The world’s first comprehensive AI law is now in force. The world’s largest AI economy has no federal AI law at all. That is the central fact of the global regulatory landscape in mid-2026, and it is creating a compliance reality that is less about harmonization and more about jurisdictional whiplash.

A detailed guide published by AI Tool Discovery in July 2026 lays out the numbers. The EU AI Act, which entered into force in August 2024, bans six categories of unacceptable-risk AI outright as of February 2, 2025. Fines for the worst violations reach €35 million or 7% of global annual turnover. High-risk AI systems — covering employment screening, credit scoring, law enforcement tools, and critical infrastructure management — face full compliance obligations from August 2, 2026. That date is now weeks away.

The United States has zero federal AI laws as of May 2026. The Biden administration’s Executive Order 14110, which required frontier AI developers to report safety test results before public release, was rescinded by the Trump administration on January 20, 2025, through Executive Order 14179. The replacement positioned AI competitiveness and “freedom to innovate” as the primary objectives, explicitly removing mandatory safety reporting. Forty state bills have been introduced. Only one — Colorado’s AI Act (SB 24-205), effective February 1, 2026 — constitutes a meaningful state-level framework requiring developers and deployers of high-risk AI to avoid algorithmic discrimination and disclose AI use.

The gap is not theoretical. A US startup building an AI hiring tool must comply with the EU AI Act if it sells to French companies, must navigate Colorado’s algorithmic discrimination rules if it operates there, and faces no federal AI law at all. The same tool, deployed in China, must meet the Generative AI Interim Measures from August 2023, which require government approval before public release.

What the EU AI Act Actually Requires

The Act uses a four-tier risk pyramid. Unacceptable-risk AI is banned. High-risk AI requires conformity assessments, technical documentation, human oversight, audit logs, and EU database registration. Limited-risk AI — chatbots, deepfakes, AI-generated content — requires only disclosure to users. Minimal-risk AI — spam filters, video game AI — has no obligations.

The banned category is the most consequential. Real-time remote biometric identification in public spaces is prohibited, with narrow exceptions for terrorism investigation requiring prior judicial authorization. Biometric categorization by sensitive characteristics — race, political opinion, religion, sexual orientation — from publicly available data is banned. Emotion recognition in workplaces and educational institutions is banned. Social scoring systems are banned. AI targeting vulnerable groups through subliminal manipulation is banned. AI systems exploiting psychological vulnerabilities to distort decisions is banned.

The emotion recognition ban drew significant industry attention. Many HR technology products had incorporated emotional state analysis into video interview screening. Those features are no longer legally deployable in the EU for employment purposes.

High-risk AI covers eight categories in Annex III of the Act: biometric identification, critical infrastructure, education and vocational training, employment and HR management, access to essential services, law enforcement, migration and border control, and administration of justice. For each, providers must implement a risk management system, use quality-tested training data, maintain technical documentation, enable automatic audit trail logging, provide human oversight capability including shutdown, and achieve defined accuracy and cybersecurity standards. High-risk penalties reach €15 million or 3% of global annual turnover.

The Act also includes a separate compliance track for General-Purpose AI (GPAI) models — large foundation models used as building blocks for other applications. Providers must make technical documentation available to downstream users, comply with EU copyright law, and publish a summary of training data sources. For GPAI models with systemic risk — those trained on compute exceeding 10^25 FLOPs, which includes ChatGPT 5.2, Gemini 3.1 Pro, and Claude Opus 4.7 — additional requirements apply: mandatory adversarial testing before release, incident reporting to the European AI Office, and ongoing cybersecurity measures.

The US Patchwork

Without federal AI legislation, existing US regulators apply existing authority. The FDA governs AI medical devices through the Software as a Medical Device framework. Over 950 AI-enabled devices received FDA clearance by 2025. The FTC has brought enforcement actions under consumer protection authority against companies making false claims about AI capabilities or safety. The EEOC confirmed in 2023 that Title VII and the Americans with Disabilities Act apply to automated employment screening tools. The CFPB confirmed in 2024 that the Equal Credit Opportunity Act applies to AI credit decisions. The NIST AI Risk Management Framework, published January 2023, is voluntary but widely adopted by federal contractors and large enterprises as a compliance baseline.

California’s SB 1047, which would have required frontier AI developers to conduct safety testing and implement kill switches, passed the state legislature in 2024. Governor Gavin Newsom vetoed it in September 2024, citing concerns about displacing AI innovation from California and applying impractical requirements before harm was demonstrated.

The US approach is frequently described as “sector-specific and ex-post,” applying existing product liability, consumer protection, and civil rights law after harm occurs. The EU approach is ex-ante: classify before you deploy.

GDPR Already Regulates AI

The General Data Protection Regulation (GDPR) already applies to AI systems handling EU personal data. Article 22 provides a right to human review of automated decisions. Articles 13 and 14 require transparency about AI processing. GDPR fines reach €20 million or 4% of global revenue. For any AI system that processes personal data of EU residents, GDPR compliance is mandatory regardless of where the company is headquartered. This is not new law. It is existing law that AI systems increasingly trigger.

What This Means for Builders

The compliance picture in 2026 is fragmented by jurisdiction and by risk tier. A company building a low-risk AI product for the US market may face no AI-specific legal requirements at all. The same company building a high-risk AI product for the EU market faces a compliance process that can take months and cost hundreds of thousands of euros. A company building a general-purpose AI model with systemic risk faces mandatory adversarial testing, incident reporting, and ongoing cybersecurity obligations in the EU, no federal requirements in the US, and government pre-approval in China.

The divergence is not accidental. The EU has chosen a precautionary framework. The US has chosen a deregulatory framework. China has chosen a state-controlled framework. Each choice reflects different assumptions about risk, innovation, and the role of government.

The question for builders is not which framework is best. The question is which frameworks apply to their users. The answer, in 2026, is increasingly all of them.

The EU has chosen a precautionary framework. The US has chosen a deregulatory framework. China has chosen a state-controlled framework. Each choice reflects different assumptions about risk, innovation, and the role of government.

The August 2, 2026 deadline for high-risk AI compliance in the EU is the next major milestone. Companies that have not started the conformity assessment process for their high-risk systems are running out of time. Companies that assumed the US would follow the EU’s lead are adjusting to a regulatory environment that is not converging but diverging. The gap between the world’s two largest AI economies is not narrowing. It is widening.