KnowledgeInSight
AI Literacy
0% of Course 3 complete

Module 4 · Lesson 1

Governance: Regulatory models: the European Union, the United States, and China

You'll compare three ways governments are regulating AI: one comprehensive risk-based law, a contest between federal and state authority, and state-led rules aimed at content and security. You'll be able to state the case for and against each.

What you will be able to do

  • Compare the main regulatory approaches to AI and the case for and against each.

0% of this lesson · 9 items · 1h 3m total · 48m without the optional journal

Contents of this lesson9 items
  1. ReadingOne Technology, Three Rulebooks3 min
  2. ReadingThe European Union's Risk-Based Law: Four Tiers and a Delayed Timetable4 min
  3. ReadingThe United States: Executive Action, State Laws, and the Preemption Dispute4 min
  4. ReadingChina: State-Led Rules for Generative AI Services and Content Labeling4 min
  5. ReadingThe Case For and Against Each Regulatory Model4 min
  6. Guided ReadingGuided Close Reading: The European Commission's Four Risk Tiers7 min
  7. Guided ConversationRegulate One Use of AI Three Ways12 min
  8. Journal · optionalThe Trade-Off You'd Accept15 min
  9. Knowledge CheckRegulatory models: the European Union, the United States, and China10 min

Reading 3 min

One Technology, Three Rulebooks

This content reflects the field as of October 2026.

News stories often say that AI is "unregulated," and others say that regulators are "cracking down." Both can be accurate on the same day, because the same kind of AI system meets very different rules depending on where it's offered.

In the European Union, a company offering a chatbot answers to a single detailed law. The European Commission, the EU's executive body, calls its AI Act "the first-ever legal framework on AI" (European Commission 2026a). The law sorts uses of AI into levels of risk. It bans a short list of uses outright, attaches duties to others, and leaves most alone.

In the United States, no comprehensive federal AI statute exists. Federal direction comes mainly from the president. An executive order signed in December 2025 declares it national policy "to sustain and enhance the United States' global AI dominance through a minimally burdensome national policy framework for AI" (Executive Office of the President 2025, sec. 2). Several states have passed AI laws of their own, and the same order sets up a task force to challenge state laws in court.

In China, a company offering a generative AI service to the public answers to measures issued by state agencies. Measures in effect since August 2023 require providers to use training data with "lawful sources" and to label generated content. Services with "public opinion properties or the capacity for social mobilization" must pass a security assessment and file their algorithms with the authorities (Cyberspace Administration of China and six other agencies 2023, arts. 7, 12, and 17). The quotations come from an unofficial English translation.

Each rulebook rests on a view about three things.

  • Where the danger lies. The EU law locates it in particular uses, such as hiring or policing. The US order locates a danger in regulation itself, which it treats as a threat to the country's lead. China's measures locate it in content and in threats to public order and security.
  • What innovation needs. The US order assumes that light rules produce faster progress. The EU law assumes that people will adopt AI more readily if they trust it. China's measures state both development and security as aims.
  • Who should decide. In the EU, legislators wrote one law for 27 countries. In the United States, the president, Congress, and the states are contesting the question. In China, state agencies decide.

None of these descriptions tells you which approach works best. That is disputed, and most of the evidence isn't in yet, since many of the rules are new and some haven't taken effect.

The comparison does give you a habit for reading the news. When a headline says a government is "regulating AI," the first useful question is where. The second is what kind of rule it is: a law passed by a legislature, an order from an executive, or a measure from an agency. A report about one place tells you little about the others. All of these rules are also changing, so the date of a report matters as much as its location.

References

  • Cyberspace Administration of China and six other agencies. 2023. "Interim Measures for the Management of Generative Artificial Intelligence Services." Effective August 15, 2023. English translation.
  • European Commission. 2026a. "AI Act." Policy page. Last updated August 3, 2026.
  • Executive Office of the President. 2025. Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence." Federal Register 90: 58499, December 16, 2025.

Report an issue with this item

Reading 4 min

The European Union's Risk-Based Law: Four Tiers and a Delayed Timetable

This content reflects the field as of October 2026.

Introduction

You may have read that Europe "banned AI." The EU's AI Act bans a few uses, regulates some heavily, and leaves most untouched.

This reading explains how the Act sorts uses of AI by risk, what it asks of the companies that build general-purpose models, and how its timetable changed in 2026. It describes the law and gives no legal advice.

Sorting Uses by Risk

Risk-based regulation is an approach to lawmaking that sets heavier duties for uses of a technology that could do more harm. The AI Act, formally Regulation (EU) 2024/1689, applies this approach to AI across the EU's 27 member countries (European Union 2024). The European Commission, the EU's executive body, describes four levels (European Commission 2026a).

