The Regulatory Trilemma
AI regulation in 2025 is split into three competing philosophies: the European Union’s comprehensive, risk-based approach; the United States’ fragmented, innovation-friendly framework; and China’s state-directed, security-focused model. Each has its logic, its advocates, and its critics. Understanding the differences matters because AI companies increasingly have to comply with all three simultaneously — and sometimes the requirements conflict.
The EU AI Act: Risk-Based and Comprehensive
The EU AI Act, formally adopted in May 2024 and entering full effect through 2025-2027, is the world’s first comprehensive AI regulation. Its structure is a risk pyramid:
Prohibited practices (unacceptable risk): Social scoring systems (the “China clause,” effectively), real-time remote biometric identification in public spaces (with narrow exceptions for law enforcement), emotion recognition in workplaces and schools, AI systems that exploit vulnerabilities of specific groups, and predictive policing based on profiling. These are banned outright with fines of up to €35 million or 7% of global annual turnover.
High-risk AI systems: This is the broadest and most impactful category. It covers AI in critical infrastructure, education, employment, law enforcement, migration, and democratic processes. High-risk systems must meet requirements for risk management, data governance, technical documentation, transparency, human oversight, and accuracy. Conformity assessments are required before deployment.
Limited risk: AI systems like chatbots must disclose that users are interacting with AI. Deepfakes must be labeled. These transparency obligations are relatively light.
Minimal risk: Most AI applications (AI-powered video games, spam filters, etc.) are unregulated.
For general-purpose AI models (what the EU calls “GPAI”), including foundation models like GPT-4 and Claude, the Act creates a two-tier system. Models trained with cumulative compute exceeding 10^25 FLOPs face stricter requirements including model evaluations, adversarial testing, incident reporting, and cybersecurity measures. The compute threshold targets the largest models while exempting smaller open-source efforts.
Critics argue the Act will hamper European AI innovation. Supporters counter that clear rules create regulatory certainty that benefits business. The truth probably depends on the specific provision — the transparency requirements are widely supported, while the high-risk conformity assessment process is genuinely burdensome, especially for startups.
United States: Executive Orders and Agency Action
The US approach in 2025 is fragmented, with no comprehensive AI legislation from Congress despite years of hearings and multiple proposed bills. The primary framework comes from executive action:
President Biden’s Executive Order 14110 (October 2023) invoked the Defense Production Act to require companies developing the largest AI models to report training runs, safety test results, and security measures to the federal government. It directed NIST to develop AI safety standards (released 2024: the AI Risk Management Framework and accompanying guidance on synthetic content, red-teaming, and model evaluation) and instructed federal agencies to develop sector-specific AI policies.
The White House secured voluntary commitments from 15 leading AI companies (Amazon, Anthropic, Google, Inflection, Meta, Microsoft, OpenAI, and others) for safety testing, information sharing, watermarking AI-generated content, and investing in cybersecurity. These commitments aren’t legally binding, but the implicit threat of legislation creates compliance pressure.
At the state level, things get chaotic. Colorado passed a comprehensive AI law (SB 205, effective 2026) closely modeled on the EU AI Act’s risk-based framework. California has over 30 proposed AI bills covering everything from safety testing requirements to watermarking to liability for AI-caused harm. Utah, Connecticut, and Texas have focused AI laws, primarily around deepfakes and consumer protection. The resulting patchwork means AI companies face different requirements in different states — exactly the fragmentation that federal legislation could resolve.
China: State Control and Sectoral Regulation
China’s approach to AI regulation is fundamentally different from both the EU and US models — it’s grounded in state control, censorship requirements, and alignment with Communist Party values.
China’s approach is sector-specific rather than comprehensive. The 2022 regulations on algorithmic recommendations require transparency, user opt-out rights, and bans on price discrimination via algorithms. The 2023 “Deep Synthesis” regulations require clear labeling of AI-generated content and consent from individuals whose likenesses are used. The 2023 generative AI regulations require AI services to adhere to “core socialist values,” not engage in “subversion of state power,” obtain licenses, and conduct security assessments before public release.
The practical effect is a licensing regime. As of 2025, over 200 AI models have received approval for public release in China, but the approval process is opaque and the criteria are explicitly political. Models that could generate “harmful information” — undefined in the law, giving regulators maximum discretion — can be denied or have their approval revoked retroactively.
China’s regulatory approach creates an advantage in one dimension: unlike in the EU and US, there’s no ambiguity about what’s permitted. Companies know the rules and can operate within them. The tradeoff is that the rules are designed to serve state interests, not individual rights. Innovation that threatens political control won’t happen in China. Innovation that serves economic growth will be actively supported — which is why Chinese AI companies are advancing rapidly in areas like computer vision, autonomous driving, and industrial AI, but are constrained in areas like general-purpose chatbots and political analysis.
Global Convergence or Divergence?
The trend in 2025 is toward partial convergence around shared principles (transparency, accountability, human oversight) combined with persistent divergence in implementation. The EU AI Act is becoming a de facto global standard — not because companies love it, but because it’s the most detailed framework available and complying with it often satisfies requirements in other jurisdictions.
International coordination efforts exist (G7 Hiroshima AI Process, UK AI Safety Summit and follow-ups, UN AI Advisory Body) but haven’t produced binding agreements. The fundamental tension — between the EU’s precautionary approach, the US’s innovation-first posture, and China’s state-control model — reflects deeper differences in political values that won’t be resolved by international summits.
AI companies operating globally in 2025 need to navigate all three regulatory regimes simultaneously. That’s expensive, legally complex, and — depending on your perspective — either a necessary protection against AI risks or a drag on innovation that entrenches incumbent advantages.
