How governments are trying to govern the technology.
AI regulation and policy covers the rules, institutions and political choices that govern how artificial intelligence is developed, deployed and monitored. The field is moving beyond broad principles toward risk-based obligations, safety documentation, transparency requirements and conflicts over whether rules should be set locally, nationally or across borders.
AI policy spans more than restrictions on model development. It includes requirements for safety testing, disclosure, human oversight, data governance, public-sector use and accountability when systems are deployed in consequential settings. The central question is increasingly operational: who may authorize an AI system’s use, how risks are evaluated, and which institution is responsible when the system causes harm or fails.
The scope also reaches industrial policy and sovereignty. Governments can shape AI capacity and access through procurement, infrastructure, trade, standards and regulatory acceleration, while treating model access, hosting location and supplier dependence as strategic concerns rather than ordinary software choices.
The European Union’s AI Act is a major example of comprehensive AI regulation. It establishes a risk-based framework for AI developers and applications, with different obligations tied to the type and level of risk associated with a system. The Act also places restrictions on some uses, including facial recognition, and includes transparency and data-disclosure requirements.
The Act came into force on August 1, 2024, with most provisions becoming fully applicable by mid-2026. Its approach extends to foundation models, with additional obligations for certain proprietary models classified as presenting systemic risk. The European Commission has supplemented the framework with guidelines and voluntary codes of practice intended to help companies document AI features and meet compliance expectations.
US AI governance has developed through a mix of executive action, agency guidance, congressional proposals and state legislation. Federal guidance has addressed the government’s own use of AI, including annual reporting by agencies and senior oversight of agency AI systems. At the state level, California has pursued AI-risk initiatives and a safety law requiring companies to disclose their safety-testing regimes.
A central policy conflict is whether federal rules should preempt state AI laws. The White House has called on Congress to create a federal framework that includes preemption and age-gating for AI models, while bipartisan legislation has proposed overriding some state rules and requiring leading developers to implement risk-management plans. Supporters of a national standard emphasize consistency, while state lawmakers continue to pursue their own approaches to safety, disclosure and accountability.
The policy debate is increasingly focused on whether voluntary developer commitments can be converted into repeatable, inspectable controls. Emerging requirements and proposals center on safety protocols, incident disclosure, risk-management plans and documentation. California’s SB 53 and the RAISE Act illustrate a direction of travel toward making developers describe their testing and report significant safety incidents.
This moves AI governance from abstract commitments toward operational assurance. Instead of evaluating a model only before release, regulators and users may seek recurring audits, documented controls, model-inspection methods and deployment-specific monitoring. The challenge is to make oversight meaningful while retaining enough clarity that developers and deployers can understand what compliance requires.
Different jurisdictions are advancing distinct approaches. China has adopted sweeping AI rules overseen by multiple agencies and has considered requirements for human-like AI that would tell users when they are interacting with AI. The United Kingdom has emphasized practical, sector-specific guidance, while the United States, United Kingdom, European Union and others have signed a Council of Europe treaty linking AI use to human rights, democracy and the rule of law.
These approaches are not only legal differences; they are contests over standards-setting, market access and strategic control of frontier capabilities. AI sovereignty therefore includes the ability to determine which providers operate locally, where models are hosted and who can use them. For frontier AI companies, access to capital, deployment rights, safety commitments and model-release practices can become increasingly intertwined with government relationships and national-security priorities.
Implementation will matter as much as legislation. The EU AI Act’s compliance timetable, guidance for models deemed to have systemic risks and voluntary codes of practice will show how a broad statutory framework is translated into developer and deployer obligations. In the United States, the unresolved relationship between federal action and state law will remain a defining institutional question.
Policy will also be tested by new forms of deployment. AI used in public safety, regulated professions, critical infrastructure and emotionally salient companion systems raises different questions about privacy, due process, vulnerable users, disclosure and human-like design. The durable trend is toward governance that addresses both the capabilities of AI systems and the real-world institutions, markets and users affected by their operation.
Grounded in the archive and knowledge graph. Browse all topic guides, the concept reference, or the posts.