LevelWhat falls in itExampleWhat the law does
Unacceptable riskUses considered "a clear threat to the safety, livelihoods and rights of people"Social scoring; emotion recognition at work or in schoolsBans them
High riskUses that "can pose serious risks to health, safety or fundamental rights"Software that sorts job applicationsSets strict duties before and after sale
Transparency riskUses where people need to know AI is involvedA chatbot; a deepfakeRequires disclosure or labeling
Minimal or no riskEverything elseSpam filters; AI in video gamesSets no new rules

A prohibited practice is a use of AI that the law bans outright. A high-risk system is an AI system used in an area the law lists as able to seriously affect health, safety, or basic rights. Its provider must assess and reduce risks, use good-quality data, keep records, and provide for human oversight. A transparency obligation is a duty to tell people that they're dealing with AI or with AI-generated content.

The Commission says that the "vast majority" of AI systems in use in the EU fall into the lowest level (European Commission 2026a).

Rules for General-Purpose Models

The four levels sort uses. The models behind chatbots don't have one use, so the Act treats them separately. General-purpose AI means AI models that can perform a wide range of tasks and that other products are built on.

The Commission's summary says the Act sets rules "on transparency and copyright" for providers of these models, and that providers of models that "may pose systemic risks" must assess and reduce those risks (European Commission 2026a). A code of practice gives guidance on meeting the duties. The Commission describes it as "a voluntary compliance tool."

The Timetable and the 2026 Amendment

The Act took effect in stages.

DateWhat began to apply
February 2, 2025The prohibitions
August 2, 2025Rules for general-purpose models
August 2026Transparency rules
December 2, 2027Duties for stand-alone high-risk systems
August 2, 2028Duties for high-risk systems built into products

The last two dates are new. Under the original text, most of the Act, including the high-risk duties, was to apply from August 2, 2026. An amending law, Regulation (EU) 2026/1744, entered into force on July 27, 2026 and moved the high-risk dates to those in the table (European Union 2026; European Commission 2026a).

The same amendment added to the list of banned uses. It prohibits AI systems that generate sexual images of people without their consent or child sexual abuse material, with effect from December 2026. It also set December 2, 2026 as the deadline for providers of systems already on the market to make AI-generated content identifiable (Council of the European Union 2026).

What the Delay Shows

The Council of the European Union, where member governments vote, presented the amendment as part of a wider effort to cut regulatory burdens, and its announcement points to reports on European competitiveness (Council of the European Union 2026).

Critics of the Act read the delay as evidence that the high-risk duties were too heavy to apply on schedule. Supporters point out that the structure survived: the four levels stand, the prohibitions and the model rules are in force, and a prohibition was added. Both observations are accurate. Whether the delay is a correction or a retreat is a judgment about the law's purpose.

Conclusion

As of October 2026 the AI Act is in force. Its prohibitions, its rules for general-purpose models, and its transparency rules apply, and its duties for high-risk systems are postponed to December 2027 and August 2028. The law regulates uses according to their risk and sets separate rules for the models that many uses are built on. How it works in practice is largely unknown, because its heaviest duties haven't yet applied.

Key Terms

  • Risk-based regulation: An approach to lawmaking that sets heavier duties for uses of a technology that could do more harm.
  • Prohibited practice: A use of AI that the law bans outright.
  • High-risk system: An AI system used in an area the law lists as able to seriously affect health, safety, or basic rights.
  • Transparency obligation: A duty to tell people that they're dealing with AI or with AI-generated content.
  • General-purpose AI: AI models that can perform a wide range of tasks and that other products are built on.

References

  • Council of the European Union. 2026. "Artificial Intelligence: Council Gives Final Green Light to Simplify and Streamline Rules." Press release, June 29, 2026.
  • European Commission. 2026a. "AI Act." Policy page. Last updated August 3, 2026.
  • European Union. 2024. Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union, July 12, 2024.
  • European Union. 2026. Regulation (EU) 2026/1744 (Digital Omnibus on AI). Official Journal of the European Union, July 24, 2026.

Report an issue with this item

Reading 4 min

The United States: Executive Action, State Laws, and the Preemption Dispute

This content reflects the field as of October 2026.

Introduction

People often say the United States has no AI rules. It has many. What it lacks is a single federal law written for AI, so the main argument is over who gets to write the rules: the federal government or the states.

This reading covers federal action by executive order, the laws states have passed, and the dispute over preemption. It describes the situation and gives no legal advice.

