The regulatory landscape for AI safety has fractured along jurisdictional lines. The EU has taken a prescriptive, risk-based approach. The US has taken a sector-specific, agency-led approach. The UK has positioned itself as an innovation-friendly regulator. Asia is a patchwork, with China moving toward comprehensive regulation and Japan, South Korea, and Singapore taking lighter-touch approaches.
For data teams operating across jurisdictions, the regulatory divergence creates a compliance matrix that is difficult to navigate with a one-size-fits-all approach.
The EU: Prescriptive and Risk-Based
The EU AI Act is the most comprehensive AI regulation globally. It classifies AI systems by risk tier and imposes obligations proportional to risk. The Act is prescriptive: it tells organizations what they must do, not just what outcomes they must achieve.
Key obligations for data teams: training data documentation, model logging and traceability, bias testing, human oversight mechanisms, and conformity assessments for high-risk systems. The enforcement mechanism is fines (up to 7% of global turnover) and market access restrictions (non-compliant systems cannot be sold or used in the EU).
The Act is in force with rolling enforcement deadlines through 2027. The codes of practice, which will provide sector-specific implementation guidance, are expected in Q3 2026.
The US: Sector-Specific and Fragmented
The US has no single comprehensive AI regulation. Instead, AI governance is distributed across existing agencies: the FTC handles consumer protection, the SEC handles financial applications, the FDA handles medical devices, and the EEOC handles employment decisions. Each agency applies its existing authority to AI systems within its domain.
The executive order on AI safety (EO 14110) established reporting requirements for large-scale AI training runs and directed agencies to develop AI-specific guidance. The guidance is emerging inconsistently: some agencies have published detailed requirements (the FDA’s guidance on AI in medical devices), while others have issued general principles with no enforcement teeth.
For data teams, the US approach means compliance is determined by industry. A healthcare AI system must comply with FDA guidance. A financial AI system must comply with SEC and CFPB requirements. A general-purpose AI system that does not fall under a specific sector regulator has minimal federal compliance obligations.
The risk is state-level regulation. California, Colorado, Illinois, and New York have each proposed or enacted AI-specific legislation that goes beyond federal requirements. The patchwork is growing, and multi-state operations face a compliance burden that resembles the EU’s in complexity, if not in coherence.
The UK: Principles-Based and Pro-Innovation
The UK has positioned itself as a pro-innovation regulator. The UK AI Safety Institute conducts evaluations of frontier models, but the regulatory approach is principles-based rather than prescriptive. Existing regulators (the FCA, Ofcom, the CMA, the ICO) apply five cross-cutting principles — safety, transparency, fairness, accountability, and contestability — to AI systems within their domains.
The UK approach is lighter than the EU’s, which is by design. The UK government has explicitly stated that it wants to avoid regulation that could stifle AI innovation. For data teams, this means fewer mandatory compliance requirements but less regulatory certainty. The principles are broad enough that compliance is a matter of judgment rather than checklist.
China: Comprehensive and State-Aligned
China’s AI regulation is the most comprehensive outside the EU, but its objectives are different. The primary concerns are content control, social stability, and state alignment. China’s regulations on deepfakes, recommendation algorithms, and generative AI require algorithmic transparency, content labeling, and state review of model outputs.
For data teams serving the Chinese market, the compliance requirements are substantial but well-defined. Models must be registered with the Cyberspace Administration of China. Training data must be reviewed for content that violates Chinese law. Generated content must be labeled as AI-generated.
Asia-Pacific: Diverse Approaches
Japan, South Korea, and Singapore have each adopted lighter-touch approaches that emphasize voluntary guidelines, industry standards, and sandbox programs. Japan’s approach is heavily influenced by its desire to be an AI development hub and is the most permissive of the group. Singapore’s AI Verify framework is a voluntary governance testing toolkit that organizations can adopt to demonstrate responsible AI practices.
For data teams, the Asia-Pacific landscape is simpler than the US or EU landscape but requires country-specific assessment for organizations operating across multiple markets.
What This Means for Global Data Teams
The regulatory divergence creates a design challenge: building AI systems that can comply with the most restrictive applicable regulation without over-engineering for jurisdictions where requirements are lighter.
The practical approach is to build to the EU standard as a baseline. The EU AI Act is the most prescriptive, and compliance with its requirements (data documentation, logging, bias testing, human oversight) satisfies most requirements in other jurisdictions. Jurisdiction-specific add-ons — Chinese content review, US sector-specific requirements, UK principles-based assessments — can be layered on top.
This is not a recommendation to comply with EU regulation because it is the best regulation. It is a pragmatic observation that building to the highest standard and selectively relaxing for lighter jurisdictions is cheaper than building to the lowest standard and retrofitting for stricter ones.
Bounded Recommendation
Map your AI systems to the jurisdictions where they operate. For each system, identify the most restrictive applicable regulation. Build compliance infrastructure to that standard. Maintain a regulatory watch for changes in each jurisdiction, because the landscape is moving fast and the next 12 months will bring significant updates in every major market.