that are not harmful in themselves. Regulating uses is better targeted and misses upstream problems entirely.

Openness. Whether open-weight release should carry obligations at all is unresolved, and it maps directly onto the concentration of power debate.

Compliance cost and competition. Whether serious rules protect the public or entrench incumbents is an empirical question that the next few years will answer, and both sides currently assert it as settled.

What matters if you build

Extraterritorial reach means your users' location can pull you into a regime you did not choose. Disclosure that a person is interacting with AI is the closest thing to a global default. If you are anywhere near hiring, credit, health, education or biometrics, assume high-risk obligations somewhere. Document your data sources, evaluations and human-oversight design as you go, because reconstructing that later is miserable.

Related: the copyright debate, privacy and data use.

ethicsregulationpolicycompliance

Keep going

Build something with the prompt generator, decode the jargon in the glossary, or compare the tools on our platform deep-dives.