Federal Direction by Executive Order

An executive order is a written directive from the president to federal agencies. It doesn't need a vote in Congress, and a later president can revoke it.

AI policy shows how quickly that can happen. In October 2023 President Biden signed an order on safe and trustworthy AI. Among other things, it required developers of the most powerful models to report the results of their safety tests to the federal government (Executive Office of the President 2023, sec. 4.2). President Trump revoked it on January 20, 2025, his first day in office.

In December 2025 President Trump signed a different kind of order. It states a policy of "a minimally burdensome national policy framework for AI" (Executive Office of the President 2025, sec. 2). It directs the attorney general to create a task force to challenge state AI laws in court. It directs the Commerce Department to identify state laws it considers onerous. It also allows some federal funding to be withheld from states with such laws.

In March 2026 the White House published legislative recommendations organized under seven headings, from protecting children to workforce training. The seventh asks for a federal framework, saying that "Congress should preempt state AI laws that impose undue burdens" (White House 2026, pillar 7). These are recommendations to Congress. They have no legal force unless Congress enacts them.

States Acting

A state law is a law passed by one state's legislature that applies within that state. While Congress has not passed a comprehensive AI statute, states have passed their own.

Two examples show the range.

  • California. A law signed in September 2025 applies to large developers of the most capable models. It requires each to publish a framework describing how it has built national standards, international standards, and industry best practices into its approach. It sets up a way to report critical safety incidents to a state office, and it protects employees who report dangers (Office of the Governor of California 2025).
  • Colorado. A law signed in May 2026 repealed and re-enacted the provisions of a 2024 Colorado AI law. It sets requirements for those who build and use automated systems that shape consequential decisions about people, and it lets people correct inaccurate personal data that such a system used. It takes effect on January 1, 2027 (Colorado General Assembly 2026; Colorado Attorney General n.d.).

California's law is built on a disclosure requirement: a duty to make specified information available to the public, to a regulator, or to the people a decision affects. It tells developers what to publish and report. It doesn't tell them how to build a model.

States have kept legislating. In September 2026 alone, California's governor signed more than a dozen further AI bills, on subjects from chatbots used by children to employers' use of AI in firing decisions (Lau and others 2026).

The Preemption Dispute

Preemption is the rule that a federal law overrides state laws on the same subject. If Congress passed an AI statute that preempted state laws, the state laws it covered would stop applying.

Supporters of preemption argue that companies now face a patchwork: a set of rules that differ from one state to the next. They say one national standard would be simpler and would keep any single state from setting policy for the country. Opponents answer that the proposed federal standard is weaker than the state laws it would replace, and that states are acting because Congress hasn't.

As of October 2026 Congress has not passed a preemption statute. A monthly review of US technology policy reported that three senators from both parties were negotiating a bill that would preempt some state AI safety laws, and that its text hadn't been released. The same review reported that 26 state attorneys general asked Congress to legislate while preserving state oversight (Lau and others 2026).

The executive branch has tools short of a statute, including lawsuits and funding conditions. Those can pressure a state. Only Congress or a court can set a state law aside.

Conclusion

As of October 2026 the United States has no comprehensive federal AI statute. Federal policy rests on executive orders that the next president can reverse, and on existing laws that already apply to AI. Several states have passed their own laws. Whether federal law will override those state laws is unresolved.

Key Terms

  • Executive order: A written directive from the president to federal agencies.
  • State law: A law passed by one state's legislature that applies within that state.
  • Disclosure requirement: A duty to make specified information available to the public, to a regulator, or to the people a decision affects.
  • Preemption: The rule that a federal law overrides state laws on the same subject.
  • Patchwork: A set of rules that differ from one state to the next.

References

  • Colorado Attorney General. n.d. "Colorado Automated Decision-Making Technology and Chatbot Safety Rulemaking." Accessed October 3, 2026.
  • Colorado General Assembly. 2026. SB 26-189, "Automated Decision-Making Technology."
  • Executive Office of the President. 2023. Executive Order 14110, "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence." Federal Register 88: 75191, November 1, 2023. Revoked January 20, 2025.
  • Executive Office of the President. 2025. Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence." Federal Register 90: 58499, December 16, 2025.
  • Lau, Rachel, Shirley Frame, Justin Hendrix, and Ashley Faler. 2026. "September 2026 US Tech Policy Roundup." Tech Policy Press, October 1, 2026.
  • Office of the Governor of California. 2025. "Governor Newsom Signs SB 53, Advancing California's World-Leading Artificial Intelligence Industry." September 29, 2025.
  • White House. 2026. A National Policy Framework for Artificial Intelligence: Legislative Recommendations. March 20, 2026.

