Three AI Regulatory Models: The Complete Comparison Between the EU, the US, and China

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-07-28 | By: Carlos Montiel | Reading time: ~5 minutes

After 24 country-by-country articles, a pattern becomes clear: almost all of the world's AI regulation is a variation on three distinct philosophies. Understanding them is more useful than memorizing each individual law.

Model 1: preventive horizontal risk (European Union)

The EU AI Act classifies any AI system by abstract risk level — minimal, limited, high, unacceptable — before it causes any harm, and requires documentation, conformity assessment, and oversight proportional to that classification from the design stage. It's preventive by design: the obligation exists regardless of whether the system ever fails. The cost is a high, uniform compliance burden; the benefit is predictability — a company knows exactly which category applies to it and what's expected, without depending on case-by-case litigation.

Model 2: market + fragmented state laws, challenged by the federal government itself (United States)

The US has no federal AI law. Instead, states legislate independently (Colorado, California, and dozens more proposals), while the federal government — through the DOJ's AI Litigation Task Force we covered — actively challenges those same state laws in federal court on preemption grounds. The result is an inherently unstable model: no state law can be treated as final until it survives its first court challenge, as happened to Colorado's SB 205.

Model 3: centralized state control by product category (China)

China doesn't classify by abstract risk level — it regulates product category by product category as each gains scale: first generative AI in general (2023), then anthropomorphic-interaction AI (2026). Each new category requires its own security assessment and registration with the CAC. It's reactive but fast, and centralized: a single authority (the CAC, alongside other ministries) decides and enforces, without the US's state fragmentation or the EU's multi-year legislative process.

The hybrid models that borrow pieces from each

Most other countries don't invent a fourth model — they mix pieces of these three. South Korea adopted a "high-impact" structure very similar to Europe's risk classification, but with a one-year grace period before real sanctions. Brazil mirrors the EU's risk structure in PL 2338, still unapproved. Japan and the UK, by contrast, deliberately move away from Europe's preventive model — Japan with a fines-free, reputation-based regime, the UK delegating to existing sector regulators.

What it means to operate under all three models at once

For a company with a presence in the EU, the US, and China simultaneously, the compliance strategy can't be "comply with the strictest law and call it done" — because the three models demand different types of evidence: detailed conformity documentation for the EU, active monitoring of shifting state litigation for the US, and product-specific algorithm registration for China. Mature AI compliance in 2026 is no longer "read a law" — it's maintaining three parallel, structurally distinct processes, each with its own pace of change.

Carlos Montiel
Enterprise AI Solutions Architect
Specialist in LLMs, Agents, and Orchestration
guatemalia.com/en/#contact · info@guatemalia.com

Need to implement AI at your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com