Report an issue with this item

Reading 4 min

China: State-Led Rules for Generative AI Services and Content Labeling

This content reflects the field as of October 2026.

Introduction

A common assumption outside China is that its government lets AI companies do as they please in order to win a race. China has in fact issued binding rules for generative AI, and it did so earlier than most countries.

This reading describes two sets of Chinese measures and one policy statement, and what can and can't be learned from reading them. It relies on unofficial English translations and gives no legal advice.

Rules Issued by Agencies

State-led governance is an approach in which government agencies write and enforce the rules directly, with the state's own priorities at the center. China's AI rules follow this approach. They come from agencies, chiefly the Cyberspace Administration of China, which regulates the country's internet. Each set of rules targets one kind of service or one problem.

The term interim measures refers to binding rules that an agency issues as a provisional step, expecting to revise them. The best-known example took effect on August 15, 2023. Seven agencies issued it, and it governs generative AI services offered to the public in mainland China (Cyberspace Administration of China and six other agencies 2023).

The 2023 Measures for Generative AI Services

The measures state two aims side by side: to promote the "healthy development" of generative AI and to "preserve national security and the societal public interest" (art. 1). The duties fall on the companies that provide services.

  • Training data. Providers must use data and models "that have lawful sources," and must "respect intellectual property rights" (arts. 4 and 7).
  • Content. Services must "uphold the Core Socialist Values," a set of official principles, and must not generate content the law prohibits (art. 4).
  • Labels. Providers must label generated content such as images and video (art. 12).
  • Security checks. Services with "public opinion properties or the capacity for social mobilization" face two further duties (art. 17). A security assessment is a review of a service's risks that the provider must carry out and report to the authorities. Algorithm filing is the registration of a service's algorithm with the regulator.

The measures don't apply to research and development that isn't offered to the public (art. 2).

The 2025 Labeling Measures

Four agencies issued a second set of rules, in effect since September 1, 2025. Content labeling means marking AI-generated content so that people or software can tell how it was made. The measures require two kinds of label (Cyberspace Administration of China and three other agencies 2025, art. 3).

Kind of labelWhere it sitsWho can see it
ExplicitOn the content or the screen, as text, sound, or an imageUsers, who can clearly perceive it
ImplicitIn the file's dataSoftware; users don't easily notice it

The implicit label carries information such as the provider's name or code and a reference number for the content (art. 5). Platforms that distribute content must check for these labels and add notices (art. 6). Nobody may "maliciously" delete, alter, fabricate, or conceal a label (art. 10).

The 2025 Action Plan

In July 2025 China's foreign ministry published a Global AI Governance Action Plan with 13 points. It's a statement of policy toward other countries and places no duties on companies. It calls for international cooperation, for help to developing countries in building their own capacity, and for the United Nations to serve as "the main channel" (Ministry of Foreign Affairs of the People's Republic of China 2025). It also calls for a widely recognized framework for AI safety.

The plan serves China's interests as its government sees them. A system centered on the United Nations, where every state has a vote, gives less weight to groupings led by the United States and its allies.

What the Texts Can't Tell You

Three cautions apply to everything above.

  • These are translations. The English wording comes from an independent translation project, and the Chinese text is the one with legal force.
  • A rule's text doesn't show how it's enforced. Terms such as "public opinion properties" leave wide discretion to officials. The texts alone can't tell you how strictly or evenly the rules are applied.
  • The same measures do two jobs. Labeling rules and data rules address problems that other countries also worry about. Content rules tie AI services to the state's control of information.

As of October 2026 China's AI rules take the form of targeted measures like these. The sources used here show no single comprehensive AI statute.

Conclusion

China regulates generative AI through binding measures issued by state agencies, aimed at content, security, and registration. The 2023 measures set duties on training data, content, and security checks, and the 2025 measures require visible and embedded labels on AI-generated content. The texts show what's required on paper. How the rules operate in practice needs other evidence.

Key Terms

  • State-led governance: An approach in which government agencies write and enforce the rules directly, with the state's own priorities at the center.
  • Interim measures: Binding rules that an agency issues as a provisional step, expecting to revise them.
  • Security assessment: A review of a service's risks that the provider must carry out and report to the authorities.
  • Algorithm filing: The registration of a service's algorithm with the regulator.
  • Content labeling: Marking AI-generated content so that people or software can tell how it was made.

References

  • Cyberspace Administration of China and six other agencies. 2023. "Interim Measures for the Management of Generative Artificial Intelligence Services." Effective August 15, 2023. English translation.
  • Cyberspace Administration of China and three other agencies. 2025. "Measures for Labeling of AI-Generated Synthetic Content." Effective September 1, 2025. English translation.
  • Ministry of Foreign Affairs of the People's Republic of China. 2025. "Global AI Governance Action Plan." July 26, 2025.

Report an issue with this item

Reading 4 min

The Case For and Against Each Regulatory Model

Introduction

Arguments about AI regulation often sound like arguments about whether to regulate at all. Most of the real disagreement is about which kind of rule, written by whom. Each of the main models has a coherent rationale and a standard objection.

This reading sets out the case for and against four models, with the people who make each case and what they have at stake. All of it is contested.

Two Models Built on Written Law

Risk-based law: the case for. A single law that scales duties to potential harm gives everyone the same rules in advance. A company knows what it must do before it builds, and a person affected by a system knows what protections apply. The European Commission argues that existing law "is insufficient to address the specific challenges AI systems may bring," such as the difficulty of finding out why a system made a decision (European Commission 2026a).

Risk-based law: the case against. A detailed law takes years to write, and the technology moves during those years. It also carries a compliance cost: the money and staff time an organization spends meeting legal requirements. Critics argue that large firms can absorb that cost and small ones can't, so a law meant to restrain big companies may protect them.

State-level rules: the case for. When a national legislature doesn't act, states can. Different states try different rules, and the country learns which ones work. Problems get some response while a national debate continues.

State-level rules: the case against. The result is a regulatory patchwork: a set of rules that differ from one state or country to the next, so that one product must meet many standards. Andrew Ng, founder of the education company DeepLearning.AI and an investor in AI startups, supports a federal framework that overrides state laws, "to prevent a patchwork of state regulations that hamper AI development" (Ng 2026a). Ng's companies build on AI and gain from lighter rules.

Two Models Built on Discretion

Minimal federal regulation: the case for. The argument rests on competitiveness: a country's or company's ability to keep up with or outdo its rivals. On this view, rules written now would slow the companies that follow them, and rivals abroad wouldn't slow down. Jensen Huang, chief executive of the chip maker Nvidia, argued in a September 2026 podcast interview that fears about AI are overstated and that the industry needs no new regulation (Klein 2026b). Nvidia sells the chips that AI development runs on, so it gains when development is fast and unrestricted.

Minimal federal regulation: the case against. Without binding rules, safety depends on what companies choose to do. Bill Gates, co-founder of Microsoft, argued in a podcast interview the same month that the industry can't be relied on to regulate itself and that governments must require safeguards (Klein 2026c). Microsoft is a major AI developer and investor, so Gates's position runs against the usual interest of the industry he comes from.

State-led control: the case for. When government agencies write and enforce rules directly, they can act quickly. A rule can be issued within months and revised as the technology changes. Enforcement, meaning the steps an authority takes to make people and companies follow a rule, is direct, because the agencies that write the rules also license the services.

State-led control: the case against. The speed comes from the absence of checks on the agencies. In practice this model has been tied to the state's control of information, with rules about what content AI may produce. People who value independent courts and free expression see that as the central cost.

The Models Compared and the State of the Evidence

ModelWhat it assumesStrongest objection
Risk-based lawHarms can be anticipated and sorted by useSlow to write, costly to follow, soon out of date
State-level rulesActing locally beats waiting for national agreementA patchwork burdens developers
Minimal federal regulationSpeed matters most, and existing law is enoughSafety is left to companies' own choices
State-led controlThe state can judge and correct risks directlyBound up with control of information

Some parts of this debate rest on facts. Compliance costs are real, and the European Union postponed its own high-risk duties in 2026. Differences among state laws are real and can be read in the laws themselves.

The larger claims are forecasts. Nobody has yet measured whether risk-based law prevents harm or slows innovation, because its heaviest duties haven't applied. Nobody has shown that light regulation produces either a lasting lead or a serious accident. Each side is predicting what will happen, and each named advocate has an interest in the answer.

Conclusion

Each model answers a different fear: unpredictable harm, government inaction, falling behind, or loss of control. Each objection names a real cost. The choice among them depends on forecasts that can't yet be tested and on values about who should hold power.

Key Terms

  • Compliance cost: The money and staff time an organization spends meeting legal requirements.
  • Regulatory patchwork: A set of rules that differ from one state or country to the next, so that one product must meet many standards.
  • Competitiveness: A country's or company's ability to keep up with or outdo its rivals.
  • Enforcement: The steps an authority takes to make people and companies follow a rule.

References

  • European Commission. 2026a. "AI Act." Policy page. Last updated August 3, 2026.
  • Klein, Ezra, host. 2026b. "Jensen Huang Thinks A.I. Alarmism Has Gone Too Far." The Ezra Klein Show, podcast, New York Times, September 23, 2026.
  • Klein, Ezra, host. 2026c. "Bill Gates's Blunt Warning on A.I." The Ezra Klein Show, podcast, New York Times, September 29, 2026.
  • Ng, Andrew. 2026a. "How Anti-AI Propaganda Hurts the Public." The Batch, DeepLearning.AI, March 27, 2026.

Report an issue with this item

Guided Reading 7 min

Guided Close Reading: The European Commission's Four Risk Tiers

Introduction

Summaries of the EU's AI Act usually say it has "four risk tiers" and stop there. The tiers are easier to understand, and to argue about, once you've read how the European Commission describes each one and noticed what kind of thing is being sorted.

This reading walks through the Commission's description of the four levels, one at a time, and then places three everyday uses of AI into them.

Locating the Passage

The passage is on the European Commission's policy page titled "AI Act," which is free and listed in the References. The Commission is the EU's executive body, and this page is its plain-language summary of the law. The version read here was last updated on August 3, 2026.

The page has a section on the law's risk-based approach. It says that "the AI Act defines 4 levels of risk for AI systems" and then describes them from the top down: unacceptable risk, high risk, transparency risk, and minimal or no risk. All quotations are from this page (European Commission 2026a). The law itself is Regulation (EU) 2024/1689, and its articles and annexes hold the binding definitions (European Union 2024).

Walking Through the Passage

Step 1: Read the unacceptable-risk level and find its test

The page says that AI systems considered "a clear threat to the safety, livelihoods and rights of people" are banned. That phrase is the test for the top level. It names three things that could be threatened, and it asks for a threat that is "clear."

A list of banned practices follows. It includes "social scoring," "harmful AI-based manipulation and deception," "emotion recognition in workplaces and education institutions," and "untargeted scraping of the internet or CCTV material to create or expand facial recognition databases."

Every item on the list is a use. The list doesn't ban a kind of software, such as face recognition in general. It bans doing particular things with it, such as building a face database by collecting images indiscriminately.

The list has also grown. As the page stood in August 2026 it had nine items, the ninth being AI systems that generate sexual images without consent or child sexual abuse material. The page notes that the first eight applied from February 2025 and the ninth applies from December 2026.

Step 2: Read the high-risk level and list the kinds of use

The page gives the test: "AI use cases that can pose serious risks to health, safety or fundamental rights are classified as high-risk." Compare the wording with the top level. A "clear threat" has become "can pose serious risks." These uses are permitted, and the law's concern is that they might go wrong.

The page then lists areas. Among them are "AI safety components in critical infrastructures (e.g. transport)," tools used in schools "that may determine the access to education and course of someone's professional life," "AI tools for employment, management of workers and access to self-employment," uses that "give access to essential private and public services," and uses in law enforcement, migration and border control, and the administration of justice.

These areas have something in common. In each, a system's output can change what happens to a person: whether they get a job, a loan, a school place, or a visa.

The duties come next. Providers need "adequate risk assessment and mitigation systems," "logging of activity to ensure traceability of results," and "appropriate human oversight measures," among other things. The page gives December 2, 2027 as the date these duties begin to apply.

Step 3: Read the transparency level and say what it requires

The page describes this level as covering "the risks associated with a need for transparency around the use of AI." The law responds with "specific disclosure obligations to ensure that humans are informed when necessary to preserve trust."

Three duties are named. When people use "AI systems such as chatbots," they "should be made aware that they are interacting with a machine." Providers of generative AI "have to ensure that AI-generated content is identifiable." And deepfakes, along with AI-written text published to inform the public on matters of public interest, "should be clearly and visibly labelled."

This level doesn't restrict what a system does. A chatbot may say what it likes, within other laws. The duty is to tell you what you're dealing with.

Step 4: Read the minimal-risk level and note how much falls here

The fourth description is the shortest: "The AI Act does not introduce rules for AI that is deemed minimal or no risk." The page adds that "the vast majority of AI systems currently used in the EU fall into this category," and gives as examples "AI-enabled video games or spam filters."

This sentence is easy to pass over, and it changes the picture. By the Commission's own account, the law leaves most AI in use alone. The Commission has an interest in presenting its law as measured, so treat "vast majority" as its claim. The claim is consistent with the structure of the law, since the first three levels are defined by lists and the fourth is everything not on them.

Step 5: Place three everyday uses and ask what would move each one up

Take three uses you might meet in a week.

  • A spam filter in your email. The page names spam filters as minimal risk, so no duties apply. The filter itself wouldn't move up. A similar sorting system would, if an employer used it to rank job applications, because employment is a listed high-risk area.
  • A customer-service chatbot on a shop's website. This falls in the transparency level. The shop must make sure you know you're talking to a machine. It would move to high risk if the same chatbot decided whether you qualify for an essential service, such as credit or a public benefit.
  • Software that screens job applications. This is high risk, since the page lists tools for employment and names "CV-sorting software for recruitment" as an example. It would move to the banned level if it tried to read applicants' emotions from their faces or voices in an interview, because "emotion recognition in workplaces" is on the prohibited list.

In each case the software barely changes. The level changes because the use does.

Key Considerations

The page is a summary. It's the Commission's account of the law, written for the public, and it leaves out the conditions and exceptions that the regulation contains. The binding categories are in the regulation itself: the prohibited practices in Article 5 and the high-risk areas in Annex III (European Union 2024). A real system's classification depends on that text, and on guidance and court decisions still to come.

A common mistake is to assume that the Act regulates AI as a technology. For the most part it regulates uses. The same model can power a minimal-risk game and a high-risk hiring tool. The main exception is the Act's separate set of rules for general-purpose models, which apply to a model's provider whatever the model is used for.

A second mistake is to read "high-risk" as "discouraged." High-risk uses are legal. The label triggers duties, and the page presents those duties as what allows such systems to be trusted.

Summary

The Commission describes four levels, each with a test, and the tests concern what a system is used for. The result of the reading is this table.

LevelTestExampleDuty
Unacceptable risk"A clear threat to the safety, livelihoods and rights of people"Social scoringThe use is banned
High risk"Can pose serious risks to health, safety or fundamental rights"Software that sorts job applicationsRisk assessment, record-keeping, human oversight, and other duties, from December 2027
Transparency riskPeople need to know AI is involvedA chatbot; a deepfakeTell people; make AI-generated content identifiable
Minimal or no riskEverything not listed aboveA spam filterNo new rules

References

  • European Commission. 2026a. "AI Act." Policy page. Last updated August 3, 2026.
  • European Union. 2024. Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union, July 12, 2024.

Report an issue with this item

Guided Conversation 12 min

Regulate One Use of AI Three Ways

In this conversation you'll pick one use of AI you care about and work out how three different regulatory models would treat it. You'll leave with a statement of the trade-off you'd be willing to accept.

You'll have this conversation with an AI assistant, using your own account. Choose a button to open a new chat with the prompt already filled in, then press send to start. If the chat opens empty, copy the prompt and paste it in.

Run this conversation in whichever assistant you already use:

Claude desktop app

To use another LLM, simply copy and paste the prompt into its chat window.

Show the full prompt (it lists misreadings to watch for, so skip it if you would rather come to the conversation fresh)
Guided Conversation: Regulate One Use of AI Three Ways (about 12 minutes)

Note to the learner: press send to start. Everything below is facilitator guidance for the AI. It lists misconceptions to watch for, so skip it if you'd rather come to the conversation fresh.

Please facilitate a reflective dialogue with me. I'm an adult with no technical background who has used AI chatbots for everyday tasks, and I'm studying how governments regulate AI: the European Union's risk-based law, the contest between federal and state rules in the United States, and China's state-led measures. Follow this guidance for the whole conversation.

GOAL
I can compare the main regulatory approaches to AI and state the case for and against each, using one use of AI that I care about.

HOW TO RUN THE CONVERSATION
- Ask one question at a time, then wait for my reply. Keep each of your turns under about 120 words.
- Don't lecture. Explain a point only when I need it to continue, then return to my chosen use.
- Be curious and collegial. Use plain words and define any legal or technical term briefly on first use. Welcome disagreement when I give a reason.
- Map positions and evidence. Don't advocate, and give no view of your own on which model is better.
- Plain conversation only: don't search the web or create files or documents.
- Don't ask for anything confidential or personal, and remind me not to share any if I start to.
- Aim for about 12 minutes. Spend most of the time on topics 1 and 3. If my replies are brief, offer one concrete prompt, such as "Think of software that screens job applications, or a chatbot that tutors children," and move on. If I seem uncertain, shorten the conversation to 5-7 minutes. Always reach the final topic.
- Start now. Open with one or two warm sentences: this is a conversation, not a quiz; my reasons matter more than getting the law right; I can ask you to clarify anything. Then ask me to name one use of AI I care about and who it affects.

TOPICS, IN ORDER
1. Three treatments. For my use, work out with me how each model would treat it: where it would likely fall among the EU's four risk levels and what duties follow; what would apply in the United States, where the answer depends on the state and on existing law; and what China's measures would require of a public generative AI service. Ask me to guess first, then fill in what I miss.
2. What each assumes. Ask what each treatment assumes about where harm comes from: particular uses, regulation itself, or content and public order. Follow up on the one I find least convincing.
3. The strongest objection. Ask which treatment I prefer. Then give the strongest objection to it as its critics would, and ask me to answer.
4. Closing. Ask me to state which trade-off I'd accept: what I'd give up to keep the model I prefer. Tell me I can take that into a short optional journal entry.

KEY POINTS TO KEEP ACCURATE
- Give every description of law with a date, and say that it may have changed since. As of October 2026:
- The EU's AI Act is in force. It sorts uses into four levels: banned practices, high-risk uses with strict duties, uses with transparency duties, and minimal-risk uses with no new rules. Bans and rules for general-purpose models already apply. A 2026 amendment postponed the high-risk duties to December 2027 and August 2028.
- The United States has no comprehensive federal AI statute. Executive orders set federal direction and can be revoked. Several states have passed AI laws, including California and Colorado. A December 2025 executive order set up a task force to challenge state laws, and the White House has asked Congress to preempt them. Preemption means federal law overriding state law. Congress had not passed such a statute.
- China regulates through targeted measures from state agencies: 2023 measures on generative AI services (lawful training data, content rules, security assessment and algorithm filing for services that can shape public opinion) and 2025 measures requiring visible and embedded labels on AI-generated content.
- The standard objections: risk-based law is slow, costly, and soon outdated; state-level rules create a patchwork; minimal regulation leaves safety to companies; state-led control is tied to control of information.
- Most claims about which model works best are forecasts. Many of the rules are new or not yet applied.

MISCONCEPTIONS TO CORRECT GENTLY
When one appears, name the accurate version briefly, then return to my use.
- "The US has no AI rules": executive orders, state laws, and existing laws on matters such as consumer protection and discrimination apply.
- "The EU banned AI": it bans a short list of practices and leaves most uses without new rules.
- "China has no AI regulation": it has several binding measures.
- "The EU law regulates the technology": it mostly regulates uses, so the same software can fall in different levels.

LIMITS
- No legal advice. If I ask what the law requires of me, tell me to check the rules that apply to me.
- No policy recommendation, and no view on which model is right.
- Don't favor or disparage any company or government, including the company that built you.
- If you're unsure whether a rule has changed, say so instead of guessing.

TO FINISH
After my closing answer, close in one short turn:
- Affirm one specific thing I worked out, in my own words where possible.
- Suggest one or two next steps that fit how the conversation went. Possible steps: write a journal entry on the trade-off I'd accept; look up whether my own state or country has an AI law; read the European Commission's description of the four risk levels.
- Restate my trade-off on its own line, labeled "The trade-off I'd accept", so I can copy it.

Report an issue with this item

Journal 15 minOptional

The Trade-Off You'd Accept

Overview

You'll choose the regulatory model you find most defensible and write about what it costs. Every model gives something up, and writing down the cost you'd accept shows what you value most in the debate.

The entry is optional. It's for you, and nobody collects it.

Writing Prompt

Choose the regulatory model you find most defensible, state the strongest objection to it, and say what you'd give up to keep it. Write 250–400 words.

Steps

  1. State the model and its rationale. Pick one: a single risk-based law, rules made state by state, minimal federal regulation, or direct control by state agencies. In two or three sentences, say what problem it's meant to solve and what it assumes about where harm comes from.
  2. State the strongest objection as an opponent would. Write it the way someone who holds it would put it. The usual ones are that a detailed law is slow and costly, that state-by-state rules form a patchwork, that light regulation leaves safety to companies, and that state control is tied to control of information.
  3. Say what cost you'd accept. Name something specific you'd give up, such as slower products, uneven protection between places, or less say for local governments. Say why it's worth it to you.
  4. Name a development that would change your choice. Describe one thing that, if it happened, would make you pick a different model. You can draw on any notes of your own.

Self-Check

Before you finish, check that your entry:

  • Describes the model accurately, including what it assumes
  • States the objection at full strength, as an opponent would
  • Names a real cost you'd accept
  • Names something that would change your mind

Nothing is uploaded. Write in your own notebook or document and keep it.

Report an issue with this item

Knowledge Check 10 min

Regulatory models: the European Union, the United States, and China

This ungraded knowledge check assesses your understanding of three approaches to regulating AI. You'll be asked about the EU's risk levels and timetable, the US federal and state picture and preemption, China's measures, and the case for and against each model.

Note: Use this to test yourself, review the feedback on any questions you miss, and retry until you feel confident before moving forward.

5 questions · ungraded · retry as often as you like

Report an issue with this item